Block chain cross-system login-based authentication and data storage method and device

By using blockchain technology to encrypt and store user information and authentication factors in inter-system identity authentication, and perform double-matching verification, the problem of lack of multi-level security guarantee for identity authentication in the existing technology is solved, and a cross-system login solution with high security and data reliability is achieved.

CN120017406AActive Publication Date: 2025-05-16中国邮政储蓄银行股份有限公司
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510328696.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-19
Publication Date
2025-05-16
Estimated Expiration
2045-03-19

AI Technical Summary

Technical Problem

The prior art lacks multi-level security guarantees in inter-system identity authentication, and the authentication data is susceptible to tampering and cannot achieve data reliability and traceability.

Method used

Blockchain technology is adopted to encrypt user information and authentication factors and store them in the blockchain, and through the double matching process of system jump request and authentication factors, ensuring that the data transmitted across the system undergoes strict identity verification and security.

Benefits of technology

Through blockchain technology, high security and consistency of cross-system login is achieved, preventing tampering and forgery of authentication factors, ensuring data integrity and traceability, and improving the system's anti-attack capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017406A_ABST
    Figure CN120017406A_ABST
Patent Text Reader

Abstract

The invention provides an authentication and data storage method and device based on block chain cross-system login. User information and an authentication factor are encrypted and stored in a block chain, and through dual matching of a system jump request and the authentication factor, it is ensured that cross-system data transmission is subjected to strict identity verification and security guarantee. By extracting the authentication factor and sending the decryption request, the second system node can be ensured to perform identity verification based on the effective authentication factor, thereby preventing illegal user intrusion. And meanwhile, authentication of all operation messages is realized through interaction of the block chain among the system nodes, and the security and consistency of cross-system data exchange are ensured. In the aspect of data storage, user information is managed in a decentralized mode through the block chain, and the problems of single-point faults and data tampering are avoided. And all data are stored in an encrypted manner and verified in a decrypted manner, so that the consistency and security are ensured, and the anti-attack capability of the system is improved. Therefore, the invention provides a safe and efficient cross-system authentication mechanism.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of system login technology, and in particular to an authentication and data storage method based on blockchain cross-system login, and an authentication and data storage device based on blockchain cross-system login. Background Art

[0002] With the rapid development of information and digital technology, more and more companies rely on the interaction and collaboration between multiple systems in their daily operations. However, with the frequent data transmission and jump between systems, how to ensure the effective authentication of user identities and the safe switching between systems has become a major challenge in the current technology application. Especially in enterprise-level applications, the single sign-on (SSO) mechanism has become a common identity authentication solution. With single sign-on, users only need to log in once on one system to access all related systems without having to repeatedly enter their usernames and passwords. Although this mechanism facilitates user operations, it also has obvious security risks.

[0003] At present, many systems rely only on the authentication factors carried by the first system for subsequent system access verification during the single sign-on process. Although this method reduces the complexity of user operations, its security is greatly reduced. Specifically, all cross-system requests only use the authentication factors generated by the first system, and fail to perform separate encryption or security verification of identity authentication between different systems, which can easily lead to the leakage or forgery of authentication factors, and cannot fully guarantee the legitimacy of user access and the security of the system.

[0004] In addition, most of the existing systems on the market only use traditional encryption and decryption methods to protect identity authentication data, and lack a trusted storage and traceability mechanism for the core data of authentication factors. Specifically, although these systems use encryption and decryption to protect authentication data to a certain extent, they fail to upload the core data of authentication factors to the blockchain, lack tamper-proof and traceable records, and cannot effectively guarantee the integrity and reliability of authentication data.

[0005] In summary, the current single sign-on mechanism has serious security issues in cross-system identity authentication: on the one hand, excessive reliance on the first system authentication factor leads to low security of other systems; on the other hand, the lack of blockchain technology to protect the authentication factor data and on-chain operation makes the data easy to be tampered with, and the authenticity and integrity of the authentication data cannot be ensured. Therefore, the existing technology has the problem of lack of multi-level security protection for identity authentication between systems, the authentication data is easy to be tampered with, and the reliability and traceability of data cannot be achieved. Summary of the invention

[0006] The main purpose of this application is to provide an authentication and data storage method based on cross-system login of blockchain, and an authentication and data storage device based on cross-system login of blockchain, so as to at least solve the problems existing in the prior art that identity authentication between systems lacks multi-level security protection, authentication data is susceptible to tampering, and data reliability and traceability cannot be achieved.

[0007] In order to achieve the above-mentioned purpose, according to one aspect of the present application, there is provided an authentication method based on cross-system login of blockchain, the blockchain comprising a user node, a first system node and a second system node, the method comprising: in response to a system jump request initiated by the user node, extracting a first authentication factor according to the system jump request, the system jump request being used to request a jump to the second system node when the user node logs in to the first system node, the first authentication factor being an authentication factor generated by the first system node based on encryption of authentication information and user information; sending a first decryption request to the blockchain based on the first authentication factor, the first decryption request being used to instruct the blockchain to decrypt and match the first authentication factor, and sending the user information to the second system node when the decryption match passes; in response to the user information, encrypting through blockchain technology, generating a second authentication factor, and uploading the second authentication factor to the blockchain; in the process of interaction between the second system node and the blockchain, authenticating all messages according to the first authentication factor and the second authentication factor.

[0008] Optionally, in response to the user information, encryption is performed through blockchain technology, and a second authentication factor is generated, including: combining the user information and the authentication information of the second system node to obtain a data packet to be encrypted, the authentication information including one or more of a unique identifier, a timestamp and a random number of the second system node; in response to the user information, encryption is performed through blockchain technology, and a second authentication factor is generated, and the second authentication factor is uploaded to the blockchain.

[0009] Optionally, in response to the user information, after encrypting through blockchain technology and generating a second authentication factor, and uploading the second authentication factor to the blockchain, the method also includes: embedding the second authentication factor into a local token to obtain a first authentication token; and issuing the first authentication token to the user node so that the user node adds the second authentication factor to all operations of the second system node.

[0010] Optionally, during the interaction between the second system node and the blockchain, all messages are authenticated according to the first authentication factor and the second authentication factor, including: when the second system node sends a message to the blockchain, generating a data packet to be sent according to an operation instruction and relevant data; appending the first authentication factor and the second authentication factor to the data packet to be sent to obtain a message to be sent; sending the message to be sent to the blockchain, the blockchain is used to use a private key in an asymmetric algorithm to decrypt the received message to be sent to obtain the second authentication factor, and when the second authentication factor is obtained, the first authentication factor is decrypted using an asymmetric decryption algorithm to obtain the first authentication factor, and the authentication information stored in the blockchain based on the first authentication factor and the second authentication factor is matched to complete the authentication process.

[0011] Optionally, during the interaction between the second system node and the blockchain, all messages are authenticated according to the first authentication factor and the second authentication factor, including: when the blockchain sends a message to the second system node, receiving the message to be decrypted sent by the blockchain, and parsing the message to be decrypted to obtain an operation instruction, the first authentication factor, and the second authentication factor; obtaining a private key in an asymmetric algorithm, decrypting the first authentication factor, and decrypting the second authentication factor when the decryption of the first authentication factor is completed; matching based on the first authentication factor and the second authentication factor, and executing the operation instruction when the match passes.

[0012] According to another aspect of the present application, a data storage method based on blockchain cross-system login is provided, the blockchain includes a user node, a first system node, and a second system node, the method including: in response to login verification information uploaded by the first system node, matching based on the login verification information and the user information stored in the blockchain, and generating a matching result and sending it to the first system node; in response to a first authentication factor and the user information uploaded by the first system node, storing the first authentication factor, and updating the user information stored in the blockchain according to the user information uploaded by the first system node; in response to a first decryption request uploaded by the second system node, matching the first authentication factor carried in the first decryption request with the first authentication factor stored in the blockchain, and if the match is successful, sending the user information stored in the blockchain to the second system node; in response to a second authentication factor and the user information uploaded by the second system node, storing the second authentication factor, and updating the user information stored in the blockchain according to the user information uploaded by the second system node.

[0013] Optionally, in response to the login verification information uploaded by the first system node, matching is performed based on the login verification information and the user information stored in the blockchain, and a matching result is generated and sent to the first system node, including: decrypting the login verification information according to a private key in the asymmetric encryption technology, and analyzing the decrypted login verification information to obtain the first user information; comparing the first user information with the second user information, and when the second user information is consistent with the first user information, determining that the matching result is a passed match, and the second user information is the user information stored in the blockchain; when the second user information is inconsistent with the first user information, determining that the matching result is a failed match; and sending the matching result to the first system node.

[0014] Optionally, in response to the first decryption request uploaded by the second system node, matching the first authentication factor carried in the first decryption request with the first authentication factor stored in the blockchain, and if the match succeeds, sending the user information stored in the blockchain to the second system node, including: parsing the first decryption request, extracting the first authentication factor carried in the first decryption request, and obtaining a first target factor; based on the first target factor and the second target factor, comparing, if the first target factor is consistent with the second target factor, determining that the matching result is a match passed, and the second target factor is the first authentication factor stored in the blockchain; if the first target factor is inconsistent with the second target factor, determining that the matching result is a match failed; if the matching result is a match passed, sending the user information stored in the blockchain to the second system node.

[0015] According to another aspect of the present application, there is provided an authentication device based on cross-system login of blockchain, the blockchain comprising a user node, a first system node and a second system node, the device comprising:

[0016] A first acquisition unit is used to respond to a system jump request initiated by the user node, and extract a first authentication factor according to the system jump request, wherein the system jump request is used to request a jump to a second system node when the user node logs in to the first system node, and the first authentication factor is an authentication factor generated by the first system node based on authentication information and user information encryption; a first sending unit is used to send a first decryption request to the blockchain based on the first authentication factor, and the first decryption request is used to instruct the blockchain to decrypt and match the first authentication factor, and send the user information to the second system node when the decryption match passes; a first processing unit is used to encrypt the user information through blockchain technology in response to the user information, generate a second authentication factor, and upload the second authentication factor to the blockchain; a control unit is used to authenticate all messages according to the first authentication factor and the second authentication factor during the interaction with the blockchain.

[0017] According to another aspect of the present application, a data storage device based on blockchain cross-system login is provided, the blockchain includes a user node, a first system node and a second system node, and the device includes:

[0018] A second sending unit is used to respond to the login verification information uploaded by the first system node, match the login verification information with the user information stored in the blockchain, and generate a matching result and send it to the first system node;

[0019] a first storage unit, configured to store the first authentication factor in response to the first authentication factor and the user information uploaded by the first system node, and update the user information stored in the blockchain according to the user information uploaded by the first system node;

[0020] a third sending unit, configured to respond to the first decryption request uploaded by the second system node, match the first authentication factor carried in the first decryption request with the first authentication factor stored in the blockchain, and if the match is successful, send the user information stored in the blockchain to the second system node;

[0021] A second storage unit is used to store the second authentication factor in response to the second authentication factor and the user information uploaded by the second system node, and to update the user information stored in the blockchain according to the user information uploaded by the second system node.

[0022] By applying the technical solution of the present application, user information and authentication factors are encrypted and stored in the blockchain by adopting blockchain technology, and through the dual matching process of system jump request and authentication factor, it is ensured that all data transmitted between systems are strictly authenticated and secure. By extracting the first authentication factor and sending a decryption request, it is ensured that during the login process of the second system node, identity matching can be performed based on the valid authentication factor, thereby avoiding the intrusion of illegal users. In addition, through the interaction of blockchain between cross-system nodes, all operation messages are authenticated in detail between the first authentication factor and the second authentication factor, ensuring the high security and consistency in the cross-system data exchange process. In terms of data storage, by storing user information in the blockchain and automatically updating and matching user authentication factors between each system node, decentralized management of information is achieved, avoiding single point failure and data tampering problems in traditional storage methods. All data related to user information and authentication factors are encrypted, stored and decrypted for verification, ensuring the consistency and security of the data and enhancing the system's anti-attack capability. Finally, through this cross-system authentication mechanism, users can log in safely and seamlessly between multiple systems, improving user experience while also ensuring the security and stability of the system. Therefore, the technical solution of the present application effectively solves the problems existing in the prior art, such as the lack of multi-level security protection for identity authentication between systems, the vulnerability of authentication data to tampering, and the inability to achieve data reliability and traceability. Through blockchain technology, a more secure, efficient and reliable cross-system login solution is achieved, which can meet the high requirements for authentication and data storage in a multi-system environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 A hardware structure block diagram of a mobile terminal for authentication and data storage based on blockchain cross-system login provided in an embodiment of the present application is shown;

[0024] Figure 2 A schematic diagram of a process of an authentication method based on blockchain cross-system login provided according to an embodiment of the present application is shown;

[0025] Figure 3 A schematic diagram of a data storage method based on blockchain cross-system login provided according to an embodiment of the present application is shown;

[0026] Figure 4 A structural block diagram of an authentication device based on blockchain cross-system login provided according to an embodiment of the present application is shown.

[0027] Figure 5 A structural block diagram of a data storage device based on blockchain cross-system login provided according to an embodiment of the present application is shown.

[0028] The above drawings include the following reference numerals:

[0029] 102, processor; 104, memory; 106, transmission device; 108, input and output devices. DETAILED DESCRIPTION

[0030] It should be noted that, in the absence of conflict, the embodiments and features in the embodiments of the present application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0031] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.

[0032] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present application described here. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0033] For the convenience of description, some nouns or terms involved in the embodiments of the present application are explained below:

[0034] Blockchain: Blockchain technology is a new distributed infrastructure and computing paradigm that uses block chain data structures to verify and store data, uses distributed node consensus algorithms to generate and update data, uses cryptography to ensure the security of data transmission and access, and uses smart contracts composed of automated script codes to program and operate data;

[0035] Alliance chain: Only stakeholders or agreed-upon specific organizational clients can use it. Nodes must be authenticated and authorized before they can join the blockchain network. Nodes in the alliance chain have different divisions of labor. They participate in ledger maintenance and access nodes as needed according to the blockchain's transaction submission method and consensus mechanism, and have weak decentralization characteristics.

[0036] Consensus verification: The consensus mechanism is a way for all accounting nodes in the blockchain to determine whether a record is valid. This is both a means of identification and a means of preventing tampering. The consensus mechanism has the characteristics of "the minority obeys the majority" and "everyone is equal". Among them, "the minority obeys the majority" does not completely refer to the number of nodes, but can also be computing power, number of shares or other characteristic quantities that can be compared by computers. "Everyone is equal" means that when the nodes meet the conditions, all nodes have the right to propose consensus results first, which may be directly recognized by other nodes and finally become the final consensus results;

[0037] Decentralization: Blockchain technology does not rely on additional third-party management agencies or hardware facilities, and has no central control. In addition to the self-contained blockchain itself, through distributed accounting and storage, each node realizes self-verification, transmission and management of information. Decentralization is the most prominent and essential feature of blockchain;

[0038] Asymmetric encryption algorithm: Unlike symmetric encryption algorithms, asymmetric encryption algorithms require two keys: a public key and a private key. The public key and the private key are a pair. If the public key is used to encrypt data, it can only be decrypted with the corresponding private key; if the private key is used to encrypt data, it can only be decrypted with the corresponding public key. Because two different keys are used for encryption and decryption, this algorithm is called an asymmetric encryption algorithm.

[0039] As introduced in the background technology, there are problems in the prior art such as lack of multi-level security protection for identity authentication between systems, susceptibility of authentication data to tampering, and inability to achieve data reliability and traceability. To solve the problems in the prior art, the embodiments of the present application provide an authentication and data storage method based on cross-system login of blockchain, an authentication and data storage device based on cross-system login of blockchain, a computer-readable storage medium, a processor, and an electronic device.

[0040] The technical solutions in the embodiments of the present invention will be described clearly and completely below in conjunction with the accompanying drawings in the embodiments of the present invention.

[0041] The method embodiments provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Taking running on a mobile terminal as an example, Figure 1 This is a hardware structure block diagram of a mobile terminal of an authentication and data storage method based on blockchain cross-system login in an embodiment of the present invention. Figure 1 As shown, the mobile terminal may include one or more ( Figure 1Only one is shown in the figure) a processor 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data, wherein the mobile terminal may also include a transmission device 106 and an input / output device 108 for communication functions. It can be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the mobile terminal. Figure 1 More or fewer components as shown, or with Figure 1 Different configurations are shown.

[0042] The memory 104 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the display method of device information in the embodiment of the present invention. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, the above method is implemented. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, the memory 104 may further include a memory remotely arranged relative to the processor 102, and these remote memories can be connected to the mobile terminal via a network. Examples of the above-mentioned network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof. The transmission device 106 is used to receive or send data via a network. The above-mentioned specific examples of the network may include a wireless network provided by a communication provider of the mobile terminal. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, referred to as NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0043] In this embodiment, a blockchain-based cross-system login authentication and data storage method running on a mobile terminal, a computer terminal or a similar computing device is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in an order different from that shown here.

[0044] Figure 2 Flowchart of the authentication method based on blockchain cross-system login according to the embodiment of the present application. Figure 2As shown, the blockchain includes a user node, a first system node and a second system node, and the method includes the following steps:

[0045] Step S201, in response to a system jump request initiated by a user node, extract a first authentication factor according to the system jump request, the system jump request is used to request a jump to a second system node when the user node logs in to the first system node, and the first authentication factor is an authentication factor generated by the first system node based on authentication information and user information encryption.

[0046] Specifically, when a user node initiates a cross-system jump request, the request information is obtained from the user node, and the first authentication factor used for authentication is extracted. The authentication factor is generated by the first system node based on user information (such as user name, password, biometrics, etc.) and authentication information (such as session information, token, etc.) when the user logs in. The first authentication factor is encrypted to ensure that it is not leaked or tampered with during transmission. The first authentication factor extracted and encrypted can effectively prevent the authentication information from being maliciously tampered with or misappropriated, while reducing the exposure of sensitive data transmitted between systems and enhancing the security of cross-system jumps.

[0047] Step S202: Send a first decryption request to the blockchain based on the first authentication factor. The first decryption request is used to instruct the blockchain to decrypt and match the first authentication factor, and send user information to the second system node if the decryption match passes.

[0048] Specifically, after the user node initiates a jump request and carries the first authentication factor, the first system node will send a first decryption request to the blockchain, requesting the blockchain to verify and decrypt the authentication factor. The blockchain will perform a decryption matching operation based on the pre-stored public key and private key. If the decryption match is successful, it means that the user identity has been verified, and the blockchain will forward the user information to the second system node for continued authentication and authorization. By decrypting and verifying the authentication factor, the blockchain can ensure data consistency and identity legitimacy during the cross-system jump process, avoiding the risk of identity forgery or illegal access. The decryption matching process is supported by blockchain technology, which increases trust and system security.

[0049] Step S203, in response to the user information, encrypt it through blockchain technology, generate a second authentication factor, and upload the second authentication factor to the blockchain.

[0050] Specifically, when the blockchain receives the user information of the second system node, the system will encrypt the information and generate a second authentication factor. This second authentication factor is generated based on the user's authentication data after encryption and uploaded to the blockchain for subsequent authentication. By encrypting the user information, the security of the authentication data during transmission is guaranteed.

[0051] Step S204: During the interaction between the second system node and the blockchain, all messages are authenticated according to the first authentication factor and the second authentication factor.

[0052] Specifically, when the second system node interacts with the blockchain, the system authenticates the message based on the first authentication factor and the second authentication factor that have been uploaded to the blockchain. By comparing the matching of the two authentication factors, the legitimacy of the user's identity is ensured. If the match is successful, the user is allowed to access the second system; otherwise, the access request is denied. By authenticating the message based on two authentication factors, the security of the system is further improved. The mechanism of dual authentication factors can effectively prevent malicious attacks and ensure that only verified legitimate users can access cross-system resources, greatly improving the system's protection capabilities.

[0053] It can be seen that the embodiment of the present application provides an authentication method based on cross-system login of blockchain, which significantly improves the security of identity authentication between systems by utilizing the decentralized, tamper-proof and traceable characteristics of blockchain technology. The first and second authentication factors are generated by encryption and uploaded to the blockchain, ensuring the integrity and security of the authentication data. The blockchain verifies the user's identity through decryption matching, avoiding the problem of authentication factors being tampered with or forged. During the entire authentication process, the dual authentication factors are used to perform strict identity authentication on the message to prevent illegal access, thereby ensuring the legitimacy of the user and the security of cross-system operations.

[0054] As a possible implementation, in response to user information, encryption is performed through blockchain technology, and a second authentication factor is generated, including the following steps:

[0055] Step S301, combining user information and authentication information of the second system node to obtain a data packet to be encrypted, wherein the authentication information includes one or more of a unique identifier of the second system node, a timestamp, and a random number.

[0056] Specifically, the user information is combined with the authentication information of the second system node to form a data packet to be encrypted. The authentication information of the second system node may include the following aspects: Unique identification: a unique string or identifier used to identify the second system node itself, which helps to ensure that the authentication process is performed for a specific system. Timestamp: used to identify the specific time of the authentication request to prevent replay attacks or expiration of authentication information. Random number: used to increase the randomness in the encryption process to ensure that each authentication factor generated is unique, and even if the user information is the same, different authentication factors can be generated. By combining this information, a data packet with sufficient complexity and security can be generated for subsequent encryption operations. The combination of multiple authentication information (such as unique identification, timestamp, random number) to generate the data packet to be encrypted effectively increases the complexity and security of the authentication factor. In this way, even if an attacker can obtain part of the authentication information, it is difficult to restore the valid authentication factor, thereby effectively preventing identity forgery and replay attacks, and further enhancing the system's anti-attack capabilities.

[0057] Step S302, in response to the user information, encrypt it through blockchain technology, generate a second authentication factor, and upload the second authentication factor to the blockchain.

[0058] Specifically, after the data packet to be encrypted is generated, it is encrypted by blockchain technology. Specifically, the data packet to be encrypted is encrypted using an encryption algorithm (such as symmetric encryption or asymmetric encryption), and a second authentication factor is generated based on the encryption result. The encryption process is implemented through blockchain technology, which means that the encryption operation not only ensures that the data cannot be tampered with during the encryption process, but also ensures that the generated authentication factor is safe and cannot be forged. Finally, the generated second authentication factor is uploaded to the blockchain and stored in the blockchain's tamper-proof distributed ledger for use in subsequent authentication processes. By using blockchain technology for encryption, the security of the second authentication factor during the generation and storage process can be ensured. The decentralized nature of the blockchain ensures that the encrypted data cannot be tampered with, and the authentication factor uploaded to the blockchain can also be effectively traced and verified, greatly enhancing the security of identity authentication.

[0059] It can be seen that the embodiment of the present application generates a data packet to be encrypted by combining user information with the authentication information of the second system node, and then encrypts it through blockchain technology to generate a second authentication factor, and uploads it to the blockchain for storage. By combining multiple authentication information (unique identification, timestamp, and random number, etc.), the generated authentication factor is more complex and secure, which prevents the forgery and tampering of the authentication factor. Encryption and uploading through blockchain technology ensures the immutability and traceability of the data, greatly enhancing the security of the cross-system login process. The entire authentication process is supported by a decentralized blockchain, which avoids the security vulnerabilities of traditional centralized systems and makes the entire system more secure and reliable.

[0060] As a possible implementation, after encrypting the user information through blockchain technology and generating a second authentication factor, and uploading the second authentication factor to the blockchain, the method further includes the following steps:

[0061] Step S401: embed the second authentication factor into the local token to obtain a first authentication token.

[0062] Specifically, the second authentication factor is embedded in the local token to generate the first authentication token. The local token is an identifier that carries authentication information. After the authentication factor is embedded, it can carry the factor to authenticate the identity in subsequent operations. The first authentication token usually comes with some additional information, such as timestamp, session information, etc., to ensure the validity and uniqueness of the token and prevent replay attacks or forgery. Embedding the second authentication factor in the local token can make the authentication factor carrying more convenient and efficient.

[0063] Step S402: Send the first authentication token to the user node so that the user node can add the second authentication factor to all operations of the second system node.

[0064] Specifically, after the first authentication token with the second authentication factor embedded in it is generated and embedded, the authentication token will be sent to the user node. The user node will use the authentication token for identity authentication during the interaction with the second system node. Specifically, the user node will attach the first authentication token in the request, and the second authentication factor contained in the token will play a role when the second system node performs identity authentication and authorization operations. By sending the first authentication token to the user node, the user node can automatically add the second authentication factor to all operations with the second system node, making the identity authentication process more automated and efficient. There is no need to perform complex authentication factor generation and verification every time, which greatly improves the convenience of cross-system operations. In addition, the use of the first authentication token can reduce the repeated input of user information, improve user experience, and enhance the security of the system.

[0065] It can be seen that the embodiment of the present application further improves the convenience and security of identity authentication by embedding the second authentication factor into the local token to generate the first authentication token and issuing it to the user node. First, the generated first authentication token carries the encrypted second authentication factor, making the authentication process in cross-system operations more efficient and avoiding the tediousness of regenerating the authentication factor and the verification process each time; secondly, the first authentication token enables the user node to automatically add the authentication factor when performing all operations with the second system node, effectively simplifying the authentication process and improving the degree of automation of the operation; finally, using the token for identity authentication avoids the frequent transmission of user sensitive information, thereby improving the security and protection capabilities of the system. This method is suitable for scenarios where secure and efficient identity authentication is required between multiple systems, and improves the convenience, security and user experience of cross-system operations.

[0066] As a possible implementation method, during the interaction between the second system node and the blockchain, all messages are authenticated according to the first authentication factor and the second authentication factor, including the following steps:

[0067] Step S501, when the second system node sends a message to the blockchain, a data packet to be sent is generated according to the operation instruction and related data;

[0068] Specifically, when the second system node is ready to send a message to the blockchain, it first generates a data packet to be sent based on the executed operation instructions and related data. The operation instructions may include user operations, requested resources, information about the target system, etc., and the related data includes user information, session information, etc. This information constitutes the data packet to be sent for subsequent verification and processing. The process of generating the data packet to be sent ensures that the content and request of each message are valid and purposeful, and all information is preprocessed and organized, providing a solid foundation for subsequent identity verification and data security.

[0069] Step S502, attaching the first authentication factor and the second authentication factor to the data packet to be sent to obtain a message to be sent;

[0070] Specifically, in the data packet to be sent, the first authentication factor and the second authentication factor are attached to the data packet as key data for identity authentication. The two authentication factors contain the user's identity information and authentication data, ensuring that the data packet can carry complete identity authentication information during transmission. Attaching the first authentication factor and the second authentication factor to the data packet to be sent ensures the security of the authentication process during data transmission. As part of the message, the authentication factor can be verified in a timely manner at the receiving end, ensuring the legitimacy and integrity of data transmission. The step of attaching the authentication factor adds multiple layers of verification, thereby reducing the risk of tampering or forgery.

[0071] Step S503: Send the message to be sent to the blockchain. The blockchain is used to decrypt the received message to be sent using the private key in the asymmetric algorithm to obtain the second authentication factor. When the second authentication factor is obtained, the asymmetric decryption algorithm is used to decrypt the first authentication factor to obtain the first authentication factor. The authentication information stored in the blockchain is matched based on the first authentication factor and the second authentication factor to complete the authentication process.

[0072] Specifically, the message to be sent contains the first authentication factor and the second authentication factor. After being sent to the blockchain, the blockchain uses the private key in the asymmetric algorithm to decrypt the received message and first obtain the second authentication factor. Subsequently, based on the decryption result of the second authentication factor, the blockchain uses the asymmetric decryption algorithm to decrypt the first authentication factor again and finally obtains the value of the factor. The blockchain will complete the final identity authentication process by matching the decrypted first authentication factor and the second authentication factor with the authentication information stored on the blockchain. The use of asymmetric encryption and decryption technology ensures the security and privacy of the message during transmission. Since asymmetric encryption requires a private key to decrypt, only the blockchain holding the private key can correctly decrypt the message, thereby effectively avoiding the risk of man-in-the-middle attacks or data tampering. In addition, the matching method based on the decrypted authentication factor improves the accuracy and security of authentication, so that the user identity is reliably verified, thereby preventing identity forgery and illegal access.

[0073] It can be seen that the embodiment of the present application significantly improves the security of cross-system data transmission by authenticating all messages based on the first authentication factor and the second authentication factor during the interaction between the second system node and the blockchain. On the basis of generating the data packet to be sent, the first authentication factor and the second authentication factor are attached to the message, and the message is decrypted and verified by an asymmetric encryption algorithm, ensuring the reliability and integrity of the authentication information during the data transmission process. This method effectively prevents security threats such as data tampering, identity forgery, and man-in-the-middle attacks, and ensures the legitimacy and data security of inter-system communications. Through this authentication mechanism, it can be ensured that each message in the cross-system operation undergoes strict identity authentication, which improves the security of the system and is suitable for cross-domain authentication and data exchange between multiple systems.

[0074] As a possible implementation method, during the interaction between the second system node and the blockchain, all messages are authenticated according to the first authentication factor and the second authentication factor, including the following steps:

[0075] Step S601, when the blockchain sends a message to the second system node, receiving the message to be decrypted sent by the blockchain, and parsing the message to be decrypted to obtain the operation instruction, the first authentication factor and the second authentication factor;

[0076] Specifically, the second system node first receives a message from the blockchain. After receiving the message, the system parses the message and extracts the operation instructions and authentication factors (i.e., the first authentication factor and the second authentication factor) contained therein. The operation instructions may contain specific operations or data requests that need to be performed, while the first authentication factor and the second authentication factor are used to verify whether the identity initiating the request is legitimate. Parsing the message to be decrypted can ensure that the message sent by the blockchain contains all necessary information, especially the authentication factor for identity verification. This process ensures the integrity of the data and the accuracy of the authentication information, laying the foundation for subsequent decryption and authentication operations.

[0077] Step S602, obtaining a private key in the asymmetric algorithm, decrypting the first authentication factor, and decrypting the second authentication factor when the decryption of the first authentication factor is completed;

[0078] Specifically, after the second system node receives the message containing the authentication factor, the system will use the private key in the asymmetric encryption algorithm to decrypt the first authentication factor. After successfully decrypting the first authentication factor, the system continues to use the private key to decrypt the second authentication factor. This process ensures that only legitimate systems can decrypt the authentication factor and complete identity authentication. By using an asymmetric algorithm to decrypt the authentication factor, the system can ensure that only legitimate nodes holding private keys can decrypt the data, which greatly enhances the security of the system and prevents identity information from being maliciously tampered with or forged during transmission. Asymmetric encryption technology makes the identity authentication process more secure and reliable through the cooperation of public and private key pairs, and effectively avoids man-in-the-middle attacks.

[0079] Step S603: Matching is performed based on the first authentication factor and the second authentication factor, and the operation instruction is executed if the match succeeds.

[0080] Specifically, after the decryption is successful, the system will match the decrypted first authentication factor and second authentication factor with the authentication information stored in the system. If the match succeeds, it proves that the identity of the sender of the message is legitimate, and the system will execute the operation instructions contained in the message (for example, query, modify data, etc.). If the match fails, the system will refuse to perform the operation and record the security event. By matching the authentication factors, the system can confirm the legitimacy of the identity information and ensure that only authenticated users can perform operations. This step effectively prevents operations by illegal users and increases the system's protection level. The success or failure of the matching process directly affects whether the operation is executed, so its correctness is directly related to the security of the system and the reliability of the data.

[0081] It can be seen that the embodiment of the present application significantly enhances the security of cross-system operations by receiving and parsing the to-be-decrypted message from the blockchain at the second system node, and performing identity authentication and operation instruction execution based on the decrypted first authentication factor and second authentication factor. First, the message parsing process ensures that all necessary authentication information and operation instructions are accurately extracted, providing complete data for subsequent identity authentication; secondly, the authentication factor is decrypted using an asymmetric encryption algorithm, ensuring that only legitimate system nodes can decrypt the data, effectively avoiding malicious tampering and forgery; finally, by matching the decrypted authentication factor with the stored authentication information, the system can ensure that only requests with legitimate identities are executed, thereby effectively preventing illegal operations. The entire process not only improves the accuracy and security of identity authentication, but also makes cross-system operations more efficient and reliable, preventing potential security risks.

[0082] Figure 3 This is a flow chart of a data storage method based on blockchain cross-system login according to an embodiment of the present application. Figure 3 As shown, the blockchain includes a user node, a first system node and a second system node, and the method includes the following steps:

[0083] Step S701, in response to the login verification information uploaded by the first system node, matching is performed based on the login verification information and the user information stored in the blockchain, and a matching result is generated and sent to the first system node;

[0084] Specifically, when a user attempts to log in to the first system, the first system node uploads login verification information (such as user name, password, authentication factor, etc.), which is matched with the user information stored in the blockchain. After a successful match, the system generates a matching result and returns the result to the first system node, indicating that the user's identity authentication has passed or failed. This ensures the uniformity and security of the identity authentication process between multiple systems. Matching the user information stored in the blockchain can ensure that the user's identity information in different systems is consistent, avoiding tampering and forgery of identity information. The generation and issuance of matching results ensures the legitimacy and accuracy of the user's login operation.

[0085] Step S702, in response to the first authentication factor and user information uploaded by the first system node, the first authentication factor is stored, and the user information stored in the blockchain is updated according to the user information uploaded by the first system node;

[0086] Specifically, when the first system node uploads the first authentication factor, the authentication factor will be stored in the blockchain and used as the core data for user identity authentication. At the same time, the first system node will also upload relevant information of the user (such as personal information, account status, etc.), which will be used to update the user information stored on the blockchain to keep the user data up to date. By storing and updating the first authentication factor and user information, the blockchain can ensure that users have consistent and up-to-date authentication information in multiple systems. This not only improves the efficiency of data synchronization between systems, but also improves the security and reliability of data through decentralized storage, preventing data loss and tampering.

[0087] Step S703, in response to the first decryption request uploaded by the second system node, matching the first authentication factor carried in the first decryption request with the first authentication factor stored in the blockchain, and sending the user information stored in the blockchain to the second system node if the match is successful;

[0088] Specifically, when the second system node receives the first decryption request from the user, the system uses the first authentication factor carried in the first decryption request to match the authentication factor stored on the blockchain. If the match is successful, the user's relevant information is retrieved from the blockchain and the user information is sent to the second system node for further identity authentication or authorization operations. By matching the decryption request with the first authentication factor stored in the blockchain, it is ensured that the second system node can verify the legitimacy of the user through accurate authentication information. This method improves the reliability and security of cross-system authentication and avoids tampering and leakage of identity information.

[0089] Step S704: In response to the second authentication factor and user information uploaded by the second system node, the second authentication factor is stored, and the user information stored in the blockchain is updated according to the user information uploaded by the second system node.

[0090] Specifically, after the second system node successfully verifies the user's identity, it will upload the second authentication factor and related user information. The system will store the second authentication factor in the blockchain and update the user data in the blockchain based on the user information uploaded by the second system node to ensure the consistency and real-time nature of the user's authentication information and personal data in all systems.

[0091] It can be seen that the embodiment of the present application provides a data storage method based on cross-system login of blockchain, by performing identity authentication based on user information stored in blockchain between the first system node and the second system node, to ensure the security and consistency of user information. After uploading the authentication factor and user information at each system node, the blockchain can update and store the latest user data in real time to ensure the validity and consistency of the data. Through the decentralized storage method of blockchain, not only the security of the data is improved, but also the risk of data tampering and loss is reduced. In addition, the method can achieve efficient data synchronization between multiple systems, so that users have consistent authentication information in different systems, improve the interoperability and security between systems, and is suitable for cross-platform identity authentication and data storage needs in a multi-system environment.

[0092] As a possible implementation method, in response to the login verification information uploaded by the first system node, matching is performed based on the login verification information and the user information stored in the blockchain, and a matching result is generated and sent to the first system node, including the following steps:

[0093] Step S801, decrypting the login verification information according to the private key in the asymmetric encryption technology, and analyzing the decrypted login verification information to obtain the first user information;

[0094] Specifically, after the user's login verification information is uploaded to the first system node, the system first uses the private key in the asymmetric encryption technology to decrypt the information. The decrypted login verification information contains the user's basic authentication information (such as user name, password, device information, etc.). The system analyzes the decrypted information and extracts the first user information as the basis for matching with the user information stored in the blockchain. The login verification information is decrypted by the private key in the asymmetric encryption technology, ensuring the confidentiality and integrity of the information during transmission. The decrypted user information can effectively prevent data from being tampered with or leaked, ensuring the security and credibility of identity authentication. In addition, by analyzing and extracting the first user information, accurate data is provided for the subsequent matching process, enhancing the system's identity authentication capabilities.

[0095] Step S802, based on the comparison between the first user information and the second user information, if the second user information is consistent with the first user information, determining that the matching result is a successful match, and the second user information is the user information stored in the blockchain;

[0096] Specifically, the decrypted first user information is compared with the second user information stored in the blockchain. The second user information is the user authentication information stored on the blockchain, including the user's personal information, account status, etc. If the first user information is consistent with the second user information, it means that the user identity authentication is successful, the matching result is "match passed", and the second user information is confirmed to be valid user information. By comparing user information, the legitimacy of the user identity can be effectively confirmed to ensure that only legitimate users can pass the identity authentication. The comparison process avoids the identity forgery or tampering of illegal users, and improves the accuracy and security of identity authentication.

[0097] Step S803, when the second user information is inconsistent with the first user information, determining that the matching result is a match failure;

[0098] Specifically, if the first user information is inconsistent with the second user information stored in the blockchain, the user identity authentication will be considered to have failed, and the matching result will be "match failed". In this case, the user information will not be fed back to the first system node, and the user will not be allowed to continue to log in or perform other operations. By detecting inconsistent user information, illegal users can be prevented from logging in by forging identity information. The result of the match failure enables the system to reject illegal requests, thereby effectively protecting user data and system security, and avoiding fraud and abuse of identity information.

[0099] Step S804: Send the matching result to the first system node.

[0100] Specifically, whether the match is successful or unsuccessful, the system will feed back the final matching result (i.e., "match passed" or "match failed") to the first system node. The first system node decides whether to allow the user to log in based on the matching result, or prompts the user to perform further identity authentication. By sending the matching result to the first system node in a timely manner, the system can ensure that the first system node can make a correct response. If the match is successful, the system allows the user to continue to log in; if the match is unsuccessful, the user cannot log in to the system. This process improves the response efficiency of the system, ensures that the identity authentication process is concise and fast, and reduces unnecessary waiting time.

[0101] It can be seen that the embodiment of the present application effectively improves the security and efficiency of cross-system identity authentication by decrypting the login verification information and comparing and matching the user information. First, the login verification information is decrypted using asymmetric encryption technology to ensure data security during transmission and accurately extract the first user information. Secondly, by comparing the first user information with the second user information stored in the blockchain, it is ensured that only legal and consistent user information can pass the identity authentication, thereby effectively preventing the forgery or tampering of identity information. When the match fails, the system can automatically reject the access request of the illegal user, thereby ensuring the security of the system. Finally, the matching result is fed back to the first system node in a timely manner to ensure the smoothness and security of the user login process.

[0102] As a possible implementation, in response to the first decryption request uploaded by the second system node, matching the first authentication factor carried in the first decryption request with the first authentication factor stored in the blockchain, and sending the user information stored in the blockchain to the second system node if the match is successful, includes the following steps:

[0103] Step S901, parsing the first decryption request, extracting the first authentication factor carried in the first decryption request, and obtaining the first target factor;

[0104] Specifically, when the second system node uploads the first decryption request, the system will parse the request and extract the first authentication factor carried therein. The factor contains information required for user identity authentication, which is usually an authentication identifier generated by an encryption algorithm.

[0105] Step S902: Based on the comparison between the first target factor and the second target factor, if the first target factor and the second target factor are consistent, determine that the matching result is a pass, and the second target factor is the first authentication factor stored in the blockchain;

[0106] Specifically, after obtaining the first target factor, the system will compare it with the second target factor stored in the blockchain. The second target factor is the authentication data generated by the first authentication factor and stored on the blockchain. If the first target factor is consistent with the second target factor, it means that the identity authentication is successful, and the system determines the matching result as "match passed". At this time, the second target factor is the first authentication factor stored in the blockchain. After the verification is passed, the system allows further operations. By comparing the authentication factors, the system can accurately verify the legitimacy of the user's identity. This comparison process effectively prevents identity forgery and data tampering, and ensures the authenticity and consistency of the user's identity. The confirmation of the match provides security for the system and avoids unauthorized access.

[0107] Step S903, when the first target factor and the second target factor are inconsistent, determining the matching result as a match failure;

[0108] Specifically, if the first target factor is inconsistent with the second target factor stored in the blockchain, it indicates that the identity authentication has failed. At this point, the matching result will be determined as "match failed". This usually occurs when the identity authentication information does not match or has been tampered with, and further operations will be rejected. It ensures that only legitimate users can pass the identity authentication, preventing illegal users from forging or tampering with authentication information to enter the system. By accurately identifying the matching failure, the system can prevent unauthorized access in a timely manner and effectively improve the security of the system.

[0109] Step S904: When the matching result is a successful match, the user information stored in the blockchain is sent to the second system node.

[0110] Specifically, when the matching result is "match passed", the system will send the user information stored in the blockchain to the second system node. User information includes the user's personal information, account status, etc., which will be used for subsequent operation verification, access permission allocation, etc. Once the authentication factor is matched successfully, the system can promptly pass the complete user information to the second system node, allowing the user to smoothly access the system. By sending the information to the second system node, the consistency and transparency of user data across systems are ensured. This process improves the user experience and makes cross-system access smoother and safer.

[0111] It can be seen that the embodiment of the present application parses the first decryption request uploaded by the second system node and compares the extracted first authentication factor with the authentication factor stored in the blockchain, thereby ensuring the security and reliability of identity authentication. Through the precise matching process, the system can accurately verify the identity of the user and prevent illegal users from obtaining access rights by forging or tampering with authentication information. Only when the first target factor is consistent with the second target factor stored in the blockchain will the system allow the user information to be sent, ensuring the security and consistency of the data. The entire process improves the accuracy of identity authentication and the security protection capabilities of the system, and enhances cross-system collaboration and user experience.

[0112] It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and that, although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0113] The embodiment of the present application also provides an authentication and data storage device based on blockchain cross-system login. It should be noted that the authentication and data storage device based on blockchain cross-system login in the embodiment of the present application can be used to execute the authentication and data storage method for blockchain cross-system login provided in the embodiment of the present application. The device is used to implement the above-mentioned embodiments and preferred implementations, and those that have been described will not be repeated. As used below, the term "module" can implement a combination of software and / or hardware for a predetermined function. Although the device described in the following embodiments is preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceived.

[0114] The following introduces the authentication and data storage device based on blockchain cross-system login provided in an embodiment of the present application.

[0115] Figure 4 : is a structural block diagram of an authentication device based on blockchain cross-system login according to an embodiment of the present application. Figure 4 As shown, the device includes: a first acquisition unit 10, a first sending unit 20, a first processing unit 30, and a control unit 40.

[0116] A first acquisition unit 10 is configured to extract a first authentication factor in response to a system jump request initiated by a user node according to the system jump request, wherein the system jump request is used to request a jump to a second system node when the user node logs in to the first system node, and the first authentication factor is an authentication factor encrypted and generated by the first system node according to authentication information and user information;

[0117] A first sending unit 20 is used to send a first decryption request to the blockchain based on the first authentication factor, where the first decryption request is used to instruct the blockchain to decrypt and match the first authentication factor, and to send user information to the second system node if the decryption match passes;

[0118] The first processing unit 30 is used to encrypt the user information through the blockchain technology in response to the user information, generate a second authentication factor, and upload the second authentication factor to the blockchain;

[0119] The control unit 40 is used to authenticate all messages according to the first authentication factor and the second authentication factor during the interaction with the blockchain.

[0120] As a possible implementation manner, the first processing unit includes:

[0121] A combining module, used to combine the user information and the authentication information of the second system node to obtain a data packet to be encrypted, wherein the authentication information includes one or more of a unique identifier of the second system node, a timestamp, and a random number;

[0122] The second authentication factor uploading module is used to respond to user information, encrypt through blockchain technology, generate a second authentication factor, and upload the second authentication factor to the blockchain.

[0123] As a possible implementation method, the authentication device based on blockchain cross-system login also includes:

[0124] A second authentication factor embedding and token generation unit, used to embed the second authentication factor into the local token to obtain a first authentication token;

[0125] The first authentication token issuing unit is used to issue the first authentication token to the user node so that the user node can add the second authentication factor to all operations of the second system node.

[0126] As a possible implementation, the control unit includes:

[0127] A module for generating data packets to be sent, used to generate data packets to be sent according to operation instructions and relevant data when the second system node sends a message to the blockchain;

[0128] A message attaching authentication factor module, used for attaching the first authentication factor and the second authentication factor to the data packet to be sent, so as to obtain a message to be sent;

[0129] The message sending module is used to send the message to be sent to the blockchain. The blockchain is used to use the private key in the asymmetric algorithm to decrypt the received message to be sent to obtain the second authentication factor. When the second authentication factor is obtained, the asymmetric decryption algorithm is used to decrypt the first authentication factor to obtain the first authentication factor, and the authentication information stored in the blockchain based on the first authentication factor and the second authentication factor is matched to complete the authentication process.

[0130] As a possible implementation, the control unit includes:

[0131] A decryption message parsing module, used for receiving a message to be decrypted sent by the blockchain when the blockchain sends a message to the second system node, and parsing the message to be decrypted to obtain an operation instruction, a first authentication factor, and a second authentication factor;

[0132] an asymmetric decryption processing module, used to obtain a private key in the asymmetric algorithm, decrypt the first authentication factor, and decrypt the second authentication factor when the decryption of the first authentication factor is completed;

[0133] The execution module is used to perform matching based on the first authentication factor and the second authentication factor, and execute the operation instruction if the matching succeeds.

[0134] Figure 5: is a structural block diagram of a data storage device based on blockchain cross-system login according to an embodiment of the present application. Figure 5 As shown, the device includes: a second sending unit 11, a first storage unit 21, a third sending unit 31, and a second storage unit 41.

[0135] The second sending unit 11 is used to respond to the login verification information uploaded by the first system node, match the login verification information with the user information stored in the blockchain, and generate a matching result and send it to the first system node;

[0136] A first storage unit 21 is used to store the first authentication factor in response to the first authentication factor and the user information uploaded by the first system node, and to update the user information stored in the blockchain according to the user information uploaded by the first system node;

[0137] The third sending unit 31 is used to respond to the first decryption request uploaded by the second system node, match the first authentication factor carried in the first decryption request with the first authentication factor stored in the blockchain, and send the user information stored in the blockchain to the second system node if the match is successful;

[0138] The second storage unit 41 is used to store the second authentication factor in response to the second authentication factor and user information uploaded by the second system node, and to update the user information stored in the blockchain according to the user information uploaded by the second system node.

[0139] As a possible implementation, the first storage unit includes:

[0140] A decryption analysis module, used to decrypt the login verification information according to the private key in the asymmetric encryption technology, and analyze the decrypted login verification information to obtain the first user information;

[0141] An information comparison module, used to compare the first user information with the second user information, and if the second user information is consistent with the first user information, determine that the matching result is a pass, and the second user information is the user information stored in the blockchain;

[0142] A matching result determination module, configured to determine that the matching result is a failed match when the second user information is inconsistent with the first user information;

[0143] The matching result sending module is used to send the matching result to the first system node.

[0144] As a possible implementation manner, the third sending unit includes:

[0145] A parsing and extraction module, used to parse the first decryption request, extract the first authentication factor carried in the first decryption request, and obtain the first target factor;

[0146] A matching confirmation module is used to compare the first target factor with the second target factor, and if the first target factor is consistent with the second target factor, determine that the matching result is a matching result, and the second target factor is the first authentication factor stored in the blockchain;

[0147] A matching failure confirmation module, used for determining that the matching result is a matching failure when the first target factor and the second target factor are inconsistent;

[0148] The information generation module is used to send the user information stored in the blockchain to the second system node when the matching result is a passed match.

[0149] The above-mentioned authentication and data storage device based on cross-system login of blockchain includes a processor and a memory. The above-mentioned first acquisition unit, first sending unit, first processing unit, control unit, second sending unit, first storage unit, third sending unit, second storage unit, etc. are all stored in the memory as program units, and the processor executes the above-mentioned program units stored in the memory to realize the corresponding functions. The above-mentioned modules are all located in the same processor; or, the above-mentioned modules are located in different processors in any combination.

[0150] The processor includes a kernel, which calls the corresponding program unit from the memory. One or more kernels can be set, and the communication efficiency can be improved by adjusting the kernel parameters.

[0151] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.

[0152] An embodiment of the present invention provides a computer-readable storage medium, which includes a stored program, wherein when the program is running, the device where the computer-readable storage medium is located is controlled to execute an authentication and data storage method based on blockchain cross-system login.

[0153] An embodiment of the present invention provides a processor, which is used to run a program, wherein an authentication and data storage method based on blockchain cross-system login is executed when the program is running.

[0154] An embodiment of the present invention provides a device, which includes a processor, a memory, and a program stored in the memory and executable on the processor. The device in this article may be a server, a PC, a PAD, a mobile phone, etc. When the processor executes the program, at least the authentication and data storage method steps for cross-system login based on blockchain are implemented.

[0155] The present application also provides a computer program product, which, when executed on a data processing device, is suitable for executing a program that initializes at least the authentication and data storage method steps based on blockchain cross-system login.

[0156] Obviously, those skilled in the art should understand that each module or each step of the present invention can be implemented by a general computing device, they can be concentrated on a single computing device, or distributed on a network composed of multiple computing devices, they can be implemented by a program code executable by a computing device, so that they can be stored in a storage device and executed by the computing device, and in some cases, the steps shown or described can be executed in a different order than here, or they can be made into individual integrated circuit modules, or multiple modules or steps therein can be made into a single integrated circuit module for implementation. Thus, the present invention is not limited to any specific combination of hardware and software.

[0157] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.

[0158] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0159] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0160] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0161] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0162] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0163] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0164] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0165] From the above description, it can be seen that the above embodiments of the present application achieve the following technical effects:

[0166] 1) The blockchain-based cross-system login authentication method of this application significantly improves the security of identity authentication between systems by utilizing the decentralized, tamper-proof, and traceable characteristics of blockchain technology. The first and second authentication factors are generated by encryption and uploaded to the blockchain to ensure the integrity and security of the authentication data. The blockchain verifies the user's identity through decryption matching, avoiding the problem of authentication factors being tampered with or forged. During the entire authentication process, the dual authentication factors are used to strictly authenticate the message to prevent illegal access, thereby ensuring the legitimacy of the user and the security of cross-system operations.

[0167] 2) The data storage method based on blockchain cross-system login of the present application ensures the security and consistency of user information by performing identity authentication based on user information stored in blockchain between the first system node and the second system node. After uploading the authentication factor and user information at each system node, the blockchain can update and store the latest user data in real time to ensure the validity and consistency of the data. The decentralized storage method of blockchain not only improves the security of data, but also reduces the risk of data tampering and loss. In addition, the method can achieve efficient data synchronization between multiple systems, so that users have consistent authentication information in different systems, improve the interoperability and security between systems, and is suitable for cross-platform identity authentication and data storage needs in a multi-system environment.

[0168] 3) The authentication device based on blockchain cross-system login of the present application includes: a first acquisition unit, a first sending unit, a first processing unit, and a control unit. By utilizing the decentralized, tamper-proof, and traceable characteristics of blockchain technology, the security of identity authentication between systems is significantly improved. The first and second authentication factors are generated by encryption and uploaded to the blockchain to ensure the integrity and security of the authentication data. The blockchain verifies the user's identity through decryption matching, avoiding the problem of tampering or forgery of the authentication factor. During the entire authentication process, the dual authentication factors are used to perform strict identity authentication on the message to prevent illegal access, thereby ensuring the legitimacy of the user and the security of cross-system operations.

[0169] 4) The data storage device based on cross-system login of blockchain of the present application comprises: a second sending unit, a first storage unit, a third sending unit, and a second storage unit. By performing identity authentication based on user information stored in blockchain between the first system node and the second system node, the security and consistency of user information are ensured. After uploading the authentication factor and user information at each system node, the blockchain can update and store the latest user data in real time to ensure the validity and consistency of the data. The decentralized storage method of blockchain not only improves the security of data, but also reduces the risk of data tampering and loss. In addition, the method can achieve efficient data synchronization between multiple systems, so that users have consistent authentication information in different systems, improve the interoperability and security between systems, and is suitable for cross-platform identity authentication and data storage needs in a multi-system environment.

[0170] The above description is only the preferred embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. An authentication method based on blockchain cross-system login, characterized in that: The blockchain includes a user node, a first system node, and a second system node, and the method includes: In response to a system jump request initiated by the user node, extracting a first authentication factor according to the system jump request, wherein the system jump request is used to request a jump to a second system node when the user node logs in to the first system node, and the first authentication factor is an authentication factor encrypted and generated by the first system node according to authentication information and user information; Sending a first decryption request to the blockchain based on the first authentication factor, wherein the first decryption request is used to instruct the blockchain to decrypt and match the first authentication factor, and to send the user information to the second system node if the decryption match passes; In response to the user information, encrypt the information through blockchain technology and generate a second authentication factor, and upload the second authentication factor to the blockchain; During the interaction between the second system node and the blockchain, all messages are authenticated according to the first authentication factor and the second authentication factor.

2. The method according to claim 1, characterized in that In response to the user information, encryption is performed through blockchain technology, and a second authentication factor is generated, including: Combining the user information with the authentication information of the second system node to obtain a data packet to be encrypted, wherein the authentication information includes one or more of a unique identifier of the second system node, a timestamp, and a random number; In response to the user information, encryption is performed through blockchain technology to generate a second authentication factor, and the second authentication factor is uploaded to the blockchain.

3. The method according to claim 1, characterized in that After encrypting the user information by blockchain technology and generating a second authentication factor in response to the user information, and uploading the second authentication factor to the blockchain, the method further includes: Embed the second authentication factor into a local token to obtain a first authentication token; The first authentication token is issued to the user node so that the user node adds the second authentication factor to all operations of the second system node.

4. The method according to claim 1, characterized in that: During the interaction between the second system node and the blockchain, all messages are authenticated according to the first authentication factor and the second authentication factor, including: When the second system node sends a message to the blockchain, generating a data packet to be sent according to the operation instruction and related data; Adding the first authentication factor and the second authentication factor to the data packet to be sent to obtain a message to be sent; The message to be sent is sent to the blockchain, and the blockchain is used to use the private key in the asymmetric algorithm to decrypt the received message to be sent to obtain the second authentication factor. When the second authentication factor is obtained, the first authentication factor is decrypted by using an asymmetric decryption algorithm to obtain the first authentication factor, and the authentication information stored in the blockchain based on the first authentication factor and the second authentication factor is matched to complete the authentication process.

5. The method according to claim 1, characterized in that During the interaction between the second system node and the blockchain, all messages are authenticated according to the first authentication factor and the second authentication factor, including: In the case where the blockchain sends a message to the second system node, receiving the message to be decrypted sent by the blockchain, and parsing the message to be decrypted to obtain an operation instruction, the first authentication factor, and the second authentication factor; Obtaining a private key in an asymmetric algorithm, decrypting the first authentication factor, and decrypting the second authentication factor when the decryption of the first authentication factor is completed; A match is performed based on the first authentication factor and the second authentication factor, and the operation instruction is executed if the match succeeds.

6. A data storage method based on cross-system login of blockchain, characterized in that: The blockchain includes a user node, a first system node, and a second system node, and the method includes: In response to the login verification information uploaded by the first system node, matching is performed based on the login verification information and the user information stored in the blockchain, and generating a matching result and sending it to the first system node; In response to the first authentication factor and the user information uploaded by the first system node, the first authentication factor is stored, and the user information stored in the blockchain is updated according to the user information uploaded by the first system node; In response to the first decryption request uploaded by the second system node, matching the first authentication factor carried in the first decryption request with the first authentication factor stored in the blockchain, and sending the user information stored in the blockchain to the second system node if the match is successful; In response to the second authentication factor and the user information uploaded by the second system node, the second authentication factor is stored, and the user information stored in the blockchain is updated according to the user information uploaded by the second system node.

7. The method according to claim 6, characterized in that In response to the login verification information uploaded by the first system node, matching is performed based on the login verification information and the user information stored in the blockchain, and generating a matching result and sending it to the first system node, including: Decrypting the login verification information according to a private key in the asymmetric encryption technology, and analyzing the decrypted login verification information to obtain the first user information; Based on the comparison between the first user information and the second user information, if the second user information is consistent with the first user information, determining that the matching result is a pass, and the second user information is the user information stored in the blockchain; When the second user information is inconsistent with the first user information, determining that the matching result is a match failure; The matching result is sent to the first system node.

8. The method according to claim 6, characterized in that In response to the first decryption request uploaded by the second system node, matching the first authentication factor carried in the first decryption request with the first authentication factor stored in the blockchain, and sending the user information stored in the blockchain to the second system node if the match passes, including: Parsing the first decryption request, extracting the first authentication factor carried in the first decryption request, and obtaining a first target factor; Based on the comparison between the first target factor and the second target factor, if the first target factor is consistent with the second target factor, determining that the matching result is a passed match, and the second target factor is the first authentication factor stored in the blockchain; When the first target factor is inconsistent with the second target factor, determining the matching result as a match failure; If the matching result is a successful match, the user information stored in the blockchain is sent to the second system node.

9. An authentication device based on blockchain cross-system login, characterized in that: The blockchain includes a user node, a first system node, and a second system node, and the device includes: a first acquiring unit, configured to respond to a system jump request initiated by the user node and extract a first authentication factor according to the system jump request, wherein the system jump request is used to request a jump to a second system node when the user node logs in to the first system node, and the first authentication factor is an authentication factor encrypted and generated by the first system node according to authentication information and user information; A first sending unit is configured to send a first decryption request to the blockchain based on the first authentication factor, wherein the first decryption request is used to instruct the blockchain to decrypt and match the first authentication factor, and to send the user information to the second system node if the decryption match passes; A first processing unit, configured to generate a second authentication factor by encrypting the user information through blockchain technology in response to the user information, and upload the second authentication factor to the blockchain; A control unit is used to authenticate all messages according to the first authentication factor and the second authentication factor during interaction with the blockchain.

10. A data storage device based on blockchain cross-system login, characterized in that: The blockchain consists of user nodes, A first system node and a second system node, the device comprising: A second sending unit is used to respond to the login verification information uploaded by the first system node, match the login verification information with the user information stored in the blockchain, and generate a matching result and send it to the first system node; a first storage unit, configured to store the first authentication factor in response to the first authentication factor and the user information uploaded by the first system node, and update the user information stored in the blockchain according to the user information uploaded by the first system node; a third sending unit, configured to respond to the first decryption request uploaded by the second system node, match the first authentication factor carried in the first decryption request with the first authentication factor stored in the blockchain, and if the match is successful, send the user information stored in the blockchain to the second system node; A second storage unit is used to store the second authentication factor in response to the second authentication factor and the user information uploaded by the second system node, and to update the user information stored in the blockchain according to the user information uploaded by the second system node.

Citation Information

Patent Citations

  • Login method and system of double-Token cross-end jump system

    CN115102724A

  • Digital identity login method and device, computer equipment and storage medium

    CN116318776A

  • Login authentication method and device based on block chain, equipment and storage medium

    CN117614704A

  • Identity authentication method and apparatus, device, and computer readable storage medium

    WO2023142437A1

  • Data processing method and apparatus, computer device, and readable storage medium

    WO2023221719A1