Website access method, device, electronic device and storage medium
By building a consortium certificate blockchain in the public key infrastructure, the problem of website access reliability caused by the distrust of root certificate authority distribution is solved, stable and efficient access to network devices is achieved, and the tamper-proof nature of the blockchain is used to ensure the validity and security of the certificate.
Patent Information
- Application Number
- CN202411441170.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-15
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2044-10-15
AI Technical Summary
In the existing public key infrastructure, since root certificate authorities are usually distributed in different regions and their management is not trusted, there are trust issues, certificate invalidity, revocation risks, tampering risks and information security risks when network devices access websites, resulting in low reliability of website access for network devices.
By building a federation certificate blockchain, multiple root certificate authorities are managed in alliance, and the legitimate root of each root certificate authority is stored in the federation certificate blockchain. By utilizing the tamper-proof characteristics of the blockchain, network devices are ensured to obtain the target root certificate of the target root certificate authority from the federation certificate blockchain for access.
It improves the reliability of network devices accessing websites, avoids the possibility of invalid certificates, reduces communication overhead by presetting the acquisition cycle time, and ensures the stability and security of access.
Smart Images

Figure CN119449318B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to a website access method, device, electronic device, and storage medium. Background Art
[0002] A public key infrastructure (PKI) is a system that uses public key cryptography to implement secure communications and digital signatures. Within a PKI, there are typically multiple layers of interconnected certificate authorities (CAs), each managing the certificate resources of all the CAs to which it is associated.
[0003] In related technologies, when a network device accesses a website, it uses relevant certificate resources for verification. Only after verification is passed is the network device allowed to access the website, thereby ensuring the security of website access. However, the upper-level certificate authorities are typically located in different regions and managed by the management objects of that region. When using this traditional method to access a website, there is a possibility that the certificate resources used by the network device may be invalid due to issues such as the regional differences between the network device and the upper-level certificate authority, network interference, and human interference, thus preventing normal website access. Summary of the Invention
[0004] The embodiments of the present application provide a website access method, device, electronic device, and storage medium, which can effectively improve the reliability of website access by network devices.
[0005] To achieve the above-mentioned purpose, a first aspect of an embodiment of the present application provides a website access method, the method comprising:
[0006] Determining a target root certificate authority corresponding to the target website from a plurality of root certificate authorities, wherein the plurality of root certificate authorities are located in the same alliance certificate blockchain, and the alliance certificate blockchain is used to store at least an institutional root certificate of each of the root certificate authorities;
[0007] Obtaining a target organization root certificate corresponding to the target root certificate authority from the alliance certificate blockchain;
[0008] The target website is accessed based on the target organization root certificate.
[0009] In some embodiments, obtaining the target authority root certificate corresponding to the target root certificate authority from the federated certificate blockchain includes:
[0010] Obtaining root authority identifiers and root certificates of all root certificate authorities from the alliance certificate blockchain;
[0011] A target organization identifier corresponding to the target root certificate authority is obtained, and the target organization root certificate is selected from the plurality of organization root certificates based on the target organization identifier.
[0012] In some embodiments, obtaining the root authority identifiers and authority root certificates of all root certificate authorities from the federated certificate blockchain includes:
[0013] Get the preset acquisition cycle time;
[0014] Based on the preset acquisition cycle time, the root authority identifiers and the authority root certificates of all root certificate authorities are periodically obtained from the alliance certificate blockchain.
[0015] In some embodiments, obtaining a preset acquisition cycle time includes:
[0016] Obtaining a first update interval mean and a first update interval median for all newly added block information in the federated certificate blockchain within a first past time period, and obtaining a second update interval mean and a second update interval median for all newly added block information in the federated certificate blockchain within a second past time period, wherein the first time period is less than the second time period;
[0017] Performing data averaging processing on the first update interval mean and the first update interval median to obtain a first interval mean, and performing data averaging processing on the second update interval mean and the second update interval median to obtain a second interval mean;
[0018] Multiply the first interval mean by the first weight to obtain a first weight interval, multiply the second interval mean by the second weight to obtain a second weight interval, accumulate the first weight interval and the second weight interval to obtain the preset acquisition cycle time, the first weight is greater than the second weight, and the sum of the first weight and the second weight is equal to one.
[0019] In some embodiments, the network device stores a backup organization root certificate corresponding to the target organization identifier, and obtaining the root organization identifiers and organization root certificates of all root certificate organizations from the alliance certificate blockchain includes:
[0020] Sending an access request to the target website based on the backup organization root certificate;
[0021] receiving failure feedback information issued by the website server corresponding to the target website according to the access request and the backup organization root certificate;
[0022] According to the failure feedback information, the root authority identifiers and the root certificates of all root certificate authorities are obtained from the alliance certificate blockchain.
[0023] In some embodiments, the network device stores a certificate validity period corresponding to the target organization identifier, and obtaining the root organization identifiers and organization root certificates of all root certificate authorities from the alliance certificate blockchain includes:
[0024] If the current time is not within the validity period of the certificate, the root authority identifiers and the root certificates of all root certificate authorities are obtained from the alliance certificate blockchain.
[0025] In some embodiments, before obtaining the target organization root certificate corresponding to the target root certificate authority from the alliance certificate blockchain, when a new root certificate authority joins the alliance certificate blockchain, at least one of the organization root certificate, root organization identifier, organization registration information, region code, applicable software information, and region signature information of the new root certificate authority is synchronously uploaded to the chain.
[0026] To achieve the above-mentioned purpose, a second aspect of an embodiment of the present application provides a website access device, the device comprising:
[0027] an organization determination module, configured to determine a target root certificate authority corresponding to a target website from a plurality of root certificate authorities, wherein the plurality of root certificate authorities are located in a same alliance certificate blockchain, and the alliance certificate blockchain is configured to store at least an organization root certificate of each of the root certificate authorities;
[0028] A certificate acquisition module, configured to obtain a target organization root certificate corresponding to the target root certificate authority from the alliance certificate blockchain;
[0029] A login module is used to access the target website based on the target organization root certificate.
[0030] To achieve the above-mentioned purpose, a third aspect of an embodiment of the present application proposes an electronic device, which includes a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, it implements the website access method described in the first aspect.
[0031] To achieve the above-mentioned purpose, the fourth aspect of the embodiments of the present application proposes a storage medium, which is a computer-readable storage medium and stores a computer program. When the computer program is executed by a processor, it implements the website access method described in the first aspect above.
[0032] The website access method, device, electronic device and storage medium proposed in the embodiment of the present application include the following steps: first, determining the target root certificate authority corresponding to the target website from multiple root certificate authorities, wherein the multiple root certificate authorities are located in the same alliance certificate blockchain, and the alliance certificate blockchain is used to store at least the institutional root certificate of each root certificate authority; then, obtaining the target institution root certificate corresponding to the target root certificate authority from the alliance certificate blockchain; and finally, accessing the target website based on the target institution root certificate. The embodiment of the present application utilizes the alliance certificate blockchain to manage multiple root certificate authorities in the same or different regions, and utilizes the characteristic that the blockchain's chain information cannot be tampered with to store the legitimate institutional root of each root certificate authority in the alliance on the alliance certificate blockchain. Therefore, when a network device accesses a target website, the target institution root certificate corresponding to the target root certificate authority corresponding to the target website obtained from the alliance certificate blockchain can be used to perform normal target website access, thereby avoiding the possibility of invalid certificates, thereby greatly improving the reliability of website access by network devices.
[0033] Other features and advantages of the present application will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present application. The purposes and other advantages of the present application can be achieved and obtained through the structures particularly pointed out in the description, claims and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] Figure 1 This is a structural diagram of a website public key infrastructure provided by an embodiment of the present application.
[0035] Figure 2 This is a flowchart of a website access method provided by another embodiment of the present application.
[0036] Figure 3 This is a schematic diagram of the architecture of a root certificate authority alliance provided in another embodiment of the present application.
[0037] Figure 4 yes Figure 2 Flowchart of step 202 in FIG.
[0038] Figure 5 yes Figure 4 Flowchart of step 401 in FIG.
[0039] Figure 6 yes Figure 5 Flowchart of step 501 in FIG.
[0040] Figure 7 yes Figure 4 Another flow chart of step 401 in FIG.
[0041] Figure 8 yes Figure 4 Another flow chart of step 401 in FIG.
[0042] Figure 9 Schematic diagram of the structure of a website access device provided in one embodiment of the present application.
[0043] Figure 10 This is a schematic diagram of the hardware structure of an electronic device provided in another embodiment of the present application. DETAILED DESCRIPTION
[0044] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0045] It should be noted that although the functional modules are divided in the device schematic and the logical order is shown in the flowchart, in some cases, the steps shown or described can be performed in a different order than the module division in the device or the order in the flowchart.
[0046] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application pertains. The terms used herein are for the purpose of describing the embodiments of this application only and are not intended to limit this application.
[0047] First, let’s analyze some of the terms used in this application:
[0048] Web Public Key Infrastructure (WebPKI) is a system that uses public key cryptography to implement secure communications and digital signatures. It provides a trust model that allows users to be confident that the person they are communicating with is trustworthy and that the content of the communication cannot be tampered with.
[0049] Reference Figure 1 , is a schematic diagram of the structure of a website public key infrastructure provided by an embodiment of the present application. Figure 1 As shown in , in the related art, it is usually composed of multiple certificate authorities that are associated layer by layer, including a root certificate authority at the top layer, multiple upper-layer certificate authorities associated with the root certificate authority, and multiple lower-layer certificate authorities associated with the upper-layer certificate authority. Each lower-layer certificate authority is associated with multiple website servers and is used to authorize resource certificates for these website servers so that these website servers can manage multiple resource websites. It is understandable that the embodiment of this application only illustrates a three-layer certificate authority. In actual applications, there are usually more certificate authority architectures than three layers.
[0050] When any network device accesses a resource website managed by a network server, the network device usually uses the pre-acquired agency certificate of the certificate authority corresponding to the network server as login verification information. Then, when the network server receives the access request and agency certificate of the network device, it will verify it based on the agency certificate and allow the network device to access the resource website after the verification is passed, thereby ensuring the security of website access.
[0051] However, if Figure 1 As shown in the website public key infrastructure, root certificate authorities and upper-level certificate authorities are typically located in different regions and managed by the management objects of those regions. When network devices in different regions need to access resource websites indirectly managed by the upper-level certificate authority in that region, trust issues may arise due to regional differences between the network devices and the upper-level certificate authority, network interference, and human interference, as described below.
[0052] 1) Risk of root CA ceasing to issue certificates (risk of isolation and blindness): When the certificate resource registration used by a website server in a certain region depends on the root certificate authority in another region, once the root certificate authority in the other region does not issue the resource certificate to the website server due to distrust between the two regions, or due to network problems between the two regions, the resource website managed by the network server will not be able to be used normally.
[0053] 2) Risk of root CA revoking issued certificates (disappearance risk): When the certificate resource registration used by a website server in a certain region depends on the root certificate authority in another region, once the root certificate authority in the other region cancels the resource certificate originally issued to the website server due to distrust between the two regions, the encryption services of all domain name websites of the website server will disappear, and the encryption services between its corresponding domain name websites and users will be interrupted, causing the entire network system to be paralyzed.
[0054] 3) Risk of certificate tampering (hijacking): When the certificate resource registration used by a website server in a certain region relies on a root certificate authority in another region, when the root certificate authority in another region is attacked or performs malicious operations or issues certificates containing false information, it is easy for the resource website held by the website server to be attacked or even hijacked.
[0055] 4) Information security risk: When the certificate resource registration used by a website server in a certain region relies on the root certificate authority in another region, the daily traffic network service information of the website server in that region (such as website access information of network devices) will be mastered by the root certificate authority in the other region. If the relationship between the two regions is not harmonious, it will cause serious information security leakage risks.
[0056] In reality, in current website public key infrastructure, multiple root certificate authorities are typically located in a few regions. These root certificate authorities are then directly or indirectly linked to website servers in most regions. When there's distrust or conflict between regions, the four aforementioned scenarios are prone to occur, reducing the reliability of website access on network devices.
[0057] Based on this, in order to effectively improve the reliability of website access by network devices, the embodiment of the present application utilizes the alliance certificate blockchain to manage multiple root certificate authorities in the same or different regions in an alliance, and utilizes the characteristic that the blockchain's on-chain information cannot be tampered with, and stores the legitimate institutional roots of each root certificate authority in the alliance on the alliance certificate blockchain. Therefore, when the network device accesses the target website, it can use the target institutional root certificate corresponding to the target root certificate authority corresponding to the target website obtained from the alliance certificate blockchain to perform normal target website access, so as to avoid the possibility of invalid certificate, thereby greatly improving the reliability of website access by network devices.
[0058] The website access method, device, electronic device, and storage medium provided by the embodiments of the present application will be further described below. The website access method is applicable to any network device.
[0059] Reference Figure 2 , which is an optional flow chart of the website access method provided in an embodiment of the present application, Figure 2 The method may include but is not limited to steps 201 to 203. It is also understood that this embodiment is for Figure 2 The order of step 201 to step 203 is not specifically limited, and the order of steps can be adjusted or some steps can be reduced or added according to actual needs.
[0060] Step 201: Determine a target root certificate authority corresponding to a target website from multiple root certificate authorities.
[0061] Step 201 is described in detail below.
[0062] In some embodiments, in order to avoid the problem mentioned in the related art that the certificate resources used by the network device are invalid due to the different regions between the network device and the upper certificate authority, network and human interference, etc. Figure 1 In addition to the public key infrastructure architecture for websites shown in the previous section, a new root certificate authority alliance was also established. Figure 3 , is a schematic diagram of the architecture of a root certificate authority alliance provided by the embodiment of this application. Figure 3As shown in , multiple root certificate authorities (which can be in the same region or different regions) Figure 1 The upper-level certificate authorities or root certificate authorities or even the certificate authorities at a certain level in the middle shown in the figure form an institution alliance. Then all the root certificate authorities in the alliance trust each other's root certificates, and each root certificate authority directly or indirectly authorizes multiple website servers.
[0063] Thus, it is possible to achieve that the root certificates held by all root certificate authorities in the root certificate authority alliance are generated based on the cross-signature of the root certificate authority's root. It is understandable that the root certificate refers to the random number private key generated by the root certificate authority.
[0064] In addition, the root certificate authority alliance is also provided with a federation certificate blockchain, which stores the root authority-related information of all root certificate authorities in the root certificate authority alliance, wherein the root authority-related information includes: the institution's root certificate, root authority identification, institution registration information, certificate validity period, region code, applicable software information (i.e., the browser software name and version applicable to accessing the resource website corresponding to the institution's certificate), signature information of the region, and the region code of all root certificate authorities in the institution alliance. It is understandable that in the root certificate authority alliance, there may be a situation where a region has multiple root certificate authorities, and the root authority-related information of multiple root certificate authorities in the region are all stored in the federation certificate blockchain. Thus, by utilizing the characteristic that the blockchain's on-chain information cannot be tampered with, the possibility of invalid root certificates obtained by network devices from the federation certificate blockchain is avoided.
[0065] In addition, when a new root certificate authority joins the root certificate authority alliance, that is, joins the alliance certificate blockchain, the root authority-related information and chain-up time of the new root certificate authority are uploaded to the alliance certificate blockchain to generate a new block.
[0066] Based on Figure 3 In the root certificate authority alliance shown, when any network device that can be connected to the alliance certificate blockchain responds to the access request of the resource website managed by the root certificate authority alliance (i.e., the target website), the network device first determines the website server corresponding to the target website, and then further determines the target root certificate authority corresponding to the target website from multiple root certificate authorities based on the certificate authority to which the website server belongs.
[0067] Step 202: Obtain the target organization root certificate corresponding to the target root certificate authority from the alliance certificate blockchain.
[0068] Step 202 is described in detail below.
[0069] In some embodiments, after the network device determines the target root certificate authority, to further ensure normal access to the target website, the network device will obtain the target organization root certificate corresponding to the target root certificate authority from the federated certificate blockchain, thereby facilitating subsequent use of the target organization root certificate to access the target website. The following further describes how to obtain the target organization root certificate from the federated certificate blockchain.
[0070] Reference Figure 4 , obtaining the target organization root certificate corresponding to the target root certificate authority from the alliance certificate blockchain, including the following steps 401 to 402.
[0071] Step 401: Obtain the root authority identifiers and root certificates of all root certificate authorities from the alliance certificate blockchain.
[0072] Step 402: Obtain a target organization identifier corresponding to a target root certificate authority, and select a target organization root certificate from multiple organization root certificates based on the target organization identifier.
[0073] Steps 401 to 402 are described in detail below.
[0074] In some embodiments, to improve the efficiency of obtaining institutional root certificates, after determining a target root certificate authority, the network device obtains the root authority identifiers and institutional root certificates of all root certificate authorities in a root certificate authority alliance from a federated certificate blockchain in advance, and then installs these institutional root certificates in the network device so that the network device can use these institutional root certificates when accessing a resource website through a browser carried by the network device. The target institution identifier corresponding to the target root certificate authority is then further determined, and the target institution identifier is used to determine the target institutional root certificate from multiple institutional root certificates.
[0075] Since it is cumbersome and communication overhead for a network device to obtain relevant data information from the alliance certificate blockchain each time it accesses a resource website, and the information in the alliance certificate blockchain is not frequently updated, in order to further reduce communication overhead, this embodiment will pre-acquire the root organization identifiers and organization root certificates of all root certificate organizations in the alliance certificate blockchain and save them in the storage device of the network device for use when accessing a resource website (including a target website), as described in detail below.
[0076] Reference Figure 5 , obtaining the root authority identifiers and authority root certificates of all root certificate authorities from the alliance certificate blockchain, including the following steps 501 to 502.
[0077] Step 501: Obtain a preset acquisition cycle time.
[0078] Step 502: Based on a preset acquisition cycle time, periodically obtain the root authority identifiers and authority root certificates of all root certificate authorities from the alliance certificate blockchain.
[0079] Steps 501 to 502 are described in detail below.
[0080] In some embodiments, in order to effectively reduce the communication overhead of network devices, frequency information will be added in advance based on the data of the alliance certificate blockchain to obtain a preset acquisition cycle time, and then based on the preset acquisition cycle time, the root organization identifiers and organization root certificates of all root certificate organizations are periodically obtained from the alliance certificate blockchain and saved in the storage device of the network device for use when accessing resource websites (including target websites).
[0081] Through the above steps 501 to 502, the root organization identifiers and organization root certificates of all root certificate organizations are periodically obtained from the alliance certificate blockchain using the preset acquisition cycle time obtained from the frequency information of new data additions to the alliance certificate blockchain. Therefore, when the network device accesses the target website, the target organization root certificate required by the target website can be directly used without having to obtain data from the alliance certificate blockchain again, thereby effectively reducing the communication overhead of the network device.
[0082] How to determine the preset acquisition cycle time will be further described below.
[0083] Reference Figure 6 , obtaining a preset acquisition cycle time, including the following steps 601 to 603.
[0084] Step 601: Obtain a first update interval mean and a first update interval median for all newly added block information in the alliance certificate blockchain within a first past time period, and obtain a second update interval mean and a second update interval median for all newly added block information in the alliance certificate blockchain within a second past time period.
[0085] Step 602: performing data averaging processing on the first update interval mean and the first update interval median to obtain a first interval mean, and performing data averaging processing on the second update interval mean and the second update interval median to obtain a second interval mean.
[0086] Step 603: multiply the first interval mean by the first weight to obtain a first weight interval, multiply the second interval mean by the second weight to obtain a second weight interval, and accumulate the first weight interval and the second weight interval to obtain a preset acquisition cycle time.
[0087] Steps 601 to 603 are described in detail below.
[0088] In some embodiments, in order to generate an appropriate preset acquisition cycle time, the first update intervals x between every two consecutive newly added blocks (i.e., a new root certificate authority joins the root certificate authority alliance, and the root institution related information of the new root certificate authority is uploaded to the blockchain to generate a newly added block) in the alliance certificate blockchain for multiple preset time periods in the past (including a first time period t1 for a short time period recently and a second time period t2 for a relatively long time period, and t1 < t2) are pre-acquired, and the average value and median value of these first update intervals x are obtained to get the first update interval average value corresponding to the first time period and the first update interval median value y1, as well as the second update interval average value corresponding to the second time period and the second update interval median value y2.
[0089] Next, the data of the first update interval average value and the first update interval median value y1 are averaged to obtain the first interval average value and the data of the second update interval average value and the second update interval median value y2 are averaged to obtain the second interval average value Then, the first interval average value is multiplied by the first weight α1 to obtain the first weighted interval, the second interval average value is multiplied by the second weight α2 to obtain the second weighted interval, and finally the first weighted interval and the second weighted interval are accumulated to obtain the preset restart time
[0090]
[0091] Among them, since the first time period is smaller than the second time period, that is, the first time period is closer to the current update moment compared with the second time period, the data information of the first interval average value corresponding to the first time period can better reflect the new addition interval of the newly added blocks in the alliance certificate blockchain at the current moment. Therefore, the first weight α1 is greater than the second weight α2, and the sum of the first weight and the second weight is equal to one.
[0092] Through the above steps 601 to step 603, by using the update interval average value and update interval median value corresponding to two recent time periods in the alliance certificate blockchain, and further combining different weights corresponding to different time periods, a preset restart time that better conforms to the new addition interval of the newly added blocks in the alliance certificate blockchain at the current moment can be generated more effectively.
[0093] Referring to Figure 7 , to obtain the root institution identifiers and institution root certificates of all root certificate authorities from the alliance certificate blockchain, the following steps 701 to step 703 are further included.
[0094] Step 701: Send an access request to the target website based on the backup organization root certificate.
[0095] Step 702: Receive failure feedback information sent by the website server corresponding to the target website based on the access request and the backup organization's root certificate.
[0096] Step 703: According to the failure feedback information, the root authority identifiers and the root certificates of all root certificate authorities are obtained from the alliance certificate blockchain.
[0097] Steps 701 to 703 are described in detail below.
[0098] In some embodiments, after the network device obtains the root organization identifiers and organization root certificates of all root certificate authorities from the alliance certificate blockchain in advance and stores them in a storage device as backup data (including the backup organization root certificate corresponding to the target organization identifier), the network device sends an access request to the target website based on the backup organization root certificate. At this time, there is a situation where the organization root certificate corresponding to the target organization identifier has been updated, that is, the organization root of the target root certificate authority itself has been updated, so that the organization root certificate has been updated. At this time, the target root certificate authority will chain the updated root organization related information again in the alliance certificate blockchain to generate a new block, but this new block occurs within the preset acquisition cycle time (that is, after the network device last acquired data in the alliance certificate blockchain and before the next data acquisition in the alliance certificate blockchain).
[0099] At this point, the network device will receive a failure feedback message from the website server corresponding to the target website, based on the target website's access request and the backup organization's root certificate. Based on this failure feedback message, the network device will retrieve the root organization identifiers and organization root certificates of all root certificate authorities from the alliance certificate blockchain again, so as to obtain a new target organization root certificate for the target root certificate authority corresponding to the target website, thereby facilitating the subsequent use of the new target organization root certificate to access the target website.
[0100] Reference Figure 8 , obtaining the root authority identifiers and authority root certificates of all root certificate authorities from the alliance certificate blockchain, also includes the following steps 801.
[0101] Step 801: If the current time is not within the certificate validity period, obtain the root authority identifiers and root certificates of all root certificate authorities from the alliance certificate blockchain.
[0102] Step 801 is described in detail below.
[0103] In some embodiments, each root certificate held by a root certificate authority has a certain certificate validity period (i.e., it is not held indefinitely), and since the certificate validity period is also stored in the alliance certificate blockchain, when the network device obtains data from the alliance certificate blockchain, it will also obtain the certificate validity period corresponding to each root certificate. When accessing a target website, if it is determined that the current time is not within the certificate validity period of the target root certificate, the network device will again obtain the root authority identifiers and root certificates of all root certificate authorities from the alliance certificate blockchain to obtain a new target root certificate of the target root certificate authority corresponding to the target website, thereby facilitating the subsequent use of the new target root certificate to access the target website.
[0104] Step 203: Access the target website based on the target organization root certificate.
[0105] Step 203 is described in detail below.
[0106] In some embodiments, after obtaining the target organization's root certificate, the network device uses the browser it carries to log in to the address corresponding to the target website, and sends the target organization's root certificate to the target website so that the server corresponding to the target website can verify whether the network device is an identity that can access the target website based on the target organization's root certificate. After the verification is successful, an encrypted connection (such as HTTPS) is established between the browser and the target website so that the network device can access the target website.
[0107] It is understandable that the network device generally refers to the network device in the region where all the root certificate authorities in the root certificate authority alliance are located, but the network devices in other regions that can be connected to the alliance certificate blockchain can also implement the above-mentioned website access method.
[0108] The website access method, device, electronic device and storage medium proposed in the embodiment of the present application include: first, determining the target root certificate authority corresponding to the target website from multiple root certificate authorities, the multiple root certificate authorities are located in the same alliance certificate blockchain, and the alliance certificate blockchain is used to store at least the institutional root certificate of each root certificate authority; then, obtaining the first update interval mean and the first update interval median of all new block information in the alliance certificate blockchain in the past first time period, and obtaining the second update interval mean and the second update interval median of all new block information in the alliance certificate blockchain in the past second time period, the first time period is shorter than the second time period, and the first update interval mean and the first update interval median are subjected to data averaging processing A first interval mean is obtained, and the second update interval mean and the second update interval median are averaged to obtain a second interval mean, the first interval mean is multiplied by the first weight to obtain a first weight interval, the second interval mean is multiplied by the second weight to obtain a second weight interval, the first weight interval and the second weight interval are accumulated to obtain a preset acquisition cycle time, the first weight is greater than the second weight, and the sum of the first weight and the second weight is equal to one, based on the preset acquisition cycle time, the root organization identifier and the organization root certificate of all root certificate organizations are periodically obtained from the alliance certificate blockchain, the target organization identifier corresponding to the target root certificate organization is obtained, and the target organization root certificate is selected from multiple organization root certificates based on the target organization identifier; finally, the target website is accessed based on the target organization root certificate.
[0109] The embodiment of the present application utilizes the alliance certificate blockchain to manage multiple root certificate authorities in the same or different regions, and utilizes the characteristic that the blockchain's chain information cannot be tampered with to store the legitimate institution root of each root certificate authority in the alliance on the chain in the alliance certificate blockchain. Therefore, when a network device accesses a target website, it can use the target institution root certificate corresponding to the target root certificate authority of the target website obtained from the alliance certificate blockchain to access the target website normally, thereby avoiding the possibility of invalid certificates, thereby greatly improving the reliability of website access by network devices. In addition, the frequency information added by the data of the alliance certificate blockchain is used to The preset acquisition cycle time obtained by the information is used to periodically obtain the root organization identifiers and organization root certificates of all root certificate authorities from the alliance certificate blockchain, so that when the network device visits the target website, it can directly use the target organization root certificate required by the target website without having to obtain data from the alliance certificate blockchain again, thereby effectively reducing the communication overhead of the network device; and, by using the update interval mean and update interval median corresponding to the recent two time periods of the alliance certificate blockchain, and further combining the different weights corresponding to different time periods, a preset restart time for the new block addition interval of the alliance certificate blockchain that is more in line with the current moment can be better generated.
[0110] The present application also provides a website access device that can implement the above website access method. Figure 9 , the apparatus 900 comprises:
[0111] An organization determination module 910 is configured to determine a target root certificate authority corresponding to a target website from a plurality of root certificate authorities, wherein the plurality of root certificate authorities are located in the same federated certificate blockchain, and the federated certificate blockchain is configured to store at least the organization root certificate of each root certificate authority;
[0112] The certificate acquisition module 920 is used to obtain the target organization root certificate corresponding to the target root certificate authority from the alliance certificate blockchain;
[0113] The login module 930 is used to access the target website based on the target organization root certificate.
[0114] In some embodiments, the certificate acquisition module 920 is further configured to:
[0115] Obtain the root authority identifiers and root certificates of all root certificate authorities from the alliance certificate blockchain;
[0116] Obtain a target organization identifier corresponding to a target root certificate authority, and select a target organization root certificate from multiple organization root certificates based on the target organization identifier.
[0117] In some embodiments, the certificate acquisition module 920 is further configured to:
[0118] Get the preset acquisition cycle time;
[0119] Based on the preset acquisition cycle time, the root authority identifiers and agency root certificates of all root certificate authorities are periodically obtained from the alliance certificate blockchain.
[0120] In some embodiments, the certificate acquisition module 920 is further configured to:
[0121] Obtaining a first update interval mean and a first update interval median for all newly added block information in a past first time period of the alliance certificate blockchain, and obtaining a second update interval mean and a second update interval median for all newly added block information in a past second time period of the alliance certificate blockchain, where the first time period is less than the second time period;
[0122] Performing data averaging processing on the first update interval mean and the first update interval median to obtain a first interval mean, and performing data averaging processing on the second update interval mean and the second update interval median to obtain a second interval mean;
[0123] Multiply the first interval mean by the first weight to obtain the first weight interval, multiply the second interval mean by the second weight to obtain the second weight interval, accumulate the first weight interval and the second weight interval to obtain the preset acquisition cycle time, the first weight is greater than the second weight, and the sum of the first weight and the second weight is equal to one.
[0124] In some embodiments, the certificate acquisition module 920 is further configured to:
[0125] Send an access request to the target website based on the backup organization's root certificate;
[0126] Receiving failure feedback information issued by the website server corresponding to the target website based on the access request and the backup organization's root certificate;
[0127] According to the failure feedback information, the root authority identifiers and root certificates of all root certificate authorities are obtained from the alliance certificate blockchain.
[0128] In some embodiments, the certificate acquisition module 920 is further configured to:
[0129] If the current time is not within the validity period of the certificate, the root authority identifiers and root certificates of all root certificate authorities are obtained from the alliance certificate blockchain.
[0130] In the above embodiments, the description of each embodiment has different emphases. For parts not described in detail in a certain embodiment, the specific implementation of the website access device is basically the same as the specific implementation of the above website access method, and will not be repeated here.
[0131] In the embodiment of the present application, the website access device of the present application utilizes the alliance certificate blockchain to manage multiple root certificate authorities in the same or different regions, and utilizes the characteristic that the chain information of the blockchain cannot be tampered with, and stores the legitimate institution root of each root certificate authority in the alliance on the chain in the alliance certificate blockchain, so that when the network device accesses the target website, the target institution root certificate corresponding to the target root certificate authority of the target website obtained from the alliance certificate blockchain can be used to perform normal target website access, so as to avoid the possibility of invalid certificate, thereby greatly improving the reliability of website access by the network device; in addition, by utilizing the alliance certificate blockchain The preset acquisition cycle time obtained from the data addition frequency information is used to periodically obtain the root organization identifiers and organization root certificates of all root certificate organizations from the alliance certificate blockchain, so that when the network device accesses the target website, it can directly use the target organization root certificate required by the target website without having to obtain data from the alliance certificate blockchain again, thereby effectively reducing the communication overhead of the network device; and, by utilizing the update interval mean and update interval median corresponding to the two recent time periods of the alliance certificate blockchain, and further combining the different weights corresponding to different time periods, a preset restart time for the new block addition interval of the alliance certificate blockchain that is more in line with the current moment can be better generated.
[0132] An embodiment of the present application further provides an electronic device, including:
[0133] at least one memory;
[0134] at least one processor;
[0135] at least one program;
[0136] The program is stored in the memory, and the processor executes the at least one program to implement the website access method implemented in this application. The electronic device can be any smart terminal including a mobile phone, a tablet computer, a personal digital assistant (PDA), a car computer, etc.
[0137] See also Figure 10 , Figure 10 The hardware structure of an electronic device according to another embodiment is shown. The electronic device includes:
[0138] The processor 1001 can be implemented as a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present application;
[0139] The memory 1002 can be implemented in the form of ROM (Read Only Memory), static storage device, dynamic storage device or RAM (Random Access Memory). The memory 1002 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program codes are stored in the memory 1002 and are called by the processor 1001 to execute the website access method of the embodiments of this application.
[0140] Input / output interface 1003, used to implement information input and output;
[0141] Communication interface 1004, used to implement communication interaction between this device and other devices, which can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WiFi, Bluetooth, etc.);
[0142] Bus 1005 , which transmits information between various components of the device (e.g., processor 1001 , memory 1002 , input / output interface 1003 , and communication interface 1004 );
[0143] The processor 1001 , the memory 1002 , the input / output interface 1003 and the communication interface 1004 are connected to each other in communication within the device via the bus 1005 .
[0144] An embodiment of the present application further provides a storage medium, which is a computer-readable storage medium and stores a computer program. When the computer program is executed by a processor, the above-mentioned website access method is implemented.
[0145] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory may optionally include a memory remotely arranged relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0146] The embodiments described in the embodiments of this application are intended to more clearly illustrate the technical solutions of the embodiments of this application and do not constitute a limitation on the technical solutions provided by the embodiments of this application. Those skilled in the art will appreciate that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0147] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than shown in the figures, or a combination of certain steps, or different steps.
[0148] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, i.e., they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of this embodiment.
[0149] Those skilled in the art will appreciate that all or some of the steps in the methods, systems, and functional modules / units in the devices disclosed above may be implemented as software, firmware, hardware, or appropriate combinations thereof.
[0150] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0151] It should be understood that in this application, "at least one (item)" means one or more, and "plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.
[0152] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the above-mentioned units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. The mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0153] The units described above as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0154] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0155] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes multiple instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of various embodiments of the present application. The aforementioned storage medium includes: various media that can store programs, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0156] The preferred embodiments of the present invention are described above with reference to the accompanying drawings, but are not intended to limit the scope of the present invention. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and essence of the present invention should be within the scope of the present invention.
Claims
1. A website access method, characterized in that: include: Determining a target root certificate authority corresponding to the target website from a plurality of root certificate authorities, wherein the plurality of root certificate authorities are located in the same alliance certificate blockchain, and the alliance certificate blockchain is used to store at least an institutional root certificate of each of the root certificate authorities; Obtaining a target organization root certificate corresponding to the target root certificate authority from the alliance certificate blockchain; Accessing the target website based on the target organization root certificate; The obtaining, from the alliance certificate blockchain, a target organization root certificate corresponding to the target root certificate authority, includes: Obtaining root authority identifiers and root certificates of all root certificate authorities from the alliance certificate blockchain; Obtaining a target organization identifier corresponding to the target root certificate authority, and selecting the target organization root certificate from a plurality of organization root certificates based on the target organization identifier; The accessing the target website based on the target organization root certificate includes: The target organization root certificate is sent to the target website so that the server corresponding to the target website can verify whether the network device is an identity that can access the target website based on the target organization root certificate, and after the verification is passed, establish an encrypted connection between the browser and the target website so that the network device can access the target website.
2. The website access method according to claim 1, wherein: The obtaining of the root authority identifiers and the root certificates of all root certificate authorities from the alliance certificate blockchain includes: Get the preset acquisition cycle time; Based on the preset acquisition cycle time, the root authority identifiers and the authority root certificates of all root certificate authorities are periodically obtained from the alliance certificate blockchain.
3. The website access method according to claim 2, characterized in that: The obtaining of the preset acquisition cycle time includes: Obtaining a first update interval mean and a first update interval median for all newly added block information in the federated certificate blockchain within a first past time period, and obtaining a second update interval mean and a second update interval median for all newly added block information in the federated certificate blockchain within a second past time period, wherein the first time period is less than the second time period; Performing data averaging processing on the first update interval mean and the first update interval median to obtain a first interval mean, and performing data averaging processing on the second update interval mean and the second update interval median to obtain a second interval mean; Multiply the first interval mean by the first weight to obtain a first weight interval, multiply the second interval mean by the second weight to obtain a second weight interval, accumulate the first weight interval and the second weight interval to obtain the preset acquisition cycle time, the first weight is greater than the second weight, and the sum of the first weight and the second weight is equal to one.
4. The website access method according to claim 1, wherein: The network device stores a backup organization root certificate corresponding to the target organization identifier, and obtaining the root organization identifiers and organization root certificates of all root certificate organizations from the alliance certificate blockchain includes: Sending an access request to the target website based on the backup organization root certificate; receiving failure feedback information issued by the website server corresponding to the target website according to the access request and the backup organization root certificate; According to the failure feedback information, the root authority identifiers and the authority root certificates of all root certificate authorities are obtained from the alliance certificate blockchain.
5. The website access method according to claim 1, wherein: The network device stores the certificate validity period corresponding to the target organization identifier, and obtaining the root organization identifiers and organization root certificates of all root certificate organizations from the alliance certificate blockchain includes: If the current time is not within the validity period of the certificate, the root authority identifiers and the root certificates of all root certificate authorities are obtained from the alliance certificate blockchain.
6. The website access method according to claim 1, wherein: Before obtaining the target organization root certificate corresponding to the target root certificate authority from the alliance certificate blockchain, when a new root certificate authority joins the alliance certificate blockchain, at least one of the organization root certificate, root organization identifier, organization registration information, region code, applicable software information, and region signature information of the new root certificate authority is synchronously uploaded to the chain.
7. A website access device, characterized in that: include: an organization determination module, configured to determine a target root certificate authority corresponding to a target website from a plurality of root certificate authorities, wherein the plurality of root certificate authorities are located in a same alliance certificate blockchain, and the alliance certificate blockchain is configured to store at least an organization root certificate of each of the root certificate authorities; A certificate acquisition module, configured to obtain a target organization root certificate corresponding to the target root certificate authority from the alliance certificate blockchain; A login module, configured to access the target website based on the target organization root certificate; The obtaining, from the alliance certificate blockchain, a target organization root certificate corresponding to the target root certificate authority, includes: Obtaining root authority identifiers and root certificates of all root certificate authorities from the alliance certificate blockchain; Obtaining a target organization identifier corresponding to the target root certificate authority, and selecting the target organization root certificate from a plurality of organization root certificates based on the target organization identifier; The accessing the target website based on the target organization root certificate includes: The target organization root certificate is sent to the target website so that the server corresponding to the target website can verify whether the network device is an identity that can access the target website based on the target organization root certificate, and after the verification is passed, establish an encrypted connection between the browser and the target website so that the network device can access the target website.
8. An electronic device, characterized in that: The method comprises a memory and a processor, wherein the memory stores a computer program, and the processor implements the website access method according to any one of claims 1 to 6 when executing the computer program.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the website access method according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Alliance chain-based authentication model, method, server and system, and storage medium
CN114398624A