Communication Security Management Method and Device Based on Blockchain Nodes

Through the communication security management method of blockchain nodes, the hash link structure and behavioral analysis are used to detect malicious nodes, combined with asymmetric encryption and message authentication code, the problems of identity authentication and malicious node detection in the communication network are solved, and the security and stability of the network are improved.

CN119675997BActive Publication Date: 2025-07-18NANJING UNIV OF INFORMATION SCI & TECH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510187826.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-07-18
Estimated Expiration
2045-02-20

AI Technical Summary

Technical Problem

The existing communication network security management methods rely on centralized authentication, pose a risk of identity authentication, malicious nodes are difficult to detect, and traditional methods cannot detect changes in node behavior in real time and comprehensively, resulting in network security risks.

Method used

The communication security management method of blockchain nodes is adopted, and the public key and identity information of the blockchain store nodes with a hash link structure is used to detect malicious nodes in combination with behavioral analysis and statistical methods, and asymmetric encryption algorithms and message authentication codes are used to ensure communication security.

Benefits of technology

Improves the credibility and security of the network, enhances the accuracy of malicious node detection, prevents attacks and sabotage, and ensures the confidentiality and integrity of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119675997B_ABST
    Figure CN119675997B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of communication security technologies, and specifically to a communication security management method and device based on blockchain nodes. Based on blockchain technology, the present invention uses public key encryption algorithms to ensure the authenticity and reliability of the identities of both communication parties. Each node stores the public keys, registration times, and identity information of known nodes through blockchain records to ensure the security and consistency of identity authentication, improving the credibility and security of the network; the present invention conducts regular evaluations of the behaviors of each node through behavioral analysis and statistical methods, combined with request frequency, behavioral consistency, and tampered data detection, and expels malicious nodes from the network through a consensus protocol, enhancing the accuracy of malicious node detection, effectively preventing attacks and sabotages, and improving the stability and reliability of the network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of communication security, and specifically to a communication security management method and device based on blockchain nodes. Background Art

[0002] With the rapid development of information technology, communication networks have become one of the important infrastructures globally. Especially after blockchain technology has been widely applied in fields such as finance, the Internet of Things, and smart contracts, communication security issues have become an increasingly serious challenge. The characteristics of blockchain itself, such as decentralization, data immutability, and transparency, have been applied in the security management of multiple industries, but there are still some technical bottlenecks and deficiencies in the security management of communication networks.

[0003] Currently, the security management methods in communication networks mainly rely on traditional identity authentication technologies, firewalls, intrusion detection systems (IDS), virtual private networks (VPN), etc. Although these methods can ensure communication security to a certain extent, they still have some significant problems.

[0004] Firstly, the existing identity authentication methods rely on centralized authentication institutions, which have the risk of being breached or forged. Especially in decentralized and distributed networks, it is difficult to effectively solve the problem of node identity authentication, and it is extremely vulnerable to forgery and abuse threats. Secondly, the existing malicious behavior detection methods mostly rely on rule bases and feature matching, and cannot detect and analyze the behavior changes of nodes in real time and comprehensively. Malicious nodes can often cleverly hide their behaviors or disguise themselves as legitimate nodes, resulting in misjudgment of malicious behaviors or failure to detect them in time, causing network security risks.

[0005] In view of the above problems, it is necessary to propose a communication security management method and device based on blockchain nodes. Summary of the Invention

[0006] The purpose of the present invention is to solve the problems existing in the background art, and to propose a communication security management method and device based on blockchain nodes.

[0007] The purpose of the present invention can be achieved through the following technical solutions:

[0008] In a first aspect, the present invention provides a communication security management method based on blockchain nodes, including the following steps:

[0009] Step 1: Node identity authentication;

[0010] Authenticate the nodes where the two communication parties are located to ensure the authenticity of their identities and prevent malicious nodes from joining the network.

[0011] In a communication network, each node locally stores a blockchain, which together form a blockchain network for node identity authentication. The blockchain stored by each node contains the public keys, registration times, and metadata related to identity information of all known nodes, which are used for identity information authentication and comparison. All blockchains adopt a hash-linked structure, making the data of each block associated with the previous block, ensuring that if the information of one block in a blockchain is tampered with, all subsequent blocks in that blockchain will become invalid.

[0012] Whenever a new node sends a request to join the communication network, all nodes in the communication network are made to verify the identity of the newly joined node, including querying whether the public key of the newly joined node exists in the blocks stored by each node and verifying the matching degree between the public key of the newly joined node and its own identity information. The specific process is as follows:

[0013] First, query through the blockchain whether the public key of the newly joined node already exists in the blockchains stored by each node. If the blockchain of at least one node among all nodes already contains this public key, then enter the identity authentication verification stage. Each node uses the public key saved in its stored blockchain to authenticate the newly joined node, obtaining the identity authentication results of each node for the newly joined node. Among them, the identity authentication result is obtained through the RSA public key encryption algorithm. If the identity authentication results of all nodes for the newly joined node are passed, it is determined that the node newly joining the communication network passes the node identity authentication, and the request of the newly joined node to join the communication network is allowed;

[0014] If not, it is determined that the node newly joining the communication network fails to pass the identity authentication, and the identity information of the node newly joining the communication network is registered. A pair of public and private keys for identity authentication is generated and the public key is registered in the blockchains of all nodes. Among them, the private key is used for node identity information encryption, and the public key is used for node identity information verification.

[0015] The specific process of registering the identity information of the newly joined node is as follows: Encrypt the identity information of the newly joined node with the generated private key, and save the encrypted result in the local storage space of the newly joined node. Make each node in the communication network add the public key of the newly joined node to the locally stored blockchain, ensuring that all nodes can obtain this public key for subsequent identity authentication.

[0016] Step 2: Detection of malicious node behavior;

[0017] Through behavioral analysis and statistical methods, combined with request frequency, behavioral consistency, and tampered data detection, regularly evaluate whether the behavior of each node complies with network regulations, and promptly discover and eliminate malicious nodes.

[0018] Detect node malicious behavior in combination with the request frequency, and set the request frequency threshold for the node Obtain the number of requests sent by each newly added node to join the communication network within the last preset time interval t If the conditions are met Then it is determined that the join request of the newly added node contains potential malicious behavior, and a malicious request signal regarding node i is generated

[0019] Detect node malicious behavior in combination with behavior consistency. Every preset time interval t, obtain the communication protocol identifier Pi(t), response time RTi(t), and data packet size Si(t) of each node in the communication network, where i is the node number in the communication network, i = 1, 2,..., n; n is the total number of nodes. Among them, the specific value of the communication protocol identifier Pi is 1, 2, 3, or 4 for the preset communication protocols TCP, UDP, HTTP, and WebSocket in the communication network respectively. Obtain the connection duration C(i1, i2) of each node with other nodes, where i1 ∈ i and i2 ∈ i; i1 is the initiating node number of the connection, and i2 is the target node number of the connection. Generate the behavior feature vector Bi(t) = {Pi, RTi(t), Si(t), C(i, 1), C(i, 2),..., C(i, n)} of each node i at time t, and through the preset formula Calculate the behavior consistency eigenvalue of node i at time t If it is lower than the set threshold, it is considered that the behavior of the node has abnormal fluctuations, a malicious behavior change signal regarding node i is generated, and the potential malicious behavior of node i in terms of behavior consistency is determined. Among them Is the behavior feature vector of the previous preset time interval t of the current time t. Among them Is the Euclidean distance, that is, the straight-line distance between two points Bi(t) and Bi(t - 1) in the vector space

[0020] Detect node malicious behavior in combination with tampering with data records. Perform tampering detection by comparing whether the blockchain data saved by the node is consistent with the blockchain data stored by all other nodes. Every preset time interval, obtain the block data Di saved by the blockchain of each node i. If it is detected that the block data Di saved by the blockchain of node i is inconsistent with the block data saved by the blockchains of other nodes, a malicious tampering signal regarding node i is generated, and it is determined that node i has the behavior of tampering with blockchain data

[0021] Obtain the number of malicious request signals, malicious behavior change signals, or malicious tampering signals of each node

[0022] If the weighted sum result of the number of malicious request signals, the number of malicious behavior change signals, and the number of malicious tampering signals generated by a node exceeds a preset threshold, it is determined that the node has serious malicious behavior and security risks, and it is expelled from the network through the consensus protocol.

[0023] During the node communication process, the generation time of malicious request signals, malicious behavior change signals, or malicious tampering signals of all nodes and the corresponding node numbers are recorded in the node's security log for later auditing.

[0024] Step Three: Encrypted Communication;

[0025] Whenever communication is established between two nodes i1 and i2, the encrypted public keys of nodes i1 and i2 are exchanged. Using the asymmetric encryption algorithm, let the initiating node i1 of the communication encrypt the message to be sent with its own private key and send the message to the target node i2.

[0026] Let the target node i2 decrypt the message encrypted with the private key using the public key of the initiating node i1 of the communication to obtain the original message.

[0027] Step Four: Message Integrity Verification;

[0028] Whenever communication is established between two nodes i1 and i2, let both communication parties use a message authentication code to verify the integrity of the message. Ensure that the data has not been tampered with during the transmission process.

[0029] Whenever the initiating node i1 of the communication sends a message Mi1, it will first calculate the MAC value of the message Mi1 before encryption to obtain the message authentication code MACi1 based on the hash function;

[0030] When the target node i2 of the communication receives the message Mi1, it first calculates the MAC value of the result after decrypting the message Mi1 to obtain the message authentication code MACi2 based on the hash function;

[0031] Check the consistency of the message authentication codes MACi1 and MACi2. If the matching results are consistent, it indicates that the message has not been tampered with during the transmission process; otherwise, let the target node i2 of the communication reject the message.

[0032] In a second aspect, the present invention provides a communication security management device based on blockchain nodes, including several nodes, and all nodes jointly form a communication network. Among them, the types of communication nodes include servers, personal computers, and personal mobile communication terminals. Each communication node includes a computing unit, a storage unit, a network interface, and an encryption module. Nodes communicate with other nodes through network connections and ensure identity authentication and data consistency through the blockchain. Each node stores a blockchain in its local storage space.

[0033] The blockchain stored by each node has the following characteristics: The blockchain adopts a hash-linked structure, and each block contains a hash value pointing to the previous block to ensure the immutability of data. The blockchain data is encrypted and protected through encryption algorithms. Nodes perform identity authentication and share behavior data through the blockchain. Each node adds metadata such as the public key and identity information of newly joined nodes to the local blockchain and maintains the consistency of the network state through a consensus protocol.

[0034] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0035] 1. The present invention is based on blockchain technology and uses public key encryption algorithms to ensure the authenticity and reliability of the identities of both communication parties. Each node stores the public keys, registration times, and identity information of known nodes through the blockchain record to ensure the security and consistency of identity authentication. Through the hash-linked structure of the blockchain, the tampering of node identity information is prevented, enhancing network security. This method uses encryption technology and blockchain consensus mechanisms to avoid potential trust issues in traditional identity authentication methods, improving the credibility and security of the network;

[0036] 2. The present invention regularly evaluates the behavior of each node through behavior analysis and statistical methods, combined with request frequency, behavior consistency, and tampered data detection. This method can detect abnormal behaviors of nodes in a timely manner, such as abnormal signals like frequent requests or abnormal packet sizes and connection durations. If a node's behavior is abnormal, a malicious signal is generated, and the malicious node is expelled from the network through a consensus protocol. This mechanism combines multiple monitoring methods, enhancing the accuracy of malicious node detection, effectively preventing attacks and disruptions, and improving the stability and reliability of the network;

[0037] 3. The present invention uses an asymmetric encryption algorithm to encrypt communication content to ensure that data will not be stolen or tampered with during transmission in the network. In addition, data integrity verification is performed through a message authentication code (MAC) mechanism to further ensure that the message has not been tampered with during transmission. This mechanism supports the encryption and decryption processes through a hardware encryption module and a dedicated accelerator, improving the security and efficiency of data transmission. With the dual protection of encryption and message authentication code, the confidentiality and integrity of data during the entire communication process are effectively guaranteed, enhancing communication security. Description of the Drawings

[0038] For the convenience of those skilled in the art to understand, the present invention will be further described below in conjunction with the drawings:

[0039] Figure 1 It is the method flow chart of the present invention;

[0040] Figure 2Schematic diagram of the communication security management device based on blockchain nodes of the present invention. Detailed implementation manners

[0041] The technical solutions of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0042] Please refer to Figure 1 As shown, the communication security management method based on blockchain nodes includes the following steps:

[0043] Step 1: Node identity authentication;

[0044] Authenticate the identities of the nodes where the two communication parties are located to ensure the authenticity of their identities and prevent malicious nodes from joining the network.

[0045] In the communication network, each node stores a blockchain locally, jointly forming a blockchain network for node identity verification. The blockchains stored by each node contain the public keys, registration times, and metadata related to identity information of all known nodes, which are used for identity information authentication and comparison. All blockchains adopt a hash link structure, making the data of each block associated with the previous block, ensuring that if the information of one block in each blockchain is tampered with, all subsequent blocks in that blockchain will become invalid.

[0046] Whenever a new node sends a request to join the communication network, all nodes in the communication network are required to verify the identity of the newly added node, including querying whether the public key of the newly added node exists in the blocks stored by each node and verifying the matching degree between the public key of the newly added node and its own identity information. The specific process is as follows:

[0047] First, query through the blockchain whether the public key of the newly added node already exists in the blockchains stored by each node. If the blockchains of at least one node among all nodes already contain the public key, then enter the identity authentication verification stage. Each node uses the public key saved in its stored blockchain to authenticate the newly added node, obtaining the identity authentication results of each node for the newly added node. Among them, the identity authentication result is obtained through the RSA public key encryption algorithm. If the identity authentication results of all nodes for the newly added node are passed, it is determined that the node newly joining the communication network passes the node identity authentication, and the request of the newly added node to join the communication network is allowed;

[0048] Otherwise, it is determined that the node newly added to the communication network fails the identity authentication, and the identity information of the node newly added to the communication network is registered. A public key and a private key for identity authentication are generated and the public key is registered in the blockchains of all nodes. Among them, the private key is used for encrypting the node identity information, and the public key is used for verifying the node identity information.

[0049] The specific process of registering the identity information of the newly added node is as follows: Encrypt the identity information of the newly added node with the generated private key, and save the encryption result in the local storage space of the newly added node. Let each node in the communication network add the public key of the newly added node to the locally stored blockchain to ensure that all nodes can obtain the public key for subsequent identity verification.

[0050] Step 2: Node malicious behavior detection;

[0051] Through behavioral analysis and statistical methods, combined with request frequency, behavioral consistency, and tampered data detection, regularly evaluate whether the behavior of each node complies with network regulations, and promptly detect and eliminate malicious nodes.

[0052] Combined with the request frequency for node malicious behavior detection, set the request frequency threshold of the node , obtain the number of requests sent by each newly added node to join the communication network within the last preset time interval t , if the condition is met, it is determined that the join request of the newly added node contains potential malicious behavior, and a malicious request signal for node i is generated.

[0053] Combined with behavioral consistency for node malicious behavior detection, obtain the communication protocol identifier Pi(t), response time RTi(t), and packet size Si(t) of each node in the communication network at every preset time interval t, where i is the node number in the communication network, i = 1, 2,..., n; n is the total number of nodes. Among them, the specific value of the communication protocol identifier Pi is 1, 2, 3, or 4, corresponding to the preset communication protocols TCP, UDP, HTTP, and WebSocket in the communication network respectively. Obtain the connection duration C(i1, i2) of each node with other nodes, where i1 ∈ i and i2 ∈ i; i1 is the number of the initiating node of the connection, and i2 is the number of the target node of the connection. Generate the behavior feature vector Bi(t) = {Pi, RTi(t), Si(t), C(i, 1), C(i, 2),..., C(i, n)} of each node i at time t, and through the preset formula calculate the behavior consistency eigenvalue of node i at time t , if it is lower than the set threshold, it is considered that there are abnormal fluctuations in the behavior of the node, a malicious behavior change signal regarding node i is generated, and the potential malicious behavior of node i in terms of behavior consistency is determined. Among them, is the behavior feature vector of the previous preset time interval t of the current moment t. Among them is the Euclidean distance, that is, the straight-line distance between two points Bi(t) and Bi(t - 1) in the vector space.

[0054] It should be noted that the behavior consistency of the node is used to detect whether the change in the node's behavior is abnormal. The behavior of normal nodes should be consistent in the network and should not change frequently. Moreover, information such as the number of connections of the node to other nodes and the connection duration has continuity. If a node suddenly increases or decreases its connections to other nodes, it may be a sign of malicious behavior; for example, an infected node may frequently change the nodes it connects to in order to avoid detection.

[0055] Combined with tampering with data records for node malicious behavior detection, tampering detection is carried out by comparing whether the blockchain data saved by the node is consistent with the blockchain data stored by all other nodes. Every preset time interval, the block data Di saved by the blockchain of each node i is obtained. If it is detected that the block data Di saved by the blockchain of node i is inconsistent with the block data saved by the blockchains of other nodes, a malicious tampering signal regarding node i is generated, and it is determined that node i has the behavior of tampering with blockchain data.

[0056] Obtain the number of malicious request signals, malicious behavior change signals or malicious tampering signals of each node.

[0057] If the weighted sum result of the number of malicious request signals, the number of malicious behavior change signals, and the number of malicious tampering signals generated by a node exceeds the preset threshold, it is determined that the node has serious malicious behavior and security risks, and it is expelled from the network through the consensus protocol.

[0058] During the node communication process, the generation time of the malicious request signals, malicious behavior change signals or malicious tampering signals of all nodes and the corresponding node numbers are recorded in the security log of the node for later auditing.

[0059] Step Three: Encrypted Communication;

[0060] Whenever communication is established between two nodes i1 and i2, the encrypted public keys of nodes i1 and i2 are exchanged. Using the asymmetric encryption algorithm, let the initiating node i1 of the communication encrypt the message to be sent with its own private key and send the message to the target node i2.

[0061] Let the target node i2 use the public key of the initiating node i1 of the communication to decrypt the message encrypted with the private key to obtain the original message.

[0062] Step Four: Message Integrity Verification;

[0063] Whenever communication is established between two nodes i1 and i2, let both communication parties use a message authentication code to verify the integrity of the message. Ensure that the data has not been tampered with during transmission.

[0064] Whenever the initiating node i1 of the communication sends a message Mi1, it will first calculate the MAC value of the message Mi1 before encryption to obtain the message authentication code MACi1 based on the hash function;

[0065] When the target node i2 of the communication receives the message Mi1, it first calculates the MAC value of the result after decrypting the message Mi1 to obtain the message authentication code MACi2 based on the hash function;

[0066] Analyze the consistency of the message authentication codes MACi1 and MACi2 through a matching operation. If the result of the matching operation is consistent, it means that the message has not been tampered with during transmission; otherwise, let the target node i2 of the communication reject the message.

[0067] Please refer to Figure 2 As shown, the communication security management device based on blockchain nodes includes several nodes, and all nodes jointly form a communication network. Among them, the types of communication nodes include servers, personal computers, and personal mobile communication terminals. Each communication node includes a computing unit, a storage unit, a network interface, and an encryption module. Nodes communicate with other nodes through network connections and ensure identity authentication and data consistency through the blockchain. Each node stores a blockchain in its local storage space.

[0068] The blockchain stored by each node has the following characteristics: The blockchain adopts a hash link structure, and each block contains a hash value pointing to the previous block to ensure the immutability of the data. The blockchain data is encrypted and protected through encryption algorithms. Nodes perform identity verification and sharing of behavioral data through the blockchain. Each node adds metadata such as the public key and identity information of the newly added node to its local blockchain and maintains the state consistency of the network through a consensus protocol.

[0069] It should be understood that the terms "including" and "comprising" used in the specification and claims of this disclosure indicate the presence of the described features, wholes, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.

[0070] It should also be understood that the terminology used herein in this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the disclosure. As used in this disclosure specification and the claims, the singular forms "a", "an" and "the" are intended to include the plural forms as well, unless the context clearly dictates otherwise. It should be further understood that the term "and / or" as used in this disclosure specification and the claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations;

[0071] The preferred embodiments of the present invention disclosed above are only used to help illustrate the present invention. The preferred embodiments do not describe all the details in detail, nor do they limit the present invention to only the specific embodiments. Obviously, many modifications and variations can be made according to the content of this specification. These embodiments are selected and specifically described in this specification in order to better explain the principles and practical applications of the present invention, so that those skilled in the art can well understand and utilize the present invention. The present invention is only limited by the claims and their full scope and equivalents.

Claims

1. A communication security management method based on blockchain nodes, characterized in that It includes the following steps; Step 1, node identity authentication; Set up a blockchain network for node identity verification; authenticate the nodes where both communication parties are located to ensure the authenticity of their identities and prevent malicious nodes from joining the network; whenever a new node requests to join, let all nodes in the communication network verify the identity of the newly joined node; through the public key encryption algorithm, each node uses the public key it stores to verify the identity of the new node; Step 2, detection of malicious node behavior; Through behavioral analysis and statistical methods, combined with request frequency, behavioral consistency, and tampered data detection, regularly evaluate whether the behavior of each node complies with network regulations. Generate malicious request signals, malicious behavior change signals, or malicious tampering signals according to the evaluation results, and obtain the number of malicious request signals, malicious behavior change signals, or malicious tampering signals of each node; if the weighted sum result of the number of malicious request signals, the number of malicious behavior change signals, and the number of malicious tampering signals generated by a node exceeds a preset threshold, it is determined that the node has serious malicious behavior and security risks, and it is expelled from the network through the consensus protocol; The specific process of detecting malicious node behavior in combination with behavioral consistency is: At every preset time interval t, the communication protocol number symbol Pi(t), response time RTi(t), and data packet size Si(t) of each node in the communication network are obtained, where i is the node number in the communication network, i=1,2,...,n; n is the total number of nodes; wherein the specific value of the communication protocol number symbol Pi is 1, 2, 3 or 4, corresponding to the preset communication protocols TCP, UDP, HTTP and WebSocket in the communication network respectively; the connection duration C(i1, i2) of each node with other nodes is obtained, where i1∈i and i2∈i; i1 is the initiating node number of the connection, and i2 is the target node number of the connection; the behavior feature vector Bi(t)={Pi, RTi(t), Si(t), C(i,1), C(i,2),..., C(i,n)} of each node i at time t is generated, and the behavior feature vector Bi(t)={Pi, RTi(t), Si(t), C(i,1), C(i,2),..., C(i,n)} of each node i is obtained through the preset formula Calculate the behavior consistency eigenvalue of node i at time t , if it is lower than the set threshold, it is considered that the node's behavior has abnormal fluctuations, a malicious behavior change signal about node i is generated, and the potential malicious behavior of node i in terms of behavior consistency is determined; among them, is the behavior feature vector of the previous preset time interval t before the current time t; is the Euclidean distance, that is, the straight-line distance between two points Bi(t) and Bi(t-1) in the vector space; The specific process of detecting malicious node behavior in combination with tampered data records is: Conduct tampering detection by comparing whether the blockchain data stored by a node is consistent with the blockchain data stored by all other nodes. Obtain the block data Di stored in the blockchain of each node i at every preset time interval. If it is detected that the block data Di stored in the blockchain of node i is inconsistent with the block data stored in the blockchains of other nodes, generate a malicious tampering signal regarding node i and determine that node i has the behavior of tampering with blockchain data; Step 3, encrypted communication; When two nodes establish communication, the nodes use the asymmetric encryption algorithm to exchange encryption public keys, and encrypt the message with the private key of the initiating node; Step 4, message integrity verification; Use a message authentication code based on a hash function to verify the integrity of the communication message; confirm that the message has not been tampered with by calculating the MAC value of the message and comparing it with the result calculated by the target node; The specific process of message integrity verification is: Whenever the initiating node i1 of the communication sends a message Mi1, first calculate the MAC value of the message Mi1 before encryption to obtain the message authentication code MACi1 based on the hash function; When the target node i2 of the communication receives the message Mi1, first calculate the MAC value of the decryption result obtained after decrypting the message Mi1 to obtain the message authentication code MACi2 based on the hash function; Perform consistency matching on the message authentication codes MACi1 and MACi2. If the matching result is consistent, it indicates that the message has not been tampered with during transmission; otherwise, let the target node i2 of the communication reject the message.

2. The communication security management method based on a blockchain node according to claim 1, characterized in that The specific process of setting up a blockchain network for node identity verification is: In a communication network, each node locally stores a blockchain, which together forms a blockchain network for node identity authentication; the blockchains stored by each node contain the public keys, registration times, and metadata related to identity information of all known nodes, which are used for identity information authentication and comparison; all blockchains adopt a hash-linked structure, enabling the data of each block to be associated with that of the previous block, ensuring that if the information of one block in a blockchain is tampered with, all subsequent blocks in that blockchain will become invalid.

3. The communication security management method based on blockchain nodes according to claim 1, characterized in that, The specific process for all nodes in the communication network to verify the identity of a newly joined node is as follows: First, query through the blockchain whether the public key of the newly joined node already exists in the blockchains stored by each node; if the blockchain of at least one node among all nodes already contains this public key, enter the identity authentication verification stage; each node uses the public key saved in its stored blockchain to verify the identity of the newly joined node, obtaining the identity verification results of each node for the newly joined node; among them, the identity verification result is obtained through the RSA public key encryption algorithm; if the identity verification results of all nodes for the newly joined node are passed, it is determined that the node newly joined to the communication network passes the node identity verification, and the request for the newly joined node to join the communication network is allowed. Otherwise, it is determined that the node newly joined to the communication network fails the identity verification, and the identity information of the newly joined node to the communication network is registered.

4. The communication security management method based on blockchain nodes according to claim 3, characterized in that, The specific process for registering the identity information of a newly joined node to the communication network is as follows: Generate a pair of public and private keys for identity authentication and register the public key in the blockchains of all nodes; among them, the private key is used for encrypting node identity information, and the public key is used for verifying node identity information. Encrypt the identity information of the newly joined node with the generated private key and save the encrypted result in the local storage space of the newly joined node; let each node in the communication network add the public key of the newly joined node to the locally stored blockchain to ensure that all nodes can obtain this public key for subsequent identity verification.

5. The communication security management method based on a blockchain node according to claim 1, wherein The specific process for detecting malicious node behavior in combination with the request frequency is as follows: Set the request frequency threshold of the node , and obtain the number of requests for joining the communication network sent by each newly added node within the last preset time interval t , if the condition is met , then it is determined that the join request of the newly added node contains potential malicious behavior, and a malicious request signal for node i is generated 6. The communication security management method based on blockchain nodes according to claim 1, wherein The specific process for encrypting a message with the private key of the initiating node is as follows: Whenever communication is established between two nodes i1 and i2, the encrypted public keys of nodes i1 and i2 are exchanged; using the asymmetric encryption algorithm, let the initiating node i1 of the communication use its own private key to encrypt the message to be sent and send the message to the target node i2. Let the target node i2 decrypt the message encrypted with the private key using the public key of the initiating node i1 of the communication to obtain the original message.

7. Communication security management device based on blockchain nodes, characterized in that Implement the communication security management method based on blockchain nodes described in any one of claims 1-6: including several nodes, and all nodes together form a communication network; among them, the types of nodes include servers, personal computers, and personal mobile communication terminals; each node includes a computing unit, a storage unit, a network interface, and an encryption module; the nodes communicate with other nodes through network connections and ensure identity authentication and data consistency through the blockchain; each node saves a blockchain in its local storage space. The blockchain stored in each node is as follows: The blockchain adopts a hash-linked structure, and each block contains a hash value pointing to the previous block; The blockchain data is encrypted and protected through encryption algorithms; Nodes perform identity authentication and sharing of behavioral data through the blockchain; Each node adds the public key and identity information metadata of newly joined nodes to the local blockchain and maintains the state consistency of the network through a consensus protocol.

Citation Information

Patent Citations

  • Communication security management method and system based on block chain nodes

    CN118381613A