Federal cloud service method and system based on alliance block chain
By adopting a federated cloud service method based on alliance blockchain in the global cloud resource federated management, the mutual recognition and interoperability problem between different resource providers and users is solved, the effect of user identity recognition and cloud resource interoperability is achieved, and the confidentiality and credibility of transactions are ensured.
Patent Information
- Application Number
- CN202510186018.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-19
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-02-19
AI Technical Summary
In the global cloud resource federal management and trusted services, it is necessary to solve the problem of mutual recognition and interoperability between different resource providers and users, especially on the premise that the unified identity authentication and authorization system in various countries and regions remains unchanged.
The federated cloud service method based on the federated blockchain is adopted, and the first regional peer node is invited to join through the members of the cloud federated blockchain, and the node initialization and identity authentication are completed when the pass ratio is reached or above. Users generate identity authentication identifiers and conduct cross-domain access through public key/private key encryption mechanism to realize the on-link storage of cloud resource application, review and transaction data.
It realizes mutual recognition of user identities and interoperability of cloud resources between different countries and regions, ensures the confidentiality and credibility of internal transactions in the Cloud Federation blockchain, and solves the problem of mutual recognition and interoperability between resource providers and users.
Smart Images

Figure CN120075232A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of cloud computing, and discloses a federated cloud service method and system based on a consortium blockchain. Background Art
[0002] Some countries / regions have established scientific research cloud federated service platforms within their respective jurisdictions, such as China Science Cloud, European EGI, and African Open Science Platform (AOSP). In September 2019, during the CODATA Beijing Conference, the China Science Cloud team pioneered the initiative to jointly build the "Global Open Science Cloud" (GOSC). The "Global Open Science Cloud" is based on the open science clouds or scientific research informatization infrastructure and platforms under construction or to be built in current countries and regions. Following the principle of mutually recognized peer-to-peer exchange and sharing of resources and services, and adopting common technical specifications and interface standards, it realizes cross-continental cloud service mutual access, interoperability, and federated services, achieving network interconnection, resource exchange, data and information sharing, algorithm and software tool sharing, etc., to comprehensively support major global scientific and technological innovations.
[0003] According to the public access situation of data, blockchains are divided into public blockchains, consortium blockchains, and private blockchains. Public blockchain data is completely open and can be accessed by anyone. For example, blockchains are designed to achieve value transfer and information sharing on a global scale; private blockchain data is only for internal use and is often used for enterprise internal management to ensure data security and efficient processing to meet specific business needs; consortium blockchains are between public blockchains and private blockchains and are jointly managed by multiple organizations or institutions. The management and read / write permissions of each organization or institution can be set. Each node of the consortium blockchain can only join and exit the network after authorization and usually corresponds to an entity organization. Mature open-source consortium blockchains in the market include Hyperledger Fabric, FISCO BCOS, etc. The mutual recognition between nodes is generally achieved through digital certificates. Generally, a CA node collects user personal identity information and issues a digital certificate for it; the user personal identity information is recorded in the state database. When the user cancels the account, the digital certificate will be revoked and the relevant personal identity information will also be deleted.
[0004] When each country / region establishes its own federal system, it will operate its own unified identity authentication and authorization system and IaaS cloud resource management system. Therefore, when building a global cloud resource federation management and trusted service in the form of peer nodes, it is necessary to focus on the application of the regionally self-built unified identity authentication in the consortium blockchain. While managing peers among nodes, keep the unified identity authentication and authorization systems of each country and region unchanged, and achieve mutual recognition of user identities and interoperability of cloud resources among different countries and regions. Therefore, it is necessary to construct a federated cloud service method based on the consortium blockchain to solve the problem of mutual recognition and interoperability between different resource providers and users. Summary of the Invention
[0005] To solve the problem of mutual recognition and interoperability between different resource providers and users, the present invention discloses a federated cloud service method based on the consortium blockchain. The method includes:
[0006] When a member of the cloud federation consortium blockchain invites a peer node in the first region to join and obtains permission, a new peer node in the first region is added;
[0007] The peer node in the first region is initialized. The peer node in the first region generates a pair of public and private keys, and exchanges the public key, regional management service URL, and regional identification code with other peer nodes in the cloud federation consortium blockchain;
[0008] The peer node in the first region calls the regional management service URL of other peer nodes to obtain a list of available cloud resources;
[0009] The peer node in the first region generates an identity authentication identifier for the user of the peer node in the first region; the identity authentication identifier includes the regional identification code information of the peer node in the first region and the uuid returned by the unified identity authentication and authorization service;
[0010] The user of the peer node in the first region submits a cloud resource application. The peer node in the first region generates an application for cloud resource transaction and signs it, and packages the application cloud resource transaction information into a block for storage on the chain; the application for cloud resource transaction includes application user information and application cloud resource configuration information, where the application user information is encrypted using the public key of the peer node in the second region, and the peer node in the second region is the peer node of the region where the cloud resource is applied for;
[0011] The peer node in the second region periodically pulls the application cloud resource transaction for the peer node in its own region from the cloud federation consortium blockchain, decrypts and parses it using the private key of the peer node in its own region, converts it into relational data, and stores the user application record in the local database;
[0012] The administrator of the second - region peer node obtains the application records of the local database from the front - end page, verifies the identity authentication identifier of the applying user. After successful verification, the second - region peer node generates and signs an audit cloud resource transaction, and packages the audit cloud resource transaction information into a block for storage on the chain; the audit cloud resource transaction information includes applying user information, applying cloud resource configuration information, audit result information, and auditing user information. Among them, the applying user information and auditing user information are encrypted using the public key of the first - region peer node.
[0013] The cloud resource center of the second - region peer node releases the cloud resources and updates the used cloud resource table and available cloud resource table in the local database.
[0014] The first - region peer node regularly pulls the audit results of the user cloud resource applications of its own region from the cloud - federated alliance blockchain, decrypts and parses them using the private key of its own region peer node, converts them into relational data, and stores the audit results in the local database.
[0015] The user of the first - region peer node uses the applied cloud resources.
[0016] When a member of the cloud - federated alliance blockchain invites the first - region peer node to join, when the passing ratio is reached or above, the first - region peer node joins the cloud - federated alliance blockchain.
[0017] When the first - region peer node exits the cloud - federated alliance blockchain, when the passing ratio is reached or above, the first - region peer node exits the cloud - federated alliance blockchain.
[0018] The formula for the passing ratio is:
[0019]
[0020] where n represents the number of members who agree, and m represents the total number of members of the cloud - federated alliance blockchain.
[0021] The first - region peer node exiting the cloud - federated alliance blockchain has no impact on users who are using cloud resources.
[0022] The regional management service of the second - region peer node conducts cloud resource expiration detection. If cloud resources that will expire in 1 week are detected, it prompts the user to renew;
[0023] If expired cloud resources are detected, the relevant cloud resources are deleted for cloud resource recycling.
[0024] The initialization steps of the first - region peer node also include:
[0025] Deploy and run the consortium chain software, and the software version needs to be consistent with the cloud - federated alliance blockchain, and synchronize the relevant ledger.
[0026] Deploy the operation area management service, whose responsibility is to call the relevant management and operation interfaces of the cloud resource center and cross-regionally call the area management services of peer nodes in other regions;
[0027] Deploy the operation front-end service to provide a unified cloud resource management and access entry for users in this region;
[0028] Deploy the unified identity authentication and authorization service to provide identity authentication and authorization for users in this region, generate identity authentication identifiers for users, and provide identity authentication identifier authentication services;
[0029] Deploy the relevant software of the cloud resource center. If the peer node in this region does not provide cloud resource services, there is no need to deploy;
[0030] Deploy and run the local database and initialize the relevant data tables;
[0031] Exchange public keys, area management service URLs, and area identification codes with other members of the cloud federation blockchain.
[0032] The application record table of the local database includes: application record id, user identity authentication identifier, cloud resource configuration applied by the user, application duration, peer node and cloud resource center of the requested resource, reviewer, application status; among them, the cloud resource configuration applied by the user can optionally apply for two basic resources: cloud host and object storage.
[0033] The steps for the administrator of the second peer node to verify the identity authentication identifier of the applying user specifically include:
[0034] The second peer node generates an identity authentication identifier for the user of the second peer node, that is, generates an identity authentication identifier for the administrator;
[0035] The administrator reviews the cloud resource application, and sends a cloud resource review request from the front-end page. The content of the cloud resource review request includes: identity authentication identifier of the applying user, cloud resource application content, and review result;
[0036] The area management service of the second peer node receives the request and determines the peer node where the user is located according to the identity authentication identifier of the applying user;
[0037] The second peer node requests the area management service of the first peer node to verify the identity authentication identifier of the applying user;
[0038] The area management service of the first peer node requests the unified authentication and authorization service of its own peer node to verify the identity authentication identifier of the applying user and returns the result to the area management service of its own peer node;
[0039] The area management service of the first area peer node returns the authentication result to the front end;
[0040] After verifying the identity of the applying user, the area management service of the second area peer node updates the application record table in the local database, updates the application status to approved; updates the auditor to the identity authentication identifier of the administrator.
[0041] Second, the present invention also provides a federated cloud service system based on a consortium blockchain, which is characterized in that it is used to implement the above method, including:
[0042] The cloud federation consortium blockchain is run by the consortium chain software of multiple area peer nodes, and is composed of modules such as a consensus algorithm and a ledger. The peer nodes trust each other through public keys / private keys, and are used to achieve consensus among peer nodes and ensure trusted services for cross-domain federation;
[0043] The area peer node includes software or services such as consortium chain software, local database, area management service, front-end service, and unified identity authentication and authorization service, and is used to interact with the cloud federation consortium blockchain through APIs to implement functions such as user authentication and authorization of the local area peer node, user authentication of cross-area peer nodes, cloud resource management, user management, and service management, realize cloud resource application, audit transaction data on the chain, and provide a unified front-end access entrance; The cloud resource center is used to provide cloud resource services. The cloud resource service types include cloud hosts and object storage. The cloud host realizes virtualized management of computing, storage, and network resources through a private cloud management system, and the object storage realizes storage resource pooling management through an object storage system.
[0044] The present invention proposes a federated cloud service method based on a consortium blockchain. Its advantage is that each user of the area peer node will have an identity authentication identifier associated with the area node identifier, which is unique in the entire federated cloud service. When starting a transaction, the user identity information in the transaction information is encrypted, and the user identity is authenticated through cross-domain access, so that the applying user and the auditing user information are only visible to the applicant and the auditor, and other area peer nodes can only read the transaction content and cannot know the user information, realizing the confidentiality and trust of transactions within the cloud federation consortium blockchain. Description of the Drawings
[0045] Figure 1 It is a system diagram of a federated cloud service system based on a consortium blockchain according to an embodiment of the present invention;
[0046] Figure 2 It is a flowchart of a federated cloud service method based on a consortium blockchain according to an embodiment of the present invention;
[0047] Figure 3"Join Blockchain Transaction" block structure of the federated cloud service based on the consortium blockchain according to an embodiment of the present invention;
[0048] Figure 4 "Apply for Cloud Resource Transaction" block structure of the federated cloud service based on the consortium blockchain according to an embodiment of the present invention;
[0049] Figure 5 "Audit Cloud Resource Transaction" block structure of the federated cloud service based on the consortium blockchain according to an embodiment of the present invention;
[0050] Figure 6 "Exit Blockchain Transaction" block structure of the federated cloud service based on the consortium blockchain according to an embodiment of the present invention. Detailed implementation manners
[0051] The following describes the best implementation manners of the present invention through embodiments. It should be understood that the specific implementation manners here are used to explain the present invention in detail and should not be construed as a limitation to the present invention. It should be noted that various changes and modifications can be made on the premise of following the principles and core scope of the present invention, and these changes should be regarded as falling within the protection scope of the present invention. In combination with the accompanying drawings, the specific implementation steps of the present invention are described in detail.
[0052] Figure 1 A federated cloud service system provided by an embodiment of this specification is shown. The system mainly includes a cloud federation consortium blockchain, regional peer nodes, and a cloud resource center.
[0053] The cloud federation consortium blockchain is run by the consortium chain software of multiple regional peer nodes and is used to achieve consensus among peer nodes and ensure trusted services for cross-domain federation.
[0054] In a specific embodiment, the cloud federation consortium blockchain consists of modules such as a consensus algorithm and a ledger. Among them, the consensus algorithm can be selected from PBFT, PoW, PoS, DPos, RAFT, etc. to implement; the ledger is based on a Merkle tree to achieve distributed storage. The peer nodes trust each other through public keys / private keys. For example, asymmetric key encryption algorithms such as RSA, DSA, ECC, DH, etc. can be used. The consortium chain software can be implemented using Hyperledger Fabric, FISCO BCOS, etc.
[0055] The regional peer nodes interact with the cloud federation consortium blockchain through the API and are used to implement functions such as user authentication and authorization of peer nodes in this region, user authentication of cross-regional peer nodes, cloud resource management, user management, service management, etc., realize the application for cloud resources, audit transaction data to be uploaded to the chain, and provide a unified front-end access entrance.
[0056] In a specific embodiment, the regional peer node includes software or services such as alliance chain software, local database, regional management service, front-end service and unified identity authentication and authorization service.
[0057] Among them, the unified identity authentication and authorization service is used to implement user authentication and authorization of peer nodes in this region; the front-end service is used to provide users with a unified access portal; the regional management service is used to provide cloud resource management, user management, service management and other related interfaces within this region; the alliance chain software is used to encapsulate user requests into transactions and sign them, and store transaction results on the chain; the local database is a relational database used to record local business data, including user information, cloud resource information, regional peer node information and resource application information.
[0058] The cloud resource center is called by the regional management service to provide cloud resource services and is authenticated through the unified identity authentication and authorization service.
[0059] In a specific embodiment, the cloud service types provided by the cloud resource center include cloud hosts and object storage. The cloud hosts are virtualized and managed by a private cloud management system for computing, storage, and network resources, and object storage is managed by an object storage system for storage resource pooling.
[0060] Figure 2 A flowchart of a federated cloud service method based on a consortium blockchain according to an embodiment of the present invention is provided as follows: Figure 2 As shown, the method of the present invention comprises the following steps:
[0061] S101: A member of the cloud federation alliance blockchain invites a first regional peer node to join. When the passing ratio is reached or above, the "new regional peer node" joins the cloud federation alliance blockchain. In order to better describe the method of the present invention, it will be referred to as the first regional peer node below.
[0062] Wherein, step S101 specifically includes the following steps:
[0063] S1011: One of the members of the cloud federation alliance blockchain initiates an invitation to the first regional peer node, inviting the first regional peer node to join the cloud federation alliance blockchain. The invitation request contains information about the first regional peer node, i.e., whether it provides unified identity authentication and authorization services, whether it provides cloud resource services, etc. The request is packaged as a "join blockchain transaction" and is stored on the chain after signing.
[0064] In a specific embodiment, the block structure is as follows Figure 3As shown, the block body includes a transaction header, a transaction subject, and transaction content. The transaction header includes the transaction time, transaction hash, and version number. The transaction subject is the first regional peer node, and the transaction content includes an introduction to the first regional peer node, information on whether the first regional peer node provides unified identity authentication and authorization services, and information on whether the first regional peer node provides cloud resource services.
[0065] S1012: All members of the cloud federation blockchain vote on the invitation for the first regional peer node to join, reply with consent or dissent, and sign. If the passing ratio is reached or exceeded, the first regional peer node joins and enters process S1013; otherwise, it cannot join and the process terminates.
[0066] The calculation formula for the passing ratio is:
[0067]
[0068] where n represents the number of members who agree; m represents the total number of members of the cloud federation blockchain.
[0069] S1013: Initialize the first regional peer node.
[0070] Among them, the initialization includes the following steps:
[0071] ①. Generate a pair of public / private keys.
[0072] ②. Deploy and run the consortium chain software, and the software version needs to be consistent with the cloud federation blockchain, and synchronize the relevant ledger.
[0073] ③. Deploy and run the regional management service, whose responsibility is to call the relevant management and operation interfaces of the cloud resource center and cross-regionally call the regional management services of other regional peer nodes.
[0074] ④. Deploy and run the front-end service to provide a unified cloud resource management and access entry for users in this region.
[0075] ⑤. Deploy and run the unified identity authentication and authorization service to provide identity authentication and authorization for users in this region, generate an identity authentication identifier of RegionCode-uuid for users, provide an identity authentication identifier authentication service, and the identity authentication identifier includes the regional identification code information of the first regional peer node and the uuid returned by the unified identity authentication and authorization service.
[0076] ⑥. Deploy the relevant software of the cloud resource center. If this regional peer node does not provide cloud resource services, there is no need to deploy.
[0077] ⑦. Deploy and run the local database and initialize the relevant data tables.
[0078] The "Available Cloud Resource Table" is batch-written according to the cloud resources provided by the cloud resource centers in the peer nodes of this region; if no cloud resources are provided, it is initialized to be empty.
[0079] The "Used Cloud Resource Table" is initialized to be empty and updated according to application and approval transactions.
[0080] The "User Table" is updated according to user registration.
[0081] The "Regional Peer Node Information Table" is updated in item ⑧.
[0082] The "Application Record Table" is updated according to the cloud resource application situation of users.
[0083] ⑧. Exchange public keys, regional management service URLs, and regional identification codes (RegionCode) with other members of the cloud federation blockchain.
[0084] S102: Users of the first regional peer node apply for cloud resources.
[0085] Among them, step S102 specifically includes the following steps:
[0086] S1021: Users of the first regional peer node log in to the front-end page through the unified authentication and authorization service for authentication; the unified authentication and authorization service returns relevant information to the users, including: user email, user name, affiliated regional peer node, identity authentication identifier RegionCode-uuid, and JWT token.
[0087] Among them, Json web token (JWT) is an open standard based on JSON executed to transfer claims between network application environments. The claims of JWT can be used to transfer the authenticated user identity information between the identity provider and the service provider, so as to obtain resources from the resource server. This token can also be directly used for authentication and can also be encrypted.
[0088] S1022: The front end automatically polls and calls the regional management service URLs of other regional peer nodes to obtain the available cloud resource list.
[0089] S1023: Users apply for cloud resources. The front-end page sends a cloud resource application request, and the request header carries the JWT token. The request content includes: user information (user email, user name, identity authentication identifier RegionCode-uuid), cloud resource application information (configured cloud resources for application, duration, cloud resource center of the applied resources).
[0090] To better describe the method of the present invention, the regional peer node of the applied resources will hereinafter be referred to as the second regional peer node.
[0091] S1024: The area management service writes the user application record into the "Application Record Table" of the local database.
[0092] In a specific embodiment, the database definition of the "Application Record Table" in the local database is as follows:
[0093]
[0094]
[0095] S1025: Trigger the alliance chain software, call the relevant interface to read the "Application Record Table" of the local database, generate the "Application for Cloud Resource Transaction" and sign it, and package the "Application for Cloud Resource Transaction" information into a block for storage on the chain.
[0096] In a specific embodiment, the block structure is as Figure 4 shown. The block body includes a transaction header, a transaction body, and transaction content. Among them, the transaction header includes the transaction time, transaction hash, and version number. The transaction body is the applicant and the auditor. The transaction content includes the applying user and the cloud resource configuration information for the application.
[0097] Among them, the specific content of the "Application for Cloud Resource Transaction" is as follows:
[0098] Applying user information: It contains the user identity authentication identifier. Among them, the applying user information is encrypted with the public key of the second area peer node.
[0099] Cloud resource configuration information for the application: It includes cloud resource configuration, the name of the cloud resource center of the second area peer node, the cloud resource usage duration, etc.
[0100] S103: The second area peer node regularly pulls, parses, and stores the "Application for Cloud Resource Transaction" for this area peer node from the cloud federation alliance blockchain.
[0101] In a specific embodiment, S103 includes the following steps:
[0102] S1031: The alliance chain software of the second area peer node calls the relevant interface to regularly pull the "Application for Cloud Resource Transaction" for this area peer node from the cloud federation alliance blockchain, decrypts and parses it using its own private key, and converts it into relational data.
[0103] S1032: Store the user application record in the "Application Record Table" of the local database.
[0104] In a specific embodiment, the database definition of the "Application Record Table" in the local database is the same as the database table definition in step S1024.
[0105] S104: The administrator of the peer node in the second region reviews the cloud resource application.
[0106] In a specific embodiment, S104 includes the following steps:
[0107] S1041: The administrator of the peer node in the second region authenticates and logs in to the front-end page through the unified authentication and authorization service; the unified authentication and authorization service returns relevant information to the administrator, including the user email, user name, the peer node in the region where the applying user belongs (i.e., the peer node in the first region), the identity authentication identifier RegionCode-uuid, and the JWT token.
[0108] S1042: The administrator of the peer node in the second region reviews the cloud resource application. The front-end page sends a request for reviewing the cloud resource, and the request header carries the JWT token. The request content includes: the identity authentication identifier of the applying user, the cloud resource application content, and the review result.
[0109] S1043: The regional management service of the peer node in the second region receives the request. After the following processing, it returns a response indicating successful review to the administrator.
[0110] In a specific embodiment, S1043 includes the following processing:
[0111] ①. According to the identity authentication identifier of the applying user, determine the peer node in the region where the user is located, i.e., the peer node in the first region;
[0112] ②. Request the regional management service of the peer node in the first region to verify the identity authentication identifier of the applying user;
[0113] ③. The regional management service of the peer node in the first region requests the unified authentication and authorization service of its own regional peer node to verify the identity authentication identifier of the applying user and returns the result to the regional management service of its own regional peer node;
[0114] ④. The regional management service of the peer node in the first region returns the authentication result;
[0115] ⑤. After verifying the identity of the applying user, the regional management service of the peer node in the second region updates the "application record table" in the local database, updates the "apply_status" field to "approved"; updates the "reviewer" field to the identity authentication identifier of the administrator.
[0116] S1044: Trigger the consortium chain software. The peer node in the second region reads the "application record table" in the local database, generates an "audit cloud resource transaction" and signs it, and packages the "audit cloud resource transaction" information into a block for storage on the chain.
[0117] In a specific embodiment, the block structure is asFigure 5 As shown in Figure 5 , the content of "Auditing Cloud Resource Transactions" includes applicant user information, applied cloud resource configuration information, audit result information, and auditing users. Among them, the applicant user information and the auditing user information are encrypted using the public key of the first-region peer node.
[0118] Among them, the specific content of "Auditing Cloud Resource Transactions" is as follows:
[0119] Applicant user information: The authentication identifier of the applicant user.
[0120] Applied cloud resource configuration information: Includes cloud resource configuration, the cloud resource center of the second-region peer node, cloud resource usage duration, etc.
[0121] Audit result information: Passed or not passed the audit.
[0122] Auditing user information: The authentication identifier of the auditing user.
[0123] S1045: The cloud resource center of the second-region peer node releases the cloud resources and updates the "Used Cloud Resource Table" and the "Available Cloud Resource Table" in the local database. At this time, the applicant user of the first-region peer node can start using the cloud resources.
[0124] S105: The first-region peer node regularly pulls, parses, and stores the audit results of the user's application for cloud resources of its own region peer node from the cloud federation blockchain, that is, "Auditing Cloud Resource Transactions".
[0125] In a specific embodiment, S105 includes the following steps:
[0126] S1051: The alliance chain software of the first-region peer node calls the relevant interfaces to regularly pull the audit results of the user's application for cloud resources of its own region peer node from the cloud federation blockchain, decrypts and parses them using its own private key, and converts them into relational data.
[0127] S1052: Store the relevant audit results (reviewer, apply_status) in the "Application Record Table" of the local database.
[0128] S106: The regional management service of the regional peer node performs cloud resource expiration detection.
[0129] In a specific embodiment, the regional management service of the regional peer node performs cloud resource expiration detection. If it detects cloud resources that will expire in one week, it prompts the user to renew.
[0130] If it detects expired cloud resources, directly delete the relevant cloud resources and perform cloud resource recycling.
[0131] S107: When the first - region peer node exits the cloud - federated consortium blockchain, when the passing ratio is reached or above, the first - region peer node exits the cloud - federated consortium blockchain;
[0132] In a specific embodiment, S107 includes the following steps:
[0133] S1071: The first - region peer node of the cloud - federated consortium blockchain initiates an exit request, packages the request as an "exit blockchain transaction", signs it, and stores it on the chain.
[0134] In a specific embodiment, the block structure is as Figure 6 shown. The block body includes a transaction header, a transaction body, and transaction content. Among them, the transaction header includes the transaction time, transaction hash, and version number. The transaction body is the exiting regional peer node, and the transaction content is the exiting regional peer node.
[0135] S1072: All members of the cloud - federated consortium blockchain vote on the exit request of the first - region peer node, reply with consent or dissent, and sign. If the passing ratio is reached or above, the first - region peer node exits; otherwise, it cannot exit and the process terminates.
[0136] The calculation formula for the passing ratio is:
[0137]
[0138] where n represents the number of members who agree; m represents the total number of members of the cloud - federated consortium blockchain. In a specific embodiment, the total number of members of the cloud - federated consortium blockchain includes the members who apply to exit.
[0139] In a specific embodiment, the first - region peer node's exit from the cloud - federated consortium blockchain has no impact on users who are using cloud resources.
Claims
1. A federal cloud service method based on alliance blockchain, characterized in that: include: When a member of the Cloud Federation Alliance blockchain invites the first regional peer node to join, and after obtaining permission, the first regional peer node is added; The first regional peer node is initialized, the first regional peer node generates a pair of public keys and private keys, and exchanges public keys, regional management service URLs and regional identification codes with other regional peer nodes of the cloud federation alliance blockchain; The first regional peer node calls the regional management service URL of other regional peer nodes to obtain a list of available cloud resources; The first regional peer node generates an identity authentication identifier for a user of the first regional peer node; the identity authentication identifier includes the regional identification code information of the first regional peer node and the uuid returned by the unified identity authentication authorization service; The user of the first regional peer node submits a cloud resource application, the first regional peer node generates and signs a cloud resource application transaction, and packages the cloud resource application transaction information into a block for on-chain storage; the cloud resource application transaction includes application user information and application cloud resource configuration information, wherein the application user information is encrypted using the public key of the second regional peer node, and the second regional peer node is a regional peer node for the resource being applied for among other regional peer nodes of the cloud federation alliance blockchain; The second regional peer node periodically pulls the cloud resource application transactions of the peer node in the region from the cloud federation alliance blockchain, decrypts and parses them using the private key of the peer node in the region, converts them into relational data, and stores the user application records in the local database; The administrator of the second regional peer node obtains the application record of the local database from the front-end page, verifies the identity authentication identifier of the applicant user, and after the verification is passed, the second regional peer node generates and signs the audit cloud resource transaction, and packages the audit cloud resource transaction information into a block chain for storage; the audit cloud resource transaction information includes the application user information, the application cloud resource configuration information, the audit result information and the audit user information, wherein the application user information and the audit user information are encrypted using the public key of the first regional peer node; The cloud resource center of the second regional peer node releases cloud resources and updates a used cloud resource table and an available cloud resource table in a local database; The first regional peer node periodically pulls the audit results of the user cloud resource application of the regional peer node from the cloud federation alliance blockchain, decrypts and parses it using the private key of the regional peer node, converts it into relational data, and stores the audit results in the local database; The user of the first regional peer node uses the cloud resources applied for.
2. The method according to claim 1, characterized in that Also includes: When a member of the cloud federation alliance blockchain invites the first regional peer node to join, the first regional peer node joins the cloud federation alliance blockchain when the passing ratio is reached or above; When the first regional peer node exits the cloud federation alliance blockchain, the first regional peer node exits the cloud federation alliance blockchain when the passing ratio is reached or above; The calculation formula of the passing ratio is: Among them, n represents the number of members who agree; m represents the total number of members of the Cloud Federation Alliance blockchain; The withdrawal of the first regional peer node from the cloud federation alliance blockchain has no impact on users who are currently using cloud resources.
3. The method according to claim 1, characterized in that Also includes: The regional management service of the peer node in the second region performs cloud resource expiration detection. If cloud resources that expire in one week are detected, the user is prompted to renew. If expired cloud resources are detected, the relevant cloud resources will be deleted and recycled.
4. The method according to claim 1, characterized in that: The first regional peer node initialization step further includes: Deploy and run the alliance chain software. The software version must be consistent with the cloud federation alliance blockchain, and synchronize the relevant ledgers; Deploy and run regional management services, whose responsibilities are to call the relevant management and operation interfaces of the cloud resource center and to call the regional management services of peer nodes in other regions across domains; Deploy and run front-end services to provide unified cloud resource management and access portals for users in the region; Deploy and run unified identity authentication and authorization services, provide identity authentication and authorization for users in this area, generate identity authentication tags for users, and provide identity authentication tag authentication services; Deploy cloud resource center related software. If the peer node in the region does not provide cloud resource services, there is no need to deploy it. Deploy and run the local database and initialize related data tables; Exchange public keys, regional management service URLs, and regional identification codes with other members of the Cloud Federation Alliance blockchain.
5. The method according to claim 1, characterized in that The application record table of the local database includes: application record id, user identity authentication identifier, cloud resource configuration applied by the user, application duration, second region peer node and cloud resource center, reviewer, and application status; wherein the cloud resource configuration applied by the user can optionally apply for two basic resources: cloud host and object storage.
6. The method according to claim 1, characterized in that The step of the administrator of the second region peer node verifying the identity authentication identification of the applicant user specifically includes: The second regional peer node generates an identity authentication identifier for a user of the second regional peer node, that is, generates an identity authentication identifier for an administrator; The administrator reviews the cloud resource application, and the front-end page sends a cloud resource review request, the cloud resource review request content includes: the identity authentication identifier of the applicant user, the cloud resource application content, and the review result; The regional management service of the second regional peer node receives the request and determines the regional peer node where the user is located according to the identity authentication identifier of the applicant user; The second regional peer node requests the regional management service of the first regional peer node to verify the identity authentication identifier of the applicant user; The regional management service of the first regional peer node requests the unified authentication and authorization service of the regional peer node to verify the identity authentication identifier of the applicant user, and returns the result to the regional management service of the regional peer node; The regional management service of the first regional peer node returns the authentication result to the front end; After verifying the identity of the applicant, the regional management service of the second regional peer node updates the application record table of the local database, updates the application status to approved, and updates the reviewer to the administrator's identity authentication identifier.
7. A federal cloud service system based on alliance blockchain, characterized in that: include: The cloud federation alliance blockchain is run by alliance chain software of multiple regional peer nodes, and consists of consensus algorithms, ledgers and other modules. The peer nodes trust each other through public / private keys to achieve consensus between peer nodes and ensure trusted services across domain federations. Regional peer nodes, including alliance chain software, local database, regional management services, front-end services and unified identity authentication and authorization services, are used to interact with the cloud federation alliance blockchain through APIs to achieve regional peer node user authentication and authorization, cross-regional peer node user authentication, cloud resource management, user management, service management and other functions, realize cloud resource application, review transaction data on the chain, and provide a unified front-end access portal; The cloud resource center is used to provide cloud resource services. The cloud resource service types include cloud hosts and object storage. The cloud hosts are virtualized and managed by a private cloud management system for computing, storage, and network resources, and the object storage is managed by an object storage system for storage resource pooling.
Citation Information
Patent Citations
Energy internet credible interaction data model based on block chain in heterogeneous environment
CN113708934A
Cross-domain access control method and system based on block chain
CN115426136A
Cloud service providing method for resource-constrained nodes in block chain
CN116633675A
Cross-mechanism cloud computing resource trusted sharing method and system
CN118733272A
Method for generating and managing multimodal identified network on the basis of consortium blockchain voting consensus algorithm
WO2020113545A1