Security authentication method and device, computer equipment, storage medium and program product
By having the first host apply for hardware features from the second host that has already joined the blockchain and join before the hyperconverged node is expanded, the problem of insufficient data security during the expansion of the hyperconverged node is solved, and the security authentication and data protection of the target blockchain are realized.
Patent Information
- Application Number
- CN202511326398.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-16
- Publication Date
- 2025-11-18
AI Technical Summary
When expanding hyperconverged nodes, the lack of security authentication for physical hosts leads to insufficient data security and poses a risk of data leakage.
The first host requests hardware features from the second host that has already joined the target blockchain, and sends a request to join the target blockchain based on these features. After receiving the consent to join the blockchain, the host joins the blockchain, ensuring the reliability of the host and the security of the data.
During node expansion, hardware feature authentication ensures the reliability of the host, improves the data security of the target blockchain, and prevents data leakage.
Smart Images

Figure CN120979800A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of blockchain technology, specifically to secure authentication methods, devices, computer equipment, storage media, and program products. Background Technology
[0002] Blockchain is a decentralized distributed ledger technology that uses core components such as cryptography, consensus mechanisms, and smart contracts to achieve data immutability, transparency, traceability, and peer-to-peer value transfer. Hyper-Converged Infrastructure (HCI) is a software-defined architecture that integrates computing, storage, networking, and virtualization resources into standardized hardware nodes.
[0003] In related technologies, combining blockchain and hyperconvergence involves deploying blockchain nodes and data nodes simultaneously on physical hosts as hyperconverged nodes. This enables the use of hyperconverged computing, storage, network, and virtualization resources to provide services to the decentralized blockchain nodes, improving resource allocation efficiency, business efficiency, and security. However, when scaling up hyperconverged nodes, simply deploying blockchain distributed software allows for joining without secure authentication of the physical host, compromising data security and potentially leading to data leaks. Summary of the Invention
[0004] In view of this, the purpose of the present invention is to provide a security authentication method, apparatus, computer equipment, storage medium and program product to solve the problem of insufficient security when expanding node capacity.
[0005] In a first aspect, the present invention provides a security authentication method, executed by a first host, the method comprising:
[0006] The system requests a first hardware feature from a second host; the second host contains nodes of the target blockchain; the first hardware feature is the hardware feature provided by the second host when it joins the target blockchain.
[0007] Based on the first hardware feature, a request to join is sent to the target blockchain;
[0008] Upon receiving a consent instruction to join the target blockchain, join the target blockchain.
[0009] In one optional implementation, joining the target blockchain upon receiving a consent instruction from the target blockchain includes:
[0010] Obtain the second hardware characteristics of the first host;
[0011] Upon receiving the consent to join instruction from the target blockchain, an on-chain identifier is generated based on the second hardware feature;
[0012] Join the target blockchain according to the on-chain identifier.
[0013] In an optional implementation, the method further includes:
[0014] Based on the first hardware feature and the second hardware feature of the first host, the request to join instruction is generated and sent to the target blockchain.
[0015] In one optional implementation, the consent to join instruction is generated when there is a hardware feature matching the first hardware feature among the various hardware features stored in the target blockchain, but no hardware feature matching the second hardware feature.
[0016] After the first host joins the target blockchain, the method further includes:
[0017] A backup instruction is sent to the target blockchain; the backup instruction includes the identifier of a third host; the third host contains nodes of the target blockchain.
[0018] Upon receiving a backup instruction from the target blockchain, the data to be backed up corresponding to the third host is backed up to the first host.
[0019] In an optional implementation, the method further includes:
[0020] Upon receiving a consent instruction to join the target blockchain, join the data cluster corresponding to the target blockchain.
[0021] In an optional implementation, the method further includes:
[0022] If a fourth host failure is detected, a replacement instruction is sent to the target blockchain;
[0023] When a consent replacement instruction corresponding to the target blockchain is received, the backup data of the fourth host is obtained from the fifth host;
[0024] The step of joining the target blockchain according to the on-chain identifier includes:
[0025] If the backup data is detected to be complete, it is added to the target blockchain according to the on-chain identifier.
[0026] In an optional implementation, the method further includes:
[0027] If the backup data is detected to be incomplete, the backup data of the fourth host is obtained from the data cluster corresponding to the target blockchain;
[0028] Join the target blockchain according to the on-chain identifier.
[0029] In one optional implementation, the step of obtaining the backup data of the fourth host from the fifth host when receiving the consent to replace instruction corresponding to the target blockchain includes:
[0030] When a consent to change instruction is received corresponding to the target blockchain, a fifth host is determined in the target blockchain based on the data packet identifier corresponding to the data of the fourth host; the fifth host stores backup data of the fourth host; the data packet identifier corresponding to the backup data is the same as the data packet identifier corresponding to the data of the fourth host.
[0031] The backup data of the fourth host is obtained from the fifth host.
[0032] In an optional implementation, the method further includes:
[0033] Parse the data group identifiers and total number of files in the backup data;
[0034] If the data group identifier of the backup data is consistent with the data group identifier corresponding to the fourth host stored in the target blockchain, and the total number of files in the backup data is consistent with the total number of files corresponding to the fourth host stored in the target blockchain, then the backup data is determined to be complete.
[0035] Secondly, the present invention provides a security authentication device, disposed in a first host, the device comprising:
[0036] The feature application module is used to apply for a first hardware feature from the second host; the second host has nodes of the target blockchain configured; the first hardware feature is the hardware feature provided when the second host joins the target blockchain;
[0037] The application module is used to send an application to join the target blockchain based on the first hardware feature.
[0038] The joining module is used to join the target blockchain when it receives a consent joining instruction from the target blockchain.
[0039] Thirdly, the present invention provides a computer device, comprising: a memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the computer instructions to perform the security authentication method described in the first aspect or any corresponding embodiment thereof.
[0040] Fourthly, the present invention provides a computer-readable storage medium storing computer instructions for causing a computer to execute the security authentication method described in the first aspect or any corresponding embodiment thereof.
[0041] Fifthly, the present invention provides a computer program product, including computer instructions, which are used to cause a computer to execute the security authentication method described in the first aspect or any corresponding embodiment thereof.
[0042] The technical solution provided by this invention may include the following beneficial effects:
[0043] The security authentication method provided by this invention is executed by a first host. During security authentication, the first host requests a first hardware feature from a second host. The second host has nodes configured in the target blockchain, and the first hardware feature is the hardware feature provided when the second host joins the target blockchain. Next, based on the first hardware feature, a join request instruction is sent to the target blockchain. Upon receiving a join acceptance instruction from the target blockchain, the first host joins the target blockchain. This scheme ensures that the first host is recommended by hosts already in the target blockchain before joining, guaranteeing the reliability of the first host and thus ensuring the security of the target blockchain during node expansion and the data security of the target blockchain. Attached Figure Description
[0044] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0045] Figure 1 This diagram illustrates the logical combination of blockchain and hyperconvergence in related technologies.
[0046] Figure 2 A schematic diagram of the combined structure of blockchain and hyperconverged infrastructure in related technologies is shown;
[0047] Figure 3 This is a flowchart illustrating a security authentication method according to an embodiment of the present invention;
[0048] Figure 4 This is a flowchart illustrating another security authentication method according to an embodiment of the present invention;
[0049] Figure 5This is a schematic diagram of the system structure corresponding to the security authentication method according to an embodiment of the present invention;
[0050] Figure 6 This is a structural block diagram of a security authentication device according to an embodiment of the present invention;
[0051] Figure 7 This is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. Detailed Implementation
[0052] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0053] Blockchain is a data structure that combines valid data blocks in a chronological order, forming a chain. It is also a decentralized shared ledger technology that uses cryptography, consensus mechanisms, and smart contracts as core components to achieve data immutability, transparency, traceability, and peer-to-peer value transfer. In a broader sense, blockchain technology is a novel decentralized infrastructure and distributed computing paradigm that utilizes encrypted chain-like block structures to verify and store data, distributed node consensus algorithms to generate and update data, and automated script code (smart contracts) to program and manipulate data.
[0054] Hyper-Converged Infrastructure (HCI) is a technology architecture based on standard general-purpose hardware platforms. It integrates computing, storage, networking, and virtualization resources into standardized hardware nodes through software definition. HCI architecture combines the fundamental elements of a data center, such as computing, storage, networking, and management tools, using general-purpose server hardware to replace dedicated hardware in traditional architectures, thus solving problems such as management complexity and scalability. The core technologies of HCI architecture include compute virtualization, distributed storage, and network virtualization.
[0055] Blockchain is widely used in fields such as healthcare and finance, and hyperconverged infrastructure (HCI) products are used to support blockchain digital infrastructure. Among related technologies, combining blockchain and HCI involves deploying blockchain nodes in HCI devices. This enables the distributed nodes of the blockchain to receive services through the computing, storage, networking, and virtualization resources of HCI, improving resource allocation efficiency, business efficiency, and security. Figure 1The diagram illustrates the logical integration of blockchain and hyper-converged infrastructure in related technologies, comprising multiple blockchain nodes and multiple data nodes. These blockchain nodes acquire and transmit data based on identifiers. The data nodes can be uploaded to the blockchain using their identifiers, allowing the blockchain to manage the data within these nodes. Uploading to the blockchain refers to the process of writing data or transactions into the blockchain's distributed ledger through a consensus mechanism.
[0056] Figure 2 A schematic diagram of the combined structure of blockchain and hyperconverged infrastructure in related technologies is shown. Figure 2 Taking a hyperconverged node (corresponding to a physical host) as an example, deploying a blockchain node and a data node, the blockchain node and the data node maintain logical isolation, the various blockchain nodes form a blockchain cluster, and the various data nodes form a data cluster.
[0057] However, when it is necessary to expand the capacity of hyperconverged nodes, they can be added simply by deploying blockchain distributed software. The lack of security authentication of physical hosts affects data security and leads to data leakage.
[0058] According to an embodiment of the present invention, a security authentication method embodiment is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0059] This embodiment provides a security authentication method, which is executed by a first host, which may be a desktop computer, laptop computer, tablet computer, server, smartphone, etc.
[0060] Figure 3 This is a flowchart of a security authentication method according to an embodiment of the present invention, such as... Figure 3 As shown, the process includes the following steps:
[0061] Step S301: Request the first hardware feature from the second host.
[0062] The first host is the host that needs to join but has not yet joined the target blockchain. The second host is any of the hosts that have already joined the target blockchain, and the second host has the nodes of the target blockchain configured.
[0063] When the first host needs to join the target blockchain, it first requests a first hardware feature from the second host. This first hardware feature is the hardware feature provided by the second host when joining the target blockchain, such as the second host's own unique device code or the hardware code corresponding to the hardware set in the second host.
[0064] Step S302: Based on the first hardware feature, send a request to join the target blockchain.
[0065] Only after receiving the first hardware feature sent by the second host, i.e., after obtaining the recommendation of an existing host in the target blockchain, can the first host send a request to join the target blockchain through the first hardware feature. This ensures the security of the first host and, consequently, the security of the data in the target blockchain.
[0066] Step S303: Upon receiving the consent to join instruction from the target blockchain, join the target blockchain.
[0067] The target blockchain can verify the first hardware feature included in the application to join, determining whether the first host meets the joining conditions. If the first host meets the joining conditions, an agreement to join is sent to the first host. After receiving the agreement to join from the target blockchain, the first host can perform the on-chain operation to join the target blockchain.
[0068] The security authentication method provided in this embodiment is executed by a first host. During security authentication, the first host first requests a first hardware feature from a second host. The second host has nodes configured in the target blockchain, and the first hardware feature is the hardware feature provided when the second host joins the target blockchain. Next, based on the first hardware feature, a join request instruction is sent to the target blockchain. Upon receiving a join acceptance instruction from the target blockchain, the first host joins the target blockchain. In this scheme, before the first host joins the target blockchain, it needs to obtain the hardware feature provided by the second host, which has already joined the target blockchain, to ensure that the first host is recommended by the host already in the target blockchain before joining, thus ensuring the reliability of the first host and consequently ensuring the security of the target blockchain during node expansion and the data security of the target blockchain.
[0069] This embodiment provides a security authentication method, executed by a first host, which may be a desktop computer, laptop computer, tablet computer, server, smartphone, etc. Figure 4 This is a flowchart of a security authentication method according to an embodiment of the present invention, such as... Figure 4 As shown, the process includes the following steps:
[0070] Step S401: Request the first hardware feature from the second host.
[0071] The second host is any of the hosts that have joined the target blockchain. The second host has nodes of the target blockchain set up. That is, any host that has joined the target blockchain has nodes of the target blockchain set up. There is no limit to the number of blockchain nodes set up on the same host. For example, one blockchain node can be set up on one host, or multiple blockchain nodes can be set up on one host.
[0072] The first hardware feature is the hardware feature provided by the second host when it joins the target blockchain. In other words, any host joining the target blockchain needs to provide at least one of its own hardware features. After joining the target blockchain, the second host can also store other hardware features of itself in the target blockchain as needed, so that they can be sent to new hosts when they join the target blockchain in the future.
[0073] For example, the first hardware feature is the Central Processing Unit (CPU) serial number; or, the first hardware feature is the network interface card (NIC) physical address (MAC address). Alternatively, other unique hardware features corresponding to the host can be set as the first hardware feature as needed, such as the host's motherboard serial number, hard drive serial number, etc.
[0074] For example, the first host uses the `cat` command to obtain the CPU serial number and the `ifconfig` command to obtain the network interface card physical address. The code example is shown below; the content after " / / " is a comment.
[0075] #cat / sys / devices / virtual / dmi / id / product_serial / / Get the CPU serial number
[0076] 210235A3M46221VM000Z / / Central Processing Unit Serial Number
[0077] ifconfig eth0 / / Get the physical address of the network interface card
[0078] ether 00:dd:b6:91:52:29 / / Network interface card physical address
[0079] Step S402: Based on the first hardware feature, send a request to join the target blockchain.
[0080] Optionally, when applying to join the target blockchain, the first host needs to provide not only the first hardware characteristic of the second host already joined in the target blockchain, but also at least one of its own hardware characteristics. Specifically, the first host generates the application to join based on the first hardware characteristic and the second hardware characteristic of the first host, and sends the application to join to the target blockchain. It should be noted that the second hardware characteristic is a unique hardware characteristic corresponding to the first host, and can be a central processing unit serial number, network card physical address, etc., and the difference between it and the first hardware characteristic is that it corresponds to a different host.
[0081] Step S403: Upon receiving the consent to join instruction from the target blockchain, join the target blockchain.
[0082] When the target blockchain receives a request to join from the first host, it needs to determine whether the first host meets the joining qualifications. If the first host meets the joining qualifications, a joining consent instruction is sent to the first host. This joining consent instruction is generated when there is a hardware feature matching the first hardware feature among the various hardware features stored in the target blockchain, but no hardware feature matching the second hardware feature. That is, when the request to join contains one of the hardware features (the first hardware feature in this embodiment) corresponding to a host already joined in the target blockchain (the second host in this embodiment) and the hardware feature (the second hardware feature in this embodiment) corresponding to a new host not yet joined in the target blockchain, the target blockchain determines that the first host meets the joining qualifications and sends a joining consent instruction to the first host. The first hardware feature can ensure that the first host is recommended by a host already joined in the target blockchain, and the second hardware feature can ensure that the first host has not joined in the target blockchain, ensuring the uniqueness of the first host's identity in the target blockchain, thereby ensuring the stability of the target blockchain and avoiding network centralization.
[0083] After receiving a consent instruction from the target blockchain, the first host can perform the joining operation to join the target blockchain. Specifically, the first host first obtains its second hardware characteristic. Then, upon receiving the consent instruction from the target blockchain, the first host generates an on-chain identifier based on the second hardware characteristic, which serves as the first host's identifier in the target blockchain. Based on this on-chain identifier, the first host then joins the target blockchain. The on-chain identifier can, for example, include numbers, text, symbols, or any combination of numbers, text, and symbols.
[0084] Optionally, when the first host receives the consent to join the target blockchain, it also joins the data cluster corresponding to the target blockchain. This data cluster contains multiple data nodes, each with a corresponding data node identifier. In this embodiment, the data node identifier can be, for example, a number. Each data node stores corresponding data. These multiple data nodes are respectively set in each host corresponding to the target blockchain, and have a corresponding relationship with the blockchain nodes in each host. The number of data nodes set in each host is not limited here; it can be set according to actual needs. The blockchain nodes and data nodes in each host are logically isolated. When the first host joins the data cluster corresponding to the target blockchain, it also generates a data node number corresponding to the first host based on the second hardware feature, and joins the data cluster according to this data node number.
[0085] Optionally, when storing data, data nodes can set grouping rules, such as grouping data according to business scenarios. The first group stores data for the first business scenario, the second group stores data for the second business scenario, and each group is assigned a corresponding data group identifier, such as group1 and group2. Each host reports the data group identifier and the total number of files of the data stored by the corresponding data node to the target blockchain at a preset period. The target blockchain stores the data group identifier and the total number of files corresponding to each host.
[0086] Step S404: Send a backup command to the target blockchain.
[0087] To ensure data security and prevent data loss due to accidents, each host in the target blockchain backs up the data stored in its own data nodes. The target blockchain can preset a backup cycle, causing each host to perform backup operations. For example, if the backup cycle is set to one week, each host will perform a backup operation once a week. After the first host joins the target blockchain, it can back up data from other hosts in the target blockchain to itself, and it can also back up its own data to other hosts in the target blockchain.
[0088] Taking the example of a first host backing up data from a third host in a target blockchain to itself, the first host first sends a backup command to the target blockchain. The third host is any host in the target blockchain other than the first host, and this third host has nodes configured for the target blockchain. The backup command includes the identifier of the third host, which may be the on-chain identifier used when the third host joined the target blockchain, and includes the hardware characteristics of the third host.
[0089] Step S405: When the backup instruction of the target blockchain is received, the data to be backed up corresponding to the third host is backed up to the first host.
[0090] After receiving the backup instruction from the first host, the target blockchain needs to verify whether the first host is currently qualified to perform the backup operation. For example, it needs to check if the backup cycle has arrived and whether the first host's performance meets the backup requirements of the third host. If the first host is qualified, the target blockchain sends a backup consent instruction to the target blockchain. Upon receiving the backup consent instruction from the target blockchain, the first host backs up the data to be backed up corresponding to the third host to its own data node.
[0091] Optionally, the data to be backed up can be stored in encrypted form. This means the backup data exists in encrypted form and cannot be deciphered after leaving the target blockchain, further enhancing data security. For example, when a first host backs up its own data to a first target host within the target blockchain, the first target host sends a backup command to the target blockchain. Upon receiving the target blockchain's agreement to back up the data, the first target host backs up the corresponding data to be backed up to itself.
[0092] Furthermore, once the first host joins the target blockchain, it can also provide hardware characteristics for new hosts that subsequently join the target blockchain. Taking a second target host as an example, the second target host first requests the first target hardware characteristics from the first host. Then, based on these first target hardware characteristics, the second target host sends a join request instruction to the target blockchain. When the second target host receives the target blockchain's acceptance instruction, the second target host joins the target blockchain. The steps for the second target host to join the target blockchain are similar to those for the first host to join the first blockchain, and will not be elaborated here.
[0093] In one optional implementation, different security authentication rules are set for the first stage of creating the target blockchain and the second stage after the target blockchain is created. In this embodiment, steps S401 to S403 correspond to the security authentication rules for joining the target blockchain in the second stage. That is, a second host that has already joined the target blockchain needs to apply for a first hardware feature and obtain the recommendation of the second host before it can join the target blockchain. Taking the second host joining the target blockchain in the first stage as an example, the first stage only requires providing a hardware feature as the basis for verifying the uniqueness of the identity. When the second host joins the target blockchain, it obtains the first hardware feature of the second host and sends a request to join the target blockchain based on the first hardware feature. The target blockchain verifies the uniqueness of the second host's identity based on the first hardware feature. After receiving the consent to join instruction from the target blockchain, the second host joins the target blockchain.
[0094] Furthermore, to enhance security, the hardware characteristics of the host already joined in the target blockchain that the new host requests when joining the blockchain are not the same as the hardware characteristics provided by the host already joined in the target blockchain. For example, the first hardware characteristic requested by the first host from the second host is not the same as the hardware characteristic in the application to join the target blockchain sent by the second host. In this case, the host joining the target blockchain in the first phase needs to provide at least two hardware characteristics. One of these at least two hardware characteristics is used to generate the on-chain identifier, and the other of these at least two hardware characteristics is stored in the target blockchain and sent to the new host when it requests hardware characteristics to join the target blockchain later.
[0095] Taking the second host joining the target blockchain in the first stage as an example, when the second host joins the target blockchain, it obtains the first hardware feature and the third hardware feature of the second host, and sends a request to join the target blockchain based on the first hardware feature and the third hardware feature. The target blockchain verifies the uniqueness of the second host's identity based on the third hardware feature, and stores the first hardware feature for the first host to apply to the second host to join the target blockchain later. After receiving the consent to join instruction from the target blockchain, the second host joins the target blockchain.
[0096] Furthermore, the hosts joining the target blockchain in the second phase also need to provide hardware features in addition to those provided when joining the target blockchain. For example, the first host may also store a fourth hardware feature in the target blockchain so that when a new host joins the target blockchain, if the first host receives a request for the fourth hardware feature from a new host, it can send the fourth hardware feature to the new host. The new host can then send a request to join the target blockchain based on the fourth hardware feature. This will not be elaborated further here.
[0097] Optionally, when a host in the target blockchain fails, the data on the failed host needs to be recovered, and a new host is used to replace the failed host and join the target blockchain. Taking replacing the failed host with the first host as an example, if a fourth host fails, the first host sends a replacement instruction to the target blockchain. The fourth host can be any of the hosts in the target blockchain other than the first host. The target host determines whether the first host currently meets the conditions for replacing the fourth host, such as whether it is currently due for maintenance or whether the performance of the first host meets the performance requirements for replacing the fourth host. If it does, the target host sends a replacement consent instruction to the first host. When the first host receives the replacement consent instruction corresponding to the target blockchain, it obtains the backup data of the fourth host from the fifth host. Since directly obtaining the backup data of the failed host is more efficient than obtaining the complete data of the failed host from the data cluster, when the first host receives the replacement consent instruction corresponding to the target blockchain, it prioritizes obtaining the backup data of the fourth host from the fifth host to ensure data recovery efficiency. The fifth host has pre-backed up the data in the fourth host.
[0098] Furthermore, since the backup data obtained by the first host may not be complete—for example, the backup cycle may not have arrived—the fourth host may not have backed up the updated data in time before the failure, resulting in incomplete backup data for the fourth host in the fifth host. Therefore, the first host also checks the completeness of the obtained backup data. If the backup data is found to be complete, it is added to the target blockchain according to the on-chain identifier. If the backup data is found to be incomplete, the backup data of the fourth host is obtained from the data cluster corresponding to the target blockchain. For example, the missing data is recovered through a comprehensive comparison of the data in the data cluster, thereby obtaining the complete data corresponding to the fourth host, and then added to the target blockchain according to the on-chain identifier.
[0099] In one optional implementation, the backup host corresponding to the faulty host is quickly identified based on the data packet identifier corresponding to the data of the faulty host, simplifying the identification process and improving data recovery efficiency. Specifically, when a consent to replace instruction is received from the target blockchain, a fifth host is determined in the target blockchain based on the data packet identifier corresponding to the data of the fourth host. This fifth host stores the backup data of the fourth host, and the data packet identifier corresponding to this backup data is the same as that of the data of the fourth host. In other words, when storing backup data, the backup host also stores the original data packet identifier of the backup data. After identifying the fifth host, the backup data of the fourth host can be retrieved from the fifth host.
[0100] In one optional implementation, when checking the integrity of backup data, the data group identifier and total number of files in the backup data can be verified first. If the backup data is complete, the step of performing a comprehensive comparison of the data in the data cluster is eliminated, improving verification efficiency and thus improving data recovery efficiency. Specifically, first, the data group identifier and total number of files in the backup data are parsed. Then, the data group identifier of the backup data is compared with the data group identifier corresponding to the fourth host stored in the target blockchain, and the total number of files in the backup data is compared with the total number of files corresponding to the fourth host stored in the target blockchain. If the data group identifier of the backup data matches the data group identifier corresponding to the fourth host stored in the target blockchain, and the total number of files in the backup data matches the total number of files corresponding to the fourth host stored in the target blockchain, then the backup data is determined to be complete, realizing the rapid determination of the integrity of the backup data through the data group identifier and the total number of files, thereby improving data recovery efficiency; otherwise, the backup data is determined to be incomplete, and a step of performing a comprehensive comparison of the data in the data cluster is required to recover the data.
[0101] The security authentication method provided in this embodiment requires obtaining the hardware characteristics provided by the second host that has already joined the target blockchain before the first host joins the target blockchain. This ensures that the first host is recommended by the host that has already joined the target blockchain before joining the target blockchain, thus ensuring the reliability of the first host and consequently ensuring the security of the target blockchain when nodes are expanded, and ensuring the data security of the target blockchain.
[0102] Furthermore, the first host sends a backup instruction to the target blockchain. Upon receiving the target blockchain's agreement to back up the data to be backed up from the third host, it backs up the data to be backed up to the first host, ensuring that even if data backup is performed, data loss due to accidents is prevented. If a failure of the fourth host is detected, the first host also sends a replacement instruction to the target blockchain. Upon receiving the target blockchain's agreement to replace the fourth host, it retrieves the backup data of the fourth host from the fifth host, thereby achieving rapid data recovery.
[0103] Furthermore, in this embodiment, when checking whether the backup data is complete, the data group identifier and total number of files of the backup data can be verified first. If the backup data is complete, the step of performing a comprehensive comparison of the data in the data cluster is eliminated, thus improving the data recovery efficiency.
[0104] As one or more specific application embodiments of the present invention, the optimal implementation scheme or the scheme that the inventors most want to embody is described below in conjunction with specific application scenarios.
[0105] Figure 5 This is a schematic diagram of the system structure corresponding to the security authentication method according to an embodiment of the present invention, such as... Figure 5As shown, the system architecture includes multiple hosts, multiple blockchain nodes, and multiple data nodes. These blockchain nodes form the target blockchain, and the data nodes form a data cluster. The blockchain nodes are used for inputting and managing data keys (corresponding to data node numbers) and host keys (corresponding to on-chain identifiers), for example... Figure 5 The diagram shows blockchain node 1, which stores a hostkey. Blockchain node 1 can also store data asset keys, which are used to identify data assets. This data node is used for data entry and management, and each data node includes at least one data asset, such as... Figure 5 The diagram shows data node 1, which includes data asset 1 and data asset 2. Data asset 1 corresponds to data group identifier group1, and group1 stores data 1. Data asset 2 corresponds to data group identifier group2, and group2 stores data 2. Each of the multiple hosts is equipped with a host processing module, which is used for applying to join the target blockchain, performing data backup and data recovery, etc.
[0106] This embodiment also provides a security authentication device for implementing the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that performs a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.
[0107] This embodiment provides a security authentication device, which is installed in a first host, such as... Figure 6 As shown, it includes:
[0108] The feature application module 601 is used to apply for a first hardware feature from the second host; the second host has nodes of the target blockchain configured; the first hardware feature is the hardware feature provided when the second host joins the target blockchain;
[0109] The application module 602 is used to send an application to join the target blockchain based on the first hardware feature.
[0110] The joining module 603 is used to join the target blockchain when it receives a consent joining instruction from the target blockchain.
[0111] In one optional implementation, the joining module is further configured to: obtain a second hardware feature of the first host; generate an on-chain identifier based on the second hardware feature when a consent joining instruction is received from the target blockchain; and join the target blockchain according to the on-chain identifier.
[0112] In an optional implementation, the join request module is further configured to: generate the join request instruction based on the first hardware feature and the second hardware feature of the first host, so as to send the join request instruction to the target blockchain.
[0113] In one alternative implementation, the consent to join instruction is generated when there is a hardware feature matching the first hardware feature among the various hardware features stored in the target blockchain, but no hardware feature matching the second hardware feature.
[0114] After the first host joins the target blockchain, the device also includes:
[0115] The backup request module is used to send a backup instruction to the target blockchain; the backup instruction includes the identifier of a third host; the third host contains nodes of the target blockchain.
[0116] The backup module is used to back up the data to be backed up corresponding to the third host to the first host when it receives a backup instruction from the target blockchain.
[0117] In one optional implementation, the device further includes a data cluster joining module, configured to join the data cluster corresponding to the target blockchain upon receiving an agreement to join instruction from the target blockchain.
[0118] In one optional implementation, the device further includes: a fault detection module, configured to send a replacement instruction to the target blockchain if a fault is detected in the fourth host; and a first backup acquisition module, configured to acquire backup data of the fourth host from the fifth host when a replacement consent instruction corresponding to the target blockchain is received.
[0119] The addition module is also used to: if the backup data is detected to be complete, add it to the target blockchain according to the on-chain identifier.
[0120] In one optional implementation, the joining module is further configured to: if the backup data is detected to be incomplete, obtain the backup data of the fourth host from the data cluster corresponding to the target blockchain; and join the target blockchain according to the on-chain identifier.
[0121] In an optional implementation, the first backup acquisition module is further configured to: when receiving an agreement to replace instruction corresponding to the target blockchain, determine a fifth host in the target blockchain based on the data packet identifier corresponding to the data of the fourth host; the fifth host stores backup data of the fourth host; the data packet identifier corresponding to the backup data is the same as the data packet identifier corresponding to the data of the fourth host; and acquire the backup data of the fourth host from the fifth host.
[0122] In one optional implementation, the joining module is further configured to: parse the data group identifier and total number of files of the backup data; if the data group identifier of the backup data is consistent with the data group identifier corresponding to the fourth host stored in the target blockchain, and the total number of files of the backup data is consistent with the total number of files corresponding to the fourth host stored in the target blockchain, then the backup data is determined to be complete.
[0123] Further functional descriptions of the above modules and units are the same as those in the corresponding embodiments described above, and will not be repeated here.
[0124] In this embodiment, the security authentication device is presented in the form of a functional unit. Here, a unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that execute one or more software or fixed programs, and / or other devices that can provide the above functions.
[0125] This invention also provides a computer device having the above-described features. Figure 6 The security authentication device shown.
[0126] Please see Figure 7 , Figure 7 This is a schematic diagram of the structure of a computer device provided in an optional embodiment of the present invention, such as... Figure 7 As shown, the computer device includes one or more processors 10, memory 20, and interfaces for connecting the components, including high-speed interfaces and low-speed interfaces. The components communicate with each other via different buses and can be mounted on a common motherboard or otherwise installed as needed. The processors can process instructions executed within the computer device, including instructions stored in or on memory to display graphical information of a GUI on external input / output devices (such as display devices coupled to the interfaces). In some alternative implementations, multiple processors and / or multiple buses can be used with multiple memories and multiple memory modules, if desired. Similarly, multiple computer devices can be connected, each providing some of the necessary operations (e.g., as a server array, a group of blade servers, or a multiprocessor system). Figure 7 Take a processor 10 as an example.
[0127] Processor 10 may be a central processing unit, a network processor, or a combination thereof. Processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The programmable logic device may be a complex programmable logic device (CAMP), a field-programmable gate array (FPGA), a general-purpose array logic (GDA), or any combination thereof.
[0128] The memory 20 stores instructions executable by at least one processor 10 to cause the at least one processor 10 to perform the method shown in the above embodiments.
[0129] The memory 20 may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function; the data storage area may store data created based on the use of the computer device. Furthermore, the memory 20 may include high-speed random access memory and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some alternative embodiments, the memory 20 may optionally include memory remotely located relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.
[0130] The memory 20 may include volatile memory, such as random access memory; the memory may also include non-volatile memory, such as flash memory, hard disk or solid-state drive; the memory 20 may also include a combination of the above types of memory.
[0131] The computer device also includes an input device 30 and an output device 40. The processor 10, memory 20, input device 30, and output device 40 can be connected via a bus or other means. Figure 7 Taking the example of a connection between China and Israel via a bus.
[0132] Input device 30 can receive input numerical or character information, and generate key signal inputs related to user settings and function control of the computer device, such as a touchscreen, keypad, mouse, trackpad, touchpad, joystick, one or more mouse buttons, trackball, joystick, etc. Output device 40 may include display devices, auxiliary lighting devices (e.g., LEDs), and haptic feedback devices (e.g., vibration motors). The aforementioned display devices include, but are not limited to, liquid crystal displays, light-emitting diodes, displays, and plasma displays. In some alternative embodiments, the display device may be a touchscreen.
[0133] This invention also provides a computer-readable storage medium. The methods described above according to embodiments of the invention can be implemented in hardware or firmware, or implemented as computer code that can be recorded on a storage medium, or implemented as computer code downloaded over a network and originally stored on a remote storage medium or a non-transitory machine-readable storage medium and then stored on a local storage medium. Thus, the methods described herein can be processed by software stored on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. The storage medium can be a magnetic disk, optical disk, read-only memory, random access memory, flash memory, hard disk, or solid-state drive, etc.; further, the storage medium can also include combinations of the above types of memory. It is understood that computers, processors, microprocessor controllers, or programmable hardware include storage components capable of storing or receiving software or computer code, which, when accessed and executed by the computer, processor, or hardware, implements the methods shown in the above embodiments.
[0134] A portion of this invention can be applied as a computer program product, such as computer program instructions, which, when executed by a computer, can invoke or provide the methods and / or technical solutions according to the invention through the operation of the computer. Those skilled in the art will understand that the forms in which computer program instructions exist in a computer-readable medium include, but are not limited to, source files, executable files, installation package files, etc. Correspondingly, the ways in which computer program instructions are executed by a computer include, but are not limited to: the computer directly executing the instructions, or the computer compiling the instructions and then executing the corresponding compiled program, or the computer reading and executing the instructions, or the computer reading and installing the instructions and then executing the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to a computer.
[0135] Although embodiments of the present invention have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations all fall within the protection scope of the present invention.
Claims
1. A security authentication method, characterized in that, The method, executed by a first host, includes: The system requests a first hardware feature from a second host; the second host contains nodes of the target blockchain; the first hardware feature is the hardware feature provided by the second host when it joins the target blockchain. Based on the first hardware feature, a request to join is sent to the target blockchain; Upon receiving a consent instruction to join the target blockchain, join the target blockchain.
2. The method according to claim 1, characterized in that, The step of joining the target blockchain upon receiving a consent instruction from the target blockchain includes: Obtain the second hardware characteristics of the first host; Upon receiving the consent to join instruction from the target blockchain, an on-chain identifier is generated based on the second hardware feature; Join the target blockchain according to the on-chain identifier.
3. The method according to claim 2, characterized in that, The method further includes: Based on the first hardware feature and the second hardware feature of the first host, the request to join instruction is generated and sent to the target blockchain.
4. The method according to claim 3, characterized in that, The consent instruction is generated when there is a hardware feature that matches the first hardware feature among the various hardware features stored in the target blockchain, but there is no hardware feature that matches the second hardware feature.
5. The method according to any one of claims 1 to 4, characterized in that, After the first host joins the target blockchain, the method further includes: A backup instruction is sent to the target blockchain; the backup instruction includes the identifier of a third host; the third host contains nodes of the target blockchain. Upon receiving a backup instruction from the target blockchain, the data to be backed up corresponding to the third host is backed up to the first host.
6. The method according to any one of claims 2 to 4, characterized in that, The method further includes: If a fourth host failure is detected, a replacement instruction is sent to the target blockchain; When a consent replacement instruction corresponding to the target blockchain is received, the backup data of the fourth host is obtained from the fifth host; The step of joining the target blockchain according to the on-chain identifier includes: If the backup data is detected to be complete, it is added to the target blockchain according to the on-chain identifier.
7. The method according to claim 6, characterized in that, The method further includes: If the backup data is detected to be incomplete, the backup data of the fourth host is obtained from the data cluster corresponding to the target blockchain; Join the target blockchain according to the on-chain identifier.
8. The method according to claim 6, characterized in that, When a consent to change instruction corresponding to the target blockchain is received, obtaining the backup data of the fourth host from the fifth host includes: When a consent to change instruction is received corresponding to the target blockchain, a fifth host is determined in the target blockchain based on the data packet identifier corresponding to the data of the fourth host; the fifth host stores backup data of the fourth host; the data packet identifier corresponding to the backup data is the same as the data packet identifier corresponding to the data of the fourth host. The backup data of the fourth host is obtained from the fifth host.
9. The method according to claim 8, characterized in that, The method further includes: Parse the data group identifiers and total number of files in the backup data; If the data group identifier of the backup data is consistent with the data group identifier corresponding to the fourth host stored in the target blockchain, and the total number of files in the backup data is consistent with the total number of files corresponding to the fourth host stored in the target blockchain, then the backup data is determined to be complete.
10. A security authentication device, characterized in that, Located in the first host, the device includes: The feature application module is used to apply for a first hardware feature from the second host; the second host has nodes of the target blockchain configured; the first hardware feature is the hardware feature provided when the second host joins the target blockchain; The application module is used to send an application to join the target blockchain based on the first hardware feature. The joining module is used to join the target blockchain when it receives a consent joining instruction from the target blockchain.
11. A computer device, characterized in that, include: A memory and a processor are communicatively connected, the memory stores computer instructions, and the processor executes the computer instructions to perform the security authentication method according to any one of claims 1 to 9.
12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing a computer to perform the security authentication method according to any one of claims 1 to 9.
13. A computer program product, characterized in that, Includes computer instructions for causing a computer to perform the security authentication method according to any one of claims 1 to 9.