Block chain-based detrust cross-domain Internet of Things identity authentication method and system

By adopting the multi-chain architecture and cross-chain bridging technology of blockchain in IoT identity authentication, combining off-chain signature and on-chain verification, the centralized limitations and cross-domain complexity problems in IoT identity authentication are solved, and efficient and secure cross-domain identity authentication is achieved.

CN119966602APending Publication Date: 2025-05-09LANZHOU UNIV
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510110017.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-23
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

The existing IoT identity authentication technology has centralized limitations, complexity of cross-domain authentication and privacy security risks, and it is difficult to meet the needs of large-scale IoT scenarios.

Method used

Adopt blockchain-based multi-chain architecture and cross-chain bridging technology, combining off-chain signature and on-chain verification mechanisms to achieve efficient and secure cross-domain Internet of Things identity authentication.

Benefits of technology

Through decentralization, data isolation and efficient information exchange, efficient and reliable identity authentication in a multi-domain environment is achieved, and privacy protection and system performance are enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966602A_ABST
    Figure CN119966602A_ABST
Patent Text Reader

Abstract

The invention discloses a blockchain-based detrust cross-domain Internet of Things identity authentication method and system, and belongs to the technical field of Internet of Things identity authentication, and the method comprises the steps: a device submits a registration request to a management domain where the device is located, and the management domain verifies the request through an intelligent contract, and registers the device information to a local domain blockchain; a device generates an authentication request in a source domain, generates a data integrity proof through a source domain block chain, then packages the authentication request and the data integrity proof into a transaction, broadcasts the transaction to a network and waits for being packaged and chained, and after a source domain block chain light node deployed in a target domain block chain obtains the transaction, the transaction is sent to the target domain block chain. The authentication request and the integrity proof are sent to a smart contract of a target domain block chain, the target domain smart contract verifies the validity of the request and the proof, and if the verification is passed, an authorization token is generated for the device; according to the method, efficient and safe identity authentication is realized through a multi-chain architecture and a cross-chain bridging technology in combination with an off-chain signature and on-chain verification mechanism.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of Internet of Things identity authentication, and specifically to a blockchain-based trustless cross-domain Internet of Things identity authentication method and system. Background Art

[0002] Centralized authentication agencies are the main way to implement IoT identity authentication, usually through public key infrastructure (PKI) or identity-based encryption (IBC). However, with the rise of blockchain technology, its decentralized, tamper-proof and consistent characteristics are gradually being applied to IoT identity authentication.

[0003] In the public key infrastructure (PKI) authentication method, each device is issued a digital certificate by a trusted certification authority (CA), which contains the device's public key and identity. During the authentication process, the device verifies the legitimacy of the other party's certificate and completes identity confirmation through key exchange; in the identity-based encryption (IBC) authentication method, the identity of each device is directly bound to its public key, and the centralized key generation center (KGC) generates the device's private key; in the blockchain authentication method, in a single blockchain network, the device stores its identity information (such as device identification and public key) on the chain when it is registered. Authentication is completed between devices through on-chain smart contracts to ensure the authenticity and consistency of data.

[0004] With the rapid development of the Internet of Things (IoT), the demand for interconnection between devices is increasing, especially in multi-domain management scenarios, cross-domain device authentication has become a key issue. However, the existing technology has the following shortcomings: First, the limitations of centralized authentication: Traditional IoT identity authentication relies on centralized institutions (such as public key infrastructure PKI), which has the risk of single point failure, excessive trust dependence and performance bottlenecks, making it difficult to meet the needs of large-scale IoT scenarios. Second, the complexity of cross-domain authentication: The authentication protocols and technical standards adopted by different management domains are inconsistent, resulting in poor authentication interoperability and low efficiency. In addition, the device identity information may be leaked during the authentication process, posing privacy and security risks. In addition, the shortcomings of existing blockchain solutions: Blockchain technology provides new ideas for identity authentication due to its decentralized, tamper-proof and consistent characteristics. However, most existing solutions are single-chain architectures, which cannot meet the needs of data isolation and efficient cross-domain authentication in multi-domain environments.

[0005] In summary, it is difficult for existing technologies to balance decentralization, efficiency, and privacy protection. To address this problem, there is an urgent need for an identity authentication mechanism that supports trustless authentication, cross-domain data isolation, and efficient information exchange to adapt to the complexity and diversity of the multi-domain environment of the Internet of Things. Summary of the invention

[0006] In view of the problems existing in the prior art, the present invention provides a trustless cross-domain IoT identity authentication method based on blockchain, which realizes efficient and secure identity authentication through a multi-chain architecture and cross-chain bridging technology, combined with off-chain signature and on-chain verification mechanism.

[0007] The present invention is achieved through the following technical solutions: In the first aspect, the present application provides a blockchain-based trustless cross-domain IoT identity authentication method, comprising the following steps: The device submits a registration request to the management domain where it is located. The management domain verifies the request through a smart contract and registers the device information to the blockchain of the domain. The device sends an authentication request to the management domain where it is located. The blockchain verifies the authentication request. After the verification is passed, the management domain returns an authorization token. Use cross-chain bridging technology to connect the target domain and the source domain for cross-domain authentication of devices, including: Deploy the light node of the target domain blockchain on the source domain blockchain, and deploy the light node of the source domain blockchain on the target domain blockchain; The device generates an authentication request in the source domain and generates a data integrity certificate through the source domain blockchain. It then packages the authentication request and data integrity certificate into a transaction, broadcasts it to the network and waits to be packaged and uploaded to the chain. After the source domain blockchain light node deployed on the target domain blockchain obtains the transaction, it sends the authentication request and integrity certificate to the smart contract of the target domain blockchain. The target domain smart contract verifies the validity of the request and certificate. If the verification passes, an authorization token is generated for the device.

[0008] Preferably, the registration request submitted by the device to the management domain includes a device identifier, a public key, a timestamp and a random number.

[0009] Preferably, the management domain verifies the request through a smart contract including: The smart contract checks whether the device identifier is unique and verifies the legitimacy of the timestamp and random number; After verification, use the private key sk to verify the device's public key pk, identifier Sign with the random value nonce to generate a signature value; The signature value and other device information are called and stored in the blockchain through the registration function to complete the registration of the device in all management domains.

[0010] Preferably, the device sending an authentication request to the management domain where it is located includes: The management domain authenticates the device's authentication request based on the smart contract. The authentication includes identity verification, validity period verification, and signature verification. When all verifications are passed, the management domain returns an authorization token, which contains the device identification, access rights and validity period.

[0011] Preferably, the cross-domain authentication of the device by connecting the target domain with the source domain using the cross-link bridging technology includes: Use the device's private key to sign the cross-domain authentication request and generate a digital signature; The source domain blockchain generates a proof of data integrity for the cross-domain authentication request with a digital signature; The source domain blockchain records the data integrity proof of the authentication request into the ledger of the source domain blockchain through a consensus mechanism; The light node of the target domain blockchain monitors the events of the source domain blockchain, captures the authentication request and proof data, and packages them into a cross-chain message and sends them to the light node of the source domain blockchain; The light node of the source domain blockchain receives the cross-chain message and submits it to the smart contract of the target domain blockchain for verification. After the verification is passed, the target domain blockchain generates an authorization token for the device.

[0012] Preferably, the cross-domain authentication request includes a device identifier , target domain ID, random number and timestamp, and sign the serious request.

[0013] Preferably, the data integrity proof is a block header hash or Merkle root generated by the authentication request.

[0014] Preferably, the smart contract of the target domain blockchain is verified using an on-chain verification algorithm, including: verifying the legitimacy of the device signature and checking the authority configuration.

[0015] Preferably, the on-chain verification algorithm includes: According to the smart contract's verification signature function, the device signature generates a complete signature data hash, and the signature data hash generates a standard hash that conforms to the Ethereum signature. The signer's address is restored from the standard hash and the signature is verified.

[0016] In the second aspect, the present application provides a blockchain-based trustless cross-domain IoT identity authentication system, including: The registration module is used for the device to submit a registration request to the management domain where it is located. The management domain verifies the request through a smart contract and registers the device information to the blockchain of the domain; The intra-domain authentication module is used for the device to send an authentication request to the management domain where it is located. The blockchain node verifies the authentication request. After the verification is passed, the management domain returns an authorization token; The cross-domain authentication module is used to connect the target domain and the source domain using cross-chain bridging technology to perform cross-domain authentication of devices, including: Deploy the light node of the target domain blockchain on the source domain blockchain, and deploy the light node of the source domain blockchain on the target domain blockchain; The device generates an authentication request in the source domain and generates a data integrity certificate through the source domain blockchain. It then packages the authentication request and data integrity certificate into a transaction, broadcasts it to the network and waits to be packaged and uploaded to the chain. After the source domain blockchain light node deployed on the target domain blockchain obtains the transaction, it sends the authentication request and integrity certificate to the smart contract of the target domain blockchain. The target domain smart contract verifies the validity of the request and certificate. If the verification passes, an authorization token is generated for the device.

[0017] Compared with the prior art, the present invention has the following beneficial technical effects: This application provides a blockchain-based trustless cross-domain IoT identity authentication method, covering the complete process of device registration, intra-domain authentication and cross-domain authentication. Through the decentralization and consistency characteristics of blockchain, a cross-domain authentication mechanism of multi-chain architecture is proposed, combining off-chain signatures with on-chain verification to achieve efficient and reliable identity authentication. This method designs a cross-chain bridging mechanism to ensure data isolation, secure information exchange and trust transfer; at the same time, an identity authentication smart contract is developed to support unified verification, heterogeneous shielding and direct communication between devices. The experimental results verify the feasibility and high authentication efficiency of the mechanism, which is suitable for multi-domain IoT environments.

[0018] This application also proposes a blockchain-based trustless cross-domain IoT identity authentication system, an electronic device and a computer storage medium, which have all the advantages of the above-mentioned blockchain-based trustless cross-domain IoT identity authentication method. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without creative work.

[0020] Figure 1 This is a flow chart of a blockchain-based trustless cross-domain IoT identity authentication method of the present invention; Figure 2 This is a cross-domain authentication flow chart of the present invention; Figure 3 This is the domain authentication flow chart of the present invention. DETAILED DESCRIPTION

[0021] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. The components of the embodiments of the present application described and shown in the drawings here can be arranged and designed in various different configurations.

[0022] Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application for which protection is sought, but merely represents selected embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in the field without creative work are within the scope of protection of the present application.

[0023] It should be noted that similar reference numerals and letters denote similar items in the following drawings, and therefore, once an item is defined in one drawing, further definition and explanation thereof is not required in subsequent drawings.

[0024] The rapid growth of Internet of Things (IoT) devices has led to the complexity of multi-domain scenarios, and the demand for cross-domain resource sharing has increased significantly. In a multi-domain environment, device authentication is the key to security and interoperability. However, existing authentication mechanisms, such as those based on public key infrastructure (PKI) and identity-based cryptography (IBC), usually rely on centralized entities and have problems such as single point failure, trust dependence, and performance bottlenecks. In addition, although blockchain technology has the characteristics of decentralization and consistency, the existing blockchain authentication scheme based on a single-chain architecture is difficult to meet the needs of data isolation and efficient cross-domain authentication in a multi-domain environment.

[0025] In response to the above problems, this application proposes a trustless cross-domain IoT identity authentication method based on blockchain. Through multi-chain architecture and cross-chain bridging technology, combined with off-chain signature and on-chain verification mechanism, efficient and secure identity authentication is achieved, which comprehensively solves the shortcomings of the existing technology. The authentication method includes three parts: device registration, intra-domain authentication and cross-domain authentication. Intra-domain authentication mainly manages the permissions of devices in the same domain to ensure secure access to resources in the domain. In contrast, cross-domain authentication solves the problem of authenticating devices across different domains. Its goal is to maintain operational consistency and security in multiple control domains and trust environments. The specific implementation process is described in detail below.

[0026] A blockchain-based trustless cross-domain IoT identity authentication method comprises the following steps: Step 1: The device submits a registration request to the management domain where it is located. The management domain verifies the request through a smart contract and registers the device information to the blockchain of the domain. Step 2: The device sends an authentication request to the management domain where it is located. The blockchain node verifies the authentication request. After the verification is passed, the management domain returns an authorization token. Step 3: Use cross-chain bridging technology to connect the target domain and the source domain to perform cross-domain authentication of the device, including: Deploy the light node of the target domain blockchain on the source domain blockchain, and deploy the light node of the source domain blockchain on the target domain blockchain; The device generates an authentication request in the source domain and generates a data integrity certificate through the source domain blockchain. It then packages the authentication request and certificate into a transaction, broadcasts it to the network, and waits to be packaged and uploaded to the chain. After the source domain blockchain light node deployed in the target domain obtains the transaction, it sends the authentication request and integrity certificate to the smart contract of the target domain blockchain. The target domain smart contract verifies the validity of the request and certificate. If the verification is successful, an authorization token is generated for the device, allowing the device to perform related operations in the target domain, thereby completing the cross-domain authentication and authorization process.

[0027] It is important to note that: The source domain refers to the management domain where the device is located, which is responsible for generating authentication requests and data integrity proofs, and transmitting them across chains through the source domain cross-chain bridge node chain.

[0028] The target domain is the authentication management domain, which is responsible for deploying a light node of the source chain on the chain to capture transaction events from the source domain and execute identity authentication logic through smart contracts.

[0029] During the entire cross-domain process, the smart contracts of the source domain and the target domain are responsible for generating authentication proofs and performing authentication verification respectively, ensuring the integrity and security of cross-domain authentication.

[0030] Example 1 See also Figure 1-3 , a trustless cross-domain IoT identity authentication method based on blockchain, comprising the following steps: S100: The target device registers with the management domain.

[0031] 1) The device submits a registration request to the domain administrator of its management domain, including the following information: device identifier, public key, timestamp, and random number.

[0032] 2) The domain administrator calls the smart contract to verify the registration request, including checking whether the device identifier is unique and verifying the legitimacy of the timestamp and random number.

[0033] 3) After verification, the domain administrator uses the private key sk to verify the device's public key pk, identifier Sign with the random value nonce to generate a signature value (pk|| ).

[0034] 4) The signature and other device information are stored on the blockchain by calling the registration function to complete the registration of the device in all management domains.

[0035] Other device information: info=( , name, pk, domain, validity, nonce) Among them, name is the name of the device, pk is the public key of the device, domain is the domain name registered by the device, validity is the validity period of the device, and nonce is a unique random value generated for each device.

[0036] The method for generating the public key and private key of the device is as follows: First, a base point g is selected from the elliptic curve group, and a 256-bit large integer α is randomly selected as a random parameter during the private key generation process. The device public key component is calculated based on the base point g and the random parameter. ; Then, use the device's identifier and the device public key component , base point g and system public key As input. Using the formula Generate hash value h1, using the formula ∗x(mod p) computes the device's partial private key The device then randomly selects a 256-bit integer Compute the other part of the device's public key = p. Finally, the public key pk of the device is given by ( , ), the private key sk consists of ( , The generated public key pk is used for authentication between devices, while the private key sk is stored locally for signing and decryption operations.

[0037] S200: The target device authenticates its authority to the management domain where it is located.

[0038] The device initiates an authentication request for the management domain in which it resides. The request content contains the identifier of the device. When the domain administrator receives the request, it will request the blockchain node to authenticate the device. The blockchain node authenticates the device according to the smart contract as follows: Authentication: Checks whether the device identifier is registered.

[0039] Permission verification: Checks whether the device has permission to access the target resource.

[0040] Validity Verification: Check whether the device has expired.

[0041] Signature verification: Use the device's public key to verify the legitimacy of the signature.

[0042] When all verifications are passed, the management domain returns an authorization token (Token), which contains the device identification, access rights and validity period.

[0043] S300: The target device performs cross-domain authentication on the target domain.

[0044] 1) Generate a cross-domain authentication request for the target device, which includes a device identifier , target domain identifier, random number and timestamp, and use the device's private key to sign the authentication request to generate a digital signature, Signature = Sign(sk, Hash( , TargetDomain, Nonce, Timestamp)).

[0045] Device identifier ): Device unique identifier; Target domain identifier (TargetDomain): identifies the target domain; Nonce: ensures the uniqueness of the request; Timestamp: Identifies the time when the request was generated to prevent replay attacks.

[0046] 2) The source domain blockchain stores the identity information and authentication request of the target device, and generates a block header hash or Merkle root for the authentication request as proof of data integrity.

[0047] 3) Deploy the light node of the target domain blockchain on the source domain blockchain, and deploy the light node of the source domain blockchain on the target domain blockchain; 4) The source domain blockchain records the data integrity proof of the authentication request into the ledger of the source domain blockchain through a consensus mechanism.

[0048] 5) The light node of the target domain blockchain monitors the events of the source domain blockchain, captures the authentication request and proof data, and packages them into a cross-chain message and sends them to the light node of the source domain blockchain.

[0049] 6) The light node of the source domain blockchain receives the cross-chain message and submits it to the smart contract of the target domain blockchain for verification. After the verification is passed, the target domain blockchain generates an authorization token for the device.

[0050] Smart contracts are deployed on the blockchain of the source and target domains to generate authentication proofs and execute authentication logic, respectively.

[0051] The smart contract uses an on-chain signature verification algorithm to verify the identity and permissions of the device, including: Verify the legitimacy of the device signature to ensure that the data has not been tampered with.

[0052] Check the permission configuration to confirm whether the device has access rights to the target resources.

[0053] If the identity and permission verification is passed, the target domain smart contract generates an authorization token, which contains the following information: device identification, target resource identification, and authorization time range.

[0054] The on-chain signature verification algorithm is used to verify the legitimacy of the device signature, including the following steps: 6.1) Generate a complete signature data hash (getMessageHash) for the device signature based on the smart contract’s verification signature function.

[0055] A signature verification function verify(address,id,signature) is written in the smart contract. The signature verification function is used to calculate the device signature to generate a complete signature data hash (messageHash).

[0056] The device signature includes the signer address, device ID and device signature, and the device signature is a random value.

[0057] The signature data hash ensures the uniqueness of the input message and prevents the message content from being tampered with.

[0058] 6.2) Hash the signature data to generate a standard hash that complies with the Ethereum signature.

[0059] Use getEthSignedMessageHash(messageHash) to hash the signature data to generate a standard hash (ethHash) that conforms to the Ethereum signature.

[0060] 6.3) Use the recoverSigner(ethHash, signature) function to recover the signer’s address in the standard hash. If the address is the same as the incoming signer address adderss, the signature verification is successful.

[0061] For the recoverSigner() function, two parameters are passed in. The first parameter is the generated standard hash, and the second parameter is the device signature value. Then the signature parsing function splitSignature(signature) is called to split the signature value and extract the three key parts of the signature (r, s, v). Finally, ecrecover(ethHash, v, r, s) is called to recover the signer address. If this signer address is consistent with the passed-in signer address, the signature verification is successful.

[0062] Among them, r and s are the two elliptic curve parameters of the signature, and V is the recovery factor, which is used to distinguish the two possible solutions of the signature.

[0063] The logic for parsing the signature uses inline assembly to efficiently extract these values ​​from the bytes type, check that the signature length is 65 bytes (the standard signature length), and perform a validity correction on the recovery factor v (if it is less than 27, add 27).

[0064] This application uses off-chain signature verification. On-chain signatures have the following advantages: 1. Reduce the computation and storage costs of on-chain operations; computational resources (such as smart contract execution) and storage resources on the blockchain are very expensive, and generating signatures directly on the chain consumes a lot of gas fees. Signature generation is a computationally intensive operation, and signing off-chain can make full use of the computing power of the user's local device or server to avoid occupying resources on the chain. The signature verification process is relatively simple, and the smart contract only needs to call the ecrecover method to verify whether the signature is valid, and the gas consumption is low.

[0065] 2. Improve system performance; Efficiency of signature generation: Off-chain signatures can be completed quickly by user devices or servers without waiting for transaction confirmation on the blockchain, avoiding the extra waiting time caused by performance bottlenecks (such as low throughput and high latency) on the blockchain.

[0066] 3. Enhanced privacy protection: When generating signatures off-chain, the user's private key will not leave the local device, avoiding the risk of private key leakage. The signature data itself can be controlled by the user whether to be made public. The chain only verifies whether the signature is valid, without disclosing the private key or specific signature details.

[0067] Based on the above blockchain-based trustless cross-domain IoT identity authentication method, correspondingly, the present application also provides a blockchain-based trustless cross-domain IoT identity authentication system, which may include: The registration module is used for the device to submit a registration request to the management domain where it is located. The management domain verifies the request through a smart contract and registers the device information to the blockchain of the domain; The intra-domain authentication module is used for the device to send an authentication request to the management domain where it is located. The blockchain node verifies the authentication request. After the verification is passed, the management domain returns an authorization token; The cross-domain authentication module is used to connect the target domain and the source domain using cross-chain bridging technology to perform cross-domain authentication of devices, including: Deploy the light node of the target domain blockchain on the source domain blockchain, and deploy the light node of the source domain blockchain on the target domain blockchain; The device generates a cross-domain authentication request, the source domain blockchain link generates a data integrity certificate for the authentication request, the light node of the target domain blockchain sends the authentication request and the data integrity certificate to the chain light node of the source domain blockchain through the consensus mechanism, the chain light node of the source domain blockchain sends the authentication request and the data integrity certificate to the target domain blockchain, the smart contract of the target domain blockchain verifies the validity of the authentication request and its data integrity certificate, after the verification is passed, the target domain blockchain generates an authorization token for the device.

[0068] Compared with the existing technology, the authentication method of this application has the following advantages: 1. Trust architecture, decentralized authentication: This invention uses the decentralized characteristics of blockchain technology to eliminate the reliance on centralized trusted entities. Each management domain runs an independent alliance chain, and the domains are interconnected through cross-chain bridges. The failure of any single node will not affect the overall authentication process. The authentication data is maintained by a distributed ledger, and the authentication logic is executed using smart contracts to ensure that the authentication process is open and transparent.

[0069] 2. Adopt cross-chain bridge technology: Connect the source domain and the target domain through a cross-chain bridge to solve the problems of data isolation and low transmission efficiency. Enhance the interoperability and flexibility of the system.

[0070] 3. Privacy protection: This invention combines off-chain signatures with on-chain verification mechanisms during the authentication process to protect the privacy of identity data. Sensitive information such as device identification and public keys are encrypted during storage and transmission, and can only be decrypted and viewed by authorized parties. A random number and timestamp are added to the authentication request to ensure that each request is unique, preventing attackers from reusing historical authentication data.

[0071] 4. Multi-chain architecture: The present invention adopts a multi-chain architecture to support data isolation and authentication efficiency improvement in cross-domain scenarios. Each management domain runs an independent alliance chain, reducing the dependence on a single main chain.

[0072] 5. Designed a unified identity authentication smart contract: Provides a standardized interface that adapts to cross-domain heterogeneous scenarios. This automated identity authentication reduces reliance on third-party trusted entities.

[0073] It should be noted that in the several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of each module is only a logical function division. There may be other division methods in actual implementation. For example, multiple modules can be combined or integrated into another device, or some features can be ignored or not executed. The module described as a separate component may or may not be physically separated. The component displayed as a module may be a physical unit or multiple physical units, that is, it may be located in one place, or it may be distributed in multiple different places. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment.

[0074] In addition, each module in each embodiment of the present invention may be integrated into a processing unit, each module may exist physically separately, or two or more modules may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of a software functional unit.

[0075] An electronic device provided in an embodiment of the present application includes a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the steps of the blockchain-based trustless cross-domain Internet of Things identity authentication method described in any of the above embodiments are implemented.

[0076] Another electronic device provided in the embodiment of the present application may also include: an input port connected to the processor, used to transmit multimodal data collected by an external acquisition device to the processor; and a display unit connected to the processor, used to display the processing results of the processor to the outside world; a communication module connected to the processor, used to realize the communication between the electronic device and the outside world. The display unit can be a display panel, a laser scanning display, etc.; the communication mode adopted by the communication module includes but is not limited to mobile high-definition link technology (HML), universal serial bus (USB), high-definition multimedia interface (HDMI), wireless connection (including wireless fidelity technology (WiFi), Bluetooth communication technology, low-power Bluetooth communication technology, and communication technology based on IEEE802.11s).

[0077] An embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the steps of the blockchain-based trustless cross-domain Internet of Things identity authentication method described in any of the above embodiments are implemented.

[0078] For the description of the relevant parts of the blockchain-based trustless cross-domain IoT identity authentication system, electronic device, and computer-readable storage medium provided in the embodiments of the present application, please refer to the detailed description of the corresponding parts in the blockchain-based trustless cross-domain IoT identity authentication method provided in the embodiments of the present application, which will not be repeated here. In addition, the parts of the above-mentioned technical solutions provided in the embodiments of the present application that are consistent with the corresponding technical solutions in the prior art are not described in detail to avoid excessive elaboration.

[0079] The above contents are only for explaining the technical idea of ​​the present invention and cannot be used to limit the protection scope of the present invention. Any changes made on the basis of the technical solution in accordance with the technical idea proposed by the present invention shall fall within the protection scope of the claims of the present invention.

Claims

1. A trustless cross-domain IoT identity authentication method based on blockchain, characterized in that: The following steps are involved: The device submits a registration request to the management domain where it is located. The management domain verifies the request through a smart contract and registers the device information to the blockchain of the domain. The device sends an authentication request to the management domain where it is located. The blockchain verifies the authentication request. After the verification is passed, the management domain returns an authorization token. Use cross-chain bridging technology to connect the target domain and the source domain for cross-domain authentication of devices, including: Deploy the light node of the target domain blockchain on the source domain blockchain, and deploy the light node of the source domain blockchain on the target domain blockchain; The device generates an authentication request in the source domain and generates a data integrity certificate through the source domain blockchain. It then packages the authentication request and data integrity certificate into a transaction, broadcasts it to the network and waits to be packaged and uploaded to the chain. After the source domain blockchain light node deployed on the target domain blockchain obtains the transaction, it sends the authentication request and integrity certificate to the smart contract of the target domain blockchain. The target domain smart contract verifies the validity of the request and certificate. If the verification passes, an authorization token is generated for the device.

2. According to claim 1, a blockchain-based trustless cross-domain Internet of Things identity authentication method is characterized in that: The registration request submitted by the device to the management domain includes a device identifier, a public key, a timestamp and a random number.

3. According to claim 1, a blockchain-based trustless cross-domain IoT identity authentication method is characterized in that: The management domain verifies the request through a smart contract including: The smart contract checks whether the device identifier is unique and verifies the legitimacy of the timestamp and random number; After verification, use the private key sk to verify the public key pk of the device, the identifier Sign with the random value nonce to generate a signature value; The signature value and other device information are called and stored in the blockchain through the registration function to complete the registration of the device in all management domains.

4. According to claim 1, a blockchain-based trustless cross-domain IoT identity authentication method is characterized in that: The device sending an authentication request to the management domain where it is located includes: The management domain authenticates the device's authentication request based on the smart contract. The authentication includes identity verification, validity period verification, and signature verification. When all verifications are passed, the management domain returns an authorization token, which contains the device identification, access rights and validity period.

5. According to claim 1, a blockchain-based trustless cross-domain IoT identity authentication method is characterized in that: The cross-domain authentication of the device by connecting the target domain and the source domain using the cross-chain bridging technology includes: Use the device's private key to sign the cross-domain authentication request and generate a digital signature; The source domain blockchain generates a proof of data integrity for the cross-domain authentication request with a digital signature; The source domain blockchain records the data integrity proof of the authentication request into the ledger of the source domain blockchain through a consensus mechanism; The light node of the target domain blockchain monitors the events of the source domain blockchain, captures the authentication request and proof data, and packages them into a cross-chain message and sends them to the light node of the source domain blockchain; The light node of the source domain blockchain receives the cross-chain message and submits it to the smart contract of the target domain blockchain for verification. After the verification is passed, the target domain blockchain generates an authorization token for the device.

6. According to claim 5, a blockchain-based trustless cross-domain IoT identity authentication method is characterized in that: The cross-domain authentication request includes a device identifier , target domain ID, random number and timestamp, and sign the serious request.

7. According to claim 5, a blockchain-based trustless cross-domain IoT identity authentication method is characterized in that: The data integrity proof is a block header hash or Merkle root generated by the authentication request.

8. According to claim 5, a blockchain-based trustless cross-domain IoT identity authentication method is characterized in that: The smart contract of the target domain blockchain is verified using an on-chain verification algorithm, including: verifying the legitimacy of the device signature and checking the permission configuration.

9. According to claim 8, a blockchain-based trustless cross-domain IoT identity authentication method is characterized in that: The on-chain verification algorithm includes: According to the verification signature function of the smart contract, the device signature generates a complete signature data hash, and the signature data hash generates a standard hash that conforms to the Ethereum signature. The signer's address is restored from the standard hash and the signature is verified.

10. A trustless cross-domain IoT identity authentication system based on blockchain, characterized in that: include: The registration module is used for the device to submit a registration request to the management domain where it is located. The management domain verifies the request through a smart contract and registers the device information to the blockchain of the domain; The intra-domain authentication module is used for the device to send an authentication request to the management domain where it is located. The blockchain node verifies the authentication request. After the verification is passed, the management domain returns an authorization token; The cross-domain authentication module is used to connect the target domain and the source domain using cross-chain bridging technology to perform cross-domain authentication of devices, including: Deploy the light node of the target domain blockchain on the source domain blockchain, and deploy the light node of the source domain blockchain on the target domain blockchain; The device generates an authentication request in the source domain and generates a data integrity certificate through the source domain blockchain. It then packages the authentication request and data integrity certificate into a transaction, broadcasts it to the network and waits to be packaged and uploaded to the chain. After the source domain blockchain light node deployed on the target domain blockchain obtains the transaction, it sends the authentication request and integrity certificate to the smart contract of the target domain blockchain. The target domain smart contract verifies the validity of the request and certificate. If the verification passes, an authorization token is generated for the device.

Citation Information

Patent Citations

  • Multi-layer blockchain cross-domain authentication method in Internet of Things application scene

    CN112637189A

  • Cross-chain method and system for realizing multi-chain intercommunication

    CN113114759A

  • Block chain certificateless identity authentication scheme in cloud computing environment

    CN114154125A

  • Internet of Things equipment cross-domain authentication method and system based on cross-chain technology

    CN117997640A

  • Consortium blockchain consensus identity authentication method

    WO2023115850A1