Block chain-based trusted network connection identity authentication and secure communication method
By generating public-private key pairs on the blockchain and generating session keys using the Diffie-Hellman algorithm, combining timestamps and hash eigenvalues to evaluate the stability and consistency of the communication link, and using the gradient boosting tree model for security evaluation, it solves the problem of failing to effectively deal with complex security threats in the existing solution, and achieves efficient and flexible secure communication.
Patent Information
- Application Number
- CN202510596422.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-09
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2045-05-09
AI Technical Summary
The existing blockchain-based identity authentication and communication security solutions have not been fully integrated with the dynamic key exchange mechanism, and it is difficult to effectively deal with complex security threats. It lacks a systematic communication link stability and consistency assessment method, cannot accurately quantify potential risks, and lacks an adaptive adjustment mechanism.
By generating public-private key pairs and storing them on the blockchain, the temporary session key is generated using the Diffie-Hellman algorithm, the timestamp and hash eigenvalues are calculated to evaluate link stability and consistency, and a gradient boosting tree model is used for comprehensive security evaluation, and the session key is dynamically adjusted to deal with potential threats.
It realizes efficient authentication and secure communication, can accurately identify potential attack behaviors, quickly respond and adjust policies, significantly improve the security and flexibility of the system, and ensure the confidentiality and integrity of data transmission.
Smart Images

Figure CN120389845A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and particularly to a trusted network connection identity authentication and secure communication method based on blockchain. Background Art
[0002] With the rapid development of information technology, network security issues have increasingly become the focus of attention from all sectors of society, especially the urgent needs in identity authentication and data transmission security. Traditional network connection identity authentication methods often rely on a centralized server for storing and verifying user information. This method not only faces the risk of single-point failure, but also has deficiencies in data privacy protection and is vulnerable to attacks or leaks. Blockchain technology, with its characteristics of decentralization, immutability, and high transparency, provides new ideas and technical means to solve these problems. By storing the user's public key on the blockchain and using smart contracts to implement an automated identity verification process, the security and reliability of the system can be significantly improved, while enhancing the user's control over personal data.
[0003] The existing technologies have the following deficiencies: However, the existing blockchain-based identity authentication and communication security solutions still have some limitations. First of all, most solutions fail to fully integrate a dynamic key exchange mechanism, making it difficult to effectively cope with complex security threats such as man-in-the-middle attacks and replay attacks in practical applications. Secondly, there is a lack of a systematic method for evaluating the stability and consistency of communication links. Only relying on simple threshold judgments, the potential risks cannot be accurately quantified, thus affecting the overall security level. In addition, many existing systems lack an adaptive adjustment mechanism. Once security risks are discovered, they cannot respond quickly and take measures, which greatly limits the flexibility and security of the system. Therefore, it is particularly important to develop a new method that can comprehensively cover the entire process from identity authentication to secure communication and has the capabilities of efficient detection and immediate response. Summary of the Invention
[0004] The purpose of the present invention is to provide a trusted network connection identity authentication and secure communication method based on blockchain to solve the problems in the above background.
[0005] The purpose of the present invention can be achieved through the following technical solutions: A trusted network connection identity authentication and secure communication method based on blockchain, comprising the following steps: S1: When a user registers, a pair of public and private key pairs are generated, and the public key is uploaded and stored in the blockchain smart contract. When the user requests a service, the message containing the identity authentication information is signed with the user's private key and sent to the service provider, and the service provider verifies the validity of the signature using the user's public key stored on the blockchain; S2: After successful authentication, both parties use the Diffie-Hellman algorithm to generate and exchange a temporary session key. The service provider encrypts the session key and sends it to the user; S3: After the user decrypts and obtains the session key, compare the difference between the timestamp when the key was generated and the current time, and calculate the timestamp deviation eigenvalue to evaluate the stability of the communication link; S4: Divide the session key into several small pieces of fixed length, calculate the hash value of each small piece respectively, count the distribution of these hash values, and calculate the consistency deviation eigenvalue of the key to evaluate the consistency of the communication link; S5: Conduct a comprehensive analysis of the timestamp deviation eigenvalue and the consistency deviation eigenvalue of the communication link. According to the analysis results, judge whether the current communication link is secure. If the judgment result is an insecure communication link, regenerate and exchange a new session key mechanism.
[0006] As a further solution of the present invention: The service provider uses the user public key stored on the blockchain to verify the validity of the signature, specifically including: When the user requests a service, the user first signs the message containing the authentication information with its private key to generate a digital signature. The digital signature and the original message are sent to the service provider together. After receiving the message and the digital signature, the service provider obtains the public key related to the user from the smart contract on the blockchain. The service provider uses this public key and the same signature algorithm to process the original message to calculate the signature value. If the calculated signature value matches the digital signature sent by the user, it proves that the message indeed comes from the user with the corresponding private key and has not been tampered with during the transmission process, thereby confirming the validity of the signature and the legality of the user identity.
[0007] As a further solution of the present invention: The evaluation of the stability of the communication link specifically includes: By comparing the difference between the timestamp when the key was generated and the current time, calculate the timestamp deviation eigenvalue, and judge whether the timestamp deviation eigenvalue is greater than or equal to the preset threshold. If so, the communication link is unstable; if not, the communication link is stable.
[0008] As a further solution of the present invention: The process of obtaining the timestamp deviation eigenvalue is: The process of obtaining the timestamp deviation eigenvalue is: Obtain the historical key generation timestamp and the corresponding current timestamp, calculate the difference between the current timestamp and the generation timestamp to obtain the timestamp deviation; Form a data set with all the calculated timestamp deviations; Initialize the clustering centers, including normal clusters and abnormal clusters, iteratively update the clustering centers. For each timestamp deviation in the dataset, assign it to the nearest clustering center and update the clustering center. Repeat the assignment and update steps until the clustering centers reach the maximum number of iterations; Calculate the mean of each cluster through the mean calculation expression, calculate the variance of each cluster through the standard deviation calculation expression, and preset the new timestamp deviation as , calculate the distance to each clustering center, and calculate the timestamp deviation eigenvalue according to the standard deviation of each cluster and the distance from the new timestamp deviation to each clustering center.
[0009] As a further solution of the present invention: The evaluation of the consistency of the communication link specifically includes: Divide the session key into several small pieces of fixed length, calculate the hash value of each small piece respectively, count the degree of distribution abnormality of these hash values, calculate the consistency deviation eigenvalue of the key, and determine whether the consistency deviation eigenvalue of the key is greater than or equal to the preset threshold. If so, the corresponding communication link is inconsistent; if not, the corresponding communication link is consistent.
[0010] As a further solution of the present invention: The process of obtaining the consistency deviation eigenvalue is: The process of obtaining the consistency deviation eigenvalue is: Divide the session key into several small pieces of fixed length, and the length of each small piece is bits. For each small piece, use the SHA-256 secure hash algorithm to calculate its corresponding hash value; count the number of occurrences of all small piece hash values, and preset the size of the hash value space as , calculate the ratio of the number of small pieces of fixed length to the size of the hash value space to obtain the expected frequency of each hash value. According to the difference between the actual observed frequency and the expected frequency, calculate the chi-square statistic. According to the selected confidence level, look up the chi-square distribution table to find the corresponding critical value, and calculate the ratio of the chi-square statistic to the corresponding critical value to obtain the consistency deviation eigenvalue.
[0011] As a further solution of the present invention: The comprehensive analysis of the timestamp deviation eigenvalue and the consistency deviation eigenvalue of the communication link specifically includes: Obtain the timestamp deviation eigenvalue and the consistency deviation eigenvalue of the communication link, and construct the timestamp deviation eigenvalue and the consistency deviation eigenvalue into a comprehensive feature vector as the input of the machine learning model. Take minimizing the error between the predicted communication security score and the actual communication security score as the training objective, and output the communication security score according to the trained model. The machine learning model is a gradient boosting tree model.
[0012] As a further solution of the present invention: The training process of the machine learning model is as follows: After constructing the feature vectors, a gradient boosting tree model is used for training. During the training process, minimizing the error between the predicted communication security score and the actual communication security score is used as the objective function. The gradient boosting tree model is an ensemble learning method that iteratively constructs multiple decision trees, and each new tree is dedicated to correcting the prediction errors of all previous trees, thereby gradually improving the overall performance of the model. The cross-validation technique is adopted, and the training set is divided multiple times, and different data subsets are used for model training and validation.
[0013] As a further solution of the present invention: Judging whether the current communication link is secure specifically includes: Judging whether the communication security score of the current communication link is greater than or equal to a preset threshold. If so, the current communication link is secure; if not, the current communication link is insecure.
[0014] Advantages of the present invention: (1) By integrating blockchain technology, an advanced key exchange mechanism, and a precise security assessment method, the present invention constructs a highly secure and reliable communication framework. First, during the user registration phase, blockchain technology is used to store the public keys of users. This approach not only ensures the immutability and high availability of the public keys but also greatly enhances the trust and security in the user authentication process. As a decentralized distributed ledger technology, blockchain's unique data structure and consensus algorithm ensure that the information stored on the chain has extremely high transparency and anti-tampering ability, providing a solid foundation for subsequent authentication. During the actual communication process, the present invention uses the Diffie-Hellman algorithm to dynamically generate temporary session keys and encrypts and transmits these keys using the public keys of users. This strategy ensures that only users holding the corresponding private keys can decrypt and obtain the original session key content. This method not only effectively prevents man-in-the-middle attacks but also ensures that both communication parties can establish a secure communication channel without exposing long-term keys, thereby greatly enhancing the security and confidentiality of data transmission. Furthermore, to comprehensively evaluate the stability and consistency of the communication link, the present invention introduces the concepts of timestamp deviation eigenvalue and consistency deviation eigenvalue. By analyzing the difference between the timestamp when the session key is generated and the current time, the timestamp deviation eigenvalue is calculated to evaluate the stability of the communication link; at the same time, the key is divided into several small pieces, the SHA-256 algorithm is used to calculate the hash values, and the consistency deviation eigenvalue is calculated based on the distribution of these hash values to evaluate the consistency of the link. The calculation and application of these two eigenvalues enable the system to accurately identify potential attack behaviors (such as delay attacks or replay attacks) and take corresponding protection measures at an early stage, significantly improving the defense ability and response speed of the entire system.
[0015] (2) The present invention innovatively introduces a comprehensive security assessment method for communication links based on the gradient boosting tree model. This method constructs a comprehensive feature vector containing timestamp deviation eigenvalues and consistency deviation eigenvalues as input, and trains with the goal of minimizing the error between the predicted communication security score and the actual communication security score, so as to achieve a rapid and accurate assessment of the security level of the communication link. Once it is detected that the security score of the communication link is lower than the preset threshold, indicating the existence of potential security threats, the system will automatically activate the mechanism to regenerate and exchange new session keys, ensuring timely adjustment of response strategies and effectively resisting security challenges such as delay attacks or replay attacks. This dynamic adaptation mechanism not only significantly improves the accuracy of security assessment, but also can identify and respond to potential security hazards at an early stage, ensuring the confidentiality and integrity of data transmission. In addition, by adopting cross-validation technology to optimize model parameters, the stability and generalization ability of the system are further enhanced, enabling the entire communication framework to have a high degree of adaptability and response speed, providing strong technical support for building a more secure and reliable data transmission environment. Description of the Drawings
[0016] The present invention will be further described below with reference to the drawings.
[0017] Figure 1 It is a specific step flow block diagram of the method for authenticating the identity and secure communication of a trusted network connection based on blockchain according to the present invention. Detailed Embodiments
[0018] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0019] Please refer to Figure 1 As shown, the present invention is a method for authenticating the identity and secure communication of a trusted network connection based on blockchain, including the following steps: S1: When a user registers, a pair of public and private key pairs are generated, and the public key is uploaded to and stored in the blockchain smart contract. When the user requests a service, the private key is used to sign the message containing the identity verification information and send it to the service provider, and the service provider uses the public key of the user stored on the blockchain to verify the validity of the signature; S2: After successful identity verification, both parties use the Diffie-Hellman algorithm to generate and exchange a temporary session key, and the service provider encrypts the session key and sends it to the user; S3: After the user decrypts to obtain the session key, compare the time stamp at the time of key generation with the current time, and calculate the time stamp deviation eigenvalue to evaluate the stability of the communication link; S4: Divide the session key into several small blocks of fixed length, calculate the hash value of each small block respectively, count the distribution of these hash values, and calculate the consistency deviation eigenvalue of the key to evaluate the consistency of the communication link; S5: Conduct a comprehensive analysis of the time stamp deviation eigenvalue and the consistency deviation eigenvalue of the communication link. According to the analysis results, judge whether the current communication link is secure. If the judgment result is an insecure communication link, regenerate and exchange a new session key mechanism.
[0020] In S1, when the user registers, a pair of public and private key pairs are generated, and the public key is uploaded to the blockchain smart contract for storage. When the user requests a service, the user signs the message containing the authentication information with its private key and sends it to the service provider. The service provider uses the public key of the user stored on the blockchain to verify the validity of the signature, specifically including: The user-side software creates the key pair using a secure key generation algorithm. The private key is securely stored on the user's device to ensure that it is not accessed or leaked without authorization. The user uploads the generated public key to the blockchain network through an encrypted communication channel and calls the smart contract interface to permanently record it on the blockchain. This process not only ensures the immutability and high availability of the public key but also provides a basis for subsequent authentication and data exchange.
[0021] The service provider uses the public key of the user stored on the blockchain to verify the validity of the signature, specifically including: When the user requests a service, the user first signs the message containing the authentication information with its private key to generate a digital signature. The digital signature and the original message are sent to the service provider together. After receiving the message and the digital signature, the service provider obtains the public key related to the user from the smart contract on the blockchain. The service provider uses this public key and the same signature algorithm to process the original message to calculate the signature value. If the calculated signature value matches the digital signature sent by the user, it proves that the message indeed comes from the user with the corresponding private key and has not been tampered with during the transmission process, thus confirming the validity of the signature and the legitimacy of the user's identity.
[0022] In S2, after successful authentication, both parties use the Diffie-Hellman algorithm to generate and exchange a temporary session key. The service provider encrypts the session key and sends it to the user, specifically including: After successful authentication, the two parties first publicly share a set of parameters (such as large prime numbers and bases), then each independently selects a private random number, and calculates the corresponding public value based on this. Then, the two parties exchange these public values with each other, and combine the other party's public value with their own private random number through a specific calculation formula, so as to generate the same temporary session key at both ends. This process ensures that even if a third party intercepts all the exchanged information, it is impossible to easily deduce the session key.
[0023] After generating the temporary session key, the service provider encrypts the session key using the user's public key and sends it to the user. To achieve this, the service provider obtains the user's public key from the blockchain and encrypts the session key using this public key to ensure that only the holder of the corresponding private key (i.e., the user) can decrypt and obtain the original session key content. The encrypted session key is transmitted to the user side through a secure channel. After receiving the encrypted information, the user decrypts it using its private key to obtain the session key. In this way, the two parties establish a secure communication channel based on symmetric encryption, and can use this temporary session key for subsequent data encryption transmission, ensuring the confidentiality and integrity of the data, while reducing the risk of the key being stolen.
[0024] In S3, after the user decrypts to obtain the session key, compare the time stamp when the key was generated with the current time, and calculate the time stamp deviation eigenvalue to evaluate the stability of the communication link, specifically including: By comparing the time stamp when the key was generated with the current time, calculate the time stamp deviation eigenvalue, and judge whether the time stamp deviation eigenvalue is greater than or equal to the preset threshold. If so, the communication link is unstable; if not, the communication link is stable.
[0025] The process of obtaining the time stamp deviation eigenvalue is as follows: Obtain the historical key generation time stamp and the corresponding current time stamp, calculate the difference between the current time stamp and the generation time stamp to obtain the time stamp deviation; Form a data set with all the calculated time stamp deviations; Initialize the clustering center , where represents the number of clustering centers, , preset , including a normal cluster and an abnormal cluster, iteratively update the clustering center. For each time stamp deviation in the data set, assign it to the nearest clustering center, and the calculation formula is: ; where represents the number of time stamp deviations in the data set, represents the th time stamp deviation in the data set, represents the clustering center, Indicates that is assigned to the cluster center that makes the smallest, indicating the cluster to which it belongs; Update the cluster center, and calculate the expression: ; where represents the set of all timestamp deviations of the th cluster center, represents the number of all timestamp deviations of the th cluster center. Repeat the assignment and update steps until the cluster center reaches the maximum number of iterations; Calculate the mean of each cluster through the mean calculation expression, calculate the variance of each cluster through the standard deviation calculation expression, preset the new timestamp deviation as , calculate the distance to each cluster center, and the calculation expression is: ; where represents the distance to each cluster center, represents the mean of each cluster; Calculate the timestamp deviation eigenvalue according to the standard deviation of each cluster and the distance from the new timestamp deviation to each cluster center, and the calculation expression is: ; where represents the timestamp deviation eigenvalue, represents the standard deviation of each cluster.
[0026] It should be noted that: By comparing the difference between the timestamp when the session key is generated and the current time, calculate the timestamp deviation eigenvalue to evaluate the stability of the communication link, and use the clustering analysis method to classify and identify the timestamp deviation, distinguishing normal and abnormal timestamp deviation patterns. This method not only improves the evaluation accuracy of the communication link stability, but also can effectively identify potential abnormal situations, such as delay attacks or replay attacks, thereby enhancing the security and reliability of the system.
[0027] In S4, divide the session key into several fixed-length chunks, calculate the hash value of each chunk respectively, count the distribution of these hash values, and calculate the consistency deviation eigenvalue of the key to evaluate the consistency of the communication link, specifically including: Divide the session key into several fixed-length chunks, calculate the hash value of each chunk respectively, count the degree of distribution abnormality of these hash values, calculate the consistency deviation eigenvalue of the key, and determine whether the consistency deviation eigenvalue of the key is greater than or equal to the preset threshold. If so, the corresponding communication link is inconsistent; if not, the corresponding communication link is consistent.
[0028] The process of obtaining the consistency deviation eigenvalue is: Split the session key into several small blocks of a fixed length, where the length of each small block is bits. For each small block, use the SHA-256 secure hash algorithm to calculate its corresponding hash value; count the occurrences of all small block hash values. Preset the size of the hash value space to . Calculate the ratio of the number of fixed-length small blocks to the size of the hash value space to obtain the expected frequency of each hash value. According to the difference between the actual observed frequency and the expected frequency, calculate the chi-square statistic. The calculation expression is: In the formula, represents the chi-square statistic, represents the th hash value, represents the size of the hash value space, represents the th occurrence count of the hash value, represents the th expected frequency of the hash value; calculate the degrees of freedom. The calculation expression is: where represents the degrees of freedom, represents the size of the hash value space after grouping. According to the selected confidence level (95%), look up the chi-square distribution table to find the corresponding critical value. Calculate the ratio of the chi-square statistic to the corresponding critical value to obtain the consistency deviation eigenvalue.
[0029] It should be noted that: by splitting the session key used in the communication link into small blocks of a fixed length, calculating the hash value for each small block using the SHA-256 algorithm, and evaluating the consistency deviation eigenvalue of the key according to the distribution of the hash values, the consistency and security of the communication link can be effectively judged. Using statistical methods (chi-square test) to quantify the deviation between the actual distribution and the theoretical distribution of the key block hash values, which is used as an important indicator to measure the consistency of the communication link; this method not only improves the accuracy of detecting communication link anomalies but also can detect potential security threats at an early stage, ensuring the confidentiality and integrity of data transmission.
[0030] In S5, comprehensively analyze the timestamp deviation eigenvalue and the consistency deviation eigenvalue of the communication link. According to the analysis results, judge whether the current communication link is secure. If the judgment result is an insecure communication link, regenerate and exchange a new session key mechanism, which specifically includes: Obtain the timestamp deviation eigenvalue and the consistency deviation eigenvalue of the communication link, and construct the timestamp deviation eigenvalue and the consistency deviation eigenvalue into a comprehensive feature vector as the input of the machine learning model. Take minimizing the error between the predicted communication security score and the actual communication security score as the training objective. According to the trained model, output the communication security score. The machine learning model is a gradient boosting tree model; The training process of the machine learning model is as follows: After constructing the feature vectors, a gradient boosting tree model is used for training. During the training process, minimizing the error between the predicted communication security score and the actual communication security score is used as the objective function. The GBT model is an ensemble learning method that gradually improves the overall performance of the model by iteratively constructing multiple decision trees, and each new tree is dedicated to correcting the prediction errors of all previous trees. To ensure the generalization ability of the model and avoid overfitting, the embodiments of the present invention adopt a cross-validation technique, divide the training set multiple times, use different data subsets for model training and validation, and finally determine the optimal configuration of the model parameters; The determination of whether the current communication link is secure specifically includes: Judge whether the communication security score of the current communication link is greater than or equal to a preset threshold. If so, the current communication link is secure; if not, the current communication link is insecure. If the judgment result is an insecure communication link, a new session key mechanism is regenerated and exchanged.
[0031] It should be noted that: for the trained gradient boosting tree model, when receiving new communication link data, the corresponding communication security score can be quickly output. This score reflects the security level of the communication link, and the higher the score, the more secure the communication.
[0032] Working principle of the present invention: In the user registration stage, by generating a pair of public and private key pairs and uploading the public key to the blockchain smart contract for storage, the immutability and high availability of the public key are ensured, providing a solid foundation for subsequent identity authentication and data exchange. When a user requests a service, the user uses their private key to sign a message containing identity authentication information and sends it to the service provider; the service provider then uses the user's public key obtained from the blockchain to verify the validity of the signature and confirm the legitimacy of the user's identity. After successful identity authentication, both parties use the Diffie-Hellman algorithm to generate and exchange a temporary session key. The service provider encrypts the key and transmits it to the user through a secure channel, establishing a secure communication channel based on symmetric encryption. Further, in order to evaluate the stability and consistency of the communication link, the present invention respectively proposes calculation methods for the timestamp deviation eigenvalue and the consistency deviation eigenvalue. For stability evaluation, the timestamp deviation eigenvalue is calculated by comparing the difference between the timestamp at the time of key generation and the current time, and a clustering analysis method is used to identify normal and abnormal patterns; for consistency evaluation, the key is divided into several small pieces, the SHA-256 algorithm is used to calculate the hash value, and the consistency deviation eigenvalue is evaluated based on the hash value distribution. Through comprehensive analysis of the timestamp deviation eigenvalue and the consistency deviation eigenvalue, a comprehensive feature vector is constructed as the input of the gradient boosting tree model, and the model is trained with the goal of minimizing the error between the predicted communication security score and the actual communication security score. The gradient boosting tree model can quickly output the communication security score, reflecting the security level of the communication link. If it is determined that the communication link is insecure, a new session key needs to be regenerated and exchanged. The present invention not only improves the accuracy of evaluating the security of the communication link, but also can timely detect and handle potential security problems, ensuring the security and integrity of data transmission, thus providing strong technical support for building a more secure and reliable communication environment.
[0033] The above has described in detail one embodiment of the present invention, but the content described is only a preferred embodiment of the present invention and cannot be considered as limiting the scope of implementation of the present invention. All equivalent changes and improvements made within the scope of the application of the present invention should still fall within the scope covered by the patent of the present invention.
Claims
1. A method for identity authentication and secure communication of a trusted network connection based on blockchain, characterized in that It includes the following steps: S1: When a user registers, a pair of public and private key pairs are generated, and the public key is uploaded and stored in the blockchain smart contract. When the user requests a service, the user signs the message containing the authentication information with their private key and sends it to the service provider. The service provider verifies the validity of the signature using the user's public key stored on the blockchain; S2: After successful authentication, both parties use the Diffie-Hellman algorithm to generate and exchange a temporary session key. The service provider encrypts the session key and sends it to the user; S3: After the user decrypts to obtain the session key, the user compares the time difference between the timestamp when the key was generated and the current time, and calculates the timestamp deviation eigenvalue to evaluate the stability of the communication link; S4: The session key is divided into several small blocks of a fixed length, the hash value of each small block is calculated respectively, the distribution of these hash values is statistically analyzed, and the consistency deviation eigenvalue of the key is calculated to evaluate the consistency of the communication link; S5: Comprehensive analysis is performed on the timestamp deviation eigenvalue and the consistency deviation eigenvalue of the communication link. According to the analysis results, it is judged whether the current communication link is secure. If the judgment result is an insecure communication link, a new session key mechanism is regenerated and exchanged.
2. The method for authenticating identity and secure communication of a trusted network connection based on blockchain according to claim 1, characterized in that, The service provider verifies the validity of the signature using the user's public key stored on the blockchain, which specifically includes: When the user requests a service, the user first signs the message containing the authentication information with their private key to generate a digital signature. The digital signature and the original message are sent to the service provider together. After receiving the message and the digital signature, the service provider obtains the public key related to the user from the smart contract on the blockchain. The service provider processes the original message using this public key and the same signature algorithm to calculate the signature value. If the calculated signature value matches the digital signature sent by the user, it proves that the message indeed comes from the user with the corresponding private key and has not been tampered with during the transmission process, thereby confirming the validity of the signature and the legality of the user's identity.
3. The method for authenticating the identity of a trusted network connection and secure communication based on blockchain according to claim 1, characterized in that, The evaluation of the stability of the communication link specifically includes: By comparing the time difference between the timestamp when the key was generated and the current time, the timestamp deviation eigenvalue is calculated, and it is judged whether the timestamp deviation eigenvalue is greater than or equal to the preset threshold. If so, the communication link is unstable; if not, the communication link is stable.
4. The method for authenticating the identity of a trusted network connection and secure communication based on a blockchain according to claim 3, wherein The process of obtaining the timestamp deviation eigenvalue is: The process of obtaining the timestamp deviation eigenvalue is: Obtain the historical key generation timestamp and the corresponding current timestamp, calculate the difference between the current timestamp and the generation timestamp to obtain the timestamp deviation; Form a dataset with all the calculated timestamp deviations; Initialize the clustering centers, including the normal cluster and the abnormal cluster, and iteratively update the clustering centers. For each timestamp deviation in the dataset, assign it to the nearest clustering center and update the clustering center. Repeat the assignment and update steps until the clustering centers reach the maximum number of iterations; Calculate the mean of each cluster through the mean calculation expression, calculate the variance of each cluster through the standard deviation calculation expression, and preset the new timestamp deviation as , calculate the distance to each cluster center, and calculate the timestamp deviation eigenvalue based on the standard deviation of each cluster and the distance to each cluster center with the new timestamp deviation.
5. The method for authenticating the identity of a trusted network connection and secure communication based on a blockchain according to claim 1, characterized in that The evaluation of the consistency of the communication link specifically includes: The session key is divided into several small blocks of a fixed length. The hash value of each small block is calculated respectively, the degree of abnormal distribution of these hash values is statistically analyzed, the consistency deviation eigenvalue of the key is calculated, and it is judged whether the consistency deviation eigenvalue of the key is greater than or equal to a preset threshold. If so, the corresponding communication link is inconsistent; if not, the corresponding communication link is consistent.
6. The method for authenticating the identity of a trusted network connection and secure communication based on a blockchain according to claim 5, wherein The process of obtaining the consistency deviation eigenvalue is as follows: The process of obtaining the consistency deviation eigenvalue is as follows: Split the session key into several small pieces of a fixed length, where the length of each small piece is bits. For each small piece, use the SHA-256 secure hash algorithm to calculate its corresponding hash value; count the occurrence times of all small piece hash values. Preset the space size of the hash value as , calculate the ratio of the number of small pieces of fixed length to the space size of the hash value to obtain the expected frequency of each hash value. According to the difference between the actual observed frequency and the expected frequency, calculate the chi-square statistic. According to the selected confidence level, look up the chi-square distribution table to find the corresponding critical value, and calculate the ratio of the chi-square statistic to the corresponding critical value to obtain the consistency deviation eigenvalue.
7. The method for identity authentication and secure communication of a trusted network connection based on blockchain according to claim 1, wherein The comprehensive analysis of the timestamp deviation eigenvalue and the consistency deviation eigenvalue of the communication link specifically includes: Obtain the timestamp deviation eigenvalue and the consistency deviation eigenvalue of the communication link, and construct the timestamp deviation eigenvalue and the consistency deviation eigenvalue into a comprehensive feature vector as the input of the machine learning model. Taking minimizing the error between the predicted communication security score and the actual communication security score as the training objective, according to the trained model, output the communication security score. The machine learning model is a gradient boosting tree model.
8. The method for authenticating the identity of a trusted network connection and secure communication based on blockchain according to claim 7, characterized in that, The training process of the machine learning model is as follows: After constructing the feature vector, use the gradient boosting tree model for training. During the training process, taking minimizing the error between the predicted communication security score and the actual communication security score as the objective function, the gradient boosting tree model is an ensemble learning method. By iteratively constructing multiple decision trees, and each new tree is dedicated to correcting the prediction errors of all previous trees, thereby gradually improving the overall performance of the model. The cross-validation technique is adopted, the training set is divided multiple times, and different data subsets are used for model training and validation.
9. The method for authenticating the identity of a trusted network connection and secure communication based on a blockchain according to claim 1, wherein The judgment of whether the current communication link is secure specifically includes: Judge whether the communication security score of the current communication link is greater than or equal to a preset threshold. If so, the current communication link is secure; if not, the current communication link is insecure.
Citation Information
Patent Citations
Internet of Things trusted data management method based on block chain technology
CN113553574A
Authentication method and system of security terminal based on blockchain
CN113824570A
Distributed device identity authentication and access control method and system based on block chain
CN119363318A
Auditable privacy protection deep learning platform construction method based on block chain incentive mechanism
US20200193292A1
Cited By
Multi-party security electronic signature and certificate authentication method based on key component collaboration
CN122160190A