Block chain network access control method and device, equipment and storage medium

CN121603221APending Publication Date: 2026-03-03CHENGDU PRIME STARK TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-08-16
Publication Date
2026-03-03

Smart Images

  • Figure CN121603221A_ABST
    Figure CN121603221A_ABST
Patent Text Reader

Abstract

The invention provides a block chain network access control method and device, equipment and a storage medium, and relates to the technical field of access control. The method comprises the steps of firstly obtaining a user certificate issued by a certificate issuing mechanism in a block chain system; the method comprises the steps of obtaining a TLS certificate issued by a TLS certificate issuing mechanism, carrying out integrity verification on the TLS certificate issued by the TLS certificate issuing mechanism, ensuring communication security between a user and a block chain system, obtaining a data signature certificate issued by a signature issuing mechanism after the integrity verification is passed, and signing target transaction data information and a user certificate by using the data signature certificate. And sending the signed target transaction data information and the user credential to a target institution, and applying for data access, and after the target institution verifies that the data access permission of the user is passed, the user can access the target transaction data. According to the method and the system, the security of the system is enhanced by implementing access permission control on different levels of the block chain system through the multi-level certificate structure.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of access control technology, and in particular to a blockchain network access control method, apparatus, device, and storage medium. Background Technology

[0002] Blockchain is a distributed ledger technology that ensures the security and reliability of transactions by linking transaction records chronologically into an immutable data chain. Blockchain technology enables dynamic management and authorization mechanisms for digital identities. Through technologies such as smart contracts, user identity information can be dynamically managed and controlled, achieving authorization-based identity verification and access control. This mechanism can better meet the identity verification needs in different scenarios, improving the flexibility and scalability of digital identities.

[0003] However, current blockchain technology-based verification and control of user identities relies on a relatively simple verification method, making it difficult to implement multi-level access control at different levels, resulting in low security for user access control. Summary of the Invention

[0004] The purpose of this invention is to provide a blockchain network connection communication method, apparatus, device and storage medium to solve the problem that existing blockchain networks have difficulty in implementing multi-level access control and have low access control security.

[0005] The specific technical solution of this invention is as follows: In a first aspect of the present invention, a blockchain network access control method is provided, comprising: Users initiate a user registration request to the blockchain system and obtain user credentials issued by a credential issuing authority; Initiate a network access verification request to the TLS Certificate Authority and obtain the TLS certificate issued by the TLS Certificate Authority; The integrity of the TLS certificate is verified. Once the integrity verification is successful, a data signature request is sent to the signing authority to obtain the issued data signature certificate. The target transaction data and user credentials are signed using a data signature certificate. The signed target transaction data and user credentials are then sent to the target institution, and a data access request is made. The target institution verifies the user's data access permissions. Once the access permission verification is successful, the target transaction data can be accessed.

[0006] Furthermore, the user initiates a user registration request to the blockchain network and obtains a user credential issued by a credential issuing authority, including: Users generate a user registration request based on their own identity information and submit the user registration request to the credential issuing authority in the blockchain system; The issuing authority verifies the identity of the user information in the user registration request. After the verification is successful, it generates a user credential corresponding to the user information using the issuing authority's root certificate, uploads the user credential to the blockchain network for storage, and returns the user credential to the client of the user's node.

[0007] Further, the step of initiating a network access verification request to the TLS certificate authority and obtaining the TLS certificate issued by the TLS certificate authority includes: The user generates a network access verification request based on the user credentials and sends the network access verification request to the TLS certificate authority. The TLS certificate authority receives and parses the network access verification request to obtain the user's credentials. It then retrieves the authority's root certificate from the certificate authority to authenticate the user's credentials. Once the user is successfully authenticated, the authority's TLS root certificate is used to issue a TLS certificate to the user.

[0008] Furthermore, the process of performing integrity verification on the TLS certificate, and then, upon successful integrity verification, initiating a data signing request to the signing authority to obtain the issued data signing certificate, includes: Users verify the validity and integrity of TLS certificates using the TLS root certificate of the TLS certificate authority pre-installed in the operating system or browser on the client side; If the TLS certificate is valid and the certificate file is complete, upload the TLS certificate to the blockchain system's server, configure the TLS certificate in the server's HTTPS configuration file, and use an SSL testing tool to test the HTTPS configuration file. After the HTTPS configuration file is tested and found to be correct, the user generates a data signature request based on the user credentials and sends the data signature request to the blockchain system through the HTTPS service; The blockchain system receives data signature requests and verifies the user credentials in the data signature requests. After confirming that the user's identity is correct, it issues a data signature certificate to the user through the institution's signature root certificate.

[0009] Furthermore, the step of verifying the user's data access permissions at the target institution, and accessing the target transaction data after the access permission verification is successful, includes: After receiving a user's data access request via HTTPS, the target institution in the blockchain system parses the data access request to obtain the requested target transaction data information and user credentials. The system calls the root certificate of the issuing authority to verify the user's credentials. If the user's credentials are verified to be correct, the system determines whether the user corresponding to the credentials has data access rights based on the preset data permissions. If the user has data access permissions, the target transaction data will be retrieved from the database based on the target transaction data information and then sent back to the user's client via HTTPS service.

[0010] In a second aspect, the present invention provides a blockchain network access control device, comprising: The user registration module is used by users to initiate user registration requests to the blockchain system and obtain user credentials issued by the credential issuing authority. The access verification module is used to initiate a network access verification request to the TLS certificate authority and obtain the TLS certificate issued by the TLS certificate authority. The signature request module is used to perform integrity verification on the TLS certificate. After the integrity verification is successful, it sends a data signature request to the signing authority and obtains the issued data signature certificate. The data access module is used to sign the target transaction data information and user credentials using a data signature certificate, send the signed target transaction data information and user credentials to the target institution, and request data access. The access response module is used to verify the user's data access permissions at the target institution. Once the access permission verification is successful, the target transaction data can be accessed.

[0011] Thirdly, the present invention provides an electronic device, comprising: One or more processors; A storage device for storing one or more programs, which, when executed by one or more processors, cause the one or more processors to implement the blockchain network access control method of the first aspect.

[0012] Fourthly, the present invention provides a computer-readable medium having a computer program stored thereon, which, when executed by a processor, implements the blockchain network access control method of the first aspect.

[0013] The beneficial effects of this invention are as follows: The blockchain network access control method provided by this invention involves the user first obtaining a user credential issued by a credential authority in the blockchain system; then, the user performs an integrity verification of the TLS certificate with a TLS certificate authority to ensure secure communication between the user and the blockchain system. After the integrity verification is passed, the user obtains a data signature certificate issued by a signature authority, uses the data signature certificate to sign the target transaction data and the user credential, sends the signed target transaction data and the user credential to the target authority, and requests data access. After the target authority verifies that the user's data access permissions are approved, the user can access the target transaction data. This invention enhances the security of the system by implementing access control at different levels of the blockchain system through a multi-level certificate structure. Attached Figure Description

[0014] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention, and those skilled in the art can obtain other drawings based on these drawings without creative effort.

[0015] Figure 1 This is a schematic diagram of the blockchain network access control method of the present invention; Figure 2 This is a diagram of the certificate system architecture of the present invention; Figure 3 This is a schematic diagram of the blockchain network access control device module structure of the present invention. Detailed Implementation

[0016] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.

[0017] Example 1: Figure 1 This is a schematic flowchart of a blockchain network access control method according to an embodiment of the present invention, referred to... Figure 1 As shown, the method of this embodiment of the invention includes: Users initiate a user registration request to the blockchain system and obtain user credentials issued by a credential issuing authority; Initiate a network access verification request to the TLS Certificate Authority and obtain the TLS certificate issued by the TLS Certificate Authority; The integrity of the TLS certificate is verified. Once the integrity verification is successful, a data signature request is sent to the signing authority to obtain the issued data signature certificate. The target transaction data and user credentials are signed using a data signature certificate. The signed target transaction data and user credentials are then sent to the target institution, and a data access request is made. The target institution verifies the user's data access permissions. Once the access permission verification is successful, the target transaction data can be accessed.

[0018] Specifically, embodiments of the present invention establish a multi-level certificate structure within the organization to ensure the security of user access to the blockchain system. For example, in node permission control and transaction permission control, different levels of Certificate Authorities (CAs) are responsible for issuing certificates with different permissions, ensuring that only authorized nodes and users can perform the corresponding operations.

[0019] Reference Figure 2 As shown, in one embodiment of the present invention, a three-tier certificate structure is established within an organization. This certificate structure includes an organization TLS root certificate, an organization signature root certificate, and an organization credential root certificate. These three root certificates are used to issue TLS certificates, digital signature certificates, and user credentials, respectively. Specifically, the organization TLS root certificate is used to issue TLS certificates to blockchain nodes or clients, enabling blockchain nodes and clients to perform trusted verification of the server hosting the blockchain system.

[0020] During trusted verification, a node or client can ensure an encrypted connection is established with a correct, trusted server through a series of verification steps. These steps include verifying the certificate format, integrity, signature, validity period, revocation status, and domain name or IP address. Once verification is successful, the client and server will use the public and private keys from the certificate to conduct encrypted communication, ensuring the security of file transfers.

[0021] Furthermore, the multi-level certificate structure in this embodiment of the invention is scalable and supports horizontal expansion of the certificate structure, similar to horizontal sharding of a database. It can distribute data across multiple databases with the same table structure, theoretically enabling unlimited horizontal expansion and improving the scalability of blockchain projects.

[0022] Specifically, a fourth or fifth root certificate can be added at the root certificate level to achieve horizontal expansion and implement multi-factor authentication. Simultaneously, multiple sub-certificates can be further subdivided under TLS certificates, credentials, or signatures for enhanced access authentication, thereby further strengthening network access security.

[0023] Furthermore, in this embodiment of the invention, the user initiates a user registration request to the blockchain network and obtains a user credential issued by a credential issuing authority, specifically including: Users generate a user registration request based on their own identity information and submit the user registration request to the credential issuing authority in the blockchain system.

[0024] The issuing authority verifies the identity of the user information in the user registration request. After the verification is successful, it generates a user credential corresponding to the user information using the issuing authority's root certificate, uploads the user credential to the blockchain network for storage, and returns the user credential to the client of the user's node.

[0025] In this embodiment of the invention, users pre-register in the blockchain system and obtain corresponding user credentials to verify their identity in subsequent processes.

[0026] Furthermore, in this embodiment of the invention, initiating a network access verification request to a TLS certificate authority and obtaining a TLS certificate issued by the TLS certificate authority specifically includes: The user generates a network access verification request based on the user credentials and sends the network access verification request to the TLS certificate authority. The TLS certificate authority receives and parses the network access verification request to obtain the user's credentials. It then retrieves the authority's root certificate from the certificate authority to authenticate the user's credentials. Once the user is successfully authenticated, the authority's TLS root certificate is used to issue a TLS certificate to the user.

[0027] Specifically, users can combine their user credentials with a TLS certificate request on the client side to generate a network access authentication request. After verifying the user credentials, the TLS certificate authority can respond to the TLS certificate request and issue a TLS certificate to the user's client, enabling the client to authenticate the blockchain system's server.

[0028] Furthermore, in this embodiment of the invention, the TLS certificate undergoes integrity verification. Upon successful integrity verification, a data signing request is initiated to the signing authority to obtain the issued data signing certificate. Specifically, this includes: Users verify the validity and integrity of TLS certificates using the TLS root certificate of the TLS certificate authority pre-installed in the operating system or browser on the client side.

[0029] If the TLS certificate is valid and the certificate file is complete, the TLS certificate is uploaded to the blockchain system's server, and the TLS certificate is configured in the server's HTTPS configuration file. The HTTPS configuration file is then tested using an SSL testing tool.

[0030] After the HTTPS configuration file is tested and found to be correct, the user generates a data signature request based on the user credentials and sends the data signature request to the blockchain system through the HTTPS service.

[0031] The blockchain system receives data signature requests and verifies the user credentials in the data signature requests. After confirming that the user's identity is correct, it issues a data signature certificate to the user through the institution's signature root certificate.

[0032] In some embodiments, a TLS certificate includes a root certificate, intermediate certificates, and a server certificate. Before verifying the validity and integrity of a TLS certificate, if the TLS certificate contains multiple certificates (root certificate and intermediate certificates), the multiple certificates need to be merged into a single file so that the server can correctly load the entire certificate chain. During merging, the server certificate is typically placed first, followed by the intermediate certificates, and finally the corresponding root certificate.

[0033] In this embodiment of the invention, a TLS certificate is successfully added to the communication service, ensuring secure communication between the server and the client. The TLS certificate, through mechanisms such as certificate issuance and verification, authenticates and authorizes participating nodes (or clients), ensuring that only authorized nodes (clients) can join the network and conduct secure communication.

[0034] Furthermore, in this embodiment of the invention, after the target institution verifies the user's data access permissions and the access permission verification is successful, access to the target transaction data specifically includes: After receiving a user's data access request via HTTPS, the target institution in the blockchain system parses the data access request to obtain the requested target transaction data information and user credentials. The system calls the root certificate of the issuing authority to verify the user's credentials. If the user's credentials are verified to be correct, the system determines whether the user corresponding to the credentials has data access rights based on the preset data permissions. If the user has data access permissions, the target transaction data will be retrieved from the database based on the target transaction data information and then sent back to the user's client via HTTPS service.

[0035] The embodiments of the present invention enhance the security of the blockchain system by implementing access control at different levels through a multi-level certificate structure.

[0036] Example 2: Refer to Figure 3 As shown, this embodiment of the invention also provides a blockchain network access control device, which includes: The user registration module is used by users to initiate user registration requests to the blockchain system and obtain user credentials issued by the credential issuing authority. The access verification module is used to initiate a network access verification request to the TLS certificate authority and obtain the TLS certificate issued by the TLS certificate authority. The signature request module is used to perform integrity verification on the TLS certificate. After the integrity verification is successful, it sends a data signature request to the signing authority and obtains the issued data signature certificate. The data access module is used to sign the target transaction data information and user credentials using a data signature certificate, send the signed target transaction data information and user credentials to the target institution, and request data access. The access response module is used to verify the user's data access permissions at the target institution. Once the access permission verification is successful, the target transaction data can be accessed.

[0037] This invention also provides an electronic device, comprising: One or more processors; A storage device for storing one or more programs, which, when executed by one or more processors, cause the one or more processors to implement the blockchain network access control method of Embodiment 1.

[0038] This invention also provides a computer-readable medium storing a computer program thereon, which, when executed by a processor, implements the blockchain network access control method of Embodiment 1.

[0039] The various embodiments in this specification are described in a related manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0040] The above description is merely a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention are included within the scope of protection of the present invention.

Claims

1. A blockchain network access control method, characterized in that, include: Users initiate a user registration request to the blockchain system and obtain user credentials issued by a credential issuing authority; Initiate a network access verification request to the TLS Certificate Authority and obtain the TLS certificate issued by the TLS Certificate Authority; The integrity of the TLS certificate is verified. Once the integrity verification is successful, a data signature request is sent to the signing authority to obtain the issued data signature certificate. The target transaction data and user credentials are signed using a data signature certificate. The signed target transaction data and user credentials are then sent to the target institution, and a data access request is made. The target institution verifies the user's data access permissions. Once the access permission verification is successful, the target transaction data can be accessed.

2. The blockchain network access control method according to claim 1, characterized in that, The user initiates a user registration request to the blockchain network and obtains a user credential issued by a credential issuing authority, including: Users generate a user registration request based on their own identity information and submit the user registration request to the credential issuing authority in the blockchain system; The issuing authority verifies the identity of the user information in the user registration request. After the verification is successful, it generates a user credential corresponding to the user information using the issuing authority's root certificate, uploads the user credential to the blockchain network for storage, and returns the user credential to the client of the user's node.

3. The blockchain network access control method according to claim 1, characterized in that, The step of initiating a network access verification request to a TLS certificate authority and obtaining a TLS certificate issued by the TLS certificate authority includes: The user generates a network access verification request based on the user credentials and sends the network access verification request to the TLS certificate authority. The TLS certificate authority receives and parses the network access verification request to obtain the user's credentials. It then retrieves the authority's root certificate from the certificate authority to authenticate the user's credentials. Once the user is successfully authenticated, the authority's TLS root certificate is used to issue a TLS certificate to the user.

4. The blockchain network access control method according to claim 1, characterized in that, The process of performing integrity verification on the TLS certificate, and then, upon successful integrity verification, initiating a data signature request to the signing authority to obtain the issued data signature certificate, includes: Users verify the validity and integrity of TLS certificates using the TLS root certificate of the TLS certificate authority pre-installed in the operating system or browser on the client side; If the TLS certificate is valid and the certificate file is complete, upload the TLS certificate to the blockchain system's server, configure the TLS certificate in the server's HTTPS configuration file, and use an SSL testing tool to test the HTTPS configuration file. After the HTTPS configuration file is tested and found to be correct, the user generates a data signature request based on the user credentials and sends the data signature request to the blockchain system through the HTTPS service; The blockchain system receives data signature requests and verifies the user credentials in the data signature requests. After confirming that the user's identity is correct, it issues a data signature certificate to the user through the institution's signature root certificate.

5. The blockchain network access control method according to claim 1, characterized in that, The process of verifying the user's data access permissions at the target institution, and accessing the target transaction data after the access permission verification is successful, includes: After receiving a user's data access request via HTTPS, the target institution in the blockchain system parses the data access request to obtain the requested target transaction data information and user credentials. The system calls the root certificate of the issuing authority to verify the user's credentials. If the user's credentials are verified to be correct, the system determines whether the user corresponding to the credentials has data access rights based on the preset data permissions. If the user has data access permissions, the target transaction data will be retrieved from the database based on the target transaction data information and then sent back to the user's client via HTTPS service.

6. A blockchain network access control device, characterized in that, include: The user registration module is used by users to initiate user registration requests to the blockchain system and obtain user credentials issued by the credential issuing authority. The access verification module is used to initiate a network access verification request to the TLS certificate authority and obtain the TLS certificate issued by the TLS certificate authority. The signature request module is used to perform integrity verification on the TLS certificate. After the integrity verification is successful, it sends a data signature request to the signing authority and obtains the issued data signature certificate. The data access module is used to sign the target transaction data information and user credentials using a data signature certificate, send the signed target transaction data information and user credentials to the target institution, and request data access. The access response module is used to verify the user's data access permissions at the target institution. Once the access permission verification is successful, the target transaction data can be accessed.

7. An electronic device, characterized in that, include: One or more processors; A storage device for storing one or more programs, which, when executed by one or more processors, cause the one or more processors to implement the blockchain network access control method as described in any one of claims 1 to 5.

8. A computer-readable medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the blockchain network access control method as described in any one of claims 1 to 5.