Access authentication method and spatial information network system based on web3.0 of blockchain

By dynamically adapting the access process using access time intervals and credit levels in the Web3.0 spatial information network, and by using historical session keys or conducting two-way authentication, the problems of low user access efficiency and excessive computing power consumption are solved, thus realizing an efficient and secure access mechanism.

CN121531363BActive Publication Date: 2026-05-08CHINA ACADEMY OF INFORMATION & COMM
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA ACADEMY OF INFORMATION & COMM
Filing Date
2026-01-08
Publication Date
2026-05-08

AI Technical Summary

Technical Problem

In the spatial information network of Web3.0, the authentication process for each user access leads to inefficiency and excessive consumption of network computing resources.

Method used

By combining the access time interval and credit level of mobile users, the access process is dynamically adapted. When the preset fast access conditions are met, the historical session key is used for direct interaction. When the conditions are not met, two-way trust verification is performed to generate a session key.

Benefits of technology

It significantly reduces the computational overhead of repeated verification, improves access efficiency, takes into account the convenience of high-frequency compliant users, and reduces the ineffective use of network computing power, thus achieving a balance between security protection and access efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121531363B_ABST
    Figure CN121531363B_ABST
Patent Text Reader

Abstract

The present disclosure provides a blockchain-based Web3.0 access authentication method and a spatial information network system. A first satellite access node determines an access time interval. When the access time interval and the credit level of a mobile user both satisfy a preset fast access condition, the mobile user and the spatial information network system interact based on a historical session key. When the access time interval and / or the credit level of the mobile user does not satisfy the preset fast access condition, the first satellite access node and the mobile user perform two-way trust verification. When the mobile user and the first satellite access node both pass the trust verification, the client and the first consensus ground node obtain a session key. Thus, the access convenience of high-frequency compliant users is considered, and the invalid occupation of network computing power is reduced through differentiated verification strategies, achieving a balance between spatial information network security protection and access efficiency, and computing power optimization.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to Web3.0 technology, blockchain technology, and in particular to a blockchain-based Web3.0 access authentication method and spatial information network system. Background Technology

[0002] Web3.0, as the third major evolutionary stage of the internet, is characterized by its reliance on blockchain, decentralized technology, and smart contracts. Spatial Information Networks (SINs), built using space platforms such as satellites and aircraft, are three-dimensional communication networks. With their global geographic coverage and highly dynamic topology, they have become a crucial application scenario for the Web3.0 ecosystem. In related technologies, to ensure the security of data transmission and interaction, users must complete two-way authentication with network nodes based on their digital identity certificates each time they access the spatial information network. This mechanism requires both the user and network sides to perform numerous authentication-related calculations each time a user connects, significantly reducing the efficiency of user access to the spatial information network and causing excessive consumption of network computing resources. Summary of the Invention

[0003] To address the aforementioned technical issues, this disclosure provides a blockchain-based Web3.0 access authentication method and a spatial information network system.

[0004] One aspect of this disclosure provides a blockchain-based Web3.0 access authentication method applied to a space information network system. The space information network system includes a terrestrial blockchain network and an inter-satellite blockchain network. The terrestrial blockchain network includes multiple ordinary ground nodes and multiple consensus ground nodes. The inter-satellite blockchain network includes multiple satellite access nodes. The method includes: in response to receiving an access request for a mobile user sent by a client, a first satellite access node determines an access time interval based on the historical access time information of the mobile user's last access to the space information network system and the current time, wherein the first satellite access node is one of the multiple satellite access nodes; in response to the access request... If both the time interval and the mobile user's credit rating meet the preset fast access conditions, the mobile user and the space information network system interact based on the historical session key from their previous access to the space information network system. If the access time interval and / or the mobile user's credit rating do not meet the preset fast access conditions, the first satellite access node and the mobile user perform bidirectional trust verification. If both the mobile user and the first satellite access node pass the trust verification, the client and the first consensus ground node respectively obtain a session key, enabling the mobile user to interact with the space information network system based on the session key. The first consensus ground node is one of the plurality of consensus ground nodes.

[0005] Another aspect of this disclosure provides a Web3.0-based spatial information network system, comprising a terrestrial blockchain network and an inter-satellite blockchain network. The terrestrial blockchain network includes multiple ordinary ground nodes and multiple consensus ground nodes, and the inter-satellite blockchain network includes multiple satellite access nodes. A first satellite access node is configured to, in response to receiving an access request from a client for a mobile user, determine an access time interval based on the mobile user's previous access time to the spatial information network system and the current time; in response to both the access time interval and the mobile user's credit rating meeting preset fast access conditions, the mobile user interacts with the spatial information network system based on the historical session key of the previous access to the spatial information network system; in response to the access time interval and / or the mobile user's credit rating meeting preset fast access conditions, the mobile user interacts with the spatial information network system based on the historical session key of the previous access to the spatial information network system; and in response to the access time interval and / or the mobile user's credit rating meeting preset fast access conditions, the first satellite access node is configured to, in response to the previous access time interval and / or the mobile user's credit rating meeting preset fast access conditions, interact with the spatial information network system based on the historical session key of the previous access to the spatial information network system. If the user's credit rating does not meet the preset fast access conditions, the client undergoes trustworthiness verification. The first satellite access node is one of the plurality of satellite access nodes. A first consensus ground node is used to obtain a session key in response to both the mobile user and the first satellite access node passing the trustworthiness verification, so that the mobile user can interact with the space information network system based on the session key. The first consensus ground access node is one of the plurality of consensus ground nodes. The client is used to perform trustworthiness verification on the first satellite access node in response to the access time interval and / or the mobile user's credit rating not meeting the preset fast access conditions. In response to both the mobile user and the first satellite access node passing the trustworthiness verification, the client obtains a session key in response to both the mobile user and the first satellite access node passing the trustworthiness verification, so that the mobile user can interact with the space information network system based on the session key.

[0006] In another aspect of this disclosure, an electronic device is provided, comprising: a memory for storing a computer program; and a processor for executing the computer program stored in the memory, wherein when the computer program is executed, it implements the method described above.

[0007] In another aspect of this disclosure, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the method described above.

[0008] Based on the embodiments of this disclosure, by dynamically adapting the access process by combining the access time interval and credit level of mobile users, when both the access time interval and credit level meet the preset fast access conditions, direct interaction can be achieved based on historical session keys, which greatly reduces the computational overhead of repeated verification and improves access efficiency. When the fast access conditions are not met, a session key is generated to ensure security after bidirectional trust verification between the mobile user and the satellite access node. This approach takes into account both the access convenience of high-frequency compliant users and reduces the ineffective use of network computing power through differentiated verification strategies, thus achieving a balance between space information network security protection and access efficiency and computing power optimization.

[0009] The technical solutions of this disclosure will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description

[0010] The accompanying drawings, which form part of this specification, illustrate embodiments of this disclosure and, together with the description, serve to explain the principles of this disclosure.

[0011] This disclosure will become clearer with reference to the accompanying drawings and the following detailed description, wherein:

[0012] Figure 1 This is a schematic diagram of the structure of a spatial information network system provided in an embodiment of the present disclosure;

[0013] Figure 2 This is a schematic flowchart of a blockchain-based Web3.0 access authentication method provided in an exemplary embodiment of this disclosure;

[0014] Figure 3 This is a schematic flowchart of a blockchain-based Web3.0 access authentication method provided in another exemplary embodiment of this disclosure;

[0015] Figure 4 This is a flowchart illustrating step S100 provided in an exemplary embodiment of this disclosure;

[0016] Figure 5 This is a flowchart illustrating step S120 provided in an exemplary embodiment of this disclosure;

[0017] Figure 6 This is a flowchart illustrating step S124 provided in an exemplary embodiment of this disclosure;

[0018] Figure 7 This is a flowchart illustrating step S125 provided in an exemplary embodiment of this disclosure;

[0019] Figure 8 This is a flowchart illustrating step S130 provided in an exemplary embodiment of this disclosure;

[0020] Figure 9This is a structural block diagram of a Web3.0-based spatial information network system based on blockchain, provided in an exemplary embodiment of this disclosure.

[0021] Figure 10 This is a schematic diagram of the structure of an application embodiment of the electronic device disclosed herein. Detailed Implementation

[0022] Various exemplary embodiments of the present disclosure will now be described in detail with reference to the accompanying drawings. It should be noted that, unless otherwise specifically stated, the relative arrangement, numerical expressions, and values ​​of the components and steps set forth in these embodiments do not limit the scope of the present disclosure.

[0023] Those skilled in the art will understand that the terms "first," "second," etc., in the embodiments of this disclosure are only used to distinguish different steps, devices, or modules, and do not represent any specific technical meaning, nor do they indicate a necessary logical order between them.

[0024] It should also be understood that in the embodiments disclosed herein, "a plurality of" may refer to two or more, and "at least one" may refer to one, two or more.

[0025] It should also be understood that any component, data or structure mentioned in the embodiments of this disclosure can generally be understood as one or more unless expressly defined or given to the contrary in the context.

[0026] Furthermore, the term "and / or" in this disclosure is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this disclosure generally indicates that the preceding and following related objects have an "or" relationship.

[0027] It should also be understood that the description of the various embodiments in this disclosure emphasizes the differences between the various embodiments, and the similarities or similarities can be referred to each other. For the sake of brevity, they will not be described in detail.

[0028] At the same time, it should be understood that, for ease of description, the dimensions of the various parts shown in the accompanying drawings are not drawn according to actual scale.

[0029] The following description of at least one exemplary embodiment is merely illustrative and is in no way intended to limit this disclosure or its application or use.

[0030] Techniques, methods, and equipment known to those skilled in the art may not be discussed in detail, but where appropriate, such techniques, methods, and equipment should be considered part of the specification.

[0031] It should be noted that similar labels and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be discussed further in subsequent figures.

[0032] The embodiments disclosed herein can be applied to electronic devices such as terminal devices, computer systems, and servers, and can operate together with a wide range of other general-purpose or special-purpose computing system environments or configurations. Examples of well-known terminal devices, computing systems, environments, and / or configurations suitable for use with electronic devices such as terminal devices, computer systems, and servers include, but are not limited to: personal computer systems, server computer systems, thin clients, thick clients, handheld or laptop devices, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputer systems, mainframe computer systems, and distributed cloud computing environments including any of the above systems, etc.

[0033] Electronic devices such as terminal devices, computer systems, and servers can be described in the general context of computer system executable instructions (such as program modules) executed by a computer system. Typically, program modules can include routines, programs, object programs, components, logic, data structures, etc., which perform specific tasks or implement specific abstract data types. Computer systems / servers can be implemented in distributed cloud computing environments, where tasks are executed by remote processing devices linked through communication networks. In distributed cloud computing environments, program modules can reside on local or remote computing system storage media, including storage devices.

[0034] In the embodiments disclosed herein:

[0035] Web3.0 (the third generation of the Internet) is a user-centric, trustworthy value Internet built on decentralized technologies such as blockchain. Its core is that users have independent control over their data, identity, and assets, and the network architecture is decentralized, allowing value to flow freely.

[0036] In a narrow sense, blockchain technology can be defined as a chain-like data structure that combines data blocks sequentially in chronological order, creating a distributed ledger that is cryptographically guaranteed to be immutable and unforgeable. In a broader sense, blockchain technology can utilize a chain-like data structure to verify and store data, node consensus algorithms to generate and update data, cryptographic methods to ensure the security of data transmission and access, and smart contracts composed of automated script code.

[0037] A space information network system is a network system that uses space platforms (such as geostationary satellites or medium and low orbit satellites, stratospheric balloons, manned or unmanned aircraft, etc.) as carriers to acquire, transmit and process information in real time.

[0038] For example, Figure 1 This is a schematic diagram of the structure of a spatial information network system provided in one embodiment of this disclosure. Figure 1 As shown, the space information network system includes a terrestrial network (terrestrial blockchain network) and an inter-satellite network (inter-satellite blockchain network). The terrestrial blockchain network is a blockchain network jointly constructed by multiple ground stations (ordinary ground nodes) and multiple gateway stations (consensus ground nodes). It serves as the trust core and management center of the entire space information network system, responsible for identity registration, key distribution, and global authentication. The basic function of a ground station is to transmit signals to the satellite and simultaneously receive signals relayed from other ground stations via satellite. Gateway stations, as data center nodes in the satellite communication space-ground system, primarily undertake the distribution and collection of satellite communication service data. Gateway stations have a Network Control Center (NCC). The inter-satellite blockchain network includes an inter-satellite distributed evidence storage cluster (blockchain network) composed of multiple Satellite Access Points (SAPs). It is responsible for verifying access users, relaying data, and transmitting data on the space side. Satellite access points can be, for example, Low Earth Orbit (LEO) satellites.

[0039] Consensus ground nodes participate in the blockchain consensus process and are responsible for the management and control of satellite access nodes, such as the registration, selection, and modification of satellite access nodes. Ordinary ground nodes are responsible for communication relay functions, such as forwarding data transmitted from the space network to the space network. In the space information network system, each consensus ground node communicates with at least one satellite access node. Mobile users (MUs) can access the space information network system using clients deployed on electronic devices, which may include at least one of the following: smartphones, smart cars, ships, airplanes, drones, and IoT devices.

[0040] Figure 2 This is a schematic flowchart illustrating an exemplary embodiment of a blockchain-based Web3.0 access authentication method provided in this disclosure. This embodiment can be applied to spatial information network systems, such as... Figure 2 As shown, this blockchain-based Web3.0 access authentication method may include the following steps:

[0041] In step S100, in response to receiving an access request for a mobile user from a client, the first satellite access node determines the access time interval based on the historical access time information of the mobile user's last access to the space information network system and the current time.

[0042] The space information network system includes a terrestrial blockchain network and an inter-satellite blockchain network. The terrestrial blockchain network includes multiple ordinary ground nodes and multiple consensus ground nodes; the inter-satellite blockchain network includes multiple satellite access nodes. The first satellite access node is one of these multiple satellite access nodes. The client can be deployed, for example, in the mobile user's electronic device. The client communicates with the satellite access nodes. For example, the client communicates with the first satellite access node. The historical access time information of the last time the mobile user accessed the space information network system can be understood as the time since the mobile user last accessed the space information network system through the client.

[0043] For example, the blockchain corresponding to the inter-satellite blockchain network stores a mobile user access information table, which includes the time information of each time the mobile user accesses the space information network. When a mobile user needs to access the space information network system, the mobile user generates an access request on the client and sends the access request to the first satellite access node. When the first satellite access node receives the access request, it retrieves the mobile user's access information table from the blockchain corresponding to the inter-satellite blockchain network, then determines the historical access time information of the last access to the space information network system from the mobile user's access information table, and determines the absolute value of the difference between the historical access time information and the current time information as the access time interval.

[0044] In step S110, in response to the fact that both the access time interval and the mobile user's credit level meet the preset fast access conditions, the mobile user interacts with the spatial information network system based on the historical session key of the last access to the spatial information network system.

[0045] In this embodiment, the session key generated when the mobile user last accessed the space information network system is referred to as the historical session key. Both the client and the corresponding blockchain of the terrestrial blockchain network store the session key generated each time the mobile user accesses the space information network system.

[0046] For example, the blockchain corresponding to the inter-satellite blockchain network stores preset time intervals, preset credit levels, and mobile user credit levels. The first satellite access node obtains the preset time intervals, preset credit levels, and mobile user credit levels from the blockchain corresponding to the inter-satellite blockchain network. If it is determined that the access time interval does not exceed the preset time interval, it is determined that the access time interval meets the preset fast access conditions; if it is determined that the access time interval exceeds the preset time interval, it is determined that the access time interval does not meet the preset fast access conditions. Similarly, if the mobile user's credit level exceeds the preset credit level, it is determined that the mobile user's credit level meets the preset fast access conditions; if the mobile user's credit level does not exceed the preset credit level, it is determined that the mobile user's credit level does not meet the preset fast access conditions.

[0047] In step S120, in response to the access time interval and / or the mobile user's credit rating not meeting the preset fast access conditions, the first satellite access node and the mobile user perform bidirectional trustworthiness verification.

[0048] The two-way trustworthiness verification between the first satellite access node and the mobile user may include: the first satellite access node performing feasibility verification on behalf of the mobile user, and the mobile user performing trustworthiness verification on behalf of the first satellite node.

[0049] In this embodiment of the disclosure, steps S110 and S120 are not executed in any particular order.

[0050] In step S130, in response to the mobile user and the first satellite access node both passing the trust verification, the client and the first consensus ground node respectively obtain the session key, so that the mobile user and the space information network system can interact based on the session key.

[0051] The first consensus ground node is one of multiple consensus ground nodes. The mobile user and the first consensus ground node can obtain a session key using any session key generation method. For example, the first consensus ground node can generate and store a random number as the session key, and the first consensus ground node can send the session key to the client through the first satellite access node, whereby the client receives and stores the session key. If the mobile user fails the trust verification and / or the first satellite access node fails the trust verification, the operation terminates, and the client is not allowed to access the space information network system.

[0052] In one implementation, interaction between a mobile user and a space information network system may include, for example, the following: when a mobile user requests access to resources within the space information network system or communicates with other users through the space information network system, the client and the first consensus ground node can establish a secure channel in the first satellite access node using a session key, and interact based on this secure channel. Specifically, on the client side, plaintext interaction data (e.g., temperature = 25°C) and the session key are input into a symmetric encryption algorithm. The symmetric encryption algorithm outputs ciphertext, which the client sends to the first satellite access node. The first satellite access node receives the ciphertext and sends it to the first consensus ground node. At the first consensus ground node, the session key and the ciphertext are input into the symmetric encryption algorithm, which outputs plaintext interaction data. The first consensus ground node can generate response data for the interaction data and, using the aforementioned encryption and data transmission method, send the response data to the client. The symmetric encryption algorithm may, for example, be Advanced Encryption Standard - Galois / Counter Mode (AES-GCM) or SM4 Block Cipher Algorithm.

[0053] In this embodiment, by combining the access time interval and credit level of mobile users to dynamically adapt the access process, when both the access time interval and credit level meet the preset fast access conditions, direct interaction can be achieved based on historical session keys, which greatly reduces the computational overhead of repeated verification and improves access efficiency. When the fast access conditions are not met, a session key is generated to ensure security after bidirectional trust verification between the mobile user and the satellite access node. This approach takes into account the access convenience of high-frequency compliant users and reduces the ineffective use of network computing power through differentiated verification strategies, thus achieving a balance between space information network security protection and access efficiency and computing power optimization.

[0054] In some optional implementations, the step between step S100 and step S110 in this embodiment may further include: in response to the access time interval not exceeding the preset time interval, determining that the access time interval meets the preset fast access conditions, generating a fast access request, and sending the fast access request to the first consensus ground node, the first consensus ground node determining the credit level of the mobile user based on the blockchain identity, and determining that the credit level of the mobile user meets the preset fast access conditions when the credit level of the mobile user exceeds the preset credit level.

[0055] The fast access request includes the mobile user's blockchain identity, which is used to identify the mobile user. When a mobile user registers for the spatial information network system, a consensus ground node issues a blockchain identity to the mobile user, who then stores this identity on their client. For example, any consensus ground node generates n random numbers and selects the q-th random number. Based on the formula Generate blockchain identity for mobile users , User identifier representing a mobile user A pre-defined hash function (e.g., SHA-1 (Secure Hash Algorithm-1)) for consensus ground nodes.

[0056] In one embodiment, the blockchain storage corresponding to the inter-satellite blockchain network has a preset time interval, and the blockchain storage corresponding to the terrestrial blockchain network has a preset credit rating and the credit rating of the mobile user. The mobile user's credit rating is bound to the mobile user's blockchain identity.

[0057] The first satellite access node can obtain a preset time interval from the blockchain corresponding to the inter-satellite blockchain network, calculate the access time interval, and if it is determined that the access time interval exceeds the preset time interval, it is determined that the access time interval does not meet the preset fast access conditions, and execute step S120. If it is determined that the access time interval does not exceed the preset time interval, it is determined that the access time interval meets the preset fast access conditions, generates a fast access request, and sends the fast access request to the first consensus ground node. The first consensus ground node obtains a preset credit level from the blockchain corresponding to the ground blockchain network, and obtains the mobile user's credit level based on the blockchain identity. If it is determined that the mobile user's credit level does not exceed the preset credit level, it is determined that the mobile user's credit level does not meet the preset fast access conditions, and execute step S120. If it is determined that the mobile user's credit level exceeds the preset credit level, it is determined that the mobile user's credit level meets the preset fast access conditions, triggers the smart contract in the first consensus ground node, generates a fast access message, and sends the fast access information to the client through the first satellite access node, so that the mobile user and the space information network system can interact based on the historical session key of the last access to the space information network system.

[0058] In some optional implementations, in embodiments of this disclosure, the client stores system parameters of the spatial information network system and the mobile user's public-private key pair. The system parameters include: base point data, a first secure hash function, a second secure hash function, and a third secure hash function.

[0059] The system parameters are stored in both the terrestrial blockchain network and the inter-satellite blockchain network. The client stores the mobile user's public-private key pair. Each consensus ground node stores its own public-private key pair, which includes a public key and a private key.

[0060] In one embodiment, the system parameters further include elliptic curve parameters. Elliptic curve parameters include: prime region F P and elliptic curve E P (a,b) and base point G. Prime field F P A finite field containing p elements, where p is a large prime number; for example, p can be a 256-bit or 512-bit large prime number. Elliptic curve E P (a,b) represents the region in the finite field F. P The elliptic curve is defined above, where a and b are the curve coefficients of the elliptic curve, satisfying 4a 3 +27b 2 ≠ 0 mod p, where the base point G is a specific point on the elliptic curve, serving as the generator for the key. The cyclic subgroup generated by the base point G has a large prime order. The order of the cyclic subgroup is the size (number of elements) of the cyclic subgroup generated by the base point G, typically a large prime number, defining the range of values ​​for the private key. The base point G in the elliptic curve parameters is determined as the base point data. Standard elliptic curve parameters can be selected, such as those used in national cryptographic algorithms (e.g., the curve parameters specified in SM2 (Elliptic Curve Public Key Cryptography), Curve25519, and Curve448.

[0061] The first secure hash function H1, the second secure hash function H2, and the third secure hash function H3 are used to map inputs of arbitrary length to outputs (hash values) of fixed length. H1, H2, and H3 can be any of the following hash functions: SHA-256 (Secure Hash Algorithm-256), SHA-384 (Secure Hash Algorithm-384), SHA-512 (Secure Hash Algorithm-512), SHA-3 (Secure Hash Algorithm-3), and SM3 (China's national commercial cryptographic algorithm). H1, H2, and H3 can be different hash functions.

[0062] The user's public / private key pair includes: public key and private key Public key in user public-private key pair Includes: the first child user's public key Second sub-user public key The private key in the user's public-private key pair Including: First sub-user's private key Second sub-user private key .

[0063] For example, the user's public-private key pair can be generated by the client and any consensus ground node. The client and any consensus ground node can use Certificateless Public Key Cryptography (CL-PKC) generation technology to generate the user's public-private key pair. Alternatively,

[0064] Multiple assisting nodes are selected from among the consensus ground nodes. Each assisting node generates a key fragment and sends each key fragment to the client. The client adds up the key fragments to obtain the user secret value, and then uses this user secret value as the first sub-user's private key. Then utilize Determine the public key of the first sub-user The first sub-user's public key is sent to any consensus ground node, and any consensus ground node generates a random number as the first node's random number. Based on the first node's random number and the base point data, using the formula Determine user random commitment data Using the formula Generate a second sub-user's private key , This refers to the private key in the public-private key pair of any consensus ground node. For mobile users' user identifiers, For each user's timestamp (the moment the first child user's public key is sent), the second child user's private key and user random commitment data are sent to the client. On the client side, based on the formula... Generate the second sub-user's public key ,based on Generate the public key in the user's public-private key pair ,based on Generate the private key in the user's public-private key pair .

[0065] Correspondingly, Figure 3 This is a schematic flowchart illustrating a blockchain-based Web3.0 access authentication method provided in another exemplary embodiment of this disclosure. In some alternative implementations, such as... Figure 3 As shown, the client generates an access request in the following way:

[0066] Step S200: Generate a user random number, a user timestamp, and a request message, and generate a user temporary public key based on the base point data and the user random number.

[0067] The user timestamp includes the moment when the user's random number was generated.

[0068] In one embodiment, on the client side: generating user random numbers. User timestamp and request message Based on the formula Generate user temporary public key .

[0069] Step S210: Based on the mobile user's blockchain identity, user public-private key pair, user temporary public key, user timestamp, and request message, the user's core parameters are generated using a preset algorithm through the first secure hash function, the second secure hash function, and the third secure hash function.

[0070] Among them, on the client side, based on the formula , , Generate user intermediate hash value , and Then based on the formula Generate partial user signatures Based on the formula Generate user core parameters .

[0071] Step S220: Use the private key in the user's public-private key pair to sign the user authentication information to obtain signed user authentication information.

[0072] The user authentication information includes: core user parameters and basic user information. The basic user information includes: temporary public key, blockchain identity, request message, user timestamp, and node identifier of the first satellite access node.

[0073] Step S230: Generate an access request based on the signed user authentication information.

[0074] The access request includes signed user authentication information. The client sends the access request to the first satellite access node.

[0075] Figure 4 This is a flowchart illustrating step S100 provided in an exemplary embodiment of this disclosure. In some alternative embodiments, such as Figure 4 As shown, step S100 may include the following steps:

[0076] Step S101: Use the public key in the user's public-private key pair to verify the signature of the user authentication information.

[0077] The access request includes the user's authentication information. The blockchain corresponding to the inter-satellite blockchain network stores the public key from the mobile user's public-private key pair.

[0078] For example, the first satellite access node obtains the public key from the user's public-private key pair from the blockchain corresponding to the inter-satellite blockchain network, and uses the public key from the user's public-private key pair to verify the signature of the user authentication information. If the signature verification fails, the operation of the mobile user accessing the space information network system ends.

[0079] Step S102: When the signed user authentication information passes the signature verification, the user authentication information is obtained.

[0080] Step S103: Determine the delay information of the access request based on the user's timestamp and the current time.

[0081] The delay information can include a time difference, which can be determined by the absolute value of the difference between the user's timestamp and the current time.

[0082] Step S104: In response to the delay information meeting the preset delay condition, determine the access time interval.

[0083] Specifically, if the time difference in the delay information is less than the preset time difference, it is determined that the delay information meets the preset delay condition, and then the access time interval is determined; if the time difference in the delay information is greater than or equal to the preset time difference, it is determined that the delay information does not meet the preset delay condition, and the operation of the mobile user accessing the spatial information network system is terminated.

[0084] Figure 5 This is a flowchart illustrating step S120 provided in an exemplary embodiment of this disclosure. In some alternative embodiments, such as Figure 5 As shown, step S120 may include the following steps:

[0085] Step S121: The first satellite access node verifies the legitimacy of the mobile user based on the user authentication information.

[0086] In one implementation, verifying the legitimacy of a mobile user may include:

[0087] S1 generates a user verification public key based on user basic information, user core parameters, and system parameters using a preset algorithm.

[0088] Among them, the first satellite access node is generated. , and Then use the formula Generate user authentication public key .

[0089] S2, in response to the user's temporary public key matching the user's verification public key, confirms that the mobile user has passed the legitimacy verification.

[0090] Among them, at the first satellite access node: determined and If the results are equal, the mobile user is deemed to have passed the legitimacy verification; otherwise, the mobile user is deemed to have failed the legitimacy verification, and the operation ends.

[0091] Step S122: In response to the mobile user passing the legitimacy verification, the first consensus ground node determines the detection result of whether the mobile user is in the access control list based on the blockchain identity.

[0092] The terrestrial blockchain network stores access control lists (ACLs) within its blockchain, which include the blockchain identities of users qualified to access the space information network system. The detection results indicate whether the mobile user is on the ACL or not.

[0093] For example, when a mobile user passes the legitimacy verification, the first satellite access node sends the blockchain identity to the first consensus ground node. The first consensus ground node retrieves the access control list from the blockchain of the surface blockchain network. If the access control list contains the mobile user's blockchain identity, it generates a detection result that includes the mobile user's presence in the access control list. If the access control list does not contain the mobile user's blockchain identity, it generates a detection result that includes the mobile user's absence from the access control list.

[0094] In step S123, in response to the detection result indicating that the mobile user is in the access control list, the first satellite access node determines that the mobile user has passed the trust verification.

[0095] The first consensus ground node sends the detection result to the first satellite access node. When the received detection result indicates that the mobile user is not in the access control list, the first satellite access node determines that the mobile user has failed the trust verification and ends the operation. When it is determined that the mobile user has passed the trust verification, the first satellite access node generates a verification pass message and sends the verification pass message to the first satellite access node. Upon receiving the verification pass message, the first satellite access node executes step S124.

[0096] In step S124, the first satellite access node generates satellite authentication information and sends the satellite authentication information to the client.

[0097] Among them, satellite authentication information is used to prove the trustworthiness of the first satellite access node.

[0098] In step S125, the client verifies the trustworthiness of the first satellite access node based on the satellite authentication information.

[0099] Specifically, when the first satellite access node passes the trustworthiness verification, the client generates a session key and sends trustworthiness verification information back to the first satellite access node. The first satellite access node then sends a notification message to the first consensus ground node to generate the session key. When the first consensus ground node receives the notification message, it generates the session key.

[0100] Figure 6 This is a flowchart illustrating step S124 provided in an exemplary embodiment of this disclosure. In some alternative embodiments, such as Figure 6 As shown, step S124 may include the following steps:

[0101] Step S1241: Generate satellite random number and satellite timestamp, and generate satellite temporary public key based on base point data and satellite random number.

[0102] The satellite timestamp includes the time when the satellite random number was generated.

[0103] In one instance, at the first satellite access node: generating satellite random numbers. and satellite timestamp Based on formula Generate satellite temporary public key .

[0104] Step S1242: Based on the node identifier of the first satellite access node and the satellite public-private key pair, as well as the satellite temporary public key, satellite timestamp and request message, the satellite core parameters are generated using a preset algorithm through the first secure hash function, the second secure hash function and the third secure hash function.

[0105] In one example, each satellite access node stores its own satellite public-private key pair, which includes: the public key. and private key Public key in satellite public-private key pair Includes: the public key of the first sub-satellite Second satellite public key The private key in the user's public-private key pair Including: the private key of the first sub-satellite Second satellite private key .

[0106] The satellite public-private key pair for the first satellite access node can be generated by the first satellite access node and any consensus ground node. The first satellite access node and any consensus ground node can use Certificateless Public Key Cryptography (CL-PKC) generation technology to generate the satellite public-private key pair; alternatively, the first satellite access node generates a random number as its node secret value and uses this node secret value as the private key for the first sub-satellite. Then utilize Determine the public key of the first subsatellite The public key of the first sub-satellite Send to any consensus ground node, and any consensus ground node generates a random number as the second node's random number. Based on the random number of the second node and the base point data, using the formula Determine satellite random commitment data Using the formula Generate the private key for the second subsatellite , This serves as the node identifier for the satellite access node. For the satellite timestamp (the moment the first sub-satellite public key is sent), any consensus ground node sends the second sub-satellite private key and satellite random commitment data to the first satellite access node. The first satellite access node: based on... Generate the public key in the satellite public-private key pair ;based on Generate the private key in the satellite public-private key pair .

[0107] First satellite access node: based on formula , , Generate satellite intermediate hash value , and Based on the formula Generate partial satellite signatures Based on the formula Generate satellite core parameters .

[0108] Step S1243: Use the private key in the satellite public-private key pair to sign the satellite authentication information to obtain signed satellite authentication information.

[0109] The satellite authentication information includes: core satellite parameters and basic satellite information. The basic satellite information includes: the node identifier of the first satellite access node, the satellite temporary public key, the satellite timestamp, and the blockchain identity.

[0110] Step S1244: Generate satellite identity verification information based on the signed satellite authentication information.

[0111] The satellite authentication information includes: signature satellite authentication information.

[0112] Figure 7 This is a flowchart illustrating step S125 provided in an exemplary embodiment of this disclosure. In some alternative embodiments, such as Figure 7 As shown, step S125 may include the following steps:

[0113] Step S1251: Based on the satellite's basic information, core satellite parameters, and system parameters, a satellite verification public key is generated using a preset algorithm.

[0114] On the client side: generation , and Based on the formula Generate satellite verification public key .

[0115] Step S1252: In response to the satellite temporary public key being consistent with the satellite verification public key, it is determined that the first satellite access node has passed the legitimacy verification.

[0116] On the client side: Determine and If the two nodes are equal (i.e., consistent), then the first satellite access node is determined to have passed the legitimacy verification; otherwise, the first satellite access node is determined to have failed the legitimacy verification, and the operation ends.

[0117] Figure 8 This is a flowchart illustrating step S130 provided in an exemplary embodiment of this disclosure. In some alternative embodiments, such as Figure 8 As shown, step S130 may include the following steps:

[0118] Step S131: The client generates a session key based on the user's random number and negotiated parameters.

[0119] Negotiation parameters are stored in both the terrestrial blockchain network and the inter-satellite blockchain network. and gateway random number The negotiation parameters are generated based on the gateway random number and the base point data. For example, the first consensus ground node deploys a gateway (network control center), and the gateway of the first consensus ground node can choose a random number as the gateway random number. Based on the formula Generate negotiation parameters .

[0120] The satellite timestamp includes the time the satellite random number was generated. The client uses a formula... Generate session key .

[0121] In step S132, the first consensus ground node generates a session key based on the gateway random number and the user's temporary public key.

[0122] Among them, the first consensus ground node is based on the formula Generate session key .

[0123] Figure 9 This is a structural block diagram of a Web3.0-based spatial information network system based on blockchain, provided in an exemplary embodiment of this disclosure. The spatial information network system includes a terrestrial blockchain network and an inter-satellite blockchain network. The terrestrial blockchain network includes multiple ordinary ground nodes and multiple consensus ground nodes, and the inter-satellite blockchain network includes multiple satellite access nodes.

[0124] The first satellite access node 300 is configured to, in response to receiving an access request from a client for a mobile user, determine an access time interval based on the mobile user's historical access time information of the last access to the space information network system and the current time; in response to the access time interval and the mobile user's credit level both meeting preset fast access conditions, the mobile user and the space information network system interact based on the historical session key of the last access to the space information network system; in response to the access time interval and / or the mobile user's credit level not meeting the preset fast access conditions, perform trust verification on the client, wherein the first satellite access node is one of the plurality of satellite access nodes;

[0125] The first consensus ground node 310 is used to obtain a session key in response to the mobile user and the first satellite access node both passing the trust verification, so that the mobile user can interact with the space information network system based on the session key. The first consensus ground access node is one of the plurality of consensus ground nodes.

[0126] Client 320 is configured to perform trustworthiness verification on the first satellite access node in response to the access time interval and / or the mobile user's credit rating not meeting the preset fast access conditions, and to obtain a session key in response to both the mobile user and the first satellite access node passing the trustworthiness verification, so that the mobile user can interact with the space information network system based on the session key.

[0127] In some alternative examples, in the embodiments described above in this disclosure,

[0128] The first satellite access node 300 is further configured to, in response to the access time interval not exceeding the preset time interval, determine that the access time interval meets the preset fast access condition, generate a fast access request, and send the fast access request to the first consensus ground node, wherein the fast access request includes a blockchain identity for identifying the mobile user;

[0129] The first consensus ground node 310 is also used to determine the credit rating of the mobile user based on the blockchain identity; when the credit rating of the mobile user exceeds a preset credit rating, it is determined that the credit rating of the mobile user meets the preset fast access conditions.

[0130] In some optional examples, in the embodiments described above in this disclosure, the client stores system parameters of the spatial information network system and the mobile user's public-private key pair. The system parameters include base point data, a first secure hash function, a second secure hash function, and a third secure hash function. The client generates the access request in the following manner:

[0131] The client 320 is further configured to generate a user random number, a user timestamp, and a request message; and generate a user temporary public key based on the base point data and the user random number, wherein the user timestamp includes the time when the user random number was generated; based on the mobile user's blockchain identity, the user public-private key pair, the user temporary public key, the user timestamp, and the request message, generate user core parameters using a preset algorithm through the first secure hash function, the second secure hash function, and the third secure hash function; use the private key in the user public-private key pair to sign the user authentication information to obtain signed user authentication information, wherein the user authentication information includes the user core parameters and user basic information, wherein the user basic information includes the user temporary public key, the blockchain identity, the request message, the user timestamp, and the node identifier of the first satellite access node; generate the access request based on the signed user authentication information, and send the access request to the first satellite access node.

[0132] In some optional examples, in the above embodiments of this disclosure, determining the access time interval includes: using the public key in the user public-private key pair to perform signature verification on the signed user authentication information; obtaining the user authentication information when the signed user authentication information passes the signature verification; determining the delay information of the access request based on the user timestamp and the current time; and determining the access time interval in response to the delay information satisfying a preset delay condition.

[0133] In some optional examples, in the embodiments described above in this disclosure, the first satellite access node and the mobile user perform bidirectional trust verification, including:

[0134] The first satellite access node 300 is also used to verify the legitimacy of the mobile user based on the user authentication information;

[0135] The first consensus ground node 310 is also used to determine, in response to the mobile user passing the legitimacy verification, whether the mobile user is in the access control list based on the blockchain identity;

[0136] The first satellite access node 300 is further configured to, in response to the detection result instructing the mobile user in the access control list, determine that the mobile user has passed the trust verification, generate satellite authentication information, and send the satellite authentication information to the client, wherein the satellite authentication information is used to prove the trustworthiness of the first satellite access node;

[0137] The client 320 is also used to verify the trustworthiness of the first satellite access node based on the satellite authentication information.

[0138] In some optional examples, in the embodiments described above in this disclosure, verifying the legitimacy of the mobile user based on the user authentication information includes:

[0139] Based on the user's basic information, the user's core parameters, and the system parameters, a user verification public key is generated using the preset algorithm; in response to the user's temporary public key matching the user verification public key, it is determined that the mobile user has passed the legitimacy verification.

[0140] In some optional examples, in the embodiments described above in this disclosure, generating satellite authentication information includes: generating a satellite random number and a satellite timestamp, and generating a satellite temporary public key based on the base point data and the satellite random number, wherein the satellite timestamp includes the time when the satellite random number was generated; generating satellite core parameters using a preset algorithm through the first secure hash function, the second secure hash function, and the third secure hash function, based on the node identifier of the first satellite access node and the satellite public-private key pair, as well as the satellite temporary public key, the satellite timestamp, and the request message; signing the satellite authentication information using the private key in the satellite public-private key pair to obtain signed satellite authentication information, wherein the satellite authentication information includes the satellite core parameters and satellite basic information, wherein the satellite basic information includes the node identifier of the first satellite access node, the satellite temporary public key, the satellite timestamp, and the blockchain identity; and generating the satellite authentication information based on the signed satellite authentication information.

[0141] In some optional examples, in the embodiments of this disclosure described above, verifying the trustworthiness of the first satellite access node based on the satellite authentication information includes:

[0142] Based on the satellite basic information, the satellite core parameters, and the system parameters, a satellite verification public key is generated using the preset algorithm; in response to the satellite temporary public key being consistent with the satellite verification public key, it is determined that the first satellite access node has passed the legitimacy verification.

[0143] In some optional examples, in the above embodiments of this disclosure, both the blockchain of the terrestrial blockchain network and the blockchain of the inter-satellite blockchain network store negotiation parameters and gateway random numbers, wherein the negotiation parameters are generated based on the gateway random numbers and base point data;

[0144] The client 320 is further configured to generate the session key based on the user random number and the negotiation parameters;

[0145] The first consensus ground node 310 is also used to generate a session key based on the gateway random number and the user's temporary public key.

[0146] The blockchain-based Web3.0 spatial information network system disclosed herein corresponds to the embodiments of the blockchain-based Web3.0 access authentication methods described above, and the relevant contents can be referred to each other, which will not be repeated here.

[0147] The beneficial technical effects of the exemplary embodiment of the blockchain-based Web3.0 spatial information network system disclosed herein can be found in the corresponding beneficial technical effects in the exemplary method section above, and will not be repeated here.

[0148] In addition, this disclosure also provides an electronic device, including:

[0149] Memory, used to store computer programs;

[0150] A processor is configured to execute a computer program stored in the memory, wherein when the computer program is executed, it implements the blockchain-based Web3.0 access authentication method described in any of the above embodiments of this disclosure.

[0151] Figure 10 This is a schematic diagram illustrating the structure of an application embodiment of the electronic device disclosed herein. Below, reference is made to… Figure 10 This describes an electronic device according to embodiments of the present disclosure. The electronic device may be either or both of a first device and a second device, or a standalone device independent of them, which may communicate with the first device and the second device to receive acquired input signals from them.

[0152] like Figure 10 As shown, the electronic device includes one or more processors and memory.

[0153] A processor can be a central processing unit (CPU) or other form of processing unit with data processing and / or instruction execution capabilities, and can control other components in an electronic device to perform desired functions.

[0154] The memory may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, and a processor may execute the program instructions to implement the blockchain-based Web3.0 access authentication method and / or other desired functions described in the various embodiments of this disclosure above.

[0155] In one example, the electronic device may also include input devices and output devices, which are interconnected via a bus system and / or other forms of connection mechanism (not shown).

[0156] In addition, the input device may include, for example, a keyboard, a mouse, etc.

[0157] This output device can output various information to the outside, including determined distance information, direction information, etc. The output device may include, for example, a display, a speaker, a printer, and a communication network and its connected remote output devices, etc.

[0158] Of course, for the sake of simplicity, Figure 10 Only some of the components of the electronic device relevant to this disclosure are shown, omitting components such as buses, input / output interfaces, etc. In addition, the electronic device may include any other suitable components depending on the specific application.

[0159] In addition to the methods and devices described above, embodiments of this disclosure may also be computer program products comprising computer program instructions that, when executed by a processor, cause the processor to perform the steps in the blockchain-based Web3.0 access authentication methods according to various embodiments of this disclosure as described in the foregoing sections of this specification.

[0160] The computer program product can be written in any combination of one or more programming languages ​​to perform the operations of the embodiments of this disclosure. The programming languages ​​include object-oriented programming languages ​​such as Java and C++, as well as conventional procedural programming languages ​​such as C or similar languages. The program code can be executed entirely on a user's computing device, partially on a user's computing device, as a standalone software package, partially on a user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0161] Furthermore, embodiments of this disclosure may also be computer-readable storage media storing computer program instructions that, when executed by a processor, cause the processor to perform the steps in the blockchain-based Web3.0 access authentication method according to various embodiments of this disclosure as described in the foregoing portion of this specification.

[0162] The computer-readable storage medium may be any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof.

[0163] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium includes various media that can store program code, such as ROM, RAM, magnetic disk, or optical disk.

[0164] The basic principles of this disclosure have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, and effects mentioned in this disclosure are merely examples and not limitations, and should not be considered as essential features of each embodiment of this disclosure. Furthermore, the specific details disclosed above are for illustrative and facilitative purposes only, and are not limitations. These details do not limit the scope of this disclosure to the necessity of employing the aforementioned specific details for implementation.

[0165] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For system embodiments, since they largely correspond to method embodiments, the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.

[0166] The block diagrams of devices, apparatuses, devices, and systems disclosed herein are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, devices, and systems can be connected, arranged, and configured in any manner. Words such as “comprising,” “including,” “having,” etc., are open-ended terms meaning “including but not limited to,” and are used interchangeably with them. The terms “or” and “and” as used herein refer to the terms “and / or,” and are used interchangeably with them unless the context clearly indicates otherwise. The term “such as” as used herein refers to the phrase “such as but not limited to,” and is used interchangeably with it.

[0167] The methods and apparatus of this disclosure may be implemented in many ways. For example, they may be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above-described order of steps for the methods is for illustrative purposes only, and the steps of the methods of this disclosure are not limited to the order specifically described above, unless otherwise specifically stated. Furthermore, in some embodiments, this disclosure may also be implemented as a program recorded on a recording medium, the program including machine-readable instructions for implementing the methods according to this disclosure. Thus, this disclosure also covers recording media storing programs for performing the methods according to this disclosure.

[0168] It should also be noted that in the apparatus, devices, and methods of this disclosure, the components or steps can be disassembled and / or recombined. These disassemblies and / or recombinations should be considered as equivalent solutions to this disclosure.

[0169] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the aspects shown herein, but rather to be carried out within the widest scope consistent with the principles and novel features disclosed herein.

[0170] The above description has been given for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of this disclosure to the forms disclosed herein. Although numerous exemplary aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations therein.

Claims

1. A Web3.0 access authentication method based on blockchain, characterized in that, The method is applied to a space information network system, which includes a terrestrial blockchain network and an inter-satellite blockchain network. The terrestrial blockchain network includes multiple ordinary ground nodes and multiple consensus ground nodes, and the inter-satellite blockchain network includes multiple satellite access nodes. In response to receiving an access request for a mobile user from a client, the first satellite access node determines an access time interval based on the historical access time information of the mobile user's last access to the space information network system and the current time. The first satellite access node is one of the plurality of satellite access nodes. In response to the fact that both the access time interval and the credit level of the mobile user meet the preset fast access conditions, the mobile user interacts with the spatial information network system based on the historical session key of the previous access to the spatial information network system. In response to the access time interval and / or the mobile user's credit rating not meeting the preset fast access conditions, the first satellite access node and the mobile user perform bidirectional trust verification. In response to the mobile user and the first satellite access node both passing the trust verification, the client and the first consensus ground node respectively obtain a session key, so that the mobile user can interact with the space information network system based on the session key, wherein the first consensus ground node is one of the plurality of consensus ground nodes.

2. The method according to claim 1, characterized in that, Also includes: In response to the fact that the access time interval does not exceed the preset time interval, it is determined that the access time interval meets the preset fast access condition, a fast access request is generated, and the fast access request is sent to the first consensus ground node. The fast access request includes a blockchain identity for identifying the mobile user. The first consensus ground node determines the credit rating of the mobile user based on the blockchain identity; When the credit rating of the mobile user exceeds a preset credit rating, it is determined that the credit rating of the mobile user meets the preset fast access conditions.

3. The method according to claim 1, characterized in that, The client stores system parameters of the spatial information network system and the mobile user's public-private key pair. The system parameters include base point data, a first secure hash function, a second secure hash function, and a third secure hash function. The client generates the access request in the following manner: Generate a user random number, a user timestamp, and a request message; and based on the base point data and the user random number, generate a user temporary public key, wherein the user timestamp includes the time when the user random number was generated; Based on the mobile user's blockchain identity, the user's public and private key pair, the user's temporary public key, the user's timestamp, and the request message, the user's core parameters are generated using a preset algorithm through the first secure hash function, the second secure hash function, and the third secure hash function. The user authentication information is signed using the private key in the user public-private key pair to obtain signed user authentication information. The user authentication information includes the user core parameters and user basic information. The user basic information includes the user temporary public key, the blockchain identity, the request message, the user timestamp, and the node identifier of the first satellite access node. The access request is generated based on the signed user authentication information.

4. The method according to claim 3, characterized in that, The determination of the access time interval includes: The signature of the user authentication information is verified using the public key in the user public-private key pair; The user authentication information is obtained when the signature user authentication information passes signature verification; Based on the user timestamp and the current time, determine the delay information of the access request; In response to the delay information satisfying a preset delay condition, the access time interval is determined.

5. The method according to claim 4, characterized in that, The first satellite access node and the mobile user perform bidirectional trust verification, including: The first satellite access node verifies the legitimacy of the mobile user based on the user authentication information; In response to the mobile user passing the legitimacy verification, the first consensus ground node determines the detection result of whether the mobile user is in the access control list based on the blockchain identity; In response to the detection result indicating that the mobile user is in the access control list, the first satellite access node determines that the mobile user has passed the trust verification; The first satellite access node generates satellite authentication information and sends the satellite authentication information to the client. The satellite authentication information is used to prove the trustworthiness of the first satellite access node. The client verifies the trustworthiness of the first satellite access node based on the satellite authentication information.

6. The method according to claim 5, characterized in that, The first satellite access node verifies the legitimacy of the mobile user based on the user authentication information, including: Based on the user's basic information, the user's core parameters, and the system parameters, a user verification public key is generated using the preset algorithm. In response to the user's temporary public key matching the user's verification public key, it is determined that the mobile user has passed the legitimacy verification.

7. The method according to claim 5, characterized in that, The first satellite access node generates satellite authentication information, including: Generate a satellite random number and a satellite timestamp, and based on the base point data and the satellite random number, generate a satellite temporary public key, wherein the satellite timestamp includes the time when the satellite random number was generated; Based on the node identifier and satellite public-private key pair of the first satellite access node, as well as the satellite temporary public key, the satellite timestamp, and the request message, the satellite core parameters are generated using a preset algorithm through the first secure hash function, the second secure hash function, and the third secure hash function. The satellite authentication information is signed using the private key in the satellite public-private key pair to obtain signed satellite authentication information. The satellite authentication information includes the satellite core parameters and satellite basic information. The satellite basic information includes the node identifier of the first satellite access node, the satellite temporary public key, the satellite timestamp, and the blockchain identity. The satellite identity verification information is generated based on the signed satellite authentication information.

8. The method according to claim 7, characterized in that, The client verifies the trustworthiness of the first satellite access node based on the satellite authentication information, including: Based on the satellite's basic information, core satellite parameters, and system parameters, a satellite verification public key is generated using the preset algorithm. In response to the satellite temporary public key matching the satellite verification public key, it is determined that the first satellite access node has passed the legitimacy verification.

9. The method according to any one of claims 1-8, characterized in that, Negotiation parameters and gateway random numbers are stored in both the blockchain of the terrestrial blockchain network and the blockchain of the inter-satellite blockchain network. The negotiation parameters are generated based on the gateway random numbers and base point data. The client and the first consensus ground node respectively obtain the session key, including: The client generates the session key based on the user's random number and the negotiation parameters; The first consensus ground node generates a session key based on the gateway random number and the user's temporary public key.

10. A Web3.0-based spatial information network system, characterized in that, The space information network system includes a terrestrial blockchain network and an inter-satellite blockchain network. The terrestrial blockchain network includes multiple ordinary ground nodes and multiple consensus ground nodes. The inter-satellite blockchain network includes multiple satellite access nodes. The first satellite access node is used to respond to an access request sent by a client for a mobile user, and determine the access time interval based on the historical access time information of the mobile user's last access to the space information network system and the current time; In response to the fact that both the access time interval and the credit rating of the mobile user meet the preset fast access conditions, the mobile user interacts with the space information network system based on the historical session key of the previous access to the space information network system; in response to the fact that the access time interval and / or the credit rating of the mobile user do not meet the preset fast access conditions, the client is verified for trustworthiness, and the first satellite access node is one of the plurality of satellite access nodes; The first consensus ground node is used to obtain a session key in response to both the mobile user and the first satellite access node passing the trust verification, so that the mobile user can interact with the space information network system based on the session key. The first consensus ground node is one of the plurality of consensus ground nodes. The client is configured to perform a trustworthiness verification on the first satellite access node in response to the access time interval and / or the mobile user's credit rating failing to meet the preset fast access conditions, and to obtain a session key in response to both the mobile user and the first satellite access node passing the trustworthiness verification, so that the mobile user can interact with the space information network system based on the session key.

11. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor for executing a computer program stored in the memory, wherein when the computer program is executed, it implements the method described in any one of claims 1-9.

12. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method described in any one of claims 1-9.

Citation Information

Patent Citations

  • Decentralized Internet of Things security authentication system, equipment registration and identity authentication method

    CN109768988A

  • Access authentication and authority management control flow method of spatial information network based on blockchain

    CN112615721A