Security authentication and authority management method and system based on block chain
By building a blockchain distributed storage network on the cloud computing center and using artificial intelligence algorithms to build an automatic security authentication and access permission generation model, the problems of low authentication reliability, low security level, low security efficiency and lack of dynamic permission management in existing data security technologies are solved, and efficient and reliable security authentication and flexible permission management are achieved.
Patent Information
- Application Number
- CN202510141364.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-08
- Publication Date
- 2025-05-09
AI Technical Summary
Existing data security technologies have problems such as low authentication reliability, low security level, low security certification efficiency and lack of dynamic permission management.
Using blockchain-based security authentication and permission management methods, a distributed storage network is built using blockchain technology through the cloud computing center, and an automatic security authentication model and access permission generation model are used to build an automated security authentication model to realize automated security authentication and dynamic permission management.
It significantly improves the reliability of the authentication process and data integrity, reduces the risk of misidentification and misidentification, improves the overall reliability and efficiency of the authentication system, and realizes flexible permission management and rapid response to permission changes.
Smart Images

Figure CN119966729A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data management, and specifically relates to a blockchain-based security authentication and authority management method and system. Background Art
[0002] In today's digital age, data has become the core asset of enterprises. However, data leakage, identity theft, unauthorized access and other network security incidents occur frequently, bringing huge risks to individuals and enterprises. With data security receiving increasing attention, user identity security authentication and permission management have become important measures to ensure data security.
[0003] Existing data security technologies have the following defects:
[0004] 1) Low authentication reliability: With the development and advancement of attack technologies, the authentication reliability of existing technologies is low, and there are problems of misidentification (incorrect acceptance of unauthorized users) and missed identification (incorrect rejection of authorized users), which affects user experience and system security, and causes user information to be leaked due to system vulnerabilities, internal leaks or external attacks;
[0005] 2) Low security level: The existing technology relies on the authentication system of the centralized server, which may have the risk of single point failure. Once the central server is breached, the security of the entire system will be threatened, and the security level is low;
[0006] 3) Low efficiency of security authentication: Most existing technologies use a simple rule-based security authentication process, which requires traversing the user database to complete user identity authentication. This method is inefficient and cannot adapt to large-scale data application scenarios;
[0007] 4) Lack of dynamic permission management. Static permission management may be too centralized, resulting in the failure of the permission control of the entire system once the permission holder's account is compromised. Permission configuration may be too complex or not flexible enough, resulting in improper permission allocation. Users may obtain permissions beyond their responsibilities. Therefore, there is a lack of dynamic permission management to solve the above problems. Summary of the invention
[0008] In order to solve the problems of low authentication reliability, low security level, low security authentication efficiency and lack of dynamic authority management in the prior art, the purpose of the present invention is to provide a blockchain-based security authentication and authority management method and system.
[0009] The technical solution adopted by the present invention is:
[0010] A blockchain-based security authentication and authority management method comprises the following steps:
[0011] The cloud computing center uses blockchain technology to build a distributed storage network and uses artificial intelligence algorithms to build automatic security authentication models and access rights generation models;
[0012] An information collection device collects real-time user information data of users, and encrypts the real-time user information data and uploads it to a cloud computing center;
[0013] The cloud computing center uses an automatic security authentication model to perform automatic security authentication based on real-time user information data and obtains the user's real-time security authentication result;
[0014] The cloud computing center, if the real-time security authentication result is that the security authentication is passed, proceeds to the next step, otherwise, returns a real-time security authentication failure signal and ends the security authentication;
[0015] The cloud computing center generates access rights based on real-time user information data using an access rights generation model to obtain real-time access rights data;
[0016] The cloud computing center uses a distributed storage network to distribute the user's real-time user information data and real-time access permission data.
[0017] Furthermore, the cloud computing center uses blockchain technology to build a distributed storage network, and uses artificial intelligence algorithms to build an automatic security authentication model and access rights generation model, including the following steps:
[0018] The cloud computing center performs function allocation and hierarchical management on all data nodes in distributed connections to obtain a distributed storage network;
[0019] Based on some historical user information data, a multimodal fusion algorithm is used to build an automatic security authentication model and obtain some historical multimodal fusion features;
[0020] Based on several historical multimodal fusion features, a deep learning algorithm is used to build an access rights generation model.
[0021] Furthermore, the cloud computing center performs function allocation and hierarchical management on all data nodes of the distributed connection to obtain a distributed storage network, including the following steps:
[0022] The cloud computing center initializes all data nodes to obtain a number of initialized data nodes, and performs distributed connections to obtain a number of distributed connected data nodes;
[0023] Collect the basic node parameters of each data node of the distributed connection, and perform clustering processing on all data nodes according to several basic node parameters to obtain several clustering centers and corresponding clustering clusters;
[0024] Set a corresponding functional label for each cluster center, and spread the functional label of the cluster center to the corresponding cluster cluster;
[0025] Several clusters are managed in layers to obtain several functional layers, and a distributed storage network is obtained based on the several functional layers.
[0026] Furthermore, the basic node parameters of each data node of the distributed connection are collected, and according to the basic node parameters, all data nodes are clustered to obtain a number of cluster centers and corresponding cluster clusters, including the following steps:
[0027] Collect the basic node parameters of each data node of the distributed connection, and build a similarity matrix of the data nodes based on several basic node parameters;
[0028] According to the similarity matrix, the objective function is set, and based on the objective function, the ISSA algorithm is used to generate several initial cluster centers;
[0029] According to the basic node parameters of the data nodes, the AP clustering algorithm is used to obtain the initial attraction information and initial belonging information of each data node to each initial cluster center;
[0030] Introduce an iterative attenuation coefficient, update the attraction information and belonging information of all nodes, and obtain the updated attraction information and updated belonging information of each data node to each initial cluster center;
[0031] According to the updated attraction information and the updated belonging information, several initial cluster centers are updated to obtain several updated cluster centers;
[0032] Repeat the above cluster center update steps. If the cluster center does not change, output several final cluster centers.
[0033] According to the basic parameters of the data nodes, the similarity between each data node and several final cluster centers is obtained;
[0034] According to the similarity, all data nodes are grouped to obtain the clusters belonging to each final cluster center.
[0035] Furthermore, the functional layer includes a storage layer with several storage nodes, a consensus layer with several consensus nodes, a confirmation layer with several confirmation nodes, a supervision layer with several supervision nodes, a transaction layer with several transaction nodes, an intermediary layer with several intermediary nodes, a guarantee layer with several guarantee nodes, and a crawling layer with several crawling nodes.
[0036] Furthermore, according to the similarity matrix, an objective function is set, and based on the objective function, an ISSA algorithm is used to generate several initial cluster centers, including the following steps:
[0037] According to the similarity matrix, an objective function is set, the objective function is used as the fitness function of the ISSA algorithm, and the ISSA algorithm parameters of the ISSA algorithm are set;
[0038] The positions of several initial cluster centers are encoded as individual vectors of ISSA individuals. According to the ISSA algorithm parameters and fitness function, several ISSA individuals are iteratively optimized and the best individual is retained.
[0039] The individual vector of the optimal individual is decoded to obtain the optimal number of initial cluster centers and the position of each initial cluster center.
[0040] Furthermore, the historical user information data includes the user's historical identity information data, historical user behavior data, and historical user biometric image data;
[0041] The real-time user information data includes the user's real-time identity information data, real-time user behavior data, and real-time user biometric image data.
[0042] Furthermore, the automatic security authentication model is constructed based on the CNN-LSTM-Attention-DBN algorithm, and the perception model includes an image feature extraction module constructed based on the CNN algorithm, a sequence feature extraction module constructed based on the LSTM algorithm, a behavior feature extraction module constructed based on the LSTM algorithm, an attention weight module constructed based on the Attention mechanism, and an automatic security authentication module constructed based on the DBN algorithm. The image feature extraction module, the sequence feature extraction module, and the behavior feature extraction module are all connected to the attention weight module, and the attention weight module is connected to the automatic security authentication module;
[0043] The access permission generation model is constructed based on the RF-MLP algorithm, and the access permission generation model includes a key feature screening module constructed based on the RF algorithm and an access permission generation module constructed based on the MLP algorithm.
[0044] Furthermore, the cloud computing center uses a distributed storage network to perform distributed storage of the user's real-time user information data and real-time access permission data, including the following steps:
[0045] The cloud computing center sends the user's real-time user information data and real-time access permission data to the transaction layer of the distributed storage network;
[0046] Use any transaction node in the transaction layer to generate real-time transaction data based on the user's real-time user information data and real-time access permission data;
[0047] Use the consensus layer to reach consensus on real-time transaction data. If the consensus is successful, a real-time consensus success message is generated;
[0048] Use the confirmation layer to confirm the real-time consensus success information. If the consensus confirmation is successful, use the consensus node that receives the real-time transaction data to convert the real-time transaction data into a real-time data block;
[0049] Use any storage node in the storage layer to distribute the real-time data blocks and update the distributed ledger of the distributed storage network.
[0050] A blockchain-based security authentication and authority management system is used to implement a security authentication and authority management method. The system includes a cloud computing center and an information collection device. The information collection device is communicatively connected to the cloud computing center. The cloud computing center includes a model building unit, an automatic security authentication unit, a failure signal generating unit, an access authority generating unit and a distributed storage unit connected in sequence.
[0051] The beneficial effects of the present invention are:
[0052] The present invention provides a blockchain-based security authentication and authority management method and system. By combining the tamper-proof characteristics of blockchain technology, the reliability of the authentication process and the integrity of data are ensured, and the risks of misidentification and missed identification are significantly reduced. The distributed storage technology of blockchain is used to achieve decentralized authentication, reduce the risk of single point failure, and thus improve the overall reliability of the authentication system. Through the application of blockchain technology, the risk of single point failure brought by centralized servers is eliminated, and the entire system can still maintain safe operation even when some nodes are attacked. The automatic security authentication model constructed by using artificial intelligence algorithm can perform automatic security authentication according to real-time user information data collected in real time, simplify the security authentication process, improve the efficiency of security authentication, and adapt to the application scenario of large-scale data. The constructed access authority generation model realizes a dynamic authority management mechanism, which can automatically adjust the authority according to the identity information and user behavior in the user's real-time user information data, ensure the reasonable allocation and effective control of the authority, and the dynamic authority management makes the authority configuration more flexible, can quickly respond to the authority change requirements, and effectively prevent the abuse of authority and unauthorized access.
[0053] Other beneficial effects of the present invention will be further described in the specific embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] Figure 1 It is a flowchart of the security authentication and authority management method based on blockchain in the present invention.
[0055] Figure 2 It is a structural block diagram of the security authentication and authority management system based on blockchain in the present invention. DETAILED DESCRIPTION
[0056] The present invention will be further explained below in conjunction with the accompanying drawings and specific embodiments.
[0057] Embodiment 1:
[0058] like Figure 1 As shown, this embodiment provides a blockchain-based security authentication and authority management method, comprising the following steps:
[0059] S1: Cloud computing center uses blockchain technology to build a distributed storage network, and uses artificial intelligence algorithms to build an automatic security authentication model and access rights generation model, including the following steps:
[0060] S1-1: The cloud computing center performs function allocation and hierarchical management on all data nodes in distributed connections to obtain a distributed storage network, including the following steps:
[0061] S1-1-1: The cloud computing center initializes all data nodes to obtain a number of initialized data nodes, and performs distributed connections to obtain a number of distributed connected data nodes; ensuring that all nodes are in a consistent state at the beginning to facilitate subsequent management and maintenance. Distributed connections provide a reliable network foundation for data storage and transmission;
[0062] S1-1-2: Collect the basic node parameters of each data node of the distributed connection, and cluster all data nodes according to several basic node parameters to obtain several cluster centers and corresponding cluster clusters. Through clustering, reasonable function allocation and hierarchical management can be carried out according to the characteristics of the nodes, which is convenient for realizing homogeneous management. The steps include the following:
[0063] S1-1-2-1: Collect the basic node parameters of each data node of the distributed connection, and build a similarity matrix of the data nodes based on several basic node parameters, including processing capacity parameters, storage capacity parameters, network bandwidth parameters, location parameters, etc. The similarity matrix provides quantitative inter-node relationships for subsequent clustering, which helps to classify more accurately;
[0064] S1-1-2-2: According to the similarity matrix, set the objective function, and based on the objective function, use the Improved Sparrow Search Algorithm (ISSA) algorithm to generate several initial cluster centers. The ISSA algorithm can find a more reasonable initial cluster center and provide a good starting point for clustering. The steps include:
[0065] S1-1-2-2-1: according to the similarity matrix, set the objective function, use the objective function as the fitness function of the ISSA algorithm, and set the ISSA algorithm parameters of the ISSA algorithm;
[0066] The formula of the fitness function is:
[0067]
[0068] In the formula, f(X c ) is the ISSA entity X c The fitness function of the ISSA individual X c Separation calculation function; S is the similarity matrix; ψ is the smallest real number that is not 0; α is the weight coefficient; X c is the ISSA individual variable; c is the ISSA individual indicator;
[0069] S1-1-2-2-2: Encode the positions of several initial cluster centers into individual vectors of ISSA individuals, iterate and optimize several ISSA individuals according to ISSA algorithm parameters and fitness function, and retain the best individual, including the following steps:
[0070] S1-1-2-2-2-1: Encode the positions of several initial cluster centers as individual vectors of ISSA individuals, use the Circle chaotic mapping sequence to initialize, and obtain the initial ISSA population, which includes several initial ISSA individuals;
[0071] The formula is:
[0072]
[0073] Where X' c is the initial ISSA individual of the Circle chaos map; X c * is the randomly generated initial ISSA individual; c is the ISSA individual indicator; mod(*) is the remainder function;
[0074] S1-1-2-2-2-2: Use the fitness function to obtain the real-time fitness value of each initial ISSA individual in the initial ISSA population;
[0075] S1-1-2-2-2-3: Sort the initial ISSA individuals according to their fitness values to obtain the initial discoverers, initial joiners and initial predators;
[0076] S1-1-2-2-2-4: update the initial ISSA population to obtain an updated ISSA population; the updated ISSA population includes updated discoverers, updated joiners and updated predators;
[0077] The update formula of the discoverer is:
[0078]
[0079] In the formula, are the cth discoverer ISSA individuals in the t+1th and tth iterations respectively; t max is the maximum number of iterations; ξ is a random number between 0 and 1; Q is a normally distributed random number; L is a 1×D matrix whose elements are all 1; R2 is the warning value; ST is the safety threshold;
[0080] The update formula for the joiner is:
[0081]
[0082] In the formula, are the cth joiner ISSA individuals in the t+1th and tth iterations respectively; The best position for the exposed person to occupy; is the current worst position; ξ is a random number between 0 and 1; L is a 1×D matrix whose elements are all 1 or -1; c is the ISSA individual indicator; h is the total number of ISSA individuals; A + To update the parameters;
[0083] The update formula of the predator is:
[0084]
[0085] In the formula, are the cth predator ISSA individuals of the t+1th and tth iterations respectively; δ is the step-size control parameter, and δ=a"·γ', a" is the convergence factor, and γ' is a non-zero positive real number for step-size control; is the current best position; f c 、f g 、f w are the current, best and worst fitness of ISSA individuals respectively;
[0086]
[0087] Where a" is the convergence factor; tanh(*) is the hyperbolic tangent function; a max 、a min are the maximum and minimum values of the convergence factor, respectively; λ' is the decreasing rate parameter, k" is the decreasing period parameter, λ=-2π, k"=π;
[0088] S1-1-2-2-2-5: Use the dynamic reverse learning algorithm to perform dynamic reverse learning on the updated ISSA population to generate a dynamic reverse ISSA population;
[0089] The formula is:
[0090]
[0091] In the formula, is the dynamic reverse ISSA individual; γ * is the decreasing inertia coefficient; ub is the upper limit of the search space in the constraint condition; lb is the lower limit of the search space in the constraint condition; For the updated ISSA entity;
[0092] S1-1-2-2-2-6: According to the fitness function, calculate the real-time fitness values of all ISSA individuals in the updated ISSA population and the dynamically reversed ISSA population, and take the ISSA individual with the minimum real-time fitness value as the optimal individual;
[0093] S1-1-2-2-2-7: If the number of iterations of the algorithm reaches the maximum number of iterations or the fitness value of the optimal individual meets the requirements, the optimal individual is output;
[0094] S1-1-2-2-3: Decode the individual vector of the optimal individual to obtain the optimal number of initial cluster centers and the position of each initial cluster center;
[0095] S1-1-2-3: According to the basic node parameters of the data nodes, the Affinity-Propagation (AP) clustering algorithm is used to obtain the initial attraction information and initial affiliation information of each data node to each initial cluster center; the initial cluster affiliation is provided for each node, which provides a basis for subsequent iterations;
[0096] The formula for attractiveness information is:
[0097]
[0098] In the formula, r t (i,k),r t+1 (i, k) is the initial attraction information of node k to node i at iterations t and t+1; a t (i, k) is the initial belonging information of node k to node i at iteration number t; s(i, k) is the similarity of node k as the cluster center of node i; i, j and k are all node indicators;
[0099] The formula for attribution information is:
[0100]
[0101] In the formula, r t+1 (k, k) is the initial belonging information of node k to node k at iteration number t+1; ∑ j≠i,k max{r t+1 (j,k),0} is the initial attribution information of node k to other cluster centers except node i when the iteration number is t+1;
[0102] S1-1-2-4: Introduce an iterative attenuation coefficient to update the attraction information and belonging information of all nodes, and obtain the updated attraction information and updated belonging information of each data node to each initial cluster center; through iterative updating, the clustering result can more accurately reflect the actual relationship between nodes;
[0103] The formula is:
[0104] r' t+1 (i,k)=λ*r t (i,k)+(1-λ)*r t+1 (i,k)
[0105] a' t+1 (i,k)=λ*a t (i,k)+(1-λ)*a t+1 (i,k)
[0106] In the formula, r' t+1 (i,k), a' t+1 (i, k) is the updated attraction information and updated belonging information of node k to node i at the iteration number t+1; λ is the iteration attenuation coefficient;
[0107] k=argmax{a' t+1 (i,k)+r' t+1 (i,k)}
[0108] Wherein, if i=k, then node i is the updated cluster center of node k; if i≠k, then node k is the updated cluster center of node i;
[0109] S1-1-2-5: According to the updated attraction information and the updated belonging information, several initial cluster centers are updated to obtain several updated cluster centers; by continuously updating the cluster centers, the accuracy and stability of clustering can be gradually improved;
[0110] S1-1-2-6: Repeat the above cluster center update steps. If the cluster center does not change, output several final cluster centers;
[0111] S1-1-2-7: Obtain the similarity between each data node and several final clustering centers according to the basic node parameters of the data node;
[0112] S1-1-2-8: Group all data nodes according to similarity to obtain clusters belonging to each final cluster center;
[0113] S1-1-3: Set a corresponding functional label for each cluster center, and spread the functional label of the cluster center to the corresponding cluster cluster; the functional label helps to quickly identify the function of each node or cluster, which is convenient for subsequent function allocation and hierarchical management;
[0114] S1-1-4: Manage several clusters in layers to obtain several functional layers, and obtain a distributed storage network based on the functional layers; organize different clusters according to the functional layers to form a hierarchical management structure. Each functional layer is responsible for specific data processing or storage tasks. Through the division of functional layers, nodes can be easily added or removed, which improves the flexibility and scalability of the network;
[0115] The functional layer includes a storage layer with a number of storage nodes, a consensus layer with a number of consensus nodes, a confirmation layer with a number of confirmation nodes, a supervision layer with a number of supervision nodes, a transaction layer with a number of transaction nodes, an intermediary layer with a number of intermediary nodes, a guarantee layer with a number of guarantee nodes, and a crawling layer with a number of crawling nodes;
[0116] Storage nodes are responsible for the actual storage and retrieval of data, usually with large-capacity storage space, and ensure the persistence and reliability of data through redundancy and backup mechanisms; consensus nodes are responsible for reaching consensus in the network, ensuring that all nodes have a consistent understanding of the authenticity and status of the data, and verifying the validity of transactions and blocks by executing specific consensus algorithms; confirmation nodes are responsible for verifying the validity of transactions and blocks. These nodes may perform additional checks on the data to ensure that they comply with the rules and standards of the network; supervision nodes monitor the health status and node behavior of the distributed storage network, ensure that all nodes comply with network rules, and can detect and report abnormal behavior such as double-spending attacks or malicious nodes; transaction nodes are used to generate transaction data and send it to the consensus layer in the network for verification and storage, and are responsible Ensure the correctness and integrity of transactions; Intermediary nodes act as intermediaries between the two parties to the transaction, helping to facilitate transactions and may provide additional services such as reputation evaluation or dispute resolution; Guarantee nodes provide guarantee services for transactions to ensure that both parties to the transaction fulfill their contracts, and may hold a deposit as compensation for transaction failures; Crawling nodes are responsible for crawling information from external data sources and introducing it into the distributed storage network, usually for initial collection and update of data; Nodes in each functional layer play a specific role and work together to ensure the smooth operation of the distributed storage network. This layered design improves the efficiency and scalability of the network, while also enhancing the security and reliability of the system. Through clear division of labor, each node can focus on its core functions, thereby improving the processing power and service quality of the entire network;
[0117] S1-2: Based on some historical user information data, use the multimodal fusion algorithm to build an automatic security authentication model and obtain some historical multimodal fusion features;
[0118] Historical user information data includes historical user identity information data, historical user behavior data, and historical user biometric image data; identity information data is the user's ID number, login password, or other text sequence that can prove the identity; user behavior data includes the user's access records to the cloud computing center, the history of data retrieval, or historical permission applications; user biometric image data includes the user's biometric feature images, such as face images, iris images, or fingerprint images;
[0119] The automatic security authentication model is constructed based on the Convolutional Neural Networks (CNN)-Long Short-Term Memory Networks (LSTM)-Attention-Deep Belief Nets (DBN) algorithm, and the perception model includes an image feature extraction module constructed based on the CNN algorithm, a sequence feature extraction module constructed based on the LSTM algorithm, a behavior feature extraction module constructed based on the LSTM algorithm, an attention weight module constructed based on the Attention mechanism, and an automatic security authentication module constructed based on the DBN algorithm. The image feature extraction module, the sequence feature extraction module, and the behavior feature extraction module are all connected to the attention weight module, and the attention weight module is connected to the automatic security authentication module;
[0120] The image feature extraction module uses a convolutional neural network (CNN) to extract features such as edges, textures, and shapes from the input image. Through multi-layer convolution and pooling operations, CNN can capture the deep structural information of the image. CNN can automatically learn the representative features of the image without manual intervention. The sequence feature extraction module uses a long short-term memory network (LSTM) to process sequence data, such as time series or text sequences, and can capture dynamic changes and patterns in time series data. The behavior feature extraction module is specifically used to extract behavioral features, such as user behavior patterns or action sequences. This module can identify and encode user behavior habits and action sequences. By analyzing behavioral features, it can better distinguish between legitimate users and potential attackers. The attention weight module is used to assign different weights to different features, emphasize certain key information and ignore unimportant parts, and help the model focus on the most relevant parts of the input data. Through the attention mechanism, the model can pay more attention to the most important features for authentication, which helps to reduce the impact of noise and irrelevant information and improve the efficiency and accuracy of the model. The deep belief network (DBN) used in the automatic security authentication module is a deep learning model that makes accurate security authentication decisions based on the extracted features, which helps the model make reasonable predictions when facing unseen data.
[0121] S1-3: Based on several historical multimodal fusion features, a deep learning algorithm is used to build an access rights generation model;
[0122] The access permission generation model is constructed based on the Random Forest (RF)-Multi-Layer Perceptron (MLP) algorithm, and the access permission generation model includes a key feature screening module constructed based on the RF algorithm and an access permission generation module constructed based on the MLP algorithm;
[0123] The key feature extraction module uses the internal Classification And Regression Tree (CART) to perform key feature screening on the input multimodal fusion features, and extracts several key features related to the user permission prediction label, including user information integrity, behavior legitimacy, etc., which reduces the complexity and computational cost of the model, while improving the generalization and interpretability of the model; the access permission generation module adopts the form of a fully connected network to fuse different key features, improve the representation ability of the prediction situation, and realize efficient and accurate user permission prediction. It can not only process a large number of input features, but also adapt to the complex interactions between features, and finally provide users with appropriate access rights, while ensuring the security and efficiency of the system;
[0124] S2: an information collection device that collects real-time user information data of users and encrypts and uploads the real-time user information data to a cloud computing center;
[0125] The real-time user information data includes the user's real-time identity information data, real-time user behavior data, and real-time user biometric image data;
[0126] S3: The cloud computing center uses the automatic security authentication model to perform automatic security authentication based on real-time user information data to obtain the user's real-time security authentication result, including the following steps:
[0127] S3-1: using the image feature extraction module of the automatic security authentication model to extract the real-time image features of the real-time user biometric image data in the real-time user information data;
[0128] S3-2: Use the sequence feature extraction module of the automatic security authentication model to extract the real-time sequence features of the real-time identity information data in the real-time user information data;
[0129] S3-3: Use the behavior feature extraction module of the automatic security authentication model to extract the real-time behavior features of the real-time user behavior data in the real-time user information data;
[0130] S3-4: According to the preset attention weight value, the real-time image features, the real-time sequence features and the real-time behavior features are weightedly fused to obtain the real-time multimodal fusion features;
[0131] S3-5: Based on the real-time multimodal fusion features, use the automatic security authentication module to perform automatic security authentication and obtain the user's real-time security authentication result;
[0132] S4: The cloud computing center, if the real-time security authentication result is that the security authentication is passed, proceed to the next step; otherwise, return a real-time security authentication failure signal and end the security authentication;
[0133] S5: The cloud computing center generates access rights based on the real-time user information data using the access rights generation model to obtain real-time access rights data, including the following steps:
[0134] S5-1: The cloud computing center uses the key feature screening module of the access permission generation model to extract several real-time key features of the real-time multimodal fusion features of the real-time user information data;
[0135] S5-2: Based on a number of real-time key features, the access permission generation module of the access permission generation model is used to generate access permissions to obtain real-time access permission data;
[0136] S7: The cloud computing center uses a distributed storage network to perform distributed storage of the user's real-time user information data and real-time access permission data, including the following steps:
[0137] S7-1: The cloud computing center sends the user's real-time user information data and real-time access permission data to the transaction layer of the distributed storage network;
[0138] S7-2: using any transaction node in the transaction layer to generate real-time transaction data based on the user's real-time user information data and real-time access permission data;
[0139] S7-3: Use the consensus layer to reach consensus on real-time transaction data. If the consensus is successful, a real-time consensus success message is generated;
[0140] S7-4: Use the confirmation layer to confirm the real-time consensus success information. If the consensus confirmation is successful, use the consensus node that receives the real-time transaction data to convert the real-time transaction data into a real-time data block;
[0141] S7-5: Use any storage node of the storage layer to distribute the real-time data blocks and update the distributed ledger of the distributed storage network.
[0142] Embodiment 2:
[0143] like Figure 2 As shown, this embodiment provides a blockchain-based security authentication and authority management system for implementing a security authentication and authority management method. The system includes a cloud computing center and an information collection device, the information collection device is communicatively connected to the cloud computing center, and the cloud computing center includes a model building unit, an automatic security authentication unit, a failure signal generating unit, an access authority generating unit, and a distributed storage unit connected in sequence;
[0144] An information collection device is used to collect real-time user information data of users, and encrypt the real-time user information data and upload it to the cloud computing center;
[0145] A model building unit, which is used to build a distributed storage network using blockchain technology, and to build an automatic security authentication model and an access rights generation model using artificial intelligence algorithms;
[0146] The automatic security authentication unit is used to perform automatic security authentication based on real-time user information data using an automatic security authentication model to obtain a real-time security authentication result of the user;
[0147] A failure signal generating unit, used to generate a real-time security authentication failure signal when the real-time security authentication result is a security authentication failure, and return the real-time security authentication failure signal to the corresponding information collection device;
[0148] An access permission generation unit, used to generate access permissions according to real-time user information data using an access permission generation model to obtain real-time access permission data;
[0149] The distributed storage unit is used to use a distributed storage network to perform distributed storage on the real-time user information data and real-time access permission data of the user.
[0150] The present invention provides a blockchain-based security authentication and authority management method and system. By combining the tamper-proof characteristics of blockchain technology, the reliability of the authentication process and the integrity of data are ensured, and the risks of misidentification and missed identification are significantly reduced. The distributed storage technology of blockchain is used to achieve decentralized authentication, reduce the risk of single point failure, and thus improve the overall reliability of the authentication system. Through the application of blockchain technology, the risk of single point failure brought by centralized servers is eliminated, and the entire system can still maintain safe operation even when some nodes are attacked. The automatic security authentication model constructed by using artificial intelligence algorithm can perform automatic security authentication according to real-time user information data collected in real time, simplify the security authentication process, improve the efficiency of security authentication, and adapt to the application scenario of large-scale data. The constructed access authority generation model realizes a dynamic authority management mechanism, which can automatically adjust the authority according to the identity information and user behavior in the user's real-time user information data, ensure the reasonable allocation and effective control of the authority, and the dynamic authority management makes the authority configuration more flexible, can quickly respond to the authority change requirements, and effectively prevent the abuse of authority and unauthorized access.
[0151] The present invention is not limited to the above optional implementations, and anyone can derive other various forms of products under the enlightenment of the present invention. The above specific implementations should not be understood as limiting the scope of protection of the present invention. The scope of protection of the present invention should be based on the definition in the claims, and the description can be used to interpret the claims.
Claims
1. A blockchain-based security authentication and rights management method, characterized by: The steps include: The cloud computing center uses blockchain technology to build a distributed storage network and uses artificial intelligence algorithms to build automatic security authentication models and access rights generation models; An information collection device collects real-time user information data of users, and encrypts the real-time user information data and uploads it to a cloud computing center; The cloud computing center uses an automatic security authentication model to perform automatic security authentication based on real-time user information data and obtains the user's real-time security authentication result; The cloud computing center, if the real-time security authentication result is that the security authentication is passed, proceeds to the next step, otherwise, returns a real-time security authentication failure signal and ends the security authentication; The cloud computing center generates access rights based on real-time user information data using an access rights generation model to obtain real-time access rights data; The cloud computing center uses a distributed storage network to distribute the user's real-time user information data and real-time access permission data.
2. According to claim 1, a blockchain-based security authentication and authority management method is characterized by: The cloud computing center uses blockchain technology to build a distributed storage network and uses artificial intelligence algorithms to build an automatic security authentication model and access rights generation model, including the following steps: The cloud computing center performs function allocation and hierarchical management on all data nodes in distributed connections to obtain a distributed storage network; Based on some historical user information data, a multimodal fusion algorithm is used to build an automatic security authentication model and obtain some historical multimodal fusion features; Based on several historical multimodal fusion features, a deep learning algorithm is used to build an access rights generation model.
3. According to claim 2, a blockchain-based security authentication and authority management method is characterized in that: The cloud computing center performs function allocation and hierarchical management on all data nodes in distributed connections to obtain a distributed storage network, including the following steps: The cloud computing center initializes all data nodes to obtain a number of initialized data nodes, and performs distributed connections to obtain a number of distributed connected data nodes; Collect the basic node parameters of each data node of the distributed connection, and perform clustering processing on all data nodes according to several basic node parameters to obtain several clustering centers and corresponding clustering clusters; Set a corresponding functional label for each cluster center, and spread the functional label of the cluster center to the corresponding cluster cluster; Several clusters are managed in layers to obtain several functional layers, and a distributed storage network is obtained based on the several functional layers.
4. According to claim 3, a blockchain-based security authentication and authority management method is characterized in that: The basic node parameters of each data node of the distributed connection are collected, and all data nodes are clustered according to several basic node parameters to obtain several cluster centers and corresponding cluster clusters, including the following steps: Collect the basic node parameters of each data node of the distributed connection, and build a similarity matrix of the data nodes based on several basic node parameters; According to the similarity matrix, the objective function is set, and based on the objective function, the ISSA algorithm is used to generate several initial cluster centers; According to the basic node parameters of the data nodes, the AP clustering algorithm is used to obtain the initial attraction information and initial belonging information of each data node to each initial cluster center; Introduce an iterative attenuation coefficient, update the attraction information and belonging information of all nodes, and obtain the updated attraction information and updated belonging information of each data node to each initial cluster center; According to the updated attraction information and the updated belonging information, several initial cluster centers are updated to obtain several updated cluster centers; Repeat the above cluster center update steps. If the cluster center does not change, output several final cluster centers. According to the basic parameters of the data nodes, the similarity between each data node and several final cluster centers is obtained; According to the similarity, all data nodes are grouped to obtain the clusters belonging to each final cluster center.
5. According to claim 4, a blockchain-based security authentication and authority management method is characterized in that: The functional layer includes a storage layer with several storage nodes, a consensus layer with several consensus nodes, a confirmation layer with several confirmation nodes, a supervision layer with several supervision nodes, a transaction layer with several transaction nodes, an intermediary layer with several intermediary nodes, a guarantee layer with several guarantee nodes and a crawling layer with several crawling nodes.
6. A blockchain-based security authentication and authority management method according to claim 2, characterized in that: According to the similarity matrix, the objective function is set, and based on the objective function, the ISSA algorithm is used to generate several initial cluster centers, including the following steps: According to the similarity matrix, an objective function is set, the objective function is used as the fitness function of the ISSA algorithm, and the ISSA algorithm parameters of the ISSA algorithm are set; The positions of several initial cluster centers are encoded as individual vectors of ISSA individuals. According to the ISSA algorithm parameters and fitness function, several ISSA individuals are iteratively optimized and the best individual is retained. The individual vector of the optimal individual is decoded to obtain the optimal number of initial cluster centers and the position of each initial cluster center.
7. According to claim 2, a blockchain-based security authentication and authority management method is characterized in that: The historical user information data includes the user's historical identity information data, historical user behavior data and historical user biometric image data; The real-time user information data includes the user's real-time identity information data, real-time user behavior data and real-time user biometric image data.
8. A blockchain-based security authentication and authority management method according to claim 7, characterized in that: The automatic safety authentication model is constructed based on the CNN-LSTM-Attention-DBN algorithm, and the perception model includes an image feature extraction module constructed based on the CNN algorithm, a sequence feature extraction module constructed based on the LSTM algorithm, a behavior feature extraction module constructed based on the LSTM algorithm, an attention weight module constructed based on the Attention mechanism, and an automatic safety authentication module constructed based on the DBN algorithm. The image feature extraction module, the sequence feature extraction module, and the behavior feature extraction module are all connected to the attention weight module, and the attention weight module is connected to the automatic safety authentication module; The access permission generation model is constructed based on the RF-MLP algorithm, and the access permission generation model includes a key feature screening module constructed based on the RF algorithm and an access permission generation module constructed based on the MLP algorithm.
9. A blockchain-based security authentication and authority management method according to claim 5, characterized in that: The cloud computing center uses a distributed storage network to perform distributed storage of real-time user information data and real-time access permission data of users, including the following steps: The cloud computing center sends the user's real-time user information data and real-time access permission data to the transaction layer of the distributed storage network; Use any transaction node in the transaction layer to generate real-time transaction data based on the user's real-time user information data and real-time access permission data; Use the consensus layer to reach consensus on real-time transaction data. If the consensus is successful, a real-time consensus success message is generated; Use the confirmation layer to confirm the real-time consensus success information. If the consensus confirmation is successful, use the consensus node that receives the real-time transaction data to convert the real-time transaction data into a real-time data block; Use any storage node in the storage layer to distribute the real-time data blocks and update the distributed ledger of the distributed storage network.
10. A blockchain-based security authentication and authority management system, used to implement the security authentication and authority management method as described in any one of claims 1 to 9, characterized in that: The system includes a cloud computing center and an information collection device, wherein the information collection device is communicatively connected to the cloud computing center, and the cloud computing center includes a model building unit, an automatic security authentication unit, a failure signal generating unit, an access permission generating unit and a distributed storage unit connected in sequence.