A zero-trust framework design method based on a smart contract

By constructing a zero-trust framework based on smart contracts and utilizing blockchain and artificial intelligence technologies, the authentication nodes and conditions can be flexibly adjusted, solving the problems of immutability and low efficiency of traditional authentication protocols, and achieving efficient and secure authentication control.

CN119690383BActive Publication Date: 2026-01-06BEIJING INST OF COMP TECH & APPL
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411679562.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-22
Publication Date
2026-01-06
Estimated Expiration
2044-11-22

AI Technical Summary

Technical Problem

Traditional smart contract authentication protocols suffer from immutability and low efficiency, failing to meet the demands for efficient and secure authentication in complex information systems.

Method used

Design a zero-trust framework based on smart contracts. By constructing trust verification nodes, smart contract models, and smart authentication models, blockchain technology is used to achieve flexible adjustment of authentication nodes and dynamic adjustment of authentication conditions. Artificial intelligence models are combined to match and optimize authentication behavior.

Benefits of technology

It achieves flexibility and efficiency in the authentication process, meets the security control requirements of large-scale and complex authentication needs, and improves authentication efficiency without affecting business progress.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119690383B_ABST
    Figure CN119690383B_ABST
Patent Text Reader

Abstract

The present application relates to a kind of zero trust framework design method based on smart contract, belong to artificial intelligence model and blockchain field.The intelligence of the present application is mainly reflected in the intelligence of contract and the intelligence of authentication.The intelligence of contract is reflected in that contract can be flexibly changed, is not based on the fixed contract of establishment, but the authentication mode of authentication node and node can be changed based on the form of blockchain;The intelligence of authentication is reflected in that the specific authentication mode of authentication behavior, authentication strength and different authentication modes in the authentication based on artificial intelligence model can be switched according to specific authentication demand, can be matched and adjusted according to actual demand, meet the safe flexible authentication under the large-scale complex authentication demand.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the fields of artificial intelligence models and blockchain, specifically involving a zero-trust framework design method based on smart contracts. Background Technology

[0002] A smart contract is an agreement that automatically executes corresponding actions based on pre-determined conditions. In concrete form, it is a string of computer code that executes according to specific conditions. The main characteristic of smart contracts is that they authorize the blockchain with the compliance and operability of specific actions based on its distributed verification and decentralized trust system. Through the joint verification of on-chain users and pre-agreed action execution mechanisms, the immutability and non-repudiation of the action conditions and execution are guaranteed.

[0003] Zero Trust is a trust architecture or system for computer or information systems built upon the principles of never trusting and continuous authentication. Its main characteristic is that it maximizes the controllability of relevant information permissions and the corresponding operational space, achieving fine-grained permission control for different personnel in different states and on different devices at different stages within the same information system. This meets the needs of current and future complex information system architectures, including scenarios with complex business processes, massive data volumes, and significant personnel overlap, ensuring the security and status control of personnel and equipment.

[0004] However, with the increasingly complex computing and information system usage environments, the number of zero-trust trust chains has surged, and the concurrent authentication tasks at various stages of the same task are enormous. Traditional authentication is extremely inefficient, and the contradiction between authentication application scheduling and business scheduling is intensifying. There is an urgent need to develop a dual technical framework that can meet both the security enhancement requirements of authentication and the efficient execution of corresponding business processes.

[0005] Traditional smart contracts rely on automated execution of pre-negotiated authentication mechanisms and conditions. When a condition is met, the corresponding authentication action is automatically executed, making it unchangeable once negotiated. While traditional smart contracts significantly reduce the complexity of automated authentication, the increasing number of multi-scenario authentication demands and the growing immutability of authentication protocols necessitate a truly intelligent model. This model should fully integrate intelligent authentication condition negotiation with the immutability and distributed trust mechanisms of blockchain, forming a smart model-based authentication protocol negotiation framework. This framework would replace the pre-set authentication mechanisms in traditional smart contracts, creating an online authentication system with variable and adjustable authentication conditions, and a traceable authentication process recorded on the blockchain. Summary of the Invention

[0006] (a) Technical problems to be solved

[0007] The technical problem this invention aims to solve is how to provide a zero-trust framework design method based on smart contracts to address the issues of immutability of authentication protocols and the need for intelligent development of authentication.

[0008] (II) Technical Solution

[0009] To address the aforementioned technical problems, this invention proposes a zero-trust framework design method based on smart contracts, which includes the following steps:

[0010] Step 1: Constructing the trust verification node of the zero-trust framework

[0011] By setting trust verification requirement nodes based on the needs of actual scenarios, that is, setting authentication nodes with different security strengths at different time and space nodes according to the specific needs of actual scenarios, the authentication nodes in the authentication process are adjustable.

[0012] Step 2: Building a smart contract model

[0013] The smart contract model is the contract module in the blockchain module. In each block, different triggering conditions are generated for the creation and modification of the contract. When designing the smart contract model, historical authentication triggering conditions and corresponding authentication behaviors are used as the raw data for training the model. Through different authentication triggering conditions and corresponding authentication behaviors, a basic smart contract model is learned and generated. The correctness of the matching relationship between the current authentication triggering conditions and authentication behaviors is used as the detection standard for the model's learning quality. The difference between the authentication behaviors learned by the model and the actual authentication behaviors is used as the input value for learning feedback. The model is repeatedly iterated to complete the adjustment and optimization.

[0014] Step 3: Setting up the smart authentication model based on the smart contract model.

[0015] Based on the smart contract model trained in the second step, a specific smart authentication model is set up. The smart authentication model makes a comprehensive decision on different authentication factors under the same authentication condition to match the real authentication mode.

[0016] Step 4: Set up a zero-trust smart contract framework based on the smart contract model in Step 2 and the smart authentication model in Step 3.

[0017] (III) Beneficial Effects

[0018] This invention proposes a zero-trust framework design method based on smart contracts, and a smart authentication framework based on artificial intelligence models and blockchain. The intelligence is mainly reflected in two aspects: the intelligence of the contracts and the intelligence of the authentication. The intelligence of the contracts lies in their flexible modification; they are not based on fixed pre-defined contracts, but rather on the ability to change authentication nodes and their authentication methods within the blockchain framework. The intelligence of the authentication lies in the fact that the specific authentication methods, authentication strengths, and different authentication modes in the AI-based authentication process can be switched according to specific authentication needs. This allows for matching and adjustment based on actual requirements, satisfying secure and flexible authentication needs under large-scale and complex authentication requirements. Attached Figure Description

[0019] Figure 1 This is a diagram of the zero-trust framework based on smart contracts of this invention. Detailed Implementation

[0020] To make the objectives, contents, and advantages of the present invention clearer, the specific embodiments of the present invention will be described in further detail below with reference to the accompanying drawings and examples.

[0021] This invention provides a zero-trust authentication mechanism based on blockchain smart contracts, offering an authentication framework that meets practical needs to address the aforementioned issues. It fully leverages the characteristics of smart contracts in blockchain technology, such as contract creation and sharing mechanisms, self-triggered execution mechanisms, and the immutability of contracts. This not only solves the continuous authentication requirement of constantly verifying user behavior in zero-trust mechanisms but also improves authentication efficiency without affecting the normal progress of business through the automatic execution mechanism of blockchain smart contracts.

[0022] In this invention, the specific execution action based on the blockchain smart contract mechanism is the authentication behavior. The specific conditions for executing the authentication behavior are the same as those in the zero-trust mechanism, both being specific authentication conditions determined based on defined authentication requirements. The intelligence in the smart contract zero-trust authentication system of this invention is reflected in two aspects: the intelligence of the contract and the intelligence of the authentication. The specific framework of the smart contract zero-trust authentication system is as follows: Figure 1 As shown.

[0023] The main principles of this invention are as follows:

[0024] The zero-trust framework establishes trust verification nodes. Trust verification nodes are set based on real-world scenario requirements; that is, authentication nodes of varying strengths are set at different times and locations according to actual needs. The authentication process and the number of nodes are adjustable. However, all actions at the beginning and during the process, including adding and revoking nodes and changes to authentication behavior for the same node, are initiated through blockchain sharing and confirmed on-chain. Every action is recorded on the chain, making it traceable, verifiable, and tamper-proof.

[0025] A smart model for setting trust conditions is constructed. This model is the smart contract model in the block, generating different trigger conditions for the creation and modification of the contract, rather than generating them in a pre-agreed, lifelong manner. The design of this model comprehensively utilizes historical authentication conditions as raw data for model generation and training. Through different authentication trigger conditions and corresponding authentication behaviors, the model learns the matching relationship between trigger conditions and authentication behaviors to generate the basic model of the smart contract. Then, through the current authentication trigger conditions, it learns specific authentication behaviors and judges the matching relationship between the learned authentication behaviors and the actual authentication behaviors. This learning result is used as the criterion for evaluating the model's learning quality. The difference between the model's learned matching results and the actual results is used as the input value for learning feedback. Specifically, this can be achieved by quantifying the values ​​of the authentication mode and the model's learned matching mode, as well as the different norms of their difference. A well-performing smart model is obtained by using the magnitude of this difference or other quantitative indicators. The end of model learning is determined by a combination of the number of feedback iterations and the learning accuracy, specifically based on the security strength of different authentication conditions and authentication modes. For example, in a specific authentication scenario, different security strengths of authentication can correspond to different accuracy levels of the model under different conditions.

[0026] Construct an intelligent authentication model for authentication. This model can comprehensively determine the matching true authentication mode for different authentication factors under the same authentication conditions. For example, in multi-factor authentication, it can match multiple modes based on different static and dynamic biometrics, identity identifiers, and public key certificates. Specifically, it can be divided into different levels of authentication results, and the level can be determined according to the actual situation.

[0027] A zero-trust smart contract framework is established based on the trained and validated smart contract model and smart authentication model. The specific contract framework is then set up based on the two AI models trained in the previous step. This framework can be divided into multiple layers of contract constraints. For example, different contract models can be set on different blockchains, such as those on public blockchains, private blockchains, and consortium blockchains. On-chain contract verification is performed based on the different contracts within each model, and the verification is comprehensively conducted across different blocks, combining the blockchain's form and authentication model.

[0028] This invention proposes a zero-trust framework design method based on smart contracts, which specifically includes the following steps:

[0029] Step 1: Build the trust verification node of the zero-trust framework.

[0030] Trust verification nodes are set up based on the needs of real-world scenarios. This means that authentication nodes with varying security levels are set up at different times and locations according to specific requirements of the actual scenario. This makes the authentication process adjustable; the number and setup of authentication nodes can be adjusted based on actual needs. However, all actions from start to finish, including adding and removing nodes, and changes to the authentication mode for the same node, are initiated and confirmed on the blockchain through shared data, ensuring that every action is recorded on the chain, traceable, and tamper-proof.

[0031] Step 2: Build a smart contract model.

[0032] A smart contract model is a contract module within a blockchain module. In each block, it generates different triggering conditions for the creation and modification of the contract, rather than relying on pre-agreed, unchanging conditions. This smart contract model is designed by comprehensively utilizing historical authentication triggering conditions and corresponding authentication behaviors as the raw data for training. Through different authentication triggering conditions and corresponding authentication behaviors, it learns and generates a basic smart contract model. The correctness of the matching relationship between the current authentication triggering conditions and authentication behaviors is then used as the criterion for evaluating the model's learning performance. The difference between the authentication behaviors learned by the model and actual authentication behaviors serves as the input value for learning feedback, and the model is iteratively adjusted and optimized through repeated iterations.

[0033] Specifically, this can be achieved by quantifying the authentication pattern and the matching pattern obtained from model learning, as well as the different norms of the difference between the two, and by learning a well-performing model through the magnitude of this difference or other quantitative indicators.

[0034] The sign that the model learning is over can be determined by a combination of the number of feedback iterations and the learning accuracy, and specifically by the matching degree of different authentication trigger conditions and authentication behaviors.

[0035] Step 3: Set up the smart authentication model based on the smart contract model.

[0036] Based on the smart contract model trained in the second step, a specific smart authentication model is set up. The smart authentication model can comprehensively determine the matching real authentication mode for different authentication factors in the same authentication condition. For example, in multi-factor authentication, multiple modes can be matched based on different static and dynamic biometrics, identity identifiers, and public key certificates. Specifically, authentication factor combination modes with different security levels can be divided according to the number of authentication factors and the security strength of the factors. The level needs to be determined according to actual needs.

[0037] Step 4: Set up a zero-trust smart contract framework based on the smart contract model in Step 2 and the smart authentication model in Step 3.

[0038] Smart contract frameworks can be divided into multiple layers of contract constraints. For example, different contract models can be set on different blockchains, such as contract models on public blockchains, contract models on private blockchains, and contract models on consortium blockchains. On-chain contract verification is performed based on different contracts in different models, and comprehensive verification is conducted across different blocks of the blockchain by combining the chain form and authentication model.

[0039] Step 5: Updating and upgrading the model on different block and chain patterns.

[0040] The artificial intelligence model in smart contracts has the ability to learn and upgrade, and can be updated and upgraded on different blocks and different chain modes. In this way, the strength of zero trust can be strengthened or weakened according to actual specific needs. The strength of zero trust and the authentication method can both serve as the basic components of zero trust, and can be adjusted and changed on the trust verification chain.

[0041] This invention proposes an intelligent authentication framework based on an artificial intelligence model and blockchain. The intelligence is primarily reflected in two aspects: the intelligence of the contract and the intelligence of the authentication process. The intelligence of the contract lies in its flexible modification; it is not based on a fixed, predetermined contract, but rather on the ability to change the authentication nodes and their authentication methods within the blockchain framework. The intelligence of the authentication process lies in the ability of the specific authentication methods, authentication strengths, and different authentication modes within the AI-based authentication model to switch according to specific authentication needs. This allows for matching and adjustment based on actual requirements, satisfying secure and flexible authentication needs under large-scale and complex authentication demands.

[0042] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the technical principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A method for designing a smart contract-based zero-trust framework, characterized in that, The method comprises the following steps: First step: constructing an authentication node of a zero trust framework By setting the authentication node based on the actual scene requirements, that is, setting authentication nodes with different security strengths at different time and space nodes according to the specific requirements of the actual scene, the authentication nodes in the authentication process are adjustable; Second step: constructing an intelligent contract model The intelligent contract model is a contract module in the blockchain module, which generates different authentication trigger conditions for the generation and change of the contract in each block; When designing the intelligent contract model, historical authentication trigger conditions and corresponding authentication behaviors are comprehensively utilized as the original data for training the model, different authentication trigger conditions and corresponding authentication behaviors are used to learn and generate a basic intelligent contract model, and whether the matching relationship between the current authentication trigger condition and the authentication behavior is correct or not is used as the detection standard for the learning of the model, and the difference value between the authentication behavior learned by the model and the real authentication behavior is used as the input value for learning feedback, and the adjustment and optimization of the model are completed through repeated iteration; Third step: setting an intelligent authentication model based on the intelligent contract model Based on the intelligent contract model trained in the second step, a specific intelligent authentication model is set, which comprehensively determines the matching real authentication mode for different authentication factors in the same authentication trigger condition; Fourth step: setting a zero trust intelligent contract framework based on the intelligent contract model in the second step and the intelligent authentication model in the third step.

2. The smart contract based zero trust framework design method of claim 1, wherein, The setting of the authentication node and the number of authentication nodes are adjusted according to actual requirements.

3. The smart contract based zero trust framework design method of claim 2, wherein, All actions from the beginning to the end, including the addition and revocation of nodes and the change of authentication modes for the same node, are initiated through the shared blockchain and the confirmed mode on the blockchain, ensuring that each action can be recorded on the chain and is traceable and tamper-proof.

4. The smart contract based zero trust framework design method of claim 1, wherein, In the second step, the values of the matching mode learned by the model and the different norm modes of the difference value are quantified, and the model with good performance is learned through the size of the difference value or other quantitative indicators.

5. The smart contract based zero trust framework design method of claim 4, wherein, In the second step, the sign of the end of model learning is determined by the number of feedback iterations and the accuracy of learning, which can be determined according to the matching degree of different authentication trigger conditions and authentication behaviors.

6. The smart contract based zero trust framework design method of claim 1, wherein, The third step of the intelligent authentication model matches multiple modes based on different static and dynamic biometric features, identity identification and public key certificates in multi-factor authentication.

7. The smart contract based zero trust framework design method of claim 6, wherein, In the third step, the authentication factor combination mode is divided into different security level authentication factor combinations according to the number of authentication factors and the security strength of the factors.

8. The smart contract based zero trust framework design method of claim 1, wherein, In the fourth step, the intelligent contract framework can be divided into multiple levels of contract constraints.

9. The smart contract based zero trust framework design method of claim 8, wherein, In the fourth step, different contract modes can be set on different blockchains, that is, contract modes on public chains, contract modes on private chains and contract modes on alliance chains, and the contract verification on the chain is carried out according to different contracts in different modes, and the form of the chain and the authentication mode are combined to verify between different blocks of the blockchain.

10. The smart contract based zero trust framework design method of claim 1, wherein, The fourth step further comprises: Fifth step: updating and upgrading the model on different blocks and different chain modes The artificial intelligence model in the smart contract has learning ability and upgrading evolution ability, and can be updated and upgraded on different blocks and different chain modes, and then can enhance and weaken the trust strength of zero trust according to actual specific needs. The strength and authentication method of zero trust can be used as the basic constituent elements of zero trust, and can be adjusted and changed on the trust verification chain.

Citation Information

Patent Citations

  • Multi-modal biological recognition method and device

    CN111368921A

  • Block chain and privacy computing-based construction guide type decision-making method and system

    CN117972781A