Cross-chain based adaptive identity revocation method and system

By introducing an adaptive identity revocation mechanism in a cross-chain system, combining smart contracts, heartbeat mechanisms and trusted hardware, the efficiency and security issues of identity revocation operations in a multi-chain environment are solved, and efficient and reliable identity management and transparent revocation process are achieved.

CN119766419BActive Publication Date: 2025-06-06NANJING UNIV OF INFORMATION SCI & TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510266455.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-07
Publication Date
2025-06-06
Estimated Expiration
2045-03-07

AI Technical Summary

Technical Problem

In a multi-chain environment, traditional identity revocation mechanisms are difficult to balance efficiency and security, especially in the case of network delay or malicious user interference, resulting in the revocation operation failing and affecting the trustworthiness and consistency of the system.

Method used

A cross-chain-based adaptive identity revocation system is adopted, which includes application chains, superchain, trusted hardware and automatic proxy nodes. Through smart contracts, users can identify and transmit cross-chain operations, use heartbeat mechanism and trusted hardware to achieve time synchronization and identity revocation operations, combining the dual strategies of self-revocation and automatic revocation.

Benefits of technology

It realizes the efficiency and reliability of identity management in a multi-chain environment, significantly reduces the risks caused by network delays or malicious nodes, ensures the security and consistency of identity revocation, and enhances the transparency and immutability of the system through transparent revocation trajectory records.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119766419B_ABST
    Figure CN119766419B_ABST
Patent Text Reader

Abstract

The present invention discloses a cross-chain-based adaptive identity revocation method and system, which belongs to the field of blockchain technology; the cross-chain-based adaptive identity revocation system includes: an application chain, a super chain, trusted hardware and an automatic proxy node; the application chain provides initiators and receivers for cross-chain transactions, and recognizes user cross-chain operations through smart contracts and transmits them to the automatic proxy node; the super chain regularly publishes revocation list information to the automatic proxy node through a heartbeat mechanism; the automatic proxy nodes are all equipped with the trusted hardware, which provides a trusted execution environment for the identity revocation mechanism, which is used to verify the heartbeat information and synchronize the time, and execute the identity revocation operation at the same time. The system is suitable for financial transactions, supply chain management and IoT identity authentication scenarios in multi-chain environments, and effectively improves the security, transparency and revocation efficiency of the cross-chain system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of blockchain, and in particular relates to a cross-chain based adaptive identity revocation method and system. Background Art

[0002] Blockchain technology is a decentralized distributed ledger technology that establishes trust between different entities in the blockchain network through cryptography, distributed networks, and consensus mechanisms. This feature enables each node in the blockchain to process transactions more transparently and reliably in a trusted network. At the same time, the encryption technology used in the blockchain can effectively ensure the tamper-proof nature of the data, thereby achieving the recording and tracking of suspicious transactions. Therefore, blockchain technology has received widespread attention and has been continuously developed in multiple application scenarios.

[0003] As blockchain application scenarios become increasingly complex, how to solve the data island problem between different blockchains and promote data circulation between different chains has become an urgent need of the industry. Cross-chain technology has emerged to connect homogeneous or heterogeneous blockchains and achieve interoperability between different chains. At present, the existing cross-chain solutions mainly include notarization solutions, hash locking, side chains, and relay chains. In particular, the cross-chain solution based on the relay chain has been widely used in multiple application scenarios due to its good scalability.

[0004] However, the traditional identity revocation mechanism is difficult to strike a balance between efficiency and security, especially in a multi-chain environment, where the identity revocation operation may be affected by network delays or interference from malicious users, causing the revocation operation to fail, thus affecting the credibility and consistency of the system. In the cross-chain scenario of blockchain, the effectiveness and timeliness of identity revocation are particularly critical.

[0005] At the same time, trusted hardware is a technology that provides an isolated execution environment at the hardware layer to ensure the security of sensitive data and critical operations. It ensures the confidentiality and integrity of data processing through an isolated environment independent of the operating system, and can effectively prevent malicious attacks even if the operating system or software layer is compromised. TEE has many advantages, including high security, hardware-level protection capabilities, and trusted execution verification functions, while providing efficient data processing performance. However, TEE also has certain limitations, such as strong dependence on specific hardware, compatibility issues between different industry standards, high costs, and scalability limitations in high-concurrency or large-scale scenarios. With its advantages, TEE can be widely used to solve problems such as data security and confidentiality, prevent malicious attacks, provide trusted operation verification, and resist physical attacks. It is particularly suitable for scenarios with extremely high security requirements such as financial transactions, identity authentication, and privacy protection.

[0006] Specifically, the design of identity revocation systems and methods in cross-chain scenarios faces many challenges, including but not limited to security, transparency, and revocation efficiency. For example, in terms of security and transparency, the automatic proxy node needs to ensure that it can correctly receive cross-chain data and record the revocation track on the relay chain. In addition, the identity authentication of the proxy node itself is also one of the factors that must be considered. On the other hand, due to the inherent latency problem of the blockchain network, how to use trusted hardware to ensure that identity certificates can be revoked in a timely manner is still a major challenge in the design of a cross-chain adaptive identity revocation mechanism. Summary of the invention

[0007] In view of the deficiencies in the prior art, the purpose of the present invention is to provide a cross-chain based adaptive identity revocation method and system to solve the problems in the prior art.

[0008] The purpose of the present invention can be achieved through the following technical solutions:

[0009] An adaptive identity revocation system based on cross-chain, including: application chain, super chain, trusted hardware and automatic proxy nodes;

[0010] The application chain provides initiators and receivers for cross-chain transactions, and recognizes user cross-chain operations through smart contracts and transmits them to the automatic proxy node; the super chain regularly publishes revocation list information to the automatic proxy node through the heartbeat mechanism; the automatic proxy nodes are all equipped with the trusted hardware to provide a trusted execution environment for the identity revocation mechanism, which is used to verify the heartbeat information and synchronize the time, and perform the identity revocation operation at the same time.

[0011] Furthermore, the revocation operation includes self-revocation and automatic revocation.

[0012] Furthermore, the application chain and super chain contain an identity authentication smart contract for application chain user identity registration.

[0013] The cross-chain based adaptive identity revocation method uses the above cross-chain based adaptive identity revocation system and includes the following steps:

[0014] When the application chain is newly added to the cross-chain system, some nodes of the application chain run the client of the hyperchain locally and become a node of the hyperchain. The identity authentication smart contract is called in the application chain, and the address in the application chain and the node public key registered in the hyperchain are input. Similarly, in the hyperchain, the identity authentication smart contract is called, and the address in the hyperchain and the node public key in the application chain are input. The smart contract returns the hash value of the automatic proxy node public key as the identity certificate to complete the identity registration;

[0015] The revocation agency regularly broadcasts heartbeat information on the hyperchain, automatically verifies and receives heartbeat information on the proxy node, forwards it to the trusted hardware, updates the timestamp, and achieves time synchronization. The heartbeat information contains the revocation list, timestamp, and time synchronization. hb and digital signatures;

[0016] The smart contract detects the improper behavior of the node, uploads the improper behavior information and the node identity to the revocation agency, and the revocation agency generates a revocation instruction and adds the revoked node identity certificate to the revocation list, broadcasts the heartbeat information and revocation instruction, and the automatic proxy node receives the heartbeat information and forwards it to the trusted hardware. The trusted hardware checks whether the identity has been revoked according to the revocation list. If it has been revoked, it will perform self-revocation. If the trusted hardware refuses to receive the heartbeat information due to network delay or malicious user refusal, the trusted hardware will perform automatic revocation due to long-term non-reception of HB.

[0017] Furthermore, the formula for implementing time synchronization by the trusted hardware is as follows:

[0018] now = max(now , t hb )

[0019] Among them, now is the current timestamp inside the trusted hardware, which is compared with the timestamp of the received heartbeat information t hb Compare and take the maximum value to update and synchronize the time.

[0020] Furthermore, the self-revocation process includes:

[0021] Set the time window T v When the revocation authority issues a revocation instruction, the timestamp of the heartbeat information is t rev ,After a maximum time window time, the automatic proxy node receives the revocation command and the heartbeat information;

[0022] The trusted hardware verifies the signature using the revocation authority public key, performs a revocation list check, performs self-revocation, and, at most, v The time processing is over and the undo operation is completed;

[0023] The judgment formula for the revocation list check is:

[0024]

[0025] in, It means that the identity certificate cannot be detected in PRL, that is, the detection result is an empty set. Cert represents the identity certificate and PRL represents the revocation list. If the formula is satisfied, it means that the identity has not been revoked. On the contrary, if the formula is not satisfied, it means that the identity has been revoked and the transaction request fails.

[0026] Furthermore, the automatic revocation process includes:

[0027] The automatic proxy node fails to receive the revocation instruction and heartbeat information sent by the revocation agency due to network delay, or maliciously fails to forward the information to the trusted hardware after receiving it, thus preventing the trusted hardware from executing self-revocation;

[0028] Since no new heartbeat information or other transaction information is received to synchronize the time, the timestamp is outdated and exceeds the time window T V , then the trusted hardware of the automatic proxy node without time synchronization will perform automatic revocation due to timeout and failure to update the timestamp;

[0029] When any information received by the trusted hardware is timestamped msg Satisfy: t msg >now+T V When the command is executed, it will also trigger automatic cancellation;

[0030] When the automatic proxy node receives any information, it will check the freshness of the information. If the timestamp t of the information does not satisfy: t≥now-T V When the information is outdated, the trusted hardware will automatically revoke the outdated information.

[0031] A computer storage medium stores a readable program, which can execute the above-mentioned cross-chain-based adaptive identity revocation method when the program is run.

[0032] An electronic device, comprising: a processor, a memory, a communication interface and a communication bus, wherein the processor, the memory and the communication interface communicate with each other through the communication bus;

[0033] The memory is used to store at least one executable instruction, and the executable instruction enables the processor to perform operations corresponding to the above-mentioned cross-chain-based adaptive identity revocation method.

[0034] A computer program product includes computer instructions, wherein the computer instructions instruct a computing device to perform operations corresponding to the above-mentioned cross-chain based adaptive identity revocation method.

[0035] Beneficial effects of the present invention:

[0036] 1. The present invention proposes a cross-chain-based adaptive identity revocation method, which combines trusted hardware, heartbeat mechanism and smart contracts to achieve high efficiency and reliability of identity management in a multi-chain environment. In particular, in complex cross-chain systems, the present invention can effectively handle the security and consistency issues of identity revocation while ensuring data integrity, significantly reducing the risks caused by network delays or malicious nodes. At the same time, the revocation track is recorded on the hyperchain to achieve transparency and non-tamperability of the revocation process.

[0037] 2. The present invention designs an automatic proxy node equipped with a trusted hardware solution, which effectively ensures that the timestamp is not maliciously tampered with, prevents the time from being disturbed, and realizes time synchronization.

[0038] 3. The heartbeat mechanism proposed in this invention ensures the timing consistency of all nodes in the system through time synchronization, effectively solving the identity revocation lag problem caused by time differences in the prior art. Through the dynamically updated revocation list (PRL), the system can detect and revoke invalid identities in a timely manner, improving the overall security and transparency of the cross-chain system.

[0039] 4. The present invention designs an adaptive revocation operation execution mechanism, combining the dual strategies of self-revocation and automatic revocation. Self-revocation achieves rapid response through real-time detection of node misbehavior by smart contracts, while automatic revocation is automatically triggered by not receiving heartbeat information for a long time, which enhances the fault tolerance and robustness of the system and further improves the reliability of identity revocation.

[0040] 5. The present invention has good scalability and applicability, and can be applied to a variety of blockchain-based scenarios, including financial transactions, supply chain management, Internet of Things identity authentication, etc. It provides a safe, efficient and reliable solution for cross-chain data interaction and identity management, which is of great significance to promoting the application of cross-chain technology. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0042] Figure 1 It is a schematic diagram of the framework of the basic cross-chain system of the present invention;

[0043] Figure 2 It is a schematic diagram of a specific cross-chain identity revocation scheme of the present invention;

[0044] Figure 3 It is a schematic diagram of chain registration of the present invention;

[0045] Figure 4 It is a schematic diagram of the automatic revocation timeline of the present invention. DETAILED DESCRIPTION

[0046] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0047] The following is an introduction to the relevant terms involved in the embodiments of the present application:

[0048] Blockchain is a distributed database that stores data in the form of blocks and uses cryptography to ensure the security and integrity of the data. Each block contains a certain number of transaction records, which are linked to the previous blocks to form an immutable chain.

[0049] Application Chain (AC) i ), is a participant in the cross-chain system. Users on the application chain play the role of senders and receivers of cross-chain operations in the system. For application chains that support smart contracts, each application chain has a cross-chain smart contract that interacts with users, which can identify user cross-chain operations and pass them to the automatic agent. For application chains that do not support smart contracts, they can only implement simple transfer functions with the help of automatic agent nodes.

[0050] Relay Chain, as a special blockchain architecture, acts as a bridge between different blockchain systems to achieve cross-chain communication and data exchange. Its main function is to coordinate and manage transactions and data flows between different blockchains. The relay chain listens to transaction requests and processing results on different blockchains through the gateway, and records cross-chain transactions in the block. It does not directly process data on the blockchain, but transmits cross-chain messages through consensus mechanisms and network protocols. The relay chain usually has high scalability and flexibility, can support interoperability between many different types of blockchain systems, and plays a core coordination role in the cross-chain system to ensure data consistency and integrity. In the scheme of the present invention, Superchain (SC) is the relay chain, and its main function is to store identity certificates and record users' cross-chain operations for supervision. When cross-chain operations are performed through the super chain, the super chain will verify both parties involved in the cross-chain operation.

[0051] Auto Agent, AG i), is a virtual user abstracted from each chain, playing the role of super chain node and application chain node in the cross-chain network. Each application chain can have multiple automatic agents, forming an automatic agent committee, which can repackage transactions in the application chain (super chain) into the data format of super chain (application chain) transactions, thereby realizing transaction transmission in the cross-chain system.

[0052] Smart contract is a computer protocol designed to communicate, verify or execute contracts in an information-based manner. Smart contracts allow for trusted transactions without a third party, which are traceable and irreversible. The concept of smart contracts was first proposed by Nick Szabo in 1994. The purpose of smart contracts is to provide a security method that is superior to traditional contracts and to reduce other transaction costs associated with contracts.

[0053] Trusted Execution Environment (TEE) is a secure computing environment designed to protect code and data from external attacks and unauthorized access. TEE ensures the confidentiality, integrity, and immutability of applications running and data processed in it by providing an isolated execution space. TEE is usually embedded in hardware and uses encryption technology and security protocols to verify the authenticity and credibility of the execution environment. It supports advanced security features such as secure boot, remote authentication, and fault recovery to prevent malware intrusion and data leakage. TEE plays a vital role in processing sensitive operations and storing critical data. It is widely used in financial services, identity authentication, secure communications and other fields, providing users with a reliable security guarantee.

[0054] Example 1

[0055] like Figure 1 As shown, the cross-chain-based adaptive identity revocation system includes: application chain, super chain, trusted hardware, and automatic proxy node;

[0056] The application chain is a participant in the cross-chain system. Users on the application chain play the role of senders and receivers of cross-chain operations in the system. The user's cross-chain operations are identified through smart contracts and passed to the automatic proxy node;

[0057] The hyperchain is the relay chain, which is used to store identity certificates and record the cross-chain operations of nodes for supervision. It detects improper behavior through smart contracts, and the revocation agency regularly publishes heartbeat information to achieve automatic proxy node time synchronization and identity revocation.

[0058] The automatic proxy node is a virtual user abstracted from each chain, playing the role of super chain node and application chain node in the cross-chain network; each application chain can have multiple automatic agents to form an automatic proxy committee, which can repackage transactions in the application chain / super chain into the data format of super chain / application chain transactions, thereby realizing transaction transmission in the cross-chain system.

[0059] The automatic proxy nodes are all equipped with trusted hardware to provide a trusted execution environment for the identity revocation mechanism to verify heartbeat information and synchronize time while performing identity revocation operations.

[0060] There are identity authentication smart contracts in the application chain and super chain to realize the identity registration of the application chain nodes in these two chains and become automatic proxy nodes.

[0061] The revocation operations include: self-revocation and automatic revocation.

[0062] Example 2

[0063] Based on the cross-chain adaptive identity revocation system mentioned in Example 1, in this embodiment, a cross-chain adaptive identity revocation method is proposed, such as Figure 2 As shown, the specific steps include:

[0064] Step 1: Identity Registration

[0065] like Figure 3 As shown, the green nodes belong to AC i , blue nodes belong to SC, AG i By an AC i Each AC node consists of a i There is a group of AG i , including AC i Therefore, AG i Can create AC i User u i and SC user u s Each automatic agent node has a transaction processing program AGRobot i , and AG i In AC i User u i Key pair <PKu i , SKu i > and user u in SC s Key pair <PKu s , SKu s > About AGRobot i are all visible.

[0066] In order to achieve AGi Access control and authentication, the system needs to perform the following additional processes to implement AC i Mutual authentication between SC:

[0067] SC deploys identity authentication contracts (ACIACs) to store each AG i In AC i User u i The public key PKu i , A.G. i A node can have only one user, whose behavior rules are specified by the code. i It is also necessary to deploy an identity authentication contract (ACIACi) in the application chain to store each AG i User u in SC s PKu of the public key s .

[0068] AGSCaddr j s Indicates AG i At the address of SC, each AG i Will call the parameter <AGSCaddr j s , PKu i >ACIAC to store SC in AG i Address and AC i China AG i The public key of AGSCaddr j i Indicates AG i In AC i The address in and call the parameters <AGACaddr j i , PKu s >ACIAC i To store AC i China AG i Address and SC in AG i The public key of

[0069] After the chain registration process of identity authentication, ACIAC i PKu is stored s and AGACaddr i , ACIAC s It stores PKu, AGSCaddr and the corresponding ChainID, returns the node identity certificate, and realizes the automatic agent registration in the hyperchain and application chain.

[0070] Step 2: Time Synchronization

[0071] The SC's Registration Authority (RA) node periodically sends a heartbeat message (HB). The HB structure is as follows:

[0072] HB = PRL || t hb || sig RA (PRL || t hb )

[0073] PRL stands for revocation list, which contains all revoked identity information. hb Indicates the heartbeat information timestamp, used for time synchronization, sig RA () is the digital signature using RA.

[0074] The automatic proxy node receives the HB broadcast by RA, and uses the RA's public key to verify the signature in the trusted hardware to compare the decrypted content with the content in HB to ensure the validity of the HB information.

[0075] After successfully verifying HB, TEE will synchronize its time as follows:

[0076] now = max(now , t hb )

[0077] Among them, now is the timestamp inside the trusted hardware of the automatic proxy node, and its timestamp will take the maximum value of the HB timestamp and the existing timestamp for time update and synchronization.

[0078] Step 3: Smart Contract Detection

[0079] Sending chain user u i Call AC i A cross-chain smart contract that generates i To AC j Cross-chain transaction tx i ,parameter <FromChainID, ToChainID, Options, Sigu i >, where FromChainID represents the sending chain, ToChainID represents the target chain, Options represents the cross-chain transaction options, including cross-chain transaction information, Sigu i Represents user u i Signature.

[0080] AC i Verify the user signature Sigu according to its own user identity management scheme. Then, broadcast the transaction tx i .

[0081] AG i Receive tx i After that, call the SC cross-chain smart contract to obtain the ToChianID certificate, with the following parameters: <FromChainID, ToChianID, Sig AGi >, where Sig AGi It is AG i Private key SK AGi The computed digital signature of this option.

[0082] SC verifies AG through smart contracts i identity certificate, and use PK AGi Verify the signature Sig AGi , verify the integrity and validity of the information.

[0083] If the smart contract detects improper behavior such as signature forgery or sending false, confusing or corrupted information, it will submit the improper behavior information to the RA of the SC. For example, if the reported ToChianID does not match the information transmitted, it indicates false information.

[0084] RA generates a revocation instruction based on the misconduct information detected by the smart contract, updates the PRL, and adds the revoked identity certificate to the PRL. The structure of the revocation instruction is:

[0085] OSR-REQ{|“revoke”||Ps(cert)||reason|}SK RA

[0086] Among them, revoke indicates the revocation instruction, Ps(cert) indicates the revoked certificate, reason indicates the revocation reason, SK RA Indicates RA's private key signature.

[0087] RA broadcasts the revocation instruction in SC.

[0088] Step 4: Undo the operation

[0089] (1) Self-revocation: voluntarily executing revocation;

[0090] Set the time window to T v After RA issues HB and cancels the order, after a maximum of T v Time, received by the automatic proxy node;

[0091] The automatic proxy node forwards the information to the trusted hardware, which verifies the information using the RA’s public key;

[0092] After the information is verified, the trusted hardware checks whether the identity certificate of its automatic proxy node exists in the revocation list according to the PRL of HB. The judgment formula for the revocation list check is:

[0093]

[0094] in, It means that the identity certificate cannot be detected in the PRL, that is, the detection result is an empty set. Cert represents the identity certificate. If the formula is satisfied, it means that the identity has not been revoked. On the contrary, if the formula is not satisfied, it means that the identity has been revoked and the transaction request fails.

[0095] Finally, at most T v When the time processing is over, the cancellation operation is completed. The implementation formula of self-cancellation is:

[0096]

[0097] Among them, self-revoke() means executing self-revoke.

[0098] (2) Automatic revocation: passive execution revocation;

[0099] When any information received (whether HB or transaction information) is timestamped msg When it is much greater than the current time, automatic cancellation will be triggered, as shown in the following formula:

[0100]

[0101] That is, the synchronization time exceeds T v Users who process any new information will be automatically revoked.

[0102] Furthermore, if the automatic proxy node refuses to receive information into the TEE, to avoid triggering self-revocation, the trusted hardware will detect that the synchronization time has not been updated for a long time and perform automatic revocation.

[0103] like Figure 4 As shown, due to the RA at t rev After deciding to revoke the node identity certificate, in order to avoid self-revocation, the node refuses to receive t rev Any subsequent information has a timestamp of t since the most recent HB time synchronization hb , then at the desynchronization time T v The node identity certificate is in t expd Automatically revoked.

[0104] On the other hand, when the automatic proxy node receives the cross-chain transaction message sent by the target chain, it verifies the message and checks its freshness to ensure that the timestamp t of the message is not less than its current time minus the time window T.v , as shown below:

[0105] t≥now-T V

[0106] If this formula is not satisfied, it means that the message is outdated and the trusted hardware will automatically revoke the outdated information.

[0107] like Figure 4 As shown in the figure, the timeline diagram shows the relationship between the time and information of automatic revocation of identity certificates. When estimating the worst-case revocation time, AG i The time t of the last HB reception hb Will broadcast decision to remove AG with RA i The time t at which the identity updates the PRL rev coincide.

[0108] Its specific implementation has the following characteristics:

[0109] Assuming the worst case, t rev With t hb coincidence, at time t rev RA broadcasts the revocation of AG i The decision on the identity certificate, at this time AG i Will give up rev All HB and information generated thereafter to prevent the trusted hardware from locking. The trusted hardware will only update its internal time when processing the above information, so t rev is the highest value currently stored as an internal value by the trusted hardware. Therefore, all transaction information signed by the trusted hardware is timestamped by t 1 ≤ t rev .

[0110] Target chain automatic proxy node AG j The information received should meet the following conditions:

[0111] now j ≤ t rev + T v

[0112] On the contrary, if the internal time of its trusted hardware is now j More than t rev + T v , then the trusted hardware will discard the AG i All transaction information issued by trusted hardware.

[0113] All honest nodes in the network are at most T behind the current time t of RA v , the timestamp range of all honest nodes is as follows:

[0114] t - T v ≤ now j ≤ t rev + T v

[0115] Among them, now j represents the current timestamp inside the node’s trusted hardware, t represents the RA’s current timestamp, and t rev The timestamp when RA broadcasts the decision to revoke the node identity certificate, T v Represents a time window.

[0116] Revocation time T eff as follows:

[0117] T eff = 2T v

[0118] This means that the maximum time from when the revocation order is issued to when the revocation actually takes effect is 2T v , that is, in the worst case, t rev After the cancellation order is issued, it will take at most T v time, HB will be broadcast to all automatic proxy nodes, and at most after T v Time, at t rcv The information has been revoked.

[0119] Based on similar inventive concepts, an embodiment of the present invention also provides a computer storage medium storing a readable program, which can execute the above-mentioned cross-chain-based adaptive identity revocation method when the program is running.

[0120] Based on similar inventive concepts, an embodiment of the present invention provides an electronic device, comprising: a processor, a memory, a communication interface and a communication bus, wherein the processor, the memory and the communication interface communicate with each other through the communication bus;

[0121] The memory is used to store at least one executable instruction, and the executable instruction enables the processor to perform operations corresponding to the above-mentioned cross-chain-based adaptive identity revocation method.

[0122] Based on similar inventive concepts, an embodiment of the present invention also provides a computer program product, including computer instructions, which instruct a computing device to perform operations corresponding to the above-mentioned cross-chain-based adaptive identity revocation method.

[0123] The method of the present invention may be implemented in hardware, firmware, or as software or computer code that may be stored in a recording medium (such as a CDROM, RAM, floppy disk, hard disk, or magneto-optical disk), or as computer code that is originally stored in a remote recording medium or a non-temporary machine-readable medium downloaded over a network and will be stored in a local recording medium, so that the method described herein may be stored in such software processing on a recording medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware (such as an ASIC or FPGA). It is understood that a computer, processor, microprocessor controller, or programmable hardware includes a storage component (e.g., RAM, ROM, flash memory, etc.) that can store or receive software or computer code, and when the software or computer code is accessed and executed by a computer, processor, or hardware, the method described herein is implemented. In addition, when a general-purpose computer accesses the code for implementing the method shown herein, the execution of the code converts the general-purpose computer into a dedicated computer for executing the method shown herein.

[0124] The above shows and describes the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments, and the above embodiments and descriptions are only for explaining the principles of the present invention. Without departing from the spirit and scope of the present invention, the present invention may have various changes and improvements, and these changes and improvements all fall within the scope of the present invention to be protected.

Claims

1. An adaptive identity revocation system based on cross-chain, characterized by: include: Application chains, super chains, trusted hardware, and automatic proxy nodes; The application chain provides initiators and receivers for cross-chain transactions, and recognizes user cross-chain operations through smart contracts and transmits them to the automatic proxy node; the hyperchain regularly publishes revocation list information to the automatic proxy node through the heartbeat mechanism; the automatic proxy nodes are all equipped with the trusted hardware to provide a trusted execution environment for the identity revocation mechanism, which is used to verify the heartbeat information and synchronize the time, and perform the identity revocation operation at the same time; When the application chain is newly added to the cross-chain system, some nodes of the application chain run the client of the hyperchain locally and become a node of the hyperchain. The identity authentication smart contract is called in the application chain, and the address in the application chain and the node public key registered in the hyperchain are input. Similarly, in the hyperchain, the identity authentication smart contract is called, and the address in the hyperchain and the node public key in the application chain are input. The smart contract returns the hash value of the automatic proxy node public key as the identity certificate to complete the identity registration; The revocation agency regularly broadcasts heartbeat information on the hyperchain, automatically verifies and receives heartbeat information on the proxy node, forwards it to the trusted hardware, updates the timestamp, and achieves time synchronization. The heartbeat information contains the revocation list, timestamp, and time synchronization. hb and digital signatures; The smart contract detects the improper behavior of the node, uploads the improper behavior information and node identity to the revocation agency, and the revocation agency generates a revocation instruction and adds the revoked node identity certificate to the revocation list, broadcasts the heartbeat information and revocation instruction, and the automatic proxy node receives the heartbeat information and forwards it to the trusted hardware. The trusted hardware checks whether the identity has been revoked according to the revocation list. If it has been revoked, it executes self-revocation; If the trusted hardware refuses to receive heartbeat information due to network delay or malicious user refusal, the trusted hardware will automatically revoke the execution due to long-term non-reception of heartbeat information.

2. The cross-chain adaptive identity revocation system according to claim 1 is characterized in that: The application chain and super chain contain identity authentication smart contracts for application chain user identity registration.

3. A cross-chain-based adaptive identity revocation method, using the cross-chain-based adaptive identity revocation system according to any one of claims 1-2, characterized in that: The following steps are involved: When the application chain is newly added to the cross-chain system, some nodes of the application chain run the client of the hyperchain locally and become a node of the hyperchain. The identity authentication smart contract is called in the application chain, and the address in the application chain and the node public key registered in the hyperchain are input. Similarly, in the hyperchain, the identity authentication smart contract is called, and the address in the hyperchain and the node public key in the application chain are input. The smart contract returns the hash value of the automatic proxy node public key as the identity certificate to complete the identity registration; The revocation agency regularly broadcasts heartbeat information on the hyperchain, automatically verifies and receives heartbeat information on the proxy node, forwards it to the trusted hardware, updates the timestamp, and achieves time synchronization. The heartbeat information contains the revocation list, timestamp, and time synchronization. hb and digital signatures; The smart contract detects the improper behavior of the node, uploads the improper behavior information and node identity to the revocation agency, and the revocation agency generates a revocation instruction and adds the revoked node identity certificate to the revocation list, broadcasts the heartbeat information and revocation instruction, and the automatic proxy node receives the heartbeat information and forwards it to the trusted hardware. The trusted hardware checks whether the identity has been revoked according to the revocation list. If it has been revoked, it executes self-revocation; If the trusted hardware refuses to receive heartbeat information due to network delay or malicious user refusal, the trusted hardware will automatically revoke the execution due to long-term non-reception of heartbeat information.

4. The cross-chain adaptive identity revocation method according to claim 3 is characterized in that: The formula for implementing time synchronization with the trusted hardware is as follows: now= max(now , t hb ) Among them, now is the current timestamp inside the trusted hardware, which is compared with the timestamp of the received heartbeat information t hb Compare and take the maximum value to update and synchronize the time.

5. The cross-chain adaptive identity revocation method according to claim 4 is characterized in that: The self-revocation process includes: Set the time window T v When the revocation authority issues a revocation instruction, the timestamp of the heartbeat information is t rev ,After a maximum time window time, the automatic proxy node receives the revocation command and the heartbeat information; The trusted hardware verifies the signature using the revocation authority public key, performs a revocation list check, performs self-revocation, and, at most, v The time processing is over and the undo operation is completed; The judgment formula for the revocation list check is: in, It means that the identity certificate cannot be detected in PRL, that is, the detection result is an empty set. Cert represents the identity certificate and PRL represents the revocation list. If the formula is satisfied, it means that the identity has not been revoked. On the contrary, if the formula is not satisfied, it means that the identity has been revoked and the transaction request fails.

6. The cross-chain adaptive identity revocation method according to claim 5 is characterized in that: The automatic revocation process includes: The automatic proxy node fails to receive the revocation instruction and heartbeat information sent by the revocation agency due to network delay, or maliciously fails to forward the information to the trusted hardware after receiving it, thus preventing the trusted hardware from executing self-revocation; Since no new heartbeat information or other transaction information is received to synchronize the time, the timestamp is outdated and exceeds the time window T V , then the trusted hardware of the automatic proxy node without time synchronization will perform automatic revocation due to timeout and failure to update the timestamp; When any information received by the trusted hardware is timestamped msg Satisfy: t msg >now+T V When the command is executed, it will also trigger automatic cancellation; When the automatic proxy node receives any information, it will check the freshness of the information. If the timestamp t of the information does not satisfy: t≥now-T V When the information is outdated, the trusted hardware will automatically revoke the outdated information.

7. A computer storage medium storing a readable program, characterized in that: When the program is executed by the processor, the cross-chain based adaptive identity revocation method described in any one of claims 3 to 6 can be executed.

8. An electronic device, characterized in that: include: A processor, a memory, a communication interface and a communication bus, wherein the processor, the memory and the communication interface communicate with each other via the communication bus; The memory is used to store at least one executable instruction, and the executable instruction enables the processor to perform operations corresponding to the cross-chain based adaptive identity revocation method as described in any one of claims 3-6.

9. A computer program product comprising computer instructions, characterized in that The computer instructions instruct the computing device to perform operations corresponding to the cross-chain based adaptive identity revocation method as described in any one of claims 3-6.

Citation Information

Patent Citations

  • Decentralization identity verification method based on password accumulator

    CN119519988A

  • Web3 Decentralized Blockchain Based NFT Framework... Applications

    US20240185191A1