Network security protection method and system based on block chain
By adopting a blockchain-based method in network security protection, using device unique identification and biometrics to generate digital identities, combined with deep learning models and encryption technology, the shortcomings of identity authentication, permission management and traffic monitoring in the existing technology are solved, and a comprehensive network security protection and performance improvement are achieved.
Patent Information
- Application Number
- CN202510197310.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-21
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2045-02-21
AI Technical Summary
The existing network security protection technology has many problems in identity authentication, permission management, traffic monitoring, etc., and it is difficult to effectively deal with the complex and severe network security situation.
The blockchain-based network security protection method is adopted, and digital identity on the chain is generated by obtaining the unique identification of the device and the user's biometrics, combining the adversarial training deep learning model to detect network traffic in real time, dynamically adjust the number of blockchain subchains, and encrypted verification using threshold signatures and zero-knowledge proof technology.
It realizes all-round network security protection from identity authentication, threat detection, network resource management to data encryption, improves the security and performance of the system, and effectively responds to network load changes and threat intelligence synchronization needs.
Smart Images

Figure CN120050094A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security, and specifically to a network security protection method and system based on blockchain. Background Art
[0002] In the current era of rapid digital development, network security has become a crucial issue. With the popularization of the Internet and the rapid progress of information technology, network attack methods have become increasingly diverse and complex, posing severe challenges and many problems to existing network security protection technologies. In terms of identity authentication, traditional network security protection methods often rely on centralized authentication mechanisms, such as the common combination of username and password. However, this method is vulnerable to single-point attacks. Once the centralized authentication server is breached, the authentication information of a large number of users will be at risk of leakage, thereby threatening the security of the entire network system. In terms of permission management, the static permission allocation mode cannot adapt to the dynamic network environment and user needs. For sudden network access requirements, permissions cannot be adjusted in a timely and effective manner, which may result in legitimate users being unable to access the required resources normally, or illegal users obtaining excessive permissions. In terms of network traffic monitoring, existing technologies often struggle to ensure detection efficiency and accuracy when faced with large-scale and high-concurrency network traffic. For new and complex network threats, such as advanced persistent threats (APTs) and zero-day attacks, traditional detection methods are often unable to effectively identify them, allowing threats to lurk in the network and cause serious damage.
[0003] In summary, there are many problems with existing network security protection technologies in aspects such as identity authentication, permission management, traffic monitoring, encryption technology, blockchain application, and resource allocation. There is an urgent need for an innovative and comprehensive network security protection method to address the increasingly complex and severe network security situation. Summary of the Invention
[0004] To overcome the above-mentioned defects of the prior art, embodiments of the present invention provide a network security protection method and system based on blockchain to solve the problems raised in the above background art.
[0005] A blockchain-based network security protection method, characterized by comprising the following steps: S1 Obtain the device unique identifier and the user's biometric characteristics, generate a digital identity on the chain based on the device unique identifier and the biometric characteristics, and map it to an initial permission level; S2 Use a deep learning model trained by adversarial training to detect network traffic in real time to generate a threat detection result. When the threat detection result exceeds the threshold, trigger a smart contract to update the permission level; S3 According to the updated permission level and the real-time network load, use the sharded blockchain network technology to dynamically adjust the number of blockchain sub-chains and achieve cross-chain threat intelligence synchronization through the relay chain; S4 Use threshold signature and zero-knowledge proof technologies to encrypt and verify the permission change records and cross-chain data.
[0006] Further, the obtaining of the device unique identifier and the user's biometric characteristics includes: obtaining at least one of the physical identifier of the device hardware, machine code, MAC address, and CPU serial number as the unique identifier to generate an asymmetric key, which is only valid for the current device; using an optical sensor, an image acquisition device, or a fingerprint acquisition device to obtain the user's biometric information, where the biometric information includes at least one of fingerprint, facial image, and iris feature; the generating of the digital identity on the chain based on the device unique identifier and the biometric characteristics and mapping it to the initial permission level includes fusing the device identifier and the biometric information in a trusted execution environment (TEE) to generate a unique digital identity on the chain, and mapping it to the initial permission level according to a preset rule.
[0007] Further, in the process of generating the digital identity on the chain, a hash algorithm is used to process the device unique identifier and the user's biometric characteristics to ensure the uniqueness and security of the digital identity.
[0008] Further, S1 further includes calculating a real-time score based on the device's historical behavior, triggering a smart contract permission adjustment, encrypting and storing the user's iris feature through a trusted execution environment (TEE), and generating a composite hash value bound to the device's public key.
[0009] Further, the real-time detection of network traffic by the deep learning model trained by adversarial training to generate a threat detection result includes: collecting network traffic data in real time and performing preprocessing, extracting key features of the traffic data through convolution operations, and using a deep convolutional neural network to perform threat detection on the extracted key features and generate a threat detection result.
[0010] Further, during the training process of the deep learning model trained by adversarial training, adversarial samples generated by a generative adversarial network are introduced to improve the model's detection ability for complex threats.
[0011] Furthermore, the dynamic adjustment of the number of blockchain sub-chains and the cross-chain threat intelligence synchronization through the relay chain include: real-time monitoring of the network load conditions, including transaction volume, data traffic, etc., dynamically increasing or decreasing the number of blockchain sub-chains according to the network load conditions to optimize the network performance, and adjusting the cross-chain synchronization strategy according to the updated permission levels and network load conditions to ensure data consistency and security.
[0012] Furthermore, the use of threshold signature and zero-knowledge proof technologies to encrypt and verify the permission change records and cross-chain data includes: using the threshold signature algorithm to achieve multi-node collaborative signature to ensure the legality and immutability of the permission change records, and using the zero-knowledge proof technology to verify the authenticity and integrity of the cross-chain data while protecting the privacy of the data.
[0013] Furthermore, when updating the permission level, the smart contract makes a comprehensive judgment by combining the network environment parameters where the device is located and historical threat data.
[0014] This application also proposes a blockchain-based network security protection system, which is characterized by including the following modules: a dynamic identity authentication module: obtaining the unique device identifier and the user's biometric characteristics, generating a digital identity on the chain based on the unique device identifier and the biometric characteristics and mapping it to the initial permission level; a threat detection module: real-time detecting network traffic through an adversarial training deep learning model to generate a threat detection result, and when the threat detection result exceeds the threshold, triggering the smart contract to update the permission level; a blockchain network module: according to the updated permission level and the real-time network load, using the sharded blockchain network technology to dynamically adjust the number of blockchain sub-chains and achieve cross-chain threat intelligence synchronization through the relay chain; an encryption verification module: using the threshold signature and zero-knowledge proof technologies to encrypt and verify the permission change records and cross-chain data.
[0015] A blockchain-based network security protection method and system provided by the present invention ensure the security and privacy of data by fusing the unique device identifier and biometric characteristics to generate a digital identity on the chain, and using the threshold signature and zero-knowledge proof technologies to encrypt and verify the permission change records and cross-chain data; using the sharded blockchain network technology and dynamically adjusting the number of sub-chains improves the performance and scalability of the blockchain network, effectively coping with the changes in network load and the synchronization requirements of threat intelligence; real-time detecting network traffic through an adversarial training deep learning model, and when the threat detection result exceeds the threshold, triggering the smart contract to update the permission level in real time, improving the real-time performance of threat detection and response; through the close collaborative work of the system, an all-round network security protection from identity authentication, threat detection, network resource management to data encryption is realized. This collaborative effect not only improves the security of the system, but also significantly enhances the performance and resource utilization rate of the system, effectively solving the problems in the prior art and having a wide range of application prospects. Brief Description of the Drawings
[0016] Figure 1 It is a schematic flowchart of a blockchain-based network security protection method according to an embodiment of the present application.
[0017] The realization of the object of the present invention, functional features and advantages will be further described in conjunction with the embodiments with reference to the drawings. Detailed Embodiments
[0018] In order to make the object, technical solution and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0019] Those skilled in the art of the present technology can understand that, unless otherwise defined, all terms (including technical terms and scientific terms) used here have the same meaning as the general understanding of those of ordinary skill in the art to which the present invention belongs. It should also be understood that terms such as those defined in a general dictionary should be understood to have a meaning consistent with the meaning in the context of the prior art, and will not be interpreted with an idealized or overly formal meaning unless specifically defined as here.
[0020] Referring to Figure 1 , in order to achieve the above object of the invention, the present invention provides a blockchain-based network security protection method, including the following steps: S1 Obtain the device unique identifier and user biometric feature, generate a digital identity on the chain based on the device unique identifier and biometric feature and map it to an initial permission level; S2 Real-time detect network traffic through an adversarial training deep learning model to generate a threat detection result, and when the threat detection result exceeds a threshold, trigger a smart contract to update the permission level; S3 According to the updated permission level and real-time network load, use the sharded blockchain network technology to dynamically adjust the number of blockchain sub-chains and achieve cross-chain threat intelligence synchronization through a relay chain; S4 Adopt threshold signature and zero-knowledge proof technologies to encrypt and verify the permission change record and cross-chain data.
[0021] In the prior art, traditional network security protection solutions mainly rely on a centralized identity authentication system (such as LDAP). Such a system has a single point of failure risk. The system relies on a centralized server. Once this server is attacked, the security of the entire system will be threatened; when blockchain technology processes network traffic and threat detection, it usually adopts a static sharding method and cannot dynamically adapt to changes in network load. There is serious resource waste and response delay under sudden traffic (such as DDoS attacks); at the same time, existing encryption algorithms (such as ECDSA) have a significant reduction in security when facing quantum computing attacks and cannot effectively protect user privacy.
[0022] In this embodiment, the hardware information of the device, such as MAC address, CPU serial number, etc., is obtained as the unique identification of the device. This information can uniquely determine the identity of the device and ensure the uniqueness and identifiability of the device. The user's biometric information, such as fingerprints, facial images, and iris features, are obtained through biometric technology. These biometric features are unique to the user and can ensure the uniqueness and security of the user's identity. Based on the unique identification of the device and the biometric features, a digital identity on the chain is generated and mapped to the initial authority level. By integrating the unique identification of the device and the biometric features of the user to generate a digital identity on the chain, the uniqueness and security of the device and user identity are ensured, and identity impersonation and illegal access are prevented. Biometric technology has the advantages of high reliability and difficulty in being copied. point, which can effectively prevent identity fraud; for example, the misidentification rate of fingerprint recognition can be as low as one in a million, which greatly improves the accuracy of identity authentication. According to the preset rules, the generated on-chain digital identity is mapped to the initial permission level. The initial permission level can be set according to factors such as the type of device and the role of the user to ensure that different devices and users have corresponding access rights; for example, the initial permission level is set to ordinary users, who can only access basic functions of the system, such as viewing public information and performing basic operations. In addition to all the permissions of ordinary users, advanced users can also access some advanced functions, such as custom settings and advanced queries. Administrators have system management permissions and can perform operations such as user management, permission allocation, and system configuration.
[0023] Through adversarial training, a deep learning model can identify normal network traffic and potential threat traffic by learning a large amount of network traffic data. During the training process, the model introduces adversarial samples through adversarial training to improve its ability to detect complex threats. Adversarial training can make the model more robust, enabling it to effectively identify unknown threats and zero-day attacks. Through adversarial training, the model can better identify abnormal patterns in network traffic, improving the accuracy and recall rate of threat detection. For example, the overall accuracy of an LSTM-based model on the CIC-IDS-2017 dataset reaches 99%, effectively improving the efficiency and accuracy of abnormal traffic detection. The model collects network traffic data in real time and preprocesses it. Key features of the traffic data are extracted through convolutional operations, and a deep convolutional neural network is used to detect threats in the extracted key features and generate threat detection results. Real-time detection can promptly discover potential threats such as malware and network attacks, improving the system's response speed and security. For example, the D-PACK model only examines the first two packets of each flow, still has nearly 100% accuracy, and has an extremely low false positive rate. When the threat detection result exceeds a preset threshold, the system triggers a smart contract to automatically update the permission level of the device or user. The threshold can be adjusted according to the security requirements and actual situation of the system. For example, when more than 10 malicious access attempts are detected within 24 hours, an alarm is triggered. By setting a reasonable threshold, the system can promptly discover and handle potential network attack events, ensuring the security and stability of the system. The automatic execution of the smart contract ensures the timeliness and accuracy of permission updates, reducing the cost and risk of manual intervention;
[0024] According to the updated permission level and real-time network load, dynamically adjust the number of sub-chains of the blockchain. The sharded blockchain network technology divides the entire blockchain network into multiple shards, and each shard independently processes transactions and stores data, improving network throughput and scalability through parallel processing. When the network load increases, the system automatically increases the number of sub-chains to disperse the processing pressure; when the network load decreases, the system reduces the number of sub-chains to save resources; cross-chain threat intelligence synchronization is achieved through the relay chain. By dynamically adjusting the number of sub-chains, the system can better cope with changes in network load, improving network throughput and response speed. The sharded blockchain network technology enables the network to process transactions in parallel, significantly enhancing network performance and scalability; the relay chain, as a bridge between different blockchain networks, is responsible for transmitting threat intelligence information between each sub-chain to achieve coordinated defense across the network. When a sub-chain detects a threat, the threat intelligence is transmitted to other sub-chains through the relay chain to ensure that the entire network can promptly respond to potential security threats;
[0025] Threshold signature technology is a signature technology that divides the private key into multiple parts, each held by a different node. When signing, multiple nodes work together, using their respective private key parts to generate partial signatures, which are finally combined into a complete signature. This technology can improve the security and reliability of the system. Even if some nodes are attacked or fail, the attacker cannot obtain the complete private key and thus cannot forge signatures. Zero-knowledge proof technology allows users to prove their identity or identity attributes without revealing the actual information. Through complex mathematical algorithms and cryptography techniques, the verifier can be convinced that the statement claimed by the prover is true without obtaining any additional information. This technology can effectively protect the privacy and data security of users. By adopting threshold signature and zero-knowledge proof technologies, through the encryption verification of permission change records and cross-chain data, the authenticity and integrity of the data are ensured, preventing the data from being tampered with or leaked during transmission and storage, improving the transparency and trust of the system, and enabling the participants in the system to trust each other's operations and data more;
[0026] In summary, the present invention ensures the security and privacy of data by fusing the device unique identifier and biometric features to generate an on-chain digital identity, and by using threshold signature and zero-knowledge proof technologies to encrypt and verify permission change records and cross-chain data; by utilizing the sharded blockchain network technology and dynamically adjusting the number of sub-chains, the performance and scalability of the blockchain network are improved, effectively coping with the changes in network load and the synchronization requirements of threat intelligence; by using a deep learning model with adversarial training to detect network traffic in real time, when the threat detection result exceeds the threshold, the smart contract is triggered in real time to update the permission level, improving the real-time performance of threat detection and response; through the close cooperation of the system, an all-round network security protection from identity authentication, threat detection, network resource management to data encryption is achieved. This synergy not only improves the security of the system, but also significantly enhances the performance and resource utilization rate of the system.
[0027] In one embodiment, the obtaining of the device unique identifier and user biometric features includes: obtaining at least one of the physical identifier of the device hardware, machine code, MAC address, and CPU serial number as the unique identifier to generate an asymmetric key, which is only valid for the current device; using an optical sensor, image acquisition device, or fingerprint acquisition device to obtain the user's biometric information, where the biometric information includes at least one of fingerprint, facial image, and iris feature; the generating of the on-chain digital identity based on the device unique identifier and biometric features and mapping it to the initial permission level includes fusing the device identifier and biometric information in a trusted execution environment (TEE) to generate a unique on-chain digital identity and mapping it to the initial permission level according to a preset rule.
[0028] In this embodiment, by obtaining at least one of the physical identifier, machine code, MAC address, and CPU serial number of the device hardware, an asymmetric key is generated, which is only valid for the current device uniquely, ensuring the uniqueness and security of the device identity. The generation of the asymmetric key pair can use algorithms such as RSA and can be generated through online tools or command-line tools. The biological characteristic information of the user is obtained by using an optical sensor, an image acquisition device, or a fingerprint acquisition device, including at least one of fingerprint, facial image, and iris feature. These biological characteristic information have the characteristics of uniqueness and difficulty in replication, which can effectively improve the accuracy and security of identity authentication; in the trusted execution environment (TEE), the device identifier and the biological characteristic information are fused and processed to generate a unique on-chain digital identity. The trusted execution environment (TEE) provides a secure execution environment to ensure the security of the processing and storage of sensitive data; according to the preset rules, the generated on-chain digital identity is mapped to an initial permission level, for example, ordinary user, advanced user, administrator, etc.
[0029] In one embodiment, during the process of generating the on-chain digital identity, a hash algorithm is used to process the device unique identifier and the user biological characteristics to ensure the uniqueness and security of the digital identity.
[0030] In this embodiment, the hash algorithm processes the device unique identifier and the user biological characteristics. The hash algorithm is an algorithm that converts input data of any length into an output of a fixed length. The output result is called a hash value. By processing the device unique identifier and the user biological characteristic information through the hash algorithm, a unique on-chain digital identity is generated, ensuring the security of identity authentication. Even if an attacker obtains the hash value, it is impossible to reverse-engineer the original data, thereby protecting the identity information of the device and the user. The uniqueness characteristic of the hash algorithm ensures that the identity of each device and user is unique, preventing identity duplication and conflicts, which improves the reliability of identity authentication and ensures that only legitimate devices and users can pass the authentication. By generating the on-chain digital identity through the hash algorithm, the authentication requirements of different devices and users can be flexibly met. The high efficiency of the hash algorithm ensures the rapidity and efficiency of the identity authentication process, improving the scalability and flexibility of the system.
[0031] In one embodiment, S1 further includes calculating a real-time score based on the historical behavior of the device, triggering the adjustment of the smart contract permissions, and encrypting and storing the user iris feature through the trusted execution environment (TEE) to generate a composite hash value bound to the device public key.
[0032] In this embodiment, a real-time score is calculated by collecting and analyzing the historical behavior data of the device, such as the frequency of use of the device, the type of resources accessed, the time distribution of operations, etc. This score can reflect the usage pattern and potential risks of the device. For example, if a device is often accessed at abnormal times or places, or frequently attempts high-authority operations, its score may be reduced; based on the calculated real-time score, the smart contract can automatically adjust the permission level of the device. If the score is lower than the preset threshold, the smart contract can reduce the permission of the device and restrict its access to sensitive resources; conversely, if the score is higher than the threshold, the smart contract can increase the permission of the device; the user's iris feature data is encrypted and stored in the TEE to prevent the data from being stolen or tampered with during storage and transmission. The user's iris feature is further limited to the binding of the device public key. The system can more accurately identify and verify the user's identity and prevent identity fraud and illegal access. Iris recognition can collect images in a non-contact manner and obtain iris digital images from a certain distance without the user touching the device. At the same time, iris features have significant advantages in uniqueness, stability, anti-counterfeiting and non-contact.
[0033] In one embodiment, the real-time detection of network traffic by a deep learning model trained adversarially to generate threat detection results includes: real-time collection of network traffic data and preprocessing, extracting key features of the traffic data through convolution operations, and using a deep convolutional neural network to perform threat detection on the extracted key features and generate threat detection results.
[0034] In this embodiment, by real-time collection and preprocessing of network traffic data, the convolution layer of a convolutional neural network (CNN) is used to extract features from the preprocessed data. The CNN can effectively extract local features and patterns in the network traffic data through convolution operations. These features are crucial for identifying abnormal behaviors in network traffic. The extracted key features are input into a deep convolutional neural network for threat detection. The deep convolutional neural network can automatically learn and extract high-level features of data through multi-layer convolution and pooling operations, so as to more accurately identify threats in network traffic. The deep convolutional neural network outputs threat detection results, including information such as the type and confidence of the threat. These results can be used to monitor network traffic in real time and discover abnormal behaviors, such as DDoS attacks and malware propagation. The feature extraction and classification capabilities of the deep convolutional neural network can more accurately identify threats in network traffic and improve the accuracy and efficiency of threat detection. The deep learning model of adversarial training can effectively deal with unknown threats and zero-day attacks, improve the robustness and generalization ability of the model, and can timely discover and respond to network threats and reduce security risks by collecting and analyzing network traffic data in real time.
[0035] In one embodiment, during the training process of the adversarial training deep learning model, adversarial samples generated by a generative adversarial network are introduced to improve the model's detection ability for complex threats.
[0036] In this embodiment, introducing the adversarial samples generated by the generative adversarial network enables the model to be exposed to more diverse data during the training process, thereby enhancing the model's generalization ability. For example, when the BindingNet v2 model is trained using data with Tc < 0.3, the generalization ability is significantly improved to 64.25%. By introducing the adversarial samples generated by the adversarial network, the model can better identify abnormal patterns in network traffic, improving the accuracy and efficiency of threat detection. For example, the Transformer-based model has excellent performance in terms of accuracy and detection time, effectively solving the problems of remote dependence on network data traffic and data sample imbalance. The adversarial training deep learning model can process large-scale network traffic data and adapt to complex network environments. For example, the Deep Convolutional Generative Adversarial Network (DCGAN) improves the image generation quality and training stability by using a fully convolutional structure and batch normalization.
[0037] In one embodiment, the dynamic adjustment of the number of blockchain sub-chains and the cross-chain threat intelligence synchronization through the relay chain includes: real-time monitoring of the network load conditions, including transaction volume, data traffic, etc., and dynamically increasing or decreasing the number of blockchain sub-chains according to the network load conditions to optimize the network performance, and adjusting the cross-chain synchronization strategy according to the updated permission level and network load conditions to ensure data consistency and security.
[0038] In this embodiment, by real-time monitoring of indicators such as the transaction volume and data traffic of the network, the system can dynamically grasp the current load status of the network. According to the monitored network load conditions, the system will dynamically increase or decrease the number of blockchain sub-chains. When the network load increases, the number of sub-chains is increased to disperse the processing pressure and improve the network throughput; when the network load decreases, the number of sub-chains is reduced to save resources and avoid unnecessary energy consumption. The relay chain, as a bridge between different blockchain networks, is responsible for transmitting threat intelligence information between each sub-chain. When a sub-chain detects a threat, the threat intelligence is transmitted to other sub-chains through the relay chain to achieve the collaborative defense of the entire network. This is similar to establishing an information sharing mechanism between multiple security systems to ensure that each system can timely obtain and respond to potential security threats. According to the updated permission level and network load conditions, the system will adjust the cross-chain synchronization strategy to ensure data consistency and security. This includes selecting appropriate synchronization timing, synchronization frequency, and synchronization method to avoid data conflicts and inconsistencies. For example, a cross-chain mechanism based on hash locking can be used to construct a smart contract to ensure the security of information exchange between multiple chains.
[0039] In one embodiment, the use of threshold signature and zero-knowledge proof technologies to encrypt and verify permission change records and cross-chain data includes: using the threshold signature algorithm to achieve multi-node collaborative signature to ensure the legality and immutability of permission change records, and using the zero-knowledge proof technology to verify the authenticity and integrity of cross-chain data while protecting the privacy of the data.
[0040] In this embodiment, the threshold signature algorithm ensures the legality and immutability of permission change records through multi-node collaborative signature. Even if some nodes are attacked or fail, the attacker cannot obtain the complete private key and thus cannot forge the signature. The zero-knowledge proof technology proves identity or attributes without revealing the actual information, effectively protecting the privacy and data security of users. In cross-chain data verification, the zero-knowledge proof technology can verify the authenticity and integrity of data while protecting the privacy of the data. By encrypting and verifying permission change records and cross-chain data, the consistency and integrity of the data are ensured, preventing the data from being tampered with or leaked during transmission and storage. The use of threshold signature and zero-knowledge proof technologies improves the transparency and trust of the system, enabling the participants in the system to trust each other's operations and data more.
[0041] In one embodiment, when updating the permission level, the smart contract makes a comprehensive judgment in combination with the network environment parameters of the device and historical threat data.
[0042] In this embodiment, the smart contract assesses the security status of the device by accessing the network environment parameters of the device (such as IP address, network latency, bandwidth, etc.) and historical threat data (such as past attack records, threat types, etc.). These parameters and data can help the smart contract more accurately determine whether the device faces potential threats and thus decide whether to update the permission level. For example, if the device is located in a high-risk network environment or has been attacked multiple times historically, the smart contract may lower its permission level to reduce potential security risks; this helps prevent malicious or infected devices from obtaining excessive permissions, thereby improving the security of the entire system. The smart contract can flexibly adjust the permission level according to different network environments and threat situations. This flexibility enables the system to better adapt to various complex and changing network environments and improves the robustness of the system. The automatic execution feature of the smart contract makes the permission management process more automated and efficient. The system can automatically adjust permissions according to preset rules, reducing the need for manual intervention and lowering the management cost.
[0043] An embodiment of the present application further provides a blockchain-based network security protection system, which is characterized by including the following modules: a dynamic identity authentication module: obtaining a unique device identifier and user biometric features, generating a digital identity on the chain based on the unique device identifier and biometric features, and mapping it to an initial permission level; a threat detection module: detecting network traffic in real time through an adversarial training deep learning model to generate a threat detection result, and triggering a smart contract to update the permission level when the threat detection result exceeds a threshold; a blockchain network module: according to the updated permission level and real-time network load, using sharded blockchain network technology, dynamically adjusting the number of blockchain sub-chains and achieving cross-chain threat intelligence synchronization through a relay chain; an encryption verification module: using threshold signature and zero-knowledge proof technologies to encrypt and verify permission change records and cross-chain data.
[0044] The operation mode of the device in this embodiment refers to the foregoing method embodiment and will not be elaborated here.
[0045] In summary, the blockchain-based network security protection method and system provided by the present invention ensure the security and privacy of data by fusing the unique device identifier and biometric features to generate a digital identity on the chain, and using threshold signature and zero-knowledge proof technologies to encrypt and verify permission change records and cross-chain data; by using sharded blockchain network technology and dynamically adjusting the number of sub-chains, it improves the performance and scalability of the blockchain network, effectively coping with the changes in network load and the synchronization requirements of threat intelligence; by detecting network traffic in real time through an adversarial training deep learning model and triggering a smart contract to update the permission level in real time when the threat detection result exceeds the threshold, it improves the real-time performance of threat detection and response; through the close collaborative work of the system, it realizes all-round network security protection from identity authentication, threat detection, network resource management to data encryption. This synergy not only improves the security of the system, but also significantly enhances the performance and resource utilization rate of the system, effectively solving the problems in the prior art and having a wide range of application prospects.
[0046] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium provided in this application and used in the embodiments can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, there are various forms of RAM, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0047] It should be noted that in this text, the term "including", "comprising", or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, apparatus, article, or method that includes a series of elements includes not only those elements but also other elements not expressly listed, or elements that are inherent to such process, apparatus, article, or method. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, apparatus, article, or method that includes the element.
[0048] The above are only the preferred embodiments of this application, and thus do not limit the patent scope of this application. Any equivalent structural or equivalent process transformation made using the content of the specification and drawings of this application, or directly or indirectly applied in other related technical fields, is equally included in the patent protection scope of this application.
Claims
1. A network security protection method based on blockchain, characterized in that: The following steps are involved: S1 obtains the unique device identifier and user biometrics, generates an on-chain digital identity based on the unique device identifier and biometrics, and maps it to the initial permission level; S2 uses a deep learning model trained against adversarial training to detect network traffic in real time and generate threat detection results. When the threat detection results exceed the threshold, the smart contract is triggered to update the permission level. S3 uses sharded blockchain network technology to dynamically adjust the number of blockchain subchains and synchronize cross-chain threat intelligence through the relay chain based on the updated permission level and real-time network load; S4 uses threshold signature and zero-knowledge proof technology to encrypt and verify permission change records and cross-chain data.
2. The network security protection system according to claim 1, characterized in that: The obtaining of the unique device identification and user biometrics includes: obtaining at least one of the physical identification, machine code, MAC address, and CPU serial number of the device hardware as a unique identification to generate an asymmetric key, where the key is only valid for the current device; obtaining the user's biometric information using an optical sensor, an image acquisition device, or a fingerprint acquisition device, where the biometric information includes at least one of a fingerprint, a facial image, and an iris feature; The method of generating an on-chain digital identity based on the unique device identifier and biometrics and mapping it to an initial permission level includes fusing the device identifier and biometric information in a trusted execution environment (TEE) to generate a unique on-chain digital identity, and mapping it to an initial permission level according to preset rules.
3. The network security protection method according to claim 2, characterized in that: In the process of generating the on-chain digital identity, a hash algorithm is used to process the device unique identifier and the user's biometric features to ensure the uniqueness and security of the digital identity.
4. The network security protection method according to claim 3, characterized in that: The S1 also includes calculating a real-time score based on the device's historical behavior, triggering smart contract permission adjustment, encrypting and storing the user's iris features through a trusted execution environment (TEE), and generating a composite hash value bound to the device's public key.
5. The network security protection method according to claim 1, characterized in that: The real-time detection of network traffic to generate threat detection results through the deep learning model of adversarial training includes: real-time collection of network traffic data and preprocessing, extracting key features of the traffic data through convolution operations, and using a deep convolutional neural network to perform threat detection on the extracted key features and generate threat detection results.
6. The network security protection method according to claim 5, characterized in that: During the training process, the adversarial training deep learning model introduces adversarial samples generated by a generative adversarial network to improve the model's ability to detect complex threats.
7. The network security protection method according to claim 1, characterized in that: The dynamic adjustment of the number of blockchain sub-chains and the realization of cross-chain threat intelligence synchronization through the relay chain include: real-time monitoring of network load conditions, including transaction volume, data traffic, etc., dynamically increasing or decreasing the number of blockchain sub-chains according to the network load conditions to optimize network performance, and adjusting the cross-chain synchronization strategy according to the updated permission level and network load conditions to ensure data consistency and security.
8. The network security protection method according to claim 1, characterized in that: The use of threshold signature and zero-knowledge proof technology to encrypt and verify permission change records and cross-chain data includes: using a threshold signature algorithm to achieve multi-node collaborative signatures to ensure the legitimacy and non-tamperability of permission change records, and using zero-knowledge proof technology to verify the authenticity and integrity of cross-chain data while protecting the privacy of the data.
9. The network security protection method according to claims 1-8, characterized in that: When updating the permission level, the smart contract makes a comprehensive judgment based on the network environment parameters and historical threat data of the device.
10. A network security protection system based on blockchain, characterized in that: Includes the following modules: Dynamic identity authentication module: obtains the device's unique identifier and user's biometrics, generates a digital identity on the chain based on the device's unique identifier and biometrics, and maps it to the initial permission level; Threat detection module: The deep learning model of adversarial training is used to detect network traffic in real time to generate threat detection results. When the threat detection results exceed the threshold, the smart contract is triggered to update the permission level; Blockchain network module: Based on the updated permission level and real-time network load, the sharded blockchain network technology is used to dynamically adjust the number of blockchain sub-chains and synchronize cross-chain threat intelligence through the relay chain; Encryption verification module: uses threshold signature and zero-knowledge proof technology to encrypt and verify permission change records and cross-chain data.
Citation Information
Patent Citations
Method and system for realizing identity digitalization on a block chain in a trusted execution environment
CN109768865A
Network security vulnerability type analysis, vulnerability detection and information protection method
CN115720161A
Internet of Things data acquisition system and method based on distributed digital identity
CN117527265A
Security protection system for cloud side end collaborative interaction of power distribution Internet of Things
CN119402235A
Network control apparatus, network system, network control method, and non-transitory computer-readable medium
US20230421595A1
Cited By
Remote attestation method for trusted data space
CN120498700A
Block chain and privacy computing collaborative verification system
CN120597323A
Blockchain and privacy computing collaborative verification system
CN120597323B
Water conservancy information safety protection method and system
CN120639418A
DDoS cross-chain cooperative defense method, system and device, medium and terminal
CN121239451A