Access control method, device, network side device, terminal and blockchain node

The access control method uses a blockchain ledger to verify terminal identities and attribute information, addressing vulnerabilities in centralized systems and enhancing resilience against DDoS attacks.

JP7766693B2Active Publication Date: 2025-11-10CHINA MOBILE COMM LTD RES INST +1
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2023539818
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-12-29
Filing Date
2021-12-27
Publication Date
2025-11-10
Estimated Expiration
2041-12-27

AI Technical Summary

Technical Problem

Conventional access control systems are vulnerable to single point failures due to Distributed Denial of Service (DDoS) attacks on centralized authentication servers, leading to system dysfunction.

Method used

An access control method utilizing a blockchain ledger to verify terminal identity through private key signature information and location, obtaining attribute information, and providing access control responses based on blockchain data.

Benefits of technology

Enhances system resilience against DDoS attacks by decentralizing authentication, reducing the risk of single point failures and maintaining system functionality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007766693000001
    Figure 0007766693000001
  • Figure 0007766693000002
    Figure 0007766693000002
  • Figure 0007766693000003
    Figure 0007766693000003
Patent Text Reader

Abstract

The present disclosure provides an access control method, an apparatus, a network side device, a terminal, and a blockchain node, in which the access control method includes receiving related information to be verified corresponding to an access request sent by a terminal, the related information to be verified including private key signature information of the terminal and location information of preset information in a blockchain; acquiring the preset information from a blockchain based on the location information; verifying the terminal based on the private key signature information and the preset information; if the verification is successful, acquiring attribute information of the terminal from a blockchain ledger based on the preset information; and feeding back a request response to access control to the terminal based on the attribute information.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] (CROSS-REFERENCE TO RELATED APPLICATIONS) This disclosure claims priority to a Chinese patent application filed in China on December 29, 2020, bearing application number 202011591112.0, the entire contents of which are incorporated herein by reference.

[0002] The present disclosure relates to the field of communications technology, and in particular to an access control method, an apparatus, a network side device, a terminal, and a blockchain node. [Background technology]

[0003] Access control is a method by which a system restricts the use of data resource capabilities to user identities and the policy groups to which they belong. Access control is an important foundation for system confidentiality, integrity, availability, and lawful use, and is one of the important policies for network security prevention and resource protection. It is also the different authorized accesses that subjects can have to themselves or their resources based on specific control policies or permissions.

[0004] The main purpose of access control is to ensure that data resources are used and managed effectively within legal limits by restricting access to objects by the accessing subject. For example, a system administrator controls user access to network resources such as servers, directories, and files. To achieve this goal, access control must complete two tasks: identify and verify users who access a system, and determine what type of access the user can have to a certain system resource.

[0005] The access control function can realize access control for an object or for a centrally located device. The former has a high demand on the object device and a serious impact on object performance when there is a large amount of access. The centrally located access control function is a currently commonly used technical means, in which an accessing subject initiates a request to a centralized access control system, and after authentication and authorization, the accessing subject begins accessing the guest.

[0006] In the prior art, it is understood that an access control system is a centralized device but is exposed to a network, making it vulnerable to network attacks such as Distributed Denial of Service (DDoS). If the controller is attacked by a network and stops providing services, the entire system may stop functioning normally.

[0007] In other words, the related technology has the problem of a single point of failure when a conventional authentication server is subjected to a DDoS attack. Summary of the Invention [Problem to be solved by the invention]

[0008] The present disclosure aims to provide an access control method, device, network side equipment, terminal, and blockchain node to solve the problem of single point failure caused by DDoS attacks on conventional authentication servers that exist in related technologies. [Means for solving the problem]

[0009] In order to solve the above technical problems, an embodiment of the present disclosure provides an access control method applied to a first network side device, the method comprising: receiving related information to be verified corresponding to the access request sent by the terminal, the related information to be verified including private key signature information of the terminal and Location of preset information in the blockchain ledger and Based on the location information, From the blockchain ledger obtaining the preset information; verifying the terminal based on the private key signature information and the preset information; If the verification is successful, obtain attribute information of the terminal from the blockchain ledger based on the preset information; feeding back a request response to access control to the terminal based on the attribute information; Here, the preset information includes public key information of the terminal, or first terminal identifier information based on the public key of the terminal, or second terminal identifier information not related to the public key of the terminal and public key information of the terminal, or the second terminal identifier information and a hash value of the public key of the terminal.

[0010] Optionally, receiving related information to be verified corresponding to an access request sent by the terminal includes: receiving an access request sent by said terminal, the access request being accompanied by relevant information to be verified; or receiving an access request sent by the terminal; feeding back a random number to the terminal based on the access request; receiving related information to be verified that is transmitted by the terminal based on the random number.

[0011] Optionally, when the preset information includes public key information of the terminal, verifying the terminal based on the private key signature information and the preset information includes: verifying the private key signature information using the public key information; If the verification is successful, acquiring attribute information of the terminal from a blockchain ledger based on the preset information, If the verification is successful, obtain corresponding third terminal identifier information from the blockchain ledger based on the public key information; When the third terminal identifier information is acquired, attribute information corresponding to the third terminal identifier information is acquired from the blockchain ledger as attribute information of the terminal.

[0012] Optionally, when the preset information includes the first terminal identifier information, verifying the terminal based on the private key signature information and the preset information includes: Obtaining public key information to be verified based on the first terminal identifier information and obtaining the public key information of the terminal stored from the blockchain ledger; verifying the public key information to be verified and the private key signature information based on public key information of the terminal; If the verification is successful, acquiring attribute information of the terminal from a blockchain ledger based on the preset information, If the verification is successful, the method includes obtaining attribute information of the terminal from a blockchain ledger based on the first terminal identifier information.

[0013] Optionally, when the preset information includes the second terminal identifier information and public key information, verifying the terminal based on the private key signature information and the preset information includes: Verifying the private key signature information using the public key information in the preset information, obtaining the public key information of the terminal stored from the blockchain ledger based on the second terminal identifier information, and verifying the public key information in the preset information based on the obtained public key information of the terminal; Or, The method includes verifying the private key signature information using public key information in the preset information, obtaining a hash value of the public key of the terminal stored from a blockchain ledger based on the second terminal identifier information, obtaining a hash value to be verified based on the public key information in the preset information, and verifying the hash value to be verified based on the obtained hash value of the public key of the terminal.

[0014] Optionally, when the preset information includes the second terminal identifier information and a hash value of a public key, verifying the terminal based on the private key signature information and the preset information includes: Obtaining the stored public key information of the terminal from a blockchain ledger based on the second terminal identifier information; obtaining public key information to be verified based on a hash value of the public key in the preset information; The method includes verifying the private key signature information based on the public key information to be verified, and verifying the public key information to be verified based on the acquired public key information of the terminal.

[0015] Optionally, if the verification is successful, obtaining attribute information of the terminal from a blockchain ledger based on the preset information; If the verification is successful, attribute information of the terminal is obtained from the blockchain ledger based on the second terminal identifier information.

[0016] Optionally, the private key signature information includes first signature information or second signature information, the first signature information being for signing a timestamp using the private key of the terminal, and the second signature information being for signing a random number sent by the first network side device in response to an access request using the private key of the terminal.

[0017] Optionally, if the private key signature information includes first signature information, the related information to be verified further includes the timestamp; Verifying the terminal based on the private key signature information and the preset information includes: checking whether the timestamp is within a valid period; If the timestamp is within a valid period, verifying the terminal based on the private key signature information and the preset information.

[0018] Optionally, the preset information further includes validity information of first information, and the first information includes at least one of the attribute information, the first terminal identifier information, and the second terminal identifier information; Verifying the terminal based on the private key signature information and the preset information includes: determining whether the first information is within a validity period based on the validity period information; If the first information is within a validity period, verifying the terminal based on the private key signature information and other information in the preset information excluding the validity period information.

[0019] Optionally, at least one authentication information related to the terminal is stored in the block chain ledger as encrypted information encrypted with a first key, and the related information to be verified further includes the first key encrypted with a public key of the first network side device; Before feeding back a request response for access control to the terminal based on the attribute information, the method further comprises: decrypting the first key encrypted with the public key using a private key of the first network side device to obtain the first key; decrypting the encrypted information obtained from the blockchain ledger based on the first key to obtain the at least one authentication information; wherein the at least one authentication information is: attribute information of the terminal; First terminal identifier information based on the public key of the terminal, second terminal identifier information not related to the public key of the terminal, or third terminal identifier information corresponding to the public key of the terminal; and, The terminal information includes at least one of public key information of the terminal or a hash value of the public key of the terminal.

[0020] Optionally, the at least one authentication information further includes a timestamp corresponding to the terminal and / or validity information of second information; wherein the timestamp is a timestamp obtained by signing using a private key of the terminal to obtain first signature information, The second information includes at least one of the attribute information, first terminal identifier information, second terminal identifier information, and third terminal identifier information.

[0021] An embodiment of the present disclosure further provides an access control method applied to a terminal, the method comprising: Sending related information to be verified corresponding to the access request to a first network side device, the related information to be verified including: private key signature information of the terminal; Location of preset information in the blockchain ledger and receiving a request response to access control fed back from the first network side device; Here, the preset information includes public key information of the terminal, or first terminal identifier information based on the public key of the terminal, or second terminal identifier information not related to the public key of the terminal and public key information of the terminal, or the second terminal identifier information and a hash value of the public key of the terminal.

[0022] Optionally, transmitting related information to be verified corresponding to the access request to a first network side device includes: sending an access request to the first network device accompanied by relevant information to be verified; or Sending an access request to a first network side device; receiving a random number fed back by the first network side device based on the access request; and transmitting related information to be verified to the first network side device based on the random number.

[0023] Optionally, the private key signature information includes first signature information or second signature information, the first signature information being for signing a timestamp using the private key of the terminal, and the second signature information being for signing a random number sent by the first network side device in response to an access request using the private key of the terminal.

[0024] Optionally, if the private key signature information includes first signature information, the related information to be verified further includes the timestamp.

[0025] Optionally, the preset information further includes validity period information of first information, and the first information includes at least one of attribute information of the terminal, the first terminal identifier information, and the second terminal identifier information.

[0026] Optionally, at least one authentication information related to the terminal is stored in a blockchain ledger as encrypted information encrypted with a first key, and the related information to be verified further includes the first key encrypted with a public key of the first network side device; wherein the at least one authentication information is: attribute information of the terminal; First terminal identifier information based on the public key of the terminal, second terminal identifier information not related to the public key of the terminal, or third terminal identifier information corresponding to the public key of the terminal; and, The terminal information includes at least one of public key information of the terminal or a hash value of the public key of the terminal.

[0027] Optionally, the at least one authentication information further includes a timestamp corresponding to the terminal and / or validity information of second information; wherein the timestamp is a timestamp obtained by signing using a private key of the terminal to obtain first signature information, The second information includes at least one of the attribute information, first terminal identifier information, second terminal identifier information, and third terminal identifier information.

[0028] Optionally, before sending related information to be verified corresponding to the access request to the first network side device, the method further comprises: sending information to be authenticated of the terminal to a first blockchain node; Here, the information to be authenticated includes user credentials and / or attribute information, and the user credentials include terminal identifier information.

[0029] An embodiment of the present disclosure further provides an access control method applied to a first blockchain node, the method comprising: receiving information to be authenticated transmitted by a terminal; authenticating the information to be authenticated; If the authentication is successful, storing at least one authentication information corresponding to the information to be authenticated in a blockchain ledger; wherein the information to be authenticated includes user credential information and / or attribute information, and the user credential information includes terminal identifier information; The at least one authentication information is attribute information of the terminal; First terminal identifier information based on the public key of the terminal, second terminal identifier information not related to the public key of the terminal, or third terminal identifier information corresponding to the public key of the terminal; and, The terminal information includes at least one of public key information of the terminal or a hash value of the public key of the terminal.

[0030] Optionally, the at least one authentication information further includes a timestamp corresponding to the terminal and / or validity information of second information; wherein the timestamp is a timestamp obtained by signing using a private key of the terminal to obtain first signature information, The second information includes at least one of the attribute information, first terminal identifier information, second terminal identifier information, and third terminal identifier information.

[0031] Optionally, if the authentication is successful, storing at least one authentication information corresponding to the information to be authenticated in a blockchain ledger; Randomly generating a first key for encryption; and encrypting the at least one authentication information using the first key before storing it in a blockchain ledger.

[0032] Optionally, after randomly generating a first key for encryption, the method further comprises: The first key is encrypted using the public key of the terminal and then stored in a blockchain ledger.

[0033] Optionally, authenticating the information to be authenticated comprises: Sending user credentials in the information to be authenticated to at least one second network side device for authentication based on a first preset policy; receiving a first authentication result and corresponding third signature information fed back from the at least one second network-side device; Obtaining a first final result of whether the authentication of the user credentials is successful or not based on a second preset policy, the first authentication result, and third signature information.

[0034] Optionally, authenticating the information to be authenticated comprises: transmitting attribute information in the information to be authenticated to at least one third network side device based on a first preset policy for authentication; receiving a second authentication result and corresponding fourth signature information fed back from the at least one third network-side device; and obtaining a second final result indicating whether the attribute information has been successfully authenticated based on a third preset policy, the second authentication result, and fourth signature information.

[0035] Optionally, authenticating the information to be authenticated comprises: sending the information to be authenticated to a second blockchain node; and, The method includes receiving a first authentication result and corresponding third signature information, which are fed back from the second blockchain node, corresponding to the user credential information in the information to be authenticated, and obtaining a first final result of whether the authentication of the user credential information is successful or not, based on a second preset policy, the first authentication result, and the third signature information; and / or receiving a second authentication result and corresponding fourth signature information, which are fed back from the second blockchain node, corresponding to the attribute information in the information to be authenticated, and obtaining a second final result of whether the authentication of the attribute information is successful or not, based on a third preset policy, the second authentication result, and the fourth signature information.

[0036] An embodiment of the present disclosure further provides an access control method applied to a second blockchain node, the method comprising: receiving information to be authenticated from the terminal sent by the first blockchain node; and, Sending user credentials in the information to be authenticated to at least one second network side device for authentication, and feeding back the first authentication result and corresponding third signature information from the at least one second network side device; and / or receiving the first authentication result and corresponding third signature information and feeding it back to the first blockchain node; and / or Sending attribute information in the information to be authenticated to at least one third network side device for authentication, and receiving a second authentication result and corresponding fourth signature information fed back from the at least one third network side device to the first block chain node; Here, the user authentication information includes terminal identifier information.

[0037] An embodiment of the present disclosure further provides an access control method applied to a second network side device, the method comprising: receiving user credentials to be authenticated from a terminal transmitted by a blockchain node; authenticating the user credential information to obtain a first authentication result and signing using third signature information; feeding back the first authentication result and the third signature information to the blockchain node; Wherein the blockchain node is a first blockchain node or a second blockchain node that communicates with the first blockchain node; The user credentials include terminal identifier information.

[0038] An embodiment of the present disclosure further provides an access control method applied to a third network side device, the method comprising: Receiving attribute information to be authenticated of a terminal transmitted by a blockchain node; authenticating the attribute information to obtain a second authentication result and signing the result using fourth signature information; feeding back the second authentication result and the fourth signature information to the blockchain node; Here, the blockchain node is a first blockchain node or a second blockchain node that communicates with the first blockchain node.

[0039] An embodiment of the present disclosure further provides an access control device applied to a first network side device, the device comprising: a first receiving module configured to receive related information to be verified corresponding to an access request sent by a terminal, the related information to be verified including private key signature information of the terminal; Location of preset information in the blockchain ledger a first receiving module including: Based on the location information, From the blockchain ledger a first acquisition module configured to acquire the preset information; a first verification module configured to verify the terminal based on the private key signature information and the preset information; a second receiving module configured to obtain attribute information of the terminal from a blockchain ledger based on the preset information if the verification is successful; a first feedback module configured to feed back a request response for access control to the terminal based on the attribute information; Here, the preset information includes public key information of the terminal, or first terminal identifier information based on the public key of the terminal, or second terminal identifier information not related to the public key of the terminal and public key information of the terminal, or the second terminal identifier information and a hash value of the public key of the terminal.

[0040] Optionally, receiving related information to be verified corresponding to an access request sent by the terminal includes: receiving an access request sent by said terminal, the access request being accompanied by relevant information to be verified; or receiving an access request sent by the terminal; feeding back a random number to the terminal based on the access request; receiving related information to be verified that is transmitted by the terminal based on the random number.

[0041] Optionally, when the preset information includes public key information of the terminal, verifying the terminal based on the private key signature information and the preset information includes: verifying the private key signature information using the public key information; If the verification is successful, acquiring attribute information of the terminal from a blockchain ledger based on the preset information, If the verification is successful, obtain corresponding third terminal identifier information from the blockchain ledger based on the public key information; When the third terminal identifier information is acquired, attribute information corresponding to the third terminal identifier information is acquired from the blockchain ledger as attribute information of the terminal.

[0042] Optionally, when the preset information includes the first terminal identifier information, verifying the terminal based on the private key signature information and the preset information includes: Obtaining public key information to be verified based on the first terminal identifier information and obtaining the public key information of the terminal stored from the blockchain ledger; verifying the public key information to be verified and the private key signature information based on public key information of the terminal; If the verification is successful, acquiring attribute information of the terminal from a blockchain ledger based on the preset information, If the verification is successful, the method includes obtaining attribute information of the terminal from a blockchain ledger based on the first terminal identifier information.

[0043] Optionally, when the preset information includes the second terminal identifier information and public key information, verifying the terminal based on the private key signature information and the preset information includes: Verifying the private key signature information using the public key information in the preset information, obtaining the public key information of the terminal stored from the blockchain ledger based on the second terminal identifier information, and verifying the public key information in the preset information based on the obtained public key information of the terminal; Or, The method includes verifying the private key signature information using public key information in the preset information, obtaining a hash value of the public key of the terminal stored from a blockchain ledger based on the second terminal identifier information, obtaining a hash value to be verified based on the public key information in the preset information, and verifying the hash value to be verified based on the obtained hash value of the public key of the terminal.

[0044] Optionally, when the preset information includes the second terminal identifier information and a hash value of a public key, verifying the terminal based on the private key signature information and the preset information includes: Obtaining the stored public key information of the terminal from a blockchain ledger based on the second terminal identifier information; obtaining public key information to be verified based on a hash value of the public key in the preset information; The method includes verifying the private key signature information based on the public key information to be verified, and verifying the public key information to be verified based on the acquired public key information of the terminal.

[0045] Optionally, if the verification is successful, obtaining attribute information of the terminal from a blockchain ledger based on the preset information; If the verification is successful, attribute information of the terminal is obtained from the blockchain ledger based on the second terminal identifier information.

[0046] Optionally, the private key signature information includes first signature information or second signature information, the first signature information being for signing a timestamp using the private key of the terminal, and the second signature information being for signing a random number sent by the first network side device in response to an access request using the private key of the terminal.

[0047] Optionally, if the private key signature information includes first signature information, the related information to be verified further includes the timestamp; Verifying the terminal based on the private key signature information and the preset information includes: checking whether the timestamp is within a valid period; If the timestamp is within a valid period, verifying the terminal based on the private key signature information and the preset information.

[0048] Optionally, the preset information further includes validity information of first information, and the first information includes at least one of the attribute information, the first terminal identifier information, and the second terminal identifier information; Verifying the terminal based on the private key signature information and the preset information includes: determining whether the first information is within a validity period based on the validity period information; If the first information is within a validity period, verifying the terminal based on the private key signature information and other information in the preset information excluding the validity period information.

[0049] Optionally, at least one authentication information related to the terminal is stored in the block chain ledger as encrypted information encrypted with a first key, and the related information to be verified further includes the first key encrypted with a public key of the first network side device; The access control device further comprises: a first decryption module configured to decrypt the first key encrypted with the public key using a private key of the first network side device to obtain the first key before feeding back a request response to access control to the terminal based on the attribute information; a second decryption module configured to decrypt the encrypted information obtained from the blockchain ledger based on the first key to obtain the at least one authentication information; wherein the at least one authentication information is: attribute information of the terminal; First terminal identifier information based on the public key of the terminal, second terminal identifier information not related to the public key of the terminal, or third terminal identifier information corresponding to the public key of the terminal; and, The terminal information includes at least one of public key information of the terminal or a hash value of the public key of the terminal. Optionally, the at least one authentication information further includes a timestamp corresponding to the terminal and / or validity information of second information; wherein the timestamp is a timestamp obtained by signing using a private key of the terminal to obtain first signature information, The second information includes at least one of the attribute information, first terminal identifier information, second terminal identifier information, and third terminal identifier information.

[0050] An embodiment of the present disclosure further provides an access control device applied to a terminal, the device comprising: a first sending module configured to send related information to be verified corresponding to an access request to a first network side device, the related information to be verified including: private key signature information of the terminal; Location of preset information in the blockchain ledger a first transmitting module including: a third receiving module configured to receive a request response to access control fed back from the first network side device; Here, the preset information includes public key information of the terminal, or first terminal identifier information based on the public key of the terminal, or second terminal identifier information not related to the public key of the terminal and public key information of the terminal, or the second terminal identifier information and a hash value of the public key of the terminal.

[0051] Optionally, transmitting related information to be verified corresponding to the access request to a first network side device includes: sending an access request to the first network device accompanied by relevant information to be verified; or Sending an access request to a first network side device; receiving a random number fed back by the first network side device based on the access request; and transmitting related information to be verified to the first network side device based on the random number.

[0052] Optionally, the private key signature information includes first signature information or second signature information, the first signature information being for signing a timestamp using the private key of the terminal, and the second signature information being for signing a random number sent by the first network side device in response to an access request using the private key of the terminal.

[0053] Optionally, if the private key signature information includes first signature information, the related information to be verified further includes the timestamp.

[0054] Optionally, the preset information further includes validity period information of first information, and the first information includes at least one of attribute information of the terminal, the first terminal identifier information, and the second terminal identifier information.

[0055] Optionally, at least one authentication information related to the terminal is stored in a blockchain ledger as encrypted information encrypted with a first key, and the related information to be verified further includes the first key encrypted with a public key of the first network side device; wherein the at least one authentication information is: attribute information of the terminal; First terminal identifier information based on the public key of the terminal, second terminal identifier information not related to the public key of the terminal, or third terminal identifier information corresponding to the public key of the terminal; and, The terminal information includes at least one of public key information of the terminal or a hash value of the public key of the terminal. Optionally, the at least one authentication information further includes a timestamp corresponding to the terminal and / or validity information of second information; wherein the timestamp is a timestamp obtained by signing using a private key of the terminal to obtain first signature information, The second information includes at least one of the attribute information, first terminal identifier information, second terminal identifier information, and third terminal identifier information.

[0056] Selectable, and more A second sending module is configured to send the information to be authenticated of the terminal to the first blockchain node before sending the related information to be verified corresponding to the access request to the first network side device; Here, the information to be authenticated includes user credentials and / or attribute information, and the user credentials include terminal identifier information.

[0057] An embodiment of the present disclosure further provides an access control device applied to a first blockchain node, the device comprising: a fourth receiving module configured to receive information to be authenticated sent by the terminal; a first authentication module configured to authenticate the information to be authenticated; a first storage module configured to store at least one authentication information corresponding to the information to be authenticated in a blockchain ledger if the authentication is successful; wherein the information to be authenticated includes user credential information and / or attribute information, and the user credential information includes terminal identifier information; The at least one authentication information is attribute information of the terminal; First terminal identifier information based on the public key of the terminal, second terminal identifier information not related to the public key of the terminal, or third terminal identifier information corresponding to the public key of the terminal; and, The terminal information includes at least one of public key information of the terminal or a hash value of the public key of the terminal.

[0058] Optionally, the at least one authentication information further includes a timestamp corresponding to the terminal and / or validity information of second information; wherein the timestamp is a timestamp obtained by signing using a private key of the terminal to obtain first signature information, The second information includes at least one of the attribute information, first terminal identifier information, second terminal identifier information, and third terminal identifier information.

[0059] Optionally, if the authentication is successful, storing at least one authentication information corresponding to the information to be authenticated in a blockchain ledger; Randomly generating a first key for encryption; and encrypting the at least one authentication information using the first key before storing it in a blockchain ledger.

[0060] Selectable, and more The first processing module is configured to randomly generate a first key for encryption, and then encrypt the first key using the public key of the terminal before storing it in a blockchain ledger.

[0061] Optionally, authenticating the information to be authenticated comprises: Sending user credentials in the information to be authenticated to at least one second network side device for authentication based on a first preset policy; receiving a first authentication result and corresponding third signature information fed back from the at least one second network-side device; Obtaining a first final result of whether the authentication of the user credentials is successful or not based on a second preset policy, the first authentication result, and third signature information.

[0062] Optionally, authenticating the information to be authenticated comprises: transmitting attribute information in the information to be authenticated to at least one third network side device based on a first preset policy for authentication; receiving a second authentication result and corresponding fourth signature information fed back from the at least one third network-side device; and obtaining a second final result indicating whether the attribute information has been successfully authenticated based on a third preset policy, the second authentication result, and fourth signature information.

[0063] Optionally, authenticating the information to be authenticated comprises: sending the information to be authenticated to a second blockchain node; and, The method includes receiving a first authentication result and corresponding third signature information, which are fed back from the second blockchain node, corresponding to the user credential information in the information to be authenticated, and obtaining a first final result of whether the authentication of the user credential information is successful or not, based on a second preset policy, the first authentication result, and the third signature information; and / or receiving a second authentication result and corresponding fourth signature information, which are fed back from the second blockchain node, corresponding to the attribute information in the information to be authenticated, and obtaining a second final result of whether the authentication of the attribute information is successful or not, based on a third preset policy, the second authentication result, and the fourth signature information.

[0064] An embodiment of the present disclosure further provides an access control device applied to a second blockchain node, the device comprising: a fifth receiving module configured to receive the terminal information to be authenticated sent by the first blockchain node; and, A second processing module configured to send user credentials in the information to be authenticated to at least one second network side device for authentication, and receive a first authentication result and corresponding third signature information fed back from the at least one second network side device and feed it back to the first blockchain node; and / or a third processing module configured to send attribute information in the information to be authenticated to at least one third network side device for authentication, receive a second authentication result and corresponding fourth signature information fed back from the at least one third network side device, and feed it back to the first block chain node; Here, the user authentication information includes terminal identifier information.

[0065] An embodiment of the present disclosure further provides an access control device applied to a second network side device, the device comprising: a sixth receiving module configured to receive user credentials to be authenticated from the terminal sending the blockchain node; a fourth processing module configured to authenticate the user credentials, obtain a first authentication result, and sign using third signature information; a second feedback module configured to feed back the first authentication result and the third signature information to the blockchain node; Wherein the blockchain node is a first blockchain node or a second blockchain node that communicates with the first blockchain node; The user credentials include terminal identifier information.

[0066] An embodiment of the present disclosure further provides an access control device applied to a third network side device, the device comprising: a seventh receiving module configured to receive attribute information to be authenticated of the terminal sent by the blockchain node; a fifth processing module configured to authenticate the attribute information, obtain a second authentication result, and sign using fourth signature information; a third feedback module configured to feed back the second authentication result and the fourth signature information to the blockchain node; Here, the blockchain node is a first blockchain node or a second blockchain node that communicates with the first blockchain node.

[0067] An embodiment of the present disclosure further provides a network side device, the network side device is a first network side device, and includes a processor and a transceiver; The processor: receiving, via the transceiver, related information to be verified corresponding to an access request sent by a terminal, the related information to be verified including private key signature information of the terminal and Location of preset information in the blockchain ledger and Based on the location information, From the blockchain ledger obtaining the preset information; verifying the terminal based on the private key signature information and the preset information; If the verification is successful, obtain attribute information of the terminal from the blockchain ledger based on the preset information; and feeding back a request response to access control to the terminal via the transceiver based on the attribute information; Here, the preset information includes public key information of the terminal, or first terminal identifier information based on the public key of the terminal, or second terminal identifier information not related to the public key of the terminal and public key information of the terminal, or the second terminal identifier information and a hash value of the public key of the terminal.

[0068] Optionally, receiving related information to be verified corresponding to an access request sent by the terminal includes: receiving an access request sent by said terminal, the access request being accompanied by relevant information to be verified; or receiving an access request sent by the terminal; feeding back a random number to the terminal based on the access request; receiving related information to be verified that is transmitted by the terminal based on the random number.

[0069] Optionally, when the preset information includes public key information of the terminal, verifying the terminal based on the private key signature information and the preset information includes: verifying the private key signature information using the public key information; If the verification is successful, acquiring attribute information of the terminal from a blockchain ledger based on the preset information, If the verification is successful, obtain corresponding third terminal identifier information from the blockchain ledger based on the public key information; When the third terminal identifier information is acquired, attribute information corresponding to the third terminal identifier information is acquired from the blockchain ledger as attribute information of the terminal.

[0070] Optionally, when the preset information includes the first terminal identifier information, verifying the terminal based on the private key signature information and the preset information includes: Obtaining public key information to be verified based on the first terminal identifier information and obtaining the public key information of the terminal stored from the blockchain ledger; verifying the public key information to be verified and the private key signature information based on public key information of the terminal; If the verification is successful, acquiring attribute information of the terminal from a blockchain ledger based on the preset information, If the verification is successful, the method includes obtaining attribute information of the terminal from a blockchain ledger based on the first terminal identifier information.

[0071] Optionally, when the preset information includes the second terminal identifier information and public key information, verifying the terminal based on the private key signature information and the preset information includes: Verifying the private key signature information using the public key information in the preset information, obtaining the public key information of the terminal stored from the blockchain ledger based on the second terminal identifier information, and verifying the public key information in the preset information based on the obtained public key information of the terminal; Or, The method includes verifying the private key signature information using public key information in the preset information, obtaining a hash value of the public key of the terminal stored from a blockchain ledger based on the second terminal identifier information, obtaining a hash value to be verified based on the public key information in the preset information, and verifying the hash value to be verified based on the obtained hash value of the public key of the terminal.

[0072] Optionally, when the preset information includes the second terminal identifier information and a hash value of a public key, verifying the terminal based on the private key signature information and the preset information includes: Obtaining the stored public key information of the terminal from a blockchain ledger based on the second terminal identifier information; obtaining public key information to be verified based on a hash value of the public key in the preset information; The method includes verifying the private key signature information based on the public key information to be verified, and verifying the public key information to be verified based on the acquired public key information of the terminal.

[0073] Optionally, if the verification is successful, obtaining attribute information of the terminal from a blockchain ledger based on the preset information; If the verification is successful, attribute information of the terminal is obtained from the blockchain ledger based on the second terminal identifier information.

[0074] Optionally, the private key signature information includes first signature information or second signature information, the first signature information being for signing a timestamp using the private key of the terminal, and the second signature information being for signing a random number sent by the first network side device in response to an access request using the private key of the terminal.

[0075] Optionally, if the private key signature information includes first signature information, the related information to be verified further includes the timestamp; Verifying the terminal based on the private key signature information and the preset information includes: checking whether the timestamp is within a valid period; If the timestamp is within a valid period, verifying the terminal based on the private key signature information and the preset information.

[0076] Optionally, the preset information further includes validity information of first information, and the first information includes at least one of the attribute information, the first terminal identifier information, and the second terminal identifier information; Verifying the terminal based on the private key signature information and the preset information includes: determining whether the first information is within a validity period based on the validity period information; If the first information is within a validity period, verifying the terminal based on the private key signature information and other information in the preset information excluding the validity period information.

[0077] Optionally, at least one authentication information related to the terminal is stored in the block chain ledger as encrypted information encrypted with a first key, and the related information to be verified further includes the first key encrypted with a public key of the first network side device; The processor further comprises: Before feeding back a request response to access control to the terminal based on the attribute information, decrypting the first key encrypted with the public key using a private key of the first network side device to obtain the first key; decrypting the encrypted information obtained from the blockchain ledger based on the first key to obtain the at least one authentication information; wherein the at least one authentication information is: attribute information of the terminal; First terminal identifier information based on the public key of the terminal, second terminal identifier information not related to the public key of the terminal, or third terminal identifier information corresponding to the public key of the terminal; and, The terminal information includes at least one of public key information of the terminal or a hash value of the public key of the terminal.

[0078] Optionally, the at least one authentication information further includes a timestamp corresponding to the terminal and / or validity information of second information; wherein the timestamp is a timestamp obtained by signing using a private key of the terminal to obtain first signature information, The second information includes at least one of the attribute information, first terminal identifier information, second terminal identifier information, and third terminal identifier information.

[0079] An embodiment of the present disclosure further provides a terminal including a processor and a transceiver; The processor: Sending related information to be verified corresponding to the access request to a first network side device via the transceiver, wherein the related information to be verified includes private key signature information of the terminal and Location of preset information in the blockchain ledger and receiving a request response to access control fed back from the first network side device via the transceiver; Here, the preset information includes public key information of the terminal, or first terminal identifier information based on the public key of the terminal, or second terminal identifier information not related to the public key of the terminal and public key information of the terminal, or the second terminal identifier information and a hash value of the public key of the terminal.

[0080] Optionally, transmitting related information to be verified corresponding to the access request to a first network side device includes: sending an access request to the first network device accompanied by relevant information to be verified; or Sending an access request to a first network side device; receiving a random number fed back by the first network side device based on the access request; and transmitting related information to be verified to the first network side device based on the random number.

[0081] Optionally, the private key signature information includes first signature information or second signature information, the first signature information being for signing a timestamp using the private key of the terminal, and the second signature information being for signing a random number sent by the first network side device in response to an access request using the private key of the terminal.

[0082] Optionally, if the private key signature information includes first signature information, the related information to be verified further includes the timestamp.

[0083] Optionally, the preset information further includes validity period information of first information, and the first information includes at least one of attribute information of the terminal, the first terminal identifier information, and the second terminal identifier information.

[0084] Optionally, at least one authentication information related to the terminal is stored in a blockchain ledger as encrypted information encrypted with a first key, and the related information to be verified further includes the first key encrypted with a public key of the first network side device; wherein the at least one authentication information is: attribute information of the terminal; First terminal identifier information based on the public key of the terminal, second terminal identifier information not related to the public key of the terminal, or third terminal identifier information corresponding to the public key of the terminal; and, The terminal information includes at least one of public key information of the terminal or a hash value of the public key of the terminal.

[0085] Optionally, the at least one authentication information further includes a timestamp corresponding to the terminal and / or validity information of second information; wherein the timestamp is a timestamp obtained by signing using a private key of the terminal to obtain first signature information, The second information includes at least one of the attribute information, first terminal identifier information, second terminal identifier information, and third terminal identifier information.

[0086] Optionally, the processor further comprises: Before transmitting related information to be verified corresponding to the access request to the first network side device, the information to be authenticated of the terminal is transmitted to the first blockchain node via the transceiver; Here, the information to be authenticated includes user credentials and / or attribute information, and the user credentials include terminal identifier information.

[0087] An embodiment of the present disclosure further provides a blockchain node, the blockchain node being a first blockchain node, comprising a processor and a transceiver; The processor: receiving information to be authenticated transmitted by a terminal via the transceiver; authenticating the information to be authenticated; If the authentication is successful, storing at least one authentication information corresponding to the information to be authenticated in a blockchain ledger; wherein the information to be authenticated includes user credential information and / or attribute information, and the user credential information includes terminal identifier information; The at least one authentication information is attribute information of the terminal; First terminal identifier information based on the public key of the terminal, second terminal identifier information not related to the public key of the terminal, or third terminal identifier information corresponding to the public key of the terminal; and, The terminal information includes at least one of public key information of the terminal or a hash value of the public key of the terminal.

[0088] Optionally, the at least one authentication information further includes a timestamp corresponding to the terminal and / or validity information of second information; wherein the timestamp is a timestamp obtained by signing using a private key of the terminal to obtain first signature information, The second information includes at least one of the attribute information, first terminal identifier information, second terminal identifier information, and third terminal identifier information.

[0089] Optionally, if the authentication is successful, storing at least one authentication information corresponding to the information to be authenticated in a blockchain ledger; Randomly generating a first key for encryption; and encrypting the at least one authentication information using the first key before storing it in a blockchain ledger.

[0090] Optionally, the processor further comprises: The method is configured to randomly generate a first key for encryption, and then encrypt the first key using the public key of the terminal before storing it in a blockchain ledger.

[0091] Optionally, authenticating the information to be authenticated comprises: Sending user credentials in the information to be authenticated to at least one second network side device for authentication based on a first preset policy; receiving a first authentication result and corresponding third signature information fed back from the at least one second network-side device; Obtaining a first final result of whether the authentication of the user credentials is successful or not based on a second preset policy, the first authentication result, and third signature information.

[0092] Optionally, authenticating the information to be authenticated comprises: transmitting attribute information in the information to be authenticated to at least one third network side device based on a first preset policy for authentication; receiving a second authentication result and corresponding fourth signature information fed back from the at least one third network-side device; and obtaining a second final result indicating whether the attribute information has been successfully authenticated based on a third preset policy, the second authentication result, and fourth signature information.

[0093] Optionally, authenticating the information to be authenticated comprises: sending the information to be authenticated to a second blockchain node; and, The method includes receiving a first authentication result and corresponding third signature information, which are fed back from the second blockchain node, corresponding to the user credential information in the information to be authenticated, and obtaining a first final result of whether the authentication of the user credential information is successful or not, based on a second preset policy, the first authentication result, and the third signature information; and / or receiving a second authentication result and corresponding fourth signature information, which are fed back from the second blockchain node, corresponding to the attribute information in the information to be authenticated, and obtaining a second final result of whether the authentication of the attribute information is successful or not, based on a third preset policy, the second authentication result, and the fourth signature information.

[0094] An embodiment of the present disclosure further provides a blockchain node, the blockchain node being a second blockchain node, comprising a processor and a transceiver; The processor: receiving, via the transceiver, information to be authenticated of the terminal sent by the first blockchain node; and, Sending user credentials in the information to be authenticated to at least one second network side device via the transceiver for authentication, and feeding back a first authentication result and corresponding third signature information from the at least one second network side device; and / or receiving the first authentication result and corresponding third signature information and feeding it back to the first blockchain node; and / or The method is configured to execute the following: transmitting attribute information in the information to be authenticated to at least one third network side device via the transceiver for authentication; feeding back a second authentication result and corresponding fourth signature information from the at least one third network side device; and feeding back the second authentication result and corresponding fourth signature information to the first blockchain node; Here, the user authentication information includes terminal identifier information.

[0095] An embodiment of the present disclosure further provides a network side device, wherein the network side device is a second network side device, and includes a processor and a transceiver; The processor: receiving user credentials to be authenticated of a terminal transmitted by a blockchain node via the transceiver; authenticating the user credential information to obtain a first authentication result and signing using third signature information; and feeding back the first authentication result and the third signature information to the blockchain node via the transceiver; Wherein the blockchain node is a first blockchain node or a second blockchain node that communicates with the first blockchain node; The user credentials include terminal identifier information.

[0096] An embodiment of the present disclosure further provides a network side device, wherein the network side device is a third network side device, and includes a processor and a transceiver; The processor: Receiving attribute information to be authenticated of the terminal transmitted by the blockchain node via the transceiver; authenticating the attribute information to obtain a second authentication result and signing the result using fourth signature information; and feeding back the second authentication result and the fourth signature information to the blockchain node via the transceiver; Here, the blockchain node is a first blockchain node or a second blockchain node that communicates with the first blockchain node.

[0097] An embodiment of the present disclosure further provides a network side device, including a memory, a processor, and a program stored in the memory and executable by the processor, wherein when the processor executes the program, the access control method on the first network side device side is realized, or when the processor executes the program, the access control method on the second network side device side is realized, or when the processor executes the program, the access control method on the third network side device side is realized.

[0098] An embodiment of the present disclosure further provides a terminal, which includes a memory, a processor, and a program stored in the memory and executable by the processor, and when the processor executes the program, realizes the access control method on the terminal side.

[0099] An embodiment of the present disclosure further provides a blockchain node, including a memory, a processor, and a program stored in the memory and executable by the processor, wherein when the processor executes the program, the access control method on the first blockchain node side is realized, or when the processor executes the program, the access control method on the second blockchain node side is realized.

[0100] An embodiment of the present disclosure further provides a readable storage medium on which a program is stored, which, when executed by a processor, realizes steps in the access control method on the first network side device side, or when executed by a processor, realizes steps in the access control method on the terminal side, or when executed by a processor, realizes steps in the access control method on the first blockchain node side, or when executed by a processor, realizes steps in the access control method on the second blockchain node side, or when executed by a processor, realizes steps in the access control method on the second network side device side, or when executed by a processor, realizes steps in the access control method on the third network side device side. [Effects of the Invention]

[0101] The above technical solutions of the present disclosure have the following beneficial effects:

[0102] In the above technical solution, the access control method receives related information to be verified corresponding to an access request sent by a terminal, where the related information to be verified includes the private key signature information of the terminal and Location of preset information in the blockchain ledger and then, based on the location information, From the blockchain ledgerThe preset information is obtained, and the terminal is verified based on the private key signature information and the preset information. If the verification is successful, attribute information of the terminal is obtained from a blockchain ledger based on the preset information, and a request response for access control is fed back to the terminal based on the attribute information, wherein the preset information includes public key information of the terminal, or first terminal identifier information based on the public key of the terminal, or second terminal identifier information unrelated to the public key of the terminal and the public key information of the terminal, or a hash value of the second terminal identifier information and the public key of the terminal. In this way, it is possible to support the realization of a means for performing access control using blockchain, and by providing attribute verification services to clients using blockchain, it is possible to avoid problems such as a single point of failure caused by a DDoS attack on a conventional authentication server.

[0103] In order to more clearly describe the technical solutions of the embodiments of the present disclosure, the following briefly describes the drawings that need to be used to describe the embodiments of the present disclosure. Obviously, the drawings in the following description are only some embodiments of the present disclosure, and those skilled in the art can obtain other drawings based on these drawings without paying creative labor. [Brief explanation of the drawings]

[0104] [Figure 1] 1 is a flow diagram of an access control method according to an embodiment of the present disclosure (part 1); [Figure 2] FIG. 2 is a flow diagram of an access control method according to an embodiment of the present disclosure (part 2). [Figure 3] 1 is a flow diagram of an access control method according to an embodiment of the present disclosure (part 3). [Figure 4] FIG. 4 is a flow diagram of an access control method according to an embodiment of the present disclosure (part 4). [Figure 5] FIG. 5 is a flow diagram of an access control method according to an embodiment of the present disclosure (part 5). [Figure 6] FIG. 6 is a flow diagram of an access control method according to an embodiment of the present disclosure (part 6). [Figure 7] FIG. 1 is a schematic diagram of an implementation architecture of an access control method according to an embodiment of the present disclosure. [Figure 8a] 1 is a schematic diagram of a specific implementation flow of an access control method according to an embodiment of the present disclosure (part 1); [Figure 8b] FIG. 2 is a schematic diagram of a specific implementation flow of the access control method according to the embodiment of the present disclosure (part 2). [Figure 9] FIG. 1 is a schematic diagram (part 1) of an authentication architecture for information to be authenticated in an embodiment of the present disclosure. [Figure 10] FIG. 2 is a schematic diagram of an authentication architecture for information to be authenticated in an embodiment of the present disclosure (part 2). [Figure 11] 1 is a schematic diagram of the configuration of an access control device according to an embodiment of the present disclosure (part 1); [Figure 12] FIG. 2 is a schematic diagram of the configuration of an access control device according to an embodiment of the present disclosure (part 2). [Figure 13] FIG. 3 is a schematic diagram of the configuration of an access control device according to an embodiment of the present disclosure (part 3). [Figure 14] FIG. 4 is a schematic diagram of the configuration of an access control device according to an embodiment of the present disclosure (part 4). [Figure 15] FIG. 5 is a schematic diagram of the configuration of an access control device according to an embodiment of the present disclosure (part 5). [Figure 16] FIG. 6 is a schematic diagram illustrating the configuration of an access control device according to an embodiment of the present disclosure (part 6). [Figure 17] FIG. 1 is a schematic diagram of a network-side device structure according to an embodiment of the present disclosure (part 1); [Figure 18] FIG. 1 is a schematic diagram of a terminal structure according to an embodiment of the present disclosure. [Figure 19] FIG. 1 is a schematic diagram of a blockchain node structure according to an embodiment of the present disclosure (part 1). [Figure 20] FIG. 2 is a schematic diagram of a blockchain node structure according to an embodiment of the present disclosure (part 2). [Figure 21] FIG. 2 is a schematic diagram of the network side device structure according to an embodiment of the present disclosure (part 2); [Figure 22] FIG. 3 is a schematic diagram of the network side device structure according to an embodiment of the present disclosure (part 3); DETAILED DESCRIPTION OF THE INVENTION

[0105] To make the technical problems, technical solutions and advantages that the present disclosure aims to solve more clear, the following detailed description will be given with reference to the drawings and specific embodiments.

[0106] To address the problem of a single point of failure caused by a DDoS attack on a conventional authentication server present in related art, the present disclosure provides an access control method to be applied to a first network side device, which includes the following steps 11 to 15, as shown in FIG. 1.

[0107] In step 11, receiving related information to be verified corresponding to the access request sent by the terminal, the related information to be verified includes the private key signature information of the terminal and Location of preset information in the blockchain ledger Includes:

[0108] In step 12, based on the location information, From the blockchain ledger The preset information is obtained.

[0109] In step 13, the terminal is verified based on the private key signature information and the preset information.

[0110] In step 14, if the verification is successful, the attribute information of the terminal is obtained from the blockchain ledger based on the preset information.

[0111] In step 15, based on the attribute information, a request response for access control is fed back to the terminal, where the preset information includes public key information of the terminal, or first terminal identifier information based on the public key of the terminal, or second terminal identifier information unrelated to the public key of the terminal and public key information of the terminal, or the second terminal identifier information and a hash value of the public key of the terminal.

[0112] Specifically, step 15 may be to feed back a request response to access control to the terminal based on the attribute information and terminal identifier information, and the terminal identifier information may be the above-mentioned first terminal identifier information, second terminal identifier information or third terminal identifier information.

[0113] According to the access control method of the embodiment of the present disclosure, related information to be verified corresponding to an access request sent by a terminal is received, where the related information to be verified includes private key signature information of the terminal and Location of preset information in the blockchain ledger and then, based on the location information, From the blockchain ledger The preset information is obtained, and the terminal is verified based on the private key signature information and the preset information. If the verification is successful, attribute information of the terminal is obtained from a blockchain ledger based on the preset information, and a request response for access control is fed back to the terminal based on the attribute information, wherein the preset information includes public key information of the terminal, or first terminal identifier information based on the public key of the terminal, or second terminal identifier information unrelated to the public key of the terminal and the public key information of the terminal, or a hash value of the second terminal identifier information and the public key of the terminal. In this way, it is possible to support the realization of a means for performing access control using blockchain, and by providing attribute verification services to clients using blockchain, it is possible to avoid problems such as a single point of failure caused by a DDoS attack on a conventional authentication server.

[0114] Here, receiving the related information to be verified corresponding to the access request sent by the terminal includes receiving the access request sent by the terminal accompanied by the related information to be verified, or receiving the access request sent by the terminal, feeding back a random number to the terminal based on the access request, and receiving the related information to be verified sent by the terminal based on the random number.

[0115] In an embodiment of the present disclosure, if the preset information includes public key information of the terminal, verifying the terminal based on the private key signature information and the preset information includes verifying the private key signature information using the public key information, and if the verification is successful, obtaining attribute information of the terminal from the blockchain ledger based on the preset information includes, if the verification is successful, obtaining corresponding third terminal identifier information from the blockchain ledger based on the public key information, and if the third terminal identifier information is obtained, obtaining attribute information corresponding to the third terminal identifier information from the blockchain ledger as attribute information of the terminal.

[0116] Here, feeding back a request response for access control to the terminal based on the attribute information may include feeding back a request response for access control to the terminal based on the third terminal identifier information and attribute information.

[0117] In an embodiment of the present disclosure, when the preset information includes the first terminal identifier information, verifying the terminal based on the private key signature information and the preset information includes obtaining public key information to be verified and acquiring the public key information of the terminal stored from a blockchain ledger based on the first terminal identifier information, and verifying the public key information to be verified and the private key signature information based on the public key information of the terminal, and if the verification is successful, acquiring attribute information of the terminal from a blockchain ledger based on the preset information includes, if the verification is successful, acquiring attribute information of the terminal from a blockchain ledger based on the first terminal identifier information.

[0118] Here, feeding back a request response for access control to the terminal based on the attribute information includes feeding back a request response for access control to the terminal based on the first terminal identifier information and attribute information.

[0119] In an embodiment of the present disclosure, when the preset information includes the second terminal identifier information and public key information, verifying the terminal based on the private key signature information and the preset information includes: Verifying the private key signature information using the public key information in the preset information, obtaining the public key information of the terminal stored from the blockchain ledger based on the second terminal identifier information, and verifying the public key information in the preset information based on the obtained public key information of the terminal; Or, The method includes verifying the private key signature information using public key information in the preset information, obtaining a hash value of the public key of the terminal stored from a blockchain ledger based on the second terminal identifier information, obtaining a hash value to be verified based on the public key information in the preset information, and verifying the hash value to be verified based on the obtained hash value of the public key of the terminal.

[0120] Here, when the preset information includes the second terminal identifier information and a hash value of a public key, verifying the terminal based on the private key signature information and the preset information includes: obtaining public key information of the terminal stored from a blockchain ledger based on the second terminal identifier information; obtaining public key information to be verified based on the hash value of the public key in the preset information; verifying the private key signature information based on the public key information to be verified; and verifying the public key information to be verified based on the obtained public key information of the terminal.

[0121] In an embodiment of the present disclosure, if the verification is successful, obtaining attribute information of the terminal from the blockchain ledger based on the preset information includes, if the verification is successful, obtaining attribute information of the terminal from the blockchain ledger based on the second terminal identifier information.

[0122] Here, feeding back a request response for access control to the terminal based on the attribute information includes feeding back a request response for access control to the terminal based on the second terminal identifier information and attribute information.

[0123] In an embodiment of the present disclosure, the private key signature information includes first signature information or second signature information, the first signature information being for signing a timestamp using the private key of the terminal, and the second signature information being for signing a random number sent by the first network side device in response to an access request using the private key of the terminal.

[0124] Here, when the private key signature information includes first signature information, the related information to be verified further includes the timestamp, and verifying the terminal based on the private key signature information and the preset information includes checking whether the timestamp is within a valid period, and if the timestamp is within a valid period, verifying the terminal based on the private key signature information and the preset information.

[0125] Specifically, but not limited to, it may be determined whether the timestamp is within the validity period based on checking the timestamp itself.

[0126] In an embodiment of the present disclosure, the preset information further includes validity period information of first information, and the first information includes at least one of the attribute information, the first terminal identifier information, and the second terminal identifier information, and verifying the terminal based on the private key signature information and the preset information includes confirming whether the first information is within a validity period based on the validity period information, and if the first information is within a validity period, verifying the terminal based on the private key signature information and other information in the preset information excluding the validity period information.

[0127] Regarding "checking whether the first information is within its validity period based on the validity period information," specifically, this may involve first comparing the validity period information in the preset information based on the validity period information (validity period information of the second information) stored in the blockchain ledger, and then, if the pairing is successful, checking whether the first information is within its validity period based on the validity period information.

[0128] wherein at least one authentication information related to the terminal is stored in the blockchain ledger as encrypted information encrypted with a first key, and the related information to be verified further includes the first key encrypted with a public key of the first network side device; and before feeding back a request response for access control to the terminal based on the attribute information, the method further includes: decrypting the first key encrypted with the public key using a private key of the first network side device to obtain the first key; and decrypting the encrypted information obtained from the blockchain ledger based on the first key to obtain the at least one authentication information, wherein the at least one authentication information is: attribute information of the terminal; First terminal identifier information based on the public key of the terminal, second terminal identifier information not related to the public key of the terminal, or third terminal identifier information corresponding to the public key of the terminal; and, The terminal information includes at least one of public key information of the terminal or a hash value of the public key of the terminal.

[0129] Furthermore, the at least one authentication information further includes a timestamp corresponding to the terminal and / or validity information of second information, wherein the timestamp is a timestamp obtained by signing using the private key of the terminal to obtain first signature information, and the second information includes at least one of the attribute information, first terminal identifier information, second terminal identifier information, and third terminal identifier information.

[0130] The embodiment of the present disclosure further provides an access control method applied to a terminal, which includes steps 21 to 22, as shown in FIG.

[0131] In step 21, send related information to be verified corresponding to the access request to a first network side device, and the related information to be verified includes the private key signature information of the terminal and Location of preset information in the blockchain ledger Includes:

[0132] In step 22, receive a request response for access control fed back from the first network side device, where the preset information includes public key information of the terminal, or first terminal identifier information based on the public key of the terminal, or second terminal identifier information unrelated to the public key of the terminal and public key information of the terminal, or the second terminal identifier information and a hash value of the public key of the terminal.

[0133] According to the access control method of the embodiment of the present disclosure, related information to be verified corresponding to the access request is sent to a first network side device, where the related information to be verified includes private key signature information of the terminal and Location of preset information in the blockchain ledger and then receiving a request response for access control fed back from the first network side device, wherein the preset information includes public key information of the terminal, or first terminal identifier information based on the public key of the terminal, or second terminal identifier information unrelated to the public key of the terminal and public key information of the terminal, or a hash value of the second terminal identifier information and the public key of the terminal. In this way, it is possible to support the realization of a means for performing access control using blockchain, and by providing attribute verification services to clients in the form of blockchain, it is possible to avoid problems such as a single point of failure caused by a DDoS attack on a conventional authentication server.

[0134] Here, transmitting the related information to be verified corresponding to the access request to the first network side device includes transmitting the access request accompanied by the related information to be verified to the first network side device, or transmitting the access request to the first network side device, receiving a random number fed back by the first network side device based on the access request, and transmitting the related information to be verified to the first network side device based on the random number.

[0135] In an embodiment of the present disclosure, the private key signature information includes first signature information or second signature information, the first signature information being for signing a timestamp using the private key of the terminal, and the second signature information being for signing a random number sent by the first network side device in response to an access request using the private key of the terminal.

[0136] Here, when the private key signature information includes first signature information, the related information to be verified further includes the timestamp.

[0137] In an embodiment of the present disclosure, the preset information further includes validity information of first information, and the first information includes at least one of attribute information of the terminal, the first terminal identifier information, and the second terminal identifier information.

[0138] Here, at least one authentication information related to the terminal is stored in the blockchain ledger as encrypted information encrypted with a first key, and the related information to be verified further includes the first key encrypted with the public key of the first network side device, where the at least one authentication information is: attribute information of the terminal; First terminal identifier information based on the public key of the terminal, second terminal identifier information not related to the public key of the terminal, or third terminal identifier information corresponding to the public key of the terminal; and, The terminal information includes at least one of public key information of the terminal or a hash value of the public key of the terminal.

[0139] Furthermore, the at least one authentication information further includes a timestamp corresponding to the terminal and / or validity information of second information, wherein the timestamp is a timestamp obtained by signing using the private key of the terminal to obtain first signature information, and the second information includes at least one of the attribute information, first terminal identifier information, second terminal identifier information, and third terminal identifier information.

[0140] In an embodiment of the present disclosure, before sending the relevant information to be verified corresponding to the access request to the first network side device, the method further includes sending the information to be authenticated of the terminal to the first blockchain node, where the information to be authenticated includes user credentials and / or attribute information, and the user credentials include terminal identifier information.

[0141] An embodiment of the present disclosure further provides an access control method applied to a first blockchain node, which includes steps 31 to 33, as shown in FIG.

[0142] In step 31, information to be authenticated sent by the terminal is received.

[0143] In step 32, the information to be authenticated is authenticated.

[0144] In step 33, if the authentication is successful, store at least one authentication information corresponding to the information to be authenticated in the blockchain ledger, where the information to be authenticated includes user credentials and / or attribute information, the user credentials include terminal identifier information, and the at least one authentication information is: attribute information of the terminal; First terminal identifier information based on the public key of the terminal, second terminal identifier information not related to the public key of the terminal, or third terminal identifier information corresponding to the public key of the terminal; and, The terminal information includes at least one of public key information of the terminal or a hash value of the public key of the terminal.

[0145] Step 32 may specifically be to authenticate the information to be authenticated using a common recognition mechanism.

[0146] According to the above-mentioned access control method of the embodiment of the present disclosure, information to be authenticated sent by a terminal is received, the information to be authenticated is authenticated, and if the authentication is successful, at least one authentication information corresponding to the information to be authenticated is stored in a blockchain ledger, wherein the information to be authenticated includes user credentials and / or attribute information, the user credentials include terminal identifier information, and the at least one authentication information includes at least one of the attribute information of the terminal, first terminal identifier information based on the public key of the terminal, or second terminal identifier information unrelated to the public key of the terminal, or third terminal identifier information corresponding to the public key of the terminal, and public key information of the terminal or a hash value of the public key of the terminal. In this way, it is possible to support the realization of a means for performing access control using blockchain, and by providing attribute verification services to clients using blockchain, it is possible to avoid problems such as a single point of failure caused by a DDoS attack on a traditional authentication server.

[0147] Furthermore, the at least one authentication information further includes a timestamp corresponding to the terminal and / or validity information of second information, wherein the timestamp is a timestamp obtained by signing using the private key of the terminal to obtain first signature information, and the second information includes at least one of the attribute information, first terminal identifier information, second terminal identifier information, and third terminal identifier information.

[0148] Here, if the authentication is successful, storing at least one authentication information corresponding to the information to be authenticated in the blockchain ledger includes randomly generating a first key for encryption, and encrypting the at least one authentication information using the first key and then storing it in the blockchain ledger.

[0149] Furthermore, after randomly generating a first key for encryption, the method further includes encrypting the first key using the public key of the terminal before storing it in a blockchain ledger.

[0150] In a situation where multi-platform authentication is used, in an embodiment of the present disclosure, authenticating the information to be authenticated includes: sending user credentials in the information to be authenticated to at least one second network side device for authentication based on a first preset policy; receiving a first authentication result and corresponding third signature information fed back from the at least one second network side device; and obtaining a first final result of whether the authentication of the user credentials is successful or not based on the second preset policy, the first authentication result, and the third signature information; and / or Authenticating the information to be authenticated includes sending attribute information in the information to be authenticated to at least one third network side device for authentication based on a first preset policy; receiving a second authentication result and corresponding fourth signature information fed back from the at least one third network side device; and obtaining a second final result of whether the authentication of the attribute information is successful or not based on the third preset policy, the second authentication result, and the fourth signature information.

[0151] Here, the first preset policy, the third preset policy, and / or the third preset policy are policies that are set in advance or policies that are agreed upon in a smart contract.

[0152] In a situation where multi-platform authentication is used via an intermediate node, in an embodiment of the present disclosure, authenticating the information to be authenticated includes: sending the information to be authenticated to a second blockchain node; and, The method includes receiving a first authentication result and corresponding third signature information, which are fed back from the second blockchain node, corresponding to the user credential information in the information to be authenticated, and obtaining a first final result of whether the authentication of the user credential information is successful or not, based on a second preset policy, the first authentication result, and the third signature information; and / or receiving a second authentication result and corresponding fourth signature information, which are fed back from the second blockchain node, corresponding to the attribute information in the information to be authenticated, and obtaining a second final result of whether the authentication of the attribute information is successful or not, based on a third preset policy, the second authentication result, and the fourth signature information.

[0153] Here, the third preset policy and / or the third preset policy is a policy set in advance or a policy agreed upon in a smart contract.

[0154] An embodiment of the present disclosure further provides an access control method applied to a second blockchain node, which includes steps 41 to 42, as shown in FIG.

[0155] In step 41, the information to be authenticated of the terminal sent by the first blockchain node is received.

[0156] In step 42, the method includes sending user credential information in the information to be authenticated to at least one second network side device for authentication, feeding back the at least one second network side device, receiving a first authentication result and corresponding third signature information and feeding back the first authentication result to the first blockchain node, and / or sending attribute information in the information to be authenticated to at least one third network side device for authentication, feeding back the at least one third network side device, receiving a second authentication result and corresponding fourth signature information and feeding back the first blockchain node, where the user credential information includes terminal identifier information.

[0157] According to the above-mentioned access control method of the embodiment of the present disclosure, information to be authenticated of a terminal sent by a first blockchain node is received, and user credential information in the information to be authenticated is sent to at least one second network side device for authentication, and a first authentication result and corresponding third signature information fed back from the at least one second network side device are received and fed back to the first blockchain node; and / or attribute information in the information to be authenticated is sent to at least one third network side device for authentication, and a second authentication result and corresponding fourth signature information fed back from the at least one third network side device are received and fed back to the first blockchain node, where the user credential information includes terminal identifier information. In this way, it is possible to support the realization of a means for performing access control using blockchain, and by providing attribute verification services to clients in the form of blockchain, it is possible to avoid problems such as a single point of failure caused by a traditional authentication server being subjected to a DDoS attack.

[0158] The embodiment of the present disclosure further provides an access control method applied to a second network side device, which includes steps 51 to 53, as shown in FIG.

[0159] In step 51, the user credentials to be authenticated of the terminal sent by the blockchain node are received.

[0160] In step 52, the user credentials are authenticated to obtain a first authentication result, which is signed using third signature information.

[0161] In step 53, the first authentication result and the third signature information are fed back to the blockchain node, where the blockchain node is the first blockchain node or a second blockchain node that communicates with the first blockchain node, and the user credentials include terminal identifier information.

[0162] According to the above-mentioned access control method of the embodiment of the present disclosure, the user credential information to be authenticated of the terminal sent by the blockchain node is received, the user credential information is authenticated, a first authentication result is obtained, and signed using third signature information, and the first authentication result and the third signature information are fed back to the blockchain node, where the blockchain node is a first blockchain node or a second blockchain node communicating with the first blockchain node, and the user credential information includes terminal identifier information. In this way, it is possible to support the realization of a means for performing access control using blockchain, and by providing attribute verification services to clients in the form of blockchain, it is possible to avoid problems such as a single point of failure caused by a DDoS attack on a traditional authentication server.

[0163] The embodiment of the present disclosure further provides an access control method applied to a third network side device, which includes steps 61 to 63, as shown in FIG.

[0164] In step 61, attribute information to be authenticated of the terminal sent by the blockchain node is received.

[0165] In step 62, the attribute information is authenticated to obtain a second authentication result, which is signed using fourth signature information.

[0166] In step 63, the second authentication result and the fourth signature information are fed back to the blockchain node, where the blockchain node is the first blockchain node or a second blockchain node that communicates with the first blockchain node.

[0167] According to the above-mentioned access control method of the embodiment of the present disclosure, attribute information to be authenticated of the terminal sent by the blockchain node is received, the attribute information is authenticated, a second authentication result is obtained, and a signature is made using fourth signature information, and the second authentication result and the fourth signature information are fed back to the blockchain node, where the blockchain node is a first blockchain node or a second blockchain node that communicates with the first blockchain node. In this way, it is possible to support the realization of a means for performing access control using blockchain, and by providing attribute verification services to clients in the form of blockchain, it is possible to avoid problems such as a single point of failure caused by a DDoS attack on a traditional authentication server.

[0168] Below, the above access control method according to the embodiment of the present disclosure will be further described from multiple aspects, such as the first network side device, the second network side device, the third network side device, the terminal, the first blockchain node, and the second blockchain node.

[0169] To address the above technical issues, an embodiment of the present disclosure provides an access control method, which can be specifically implemented as a method for implementing access control using blockchain. By providing authentication and verification services to clients using blockchain, the problem of a single point of failure caused by a DDoS attack on a traditional authentication server can be avoided.

[0170] Specifically, as shown in FIG. 7, the realization architecture of the access control method according to the embodiment of the present disclosure relates to a user (corresponding to the terminal), a blockchain system (corresponding to the blockchain including a first blockchain node and a second blockchain node), and an application (corresponding to the first network-side device). The blockchain network nodes in the specific blockchain system are composed of multiple authentication nodes, among which the authentication nodes are mainly responsible for authenticating user identities (corresponding to the user credentials), authenticating user attributes (corresponding to the attribute information), and recording the authentication results in a blockchain ledger. When a user accesses a service system (corresponding to the first network-side device), the service system queries the blockchain for user identity and attribute information. Both the user (client end) and the service system (specifically, the application (server) in the system) possess their own public and private keys.

[0171] In this method, the user (client end) first submits an authentication request (corresponding to the above information to be authenticated) including identity authentication information (corresponding to the above user certification information) and attribute information to the blockchain system. The authentication node in the blockchain system authenticates the identity authentication information and attribute information respectively, and records the information that has passed authentication and consensus recognition in the blockchain ledger. The main flow is as follows:

[0172] Operation 1. The user (client end) submits identity authentication information and / or attribute information to the blockchain system.

[0173] Operation 2. The blockchain node (i.e., the first blockchain node) verifies the information (identity authentication information and / or attribute information) (specifically, it may verify the accuracy of this information).

[0174] Operation 3. After the above information has been authenticated and recognized by the blockchain node, the blockchain node records the user ID (corresponding to the above user certification information, which may specifically correspond to the first terminal identifier information, the second terminal identifier information, or the third terminal identifier information), and / or the user public key hash value and / or the user public key, user attribute information (i.e., the attribute information of the above terminal), validity period (i.e., the above validity period information), etc. in the blockchain ledger.

[0175] Optionally, data can be encrypted and stored to prevent information leakage. For example, the plaintext of the data that needs to be recorded is denoted as info, and the ciphertext recorded in the blockchain ledger is denoted as (Epk_C(K), Ek(info)). Here, pk_C is the user's public key. E stands for encryption, the subscript of E represents the key used, the data in parentheses represents the data, and K is the first key randomly generated by the blockchain node.

[0176] Operation 4: The user initiates an access request to the application server (corresponding to the above-mentioned first network side device).

[0177] a) Method 1 (Timestamp Signature) The information includes a timestamp, a signature of the user private key on the timestamp (i.e., the first signature information described above), the user ID and / or user public key hash value and / or user public key, user attribute information, validity period, and other information in the blockchain (i.e., the above location information), and if the user public key is not recorded in operation 3 (if a hash value is recorded), the user public key must also be included in this operation.

[0178] b) Method 2 (Random Number Signature) A request is made to not attach user information, and the application server returns a random number. The user signs the random number using his / her private key (i.e., the above-mentioned second signature information), and then sends the signature and the user ID and / or user public key hash value and / or user public key, user attribute information, validity period, and other information in the blockchain to the application server. If the user public key is not recorded in operation 3, the user public key must also be attached in this operation.

[0179] In addition, if the data is stored in encrypted form, in the above two methods, the access request should further include a decryption key (Epk_S(K)) (i.e., the first key encrypted with the public key of the first network side device), where pk_S is the public key of the application server.

[0180] Operation 5. The application server verifies the user (client end) by querying the relevant information in the blockchain ledger.

[0181] a) Method 1 (Timestamp Signature) The user public key is used to verify whether the signature on the timestamp is accurate, whether the timestamp is within the validity period, and whether the user public key or hash value matches with that recorded in the ledger. If the verification is successful, it is explained that the user is a user in the ledger and the attribute information recorded in the ledger is the attribute of the user, and the application server can further grant access permission (control access) using the attribute information and user ID.

[0182] b) Method 2 (Random Number Signature) The user public key is used to verify whether the signature on the random number is accurate, and whether the user public key or hash value matches the one recorded in the ledger. If the verification is successful, it is explained that the user is a user in the ledger, and the attribute information recorded in the ledger is the attribute of the user, and the application server can further grant access using the attribute information and user ID.

[0183] If the data is encrypted and stored, in the above two methods, the application server should further decrypt K using the server private key, and then perform a decryption operation (DK(Ek(info))) on the ciphertext in the ledger to obtain info, i.e., user information (user ID) and attribute information, where D represents decryption.

[0184] Specifically, in some embodiments, the above-mentioned access control method according to the embodiment of the present disclosure may include steps 81 to 88, as shown in FIG. 8a (taking the first network side device, which is an application server (gateway), as an example).

[0185] In step 81, the user (client end) sends an authentication request (corresponding to the information to be authenticated) to the blockchain node (i.e., the first blockchain node).

[0186] In step 82, the blockchain node performs an authentication operation.

[0187] In step 83, if the authentication is successful, it is recorded in the blockchain ledger (user ID and / or public key, attribute information).

[0188] In step 84, the blockchain node feeds back the authentication response to the user (client end).

[0189] In step 85, the user (client end) sends an access request to the application server (gateway).

[0190] In step 86, the application server (gateway) queries the blockchain ledger for user authentication and attribute information.

[0191] In step 87, the application server (gateway) validates the user (client end) based on the queried information.

[0192] In step 88, the application server (gateway) feeds back the request response to the user (client end).

[0193] In another embodiment, the access control method of the embodiment of the present disclosure can also be applied to a Software Defined Perimeter (SDP) scenario, and a specific implementation flow is shown in FIG. 8b (taking the first network side device as an SDP connection accepting host (AH) as an example), where the method includes steps 810 to 880.

[0194] In step 810, the SDP connection initiating host (IH) sends an authentication request (corresponding to the information to be authenticated) to a blockchain node (i.e., the first blockchain node).

[0195] In step 820, the blockchain node performs an authentication operation.

[0196] In step 830, if the authentication is successful, it is recorded in the blockchain ledger (IH's ID and / or public key, attribute information).

[0197] In step 840, the blockchain node feeds back the authentication response to the IH.

[0198] In step 850, the IH sends an access request to the AH.

[0199] In step 860, the AH queries the blockchain ledger for the IH authentication information and attribute information.

[0200] In step 870, the AH verifies the IH based on the queried information.

[0201] In step 880, the AH feeds back the request response to the IH.

[0202] In addition, in the authentication process of the above operation 2, if the identity authentication information and attribute information need to be authenticated by different nodes, the specific flow can be as follows:

[0203] Method one In this method, it is necessary to formulate an authentication policy (including the above-mentioned first preset policy, second preset policy and third preset policy) for the authentication information (i.e., identity authentication information) and attribute information, and the policy should include an information transfer policy (i.e., the above-mentioned first preset policy), as shown in FIG. 9: a) After receiving the identity authentication information and attribute information, the blockchain node transfers the authentication information and attribute information to the corresponding authentication node based on the policy (corresponding to sending the user credential information in the information to be authenticated to at least one second network side device for authentication, and sending the attribute information in the information to be authenticated to at least one third network side device for authentication), and different authentication nodes can authenticate different authentication information or attribute information, for example, attribute authentication node 1 authenticates attribute 1, attribute authentication node 2 authenticates attribute 2, and the present disclosure is not limited thereto.

[0204] b) The authentication information authentication node and the attribute authentication node each authenticate the above information and sign the authentication result.

[0205] Specifically, the credential authentication node may be an authentication server. For example, a user submits a username and password credential, and the blockchain node transfers the credential to the credential authentication node, which then authenticates the username and password. Here, the credential authentication node 1 and the credential authentication node 2 can be compared to WeChat and Alipay. When a user submits one of the passwords, the blockchain node submits the credential to the corresponding credential authentication node.

[0206] c) The authentication information authentication node and the attribute authentication node return the verification results (corresponding to the above-mentioned first authentication result and second authentication result) and the signatures for those results (corresponding to the above-mentioned third signature information and fourth signature information).

[0207] d) The blockchain node determines the final authentication result (corresponding to the first final result and second final result above) based on the received authentication result and signature.

[0208] Method 2 This method requires the use of an intermediate node (i.e., the second blockchain node), as shown in Figure 10: a) After receiving the identity authentication information and attribute information, the blockchain node (i.e., the first blockchain node) forwards the authentication information and attribute information to the intermediate node.

[0209] b) The intermediate node forwards the authentication information and attribute information to a corresponding authentication node (corresponding to sending the user credential information in the information to be authenticated to at least one second network side device for authentication, and sending the attribute information in the information to be authenticated to at least one third network side device for authentication), and different authentication nodes can authenticate different authentication information or attribute information, for example, attribute authentication node 1 authenticates attribute 1, attribute authentication node 2 authenticates attribute 2, and the present disclosure is not limited thereto.

[0210] c) The authentication information authentication node and the attribute authentication node each authenticate the above information and sign the authentication result.

[0211] Specifically, the credential authentication node may be an authentication server, for example, a user submits a username and password credential, the blockchain node transfers the credential to the credential authentication node, and the credential authentication node authenticates the username and password, where the credential authentication node 1 and the credential authentication node 2 can be compared to WeChat and Alipay, when a user submits one of the passwords, the blockchain node submits the credential to the corresponding credential authentication node.

[0212] d) The authentication information authentication node and the attribute authentication node transmit the authentication results (corresponding to the above-mentioned first authentication result and second authentication result) and the signatures for those results (corresponding to the above-mentioned third signature information and fourth signature information) to the intermediate node.

[0213] e) The blockchain node obtains the authentication result and signature from the intermediate node and determines the final authentication result (corresponding to the first final result and second final result above).

[0214] Such a scheme can reduce overhead and information interaction.

[0215] The following examples illustrate aspects of the present disclosure.

[0216] Example 1: Unified authentication (This example provides another implementation method for operation 5 above) In this example, the blockchain plays the role of a unified authentication platform, and a user submits an authentication request to the blockchain system. A blockchain node (corresponding to the first blockchain node) authenticates the user and records the user information, public key information, and attribute information in the blockchain ledger. When a user submits an access request to an application system, the application system needs to verify the user signature to ensure the accuracy of the user public key, and then query the blockchain for user information and attribute information based on the public key to authenticate the user.

[0217] 1. A user initiates an authentication request to the blockchain, accompanied by the information to be authenticated.

[0218] 2. The blockchain system authenticates the information to be authenticated from the user, and after successful authentication, records the user's identity or attribute information in the blockchain ledger.

[0219] 3. The user initiates an access request to the application system accompanied by a signature of the user's private key timestamp, or the application system sends a random number to the user, who signs the random number with their private key and sends it to the application system. Optionally, the access request may further be accompanied by the record location in the blockchain of the user's identity or attribute information.

[0220] 4. If the access request is accompanied by a public key, the application system can directly verify the user's signature using the public key, and if the signature is accurate, it can query the user's identity (user ID) and attribute information in the blockchain using the public key.

[0221] 5. The application system can further grant access permission using the attribute information and the user's identity.

[0222] Example 2: Double authentication (corresponding to the authentication methods in Figures 9 and 10 above) Some high-security application scenarios require very strict authentication of user identity, for example, requiring authentication information provided by two or more authentication mechanisms. In this embodiment, a user has authentication information from two authentication platforms (e.g., the WeChat platform and the Alipay platform). The user submits an authentication request to the blockchain system, which may include authentication data from multiple authentication platforms (e.g., the WeChat platform and the Alipay platform). The blockchain node extracts the user authentication data and sends it to the corresponding authentication platform for authentication, as shown in FIG. 9 or FIG. 10. The authentication platform authenticates the user based on the user's authentication data and returns the authentication result to the blockchain node. The blockchain node processes the authentication result based on the received authentication result using a preset policy or a policy agreed upon in a smart contract. The authentication node can obtain the authentication results for the user from the two authentication platforms, thereby realizing dual authentication of the user identity.

[0223] As can be seen from the above, an aspect of an embodiment of the present disclosure specifically relates to an access control method based on blockchain, in which a user (client end) submits an authentication request to a blockchain system, the blockchain verifies the authentication information and attribute information, and records the authenticated and consensus information in a blockchain ledger. When the user accesses a service system, the service system queries the blockchain for the user identity and attribute information.

[0224] Specifically, a user (client end) submits an authentication request including authentication information and attribute information to the blockchain system, and the blockchain node sends the authentication request to the corresponding authentication information authentication node and attribute information authentication node. The corresponding authentication information authentication node and attribute information authentication node authenticate the request and feed back the authentication result, and the blockchain node processes the authentication result.

[0225] As described above, according to the aspects of the embodiments of the present disclosure, the problem of a single point of failure can be avoided, and by realizing authentication and authorization using smart contracts, normal service will not be affected even if a node is tampered with.

[0226] The embodiment of the present disclosure further provides an access control device applied to a first network side device, as shown in FIG. 11 : a first receiving module 111 configured to receive related information to be verified corresponding to an access request sent by a terminal, wherein the related information to be verified includes private key signature information of the terminal; Location of preset information in the blockchain ledger a first receiving module 111 including: Based on the location information, From the blockchain ledger a first acquisition module 112 configured to acquire the preset information; a first verification module 113 configured to verify the terminal based on the private key signature information and the preset information; a second receiving module 114 configured to obtain attribute information of the terminal from the blockchain ledger based on the preset information if the verification is successful; a first feedback module 115 configured to feed back a request response for access control to the terminal based on the attribute information; Here, the preset information includes public key information of the terminal, or first terminal identifier information based on the public key of the terminal, or second terminal identifier information not related to the public key of the terminal and public key information of the terminal, or the second terminal identifier information and a hash value of the public key of the terminal.

[0227] According to the access control device according to the embodiment of the present disclosure, related information to be verified corresponding to an access request sent by a terminal is received, where the related information to be verified includes private key signature information of the terminal and Location of preset information in the blockchain ledger and then, based on the location information, From the blockchain ledger The preset information is obtained, and the terminal is verified based on the private key signature information and the preset information. If the verification is successful, attribute information of the terminal is obtained from a blockchain ledger based on the preset information, and a request response for access control is fed back to the terminal based on the attribute information, wherein the preset information includes public key information of the terminal, or first terminal identifier information based on the public key of the terminal, or second terminal identifier information unrelated to the public key of the terminal and the public key information of the terminal, or a hash value of the second terminal identifier information and the public key of the terminal. In this way, it is possible to support the realization of a means for performing access control using blockchain, and by providing attribute verification services to clients using blockchain, it is possible to avoid problems such as a single point of failure caused by a DDoS attack on a conventional authentication server.

[0228] Here, receiving the related information to be verified corresponding to the access request sent by the terminal includes receiving the access request sent by the terminal accompanied by the related information to be verified, or receiving the access request sent by the terminal, feeding back a random number to the terminal based on the access request, and receiving the related information to be verified sent by the terminal based on the random number.

[0229] In an embodiment of the present disclosure, if the preset information includes public key information of the terminal, verifying the terminal based on the private key signature information and the preset information includes verifying the private key signature information using the public key information, and if the verification is successful, obtaining attribute information of the terminal from the blockchain ledger based on the preset information includes, if the verification is successful, obtaining corresponding third terminal identifier information from the blockchain ledger based on the public key information, and if the third terminal identifier information is obtained, obtaining attribute information corresponding to the third terminal identifier information from the blockchain ledger as attribute information of the terminal.

[0230] Here, when the preset information includes the first terminal identifier information, verifying the terminal based on the private key signature information and the preset information includes obtaining public key information to be verified based on the first terminal identifier information and acquiring the public key information of the terminal stored from a blockchain ledger, and verifying the public key information to be verified and the private key signature information based on the public key information of the terminal, and if the verification is successful, acquiring attribute information of the terminal from a blockchain ledger based on the preset information includes, if the verification is successful, acquiring attribute information of the terminal from a blockchain ledger based on the first terminal identifier information.

[0231] In an embodiment of the present disclosure, when the preset information includes the second terminal identifier information and public key information, verifying the terminal based on the private key signature information and the preset information includes: Verifying the private key signature information using the public key information in the preset information, obtaining the public key information of the terminal stored from the blockchain ledger based on the second terminal identifier information, and verifying the public key information in the preset information based on the obtained public key information of the terminal; Or, The method includes verifying the private key signature information using public key information in the preset information, obtaining a hash value of the public key of the terminal stored from a blockchain ledger based on the second terminal identifier information, obtaining a hash value to be verified based on the public key information in the preset information, and verifying the hash value to be verified based on the obtained hash value of the public key of the terminal.

[0232] Here, when the preset information includes the second terminal identifier information and a hash value of a public key, verifying the terminal based on the private key signature information and the preset information includes: obtaining public key information of the terminal stored from a blockchain ledger based on the second terminal identifier information; obtaining public key information to be verified based on the hash value of the public key in the preset information; verifying the private key signature information based on the public key information to be verified; and verifying the public key information to be verified based on the obtained public key information of the terminal.

[0233] In an embodiment of the present disclosure, if the verification is successful, obtaining attribute information of the terminal from the blockchain ledger based on the preset information includes, if the verification is successful, obtaining attribute information of the terminal from the blockchain ledger based on the second terminal identifier information.

[0234] Here, the private key signature information includes first signature information or second signature information, the first signature information being used to sign a timestamp using the private key of the terminal, and the second signature information being used to sign a random number sent by the first network side device in response to an access request using the private key of the terminal.

[0235] In an embodiment of the present disclosure, when the private key signature information includes first signature information, the related information to be verified further includes the timestamp, and verifying the terminal based on the private key signature information and the preset information includes checking whether the timestamp is within a valid period, and if the timestamp is within a valid period, verifying the terminal based on the private key signature information and the preset information.

[0236] Here, the preset information further includes validity period information of first information, and the first information includes at least one of the attribute information, the first terminal identifier information, and the second terminal identifier information, and verifying the terminal based on the private key signature information and the preset information includes confirming whether the first information is within its validity period based on the validity period information, and if the first information is within its validity period, verifying the terminal based on the private key signature information and other information in the preset information excluding the validity period information.

[0237] In an embodiment of the present disclosure, at least one authentication information related to the terminal is stored in the blockchain ledger as encrypted information encrypted with a first key, and the related information to be verified further includes the first key encrypted with a public key of the first network side device, and the access control device further includes: a first decryption module configured to decrypt the first key encrypted with the public key using a private key of the first network side device to obtain the first key based on the attribute information before feeding back a request response for access control to the terminal; and a second decryption module configured to decrypt the encrypted information obtained from the blockchain ledger based on the first key to obtain the at least one authentication information, wherein the at least one authentication information is: attribute information of the terminal; First terminal identifier information based on the public key of the terminal, second terminal identifier information not related to the public key of the terminal, or third terminal identifier information corresponding to the public key of the terminal; and, The terminal information includes at least one of public key information of the terminal or a hash value of the public key of the terminal.

[0238] Furthermore, the at least one authentication information further includes a timestamp corresponding to the terminal and / or validity information of second information, wherein the timestamp is a timestamp obtained by signing using the private key of the terminal to obtain first signature information, and the second information includes at least one of the attribute information, first terminal identifier information, second terminal identifier information, and third terminal identifier information.

[0239] Here, any of the above-mentioned embodiments of the access control method on the first network side device side can be applied to the embodiments of the access control device, and can achieve the same technical effects.

[0240] The embodiment of the present disclosure further provides an access control device applied to a terminal, as shown in FIG. 12 : A first sending module 121 is configured to send related information to be verified corresponding to an access request to a first network side device, the related information to be verified includes private key signature information of the terminal and Location of preset information in the blockchain ledger a first transmitting module 121 including: a third receiving module 122 configured to receive a request response to access control fed back from the first network side device; Here, the preset information includes public key information of the terminal, or first terminal identifier information based on the public key of the terminal, or second terminal identifier information not related to the public key of the terminal and public key information of the terminal, or the second terminal identifier information and a hash value of the public key of the terminal.

[0241] According to the access control device according to the embodiment of the present disclosure, related information to be verified corresponding to the access request is sent to a first network side device, where the related information to be verified includes private key signature information of the terminal and Location of preset information in the blockchain ledgerand then receiving a request response for access control fed back from the first network side device, wherein the preset information includes public key information of the terminal, or first terminal identifier information based on the public key of the terminal, or second terminal identifier information unrelated to the public key of the terminal and public key information of the terminal, or a hash value of the second terminal identifier information and the public key of the terminal. In this way, it is possible to support the realization of a means for performing access control using blockchain, and by providing attribute verification services to clients in the form of blockchain, it is possible to avoid problems such as a single point of failure caused by a DDoS attack on a conventional authentication server.

[0242] Here, transmitting the related information to be verified corresponding to the access request to the first network side device includes transmitting the access request accompanied by the related information to be verified to the first network side device, or transmitting the access request to the first network side device, receiving a random number fed back by the first network side device based on the access request, and transmitting the related information to be verified to the first network side device based on the random number.

[0243] In an embodiment of the present disclosure, the private key signature information includes first signature information or second signature information, the first signature information being for signing a timestamp using the private key of the terminal, and the second signature information being for signing a random number sent by the first network side device in response to an access request using the private key of the terminal.

[0244] Here, when the private key signature information includes first signature information, the related information to be verified further includes the timestamp.

[0245] Furthermore, the preset information further includes validity period information of first information, and the first information includes at least one of attribute information of the terminal, the first terminal identifier information, and the second terminal identifier information.

[0246] Here, at least one authentication information related to the terminal is stored in the blockchain ledger as encrypted information encrypted with a first key, and the related information to be verified further includes the first key encrypted with the public key of the first network side device, where the at least one authentication information is: attribute information of the terminal; First terminal identifier information based on the public key of the terminal, second terminal identifier information not related to the public key of the terminal, or third terminal identifier information corresponding to the public key of the terminal; and, The terminal information includes at least one of public key information of the terminal or a hash value of the public key of the terminal.

[0247] Furthermore, the at least one authentication information further includes a timestamp corresponding to the terminal and / or validity information of second information, wherein the timestamp is a timestamp obtained by signing using the private key of the terminal to obtain first signature information, and the second information includes at least one of the attribute information, first terminal identifier information, second terminal identifier information, and third terminal identifier information.

[0248] Furthermore, the access control device further includes a second sending module configured to send the information of the terminal to be authenticated to the first blockchain node before sending the related information to be verified corresponding to the access request to the first network side device, where the information to be authenticated includes user credentials and / or attribute information, and the user credentials include terminal identifier information.

[0249] Here, any of the above-mentioned embodiments of the terminal-side access control method can be applied to the embodiments of the access control device, and the same technical effects can be achieved.

[0250] An embodiment of the present disclosure further provides an access control device applied to a first blockchain node, as shown in FIG. 13 : a fourth receiving module 131 configured to receive information to be authenticated sent by the terminal; a first authentication module 132 configured to authenticate the information to be authenticated; a first storage module 133 configured to store at least one authentication information corresponding to the information to be authenticated in a blockchain ledger if the authentication is successful; wherein the information to be authenticated includes user credential information and / or attribute information, and the user credential information includes terminal identifier information; The at least one authentication information is attribute information of the terminal; First terminal identifier information based on the public key of the terminal, second terminal identifier information not related to the public key of the terminal, or third terminal identifier information corresponding to the public key of the terminal; and, The terminal information includes at least one of public key information of the terminal or a hash value of the public key of the terminal.

[0251] According to the access control device of an embodiment of the present disclosure, information to be authenticated sent by a terminal is received, the information to be authenticated is authenticated, and if the authentication is successful, at least one authentication information corresponding to the information to be authenticated is stored in a blockchain ledger, wherein the information to be authenticated includes user credentials and / or attribute information, the user credentials include terminal identifier information, and the at least one authentication information includes at least one of the attribute information of the terminal, first terminal identifier information based on the public key of the terminal, or second terminal identifier information unrelated to the public key of the terminal, or third terminal identifier information corresponding to the public key of the terminal, and public key information of the terminal or a hash value of the public key of the terminal. In this way, it is possible to support the realization of a means for performing access control using blockchain, and by providing attribute verification services to clients using blockchain, it is possible to avoid problems such as a single point of failure caused by a DDoS attack on a traditional authentication server.

[0252] Furthermore, the at least one authentication information further includes a timestamp corresponding to the terminal and / or validity information of second information, wherein the timestamp is a timestamp obtained by signing using the private key of the terminal to obtain first signature information, and the second information includes at least one of the attribute information, first terminal identifier information, second terminal identifier information, and third terminal identifier information.

[0253] Here, if the authentication is successful, storing at least one authentication information corresponding to the information to be authenticated in the blockchain ledger includes randomly generating a first key for encryption, and encrypting the at least one authentication information using the first key and then storing it in the blockchain ledger.

[0254] Furthermore, the access control device further includes a first processing module configured to randomly generate a first key for encryption, and then encrypt the first key using the public key of the terminal before storing it in a blockchain ledger.

[0255] Here, authenticating the information to be authenticated includes sending user credential information in the information to be authenticated to at least one second network side device for authentication based on a first preset policy; receiving a first authentication result and corresponding third signature information fed back from the at least one second network side device; and obtaining a first final result of whether the authentication of the user credential information is successful or not based on the second preset policy, the first authentication result, and the third signature information.

[0256] In an embodiment of the present disclosure, authenticating the information to be authenticated includes: sending attribute information in the information to be authenticated to at least one third network side device for authentication based on a first preset policy; receiving a second authentication result and corresponding fourth signature information fed back from the at least one third network side device; and obtaining a second final result of whether the authentication of the attribute information is successful or not based on the third preset policy, the second authentication result, and the fourth signature information.

[0257] Here, authenticating the information to be authenticated includes: sending the information to be authenticated to a second blockchain node; and, The method includes receiving a first authentication result and corresponding third signature information, which are fed back from the second blockchain node, corresponding to the user credential information in the information to be authenticated, and obtaining a first final result of whether the authentication of the user credential information is successful or not, based on a second preset policy, the first authentication result, and the third signature information; and / or receiving a second authentication result and corresponding fourth signature information, which are fed back from the second blockchain node, corresponding to the attribute information in the information to be authenticated, and obtaining a second final result of whether the authentication of the attribute information is successful or not, based on a third preset policy, the second authentication result, and the fourth signature information.

[0258] Here, all of the above-mentioned implementation embodiments of the access control method on the first blockchain node side can be applied to the embodiments of the access control device, and can achieve the same technical effects. The embodiments of the present disclosure further provide an access control device applied to a second blockchain node, as shown in FIG. 14 : a fifth receiving module 141 configured to receive the terminal information to be authenticated sent by the first blockchain node; and, a second processing module 142 configured to send user credential information in the information to be authenticated to at least one second network side device for authentication, and feed back the at least one second network side device, receive a first authentication result and corresponding third signature information, and feed back the result to the first blockchain node; and / or a third processing module 143 configured to send attribute information in the information to be authenticated to at least one third network side device for authentication, and feed back the at least one third network side device, receive a second authentication result and corresponding fourth signature information, and feed back the result to the first blockchain node; Here, the user authentication information includes terminal identifier information.

[0259] According to the access control device of the embodiment of the present disclosure, the device receives information to be authenticated of a terminal sent by a first blockchain node, and sends user credential information in the information to be authenticated to at least one second network side device for authentication, receives a first authentication result and corresponding third signature information fed back from the at least one second network side device, and feeds it back to the first blockchain node; and / or sends attribute information in the information to be authenticated to at least one third network side device for authentication, receives a second authentication result and corresponding fourth signature information fed back from the at least one third network side device, and feeds it back to the first blockchain node, where the user credential information includes terminal identifier information. In this way, it can support the realization of a means for access control using blockchain, and by providing attribute verification services to clients using blockchain, it can avoid problems such as a single point of failure caused by a traditional authentication server being subjected to a DDoS attack.

[0260] Here, all of the above-mentioned implementation embodiments of the access control method on the second blockchain node side can be applied to the embodiments of the access control device, and can achieve the same technical effects.

[0261] The embodiment of the present disclosure further provides an access control device applied to a second network side device, as shown in FIG. 15 : a sixth receiving module 151 configured to receive user credentials to be authenticated from the terminal sending the blockchain node; a fourth processing module 152 configured to authenticate the user credentials, obtain a first authentication result, and sign using third signature information; a second feedback module 153 configured to feed back the first authentication result and the third signature information to the blockchain node; Wherein the blockchain node is a first blockchain node or a second blockchain node that communicates with the first blockchain node; The user credentials include terminal identifier information.

[0262] According to the access control device of the embodiment of the present disclosure, the device receives user credentials to be authenticated from a terminal sent by a blockchain node, authenticates the user credentials, obtains a first authentication result, signs using third signature information, and feeds back the first authentication result and the third signature information to the blockchain node, where the blockchain node is a first blockchain node or a second blockchain node that communicates with the first blockchain node, and the user credentials include terminal identifier information. In this way, it can support the realization of a means for performing access control using blockchain, and by providing attribute verification services to clients using blockchain, it can avoid problems such as a single point of failure caused by a DDoS attack on a traditional authentication server.

[0263] Here, any of the above-mentioned embodiments of the access control method on the second network side device side can be applied to the embodiments of the access control device, and the same technical effects can be achieved.

[0264] The embodiment of the present disclosure further provides an access control device applied to a third network side device, as shown in FIG. 16 : a seventh receiving module 161 configured to receive attribute information to be authenticated of the terminal sent by the blockchain node; a fifth processing module 162 configured to authenticate the attribute information, obtain a second authentication result, and sign using fourth signature information; a third feedback module 163 configured to feed back the second authentication result and the fourth signature information to the blockchain node; Here, the blockchain node is a first blockchain node or a second blockchain node that communicates with the first blockchain node.

[0265] According to the access control device of the embodiment of the present disclosure, the attribute information to be authenticated of the terminal sent by the blockchain node is received, the attribute information is authenticated, a second authentication result is obtained, and a signature is made using fourth signature information, and the second authentication result and the fourth signature information are fed back to the blockchain node, where the blockchain node is a first blockchain node or a second blockchain node that communicates with the first blockchain node. In this way, it is possible to support the realization of a means for performing access control using blockchain, and by providing attribute verification services to clients in the form of blockchain, it is possible to avoid problems such as a single point of failure caused by a DDoS attack on a traditional authentication server.

[0266] Here, any of the above-mentioned implementation embodiments of the access control method on the third network side device side can be applied to the embodiments of the access control device, and can achieve the same technical effects.

[0267] An embodiment of the present disclosure further provides a network side device, wherein the network side device is a first network side device, and includes a processor 171 and a transceiver 172, as shown in FIG. 17 ; The processor 171 receiving, via the transceiver 172, relevant information to be verified corresponding to the access request sent by the terminal, the relevant information to be verified including the private key signature information of the terminal and Location of preset information in the blockchain ledger and Based on the location information, From the blockchain ledger obtaining the preset information; verifying the terminal based on the private key signature information and the preset information; If the verification is successful, obtain attribute information of the terminal from the blockchain ledger based on the preset information; and feeding back a request response for access control to the terminal via the transceiver 172 based on the attribute information; Here, the preset information includes public key information of the terminal, or first terminal identifier information based on the public key of the terminal, or second terminal identifier information not related to the public key of the terminal and public key information of the terminal, or the second terminal identifier information and a hash value of the public key of the terminal.

[0268] According to the network side device of the embodiment of the present disclosure, related information to be verified corresponding to an access request sent by a terminal is received, where the related information to be verified includes private key signature information of the terminal and Location of preset information in the blockchain ledger and then, based on the location information, From the blockchain ledgerThe preset information is obtained, and the terminal is verified based on the private key signature information and the preset information. If the verification is successful, attribute information of the terminal is obtained from a blockchain ledger based on the preset information, and a request response for access control is fed back to the terminal based on the attribute information, wherein the preset information includes public key information of the terminal, or first terminal identifier information based on the public key of the terminal, or second terminal identifier information unrelated to the public key of the terminal and the public key information of the terminal, or a hash value of the second terminal identifier information and the public key of the terminal. In this way, it is possible to support the realization of a means for performing access control using blockchain, and by providing attribute verification services to clients using blockchain, it is possible to avoid problems such as a single point of failure caused by a DDoS attack on a conventional authentication server.

[0269] Here, receiving the related information to be verified corresponding to the access request sent by the terminal includes receiving the access request sent by the terminal accompanied by the related information to be verified, or receiving the access request sent by the terminal, feeding back a random number to the terminal based on the access request, and receiving the related information to be verified sent by the terminal based on the random number.

[0270] In an embodiment of the present disclosure, if the preset information includes public key information of the terminal, verifying the terminal based on the private key signature information and the preset information includes verifying the private key signature information using the public key information, and if the verification is successful, obtaining attribute information of the terminal from the blockchain ledger based on the preset information includes, if the verification is successful, obtaining corresponding third terminal identifier information from the blockchain ledger based on the public key information, and if the third terminal identifier information is obtained, obtaining attribute information corresponding to the third terminal identifier information from the blockchain ledger as attribute information of the terminal.

[0271] Here, when the preset information includes the first terminal identifier information, verifying the terminal based on the private key signature information and the preset information includes obtaining public key information to be verified based on the first terminal identifier information and acquiring the public key information of the terminal stored from a blockchain ledger, and verifying the public key information to be verified and the private key signature information based on the public key information of the terminal, and if the verification is successful, acquiring attribute information of the terminal from a blockchain ledger based on the preset information includes, if the verification is successful, acquiring attribute information of the terminal from a blockchain ledger based on the first terminal identifier information.

[0272] In an embodiment of the present disclosure, when the preset information includes the second terminal identifier information and public key information, verifying the terminal based on the private key signature information and the preset information includes: Verifying the private key signature information using the public key information in the preset information, obtaining the public key information of the terminal stored from the blockchain ledger based on the second terminal identifier information, and verifying the public key information in the preset information based on the obtained public key information of the terminal; Or, it includes verifying the private key signature information using public key information in the preset information, obtaining a hash value of the public key of the terminal stored from a blockchain ledger based on the second terminal identifier information, obtaining a hash value to be verified based on the public key information in the preset information, and verifying the hash value to be verified based on the obtained hash value of the public key of the terminal.

[0273] Here, when the preset information includes the second terminal identifier information and a hash value of a public key, verifying the terminal based on the private key signature information and the preset information includes: obtaining public key information of the terminal stored from a blockchain ledger based on the second terminal identifier information; obtaining public key information to be verified based on the hash value of the public key in the preset information; verifying the private key signature information based on the public key information to be verified; and verifying the public key information to be verified based on the obtained public key information of the terminal.

[0274] In an embodiment of the present disclosure, if the verification is successful, obtaining attribute information of the terminal from the blockchain ledger based on the preset information includes, if the verification is successful, obtaining attribute information of the terminal from the blockchain ledger based on the second terminal identifier information.

[0275] Here, the private key signature information includes first signature information or second signature information, the first signature information being used to sign a timestamp using the private key of the terminal, and the second signature information being used to sign a random number sent by the first network side device in response to an access request using the private key of the terminal.

[0276] In an embodiment of the present disclosure, when the private key signature information includes first signature information, the related information to be verified further includes the timestamp, and verifying the terminal based on the private key signature information and the preset information includes checking whether the timestamp is within a valid period, and if the timestamp is within a valid period, verifying the terminal based on the private key signature information and the preset information.

[0277] Here, the preset information further includes validity period information of first information, and the first information includes at least one of the attribute information, the first terminal identifier information, and the second terminal identifier information, and verifying the terminal based on the private key signature information and the preset information includes confirming whether the first information is within its validity period based on the validity period information, and if the first information is within its validity period, verifying the terminal based on the private key signature information and other information in the preset information excluding the validity period information.

[0278] In an embodiment of the present disclosure, at least one authentication information related to the terminal is stored in the blockchain ledger as encrypted information encrypted with a first key, and the related information to be verified further includes the first key encrypted with a public key of the first network side device, and the processor further: and is configured to perform the following operations before feeding back a request response to access control to the terminal based on the attribute information: decrypting the first key encrypted with the public key using a private key of the first network side device to obtain the first key; and decrypting the encrypted information obtained from the blockchain ledger based on the first key to obtain the at least one piece of authentication information; wherein the at least one authentication information is: attribute information of the terminal; First terminal identifier information based on the public key of the terminal, second terminal identifier information not related to the public key of the terminal, or third terminal identifier information corresponding to the public key of the terminal; and, The terminal information includes at least one of public key information of the terminal or a hash value of the public key of the terminal.

[0279] Furthermore, the at least one authentication information further includes a timestamp corresponding to the terminal and / or validity information of second information, wherein the timestamp is a timestamp obtained by signing using the private key of the terminal to obtain first signature information, and the second information includes at least one of the attribute information, first terminal identifier information, second terminal identifier information, and third terminal identifier information.

[0280] Here, all of the above-mentioned implementation embodiments of the access control method on the first network side device side can be applied to the embodiment of the network side device, and the same technical effects can be achieved.

[0281] An embodiment of the present disclosure further provides a terminal, as shown in FIG. 18 , including a processor 181 and a transceiver 182; The processor 181 Sending related information to be verified corresponding to the access request to the first network side device via the transceiver 182, wherein the related information to be verified includes private key signature information of the terminal and Location of preset information in the blockchain ledger and receiving a request response to access control fed back from the first network side device via the transceiver 182; Here, the preset information includes public key information of the terminal, or first terminal identifier information based on the public key of the terminal, or second terminal identifier information not related to the public key of the terminal and public key information of the terminal, or the second terminal identifier information and a hash value of the public key of the terminal.

[0282] According to the terminal according to the embodiment of the present disclosure, related information to be verified corresponding to the access request is sent to a first network side device, where the related information to be verified includes private key signature information of the terminal and Location of preset information in the blockchain ledgerand then receiving a request response for access control fed back from the first network side device, wherein the preset information includes public key information of the terminal, or first terminal identifier information based on the public key of the terminal, or second terminal identifier information unrelated to the public key of the terminal and public key information of the terminal, or a hash value of the second terminal identifier information and the public key of the terminal. In this way, it is possible to support the realization of a means for performing access control using blockchain, and by providing attribute verification services to clients in the form of blockchain, it is possible to avoid problems such as a single point of failure caused by a DDoS attack on a conventional authentication server.

[0283] In an embodiment of the present disclosure, sending the related information to be verified corresponding to the access request to the first network side device includes sending the access request accompanied by the related information to be verified to the first network side device, or sending the access request to the first network side device, receiving a random number fed back by the first network side device based on the access request, and sending the related information to be verified to the first network side device based on the random number.

[0284] Here, the private key signature information includes first signature information or second signature information, the first signature information being used to sign a timestamp using the private key of the terminal, and the second signature information being used to sign a random number sent by the first network side device in response to an access request using the private key of the terminal.

[0285] In an embodiment of the present disclosure, when the private key signature information includes first signature information, the related information to be verified further includes the timestamp.

[0286] Here, the preset information further includes validity period information of first information, and the first information includes at least one of attribute information of the terminal, the first terminal identifier information, and the second terminal identifier information.

[0287] In an embodiment of the present disclosure, at least one authentication information related to the terminal is stored in a blockchain ledger as encrypted information encrypted with a first key, and the related information to be verified further includes the first key encrypted with a public key of the first network side device, where the at least one authentication information is: attribute information of the terminal; First terminal identifier information based on the public key of the terminal, second terminal identifier information not related to the public key of the terminal, or third terminal identifier information corresponding to the public key of the terminal; and, The terminal information includes at least one of public key information of the terminal or a hash value of the public key of the terminal.

[0288] Furthermore, the at least one authentication information further includes a timestamp corresponding to the terminal and / or validity information of second information, wherein the timestamp is a timestamp obtained by signing using the private key of the terminal to obtain first signature information, and the second information includes at least one of the attribute information, first terminal identifier information, second terminal identifier information, and third terminal identifier information.

[0289] In an embodiment of the present disclosure, the processor further comprises: Before sending related information to be verified corresponding to the access request to a first network side device, the information to be authenticated of the terminal is configured to be sent to a first blockchain node via the transceiver, where the information to be authenticated includes user credentials and / or attribute information, and the user credentials include terminal identifier information.

[0290] Here, the above-mentioned implementation embodiments of the terminal-side access control method can all be applied to the terminal embodiment, and the same technical effects can be achieved.

[0291] An embodiment of the present disclosure further provides a blockchain node, wherein the blockchain node is a first blockchain node, and includes, as shown in FIG. 19 , a processor 191 and a transceiver 192; The processor 191 receiving, via said transceiver 192, information to be authenticated transmitted by a terminal; authenticating the information to be authenticated; If the authentication is successful, storing at least one authentication information corresponding to the information to be authenticated in a blockchain ledger; wherein the information to be authenticated includes user credential information and / or attribute information, and the user credential information includes terminal identifier information; The at least one authentication information is attribute information of the terminal; First terminal identifier information based on the public key of the terminal, second terminal identifier information not related to the public key of the terminal, or third terminal identifier information corresponding to the public key of the terminal; and, The terminal information includes at least one of public key information of the terminal or a hash value of the public key of the terminal.

[0292] According to the blockchain node of the embodiment of the present disclosure, information to be authenticated sent by a terminal is received, the information to be authenticated is authenticated, and if the authentication is successful, at least one authentication information corresponding to the information to be authenticated is stored in a blockchain ledger, wherein the information to be authenticated includes user credentials and / or attribute information, the user credentials include terminal identifier information, and the at least one authentication information includes at least one of the attribute information of the terminal, first terminal identifier information based on the public key of the terminal, or second terminal identifier information unrelated to the public key of the terminal, or third terminal identifier information corresponding to the public key of the terminal, and public key information of the terminal or a hash value of the public key of the terminal. In this way, it is possible to support the realization of a means for performing access control using blockchain, and by providing attribute verification services to clients using blockchain, it is possible to avoid problems such as a single point of failure caused by a DDoS attack on a traditional authentication server.

[0293] Here, the at least one authentication information further includes a timestamp corresponding to the terminal and / or validity information of the second information, wherein the timestamp is a timestamp obtained by signing using the private key of the terminal to obtain first signature information, and the second information includes at least one of the attribute information, first terminal identifier information, second terminal identifier information, and third terminal identifier information.

[0294] In an embodiment of the present disclosure, if the authentication is successful, storing at least one authentication information corresponding to the information to be authenticated in a blockchain ledger includes randomly generating a first key for encryption, and encrypting the at least one authentication information using the first key before storing it in the blockchain ledger.

[0295] wherein the processor further comprises: The method is configured to randomly generate a first key for encryption, and then encrypt the first key using the public key of the terminal before storing it in a blockchain ledger.

[0296] In an embodiment of the present disclosure, authenticating the information to be authenticated includes: sending user credentials in the information to be authenticated to at least one second network side device for authentication based on a first preset policy; receiving a first authentication result and corresponding third signature information fed back from the at least one second network side device; and obtaining a first final result of whether the authentication of the user credentials is successful or not based on the second preset policy, the first authentication result, and the third signature information.

[0297] Here, authenticating the information to be authenticated includes sending attribute information in the information to be authenticated to at least one third network side device for authentication based on a first preset policy; receiving a second authentication result and corresponding fourth signature information fed back from the at least one third network side device; and obtaining a second final result of whether the authentication of the attribute information is successful or not based on the third preset policy, the second authentication result, and the fourth signature information.

[0298] In an embodiment of the present disclosure, authenticating the information to be authenticated includes: sending the information to be authenticated to a second blockchain node; and, The method includes receiving a first authentication result and corresponding third signature information, which are fed back from the second blockchain node, corresponding to the user credential information in the information to be authenticated, and obtaining a first final result of whether the authentication of the user credential information is successful or not, based on a second preset policy, the first authentication result, and the third signature information; and / or receiving a second authentication result and corresponding fourth signature information, which are fed back from the second blockchain node, corresponding to the attribute information in the information to be authenticated, and obtaining a second final result of whether the authentication of the attribute information is successful or not, based on a third preset policy, the second authentication result, and the fourth signature information.

[0299] Here, all of the above implementation embodiments of the access control method on the first blockchain node side can be applied to the implementation of the blockchain node, and can achieve the same technical effects.

[0300] An embodiment of the present disclosure further provides a blockchain node, wherein the blockchain node is a second blockchain node, and includes a processor 201 and a transceiver 202, as shown in FIG. 20 ; The processor 201 receiving, via the transceiver 202, information to be authenticated of the terminal sent by the first blockchain node; and, Sending user credentials in the information to be authenticated to at least one second network side device via the transceiver 202 for authentication, and feeding back the first authentication result and corresponding third signature information from the at least one second network side device; and / or receiving the first authentication result and corresponding third signature information and feeding it back to the first blockchain node; and / or configured to execute the following: transmitting attribute information in the information to be authenticated to at least one third network side device via the transceiver 202 for authentication; feeding back a second authentication result and corresponding fourth signature information from the at least one third network side device; and feeding back the second authentication result and corresponding fourth signature information to the first blockchain node; Here, the user authentication information includes terminal identifier information.

[0301] According to the blockchain node of the embodiment of the present disclosure, the blockchain node receives the information to be authenticated of the terminal sent by the first blockchain node, and sends the user credential information in the information to be authenticated to at least one second network side device for authentication, receives the first authentication result and corresponding third signature information fed back from the at least one second network side device and feeds it back to the first blockchain node; and / or sends the attribute information in the information to be authenticated to at least one third network side device for authentication, receives the second authentication result and corresponding fourth signature information fed back from the at least one third network side device and feeds it back to the first blockchain node, where the user credential information includes terminal identifier information. In this way, it can support the realization of a means for performing access control using blockchain, and by providing attribute verification services to clients in the form of blockchain, it can avoid problems such as a single point of failure caused by a traditional authentication server being subjected to a DDoS attack.

[0302] Here, all of the above implementation embodiments of the access control method on the second blockchain node side can be applied to the implementation of the blockchain node, and can achieve the same technical effects.

[0303] An embodiment of the present disclosure further provides a network side device, wherein the network side device is a second network side device, and includes: a processor 211 and a transceiver 212, as shown in FIG. 21 ; The processor 211 receiving, via the transceiver 212, user credentials of the terminal to be authenticated, transmitted by the blockchain node; authenticating the user credential information to obtain a first authentication result and signing using third signature information; and feeding back the first authentication result and the third signature information to the blockchain node via the transceiver 212; Wherein the blockchain node is a first blockchain node or a second blockchain node that communicates with the first blockchain node; The user credentials include terminal identifier information.

[0304] According to the network side device of the embodiment of the present disclosure, the network side device receives user credentials to be authenticated from a terminal sent by a blockchain node, authenticates the user credentials, obtains a first authentication result, signs using third signature information, and feeds back the first authentication result and the third signature information to the blockchain node, where the blockchain node is a first blockchain node or a second blockchain node communicating with the first blockchain node, and the user credentials include terminal identifier information. In this way, it can support the realization of a means for performing access control using blockchain, and by providing attribute verification services to clients in the form of blockchain, it can avoid problems such as a single point of failure caused by a DDoS attack on a traditional authentication server.

[0305] Here, the above-mentioned embodiments of the access control method on the second network side device side can all be applied to the embodiments of the network side device, and the same technical effects can be achieved.

[0306] An embodiment of the present disclosure further provides a network side device, wherein the network side device is a third network side device, and includes: a processor 221 and a transceiver 222, as shown in FIG. 22 ; The processor 221 Receiving attribute information to be authenticated of the terminal transmitted by the blockchain node via the transceiver 222; authenticating the attribute information to obtain a second authentication result and signing the result using fourth signature information; and feeding back the second authentication result and the fourth signature information to the blockchain node via the transceiver 222; Here, the blockchain node is a first blockchain node or a second blockchain node that communicates with the first blockchain node.

[0307] According to the network side device of the embodiment of the present disclosure, the attribute information to be authenticated of the terminal sent by the blockchain node is received, the attribute information is authenticated, a second authentication result is obtained, and a signature is made using fourth signature information, and the second authentication result and the fourth signature information are fed back to the blockchain node, where the blockchain node is a first blockchain node or a second blockchain node that communicates with the first blockchain node. In this way, it is possible to support the realization of a means for performing access control using blockchain, and by providing attribute verification services to clients in the form of blockchain, it is possible to avoid problems such as a single point of failure caused by a DDoS attack on a traditional authentication server.

[0308] Here, the above-mentioned implementation embodiments of the access control method on the third network side device side can all be applied to the embodiments of the network side device, and the same technical effects can be achieved.

[0309] An embodiment of the present disclosure further provides a network side device, including a memory, a processor, and a program stored in the memory and executable by the processor, wherein when the processor executes the program, the access control method on the first network side device side is realized, or when the processor executes the program, the access control method on the second network side device side is realized, or when the processor executes the program, the access control method on the third network side device side is realized.

[0310] Here, any of the above-mentioned implementation embodiments of the access control method on the first network side device side, the second network side device side, or the third network side device side can be applied to the embodiment of the network side device, and can achieve the same technical effects.

[0311] An embodiment of the present disclosure further provides a terminal, which includes a memory, a processor, and a program stored in the memory and executable by the processor, and when the processor executes the program, realizes the access control method on the terminal side.

[0312] Here, the above-mentioned implementation embodiments of the terminal-side access control method can all be applied to the terminal embodiment, and the same technical effects can be achieved.

[0313] An embodiment of the present disclosure further provides a blockchain node, including a memory, a processor, and a program stored in the memory and executable by the processor, wherein when the processor executes the program, the access control method on the first blockchain node side is realized, or when the processor executes the program, the access control method on the second blockchain node side is realized.

[0314] Here, the above-mentioned implementation embodiments of the access control method on the first blockchain node side or the second blockchain node side can both be applied to the implementation of the blockchain node, and can achieve the same technical effects.

[0315] An embodiment of the present disclosure further provides a readable storage medium on which a program is stored, which, when executed by a processor, realizes steps in the access control method on the first network side device side, or when executed by a processor, realizes steps in the access control method on the terminal side, or when executed by a processor, realizes steps in the access control method on the first blockchain node side, or when executed by a processor, realizes steps in the access control method on the second blockchain node side, or when executed by a processor, realizes steps in the access control method on the second network side device side, or when executed by a processor, realizes steps in the access control method on the third network side device side.

[0316] Here, the above-mentioned implementation embodiments of the access control method on the first network side device side, terminal side, first blockchain node side, second blockchain node side, second network side device side or third network side device side can all be applied to the embodiments of the readable storage medium, and can achieve the same technical effects.

[0317] It should be noted that many of the functional components described in this specification are called modules in order to more specifically emphasize the independence of their implementation methods.

[0318] In embodiments of the present disclosure, modules may be implemented in software to be executed by various types of processors. For example, an identified executable code module may include one or more physical or logical blocks of computer instructions that may be organized as an object, process, or function. Nevertheless, the executable code of an identified module need not be physically located together and may include different instructions stored in different bits that, when logically combined, constitute the module and achieve the module's intended purpose.

[0319] In practice, an executable code module may be a single instruction or multiple instructions, and may be distributed across multiple different code segments, different programs, and multiple memory devices. Similarly, operating data may be identified in modules and may be embodied according to any suitable format and organized within any suitable type of data structure. Operating data may be collected as a single data set, or may be distributed in different locations (contained in different storage devices), or may exist at least in part only as electronic signals over a system or network.

[0320] If a module can be realized using software, the corresponding functionality can be realized without cost considerations, because the level of existing hardware processes is taken into account for the software-realizable module. The software-realized module can be constructed to include corresponding hardware circuitry including conventional very large scale integrated (VLSI) circuits or gate arrays, and existing semiconductors such as logic chips, transistors, or other discrete elements. The module can also be realized with programmable hardware devices such as field programmable gate arrays, programmable array logic, programmable logic devices, etc.

[0321] Those skilled in the art will recognize that each example unit and algorithm step described in connection with the embodiments disclosed herein can be realized in electronic hardware or a combination of computer software and electronic hardware. These functions can be performed in hardware or software depending on the specific application and design constraints of the technology. Those skilled in the art will recognize that different methods can be used to realize the described functions for each specific application, and this implementation is not considered to be beyond the scope of the present disclosure.

[0322] It may be obvious to those skilled in the art that the specific operation processes of the above-described systems, devices, and units may refer to the corresponding processes in the above-described method embodiments for convenience and conciseness of description, and will not be further described here.

[0323] It should be understood that in some embodiments of the present application, the disclosed apparatus and method may be realized in other ways. The apparatus embodiment described above is merely one logical functional division, and in actual implementation, other division methods are possible, such as combining multiple units or components, integrating them into another system, or ignoring or not implementing certain features. Furthermore, the coupling, or direct coupling, or communication connection between each component shown or discussed may be electrical, mechanical, or other form through some interfaces, indirect couplings, or communication connections between devices or units.

[0324] The means described as the above-mentioned separate means may or may not be physically separated, and the means displayed as means may or may not be physically separated, that is, they may be located in one place or distributed across multiple network means, and some or all of the units can be selected according to actual needs to achieve the objectives of this embodiment.

[0325] Furthermore, the functional units in each embodiment of the present application may all be integrated into a single processing unit, each unit may stand alone as a single unit, or two or more units may be integrated into a single unit.

[0326] When the functions are realized as software functional modules and sold or used as an independent product, they may be stored in a computer-readable storage medium. Based on this understanding, the essential technical aspects of the embodiments of the present application or the parts that contribute to the prior art, stored in a storage medium containing instructions for executing all or part of the methods described in each embodiment of the present application, may be embodied in the form of a software product executed by a computer device (such as a personal computer, a server, or a network device). The storage medium includes various media capable of storing program code, such as a mobile storage device, a ROM, a RAM, a magnetic disk, or an optical disk.

[0327] It is understood that the examples described in the embodiments of the present disclosure can be realized by hardware, software, firmware, middleware, microcode, or a combination thereof. Regarding the hardware realization, the modules, units, sub-modules, sub-units, etc. can be realized by one or more Application Specific Integrated Circuits (ASICs), Digital Signal Processing (DSPs), Digital Signal Processing Devices (DSPDs), Programmable Logic Devices (PLDs), Field-Programmable Gate Arrays (FPGAs), general-purpose processors, controllers, microcontrollers, microprocessors, and other electronic units or combinations thereof for performing the functions described in the present disclosure.

[0328] It should be pointed out that what has been described above are the preferred embodiments of the present disclosure, and those skilled in the art may make some improvements and refinements without departing from the principle of the present disclosure, which should be regarded as within the protection scope of the present disclosure.

Claims

1. An access control method applied to a first network side device, comprising: The access control method includes: Receiving related information to be verified corresponding to the access request sent by the terminal, where the related information to be verified includes private key signature information of the terminal and location information of preset information in a blockchain ledger; Obtaining the preset information from the blockchain ledger based on the location information; verifying the terminal based on the private key signature information and the preset information; If the verification is successful, obtain attribute information of the terminal from the blockchain ledger based on the preset information; feeding back a request response to access control to the terminal based on the attribute information; Here, the preset information includes public key information of the terminal, or first terminal identifier information based on the public key of the terminal, or second terminal identifier information unrelated to the public key of the terminal and public key information of the terminal, or a hash value of the second terminal identifier information and the public key of the terminal.

2. receiving related information to be verified corresponding to an access request sent by the terminal; receiving an access request sent by said terminal, the access request being accompanied by relevant information to be verified; or receiving an access request sent by the terminal; feeding back a random number to the terminal based on the access request; receiving related information to be verified that the terminal transmits based on the random number. The access control method according to claim 1 .

3. When the preset information includes public key information of the terminal, verifying the terminal based on the private key signature information and the preset information includes: verifying the private key signature information using the public key information; If the verification is successful, acquiring attribute information of the terminal from the blockchain ledger based on the preset information, If the verification is successful, obtain corresponding third terminal identifier information from the block chain ledger based on the public key information; When the third terminal identifier information is acquired, attribute information corresponding to the third terminal identifier information is acquired from the blockchain ledger as attribute information of the terminal. The access control method according to claim 1 .

4. When the preset information includes the first terminal identifier information, verifying the terminal based on the private key signature information and the preset information includes: Obtaining public key information to be verified based on the first terminal identifier information and obtaining the stored public key information of the terminal from the blockchain ledger; verifying the public key information to be verified and the private key signature information based on public key information of the terminal; If the verification is successful, acquiring attribute information of the terminal from the blockchain ledger based on the preset information, If the verification is successful, acquiring attribute information of the terminal from the blockchain ledger based on the first terminal identifier information. The access control method according to claim 1 .

5. When the preset information includes the second terminal identifier information and public key information, verifying the terminal based on the private key signature information and the preset information includes: Verifying the private key signature information using public key information in the preset information, acquiring public key information of the terminal stored from the block chain ledger based on the second terminal identifier information, and verifying the public key information in the preset information based on the acquired public key information of the terminal; Or, Verifying the private key signature information using public key information in the preset information, obtaining a hash value of the public key of the terminal stored from the blockchain ledger based on the second terminal identifier information, obtaining a hash value to be verified based on the public key information in the preset information, and verifying the hash value to be verified based on the obtained hash value of the public key of the terminal. The access control method according to claim 1 .

6. When the preset information includes the second terminal identifier information and a hash value of a public key, verifying the terminal based on the private key signature information and the preset information includes: Obtaining the stored public key information of the terminal from the blockchain ledger based on the second terminal identifier information; obtaining public key information to be verified based on a hash value of the public key in the preset information; verifying the private key signature information based on the public key information to be verified, and verifying the public key information to be verified based on the acquired public key information of the terminal. The access control method according to claim 1 .

7. the private key signature information includes first signature information or second signature information, the first signature information being used to sign a timestamp using a private key of the terminal, and the second signature information being used to sign a random number transmitted by the first network side device in response to an access request using the private key of the terminal; When the private key signature information includes first signature information, the related information to be verified further includes the timestamp; Verifying the terminal based on the private key signature information and the preset information includes: checking whether the timestamp is within a valid period; If the timestamp is within a valid period, verifying the terminal based on the private key signature information and the preset information.

3. The access control method according to claim 1 or 2.

8. the preset information further includes validity period information of first information, the first information including at least one of the attribute information, the first terminal identifier information, and the second terminal identifier information; Verifying the terminal based on the private key signature information and the preset information includes: determining whether the first information is within a validity period based on the validity period information; If the first information is within a validity period, verifying the terminal based on the private key signature information and other information in the preset information excluding the validity period information. The access control method according to claim 1 .

9. At least one piece of authentication information related to the terminal is stored in the blockchain ledger as encrypted information encrypted with a first key, and the related information to be verified further includes the first key encrypted with the public key of the first network side device; Before feeding back a request response to access control to the terminal based on the attribute information, the access control method further comprises: decrypting the first key encrypted with the public key using a private key of the first network side device to obtain the first key; decrypting the encrypted information obtained from the blockchain ledger based on the first key to obtain the at least one authentication information; wherein the at least one piece of authentication information is: attribute information of the terminal; First terminal identifier information based on the public key of the terminal, second terminal identifier information not related to the public key of the terminal, or third terminal identifier information corresponding to the public key of the terminal; and, The terminal's public key information or the hash value of the terminal's public key is included. The access control method according to claim 1 .

10. The at least one piece of authentication information further includes a timestamp corresponding to the terminal and / or validity information of second information; wherein the timestamp is a timestamp obtained by signing using a private key of the terminal to obtain first signature information; The second information includes at least one of the attribute information, first terminal identifier information, second terminal identifier information, and third terminal identifier information. The access control method according to claim 9.

11. An access control method applied to a communication system including a terminal and a first network side device, The access control method includes: The terminal sends related information to be verified corresponding to the access request to the first network side device, and the related information to be verified includes private key signature information of the terminal and location information of preset information in a block chain ledger; The first network side device acquires the preset information from the blockchain ledger based on the location information, and verifies the terminal based on the private key signature information and the preset information; If the verification is successful, the first network side device acquires attribute information of the terminal from the block chain ledger based on the preset information; receiving, by the terminal, a request response to access control that is fed back to the terminal by the first network side device based on the attribute information; Here, the preset information includes public key information of the terminal, or first terminal identifier information based on the public key of the terminal, or second terminal identifier information unrelated to the public key of the terminal and public key information of the terminal, or a hash value of the second terminal identifier information and the public key of the terminal.

12. An access control method applied to a communication system including a terminal and a first blockchain node, The access control method includes: The terminal sends information to be authenticated of the terminal to the first blockchain node before sending related information to be verified corresponding to the access request to the first network side device; The first blockchain node receives the information to be authenticated sent by the terminal, authenticates the information to be authenticated, and if the authentication is successful, stores at least one authentication information corresponding to the information to be authenticated in a blockchain ledger; wherein the information to be authenticated includes user credential information and / or attribute information, and the user credential information includes terminal identifier information; The at least one authentication information is attribute information of the terminal; First terminal identifier information based on the public key of the terminal, second terminal identifier information not related to the public key of the terminal, or third terminal identifier information corresponding to the public key of the terminal; and, The terminal device includes at least one of public key information or a hash value of the public key of the terminal device, If the authentication is successful, storing at least one authentication information corresponding to the information to be authenticated in the blockchain ledger, The first blockchain node randomly generates a first key for encryption, and encrypts the at least one authentication information using the first key before storing it in the blockchain ledger; After randomly generating the first key for encryption, the access control method further comprises: The first blockchain node encrypts the first key using the public key of the terminal before storing it in the blockchain ledger; The related information to be verified includes private key signature information of the terminal and location information of preset information in the blockchain ledger, and the preset information includes public key information of the terminal, or first terminal identifier information based on the public key of the terminal, or second terminal identifier information unrelated to the public key of the terminal and public key information of the terminal, or the second terminal identifier information and a hash value of the public key of the terminal.

13. A network side device, A memory, a processor, and a program stored in the memory and executable by the processor, 11. The network-side device, when the processor executes the program, realizes the access control method according to claim 1.

14. A communication system including a terminal and a first network side device, A memory, a processor, and a program stored in the memory and executable by the processor, 12. A communication system, wherein the access control method according to claim 11 is implemented when the processor executes the program.

15. A communication system including a terminal and a blockchain node, A memory, a processor, and a program stored in the memory and executable by the processor, 13. A communication system, wherein the access control method according to claim 12 is implemented when the processor executes the program.

Citation Information

Patent Citations

  • Mobile network access authentication method and apparatus, storage medium and blockchain node

    CN108702622A

  • Authority authentication method for block chain infrastructure, terminal, and server using the same

    JP2019185775A

  • Client device, server device and access control system for authorized access

    JP2019500799A

  • How to manage trusted identities

    JP2019506103A

  • Information processing method, information processing device, program, and information processing system

    JP2020099010A