Block chain-based operation and maintenance terminal cross-domain management and control system and method
By adopting a blockchain-based cross-domain management and control system for the operation and maintenance terminals in the remote operation and maintenance system, the terminal identity authentication and fine-grained permission control are achieved using TCP three-step handshake and smart contracts, the shortcomings of the existing system in cross-domain access and security control are solved, and efficient and secure cross-domain management and control of the operation and maintenance terminals are achieved.
Patent Information
- Application Number
- CN202311775414.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-22
- Publication Date
- 2025-06-24
AI Technical Summary
The existing remote operation and maintenance systems have problems such as insufficient flexibility in cross-domain access and security control, high security risks, and centralized systems are vulnerable to attacks.
The cross-domain management and control system of operation and maintenance terminals is adopted based on blockchain, and the terminal identity authentication and fine-grained permission control are realized through TCP three-step handshake, TCP cookie mechanism and smart contracts, and the decentralization of blockchain and the transparency and immutability of smart contracts are used to improve security and control efficiency.
It has achieved the improvement of identity authentication efficiency for cross-regional multi-point access, enhanced operation and maintenance efficiency and security, avoided the risk of single point failure of the centralized system and private configuration tampering, and ensured the transparency and immutability of terminal information and access behavior.
Smart Images

Figure CN120200725A_ABST
Abstract
Description
Technical Field
[0001] The present invention provides a cross - domain control system and method for operation and maintenance terminals based on blockchain, belonging to the technical fields of security, access control, and blockchain technology. Background Technique
[0002] Abbreviations and glossary of terms are as follows:
[0003] Blockchain: A new distributed infrastructure and computing method that uses a block - chain data structure to verify and store data, uses a distributed node consensus algorithm to generate and update data, uses cryptography to ensure the security of data transmission and access, and uses smart contracts composed of automated script code to program and operate data.
[0004] TCP Cookie: A defense mechanism for preventing SYN flood attacks, also known as SYN Cookie. In the TCP protocol, when a client sends a connection request to a server, the server returns an acknowledgment (SYN ACK) packet to the client to confirm receipt of the request. Then, the server sends a SYN Cookie to the client in the SYN ACK. The client sends this Cookie back to the server in the reply ACK, and the server verifies it before establishing a connection.
[0005] Bot: An electronic device controlled by hackers, which can be various operating systems, such as Windows systems or UNIX / LINUX systems. It can be an ordinary personal computer or a large - scale server. Hackers can remotely operate them without being detected. Once controlled by hackers, these bots can be used for various illegal activities, such as DDoS attacks, information theft, data leakage, etc.
[0006] Smart contract: A smart contract based on blockchain technology that can achieve automatic execution and verification of contract terms, improve efficiency, security, and transparency. It exists in the form of program code on the blockchain and can be accessed and executed by any node. Once deployed, the smart contract automatically executes according to the preset rules and cannot be tampered with or revoked.
[0007] With the completion of the deployment and implementation of the National Safe City and Snow Bright Project, video surveillance equipment has been built in different places such as cities, villages and communities to achieve comprehensive monitoring of public areas, helping to improve public safety and public security management. With the large-scale application of monitoring equipment and China's vast territory, remote operation and maintenance has become more and more widespread. However, while remote operation and maintenance brings convenience, it also brings various security problems. For example, hackers and unscrupulous elements have begun to penetrate and invade video surveillance networks in a targeted manner, and use means such as counterfeit device access to disrupt the overall network operation, steal important sensitive data (such as large-scale social events), and steal personal privacy data (such as human / vehicle activity scenes and trajectories), thereby causing social panic and unrest and other adverse effects.
[0008] The current remote operation and maintenance mainly involves closing redundant ports, IP filtering, control lists and other methods to limit the IP range. First, as the location of the operation and maintenance terminal IP moves or changes, it needs to be reconfigured each time, and it is impossible to flexibly perform management and control authentication. Second, since both the front-end acquisition device and the back-end server and storage device have network and responsibility ownership, cross-regional access is impossible. Each time, it is necessary to go to the region of ownership or each region / department to obtain access rights. Third, the opening of access portals brings security risks, such as vulnerability scanning, weak password detection, message replay and other means to intrude and obtain identity access rights; fourth, although the server system can control the application layer, since it belongs to a centralized system, once the central system is damaged or tampered with, either the remote operation and maintenance cannot work properly or unauthorized access occurs. Fifth, for such centralized systems, once a certain authorized access device is infected by a virus and becomes a zombie, it launches an attack on the server device or security control device, which itself becomes a source of attack or data theft. Summary of the invention
[0009] This paper adopts a cross-domain management and control system and method of operation and maintenance terminals based on blockchain, which can effectively avoid the above problems. Figure 1 .
[0010] This system consists of a server subsystem and a client subsystem. Figure 2 , specifically:
[0011] 1. Service terminal system
[0012] 1.1 Access Authentication Module: Cooperate with the client subsystem to complete the identity authentication of terminal access; Based on the TCP three-way handshake to establish a connection, receive the Syn packet sent by the client, through the TCP Cookie mechanism, along with the account information, device information and timestamp information carried in the TCP option, reply the Syn Ack message; Receive the Ack message to complete the authentication, and extract the application list information reported in the client Ack message, and record it together with the terminal identity information and timestamp information into the blockchain ledger, using the device identity fingerprint block.
[0013] 1.2 Permission Control Module: Adopt the smart contract mechanism deployed by the blockchain, and query the device identity fingerprint block by extracting the terminal information, timestamp information and application information in the message sent by the client.
[0014] For terminals that cannot be queried in the block ledger, directly block their access.
[0015] For terminals that are queried in the illegal terminal fingerprint block ledger, directly block their access.
[0016] For terminals that can be queried in the block ledger, read out the application information and timestamp information in the block, trigger the smart contract, and complete the multi-level fine-grained permission control from four levels: IP, port, protocol, and content. For the access terminal, judge whether the application is trustworthy, and directly reject the access if it is not trustworthy; For the trusted application that passes the verification, allow it to continue to access the real device.
[0017] 1.3 Blockchain Module: The server acts as a node in the blockchain system. This module uses the peer-to-peer communication technology in the blockchain to synchronize the blockchain ledger with other nodes (clients) in the blockchain system; Use the dynamic delegated proof-of-stake mechanism, and the server accessed by the client on behalf of the client completes the generation and verification of the terminal identity fingerprint block, improving the operation efficiency and security.
[0018] 1.4 Blockchain Ledger 1.4.1 Terminal Identity Fingerprint Block The content is legal terminal identity information, authentication result, timestamp and trusted application list; 1.4.2 Illegal Terminal Fingerprint Block The content is illegal terminal identity information; 1.4.3 Log Alarm Record Block The content of the log alarm block recorded by the server includes the terminal authentication interaction information log, the terminal legal access behavior log, and the terminal illegal access behavior alarm.
[0019] 1.5 API Module: The API module provides two types of interfaces. One way is that the server provides API function interfaces, which provide interfaces for the server to extract blockchain ledgers, verify blockchain ledgers, and add to blockchain ledgers; the other way is to provide API methods and formats, which provide interfaces for third-party applications and devices to extract blockchain ledgers and add to blockchain ledgers. For example, after a terminal accesses the system, if other security products such as EDR, DLP, or APT detect its abnormal behavior, this interface can be used to extract terminal information and add it to the illegal terminal fingerprint block.
[0020] 2. Client Subsystem
[0021] 2.1 Access Authentication Module: Initiate TCP Syn, add timestamp information, device information (mainboard uuid, operating system, network card MAC, etc.), and account information to the TCP option field of the Syn packet, calculate the Hash value of the above information as the Seq number, and send it to the server; receive the Syn Ack message, use the TCP Cookie mechanism, and carry the list of allowed applications on the client in the TCP option field of the Ack.
[0022] 2.2 Application Identification and Monitoring Module: The client identifies the network connection status used by each application by real-time monitoring of the system process tree, network port usage list and status. By inserting a kernel Hook function, it intercepts the network packets sent by the application, adds device identity information and application information to the network packets for the server to use for identity and application identification; records information such as the running trajectories, status, and cycles of each application on the terminal into the terminal application behavior and status block.
[0023] 2.3 Blockchain Module: The client is a node in the blockchain system. This module uses the peer-to-peer communication technology in the blockchain to synchronize the blockchain ledger with the blockchain system.
[0024] 2.4 Blockchain Ledger: The client only stores the log warning record block, and the content is the terminal application behavior and status.
[0025] The present invention relates to a cross-domain control method for operation and maintenance terminals based on blockchain, see Figure 3, by adopting a cross-domain control system for operation and maintenance terminals based on blockchain of the present invention, the server and the client cooperate to implement the identity authentication of the terminal based on TCP three-way handshake to establish a connection, TCP Cookie and adding TCP Option fields. The authentication result, through the delegated proof-of-stake mechanism and the distributed ledger mechanism of the blockchain, the server generates a terminal identity fingerprint block and broadcasts it to all servers through the blockchain; the client monitors the application operation and network communication conditions on the terminal side in real time, and adds identity information, application information and timestamp information to the TCP Option or UDP extension field in the communication interaction when it accesses and connects. After receiving it, the server obtains the terminal information and queries the block to obtain the authentication result. For the terminal with no authentication result hit or the hit of an illegal terminal fingerprint block, its access is blocked; for the terminal with the authentication result passed, further permission control check is carried out. Based on the intelligent contract ability of the blockchain, fine-grained permission control is carried out from the trusted application of the access terminal to the destination IP, port, protocol and behavior of the access; for the terminal that meets the permissions, its content is further verified, and whether there is illegal content such as vulnerability scanning, backdoor utilization, virus intrusion, etc. is detected by feature matching, and it is detected whether the legal terminal side is illegally utilized, such as a virus being implanted, or being invaded and controlled as a zombie computer. For the detected abnormal terminal, it is added to the illegal terminal fingerprint block and broadcast to all servers; this system also provides an API interface to support other security products such as EDR, DLP or APT to discover abnormal behaviors of the terminal, and the terminal information in the blockchain ledger can be extracted through the interface, and the detected abnormal terminal can be added to the illegal terminal fingerprint block; all the above processes, including identity authentication, normal access, abnormal detection, all logs and alarms are stored on the chain; based on the above method, firstly, cross-region multi-point access for one-time identity authentication can be realized, greatly improving the authentication efficiency, synchronization update efficiency and operation and maintenance efficiency, and solving the problem that the single point of the centralized system cannot effectively prevent legal personnel from tampering. Secondly, the fine-grained permission control based on the intelligent contract, compared with the original manual participation in configuration, greatly improves the efficiency and scalability. At the same time, the transparency and immutability of the intelligent contract effectively prevent the occurrence of illegal operations such as privately tampering with the configuration, and the security is also enhanced accordingly. Furthermore, all terminal information, application information, application access behaviors, content and intelligent contracts are stored on the blockchain, effectively preventing the problem of inability to trace the origin due to tampering / deleting historical records in the original centralized system.
[0026] Beneficial effects:
[0027] Convenient operation and maintenance: Ensure that the operation and maintenance terminal in one area can access another area, and can cope with the changes in operators and IP addresses caused by the location movement of the operation and maintenance terminal, or the fixed PC terminal to complete cross-region access for operation and maintenance.
[0028] Security control: The client completes application recognition and control, and the server uses the smart contract of the blockchain to implement access control over devices, protocols, and content. Whether it is abnormal behavior detected by the client, abnormal communication behavior / content detected by the server, or providing APIs to third-party applications, and determining a certain abnormal terminal, all nodes will be notified based on the blockchain distributed ledger to prevent unauthorized access, abnormal access, or access from other regions.
[0029] Reliable and transparent: All access behaviors, instructions, and content records are uploaded to the blockchain to prevent problems in the original centralized architecture where internal legitimate personnel can delete / alter access records and evade traceability through privilege escalation / unauthorized access. Description of the Drawings
[0030] Figure 1 Schematic diagram of the cross-regional access system described in the present invention.
[0031] Figure 2 System module architecture diagram described in the present invention.
[0032] Figure 3 Flow chart of authentication and operation access in the method described in the present invention. Detailed Implementation Manner
[0033] The server subsystem of this system is deployed in a separate device or server virtual machine, and the client subsystem of this system is deployed in the operation and maintenance terminal computer of the access system. Through the device and application fingerprint identity authentication in cooperation between the client and the server, the decentralized technology, distributed accounting, and consensus mechanism of the server based on the blockchain, and the application recognition and control technology in cooperation between the client and the server, such as Figure 3 , the entire access control process is completed.
[0034] 1. Identity authentication mechanism: The client starts when the operation and maintenance terminal computer starts. After startup, it is completed in cooperation with the server and client authentication system. Based on the TCP three-way handshake to establish a connection, without adding additional communication messages. The client acts as the TCP Client side, and the server acts as the TCP Server side. First, the client initiates a TCP Syn. The option field of the Syn adds timestamp information, device information (mainboard uuid, operating system, network card MAC, etc.), and account information. Combine the above information and calculate the Hash as the Seq number and send it to the server. After receiving it, the server generates a Cookie value based on the timestamp information and the server device information and sends it to the client as the Seq field of the Syn Ack. After receiving it, the client replies with an Ack and carries the application list allowed by the client in the TCP option field of the Ack. After receiving the Ack field, the server verifies whether the Client carries the Cookie. If the verification passes, a connection is established. Send the IP address list of all service access points to the client through a TCP message.
[0035] After the server successfully authenticates the client, it generates a user + device information block with the client information and its Hash value and broadcasts it to all server nodes through the blockchain.
[0036] Whether the client accesses the server in the authentication area or the server in other areas, it carries the Hash value of the client information and the timestamp information in the TCP or UDP header field. Other servers can directly verify whether the client is trustworthy by looking up the corresponding block content through the blockchain.
[0037] Both the client and the server are nodes on the blockchain. However, since the client is deployed on the terminal device and the available running resources are limited, the client and the server that authenticates it adopt a dynamic delegated proof-of-stake mechanism. The server generates and validates blocks on behalf of the client, thus solving the problem of insufficient performance in generating and validating blocks due to the client's environmental resources, improving efficiency and speed. At the same time, since the usage environment of the client is not under control, security threats such as poisoning / hijacking of the botnet may occur. The delegated proof-of-stake mechanism can also solve the running security problem of the client.
[0038] This mechanism adds identity authentication on the basis of TCP Cookie, so it can resist TCP half-connection attacks while completing identity authentication.
[0039] 2. Access Permission Control: Its function is for fine-grained control at the application content level and is completed in combination with the intelligent contracts deployed on the server node blockchain. After the identity authentication is completed, when other application programs on the terminal computer initiate an operation to access devices within the area, the client intercepts the message through the injected kernel function before it is sent out of the computer, and adds a marker field to the TCP header field as an application information identification field. After receiving the message, the server analyzes and extracts client information, including account, device, application server information, etc. Based on the above information, it locates the smart contract and uses the execution function published by the smart contract to complete multi-level permission access control. First, for the client trusted application level of the access party, by searching the trusted application list in the client information block, if it is not trusted, access is directly denied. Second, for the access purpose, for the trusted application that has passed the verification, it is controlled at four levels: IP, port, protocol, and behavior. Taking Web access as an example, it can be achieved that only the Chrome browser of the client is allowed to access the Web application port of a certain IP address using the HTTP protocol, and only the Get and Post methods of HTTP are allowed for interaction; for unauthorized access, its illegal behavior interaction is intercepted.
[0040] 3. Access content monitoring: If an access passes the permission access control, the access to its content continues to be accessed and controlled; first, the request content of the access is analyzed for features. By detecting whether there is virus intrusion, vulnerability scanning, backdoor exploitation information, or signature in the incoming content for feature analysis, if found, this terminal is determined to be an abnormal terminal, and through the broadcast of the blockchain full node, it is ensured that this terminal cannot be accessed again in any area where the block is subsequently published.
[0041] 4. Access logs and alarm records: Regardless of whether it is the server subsystem or the client subsystem, for all behaviors such as normal access, unauthorized access, and abnormal content access of the terminal, as well as the authentication results and the execution results of the smart contract records, they are all recorded in the blockchain in the form of a block ledger and broadcast to all nodes, ensuring that historical records cannot be tampered with.
[0042] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: still modifications or equivalent replacements can be made to the specific implementation manners of the present invention, and any modifications or equivalent replacements without departing from the spirit and scope of the present invention shall be covered by the protection scope of the claims of the present invention.
Claims
1. A cross - domain control system for operation and maintenance terminals based on blockchain, which includes a service - end subsystem and a client - end subsystem. Among them A. The service - end subsystem includes (1)Access authentication module Based on the TCP three-way handshake to establish a connection, receive the Syn packet sent by the client, and through the TCP Cookie mechanism, together with the account information, device information, and timestamp information carried in the TCP option, reply with a Syn Ack message; Receive the Ack message to complete authentication, extract the application list information reported in the client Ack message, and record it together with the terminal identity information and timestamp information into the blockchain ledger, using the device identity fingerprint block; (2)Access permission control module Adopt the intelligent contract mechanism deployed by blockchain. By extracting the terminal information, timestamp information, and application information in the message sent by the client, query the device identity fingerprint block; For terminals that cannot be found in the block ledger, directly block their access; For terminals found in the illegal terminal fingerprint block ledger, directly block their access; For terminals that can be found in the block ledger, read out the application information and timestamp information in the block, trigger the intelligent contract, and complete multi - level and fine - grained permission control. For the accessing terminal, judge whether the application is trustworthy. If it is not trustworthy, directly reject the access; For the trusted application that passes the verification, continue to judge the access destination; Perform fine - grained control from four dimensions: IP, port, protocol, and content; (3)Blockchain module The server acts as a node in the blockchain system. This module uses the peer - to - peer communication technology in blockchain to synchronize the blockchain ledger with other nodes (clients) in the blockchain system; Use the dynamic delegated proof - of - stake mechanism. The server accessed by the client completes the generation and verification of the terminal identity fingerprint block on behalf of the client, improving the operation efficiency and security; (4)Blockchain ledger Include the terminal identity fingerprint block: the content is legal terminal identity information, authentication result, timestamp, and trusted application list; Illegal terminal fingerprint block: the content is illegal terminal identity information; Log alarm record block: the content is the terminal authentication interaction information log, terminal legal access behavior log, and terminal illegal access behavior alarm; (5)API module The API module provides two types of interfaces. One way is that the server provides an API function interface to provide interfaces for the server to record, extract, verify, and add to the blockchain ledger. The other way is to provide API methods and formats to provide interfaces for third - party applications and devices to extract and add to the blockchain ledger. For example, after the terminal accesses the system, other security products such as EDR, DLP, or APT can use this interface to extract terminal information and add it to the illegal terminal fingerprint block; B. The client - end subsystem includes: (1)Access authentication module Initiate TCP Syn, add timestamp information, device information (mainboard uuid, operating system, network card MAC, etc.), and account information in the TCP option field of the Syn message, calculate the Hash value of the above information as the Seq number, and send it to the server; Receive the Syn Ack message, use the TCP Cookie mechanism, and at the same time carry the application list allowed by the client in the TCP option field of the Ack; (2)Application identification and monitoring module The client monitors the system process tree, the list and status of network port usage in real time, identifies the network link status used by each application, intercepts the network packets sent by the application by inserting a kernel Hook function, and adds the device identity information and application information to the network packets for the server to use for identity and application identification; Record the information such as the running trajectories, status, and cycles of each application on the monitored terminal into the terminal application behavior and status block; (3) Blockchain module As a node in the blockchain system, this module uses the peer-to-peer communication technology in the blockchain to synchronize the blockchain ledger with the blockchain system; (4) Blockchain ledger The client only stores the log warning record block, and the content is the terminal application behavior and status.
2. The cross-domain control system for operation and maintenance terminals based on blockchain according to claim 1, characterized in that, Based on the delegated proof-of-stake mechanism, the server generates and broadcasts the terminal identity fingerprint block based on the client's delegation, improving the operation, authentication, and update efficiency.
3. The cross-domain control system for operation and maintenance terminals based on blockchain according to claim 1, wherein Implement multi-dimensional fine-grained permission control of the trusted applications, access destination IP, port, protocol, and behavior of the terminal through smart contracts.
4. The cross-domain control system for operation and maintenance terminals based on blockchain according to claim 1, wherein, Use three types of block ledgers, the terminal identity fingerprint block, the illegal terminal fingerprint block, and the log warning record block. The server stores the three types of blocks, and the client only stores the log warning record block.
5. The cross-domain control system for operation and maintenance terminals based on blockchain according to claim 1, characterized in that, Based on the TCP three-way handshake connection establishment and Cookie mechanism, complete the identity authentication mechanism by adding device information, user information, and timestamp information to the TCP Option header field information.
6. The cross-domain control system for operation and maintenance terminals based on blockchain according to claim 1, wherein Provide an API interface to third-party security devices, and the terminal information can be extracted from it and added to the illegal terminal fingerprint block.
7. A method for cross-domain control of operation and maintenance terminals based on blockchain, characterized in that Adopt any one of the blockchain-based operation and maintenance terminal cross-domain control systems in claims 1-6. The server and the client cooperate to implement the identity authentication of the terminal based on the TCP three-way handshake connection establishment, TCP Cookie, and adding TCP Option fields. The authentication result is through the delegated proof-of-stake mechanism and the distributed ledger mechanism of the blockchain. The server generates the terminal identity fingerprint block and broadcasts it to all servers. After successful authentication, the client monitors the application running and network communication conditions on the terminal side in real time, and adds the identity information, application information, and timestamp information to the TCP Option or UDP extension field in the communication packets it accesses. After the server receives it, it queries the block of the terminal to obtain the authentication result. For the terminal without an authentication result hit or hitting the illegal terminal fingerprint block, block its access; For terminals with successful authentication results, based on the smart contract capabilities of the blockchain, fine-grained permission control is performed on the trusted applications of the terminals, the destination IPs, ports, protocols, and behaviors accessed. Unauthorized access is directly blocked. For terminals that comply with the permissions, further verification is carried out to check whether there is illegal content such as vulnerability scanning, backdoor exploitation, and virus intrusion in the communication content. For terminals detected with anomalies, they are added to the illegal terminal fingerprint block and broadcast to all servers. Only non-anomalous terminals can finally access. This system also provides an API interface, supporting other security products to extract terminal information from the blockchain ledger through the interface after discovering abnormal behaviors of terminals, and adding the detected abnormal terminals to the illegal terminal fingerprint block; all the above identity authentication, normal access, and abnormal detection logs and alerts are stored on the chain.