A blockchain-based network security protection method and system

By using a blockchain-based network security protection method, an on-chain digital identity is generated using the device's unique identifier and biometrics. Combined with adversarial training deep learning models and sharded blockchain network technology, dynamic access control and encrypted verification are achieved. This addresses the shortcomings of existing technologies in identity authentication, access control, and traffic monitoring, thereby improving the overall performance and security of network security.

CN120050094BActive Publication Date: 2026-01-30BIT MOTION TECHNOLOGY (SHENZHEN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510197310.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-21
Publication Date
2026-01-30
Estimated Expiration
2045-02-21

AI Technical Summary

Technical Problem

Existing network security protection technologies have many problems in identity authentication, access control, and traffic monitoring, and cannot effectively cope with complex and severe network security situations. In particular, when facing advanced persistent threats and zero-day attacks, detection efficiency and accuracy are difficult to guarantee, and the security of traditional encryption algorithms decreases under quantum computing attacks.

Method used

A blockchain-based network security protection method is adopted, which generates on-chain digital identity by obtaining the device's unique identifier and the user's biometric features. It combines a deep learning model with adversarial training to detect network traffic in real time, dynamically adjusts the number of sub-chains using sharded blockchain network technology, and uses threshold signature and zero-knowledge proof technology for encrypted verification to achieve dynamic permission management and cross-chain threat intelligence synchronization.

Benefits of technology

It improves the accuracy and security of identity authentication, enhances the real-time performance and accuracy of threat detection, improves the performance and scalability of the blockchain network, ensures data security and privacy, and improves the overall security and resource utilization of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050094B_ABST
    Figure CN120050094B_ABST
Patent Text Reader

Abstract

This invention relates to a blockchain-based network security protection method and system, aiming to address a series of challenges in existing network security protection technologies, such as single point of failure in identity authentication, insufficient static blockchain sharding, limitations in threat detection, and security issues in encryption algorithms. This method generates an on-chain digital identity by fusing unique device identifiers with user biometrics, and performs dynamic permission management based on this identity. It utilizes a deep learning model with adversarial training to detect network traffic in real time, generating threat detection results, and updates permission levels based on the detection results via smart contracts. Simultaneously, it employs sharded blockchain network technology to dynamically adjust the number of sub-chains according to network load, and achieves cross-chain threat intelligence synchronization through a relay chain. Furthermore, this invention uses threshold signatures and zero-knowledge proofs to encrypt and verify permission change records and cross-chain data, ensuring data security and privacy. This invention effectively improves the efficiency and reliability of network security protection, providing users with a safer and more reliable network environment.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of network security, and in particular to a network security protection method and system based on a blockchain. BACKGROUND

[0002] In today's era of rapid digital development, network security has become a critical issue. With the popularization of the Internet and the rapid progress of information technology, network attack methods are becoming increasingly diverse and complex, making existing network security protection technologies face serious challenges and many problems. Traditional network security protection methods often rely on centralized authentication mechanisms for identity authentication, such as common username and password combinations. However, this approach is vulnerable to single-point attacks, and once the centralized authentication server is compromised, a large amount of user authentication information is at risk of being leaked, thereby threatening the security of the entire network system. In terms of permission management, static permission allocation patterns cannot adapt to dynamic changes in network environments and user needs. For sudden network access needs, permissions cannot be adjusted in a timely and effective manner, which may result in legitimate users being unable to access the required resources or non-legitimate users taking advantage of the situation to obtain excessive permissions. In terms of network traffic monitoring, existing technologies often struggle to ensure detection efficiency and accuracy when faced with large-scale, high-concurrency network traffic. For new and complex network threats such as advanced persistent threats (APT) and zero-day attacks, traditional detection methods often fail to effectively identify them, allowing threats to lurk in the network and cause serious damage.

[0003] In summary, existing network security protection technologies have many problems in terms of identity authentication, permission management, traffic monitoring, encryption technology, blockchain application, and resource allocation, and there is an urgent need for an innovative and comprehensive network security protection method to address the increasingly complex and serious network security situation. SUMMARY

[0004] To overcome the above-mentioned defects of the prior art, embodiments of the present application provide a network security protection method and system based on a blockchain to solve the problems raised in the background art.

[0005] The application discloses a blockchain-based network security protection method, and has the characteristics that the method comprises the following steps: S1, acquiring a device unique identifier and a user biological feature, generating an on-chain digital identity based on the device unique identifier and the biological feature, and mapping the on-chain digital identity into an initial permission level; S2, generating a threat detection result by using a deep learning model trained through adversarial training to detect network traffic in real time, and triggering a smart contract to update the permission level when the threat detection result exceeds a threshold; S3, dynamically adjusting the number of blockchain sub-chains by using a sharded blockchain network technology according to the updated permission level and real-time network load, and synchronizing cross-chain threat intelligence through a relay chain; and S4, using threshold signature and zero-knowledge proof technology to encrypt and verify the permission change record and cross-chain data.

[0006] Further, the acquiring of the device unique identifier and the user biological feature comprises: acquiring at least one of a physical identifier, a machine code, a MAC address and a CPU serial number of device hardware as a unique identifier to generate an asymmetric key, the key being effective only for the current device; acquiring user biological feature information by using an optical sensor, an image acquisition device or a fingerprint acquisition device, the biological feature information comprising at least one of a fingerprint, a facial image and an iris feature; and the generating of the on-chain digital identity based on the device unique identifier and the biological feature and the mapping of the on-chain digital identity into the initial permission level comprise: fusing the device identifier and the biological feature information in a trusted execution environment (TEE) to generate a unique on-chain digital identity, and mapping the on-chain digital identity into the initial permission level according to a preset rule.

[0007] Further, in the process of generating the on-chain digital identity, a hash algorithm is used to process the device unique identifier and the user biological feature, so as to ensure the uniqueness and security of the digital identity.

[0008] Further, the S1 further comprises calculating a real-time score based on device historical behaviors, triggering a smart contract permission adjustment, encrypting and storing user iris features in a trusted execution environment (TEE), and generating a composite hash value bound to a device public key.

[0009] Further, the real-time detection of network traffic by using the deep learning model trained through adversarial training to generate the threat detection result comprises: acquiring network traffic data in real time, pre-processing the network traffic data, extracting key features of the network traffic data through convolution operation, and using a deep convolutional neural network to detect the extracted key features and generate the threat detection result.

[0010] Further, in the training process of the deep learning model trained through adversarial training, an adversarial sample generated by a generative adversarial network is introduced, so as to improve the detection capability of the model on complex threats.

[0011] Further, the dynamic adjustment of the number of blockchain subchains and the realization of cross-chain threat intelligence synchronization through the relay chain include real-time monitoring of network load conditions, including transaction volume, data traffic, etc., dynamically increasing or decreasing the number of blockchain subchains according to the network load conditions to optimize network performance, adjusting the cross-chain synchronization strategy according to the updated permission level and network load conditions to ensure data consistency and security.

[0012] Further, the encryption and verification of the permission change record and cross-chain data using threshold signature and zero-knowledge proof technology include using threshold signature algorithm to realize multi-node collaborative signature to ensure the legality and tamper resistance of the permission change record, and using zero-knowledge proof technology to verify the authenticity and integrity of cross-chain data while protecting data privacy.

[0013] Further, the smart contract updates the permission level in combination with the network environment parameters of the device and historical threat data.

[0014] The application also proposes a network security protection system based on blockchain, characterized by the following modules: dynamic identity authentication module: obtaining device unique identifier and user biological characteristics, generating on-chain digital identity based on device unique identifier and biological characteristics and mapping to initial permission level; threat detection module: real-time detection of network traffic through an adversarial training deep learning model to generate threat detection results, and triggering the smart contract to update the permission level when the threat detection results exceed the threshold; blockchain network module: dynamically adjusting the number of blockchain subchains and realizing cross-chain threat intelligence synchronization through the relay chain using sharded blockchain network technology according to the updated permission level and real-time network load; encryption and verification module: using threshold signature and zero-knowledge proof technology to encrypt and verify the permission change record and cross-chain data.

[0015] The network security protection method and system based on blockchain provided by the application ensure data security and privacy by fusing device unique identifier and biological characteristics to generate on-chain digital identity and using threshold signature and zero-knowledge proof technology to encrypt and verify the permission change record and cross-chain data; improve the performance and scalability of the blockchain network by using sharded blockchain network technology and dynamically adjusting the number of subchains to effectively cope with changes in network load and the synchronization needs of threat intelligence; improve the real-time threat detection and response by using an adversarial training deep learning model to real-time detect network traffic and triggering the smart contract to update the permission level when the threat detection results exceed the threshold; achieve comprehensive network security protection from identity authentication, threat detection, network resource management to data encryption through the close collaboration of the system, which not only improves the security of the system but also significantly improves the performance and resource utilization of the system, effectively solving the problems in the prior art and having wide application prospects.BRIEF DESCRIPTION OF DRAWINGS BRIEF DESCRIPTION OF DRAWINGS

[0016] Figure 1 A flowchart of a blockchain-based network security protection method according to an embodiment of the present application.

[0017] The implementation, functional features and advantages of the present application will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION

[0018] In order to make the purpose, technical solutions and advantages of the present application more clear, the present application will be further described in detail below with reference to the accompanying drawings and embodiments, it should be understood that the specific embodiments described herein are only used to explain the present application, and are not used to limit the present application.

[0019] Those skilled in the art can understand that, unless otherwise defined, all terms (including technical terms and scientific terms) used herein have the same meaning as generally understood by those skilled in the art to which the present application belongs, and it should also be understood that terms such as those defined in a general dictionary should be understood as having meanings consistent with those in the context of the prior art, and unless specifically defined as such herein, should not be interpreted in an idealized or overly formal sense.

[0020] Reference Figure 1 In order to achieve the above-mentioned purpose of the present application, the present application provides a blockchain-based network security protection method, comprising the following steps: S1 obtaining device unique identifier and user biological characteristics, generating on-chain digital identity based on device unique identifier and biological characteristics and mapping to initial permission level; S2 generating threat detection results by real-time detection of network traffic through a deep learning model trained by confrontation, when the threat detection results exceed the threshold, triggering the smart contract to update the permission level; S3 according to the updated permission level and real-time network load, using sharded blockchain network technology, dynamically adjusting the number of blockchain subchains and realizing cross-chain threat intelligence synchronization through relay chain; S4 using threshold signature and zero-knowledge proof technology, encrypting and verifying the permission change record and cross-chain data.

[0021] The conventional network security protection scheme in the prior art mainly relies on a centralized identity authentication system (such as LDAP), such a system has a single point of failure risk, the system relies on a centralized server, once the server is attacked, the security of the entire system will be threatened; when processing network traffic and threat detection, the blockchain technology usually adopts a static sharding method, which cannot dynamically adapt to changes in network load, and in the case of burst traffic (such as DDoS attack), resources are wasted and response is delayed; at the same time, existing encryption algorithms (such as ECDSA) have a significant decline in security when facing quantum computing attacks, and cannot effectively protect user privacy.

[0022] In the embodiment, the hardware information of the device, such as the MAC address, the CPU serial number, etc., is acquired as the unique identification of the device, which can uniquely determine the identity of the device and ensure the uniqueness and identifiability of the device; the biometric information of the user, such as the fingerprint, the facial image, and the iris feature, etc., is acquired by the biometric identification technology, which is unique to the user and can ensure the uniqueness and security of the user identity; the on-chain digital identity is generated based on the device unique identification and the biometric feature and is mapped to the initial permission level, which generates the on-chain digital identity by fusing the device unique identification and the user biometric feature, ensures the uniqueness and security of the device and user identity, prevents identity impersonation and illegal access, and the biometric identification technology has the advantages of high reliability and not easy to be copied, which can effectively prevent identity impersonation; for example, the misidentification rate of fingerprint identification can be as low as one in a million, which greatly improves the accuracy of identity authentication; according to the preset rules, the generated on-chain digital identity is mapped to the initial permission level, which can be set according to the type of the device, the role of the user, and other factors, to ensure that different devices and users have corresponding access permissions; for example, the initial permission level is set to a normal user, which can only access the basic functions of the system, such as viewing public information, performing basic operations, etc., a senior user can access some advanced functions, such as custom settings, advanced queries, etc., in addition to all the permissions of a normal user, and an administrator has the management permission of the system and can perform user management, permission allocation, system configuration, etc.

[0023] The deep learning model trained by adversarial training can identify normal network traffic and potential threat traffic by learning a large amount of network traffic data. During the training process, the model introduces adversarial samples through adversarial training to improve the detection capability of complex threats. Adversarial training can make the model more robust and effectively identify unknown threats and zero-day attacks. Through adversarial training, the model can better identify abnormal patterns in network traffic, improving the accuracy and recall rate of threat detection. For example, the overall accuracy of the LSTM-based model on the CIC-IDS-2017 dataset reached 99%, effectively improving the efficiency and accuracy of abnormal traffic detection. The model collects network traffic data in real time and pre-processes it. Through convolutional operations, it extracts key features of the traffic data and uses a deep convolutional neural network to perform threat detection on the extracted key features and generate threat detection results. Real-time detection can timely detect potential threats such as malware and network attacks, improving the response speed and security of the system. For example, the D-PACK model only checks the first two packets of each flow, still with nearly 100% accuracy and extremely low false positive rate. When the threat detection result exceeds the preset threshold, the system triggers the smart contract to automatically update the device or user's permission level. The threshold can be adjusted according to the system's security needs and actual situation. For example, when more than 10 malicious access attempts are detected within 24 hours, an early warning is triggered. By setting a reasonable threshold, the system can timely detect and handle potential network attack events, ensuring the security and stability of the system. The automatic execution of the smart contract ensures the timeliness and accuracy of permission updates, reducing the cost and risk of manual intervention.

[0024] According to the updated permission level and real-time network load, the number of blockchain sub-chains is dynamically adjusted. Sharding blockchain network technology divides the entire blockchain network into multiple shards, each of which independently processes transactions and stores data. Through parallel processing, it improves network throughput and scalability. When network load increases, the system automatically increases the number of sub-chains to disperse processing pressure. When network load decreases, the system reduces the number of sub-chains to save resources. Cross-chain threat intelligence synchronization is achieved through relay chains. By dynamically adjusting the number of sub-chains, the system can better respond to changes in network load, improving network throughput and response speed. Sharding blockchain network technology enables parallel processing of transactions, significantly improving network performance and scalability. Relay chains serve as a bridge between different blockchain networks, responsible for transmitting threat intelligence information between sub-chains to achieve coordinated defense across the network. When a sub-chain detects a threat, it transmits the threat intelligence to other sub-chains through relay chains to ensure that the entire network can respond to potential security threats in a timely manner.

[0025] The threshold signature technology is a signature technology that divides the private key into multiple parts, each part is held by a different node, and when signing, multiple nodes work together to generate partial signatures using their private key parts, and these partial signatures are finally combined into a complete signature, which can improve the security and reliability of the system, even if some nodes are attacked or fail, attackers cannot obtain the complete private key, so they cannot forge signatures, and the zero-knowledge proof technology allows users to prove their identity or identity attributes without revealing the actual information, through complex mathematical algorithms and cryptography, the verifier can be sure that the statement claimed by the prover is true without obtaining any additional information, which can effectively protect the privacy and data security of users, and by using threshold signature and zero-knowledge proof technology, the authenticity and integrity of the data are ensured by encrypting and verifying the permission change record and cross-chain data, preventing data from being tampered with or leaked during transmission and storage, improving the transparency and trustworthiness of the system, so that the participants in the system can trust each other's operations and data more;

[0026] In summary, the present application generates on-chain digital identity by fusing device unique identifier and biological characteristics, and uses threshold signature and zero-knowledge proof technology to encrypt and verify the permission change record and cross-chain data, ensuring the security and privacy of the data; using sharded blockchain network technology and dynamically adjusting the number of subchains, the performance and scalability of the blockchain network are improved, effectively responding to changes in network load and synchronization requirements of threat intelligence; through the real-time detection of network traffic by the adversarial training deep learning model, when the threat detection result exceeds the threshold, the intelligent contract updates the permission level in real time, improving the real-time performance of threat detection and response; through the close cooperation of the system, it realizes the all-round network security protection from identity authentication, threat detection, network resource management to data encryption, and this synergy not only improves the security of the system, but also significantly improves the performance and resource utilization of the system.

[0027] In one embodiment, the acquisition device unique identifier and user biological characteristics include: acquiring at least one of the physical identifier, machine code, MAC address, and CPU serial number of the device hardware as a unique identifier to generate an asymmetric key, which is only valid for the current device; using an optical sensor, image acquisition device or fingerprint acquisition device to acquire user biological characteristic information, the biological characteristic information including at least one of a fingerprint, a facial image and an iris feature; the on-chain digital identity based on the device unique identifier and biological characteristics and mapped to the initial permission level includes fusing the device identifier and biological characteristic information in a trusted execution environment (TEE) to generate a unique on-chain digital identity, and mapping to an initial permission level according to a preset rule.

[0028] In this embodiment, at least one of the physical identification, machine code, MAC address, and CPU serial number of the device hardware is obtained to generate an asymmetric key that is only valid for the current device, ensuring the uniqueness and security of the device identity. The generation of the asymmetric key pair can use algorithms such as RSA, generated through online tools or command line tools. The user's biometric information, including at least one of fingerprint, facial image, and iris feature, is obtained using optical sensors, image acquisition devices, or fingerprint acquisition devices. These biometric information has the characteristics of uniqueness and difficulty to copy, which can effectively improve the accuracy and security of identity authentication. In the trusted execution environment (TEE), the device identity and biometric information are fused to generate a unique on-chain digital identity. The trusted execution environment (TEE) provides a secure execution environment to ensure the security of sensitive data processing and storage. According to the preset rules, the generated on-chain digital identity is mapped to an initial permission level, such as a normal user, a senior user, an administrator, etc.

[0029] In one embodiment, in the process of generating the on-chain digital identity, a hash algorithm is used to process the device unique identifier and user biometric features to ensure the uniqueness and security of the digital identity.

[0030] In this embodiment, the hash algorithm is used to process the device unique identifier and user biometric features. Hash algorithm is an algorithm that converts input data of arbitrary length to fixed length output. The output result is called hash value. By processing the device unique identifier and user biometric information through the hash algorithm, a unique on-chain digital identity is generated, ensuring the security of identity authentication. Even if an attacker obtains the hash value, it is impossible to reverse the original data, thereby protecting the identity information of the device and user. The uniqueness of the hash algorithm ensures that each device and user has a unique identity, preventing identity duplication and conflict, which improves the reliability of identity authentication and ensures that only legitimate devices and users can pass the authentication. The hash algorithm can flexibly handle different device and user authentication requirements. The efficiency of the hash algorithm ensures the speed and efficiency of the identity authentication process, improving the scalability and flexibility of the system.

[0031] In one embodiment, the S1 further includes calculating a real-time score based on device historical behavior, triggering smart contract permission adjustment, encrypting user iris features through trusted execution environment (TEE), and generating a composite hash value bound to the device public key.

[0032] In this embodiment, by collecting and analyzing the historical behavior data of the device, such as the frequency of use, the type of resources accessed, the time distribution of operation, etc., a real-time score is calculated, which can reflect the usage pattern and potential risks of the device, for example, if a device frequently accesses at abnormal time or place, or frequently attempts high-privilege operations, its score may be reduced; according to the calculated real-time score, the smart contract can automatically adjust the permission level of the device, if the score is lower than the preset threshold, the smart contract can reduce the permission of the device to limit its access to sensitive resources; on the contrary, if the score is higher than the threshold, the smart contract can enhance the permission of the device; the user's iris feature data is stored in the TEE and encrypted to prevent data from being stolen or tampered with during storage and transmission, further binding the user's iris feature with the device public key, the system can more accurately identify and verify the user's identity, prevent identity fraud and illegal access, and the iris recognition can collect images in a non-contact manner, obtaining iris digital images from a certain distance without the user touching the device, while the iris feature has significant advantages in uniqueness, stability, anti-counterfeiting, and non-contact.

[0033] In one embodiment, the real-time detection of network traffic by the adversarial training deep learning model generates a threat detection result, which includes: real-time acquisition of network traffic data and preprocessing, extraction of key features of the traffic data through convolution operation, threat detection of the extracted key features using a deep convolutional neural network and generation of a threat detection result.

[0034] In this embodiment, by real-time acquisition and preprocessing of network traffic data, the convolutional layer of the convolutional neural network (CNN) is used to extract features from the preprocessed data. CNN can effectively extract local features and patterns in network traffic data through convolution operation, which is crucial for identifying abnormal behavior in network traffic. The extracted key features are input into a deep convolutional neural network for threat detection. The deep convolutional neural network can automatically learn and extract high-level features of the data through multiple convolution and pooling operations, thereby more accurately identifying threats in network traffic. The deep convolutional neural network outputs threat detection results, including threat type, confidence, etc. These results can be used to monitor network traffic in real time and detect abnormal behavior such as DDoS attacks, malware propagation, etc. The feature extraction and classification capabilities of the deep convolutional neural network can more accurately identify threats in network traffic, improving the accuracy and efficiency of threat detection. The adversarial training deep learning model can effectively deal with unknown threats and zero-day attacks, improving the robustness and generalization ability of the model. By real-time acquisition and analysis of network traffic data, network threats can be detected and responded to in a timely manner, reducing security risks.

[0035] In one embodiment, the adversarial training deep learning model introduces adversarial samples generated by a generative adversarial network during training to improve the model's detection ability of complex threats.

[0036] In this embodiment, the adversarial samples generated by the generative adversarial network enable the model to be exposed to more diverse data during training, thereby enhancing the model's generalization ability. For example, the generalization ability of the BindingNet v2 model is significantly improved to 64.25% when trained using data with Tc < 0.3. By introducing adversarial samples generated by the adversarial network, the model can better identify abnormal patterns in network traffic, improving the accuracy and efficiency of threat detection. For example, the Transformer-based model has excellent performance in terms of accuracy and detection time, effectively addressing the problems of network data traffic remote dependence and data sample imbalance. The adversarial training deep learning model can handle large-scale network traffic data and adapt to complex network environments. For example, the deep convolutional neural network (DCGAN) improves image generation quality and training stability by using a fully convolutional structure and batch normalization.

[0037] In one embodiment, the dynamic adjustment of the number of blockchain subchains and the synchronization of cross-chain threat intelligence through the relay chain includes real-time monitoring of network load conditions, including transaction volume, data traffic, etc. According to the network load conditions, the number of blockchain subchains is dynamically increased or decreased to optimize network performance. According to the updated permission level and network load conditions, the cross-chain synchronization strategy is adjusted to ensure data consistency and security.

[0038] In this embodiment, by monitoring indicators such as transaction volume and data traffic in real time, the system can dynamically monitor the current load status of the network. According to the monitored network load conditions, the system will dynamically increase or decrease the number of blockchain subchains. When the network load increases, the number of subchains is increased to disperse the processing pressure and improve the throughput of the network. When the network load decreases, the number of subchains is reduced to save resources and avoid unnecessary energy consumption. The relay chain serves as a bridge between different blockchain networks, responsible for transmitting threat intelligence information between subchains. When a threat is detected in one subchain, the relay chain transmits the threat intelligence to other subchains, enabling coordinated defense across the network. This is similar to establishing an information sharing mechanism between multiple security systems to ensure that each system can timely acquire and respond to potential security threats. According to the updated permission level and network load conditions, the system adjusts the cross-chain synchronization strategy to ensure data consistency and security, including selecting appropriate synchronization timing, synchronization frequency, and synchronization methods to avoid data conflicts and inconsistencies. For example, a cross-chain mechanism based on hash locking can be used to construct smart contracts to ensure the security of information exchange between multiple chains.

[0039] In one embodiment, the threshold signature and zero-knowledge proof technology are used to encrypt and verify the permission change record and cross-chain data, including: using a threshold signature algorithm to realize multi-node collaborative signature, ensuring the legality and tamper resistance of the permission change record, and using a zero-knowledge proof technology to verify the authenticity and integrity of the cross-chain data while protecting the privacy of the data.

[0040] In this embodiment, the threshold signature algorithm ensures the legality and tamper resistance of the permission change record through multi-node collaborative signature, so that even if some nodes are attacked or fail, the attacker cannot obtain the complete private key, thus cannot forge a signature. The zero-knowledge proof technology proves the identity or property without revealing the actual information, effectively protecting the privacy and data security of the user. In cross-chain data verification, the zero-knowledge proof technology can verify the authenticity and integrity of the data while protecting the privacy of the data. By encrypting and verifying the permission change record and cross-chain data, the consistency and integrity of the data are ensured, preventing the data from being tampered with or leaked during transmission and storage. The use of threshold signature and zero-knowledge proof technology improves the transparency and trustworthiness of the system, making the participants in the system more trust each other's operations and data.

[0041] In one embodiment, the smart contract comprehensively judges the network environment parameters and historical threat data of the device when updating the permission level.

[0042] In this embodiment, the smart contract assesses the security status of the device by accessing the network environment parameters (such as IP address, network delay, bandwidth, etc.) and historical threat data (such as past attack records, threat types, etc.) of the device. These parameters and data can help the smart contract more accurately determine whether the device is facing potential threats, thus deciding whether to update the permission level. For example, if the device is located in a high-risk network environment or has been attacked multiple times in the past, the smart contract may lower its permission level to reduce potential security risks. This helps prevent malicious or infected devices from obtaining excessive permissions, thereby improving the security of the entire system. The smart contract can flexibly adjust the permission level according to different network environments and threat situations, which makes the system better adapt to various complex and changing network environments, improving the robustness of the system. The automatic execution feature of the smart contract makes the permission management process more automated and efficient. The system can automatically adjust permissions according to pre-set rules, reducing the need for human intervention and lowering management costs.

[0043] An embodiment of the present application also provides a network security protection system based on a blockchain, characterized in that it comprises the following modules: a dynamic identity authentication module: obtaining a device unique identifier and a user biological feature, generating an on-chain digital identity based on the device unique identifier and the biological feature, and mapping the on-chain digital identity to an initial permission level; a threat detection module: real-time detection of network traffic by a deep learning model trained through adversarial training to generate a threat detection result, and triggering an intelligent contract to update the permission level when the threat detection result exceeds a threshold; a blockchain network module: dynamically adjusting the number of blockchain sub-chains and synchronizing cross-chain threat intelligence through a relay chain based on the updated permission level and real-time network load by using a sharded blockchain network technology; and an encryption verification module: using threshold signature and zero-knowledge proof technology to encrypt and verify the permission change record and cross-chain data.

[0044] In the present embodiment, the operation mode of the device is as described in the foregoing method embodiment, which will not be repeated here.

[0045] In summary, the network security protection method and system based on a blockchain provided by the present application ensure the security and privacy of data by fusing a device unique identifier and a biological feature to generate an on-chain digital identity and using threshold signature and zero-knowledge proof technology to encrypt and verify the permission change record and cross-chain data; improve the performance and scalability of the blockchain network by using a sharded blockchain network technology and dynamically adjusting the number of sub-chains to effectively cope with changes in network load and the synchronization needs of threat intelligence; improve the real-time threat detection and response by real-time detection of network traffic by a deep learning model trained through adversarial training and real-time triggering of an intelligent contract to update the permission level when the threat detection result exceeds a threshold; and achieve all-round network security protection from identity authentication, threat detection, network resource management to data encryption through the close cooperation of the system, which not only improves the security of the system but also significantly improves the performance and resource utilization of the system, effectively solving the problems in the prior art and having a wide application prospect.

[0046] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when executed, can include the processes of the above-mentioned embodiment methods. Any reference to memory, storage, databases, or other media in this application and in examples provided herein, unless specifically stated otherwise, can include non-volatile and / or volatile memory. Non-volatile memory can include, for example, read only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include, for example, random access memory (RAM), or external cache memory. As an illustration and not a limitation, RAM can be available in many forms such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), Synchlink DRAM (SLDRAM), Rambus DRAM (RDRAM), direct Rambus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM).

[0047] It should be noted that the terms "comprising", "including", or any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, device, article, or method that comprises a list of elements does not include only those elements recited, but can also include other elements not expressly listed or inherent to such process, device, article, or method. Without further limitation, an element defined by the phrase "comprising a" does not exclude the presence of additional identical elements in the process, device, article, or method that includes the element.

[0048] The above description is only the preferred embodiment of the present application, and does not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation using the content of the specification and drawings, or direct or indirect application in other related technical fields, is also included in the patent protection scope of the present application.

Claims

1. A blockchain-based cyber security protection method, characterized in that, The method comprises the following steps: S1: obtaining a device unique identifier and a user biometric feature, generating an on-chain digital identity based on the device unique identifier and the biometric feature, and mapping the on-chain digital identity to an initial permission level; The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The method comprises the following steps: The threshold signature and zero-knowledge proof technology are used to encrypt and verify the permission change record and cross-chain data, including: using a threshold signature algorithm to realize multi-node collaborative signature, ensuring the legality and non-tamperability of the permission change record, using zero-knowledge proof technology to verify the authenticity and integrity of cross-chain data, and protecting the privacy of data.

2. The network security protection method of claim 1, wherein, The threat detection result is generated by real-time detection of network traffic by the adversarial training deep learning model, including: real-time collection of network traffic data and preprocessing, extraction of key features of the traffic data through convolution operation, threat detection of the extracted key features by a deep convolutional neural network, and generation of a threat detection result.

3. The network security protection method of claim 2, wherein, In the training process of the adversarial training deep learning model, adversarial samples generated by a generative adversarial network are introduced to improve the detection capability of the model for complex threats. 4.A blockchain-based network security protection system configured to implement the network security protection method according to any one of claims 1-3, characterized in that, The system includes the following modules: A dynamic identity authentication module: obtains a device unique identifier and a user biological feature, generates an on-chain digital identity based on the device unique identifier and the biological feature, and maps the on-chain digital identity to an initial permission level; A threat detection module: generates a threat detection result by real-time detection of network traffic by an adversarial training deep learning model, and triggers an intelligent contract to update the permission level when the threat detection result exceeds a threshold value; A blockchain network module: dynamically adjusts the number of blockchain subchains according to the updated permission level and real-time network load, and synchronizes cross-chain threat intelligence through a relay chain by using a sharded blockchain network technology; An encryption verification module: uses threshold signature and zero-knowledge proof technology to encrypt and verify the permission change record and cross-chain data.

Citation Information

Patent Citations

  • Method and system for realizing identity digitalization on a block chain in a trusted execution environment

    CN109768865A

  • Internet of Things data acquisition system and method based on distributed digital identity

    CN117527265A