Network node checking method, apparatus, device, medium and program product
By generating and comparing random sequences in communication nodes and verification nodes, the problem of cumbersome certificate verification process and waste of computing resources in existing technologies is solved, and efficient and secure network node verification is achieved.
Patent Information
- Application Number
- CN202411928228.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-25
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2044-12-25
AI Technical Summary
In existing trusted local area networks, certificates remain unchanged after generation and need to be verified every time access is made, resulting in a cumbersome and inefficient process. Asymmetric encryption algorithms are computationally inefficient and wasteful of resources.
A random sequence generation method based on initial key is adopted. Random sequences are generated at communication nodes and verification nodes through chaotic mapping and XOR operation, and then compared at the verification node to achieve unified verification of multiple communication nodes.
It improves the efficiency of network node verification, saves computing resources, simplifies communication processes, and enhances the security and stability of the network system.
Smart Images

Figure CN119728109B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the field of information security and financial technology, in particular to security verification of network nodes, and more particularly to a network node verification method, device, equipment, medium and program product. BACKGROUND
[0002] The existing trusted local area network is mainly guaranteed by the SSL protocol. In the SSL protocol, there is a CA agency for issuing SSL certificates to prove the authenticity and identity of the nodes. When one of the nodes accesses another node, the accessed node sends its own SSL certificate to the accessing node, and the accessing node verifies the validity of the certificate to confirm the authenticity and identity of the server, thereby ensuring the security of data transmission.
[0003] In the existing trusted local area network, the certificate authenticated by the CA agency does not change after generation, and the certificate needs to be verified by both parties for each access. The process is relatively cumbersome and inefficient. In addition, when applying for a certificate, the protocol uses an asymmetric encryption algorithm. Due to the natural mathematical calculation property of the asymmetric encryption technology, the operation efficiency is low, which is easy to cause resource waste. SUMMARY
[0004] In view of the above problems, the embodiments of the present disclosure provide a network node verification method, device, equipment, medium and program product for improving the verification efficiency of network nodes and saving computing resources.
[0005] According to a first aspect of the present disclosure, a network node verification method is provided, the network node comprising a verification node and a plurality of communication nodes, the method comprising: based on a plurality of first initial value keys, generating a random sequence in each communication node in a predetermined order to obtain a first random sequence, each first initial value key being stored in each communication node. Based on a plurality of second initial value keys, generating a random sequence in the verification node in a predetermined order to obtain a second random sequence, the second initial value key being determined based on the first initial value key stored in the verification node. Comparing the first random sequence with the second random sequence. In the case that the first random sequence and the second random sequence are consistent, it is determined that each communication node is verified.
[0006] According to an embodiment of the present disclosure, the first random sequence is generated in each communication node in a predetermined order based on the plurality of first initial value keys, and includes: obtaining an initial value key in a first order node. Chaotic mapping is performed based on the initial value key in the first order node to obtain a first binary sequence. A second binary sequence of a second order node is determined. The first binary sequence and the second binary sequence are subjected to XOR operation to obtain a fusion binary sequence. Chaotic mapping and XOR operation are repeatedly performed for subsequent order nodes until all the communication nodes are traversed to obtain the first random sequence.
[0007] According to an embodiment of the present disclosure, the algorithm corresponding to the chaotic mapping is at least one-dimensional algorithm, and the dimension of the algorithm represents the dimension of the state space of the dynamic system. When the algorithm is one-dimensional, the value of the system growth rate is between 3.5 and 4.
[0008] According to an embodiment of the present disclosure, the plurality of communication nodes form a communication node sequence, and the check node only communicates with the last communication node in the communication node sequence to obtain the first random sequence. In the check node, the first random sequence and the second random sequence are compared to check the plurality of communication nodes.
[0009] According to an embodiment of the present disclosure, the communication node sequence is a plurality of communication node sequences, each of which contains part of the plurality of communication nodes, and each of which is respectively provided with a check node.
[0010] According to an embodiment of the present disclosure, the plurality of communication nodes are checked according to a preset fixed period. Alternatively, the checking period is determined according to the size relationship between the network traffic and the preset traffic threshold. The plurality of communication nodes are checked according to the checking period. The checking period is negatively correlated with the network traffic.
[0011] According to an embodiment of the present disclosure, the network node checking method further includes: in the case that the first random sequence and the second random sequence are inconsistent, sending a warning to each communication node. And / or in the case that the first random sequence and the second random sequence are inconsistent, respectively excluding and checking each communication node to determine an abnormal communication node.
[0012] According to an embodiment of the present disclosure, the network node checking method is applied to a local area network.
[0013] The second aspect of the present disclosure provides a network node checking device, the network node comprising a check node and a plurality of communication nodes, the device comprising: a first generation module configured to generate a first random sequence in each of the communication nodes in a predetermined order based on a plurality of first initial value keys, each of the first initial value keys being stored in each of the communication nodes; a second generation module configured to generate a second random sequence in the check node in the predetermined order based on a plurality of second initial value keys, the second initial value keys being determined based on the first initial value keys stored in the check node; a comparison module configured to compare the first random sequence with the second random sequence; and a determination module configured to determine that each of the communication nodes passes the check if the first random sequence is consistent with the second random sequence.
[0014] The third aspect of the present disclosure provides an electronic device, comprising: one or more processors; and a memory configured to store one or more computer programs, wherein the one or more processors are configured to execute the one or more computer programs to implement the steps of the network node checking method.
[0015] The fourth aspect of the present disclosure further provides a computer-readable storage medium having stored thereon a computer program or instructions, wherein the computer program or instructions, when executed by a processor, implement the steps of the network node checking method.
[0016] The fifth aspect of the present disclosure further provides a computer program product comprising a computer program or instructions, wherein the computer program or instructions, when executed by a processor, implement the steps of the network node checking method. BRIEF DESCRIPTION OF DRAWINGS
[0017] The above and other objects, features and advantages of the present disclosure will become more apparent from the following description when taken in conjunction with the accompanying drawings, in which:
[0018] Figure 1 An application scenario diagram of the network node checking method, device, equipment, medium and program product according to an embodiment of the present disclosure is schematically shown;
[0019] Figure 2 A flowchart of the network node checking method according to an embodiment of the present disclosure is schematically shown;
[0020] Figure 3 A flowchart of the method for generating the first random sequence according to an embodiment of the present disclosure is schematically shown;
[0021] Figure 4 A bifurcation diagram of the logistic mapping according to an embodiment of the present disclosure is schematically shown;
[0022] Figure 5A flow chart of a network node checking method according to another embodiment of the present disclosure is schematically shown;
[0023] Figure 6 A network architecture diagram to which the network node checking method according to an embodiment of the present disclosure is applied is schematically shown;
[0024] Figure 7 A structure block diagram of a network node checking apparatus according to an embodiment of the present disclosure is schematically shown; and
[0025] Figure 8 A block diagram of an electronic device suitable for implementing the network node checking method according to an embodiment of the present disclosure is schematically shown. DETAILED DESCRIPTION
[0026] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. It is to be understood, however, that the description is merely exemplary of the present disclosure, but is not intended to limit the scope of the present disclosure. In the following detailed description of the embodiments of the present disclosure, numerous specific details are set forth in order to provide a thorough understanding of the embodiments of the present disclosure. However, it would be apparent to those skilled in the art that the embodiments of the present disclosure can be practiced without these specific details. In other instances, well-known structures and methods are not described in detail in order to avoid obscuring the concepts of the present disclosure.
[0027] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the present disclosure. As used herein, the term "including" and "comprising" and the like are meant to be inclusive in a manner that the terms are to be interpreted as retaining their ordinary meanings in the context of this disclosure.
[0028] All terms used herein, including technical and scientific terms, have the meanings commonly understood by one of ordinary skill in the art unless otherwise defined. It should be noted that the terms used herein are to be interpreted as having a meaning that is consistent with their context and consistent with the overall mechanism of the present disclosure, and should not be interpreted in an idealized or overly formal way unless expressly so defined herein.
[0029] In the case of using expressions similar to "at least one of A, B, and C, etc.", it is generally to be interpreted as including any one of A, B, and C, etc., in the meaning that the expression is understood by one of ordinary skill in the art (for example, "a system having at least one of A, B, and C" should include a system having A alone, a system having B alone, a system having C alone, a system having A and B together, a system having A and C together, a system having B and C together, and / or a system having A, B, and C together, etc.).
[0030] The embodiments of the present disclosure provide a network node verification method, device, equipment, medium and program product, which can be applied to the field of financial technology or other fields. It should be noted that the network node verification method, device, equipment, medium and program product of the present disclosure can be applied to the field of financial technology, and can also be applied to any field other than the field of financial technology. The application field of the network node verification method, device, equipment, medium and program product of the present disclosure is not limited.
[0031] In the technical solutions of the present disclosure, the user information (including but not limited to user personal information, user image information, user equipment information such as location information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved are all information and data authorized by the user or authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of related data all comply with relevant laws, regulations and standards, take necessary security measures, do not violate public order and good customs, and provide corresponding operation portal for user selection authorization or refusal.
[0032] In the scenario of using personal information for automated decision-making, the method, device and system provided by the embodiments of the present disclosure all provide corresponding operation portal for the user to select to agree or refuse the automated decision-making result; if the user chooses to refuse, the expert decision-making process is entered. The expression "automated decision-making" here refers to the activity of automatically analyzing, evaluating the behavior habits, interests and hobbies or economic, health, credit status of individuals, etc. by computer programs and making decisions. The expression "expert decision-making" here refers to the activity of making decisions by personnel who are engaged in a certain field, have special experience, knowledge and skills, and have reached a certain professional level.
[0033] The embodiments of the present disclosure provide a network node verification method, wherein the network node includes a verification node and a plurality of communication nodes, and the method includes: generating a first random sequence in each communication node in a predetermined order based on a plurality of first initial value keys, to obtain the first random sequence, and each first initial value key is stored in each communication node. Generating a second random sequence in the verification node in a predetermined order based on a plurality of second initial value keys, to obtain the second random sequence, and the second initial value key is determined based on the first initial value key stored in the verification node. Comparing the first random sequence with the second random sequence. In the case that the first random sequence is consistent with the second random sequence, it is determined that each communication node is verified to pass. The present disclosure unifies the verification among the plurality of communication nodes through a specific verification node, and the communication nodes do not need to perform bilateral verification when communicating, thereby improving the verification efficiency of the network node. At the same time, the method of generating a random sequence by using an initial value key is a kind of symmetric encryption method, which also greatly saves the computing resources.
[0034] Figure 1An application scenario diagram of the network node verification method, apparatus, device, medium and program product according to an embodiment of the present disclosure is shown schematically.
[0035] As shown in Figure 1 The application scenario 100 according to this embodiment can include terminal devices 101, 102, 103, a network 104 and a server 105. The network 104 is a medium for providing a communication link between the first terminal device 101, the second terminal device 102, the third terminal device 103 and the server 105. The network 104 can include various connection types, such as wired, wireless communication links or optical fiber cables, etc.
[0036] The user can use the first terminal device 101, the second terminal device 102, the third terminal device 103 to interact with the server 105 through the network 104 to receive or send messages, etc. Various communication client applications can be installed on the first terminal device 101, the second terminal device 102, the third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only as examples).
[0037] The first terminal device 101, the second terminal device 102, the third terminal device 103 can be various electronic devices with a display screen and supporting web browsing, including but not limited to smartphones, tablet computers, laptop computers and desktop computers, etc.
[0038] The server 105 can be a server providing various services, such as a background management server supporting a website browsed by the user using the first terminal device 101, the second terminal device 102, the third terminal device 103 (only as an example). The background management server can analyze and process the received user request data, etc., and feed back the processing result (such as a webpage, information, or data, etc. obtained or generated according to the user request) to the terminal device.
[0039] It should be noted that the network node verification method provided by the embodiments of the present disclosure can generally be executed by the server 105. Accordingly, the network node verification apparatus provided by the embodiments of the present disclosure can generally be arranged in the server 105. The network node verification method provided by the embodiments of the present disclosure can also be executed by a server or a server cluster different from the server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or the server 105. Accordingly, the network node verification apparatus provided by the embodiments of the present disclosure can also be arranged in a server or a server cluster different from the server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or the server 105.
[0040] It should be understood that Figure 1 The number of terminal devices, networks and servers in the above scenario is only illustrative. Any number of terminal devices, networks and servers can be provided according to implementation needs.
[0041] The network node verification method according to the embodiments of the present disclosure will be described below based on the scenario described above. Figure 1 The network node verification method according to the embodiments of the present disclosure will be described below based on the scenario described above. Figures 2-6 The network node verification method according to the embodiments of the present disclosure will be described below based on the scenario described above.
[0042] Figure 2 A flowchart of the network node verification method according to the embodiments of the present disclosure is shown schematically.
[0043] According to the embodiments of the present disclosure, the network node includes a verification node and a plurality of communication nodes, as shown in Figure 2 The network node verification method according to the embodiments of the present disclosure, for example, includes operations S210-S240, which can be executed by a computer program on corresponding computer hardware.
[0044] In operation S210, based on a plurality of first initial value keys, a random sequence is generated in each communication node in a predetermined order, obtaining a first random sequence, and each first initial value key is stored in each communication node.
[0045] The network node system, for example, includes one verification node and a plurality of communication nodes. These nodes cooperate together to complete the subsequent verification process.
[0046] In the initial stage, the system has a plurality of first initial value keys, which are securely stored in each communication node. According to a predetermined order (for example, in ascending or descending order of node number), each communication node will generate a random sequence based on the first initial value key stored therein. After this process, each communication node will generate a random sequence, and each random sequence will be integrated according to the above order to obtain a first random sequence.
[0047] For example, the generation of the first initial value key can be completed by using a secure random number generator or a cryptographic algorithm (such as AES (Advanced Encryption Standard) and the like). The generated first initial value key is distributed to the corresponding communication node through a secure transmission method (such as encrypted communication), and stored in the secure storage area of the node.
[0048] It can be understood that the initial value key can be generated and assigned to each communication node at initialization, or can be pre-embedded in each communication node.
[0049] For example, each communication node uses its stored first initial key as a seed to call a pseudo-random number generator to generate a fixed-length random sequence. To ensure the unpredictability of the random sequence, the pseudo-random number generator should have good statistical properties and a long period.
[0050] In operation S220, based on the plurality of second initial keys, the random sequence generation is performed in the check node in a predetermined order to obtain a second random sequence, the second initial key being determined based on the first initial key stored in the check node.
[0051] Similar to the communication node, the check node also participates in the generation of the random sequence, but it is based on a plurality of second initial keys.
[0052] These second initial keys are not given directly, but are determined based on one or more first initial keys stored in the check node (which may be determined directly or converted through an algorithm or function). The check node also generates the random sequence in the predetermined order, and finally obtains a second random sequence.
[0053] For example, the check node uses its determined second initial key as a seed to call the same pseudo-random number generator as the communication node to generate a random sequence of the same length.
[0054] In operation S230, the first random sequence is compared with the second random sequence.
[0055] After all communication nodes and check nodes complete the generation of the random sequence, the system compares the first random sequence (from one of the communication nodes) with the second random sequence (from the check node). This comparison process aims to check whether the two are completely consistent.
[0056] For example, after generating the first random sequence, the corresponding communication node needs to send it to the check node. This can be done through network communication, but attention should be paid to the security during transmission, such as using an encrypted communication protocol.
[0057] After receiving the first random sequence, the check node compares it bit by bit with the second random sequence it generated. The check node only receives the random sequence and does not participate in regular communication, and the check node is secure by default. Except for the check node, other nodes do not check the received information, but only do simple calculations on the received random sequence, and the communication process is simpler, and this scheme belongs to the symmetric encryption algorithm system, and the operation efficiency is higher than that of the asymmetric encryption algorithm, and the operation resources are also saved.
[0058] In operation S240, in the case where the first random sequence and the second random sequence are consistent, it is determined that each communication node passes the check.
[0059] If the first random sequence is identical to the second random sequence, the system determines that each communication node passes the check, indicating that the keys and random sequence generation processes of these nodes are correct, and the security of the network is guaranteed.
[0060] If the two are not identical, further inspection or other security measures may be required.
[0061] This embodiment verifies the security of the communication nodes by generating random sequences in each communication node and the check node based on the initial value keys respectively, and comparing them. If the random sequence generated by each communication node is identical to the random sequence generated by the check node, it is confirmed that each communication node passes the check. This method uses the combination of randomness and key technology to improve the security check efficiency of the network nodes.
[0062] Figure 3 A flowchart of a method for generating a first random sequence according to an embodiment of the present disclosure is schematically shown. In this embodiment, in addition to the operations S210-S240 described above with reference to Figure 2 The description of operations S210-S240 is omitted here for the sake of brevity, and subsequent related method embodiments are also the same, and will not be repeated.
[0063] According to an embodiment of the present disclosure, as Figure 3 shown, for example, by operations S311-S315, the random sequence generation is sequentially performed in each communication node according to a predetermined order based on a plurality of first initial value keys, to obtain a first random sequence.
[0064] In operation S311, the initial value key in the first-order node is obtained.
[0065] First, the system identifies the first-order node in all communication nodes and obtains the first initial value key stored therein.
[0066] In a generation sequence of a first random number, each communication node forms a communication chain in series. The first-order node is the communication node that ranks first in the communication chain when the random sequence generation is performed according to the predetermined order described above. Then, according to the predetermined order, the second-order node, the third-order node, and so on are sequentially arranged.
[0067] In operation S312, according to the initial value key in the first-order node, chaotic mapping is performed to obtain a first binary sequence.
[0068] For example, using the first initial key of the first order node as input, a chaotic mapping function (such as Logistic mapping, Tent mapping, etc.) is called to generate a fixed-length binary sequence (01 sequence). This sequence has high randomness and complexity, and is difficult to predict.
[0069] In operation S313, a second binary sequence of the second order node is determined.
[0070] The second order node also generates a binary sequence of the same length using its stored first initial key through a chaotic mapping function. This sequence is independent of the first order node's sequence at the initial stage.
[0071] In operation S314, the first binary sequence and the second binary sequence are subjected to XOR operation to obtain a fusion binary sequence.
[0072] Next, the first binary sequence of the first order node and the second binary sequence of the second order node are subjected to bitwise XOR operation. The result of the XOR operation is a new binary sequence that fuses the information of the first two sequences while maintaining high randomness.
[0073] In operation S315, for subsequent order nodes, chaotic mapping and XOR operation are repeated in turn until all communication nodes are traversed to obtain the first random sequence.
[0074] For subsequent order nodes, the system repeats the above chaotic mapping and XOR operation steps in turn. Each node generates a binary sequence using its stored first initial key and performs XOR operation with the previous fusion binary sequence to obtain a new fusion binary sequence.
[0075] When all communication nodes have completed chaotic mapping and XOR operation, the final fusion binary sequence obtained is the first random sequence. This sequence contains the initial key information of all communication nodes, and due to the complexity of chaotic mapping and XOR operation, it is difficult to be predicted or cracked.
[0076] Finally, the check node also generates a second random sequence based on its second initial key (which, for example, corresponds one-to-one with the first initial keys in the communication nodes). Then, the system compares the first random sequence with the second random sequence. If they are consistent, it is determined that the communication nodes pass the check; if they are not consistent, further inspection or other security measures may be needed.
[0077] This embodiment combines the complexity of chaotic mapping and the fusion of XOR operation to generate a highly random and unpredictable first random sequence. This method not only improves the efficiency of security check of network nodes, but also enhances the security and stability of the entire network system.
[0078] According to an embodiment of the present disclosure, the algorithm corresponding to the chaotic mapping is at least one-dimensional, and the dimension of the algorithm represents the dimension of the state space of the dynamic system. When the algorithm is one-dimensional, the system growth rate is between 3.5 and 4.
[0079] In a network node verification method, a specific one-dimensional chaotic mapping algorithm is used to generate a random sequence, which not only has high randomness and complexity, but also meets the specific requirements of chaotic mapping.
[0080] For example, the Logistic mapping algorithm has been widely applied and deeply researched in chaotic theory. The expression of the Logistic mapping is:
[0081]
[0082] where x n is the state of the system at the nth time, and r is the system growth rate, which determines the chaotic behavior of the system.
[0083] Figure 4 The bifurcation diagram of the logistic mapping according to an embodiment of the present disclosure is schematically shown.
[0084] According to the requirements of the chaotic mapping algorithm, the value range of the system growth rate should be between 3.5 and 4. As Figure 4 shown, within this range, the Logistic mapping will exhibit typical chaotic behavior, i.e., the system state will exhibit high randomness and unpredictability.
[0085] Accordingly, the random sequence generation process includes, for example:
[0086] First, convert the first initial key of each communication node into a real number between 0 and 1 as the initial state of the Logistic mapping.
[0087] Using the Logistic mapping algorithm, iterate the initial state of each communication node to generate a binary sequence of fixed length. The number of iterations can be determined according to actual needs to ensure that the generated sequence has sufficient length and complexity.
[0088] In each iteration, according to the result of the Logistic mapping, it is converted into a binary number (for example, by threshold judgment, the result greater than 0.5 is converted to 1, and the result less than or equal to 0.5 is converted to 0). In this way, after multiple iterations, a binary sequence composed of 0 and 1 can be generated.
[0089] For subsequent in-order nodes, the above steps of chaotic mapping and binary sequence generation can be repeated in turn. Then, the binary sequences of the respective nodes can be fused using an XOR operation or other fusion method to obtain a final first random sequence.
[0090] It can be understood that, in order to simplify the process, the binary sequence generated by each node can also be directly used as part of the first random sequence.
[0091] The embodiment utilizes the chaotic behavior of the Logistic mapping to generate binary sequences with high randomness and complexity. These sequences are not only difficult to predict and crack, but also meet the specific requirements of chaotic mapping. Through this method, the security verification efficiency of network nodes can be effectively improved, and the security and stability of the entire network system can be enhanced.
[0092] According to embodiments of the present disclosure, the plurality of communication nodes form a communication node sequence, and the check node only communicates with the last communication node in the communication node sequence to obtain the first random sequence. In the check node, the first random sequence is compared with the second random sequence to implement the check on the plurality of communication nodes.
[0093] In some embodiments, the network system is composed of a plurality of communication nodes and a check node. Each communication node is provided with a unique first initial value key for subsequent chaotic mapping and random sequence generation.
[0094] According to the network topology or specific requirements, the plurality of communication nodes are arranged in a certain order to form a communication node sequence. The communication nodes in the sequence perform chaotic mapping and XOR operation in a predetermined order to generate a first random sequence.
[0095] The first communication node in the communication node sequence uses its first initial value key to perform chaotic mapping to generate a binary sequence.
[0096] Subsequent communication nodes in the sequence use their respective first initial value keys to perform chaotic mapping in turn, and perform XOR operation on the generated binary sequence and the sequence of the previous node to obtain a new fused binary sequence.
[0097] This process continues until the last communication node in the communication node sequence, which completes chaotic mapping and XOR operation to obtain the final first random sequence.
[0098] In the embodiment, the check node only communicates with the last communication node in the communication node sequence. The last communication node sends the generated first random sequence to the check node through a secure communication channel.
[0099] The check node uses its second initial key to perform chaotic mapping to generate a second random sequence.
[0100] It should be noted that the chaotic mapping algorithm and parameters used by the check node to generate the second random sequence should be consistent with the algorithm and parameters used by the communication node to generate the first random sequence to ensure comparability between the two.
[0101] The check node compares the received first random sequence with the second random sequence it generates.
[0102] If they are completely consistent, it indicates that all communication nodes have correctly generated random sequences according to the predetermined rules, and there has been no data tampering or loss during communication.
[0103] If they are not consistent, it indicates that there may be abnormal situations such as communication node failure, data tampering, or network attack, which need to be further checked or security measures taken.
[0104] If the check node finds that the first random sequence and the second random sequence are not consistent, it immediately triggers an abnormal detection mechanism. The system can notify the network administrator or security team for further investigation and processing through log recording, alarm prompt, etc.
[0105] According to the results of abnormal detection, the network administrator can take appropriate security measures, such as isolating faulty nodes, strengthening network communication encryption, updating security policies, etc.
[0106] At the same time, the chaotic mapping algorithm and parameters of the communication nodes and the check nodes can also be checked and updated regularly to improve the security and stability of the system.
[0107] The present embodiment realizes effective checking of multiple communication nodes by constructing communication node sequences, generating random sequences using chaotic mapping and XOR operation, and the security communication mechanism between the check node and the communication node.
[0108] According to embodiments of the present disclosure, the communication node sequences are multiple, each communication node sequence contains part of the multiple communication nodes, and each communication node sequence is respectively provided with a check node.
[0109] In some embodiments, according to the network topology, business requirements or security policies, the multiple communication nodes can be divided into multiple different communication node sequences. Each communication node sequence contains a part of the multiple communication nodes, and each communication node sequence can be provided with a check node.
[0110] In each sequence of communication nodes, the communication nodes perform chaotic mapping and XOR operation in a predetermined order to generate their respective first random sequences. The chaotic mapping algorithm and parameters are consistent in each sequence to ensure the comparability of the first random sequences generated among different sequences.
[0111] The last communication node in each sequence of communication nodes sends its generated first random sequence to the corresponding check node.
[0112] The check node performs chaotic mapping using its second initial key to generate a corresponding second random sequence. The length of these second random sequences should match the first random sequences received from the corresponding sequence of communication nodes. Each check node compares the received first random sequence with its corresponding second random sequence.
[0113] The comparison can be a bit-by-bit comparison or calculating a similarity index such as Hamming distance.
[0114] If all first random sequences match the corresponding second random sequences, it indicates that all sequences of communication nodes have correctly generated random sequences according to the predetermined rules, and no data tampering or loss has occurred during the communication process.
[0115] For example, if there are too many nodes in a network, it can be attempted to split them by dividing the local area network. For example, 100 nodes can be divided into 10 small local area networks, each with a check node. These 10 check nodes can also form a separate check local area network and communicate with a central check node to further improve network efficiency.
[0116] Due to multiple sequences of communication nodes, multiple check nodes can handle the verification tasks of these sequences in parallel. That is, each check node can simultaneously receive different first random sequences from each sequence of communication nodes and generate and compare multiple second random sequences at the same time.
[0117] Parallel verification can significantly improve the efficiency of verification, especially in large network systems.
[0118] It can be understood that, according to the changes in network topology, changes in business requirements, or adjustments in security policies, the sequence of communication nodes can be dynamically added, deleted, or reorganized. This can be achieved through a configuration management interface or automated tools.
[0119] To further improve the complexity and security of the random sequences, higher-dimensional chaotic mapping algorithms or combinations of multiple chaotic mapping algorithms can be used to increase the difficulty for attackers to crack the random sequences.
[0120] The embodiment realizes parallel verification of multiple communication node sequences by constructing multiple sequences containing partial communication nodes and using multiple check nodes to process check tasks in parallel. This method not only improves the verification efficiency and security of the network system, but also provides flexible configuration and management options for network administrators.
[0121] According to an embodiment of the present disclosure, the multiple communication nodes are verified according to a preset fixed period. Alternatively, the verification period is determined according to the size relationship between the network traffic and the preset traffic threshold. The multiple communication nodes are verified according to the verification period. The verification period is inversely related to the network traffic.
[0122] In some embodiments, a fixed period or a verification period of the network node based on dynamic network traffic can be used.
[0123] During system initialization, a fixed verification period (e.g., every hour, every day, etc.) is preset for periodic verification of the status of the communication nodes. Alternatively, one or more network traffic thresholds are set to determine the high or low state of the current network traffic.
[0124] For example, according to the preset fixed verification period, the check node starts the verification process. In each verification period, the check node communicates with the communication nodes according to the method described in the above embodiments, generates and compares random sequences to verify the correctness of the communication nodes.
[0125] For another example, the check node or a special traffic monitoring module monitors the network traffic in real time. The traffic data can be the usage rate of network bandwidth, the number or rate of data packets, etc.
[0126] The real-time monitored network traffic is compared with the preset traffic threshold.
[0127] If the network traffic is below a certain low threshold, indicating that the network load is low, the verification period can be shortened to monitor the status of the communication nodes more frequently, ensuring the security and stability of the network.
[0128] If the network traffic is above a certain high threshold, indicating that the network load is high, the verification period can be appropriately extended to reduce the occupation of network resources by the verification process.
[0129] The verification period is dynamically adjusted according to the real-time changes of the network traffic. The verification period is inversely related to the network traffic, i.e., the higher the network traffic, the shorter the verification period; the lower the network traffic, the longer the verification period. The adjusted verification period should be within a reasonable preset range to avoid excessively frequent or excessively sparse verification.
[0130] According to the currently effective check period (fixed period or dynamically adjusted period), the check node performs the check process. The check process includes steps such as communicating with the communication node, generating and comparing random sequences, etc.
[0131] In addition, a machine learning algorithm can also be introduced to intelligently predict future network traffic trends based on historical traffic data and check results, and adjust the check period accordingly. This will further improve the adaptability and accuracy of the check method.
[0132] For key communication nodes or high-security network environments, a multi-level check strategy can also be implemented.
[0133] For example, on the basis of fixed period checking, random checking or event-based checking can be added to improve the coverage and reliability of the check.
[0134] This embodiment not only checks according to the preset fixed period, but also dynamically adjusts the check period according to the real-time changes of network traffic to achieve a more efficient check strategy. This method not only improves the security and stability of the network system, but also reduces the occupation of network resources by the check process, providing network administrators with more flexible and intelligent check options.
[0135] Figure 5 The flowchart of the network node check method according to another embodiment of the present disclosure is schematically shown.
[0136] According to an embodiment of the present disclosure, as Figure 5 shown, the network node check method of this embodiment further includes operations S510~S520, for example.
[0137] In operation S510, if the first random sequence and the second random sequence are inconsistent, a warning is sent to each communication node. And / or
[0138] In operation S520, if the first random sequence and the second random sequence are inconsistent, an exclusion check is performed on each communication node to determine the abnormal communication node.
[0139] In some embodiments, if the first random sequence of any communication node is found to be inconsistent with the corresponding second random sequence during the check process, an inconsistency detection mechanism is triggered immediately.
[0140] For example, the check node sends a warning message to all communication nodes, informing them of the inconsistent check results.
[0141] The warning message can contain the inconsistent communication node identifier, the check timestamp, and possibly an error code or description.
[0142] For example, after sending the warning, the check node can initiate an exclusion check process to further determine which communication node (or which communication nodes) is abnormal.
[0143] The exclusion check can be performed by repeating the basic check process, individually for each communication node, or using other more refined check methods.
[0144] For example, when the check node does not match the first random sequence and the second random sequence, the abnormal node can be located by requiring each communication node to individually resend the 01 sequence after the communication node XOR to the check node once. Assuming there are four nodes A, B, C, and D in the network, and E is the check node, E can require A, B, C, and D to send A', AB', ABC', and ABCD' to E respectively after receiving and processing, and then the check node generates A'', AB'', ABC'', and ABCD'' according to the initial value of each communication node stored in itself, and compares the received sequences. Assuming that the original C node in the network is replaced by an illegal C1 node, then the check node matches A' and A'', AB' and AB'', but ABC' and ABC'' are not consistent, which can locate the problem to the C node.
[0145] Once the abnormal communication node is determined, the check node can isolate it from the network to prevent it from continuing to affect other nodes or the overall performance of the network.
[0146] At the same time, the network administrator can receive a notification and take appropriate measures to handle the abnormal node, such as repairing the fault, updating the software or hardware, etc.
[0147] To improve processing efficiency, an automated processing mechanism can be introduced, such as automatically isolating abnormal nodes, automatically triggering repair scripts, etc. This will reduce the intervention of network administrators and speed up the recovery of abnormal nodes.
[0148] The check node should record the results of each check and the abnormal handling process for subsequent analysis and auditing. By analyzing the log records, the network administrator can identify potential problems in the network and take appropriate preventive measures.
[0149] The embodiment adds a warning mechanism and an exclusion check step when the check results are inconsistent based on the above-mentioned embodiments. This not only improves the security and stability of the network system, but also helps the network administrator to more accurately locate and handle the abnormal communication node, thereby reducing the risk of network interruption and service quality degradation caused by node failure.
[0150] According to embodiments of the present disclosure, the network node check method is applied to a local area network.
[0151] Figure 6A network architecture diagram to which a network node verification method according to an embodiment of the present disclosure is applied is schematically shown.
[0152] In some embodiments, as shown in Figure 6 Assuming that there are five nodes A, B, C, D and E in a local area network, E is a verification node, and the chaos initial value keys of A, B, C and D are fixed in the hardware system when the local area network is established, and the values cannot be read or modified, and the chaos initial value keys of A, B, C and D are fixed and stored in the E node.
[0153] In addition to the verification node, each node uses the initial value key to generate a string of 01 sequences through chaos mapping iteration at a fixed interval, and sends the generated chaos sequence in the order of A-B-C-D.
[0154] Assuming that the chaos sequence generated by the A node is A', after receiving A', the B node performs XOR operation on A' and the chaos sequence B' generated by itself to obtain a new sequence AB' and sends it to C, C sends the sequence ABC' obtained in the same way to D, and D obtains the sequence ABCD' through the same steps and finally sends it to the verification node E.
[0155] The verification node E generates four chaos sequences A'', B'', C'' and D'' at a local interval using the fixed initial value keys of the four nodes according to the same rules, and performs XOR operation on the sequences in the same order of A-B-C-D to obtain a verification sequence ABCD'', and after receiving the sequence ABCD', compares it with the verification sequence ABCD''.
[0156] If the comparison is consistent, it means that all the nodes in the local area network are legal nodes, and the communication in the local area network is secure. If the comparison is inconsistent, it means that there is an illegal node in the local area network, and the verification node E issues a warning to all members of the local area network, prompting that the current local area network is under attack.
[0157] During the entire authentication process, the security verification of each period is only completed by one verification node, and other nodes in the local area network only perform chaos mapping iteration and sequence XOR operation, which greatly improves the communication efficiency and saves resources.
[0158] At the same time, based on the initial value sensitive characteristics of chaos mapping, each node can ensure at least 10 30 key space, and the key space of the entire local area network is 10 30N N is the number of nodes in the local area network, and the key space increases geometrically with the increase of the number of nodes in the local area network, which can effectively prevent brute force cracking.
[0159] In addition, the initial value key of the chaotic mapping only needs a small amount of storage space, and there is no key management problem in the traditional symmetric encryption algorithm.
[0160] Based on the network node checking method described above, the present disclosure further provides a network node checking device. The following will be described in detail in combination with Figure 7 The network node checking device is described in detail.
[0161] Figure 7 The structure block diagram of the network node checking device according to the embodiment of the present disclosure is schematically shown.
[0162] As Figure 7 shown, the network node includes a checking node and a plurality of communication nodes, and the network node checking device 700 of the embodiment includes, for example, a first generation module 710, a second generation module 720, a comparison module 730 and a determination module 740.
[0163] The first generation module 710 is configured to generate a first random sequence in each communication node in a predetermined order based on a plurality of first initial value keys, and each first initial value key is stored in each communication node. In an embodiment, the first generation module 710 can be configured to perform the operation S210 described above, and details are not repeated here.
[0164] The second generation module 720 is configured to generate a second random sequence in the checking node in a predetermined order based on a plurality of second initial value keys, and the second initial value key is determined based on the first initial value key stored in the checking node. In an embodiment, the second generation module 720 can be configured to perform the operation S220 described above, and details are not repeated here.
[0165] The comparison module 730 is configured to compare the first random sequence with the second random sequence. In an embodiment, the comparison module 730 can be configured to perform the operation S230 described above, and details are not repeated here.
[0166] The determination module 740 is configured to determine that each communication node is checked through in the case that the first random sequence is consistent with the second random sequence. In an embodiment, the determination module 740 can be configured to perform the operation S240 described above, and details are not repeated here.
[0167] According to an embodiment of the present disclosure, any of the first generation module 710, the second generation module 720, the comparison module 730 and the determination module 740 can be combined in one module, or any of them can be split into multiple modules. Alternatively, at least part of the function of one or more of these modules can be combined with at least part of the function of the other modules, and implemented in one module. According to an embodiment of the present disclosure, at least one of the first generation module 710, the second generation module 720, the comparison module 730 and the determination module 740 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on board, a system on package, an application specific integrated circuit (ASIC), or any other reasonable way of integrating or packaging a circuit, etc. hardware or firmware, or any one of software, hardware and firmware or a suitable combination of any of them. Alternatively, at least one of the first generation module 710, the second generation module 720, the comparison module 730 and the determination module 740 can be at least partially implemented as a computer program module which can perform corresponding functions when executed.
[0168] According to an embodiment of the present disclosure, the first generation module 710 includes an acquisition sub-module, a mapping sub-module, a determination sub-module, a fusion sub-module and a traversal sub-module.
[0169] The acquisition sub-module is configured to acquire the initial value key in the first order node.
[0170] The mapping sub-module is configured to perform chaotic mapping according to the initial value key in the first order node to obtain a first binary sequence.
[0171] The determination sub-module is configured to determine a second binary sequence of the second order node.
[0172] The fusion sub-module is configured to perform XOR operation on the first binary sequence and the second binary sequence to obtain a fusion binary sequence.
[0173] The traversal sub-module is configured to repeatedly perform chaotic mapping and XOR operation for subsequent order nodes in sequence until all the plurality of communication nodes are traversed to obtain the first random sequence.
[0174] According to an embodiment of the present disclosure, the network node verification device 700 further includes an alarm module and an exclusion module.
[0175] The alarm module is configured to send a warning to each communication node in the case that the first random sequence and the second random sequence are inconsistent. And / or
[0176] The excluding module is configured to exclude each communication node respectively for determining an abnormal communication node in case that the first random sequence is inconsistent with the second random sequence.
[0177] Figure 8 A block diagram of an electronic device suitable for implementing the network node checking method according to an embodiment of the present disclosure is shown schematically.
[0178] As shown in Figure 8 The electronic device 800 according to an embodiment of the present disclosure includes a processor 801, which can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 802 or loaded into a random access memory (RAM) 803 from a storage section 808. The processor 801 can include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor, and / or a related chipset, and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), and / or the like. The processor 801 can also include an on-board memory for cache use. The processor 801 can include a single processing unit or multiple processing units for performing different actions of the method processes according to embodiments of the present disclosure.
[0179] In the RAM 803, various programs and data required for the operation of the electronic device 800 are stored. The processor 801, the ROM 802, and the RAM 803 are connected to each other through a bus 804. The processor 801 performs various operations of the method processes according to embodiments of the present disclosure by executing programs in the ROM 802 and / or the RAM 803. It should be noted that the programs can also be stored in one or more memories other than the ROM 802 and the RAM 803. The processor 801 can also perform various operations of the method processes according to embodiments of the present disclosure by executing programs stored in the one or more memories.
[0180] According to an embodiment of the present disclosure, the electronic device 800 can further include an input / output (I / O) interface 805 also connected to the bus 804. The electronic device 800 can further include one or more of the following components connected to the input / output (I / O) interface 805: an input part 806 including a keyboard, a mouse, etc.; an output part 807 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage part 808 including a hard disk, etc.; and a communication part 809 including a network interface card such as a LAN card, a modem, etc. The communication part 809 performs communication processing via a network such as the Internet. A driver 810 is also connected to the input / output (I / O) interface 805 as necessary. A removable medium 811 such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc. is mounted on the driver 810 as necessary, so that a computer program read out therefrom is installed in the storage part 808 as necessary.
[0181] The present disclosure also provides a computer readable storage medium, which can be included in the device / apparatus / system described in the above embodiments, or can exist separately without being assembled into the device / apparatus / system. The above computer readable storage medium carries one or more programs, which when executed, implement the network node verification method according to the embodiments of the present disclosure.
[0182] According to an embodiment of the present disclosure, the computer readable storage medium can be a non-volatile computer readable storage medium, which can include, but is not limited to, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any appropriate combination thereof. In the present disclosure, the computer readable storage medium can be any tangible medium that contains or stores a program that can be used by or in connection with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present disclosure, the computer readable storage medium can include one or more of the above-described ROM 802 and / or RAM 803 and / or a memory other than the ROM 802 and the RAM 803.
[0183] The embodiments of the present disclosure also include a computer program product, which includes a computer program containing program codes for executing the methods shown in the flowcharts. When the computer program product is run in a computer system, the program codes are used to make the computer system implement the network node verification method provided by the embodiments of the present disclosure.
[0184] The above-described functions of the system / apparatus defined in the embodiments of the present disclosure are performed when the computer program is executed by the processor 801. According to the embodiments of the present disclosure, the system, apparatus, module, unit, etc. described above can be implemented by the computer program modules.
[0185] In one embodiment, the computer program can be stored in a tangible storage medium, such as an optical, magnetic, or other memory on a server, computer, or other computing device. In another embodiment, the computer program can be transmitted over a network, including the Internet, WAN, LAN, or other network, including a wireless network, between a server and a client (e.g., using a web server or other server) or between two client devices (e.g., using a peer-to-peer network), using signal(s) in the form of packets, electronic signals, electrical, magnetic, optical, or other signals, and can be downloaded and installed by the communication portion 809 and / or installed from the removable medium 811. The program code contained in the computer program can be transmitted using any suitable network medium, including, but not limited to, wireless, wireline, optical, or any suitable combination of the above.
[0186] In such an embodiment, the computer program can be downloaded and installed from a network, using the communication portion 809 and / or installed from the removable medium 811. When the computer program is executed by the processor 801, the above-described functions of the system defined in the embodiments of the present disclosure are performed. According to the embodiments of the present disclosure, the system, apparatus, device, module, unit, etc. described above can be implemented by the computer program modules.
[0187] According to the embodiments of the present disclosure, the program code for execution of the computer program provided by the embodiments of the present disclosure can be written in any combination of one or more programming languages, and specifically, can be implemented using a high-level procedural and / or object-oriented programming language, and / or an assembly / machine language. The programming language includes, but is not limited to, such as Java, C++, python, “C” language, or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In the case involving a remote computing device, the remote computing device can be connected to the user computing device through any kind of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (e.g., using an Internet service provider to connect through the Internet).
[0188] The computer program product of the first aspect can include one or more non-transitory computer-readable media storing instructions that, when executed, cause one or more processors to perform the operations of the first aspect. The one or more non-transitory computer-readable media can include, for example, magnetic media such as one or more magnetic disks, magnetic tapes or cassettes; optical media such as one or more compact discs (CD), optical discs or discs (for example, DVD, Blu-ray Disc®, digital video disc, ultra density disc, ultra-compact disc, any optical media, etc.); semiconductor media such as solid state hard drives (for example, flash memory, solid state USB drives, etc.); any other suitable medium; or any suitable combination of media.
[0189] Those skilled in the art will understand that features recited in the various embodiments of the present disclosure can be combined and / or integrated in a variety of ways, even if such combinations or integrations are not expressly noted in the present disclosure. In particular, features recited in the various embodiments of the present disclosure can be combined and / or integrated in a variety of ways without departing from the spirit and teachings of the present disclosure. All such combinations and / or integrations are within the scope of the present disclosure.
[0190] The above describes embodiments of the present disclosure. However, these embodiments are merely for illustrative purposes, and are not intended to limit the scope of the present disclosure. Although each embodiment is described above separately, this does not mean that the measures in each embodiment cannot be used advantageously in combination. Those skilled in the art can make various substitutions and modifications without departing from the scope of the present disclosure, and these substitutions and modifications shall fall within the scope of the present disclosure.
Claims
1. A network node checking method, characterized by, The network node comprises a check node and a plurality of communication nodes, and the method comprises: obtaining a first initial value key in a first order node; performing chaotic mapping according to the first initial value key in the first order node to obtain a first binary sequence; determining a second binary sequence of a second order node; performing XOR operation on the first binary sequence and the second binary sequence to obtain a fusion binary sequence; repeating the chaotic mapping and the XOR operation for subsequent order nodes in turn until the plurality of communication nodes are traversed to obtain a first random sequence, wherein the plurality of communication nodes constitute a communication node sequence, and the check node only communicates with the last communication node in the communication node sequence to obtain the first random sequence; each first initial value key is stored in each communication node; based on a plurality of second initial value keys, a random sequence is generated in the check node according to a predetermined order to obtain a second random sequence, the second initial value key is determined based on the first initial value key stored in the check node; the check node uses the determined second initial value key as a seed; a pseudo-random number generator identical to the communication node is called to generate a second random sequence of the same length, and the chaotic mapping algorithm and parameters used by the check node to generate the second random sequence should be consistent with the algorithm and parameters used by the communication node to generate the first random sequence; in the check node, the first random sequence and the second random sequence are compared to realize the check of the plurality of communication nodes; in the case that the first random sequence and the second random sequence are consistent, it is determined that each communication node passes the check.
2. The method of claim 1, wherein, The algorithm corresponding to the chaotic mapping is at least one-dimensional algorithm, and the dimension of the algorithm represents the dimension of the state space of the dynamic system; when the algorithm is one-dimensional, the value of the system growth rate is between 3.5 and 4.
3. The method of claim 1, wherein, The communication node sequence is a plurality, each communication node sequence contains part of the plurality of communication nodes, and each communication node sequence is respectively provided with one check node.
4. The method of claim 1, wherein, The plurality of communication nodes are checked according to a preset fixed period; or determining the check period according to the size relationship between the network traffic and the preset traffic threshold; checking the plurality of communication nodes according to the check period; wherein the check period is negatively related to the network traffic.
5. The method of claim 1, wherein, The method further comprises: in the case that the first random sequence and the second random sequence are inconsistent, sending a warning to each communication node; and / or in the case that the first random sequence and the second random sequence are inconsistent, respectively excluding and checking each communication node to determine an abnormal communication node.
6. The method of claim 1, wherein, The method is applied to a local area network.
7. A network node checking apparatus, characterized by, The network node comprises a check node and a plurality of communication nodes, and the device comprises: The first generation module is configured to obtain a first initial value key in a first order node; perform chaotic mapping according to the first initial value key in the first order node to obtain a first binary sequence; determine a second binary sequence of a second order node; perform XOR operation on the first binary sequence and the second binary sequence to obtain a fusion binary sequence; and repeatedly perform chaotic mapping and XOR operation for subsequent order nodes until all the communication nodes are traversed to obtain a first random sequence, wherein the plurality of communication nodes form a communication node sequence, the check node only communicates with the last communication node in the communication node sequence to obtain the first random sequence, and each first initial value key is stored in each communication node. The second generation module is configured to generate a second random sequence in the check node based on a plurality of second initial value keys according to a predetermined order, wherein the second initial value keys are determined based on the first initial value key stored in the check node, the check node uses the determined second initial value key as a seed, and the check node uses the same pseudo-random number generator as the communication node to generate a second random sequence of the same length, and the chaotic mapping algorithm and parameters used by the check node to generate the second random sequence should be consistent with the algorithm and parameters used by the communication node to generate the first random sequence. The comparison module is configured to compare the first random sequence and the second random sequence in the check node to check the plurality of communication nodes. The determination module is configured to determine that each communication node passes the check when the first random sequence and the second random sequence are consistent. 8.An electronic device comprising: one or more processors; memory for storing one or more computer programs, characterized in that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1-6.
9. A computer readable storage medium having stored thereon a computer program or instructions, characterized in that, The computer program or instruction is executed by the processor to implement the steps of the method according to any one of claims 1-6.
10. A computer program product comprising computer programs or instructions, characterized in that, The computer program or instruction is executed by the processor to implement the steps of the method according to any one of claims 1-6.
Citation Information
Patent Citations
Quantum encryption communication method and corresponding communication system
CN114726515A
Secure communication method and system, storage medium and vehicle
CN116155579A