RPKI data management method and system

By managing the identity and permissions of RPKI service builders using blockchain technology, the security issues of outsourced data repository publishing points in RPKI data management are resolved, ensuring the security and reliability of the managed service and achieving transparency and efficiency in data management.

CN120896757APending Publication Date: 2025-11-04CHINA INTERNET NETWORK INFORMATION CENTER
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511168235.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-20
Publication Date
2025-11-04

AI Technical Summary

Technical Problem

In RPKI data management, when resource holders outsource the management of database publishing points, there are security issues in the data storage, management, and synchronization processes, including unauthorized deletion, modification, and illegal data injection.

Method used

By establishing an RPKI public infrastructure service management chain using blockchain technology, the identity, permissions, and conflicts of RPKI service builders are managed, hosting service identity identifiers are issued to hosting service providers, and a hosting service chain is established to ensure the security and reliability of data hosting services.

Benefits of technology

It effectively prevents unauthorized malicious operations, ensures that the hosting service provider provides secure and reliable services within the RPKI system, and improves the transparency and reliability of data management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120896757A_ABST
    Figure CN120896757A_ABST
Patent Text Reader

Abstract

The invention discloses an RPKI data management method and system, and the method comprises the steps: firstly building an RPKI public facility service management chain through a block chain technology, carrying out the management of the identity, authority and conflict of an RPKI service building party, issuing a hosting service identity identifier to a first hosting service party when the first hosting service party joins in the RPKI public facility service management chain, and carrying out the management of the hosting service identity identifier to the first hosting service party; a first hosting service party is identified to have hosting database service qualification, then a hosting service chain of the first hosting service party is established through a block chain technology, an address of the hosting service chain is stored in an RPKI public facility service management chain, and the hosting service chain is used for providing data hosting service for a delegation party of the first hosting service party. Therefore, a trust chain from a management chain to a trusteeship service chain is established, malicious operation which is not authorized by an entrusting party can be effectively avoided based on tampering resistance recorded on the block chain, it is ensured that the trusteeship service party provides safe and reliable services in an RPKI system, and therefore the data security of RPKI trusteeship data is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, in particular to an RPKI data management method and system. BACKGROUND

[0002] Resource Public Key Infrastructure (RPKI) is an Internet routing security protocol based on public key encryption technology, aiming to solve the problems of Border Gateway Protocol (BGP) route hijacking and route source forgery. By binding the ownership of IP address and Autonomous System (AS) with a cryptographic certificate, RPKI builds a trusted authorization framework, enabling network operators to verify the legitimacy of route announcements, thereby improving the security of the global Internet routing system.

[0003] There are several modes for RPKI deployment: resource holders run their own Certificate Authority (CA) and manage their own repository publication points; resource holders run their own CA, but outsource the repository publication points to their superior Certificate Issuing Management Agency or other entities; resource holders outsource both their CA and repository publication points to the superior Certificate Issuing Management Agency.

[0004] However, for the scenario of resource holders outsourcing repository publication point management, there are still security issues in the management of RPKI repository data. SUMMARY

[0005] Therefore, the present application provides an RPKI data management method, which uses blockchain technology to secure the RPKI data management process, ensuring the security and reliability of RPKI hosting service management.

[0006] To solve the above problems, the technical solutions provided by the present application are as follows:

[0007] On the one hand, the present application provides an RPKI data management method, which comprises:

[0008] establishing an RPKI public infrastructure service management chain, the RPKI public setting service management chain being established through blockchain technology, the RPKI public infrastructure service management chain being used to manage the identity, authority and conflicts of RPKI service construction participants;

[0009] issuing a hosting service identity for the first hosting service party based on the first hosting service party joining the RPKI public facility service management chain, the hosting service identity being used to indicate that the first hosting service party has the hosting repository service qualification;

[0010] establishing a hosting service chain for the first hosting service party through the blockchain technology, an address of the hosting service chain being stored in the RPKI public facility service management chain, the hosting service chain being used to provide data hosting service for a delegate party of the first hosting service party.

[0011] In a possible implementation, the hosting service type of the first hosting service party includes primary hosting and secondary hosting, the primary hosting indicating that the first hosting service party proxies the delegate party to interact with a superior authority of the delegate party in a certificate issuance process and stores, synchronizes and manages data, and the secondary hosting indicating that the first hosting service party proxies the delegate party to store, synchronize and manage data.

[0012] In a possible implementation, the method further includes:

[0013] performing a data management operation on the delegate party based on an operation identity, the operation identity including the hosting service type, an operation type, an operation abstract, an operation time, an object name, an object hash and identity authentication information of the delegate party.

[0014] In a possible implementation, if the hosting service type is the primary hosting, the method further includes:

[0015] in response to the delegate party initiating a data issuance task on the hosting service chain through a first operation identity, establishing an interaction interface between the hosting service chain and a superior certificate issuance management authority of the delegate party;

[0016] transmitting the data issuance task to the superior certificate issuance management authority through the interaction interface;

[0017] after the data issuance task is completed and returned through the interaction interface, the hosting service chain checks first data returned based on the first operation identity, and stores the first data in a storage system constructed by the first hosting service party for the delegate party after the checking is passed;

[0018] generating an object name and an object hash field of the first operation identity based on the first data, and storing information of the first operation identity on the hosting service chain, wherein when the superior certificate issuance management authority performs data modification, deletion or writing operation, the operation is executed after being confirmed by the delegate party through the hosting service chain.

[0019] In a possible implementation, if the type of the hosting service is the secondary hosting, the method further includes:

[0020] In response to the principal initiating a data publishing task through a second operation identifier, storing the second data signed by the principal to a storage system built by the first hosting service for the principal;

[0021] Generating an object name and an object hash field of the second operation identifier based on the second data, and storing information of the second operation identifier on the hosting service chain.

[0022] In a possible implementation, the principals include a plurality of target principals, and the data signed by the target principals is published to the storage system built by the first hosting service for the principals in a batch data publishing manner. The method further includes:

[0023] After the data publishing of the first principal among the plurality of principals is completed, the hosting service chain generates an update notification file for the principal based on the information of the operation identifier, and the update notification file is stored on the corresponding hosting service chain to trigger a dependent party to perform data synchronization update. The update notification file includes a position link of a specific change entry file, and the specific change entry file is stored in an off-chain storage system.

[0024] In a possible implementation, the method further includes:

[0025] Based on an independent data publishing point address set by the first hosting service for the principal, writing the data publishing point address in a certificate for use by a dependent party to synchronize data.

[0026] In a possible implementation, the method further includes:

[0027] Verifying the service capability of the first hosting service from the aspects of function and performance index based on the RPKI public facility service management chain.

[0028] In a possible implementation, the hosting service chain includes a supervision node, and the method further includes:

[0029] Performing consensus verification on the operation of the first hosting service by the supervision node.

[0030] In another aspect, the application provides an RPKI data management system, which includes a building unit and an issuing unit:

[0031] The establishing unit is configured to establish an RPKI public service management chain, the RPKI public service management chain is established by using a block chain technology, and the RPKI public service management chain is configured to manage the identity, rights and conflicts of a participant of an RPKI public service.

[0032] The issuing unit is configured to issue a hosting service identity to a first hosting service party based on the first hosting service party joining the RPKI public service management chain, and the hosting service identity is configured to indicate that the first hosting service party has a hosting database service qualification.

[0033] The establishing unit is further configured to establish a hosting service chain for the first hosting service party by using the block chain technology, an address of the hosting service chain is stored in the RPKI public service management chain, and the hosting service chain is configured to provide a data hosting service for a delegate of the first hosting service party.

[0034] In a possible implementation, the hosting service types of the first hosting service party include first-level hosting and second-level hosting, the first-level hosting indicates that the first hosting service party proxies the delegate to interact with a superior authority of the delegate in a certificate issuing process and stores, synchronizes and manages data, and the second-level hosting indicates that the first hosting service party stores, synchronizes and manages data for the delegate.

[0035] In a possible implementation, the system further includes a data management unit, and the data management unit is configured to:

[0036] perform a data management operation on the delegate based on an operation identity, and the operation identity includes the hosting service type, an operation type, an operation abstract, an operation time, an object name, an object hash and identity authentication information of the delegate.

[0037] In a possible implementation, the system further includes a transmission unit, a verification unit and a storage unit.

[0038] The establishing unit is further configured to establish an interaction interface between the hosting service chain and a superior certificate issuing management authority of the delegate in response to the delegate initiating a data issuing task on the hosting service chain by using a first operation identity.

[0039] The transmission unit is configured to transmit the data issuing task to the superior certificate issuing management authority through the interaction interface.

[0040] The verification unit is configured to verify first data returned by the hosting service chain based on the first operation identity after the data issuing task is completed and returned through the interaction interface.

[0041] The storage unit is configured to store the first data in a storage system built by the first hosting service for the principal after verification, generate an object name and an object hash field of the first operation identifier based on the first data, and store information of the first operation identifier on the hosting service chain, wherein the upper certificate issuing authority performs data modification, deletion, and writing operation, and executes the operation after confirmation by the principal through the hosting service chain.

[0042] In a possible implementation, the system storage unit is further configured to:

[0043] In response to the principal initiating a data publishing task through a second operation identifier, store the second data signed by the principal to a storage system built by the first hosting service for the principal;

[0044] Generate an object name and an object hash field of the second operation identifier based on the second data, and store information of the second operation identifier on the hosting service chain.

[0045] In a possible implementation, the principals include a plurality of target principals, and the data signed by the target principals is published to the storage system built by the first hosting service for the principals in a batch data publishing manner. The system further includes a generation unit.

[0046] The generation unit is configured to generate an update notification file for the principal based on the information of the operation identifier after data publishing of a first principal in the plurality of principals is completed, and store the update notification file on a corresponding hosting service chain, so as to trigger a dependent party to perform data synchronization update. The update notification file includes a position link of a corresponding specific change item file, and the specific change item file is stored in an off-chain storage system.

[0047] In a possible implementation, the system further includes a writing unit.

[0048] The writing unit is configured to write a data publishing point address set by the first hosting service for the principal in a certificate for use by a dependent party in synchronization of data.

[0049] In a possible implementation, the system further includes a verification unit.

[0050] The verification unit is configured to verify service capability of the first hosting service from aspects of function and performance index based on the RPKI public facility service management chain.

[0051] In a possible implementation, the managed service chain includes a supervision node, and the verification unit is further configured to:

[0052] perform consensus verification on the operation of the first managed service party by the supervision node.

[0053] In another aspect, the present application provides a computer device, which includes a processor and a memory:

[0054] The memory is configured to store a computer program.

[0055] The processor is configured to execute the method according to any one of the above-mentioned computer programs.

[0056] As can be seen from the above technical solution, the technical solution first establishes an RPKI public facility service management chain through blockchain technology, which is used to manage the identity, authority and conflict of an RPKI service constructor, issues a managed service identity for the first managed service party when the first managed service party joins the RPKI public facility service management chain, and identifies that the first managed service party has a managed repository service qualification and can manage the repository publishing points of other resource holders. Then, a managed service chain of the first managed service party is established through blockchain technology, and the address of the managed service chain is stored in the RPKI public facility service management chain. The managed service chain is used to provide data management services for the first managed service party. Thus, a trust chain from the management chain to the managed service chain is established. Based on the non-tamperable nature recorded on the blockchain, malicious operations without the authorization of the first managed service party can be effectively avoided, and the first managed service party can provide safe and reliable services in the RPKI system, thereby ensuring the data security of the RPKI managed data. BRIEF DESCRIPTION OF DRAWINGS

[0057] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed in the embodiment or prior art description will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments described in the present application, and those skilled in the art can obtain other drawings according to these drawings without creative labor.

[0058] Figure 1 A flowchart of an RPKI data management method provided by an embodiment of the present application;

[0059] Figure 2 A schematic diagram of an RPKI data management system provided by an embodiment of the present application. DETAILED DESCRIPTION

[0060] In the following, the technical solutions according to the embodiments of the present application will be described clearly and completely in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all the other embodiments obtained by those of ordinary skill in the art without creative work belong to the scope of protection of the present application.

[0061] In order to facilitate the understanding of the technical solutions of the present application, the core modules of RPKI are introduced as follows:

[0062] (1) Resource Certificate is the cornerstone of RPKI, issued by Regional Internet Registry or subordinate agencies, used to prove the legal possession of IP address segment and AS number. The certificate explicitly notes the public key of resource holder, resource range (such as IPv4 / IPv6 address block) and validity period, forming a hierarchical trust chain. For example, Regional Internet Registry as the root certificate issuing agency can issue sub-certificates to large Internet Service Providers (ISPs), and ISPs further issue end certificates to enterprise customers, forming a "tree-like" authorization system.

[0063] (2) Route Origin Authorization (ROA) is a key declaration file created and signed by resource holder, containing three elements: authorized IP address prefix, AS number allowed to announce the prefix, and maximum length limit of the prefix. For example, a certain enterprise holds IP segment 203.0.113.0 / 24, which can declare through ROA that only its AS is allowed to announce the prefix, and splitting of super-long prefix is not allowed. ROA ensures non-tamperability through digital signature and is published to the RPKI repository for global verification.

[0064] (3) Trust Anchor is the starting point of RPKI trust system, usually maintained by Regional Internet Registry, containing root certificate and public key information. Relying Party (RP) initializes the verification process by pre-configuring Trust Anchor (such as Trust Anchor Locator, TAL), and verifies the legality of subordinate certificates and ROA step by step. For example, the Trust Anchor of Asia-Pacific Network Information Centre (APNIC) can be loaded by global RPKI verifier as the trust source of resource authorization in Asia-Pacific region.

[0065] (4) RPKI repository is a distributed storage system, used to store all the published certificates, ROAs and Certificate Revocation List (CRL). The relying party obtains the latest data by periodic synchronization (such as rsync or RRDP protocol). The integrity and consistency of the repository directly affect the reliability of the verification result.

[0066] (5) The relying party is the verification executor of RPKI, responsible for pulling data from the repository, and verifying the certificate chain and ROA signature through cryptography. After verification, the RP generates Route Origin Validation (ROV) results, usually identifying the legality of route announcement as "Valid", "Invalid" or "NotFound". For example, open source tools such as Routinator can be used as RP implementation, and the results can be output to the router (such as through the RPKI-to-Router protocol) to guide real-time filtering of routing policies.

[0067] As described in the background, there are several modes for RPKI deployment: resource holders run their own CA and manage their own repository publishing points; resource holders run their own CA, but outsource the repository publishing point to their superior certificate issuing authority or other entities; resource holders outsource both their CA and repository publishing point to the superior certificate issuing authority.

[0068] In actual deployment, regional Internet registration agencies provide solutions for hosting RPKI to reduce the threshold for RPKI to enter the technology, so that each organization entity does not need to manage the specific process of certificate issuance. Resource holders can also delegate certificate issuance responsibilities to third parties, such as hosting companies or cloud providers, etc.

[0069] Currently, for the scenario of resource holder outsourcing repository publishing point management, there are still security issues in the storage, management and synchronization process of the entrusted party's hosted data. For example, RFC 8211 points out the improper behavior of RPKI repository management, mainly including deleting specific objects from the repository publishing point without the consent of the code number resource holder; deleting or publishing objects without the wishes of the resource holder; not updating the version at the publishing point when there is a new version of data; illegal data injection, modification of the publishing point, etc.

[0070] In order to solve the security problem of data management in the above-mentioned RPKI repository, the application provides an RPKI data management method, which establishes an RPKI public facility service management chain through blockchain technology, is used for managing the identity, right and conflict of an RPKI service constructor, issues a hosting service identity for a first hosting service party when the first hosting service party joins the RPKI public facility service management chain, identifies that the first hosting service party has a hosting repository service qualification and can manage the repository publishing points of other resource holders, and then establishes a hosting service chain of the first hosting service party through blockchain technology, wherein the address of the hosting service chain is stored in the RPKI public facility service management chain, and the hosting service chain is used for providing data hosting service for the delegate of the first hosting service party, so as to establish a trust chain from the management chain to the hosting service chain. Based on the non-tamperable record on the blockchain, malicious operations without authorization of the delegate can be effectively avoided, and the hosting service party can provide safe and reliable service in the RPKI system, so as to ensure the data security of the RPKI hosting data.

[0071] The scheme provided by the embodiment of the application relates to the technical field of network security, and is specifically explained through the following embodiments.

[0072] Referring to Figure 1 As shown in the figure, a flowchart of an RPKI data management method provided by the embodiment of the application includes the following steps:

[0073] S101: Establish an RPKI public facility service management chain.

[0074] The RPKI public facility service management chain is established by IANA and regional Internet registration management agencies through blockchain technology, and is used for managing the identity, right and conflict of an RPKI service constructor.

[0075] The identity and right information of each RPKI service participant (such as ISP, network operator, etc.) is recorded on the chain. Based on the information on the chain, the RPKI public facility management party can manage the qualification and identity of the hosting service party, ensure that its operation meets the relevant security and compliance standards, and can also allocate and verify the rights of each participant, for example, based on the right information of each participant recorded on the chain, determine the operation range of the participant in the RPKI service, and when two participants conflict in route announcement of the same IP address or AS number, the conflicts can be quickly found and recorded. The blockchain technology can ensure that the resource allocation record and the certificate are not tampered with.

[0076] S102: Based on the first hosting service party joining the RPKI public facility service management chain, issue a hosting service identity for the first hosting service party.

[0077] The hosting service identity is used to indicate that the first hosting service provider has the qualification of hosting the repository service.

[0078] After the resource holder entrusts the first hosting service provider to provide data hosting service such as certificate issuance or repository publication point management, the first hosting service provider applies to join the RPKI public service management chain.

[0079] According to the application materials submitted by the first hosting service provider, such as business license, legal representative identification, relevant qualification certificates, and the like, the relying party verifies the identity of the first hosting service provider through the RPKI public service management chain, and issues an authenticated hosting service identity to the first hosting service provider after the identity verification is passed, and the first hosting service provider has the identity to represent the first hosting service provider to obtain the qualification of hosting the repository service, and can act on behalf of the entrusting party to issue certificates or manage repository publication points.

[0080] Each hosting service provider has a hosting service chain, that is, the hosting service chain can be dynamically extended according to new entrustment requirements.

[0081] The first hosting service provider can provide data hosting service for multiple resource holders, in order to ensure that the resources of the first hosting service provider can bear the data hosting service of multiple entrusting parties, in a possible implementation manner, the method further includes:

[0082] The service capability of the first hosting service provider is verified based on the RPKI public service management chain from the function and performance indicators.

[0083] The relying party can verify the service function of the first hosting service provider from the function and performance indicators through technical evaluation and performance test based on the RPKI public service management chain, and thus the number and scale of the entrusting parties of the first hosting service provider can be limited based on the verification result.

[0084] Therefore, based on the resource situation of the first hosting service provider, it is ensured that the entrustment task can normally run, and the system security and reliability are improved.

[0085] In a possible implementation manner, the hosting service chain includes a supervision node, and the method further includes:

[0086] The operation of the first hosting service provider is consensus verified through the supervision node.

[0087] The supervision node refers to a node authorized to supervise and verify in the system. These nodes are responsible for verifying the operation of the first hosting service provider to ensure the legality and correctness of the operation.

[0088] Consensus verification is a mechanism to ensure the transparency and verifiability of the operation, which can ensure that all participants reach an agreement on the operation result, effectively preventing tampering and disputes of the operation.

[0089] If all the regulatory nodes are verified, a consensus is reached, the operation is considered valid, and can be accepted by all participants, thereby avoiding controversial operations such as unauthorized operations and data tampering, and enhancing the credibility and transparency of the system.

[0090] S103: Establish a hosting service chain for the first hosting service party through blockchain technology.

[0091] The address of the hosting service chain is stored in the RPKI public facility service management chain. The hosting service chain is used to provide data hosting services for the first hosting service party.

[0092] In this way, a trust chain from the management chain to the hosting service chain is established, and based on the non-tamperable nature recorded on the blockchain, malicious operations without the authorization of the delegate party can be effectively avoided, ensuring that the hosting service party provides safe and reliable services in the RPKI system, thereby ensuring the data security of the RPKI repository.

[0093] Based on the type of resource holder, the type of hosting service of the first hosting service party can be divided. In one possible implementation, the type of hosting service of the first hosting service party includes primary hosting and secondary hosting. The primary hosting indicates that the first hosting service party interacts with and verifies the superior agency of the delegate party in the certificate issuance process, and the data storage, synchronization and management. The secondary hosting indicates that the first hosting service party stores, synchronizes and manages the data of the delegate party.

[0094] The superior agency can be a superior certificate issuance management agency of the delegate party, or other organization entities, which are not limited in the present application.

[0095] In this way, dividing the type of hosting service helps to clarify the responsibilities and functions of the hosting service party, thereby improving the management efficiency and security.

[0096] The delegate party that needs to be managed by the repository publishing point selects the hosting service party and the type of hosting service, and joins or establishes a new hosting service chain. The hosting service party will verify the identity of the delegate party.

[0097] The first hosting service party sets an independent data publishing point address for each delegate party, i.e. a repository publishing point address. The Subject Information Access (SIA) extension field of the delegate party certificate is set to the above-mentioned data publishing point address, and the hosting service party also sets a data storage space for the delegate party.

[0098] In one possible implementation, based on the independent data publishing point address set by the first hosting service party for the delegate party, the data publishing point address is written in the certificate for the relying party to synchronize data.

[0099] The data publishing point address of the principal party for which the hosting service party is responsible is written into the certificate to ensure that the relying party manages data synchronization. Thus, the reliability in data synchronization and verification processes can be further ensured.

[0100] In a possible implementation, the method further includes:

[0101] performing a data management operation on the principal party based on the operation identifier.

[0102] The operation identifier includes a hosting service type, an operation type, an operation digest, an operation time, an object name, an object hash, and identity authentication information of the principal party.

[0103] The hosting service chain formulates an operation code management mechanism according to the RPKI public facility service management chain, takes the hosting service type, the operation digest, the operation time, and the identity of the principal party as input data, and generates a unique identifier of the operation, namely the operation identifier, after normalization and serialization processing and through combination and encoding hash. The principal party can perform task issuing and data review through the operation identifier.

[0104] The principal party can perform classified operations according to different hosting service types. In the whole process of RPKI data life cycle management, the principal party issues tasks on the hosting service chain through the operation identifier.

[0105] As an example, the operation identifier includes the following structure:

[0106] (1) Hosting service type, including primary hosting and secondary hosting.

[0107] (2) Operation type, which is two-level classification coding; the first-level classification is the operation type, for example, data issuance, change, deletion, or data publishing. The second-level classification is the data type, for example, the category of a signature object. According to the difference between the hosting service type and the first-level classification, the specific operation behavior will be different. When the first-level classification is data publishing, the second-level classification can be not assigned (set to 0), indicating that multiple data objects are published at a time.

[0108] (3) Operation digest, a digest of a signature record, for example, an ROA digest including an IP address prefix, an AS number, and the maximum length of the prefix.

[0109] (4) Object name: the file name of the operation object.

[0110] (5) Object hash: the hash of the content of the operation object file.

[0111] (6) Operation time: the time of performing the operation.

[0112] (7) State: identifies the state information of the operation object.

[0113] (8) Identity authentication information of the principal.

[0114] The principal can perform classification operations according to different types of hosting services.

[0115] In a possible implementation, if the hosting service type is first-level hosting, the method further includes:

[0116] A1: in response to the principal initiating a data issuance task on the hosting service chain through a first operation identifier, establishing an interactive interface between the hosting service chain and a superior certificate issuance management agency of the principal;

[0117] A2: transmitting the data issuance task to the superior certificate issuance management agency through the interactive interface;

[0118] A3: after the data issuance task is completed and returned through the interactive interface, the hosting service chain verifies the first data returned based on the first operation identifier, and stores the first data in a storage system constructed by the first hosting service for the principal after the verification is passed;

[0119] A4: generating an object name and an object hash field of the first operation identifier based on the first data, and storing the information of the first operation identifier on the hosting service chain, wherein the superior certificate issuance management agency performs data modification, deletion, and writing operations through the hosting service chain after confirmation by the principal.

[0120] When the principal initiates a data issuance task, such as a signature record issuance of an ROA record, on the hosting service chain through a first operation identifier, the principal assigns values to the fields of the operation identifier, such as the hosting service type, the operation type, the operation abstract, and the operation time, according to the task content to be issued, and establishes an interactive interface between the hosting service chain and the superior certificate issuance management agency of the principal. The data issuance task issued by the principal is transmitted to the superior certificate issuance management agency through the interactive interface, the certificate issuance management agency performs the corresponding task according to the information of the first operation identifier provided by the principal, and then returns the first data returned after the issuance is completed to the hosting service chain through the above-mentioned interactive interface. The hosting service chain verifies the first data based on the first operation identifier, verifies whether the data issuance task is successfully executed, stores the first data in the storage system constructed by the first hosting service for the principal after the verification is passed, and generates the contents of the object name and the object hash field in the first operation identifier.

[0121] In a possible implementation, if the hosting service type is second-level hosting, the method further includes:

[0122] B1: in response to the principal initiating a data publishing task through the second operation identifier, storing the second data signed by the principal to the storage system built by the first hosting service for the principal;

[0123] B2: generating the object name and object hash field of the second operation identifier based on the second data, and storing the information of the second operation identifier on the hosting service chain.

[0124] After the principal itself completes the certificate and signature object issuance, it needs to publish the signed second data to the first hosting service. The principal initiates a data publishing task through the second operation identifier, and the first hosting service stores the second data to the storage system sent by the principal. For example, optional batch data publishing and single data publishing, when batch data publishing, the operation type field of the operation identifier should be set to data publishing, and the second classification should be set to 0. The object name and object hash of the operation identifier should be set to the file name and file hash of the data list list this time. When publishing, write the operation identifier content to the hosting service chain, and write the published data to the corresponding storage system.

[0125] Thus, relying on the hosting service chain, an efficient, secure and transparent data issuance and data management process is realized, which effectively improves the efficiency and reliability of RPKI resource allocation and data management.

[0126] In a possible implementation, the principal includes a plurality of, wherein the data signed by the target principal is published to the storage system built by the first hosting service for the principal through batch data publishing, and the method further comprises:

[0127] After the first principal in the plurality of principals completes data publishing, the hosting service chain generates an update notification file for the principal based on the information of the operation identifier.

[0128] The update notification file is stored on the corresponding hosting service chain, which is used to trigger the dependent party to perform data synchronization update. Among them, the update notification file includes the location link of the corresponding specific change entry file, and the specific change entry file is stored in an off-chain storage system.

[0129] Since the data issuer may perform a series of operations before publishing new resource lists, at a certain time period, the signed objects published by the first hosting service may not be included in the current latest resource list.

[0130] The hosting service chain should distinguish and manage the signed objects included in the resource list and not included in the resource list when processing this phenomenon, and judge whether to inform the dependent party of the objects not included in the resource list according to the local policy.

[0131] In order to ensure that the relying party can effectively synchronize data with the first hosting service party's database, for the data publishing point of a specific entrusting party, when the data issuing is completed, the hosting service chain should generate a new update notification file, a snapshot file and an incremental file, wherein the update notification file is stored in the hosting service chain, the location link of the snapshot file and the incremental file is included, the snapshot file and the incremental file are stored in the storage system.

[0132] When the relying party synchronizes data with the data publishing point of the first hosting service party, the data publishing point address of each entrusting party can be obtained from the RPKI public facility service management chain, and the first hosting service party's data publishing point address can be obtained by accessing the AuthorityInformation Access (AIA) extension field along the authorized information in the certificate chain.

[0133] After the relying party obtains the data publishing point address of the first hosting service party, the update notification file is obtained from the hosting service chain, and on this basis, the data to be synchronized after version change is obtained from the storage system built by the first hosting service party for the entrusting party through the incremental file information, so as to synchronize and update the data.

[0134] Thus, the problems existing in the storage, management and synchronization process of RPKI hosting scene data are solved, the behavior in the process of hosting data management is ensured to meet the expectation, the illegal operation without the authorization of the entrusting party is avoided, the management and control right of the hosting party on the data is increased, and the transparency and maintainability of RPKI as a basic public service are effectively improved.

[0135] On the basis of the above embodiment, the embodiment of the application provides an RPKI data management system, as shown in Figure 2 Fig. 1 is a schematic diagram of an RPKI data management system provided by an embodiment of the application, and the system 200 includes an establishing unit 201 and an issuing unit 202:

[0136] The establishing unit 201 is configured to establish an RPKI public facility service management chain, wherein the RPKI public facility service management chain is established by using a block chain technology, and the RPKI public facility service management chain is configured to manage the identity, right and conflict of an RPKI public facility service construction participant;

[0137] The issuing unit 202 is configured to issue a hosting service identity for the first hosting service party based on the first hosting service party joining the RPKI public facility service management chain, wherein the hosting service identity is configured to indicate that the first hosting service party has a hosting database service qualification;

[0138] The establishing unit 201 is further configured to establish a hosting service chain for the first hosting service party by using the blockchain technology, and an address of the hosting service chain is stored in the RPKI public facility service management chain, and the hosting service chain is configured to provide data hosting service for a delegate party of the first hosting service party.

[0139] In a possible implementation, the hosting service type of the first hosting service party includes first-level hosting and second-level hosting, the first-level hosting indicates that the first hosting service party proxies the delegate party to interact with a superior authority of the delegate party in a certificate issuing process and verifies the superior authority, and the first-level hosting indicates that the first hosting service party proxies the delegate party to store, synchronize and manage data, and the second-level hosting indicates that the first hosting service party proxies the delegate party to store, synchronize and manage data.

[0140] In a possible implementation, the system further includes a data management unit, and the data management unit is configured to:

[0141] perform a data management operation on the delegate party based on an operation identifier, and the operation identifier includes the hosting service type, an operation type, an operation abstract, an operation time, an object name, an object hash and identity authentication information of the delegate party.

[0142] In a possible implementation, the system further includes a transmitting unit, a verifying unit and a storage unit.

[0143] The establishing unit is further configured to, in response to the delegate party initiating a data issuing task on the hosting service chain by using a first operation identifier, establish an interaction interface between the hosting service chain and a superior certificate issuing management authority of the delegate party.

[0144] The transmitting unit is configured to transmit the data issuing task to the superior certificate issuing management authority through the interaction interface.

[0145] The verifying unit is configured to, after the data issuing task is completed and returned through the interaction interface, verify first data returned by the hosting service chain based on the first operation identifier.

[0146] The storage unit is configured to, after the verification is passed, store the first data in a storage system constructed by the first hosting service party for the delegate party, and generate an object name and an object hash field of the first operation identifier based on the first data, and store information of the first operation identifier on the hosting service chain, wherein when the superior certificate issuing management authority performs data modification, deletion or writing operation, the data modification, deletion or writing operation is executed after being confirmed by the delegate party through the hosting service chain.

[0147] In a possible implementation, the system storage unit is further configured to:

[0148] in response to the principal initiating a data publishing task through a second operation identifier, storing the second data signed by the principal to a storage system built by the first hosting service for the principal;

[0149] generating an object name and an object hash field of the second operation identifier based on the second data, and storing information of the second operation identifier on the hosting service chain.

[0150] In a possible implementation, the principals include a plurality of target principals, and the data signed by the target principals is published to the storage system built by the first hosting service for the principals in a batch data publishing manner. The system further includes a generation unit:

[0151] The generation unit is configured to generate an update notification file for the principals based on the information of the operation identifier after data publishing of a first principal in the plurality of principals is completed, and store the update notification file on a corresponding hosting service chain, so as to trigger a dependent party to perform data synchronization update. The update notification file includes a position link of a specific change entry file, and the specific change entry file is stored in an off-chain storage system.

[0152] In a possible implementation, the system further includes a writing unit:

[0153] The writing unit is configured to write a data publishing point address set by the first hosting service for the principal in a certificate for a dependent party to use for data synchronization.

[0154] In a possible implementation, the system further includes a verification unit:

[0155] The verification unit is configured to verify service capability of the first hosting service from aspects of function and performance index based on the RPKI public facility service management chain.

[0156] In a possible implementation, the hosting service chain includes a supervision node, and the verification unit is further configured to:

[0157] perform consensus verification on the operation of the first hosting service through the supervision node.

[0158] On the basis of the above-mentioned embodiments, the embodiments of the present application provide a computer device, which includes a processor and a memory:

[0159] The memory is configured to store a computer program.

[0160] The processor is configured to execute the above-mentioned RPKI data management method according to the computer program.

[0161] It should be noted that the various embodiments described in the specification are presented by way of example only and that the application is not limited to the embodiments described. It will be apparent to a skilled person that modifications can be made without departing from the spirit or scope of the application. The various embodiments described in the specification are presented by way of example only and that the application is not limited to the embodiments described. It will be apparent to a skilled person that modifications can be made without departing from the spirit or scope of the application.

[0162] The above description of disclosed embodiments provides enabling concepts for a person skilled in the art to implement or use the application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the application. Therefore, the application will not be limited to the embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. An RPKI data management method, characterized in that, The method includes: An RPKI public facility service management chain is established. The RPKI public facility service management chain is established through blockchain technology and is used to manage the identity, permissions and conflicts of the participants in the construction of RPKI services. Based on the first hosting service provider joining the RPKI public facility service management chain, a hosting service identity identifier is issued to the first hosting service provider. The hosting service identity identifier is used to indicate that the first hosting service provider has the qualification to host database services. A hosting service chain is established for the first hosting service provider using the blockchain technology. The address of the hosting service chain is stored in the RPKI public facility service management chain. The hosting service chain is used to provide data hosting services for the client of the first hosting service provider.

2. The method according to claim 1, characterized in that, The hosting service types of the first hosting service provider include Level 1 hosting and Level 2 hosting. Level 1 hosting refers to the interaction and verification between the first hosting service provider and the client's superior institution during the certificate issuance process, as well as the storage, synchronization and management of data. Level 2 hosting refers to the storage, synchronization and management of data by the first hosting service provider on behalf of the client.

3. The method according to claim 1, characterized in that, The method further includes: Data management operations are performed on the client based on the operation identifier, which includes the hosting service type, operation type, operation summary, operation time, object name, object hash, and the client's identity authentication information.

4. The method according to claim 2, characterized in that, If the hosting service type is Level 1 hosting, the method further includes: In response to the client initiating a data issuance task on the managed service chain through a first operation identifier, an interaction interface is established between the managed service chain and the client's superior certificate issuance management authority. The data issuance task is transmitted to the superior certificate issuance management authority through the interaction interface; After the data issuance task is completed and returned through the interaction interface, the hosting service chain verifies the returned first data based on the first operation identifier, and stores the first data in the storage system built by the first hosting service provider for the client after the verification is passed; Based on the first data, the object name and object hash field of the first operation identifier are generated, and the information of the first operation identifier is stored on the managed service chain. When the superior certificate issuing and management authority performs data modification, deletion, or writing operations, it executes the operation after confirmation by the entrusting party through the managed service chain.

5. The method according to claim 2, characterized in that, If the hosting service type is the secondary hosting, the method further includes: In response to the client initiating a data publishing task through the second operation identifier, the second data signed by the client is stored in the storage system built by the first hosting service provider for the client; Based on the second data, generate the object name and object hash field of the second operation identifier, and store the information of the second operation identifier on the managed service chain.

6. The method according to claim 3, characterized in that, The delegating parties include multiple entities, and the data signed by the target delegating party is published to the storage system built by the first hosting service provider for the delegating party through a batch data publishing method. The method further includes: After the data of the first client among the multiple clients is published, the hosting service chain generates an update notification file for the client based on the information of the operation identifier. The update notification file is stored on the corresponding hosting service chain and is used to trigger the dependent party to perform data synchronization update. The update notification file includes the location link of the corresponding specific change entry file, which is stored in the off-chain storage system.

7. The method according to claim 1, characterized in that, The method further includes: Based on the independent data publishing point address set by the first hosting service provider for the client, the data publishing point address is written into the certificate for the dependent party to use for data synchronization.

8. The method according to claim 1, characterized in that, The method further includes: The service capabilities of the first hosting service provider are verified based on the RPKI public facility service management chain, using functional and performance indicators.

9. The method according to claim 1, characterized in that, The escrow service chain includes a regulatory node, and the method further includes: The supervisory node performs consensus verification on the operations of the first hosting service provider.

10. An RPKI data management system, characterized in that, The system includes an establishment unit and an issuance unit: The establishment unit is used to establish the RPKI public facility service management chain. The RPKI public facility service management chain is established through blockchain technology. The RPKI public facility service management chain is used to manage the identity, permissions and conflicts of the participants in the construction of RPKI public facility services. The issuing unit is used to issue a hosting service identity identifier to the first hosting service provider based on the first hosting service provider joining the RPKI public facility service management chain. The hosting service identity identifier is used to indicate that the first hosting service provider has the qualification to host database services. The establishment unit is further configured to establish a hosting service chain for the first hosting service provider using the blockchain technology. The address of the hosting service chain is stored in the RPKI public facility service management chain. The hosting service chain is used to provide data hosting services for the client of the first hosting service provider.

11. A computer device, characterized in that, The computer device includes a processor and memory: The memory is used to store computer programs; The processor is configured to perform the method according to any one of claims 1-9 according to the computer program.