Recursive resolution node identity authentication method based on linkage of blockchain and reverse DNS
Patent Information
- Application Number
- CN202610800195.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-04
- Publication Date
- 2026-09-18
AI Technical Summary
[0009]本发明为了克服上述现有技术的缺陷,提供基于区块链与反向DNS联动的递归解析节点身份认证方法,本发明能够有效解决现有递归解析节点在广域网中跨域身份验证困难、传统反向DNS记录易遭受篡改以及现存区块链域名方案全量上链导致解析效率低下且缺乏真实权威信任背书的问题
1、本发明,较现有技术而言,能够有效解决现有递归解析节点在广域网中跨域身份验证困难、传统反向DNS记录易遭受篡改以及现存区块链域名方案全量上链导致解析效率低下且缺乏真实权威信任背书的问题。
Smart Images

Figure CN122783271A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a recursive resolution node authentication method based on blockchain and reverse DNS linkage. Background Technology
[0002] The Domain Name System (DNS) is a core infrastructure of the Internet. In the DNS architecture, recursive resolver nodes act as the first-hop proxy for clients accessing the Internet, undertaking the crucial responsibility of initiating queries to authoritative servers on behalf of end users and caching the results. With the increasing complexity of network environments and the continuous upgrading of network attack methods such as DNS spoofing and cache poisoning, ensuring the authenticity and credibility of recursive resolver nodes and preventing network traffic from being hijacked or monitored by malicious nodes has become a key technical requirement in the field of Internet infrastructure security.
[0003] Existing resolver authentication and discovery mechanisms, exemplified by standards proposed by the Internet Engineering Task Force (IETF), primarily rely on network layer push mechanisms such as Dynamic Host Configuration Protocol (DHCP) or router advertising to send trusted resolver information to clients. However, these mechanisms have significant limitations in practical applications: their design is primarily intended to serve local area networks (LANs) or controlled single network management domains. In open, heterogeneous wide area network (WAN) environments, when clients traverse different autonomous systems or are in mobile roaming scenarios, relying solely on underlying network pushes is insufficient for efficient and secure cross-domain authentication. Clients often cannot verify whether the recursive node currently providing services to them truly belongs to the legitimate physical entity they claim to be.
[0004] To establish a mapping between IP addresses and entity identities in cross-domain scenarios, existing technologies typically rely on reverse DNS resolution architectures. However, traditional reverse DNS architectures were not designed with security verification requirements in mind. Their recorded data is primarily stored and transmitted in plaintext, lacking native encryption signatures and anti-tampering mechanisms, making them highly vulnerable to malicious forgery. To compensate for this data integrity deficiency, the Domain Name System Security Extension (DNSSEC) technology has been introduced. However, DNSSEC's operation in reverse resolution scenarios heavily relies on the massive and complex traditional Public Key Infrastructure (PKI). Directly configuring and issuing huge digital certificates containing complete public keys and signature chains for massive IP address ranges would not only result in excessively large DNS query response messages, triggering UDP truncation and retransmission, but also incur high computational and communication overhead, making it difficult to meet high-concurrency engineering requirements.
[0005] In recent years, blockchain technology, with its advantages of decentralization, tamper-proofing, and globally consistent state, has begun to be applied to build distributed public key infrastructures. By persisting the root of trust and digital credentials to the blockchain network, the single point of failure of traditional centralized institutions can be effectively eliminated. However, existing blockchain identity authentication schemes have serious problems in the underlying network communication: if nodes are required to directly synchronize the entire on-chain state every time a communication connection is established, unacceptable addressing latency will be introduced; at the same time, existing schemes mostly adopt bilateral interaction protocols, requiring both communication ends to undergo deep smart contract adaptation and modification, making cross-domain collaboration and deployment extremely difficult.
[0006] In summary, existing technologies face irreconcilable engineering contradictions when addressing recursive resolution node authentication: network layer push is difficult to cross domains; traditional reverse resolution is easily tampered with; DNSSEC, which incorporates traditional PKI, faces performance bottlenecks due to packet bloat; and conventional blockchain authentication schemes suffer from high communication latency and high costs for both ends to be modified. Furthermore, existing technologies have failed to effectively integrate the technical trust system of top-level address allocation nodes in the physical network topology with the underlying network verification mechanism.
[0007] Chinese patent application CN118381652A, published on July 23, 2024, discloses a secure and reliable distributed industrial internet identifier resolution method and apparatus. The method includes the following steps: identifier structure setting; trusted identity authentication; trusted identifier registration; and secure identifier resolution. First, ordered multi-signature technology is used to provide trusted authentication for the identities and identifiers of nodes within the identifier resolution system, ensuring the security and reliability of the identifier source data. Second, IPFS is introduced to improve the identifier structure setting, thereby achieving a strong correlation between the identifier and its source data. Finally, blockchain and asymmetric encryption are used to achieve secure storage and secure transmission of identity certificates, identifiers, and their source data.
[0008] The patent application discloses a secure and reliable distributed industrial internet identifier resolution method that utilizes blockchain and an ordered multi-group signature algorithm to ensure the security and reliability of the industrial internet identifier resolution system process. It binds the identifier to the source data to achieve source security of the industrial internet identifier, preventing malicious tampering of the industrial internet identifier and source data by enterprises. However, it still faces challenges such as difficulties in cross-domain authentication of recursive resolution nodes in wide area networks, low resolution efficiency, and a lack of genuine authoritative trust endorsement. Summary of the Invention
[0009] To overcome the shortcomings of the prior art, this invention provides a recursive resolution node authentication method based on the linkage of blockchain and reverse DNS. This invention can effectively solve the problems of cross-domain authentication difficulties of existing recursive resolution nodes in wide area networks, the susceptibility of traditional reverse DNS records to tampering, and the low resolution efficiency and lack of real authoritative trust endorsement caused by the full on-chaining of existing blockchain domain name schemes.
[0010] This invention is achieved through the following technical solution: The recursive resolution node authentication method based on blockchain and reverse DNS linkage includes the following steps: S1. Trust Anchor Point and Verification Environment Initialization The authentication end loads the pre-set public key of the superior trusted node in the secure storage module into the protected memory context, establishes it as the absolute root of trust for local authentication and verification, initializes the blockchain light node interface module, and establishes the network communication state with the external blockchain network. S2, Reverse DNS out-of-band index acquisition When the network interception module of the authentication end detects a session establishment request for the target IP address, it suspends the network communication process. The authentication end calls the DNS resolution extraction engine to convert the target IP address into a standard reverse addressing format and encapsulates it to generate a reverse query message. It then sends the query to the reverse resolution zone of the domain name system through the network communication module and receives the response data stream containing lightweight text records returned by the domain name system. S3, Index Features and Self-Proofing Analysis The authentication end calls the parsing and extraction engine to perform string segmentation and extraction matching based on preset protocol delimiters on the text payload in the response data stream; S4. On-chain credential synchronization and first-level authorization verification The authentication endpoint extracts the asset identifier index, calls the blockchain light node interface module, initiates a remote procedure call to the blockchain network, and retrieves the target tuple bound to the asset identifier index. After the key is retrieved, the authentication end schedules the cryptographic authentication module to read the base public key. For the incoming The payload performs a hash operation and runs the first level of Boolean decision logic; S5. Verification and Communication Establishment of Second-Level Entity Control Rights If the first layer of authorization verification passes, the authentication terminal will then access the verified... The public key of the target parser node is extracted from the tuple, and the anti-replay feature of the currently suspended network session is extracted. Combined with the extracted self-signature, it is handed over to the cryptographic authentication module to perform the second Boolean judgment logic. The cryptographic authentication module calculates the global authentication decision result. When both the first authorization verification and the global authentication decision result pass, the network interception module of the authentication end releases the suspension of the target network communication process, modifies the local access control policy, and allows and establishes a secure data communication tunnel with the target parser node.
[0011] In S1, the blockchain network pre-permanently stores an on-chain ownership certificate containing the target IP address range prefix and the target parsing node's public key, as well as the corresponding top-level authorized cryptographic signature.
[0012] In step S3, if the parsing fails, the authentication end discards the communication request that was suspended in step S2 and records the log; if the parsing is successful, the asset identifier index pointing to the credential data in the blockchain network and the self-signature generated by the target parsing node using the private key to the network feature parameters are extracted and loaded into the temporary variable area in memory to complete the acquisition of the out-of-band trust pointer.
[0013] In S4, when running the first Boolean judgment logic, it also includes obtaining the current network time and comparing it with the timestamp field in the credential for validity, and confirming that the target IP falls within the network segment prefix authorized by the credential.
[0014] In S5, the anti-replay feature includes the random number identifier of the currently suspended network session and the session creation timestamp.
[0015] In S1, the blockchain light node interface module adopts a simple payment verification synchronization mechanism.
[0016] In S4, the first Boolean judgment logic specifically includes: the authentication end performs a hash operation on the incoming payload to obtain a first hash value, compares the first hash value with the base hash value stored in the target tuple pulled from the chain; at the same time, it obtains the current network time, verifies whether the timestamp field in the credential is in an unexpired state and checks whether the target IP address matches the authorized IP address range prefix in the credential. If all conditions are met, the first authorization verification passes.
[0017] In S5, the second Boolean judgment logic specifically includes: the cryptographic authentication module extracts the target parsing node public key from the verified target tuple, uses the target parsing node public key to perform a signature verification algorithm on the self-signature, and uses the anti-replay feature as the original message input during verification. If the signature verification passes, it is determined that the target parsing node has the legal signature capability for the anti-replay feature, and the entity control verification passes.
[0018] The authentication terminal also includes a session management unit. When the global authentication decision fails, the network interception module releases the suspension and blocks the communication request, triggers alarm log recording and counter accumulation operations, and adds the target IP address to the dynamic blacklist when the number of authentication failures of the same target IP address within a unit time window exceeds a preset threshold.
[0019] After the secure data communication tunnel is established, the authentication end periodically re-executes S2 to S5 to perform sliding window re-authentication on the established communication tunnel. If any re-authentication fails, the secure data communication tunnel is immediately cut off and the local access control policy is rolled back.
[0020] The beneficial effects of this invention are mainly reflected in the following aspects: 1. Compared with the prior art, the present invention can effectively solve the problems of cross-domain authentication difficulties of existing recursive resolution nodes in wide area networks, the susceptibility of traditional reverse DNS records to tampering, and the low resolution efficiency and lack of real authoritative trust endorsement caused by the full on-chaining of existing blockchain domain name solutions.
[0021] 2. This invention addresses the problem of excessively long certificate chains leading to bloated messages in traditional public key infrastructures by implementing a reverse DNS out-of-band indexing mechanism. In the step of obtaining the out-of-band index, the domain name system only needs to issue an asset identifier index and self-signature of a very small number of bytes, while the large-capacity ownership certificate containing the target public key is stripped to blockchain storage. This architectural decoupling greatly reduces the network bandwidth overhead of the DNS protocol and fundamentally eliminates the UDP packet truncation problem caused by excessively large response messages and the risk of DNS amplification reflection attacks.
[0022] 3. This invention creatively designs a serially progressive dual asymmetric signature verification mechanism. The first verification uses on-chain credentials to verify the source legitimacy and time validity of the IP prefix allocation. The second verification, combined with session characteristics to prevent replay, verifies the peer node's absolute physical control over the target IP private key. Even if an attacker successfully hijacks the border gateway protocol route or tamperes with the DNS record at the network layer, they still cannot pass the second calculation decision because they cannot steal the underlying physical private key of the target resolution node. Thus, a highly reliable security barrier is built at the network boundary.
[0023] 4. This invention creatively integrates all core technical actions, such as network process suspension, protocol query encapsulation, response message parsing, cross-network data retrieval from the blockchain, and dual cryptographic decision-making, into a single authentication terminal for independent execution. This establishes a one-way closed-loop authentication architecture with the authentication terminal as the absolute core, completely eliminating the engineering barriers and potential infringement risks associated with multi-entity collaboration.
[0024] 5. In this invention, the authentication terminal, as the only physical and logical entity with complete authentication decision-making capabilities, can seamlessly access the existing network in the mode of external plug-in or bypass auditing, and is completely transparent to the underlying standard communication protocol stack. This one-sided closed-loop architecture, which is initiated and terminated entirely by the authentication terminal, eliminates any system adaptation and modification costs on the target parsing node side.
[0025] 6. This invention introduces a blockchain network as a persistent read-only state machine through a light node interface, eliminating the need for the authentication end to rely on a centralized certificate revocation list or online certificate status protocol server for real-time queries. The combination of on-chain ownership credentials and top-level authorized encrypted signatures not only ensures the global consistency and tamper-proof nature of the credentials, but also endows the authentication end with high resilience in the face of partial network paralysis or distributed denial-of-service attacks, significantly improving the overall fault tolerance and availability of the authentication system.
[0026] 7. This invention can both eliminate the need for traditional heavy PKI certificate direct transmission and achieve cross-domain security verification. It also features a lightweight identity authentication architecture with high reliability and easy one-sided deployment, which can effectively solve the current technical problem that network node identities are easily forged and difficult to verify efficiently. Attached Figure Description
[0027] The present invention will now be further described in detail with reference to the accompanying drawings and specific embodiments, wherein: Figure 1 This is a flowchart of the present invention; Figure 2 This is a schematic diagram illustrating the connection between the authentication terminal and the blockchain of this invention. Detailed Implementation
[0028] Example 1 See Figure 1 and Figure 2 The recursive resolution node authentication method based on blockchain and reverse DNS linkage includes the following steps: S1. Trust Anchor Point and Verification Environment Initialization The authentication end loads the pre-set public key of the superior trusted node in the secure storage module into the protected memory context, establishes it as the absolute root of trust for local authentication and verification, initializes the blockchain light node interface module, and establishes the network communication state with the external blockchain network. S2, Reverse DNS out-of-band index acquisition When the network interception module of the authentication end detects a session establishment request for the target IP address, it suspends the network communication process. The authentication end calls the DNS resolution extraction engine to convert the target IP address into a standard reverse addressing format and encapsulates it to generate a reverse query message. It then sends the query to the reverse resolution zone of the domain name system through the network communication module and receives the response data stream containing lightweight text records returned by the domain name system. S3, Index Features and Self-Proofing Analysis The authentication end calls the parsing and extraction engine to perform string segmentation and extraction matching based on preset protocol delimiters on the text payload in the response data stream; S4. On-chain credential synchronization and first-level authorization verification The authentication endpoint extracts the asset identifier index, calls the blockchain light node interface module, initiates a remote procedure call to the blockchain network, and retrieves the target tuple bound to the asset identifier index. After the key is retrieved, the authentication end schedules the cryptographic authentication module to read the base public key. For the incoming The payload performs a hash operation and runs the first level of Boolean decision logic; S5. Verification and Communication Establishment of Second-Level Entity Control Rights If the first layer of authorization verification passes, the authentication terminal will then access the verified... The public key of the target parser node is extracted from the tuple, and the anti-replay feature of the currently suspended network session is extracted. Combined with the extracted self-signature, it is handed over to the cryptographic authentication module to perform the second Boolean judgment logic. The cryptographic authentication module calculates the global authentication decision result. When both the first authorization verification and the global authentication decision result pass, the network interception module of the authentication end releases the suspension of the target network communication process, modifies the local access control policy, and allows and establishes a secure data communication tunnel with the target parser node.
[0029] This embodiment is the most basic implementation method. Compared with the prior art, it can effectively solve the problems of cross-domain authentication difficulties of existing recursive resolution nodes in wide area networks, the susceptibility of traditional reverse DNS records to tampering, and the low resolution efficiency and lack of real authoritative trust endorsement caused by the full on-chaining of existing blockchain domain name solutions.
[0030] Example 2 See Figure 1 and Figure 2 The recursive resolution node authentication method based on blockchain and reverse DNS linkage includes the following steps: S1. Trust Anchor Point and Verification Environment Initialization The authentication end loads the pre-set public key of the superior trusted node in the secure storage module into the protected memory context, establishes it as the absolute root of trust for local authentication and verification, initializes the blockchain light node interface module, and establishes the network communication state with the external blockchain network. S2, Reverse DNS out-of-band index acquisition When the network interception module of the authentication end detects a session establishment request for the target IP address, it suspends the network communication process. The authentication end calls the DNS resolution extraction engine to convert the target IP address into a standard reverse addressing format and encapsulates it to generate a reverse query message. It then sends the query to the reverse resolution zone of the domain name system through the network communication module and receives the response data stream containing lightweight text records returned by the domain name system. S3, Index Features and Self-Proofing Analysis The authentication end calls the parsing and extraction engine to perform string segmentation and extraction matching based on preset protocol delimiters on the text payload in the response data stream; S4. On-chain credential synchronization and first-level authorization verification The authentication endpoint extracts the asset identifier index, calls the blockchain light node interface module, initiates a remote procedure call to the blockchain network, and retrieves the target tuple bound to the asset identifier index. After the key is retrieved, the authentication end schedules the cryptographic authentication module to read the base public key. For the incoming The payload performs a hash operation and runs the first level of Boolean decision logic; S5. Verification and Communication Establishment of Second-Level Entity Control Rights If the first layer of authorization verification passes, the authentication terminal will then access the verified... The public key of the target parser node is extracted from the tuple, and the anti-replay feature of the currently suspended network session is extracted. Combined with the extracted self-signature, it is handed over to the cryptographic authentication module to perform the second Boolean judgment logic. The cryptographic authentication module calculates the global authentication decision result. When both the first authorization verification and the global authentication decision result pass, the network interception module of the authentication end releases the suspension of the target network communication process, modifies the local access control policy, and allows and establishes a secure data communication tunnel with the target parser node.
[0031] Preferably, in step S1, the blockchain network pre-permanently stores an on-chain ownership certificate containing the target IP address range prefix and the target parsing node's public key, as well as the corresponding top-level authorized cryptographic signature.
[0032] In step S3, if the parsing fails, the authentication end discards the communication request that was suspended in step S2 and records the log; if the parsing is successful, the asset identifier index pointing to the credential data in the blockchain network and the self-signature generated by the target parsing node using the private key to the network feature parameters are extracted and loaded into the temporary variable area in memory to complete the acquisition of the out-of-band trust pointer.
[0033] This embodiment is a preferred implementation. To address the problem of excessively long certificate chains leading to bloated messages in traditional public key infrastructures, it implements a reverse DNS out-of-band indexing mechanism. In the step of obtaining the out-of-band index, the domain name system only needs to issue an asset identifier index and self-signature of a very small number of bytes, while the large-capacity ownership certificate containing the target public key is stripped to blockchain storage. This architectural decoupling greatly reduces the network bandwidth overhead of the DNS protocol and fundamentally eliminates the UDP packet truncation problem caused by excessively large response messages and the risk of DNS amplification reflection attacks.
[0034] Example 3 See Figure 1 and Figure 2 The recursive resolution node authentication method based on blockchain and reverse DNS linkage includes the following steps: S1. Trust Anchor Point and Verification Environment Initialization The authentication end loads the pre-set public key of the superior trusted node in the secure storage module into the protected memory context, establishes it as the absolute root of trust for local authentication and verification, initializes the blockchain light node interface module, and establishes the network communication state with the external blockchain network. S2, Reverse DNS out-of-band index acquisition When the network interception module of the authentication end detects a session establishment request for the target IP address, it suspends the network communication process. The authentication end calls the DNS resolution extraction engine to convert the target IP address into a standard reverse addressing format and encapsulates it to generate a reverse query message. It then sends the query to the reverse resolution zone of the domain name system through the network communication module and receives the response data stream containing lightweight text records returned by the domain name system. S3, Index Features and Self-Proofing Analysis The authentication end calls the parsing and extraction engine to perform string segmentation and extraction matching based on preset protocol delimiters on the text payload in the response data stream; S4. On-chain credential synchronization and first-level authorization verification The authentication endpoint extracts the asset identifier index, calls the blockchain light node interface module, initiates a remote procedure call to the blockchain network, and retrieves the target tuple bound to the asset identifier index. After the key is retrieved, the authentication end schedules the cryptographic authentication module to read the base public key. For the incoming The payload performs a hash operation and runs the first level of Boolean decision logic; S5. Verification and Communication Establishment of Second-Level Entity Control Rights If the first layer of authorization verification passes, the authentication terminal will then access the verified... The public key of the target parser node is extracted from the tuple, and the anti-replay feature of the currently suspended network session is extracted. Combined with the extracted self-signature, it is handed over to the cryptographic authentication module to perform the second Boolean judgment logic. The cryptographic authentication module calculates the global authentication decision result. When both the first authorization verification and the global authentication decision result pass, the network interception module of the authentication end releases the suspension of the target network communication process, modifies the local access control policy, and allows and establishes a secure data communication tunnel with the target parser node.
[0035] In S1, the blockchain network pre-permanently stores an on-chain ownership certificate containing the target IP address range prefix and the target parsing node's public key, as well as the corresponding top-level authorized cryptographic signature.
[0036] In step S3, if the parsing fails, the authentication end discards the communication request that was suspended in step S2 and records the log; if the parsing is successful, the asset identifier index pointing to the credential data in the blockchain network and the self-signature generated by the target parsing node using the private key to the network feature parameters are extracted and loaded into the temporary variable area in memory to complete the acquisition of the out-of-band trust pointer.
[0037] In S4, when running the first Boolean judgment logic, it also includes obtaining the current network time and comparing it with the timestamp field in the credential for validity, and confirming that the target IP falls within the network segment prefix authorized by the credential.
[0038] In S5, the anti-replay feature includes the random number identifier of the currently suspended network session and the session creation timestamp.
[0039] This embodiment is a preferred implementation, creatively designing a serially progressive dual asymmetric signature verification mechanism. The first verification uses on-chain credentials to verify the source legitimacy and time validity of the IP prefix allocation; the second verification, combined with the session characteristics to prevent replay, verifies the peer node's absolute physical control over the target IP private key. Even if an attacker successfully hijacks the border gateway protocol route or tamperes with the DNS record at the network layer, they still cannot pass the second calculation decision because they cannot steal the underlying physical private key of the target resolution node. Thus, a highly reliable security barrier is built at the network boundary.
[0040] Example 4 See Figure 1 and Figure 2The recursive resolution node authentication method based on blockchain and reverse DNS linkage includes the following steps: S1. Trust Anchor Point and Verification Environment Initialization The authentication end loads the pre-set public key of the superior trusted node in the secure storage module into the protected memory context, establishes it as the absolute root of trust for local authentication and verification, initializes the blockchain light node interface module, and establishes the network communication state with the external blockchain network. S2, Reverse DNS out-of-band index acquisition When the network interception module of the authentication end detects a session establishment request for the target IP address, it suspends the network communication process. The authentication end calls the DNS resolution extraction engine to convert the target IP address into a standard reverse addressing format and encapsulates it to generate a reverse query message. It then sends the query to the reverse resolution zone of the domain name system through the network communication module and receives the response data stream containing lightweight text records returned by the domain name system. S3, Index Features and Self-Proofing Analysis The authentication end calls the parsing and extraction engine to perform string segmentation and extraction matching based on preset protocol delimiters on the text payload in the response data stream; S4. On-chain credential synchronization and first-level authorization verification The authentication endpoint extracts the asset identifier index, calls the blockchain light node interface module, initiates a remote procedure call to the blockchain network, and retrieves the target tuple bound to the asset identifier index. After the key is retrieved, the authentication end schedules the cryptographic authentication module to read the base public key. For the incoming The payload performs a hash operation and runs the first level of Boolean decision logic; S5. Verification and Communication Establishment of Second-Level Entity Control Rights If the first layer of authorization verification passes, the authentication terminal will then access the verified... The public key of the target parser node is extracted from the tuple, and the anti-replay feature of the currently suspended network session is extracted. Combined with the extracted self-signature, it is handed over to the cryptographic authentication module to perform the second Boolean judgment logic. The cryptographic authentication module calculates the global authentication decision result. When both the first authorization verification and the global authentication decision result pass, the network interception module of the authentication end releases the suspension of the target network communication process, modifies the local access control policy, and allows and establishes a secure data communication tunnel with the target parser node.
[0041] In S1, the blockchain network pre-permanently stores an on-chain ownership certificate containing the target IP address range prefix and the target parsing node's public key, as well as the corresponding top-level authorized cryptographic signature.
[0042] In step S3, if the parsing fails, the authentication end discards the communication request that was suspended in step S2 and records the log; if the parsing is successful, the asset identifier index pointing to the credential data in the blockchain network and the self-signature generated by the target parsing node using the private key to the network feature parameters are extracted and loaded into the temporary variable area in memory to complete the acquisition of the out-of-band trust pointer.
[0043] More preferably, in step S4, when running the first Boolean judgment logic, the method further includes obtaining the current network time and comparing it with the timestamp field in the credential for validity, and confirming that the target IP falls within the network segment prefix authorized by the credential.
[0044] In S5, the anti-replay feature includes the random number identifier of the currently suspended network session and the session creation timestamp.
[0045] In S1, the blockchain light node interface module adopts a simple payment verification synchronization mechanism.
[0046] In S4, the first Boolean judgment logic specifically includes: the authentication end performs a hash operation on the incoming payload to obtain a first hash value, compares the first hash value with the base hash value stored in the target tuple pulled from the chain; at the same time, it obtains the current network time, verifies whether the timestamp field in the credential is in an unexpired state and checks whether the target IP address matches the authorized IP address range prefix in the credential. If all conditions are met, the first authorization verification passes.
[0047] This embodiment is a preferred implementation method. It creatively integrates all the core technical actions, such as network process suspension, protocol query encapsulation, response message parsing, cross-network data retrieval from the blockchain, and dual cryptographic decision-making, into a single authentication terminal for independent execution. This establishes a one-way closed-loop authentication architecture with the authentication terminal as the absolute core, completely eliminating the engineering barriers of multi-entity collaboration and the risk of separation and infringement.
[0048] Example 5 See Figure 1 and Figure 2 The recursive resolution node authentication method based on blockchain and reverse DNS linkage includes the following steps: S1. Trust Anchor Point and Verification Environment Initialization The authentication end loads the pre-set public key of the superior trusted node in the secure storage module into the protected memory context, establishes it as the absolute root of trust for local authentication and verification, initializes the blockchain light node interface module, and establishes the network communication state with the external blockchain network. S2, Reverse DNS out-of-band index acquisition When the network interception module of the authentication end detects a session establishment request for the target IP address, it suspends the network communication process. The authentication end calls the DNS resolution extraction engine to convert the target IP address into a standard reverse addressing format and encapsulates it to generate a reverse query message. It then sends the query to the reverse resolution zone of the domain name system through the network communication module and receives the response data stream containing lightweight text records returned by the domain name system. S3, Index Features and Self-Proofing Analysis The authentication end calls the parsing and extraction engine to perform string segmentation and extraction matching based on preset protocol delimiters on the text payload in the response data stream; S4. On-chain credential synchronization and first-level authorization verification The authentication endpoint extracts the asset identifier index, calls the blockchain light node interface module, initiates a remote procedure call to the blockchain network, and retrieves the target tuple bound to the asset identifier index. After the key is retrieved, the authentication end schedules the cryptographic authentication module to read the base public key. For the incoming The payload performs a hash operation and runs the first level of Boolean decision logic; S5. Verification and Communication Establishment of Second-Level Entity Control Rights If the first layer of authorization verification passes, the authentication terminal will then access the verified... The public key of the target parser node is extracted from the tuple, and the anti-replay feature of the currently suspended network session is extracted. Combined with the extracted self-signature, it is handed over to the cryptographic authentication module to perform the second Boolean judgment logic. The cryptographic authentication module calculates the global authentication decision result. When both the first authorization verification and the global authentication decision result pass, the network interception module of the authentication end releases the suspension of the target network communication process, modifies the local access control policy, and allows and establishes a secure data communication tunnel with the target parser node.
[0049] In S1, the blockchain network pre-permanently stores an on-chain ownership certificate containing the target IP address range prefix and the target parsing node's public key, as well as the corresponding top-level authorized cryptographic signature.
[0050] In step S3, if the parsing fails, the authentication end discards the communication request that was suspended in step S2 and records the log; if the parsing is successful, the asset identifier index pointing to the credential data in the blockchain network and the self-signature generated by the target parsing node using the private key to the network feature parameters are extracted and loaded into the temporary variable area in memory to complete the acquisition of the out-of-band trust pointer.
[0051] In S4, when running the first Boolean judgment logic, it also includes obtaining the current network time and comparing it with the timestamp field in the credential for validity, and confirming that the target IP falls within the network segment prefix authorized by the credential.
[0052] In S5, the anti-replay feature includes the random number identifier of the currently suspended network session and the session creation timestamp.
[0053] In S1, the blockchain light node interface module adopts a simple payment verification synchronization mechanism.
[0054] In S4, the first Boolean judgment logic specifically includes: the authentication end performs a hash operation on the incoming payload to obtain a first hash value, compares the first hash value with the base hash value stored in the target tuple pulled from the chain; at the same time, it obtains the current network time, verifies whether the timestamp field in the credential is in an unexpired state and checks whether the target IP address matches the authorized IP address range prefix in the credential. If all conditions are met, the first authorization verification passes.
[0055] In S5, the second Boolean judgment logic specifically includes: the cryptographic authentication module extracts the target parsing node public key from the verified target tuple, uses the target parsing node public key to perform a signature verification algorithm on the self-signature, and uses the anti-replay feature as the original message input during verification. If the signature verification passes, it is determined that the target parsing node has the legal signature capability for the anti-replay feature, and the entity control verification passes.
[0056] The authentication terminal also includes a session management unit. When the global authentication decision fails, the network interception module releases the suspension and blocks the communication request, triggers alarm log recording and counter accumulation operations, and adds the target IP address to the dynamic blacklist when the number of authentication failures of the same target IP address within a unit time window exceeds a preset threshold.
[0057] After the secure data communication tunnel is established, the authentication end periodically re-executes S2 to S5 to perform sliding window re-authentication on the established communication tunnel. If any re-authentication fails, the secure data communication tunnel is immediately cut off and the local access control policy is rolled back.
[0058] This embodiment is the best implementation. As the only physical and logical entity with complete authentication decision-making capabilities, the authentication terminal can seamlessly access the existing network in the mode of external or bypass auditing. It is completely transparent to the underlying standard communication protocol stack. This one-sided closed-loop architecture, which is initiated and terminated entirely by the authentication terminal, eliminates any system adaptation and modification costs on the target parsing node side.
[0059] By introducing the blockchain network as a persistent read-only state machine through the light node interface, the authentication end does not need to rely on a centralized certificate revocation list or online certificate status protocol server for real-time querying. The combination of on-chain ownership certificate and top-level authorized cryptographic signature not only ensures the global consistency and tamper-proof nature of the certificate, but also gives the authentication end high resilience in the face of partial network paralysis or distributed denial-of-service attacks, significantly improving the overall fault tolerance and availability of the authentication system.
[0060] This lightweight identity authentication architecture not only eliminates the need for traditional heavy PKI certificate direct transmission but also enables cross-domain security verification. It is highly reliable and easy to deploy on one side, effectively solving the current technical challenges of easily forged and inefficiently verified network node identities.
[0061] The basic principle of this invention is as follows: Addressing the technical challenges of cross-domain authentication, the vulnerability of reverse DNS records to tampering, and the complexity of deploying traditional public key infrastructure in existing technologies, this invention constructs a hierarchical root of trust by using the Internet Address Allocation Authority (IOA) as the authoritative node in the consortium blockchain. During IP address allocation, ownership credentials containing the IP prefix and the public key of the recursive resolution node are written into the blockchain, generating an asset identifier index. Instead of storing physical certificates in the DNS reverse lookup zone, only a lightweight text record containing the out-of-band index and a self-signed signature is configured. The authentication end obtains the on-chain index through reverse lookup and then pulls credentials from the consortium blockchain to perform dual cryptographic verification. This invention pioneers a reverse DNS out-of-band index mechanism, placing trust verification logic post-processing on the blockchain, achieving highly efficient and secure cross-domain resolution node authentication without increasing the DNS transmission burden.
[0062] To make the technical solution of the present invention clearer, the following describes in detail, in conjunction with specific embodiments, a formal method for the end-to-end practical operation of the recursive resolution node identity authentication method based on blockchain and reverse DNS linkage in the present invention.
[0063] First, the various entities, variables and cryptographic symbols used in the formal description of this specific embodiment are defined, as shown in Table 1. Table 1 is the system formal symbol and parameter definition table.
[0064] Table 1
[0065] Specific embodiments are described below: Step 1: The authentication terminal enters during the power-on startup or system initialization phase. In the status, the secure storage module of the authentication end will store the pre-installed public key of the superior trusted node. Load into a protected set of memory contexts In this process, an absolute root of trust is established for local authentication and verification; simultaneously, the identity verification terminal initializes the blockchain light node interface module, establishing a connection with the external blockchain network. Network communication status; System prerequisite constraints Establishment means that the authentication endpoint has the prerequisite topological conditions to retrieve trusted credential data across domains via a network interface; Step 2, when the network interception module on the authentication end is in Status detection for target address When a session establishment request, such as a TCP or SYN connection request, is received, the network communication process is temporarily suspended; subsequently, the authentication end calls the DNS resolution engine to convert the target address into a standard reverse addressing format and encapsulates it to generate a reverse lookup message. : The authentication terminal communicates with the Domain Name System via a network communication module. Send the message and wait to receive the response data stream containing resource records from the Domain Name System. ; Step 3: The authentication end calls the parsing and extraction engine to process the received data. In the data stream The text payload performs string segmentation and extraction matching based on preset protocol delimiters. If the parsing fails, the authentication end discards the pending communication request from step 2 and logs it; if the parsing succeeds, the parsing extraction engine extracts the identifier index pointing to the blockchain asset. and the self-signature generated by the peer. Load the temporary variable area into memory and complete the acquisition of the out-of-band trusted pointer; Step 4: The authentication end extracts data from memory. The blockchain light node interface module is invoked to initiate an RPC remote procedure call to the blockchain network, precisely retrieving the target tuple bound to the index. After the data is retrieved, the authentication end schedules the cryptographic authentication module to read... The base public key in For the incoming The payload performs a hash operation and runs the first level of Boolean decision logic. : During this process, the system obtains the current network time. The validity of the IP address is compared with the timestamp field in the credential, and it is confirmed that the target IP falls within the network segment prefix authorized by the credential; only when the cryptographic authentication module outputs... At that time, the system establishes the source legitimacy and data integrity of the credential; Step 5, in If the verification is successful, the authentication terminal will access the verified... Extract the public key of the target parser node from the tuple. Simultaneously, the system extracts anti-replay characteristics of the currently suspended network session, such as the initial sequence number or random nonce, and combines them with the information obtained in step 3. The second Boolean decision logic is then executed by the cryptographic authentication module. : Finally, the cryptographic authentication module calculates the global authentication decision result. If and only if At that time, it is proven that the peer entity does indeed hold a legitimate private key bound to the IP address; based on this decision, the network interception module of the authentication end releases the suspension of the target network communication process, modifies the local access control policy, officially allows access, and establishes a secure data communication tunnel with the target resolution node.
Claims
1. A recursive resolution node authentication method based on blockchain and reverse DNS linkage, characterized in that, Includes the following steps: S1. Trust Anchor Point and Verification Environment Initialization The authentication end loads the pre-set public key of the superior trusted node in the secure storage module into the protected memory context, establishes it as the absolute root of trust for local authentication and verification, initializes the blockchain light node interface module, and establishes the network communication state with the external blockchain network. S2, Reverse DNS out-of-band index acquisition When the network interception module of the authentication end detects a session establishment request for the target IP address, it suspends the network communication process. The authentication end calls the DNS resolution extraction engine to convert the target IP address into a standard reverse addressing format and encapsulates it to generate a reverse query message. It then sends the query to the reverse resolution zone of the domain name system through the network communication module and receives the response data stream containing lightweight text records returned by the domain name system. S3, Index Features and Self-Proofing Analysis The authentication end calls the parsing and extraction engine to perform string segmentation and extraction matching based on preset protocol delimiters on the text payload in the response data stream; S4. On-chain credential synchronization and first-level authorization verification The authentication endpoint extracts the asset identifier index, calls the blockchain light node interface module, initiates a remote procedure call to the blockchain network, and retrieves the target tuple bound to the asset identifier index. After the key is retrieved, the authentication end schedules the cryptographic authentication module to read the base public key. For the incoming The payload performs a hash operation and runs the first level of Boolean decision logic; S5. Verification and Communication Establishment of Second-Level Entity Control Rights If the first layer of authorization verification passes, the authentication terminal will then access the verified... The public key of the target parser node is extracted from the tuple, and the anti-replay feature of the currently suspended network session is extracted. Combined with the extracted self-signature, it is handed over to the cryptographic authentication module to perform the second Boolean judgment logic. The cryptographic authentication module calculates the global authentication decision result. When both the first authorization verification and the global authentication decision result pass, the network interception module of the authentication end releases the suspension of the target network communication process, modifies the local access control policy, and allows and establishes a secure data communication tunnel with the target parser node.
2. The recursive resolution node authentication method based on blockchain and reverse DNS linkage according to claim 1, characterized in that: In S1, the blockchain network pre-permanently stores an on-chain ownership certificate containing the target IP address range prefix and the target parsing node's public key, as well as the corresponding top-level authorized cryptographic signature.
3. The recursive resolution node authentication method based on blockchain and reverse DNS linkage according to claim 1, characterized in that: In step S3, if the parsing fails, the authentication end discards the communication request that was suspended in step S2 and records the log; if the parsing is successful, the asset identifier index pointing to the credential data in the blockchain network and the self-signature generated by the target parsing node using the private key to the network feature parameters are extracted and loaded into the temporary variable area in memory to complete the acquisition of the out-of-band trust pointer.
4. The recursive resolution node authentication method based on blockchain and reverse DNS linkage according to claim 1, characterized in that: In S4, when running the first Boolean judgment logic, it also includes obtaining the current network time and comparing it with the timestamp field in the credential for validity, and confirming that the target IP falls within the network segment prefix authorized by the credential.
5. The recursive resolution node authentication method based on blockchain and reverse DNS linkage according to claim 1, characterized in that: In S5, the anti-replay feature includes the random number identifier of the currently suspended network session and the session creation timestamp.
6. The recursive resolution node authentication method based on blockchain and reverse DNS linkage according to claim 1, characterized in that: In S1, the blockchain light node interface module adopts a simple payment verification synchronization mechanism.
7. The recursive resolution node authentication method based on blockchain and reverse DNS linkage according to claim 1, characterized in that: In S4, the first Boolean judgment logic specifically includes: the authentication end performs a hash operation on the incoming payload to obtain a first hash value, compares the first hash value with the base hash value stored in the target tuple pulled from the chain; at the same time, it obtains the current network time, verifies whether the timestamp field in the credential is in an unexpired state and checks whether the target IP address matches the authorized IP address range prefix in the credential. If all conditions are met, the first authorization verification passes.
8. The recursive resolution node authentication method based on blockchain and reverse DNS linkage according to claim 1, characterized in that: In S5, the second Boolean judgment logic specifically includes: the cryptographic authentication module extracts the target parsing node public key from the verified target tuple, uses the target parsing node public key to perform a signature verification algorithm on the self-signature, and uses the anti-replay feature as the original message input during verification. If the signature verification passes, it is determined that the target parsing node has the legal signature capability for the anti-replay feature, and the entity control verification passes.
9. The recursive resolution node authentication method based on blockchain and reverse DNS linkage according to claim 1, characterized in that: The authentication terminal also includes a session management unit. When the global authentication decision fails, the network interception module releases the suspension and blocks the communication request, triggers alarm log recording and counter accumulation operations, and adds the target IP address to the dynamic blacklist when the number of authentication failures of the same target IP address within a unit time window exceeds a preset threshold.
10. The recursive resolution node authentication method based on blockchain and reverse DNS linkage according to claim 1, characterized in that: After the secure data communication tunnel is established, the authentication end periodically re-executes S2 to S5 to perform sliding window re-authentication on the established communication tunnel. If any re-authentication fails, the secure data communication tunnel is immediately cut off and the local access control policy is rolled back.
Citation Information
Patent Citations
Safe and credible distributed industrial internet identifier analysis method and device
CN118381652A