Service registration and discovery method

By employing multi-party security authentication and dynamic key management, combined with irreducible polynomial hashing and symmetric encryption techniques, the problems of complex key management and weak identity authentication in communication service registration mechanisms are solved, achieving highly secure and reliable communication service registration and discovery.

CN120980132APending Publication Date: 2025-11-18MATRICTIME DIGITAL TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511123218.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-12
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

Existing communication service registration mechanisms suffer from complex key management, weak identity authentication, and easy leakage of business data, making it difficult to balance security with system performance and meet the needs of high-security application scenarios.

Method used

Employing multi-party security authentication and dynamic key management, and utilizing irreducible polynomial hashing and symmetric encryption technologies, it achieves high-strength encrypted storage of business service information and secure control over service discovery.

Benefits of technology

It achieves physical isolation between service metadata and core logic, eliminates unauthorized access, improves the confidentiality and controllability of business services during the registration and discovery process, and enhances security and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120980132A_ABST
    Figure CN120980132A_ABST
Patent Text Reader

Abstract

The invention discloses a service registration and discovery method. The method comprises the following steps: a key provider presets communication keys for a service center, a service provider and a service caller; the service center performs identity authentication based on the registration information, acquires the registration information after the authentication is passed, and allocates a storage space for the service provider; otherwise, re-initiating the authentication process; the service center notifies a key provider to generate a service encryption key and send the service encryption key to a service provider, and the service provider encrypts the service information by using the service encryption key to obtain a service information ciphertext; the service center authenticates the device identity ID of the service provider, and stores the business service information ciphertext in the distributed storage space after the authentication is passed; and the service caller requests the service center to execute the service discovery operation. According to the invention, symmetric key encryption and identity authentication are combined, the service registration process is optimized, and the communication security and the service manageability are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a method for communication service registration and discovery. Background Technology

[0002] Current communication service registration and discovery mechanisms face numerous challenges in secure interaction between service providers, service consumers, and service centers. Traditional service registration mechanisms typically employ static keys or simple authentication methods, resulting in complex key management, insufficient authentication strength, and susceptibility to business data leakage. For example, inadequate key management mechanisms often rely on static, long-term keys without secure distribution schemes, posing a risk of key leakage; weak authentication systems often depend solely on one-way authentication or simple password verification, failing to effectively prevent forgery attacks; insufficient protection of business data, with service information frequently stored in plaintext or weak encryption, making it vulnerable to theft or tampering; and a lack of strict control over the service discovery process, allowing consumers to directly access service providers, increasing the likelihood of unauthorized access and data leakage. Existing solutions often struggle to balance security and system performance; asymmetric encryption incurs high computational overhead, while symmetric encryption faces complex key management issues, making it difficult to balance security and operational efficiency. Therefore, existing communication service registration mechanisms have significant security deficiencies, making them unsuitable for high-security application scenarios.

[0003] Therefore, there is an urgent need for an efficient and secure communication service registration and discovery method that can achieve multi-party secure authentication, dynamic key management, and encrypted storage of business data, so as to improve the security and reliability of the communication service registration and discovery mechanism. Summary of the Invention

[0004] Purpose of the invention: This application provides a communication service and registration method to solve the problems existing in the prior art.

[0005] Technical Solution: This invention provides a method for registration and discovery of communication services. The participants in the method include: a key provider, a service center, a service provider, and a service caller. The method includes the following steps:

[0006] Step 1: The key provider pre-configures communication keys for the service center, the service provider, and the service caller; among them, the service center has symmetric keys with the service provider and the service caller respectively;

[0007] Step 2: The service center authenticates the service provider based on the service provider's registration information (reg). If the authentication is successful, the service center obtains the service provider's registration information (reg) and allocates storage space to the service provider; otherwise, it records the authentication failure information and the service provider re-initiates the authentication process.

[0008] Step 3: The service center notifies the key provider to generate a business encryption key K and sends it to the service provider. The service provider uses the business encryption key K to encrypt the business service information and saves the key to obtain the encrypted business service information ciphertext URI.

[0009] Step 4: The service center authenticates the device identity ID of the service provider. After successful authentication, the encrypted URI of the business service information is stored in the storage space allocated in Step 2, thus completing the business service registration process.

[0010] Step 5: After registration is complete, the service caller requests the service center to perform a service discovery operation.

[0011] As an improvement to the present invention, step 2 specifically includes:

[0012] Step 2-1: The service provider selects a key from its local communication key pool as the first communication encryption key Kcb1 and records the first key index idx-Kcb1 of the first communication encryption key Kcb1; the service provider uses the first communication encryption key Kcb1 to encrypt the registration information reg to obtain the first ciphertext REG; the registration information reg includes at least one of the following: the service provider's IP information, port information, device identity ID, application identifier ser, and the business service information and size provided by the application.

[0013] Step 2-2: The service provider generates an irreducible polynomial p1(x) locally, and records the string consisting of the coefficients of each term in the irreducible polynomial p1(x) except for the highest term as str1; the service provider obtains the second communication key Kcb2 from the local communication key pool as the input random number, and records the second key index idx-Kcb2; a hash function is generated using the irreducible polynomial p1(x) and the second communication key Kcb2. Input the first ciphertext REG and the first key index idx-Kcb1 into the hash function. Get the first hash value

[0014] Steps 2-3: The service provider selects a key from its local communication key pool as the third communication encryption key Kcb3 and records the third key index idx-Kcb3 of this third communication encryption key Kcb3; it uses the third communication encryption key Kcb3 to encrypt the string str1, the first ciphertext REG, the first key index idx-Kcb1 and the second key index idx-Kcb2, and the first hash value H1 to generate the first message Mes1 in ciphertext form. The first message Mes1 and the third key index idx-Kcb3 are sent to the service center. The service center performs tamper-proof authentication on the received first message Mes1. If the authentication is successful, the registration information reg is obtained and storage space is allocated to the service provider; otherwise, the authentication fails and the service provider re-initiates the authentication.

[0015] As an improvement of the present invention, in steps 2-3, the tamper-proof identity authentication includes:

[0016] (a1): The service center receives information Mes1' and key index idx-Kcb3 ′ According to the key index idx-Kcb3 ′ Obtain the third communication decryption key Kcb3' from the local communication key pool, and use the third communication decryption key Kcb3' to perform a decryption operation on the message Mes1' to obtain the string str1', the ciphertext REG', and the communication decryption key index idx-Kcb1. ′ and key index idx-Kcb2 ′ and the hash value H1';

[0017] (a2): The service center uses the key index idx-Kcb2 ′ Obtain the communication key Kcb2' from the local communication key pool, generate an irreducible polynomial p′1(x) based on the string str1′, and then generate a hash function based on the irreducible polynomial p′1(x) and the communication key Kcb2'.

[0018] (a3): The service center will store the ciphertext REG' and the communication decryption key index idx-Kcb1 ′ Input hash function Obtain the second hash value The hash value H1' obtained from decryption is compared with the second hash value H2. If they match, the authentication is successful; otherwise, the authentication fails, and the service provider re-initiates the authentication process.

[0019] As an improvement of the present invention, in steps 2-3, obtaining the registration information (reg) and allocating storage space for the service provider specifically includes:

[0020] After successful authentication by the service center, the service center uses the communication decryption key index idx-Kcb1. ′ Obtain the first communication decryption key Kcb1' from the local communication key pool, use the first communication decryption key Kcb1' to decrypt the ciphertext REG', obtain the registration information reg, extract the application identifier ser from the registration information reg as the unique key value key1 of the application; the service center allocates a storage space from the local total memory and disk space, and stores the other information of the registration information reg except for the application identifier ser as the first metadata value1 into the storage space.

[0021] As an improvement to the present invention, step 3 specifically includes:

[0022] The service center notifies the key provider to send a business encryption key K to the service provider based on the size of the business service information provided by the application. In response to the request, the key provider obtains a business encryption key K of the same length as the business service information from its local machine and sends it to the service provider. The service provider receives and stores the business encryption key K, and at the same time uses the business encryption key K to encrypt the entire business service information to obtain the encrypted business service information ciphertext URI.

[0023] As an improvement of the present invention, in step 4, the service center authenticates the device identity ID of the service provider, specifically including:

[0024] (b1): The service provider selects a key from the local communication key pool as the fourth communication encryption key Kcb4, and records the fourth key index idx-Kcb4 of the fourth communication encryption key Kcb4; it uses the fourth communication encryption key Kcb4 to encrypt the combination of the business service information ciphertext URI, application identifier ser, business identifier busi, and the service provider's device identity ID to generate the second information Mes2 in ciphertext form, and sends the second information Mes2 and the fourth key index idx-Kcb4 to the service center;

[0025] (b2): The service center uses the key index idx-Kcb4 ′ The fourth communication decryption key Kcb4' is obtained from the local communication key pool. After decrypting the information Mes2' using the fourth communication decryption key Kcb4', the application identifier ser' and the device identity ID of the service provider ser' are obtained. The application identifier ser' and the device identity ID ser' are then used for authentication.

[0026] The service center searches its local storage space to see if the application identifier ser' and device identity ID' are already stored simultaneously. If they are, the authentication is successful; otherwise, the authentication fails, and the service provider is notified that the business registration failed.

[0027] As an improvement to the present invention, in step 4, storing the encrypted URI of the business service information in the storage space allocated in step 2 means:

[0028] After the service center authenticates the device identity ID of the service provider, it will use the decrypted business identifier busi as the unique key value key2 and the encrypted business service information URI as the second metadata value2 in the storage space allocated in step 2.

[0029] As an improvement of the present invention, in step 5, the service discovery operation includes:

[0030] (c1): The service caller selects a key from the local communication key pool as the fifth communication encryption key Kdb1, and records the fifth key index idx-Kdb1 of the fifth communication encryption key Kdb1; it uses the fifth communication encryption key Kdb1 to identify the application ser. ″ Encrypting the business identifier busi″ yields the second ciphertext REQ = (ser ″ ,busi″)⊕Kdb1, send the second ciphertext REQ and the fifth index idx-Kdb1 to the service center;

[0031] (c2): The service center obtains the fifth communication decryption key Kbd1′ from the local communication key pool based on the received key index idx-Kdb1′, and uses the fifth communication decryption key Kbd1′ to decrypt the ciphertext REQ' to obtain the application identifier ser. ″ The key-value pair, along with the business identifier "busi", is used to query the local storage space to see if it contains a key-value pair that is also matched with the application identifier "ser". ″ Corresponding to the business identifier "busi", if it exists, the metadata stored corresponding to this key value will be sent to the service caller; if it does not exist, the service caller will be informed of the failure of business service discovery, and the discovery process will end.

[0032] (c3): The service caller finds the service provider based on the content of the first metadata value1 in the received metadata, and initiates a call request req to the service provider. The call request req includes the second metadata value2 in the metadata.

[0033] (c4): The service provider responds to the call request req and compares whether the second metadata value2 in the received call request req is consistent with the encrypted URI of the business service information stored locally. If they are consistent, the service provider obtains the business encryption key K from the local storage, decrypts the encrypted URI of the business service information, and provides the decrypted business service information to the service caller for invocation.

[0034] Beneficial effects:

[0035] 1. All key information of the business service (including service interfaces, metadata and access rules) is registered in the service center in a highly encrypted ciphertext form. The service provider only retains the specific implementation details and sensitive data of the business service in the local secure environment, which realizes the physical isolation between service metadata and core logic.

[0036] 2. Regarding the service discovery mechanism, all service query requests must be completed through the authentication and decryption process of the service center. Service callers can only obtain encrypted service identifiers and cannot directly and proactively access service providers, thus eliminating the possibility of unauthorized access.

[0037] 3. Through layered protection of encrypted data registration, metadata isolation, and service discovery security authentication, the confidentiality and controllability of business services during the registration and discovery process are effectively ensured, further improving the security of critical information during service registration and discovery. Attached Figure Description

[0038] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0039] Figure 1 This is a structural diagram of the parties involved in this application;

[0040] Figure 2 This is a flowchart illustrating the process of this application;

[0041] Figure 3 This is a schematic diagram of the storage space corresponding to the key value key1 and the first metadata value1 in this application;

[0042] Figure 4 This is a schematic diagram of the storage space corresponding to the key value key2 and the second metadata value2 after storage in this application. Detailed Implementation

[0043] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0044] This invention provides a method for registration and discovery of communication services, such as... Figure 1As shown, the participants in the method include: key provider 1, service center 2, service provider 3, and service caller 4. Key provider 1 provides quantum encryption keys for registered services; service center 2 provides capabilities such as identity authentication, service registration, and service discovery; service provider 3 provides specific business services, such as order inquiry, bill summary, and financial payment; and service caller 4 refers to the party that needs to use the specific business services.

[0045] like Figure 2 As shown, the communication service registration and discovery method includes the following steps:

[0046] Step 1: Key provider 1 pre-configures communication keys for service center 2, service provider 3, and service caller 4. Service center 2 and service provider 3 have keys that can be paired; service center 2 and service caller 4 have keys that can be paired.

[0047] For example, the local communication key pools in service center 2 and service provider 3 have pre-set symmetrical key files, and the local communication key pools in service center 2 and service caller 4 have pre-set symmetrical key files.

[0048] Step 2: Service Center 2 authenticates Service Provider 3 based on Service Provider 3's registration information reg. If the authentication is successful, Service Center 2 obtains Service Provider 3's registration information reg and allocates storage space to Service Provider 3; otherwise, it records the authentication failure information and Service Provider 3 re-initiates the authentication process.

[0049] Specifically, step 2 includes:

[0050] Step 2-1: Service provider 3 selects a key from the local communication key pool as the first communication encryption key Kcb1, and records the first key index idx-Kcb1 of the first communication encryption key Kcb1; Service provider 3 uses the first communication encryption key Kcb1 to encrypt the registration information reg, and obtains the first ciphertext REG; The registration information reg includes at least one of the following: its own IP information, port information, device identity ID (for example, it can be its own device code, which is unique and can uniquely identify the device), application identifier ser, and the business service information and size provided by the application, etc.

[0051] In embodiments of the present invention, the business service information and its size provided by the application refer to the following: an application can provide multiple business services, and if there are multiple business services, each business service includes its own business service information; in order to ensure that the multiple business services can be registered in the future, the registration information reg mentioned above can include the size information of multiple pieces of information such as the size of the first business service information, the size of the second business service information, ..., and the size of the nth business service information provided by the application.

[0052] Step 2-2: Service provider 3 generates an irreducible polynomial p1(x) locally, and records the string consisting of the coefficients of each term except the highest term as str1; Service provider 3 obtains the second communication key Kcb2 from the local communication key pool as the input random number, and records the second key index idx-Kcb2; A hash function is generated using the irreducible polynomial p1(x) and the second communication key Kcb2. Input the first ciphertext REG and the first key index idx-Kcb1 into the hash function. Get the first hash value

[0053] Steps 2-3: Service provider 3 selects a key from its local communication key pool as the third communication encryption key Kcb3, and records the third key index idx-Kcb3 of the third communication encryption key Kcb3; it then uses the third communication encryption key Kcb3 to encrypt the string str1, the first ciphertext REG, the first key index idx-Kcb1, the second key index idx-Kcb2, and the first hash value. The combination of these elements generates a first message Mes1 in encrypted form. The first message Mes1 and the third key index idx-Kcb3 are then sent to service center 2. Service center 2 performs tamper-proof authentication on the received first message Mes1. If the authentication is successful, the registration information reg is obtained, and storage space is allocated to service provider 3. Otherwise, the authentication fails, and service provider 3 re-initiates the authentication.

[0054] Specifically, the tamper-proof identity authentication described in steps 2-3 includes:

[0055] (a1): Service Center 2 receives information Mes1 ′ and key index idx-Kcb3 ′ According to the key index idx-Kcb3 ′ Obtain the third communication decryption key Kcb3 from the local communication key pool. ′ Using the third communication decryption key Kcb3 ′Decrypt the message Mes1' to obtain the string str1', the ciphertext REG', and the communication decryption key index idx-Kcb1. ′ and key index idx-Kcb2 ′ and the hash value H1';

[0056] (a2): Service Center 2 uses the key index idx-Kcb2 ′ Obtain the communication key Kcb2 from the local communication key pool. ′ As input random numbers, an irreducible polynomial p′1(x) is generated based on the string str1′, and then based on the irreducible polynomial p′1(x) and the communication key Kcb2 ′ Generate hash function

[0057] (a3): Service Center 2 will store the ciphertext REG' and the communication decryption key index idx-Kcb1 ′ Input the hash function Obtain the second hash value The hash value H1' obtained from decryption is compared with the calculated second hash value H2. If they match, the authentication is successful; otherwise, the authentication fails, and the service provider 3 re-initiates the authentication process.

[0058] Specifically, obtaining the registration information (reg) in steps 2-3 and allocating storage space for service provider 3 includes:

[0059] After successful authentication, Service Center 2 obtains the registration information reg, extracts the unique application identifier ser as the key value key1, and allocates storage space to save the remaining first metadata value1.

[0060] More specifically, after successful identity authentication, Service Center 2 uses the communication decryption key index idx-Kcb1. ′ Obtain the first communication decryption key Kcb1 from the local communication key pool. ′ Using the first communication decryption key Kcb1 ′ Decrypt the ciphertext REG' to obtain the registration information reg. Extract the application identifier ser from the plaintext registration information reg and use it as the key1 value for this application. Note that the key1 value is unique for each application and is used to distinguish different service instances or versions. Figure 3As shown, corresponding to the key1 value, service center 2 allocates memory space and disk space from its local total memory and disk space to store registration information reg (excluding application identifier ser) and other information (IP information, port information, device identity ID, etc. of service provider 3). This other information is stored as the first metadata value1. In this embodiment of the invention, metadata is stored in both total memory and disk space. Specifically, the first metadata value1 is stored in memory space in real time to support the current service registration and discovery process. At the same time, the first metadata value1 is persistently stored in disk space to ensure that it can still be called by the running program and the service state can be restored after the device is initialized due to power failure or restart.

[0061] Step 3: Service Center 2 notifies Key Provider 1 to generate a business encryption key K and sends it to Service Provider 3. Service Provider 3 uses the business encryption key K to encrypt the business service information and saves the key to obtain the encrypted business service information ciphertext URI.

[0062] Specifically, Service Center 2, based on the size of the business service information provided by the application, notifies Key Provider 1 to send a business encryption key K to Service Provider 3. Key Provider 1 responds to the request, obtains a business encryption key K of the same length as the business service information from its local storage, and sends it to Service Provider 3. Service Provider 3 uses the received business encryption key K to fully encrypt the business service information, obtaining the encrypted business service information, denoted as the encrypted URI of the business service information. Service Provider 3 stores the business encryption key K. It should be noted that the business service information may include at least one of the following: the business service protocol, version number, and operating environment information.

[0063] Corresponding to step 2-1, if the application provides multiple business services, service center 2 will notify key provider 1 to provide multiple business encryption keys based on the size of each business service information. For example, service center 2 notifies key provider 1 to provide a first business encryption key based on the size of the first business service information, ..., and notifies key provider 1 to provide an nth business encryption key based on the size of the nth business service information. After the service provider 3 performs the encryption operation, the encrypted ciphertext URI1 of the first business service information, ..., the ciphertext URIN of the nth business service information are obtained.

[0064] In an embodiment of the present invention, the service center 2 may also have a key forwarding service registered, which can obtain the business encryption key K from the key provider 1 and forward the business key to the service provider 3.

[0065] Step 4: Service Center 2 authenticates the device identity ID of Service Provider 3. After successful authentication, the encrypted URI of the business service information is stored in the storage space allocated in Step 2, thus completing the business service registration process.

[0066] In this step, the specific process by which service center 2 authenticates the device identity ID of service provider 3 includes:

[0067] (b1): Service provider 3 selects a key from the local communication key pool as the fourth communication encryption key Kcb4, and records the fourth key index idx-Kcb4 of the fourth communication encryption key Kcb4; using the fourth communication encryption key Kcb4, it encrypts the combination of the business service information ciphertext URI, application identifier ser, business identifier busi, and device identity ID of service provider 3 to generate the second information Mes2 in ciphertext form, and sends the second information Mes2 and the fourth key index idx-Kcb4 to service center 2;

[0068] (b2): Service Center 2 uses the key index idx-Kcb4 ′ The fourth communication decryption key, Kcb4, was obtained from the local communication key pool. ′ Use the fourth communication decryption key Kcb4 ′ After decrypting the information Mes2', the application identifier ser' and the device identity ID of the service provider 3' are obtained, and the application identifier ser' and the device identity ID' are authenticated.

[0069] The authentication method in step (b2) includes: searching in the local storage space of service center 2 to see if the application identifier ser' and device identity ID' are stored simultaneously. If they are, the authentication is successful; if not, the authentication fails, and the service provider 3 is notified of the business registration failure.

[0070] After Service Center 2 successfully authenticates the device identity ID of Service Provider 3, it stores the decrypted service identifier busi as the unique key value key2 and the encrypted service information URI as the second metadata value2 in the memory and disk space allocated in step 2. This completes the service registration process. The mapping between the stored key value and metadata is as follows: Figure 4 As shown.

[0071] In an embodiment of the present invention, the service discovery operation refers to the interaction between the service caller 4 and the service center 2 when the service caller 4 needs to call a service, by querying the service center 2 to obtain the business service information of the service provider 3. The specific process of the service discovery operation includes:

[0072] (c1): Service caller 4 selects a key from the local communication key pool as the fifth communication encryption key Kdb1, and records the fifth key index idx-Kdb1 of the fifth communication encryption key Kdb1; it uses the fifth communication encryption key Kdb1 to identify the application identifier ser to be called. ″ Encrypting the business identifier busi″ yields the second ciphertext REQ = (ser ″ ,busi″)⊕Kdb1, send the second ciphertext REQ and the fifth index idx-Kdb1 to service center 2 for subsequent queries;

[0073] (c2): Service Center 2 based on the received key index idx-Kbd1 ′ The fifth communication decryption key Kbd1 is obtained from the local communication key pool. ′ Using the fifth communication decryption key Kbd1′, the ciphertext REQ′ is decrypted to obtain the application identifier ser. ″ The system checks if a key-value pair, along with the business identifier "busi", is stored in the local storage space and matches it with the application identifier "ser". ″ If the business identifier "busi" exists, the metadata corresponding to the key value will be sent to service caller 4. If it does not exist, the business service discovery failure will be reported to service caller 4, and the discovery process will end.

[0074] (c3): Service caller 4 finds service provider 3 based on the content of the first metadata value1 in the received metadata, and sends a call request req to service provider 3. The call request req includes the second metadata value2 in the metadata.

[0075] (c4): Service provider 3 responds to the call request req, compares the second metadata value2 in the received call request req with the encrypted URI of the business service information stored locally. If they match, it obtains the business encryption key K from the local storage to decrypt the encrypted URI and provides the decrypted business service information to service caller 4 for subsequent calls.

[0076] Before step (c1), service center 2 can also authenticate the identity of service caller 4 to ensure that service caller 4 is a legitimate user. The authentication process is similar to that in step 2 and will not be described again here. At this time, service center 2 retains the identity information of service caller 4. Correspondingly, in step (c3), the call request req also includes the identity information of service caller 4. In step (c4), service provider 3 can also respond to the call request req and authenticate the identity of service caller 4. The authentication process may involve sending the identity information of service caller 4 to service center 2, where service center 2 compares the identity information with the previously authenticated identity information of service caller 4. If they match, the authentication is successful; otherwise, the authentication fails, and service provider 3 refuses to provide services to service caller 4.

Claims

1. A method for registering and discovering communication services, characterized in that, The participants in the method include: a key provider, a service center, a service provider, and a service caller; the method includes the following steps: Step 1: The key provider pre-configures communication keys for the service center, the service provider, and the service caller; among them, the service center has symmetric keys with the service provider and the service caller respectively; Step 2: The service center authenticates the service provider based on the service provider's registration information (reg). If the authentication is successful, the service center obtains the service provider's registration information (reg) and allocates storage space to the service provider; otherwise, it records the authentication failure information and the service provider re-initiates the authentication process. Step 3: The service center notifies the key provider to generate a business encryption key K and sends it to the service provider. The service provider uses the business encryption key K to encrypt the business service information and saves the key to obtain the encrypted business service information ciphertext URI. Step 4: The service center authenticates the device identity ID of the service provider. After successful authentication, the encrypted URI of the business service information is stored in the storage space allocated in Step 2, thus completing the business service registration process. Step 5: After registration is complete, the service caller requests the service center to perform a service discovery operation.

2. The communication service registration and discovery method according to claim 1, characterized in that, Step 2 specifically includes: Step 2-1: The service provider selects a key from its local communication key pool as the first communication encryption key Kcb1 and records the first key index idx-Kcb1 of the first communication encryption key Kcb1; the service provider uses the first communication encryption key Kcb1 to encrypt the registration information reg to obtain the first ciphertext REG; the registration information reg includes at least one of the following: the service provider's IP information, port information, device identity ID, application identifier ser, and the business service information and size provided by the application. Step 2-2: The service provider generates an irreducible polynomial p1(x) locally, and records the string consisting of the coefficients of each term in the irreducible polynomial p1(x) except for the highest term as str1; the service provider obtains the second communication key Kcb2 from the local communication key pool as the input random number, and records the second key index idx-Kcb2; a hash function is generated using the irreducible polynomial p1(x) and the second communication key Kcb2. Input the first ciphertext REG and the first key index idx-Kcb1 into the hash function. Get the first hash value Steps 2-3: The service provider selects a key from its local communication key pool as the third communication encryption key Kcb3 and records the third key index idx-Kcb3 of this third communication encryption key Kcb3; it uses the third communication encryption key Kcb3 to encrypt the string str1, the first ciphertext REG, the first key index idx-Kcb1 and the second key index idx-Kcb2, and the first hash value H1 to generate the first message Mes1 in ciphertext form. The first message Mes1 and the third key index idx-Kcb3 are sent to the service center. The service center performs tamper-proof authentication on the received first message Mes1. If the authentication is successful, the registration information reg is obtained and storage space is allocated to the service provider; otherwise, the authentication fails and the service provider re-initiates the authentication.

3. The communication service registration and discovery method according to claim 2, characterized in that, In steps 2-3, the tamper-proof identity authentication includes: (a1): The service center receives information Mes1' and key index idx-Kcb3 ′ According to the key index idx-Kcb3 ′ Obtain the third communication decryption key Kcb3' from the local communication key pool, and use the third communication decryption key Kcb3' to perform a decryption operation on the message Mes1' to obtain the string str1', the ciphertext REG', and the communication decryption key index idx-Kcb1. ′ and key index idx-Kcb2 ′ and the hash value H1'; (a2): The service center uses the key index idx-Kcb2 ′ Obtain the communication key Kcb2' from the local communication key pool, generate an irreducible polynomial p′1(x) based on the string str1′, and then generate a hash function based on the irreducible polynomial p′1(x) and the communication key Kcb2'. (a3): The service center will store the ciphertext REG' and the communication decryption key index idx-Kcb1 ′ Input hash function Obtain the second hash value The hash value H1' obtained from decryption is compared with the second hash value H2. If they match, the authentication is successful; otherwise, the authentication fails, and the service provider re-initiates the authentication process.

4. The communication service registration and discovery method according to claim 3, characterized in that, In steps 2-3, obtaining the registration information (reg) and allocating storage space for the service provider specifically includes: After successful authentication by the service center, the service center uses the communication decryption key index idx-Kcb1. ′ Obtain the first communication decryption key Kcb1' from the local communication key pool, use the first communication decryption key Kcb1' to decrypt the ciphertext REG', obtain the registration information reg, extract the application identifier ser from the registration information reg as the unique key value key1 of the application; the service center allocates a storage space from the local total memory and disk space, and stores the other information of the registration information reg except for the application identifier ser as the first metadata value1 into the storage space.

5. The communication service registration and discovery method according to claim 2, characterized in that, Step 3 specifically includes: The service center notifies the key provider to send a business encryption key K to the service provider based on the size of the business service information provided by the application. In response to the request, the key provider obtains a business encryption key K of the same length as the business service information from its local machine and sends it to the service provider. The service provider receives and stores the business encryption key K, and at the same time uses the business encryption key K to encrypt the entire business service information to obtain the encrypted business service information ciphertext URI.

6. The communication service registration and discovery method according to claim 4, characterized in that, In step 4, the service center authenticates the device identity ID of the service provider, specifically including: (b1): The service provider selects a key from the local communication key pool as the fourth communication encryption key Kcb4, and records the fourth key index idx-Kcb4 of the fourth communication encryption key Kcb4; it uses the fourth communication encryption key Kcb4 to encrypt the combination of the business service information ciphertext URI, application identifier ser, business identifier busi, and the service provider's device identity ID to generate the second information Mes2 in ciphertext form, and sends the second information Mes2 and the fourth key index idx-Kcb4 to the service center; (b2): The service center uses the key index idx-Kcb4 ′ The fourth communication decryption key Kcb4' is obtained from the local communication key pool. After decrypting the information Mes2' using the fourth communication decryption key Kcb4', the application identifier ser' and the device identity ID of the service provider ser' are obtained. The application identifier ser' and the device identity ID ser' are then used for authentication. The service center searches its local storage space to see if the application identifier ser' and device identity ID' are already stored simultaneously. If they are, the authentication is successful; otherwise, the authentication fails, and the service provider is notified that the business registration failed.

7. The communication service registration and discovery method according to claim 6, characterized in that, In step 4, storing the encrypted URI of the business service information in the storage space allocated in step 2 means: After the service center authenticates the device identity ID of the service provider, it will use the decrypted business identifier busi as the unique key value key2 and the encrypted business service information URI as the second metadata value2 in the storage space allocated in step 2.

8. The communication service registration and discovery method according to claim 7, characterized in that, In step 5, the service discovery operation includes: (c1): The service caller selects a key from the local communication key pool as the fifth communication encryption key Kdb1, and records the fifth key index idx-Kdb1 of the fifth communication encryption key Kdb1; it uses the fifth communication encryption key Kdb1 to identify the application ser. ″ Encrypting the business identifier busi″ yields the second ciphertext REQ = (ser ″ ,busi″)⊕Kdb1, send the second ciphertext REQ and the fifth index idx-Kdb1 to the service center; (c2): The service center obtains the fifth communication decryption key Kbd1′ from the local communication key pool based on the received key index idx-Kdb1′, and uses the fifth communication decryption key Kbd1′ to decrypt the ciphertext REQ' to obtain the application identifier ser. ″ The key-value pair, along with the business identifier "busi", is used to query the local storage space to see if it contains a key-value pair that is also matched with the application identifier "ser". ″ Corresponding to the business identifier "busi", if it exists, the metadata stored corresponding to this key value will be sent to the service caller; if it does not exist, the service caller will be informed of the failure of business service discovery, and the discovery process will end. (c3): The service caller finds the service provider based on the content of the first metadata value1 in the received metadata, and initiates a call request req to the service provider. The call request req includes the second metadata value2 in the metadata. (c4): The service provider responds to the call request req and compares whether the second metadata value2 in the received call request req is consistent with the encrypted URI of the business service information stored locally. If they are consistent, the service provider obtains the business encryption key K from the local storage, decrypts the encrypted URI of the business service information, and provides the decrypted business service information to the service caller for invocation.