Distributed service credibility authentication method and system for cloud computing environment
By receiving authentication requests in the cloud computing environment, performing business status evaluation and path establishment, obtaining unique verification credentials, and recording the authentication process with smart contracts and distributed ledgers, the distributed business authentication efficiency and security problems in the cloud computing environment are solved, and an efficient and reliable authentication process is achieved.
Patent Information
- Application Number
- CN202510583494.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-08-15
AI Technical Summary
In the cloud computing environment, distributed services face problems such as difficulty in adapting to dynamic business environments, poor cross-system authentication interoperability, and lack effective recording and traceability of authentication processes, resulting in poor authentication efficiency, accuracy, security and credibility.
By receiving authentication requests, conducting business status evaluation, establishing authentication paths, obtaining unique verification credentials, calling the user's authentication data set, using smart contracts to analyze the authentication data sets of multiple authentication nodes, using distributed ledgers to record the authentication process data, and generating authentication attitude measurements. If the authentication is passed, access permission is granted.
It improves the accuracy, efficiency and security of distributed business trusted authentication, ensures the orderliness and completeness of the authentication process, and enhances the reliability and traceability of authentication.
Smart Images

Figure CN120498738A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field related to cloud computing trusted authentication, and specifically to a distributed business trusted authentication method and system for a cloud computing environment. Background Art
[0002] Distributed businesses in cloud computing environments serve as the core of everything from enterprise-level distributed data processing and cloud-based collaborative office work to large-scale distributed application services on the internet. While enjoying the many benefits of cloud computing, they also face increasingly prominent security risks, of which authentication security is a crucial component. Traditional static authentication methods based on usernames and passwords have significant limitations in distributed business scenarios in cloud computing environments. On the one hand, static passwords are easily stolen and cracked, making them vulnerable to brute force attacks, phishing, and other attacks. On the other hand, distributed businesses involve numerous participants and interact frequently, making existing authentication methods unable to effectively adapt to complex and changing business environments and dynamic network topologies, making it difficult to meet the distributed business's requirements for authentication efficiency, security, and flexibility. Furthermore, the decentralized nature of data storage and processing in cloud computing environments poses challenges to data integrity, authenticity, and privacy protection during the authentication process, impacting the secure and stable operation of distributed businesses.
[0003] Therefore, at the current stage, relevant technologies have technical problems such as difficulty in adapting to dynamic business environments, poor cross-system authentication interoperability, and lack of effective records and traceability of the authentication process, resulting in poor authentication efficiency, accuracy, security, and credibility. Summary of the Invention
[0004] This application provides a distributed business trusted authentication method and system for cloud computing environments, which solves the technical problems in the existing technology that are difficult to adapt to dynamic business environments, have poor cross-system authentication interoperability, and lack effective records and traceability of the authentication process, resulting in poor authentication efficiency, accuracy, security and credibility, and achieves the technical effect of improving the accuracy, efficiency and security of distributed business trusted authentication.
[0005] The present application provides a distributed business trusted authentication method for a cloud computing environment, the method comprising: receiving an authentication request for a distributed business; performing a business status evaluation on the distributed business, and establishing an authentication path using the business status evaluation result; parsing the authentication request, obtaining a unique verification credential and calling the user's authentication data set; after activating the authentication database using the unique verification credential, sending the authentication reference credential of the authentication database to multiple authentication nodes, the multiple authentication nodes being constructed based on the authentication path; performing authentication analysis of the authentication data sets of multiple authentication nodes based on the cloud computing environment by calling a smart contract, and establishing a node authentication result; using a distributed ledger to record authentication process data and node authentication results, and combining the node authentication results to generate an authentication attitude quantity; if the authentication attitude quantity is an authentication pass result, granting access rights to the distributed business, and the access rights generate an authorization key by attribute encryption, which is used to control access rights to audit chain data.
[0006] In a possible implementation, the distributed business trusted authentication method for a cloud computing environment further performs the following processing: after extracting business-related data from the distributed business, the business-related data is packaged and sent to a business status evaluation channel; based on the business status evaluation channel, a business status evaluation is performed under multiple features to construct a business status vector; and the business status vector is output as a business status evaluation result.
[0007] In a possible implementation, the distributed business trusted authentication method for a cloud computing environment further performs the following processing: activating a resource-sensitive sub-channel to perform resource sensitivity feature analysis of business-related data and establish a resource sensitivity vector; activating a session security level sub-channel to perform security level analysis under the access device type and access location features of the business-related data and establish a session security level vector; activating a task urgency sub-channel to perform urgency evaluation of the business-related data and establish a task urgency vector; activating a user behavior trusted analysis sub-channel to perform user behavior credibility evaluation under the business-related data and establish a user behavior credibility vector, wherein the resource-sensitive sub-channel, session security level sub-channel, task urgency sub-channel, and user behavior trusted analysis sub-channel are all sub-channels of the business status evaluation channel; and constructing a business status vector based on the resource sensitivity vector, session security level vector, task urgency vector, and user behavior credibility vector.
[0008] In a possible implementation, the distributed business trusted authentication method for a cloud computing environment further performs the following processing: establishing a decision tree for path selection through a historical database; extracting the business status evaluation results as selection key features and inputting them into the decision tree; and selecting authentication nodes according to the decision tree to establish an authentication path.
[0009] In a possible implementation, the distributed business trusted authentication method for a cloud computing environment further performs the following processing: establishing a node dynamic reputation score for each authentication node; dynamically updating the node dynamic reputation score based on the historical authentication behavior quality, response time, and error rate of the authentication node; and performing selection optimization based on the node dynamic reputation score during the authentication node selection process in the decision tree.
[0010] In a possible implementation, the distributed business trusted authentication method for a cloud computing environment further performs the following processing: establishing a mapping one-way communication between the authentication database and the multiple authentication nodes; configuring authentication requirements according to the authentication functions of the multiple authentication nodes, using the authentication requirements and the unique verification certificate to match the data in the authentication database to generate a data matching result; constructing the data matching result into an authentication reference certificate, which is a one-time authentication summary data packet that is encrypted; and sending the authentication reference certificate to the corresponding multiple authentication nodes through the mapping one-way communication.
[0011] In a possible implementation, the distributed business trusted authentication method for a cloud computing environment further performs the following processing: activating an exception rollback mechanism when any authentication node fails to authenticate or the node is unavailable; utilizing the exception rollback mechanism to roll back and record through a backup path.
[0012] In a possible implementation, the distributed business trusted authentication method for a cloud computing environment further performs the following processing: reading the authentication frequency and authentication status of the authentication subject of the distributed business; establishing a request exception value using the authentication frequency and authentication status; and updating the authentication path through the request exception value.
[0013] In a possible implementation, the distributed business trusted authentication method for a cloud computing environment further performs the following processing: if the authentication attitude value indicates that the authentication has failed, a warning signal is configured according to the authentication attitude value, and a warning alarm is issued.
[0014] The present application also provides a distributed business trusted authentication system for a cloud computing environment, the system comprising: an authentication request receiving module for receiving an authentication request for a distributed business; a business status evaluation module for performing business status evaluation on the distributed business and establishing an authentication path using the business status evaluation result; an authentication data set acquisition module for parsing the authentication request, obtaining a unique verification credential and calling the user's authentication data set; an authentication reference credential sending module for sending the authentication reference credential of the authentication database to multiple authentication nodes after activating the authentication database using the unique verification credential, the multiple authentication nodes being constructed based on the authentication path; a node authentication result establishment module for performing authentication analysis of the authentication data sets of multiple authentication nodes by calling a smart contract based on a cloud computing environment and establishing a node authentication result; an authentication attitude quantity generation module for recording authentication process data and node authentication results using a distributed ledger, and combining the node authentication results to generate an authentication attitude quantity; an access permission granting module for granting access permission to the distributed business if the authentication attitude quantity is an authentication pass result, the access permission generating an authorization key by attribute encryption, which is used to control access permission to audit chain data.
[0015] The distributed business trusted authentication method and system for cloud computing environments proposed in this application is intended to receive authentication requests for distributed businesses; establish an authentication path using the business status evaluation results; obtain a unique verification credential and call the user's authentication data set; send the authentication reference credential to multiple authentication nodes; call a smart contract based on the cloud computing environment to perform authentication analysis of the authentication data sets of multiple authentication nodes; use a distributed ledger to record authentication process data and node authentication results, and generate an authentication attitude quantity; if the authentication attitude quantity is a pass result, access rights are granted. This solves the technical problems in the existing technology that are difficult to adapt to dynamic business environments, have poor cross-system authentication interoperability, and lack effective records and traceability of the authentication process, resulting in poor authentication efficiency, accuracy, security, and credibility, and achieves the technical effect of improving the accuracy, efficiency, and security of distributed business trusted authentication. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] To more clearly illustrate the technical solutions of the embodiments of the present disclosure, the accompanying drawings of the embodiments of the present disclosure are briefly introduced below. Flowcharts are used in this application to illustrate the operations performed by the systems according to the embodiments of the present application. It should be understood that the preceding or following operations are not necessarily performed in precise order. Instead, various steps may be processed in reverse order or simultaneously as needed. Furthermore, other operations may be added to these processes, or one or more operations may be removed from these processes.
[0017] Figure 1 A flow chart of a distributed business trusted authentication method for a cloud computing environment provided in an embodiment of the present application.
[0018] Figure 2 A schematic diagram of the structure of a distributed business trusted authentication system for a cloud computing environment provided in an embodiment of the present application.
[0019] Explanation of the reference numerals: authentication request receiving module 10 , business status evaluation module 20 , authentication data set acquisition module 30 , authentication reference credential sending module 40 , node authentication result establishment module 50 , authentication attitude quantity generation module 60 , access authority granting module 70 . DETAILED DESCRIPTION
[0020] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below.
[0021] In order to make the purpose, technical solutions and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limiting this application. All other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.
[0022] In the following description, reference is made to “some embodiments”, which describes a subset of all possible embodiments, but it will be understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict, and the terms “first\second” involved are merely used to distinguish similar objects and do not represent a specific ordering of the objects. The terms “including” and “having” and any variations are intended to cover non-exclusive inclusions. For example, a process, method, system, product or server that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or modules that are not clearly listed or inherent to these processes, methods, products or devices. Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application belongs. The terms used herein are for the purpose of describing the embodiments of this application only.
[0023] The present application embodiment provides a distributed business trusted authentication method for cloud computing environment, such as Figure 1 As shown, the method includes:
[0024] Step S100: receiving an authentication request for a distributed service.
[0025] Preferably, an authentication request initiated by a distributed business in a cloud computing environment that requires identity authentication, permission verification, etc. is obtained. Specifically, the authentication request may be initiated by multiple entities. For example, when a user uses a distributed application based on cloud computing (such as online collaborative office software, distributed data storage services, etc.), in order to access specific resources or perform specific operations, an authentication request is sent; or when different business modules or service components interact with each other, an authentication request is initiated to ensure the legitimacy and security of the interaction. The authentication request usually contains necessary information related to authentication, which may include user or service identification information (such as user name, user ID, service unique identifier, etc.) to prove the identity of the requester; and information about the specific operation requested or the resource to be accessed (such as the file to be accessed, database table, specific function to be performed, etc.); the authentication request is transmitted between various components of the distributed system over the network, and various network protocols (such as HTTP, HTTPS, etc.) may be used to ensure the secure transmission of the request; the module responsible for processing the authentication request in the cloud computing environment performs preliminary parsing and verification on the request, checks whether the request format is correct and the information is complete, and then further processes the request, such as calling relevant authentication data sets and performing business status evaluation.
[0026] Step S200: performing a service status evaluation on the distributed service, and establishing an authentication path using the service status evaluation result.
[0027] Preferably, the business status of the distributed business is evaluated. Specifically, the current state of the business is evaluated, that is, by collecting and analyzing various information related to the distributed business, including the operating status of the business, resource usage, user behavior patterns, etc., the current performance status of the business is analyzed. For example, indicators such as the response time, throughput, and error rate of the business system are checked to determine whether the business is operating normally, and the user's login frequency, operation type, and access pattern of resources are analyzed to determine whether the user behavior is abnormal; the dynamics of the business environment are analyzed, that is, the dynamic changes of the cloud computing environment are evaluated, such as the elastic scaling of resources, the adjustment of network topology, and the fluctuation of business load on the business status. For example, when the cloud computing platform automatically increases or decreases computing resources according to business needs, the impact of resource changes on business operations is evaluated, and whether new security risks will be introduced; based on the analysis of the business operating status and environmental dynamics, the potential risks faced by the business are comprehensively evaluated to obtain business status evaluation results.
[0028] Preferably, based on the results of the business status evaluation, an authentication strategy and process suitable for the current business status is formulated. For example, if the business is in a high-risk state, a stricter authentication method, such as multi-factor authentication, is adopted. If the business status is relatively stable and the risk is low, the authentication process is appropriately simplified to improve authentication efficiency. Then, based on the authentication strategy, a suitable node is selected from multiple available authentication nodes in the cloud computing environment, and the authentication method to be used is determined. The authentication nodes may be different servers, service components or security modules. Each node may have different authentication functions and characteristics. For example, some nodes are good at user identity authentication, while other nodes are more suitable for permission verification. According to the business status and authentication requirements, the authentication nodes are reasonably combined. Finally, the selected authentication nodes are connected in a certain order and logic to form a complete authentication path, and the input and output of each node, as well as the information transmission and interaction methods between nodes are clearly defined. For example, after the first authentication node completes user identity authentication, it passes the verification result to the next node for permission verification, and so on until the entire authentication process is completed, thereby ensuring the orderliness and integrity of the authentication process and improving the accuracy and reliability of authentication.
[0029] Furthermore, step S200 also includes step S210, after extracting business-related data of the distributed business, packaging the business-related data and sending it to the business status evaluation channel; step S220, performing business status evaluation under multiple features based on the business status evaluation channel, and constructing a business status vector; step S230, outputting the business status vector as a business status evaluation result.
[0030] Preferably, business-related data is extracted from various data sources of the distributed business to reflect the operation status of the business, and the business-related data is packaged into a data packet and sent to a business status evaluation channel. The business status evaluation channel is used to analyze and evaluate the business status. The business status evaluation channel evaluates the business status from multiple different feature dimensions based on the received business-related data, which may include the business's resource usage and resource sensitivity, the security of the business session, the urgency of the business task, and the credibility of the user's behavior in the business. By analyzing the multiple features of the business association book, a comprehensive understanding of the current state of the business is obtained. Then, the multi-dimensional evaluation results are integrated to form a business status vector, each element of which corresponds to a business feature and contains information on the business in multiple aspects such as resource sensitivity, session security, task urgency, and user behavior credibility. Finally, the business status vector is output as the final business status evaluation result for subsequent decision-making. For example, based on the business status vector, it is determined whether the business needs to be adjusted, such as adjusting resource allocation, strengthening security measures, prioritizing urgent tasks, etc., thereby ensuring the safe and efficient operation of the distributed business.
[0031] Furthermore, step S220 also includes step S221, activating the resource-sensitive sub-channel to perform resource sensitivity feature analysis of business-related data and establish a resource sensitivity vector; step S222, activating the session security level sub-channel to perform security level analysis under the access device type and access location characteristics of the business-related data, and establish a session security level vector; step S223, activating the task urgency sub-channel to evaluate the urgency of the business-related data and establish a task urgency vector; step S224, activating the user behavior trusted analysis sub-channel to evaluate the user behavior credibility under the business-related data and establish a user behavior credibility vector. The resource-sensitive sub-channel, session security level sub-channel, task urgency sub-channel, and user behavior trusted analysis sub-channel are all sub-channels of the business status evaluation channel; step S225, constructing a business status vector based on the resource sensitivity vector, session security level vector, task urgency vector, and user behavior credibility vector.
[0032] Preferably, the business status evaluation channel includes a resource-sensitive sub-channel, a session security level sub-channel, a task urgency sub-channel, and a user behavior trust analysis sub-channel. Specifically, the resource-sensitive sub-channel mainly evaluates the business's use of resources and resource sensitivity, such as analyzing the business operations' occupancy of hardware resources such as CPU, memory, and storage, as well as the frequency and intensity of use of software resources such as databases and network bandwidth, and evaluating whether the business operations involve access to key business data, whether there is resource competition or potential resource bottlenecks, etc., and then establishing a resource sensitivity vector, where each dimension represents a different resource sensitivity indicator to intuitively reflect the business's sensitivity and status in resource usage.
[0033] Preferably, the session security level sub-channel is used to evaluate the security of business sessions, including the method of user login authentication, the degree of session encryption, and whether there are security risks such as session hijacking. For example, the type of device (such as mobile phone, computer, dedicated terminal, etc.) and access location (such as corporate intranet, public wireless network, remote network, etc.) are analyzed. Different device types and access locations may bring different security risks. The security level analysis results are then quantified to form a session security level vector to clearly understand the security status and potential risks of the business session. The task urgency sub-channel is used to evaluate the urgency of business tasks. For example, the urgency of the task is comprehensively evaluated based on the task deadline, the criticality to the business process, the priority setting of the task, etc., and the urgency evaluation results are then expressed in vector form to intuitively understand the urgency of each task in the business, so as to facilitate resource allocation and task scheduling.
[0034] Preferably, the user behavior credibility analysis subchannel is used to analyze user behavior during business processes to determine whether it is trustworthy. For example, by analyzing the user's operation patterns, operation frequency, behavioral habits, and historical behavior records, it compares them with the user's historical behavior data and normal behavior patterns to identify abnormal behavior and then determine the credibility of the user's behavior. The user behavior credibility evaluation results are then converted into a vector form to comprehensively reflect the credibility of the user's behavior during business processes, facilitating the timely detection of abnormal behavior and potential security threats. Finally, the resource sensitivity vector, session security level vector, task urgency vector, and user behavior credibility vector are integrated to generate a business status vector, which provides a comprehensive understanding of the overall business status and facilitates resource allocation and risk control.
[0035] Furthermore, step S200 also includes step S240, establishing a decision tree for path selection through a historical database; step S250, extracting the business status evaluation results as key features and inputting them into the decision tree; step S260, selecting authentication nodes according to the decision tree to establish an authentication path.
[0036] Preferably, business-related data is collected from a historical database, including business status information in different business scenarios in the past, relevant data of authentication nodes, and the final selected authentication path, etc., and features are extracted from the collected historical data to find key features related to path selection, which may include the resource sensitivity of the business, the session security level, the urgency of the task, the credibility of user behavior, etc., as well as the performance, reliability, cost and other attributes of different authentication nodes. A decision tree is then constructed based on the key features. Each node of the decision tree represents the evaluation of a feature, the branches represent different evaluation results, and the leaves correspond to the final authentication path selection. By learning and analyzing historical data, the decision tree can predict the appropriate authentication path based on the input feature information.
[0037] Preferably, features that have a key impact on the selection of authentication nodes are extracted from the business status evaluation results, such as the key resource occupancy rate in resource sensitivity, the encryption strength in the session security level, the remaining time in the task urgency, etc., and then these key features are input into the decision tree as input data. The decision tree traverses and judges in the tree structure, starting from the root node, and according to the feature evaluation conditions on each node, it gradually moves downward along the corresponding branch until it reaches the leaf node, that is, the authentication node is selected, and the corresponding authentication path is derived according to the authentication node, that is, in distributed business, the order and connection method of business data from the initiator to the target end through multiple authentication nodes, thereby ensuring the security, reliability and efficiency of business data during transmission and processing, while meeting the business requirements in different aspects, such as resource constraints, security levels, task urgency, etc.
[0038] Furthermore, step S260 also includes step S261, establishing a node dynamic reputation score for each authentication node; step S262, dynamically updating the node dynamic reputation score based on the historical authentication behavior quality, response time, and error rate of the authentication node; and step S263, performing selection optimization based on the node dynamic reputation score during the authentication node selection process in the decision tree.
[0039] Preferably, a dynamic reputation score is established for each authentication node to reflect the node's overall performance during the authentication process. The reputation of the authentication node is then evaluated based on historical authentication behavior quality, response time, error rate, and other factors. The dynamic reputation score of each authentication node is updated in real time to accurately reflect the node's current status and historical performance. The historical authentication behavior quality includes the accuracy, completeness, and compliance of the authentication node during past authentication operations, such as whether the node can accurately verify user identities, whether it operates strictly in accordance with authentication rules, and whether it can promptly detect and handle abnormal situations. If an authentication node can complete the processing of authentication requests and respond to them within a short period of time, it indicates good performance and processing capabilities, and can provide a good user experience. A shorter response time has a positive impact on the node's reputation score, while a longer response time may result in a lower reputation score. The error rate refers to the proportion of errors that occur when an authentication node processes authentication requests, including authentication failure errors, data errors, and system errors. This directly reflects the quality of the authentication node's work. A lower error rate indicates that the node is stable and reliable and can accurately complete authentication tasks, while a higher error rate indicates that there may be problems with the node.
[0040] Preferably, when the decision tree selects nodes based on the key features of the business status evaluation results, the dynamic reputation score of each candidate authentication node is also combined. Specifically, for two authentication nodes that perform similarly in other aspects (such as resource sensitivity, session security level, etc.), the node with a higher dynamic reputation score is more likely to be selected. A higher reputation score indicates that the node has historically had better authentication behavior quality, shorter response time, and lower error rate, and is more likely to perform well in the current authentication task, thereby improving the reliability and efficiency of the entire authentication process; by incorporating the node dynamic reputation score into the selection process of the decision tree, the authentication node is selected more intelligently, thereby optimizing the selection of the authentication path and improving the overall performance and security of the distributed business.
[0041] Furthermore, step S200 also includes step S270, reading the authentication frequency and authentication status of the authentication subject for the distributed business; step S280, establishing a request exception value using the authentication frequency and authentication status; step S290, updating the authentication path through the request exception value.
[0042] Preferably, the authentication frequency and authentication status of the distributed business authentication subject (such as user, device, service, etc.) are read, wherein the authentication frequency refers to the number of times the authentication subject performs authentication within a certain period of time. By analyzing the authentication frequency, the behavior pattern of the authentication subject can be understood. If the authentication frequency is too high or too low, it may indicate the existence of an abnormal situation. For example, under normal circumstances, the user logs in several times a day, but suddenly logs in frequently in a short period of time, which may indicate that the account has been stolen; the authentication status includes authentication success, authentication failure, authentication in progress, and other possible intermediate states, etc., reflecting the result of each authentication operation. For example, if an authentication subject's authentication attempt fails due to an incorrect password, the status of this authentication failure is recorded. By analyzing the historical data of authentication frequency and authentication status, setting an abnormality judgment rule based on the analysis results, and then comparing the current authentication frequency and authentication status with the normal situation, a numerical value representing the degree of abnormality is calculated, that is, the request abnormality value, which reflects the potential risk level of the current authentication request. Then, based on the outlier value, we evaluate whether the currently used authentication path is still safe and effective. If the outlier value is high, it means that the current authentication path may have risks. Finally, based on the assessment of the authentication path risk, we update the authentication path, such as replacing the authentication node, adjusting the authentication order, or adopting an alternative authentication process, so as to reduce the authentication risk and ensure the security and reliability of distributed business authentication.
[0043] Step S300: Parse the authentication request, obtain a unique verification credential, and call the user's authentication data set.
[0044] Preferably, after receiving the authentication request, it is parsed, that is, various key information is extracted from the authentication request message, such as the identification information of the user or service mentioned above, the requested operation or the accessed resource information, etc. For example, for an authentication request in HTTP format, the corresponding field values are extracted from the request header and the message body, such as the user name, password, requested URL, etc.; check whether the format of the request complies with established standards and specifications, for example, verify whether the user name complies with specific character rules, whether the password meets the length and complexity requirements, whether the requested parameters are complete and the type is correct, etc. If the request format is incorrect, the request may be rejected and a corresponding error message is returned; then perform semantic analysis on the information in the request to ensure that its meaning is clear and complies with the business logic, for example, determine whether the requested operation is within the authority of the user or service, whether the accessed resources exist and are accessible, etc.
[0045] Preferably, during the parsing of the authentication request, a unique authentication credential is extracted from the request, which is key information for uniquely identifying the authentication request and the identity of the requester. For example, a unique token can be generated using information such as the user's login name, password, and current timestamp, or a unique identifier pre-assigned to the user or service, such as a UUID (universally unique identifier), can be directly extracted from the request, and the generated or extracted authentication credential is ensured to be unique to avoid confusion and erroneous authentication. Finally, based on the unique authentication credential or user identification information in the request, the user's authentication dataset is located in the data storage in the cloud computing environment. The authentication dataset may be stored in a database or distributed file. For example, the user ID is used as the primary key to query the record corresponding to the user, which contains various authentication-related information of the user, such as a password hash value, user role, and permission list. Relevant information is read from the located authentication dataset, which may include the user's identity verification information, authorization information, and other authentication-related attributes. For example, the user's password hash value is read for comparison and verification with the password entered by the user, and the user's role information is obtained to determine the access rights the user has, etc., thereby obtaining comprehensive user authentication information, thereby accurately judging the user's identity and permissions.
[0046] Step S400: After activating the authentication database using the unique verification credential, the authentication reference credential of the authentication database is sent to a plurality of authentication nodes, wherein the plurality of authentication nodes are constructed based on the authentication path.
[0047] Preferably, the unique verification credential is compared and verified with relevant information stored in the authentication database. When the unique verification credential matches the identifier pre-stored in the database, the authentication database is activated. For example, the unique verification credential may be an encrypted token, and the authentication database stores the corresponding decryption key and verification algorithm. The database is activated only when the key and algorithm are successfully verified. After the verification is successful, access rights to the authentication database are granted for the current authentication operation, that is, relevant authentication data such as the user's detailed identity information, permission level, and historical authentication records can be read or written from the database. After the authentication database is activated, the authentication reference credential of the authentication database is sent to multiple authentication nodes constructed based on the authentication path. These authentication nodes are distributed in different locations in the cloud computing environment and may have different functions. According to the authentication path, appropriate nodes are selected from the numerous nodes in the cloud computing environment and configured accordingly to obtain multiple authentication nodes. Each node needs to have the ability and resources to perform specific authentication tasks. For example, node A may need to store a user's identity information database, and node B needs to have permission management and verification functional modules. The authentication reference credential refers to encrypted data that is destroyed once. By sending the authentication reference credential, each authentication node can obtain unified authentication information and thus perform the corresponding authentication operation.
[0048] Furthermore, step S400 also includes step S410, establishing a mapping one-way communication between the authentication database and the multiple authentication nodes; step S420, configuring authentication requirements according to the authentication functions of the multiple authentication nodes, using the authentication requirements and the unique verification certificate to match the information in the authentication database to generate a information matching result; step S430, constructing the information matching result into an authentication reference certificate, and the authentication reference certificate is a one-time authentication summary data packet that is encrypted; step S440, sending the authentication reference certificate to the corresponding multiple authentication nodes through the mapping one-way communication.
[0049] Preferably, the authentication database stores a large amount of authentication-related information, such as user identity information, permission settings, etc., and establishes a one-way communication mapping between the authentication database and multiple authentication nodes, that is, it is clear which data in the authentication database is related to each authentication node, and this communication is one-way, that is, data can only flow from the authentication database to the authentication node, and the authentication node cannot directly write data to the database, thereby enhancing the security of the database and preventing the authentication node from maliciously modifying the database. Different authentication nodes have different authentication functions. For example, some nodes are responsible for verifying the authenticity of the user's identity, and some nodes are responsible for checking whether the user's permissions meet the requirements. According to the authentication function, each node is configured with corresponding authentication requirements. For example, the node responsible for identity verification may require the user's name and password hash value information in the database, while the permission verification node requires the user's role, permission list, etc.; then, using the unique verification credential (such as the user's login token) and the configured authentication requirements, the data is matched in the authentication database, that is, the relevant user record is located according to the unique verification credential, and then the corresponding data is extracted according to the authentication requirements for comparison, and the matching generates the corresponding data matching result.
[0050] Preferably, the data matching result is constructed as an authentication reference credential, which contains key information in the authentication process, wherein the authentication reference credential is a one-time authentication summary data packet that is encrypted, and the credential is encrypted using a symmetric encryption algorithm or an asymmetric encryption algorithm to ensure that only authorized authentication nodes can decrypt and use the credential to ensure the security of the authentication reference credential and prevent it from being tampered with or stolen during transmission. The authentication reference credential is only used in the current authentication process and becomes invalid after use, effectively preventing the credential from being reused, thereby increasing the security of authentication; finally, the encrypted authentication reference credential is sent to the corresponding authentication node using a one-way communication mechanism that maps the authentication database to multiple authentication nodes, and each authentication node performs authentication operations based on the received authentication reference credential, such as performing authority verification based on the identity authentication result in the credential, thereby achieving secure and efficient transmission of authentication information between the authentication database and the authentication node, and ensuring the smooth progress of the entire authentication process.
[0051] Step S500: Based on the cloud computing environment, the smart contract is called to perform authentication analysis on the authentication data sets of multiple authentication nodes and establish node authentication results.
[0052] Preferably, the elastic computing power of cloud computing is utilized to dynamically adjust computing resources according to the complexity and load of the authentication task to ensure that the authentication process is carried out efficiently, and the smart contract is called according to the cloud computing environment. The smart contract is a self-executing contract protocol based on the blockchain, and specific logical rules are pre-written. During the authentication process, according to the set conditions and processes, the smart contract deployed on the blockchain is called to perform authentication analysis of the authentication data sets of multiple authentication nodes. Specifically, each authentication node obtains the corresponding authentication data set from its own storage or through the network based on information such as the authentication reference certificate, which contains various information related to authentication, such as user registration information, biometric data (such as fingerprints, facial recognition information), identity data, authority information, business rules, etc., and then the smart contract processes the authentication data provided by each authentication node. The set is processed and analyzed, for example, the user's identity information is compared and verified to check whether the password entered by the user matches the stored password hash value; or the user's permission information is analyzed to determine whether the user has the permission to access specific resources or perform specific operations, thereby ensuring the consistency and accuracy of the authentication process and avoiding errors and loopholes caused by human factors; finally, each authentication node generates a corresponding node authentication result based on the analysis results, which is usually a clear judgment, such as "pass" or "fail", or contains more detailed authentication information, such as the user's permission level, authentication confidence, etc. For example, if the node responsible for identity authentication successfully verifies that the user's identity information matches, it generates a "authentication passed" result; if the node responsible for permission checking finds that the user's permission meets the requested operation, it generates a "permission check passed" result.
[0053] Furthermore, step S500 also includes step S510, activating an abnormal rollback mechanism when any authentication node fails to authenticate or the node is unavailable; and step S520, utilizing the abnormal rollback mechanism to roll back and record via a backup path.
[0054] Preferably, when performing an authentication task, the authentication node is unable to successfully complete the authentication operation due to various reasons (such as incorrect verification information input, node's own algorithm error, etc.), that is, the authentication fails. For example, the authentication node responsible for verifying the user's password finds that the password entered by the user does not match the password hash value stored in the database, or the authentication node may not work properly due to hardware failure (such as server downtime, network equipment damage), software failure (such as system crash, program error) or network problem (such as network interruption, excessive delay), that is, the node is unavailable; if any authentication node fails to authenticate or is unavailable, the exception rollback mechanism is immediately triggered to deal with abnormal situations in the authentication process and ensure that it can be restored to a relatively stable and safe state in time; then based on the exception rollback The mechanism performs a rollback operation through a backup path. Specifically, it restores the authentication process to a previous state, bypasses the authentication node with the problem, and then re-authenticates along the backup path, selects other available authentication nodes to complete the corresponding authentication task, or re-obtains the correct verification information and tries authentication again to ensure that the authentication process will not be interrupted when an exception occurs; at the same time, the entire rollback operation process is recorded in detail, including the time when the exception occurred, the cause of the exception (such as the specific error message of the authentication failure, the specific situation of the node unavailability), the specific steps and operations of the rollback (such as which backup path was selected, which authentication nodes were passed through), etc., so as to quickly locate the root cause of the problem and take corresponding measures to fix the problem, thereby improving the reliability and stability of distributed services.
[0055] Step S600: Use a distributed ledger to record authentication process data and node authentication results, and combine the node authentication results to generate an authentication attitude value.
[0056] Preferably, a distributed ledger is a decentralized, tamper-proof ledger technology that allows multiple participants to jointly maintain a consistent ledger on different nodes, thereby ensuring the security, integrity, and traceability of authentication data. Specifically, using a distributed ledger to record various data generated during the authentication process, such as the time and source of the authentication request, the user information involved, and the parameters of the authentication algorithm, can facilitate auditing and troubleshooting. For example, recording the time of the authentication request can help determine the timeliness of the authentication and understand when the user initiated the authentication request. Recording the parameters of the authentication algorithm can be used to verify the correctness and consistency of the authentication process. At the same time, the authentication results generated by each authentication node are recorded, including the verification results of each node on the user's identity, permissions, etc., such as "pass", "fail", or results with detailed permission information, thereby ensuring the authenticity and non-repudiation of the results and preventing the results from being tampered with or forged.
[0057] Preferably, different authentication nodes may authenticate users or services from different perspectives. For example, the identity authentication node focuses on whether the user's identity is real and valid, and the authority authentication node focuses on whether the user has the corresponding operation authority. The authentication results of different nodes are combined. If all nodes pass, the overall authentication passes, or different weights are assigned according to the importance of different nodes. Then, the overall authentication result is comprehensively calculated to finally obtain the authentication attitude quantity, which comprehensively reflects the result of the entire authentication process and is used to represent the degree of authentication, credibility or risk level, etc. For example, through comprehensive analysis of the authentication results of each node, a numerical value of authentication credibility is generated, ranging from 0 to 100. The higher the value, the higher the credibility of the authentication and the more credible the user or service.
[0058] Furthermore, step S600 further includes, if the authentication attitude value indicates that the authentication has failed, configuring an early warning signal according to the authentication attitude value, and performing a pre-alarm output.
[0059] Preferably, if the result represented by the authentication attitude quantity does not meet the pre-set authentication pass standard, it is determined that the authentication has failed. For example, if the user enters an incorrect password multiple times, or the provided identity information does not match the record in the database, the authentication attitude quantity will be displayed as authentication failed; then the reason for the authentication failure is analyzed, which may include checking specific error information, such as incorrect password, expired certificate, insufficient authority, etc., as well as related authentication process data to determine the root cause of the problem, and configuring corresponding early warning signals according to different reasons for authentication failure, including detailed information on authentication failure, such as the identity of the authentication subject, authentication time, reason for authentication failure, and related early warning prompts, etc., and selecting an appropriate method to report the early warning signal, such as SMS notification, displaying a pop-up window or warning information on a visual interface, etc., to ensure that problems encountered during the authentication process are understood in a timely manner so that a quick response can be made to ensure the security and stability of distributed services.
[0060] Step S700: If the authentication attitude value is a result of authentication passing, the access right to the distributed service is granted. The access right generates an authorization key through attribute encryption, which is used to control the access right to the audit chain data.
[0061] Preferably, if the authentication attitude value is a passed authentication result, such as meeting the pre-set pass standard, the authentication is determined to be successful, and the entity requesting authentication (which may be a user or service) is granted access rights to the distributed business, that is, the entity can start using or operating resources and functions related to the business, such as reading, writing, and modifying data. Specifically, the access rights generate authorization keys through attribute encryption, wherein attribute encryption allows data to be encrypted and decrypted based on the attributes of the user or entity, that is, an encryption key can be generated based on the attributes of the authenticated entity (such as the user's role, authority level, department, etc.), and then the information related to the access rights (such as the scope of accessible resources, the type of executable operations, etc.) is encrypted to generate an authorization key as the key credential for accessing distributed business resources. Only entities with the correct authorization key can access the corresponding resources. Authorization keys are used to control access rights to audit chain data. Audit chain data records important information such as the relevant operations and authentication processes of distributed businesses. Only when the entity's authorization key contains the access right attribute to the audit chain data can the entity access the relevant data in the audit chain. For example, if a user's authorization key does not contain the permission attribute to access the audit log, the user will not be able to view data such as the authentication process log and business operation log recorded in the audit chain, thereby ensuring the security and confidentiality of the audit chain data. Only authorized personnel can access and use this sensitive information.
[0062] In the above, refer to Figure 1 The distributed business trusted authentication method for cloud computing environment according to the embodiment of the present invention is described in detail. Figure 2 A distributed business trusted authentication system for cloud computing environments according to an embodiment of the present invention is described.
[0063] The distributed business trusted authentication system for cloud computing environments according to the embodiments of the present invention is used to solve the technical problems existing in the prior art, such as the difficulty in adapting to dynamic business environments, poor interoperability of cross-system authentication, and lack of effective records and traceability of the authentication process, which leads to poor authentication efficiency, accuracy, security, and credibility. This achieves the technical effect of improving the accuracy, efficiency, and security of distributed business trusted authentication. Figure 2 As shown, the distributed business trusted authentication system for cloud computing environment includes: an authentication request receiving module 10, a business status evaluation module 20, an authentication data set acquisition module 30, an authentication reference credential sending module 40, a node authentication result establishment module 50, an authentication attitude quantity generation module 60, and an access permission granting module 70.
[0064] An authentication request receiving module 10 is used to receive an authentication request for a distributed business; a business status evaluation module 20 is used to evaluate the business status of the distributed business and establish an authentication path using the business status evaluation result; an authentication data set acquisition module 30 is used to parse the authentication request, obtain a unique verification credential and call the user's authentication data set; an authentication reference credential sending module 40 is used to send the authentication reference credential of the authentication database to multiple authentication nodes after activating the authentication database using the unique verification credential, and the multiple authentication nodes are constructed based on the authentication path; a node authentication result establishment module 50 is used to call a smart contract based on a cloud computing environment to perform authentication analysis of the authentication data sets of multiple authentication nodes and establish a node authentication result; an authentication attitude quantity generation module 60 is used to use a distributed ledger to record authentication process data and node authentication results, and combine the node authentication results to generate an authentication attitude quantity; an access permission granting module 70 is used to grant access permission to the distributed business if the authentication attitude quantity is an authentication pass result, and the access permission generates an authorization key through attribute encryption to control access permission to audit chain data.
[0065] The specific configuration of the service status evaluation module 20 will be described in detail below. The service status evaluation module 20 further includes: extracting service-related data from the distributed service, packaging the service-related data, and sending it to a service status evaluation channel; performing a multi-feature service status evaluation based on the service status evaluation channel to construct a service status vector; and outputting the service status vector as a service status evaluation result.
[0066] The specific configuration of the service status evaluation module 20 will be described in detail below. The service status evaluation module 20 further includes: activating the resource sensitivity sub-channel to analyze the resource sensitivity characteristics of service-related data and establish a resource sensitivity vector; activating the session security level sub-channel to analyze the security level of service-related data based on the access device type and access location characteristics and establish a session security level vector; activating the task urgency sub-channel to evaluate the urgency of service-related data and establish a task urgency vector; activating the user behavior trust analysis sub-channel to evaluate the user behavior trustworthiness of service-related data and establish a user behavior trustworthiness vector. The resource sensitivity sub-channel, session security level sub-channel, task urgency sub-channel, and user behavior trust analysis sub-channel are all sub-channels of the service status evaluation channel; and constructing a service status vector based on the resource sensitivity vector, session security level vector, task urgency vector, and user behavior trustworthiness vector.
[0067] The specific configuration of the service status evaluation module 20 will be described in detail below. The service status evaluation module 20 further includes: establishing a decision tree for path selection using a historical database; extracting the service status evaluation results as key selection features and inputting them into the decision tree; and selecting authentication nodes based on the decision tree to establish an authentication path.
[0068] The specific configuration of the service status evaluation module 20 will be described in detail below. The service status evaluation module 20 further includes: establishing a dynamic reputation score for each authentication node; dynamically updating the dynamic reputation score based on the authentication node's historical authentication behavior quality, response time, and error rate; and optimizing the selection of authentication nodes based on the dynamic reputation score during the decision tree's authentication node selection process.
[0069] The specific configuration of the authentication reference credential sending module 40 will be described in detail below. The authentication reference credential sending module 40 further includes: establishing a one-way communication mapping between the authentication database and the multiple authentication nodes; configuring authentication requirements based on the authentication functions of the multiple authentication nodes, using the authentication requirements and the unique verification credential to match data in the authentication database to generate a data matching result; constructing the data matching result into an authentication reference credential, which is an encrypted, one-time authentication summary data packet; and sending the authentication reference credential to the corresponding multiple authentication nodes via the one-way communication mapping.
[0070] The following describes in detail the specific configuration of the node authentication result establishment module 50. The node authentication result establishment module 50 further includes: activating an abnormal rollback mechanism when any authentication node fails authentication or the node is unavailable; using the abnormal rollback mechanism to roll back and record the result through the backup path.
[0071] The following will further describe the specific configuration of the service status evaluation module 20. The service status evaluation module 20 further includes: reading the authentication frequency and authentication status of the authentication subject for the distributed service; establishing a request exception value using the authentication frequency and authentication status; and updating the authentication path using the request exception value.
[0072] The following describes in detail the specific configuration of the authentication attitude quantity generating module 60. The authentication attitude quantity generating module 60 further includes: if the authentication attitude quantity indicates that the authentication has failed, configuring an early warning signal according to the authentication attitude quantity and performing an early warning output.
[0073] The distributed business trusted authentication system for cloud computing environments provided by the embodiments of the present invention can execute the distributed business trusted authentication method for cloud computing environments provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0074] Although the present application makes various references to certain modules in the system according to the embodiments of the present application, any number of different modules may be used and run on the user terminal and / or server, and the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of distinguishing each other and are not used to limit the scope of protection of the present invention.
[0075] The above specific embodiments do not constitute a limitation on the scope of protection of this application. Those skilled in the art should understand that various modifications, combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application shall be included within the scope of protection of this application.
Claims
1. A distributed business trusted authentication method for cloud computing environments, characterized in that: The method comprises: Receive authentication requests from distributed services; Performing a service status evaluation on the distributed service, and establishing an authentication path using the service status evaluation result; Parsing the authentication request, obtaining a unique verification credential and calling the user's authentication data set; After activating an authentication database using a unique verification credential, sending an authentication reference credential of the authentication database to a plurality of authentication nodes, the plurality of authentication nodes being constructed based on the authentication path; Based on the cloud computing environment, smart contracts are called to perform authentication analysis on authentication data sets of multiple authentication nodes and establish node authentication results; Using a distributed ledger to record authentication process data and node authentication results, and combining the node authentication results to generate an authentication attitude metric; If the authentication attitude value is a result of authentication passing, the access right to the distributed service is granted, and the access right generates an authorization key through attribute encryption, which is used to control the access right to the audit chain data.
2. The distributed business trusted authentication method for cloud computing environment according to claim 1, characterized in that: The performing service status evaluation on the distributed service includes: After extracting business-related data from the distributed business, the business-related data is packaged and sent to the business status evaluation channel; Performing a business state evaluation under multiple features based on the business state evaluation channel to construct a business state vector; The service state vector is output as a service state evaluation result.
3. The distributed business trusted authentication method for cloud computing environment according to claim 2, characterized in that: The performing of the multi-feature business status evaluation based on the business status evaluation channel to construct a business status vector includes: Activate the resource-sensitive sub-channel to analyze the resource sensitivity characteristics of business-related data and establish a resource sensitivity vector; Activate the session security level subchannel to analyze the security level of the service-related data based on the access device type and access location characteristics, and establish a session security level vector; Activate the task urgency sub-channel to evaluate the urgency of business-related data and establish a task urgency vector; Activate the user behavior trust analysis subchannel to evaluate the user behavior credibility under the business-related data and establish a user behavior credibility vector. The resource-sensitive subchannel, session security level subchannel, task urgency subchannel, and user behavior trust analysis subchannel are all subchannels of the business status evaluation channel. A service state vector is constructed according to the resource sensitivity vector, the session security level vector, the task urgency vector, and the user behavior credibility vector.
4. The distributed business trusted authentication method for cloud computing environment according to claim 1, characterized in that: The establishing of an authentication path using the business status evaluation result includes: Establish a decision tree for path selection through historical database; Extracting the business status evaluation results into selected key features and inputting them into the decision tree; Authentication nodes are selected according to the decision tree to establish an authentication path.
5. The distributed business trusted authentication method for cloud computing environment according to claim 4, characterized in that: The selecting an authentication node according to the decision tree to establish an authentication path includes: Establish a dynamic reputation score for each authentication node; Dynamically update the node's dynamic reputation score based on the authentication node's historical authentication behavior quality, response time, and error rate; During the process of selecting authentication nodes in the decision tree, selection optimization is performed based on the dynamic reputation score of the node.
6. The distributed business trusted authentication method for cloud computing environment according to claim 1, characterized in that: After activating the authentication database using the unique verification credential, distributing the authentication reference credential of the authentication database to multiple authentication nodes includes: Establishing a mapping one-way communication between the authentication database and the plurality of authentication nodes; Configure authentication requirements according to the authentication functions of the multiple authentication nodes, use the authentication requirements and the unique verification credentials to perform data matching in the authentication database, and generate a data matching result; Constructing the data matching result into an authentication reference credential, wherein the authentication reference credential is an encrypted one-time authentication summary data packet; The authentication reference credential is sent to the corresponding multiple authentication nodes through the mapping one-way communication.
7. The distributed business trusted authentication method for cloud computing environment according to claim 1, characterized in that: The cloud computing environment-based smart contract is called to perform authentication analysis of authentication data sets of multiple authentication nodes and establish node authentication results, including: If any authentication node fails to authenticate or the node is unavailable, the abnormal rollback mechanism will be activated; The abnormal rollback mechanism is utilized to roll back and record the operation through the backup path.
8. The distributed business trusted authentication method for cloud computing environment according to claim 1, characterized in that: The establishing of the authentication path using the business status evaluation result further includes: Read the authentication frequency and authentication status of the authentication subject for distributed services; establishing a request anomaly using the authentication frequency and the authentication status; The authentication path is updated with the request exception value.
9. The distributed business trusted authentication method for cloud computing environment according to claim 1, characterized in that: If the authentication attitude value indicates that the authentication has failed, a warning signal is configured according to the authentication attitude value, and a warning alarm is issued.
10. A distributed business trusted authentication system for cloud computing environments, characterized by: The system is used to implement the distributed business trusted authentication method for a cloud computing environment according to any one of claims 1 to 9, and the system includes: An authentication request receiving module, used to receive authentication requests for distributed services; A service status evaluation module, configured to evaluate the service status of the distributed service and establish an authentication path using the service status evaluation result; An authentication data set acquisition module, configured to parse the authentication request, obtain a unique verification credential, and call the user's authentication data set; an authentication reference credential sending module, configured to send the authentication reference credential of the authentication database to a plurality of authentication nodes constructed based on the authentication path after activating the authentication database using the unique verification credential; The node authentication result establishment module is used to call the smart contract based on the cloud computing environment to perform authentication analysis on the authentication data set of multiple authentication nodes and establish the node authentication results; An authentication attitude quantity generation module is used to use a distributed ledger to record authentication process data and node authentication results, and combine the node authentication results to generate an authentication attitude quantity; The access permission granting module is used to grant access permission to the distributed business if the authentication attitude value is an authentication pass result. The access permission generates an authorization key through attribute encryption to control the access permission to the audit chain data.
Citation Information
Patent Citations
Threat level-based multi-factor identity authentication method
CN109450959A
Safety authentication method and system
CN112989333A
Authentication information processing method and device, electronic equipment and storage medium
CN115499189A
User-defined authentication related process method based on arrangement
CN116506187A
Expandable block chain identity authentication method and system for distributed resource aggregation scene
CN119675935A
Cited By
Multi-level dynamic data access control method and device based on credential environment
CN120729631A