A network security service collaboration method based on blockchain dual chain

Through a network security service collaboration method based on a dual-chain blockchain, using onion routing nodes for three-layer encrypted transmission, and combining the collaboration of public chains and consortium chains, the problems of increased investment costs, frequent hacker attacks, and difficulty in information sharing in the network security service system are solved, and efficient security information processing and anonymity protection are achieved.

CN119892459BActive Publication Date: 2025-09-30SOUTHWEST JIAOTONG UNIV

Patent Information

Application Number
CN202510049692.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-13
Publication Date
2025-09-30
Estimated Expiration
2045-01-13

AI Technical Summary

Technical Problem

The existing network security service system faces problems such as increased investment costs, frequent hacker attacks, worsening security situation, and difficulty in information sharing.

Method used

A network security service collaboration method based on blockchain dual chains is adopted, onion routing nodes are used for three-layer encrypted transmission, and the collaboration of public chains, the first alliance chain and the second alliance chain is combined to achieve transparent sharing and anonymous processing of security information.

Benefits of technology

It improves the information processing efficiency of the blockchain, ensures the confidentiality of the source of security information, and enhances the transparency and anonymity of network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119892459B_ABST
    Figure CN119892459B_ABST
Patent Text Reader

Abstract

The present invention discloses a network security service collaboration method based on a blockchain dual chain. By constructing a universal network security collaboration and service platform, adopting a dual-chain cross-chain architecture combining a public chain and an alliance chain, and providing a unified security strategy, combined with digital asset title confirmation and legal safeguards, the rights and interests of users are protected. In the process of network security protection, the platform realizes functions such as abnormal alarm, alarm sharing, hacker behavior detection and tracking, judicial conviction and punishment, network security crime disposal, and asset loss claims. At the same time, completely anonymous technology is adopted to protect user privacy, and anonymous collaboration and service are supported, thereby improving the flexibility and processing efficiency of security services. By constructing an efficient and low-cost collaboration platform, the method enhances the collaboration ability of all parties in handling network security incidents, and provides a complete protection system for cyberspace security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of network security technology, and specifically relates to a network security service collaboration method based on a double-chain blockchain. Background Art

[0002] Blockchain is a distributed database technology whose key features are distributed, decentralized, tamper-resistant, permanent storage, and transparent data through distributed networks and cryptography. In just over a decade since its emergence, blockchain has been integrated into numerous industries, sparking new innovations in areas such as finance, supply chain management, healthcare, logistics, energy, real estate, education, and public services.

[0003] The anonymity of blockchain protects users' basic private information, but in order to ensure the traceability of data recorded on the blockchain, the blockchain cannot be completely anonymous.

[0004] Onion routing is a technology designed to enable anonymous online communication. It achieves anonymity through multiple layers of encryption (similar to the layers of an onion) and routing through a series of network nodes. Each routing node decrypts only one layer of encryption, knowing the previous and next nodes but not the origin or destination of the communication, thus protecting user privacy.

[0005] Different blockchains have different consensus mechanisms and varying bookkeeping speeds. Public chains use algorithms to form a consensus mechanism, whereby the right to record is contested. Private chains have each node's right to record data granted by a central authority. Consortium chains rely on mutual trust between nodes to establish consensus.

[0006] Existing blockchain technologies mainly use private chains and consortium chains because they allow more control and customization, while also providing higher data privacy and security. However, without the decentralization of public chains, security information will not be transparent and open enough. Summary of the Invention

[0007] In response to the above-mentioned deficiencies in the existing technology, the network security service collaboration method based on blockchain dual-chain provided by the present invention solves the problems in the existing network security service system, such as increased investment costs, frequent hacker attacks, worsening security situation, and difficulty in information sharing.

[0008] In order to achieve the above-mentioned purpose of the invention, the technical solution adopted by the present invention is: a network security service collaboration method based on a double-chain blockchain, comprising the following steps:

[0009] Initialization phase: The user sends a request message. Based on the service information of the onion routing node, a list of active nodes is obtained. Three onion routing nodes are selected as the message link according to the load balancing strategy. The user's request message is packaged with three layers of encryption and transmitted layer by layer using the message link. The third onion routing node forwards it to the public chain.

[0010] Release and collaboration phase: The security service provider obtains task information from the public blockchain, formulates a cooperation plan, and sends it to a third-party security repository that stores security services. The third-party security repository then forwards the cooperation plan to the blockchain.

[0011] Solution selection phase: Users obtain a cooperation plan through the blockchain and select a security service solution. They also obtain a new onion routing path and send the selected security service solution to the public chain through the new onion routing path.

[0012] Solution collaboration stage: The security service provider obtains the security service solution selected by the user through the public chain, sends it to the third-party security warehouse for inspection and confirmation, and then sends it to the public chain; the user obtains the confirmed security service solution from the public chain and adds the security service provider to the pipeline of the first alliance chain. The security service provider then establishes the pipeline of the second alliance.

[0013] Solution release stage: The security service provider stores the security service solution in a third-party security warehouse, and sends the address of the security service solution and the unique password generated for the user's key to the user through the pipeline of the first alliance chain; the user sends the address, unique password and security service solution request to the third-party security warehouse, and after the third-party security warehouse completes the verification, it sends the security service solution response to the user.

[0014] Furthermore, in the initialization phase, the request message is packaged with three layers of encryption to obtain encrypted information sent by the user and transmitted to three onion routing nodes in sequence. During the transmission process, after each onion routing node receives the information, it uses its private key to decrypt the received information to obtain the address of the next node. Finally, the third onion routing node obtains the request information and forwards it to the public chain.

[0015] Furthermore, in the initialization phase, the process of performing three-layer encryption on the user's request information is expressed as follows:

[0016] ,

[0017] ;

[0018]

[0019]

[0020]

[0021]

[0022]

[0023]

[0024]

[0025] in, 、 and Represents the symmetric encryption keys randomly generated by the first to third onion routing nodes, 、 and Respectively represent the safety parameters 、 and Generate algorithm keys, 、 、 and Indicates the warning information Perform hash encryption processing, 、 and Represents an encrypted cipher package that encrypts a symmetric encryption key using a node's public key. 、 and Represents the public keys of the first to third onion routing nodes respectively, 、 and Represents a data packet encrypted using the previously generated symmetric encryption key. Represents the public blockchain. Indicates whether the data is uploaded to the public chain, 1 means yes, 0 means no. Indicates the The number of sequences shared between users and onion routing nodes, and Indicates the third onion routing node and the second onion routing node selected, Indicates the encrypted information generated through three layers of encryption.

[0026] Furthermore, in the network security service collaboration method:

[0027] The public chain is used for node communication between security service providers, users, and third-party security warehouses;

[0028] The first alliance chain is used for alarm information sharing and key exchange between users and security service providers;

[0029] The second alliance chain is used for security service providers and judicial authorities to collaborate in processing alarm information.

[0030] Furthermore, during the solution release phase, the information verified by the third-party security warehouse includes the address of the security service solution and the unique password generated for the user key.

[0031] Furthermore, the network security service collaboration method further includes:

[0032] Service alert stage: When a user is attacked, an alert is generated and sent to the pipeline of the first alliance chain, and then forwarded by the security service provider to the pipeline of the second alliance chain for collaborative processing.

[0033] Furthermore, the service warning stage also includes:

[0034] When a user is attacked, the user extracts a summary of the alert and sends the alert summary to the public chain through the new onion routing path obtained, achieving collaboration between the public chain and the alliance chain.

[0035] The beneficial effects of the present invention are:

[0036] (1) The network security collaboration method based on the blockchain dual chain of the present invention utilizes the transmission efficiency of different blockchains to process different data information, thereby improving the information processing efficiency of the blockchain.

[0037] (2) The network security collaboration method based on the blockchain double chain of the present invention utilizes the second generation onion routing to encrypt the security information three times during the chain-up process, and decrypts and transmits it layer by layer through three different miners, thereby completing the anonymization process and ensuring that the source of the security information can be kept confidential. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] Figure 1 Flowchart of the network security service collaboration method based on blockchain dual-chain provided by the present invention.

[0039] Figure 2 This is a simulation diagram of the initialization phase provided by the present invention.

[0040] Figure 3 This is a simulation diagram of the release collaboration stage provided by the present invention.

[0041] Figure 4 This is a simulation diagram of the solution selection stage provided by the present invention.

[0042] Figure 5 This is a simulation diagram of the collaboration phase of the solution provided by the present invention.

[0043] Figure 6 This is a simulation diagram of the solution release phase provided by the present invention.

[0044] Figure 7 This is a simulation diagram of the service warning stage provided by the present invention. DETAILED DESCRIPTION

[0045] The specific embodiments of the present invention are described below to facilitate understanding of the present invention by those skilled in the art. However, it should be clear that the present invention is not limited to the scope of the specific embodiments. For those skilled in the art, as long as various changes are within the spirit and scope of the present invention as defined and determined by the appended claims, these changes are obvious, and all inventions and creations utilizing the concepts of the present invention are protected.

[0046] The embodiment of the present invention provides a network security service collaboration method based on a double chain of blockchain, such as Figure 1 As shown, the following steps are included:

[0047] Initialization phase: The user client sends a request message. Based on the service information of the onion routing node client, it obtains the active node list IPListResponse and selects three onion routing nodes as the message link according to the load balancing strategy. The user's request message is packaged with three layers of encryption and transmitted layer by layer using the message link. It is then forwarded to the public chain by the third onion routing node.

[0048] Release collaboration phase: The security service provider Provider obtains task information from the public chain, formulates a cooperation plan CooperatePlainMsg and sends it to the third-party security warehouse that stores security services. The third-party security warehouse then forwards the cooperation plan to the blockchain.

[0049] Solution selection phase: The user Client obtains the cooperation plan through the blockchain and selects a security service solution. At the same time, it obtains a new onion routing path and sends the selected security service solution SelectedPlainMsg to the public chain through the new onion routing path.

[0050] Solution collaboration stage: The security service provider obtains the security service solution selected by the user through the public chain, sends it to the third-party security warehouse for inspection and confirmation, and then sends it to the public chain; the user obtains the confirmed security service solution from the public chain and adds the security service provider to the pipeline of the first alliance chain AllianceChain, and the security service provider then establishes the pipeline of the second alliance;

[0051] Solution release stage: The security service provider stores the security service solution in a third-party security warehouse, and sends the security service solution address Addr and the unique password Key generated for the user key to the user through the pipeline of the first alliance chain; the user sends the address, unique password and security service solution request SolutionRequest to the third-party security warehouse. After the third-party security warehouse completes the verification, it sends the security service solution response SolutionResponse to the user.

[0052] In the embodiments of the present invention, during the initialization phase, onion routing is a technology designed to achieve anonymous online communication. It achieves anonymity through multiple layers of encryption (similar to the multi-layered structure of an onion) and routing through a series of network nodes. Each routing node decrypts only one layer of encryption and knows the previous and next nodes, but cannot determine the starting and end points of the communication, thereby protecting user privacy.

[0053] Based on this, in this embodiment, the onion routing node needs to register service information, namely the IP address and public key information, which are represented as , the user client selects three onion routing nodes according to the load balancing strategy As a transmission node in the message chain, during the initialization process, the request message is packaged with three layers of encryption to obtain encrypted information sent by the user and passed to three onion routing nodes in turn. During the transmission process, after each onion routing node receives the information, it uses its private key to decrypt the received information and obtain the address of the next node. Finally, the third onion routing node obtains the request information and forwards it to the public chain.

[0054] Furthermore, in the initialization phase, the process of performing three-layer encryption on the user's request information is expressed as

[0055] ,

[0056] ;

[0057]

[0058]

[0059]

[0060]

[0061]

[0062]

[0063]

[0064] in, 、 and Represents the symmetric encryption keys randomly generated by the first to third onion routing nodes, 、 and Respectively represent the safety parameters 、 and Generate algorithm keys, 、 、 and Indicates the warning information Perform hash encryption processing, 、 and Represents an encrypted cipher package that encrypts a symmetric encryption key using a node's public key. 、 and Represents the public keys of the first to third onion routing nodes respectively, 、 and Represents a data packet encrypted using the previously generated symmetric encryption key. Represents the public blockchain. Indicates whether the data is uploaded to the public chain, 1 means yes, 0 means no. Indicates the The number of sequences shared between users and onion routing nodes, and Indicates the third onion routing node and the second onion routing node selected, Indicates the encrypted information generated through three layers of encryption.

[0065] The six communication channels involved in the initialization phase are C1, C, C3, C4, C5, and C6;

[0066] The roles involved in the initialization phase include: TorNode1, TorNode2, TorNode3, Client, TorNodeNet, PublicChain;

[0067] The 9 pieces of communication interaction information in the initialization phase are:

[0068] 1.TorNode1 -> TorNodeNet: TorNode1, K1

[0069] 2.TorNode2 -> TorNodeNet: TorNode2, K2

[0070] 3.TorNode3 -> TorNodeNet: TorNode3, K3

[0071] 4.Client -> TorNodeNet: RS

[0072] 5.TorNodeNet -> Client: TorNode1,TorNode2,TorNode3,K1,K2,K3

[0073] 6.Client -> TorNode1: {{{H(WarningMsg), PublicChain, J, Seqi}K3p,{K3p}K3, TorNode3, J, Seqi}K23, {K23}K2, TorNode2, J, Seqi}K12, {K12}K1

[0074] 7.TorNode1 -> TorNode2: {{H(WarningMsg), PublicChain, J, Seqi}K3p,{K3p}K3, TorNode3, J, Seqi}K23, {K23}K2

[0075] 8.TorNode2 -> TorNode3:{H(WarningMsg), PublicChain, J, Seqi}K3p,{K3p}K3

[0076] 9.TorNode3 -> PublicChain: H(WarningMsg)

[0077] The security goal that needs to be met during the initialization phase is: RealMsg can be correctly transmitted to the PublicChain, which is achieved by:

[0078] 1. Flower in TorNode sends its own IP and public key through channel C1 Send to Leader to register encryption service;

[0079] 2. The client sends the message IPListRequest to the TorNode Leader through channel C2;

[0080] 3. The Leader in TorNode returns IPListResponse to the Client via channel C2;

[0081] 4. The client selects three nodes in IPListResponse based on the load balancing policy;

[0082] 5. The client uses the selected node to encrypt the data to be sent layer by layer, generates a message EncryptMsg and sends it to TorNode[IP] through the C3 channel;

[0083] 6. TorNode[IP] checks the received EncryptMsg, then {EncryptMsg}_K, generates a new EncryptMsg, and then TorNode forwards it to TorNode[IP] through channel C3;

[0084] 7. Repeat step 6) once more;

[0085] 8. TorNode[IP] checks the received EncryptMsg, then {EncryptMsg}K, generates RealMsg, and TorNode forwards RealMsg to PublicChain via channel C4;

[0086] 9. PublicChain checks received , then execute internally ;

[0087] In an embodiment of the present invention, during the collaboration release phase, after the third-party security warehouse confirms and stores the cooperation plan CooperatePlainMsg, it can be correctly uploaded to the public chain PblicChain.

[0088] The three communication channels involved in the release collaboration phase are C5, C6, and C7;

[0089] The roles involved in the release collaboration phase include: Provider, PublicChain, ThirdPartyWarehouse;

[0090] The two communication interaction messages involved in the release collaboration phase are:

[0091] 1.Provider -> PublicChain: Provider, RS

[0092] 2.PublicChain -> Provider: TaskMsg

[0093] 3.Provider -> ThirdPartyWarehouse: PublicChain, CooperatePlainMsg

[0094] 4.ThirdPartyWarehouse -> PublicChain: CooperatePlainMsg;

[0095] The implementation process is:

[0096] 1) Provider obtains TaskMsg from PublicChain through channel C5;

[0097] 2) Provider sends CooperatePlainMsg to ThirdPartyWarehouse via channel C6;

[0098] 3) rdPartyWarehouse saves the received CooperatePlainMsg and forwards it to PublicChain via the C7 channel

[0099] 4) blicChain checks the received CooperatePlainMsg and then executes it internally.

[0100] The security goal that needs to be met during the collaboration phase is that CooperatePlainMsg can be correctly transmitted to the PublicChain.

[0101] In the solution selection phase of the embodiment of the present invention, the user needs to re-select a new onion routing path through the load balancing strategy and upload the selected solution SelectedPlainMsg to the public chain.

[0102] The four communication channels involved in the scheme selection phase are C2, C5, C3, and C4;

[0103] The roles involved in the solution selection phase include Client, PublicChain, TorNodeNet, TorNode1, TorNode2, TorNode3;

[0104] The eight pieces of communication interaction information in the solution selection phase are:

[0105] 1.Client -> PublicChain : RS

[0106] 2.PublicChain -> Client: CooperatePlainMsg

[0107] 3.Client -> TorNodeNet : RS

[0108] 4.TorNodeNet -> Client: TorNode1,TorNode2,TorNode3,K1,K2,K3

[0109] 5.Client -> TorNode1: {{{H(SelectedPlainMsg), PublicChain, J, Seqi}K3p, {K3p}K3, TorNode3, J, Seqi}K23, {K23}K2, TorNode2, J, Seqi}K12, {K12}K1

[0110] 6.TorNode1 -> TorNode2: {{H(SelectedPlainMsg), PublicChain, J, Seqi}K3p, {K3p}K3', TorNode3, J, Seqi}K23, {K23}K2

[0111] 7.TorNode2 -> TorNode3:{H(SelectedPlainMsg), PublicChain, J, Seqi}K3p, {K3p}K3

[0112] 8.TorNode3 -> PublicChain: H(SelectedPlainMsg);

[0113] The implementation process is:

[0114] 1) The client obtains the CooperatePlainMsg from the PublicChain through channel C5;

[0115] 2) The client sends the message IPListRequest to the TorNode Leader through channel C2;

[0116] 3) The Leader in TorNode returns IPListResponse to the Client via channel C2;

[0117] 4) The client selects three nodes in IPListResponse based on the load balancing strategy;

[0118] 5) The client selects one of the CooperatePlainMsgs and uses the selected node to encrypt the scheme confirmation message SelectedPlainMsg layer by layer, generating the message EncryptMsg and sending it to TorNode[IP] through the C3 channel;

[0119] 6) TorNode[IP] checks the received EncryptMsg, then {EncryptMsg}_K, generates a new EncryptMsg, and then TorNode forwards it to TorNode[IP] through channel C3;

[0120] 7) Repeat step 6) once more;

[0121] 8) TorNode[IP] checks the received EncryptMsg, then {EncryptMsg}_K, generates SelectedPlainMsg, and TorNode forwards SelectedPlainMsg to PublicChain via channel C4;

[0122] 9) PublicChain verifies the received SelectedPlainMsg and then executes SelectedPlainMsg internally.

[0123] The security goal that needs to be met during the solution selection phase is that SelectedPlainMsg can be correctly transmitted to the PublicChain.

[0124] In an embodiment of the present invention, three communication links are involved in the solution release stage; among them, the public chain is used for node communication between security service providers and users and third-party security warehouses; the first alliance chain is used for alarm information sharing and key exchange between users and security service providers; the second alliance chain is used for security service providers and judicial authorities to collaborate in processing alarm information.

[0125] The four communication channels involved in the solution collaboration phase are C5, C6, C7, and C8;

[0126] The 12 communication interaction messages in the solution collaboration phase are:

[0127] 1.Provider -> PublicChain: RS

[0128] 2.PublicChain -> Provider: SelectedPlainMsg

[0129] 3.Provider -> ThirdPartyWarehouse: PublicChain, AffirmMsg

[0130] 4.ThirdPartyWarehouse -> PublicChain: AffirmMsg

[0131] 5.Client -> PublicChain: Client, RS

[0132] 6.PublicChain -> Client: AllianceChain, Provider, AffirmMsg

[0133] 7.Client -> AllianceChain: Provider, RS

[0134] 8.Channel1 -> Provider: CooperatePlainMsg

[0135] 9.Client->Channel1: WarningMsg

[0136] 10.Provider -> Channel1 : RS

[0137] 11.Channel1 -> Provider: Channel2, WarningMsg

[0138] 12.Provider -> Channel2: WarningMsg;

[0139] The implementation process is:

[0140] 1) Provider obtains SelectedPlainMsg from PublicChain through channel C5;

[0141] 2) Provider sends AffirmMsg to ThirdPartyWarehouse via channel C6;

[0142] 3) ThirdPartyWarehouse saves the received AffirmMsg and forwards it to PublicChain via the C7 channel;

[0143] 4) PublicChain checks the received AffirmMsg and then executes it internally (the public chain will);

[0144] 5) The client obtains the AffirmMsg from the PublicChain via channel C5;

[0145] 6) The Client adds the Provider to the AllianceChain channel Channel_1, allowing it to share alarm messages and exchange keys.

[0146] 7) Provider will obtain WarningMsg through channel C8;

[0147] 8) Provider will send WarningMsg to another channel Channel_2 of AllianceChain through channel C8 for collaboration.

[0148] The two security goals that need to be met during the solution collaboration phase are:

[0149] 1) AffirmMsg can be correctly transmitted to PublicChain;

[0150] 2) WarningMsg can be transmitted correctly and not be eavesdropped.

[0151] During the above-mentioned solution release phase, the information verified by the third-party security warehouse includes the address of the security service solution and the unique password generated for the user key.

[0152] The three communication channels involved in the solution release phase are: C8, C9, and C10;

[0153] The six pieces of communication interaction information during the solution release phase are:

[0154] 1.Provider -> ThirdPartyWarehouse: Solution

[0155] 2.Provider -> Channel1: Addr,Key

[0156] 3.Client -> Channel1: Client,RS

[0157] 4.Channel1 -> Client: Addr,Key

[0158] 5.Client -> ThirdPartyWarehouse: Key, SolutionRequest

[0159] 6.ThirdPartyWarehouse -> Client: SolutionResponse

[0160] The implementation process is:

[0161] 1) Provider stores the generated solution to ThirdPartyWarehouse via channel C9;

[0162] 2) Provider obtains the address Addr of the solution from the AllianceChain channel Channel_1 through channel C8 and the unique password Key generated for the Client key;

[0163] 3) The client obtains the address Addr of the solution from the AllianceChain channel Channel_1 through channel C8 and the unique password Key generated based on the client key;

[0164] 4) The Client sends a SolutionRequest to the ThirdPartyWarehouse using channel C10;

[0165] 5) ThirdPartyWarehouse verifies the SolutionRequest and returns a SolutionResponse to the Client through C10.

[0166] The four security goals that need to be met during the solution release phase are:

[0167] 1) {Addr, Key} can be transmitted correctly;

[0168] 2) SolutionRequest can be sent correctly;

[0169] 3) SolutionResponse can be transmitted correctly;

[0170] 4) The key is private.

[0171] The network security service collaboration method in the embodiment of the present invention further includes:

[0172] Service warning stage: When a user is attacked, an alert WarningMsg is generated and sent to the pipeline of the first alliance chain. It is then forwarded by the security service provider to the pipeline of the second alliance chain for collaborative processing.

[0173] In another embodiment of the present invention, the service alert stage further includes:

[0174] When a user is attacked, the user extracts a summary of the alert and sends the alert summary to the public chain through the new onion routing path obtained, achieving collaboration between the public chain and the alliance chain.

[0175] The communication channel involved in the service alert phase is C8;

[0176] The 10 communication interaction messages during the service alert phase include:

[0177] 1.Client -> AllianceChain:WarningMsg

[0178] 2.TorNode1 -> TorNodeNet: TorNode1, K1

[0179] 3.TorNode2 -> TorNodeNet: TorNode2, K2

[0180] 4.TorNode3 -> TorNodeNet: TorNode3, K3

[0181] 5.Client -> TorNodeNet: RS

[0182] 6.TorNodeNet -> Client: TorNode1,TorNode2,TorNode3,K1,K2,K3

[0183] 7.Client -> TorNode1: {{{H(WarningMsg), PublicChain, J, Seqi}K3p,{K3p}K3, TorNode3, J, Seqi}K23, {K23}K2, TorNode2, J, Seqi}K12, {K12}K1

[0184] 8.TorNode1 -> TorNode2: {{H(WarningMsg), PublicChain, J, Seqi}K3p,{K3p}K3, TorNode3, J, Seqi}K23, {K23}K2

[0185] 9.TorNode2 -> TorNode3:{H(WarningMsg), PublicChain, J, Seqi}K3p,{K3p}K3

[0186] 10.TorNode3 -> PublicChain: H(WarningMsg).

[0187] The implementation process is:

[0188] 1) When the client's service is attacked, an alarm is generated. The client reads the WarningMsg and sends it to the AllianceChain channel Channel_1 through the C8 channel;

[0189] 2) Client extracts the summary of WarningMsg and generates , Client starts the first phase;

[0190] 3) The client sends the message IPListRequest to the TorNode Leader through channel C2;

[0191] 4) The Leader in TorNode returns IPListResponse to the Client via channel C2;

[0192] 5) The client selects three nodes in IPListResponse based on the load balancing strategy;

[0193] 6) The Client uses the selected node to encrypt the M0 to be sent layer by layer, generating a message EncryptMsg and sending it to TorNode[IP] through the C3 channel;

[0194] 7) TorNode[IP] checks the received EncryptMsg, then {EncryptMsg}_K, generates a new EncryptMsg, and then TorNode forwards it to TorNode[IP] through channel C3;

[0195] 8) Repeat step 6) once more;

[0196] 9) TorNode[IP] checks the received EncryptMsg, then {EncryptMsg}K, generates RealMsg, and TorNode forwards RealMsg to PublicChain via channel C4;

[0197] 10) PublicChain verifies the received , then execute internally .

[0198] The two security goals that need to be met during the service alert phase are:

[0199] 1) WarningMsg can be transmitted correctly;

[0200] 2) RealMsg can be transmitted correctly.

[0201] In the embodiment of the present invention, experiments were conducted on the above method to verify the effectiveness of the solution.

[0202] Experimental Tool Selection: AVISPA (Automated Validation of Internet Security Protocols and Applications) is a tool for verifying Internet security protocols. It uses the High-Level Protocol Specification Language (HLPSL) to describe protocols and employs a set of in-house tools for protocol analysis. AVISPA is capable of handling large protocols and supports various security properties, including confidentiality, authentication, and integrity. Specifically, AVISPA verifies that security protocols meet predefined security properties at an abstract level. It can perform model checking on protocols in finite state spaces and theorem proving in infinite state spaces. The choice between these two approaches depends on the accuracy and efficiency requirements of the analysis.

[0203] Since the experimental scheme is too large, it is divided into six stages. The final simulation results are as follows: Figure 2-7 As shown, it can be seen that in the first three steps of the first phase, the registration of the onion node is completed. In Step 6, the user sends a message to Step 9 to realize the correct transmission of the message to the public chain; in the second phase, the cooperation plan can be correctly transmitted from the security vendor to the public chain; in the third phase, Step 1 and Step 2 realize the user pulling the cooperation plan from the blockchain, and in Step 3, the user sends a message to Step 8 to realize uploading the security service plan selected by the user to the public chain; in the fourth phase, Step 1 to Step 4 realizes the security service confirmation and uploads to the blockchain. The user determines the security service plan through Step 5 and Step 6. At the same time, the user and the security service vendor establish alliance chain channel 1 and channel 2 to facilitate subsequent work; in the fifth phase, the security service vendor sends the password to the alliance chain channel 1 and Step 2 to upload the security service plan to the third-party security warehouse. The user extracts the password through Step 3 to Step 4 and realizes the pulling of security services through Step 5 and Step 6; in the sixth phase, Step 6, the user sends a message to Step 9 to realize the correct transmission of the message to the public chain, and at the same time sends it to the alliance chain pipeline channel 1 through the channel.

[0204] Specific embodiments are used in the present invention to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core ideas. At the same time, for those skilled in the art, according to the ideas of the present invention, there may be changes in the specific implementation methods and application scopes. In summary, the contents of this specification should not be understood as limiting the present invention.

[0205] Those skilled in the art will appreciate that the embodiments described herein are intended to help readers understand the principles of the present invention, and it should be understood that the scope of protection of the present invention is not limited to such specific descriptions and embodiments. Those skilled in the art can make various other specific variations and combinations based on the technical teachings disclosed in the present invention without departing from the essence of the present invention, and such variations and combinations are still within the scope of protection of the present invention.

Claims

1. A network security service collaboration method based on a double-chain blockchain, characterized in that: The following steps are involved: Initialization phase: The user sends a request message. Based on the service information of the onion routing node, a list of active nodes is obtained. Three onion routing nodes are selected as the message link according to the load balancing strategy. The user's request message is packaged with three layers of encryption and transmitted layer by layer using the message link. The third onion routing node forwards it to the public chain. Release and collaboration phase: The security service provider obtains task information from the public blockchain, formulates a cooperation plan, and sends it to a third-party security repository that stores security services. The third-party security repository then forwards the cooperation plan to the blockchain. Solution selection phase: Users obtain a cooperation plan through the blockchain and select a security service solution. They also obtain a new onion routing path and send the selected security service solution to the public chain through the new onion routing path. Solution collaboration stage: The security service provider obtains the security service solution selected by the user through the public chain, sends it to the third-party security warehouse for inspection and confirmation, and then sends it to the public chain; the user obtains the confirmed security service solution from the public chain and adds the security service provider to the pipeline of the first alliance chain. The security service provider then establishes the pipeline of the second alliance. Solution release phase: The security service provider stores the security service solution in a third-party security warehouse and sends the security service solution address and the unique password generated for the user's key to the user through the pipeline of the first alliance chain; the user sends the address, unique password and security service solution request to the third-party security warehouse. After the third-party security warehouse completes the verification, the security service solution response is sent to the user; In the initialization phase, the process of performing three-layer encryption on the user's request information is expressed as follows: , , ; ; , , ; ; ; ; ; ; ; in, 、 and Represents the symmetric encryption keys randomly generated by the first to third onion routing nodes, 、 and Respectively represent the safety parameters 、 and Generate algorithm keys, 、 、 and Indicates the warning information Perform hash encryption processing, 、 and Represents an encrypted cipher package that encrypts a symmetric encryption key using a node's public key. 、 and Represents the public keys of the first to third onion routing nodes respectively, 、 and Represents a data packet encrypted using the previously generated symmetric encryption key. Represents the public blockchain. Indicates whether the data is uploaded to the public chain, 1 means yes, 0 means no. Indicates the The number of sequences shared between users and onion routing nodes, and Indicates the third onion routing node and the second onion routing node selected, Indicates the encrypted information generated through three layers of encryption.

2. The network security service collaboration method based on blockchain dual chain according to claim 1 is characterized in that: In the initialization phase, the request message is encrypted and packaged with three layers of encryption to obtain encrypted information sent by the user and transmitted to three onion routing nodes in sequence. During the transmission process, after each onion routing node receives the information, it uses its private key to decrypt the received information and obtain the address of the next node. Finally, the third onion routing node obtains the request information and forwards it to the public chain.

3. The network security service collaboration method based on blockchain dual chain according to claim 1 is characterized in that: In the network security service collaboration method: The public chain is used for node communication between security service providers, users, and third-party security warehouses; The first alliance chain is used for alarm information sharing and key exchange between users and security service providers; The second alliance chain is used for security service providers and judicial authorities to collaborate in processing alarm information.

4. The network security service collaboration method based on blockchain dual chain according to claim 1 is characterized in that: During the solution release phase, the information verified by the third-party security warehouse includes the address of the security service solution and the unique password generated for the user key.

5. The blockchain-based network security service collaboration method according to claim 1 is characterized in that: The network security service collaboration method further includes: Service alert stage: When a user is attacked, an alert is generated and sent to the pipeline of the first alliance chain, and then forwarded by the security service provider to the pipeline of the second alliance chain for collaborative processing.

6. The blockchain-based network security service collaboration method according to claim 5 is characterized in that: The service alert phase also includes: When a user is attacked, the user extracts a summary of the alert and sends the alert summary to the public chain through the new onion routing path obtained, achieving collaboration between the public chain and the alliance chain.

Citation Information

Patent Citations

  • Systems and methods for multi-analysis

    CN103946364A

  • Method and system for maintaining privacy and traceability of blockchain-based system

    US20210297272A1

Cited By

  • A blockchain-based secure service platform construction method

    CN122419716A