Information security authentication method and system based on block chain
By hash encryption and user trust evaluation of information modification data, combined with blockchain technology, the problem of inefficient authentication in the existing technology is solved, and efficient and accurate information security authentication and data management are achieved.
Patent Information
- Application Number
- CN202510479447.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-17
- Publication Date
- 2025-07-08
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
现有基于区块链的信息安全认证方法存在网络往返时延高,导致认证效率低下,尤其在跨境业务场景中更为明显,且数据量大导致处理效率低下。
By hashing the information modification data, the information hash code is generated, and the trust is calculated based on the user's historical behavior, the information access threshold is evaluated based on the trust, access permission is opened, and data modification is monitored and the hash code difference is recorded to form an updated blockchain.
It improves the efficiency and accuracy of information security authentication, enhances the transparency and traceability of the system, adapts to different user behavior patterns, and improves data processing efficiency and security.
Smart Images

Figure CN120281545A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of security authentication, and in particular, to an information security authentication method and system based on blockchain. Background Art
[0002] In the context of the accelerating digitalization process, information security authentication has become the core infrastructure in the fields of finance, medical electronic health records (EHR), and e-commerce. According to industry annual reports, traditional centralized authentication systems are faced with inherent defects such as single-point failures and difficulties in audit tracing due to data tampering. Blockchain Technology, with its distributed consensus mechanism and immutability guaranteed by cryptography, provides a technological paradigm innovation for building a new authentication system. In particular, the programmable nature of Smart Contracts enables the deep integration of multi-factor authentication (MFA) and real-time risk control, forming an end-to-end secure trust chain.
[0003] In the prior art, the information security authentication method based on blockchain mainly includes three steps: First, when registering, the user generates an asymmetric key pair based on Elliptic Curve Cryptography (ECC), and the public key is hashed and written into the blockchain as the user's DID (Decentralized Identifier) to serve as the unique identifier of their identity. Second, each time the user logs in or performs a sensitive operation, the user needs to sign the operation request with their private key and then send the signature along with the request to the service provider. After receiving the request, the service provider retrieves the user's public key from the blockchain and uses this public key to verify the authenticity of the signature to confirm the user's identity. Finally, all verified operation records are encrypted and stored in the blockchain to form an immutable operation log, further enhancing the security of the system.
[0004] However, this method also has some deficiencies. When using the consensus algorithm, the network round-trip time (RTT) results in an average time consumption of 1.2 seconds for a single authentication operation, which further deteriorates to more than 3 seconds in cross-border business scenarios. Coupled with a large amount of data, the processing efficiency of security authentication is low. Summary of the Invention
[0005] The present invention provides an information security authentication method and system based on blockchain to improve the efficiency of information security authentication.
[0006] In a first aspect, to solve the above technical problems, the present invention provides an information security authentication method based on a blockchain, including: Obtain information modification data, an original blockchain, and user historical behavior; Perform hash encryption on the information modification data to obtain an information hash code; Create a new block according to the information modification data, and link it with the original blockchain according to the information hash code to obtain an updated blockchain; Perform credit calculation based on the user historical behavior to obtain a user trust level; Perform credibility evaluation based on the updated blockchain to obtain an information access threshold; When the user trust level is greater than the information access threshold, open access permissions for the user.
[0007] In an optional implementation manner, the performing hash encryption on the information modification data to obtain an information hash code includes: Preprocess the information modification data to obtain standardized data; Segment the standardized data according to a preset standard segment length to obtain standardized data blocks; Perform exclusive OR transformation on the standardized data blocks to obtain absorption data blocks; Perform data extrusion on the absorption data blocks to obtain a binary hash code; Perform hexadecimal conversion on the binary hash code to obtain an information hash code.
[0008] In an optional implementation manner, the creating a new block according to the information modification data, and linking it with the original blockchain according to the information hash code to obtain an updated blockchain includes: Extract a predecessor hash code according to the original blockchain; Obtain a target hash value and a timestamp; Construct a block header according to the predecessor hash code, the target hash value, and the timestamp; Generate a block body according to the information modification data; Combine the block header and the block body to construct a new block; Link the predecessor hash code and the information hash code to obtain an updated blockchain.
[0009] In an optional implementation manner, the performing credit calculation based on the user historical behavior to obtain a user trust level includes: Obtain the current timestamp; Perform reputation evaluation based on the user historical behavior to obtain a user reputation score; Calculate the single trust degree through the following formula: Where, represents the single trust degree in the th block, represents the block generation timestamp in the th block, represents the earliest generated block timestamp, represents the current timestamp, represents the user reputation score, represents the user activity in the th block, represents the weight coefficient; Calculate the average value based on all the single trust degrees to obtain the user trust degree.
[0010] In an optional implementation manner, the credibility evaluation is performed according to the updated blockchain to obtain an information access threshold, including: Calculate the information access threshold through the following formula: Where, represents the information access threshold, represents the initial value of the access threshold, represents the weight coefficient of the th block, represents the influence degree of the th block, represents the block number, represents the total number of blocks.
[0011] In an optional implementation manner, after opening the access permission for the user when the user trust degree is greater than the information access threshold, it further includes: Obtain the data before modification and the data after modification; Perform hash learning on the data before modification to obtain a first hash code; Perform hash learning on the data after modification to obtain a second hash code; Convert the first hash code and the second hash code into hexadecimal and perform an exclusive OR operation to obtain the bit difference number; Perform weighted summation based on the bit difference number and the updated blockchain to obtain an updated influence degree; Save the updated influence degree to the updated blockchain.
[0012] In an optional implementation manner, the reputation evaluation is performed according to the user's historical behavior to obtain the user reputation score, including: The user reputation score is calculated by the following formula: Wherein, represents the user reputation score, represents the positive behavior weight of the th modification behavior, represents the th modification behavior's effective modification times, represents the time decay coefficient, represents the time difference from the occurrence of the th modification operation to the current evaluation moment, represents the benchmark value, represents the total number of modification applications.
[0013] In a second aspect, the present invention provides an information security authentication system based on a blockchain, including: A data acquisition module, configured to acquire information modification data, an original blockchain, and user historical behaviors; A hash encryption module, configured to perform hash encryption on the information modification data to obtain an information hash code; A block update module, configured to create a new block according to the information modification data, and link it with the original blockchain according to the information hash code to obtain an updated blockchain; A user credit module, configured to calculate the credit according to the user historical behaviors to obtain the user trust degree; An information threshold module, configured to perform credibility evaluation according to the updated blockchain to obtain an information access threshold; A result determination module, configured to open the access permission for the user when the user trust degree is greater than the information access threshold.
[0014] In a third aspect, the present invention further provides an electronic device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the information security authentication method based on a blockchain described in any one of the above.
[0015] In a fourth aspect, the present invention further provides a computer-readable storage medium, which includes a stored computer program. When the computer program runs, it controls the device where the computer-readable storage medium is located to execute the information security authentication method based on a blockchain described in any one of the above.
[0016] Compared with the prior art, the present invention has the following beneficial effects: (1) The process of the present invention for hashing and encrypting information modification data to generate an information hash code includes several key steps, which together ensure the uniqueness and security of the final hash code. First, the information modification data undergoes a preprocessing stage, where format differences are eliminated through a standardization process to ensure data consistency, thereby obtaining standardized data. This step is crucial for improving the efficiency and accuracy of subsequent processing steps. Next, the standardized data is segmented into several standardized data blocks according to a preset standard segment length. This segmentation strategy helps to refine the data processing process, enabling each data block to be precisely transformed and encrypted. Subsequently, these standardized data blocks are processed using an exclusive-or transformation operation to generate absorption data blocks. As a basic encryption technique, the exclusive-or transformation is used here to increase data complexity and confusion, providing an additional security layer for the data. In addition, the absorption data blocks are converted into a binary hash code through a data extrusion process. This process involves complex mathematical operations and logical operations, aiming to ensure that even a slight change in the input data can produce a significantly different output result, which is one of the important characteristics of the hash function, namely the so-called "avalanche effect". Finally, the binary hash code is converted into a hexadecimal format to obtain the final information hash code. This step not only simplifies the representation form of the hash code, facilitating storage and transmission, but also further verifies the uniqueness and immutability of the hash value.
[0017] (2) The present invention considers three main factors in the calculation of user trust: the time dimension, the user reputation score, and the user activity level. In the time dimension, the calculation uses the ratio of the difference between the block generation timestamp and the earliest generated block timestamp to the difference between the current timestamp and the earliest generated block timestamp. This ratio reflects the importance of user behavior changes over time. The user reputation score directly reflects the quality of the user's historical behavior, while the user activity level measures the enthusiasm or frequency of the user's participation in activities. These three factors are each multiplied by their respective weight coefficients, which are used to adjust the influence degree of different factors on the final trust calculation result. The design of this calculation method makes the user trust not only depend on the quality of their historical behavior (i.e., the reputation score), but also combines the time effect of the behavior (calculated through timestamps) and the activity level, thus providing a comprehensive and dynamic method for evaluating user trust. This method helps to improve the accuracy and reliability of information security authentication, especially in application scenarios based on blockchain technology, enhancing the system's adaptability and recognition accuracy for different user behavior patterns.
[0018] (3) The present invention proposes a calculation formula for user reputation scoring. This calculation method combines the user's historical behavior, the quantity and quality of positive behavior, the changes in the time dimension, and the overall activity level, forming a dynamically adjustable mechanism. This method can not only effectively identify active contributors but also adjust the score according to their latest performance, thereby improving the accuracy and fairness of user evaluation in the information security authentication process. Further, the user's historical behavior includes multi-dimensional information such as the number of logins, types of operations and their results, and interactions with other users. These comprehensively reflect the way and frequency of the user's interaction with the system. Querying these historical behavior records using system logs or specially designed databases can build a detailed behavior profile for each user. Based on these profiles, a large amount of heterogeneous data is processed and understood. This method significantly enhances the data processing efficiency of the information security authentication system.
[0019] (4) After the user trust verification is passed, the present invention further includes a data modification monitoring and evaluation mechanism. This mechanism first obtains the versions of the data before and after the user's modification, and then generates corresponding hash codes (the first hash code and the second hash code) by performing hash learning on these two sets of data respectively. This step ensures that even minor changes in the data can be accurately captured. Next, these two hash codes are converted into hexadecimal format and an exclusive OR operation is performed to calculate the number of bit differences, which quantifies the degree of data change. Subsequently, a weighted summation operation is performed based on the calculated number of bit differences and the relevant information for updating the blockchain to obtain an index - update impact degree - that measures the impact of this update. This step is crucial for evaluating the impact of data modification on the overall state of the system because it not only considers the amount of change in the data content but also combines the historical information recorded on the blockchain, making the evaluation result more comprehensive and scientific. Finally, this update impact degree is saved to the blockchain, which enhances the transparency and traceability of the system. Any user's data modification behavior and its impact are permanently and immutably recorded. This method significantly improves the accuracy and reliability of information security authentication. Brief Description of the Drawings
[0020] Figure 1 is a schematic flowchart of a blockchain-based information security authentication method provided by the first embodiment of the present invention; Figure 2 is a schematic structural diagram of a blockchain-based information security authentication system provided by the second embodiment of the present invention. Detailed Embodiments
[0021] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0022] In the context of the accelerating digitalization process, information security authentication has become the core infrastructure in the fields of finance, medical electronic health records (EHR), and e-commerce. According to industry annual reports, traditional centralized authentication systems due to data tampering face inherent defects such as single-point failures and difficulties in audit traceability. Blockchain technology, with its distributed consensus mechanism and immutability guaranteed by cryptography, provides a technological paradigm innovation for building a new authentication system. In particular, the programmable nature of smart contracts enables the deep integration of multi-factor authentication (MFA) and real-time risk control, forming an end-to-end secure trust chain.
[0023] In the prior art, the information security authentication method based on blockchain mainly includes three steps: First, when registering, the user generates an asymmetric key pair based on elliptic curve cryptography (ECC). The public key is hashed and written into the blockchain as the user's DID (Decentralized Identifier) to serve as the unique identifier of their identity. Second, when logging in or performing sensitive operations each time, the user needs to sign the operation request with their private key and then send the signature together with the request to the service provider. After receiving the request, the service provider retrieves the user's public key from the blockchain and uses this public key to verify the authenticity of the signature to confirm the user's identity. Finally, all verified operation records are encrypted and stored in the blockchain to form an immutable operation log, further enhancing the security of the system.
[0024] However, this method also has some deficiencies. When using the consensus algorithm, the network round-trip delay (RTT) results in an average time consumption of 1.2 seconds for a single authentication operation, which further deteriorates to more than 3 seconds in cross-border business scenarios. Coupled with a large amount of data, the processing efficiency of security authentication is low.
[0025] To solve the above problems, referring to Figure 1 , the first embodiment of the present invention provides an information security authentication method based on blockchain, including the following steps: S11, Obtain information modification data, the original blockchain, and the user's historical behavior; S12, Perform hash encryption on the information modification data to obtain an information hash code; S13, Create a new block based on the information modification data, and link it with the information hash code and the original blockchain to obtain an updated blockchain; S14, Perform credit calculation based on the user's historical behavior to obtain the user's trust level; S15, Perform credibility evaluation based on the updated blockchain to obtain an information access threshold; S16, When the user's trust level is greater than the information access threshold, grant the user access permission.
[0026] In step S11, obtain information modification data, the original blockchain, and the user's historical behavior.
[0027] In one implementation, the information modification data refers to the data submitted by the user when requesting to modify certain information in the system. This includes the content of operations such as adding, deleting, or updating information. For example, in an electronic health record system, a doctor updating a patient's treatment plan is an example of information modification. Obtaining this data is achieved through the front-end application programming interface (API). When the user initiates a modification request, the system captures this data.
[0028] In one implementation, the original blockchain refers to the existing blockchain state in the current system, that is, a copy of the blockchain containing all previous transaction or operation records. Here, "original" refers to the existing blockchain relative to the new block to be added. Obtaining the original blockchain can be done by accessing the locally stored blockchain database or synchronizing the latest state from other nodes on the network. It contains all block header and block body information.
[0029] In one implementation, the user's historical behavior refers to the behavior records left by the user during past interactions with the system. These behaviors include the number of logins, the types of operations performed and their results, interactions with other users, etc. These historical behaviors are used to evaluate the user's trust level. Obtaining the user's historical behavior requires querying the system log or a database specifically used to record user activities. Based on the user's historical behavior records, their behavior patterns can be analyzed, and then the user's reputation score and trust level can be calculated.
[0030] In step S12, perform hash encryption on the information modification data to obtain an information hash code.
[0031] In one implementation, the information modification data is preprocessed to obtain standardized data; the standardized data is segmented according to the standardized data and a preset standard segment length to obtain standardized data blocks; an exclusive OR transformation is performed on the standardized data blocks to obtain absorption data blocks; data extrusion is performed on the absorption data blocks to obtain a binary hash code; and the binary hash code is hexadecimally converted to obtain an information hash code.
[0032] It should be noted that preprocessing is mainly to ensure the consistency and predictability of the input information modification data. It involves operations such as removing redundant information in the data, formatting the data (such as unifying the timestamp format), padding or truncating the data to a fixed length, etc. For example, if the input data is a text string, all non-alphanumeric characters will be removed and it will be converted to lowercase.
[0033] It should be noted that the standardized data is divided into multiple small blocks of fixed length (i.e., "standard segment length"). The standard segment length is a preset value used to determine the size of each data block. This process helps to evenly distribute the data and simplify the subsequent processing flow. The standard segment length can be set to 5 characters, and this method does not limit it. For example, there is a standardized string "hellothere", and the standard segment length is set to 5, then this string will be divided into two data blocks: "hello" and "there".
[0034] It should be noted that exclusive OR (XOR) is a basic bit operation method that compares two binary digits and returns a new value: it returns 0 when the two numbers are the same and 1 when they are different. In this step, a new data block, called an absorption data block, is generated by performing an exclusive OR operation on adjacent data blocks. This can increase the security and randomness of the data. Continuing with the above example, if an exclusive OR operation is performed on the two data blocks "h" (ASCII code 104) and "t" (ASCII code 116), the result will be 12 (because 104 XOR 116 = 12).
[0035] It should be noted that the term "data extrusion" in cryptography and hash functions refers to generating a fixed-length hash value by processing input data through a specific algorithm. This method uses the SHA-256 algorithm to process these data blocks to generate the final hash code. First, the absorbed data blocks need to be padded according to the requirements of SHA-256. This involves adding a '1' bit at the end of the data, followed by a series of '0' bits until the total length of the data satisfies modulo 512 equal to 448. Then, the SHA-256 algorithm is used to perform a hash operation on these data blocks. This method uses an off-the-shelf hash operation library and does not require designing the hash operation process by itself. The last step is to convert the generated binary hash code into a more readable hexadecimal notation. This is because hexadecimal encoding is more compact and easier for humans to read than pure binary.
[0036] In step S13, a new block is created according to the data modified based on the said information, and the updated blockchain is obtained by linking according to the said information hash code and the original blockchain.
[0037] In one implementation, extraction is performed according to the original blockchain to obtain the previous hash code; the target hash value and the timestamp are obtained; a block header is constructed according to the previous hash code, the target hash value, and the timestamp; a block body is generated according to the data modified based on the said information; a new block is constructed by combining the block header and the block body; the previous hash code and the information hash code are linked to obtain the updated blockchain.
[0038] It should be noted that the previous hash code (Previous Hash) refers to the hash value of the last block in the current blockchain. Each new block needs to reference the hash value of the previous block to ensure the continuity and integrity of the blockchain. The hash value of the previous block can be obtained by querying the blockchain database or from other nodes in the network and then extracting it from the latest block information. The target hash value (Target Hash) is, in some blockchain systems, especially those using the Proof of Work (PoW) mechanism, the hash value of a new block that a miner needs to find to be less than or equal to the target hash value. The timestamp refers to the time point when the modification request occurs. The block header (BlockHeader) contains key metadata such as the previous hash code, the target hash value, and the timestamp. These information together constitute the identity identifier of the block. The block body (Block Body) contains the actual data, such as the modification request record or other forms of information-modified data. Combining the block means combining the block header and the block body to form a complete block. The implementation method is to simply serialize and connect the two, or organize them according to a specific data structure.
[0039] It should be noted that, for example, a simple blockchain is being maintained for recording the version control of files. A certain user submits a new version of a file (information modification data). First, it is necessary to extract its hash value from the previous block as the precursor hash code. Then, a timestamp is generated for the new version of the file, and its hash value is calculated as the target hash value. Next, a block header is constructed using the precursor hash code, timestamp, and the hash value of the new version of the file, and the new version of the file itself is used as the block body. Finally, these two parts are combined into a new block, which is added to the existing blockchain, and the blockchain copy is updated to reflect this change.
[0040] In step S14, credit calculation is performed based on the user's historical behavior to obtain the user trust level.
[0041] In one implementation, the current timestamp is obtained; Reputation assessment is performed based on the user's historical behavior to obtain the user reputation score; The single trust level is calculated through the following formula: where, represents the single trust level in the th block, represents the block generation timestamp in the th block, represents the earliest generated block timestamp, represents the current timestamp, represents the user reputation score, represents the user activity level in the th block, represents the weight coefficient; The average value of all the single trust levels is calculated to obtain the user trust level.
[0042] The user reputation score is calculated through the following formula: where, represents the user reputation score, represents the positive behavior weight of the th modification behavior, represents the number of effective modifications of the th modification behavior, represents the time decay coefficient, represents the time difference from the occurrence of the th modification operation to the current evaluation moment, represents the reference value, represents the total number of modification applications.
[0043] It should be noted that the effective modification count refers to the number of effective improvements or corrections actually carried out in a specific modification operation. For example, if a user submits a code update request that includes 5 independent but related code optimizations, then for this modification behavior, the effective modification count is 5. For example: The user corrected a misleading error message, and this modification was recognized by the administrator and regarded as a highly valuable positive behavior. Therefore, a relatively high positive behavior weight of 0.9 is assigned to it, and the effective modification count is 1. The user participated in the discussion and provided three useful suggestions to improve the content quality of the post. Since these proposals increased the value of the content but were not as important as directly correcting errors, a medium positive behavior weight of 0.6 was given, and the effective modification count was 3.
[0044] It should be noted that the timestamp of block generation, that is, the time point when the modified data of the currently processed information is incorporated into the new block. The timestamp of the earliest generated block is used to measure the historical starting point of the entire blockchain system. The current timestamp reflects the actual time when calculating the trustworthiness. The user reputation score reflects the degree of positive contributions of the user in past behaviors. The positive behavior weight refers to the importance of submitting beneficial modifications relative to other behaviors. The effective modification count refers to the number of times the user has performed certain specific types of positive behaviors. The time decay factor is used to represent the degree to which the influence of old behaviors on the current reputation score gradually weakens over time. The total number of modification requests includes all types of modification requests, whether positive or negative. The user activity quantifies the degree of interaction between the user and the system based on factors such as the user's login frequency and interaction times.
[0045] In step S15, a credibility assessment is performed based on the updated blockchain to obtain an information access threshold.
[0046] In one implementation, the information access threshold is calculated by the following formula: where, represents the information access threshold, represents the initial value of the access threshold, represents the weight coefficient of the th block, represents the influence degree of the th block, represents the block number,
[0047] It should be noted that the weight coefficient reflects the importance of different blocks for the final threshold. Different blocks may have different weights due to factors such as the type and scale of the data they contain. The influence degree indicates the specific impact of the block on the information access threshold, which is determined based on the information content within the block, user behavior analysis, or other security-related metrics. By accumulating the influence degrees and corresponding weight coefficients of each block, this formula can achieve dynamic adjustment of the information access threshold. This means that as new blocks are continuously added to the blockchain, the system's trust assessment will be updated accordingly to adapt to new situations.
[0048] In step S16, when the user trust level is greater than the information access threshold, access permission is granted to the user.
[0049] In one implementation, after granting access permission to the user when the user trust level is greater than the information access threshold, the following steps are further included: obtaining the data before modification and the data after modification; performing hash learning on the data before modification to obtain a first hash code; performing hash learning on the data after modification to obtain a second hash code; converting the first hash code and the second hash code into hexadecimal and performing an exclusive OR operation to obtain a bit difference number; performing weighted summation based on the bit difference number and the updated blockchain to obtain an updated influence degree; and saving the updated influence degree to the updated blockchain.
[0050] It should be noted that hash learning refers to using a hash function (such as SHA-256) to process the original data to generate a fixed-length string as the hash code. This process is irreversible, meaning that the original data cannot be directly restored from the hash code. The last step is to record the calculated updated influence degree into the blockchain to become part of the chain. For example: in a document management system, user A attempts to modify the content of a certain document. The system first checks whether user A's trust level is high enough to obtain access permission. Once confirmed, the system compares the versions of the document before and after modification and generates two hash codes through the hash algorithm respectively. Then, the system performs an exclusive OR operation on these two hash codes to calculate the bit difference number to measure the degree of modification. Next, combining the bit difference number and the user's historical behavior score, the system calculates the updated influence degree and adds this value to the blockchain to ensure that all modifications are traceable and cannot be tampered with. The purpose of this step is to leave a record of the modification operation and make an estimate of the influence degree of different data.
[0051] In summary, the present invention discloses an information security authentication method based on blockchain. This method realizes the secure authentication of information and the efficient management of user access rights through a series of steps. First, the system obtains three key data: information modification data, the original blockchain, and all historical behavior records of the user. The information modification data contains the specific content submitted when the user requests any change to the information in the system, such as adding, deleting, or updating certain specific information. The original blockchain refers to the blockchain state of all existing transaction or operation records in the current system. And the historical behavior of the user covers various activities during their interaction with the system, such as the number of logins, the types of operations performed and their results, etc. These information are used to calculate the user's trustworthiness in subsequent steps.
[0052] Next, the present invention performs hash encryption processing on the information modification data to obtain an information hash code. This process includes several important steps: First is the preprocessing stage, which converts the information modification data into a standardized format; then, according to a preset standard segment length, the standardized data is segmented to generate multiple standardized data blocks; subsequently, these data blocks are subjected to exclusive-or transformation to produce absorption data blocks; then, data extrusion is performed on the absorption data blocks to obtain a binary hash code; finally, the binary hash code is converted into a hexadecimal-encoded information hash code. This multi-step hash encryption method not only ensures the security of the data but also enhances the tamper-proof feature of the system.
[0053] Next, a new block is created based on the above information modification data and linked to the original blockchain to form an updated blockchain. In this step, it is necessary to extract the hash value from the predecessor block as the predecessor hash code, and at the same time obtain the target hash value and timestamp. Using these three elements to construct the new block header and combining the information modification data to generate the block body. Finally, by connecting the predecessor hash code and the newly generated information hash code, the addition process of the new block to the blockchain is completed, thus realizing the update of the blockchain.
[0054] In addition, the present invention also particularly emphasizes the calculation of user credit to determine the user's trustworthiness. Specifically, first, the current timestamp is obtained, and then the reputation of the user is evaluated based on the user's historical behavior to obtain the user reputation score. A formula is used here to calculate the user trustworthiness, which takes into account the changes in the time dimension (i.e., the time span from the earliest generated block to the current), the user reputation score, and the user activity level and other factors. In this way, it can comprehensively reflect the user's behavior pattern and their importance to the system.
[0055] To further enhance security, the present invention proposes to conduct credibility evaluation based on the updated blockchain to determine the information access threshold. This process also relies on a specific mathematical model that comprehensively considers factors such as the weight coefficients of each block and their influence degrees. When the user's trust level exceeds the set information access threshold, the system will grant the user the corresponding access rights.
[0056] It should be noted that after the user is successfully authenticated, the system will further monitor and evaluate data modification situations. This means that the system will record the hash codes of the data versions before and after modification, and calculate the bit difference number through exclusive OR operation to quantify the degree of data change. Subsequently, in combination with the bit difference number and relevant information of the updated blockchain, the update influence degree is calculated and saved to the blockchain. Such a mechanism not only improves the transparency of data modification but also provides a reliable basis for subsequent audits.
[0057] In summary, the method proposed by the present invention provides a complete and efficient solution by integrating blockchain technology and information security authentication processes. It not only solves the problems existing in traditional centralized authentication systems, such as single-point failures and difficulties in traceability, but also greatly improves the flexibility and efficiency of the entire system by introducing a dynamic adjustment mechanism and a detailed user credit evaluation system.
[0058] Referring to Figure 2 , the second embodiment of the present invention provides an information security authentication system based on blockchain, including: A data acquisition module for acquiring information modification data, the original blockchain, and user historical behaviors; A hash encryption module for performing hash encryption on the information modification data to obtain an information hash code; A block update module for creating a new block according to the information modification data and linking it with the original blockchain based on the information hash code to obtain an updated blockchain; A user credit module for calculating the user's trust level based on the user historical behaviors; An information threshold module for conducting credibility evaluation based on the updated blockchain to obtain an information access threshold; A result determination module for opening access rights for the user when the user's trust level is greater than the information access threshold.
[0059] Preferably, the data acquisition module is used for: Acquiring information modification data, the original blockchain, and user historical behaviors.
[0060] Preferably, the hash encryption module is used for: Performing hash encryption on the information modification data to obtain an information hash code, including: Preprocess the information modification data to obtain standardized data; Segment according to the standardized data and a preset standard segment length to obtain standardized data blocks; Perform exclusive OR transformation on the standardized data blocks to obtain absorption data blocks; Perform data extrusion on the absorption data blocks to obtain binary hash codes; Convert the binary hash codes to hexadecimal to obtain information hash codes.
[0061] Preferably, the block update module is used for: Create a new block according to the information modification data, and link it with the original blockchain according to the information hash code to obtain an updated blockchain, including: Extract the predecessor hash code according to the original blockchain; Obtain the target hash value and the timestamp; Construct a block header according to the predecessor hash code, the target hash value and the timestamp; Generate a block body according to the information modification data; Combine the block header and the block body to construct a new block; Link the predecessor hash code and the information hash code to obtain an updated blockchain.
[0062] Preferably, the user credit module is used for: Calculate the user trust degree according to the user's historical behavior, including: Obtain the current timestamp; Evaluate the reputation according to the user's historical behavior to obtain the user reputation score; Calculate the single trust degree through the following formula: where, represents the single trust degree in the th block, represents the block generation timestamp in the th block, represents the earliest generated block timestamp, represents the current timestamp, represents the user reputation score, represents the th block in the user activity, represents the weight coefficient; Calculate the average value of all the single trust degrees to obtain the user trust degree.
[0063] Preferably, the information threshold module is configured to: Perform a credibility assessment based on the updated blockchain to obtain an information access threshold, including: Calculate the information access threshold through the following formula: Wherein, Represents the information access threshold, Represents the initial value of the access threshold, Represents the Weight coefficient of the Represents the Influence degree of the Represents the block number, Represents the total number of blocks.
[0064] Preferably, the result determination module is configured to: When the user trust level is greater than the information access threshold, open the access permission for the user.
[0065] Preferably, after opening the access permission for the user when the user trust level is greater than the information access threshold, it further includes: Obtain the data before modification and the data after modification; Perform hash learning on the data before modification to obtain a first hash code; Perform hash learning on the data after modification to obtain a second hash code; Convert the first hash code and the second hash code into hexadecimal and perform an exclusive OR operation to obtain a bit difference number; Perform a weighted sum based on the bit difference number and the updated blockchain to obtain an updated influence degree; Save the updated influence degree to the updated blockchain.
[0066] Preferably, the reputation assessment based on the user's historical behavior to obtain the user reputation score includes: Calculate the user reputation score through the following formula: Wherein, Represents the user reputation score, Represents the positive behavior weight of the th modification behavior, Represents the Effective modification times of the Represents the time decay coefficient, Represents the time difference from the occurrence of the th modification operation to the current evaluation moment, Represents the reference value, Indicates the total number of modified applications.
[0067] It should be noted that an information security authentication system based on blockchain provided by an embodiment of the present invention is used to execute all process steps of an information security authentication method based on blockchain in the above embodiment. The working principles and beneficial effects of the two correspond one by one, so they will not be elaborated here.
[0068] An embodiment of the present invention also provides an electronic device. The electronic device includes: a processor, a memory, and a computer program stored in the memory and executable on the processor, such as a data acquisition program. When the processor executes the computer program, the steps in the above embodiments of various information security authentication methods based on blockchain are implemented, such as Figure 1 step S11 shown. Alternatively, when the processor executes the computer program, the functions of each module / unit in the above device embodiments are implemented, such as the data acquisition module.
[0069] Exemplarily, the computer program can be divided into one or more modules / units. The one or more modules / units are stored in the memory and executed by the processor to complete the present invention. The one or more modules / units can be a series of computer program instruction segments capable of performing specific functions, and the instruction segments are used to describe the execution process of the computer program in the electronic device.
[0070] The electronic device can be a computing device such as a desktop computer, a notebook, a palm computer, and a smart tablet. The electronic device may include, but is not limited to, a processor and a memory. Those skilled in the art can understand that the above components are only examples of the electronic device and do not constitute a limitation on the electronic device. It may include more or fewer components than the above, or combine some components, or different components. For example, the electronic device may further include input / output devices, network access devices, a bus, etc.
[0071] The so-called processor may be a Central Processing Unit (CPU), or may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The processor is the control center of the electronic device and connects all parts of the entire electronic device through various interfaces and lines.
[0072] The memory can be used to store the computer programs and / or modules. The processor realizes various functions of the electronic device by running or executing the computer programs and / or modules stored in the memory, and by calling the data stored in the memory. The memory mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function (such as a sound playback function, an image playback function, etc.); the data storage area can store data created according to the use of the mobile phone (such as audio data, phone book, etc.). In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, at least one magnetic disk storage device, a flash memory device, or other volatile solid-state storage devices.
[0073] Among them, if the modules / units integrated in the electronic device are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above-described embodiment methods of the present invention, it can also be completed by a computer program instructing relevant hardware. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-described various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc. It should be noted that the content included in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice within the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.
[0074] It should be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. In addition, in the attached drawings of the device embodiments provided by the present invention, the connection relationship between the modules indicates that they have a communication connection, which can be specifically implemented as one or more communication buses or signal lines. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0075] The above-described specific embodiments have further elaborated on the purpose, technical solutions, and beneficial effects of the present invention. It should be understood that the above are only specific embodiments of the present invention and are not used to limit the protection scope of the present invention. It is particularly pointed out that for those skilled in the art, any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention should be included in the protection scope of the present invention.
Claims
1. An information security authentication method based on blockchain, characterized in that, Including: Obtain information modification data, the original blockchain, and the user's historical behavior; Perform hash encryption on the information modification data to obtain an information hash code; Create a new block according to the information modification data, and link it with the original blockchain according to the information hash code to obtain an updated blockchain; Perform credit calculation based on the user's historical behavior to obtain the user's trustworthiness; Perform credibility evaluation based on the updated blockchain to obtain an information access threshold; When the user's trustworthiness is greater than the information access threshold, open the access permission for the user.
2. The information security authentication method based on blockchain according to claim 1, wherein The performing hash encryption on the information modification data to obtain an information hash code includes: Preprocess the information modification data to obtain standardized data; Segment the standardized data according to the standardized data and a preset standard segment length to obtain standardized data blocks; Perform exclusive OR transformation on the standardized data blocks to obtain absorption data blocks; Perform data extrusion on the absorption data blocks to obtain a binary hash code; Convert the binary hash code to hexadecimal to obtain an information hash code.
3. The information security authentication method based on blockchain according to claim 1, wherein The creating a new block according to the information modification data, and linking it with the original blockchain according to the information hash code to obtain an updated blockchain includes: Extract the predecessor hash code according to the original blockchain; Obtain the target hash value and the timestamp; Construct a block header according to the predecessor hash code, the target hash value, and the timestamp; Generate a block body according to the information modification data; Combine the block header and the block body to construct a new block; Link the predecessor hash code and the information hash code to obtain an updated blockchain.
4. The information security authentication method based on blockchain according to claim 1, wherein The performing credit calculation based on the user's historical behavior to obtain the user's trustworthiness includes: Obtain the current timestamp; Perform reputation evaluation based on the user's historical behavior to obtain the user's reputation score; Calculate the single trustworthiness through the following formula: Among them, represents the single trust degree in the th block, represents the block generation timestamp in the th block, represents the earliest generated block timestamp, represents the current timestamp, user reputation score, represents the user activity in the th block, represents the weight coefficient; Calculate the average value of all the single trustworthiness values to obtain the user's trustworthiness.
5. The information security authentication method based on blockchain according to claim 1, wherein The performing credibility evaluation based on the updated blockchain to obtain an information access threshold includes: Calculate the information access threshold through the following formula: Among them, represents the information access threshold, represents the initial value of the access threshold, represents the weight coefficient of the represents the influence degree of the represents the block number, represents the total number of blocks.
6. The information security authentication method based on blockchain according to claim 1, wherein After the step of opening the access permission for the user when the user's trustworthiness is greater than the information access threshold, it further includes: Obtain the data before modification and the data after modification; Perform hash learning on the data before modification to obtain a first hash code; Perform hash learning on the data after modification to obtain a second hash code; Convert the first hash code and the second hash code to hexadecimal and perform exclusive OR operation to obtain the bit difference number; Perform weighted summation based on the bit difference number and the updated blockchain to obtain the update influence degree; Save the update influence degree to the updated blockchain.
7. The information security authentication method based on blockchain according to claim 4, wherein The performing reputation evaluation based on the user's historical behavior to obtain the user's reputation score includes: Calculate the user's reputation score through the following formula: Among them, represents the user reputation score, represents the positive behavior weight of the th modification behavior, represents the effective modification times of the th modification behavior, represents the time decay coefficient, represents the time difference from the occurrence of the th modification operation to the current evaluation moment, represents the reference value, represents the total number of modification applications.
8. An information security authentication system based on blockchain, characterized in that, Including: A data acquisition module for obtaining information modification data, the original blockchain, and the user's historical behavior; A hash encryption module for performing hash encryption on the information modification data to obtain an information hash code; A block update module, configured to create a new block by modifying data according to the information, and link the updated blockchain based on the information hash code and the original blockchain to obtain an updated blockchain; A user credit module, configured to calculate the credit based on the user's historical behavior to obtain the user trustworthiness; An information threshold module, configured to evaluate the credibility based on the updated blockchain to obtain an information access threshold; A result determination module, configured to grant the user access permission when the user trustworthiness is greater than the information access threshold.
9. An electronic device, characterized in that, It includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the blockchain-based information security authentication method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored computer program. When the computer program runs, it controls the device where the computer-readable storage medium is located to execute the blockchain-based information security authentication method according to any one of claims 1 to 7.