A blockchain-based communication method and system
By using a decentralized architecture based on blockchain, the information security vulnerabilities of certificate authorities in the PKI system are solved, achieving consistency and real-time performance of data across the entire network, and ensuring the security and reliability of the communication system.
Patent Information
- Application Number
- CN202411694770.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-25
- Publication Date
- 2026-02-24
- Estimated Expiration
- 2044-11-25
AI Technical Summary
In the existing Public Key Infrastructure (PKI) system, Certificate Authorities (CAs) frequently suffer from information security vulnerabilities, leading to the leakage of sensitive data of certificate users and the risk of eavesdropping on information communications. There is a lack of decentralized security solutions.
It adopts a decentralized architecture based on blockchain, generating certificate operation records through multiple network nodes during certificate registration and revocation, and using blockchain technology for distributed storage and synchronization to ensure that each node holds a complete copy of the certificate list information, thereby achieving consistency and real-time performance of data across the entire network.
It enables efficient maintenance of network-wide data consistency and real-time performance without relying on certificate authorities, ensuring the security and immutability of certificate information, and improving the security and reliability of communication systems.
Smart Images

Figure CN119561697B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security, and more specifically, to a blockchain-based communication method and system. Background Technology
[0002] With the rapid advancement of internet technology, users increasingly prefer to complete various operations and obtain services through online platforms. While this greatly enhances the convenience of operations, it also brings potential risks regarding data confidentiality and security. Public Key Infrastructure (PKI), as a widely applicable security solution, relies on asymmetric encryption algorithms (i.e., public key theory) and third-party authentication mechanisms to build a solid barrier for users' secure services.
[0003] The core pillar of the PKI architecture lies in the Certificate Authority (CA). The current digital certificate authentication system consists of three key components: the CA system responsible for issuing certificates, the RA system that executes the registration and verification process, and the KMC (Key Management Center) that manages keys. The foundation of trust in this system rests on the certificate users' trust and recognition of the issuing authority (i.e., the CA). However, in recent years, frequent information security vulnerabilities exposed by certificate authorities, including data breaches and operational errors, have led to the illegal acquisition of sensitive data from numerous certificate users, posing a risk of eavesdropping on communications. These cases persist despite repeated crackdowns, causing widespread concern. Summary of the Invention
[0004] The purpose of this invention is to provide a blockchain-based communication method and system to at least partially improve the above-mentioned problems.
[0005] To achieve the above objectives, the technical solutions adopted in the embodiments of the present invention are as follows:
[0006] In a first aspect, embodiments of the present invention provide a blockchain-based communication system, the communication system comprising multiple network nodes;
[0007] The first type of network node is used to generate corresponding certificate operation records when registering or revoking certificates, add the certificate operation records to the certificate operation list in the block structure of the first type of network node, and send the certificate operation records to the second type of network node in the communication system.
[0008] Wherein, the first type of network node is any network node in the communication system;
[0009] The second type of network node is used to add the certificate operation record to the certificate operation list in the block structure of the second type of network node when the certificate operation record of the first type of network node is obtained.
[0010] The second type of network node is any network node in the communication system other than the first type of network node;
[0011] At the end of the current recording period, the target network node sends the target block structure to a third type of network node in the communication system, so that the third type of network node updates its copy of the certificate list information according to the certificate operation list in the target block structure of the target network node. The third type of network node is any network node in the communication system other than the target network node, and the target network node is the network node with the highest integrity of the certificate operation list in the current recording period. The copy of the certificate list information includes all certificate information in the blockchain's communication system.
[0012] Secondly, embodiments of the present invention provide a blockchain-based communication method applied to the aforementioned communication system, the method comprising:
[0013] When registering or revoking a certificate, the first type of network node generates a corresponding certificate operation record, adds the certificate operation record to the certificate operation list in the block structure of the first type of network node, and sends the certificate operation record to the second type of network node in the communication system.
[0014] Wherein, the first type of network node is any network node in the communication system;
[0015] When the second type of network node obtains the certificate operation record of the first type of network node, it adds the certificate operation record to the certificate operation list in the block structure of the second type of network node.
[0016] The second type of network node is any network node in the communication system other than the first type of network node;
[0017] At the end of the current recording period, the target network node sends the target block structure to a third type of network node in the communication system, so that the third type of network node updates its copy of the certificate list information according to the certificate operation list in the target block structure of the target network node. The third type of network node is any network node in the communication system other than the target network node, and the target network node is the network node with the highest integrity of the certificate operation list in the current recording period. The copy of the certificate list information includes all certificate information in the blockchain communication system.
[0018] Compared to existing technologies, the blockchain-based communication method and system provided in this invention involves a first type of network node generating a corresponding certificate operation record when registering or revoking a certificate. This record is added to the certificate operation list in the block structure of the first type of network node and then sent to a second type of network node in the communication system. Upon receiving the certificate operation record from the first type of network node, the second type of network node adds it to its own certificate operation list in its block structure. At the end of the current recording period, the target network node sends its target block structure to a third type of network node in the communication system, enabling the third type of network node to update its copy of the certificate list information based on the target block structure's certificate operation list. When any network node performs a certificate registration, revocation, or other update operation, an automatic process is triggered to synchronize the latest data changes to every network node in the network, thereby maintaining the consistency and real-time performance of the entire network's data.
[0019] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description
[0020] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0021] Figure 1 This is a schematic diagram of the architecture of a communication system provided in an embodiment of the present invention.
[0022] Figure 2 This is a schematic diagram of the block structure provided in an embodiment of the present invention.
[0023] Figure 3 This is a schematic diagram of the key distribution process provided in an embodiment of the present invention.
[0024] Figure 4 This is a flowchart illustrating a blockchain-based communication method provided in an embodiment of the present invention. Detailed Implementation
[0025] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.
[0026] Therefore, the following detailed description of the embodiments of the invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the invention without inventive effort are within the scope of protection of the invention.
[0027] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this invention, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.
[0028] In the description of this invention, it should also be noted that, unless otherwise explicitly specified and limited, the terms "set" and "connection" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in this invention based on the specific circumstances.
[0029] The following detailed description of some embodiments of the present invention is provided in conjunction with the accompanying drawings. Unless otherwise specified, the following embodiments and features can be combined with each other.
[0030] To effectively address numerous challenges in the current technological field, this approach innovatively integrates the advantages of blockchain technology with the concept of decentralization, completely eliminating the role of the Certificate Authority (CA), which is indispensable in traditional digital certificate authentication systems. This initiative aims to build a completely new mechanism that can seamlessly realize core functions such as identity authentication and public key exchange—originally carried out by traditional digital certificates—without relying on any central certificate authority.
[0031] In view of this, embodiments of the present invention provide a blockchain-based communication system, exploring and implementing a digital certificate solution that does not rely on traditional certificate authorities and adopts a decentralized architecture, becoming an effective way to solve this series of security challenges and reshape the trust environment.
[0032] Please refer to Figure 1 , Figure 1 This is a schematic diagram of the architecture of a communication system provided in an embodiment of the present invention. The blockchain-based communication system includes multiple network nodes, which can communicate with each other, but are not limited to, via a P2P network. It should be noted that any network node can communicate and connect with one or more other network nodes in the communication system.
[0033] P2P networks, also known as Peer-to-Peer or peer-to-peer networks, are a type of internet system without a centralized server, where information is exchanged entirely by a group of users.
[0034] The first type of network node is used to generate corresponding certificate operation records when registering or revoking certificates, add the certificate operation records to the certificate operation list in the block structure of the first type of network node, and send the certificate operation records to the second type of network node in the communication system.
[0035] The first type of network node is any network node in the communication system, and the second type of network node is any network node in the communication system other than the first type of network node.
[0036] It should be noted that the same network node can be both a first-type network node and a second-type network node at the same time. Optionally, there are N network nodes in the communication system. When the i-th network node registers or revokes its certificate, the i-th network node is a first-type network node, and all other network nodes are second-type network nodes corresponding to the i-th network node.
[0037] The second type of network node is used to add the certificate operation record to the certificate operation list in the block structure of the second type of network node when it obtains the certificate operation record of the first type of network node.
[0038] The second type of network node is any network node in the communication system other than the first type of network node.
[0039] Optionally, the operation records in the certificate operation list are shown in Table 1 below.
[0040] Table 1
[0041]
[0042]
[0043] The operation record is represented as: data = ttlv(node + oper + cert).
[0044] At the end of the current recording period, the target network node sends the target block structure therein to a third type of network node in the communication system, so that the third type of network node updates its copy of the certificate list information according to the certificate operation list in the target block structure of the target network node.
[0045] The third type of network node is any network node in the communication system other than the target network node. The target network node is the network node with the highest integrity of the certificate operation list within the current recording period. The certificate list information copy includes all certificate information in the blockchain's communication system. It should be noted that the target network node can be different in different recording periods.
[0046] In the blockchain-based communication system provided in this embodiment of the invention, data adopts a distributed storage architecture to ensure that each network node holds a complete copy of the certificate list information. When any network node performs update operations such as certificate registration or revocation, an automatic process is triggered to efficiently synchronize the latest data changes to every network node in the network through a peer-to-peer (P2P) network mechanism, thereby maintaining the consistency and real-time performance of the entire network data.
[0047] At the end of the current recording period, the blockchain-based communication system can determine the target network node through voting.
[0048] As shown in Table 1, in one optional implementation, the certificate operation record includes the node ID (nodeId) of the first type of network node, operation type information (oper) and operation certificate information (cert), wherein the operation type information is to register a certificate or revoke a certificate, and the operation certificate information includes the certificate ID, certificate public key and certificate signature value.
[0049] Optionally, the concatenated data of the certificate ID and the certificate public key can be signed using the certificate private key to obtain the certificate signature value.
[0050] Based on this, regarding how each network node determines its own node ID before registering a certificate, this embodiment of the invention also provides an optional implementation method, please refer to the following.
[0051] Before registering the certificate, the network node also uses a pre-set random algorithm to generate a random number of a preset length as the node's private key.
[0052] Optionally, a 256-bit (32-byte) random number can be generated as the private key using a highly secure random algorithm. This private key, like a key to the digital world, must be kept strictly confidential, as it is the core of controlling the address and subsequent certificate operations.
[0053] Network nodes are also used to forge corresponding node public keys using elliptic curve digital signature algorithms, with the node's private key as the foundation.
[0054] Optionally, an elliptic curve digital signature algorithm (ECDSA) is used to forge a corresponding 512-bit (64-byte) public key based on the private key. A strict mathematical relationship exists between the public and private keys, ensuring a one-to-one unique correspondence.
[0055] Network nodes are also used to hash the node's public key to obtain the node's hash value, and to encode the target field in the node's hash value to obtain the node ID.
[0056] Optionally, the node's public key is hashed using Keccak256 (SHA-3) to obtain a 256-bit hash value. Then, the last 20 bytes (160 bits, the target field) are selected from this complex hash value to form the prototype of the Ethereum address. Finally, Base58Check encoding is used to transform this number into a more easily recognizable and input format, thus forming the node's unique identity.
[0057] Please refer to Figure 2 , Figure 2 This is a schematic diagram of the block structure provided in an embodiment of the present invention. Figure 2 As shown, the block structure includes a block header and a block body. The block header includes the current block hash, the previous block hash, a timestamp (UTC timestamp), a random number, the blockchain version number, and the Merkle root. The block body includes a list of certificate operations.
[0058] The certificate operation list includes all certificate operation records obtained by the network node within the current recording period. The hash value of the previous block is the hash value corresponding to the target region structure in the previous recording period. The timestamp indicates the start time of the current recording period. The random number is related to the length of the current recording period. The Merkle root indicates the completeness of the certificate operation list within the current recording period. Optionally, the Merkle root is the hash value of all operation records within the current block, used to compare whether the node has recorded all block operations correctly. If this value is consistent with that of the third type of network node, it means that the operation list recorded within the node is correct and there is no need to update the operation list within the node.
[0059] In one optional implementation, all network nodes (including third-type network nodes and target network nodes) are used to store the target block structure within the current recording period, and update the blockchain table based on the current block hash value and the previous block hash value in the target block structure. The blockchain table includes the block hash value corresponding to the target block structure within each recording period, and the block hash values in the blockchain table are sorted according to the time of the recording period.
[0060] This design ensures the continuity and immutability of the blockchain. This chain structure not only guides the data traceability journey to the genesis or root block, but also provides the ability to fully traverse the entire blockchain history. Timestamps, an indispensable element of this mechanism, not only record the precise moment of block generation, but also play a crucial role in verifying the integrity and accuracy of block hash calculations. The hash calculation of the current block follows a strict and precise set of rules that ensure the uniqueness and security of the hash value. Any minute data change will result in a completely different hash value, thus guaranteeing the unforgeability and permanent storage of all information on the blockchain.
[0061] Optionally, when creating the block structure, network nodes perform hash operations based on the timestamp, random number, blockchain version number, Merkle root, and the hash value of the previous block to obtain a first-order hash value, and then reverse the first-order hash value to obtain the hash value of the current block.
[0062] The hash value calculation rules are as follows:
[0063] hash1 = sha256(sha256(version number + previous block hash + Merkle root + timestamp + random number));
[0064] currentHash = hash1[::-1];
[0065] Optionally, hash1 can be obtained by performing a double SHA-256 calculation on the version number, the hash value of the previous block, the Merkle root, the UTC timestamp, and the random number; then hash1 can be reversed to obtain the current hash value currentHash.
[0066] In one alternative implementation, the certificate list information copy adopts an MPT structure (Merkle PatriciaTree, compact prefix tree).
[0067] In traditional digital certificate management systems, applicants rely on OCSP (Online Certificate Status Protocol) to check certificate validity in real time, while CRL (Certificate Revocation List) serves as a traditional method for obtaining certificate revocation information in batches. However, these mechanisms are all rooted in a centralized design philosophy, posing risks of single points of failure and performance bottlenecks. To address this, this invention aims to conceive and construct an innovative architecture designed to enable each node in a decentralized environment to efficiently retrieve certificate information and respond instantly to any changes in certificate status.
[0068] Specifically, an optimized data storage and retrieval mechanism is introduced, among which the MPT (Merkle Patricia Tree) data structure stands out due to its unique advantages. MPT not only integrates the efficient verification characteristics of Merkle Trees but also incorporates the design philosophy of Trie trees, which reduces storage space and accelerates query speed through string prefix sharing. Furthermore, it applies advanced compression algorithms for further optimization. This ingenious combination makes MPT an ideal choice for handling large amounts of data in blockchain and distributed systems. For details on the MPT structure, please refer to the Ethereum storage structure; it will not be elaborated upon here.
[0069] Regarding how to achieve secure communication through network nodes in the system, this embodiment of the invention also provides an optional implementation method, please refer to... Figure 3 , Figure 3 This is a schematic diagram of the key distribution process provided in an embodiment of the present invention.
[0070] When the first communication node needs to communicate with the second communication node, the first communication node queries its internal copy of the certificate list information to obtain the certificate information of the second communication node. Both the first and second communication nodes are network nodes in the blockchain communication system.
[0071] The first communication node is used to verify the signature based on the certificate information of the second communication node, and if the signature verification is successful, it sends a first random number to the second communication node.
[0072] If the first communication node cannot find the certificate information of the second communication node, or if the first communication node fails to verify the signature, it will return the corresponding error response.
[0073] The second communication node is used to query its internal copy of the certificate list information when it receives the first random number in order to obtain the certificate information of the first communication node.
[0074] The second communication node is used to verify the signature based on the certificate information of the first communication node, and if the signature verification is successful, it sends a second random number to the first communication node.
[0075] If the second communication node cannot find the certificate information of the first communication node, or if the second communication node fails to verify the signature, it will return the corresponding error response.
[0076] The second communication node is also used to generate a session key based on a first random number and a second random number.
[0077] The first communication node is also used to generate a session key based on a first random number and a second random number.
[0078] The first and second communication nodes communicate using a session key.
[0079] Optionally, using a first random number and a second random number, the first and second communication nodes jointly generate a session key through a predetermined key negotiation algorithm (such as Diffie-Hellman key exchange). This key will be used to encrypt subsequent communication content, ensuring the security of data transmission. At this point, the certificate verification and session key negotiation process is successfully completed.
[0080] The core value of digital certificates lies in the public disclosure of public keys and the effective authentication of identities. When two nodes communicate, a session key needs to be generated to encrypt the communication content to ensure secure information transmission. The generation of the session key depends on the exchange and verification of the public keys of both parties. This is where digital certificates play a crucial role; they enable nodes to securely obtain the other party's public key and perform identity verification, thereby establishing a bridge for encrypted communication.
[0081] It is worth noting that the certificate system is also capable of performing the functions of traditional certificates, such as electronic signatures, code signing, and identity verification, providing strong support for trust building and data transmission security in the blockchain ecosystem.
[0082] In one alternative implementation, the blockchain-based communication system employs a PoW or PoS consensus mechanism to provide a standard for data consistency among network nodes in the communication system.
[0083] PoW, also known as Proof-of-Work, is a consensus mechanism whose core principle requires participants to complete a certain amount of computational work to prove that they have indeed put in effort and resources.
[0084] PoS, also known as Proof-of-Stack, is a consensus mechanism in which the participants selected for the next block are determined based on the amount of currency they hold or their stake.
[0085] The blockchain-based communication system proposed in this invention realizes a decentralized digital certificate system solution based on blockchain, providing quantum-secure signature services for a wide range of users, and achieving authentic and trustworthy user identities and unconditionally secure data that is tamper-proof and non-repudiable. It will become an important component of the blockchain decentralized digital certificate security infrastructure.
[0086] This invention also provides a blockchain-based communication method, applied to the aforementioned blockchain-based communication system. Please refer to... Figure 4 The communication methods based on blockchain include S10, S20 and S30, which are described in detail below.
[0087] S10, when registering or revoking a certificate, the first type of network node generates a corresponding certificate operation record, adds the certificate operation record to the certificate operation list in the block structure of the first type of network node, and sends the certificate operation record to the third type of network node in the communication system.
[0088] The first type of network node is any network node in the communication system.
[0089] S20, when the second type of network node obtains the certificate operation record of the first type of network node, it adds the certificate operation record to the certificate operation list in the block structure of the second type of network node.
[0090] The second type of network node is any network node in the communication system other than the first type of network node.
[0091] S30, at the end of the current recording period, the target network node sends the target block structure therein to the third type of network node in the communication system.
[0092] This enables the third-type network node to update a copy of the certificate list information based on the certificate operation list in the target block structure of the target network node.
[0093] Among them, the third type of network node is any network node in the communication system other than the target network node. The target network node is the network node with the highest integrity of the certificate operation list in the current recording period. The certificate list information copy includes all certificate information in the blockchain's communication system.
[0094] Optionally, the certificate operation record includes the node ID of the first type of network node, operation type information, and certificate information of the operation. The operation type information is either registering a certificate or revoking a certificate, and the certificate information of the operation includes the certificate ID, the certificate public key, and the certificate signature value.
[0095] It should be noted that the blockchain-based communication method provided in this embodiment can perform the functions and uses shown in the above-described blockchain-based communication system embodiments to achieve the corresponding technical effects. For the sake of brevity, any parts not mentioned in this embodiment can be referred to the corresponding content in the above embodiments.
[0096] In summary, the blockchain-based communication method and system provided by this invention involves the following steps: When a first type of network node registers or revokes a certificate, it generates a corresponding certificate operation record, adds this record to the certificate operation list in its block structure, and sends it to a second type of network node in the communication system. Upon receiving the certificate operation record from the first type of network node, the second type of network node adds it to its own certificate operation list in its block structure. At the end of the current recording period, the target network node sends its target block structure to a third type of network node in the communication system, enabling the third type of network node to update its copy of the certificate list information based on the target block structure's certificate operation list. When any network node performs certificate registration, revocation, or other update operations, an automatic process is triggered to synchronize the latest data changes to every network node in the network, thereby maintaining the consistency and real-time performance of the entire network's data.
[0097] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
[0098] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the invention can be implemented in other specific forms without departing from its spirit or essential characteristics. Therefore, the embodiments should be considered in all respects as exemplary and non-limiting, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of equivalents of the claims are intended to be included within the present invention. No reference numerals in the claims should be construed as limiting the scope of the claims.
Claims
1. A blockchain-based communication system, characterized in that, The communication system includes multiple network nodes; The first type of network node is used to generate corresponding certificate operation records when registering or revoking certificates, add the certificate operation records to the certificate operation list in the block structure of the first type of network node, and send the certificate operation records to the second type of network node in the communication system. Wherein, the first type of network node is any network node in the communication system; The second type of network node is used to add the certificate operation record to the certificate operation list in the block structure of the second type of network node when the certificate operation record of the first type of network node is obtained. The second type of network node is any network node in the communication system other than the first type of network node; At the end of the current recording period, the target network node sends the target block structure therein to a third type of network node in the communication system, so that the third type of network node updates its copy of the certificate list information according to the certificate operation list in the target block structure of the target network node. The third type of network node is any network node in the communication system other than the target network node, and the target network node is the network node with the highest integrity of the certificate operation list in the current recording period. The copy of the certificate list information includes all certificate information in the blockchain communication system. The block structure includes the current block hash value, the previous block hash value, a timestamp, a random number, a blockchain version number, a Merkle root, and a certificate operation list. The certificate operation list includes all certificate operation records obtained by network nodes within the current recording period. The previous block hash value is the hash value corresponding to the target region structure within the previous recording period. The timestamp represents the start time of the current recording period. The random number is related to the length of the current recording period. The network node is used to perform a hash operation based on the timestamp, the random number, the blockchain version number, the Merkle root, and the hash value of the previous block to obtain a first-order hash value, and then reverse the first-order hash value to obtain the hash value of the current block.
2. The blockchain-based communication system as described in claim 1, characterized in that, The certificate operation record includes the node ID of the first type of network node, operation type information, and operation certificate information. The operation type information is either registering a certificate or revoking a certificate, and the operation certificate information includes the certificate ID, certificate public key, and certificate signature value.
3. The blockchain-based communication system as described in claim 2, characterized in that, Before registering the certificate, the network node is also used to generate a random number of a preset number of bits as the node's private key using a pre-set random algorithm; The network node is also used to forge a corresponding node public key using the elliptic curve digital signature algorithm, with the node's private key as the foundation. The network node is also used to perform a hash operation on the node's public key to obtain a node hash value, and to encode the target field in the node hash value to obtain the node ID.
4. The blockchain-based communication system as described in claim 1, characterized in that, The network nodes are used to store the target block structure within the current recording period, and update the blockchain table based on the current block hash value and the previous block hash value in the target block structure. The blockchain table includes the block hash value corresponding to the target block structure within each recording period, and the block hash values in the blockchain table are sorted according to the time of the recording period.
5. The blockchain-based communication system as described in claim 1, characterized in that, The certificate list information copy adopts an MPT structure.
6. The blockchain-based communication system as described in claim 1, characterized in that, When the first communication node needs to communicate with the second communication node, the first communication node queries its internal certificate list information copy to obtain the certificate information of the second communication node. Both the first communication node and the second communication node are network nodes in the communication system of the blockchain. The first communication node is used to verify the signature based on the certificate information of the second communication node, and if the signature verification is successful, it sends a first random number to the second communication node. The second communication node is used to query its internal copy of the certificate list information when it receives the first random number in order to obtain the certificate information of the first communication node; The second communication node is used to verify the signature based on the certificate information of the first communication node, and if the signature verification is successful, it sends a second random number to the first communication node. The second communication node is also used to generate a session key based on the first random number and the second random number; The first communication node is also configured to generate a session key based on the first random number and the second random number; The first communication node and the second communication node communicate using the session key.
7. A blockchain-based communication method, characterized in that, The method, applied to the communication system according to any one of claims 1 to 6, comprises: When registering or revoking a certificate, the first type of network node generates a corresponding certificate operation record, adds the certificate operation record to the certificate operation list in the block structure of the first type of network node, and sends the certificate operation record to the second type of network node in the communication system. Wherein, the first type of network node is any network node in the communication system; When the second type of network node obtains the certificate operation record of the first type of network node, it adds the certificate operation record to the certificate operation list in the block structure of the second type of network node. The second type of network node is any network node in the communication system other than the first type of network node; At the end of the current recording period, the target network node sends the target block structure to a third type of network node in the communication system, so that the third type of network node updates its copy of the certificate list information according to the certificate operation list in the target block structure of the target network node. The third type of network node is any network node in the communication system other than the target network node, and the target network node is the network node with the highest integrity of the certificate operation list in the current recording period. The copy of the certificate list information includes all certificate information in the blockchain communication system.
8. The blockchain-based communication method as described in claim 7, characterized in that, The certificate operation record includes the node ID of the first type of network node, operation type information, and operation certificate information. The operation type information is either registering a certificate or revoking a certificate, and the operation certificate information includes the certificate ID, certificate public key, and certificate signature value.
Citation Information
Patent Citations
RPKI database system, construction method and storage medium
CN117220916A
Key sharing system, key sharing device and program thereof
JP2002344438A