Computing Power Access Method, Computer Device, Storage Medium, and Program Product

Through the method of identity registration and computing service credential creation in the computing power service alliance chain, the problem of low authenticity of computing power nodes is solved, and higher security and reliability are achieved.

CN119788417BActive Publication Date: 2025-06-27INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510260309.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-06-27
Estimated Expiration
2045-03-06

AI Technical Summary

Technical Problem

In the prior art, the authenticity of computing power nodes is not high, and it is difficult to ensure the authenticity and reliability of computing power resources.

Method used

By deploying computing power service authentication nodes in the computing power service alliance chain, two-factor verification is carried out to ensure the authenticity of the identity information of the node to be accessed and computing power service credential information.

Benefits of technology

It improves the security of computing power access, ensures the authenticity and reliability of computing power resources, and protects the privacy data of computing power nodes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119788417B_ABST
    Figure CN119788417B_ABST
Patent Text Reader

Abstract

The present application discloses a computing power access method, a computer device, a storage medium, and a program product, which relate to the technical field of blockchain. It includes verifying an identity registration request, generating an identity document and identity information, detecting the actual computing power of a node to be accessed, and thus issuing a computing power service certificate and computing power service certificate information. When the node to be accessed sends a computing power access request, the consortium blockchain node respectively performs identity verification and certificate verification based on the identity information and computing power service certificate information in the computing power access request to determine the computing power access result of the node to be accessed. This method uses the form of a consortium blockchain for computing power access, and performs identity registration, computing power service certificate creation, and computing power access throughout the process of computing power access. During the computing power access verification, double verification is performed on the identity information and computing power service certificate information to avoid the situation of untrue computing power service information and forged certificates of the node to be accessed, and improve the security of computing power access.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of blockchain technology, and in particular, to a computing power access method, a computer device, a storage medium, and a program product. Background Art

[0002] With the continuous improvement of the capabilities of computing infrastructure such as network communication devices, cloud computing, and edge computing, the generalization of computing power has become a trend. In practical applications, due to the uneven distribution of different computing requirements in time and space, the computing power resources of some institutions or enterprises may be idle during certain periods, resulting in waste of computing power and power resources. Through computing power access, computing power resources with different architectures and performances can be connected, the computing power services scattered in different geographical locations can be integrated, and computing power service access can be provided, so that the computing power resources can be effectively utilized.

[0003] In related technologies, external programs are usually relied on for computing power access or computing power access is based on a distributed network to achieve the interconnection and sharing of computing power resources. However, the accessed computing power information may be untrue or there may be false data, resulting in difficulty in evaluating the actual capabilities of computing power nodes and inability to ensure the authenticity and reliability of computing power. Summary of the Invention

[0004] The present application provides a computing power access method, a computer device, a storage medium, and a program product to at least solve the problem of low authenticity of computing power nodes in related technologies.

[0005] The present application provides a computing power access method applied to a computing power service authentication node deployed on a computing power service alliance chain, including:

[0006] Verifying a node to be accessed based on an identity registration request of the node to be accessed to generate an identity document of the node to be accessed and corresponding identity information, where the identity information includes at least a decentralized identity identifier;

[0007] Detecting the actual computing power of the node to be accessed based on a credential creation application of the node to be accessed, and issuing a computing power service credential and corresponding computing power service credential information according to the actual computing power, where the computing power service credential information includes at least a credential identifier; the computing power service credential and the identity document of the node to be accessed are stored in the computing power service alliance chain;

[0008] When the node to be accessed sends a computing power access request, the alliance chain node performs identity verification and credential verification respectively based on the identity information and the computing power service credential information in the computing power access request to determine the computing power access result of the node to be accessed.

[0009] The present application provides a computing power access method applied to a node to be accessed, including:

[0010] Send an identity registration request to the computing power service authentication node and receive the identity information sent by the computing power service authentication node;

[0011] Obtain the computing power service credential template and initiate a credential creation application based on the computing power service credential template to obtain the computing power service credential information. The computing power service credential information is generated after the computing power service authentication node verifies the credential creation application submitted by the node to be connected. The computing power service credential information corresponds to the computing power service credential, and the computing power service credential is used to represent that the actual computing power of the node to be connected is consistent with the computing power declared in the credential creation application;

[0012] After obtaining the computing power service credential information, send a computing power access request and receive the computing power access result. The computing power access result is used to represent whether the node to be connected accesses the computing power service alliance chain. The computing power access request includes at least the identity information and the computing power service credential information of the node to be connected, and the computing power access result is determined after the alliance chain node verifies the identity information and the computing power service credential information of the node to be connected.

[0013] This application also provides a computer device, including: a memory for storing a computer program; a processor for implementing the steps of any of the above computing power access methods when executing the computer program.

[0014] This application also provides a computer-readable storage medium, in which a computer program is stored. The computer program, when executed by a processor, implements the steps of any of the above computing power access methods.

[0015] This application also provides a computer program product, including a computer program that implements the steps of any of the above computing power access methods when executed by a processor.

[0016] This method uses the form of an alliance chain for computing power access, and performs identity registration, computing power service credential creation, and computing power access throughout the computing power access process. During computing power access verification, double verification of identity information and computing power service credential information is performed to avoid the situation of untrue computing power service information and forged credentials of the node to be connected, and improve the security of computing power access. And the semi-public nature of the alliance chain is more suitable for protecting the privacy data of computing power nodes. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] To more clearly illustrate the embodiments of the present application, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0018] Figure 1Flowchart of a computing power access method provided by an embodiment of the present application;

[0019] Figure 2 Flowchart of a computing power access method provided by an embodiment of the present application;

[0020] Figure 3 Schematic diagram of the architecture of a computing power access system provided by an embodiment of the present application;

[0021] Figure 4 Schematic diagram of the computing power access process provided by an embodiment of the present application;

[0022] Figure 5 Schematic diagram of a computer device provided by an embodiment of the present application. Detailed implementation manners

[0023] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the protection scope of the present application.

[0024] It should be noted that in the description of the present application, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present application are used to distinguish similar objects and not to describe a specific order or sequence.

[0025] In order to enable those skilled in the art of the present technology to better understand the solution of the present application, the present application will be further described in detail below in conjunction with the accompanying drawings and specific implementation manners.

[0026] In combination with the specific application environment architecture or specific hardware architecture on which the execution of the computing power access method depends, the specific application environment architecture or specific hardware architecture will be described herein.

[0027] With the continuous improvement of the capabilities of computing infrastructures such as network communication, cloud computing, and edge computing, the generalization of computing power has now become a trend. In order to more efficiently utilize the ubiquitous computing power resources, the industry has proposed the concepts of computing power network and computing power grid connection. As a new type of computing infrastructure that integrates cloud computing, edge computing, terminals, and various network resources, the core of the computing power network lies in providing users with an overall computing power service that includes computing, storage, and network connection. This service not only has a high degree of flexibility and can provide schedulable on-demand computing services according to business characteristics, but also greatly improves the utilization rate and response speed of computing resources. Through the computing power network, users can obtain the required computing power resources anytime and anywhere according to actual needs, thus meeting the requirements of various complex application scenarios.

[0028] In the actual application environment, the distribution of computing requirements in time and space shows uneven characteristics, resulting in some organizations or enterprises having underutilized computing power resources during specific periods, which in turn leads to significant waste of resources such as computing power and electricity. By means of an access system designed for computing power grid connection, the interconnection and interoperability of various computing power resources with different architectures and performances (such as supercomputers, server clusters, edge computing facilities, etc.) can be realized. In addition, the system can also uniformly integrate computing power services that are widely distributed and located in different geographical locations, provide users with convenient "one-stop" computing power access services, and support a processing flow for dynamically adjusting computing power allocation according to requirements, thereby significantly improving the utilization efficiency of computing power resources. In related technologies, plug-ins are usually used to assist in computing power access. Since such methods rely on plug-ins to implement, if there are security vulnerabilities in the plug-in programs, it will bring certain security risks, and corresponding plug-ins need to be designed for different types of computing power, resulting in high development costs and a lack of security. Based on this, the embodiments of the present invention provide a computing power access method.

[0029] The application scenario of the embodiment provided by the present invention is described below. The computing power access method provided in this embodiment is used in a scenario where there are nodes to be connected that need to join a computing power service consortium chain. The computing power service consortium chain is composed of a group of already connected computing power nodes. Each node deploys the basic functions of the consortium chain to achieve interconnection and interoperability with other nodes, and at the same time stores and maintains a ledger. The ledger is the data on the chain, and the data stored in the ledger includes user identity documents, computing power service templates, computing power service vouchers, computing power registration information, and the on-chain smart contract program code corresponding to the above data.

[0030] When a user registers a DID (Decentralized Identity) digital identity, a pair of asymmetric keys is created locally. The private key is kept by the user himself, and the public key is submitted to the computing power service authentication node to generate the DID identifier and its identity document. The identity document contains information such as the user's public key, DID identifier, the DID protocol used, the service request address of the DID, timestamp, digital signature, etc.

[0031] The computing power service credential template is a type of credential template that defines the data fields included in the credential claim and the data types of each field, and declares which fields are required. It is customized by the computing power service authenticated user and submitted through the computing power service authentication node. Each computing power service credential template is uniquely identified by a credential template ID. It can define how the computing power service is provided and what computing capabilities and performance are provided. For example, if it is provided in the form of a virtual machine, it will include the operating system (such as Windows, Linux, etc.), basic software tools and application programming interfaces, network protocols (such as TCP / IP), number of CPU cores and main frequency, disk capacity and disk I / O performance, memory size, network bandwidth, and so on.

[0032] The computing power service credential is a verifiable digital credential (VC), which is usually a descriptive statement issued by an authoritative entity to endorse certain attributes of another entity, with its own digital signature attached. The computing power service credential contains information such as the issuer's DID, issuance time, expiration date, credential template ID, credential ID, claim data, the issuer's digital signature, etc. Among them, the claim data contains the computing power service capability data (provided according to the requirements of the credential template).

[0033] The computing power registration information is information used to represent what computing power service capabilities a computing power node has, including information such as the DID identity of the computing power node, the list of computing power service credential IDs, and the status of each computing power service. That is, the computing power registration information associates the computing power node with the computing power service credential. The computing power registration information of a node can be updated, and when reading, the latest data will be obtained.

[0034] The smart contract program is deployed on the consortium blockchain and provides an interactive interface for external entities (such as application programs or users) to operate on-chain data. The smart contract program code (compiled and deployed code) itself is also on-chain data. It includes smart contracts for uploading identity documents to the chain, smart contracts for uploading credential templates to the chain, smart contracts for uploading credentials to the chain, smart contracts for uploading computing power registration information to the chain, etc.

[0035] The smart contract for uploading identity documents to the chain: Implements the contract program related to uploading identity documents to the chain and provides an interface for applications outside the consortium blockchain to read and write on-chain identity document data.

[0036] Credential Template On-chain Smart Contract: Implements the contract procedures related to the on-chain of credential templates, and provides interfaces for off-chain applications to read and write on-chain credential template data.

[0037] Credential On-chain Smart Contract: Implements the contract procedures related to the on-chain of computing power service credentials, and provides interfaces for off-chain applications to read and write on-chain computing power service credential data.

[0038] Computing Power Registration Information On-chain Smart Contract: Implements the contract procedures related to the on-chain of computing power registration information, and provides interfaces for off-chain applications to read and write on-chain computing power registration information.

[0039] According to an embodiment of the present invention, an embodiment of a computing power access method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And, although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0040] In this embodiment, a computing power access method is provided, which is applied to a computing power service authentication node. The computing power service authentication node is deployed on a computing power service consortium chain and can be used for terminals such as computing devices and servers. As Figure 1 shown, the method includes the following steps:

[0041] Step S101, verify the node to be accessed based on the identity registration request of the node to be accessed, so as to generate an identity document of the node to be accessed and the corresponding identity information.

[0042] Among them, the identity information includes at least a decentralized identity identifier. A computing power service authentication node is an authoritative institution node, which can provide identity registration and computing power service capability authentication for computing power nodes. When a group of computing devices access the computing power service consortium chain, it is necessary to create an access node, and use this node as the representative of the local computing device network to register its computing power service capabilities with the computing power service consortium chain. When the node to be accessed needs to access the computing power service consortium chain, it first needs to perform identity registration and send an identity registration request to the computing power service authentication node.

[0043] The identity registration request may carry encrypted data or identifiers, and the computing power service authentication node verifies the encrypted data or identifiers to confirm whether the node to be accessed meets the requirements of identity registration. If the node to be accessed meets the requirements of identity registration, the computing power service authentication node creates an identity document of the node to be accessed and the identity information corresponding to the identity document. The identity information includes a decentralized identity identifier, and the decentralized identity identifier is an identifier used to uniquely represent the node to be accessed. The identity document contains information such as the identity information of the node to be accessed, the protocol used, the service request address, the timestamp, and the digital signature.

[0044] The computing power service authentication node sends the identity information to the node to be connected and writes the identity document into the computing power service alliance chain. After receiving the identity information, the node to be connected completes the identity registration.

[0045] As an example, after receiving an identity registration request, the computing power service authentication node performs DID identity verification, creates a DID identifier and a DID identity document corresponding to the node to be connected, where the identity information includes the DID identifier. The computing power service authentication node sends the identity information to the node to be connected and writes the corresponding identity document into the alliance chain through the smart contract interface of the alliance chain.

[0046] Step S102: Create an application based on the credentials of the node to be connected, and detect the actual computing power of the node to be connected, so as to issue a computing power service credential and the corresponding computing power service credential information according to the actual computing power.

[0047] Among them, the computing power service credential information at least includes a credential identifier. The computing power service credential and the identity document of the node to be connected are stored in the computing power service alliance chain.

[0048] When issuing a credential creation application, an available computing power service credential template can be applied for. The available computing power service credential template represents the created computing power service credential template. The structure and content of the computing power service credential are defined in the computing power service credential template, and corresponding computing power service credential templates can be adopted for different types of node types. After the node to be connected completes the identity registration, it requests the computing power service authentication node to obtain an available computing power service credential template, and the computing power service authentication node will send the available computing power service credential template to the node to be connected. After receiving the available computing power service credential template, the node to be connected can select a matching computing power service credential template according to the computing power service type and characteristics of the local computing device. The node to be connected initiates a credential creation application using the corresponding computing power service credential template, and the credential creation application includes a declaration of its computing power service capabilities (such as virtual machines and their specifications).

[0049] After receiving the credential creation application, the computing power service authentication node will conduct further verification. If the verification passes, it will issue a computing power service credential and return the computing power service credential information to the node to be connected. The computing power service credential can prove that the actual computing power of the node to be connected is consistent with the computing power capabilities declared in the credential creation application. The credential identifier in the computing power service credential information is the identifier corresponding to the computing power service credential. After creating the computing power service credential and the computing power service credential information, the computing power service authentication node stores the computing power service credential on the chain through the smart contract interface of the alliance chain and returns the computing power service credential information to the node to be connected.

[0050] After the node to be connected accesses the alliance chain, the computing power service authentication node can regularly detect the actual computing power of each computing power node in the alliance chain to ensure the real-time performance and authenticity of the computing power nodes.

[0051] If the verification fails, a corresponding prompt is returned to the node to be connected. The node to be connected can perform the creation process of multiple computing power service vouchers.

[0052] Step S103: When the node to be connected sends a computing power access request, the consortium blockchain node performs identity verification and voucher verification based on the identity information and computing power service voucher information in the computing power access request respectively to determine the computing power access result of the node to be connected.

[0053] After obtaining the computing power service voucher information, the node to be connected can send a computing power access request to the consortium blockchain node through a specified interface. The parameters in the computing power access request can include the identity information of the node to be connected, the computing power service voucher information, etc. After receiving the computing power access request, the consortium blockchain node first verifies the identity information. After the verification passes, it then verifies the computing power service voucher information. The verification can be combined with the identity information, the computing power service voucher information, and the data stored on the consortium blockchain. In the verification process, as long as there is a situation where the verification fails, an error prompt message will be returned to the node to be connected.

[0054] As an example, after receiving the computing power access request, first read the identity document of the access node from the chain (i.e., the ledger), and then perform identity verification on the node to be connected (the verification process is exemplified as follows: encrypt a random number with the public key in the identity document, send the ciphertext to the node to be connected, and let the node to be connected decrypt it with the private key and return the plaintext for comparison and verification). When the identity verification fails, a verification failure prompt will be returned and the process ends. When the identity verification passes, the consortium blockchain node will read each computing power service voucher according to the computing power service voucher information and verify the voucher (for example: verify whether the issuer is in the white list of the computing power service authentication node, and verify the digital signature of the voucher with the public key of the issuer, etc.). When the voucher verification passes, the voucher ID and its initial status (such as idle) are added to a list. Otherwise, a voucher verification failure prompt is returned to the node to be connected (here it can be set according to requirements to allow some vouchers in the computing power service voucher ID list to pass the verification and some to fail. After all vouchers are verified, a prompt message is uniformly returned to the node to be connected; it can also be set according to requirements to directly return an error prompt and end the process once it is found that the voucher verification fails). After all vouchers are verified, the DID of the node to be connected and the list of verified vouchers are stored on the chain as computing power registration information, and the computing power access result is returned. If the verification is successful, the computing power access result is a computing power registration success prompt message.

[0055] The computing power access result also includes the computing power service information of the node to be connected written on the consortium blockchain (for example: computing power service voucher information).

[0056] Before sending a computing power access request, the node to be connected can also request the information required for computing power registration from the consortium blockchain node. After obtaining the required information, it sends a computing power access request, which contains the information required for computing power registration.

[0057] Optionally, the computing power service authentication node is allowed to update the template regularly or on demand. The new template may include more stringent verification rules, newly added computing power service types, or improved data structures. The node to be connected can subscribe to a specific computing power service credential template. When the template is updated, the computing power service authentication node notifies the node to be connected through the message queue to ensure that they always use the latest template.

[0058] The computing power access method provided in this embodiment includes verifying the node to be connected based on its identity registration request to generate an identity document and corresponding identity information for the node to be connected, detecting the actual computing power of the node to be connected based on its credential creation application, and issuing a computing power service credential and corresponding computing power service credential information according to the actual computing power. When the node to be connected sends a computing power access request, the consortium blockchain node performs identity verification and credential verification respectively based on the identity information and computing power service credential information in the computing power access request to determine the computing power access result of the node to be connected. This method uses the form of a consortium blockchain for computing power access, and performs identity registration, computing power service credential creation, and computing power access throughout the process of computing power access. Double verification is performed on the identity information and computing power service credential information during computing power access verification to avoid the situation of untrue computing power service information and forged credentials of the node to be connected, and improve the security of computing power access. Moreover, the semi-public nature of the consortium blockchain is more suitable for protecting the privacy data of computing power nodes.

[0059] In this embodiment, a computing power access method is provided, and the method includes the following steps:

[0060] Step S201, verifying the node to be connected based on its identity registration request to generate an identity document and corresponding identity information for the node to be connected.

[0061] Specifically, step S201 includes:

[0062] Step S2011, determining whether the identity registration request contains public key information.

[0063] After receiving the identity registration request, the computing power service authentication node first checks whether it contains public key information. When the node to be connected performs identity registration, it creates a pair of asymmetric keys locally at the node and carries the public key information in the sent identity registration request.

[0064] Step S2012, if the identity registration request contains public key information, generate an identity document and corresponding identity information for the node to be connected.

[0065] If it is detected that the identity registration request contains public key information, an identity document and identity information are created according to the decentralized creation specification, and the identity information includes a decentralized identity identifier.

[0066] Step S2013: Send the identity information to the node to be connected, and write the identity document of the node to be connected into the computing power service alliance chain.

[0067] Send the identity information to the node to be connected, and write the identity document into the computing power service alliance chain through the smart contract interface of the alliance chain.

[0068] Step S202: Create an application based on the credentials of the node to be connected, detect the actual computing power of the node to be connected, and issue a computing power service credential and corresponding computing power service credential information according to the actual computing power.

[0069] Specifically, step S202 includes:

[0070] Step S2021: Detect the actual computing power data of the node to be connected, and extract the declared computing power data of the node to be connected from the credential creation application of the node to be connected.

[0071] After receiving the credential creation application, the computing power service authentication node calls the computing power resource detection and verification module to detect the node to be connected. Specifically, it can detect and verify the computing power service capabilities declared by the node to be connected, including actual running test tasks, checking resource allocation, verifying performance parameters, etc. After detection, the actual computing power data of the node to be connected is obtained. Extract the declared computing power data of the node to be connected from the credential creation application of the node to be connected.

[0072] Step S2022: Compare the actual computing power data with the declared computing power data.

[0073] Compare the actual computing power data with the declared computing power data.

[0074] Step S2023: If the actual computing power data is consistent with the declared computing power data, issue a computing power service credential and corresponding computing power service credential information.

[0075] If the actual computing power data is consistent with the declared computing power data, it indicates that the performance parameters of the node to be connected meet (reach or exceed) the specification requirements or performance parameter indicators described in the service credential, and then issue a computing power service credential.

[0076] Step S2024: Send the computing power service credential information to the node to be connected, and write the computing power service credential into the computing power service alliance chain.

[0077] The computing power service certificate has a corresponding certificate identifier, and the computing power service certificate information includes at least the certificate identifier of the computing power service certificate of the node to be connected. Write the computing power service certificate into the computing power service alliance chain, and send the computing power service certificate information to the node to be connected.

[0078] In some alternative embodiments, the method further includes: sending identity information to the node to be connected, and receiving a template request sent by the node to be connected; sending a computing power service certificate template to the node to be connected based on the template request. Wherein, the node to be connected sends a certificate creation application based on the computing power service certificate template.

[0079] The template request is used to indicate a request to obtain an available computing power service certificate template.

[0080] After the node to be connected completes identity registration, it sends a template request to the computing power service authentication node to request an available computing power service certificate template. The available computing power service certificate template refers to a computing power service certificate template that has been created and stored in the alliance chain. The computing power service authentication node sends the available computing power service certificate template to the node to be connected. There may be one or more available computing power service certificate templates. If there are multiple templates, the node to be connected can select a matching certificate template according to the type of local computing power service. The node to be connected uses the computing power service certificate template to initiate a computing power service certificate creation application to the computing power service authentication node, and the certificate creation application includes a declaration of its available computing power service capabilities (such as virtual machines and their specifications).

[0081] Step S203: When the node to be connected sends a computing power access request, the alliance chain node performs identity verification and certificate verification based on the identity information and computing power service certificate information in the computing power access request respectively to determine the computing power access result of the node to be connected.

[0082] Specifically, step S203 includes:

[0083] Step S2031: The alliance chain node reads the identity document of the node to be connected from the computing power service alliance chain based on the identity information, and performs identity verification on the node to be connected based on the identity document.

[0084] After obtaining the computing power service certificate information, the node to be connected can send a computing power access request to the alliance chain node through a specified interface. The parameters in the computing power access request may include the identity information, computing power service certificate information, etc. of the node to be connected.

[0085] After receiving the computing power access request, the alliance chain node first verifies the identity information, and after the verification passes, it verifies the computing power service certificate information. The verification can be combined with the identity information, computing power service certificate information, and data stored on the alliance chain. In the verification process, as long as there is a situation where the verification fails, an error prompt message will be returned to the node to be connected.

[0086] First, based on the identity information, the corresponding identity document is searched and read from the alliance chain, and identity authentication is performed according to the identity document.

[0087] Furthermore, identity authentication of the node to be accessed based on the identity document includes: the alliance chain node obtains the public key information in the identity document to encrypt the random number to obtain the ciphertext; the alliance chain node sends the ciphertext to the node to be accessed, and receives the plaintext after the node to be accessed decrypts the ciphertext based on the private key; the alliance chain node verifies the node to be accessed based on the comparison result of the plaintext and the random number; if the plaintext is consistent with the random number, the identity authentication of the node to be accessed is passed.

[0088] A random number is encrypted using the public key stored in the identity document to generate a ciphertext, which is then sent to the node to be connected. After receiving the ciphertext, the node to be connected uses the private key to decrypt it, thereby recovering the original random number, i.e., the plaintext. Then, the node to be connected returns this plaintext to the computing service authentication node. After receiving the returned plaintext, the alliance chain node compares it with the random number it originally generated. If the two are consistent, it indicates that the node to be connected does have a private key that matches the public key in the identity document, thereby verifying the authenticity of its identity.

[0089] This method utilizes the asymmetric nature of public key encryption, that is, the public key is used for encryption and the private key is used for decryption, and only the holder of the private key can decrypt the information encrypted by the corresponding public key, providing an effective identity authentication mechanism.

[0090] If the identity authentication fails, a verification failure prompt will be returned and the process ends.

[0091] Step S2032, if the identity authentication is passed, the alliance chain node reads the computing power service credential of the node to be connected from the computing power service alliance chain based on the computing power service credential information, and verifies the computing power service credential.

[0092] If the identity authentication is passed, the corresponding computing service certificate is obtained from the alliance chain based on the computing service certificate information, so as to verify the computing service certificate. The verification may include checking the signature, validity period, and whether the computing service described in the certificate matches the service claimed by the node to be connected.

[0093] Furthermore, the verification of the computing power service certificate includes: the alliance chain node determines whether the issuer of the computing power service certificate is stored in the preset computing power service authentication node whitelist, and verifies the digital signature of the computing power service certificate based on the issuer's public key; if the issuer of the computing power service certificate is stored in the preset computing power service authentication node whitelist, and the digital signature of the computing power service certificate passes the verification, it indicates that the computing power service certificate verification has passed.

[0094] The computing power service certificate information included in the computing power access request can exist in the form of a list, which may contain one or more pieces of computing power service certificate information (i.e., there is one or more certificate identifiers). According to each certificate identifier, the corresponding computing power service certificate is read from the alliance chain, the issuer of the computing power service certificate is obtained, and it is judged whether the issuer is stored in the preset white list of computing power service authentication nodes, and the digital signature of the computing power service certificate is verified with the public key of the issuer. If the issuer is stored in the white list and the digital signature of the computing power service certificate passes the verification, the next verification can be carried out or the verification passes; if not, the certificate can be regarded as invalid and the verification ends.

[0095] Optionally, the public key corresponding to the issuer DID can be obtained from the public key library of the computing power service authentication node, and the digital signature on the certificate is verified with this public key to check whether the signature is indeed generated by the corresponding private key.

[0096] If the digital signature verification is successful, it indicates that the certificate has not been tampered with during the transmission process and is indeed issued by the claimed issuer; if the verification fails, the certificate is regarded as invalid and the verification process ends.

[0097] Since the node to be accessed may involve multiple certificates, after the certificate verification passes, the certificate ID and its initial state can be added to the list, otherwise a certificate verification failure prompt is returned to the node to be accessed. It can be set according to actual needs, and it is allowed that part of the computing power service certificates corresponding to the computing power service certificate information do not pass the verification. After all the certificates are verified, the verification result is uniformly returned to the node to be accessed, or it can also be set to directly return an error prompt and end the processing once a certificate fails.

[0098] The verification steps of the certificate can ensure that the issuer of the certificate is authorized, and can further ensure the integrity and authenticity of the source of the certificate.

[0099] Step S2033, if the computing power service certificate verification passes, the alliance chain node writes the identity information of the node to be accessed and the computing power service certificate information into the computing power service alliance chain, and sends a computing power access result to the node to be accessed.

[0100] After all the computing power service certificates are verified to pass, the alliance chain node writes the identity information of the node to be accessed and the verified computing power service certificate information into the computing power service alliance chain and sends a computing power access result.

[0101] In some alternative embodiments, the method further includes: the consortium blockchain node receives a computing power query request from the query node, authenticates the query node based on the identity identifier of the query node in the computing power query request; if the authentication of the query node is passed, reads the computing power data of the available consortium blockchain nodes from the computing power service consortium blockchain, and generates a node list, where the node list includes the computing power data of the available consortium blockchain nodes; the consortium blockchain node sends the node list to the query node.

[0102] The query node is a computing power consuming user. The computing power consuming user can be a node to be connected. If the query node needs to perform a computing power query, it can initiate a computing power query request to the consortium blockchain node. The query request contains the DID identity information of the computing power consuming user. After receiving the computing power query request, the consortium blockchain node performs identity security verification on the computing power consuming user based on the DID identity information. If the verification fails, an error prompt is returned and the process ends. If the verification passes, the API for obtaining the node list provided by the basic function of the consortium blockchain is called to obtain all the consortium blockchain nodes with normal current operating status.

[0103] Read a node from the consortium blockchain node list, read its computing power registration information from the chain according to its DID identity information, and create a data structure to store the computing power service list provided by the node (i.e., the computing power service capability data declared in multiple computing power service vouchers). Aggregate the computing power service capability data of all available nodes to construct a node list, and each element in the node list corresponds to the computing power service data structure of a node.

[0104] In this embodiment, a computing power access method is provided, which is applied to a node to be connected and can be used for terminals such as computing devices and servers. Figure 2 It is a flowchart of the computing power access method according to the embodiment of the present invention. As Figure 2 shown, the process includes the following steps:

[0105] Step S301, send an identity registration request to the computing power service authentication node and receive the identity information sent by the computing power service authentication node.

[0106] When a group of computing devices access the computing power service consortium chain, an access node needs to be created, and this node is used as the representative of the local computing device network to register its available computing power service capabilities with the computing power service consortium chain. When a node to be accessed needs to access the computing power service consortium chain, it first needs to perform identity registration and send an identity registration request to the computing power service authentication node. The identity registration request may carry encrypted data or identifiers, which are verified by the computing power service authentication node to confirm whether the node to be accessed meets the requirements of identity registration. If the node to be accessed meets the identity registration requirements, the computing power service authentication node creates the identity information of the node to be accessed. The identity information can be an identifier used to uniquely represent the node to be accessed. In addition, an identity document for the node to be accessed is generated. The identity document may include information such as the identity information of the node to be accessed, the protocol used, the service request address, the timestamp, and the digital signature. After receiving the identity information, the node to be accessed completes the identity registration.

[0107] As an example, the computing power service authentication node creates a DID identifier and a DID identity document corresponding to the node to be accessed, where the identity information includes the DID identifier. The computing power service authentication node sends the identity information to the node to be accessed and writes the corresponding identity document into the consortium chain through the smart contract interface of the consortium chain.

[0108] Step S302: Obtain the computing power service credential template and initiate a credential creation application based on the computing power service credential template to obtain the computing power service credential information.

[0109] Among them, the computing power service credential information is generated after the computing power service authentication node verifies the credential creation application submitted by the node to be accessed. The computing power service credential information corresponds to the computing power service credential, and the computing power service credential is used to represent that the actual computing power capability of the node to be accessed is consistent with the computing power capability declared in the credential creation application.

[0110] The node to be accessed requests to obtain an available computing power service credential template. The available computing power service credential template represents the already created computing power service credential template. The structure and content of the computing power service credential are defined in the computing power service credential template, and corresponding computing power service credential templates can be adopted for different types of node types. After the node to be accessed completes the identity registration, it requests the computing power service authentication node to obtain an available computing power service credential template, and the computing power service authentication node will send the available computing power service credential template to the node to be accessed.

[0111] After receiving the available computing power service credential template, the node to be accessed can select a matching computing power service credential template according to the computing power service type and characteristics of the local computing device. The node to be accessed uses the corresponding computing power service credential template to initiate a credential creation application, and the credential creation application includes a declaration of its available computing power service capabilities (such as virtual machines and their specifications).

[0112] After receiving the voucher creation application, the computing power service authentication node will conduct further verification. If the verification is passed, a computing power service voucher will be generated, and the computing power service voucher information will be returned to the node to be connected. The computing power service voucher can prove that the actual computing power of the node to be connected is consistent with the computing power declared in the voucher creation application. The computing power service voucher information is the identifier corresponding to the computing power service voucher. After creating the computing power service voucher and the computing power service voucher information, the computing power service authentication node stores the computing power service voucher on the chain through the intelligent contract interface of the alliance chain and returns the computing power service voucher information to the node to be connected.

[0113] The computing power service authentication node can regularly detect the computing power of the node to be connected to ensure the timeliness and authenticity of the computing power node.

[0114] If the verification fails, a corresponding prompt will be returned to the node to be connected. The node to be connected can create multiple computing power service vouchers for processing.

[0115] Step S303, after obtaining the computing power service voucher information, send a computing power access request and receive the computing power access result.

[0116] Among them, the computing power access result is used to represent whether the node to be connected accesses the computing power service alliance chain. The computing power access request includes at least the identity information of the node to be connected and the computing power service voucher information. The computing power access result is determined after the alliance chain node verifies the identity information and the computing power service voucher information of the node to be connected.

[0117] After obtaining the computing power service voucher information, the node to be connected can send a computing power access request to the alliance chain node through a specified interface. The parameters in the computing power access request can include the identity information of the node to be connected, the computing power service voucher information, etc. After receiving the computing power access request, the alliance chain node first verifies the identity information, and after the verification is passed, it verifies the computing power service voucher information. The verification can be combined with the identity information, the computing power service voucher information, and the data stored on the alliance chain. In the verification process, as long as there is a situation where the verification fails, an error prompt message will be returned to the node to be connected.

[0118] As an example, after receiving a computing power access request, first read the identity document of the access node from the chain (i.e., the ledger), and then authenticate the node to be accessed (the authentication process is exemplified as follows: encrypt a random number with the public key in the identity document, send the ciphertext to the node to be accessed, and let the node to be accessed decrypt it with the private key and return the plaintext for comparison and verification). When the authentication fails, a verification failure prompt will be returned and the process ends. When the authentication passes, the consortium blockchain node will read each computing power service voucher according to the computing power service voucher information and verify the voucher (for example: verify whether the issuer is in the white list of the computing power service authentication node, and verify the digital signature of the voucher with the public key of the issuer, etc.). When the voucher verification passes, add the voucher ID and its initial state (such as idle) to a list, otherwise return a voucher verification failure prompt to the node to be accessed (this can be set according to requirements, allowing some vouchers in the computing power service voucher ID list to pass verification and some not to pass. After all vouchers are verified, a prompt message will be uniformly returned to the node to be accessed; it can also be set according to requirements that once a voucher verification fails, an error prompt will be directly returned and the processing will end). After verifying all vouchers, store the DID of the node to be accessed and the list of verified vouchers on the chain as computing power access information, and return the computing power access result. If the verification is successful, the computing power access result will be a computing power access success prompt message.

[0119] The computing power access result also includes the computing power service information of the node to be accessed written on the consortium blockchain (for example: computing power service voucher information).

[0120] Before sending a computing power access request, the node to be accessed can also request the consortium blockchain node to obtain the information required for computing power access. After obtaining the required information, it sends a computing power access request, which contains the information required for computing power access.

[0121] Optionally, allow the computing power service authentication node to update the template regularly or on demand. The new template may include more stringent verification rules, newly added computing power service types, or improved data structures. The node to be accessed can subscribe to a specific computing power service voucher template. When the template is updated, the computing power service authentication node notifies the node to be accessed through the message queue to ensure that they always use the latest template.

[0122] The computing power access method provided in this embodiment includes sending an identity registration request to a computing power service authentication node and receiving the identity information of the node to be accessed sent by the computing power service authentication node; obtaining an available computing power service voucher template, and initiating a voucher creation application based on the computing power service voucher template to obtain computing power service voucher information; after obtaining the corresponding computing power service voucher information, sending a computing power access request and receiving a computing power access result, where the computing power access result is used to indicate whether the node to be accessed is connected to the computing power service alliance chain. The computing power access request includes at least the identity information of the node to be accessed and the computing power service voucher information, and the computing power access result is determined by the computing power service authentication node after verifying the identity information and the computing power service voucher information of the node to be accessed. This method uses the form of an alliance chain for computing power access, and performs identity registration, computing power service voucher creation, and computing power access throughout the computing power access process. During computing power access verification, double verification is performed on the identity information and the computing power service voucher information to avoid the situation of untrue computing power service information and forged vouchers of the node to be accessed, and improve the security of computing power access. In addition, the semi-public nature of the alliance chain is more suitable for protecting the privacy data of computing power nodes.

[0123] In this embodiment, a computing power access method is provided, and the method includes the following steps:

[0124] Step S401: Send an identity registration request to a computing power service authentication node and receive the identity information of the node to be accessed sent by the computing power service authentication node.

[0125] Specifically, step S401 includes:

[0126] Step S4011: Create an asymmetric key locally and send an identity registration request to a computing power service authentication node.

[0127] Among them, the identity registration request includes at least the public key information of the asymmetric key.

[0128] Before sending the identity registration request, the node to be accessed creates a pair of asymmetric keys locally, initiates an identity registration request to the computing power service authentication node, and the identity registration request carries the public key information. Among them, the private key in the asymmetric key pair is strictly kept by the node to be accessed and will not be shared with other nodes, and is used for operations such as digital signature.

[0129] Step S4012: Receive the identity information of the node to be accessed generated by the computing power service authentication node based on the verification result of the identity registration request.

[0130] Among them, the identity information includes at least the decentralized identity identifier of the node to be accessed, and the identity document corresponding to the identity information is written into the computing power service alliance chain.

[0131] After the computing power service authentication node receives a registration request, it checks whether the parameters carried in the request contain public key information. If not, it returns an error prompt. If so, it creates identity information and an identity document. The identity document is written into the computing power service alliance chain through the smart contract interface, and the identity information is returned to the node to be connected.

[0132] Specifically, a DID identity identifier (i.e., a decentralized identity identifier) and a DID identity document can be created according to the specification. The DID identity document stores relevant information of the node to be connected in JSON format, and does not contain content related to the identity of the node to be connected (such as the address of the node to be connected, etc.), but only contains data related to the description of the DID (such as the DID identifier, creation timestamp, public key, encryption algorithm, etc.).

[0133] Step S402: Obtain the computing power service voucher template and initiate a voucher creation application based on the computing power service voucher template to obtain computing power service voucher information.

[0134] Specifically, step S402 includes:

[0135] Step S4021: Send a template request to the computing power service authentication node and receive the computing power service voucher template.

[0136] Among them, the template request is used to represent the request to obtain an available computing power service voucher template.

[0137] After the node to be connected completes identity registration, it sends a template request to the computing power service authentication node to request an available computing power service voucher template. An available computing power service voucher template refers to a computing power service voucher template that has been created and stored in the alliance chain. The computing power service authentication node sends the available computing power service voucher template to the node to be connected.

[0138] Step S4022: Determine the target computing power service voucher template from the computing power service voucher template based on the local computing power service type.

[0139] There may be one or more available computing power service voucher templates. If there are multiple, the node to be connected can select a matching voucher template according to the local computing power service type, that is, the target computing power service voucher template.

[0140] Step S4023: Initiate a voucher creation application based on the target computing power service voucher template.

[0141] Among them, the voucher creation application at least includes the declared computing power data. The computing power service authentication node determines whether to issue a computing power service voucher based on the comparison result between the actual computing power data of the node to be connected and the declared computing power data. A computing power service voucher creation application is initiated to the computing power service authentication node using the target computing power service voucher template, and the voucher creation application contains a declaration of the computing power service capabilities it possesses (such as virtual machines and their specifications). After the computing power service authentication node performs a computing power detection on the node to be connected, it determines whether the voucher creation application passes the verification. Specifically, the computing power service authentication node detects the actual computing power of the node to be connected and compares the actual computing power with the declared computing power service capabilities, so as to verify whether the node to be connected has the computing power it declares.

[0142] Optionally, the computing power service authentication node can periodically re-check the actual computing power of the computing power nodes stored on the chain and update the information stored on the chain accordingly, so as to avoid the untrue performance of the computing power nodes through dynamic verification.

[0143] Step S4024, if the actual computing power data is consistent with the declared computing power data, the computing power service authentication node issues a computing power service voucher, and the node to be connected receives the computing power service voucher information.

[0144] Among them, the computing power service voucher information at least includes the voucher identifier, and the computing power service voucher of the node to be connected is written into the computing power service alliance chain.

[0145] After receiving the voucher creation application, the computing power service authentication node calls the computing power resource detection and verification module to detect the node to be connected. Specifically, it can detect and verify the computing power service capabilities declared by the node to be connected, involving actual running test tasks, checking resource allocation, verifying performance parameters, etc. Compare the verification result with the computing power service capability data declared in the voucher creation application. If the comparison result shows that the performance parameters of the node to be connected meet (reach or exceed) the specification requirements or performance parameter indicators described in the service voucher, issue a computing power service voucher. The computing power service voucher has corresponding computing power service voucher information, and the computing power service voucher information at least includes the identification number (ID) of the computing power service voucher of the node to be connected. Store the computing power service voucher on the chain and send the computing power service voucher information to the node to be connected.

[0146] Furthermore, if the computing power service authentication node fails to pass the verification of the voucher creation application, it receives an error prompt.

[0147] If the verification fails, no computing power service voucher is issued and an error prompt is returned.

[0148] Step S403, after obtaining the corresponding computing power service voucher information, send a computing power access request and receive a computing power access result.

[0149] Specifically, step S403 includes:

[0150] Step S4031: Obtain the information required for computing power access.

[0151] Among them, the information required for computing power access includes at least a request interface.

[0152] After obtaining the corresponding computing power service certificate information, the node to be accessed sends a request for obtaining the information required for computing power access to the consortium blockchain node, so as to obtain the information required for computing power access, including the request interface, required parameters, and specifications for computing power access, etc.

[0153] Step S4032: Generate a computing power access request based on the information required for computing power access, and send the computing power access request based on the request interface.

[0154] After receiving the information required for computing power access, the node to be accessed generates a computing power access request, which includes the identity information of the node to be accessed, computing power service certificate information, etc., and sends the computing power access request through the request interface.

[0155] Step S4033: The consortium blockchain node respectively performs identity verification and certificate verification based on the identity information and computing power service certificate information in the computing power access request. If the identity verification is passed and the computing power service certificate verification is passed, the computing power access result is received.

[0156] Among them, the computing power access result indicates that the node to be accessed joins the computing power service consortium chain, and the consortium chain node stores the identity information and computing power service voucher information of the node to be accessed into the computing power service consortium chain. After receiving the computing power access request, first read the identity document of the access node from the chain (i.e., the ledger), and then authenticate the node to be accessed (the authentication process is exemplified as follows: encrypt a random number with the public key in the identity document, send the ciphertext to the node to be accessed, and let the node to be accessed decrypt it with the private key and return the plaintext for comparison and verification). When the identity verification fails, a verification failure prompt will be returned and the process ends. When the identity verification passes, the consortium chain node will read each computing power service voucher according to the computing power service voucher information and verify the voucher (for example: verify whether the issuer is in the white list of computing power service authentication nodes, and verify the digital signature of the voucher with the public key of the issuer, etc.). When the voucher verification passes, add the voucher ID and its initial state (such as idle) to a list, otherwise return a voucher verification failure prompt to the node to be accessed (here it can be set according to requirements, allowing some vouchers in the computing power service voucher ID list to pass verification and some not to pass. After all vouchers are verified, a prompt message is uniformly replied to the node to be accessed; it can also be set according to requirements that once a voucher verification fails, an error prompt is directly returned and the processing ends). After verifying all vouchers, store the DID of the node to be accessed and the list of verified vouchers on the chain as computing power access information, and return the computing power access result. If the verification is successful, the computing power access result is a computing power access success prompt message.

[0157] In some alternative embodiments, the above computing power access method further includes: if the node to be accessed accesses the computing power service consortium chain for the first time, synchronize the data on the computing power service consortium chain to the node to be accessed.

[0158] When a computing power node (such as: the node to be accessed) accesses the computing power service consortium chain for the first time, ledger data synchronization will be performed. Ledger data synchronization is block synchronization. When a new node wants to join the consortium chain network, or an abnormal node returns to normal, the block height of this node lags behind other nodes, the state is not the latest, and it cannot participate in network transaction consensus. At this time, block synchronization is required, and this node will actively request to download blocks from other nodes.

[0159] Obtain the data that has been uploaded to the chain (including smart contract programs, user identity documents, computing power service templates, computing power service vouchers, computing power access information, etc.) from adjacent consortium chain nodes, so that the newly added node has the latest state (the latest state data of the ledger represents the latest values of all key-value pairs included in the blockchain transaction log), in order to participate in the consensus of the next new block. In addition, the basic functions of the consortium chain will automatically connect to more other consortium chain nodes, making the consortium chain network more robust. If this computing power node does not access the computing power for the first time (such as: updating the computing power access information), no additional processing is required.

[0160] The computing power access method provided by the present invention is used for a computing power access system, including a computing power service consortium chain, a node to be accessed, and a computing power service authentication node. The architecture of the computing power access system is as Figure 3 shown. Among them, the node to be accessed includes functions such as computing power resource monitoring, basic functions of the consortium chain, identity registration and verification, status monitoring, computing power registration (i.e., computing power access), computing power query, uploading of computing power service vouchers to the chain, uploading of identity documents to the chain, and smart contract programs.

[0161] The computing power resource monitoring module is used to monitor the computing resources in the local computing device network, and is also used to respond to the computing power resource detection and inspection requests from the computing power service authentication node and return the detection and inspection results. In specific implementation, it can monitor the resources on the specified computing device, or design test plugins according to industry standards, install and deploy the test plugins on the specified computing device and run the tests to return the test results.

[0162] The basic functions module of the consortium chain is used to implement the underlying basic functions of the consortium chain. FISCO BCOS consists of a basic layer, a chain core layer, an interconnection core layer, a management layer, and an interface layer, and provides services to application developers through the SDK, interactive console, and RPC interface of the interface layer.

[0163] The identity registration and verification module is used to initiate a DID identity registration request to the computing power service authentication node and cooperate with the computing power service authentication node to complete the creation of the DID identity. In addition, this module is also responsible for processing the verification requests of external entities for the DID identity of this node.

[0164] The status monitoring module is used to monitor the running status of other consortium chain nodes. In the basic functions of FISCO BCOS, a mechanism based on heartbeat packets is implemented to monitor the status of all Peer nodes, and an API for obtaining a list of Peer nodes is provided, which can obtain all nodes with normal running status.

[0165] The computing power registration module is responsible for applying for a computing power service voucher from the computing power service authentication node, and is also responsible for registering the computing power service information that this node can provide to the computing power service consortium chain.

[0166] The computing power query module is used to respond to external computing power query requests.

[0167] The module for uploading computing power service vouchers to the chain will be enabled only when this node is connected to the computing power service consortium chain, and is responsible for processing the operation of uploading the computing power service vouchers initiated by the computing power service authentication node.

[0168] The module for uploading identity documents to the chain will be enabled only when this node is connected to the computing power service consortium chain, and is responsible for processing the operation of uploading the identity documents initiated by the computing power service authentication node.

[0169] The smart contract program is used to design and implement the smart contract program for the above data on-chain operations. When the node to be connected accesses the computing power service consortium chain, through ledger data synchronization, the smart contract programs deployed on the consortium chain will be automatically deployed on the newly connected node, including the identity document on-chain smart contract, the voucher template on-chain smart contract, the voucher on-chain smart contract, and the computing power registration information on-chain smart contract. When the computing power service consortium chain is initialized, the management staff can be responsible for deploying these smart contract programs on the consortium chain.

[0170] Considering the problem of large data storage overhead on the blockchain, in the specific implementation, external storage can be used, such as: a distributed file storage system or a cloud storage platform. If a distributed file storage system is used as the external storage, each file will calculate a unique hash based on its content (i.e., the fingerprint of the file), and store the data files with large storage space overhead (including voucher templates, identity documents, computing power service vouchers) into the system, while only storing the file hash into the computing power service consortium chain.

[0171] If cloud storage is used as the external storage, the data files with large storage space overhead (including voucher templates, identity documents, computing power service vouchers) will be saved to the corresponding cloud server through the cloud storage service provided by the cloud service provider, and their access addresses (such as: URI or URL) and the hash value of the data file content will be stored on the computing power service consortium chain.

[0172] The corresponding on-chain smart contract interface is designed as follows:

[0173] Voucher template writing interface: saveCpt, parameter: voucher template file metadata (MetaData).

[0174] Write computing power service voucher: saveCredential, parameter: service voucher file metadata.

[0175] Write identity document: saveDidDoc, parameter: identity document file metadata.

[0176] The file metadata content includes information such as file name, size, IPFS file hash or cloud storage file access address and file content hash value, etc.

[0177] It is also possible to unify the interface format and provide an on-chain smart contract interface: saveData, with parameters including the data type to be written (the types include voucher templates, computing power service vouchers, identity documents) and file metadata.

[0178] The computing power service authentication node is an authoritative institution node that can provide DID identity registration and computing power service capability authentication for computing power nodes, and write identity documents and computing power service vouchers to the consortium blockchain through the smart contract upload interface provided by the consortium blockchain. At the same time, it can provide the function of customizing computing power service voucher templates for computing power service authentication users, and the corresponding voucher templates are also stored on the chain. The computing power service authentication node is a processing unit outside the consortium blockchain, which can be a single-function node or a service system composed of multiple distributed nodes (for example: the IP address list of the computing power certificate service authentication node can be written into the consortium blockchain, and the node to be connected can query this IP address list and select an IP for connection; or the smart contract program of the consortium blockchain provides an interface to obtain an authentication node, and an IP of the computing power certificate service authentication node can be directly assigned to the node to be connected through this interface).

[0179] The computing power service authentication node includes functions such as computing power service voucher templates, computing power service vouchers, identity authentication, trusted voucher services, DID services, computing power resource detection and verification, etc.

[0180] The computing power service voucher template module is used to provide the function of customizing computing power service voucher templates for computing power service authentication users. The computing power service authentication users can customize computing power service voucher templates according to the computing power service definition standard. At the same time, the created voucher templates can be written into the consortium blockchain through the smart contract program interface of the consortium blockchain, and the created computing power service voucher templates can be queried and used by computing power nodes.

[0181] The computing power service voucher module is responsible for providing computing power service voucher issuance and verification services for computing power nodes, and writing the issued computing power service vouchers to the consortium blockchain through the smart contract program interface of the consortium blockchain.

[0182] The identity authentication module is responsible for creating and verifying DID identities for computing power nodes and computing power consuming users, and writing the corresponding DID identity documents to the consortium blockchain through the smart contract program interface of the consortium blockchain.

[0183] The trusted voucher service module is used to implement a verifiable digital voucher model, provide processing interfaces for functions such as voucher template creation, voucher issuance and verification, and selective disclosure voucher issuance and verification, and provide support for the computing power service voucher template and computing power service voucher. It is the underlying support module for these two modules.

[0184] The DID service module is used to implement the creation and verification functions of distributed digital identity identifiers and DID documents, provide relevant function processing interfaces, and provide support for the identity authentication module.

[0185] The computing power resource detection and verification module is responsible for detecting and verifying the computing power service capability data (such as virtual machine resource specifications, or computing performance parameter indicators, etc.) declared in the computing power service certificate applied for by the computing power node. A computing power resource detection and verification data request will be sent to the computing power resource monitoring module of the node to be connected, and the computing power resource monitoring module of the node to be connected will return the specific detection and verification results. After receiving the detection and verification results, it will be compared with the computing power service capability data declared in the computing power service certificate application to determine whether they are consistent. If they are consistent, they will pass, otherwise an error message will be returned.

[0186] The process of accessing the computing power of the node to be connected is as follows: Figure 4 As shown, the node to be connected initiates identity registration with the computing service authentication node. After identity authentication, the computing service authentication node creates an identity document and DID identity information, stores the identity document in the alliance chain, and returns the identity information to the node to be connected. After identity registration, the node to be connected requests to obtain an available computing service credential template, and issues a computing service credential creation application based on the computing service credential template. After receiving the computing service credential creation application, the computing service authentication node performs resource detection on the node to be connected. If the actual computing power capability of the node to be connected is consistent with the computing power capability declared in the computing service credential creation application, it creates a computing service credential, stores the computing service credential in the alliance chain, and returns the computing service credential information (computing service credential ID) to the node to be connected.

[0187] The node to be connected requests the alliance chain node to obtain the information required for computing power registration, and sends a computing power access request after obtaining the required information. The alliance chain node verifies the identity information and computing power service credential information of the node to be connected and determines whether the registration is successful.

[0188] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method.

[0189] The embodiment of the present application further provides a computing power access device, which is applied to a computing power service authentication node, including:

[0190] An identity authentication module, configured to authenticate the node to be accessed based on the identity registration request of the node to be accessed, so as to generate an identity document of the node to be accessed and corresponding identity information, wherein the identity information at least includes a decentralized identity identifier;

[0191] A credential issuance module, which is used to create an application for a credential based on the credential creation application of the to-be-connected node, detect the actual computing power of the to-be-connected node, and issue a computing power service credential and corresponding computing power service credential information according to the actual computing power. The computing power service credential information at least includes a credential identifier; the computing power service credential and identity document of the to-be-connected node are stored in a computing power service consortium blockchain;

[0192] A computing power access module, which is used when the to-be-connected node sends a computing power access request, and the consortium blockchain node performs identity verification and credential verification based on the identity information and computing power service credential information in the computing power access request respectively to determine the computing power access result of the to-be-connected node.

[0193] An embodiment of the present application further provides a computing power access device, which is applied to a to-be-connected node and includes:

[0194] An identity registration module, which is used to send an identity registration request to a computing power service authentication node and receive the identity information sent by the computing power service authentication node;

[0195] A credential application module, which is used to obtain a computing power service credential template and initiate a credential creation application based on the computing power service credential template to obtain computing power service credential information. The computing power service credential information is generated after the computing power service authentication node verifies the credential creation application submitted by the to-be-connected node. The computing power service credential information corresponds to the computing power service credential, and the computing power service credential is used to represent that the actual computing power of the to-be-connected node is consistent with the computing power declared in the credential creation application;

[0196] An access determination module, which is used to send a computing power access request and receive a computing power access result after obtaining the computing power service credential information. The computing power access result is used to represent whether the to-be-connected node accesses the computing power service consortium blockchain. The computing power access request at least includes the identity information and computing power service credential information of the to-be-connected node, and the computing power access result is determined after the consortium blockchain node verifies the identity information and computing power service credential information of the to-be-connected node.

[0197] For the description of the features in the corresponding embodiment of the computing power access device, reference can be made to the relevant description in the corresponding embodiment of the computing power access method, which will not be elaborated here one by one.

[0198] An embodiment of the present application further provides a computer device, as Figure 5 shown, including a processor 10 and a memory 20. A computer program is stored in the memory 20, and the processor 10 is configured to run the computer program to execute the steps in any of the above embodiments of the computing power access method.

[0199] Embodiments of the present application also provide a computer-readable storage medium storing a computer program, where the computer program is configured to execute the steps in any of the above-described embodiments of the computing power access method when running.

[0200] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: various media such as USB flash drives, read-only memories (ROM), random access memories (RAM), external hard drives, magnetic disks, or optical discs that can store computer programs.

[0201] Embodiments of the present application also provide a computer program product. The above computer program product includes a computer program, and when the computer program is executed by a processor, it implements the steps in any of the above-described embodiments of the computing power access method.

[0202] Embodiments of the present application also provide another computer program product, including a non-volatile computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, it implements the steps in any of the above-described embodiments of the computing power access method.

[0203] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Skilled professionals can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0204] The above has introduced in detail a computing power access method provided by the present application. Specific examples are used herein to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application. It should be noted that for those of ordinary skill in the art in the technical field, without departing from the principle of the present application, several improvements and modifications can be made to the present application, and these improvements and modifications also fall within the protection scope of the claims of the present application.

Claims

1. A computing power access method, characterized in that: Applied to the computing power service authentication node, which is deployed in the computing power service alliance chain, including: Verifying the node to be accessed based on the identity registration request of the node to be accessed, so as to generate an identity document of the node to be accessed and corresponding identity information, wherein the identity information includes at least a decentralized identity identifier; Based on the credential creation application of the node to be accessed, the actual computing power of the node to be accessed is detected, so as to issue a computing power service credential and corresponding computing power service credential information according to the actual computing power, wherein the computing power service credential information at least includes a credential identifier; the computing power service credential and identity document of the node to be accessed are stored in the computing power service alliance chain; When the node to be connected issues a computing power access request, the alliance chain node performs identity authentication and credential verification based on the identity information and computing power service credential information in the computing power access request to determine the computing power access result of the node to be connected; The step of creating an application for a certificate based on the node to be accessed and detecting the actual computing power of the node to be accessed, so as to issue a computing power service certificate and corresponding computing power service certificate information according to the actual computing power, includes: Detect the actual computing power data of the node to be connected, and extract the declared computing power data of the node to be connected from the credential creation application of the node to be connected; compare the actual computing power data with the declared computing power data; if the actual computing power data is consistent with the declared computing power data, issue a computing power service certificate and corresponding computing power service certificate information; send the computing power service certificate information to the node to be connected, and write the computing power service certificate into the computing power service alliance chain.

2. The computing power access method according to claim 1, characterized in that: The verifying the node to be accessed based on the identity registration request of the node to be accessed to generate an identity document of the node to be accessed and corresponding identity information, includes: Determining whether the identity registration request contains public key information; If the identity registration request contains the public key information, generating an identity document of the node to be accessed and corresponding identity information; The identity information is sent to the node to be connected, and the identity document of the node to be connected is written into the computing power service alliance chain.

3. The computing power access method according to claim 1, characterized in that: The method further comprises: Sending the identity information to the node to be accessed, and receiving a template request sent by the node to be accessed; A computing power service voucher template is issued to the node to be connected based on the template request, and the node to be connected issues a voucher creation application based on the computing power service voucher template.

4. The computing power access method according to claim 1, characterized in that: The alliance chain node performs identity authentication and credential verification based on the identity information and computing power service credential information in the computing power access request to determine the computing power access result of the node to be accessed, including: The alliance chain node reads the identity document of the node to be connected from the computing power service alliance chain based on the identity information, and performs identity authentication on the node to be connected based on the identity document; If the identity authentication is passed, the alliance chain node reads the computing power service credential of the node to be connected from the computing power service alliance chain based on the computing power service credential information, and verifies the computing power service credential; If the computing power service credential verification is successful, the alliance chain node writes the identity information of the node to be accessed and the computing power service credential information into the computing power service alliance chain, and sends the computing power access result to the node to be accessed.

5. The computing power access method according to claim 4, characterized in that: The performing identity authentication on the node to be accessed based on the identity document includes: The alliance chain node obtains the public key information in the identity document to encrypt the random number to obtain a ciphertext; The alliance chain node sends the ciphertext to the node to be connected, and receives the plaintext after the node to be connected decrypts the ciphertext based on the private key; The alliance chain node verifies the node to be accessed based on the comparison result of the plaintext and the random number; If the plain text is consistent with the random number, the identity authentication of the node to be accessed is successful.

6. The computing power access method according to claim 4, characterized in that: The verifying of the computing power service credential includes: The alliance chain node determines whether the issuer of the computing power service certificate is stored in a preset computing power service authentication node whitelist, and verifies the digital signature of the computing power service certificate based on the public key of the issuer; If the issuer of the computing power service certificate is stored in the preset computing power service authentication node whitelist, and the digital signature of the computing power service certificate passes the verification, it indicates that the computing power service certificate passes the verification.

7. The computing power access method according to claim 1, characterized in that: The method further comprises: The alliance chain node receives a computing power query request from a query node, and authenticates the query node based on the identity identifier of the query node in the computing power query request; If the query node identity authentication is passed, the computing power data of the available alliance chain nodes are read from the computing power service alliance chain, and a node list is generated, wherein the node list includes the computing power data of the available alliance chain nodes; The alliance chain node sends the node list to the query node.

8. A computing power access method, characterized in that: Applied to the node to be connected, including: Send an identity registration request to the computing power service authentication node, and receive identity information sent by the computing power service authentication node; Obtain a computing power service credential template, and initiate a credential creation application based on the computing power service credential template to obtain computing power service credential information, wherein the computing power service credential information is generated after the computing power service authentication node verifies the credential creation application submitted by the node to be connected, and the computing power service credential information corresponds to the computing power service credential, and the computing power service credential is used to indicate that the actual computing power capability of the node to be connected is consistent with the computing power capability declared in the credential creation application; After obtaining the computing power service credential information, a computing power access request is issued, and a computing power access result is received. The computing power access result is used to indicate whether the node to be accessed is connected to the computing power service alliance chain. The computing power access request at least includes the identity information and computing power service credential information of the node to be accessed. The computing power access result is determined after the alliance chain node verifies the identity information and computing power service credential information of the node to be accessed; The method for determining the computing power service certificate includes: The computing power service authentication node detects the actual computing power data of the node to be connected, and extracts the declared computing power data of the node to be connected from the credential creation application of the node to be connected; compares the actual computing power data with the declared computing power data; if the actual computing power data is consistent with the declared computing power data, issues a computing power service credential and corresponding computing power service credential information; sends the computing power service credential information to the node to be connected, and writes the computing power service credential into the computing power service alliance chain.

9. The computing power access method according to claim 8, characterized in that: The sending of an identity registration request to a computing power service authentication node and receiving identity information sent by the computing power service authentication node includes: Creating an asymmetric key locally, and sending an identity registration request to the computing power service authentication node, wherein the identity registration request includes at least the public key information of the asymmetric key; Receive the identity information of the node to be accessed generated by the computing power service authentication node based on the verification result of the identity registration request, the identity information at least includes the decentralized identity identifier of the node to be accessed, and the identity document corresponding to the identity information is written into the computing power service alliance chain.

10. The computing power access method according to claim 8, characterized in that: The obtaining of computing power service voucher template includes: Sending a template request to the computing power service authentication node and receiving a computing power service credential template, wherein the template request is used to represent a request to obtain a computing power service credential template; A target computing power service voucher template is determined from the computing power service voucher templates based on the local computing power service type.

11. The computing power access method according to claim 10, characterized in that: The initiating a credential creation application based on the computing power service credential template to obtain computing power service credential information includes: Initiate a credential creation application based on the target computing power service credential template, the credential creation application at least including declared computing power data, and the computing power service authentication node determines whether to issue a computing power service credential based on a comparison result between the actual computing power data of the node to be connected and the declared computing power data; If the actual computing power data is consistent with the declared computing power data, the computing power service authentication node issues a computing power service certificate, and the node to be connected receives computing power service certificate information, and the computing power service certificate information at least includes a certificate identifier.

12. The computing power access method according to claim 8, characterized in that: The sending of the computing power access request and receiving the computing power access result includes: Obtaining information required for computing power access, where the information required for computing power access includes at least a request interface; Generate a computing power access request based on the computing power access required information, and issue the computing power access request based on the request interface; The alliance chain node performs identity authentication and credential verification respectively based on the identity information and computing power service credential information in the computing power access request. If the identity authentication passes and the computing power service credential verification passes, the computing power access result is received. The computing power access result represents that the node to be accessed has accessed the computing power service alliance chain. The alliance chain node stores the identity information and computing power service credential information of the node to be accessed in the computing power service alliance chain.

13. The computing power access method according to claim 8, characterized in that: The method further comprises: If the node to be connected is connecting to the computing power service alliance chain for the first time, the data on the computing power service alliance chain is synchronized to the node to be connected.

14. A computer device, characterized in that: include: Memory for storing computer programs; A processor, used to implement the steps of the computing power access method as described in any one of claims 1 to 13 when executing the computer program.

15. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the steps of the computing power access method according to any one of claims 1 to 13.

16. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the computing power access method as described in any one of claims 1 to 13 are implemented.

Citation Information

Patent Citations

  • Method, equipment, device and medium for access control

    CN117375867A

  • Under-chain computing power transaction method, device and equipment and storage medium

    CN118396624A