Virtual network configuration management method and system based on block chain smart contract

Through the combination of blockchain smart contract module and kernel protocol stack, the centralized risk and insufficient multi-tenant isolation in traditional virtual network management are solved, efficient policy management and permission verification are achieved, and the security and transparency of the virtual network are improved.

CN120378433AInactive Publication Date: 2025-07-25BEIJING ZHIJI TECHNOLOGY CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510586269.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-08
Publication Date
2025-07-25
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional virtual network management has problems such as centralized risks, insufficient multi-tenant isolation, security risks in policy management, and inefficient permission verification.

Method used

The blockchain smart contract module is used to decentralize the management of virtual network resources, combined with the 24-bit tunnel isolation tag mechanism and address generation and management module of the kernel protocol stack, realize multi-tenant isolation, and ensure policy security and permission verification accuracy through off-chain encryption storage and zero-knowledge proof technology.

Benefits of technology

It realizes decentralized management of virtual network resources, ensures traceability and security of operations, improves the security and efficiency of network isolation and policy management in a multi-tenant environment, and ensures the transparency and fairness of network management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378433A_ABST
    Figure CN120378433A_ABST
Patent Text Reader

Abstract

The invention discloses a virtual network configuration management method and system based on a block chain smart contract, and belongs to the field of virtual network management and block chains, the virtual network configuration management system comprises a block chain smart contract module, a kernel protocol stack module, an address generation and management module and a strategy storage module, the intelligent contract management module is used for realizing full-life-cycle management of a virtual network, a network element, a network strategy, a DNS strategy and a situation awareness strategy through an intelligent contract; according to the method and the system, the problems of centralization risk, insufficient multi-tenant isolation, potential safety hazard of strategy management, low authority verification efficiency and the like in the traditional virtual network management are solved. And the decentralized management of the virtual network resources is realized by utilizing the characteristics of the block chain smart contract, the efficient multi-tenant isolation is realized in combination with the optimization of the kernel protocol stack, and the security of the strategy and the accuracy and efficiency of the authority verification are ensured at the same time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the fields of virtual network management and blockchain technology, and particularly to a virtual network configuration management method and system based on blockchain smart contracts. Background Art

[0002] In the current network environment, virtual networks have been widely used in fields such as cloud computing and edge computing. However, there are many problems with traditional virtual network configuration management methods:

[0003] Disadvantages of centralized management: Traditional virtual network management usually relies on a centralized server, which makes the system vulnerable to single-point failures. Once the central server fails, the management of the entire virtual network will be paralyzed. In addition, in the centralized management mode, the storage and operation of data are concentrated in the central server, making it vulnerable to attacks and tampering, and it is difficult to effectively guarantee the security and integrity of the data.

[0004] Security risks in policy management: Network policies, DNS policies, and situation awareness policies in virtual networks contain a large amount of sensitive information. Traditional storage methods store these policies in a centralized database, making them vulnerable to hacker attacks and resulting in policy leakage. Moreover, in the traditional management mode, the process of policy update and verification is cumbersome, and it is difficult to ensure the timeliness and accuracy of the policies.

[0005] Low efficiency of permission verification: In a virtual network, the joining and leaving of network elements and users' access to policies require permission verification. Traditional permission verification methods rely on third-party institutions for identity authentication and authorization, which not only increases the complexity of the system but also easily leads to privacy leakage, and the verification efficiency is also low.

[0006] Blockchain technology has characteristics such as decentralization, immutability, and traceability, and smart contracts can achieve automated execution and condition triggering. Introducing blockchain smart contract technology into the field of virtual network configuration management is expected to solve the above problems and provide a more secure and efficient solution for virtual network management. Summary of the Invention

[0007] Aiming at the deficiencies of the prior art, the present invention provides a virtual network configuration management system and method based on blockchain smart contracts to solve problems such as centralized risks, insufficient multi-tenant isolation, security risks in policy management, and low efficiency of permission verification existing in traditional virtual network management. By utilizing the characteristics of blockchain smart contracts, decentralized management of virtual network resources is achieved, combined with the optimization of the kernel protocol stack to achieve efficient multi-tenant isolation, while ensuring the security of policies and the accuracy and efficiency of permission verification.

[0008] Technical solution: To solve the above technical problems, according to one aspect of the present invention, more specifically, it is a virtual network configuration management system based on blockchain smart contracts, including:

[0009] Blockchain smart contract module: The module is deployed on the blockchain node and is the core control unit of the entire system. It realizes the full life cycle management of virtual networks, network elements, network policies, DNS policies, and situation awareness policies through smart contracts. In terms of virtual network management, whether it is creating a new virtual network, deleting a virtual network that is no longer in use, or modifying an existing virtual network, the relevant operation records will be accurately stored on the chain. This not only ensures the traceability of operations but also makes any operation on the virtual network impossible to be tampered with, ensuring the fairness and transparency of virtual network management. There are various smart contract modules: managing networks, managing network elements, managing various policies, etc.

[0010] For the management of network elements, when a network element attempts to join a virtual network, the blockchain smart contract module will use zero-knowledge proof technology to verify its permissions. The network element only needs to submit materials that meet the requirements of zero-knowledge proof, and the smart contract will confirm through a preset verification algorithm. Without obtaining the sensitive information of the network element, it can determine whether the network element has access permissions. This verification method not only protects the privacy of the network element but also improves the security and reliability of verification. When a network element exits the virtual network, the smart contract will also record the relevant operations to ensure the reasonable release and management of resources.

[0011] In terms of policy management, the blockchain smart contract module stores the hash values of network policies, DNS policies, and situation awareness policies. These hash values are unique identifiers generated according to the policy content through a specific hash algorithm. By storing the hash values on the chain, on the one hand, it can greatly reduce the storage pressure on the blockchain. On the other hand, when it is necessary to verify the integrity of the policy, only the hash value on the chain needs to be compared with the hash value of the off-chain policy recalculated. If the two are consistent, it means that the policy has not been tampered with, thus ensuring the integrity and credibility of the policy. The specific configuration policy is found in the off-chain content storage network according to the hash value.

[0012] Kernel protocol stack module: It includes a rewritten 24-bit tunnel isolation label mechanism. In the tunnel communication protocol, this 24-bit tunnel isolation label field plays a key role. When data is transmitted in the tunnel, the kernel protocol stack at the sending end will assign a unique 24-bit label to the data according to the tenant or virtual network to which the data belongs, based on the smart contract policy, and embed this label into the tunnel protocol header. At the receiving end, the kernel protocol stack will parse this label value and establish an independent traffic forwarding channel according to the label value. Traffic with different labels will be strictly isolated and enter the corresponding virtual networks respectively, achieving 2 24Efficient isolation of sub-tenants and virtual networks. This fine-grained isolation method greatly improves the security and stability of virtual networks in a multi-tenant environment, effectively avoiding interference and data leakage risks between different tenants.

[0013] Address Generation and Management Module: The address generation and management module generates unique addresses for users, devices, or programs based on asymmetric encryption algorithms (ECC or RSA). Each address corresponds to a unique public-private key pair, which is not only used to identify the identity of users, devices, or programs but also plays an important role in permission management. This module establishes the mapping relationship between addresses, policy links, and hash values in the blockchain smart contract module. Specifically, the address corresponds to the link to the real policy information stored off-chain, and at the same time, it is associated with the hash value of this policy. Through this mapping relationship, when a user, device, or program needs to access policy information, the blockchain smart contract module can quickly index the corresponding policy link and hash value according to its address, and then obtain and verify the policy information, realizing the precise management and efficient access of policy information.

[0014] Policy Storage Module: The policy storage module is responsible for encrypting and storing important information such as virtual network configurations, network element parameters, network policies, DNS policies, and situation awareness policies off-chain. To ensure the security of policies, the default policy uses the user's public key encryption storage method. Only users with the corresponding private key can decrypt and view these policies, effectively preventing the leakage of policy information. For some policies involving permission verification, the policy storage module supports zero-knowledge proof verification methods. When users verify their permissions, they do not need to submit actual policy information. They only need to execute the zero-knowledge proof process through the blockchain smart contract module to prove that they have the corresponding permissions, further improving the security and privacy protection level of policy management. In addition, the policy storage module interacts closely with the blockchain smart contract module to realize the function of uploading and verifying the policy hash value, ensuring the consistency between the policies stored off-chain and the records on-chain.

[0015] Module for Interconnection between On-chain and Off-chain: It realizes the interconnection between the blockchain smart contract and the off-chain content network, modifies the content of the on-chain smart contract to the off-chain content network, and synchronizes the modifications of the off-chain content network to the on-chain smart contract.

[0016] According to another aspect of the present invention, more specifically, it is a virtual network configuration management method based on the above system, including the following steps:

[0017] Virtual Network Basic Operation Management: Users initiate operation requests such as creating, deleting, and modifying virtual networks by interacting with the blockchain smart contract module. After receiving the request, the blockchain smart contract module executes corresponding operations according to the preset smart contract logic and stores the operation records on the blockchain in the form of a blockchain. In this way, all virtual network operations are completely recorded, forming an immutable operation history, realizing the decentralized management of the entire life cycle of the virtual network. The virtual network management contract divides the users of the network into two types: administrator addresses and ordinary user addresses. Anyone can create their own virtual network. The administrator creates the virtual network. After successful creation, there will be a virtual network ID. The administrator can authorize others to use the virtual network. The authorized user can obtain an encrypted hash value. After decrypting this hash value with the user's private key, the access hash of the off-chain content network can be obtained. Using this hash, the operation records of the virtual network can be queried to understand its creation, modification, and deletion history information, ensuring the transparency and fairness of virtual network management.

[0018] Full Life Cycle Management of Network Elements: When a network element attempts to join a certain virtual network, it submits zero-knowledge proof materials to the blockchain smart contract module by signing with the private key of the user who has the right to use the virtual network. The blockchain smart contract module uses its built-in zero-knowledge proof verification mechanism to verify the materials submitted by the network element. Only after the verification passes can the network element obtain the configuration information of the virtual network and be allowed to join the virtual network. At the same time, the blockchain network element management smart contract module writes the access operation of the network element into the off-chain content network through the on-chain and off-chain interoperable network and records the updated hash information on the chain. This process not only ensures the legality of the network element access but also provides a traceable record for subsequent network management. When a network element needs to exit the virtual network, it calls the smart contract network element offline interface with the private key of the user who has the right to use the virtual network. After the blockchain smart contract module verifies the permission, it will trigger the resource release process, reasonably release the network resources occupied by the network element, update the records in the off-chain content network through the on-chain and off-chain interoperable network, and record the new hash information on the chain to implement the exit operation of the network element, ensuring the effective management and reuse of network resources.

[0019] Policy Secure Storage and Verification: During the policy management process, the administrator of the virtual network first encrypts network policies, DNS policies, situation awareness policies, etc. through the policy storage module, and then stores them off-chain. The hash value is updated to the blockchain through the off-chain and on-chain interoperable network. The virtual network configuration interface of the smart contract is called to ensure that users with permission to use the virtual network can obtain the hash after decrypting it with their private keys. The encrypted policy can effectively prevent information leakage and protect network security. When storing the policy, the policy storage module calculates its hash value according to the policy content and stores the hash value on the blockchain through the blockchain smart contract module. When it is necessary to verify the integrity of the policy, the hash value of the off-chain stored policy is recalculated and then compared with the hash value stored on the chain. If the two hash values are the same, it means that the policy has not been tampered with during storage and transmission, ensuring the integrity and credibility of the policy. This method of storing policies off-chain and verifying hash values on-chain not only makes full use of the security of the blockchain but also avoids storing a large amount of policy data on the blockchain, improving the performance and scalability of the system.

[0020] Multi-tenant Isolation Implementation: In the virtual network management smart contract, a tenant id is assigned to each. During the data transmission process, the kernel protocol stack module at the sending end embeds a unique 24-bit tunnel isolation label into the header of the tunnel communication protocol according to the tenant or virtual network to which the data belongs as assigned in the smart contract. When the data reaches the receiving end, the kernel protocol stack module at the receiving end parses this label value. Matching the tenant id from the virtual network management smart contract, according to the label value, the receiving end kernel protocol stack establishes an independent traffic forwarding channel, only allowing the traffic with matching labels to enter the corresponding virtual network, while isolating and filtering out other traffic with non-matching labels. In this way, fine-grained isolation of 2 24 to the power of tenants is achieved, effectively preventing traffic interference and data leakage between different tenants, and improving the security and stability of the virtual network in a multi-tenant environment.

[0021] Address Association and Policy Access: Users, devices, or programs generate unique addresses through the address generation and management module. This address serves as their identity in the system, with uniqueness and non-forgeability. The blockchain smart contract module indexes to the corresponding policy link and hash value in the mapping relationship established inside according to this address. Through the policy link, the system can obtain the real policy information stored off-chain, and at the same time use the hash value to verify the integrity of the policy information. Only after the verification passes can users, devices, or programs access the corresponding policy information, realizing accurate policy access and permission control based on the address, ensuring that only authorized entities can access specific policies, and improving the security and efficiency of policy management.

[0022] Policy permission verification mechanism: For the default policy, the policy storage module uses user public key encryption to store it. This means that only users with the corresponding private key can decrypt and view these policies, which effectively protects the privacy of the policies. For some policies involving permission verification, such as network element access permission verification, verification is performed through zero-knowledge proof technology supported by the blockchain smart contract module. When verifying permissions, users do not need to submit actual policy information. They only need to follow the rules and processes of zero-knowledge proof to prove to the blockchain smart contract module that they know certain specific information without revealing the specific content of this information. The blockchain smart contract module verifies the user's proof process to determine whether the user has the corresponding permissions. This method greatly improves the level of privacy protection and reduces the risk of sensitive information leakage while ensuring the accuracy of permission verification.

[0023] Administrators create networks and policies through smart contracts; users obtain content through authentication contracts; the on-chain and off-chain intercommunication modules open up the mapping between smart contracts and content networks, and any changes on one side are updated to the other side; the terminal interacts with the smart contract to obtain authentication information, obtains real-time configuration from the content network based on the authentication information, updates local policies based on the obtained real-time configuration, and establishes real-time connections with other terminals. The terminal regularly queries smart contract updates, obtains the latest configuration from the content network after an update, and changes local policies based on the latest configuration.

[0024] The beneficial effects of the virtual network configuration management method and system based on blockchain smart contract of the present invention are:

[0025] (1) The present invention achieves a decentralized management model for virtual network resources with the help of a blockchain smart contract module. It effectively avoids the risk of single point failures and greatly reduces the possibility of data tampering. All virtual network operation records are stored on the blockchain, and its tamper-proof nature ensures that the operations have complete traceability, thereby improving the security and credibility of the entire system. Taking a multi-tenant network environment as an example, operations of different tenants on virtual networks, whether creation, modification or deletion, will be accurately recorded in the blockchain. This prevents any party from tampering with the operation records privately, effectively protects the legitimate rights and interests of each tenant, and maintains the fairness and transparency of network management.

[0026] (2) The 24-bit tunnel isolation tag mechanism adopted by the kernel protocol stack module of the present invention realizes the 24Fine-grained isolation of secondary tenants and virtual networks. During data transmission, this mechanism can ensure that traffic between different tenants is completely isolated, effectively preventing data leakage and traffic interference between tenants. In the scenario of a network service platform with a large number of enterprise tenants, each enterprise tenant can have an independent virtual network space. This isolation feature makes the network environment between tenants independent of each other and does not affect each other, significantly improving the quality and security of network services and meeting the strict requirements for network isolation in large-scale multi-tenant environments.

[0027] (3) The policy storage module of the present invention adopts off-chain encrypted storage combined with on-chain hash verification to ensure the security and integrity of the policy. At the same time, the application of zero-knowledge proof technology realizes permission verification without leaking sensitive information, further improving the security of policy management. For example, during the network policy update process, hash verification can ensure that the updated policy has not been tampered with, and zero-knowledge proof technology allows users to prove that they have the right to perform policy update operations without exposing the specific content of the policy.

[0028] (4) The unique address generated by the address generation and management module of the present invention establishes an accurate association between the address and the policy. Through the address index policy link and hash value, efficient access to policy information and accurate permission control are achieved. Users, devices or programs can quickly access and verify authorized policy information simply by using their own addresses, improving the management efficiency of the system and user experience. In a complex edge computing network, various devices can quickly obtain and verify relevant network policies through their own addresses to ensure that the devices can access the network normally and securely. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] The present invention is further described in detail below with reference to the accompanying drawings and specific implementation methods.

[0030] Figure 1 It is a structural schematic diagram of the present invention;

[0031] Figure 2 It is a schematic diagram of the system interaction of the present invention;

[0032] Figure 3 This is an example diagram of the architecture of the present invention;

[0033] Figure 4 This is an example diagram of the virtual network topology of the present invention. DETAILED DESCRIPTION

[0034] The present invention will be described in detail below with reference to the accompanying drawings and in combination with embodiments. It should be noted that the embodiments and features in the embodiments of the present application can be combined with each other without conflict.

[0035] To make the technical solution of the present invention clearer, the following further describes the present invention in detail with reference to the accompanying drawings and specific embodiments.

[0036] Refer to Figures 1-4 , a virtual network configuration management method and system based on blockchain smart contracts, the implementation method is as follows:

[0037] System deployment and initialization: Carefully deploy the blockchain smart contract module on its blockchain nodes to ensure that the smart contract can run stably and interact effectively with other modules.

[0038] Secondly, the kernel protocol stack module is rewritten specifically. Through technical optimization, it has a 24-bit tunnel isolation label mechanism, which plays a key role in the data transmission process. It can accurately assign labels to data traffic according to different tenants and virtual networks, realize the classification and tagging of data and the efficient isolation transmission of data, and then ensure the traffic security between different tenants and virtual networks, effectively avoiding data leakage and interference problems.

[0039] At the same time, complete the deployment and configuration of the address generation and management module and the policy storage module. The address generation and management module, based on asymmetric encryption technology, generates a unique address for each user, device or program accessing the system, and establishes a mapping relationship with the policy link and hash value, so as to achieve accurate policy access and permission control. The policy storage module is responsible for off-chain encrypted storage of various important policies, supports multiple encryption methods and permission verification technologies, and interacts closely with the blockchain smart contract module to jointly ensure the security and integrity of the policies.

[0040] Virtual network creation and management: An enterprise user A hopes to create a virtual network for the internal office network of the enterprise. User A initiates a virtual network creation request by interacting with the blockchain smart contract module. After receiving the request, the blockchain smart contract module records the creation operation on the blockchain according to the preset smart contract logic and allocates relevant resources to the virtual network. Other enterprise users can query the operation record of user A creating the virtual network through the blockchain. When user A needs to modify the virtual network, such as adding a new subnet, a modification request is also initiated through the blockchain smart contract module, and the modification record will also be accurately recorded on the blockchain, realizing the transparent management of the entire life cycle of the virtual network.

[0041] Network Element Access and Management: Enterprise user A purchased a batch of new office equipment as network elements, which need to be connected to the virtual network it created. When these network elements are connected, they submit zero-knowledge proof materials to the blockchain smart contract module. The blockchain smart contract module uses the zero-knowledge proof verification mechanism to verify the permissions of the network elements. After successful verification, the network elements are allowed to access the virtual network, and the access operation records are stored on the blockchain. When some of the equipment of enterprise user A is no longer in use and needs to exit the virtual network, these network elements send an exit request to the blockchain smart contract module. The blockchain smart contract module triggers the resource release process and records the exit operation, ensuring the reasonable utilization of virtual network resources.

[0042] Policy Management and Verification: Enterprise user A formulates a series of network policies for its virtual network, such as access control policies, DNS resolution policies, etc. These policies are encrypted by the policy storage module and stored off-chain. The policy storage module calculates the hash value of the policy and stores the hash value on the blockchain through the blockchain smart contract module. During subsequent use, when it is necessary to verify whether the policy has been tampered with, the hash value of the off-chain policy is recalculated and compared with the on-chain hash value. For example, during a network security audit, auditors can quickly verify the integrity of the policy in this way to ensure the security of the network policy.

[0043] Multi-Tenant Isolation Implementation: In the network of a network service provider, there are multiple enterprise tenant virtual networks running simultaneously. When a device in the virtual network of enterprise user A sends data externally, the kernel protocol stack module at the sending end assigns a unique 24-bit tunnel isolation label to the data according to the tenant to which the device belongs (i.e., the virtual network of user A), and embeds the label into the tunnel communication protocol header. At the receiving end, the kernel protocol stack module parses the label value, and only the traffic with a matching label (i.e., the traffic belonging to the virtual network of user A) is allowed to enter the virtual network of user A, and the traffic of other tenants is isolated and filtered, achieving efficient isolation between multi-tenants and ensuring the security of each tenant's virtual network (not only for cloud services).

[0044] Address Association and Policy Access: When an employee of enterprise user A uses office equipment to access the policy information of the virtual network, the equipment generates a unique address through the address generation and management module and requests the access policy information from the blockchain smart contract module. The blockchain smart contract module indexes the corresponding policy link and hash value according to the address, obtains the real policy information stored off-chain through the policy link, and uses the hash value to verify the integrity of the policy information. After successful verification, the employee can normally access and use the relevant policies, realizing accurate policy access and permission control based on the address, and improving the efficiency and security of policy management.

[0045] Policy Permission Verification: For the default policies of the virtual network of enterprise user A, such as some sensitive network configuration policies, the policy storage module encrypts and stores them using the public key of user A. Only the internal authorized personnel of enterprise user A who possess the corresponding private key can decrypt and view these policies, protecting the privacy of the policies. When performing some special permission verification operations, such as modifying important network policies, verification is carried out through the zero-knowledge proof technology supported by the blockchain smart contract module. The authorized personnel do not need to submit the actual policy information. They only need to prove to the blockchain smart contract module that they have the corresponding permissions according to the zero-knowledge proof process. After the blockchain smart contract module verifies and passes, the authorized personnel can perform the policy modification operation, effectively avoiding the risk of leakage of sensitive information.

[0046] As Figure 2 shown, the terminal is a virtual network terminal, including devices such as apps, gateways, PCs, and servers. Its kernel protocol stack module processes secure encryption tunnels with 24-bit isolation tags.

[0047] As Figure 4 shown in the virtual network topology example, it can be fully interconnected in a fullmesh manner according to the actual configuration policy.

[0048] The above-described embodiments merely represent several implementation manners of the present invention. Their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the patent for the present invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the patent for the present invention shall be subject to the appended claims.

Claims

1. A virtual network configuration management system based on blockchain smart contracts, comprising a blockchain smart contract module, a kernel protocol stack module, an address generation and management module, and a policy storage module, characterized in that: The blockchain smart contract module: Deployed on the blockchain node, it is used to realize the full life cycle management of virtual networks, network elements, network policies, DNS policies, and situation awareness policies through smart contracts, including recording the creation / deletion / modification operations of virtual networks on the chain, verifying the zero-knowledge proofs of network elements joining / leaving the virtual network, and storing and verifying the integrity of policy hash values on the chain; The kernel protocol stack module: It includes a rewritten 24-bit tunnel isolation label mechanism, which is used to classify and label data traffic in the tunnel communication protocol, and realizes traffic isolation processing for 24 to the power of 2 tenants and virtual networks through label value parsing; The address generation and management module: It is used to generate unique addresses for users, devices, or programs based on asymmetric encryption keys, and establish the mapping relationship between the addresses, policy links, and hash values in the blockchain smart contract module, and the link points to the real policy information stored off-chain; The policy storage module: It is used to encrypt and store virtual network configurations, network element parameters, network policies, DNS policies, and situation awareness policies off-chain, support the user public key encryption storage of default policies and the zero-knowledge proof permission verification of partial policies, and interact with the blockchain smart contract module to realize the uploading and verification of policy hash values; The module for interconnection between on-chain and off-chain: It realizes the interconnection between the blockchain smart contract and the off-chain content network, modifies the content of the on-chain smart contract to the off-chain content network, and synchronizes the modifications of the off-chain content network to the on-chain smart contract.

2. The virtual network configuration management system based on a blockchain smart contract according to claim 1, characterized in that: The verification process of the blockchain smart contract module for a network element to join a virtual network includes: The network element submits zero-knowledge proof materials, and the smart contract confirms that the network element has access permission through a preset verification algorithm without obtaining the sensitive information of the network element.

3. A virtual network configuration management system based on a blockchain smart contract according to claim 1, characterized in that: The tunnel isolation label field of the kernel protocol stack module is embedded in the tunnel protocol header during data encapsulation, and the receiving-end kernel establishes an independent traffic forwarding channel according to the label value to achieve communication isolation between different tenants.

4. A virtual network configuration management system based on a blockchain smart contract according to claim 1, characterized in that: The unique address generated by the address generation and management module is generated based on the asymmetric encryption algorithm, and each address corresponds to a unique public-private key pair, which is used to identify the identity of the user, device, or program and associate its policy permissions.

5. A virtual network configuration management method based on blockchain smart contracts, which uses a virtual network configuration management system based on blockchain smart contracts as described in claim 1, characterized in that It includes the following steps: S1. Execute the creation, deletion, and modification operations of the virtual network through the blockchain smart contract module, and store the operation records on the chain to realize the decentralized management of the full life cycle of the virtual network; S2. Use the zero-knowledge proof mechanism of the blockchain smart contract module to verify the access permission when a network element joins the virtual network. After the verification is passed, record the network element access operation on the chain, and trigger the resource release and the exit record to be uploaded when the network element exits; S3. Encrypt and store network policies, DNS policies, and situation awareness policies through the policy storage module off-chain, calculate the policy hash value and upload it through the blockchain smart contract module, and verify the policy integrity based on the comparison between the on-chain hash value and the off-chain policy hash value; S4. Generate a unique address for the user, device or program through the address generation and management module, and the blockchain smart contract module indexes the policy link and hash value in the policy storage module according to the address, obtains the actual configuration off-chain according to the hash value, and implements targeted access and management of user-related policy information according to the configuration; S5. Embed a 24-bit tunnel isolation label in the tunnel communication protocol through the kernel protocol stack module to classify and label the traffic of different tenants and virtual networks. The kernel protocol stack isolates and forwards the traffic according to the label value to achieve fine-grained isolation of 24 the 2 nd -power tenants; S6. The policy storage module uses the user's public key to encrypt the default policy, and only allows the corresponding user to decrypt and view it with the private key; for policies involving authority verification, the blockchain smart contract module supports zero-knowledge proof technology, and users can prove that they have the corresponding authority without submitting actual information. S7,Administrators create networks and policies through smart contracts; users obtain content through authentication contracts; The on-chain and off-chain intercommunication modules open up the mapping between smart contracts and content networks, and any changes on one side will be updated on the other side accordingly; the terminal interacts with the smart contract to obtain authentication information, obtains real-time configuration from the content network based on the authentication information, updates local policies based on the obtained real-time configuration, and establishes real-time connections with other terminals; the terminal regularly queries smart contract updates, obtains the latest configuration from the content network after an update, and changes local policies based on the latest configuration.

6. The virtual network configuration management method based on blockchain smart contract according to claim 2, characterized in that: The generation and verification process of the policy hash value includes: performing a hash operation on the policy content stored off-chain to generate a unique hash value, storing the hash value on-chain, and recalculating the off-chain policy hash value during verification and comparing it with the on-chain hash value. If they are consistent, the policy has not been tampered with.

7. A virtual network configuration management method based on a blockchain smart contract according to claim 2, characterized in that: The implementation steps of the multi-tenant isolation include: the sending end kernel protocol stack assigns a unique 24-bit label to the traffic according to the tenant identity of the sender, and after the receiving end kernel protocol stack parses the label, only the traffic with matching labels is allowed to enter the corresponding virtual network, and the rest of the traffic is isolated and filtered.

Citation Information

Cited By

  • Block chain-based information security intelligent management system and method

    CN120639515A