WO2018184447A1 - 基于区块链的数字证书删除方法、装置及系统、存储介质 - Google Patents
基于区块链的数字证书删除方法、装置及系统、存储介质 Download PDFInfo
- Publication number
- WO2018184447A1 WO2018184447A1 PCT/CN2018/078888 CN2018078888W WO2018184447A1 WO 2018184447 A1 WO2018184447 A1 WO 2018184447A1 CN 2018078888 W CN2018078888 W CN 2018078888W WO 2018184447 A1 WO2018184447 A1 WO 2018184447A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- digital certificate
- block
- backup
- saved
- identification information
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3263—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
- H04L9/3268—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements using certificate validation, registration, distribution or revocation, e.g. certificate revocation list [CRL]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3263—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
- H04L9/3265—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements using certificate chains, trees or paths; Hierarchical trust model
Definitions
- the embodiments of the present disclosure relate to the field of network security technologies, and in particular, to a blockchain-based digital certificate deletion method, apparatus, and system.
- a digital certificate is a file issued by an authority to prove the identity of a user on the network.
- the process of issuing a digital certificate can also be called a Certification Authority (CA) process.
- CA Certification Authority
- PKI Public Key Infrastructure
- CA is the starting point of trust. If you can control a CA, you can use the CA to arbitrarily issue digital certificates. Therefore, the core CA is vulnerable to attack. . Once a CA is compromised, all digital certificates issued by the CA are no longer secure and cannot be used.
- the CA root digital certificate installed or preset by the digital certificate relying party may also be attacked. If the root digital certificate is maliciously falsified, it will affect the entire digital certificate verification process, and may even identify the fake user digital certificate as Legal user digital certificate.
- the blockchain technology emerging in the chronological order stores the blocks storing the digital certificates in a sequential manner, and generates a trusted tree corresponding to the blocks according to the digital certificates stored in each block.
- (Merkle) value for verifying the digital certificate stored in the block to prevent the digital certificate stored in the block from being tampered with.
- each verification node in the blockchain stores all the digital certificates in the blockchain, and at the same time verifies the request to generate and invoke the digital certificate, there is no central CA node, even if a certain verification node fails or suffers Attacks can also guarantee the correctness of digital certificates.
- the blockchain will contain all the historical digital certificates. Over time, the digital certificates stored in the blockchain will continue to increase, and the entire blockchain will be stored. The amount of data will be larger and larger, and the storage and computing resources of the node need to be verified, which will bring a serious burden to the verification node, affecting the operation of the verification node and the user experience.
- the embodiments of the present disclosure provide a method, a device, and a system for deleting a digital certificate based on a blockchain, which are used to solve the problem that the amount of data in the digital certificate storage process is increasing in the prior art, and the storage and computing resources of the node to be verified are required to be verified. The higher the value, the problem that affects the operation of the verification node and the user's experience.
- the embodiment of the present disclosure discloses a digital certificate deletion method for a blockchain, where the blockchain includes multiple verification nodes and at least one backup node, and the deletion method is applied to any backup node in the blockchain.
- the method includes:
- a delete message including identification information of the block is sent to each verification node in the blockchain, wherein the delete message is used to make each The verification node determines whether each digital certificate in the block of the identification information is invalid, and deletes the block body of the block of the identification information when each digital certificate in the block determining the identification information is invalid.
- the embodiment of the present disclosure discloses a blockchain-based digital certificate deletion method, where the blockchain includes multiple verification nodes and at least one backup node, and the deletion method is applied to any verification node in the blockchain. , the method includes:
- the embodiment of the present disclosure discloses a blockchain-based digital certificate deletion device, where the blockchain includes multiple verification nodes and at least one backup node, and the deletion device is applied to any backup node in the blockchain.
- the device includes:
- Determining a module configured to determine, according to information of each backup digital certificate that is saved for each block by itself, whether each backup digital certificate saved for the block is invalid;
- a sending module configured to: if each backup digital certificate saved for the block is determined to be invalid, send a deletion message including the identification information of the block to each verification node in the blockchain, so that each verification node determines itself Whether each digital certificate in the block of the identification information is invalid, and when each digital certificate in the block determining the identification information is invalid, the block body of the block of the identification information is deleted.
- the embodiment of the present disclosure discloses a blockchain-based digital certificate deletion device, where the blockchain includes multiple verification nodes and at least one backup node, and the deletion device is applied to any verification node in the blockchain.
- the device includes:
- a receiving module configured to receive a delete message that is sent by the backup node in the blockchain and includes the identifier information of the block, where the delete message is a backup node in the blockchain according to each backup that is saved for each block according to itself.
- the information of the digital certificate is determined to be sent after each backup digital certificate saved for the block is invalid;
- a judging module configured to determine whether each digital certificate in the block of the identification information saved by itself is invalid
- the module is deleted, and is configured to delete the block body of the block if it is determined that each digital certificate in the block of the identification information is invalid.
- the embodiment of the present disclosure discloses a blockchain-based digital certificate deletion system, where the deletion system includes at least one blockchain-based digital certificate deletion device applied to a backup node, and a plurality of the above-mentioned application to the verification node.
- Block certificate based digital certificate deletion device
- Embodiments of the present disclosure also disclose a computer storage medium storing computationally executable instructions; after the computer executable instructions are executed, enabling blockchain-based digital certificate deletion applied to a backup node One or more of the methods, or one or more of the blockchain-based digital certificate deletion methods applied to the verification node.
- the embodiment of the disclosure discloses a method, a device and a system for deleting a digital certificate based on a blockchain, wherein the blockchain includes a plurality of verification nodes and at least one backup node, and the deletion method is applied to the blockchain.
- the method includes: determining, according to information of each backup digital certificate that is saved for each block, whether each backup digital certificate saved for the block is invalid; if it is determined to be saved for the block Each of the backup digital certificates is invalid, and each of the verification nodes in the blockchain sends a deletion message containing the identification information of the block, so that each verification node determines whether each digital certificate in the block of the identification information is All are invalid, and when each digital certificate in the block that determines the identification information is invalid, the block body of the block of the identification information is deleted.
- a delete message including the identification information of the block is sent to each verification node in the blockchain, so that Each verification node determines whether each digital certificate in the block of the identification information is invalid, and deletes the block body of the block of the identification information when each digital certificate in the block determining the identification information is invalid.
- the storage space occupied by the data certificate storage process is reduced, the storage of the verification node and the calculation amount required for subsequent verification are saved, and the consumed computing resources are further reduced, and the operation efficiency of the verification node is improved (for example, Verify efficiency) and user experience.
- FIG. 1 is a schematic diagram of a blockchain architecture provided by the present disclosure
- FIG. 2 is a schematic diagram of a blockchain-based digital certificate deletion process according to Embodiment 1 of the present disclosure
- FIG. 3 is a schematic diagram of a storage structure for verifying a node storing a digital certificate according to Embodiment 1 and Embodiment 4 of the present disclosure
- FIG. 4 is a schematic diagram of a blockchain-based digital certificate deletion process according to Embodiment 4 of the present disclosure
- FIG. 5 is a schematic structural diagram of a blockchain-based digital certificate deletion apparatus according to Embodiment 7 of the present disclosure.
- FIG. 6 is a schematic structural diagram of a blockchain-based digital certificate deletion apparatus according to Embodiment 8 of the present disclosure.
- FIG. 7 is a schematic structural diagram of a blockchain-based digital certificate deletion system according to Embodiment 9 of the present disclosure.
- FIG. 1 is a schematic diagram of a blockchain architecture according to an embodiment of the present disclosure.
- the blockchain includes multiple verification nodes and at least one backup node, and each verification node is used to verify a user's request for generating a digital certificate and a user. An update request for the status of a digital certificate.
- Each verification node sequentially generates a new block according to a preset time sequence, and stores the digital certificate into the corresponding block according to the digital certificate generation time, and is also used to store the stored number according to the user's update request for the digital certificate status.
- the status of the certificate is updated.
- the backup node is configured to back up each digital certificate stored in the block for each block of the verification node, and update the status of the digital certificate backed up for each block according to the user's update request for the status of the digital certificate.
- FIG. 2 is a schematic diagram of a blockchain-based digital certificate deletion process according to an embodiment of the present disclosure, where the process includes:
- S201 Determine, according to information about each backup digital certificate that is saved for each block, whether each backup digital certificate saved for the block is invalid.
- a method for deleting a digital certificate based on a blockchain is applied to any backup node in a blockchain, and the backup node may be a personal computer with computing and storage functions (Personal Computer, PC) ) Machines, servers, etc.
- PC Personal Computer
- the backup node since the digital certificate stored in each corresponding block of each verification node is the same if it is not maliciously changed in the blockchain, the backup node pairs each of the blockchains.
- the digital certificates saved in each block of the verification node are backed up, that is, the digital certificates in each block saved by the verification node are backed up, and each number in the block is saved in the backup node for each block.
- the backup digital certificate corresponding to the certificate since the digital certificate stored in each corresponding block of each verification node is the same if it is not maliciously changed in the blockchain, the backup node pairs each of the blockchains.
- the digital certificates saved in each block of the verification node are backed up, that is, the digital certificates in each block saved by the verification node are backed up, and each number in the block is saved in the backup node for each block.
- the backup node determines, according to information about each backup digital certificate that is saved by each block for each block, whether each backup digital certificate saved for the block is invalid, wherein the information of the backup digital certificate may be the digital certificate.
- Validity period A plurality of backup digital certificates are stored in one block. If each backup digital certificate in the area is invalid, it indicates that each digital certificate in the block of the block is invalid, and at least the block can be deleted. The block is generated, so the delete message is generated.
- the backup node stores the backup digital certificate 1 and the backup digital certificate 2 for the block A, and the backup digital certificate 3 and the backup digital certificate 4 for the block B.
- the current time is March 29, 2017, for the block A backup node according to the validity period of the backup digital certificate 1 from July 1, 2015 to July 1, 2016, it is determined that the validity period of the backup digital certificate 1 expires, and the backup digital certificate 1 is invalid.
- the backup digital certificate 2 is invalid, and the backup digital certificate 1 for the block A is saved. Certificate 2 is invalid. It is determined that each backup digital certificate saved for block A is invalid.
- the backup number is determined according to the validity period of the backup digital certificate 3 from July 5, 2015 to July 5, 2016.
- the validity period of certificate 3 expires, and the backup digital certificate 3 is invalid.
- the validity period of the backup digital certificate 4 from May 1, 2016 to May 1, 2017, it is determined that the validity period of the backup digital certificate 4 has not expired, and the backup digital certificate 4 is valid.
- the backup digital certificate 4 saved in the block B is valid, and it is determined that there is a valid backup digital certificate in each backup digital certificate saved for the block B.
- each backup digital certificate saved for the block is invalid, send a delete message containing the identification information of the block to each verification node in the blockchain.
- the deletion message may cause each verification node to determine whether each digital certificate in the block of the identification information is invalid, and delete the area of the identification information when each digital certificate in the block determining the identification information is invalid.
- the block body of the block may cause each verification node to determine whether each digital certificate in the block of the identification information is invalid, and delete the area of the identification information when each digital certificate in the block determining the identification information is invalid.
- Each block in the blockchain is composed of a block header and a block body.
- the block header stores the time generated by the block, and the parent block hash value, that is, the previous block before the time when the block is generated.
- the hash value is stored in the block body with each digital certificate recorded in the block according to the Merkle value determined by each digital certificate held in the block.
- FIG. 3 is a schematic diagram of a storage structure for verifying a node storing a digital certificate according to an embodiment of the present disclosure.
- the verification node sequentially stores a creation block, a block 2, and a block n in time order, wherein each block is composed of The block header and the block body are composed, and each block certificate stores each digital certificate stored in the block.
- the backup node determines that each backup digital certificate saved for the block is invalid, it indicates that each backup digital certificate saved for the block can be deleted and sent to each verification node in the blockchain.
- the deletion message containing the identification information of the block if the digital certificate stored in each block of the verification node is the same as the backup digital certificate saved by the backup node, the verification node may directly delete the block body of the block with the identification information of the node.
- the valid digital certificate cannot be deleted by the error, thereby causing damage to the user's rights and interests.
- the verification node after the verification node receives the deletion message including the identification information of the block, it is determined whether each digital certificate in the block of the identification information is invalid, and each block in the identification information is determined. When the digital certificates are invalid, the block body of the block of the identification information is deleted.
- each backup digital certificate saved by the backup node for block A is invalid, it means that each backup digital certificate saved for the block A can be deleted, and the included block is sent to each verification node in the blockchain.
- A identifies the deletion message of the information 00001.
- the verification node After receiving the deletion message including the identification information 00001, the verification node identifies the block A of the identification information saved by the identification information 00001, and verifies whether each digital certificate in the own block A is invalid. If each digital certificate in its own block A is invalid, the block body of the block A is deleted.
- a delete message including the identification information of the block is sent to each verification node in the blockchain, so that Each verification node determines whether each digital certificate in the block of the identification information is invalid, and deletes the block body of the block of the identification information when each digital certificate in the block determining the identification information is invalid.
- the storage space occupied by the data certificate storage process is reduced, the storage and computing resources of the verification node are saved, and the operation efficiency of the verification node and the user experience are improved.
- each backup saved according to itself for each block The information of the digital certificate determines whether each backup digital certificate saved for the block is invalid, including:
- each backup digital certificate saved for the block is expired and/or the backup digital certificate has been revoked, it is determined that each backup digital certificate saved for that block is invalid.
- the information of the backup digital certificate includes: a validity period of the backup digital certificate and status information of the backup digital certificate, wherein the status information of the backup data certificate includes: issuing, revoking, suspending, recovering, etc., the backup node
- the status information of the backup digital certificate can be determined to determine whether the backup digital certificate has been revoked.
- the identification of the backup digital certificate status information is not described in the prior art.
- the backup node can determine whether each backup digital certificate saved for the block is invalid according to whether the validity period of each backup digital certificate saved by each block is expired. Of course, it can also be used for each zone according to itself. Whether the status of each backup digital certificate saved by the block is revoked, and it is determined whether each backup digital certificate saved for the block is invalid.
- each backup digital certificate saved for each block is invalid according to whether the validity period of each backup digital certificate saved for each block by itself and whether the backup digital certificate has been revoked. If each backup digital certificate saved for the block satisfies the expiration of the validity period of the backup digital certificate and/or the backup digital certificate has been revoked, it is determined that each backup digital certificate saved for the block is invalid. In an embodiment of the present disclosure, for each backup digital certificate, if the validity period of the backup digital certificate is expired, or the backup digital certificate is revoked, it is determined that the backup digital certificate is invalid.
- the backup node stores a backup digital certificate 5 and a backup digital certificate 6 for the block C, wherein the backup digital certificate 5 is valid from July 5, 2015 to July 5, 2016, and the status is not revoked, and the digital certificate is backed up. 6 is valid from July 5, 2016 to July 5, 2017. The status is revoked. The current time is March 29, 2017. The validity period of the backup digital certificate 5 expires. The status of the backup digital certificate 6 is revoked. Each backup digital certificate saved for block C is invalid.
- the method further include:
- Each backup digital certificate saved by itself for the block of the identification information is sent to each verification node.
- each verification node in the blockchain can use a preset for each digital certificate stored in each block according to a preset setting.
- the algorithm performs the transformation. For example, the verification node hashes each digital certificate held by each block using a hash algorithm, and each block holds each digital certificate after the hash operation.
- the backup node if the verification node converts each digital certificate held by each block using a preset algorithm, the backup node backs up the usage pre-stored in the block for each block in the blockchain. Set the algorithm to perform each digital certificate before the transformation.
- the backup node saves each backup digital certificate according to its own for each block.
- the information after determining that each backup digital certificate saved for the block is invalid, sending a deletion message including the identification information of the block to each verification node in the blockchain, and further targeting the identification information
- Each backup digital certificate saved by the block is sent to each verification node, and the verification node receives the deletion message sent by the backup node containing the identification information of the block and each backup number saved by the block for the identification information.
- the block of the identification information is determined according to the identifier information, and each backup digital certificate saved by the backup node for the block of the identification information is transformed by using a preset algorithm, and the identification information of the identifier is determined by the backup node. Whether each digital certificate saved by the block matches the digital certificate converted by the backup digital certificate, thereby determining that the backup node is targeted Whether each backup digital certificate saved by the block of the identification information is correct.
- each digital certificate saved in each block of each verification node in the blockchain is changed using a hash algorithm, and the backup node determines that each backup digital certificate saved for the block E with the identification information of 00005 is Invalid, the backup node sends a delete message including the identification information 00005 to each verification node in the blockchain, and sends each backup digital certificate saved for the block E whose identification information is 00005 to each blockchain. Verify nodes.
- the verification node After receiving the deletion message including the identification information 00005 and each backup digital certificate saved for the block of the identification information 00005, the verification node identifies the block E whose own identification information is 00005 according to the identification information 00005, and adopts a preset hash algorithm. Performing a hash operation on each backup digital certificate saved by the backup node for the block of the identification information 00005, and determining whether each digital certificate stored in the own block E matches the backup digital certificate after the hash operation, if , to determine that each backup digital certificate saved by the backup node for block E is correct.
- FIG. 4 is a schematic diagram of a blockchain-based digital certificate deletion process according to an embodiment of the present disclosure, where the process includes:
- S401 Receive a deletion message that includes the identifier information of the block sent by the backup node in the blockchain, where the delete message is a backup node in the blockchain according to each backup digital certificate that is saved for each block according to itself. Information, determined to be sent after each backup digital certificate saved for the block is invalid.
- a method for deleting a digital certificate based on a blockchain is applied to any verification node in a blockchain, and the verification node may be a PC, a server, or the like having an operation and storage function.
- the backup node since the digital certificate stored in each corresponding block of each verification node is the same if it is not maliciously changed in the blockchain, the backup node pairs each verification in the blockchain.
- the digital certificate saved in each block of the node is backed up, that is, the digital certificate in each block saved by the verification node is backed up, and each digital certificate corresponding to the block is saved in the backup node for each block.
- Backup digital certificate The backup node determines, according to the information of each backup digital certificate that is saved for each block, whether each backup digital certificate saved for the block is invalid, and is invalid for each backup digital certificate saved in the block. Sending a delete message containing the identification information of the block to each verification node in the blockchain.
- the backup node saves the backup digital certificate 1 and the backup digital certificate 2 for the block A.
- the current time is March 29, 2017, and the backup node for the block A is valid according to the validity of the backup digital certificate 1 July 1, 2015-2016 On July 1st, it is determined that the validity period of the backup digital certificate 1 expires, and the backup digital certificate 1 is invalid.
- the backup digital certificate 2 is invalid.
- the backup digital certificate 1 and the backup digital certificate 2 saved for the block A are invalid. It is determined that each backup digital certificate saved for the block A is invalid, and each verification node in the blockchain is invalid.
- a delete message containing the identification information 00001 of the block A is sent.
- the verification node receives, in the blockchain, the backup node determines, according to information of each backup digital certificate that is saved for each block, that each backup digital certificate saved for the block is invalid, and the sent The deletion message of the identification information of the block.
- S402 Determine whether each digital certificate in the block of the identification information saved by itself is invalid.
- the verification node determines whether each digital certificate in the block of the identifier information saved by the backup node is invalid, wherein the verification node may be based on the digital certificate.
- the validity period determines whether the digital certificate is valid.
- the verification node receives the deletion message of the identification information 00001 including the block sent by the backup node, and identifies the block A whose own identification information is 00001, and the block A holds the digital certificate 1 and the digital certificate 2, the current time 2017 3
- the verification node determined that the validity period of the digital certificate 1 expired according to the validity period of the digital certificate 1 from July 1, 2015 to July 1, 2016, and the digital certificate 1 is invalid.
- the validity period of the digital certificate 2 February 1, 2016 On February 1, 2017, it is determined that the validity period of the digital certificate 2 expires, the digital certificate 2 is invalid, and the digital certificate 1 and the digital certificate 2 saved for the block A are invalid, and each of the blocks A whose identification information is 00001 is determined.
- Digital certificates are invalid.
- Each block in the blockchain is composed of a block header and a block body.
- the block header stores the time generated by the block, and the parent block hash value, that is, the previous block before the time when the block is generated.
- the hash value is stored in the block body with each digital certificate recorded in the block according to the Merkle value determined by each digital certificate held in the block.
- FIG. 3 is a schematic diagram of a storage structure for verifying a node storing a digital certificate according to an embodiment of the present disclosure.
- the verification node sequentially stores a creation block, a block 2, and a block n in time order, wherein each block is composed of The block header and the block body are composed, and each block certificate stores each digital certificate stored in the block.
- each digital certificate in the block of the identification information is invalid, it indicates that each digital certificate in the block can be deleted, and deleting the block for storing the digital certificate; If the verification node determines that there is at least one valid digital certificate in the block of the identification information, it indicates that there is a non-deletable digital certificate in the block, discarding the deletion message sent by the backup node, and does not do any work on the block. deal with.
- the deleted block A is used to store the block body of the digital certificate.
- the verification node determines, according to the information of each backup digital certificate that the backup node saves for each block according to itself, whether the content of each backup digital certificate saved for a certain block is invalid and is included.
- the deletion message of the identification information of the block determines that each digital certificate in the block of the identification information is invalid, and deletes the block body of the block of the identification information, thereby reducing the storage space occupied by the data certificate storage process. , saving storage and computing resources, improving operational efficiency and user experience.
- the method further includes:
- the method further includes:
- the subsequent step includes at least the step of determining whether each digital certificate in the block of the identification information saved by itself is invalid.
- the verification node may use a preset algorithm to transform each digital certificate saved in each block according to a preset setting using a preset algorithm. For example, the verification node hashes each digital certificate held in each block using a hash algorithm, and saves each digital certificate after the hash operation for each block.
- the backup node if the verification node converts each digital certificate held by each block using a preset algorithm, the backup node backs up the usage pre-stored in the block for each block in the blockchain.
- the algorithm is set to perform each digital certificate before the conversion, and the information of each digital certificate is saved.
- the verification node receives the deletion message including the block identifier sent by the backup node in the blockchain, and receives the Each backup digital certificate saved by the backup node for the block of the identification information sent by the backup node.
- the verification node needs to determine that the backup node sends before determining whether each digital certificate in the identified block of the identity is invalid. Whether each of the backup digital certificates is correct, and optionally, the verification node converts each of the backup digital certificates by using a preset algorithm, and determines each digital certificate saved in the block for the identification information by itself. That is, the digital certificate that is transformed by using a preset algorithm is matched with the digital certificate converted by the backup digital certificate, and if the corresponding match is matched, it is determined that each of the backup nodes saves the block for the identification information.
- the backup digital certificate has not been tampered with, and each backup digital certificate saved by the backup node for the block of the identification information is correct. At this time, because the backup node has judged that each backup digital certificate saved in the block of the identification information is invalid, the verification node may also delete the block of the block of the identification information, but because the backup certificate is saved by the backup node. The reliability is not very high. In order to further ensure the security of the digital certificate, the verification node verifies whether each digital certificate in the block of the identification information is invalid.
- the verification node uses the preset algorithm to transform each of the backup digital certificates, and determines each digital certificate saved in the block for the identification information, that is, the digital certificate converted by using a preset algorithm cannot be used.
- Corresponding to the digital certificate converted by the backup digital certificate it indicates that at least one backup digital certificate is falsified in each backup digital certificate saved by the backup node for the block of the identification information, in order to ensure the number saved by itself.
- the correctness of the certificate prevents the erroneous deletion of the valid non-deletable digital certificate.
- the verification node discards the deleted message sent by the backup node, and does not perform any processing on the block of the identification information.
- the digital certificate in the block that determines the identity information saved by itself is Invalid is included:
- each digital certificate in the block of the identification information is expired and/or the status of the digital certificate is revoked, each digital certificate in the block determining the identification information is invalid.
- the information of the digital certificate includes: an expiration date of the digital certificate and status information of the digital certificate, where the status information of the data certificate includes: issuing, revoking, suspending, recovering, etc., and the verification node may identify the number
- the status information of the certificate determines whether the digital certificate has been revoked.
- the identification of the digital certificate status information is not described in the prior art. If the verification node is not preset for the verification node, the verification node performs a transformation on each digital certificate saved in each block using a preset algorithm, and the verification node performs information according to each digital certificate in the block of the identification information saved by itself.
- Identifying the validity period of each un-transformed digital certificate stored in the block of the identification information, and the verification node may determine whether the validity period of each digital certificate in the block of the identification information saved by itself is expired. Whether each digital certificate in the block of the identification information is invalid; of course, according to whether the status of each digital certificate in the block of the identification information saved by itself is revoked, each block in the identification information is determined. Whether all digital certificates are invalid.
- each digital certificate in the block of the identification information is invalid according to whether the validity period of each digital certificate in the block of the identification information saved by itself is expired and whether the digital certificate has been revoked. If each digital certificate in the block for the identification information satisfies the expiration of the validity period of the digital certificate and/or the status of the digital certificate is revoked, it is determined that each digital certificate in the block of the identification information is invalid. In an embodiment of the present disclosure, for each digital certificate, if the validity period of the digital certificate is expired, or the status of the digital certificate is revoked, it is determined that the digital certificate is invalid.
- the identification information of the block included in the delete message sent by the backup node is 00003, and the digital certificate 5 and the digital certificate 6 are stored in the block C of the verification node whose own identification information is 00003, wherein the validity period of the digital certificate 5 is 2015 7 On the 5th of May - July 5th, 2016, the status is not revoked.
- the digital certificate 6 is valid from July 5, 2016 to July 5, 2017.
- the status is revoked.
- the current time is March 29, 2017.
- the validity period of the digital certificate 5 expires, the certificate status of the digital certificate 6 is revoked, and each digital certificate in the block C whose own identification information is 00003 is invalid.
- the verification node uses a preset algorithm to transform each digital certificate saved in each block. Since the validity period of the digital certificate is recorded in the digital certificate, the verification node cannot identify the validity period of each converted digital certificate saved by the block of the identification information, in order for the verification node to determine each of the blocks of the identification information saved by itself. If the digital certificate is invalid, in the embodiment of the present disclosure, if the verification node is for each backup digital certificate sent by the backup node, it is determined that each digital certificate saved in the block for the identification information is associated with the backup.
- the digital certificate converted by the digital certificate is matched, and the verification node saves each backup digital certificate saved by the backup node for the block of the identification information and the status information of each digital certificate saved by the backup node according to the received backup node. , determining whether each digital certificate in the block of the identification information saved by itself has no effect.
- the verification node determines whether each digital certificate in the block of the identification information is determined according to whether each digital certificate in the block of the identification information has been revoked and/or the validity period of each backup digital certificate received is expired. All are invalid. If each digital certificate in the block of the identification information satisfies the status of the digital certificate as being revoked and/or each of the received digital certificates is expired, it is determined that each digital certificate in the block of the identification information is invalid. . In an embodiment of the present disclosure, for each digital certificate, if the status information of the digital certificate is revoked, or the backup digital certificate corresponding to the digital certificate is expired, it is determined that the digital certificate is invalid.
- each digital certificate saved in each block of each verification node in the blockchain is changed using a hash algorithm, and the backup node determines that each backup digital certificate saved for the block E with the identification information of 00005 is Invalid, the backup node sends a delete message including the identification information 00005 to each verification node in the blockchain, and sends each backup digital certificate saved for the block E whose identification information is 00005 to each blockchain. Verify nodes.
- the verification node After receiving the deletion message including the identification information 00005 and each backup digital certificate saved for the block of the identification information 00005, the verification node identifies the block E whose own identification information is 00005 according to the identification information 00005, and adopts a preset hash algorithm. Performing a hash operation on each backup digital certificate saved by the backup node for the block of the identification information 00005, and determining whether each digital certificate stored in the own block E matches the backup digital certificate after the hash operation, if corresponding Matching, determining that each backup digital certificate saved by the backup node for the block E has not been tampered with, each backup digital certificate is correct, and the status information of the digital certificate 8 saved in the own block E is revoked, the digital certificate 9 The status information is not revoked.
- the backup digital certificate 8 matching the digital certificate 8 is valid from July 5, 2016 to July 5, 2017.
- the backup digital certificate 9 matching the digital certificate 9 is valid for 2015. August 5th - August 5th, 2016, the current time is March 29th, 2017, the status information of the digital certificate 8 is determined to be revoked, corresponding to the digital certificate 9 Backup digital certificate validity expired 9, E determined for each digital certificate stored in its own block are invalid.
- FIG. 5 is a schematic structural diagram of a device for deleting a digital certificate based on a blockchain according to an embodiment of the present disclosure, the device includes:
- the determining module 51 is configured to determine, according to information of each backup digital certificate that is saved for each block by itself, whether each backup digital certificate saved for the block is invalid;
- the sending module 52 is configured to: if it is determined that each backup digital certificate saved for the block is invalid, send a deletion message including the identification information of the block to each verification node in the blockchain, so that each verification node determines Whether each digital certificate in the block of the identification information is invalid, and when each digital certificate in the block determining the identification information is invalid, the block body of the block of the identification information is deleted.
- the determining module 51 is configured to determine, according to information of each backup digital certificate that is saved for each block by itself, whether the validity period of each backup digital certificate saved for the block expires and/or whether the backup digital certificate has been revoked If each backup digital certificate saved for this block is expired and/or the backup digital certificate has been revoked, it is determined that each backup digital certificate saved for that block is invalid.
- the sending module 52 is further configured to: if each digital certificate saved in each block of each verification node in the blockchain is transformed by using a preset algorithm, the region that is self-targeting the identification information Each backup digital certificate saved by the block is sent to each verification node.
- the blockchain-based digital certificate deletion apparatus shown in FIG. 5 is applied to any backup node in a blockchain, wherein the blockchain includes multiple verification nodes and at least one Backup node.
- FIG. 6 is a schematic structural diagram of a blockchain-based digital certificate deletion apparatus according to an embodiment of the present disclosure, where the apparatus includes:
- the receiving module 61 is configured to receive a deletion message that includes the identifier information of the block sent by the backup node in the blockchain, where the delete message is a backup node in the blockchain according to its own saved for each block. Backing up the information of the digital certificate and determining that each backup digital certificate saved for the block is invalid and sent;
- the determining module 62 is configured to determine whether each digital certificate in the block of the identification information saved by itself is invalid;
- the deleting module 63 is configured to delete the block body of the block if it is determined that each digital certificate in the block of the identification information is invalid.
- the receiving module 61 is further configured to: if each digital certificate saved for each block is converted by using a preset algorithm, receive the backup node sent by the backup node for saving the block of the identification information. Each backup digital certificate;
- the device also includes:
- the matching module 64 is configured to perform transformation on each of the backup digital certificates by using the preset algorithm; and determine, for each digital certificate saved in the block of the identification information, whether each digital certificate saved by itself is Corresponding to the digital certificate transformed by the backup digital certificate; if the matching result is yes, the judgment module is triggered.
- the determining module 62 is configured to obtain the validity period and status information of each digital certificate in the block of the identification information saved by itself; determine whether the validity period of each digital certificate in the block of the identification information is expired and/or a digital certificate. Whether it has been revoked; if each digital certificate in the block of the identification information is expired and/or the status of the digital certificate is revoked, each digital certificate in the block determining the identification information is invalid.
- the blockchain-based digital certificate deletion apparatus shown in FIG. 6 is applied to any verification node in a blockchain, wherein the blockchain includes a plurality of verification nodes and at least one Backup node.
- FIG. 7 is a schematic structural diagram of a blockchain-based digital certificate deletion system according to an embodiment of the present disclosure, where the deletion system includes at least one blockchain-based digital certificate deletion device applied to the backup node 71, and multiple A blockchain based digital certificate deletion device applied to the verification node 72.
- the embodiment of the disclosure discloses a method, a device and a system for deleting a digital certificate based on a blockchain, wherein the blockchain includes a plurality of verification nodes and at least one backup node, and the deletion method is applied to the blockchain.
- the method includes: determining, according to information of each backup digital certificate that is saved for each block, whether each backup digital certificate saved for the block is invalid; if it is determined to be saved for the block Each of the backup digital certificates is invalid, and each of the verification nodes in the blockchain sends a deletion message containing the identification information of the block, so that each verification node determines whether each digital certificate in the block of the identification information is All are invalid, and when each digital certificate in the block that determines the identification information is invalid, the block body of the block of the identification information is deleted.
- a delete message including the identification information of the block is sent to each verification node in the blockchain, so that Each verification node determines whether each digital certificate in the block of the identification information is invalid, and deletes the block body of the block of the identification information when each digital certificate in the block determining the identification information is invalid.
- the storage space occupied by the data certificate storage process is reduced, the storage and computing resources of the verification node are saved, and the operation efficiency of the verification node and the user experience are improved.
- Embodiments of the present disclosure also disclose a computer storage medium storing computationally executable instructions; after the computer executable instructions are executed, enabling blockchain-based digital certificate deletion applied to a backup node One or more of the methods, or one or more of the blockchain-based digital certificate deletion methods applied to the verification node, for example, performing the method as shown in FIGS. 2 and/or 4.
- the computer storage medium mentioned in the embodiments of the present application may be various types of storage media, optionally a non-transitory storage medium.
- embodiments of the present application can be provided as a method, system, or computer program product.
- the present application can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment in combination of software and hardware.
- the application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) including computer usable program code.
- the computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture comprising the instruction device.
- the apparatus implements the functions specified in one or more blocks of a flow or a flow and/or block diagram of the flowchart.
- These computer program instructions can also be loaded onto a computer or other programmable data processing device such that a series of operational steps are performed on a computer or other programmable device to produce computer-implemented processing for execution on a computer or other programmable device.
- the instructions provide steps for implementing the functions specified in one or more of the flow or in a block or blocks of a flow diagram.
- a backup node finds that each backup digital certificate in all the backup digital certificates stored in an area stored by itself is invalid, a delete message is generated, so that all the verification nodes storing the block can be at least Deleting the block of the block, on the one hand, reducing the amount of stored data, thereby reducing the storage resources consumed, and on the other hand reducing the amount of check data in the subsequent blockchain generation process, thereby saving the need for verification Computational resources and improved verification efficiency have positive industrial effects.
- the technical solution provided by the embodiments of the present disclosure has the characteristics of being simple and easy to implement, and can be widely implemented in the industry.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Storage Device Security (AREA)
- Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
Abstract
一种基于区块链的数字证书删除方法、装置及系统、存储介质。方法包括:根据自身针对每个区块保存的每个备份数字证书的信息,如果针对该区块保存的每个备份数字证书均无效,向每个验证节点发送包含该区块的标识信息的删除消息,使每个验证节点确定自身该标识信息的区块中每个数字证书均无效时,删除该区块的区块体。
Description
相关申请的交叉引用
本申请基于申请号为201710218253.X、申请日为2017年04月05日的中国专利申请提出,并要求该中国专利申请的优先权,该中国专利申请的全部内容在此引入本申请作为参考。
本公开实施例涉及网络安全技术领域,尤其涉及一种基于区块链的数字证书删除方法、装置及系统。
数字证书是一种由权威机构颁发的用于在网络上证明用户身份的文件,颁发数字证书的过程也可以称为认证授权(Certification Authority,CA)过程。现有公钥基础设施(Public Key Infrastructure,PKI)技术中,CA是信任的起点,如果能够控制一个CA,那么就可以利用该CA机构随意签发数字证书,因此,处于核心的CA极易遭受攻击。一旦某个CA被破坏,那么该CA签发的所有数字证书都不再安全,不能继续使用。除此之外,数字证书依赖方事先安装或预置的CA根数字证书也有可能被攻击,如果根数字证书被恶意篡改,那么将影响整个数字证书验证过程,甚至可能将虚假用户数字证书识别为合法的用户数字证书。
近年来兴起的区块链技术,按照时间顺序将存储数字证书的区块以顺序相连的方式进行链式存储,并根据存储在每个区块中的数字证书生成该区块对应的可信树(Merkle)值,用于对该区块中存储的数字证书进行验证防止该区块中存储的数字证书被篡改。同时区块链中的每个验证节点存储 该区块链中的所有数字证书,并同时对生成及调用数字证书的请求进行验证,不存在中心的CA节点,即使某个验证节点发生故障或者遭受攻击,也能保证数字证书的正确性。
然而,区块链中却有一个很大的问题,区块链中会包含所有的历史数字证书,随着时间的推移,区块链中存储的数字证书会不断的增多,整个区块链存储的数据量会越来越大,需要验证节点的存储和计算资源也越来越多,给验证节点带来严重的负担,影响验证节点的运行和用户的体验。
发明内容
本公开实施例提供一种基于区块链的数字证书删除方法、装置及系统,用以解决现有技术中存在数字证书存储过程中数据量越来越大,需要验证节点的存储和计算资源越来越高,影响验证节点的运行和用户的体验的问题。
本公开实施例公开了一种区块链的数字证书删除方法,所述区块链中包含多个验证节点和至少一个备份节点,所述删除方法应用于区块链中的任一备份节点,所述方法包括:
根据自身针对每个区块保存的每个备份数字证书的信息,确定针对该区块保存的每个备份数字证书是否均无效;
如果确定针对该区块保存的每个备份数字证书均无效,向区块链中的每个验证节点发送包含该区块的标识信息的删除消息,其中,所述删除消息,用于使每个验证节点判断自身该标识信息的区块中每个数字证书是否均无效,并在确定该标识信息的区块中每个数字证书均无效时,删除该标识信息的区块的区块体。
本公开实施例公开了一种基于区块链的数字证书删除方法,所述区块链中包含多个验证节点和至少一个备份节点,所述删除方法应用于区块链中的任一验证节点,所述方法包括:
接收区块链中备份节点发送的包含区块的标识信息的删除消息,其中所述删除消息为区块链中的备份节点根据其自身针对每个区块保存的每个备份数字证书的信息,确定针对该区块保存的每个备份数字证书均无效后发送的;
判断自身保存的该标识信息的区块中每个数字证书是否均无效;
如果确定该标识信息的区块中每个数字证书均无效,删除该区块的区块体。
本公开实施例公开了一种基于区块链的数字证书删除装置,所述区块链中包含多个验证节点和至少一个备份节点,所述删除装置应用于区块链中的任一备份节点,所述装置包括:
确定模块,配置为根据自身针对每个区块保存的每个备份数字证书的信息,确定针对该区块保存的每个备份数字证书是否均无效;
发送模块,配置为如果确定针对该区块保存的每个备份数字证书均无效,向区块链中的每个验证节点发送包含该区块的标识信息的删除消息,使每个验证节点判断自身该标识信息的区块中每个数字证书是否均无效,并在确定该标识信息的区块中每个数字证书均无效时,删除该标识信息的区块的区块体。
本公开实施例公开了一种基于区块链的数字证书删除装置,所述区块链中包含多个验证节点和至少一个备份节点,所述删除装置应用于区块链中的任一验证节点,所述装置包括:
接收模块,配置为接收区块链中备份节点发送的包含区块的标识信息的删除消息,其中所述删除消息为区块链中的备份节点根据其自身针对每个区块保存的每个备份数字证书的信息,确定针对该区块保存的每个备份数字证书均无效后发送的;
判断模块,配置为判断自身保存的该标识信息的区块中每个数字证书 是否均无效;
删除模块,配置为如果确定该标识信息的区块中每个数字证书均无效,删除该区块的区块体。
本公开实施例公开了一种基于区块链的数字证书删除系统,所述删除系统包括至少一个上述应用于备份节点的基于区块链的数字证书删除装置,及多个上述应用于验证节点的基于区块链的数字证书删除装置。
本公开实施例还公开了一种计算机存储介质,所述计算机存储介质存储有计算可执行指令;所述计算机可执行指令被执行后,能够实现应用于备份节点的基于区块链的数字证书删除方法中的一个或多个,或实现应用于验证节点的基于区块链的数字证书删除方法中的一个或多个。
本公开实施例公开了一种基于区块链的数字证书删除方法、装置及系统,所述区块链中包含多个验证节点和至少一个备份节点,所述删除方法应用于区块链中的任一备份节点,所述方法包括:根据自身针对每个区块保存的每个备份数字证书的信息,确定针对该区块保存的每个备份数字证书是否均无效;如果确定针对该区块保存的每个备份数字证书均无效,向区块链中的每个验证节点发送包含该区块的标识信息的删除消息,使每个验证节点判断自身该标识信息的区块中每个数字证书是否均无效,并在确定该标识信息的区块中每个数字证书均无效时,删除该标识信息的区块的区块体。由于在本公开实施例中,如果备份节点判断针对某一区块保存的每个备份数字证书均无效,向区块链中的每个验证节点发送包含该区块的标识信息的删除消息,使每个验证节点判断自身该标识信息的区块中每个数字证书是否均无效,并在确定该标识信息的区块中每个数字证书均无效时,删除该标识信息的区块的区块体,减少了数据证书存储过程中占用的存储空间,节约了验证节点的存储和在后续进行验证时所需计算量,并进一步减少了所消耗的计算资源,提高了验证节点的运行效率(例如,验证 效率)和用户的体验。
图1为本公开提供的一种区块链架构示意图;
图2为本公开实施例1提供的一种基于区块链的数字证书删除过程示意图;
图3为本公开实施例1和实施例4提供的一种验证节点存储数字证书的存储结构示意图;
图4为本公开实施例4提供的一种基于区块链的数字证书删除过程示意图;
图5为本公开实施例7提供的一种基于区块链的数字证书删除装置结构示意图;
图6为本公开实施例8提供的一种基于区块链的数字证书删除装置结构示意图;
图7为本公开实施例9提供的一种基于区块链的数字证书删除系统结构示意图。
下面将结合本公开实施例中的附图,对本公开实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本公开实施例一部分实施例,而不是全部的实施例。基于本公开实施例中的实施例,本领域普通技术人员在没有作出创造性劳动前提下所获得的所有其他实施例,都属于本公开实施例保护的范围。
图1为本公开实施例提供的一种区块链架构示意图,在该区块链中包含多个验证节点和至少一个备份节点,每个验证节点用于验证用户对数字 证书的生成请求及用户对数字证书状态的更新请求。每个验证节点按照预设的时间顺序依次产生新的区块,并根据数字证书生成时间将数字证书存储到对应的区块中,还用于根据用户对数字证书状态的更新请求对存储的数字证书的状态进行更新。备份节点用于针对验证节点的每个区块,备份存入该区块的每个数字证书,并根据用户对数字证书状态的更新请求对针对每个区块备份的数字证书的状态进行更新。
实施例1:
图2为本公开实施例提供的一种基于区块链的数字证书删除过程示意图,该过程包括:
S201:根据自身针对每个区块保存的每个备份数字证书的信息,确定针对该区块保存的每个备份数字证书是否均无效。
本公开实施例实施例提供的一种基于区块链的数字证书删除方法,应用于区块链中的任一备份节点,该备份节点可以是具有运算和存储功能的个人电脑(Personal Computer,PC)机、服务器等设备。
在本公开实施例实施例中,因为在区块链中如果未遭到恶意更改,每个验证节点的每个对应区块中保存的数字证书是相同的,而备份节点对区块链中每个验证节点的每个区块保存的数字证书进行备份,即针对验证节点保存的每个区块中的数字证书进行备份,在备份节点中针对每个区块保存有该区块中每个数字证书对应的备份数字证书。
可选地,备份节点根据自身针对每个区块保存的每个备份数字证书的信息,确定针对该区块保存的每个备份数字证书是否均无效,其中备份数字证书的信息可以是该数字证书的有效期。一个区块内保存有多个备份数字证书,若该区域内每一个备份数字证书均失效了,则表明该区块的区块体内的每个数字证书均无效,则至少可以删除该区块的区块体了,故生成所述删除消息。
例如:备份节点针对区块A保存有备份数字证书1、备份数字证书2,针对区块B保存有备份数字证书3、备份数字证书4。当前时间2017年3月29日,针对区块A备份节点根据备份数字证书1的有效期2015年7月1日-2016年7月1日,确定备份数字证书1的有效期过期,备份数字证书1无效,根据备份数字证书2的有效期2016年2月1日-2017年2月1日,确定备份数字证书2的有效期过期,备份数字证书2无效,针对区块A保存的备份数字证书1、备份数字证书2均无效,确定针对区块A保存的每个备份数字证书均无效;针对区块B备份节点根据备份数字证书3的有效期2015年7月5日-2016年7月5日,确定备份数字证书3的有效期过期,备份数字证书3无效,根据备份数字证书4的有效期2016年5月1日-2017年5月1日,确定备份数字证书4的有效期未过期,备份数字证书4有效,针对区块B保存的备份数字证书4有效,确定针对区块B保存的每个备份数字证书中存在有效的备份数字证书。
S202:如果确定针对该区块保存的每个备份数字证书均无效,向区块链中的每个验证节点发送包含该区块的标识信息的删除消息。该删除消息可以使每个验证节点判断自身该标识信息的区块中每个数字证书是否均无效,并在确定该标识信息的区块中每个数字证书均无效时,删除该标识信息的区块的区块体。
区块链中的每个区块由区块头和区块体组成,区块头中保存有该区块产生的时间,父区块哈希值,即该区块产生的时间之前的上一区块的哈希值,根据该区块中保存的每个数字证书确定的Merkle值,区块体中保存有记录在该区块的每个数字证书。图3为本公开实施例实施例提供的一种验证节点存储数字证书的存储结构示意图,验证节点按照时间顺序依次存储有创世区块、区块2…区块n,其中每个区块由区块头和区块体组成,每个区块体中保存有存储在该区块的每个数字证书。
可选地,如果备份节点确定针对该区块保存的每个备份数字证书均无效,则说明针对该区块保存的每个备份数字证书均可删除,向区块链中的每个验证节点发送包含该区块的标识信息的删除消息,如果验证节点每个区块中保存的数字证书与备份节点保存的备份数字证书相同,验证节点可以直接删除自身所述标识信息的区块的区块体,但是为了保证对数字证书删除的准确性,避免错误删除有效的数字证书,在用户需要对数字证书进行验证时,无法通过该错误删除的有效的数字证书,对用户的权益造成损害,在本公开实施例实施例中验证节点接收到包含该区块的标识信息的删除消息后,判断自身该标识信息的区块中每个数字证书是否均无效,并在确定该标识信息的区块中每个数字证书均无效时,删除该标识信息的区块的区块体。
例如:备份节点针对区块A保存的每个备份数字证书均无效,则说明针对该区块A保存的每个备份数字证书均可删除,向区块链中的每个验证节点发送包含区块A标识信息00001的删除消息,验证节点接收到包含标识信息00001的删除消息后,通过标识信息00001识别自身保存的该标识信息的区块A,验证自身区块A中每个数字证书是否均无效,如果自身区块A中每个数字证书均无效,删除该区块A的区块体。
由于在本公开实施例中,如果备份节点判断针对某一区块保存的每个备份数字证书均无效,向区块链中的每个验证节点发送包含该区块的标识信息的删除消息,使每个验证节点判断自身该标识信息的区块中每个数字证书是否均无效,并在确定该标识信息的区块中每个数字证书均无效时,删除该标识信息的区块的区块体,减少了数据证书存储过程中占用的存储空间,节约了验证节点的存储和计算资源,提高了验证节点的运行效率和用户的体验。
实施例2:
为了更准确的确定针对每个区块保存的每个备份数字证书是否均无效,在上述实施例的基础上,在本公开实施例中,所述根据自身针对每个区块保存的每个备份数字证书的信息,确定针对该区块保存的每个备份数字证书是否均无效包括:
根据自身针对每个区块保存的每个备份数字证书的信息,确定针对该区块保存的每个备份数字证书的有效期是否过期和/或备份数字证书是否已吊销状态;如备份数字证书的有效期已经超过了,则表示该证书已过期,相当于该备份数字证书已无效。若一个备份数字证书的状态为吊销状态,即该备份数字证书已吊销,从而该备份数据证书已失效。
如果针对该区块保存的每个备份数字证书为有效期过期和/或备份数字证书已吊销,确定针对该区块保存的每个备份数字证书均无效。
在本公开实施例实施例中,备份数字证书的信息包括:备份数字证书的有效期及备份数字证书的状态信息,其中备份数据证书的状态信息包括:签发、吊销、挂起、恢复等,备份节点可以通过识别备份数字证书的状态信息,确定备份数字证书是否已吊销状态,可选地,对备份数字证书状态信息的识别是现有技术不再进行赘述。备份节点可以根据自身针对每个区块保存的每个备份数字证书的有效期是否均过期,确定针对该区块保存的每个备份数字证书是否均无效;当然了,也可以根据自身针对每个区块保存的每个备份数字证书的状态是否均为吊销,确定针对该区块保存的每个备份数字证书是否均无效。
可选地,可以同时根据自身针对每个区块保存的每个备份数字证书的有效期是否过期和该备份数字证书是否已吊销,确定针对每个区块保存的每个备份数字证书是否均无效。如果针对该区块保存的每个备份数字证书均满足该备份数字证书的有效期过期和/或该备份数字证书已吊销,确定针对该区块保存的每个备份数字证书均无效。在本公开实施例实施例中,针 对每个备份数字证书,如果该备份数字证书的有效期为过期,或者该备份数字证书已吊销,则确定该备份数字证书无效。
例如:备份节点针对区块C保存有备份数字证书5、备份数字证书6,其中备份数字证书5的有效期为2015年7月5日-2016年7月5日,状态为未吊销,备份数字证书6的有效期为2016年7月5日-2017年7月5日,状态为吊销,当前时间为2017年3月29日,备份数字证书5的有效期过期,备份数字证书6的状态为吊销,确定针对区块C保存的每个备份数字证书均无效。
实施例3:
为了防止因备份节点的证书被恶意篡改造成验证节点对自身保存的数字证书的错误删除,在上述各实施例的基础上,在本公开实施例中,如果所述区块链中的每个验证节点的每个区块中保存的每个数字证书使用预设的算法进行变换,所述向区块链中的每个验证节点发送包含该区块的标识信息的删除消息后,所述方法还包括:
将自身针对所述标识信息的区块保存的每个备份数字证书发送给每个验证节点。
为了保证区块链中每个验证节点保存的数字证书数据安全性,区块链中的每个验证节点可以根据预先的设定,对每个区块中保存的每个数字证书使用预设的算法进行变换。例如:验证节点对每个区块保存的每个数字证书使用散列算法进行散列运算,每个区块保存进行散列运算后的每个数字证书。在本公开实施例中,如果验证节点对每个区块保存的每个数字证书使用预设的算法进行变换,备份节点针对区块链中的每个区块备份该区块中保存的使用预设的算法进行变换之前的每个数字证书。
可选地,如果区块链中的每个验证节点的每个区块中保存的每个数字证书使用预设的算法进行变化,备份节点根据自身针对每个区块保存的每 个备份数字证书的信息,确定针对该区块保存的每个备份数字证书均无效后,向区块链中的每个验证节点发送包含该区块的标识信息的删除消息后,还将自身针对所述标识信息的区块保存的每个备份数字证书发送给每个验证节点,验证节点收到备份节点发送的包含该区块的标识信息的删除消息和针对所述标识信息的区块保存的每个备份数字证书后,根据所述标识信息确定自身该标识信息的区块,并采用预设的算法将备份节点针对该标识信息的区块保存的每个备份数字证书进行变换,通过判断自身该标识信息的区块保存的每个数字证书是否均与该备份数字证书变换后的数字证书对应匹配,从而确定备份节点针对该标识信息的区块保存的每个备份数字证书是否正确。
例如:区块链中的每个验证节点的每个区块中保存的每个数字证书使用散列算法进行变化,备份节点确定针对标识信息为00005的区块E保存的每个备份数字证书均无效,备份节点向区块链中每个验证节点发送包括标识信息00005的删除消息后,并将自身针对标识信息为00005的区块E保存的每个备份数字证书发送给区块链中的每个验证节点。
验证节点接收到包含标识信息00005的删除消息和针对标识信息00005的区块保存的每个备份数字证书后,根据标识信息00005识别自身标识信息为00005的区块E,采用预设的散列算法将备份节点针对标识信息00005的区块保存的每个备份数字证书进行散列运算,判断自身区块E中保存的每个数字证书是否均与散列运算后的备份数字证书对应匹配,如果是,确定备份节点针对区块E保存的每个备份数字证书正确。
实施例4:
图4为本公开实施例提供的一种基于区块链的数字证书删除过程示意图,该过程包括:
S401:接收区块链中备份节点发送的包含区块的标识信息的删除消息, 其中所述删除消息为区块链中的备份节点根据其自身针对每个区块保存的每个备份数字证书的信息,确定针对该区块保存的每个备份数字证书均无效后发送的。
本公开实施例实施例提供的一种基于区块链的数字证书删除方法,应用于区块链中的任一验证节点,该验证节点可以是具有运算和存储功能的PC机、服务器等设备。
在本公开实施例中,因为在区块链中如果未遭到恶意更改,每个验证节点的每个对应区块中保存的数字证书是相同的,而备份节点对区块链中每个验证节点的每个区块保存的数字证书进行备份,即针对验证节点保存的每个区块中的数字证书进行备份,在备份节点中针对每个区块保存有该区块中每个数字证书对应的备份数字证书。备份节点根据自身针对每个区块保存的每个备份数字证书的信息,确定针对该区块保存的每个备份数字证书是否均无效,如果针对该区块中保存的每个备份数字证书均无效,向区块链中每个验证节点发送包含该区块的标识信息的删除消息。
例如:备份节点针对区块A保存有备份数字证书1、备份数字证书2,当前时间2017年3月29日,针对区块A备份节点根据备份数字证书1的有效期2015年7月1日-2016年7月1日,确定备份数字证书1的有效期过期,备份数字证书1无效,根据备份数字证书2的有效期2016年2月1日-2017年2月1日,确定备份数字证书2的有效期过期,备份数字证书2无效,针对区块A保存的备份数字证书1、备份数字证书2均无效,确定针对区块A保存的每个备份数字证书均无效,向区块链中的每个验证节点发送包含该区块A的标识信息00001的删除消息。
可选地,验证节点接收区块链中备份节点根据其自身针对每个区块保存的每个备份数字证书的信息,确定针对该区块保存的每个备份数字证书均无效后,发送的包含该区块的标识信息的删除消息。
S402:判断自身保存的该标识信息的区块中每个数字证书是否均无效。
可选地,验证节点接收到备份节点发送的包含区块的标识信息的删除消息后,判断自身保存的该标识信息的区块中每个数字证书是否均无效,其中验证节点可以根据数字证书的有效期判断该数字证书是否有效。
例如:验证节点接收到备份节点发送的包含区块的标识信息00001的删除消息,识别自身标识信息为00001的区块A,区块A保存有数字证书1、数字证书2,当前时间2017年3月29日,验证节点根据数字证书1的有效期2015年7月1日-2016年7月1日,确定数字证书1的有效期过期,数字证书1无效,根据数字证书2的有效期2016年2月1日-2017年2月1日,确定数字证书2的有效期过期,数字证书2无效,针对区块A保存的数字证书1、数字证书2均无效,确定标识信息为00001的区块A中每个数字证书均无效。
S403:如果确定该标识信息的区块中每个数字证书均无效,删除该区块的区块体。
区块链中的每个区块由区块头和区块体组成,区块头中保存有该区块产生的时间,父区块哈希值,即该区块产生的时间之前的上一区块的哈希值,根据该区块中保存的每个数字证书确定的Merkle值,区块体中保存有记录在该区块的每个数字证书。图3为本公开实施例实施例提供的一种验证节点存储数字证书的存储结构示意图,验证节点按照时间顺序依次存储有创世区块、区块2…区块n,其中每个区块由区块头和区块体组成,每个区块体中保存有存储在该区块的每个数字证书。
可选地,如果验证节点确定该标识信息的区块中每个数字证书均无效,则说明该区块中每个数字证书均可删除,删除该区块用于存储数字证书的区块体;如果验证节点确定该标识信息的区块中存在至少一个有效的数字证书,则说明该区块中存在不可删除的数字证书,丢弃所述备份节点发送 的所述删除消息,不对该区块做任何处理。
例如:验证节点确定标识信息为00001的区块A中每个数字证书均无效,则删除区块A用于存储数字证书的区块体。
由于在本公开实施例中,验证节点根据备份节点根据其自身针对每个区块保存的每个备份数字证书的信息,判断针对某一区块保存的每个备份数字证书均无效后发送的包含该区块的标识信息的删除消息,确定自身该标识信息的区块中每个数字证书均无效后,删除该标识信息的区块的区块体,减少了数据证书存储过程中占用的存储空间,节约了的存储和计算资源,提高了的运行效率和用户的体验。
实施例5:
为了防止因备份节点的证书被恶意篡改造成对自身保存的数字证书的错误删除,在上述各实施例的基础上,在本公开实施例中,如果对每个区块保存的每个数字证书使用预设的算法进行变换,所述接收区块链中备份节点发送的包含区块的标识信息的删除消息后,所述方法还包括:
接收所述备份节点发送的所述备份节点针对所述标识信息的区块保存的每个备份数字证书;
所述判断自身保存的该标识信息的区块中每个数字证书的是否均无效之前,所述方法还包括:
采用所述预设的算法对所述每个备份数字证书进行变换;
针对所述标识信息的区块中保存的每个数字证书,判断自身保存的每个数字证书是否均与该备份数字证书变换后的数字证书对应匹配;
如果是,进行后续步骤。该后续步骤至少包括:判断自身保存的该标识信息的区块中每个数字证书的是否均无效的步骤。
为了保证区块链中每个验证节点保存的数字证书数据安全性,验证节点可以根据预先的设定,使用预设的算法对每个区块保存的每个数字证书 使用预设的算法进行变换,例如:验证节点对每个区块中保存的每个数字证书使用散列算法进行散列运算,针对每个区块保存进行散列运算后的每个数字证书。在本公开实施例中,如果验证节点对每个区块保存的每个数字证书使用预设的算法进行变换,备份节点针对区块链中的每个区块备份该区块中保存的使用预设的算法进行变换之前的每个数字证书,并且保存有每个数字证书的信息。
可选地,如果验证节点对每个区块中保存的每个数字证书使用预设的算法进行变化,验证节点接收区块链中备份节点发送的包含区块标识的删除消息后,接收所述备份节点发送的所述备份节点针对所述标识信息的区块保存的每个备份数字证书。
另外,为了防止备份节点针对该标识信息的区块保存的备份数字证书被恶意篡改,验证节点在判断自身保存的该标识的区块中每个数字证书是否均无效之前,还需判断备份节点发送的所述每个备份数字证书是否正确,可选地,验证节点使用预设的算法对所述每个备份数字证书进行变换,通过判断自身针对该标识信息的区块中保存的每个数字证书,即采用预设的算法进行变换后的数字证书,是否均与该备份数字证书变换后的数字证书对应匹配,如果对应匹配,则确定所述备份节点针对该标识信息的区块保存的每个备份数字证书未被篡改,备份节点针对该标识信息的区块保存的每个备份数字证书正确。此时因为备份节点已经判断该标识信息的区块中保存的每个备份数字证书均无效,则验证节点也可以将该标识信息的区块的区块体删除,但因为备份节点保存的备份证书的可靠性不是很高,为了进一步保证数字证书的安全性,该验证节点验证自身该标识信息的区块中每个数字证书是否无效。
如果验证节点使用预设的算法对所述每个备份数字证书进行变换,判断自身针对该标识信息的区块中保存的每个数字证书,即采用预设的算法 进行变换后的数字证书,不能均与该备份数字证书变换后的数字证书对应匹配,则说明所述备份节点针对该标识信息的区块保存的每个备份数字证书中存在至少一个备份数字证书被篡改,为了保证自身保存的数字证书的正确性,避免错误的删除有效的不可删除的数字证书,验证节点丢弃所述备份节点发送的所述删除消息,不对该标识信息的区块做任何处理。
实施例6:
为了准确的确定自身区块中每个数字证书是否均无效,在上述各实施例的基础上,在本公开实施例中,所述判断自身保存的该标识信息的区块中每个数字证书是否均无效包括:
获取自身保存的该标识信息的区块中每个数字证书的有效期及状态信息;
判断该标识信息的区块中每个数字证书的有效期是否过期和/或数字证书是否已吊销;
如果该标识信息的区块中每个数字证书为有效期过期和/或数字证书的状态为吊销,确定该标识信息的区块中每个数字证书均无效。
在本公开实施例实施例中,数字证书的信息包括:数字证书的有效期及数字证书的状态信息,其中数据证书的状态信息包括:签发、吊销、挂起、恢复等,验证节点可以通过识别数字证书的状态信息,确定数字证书是否已吊销,可选地,对数字证书状态信息的识别是现有技术不再进行赘述。如果没有针对验证节点预先设定,验证节点对每个区块中保存的每个数字证书使用预设的算法进行变换,验证节点根据自身保存的该标识信息的区块中每个数字证书的信息,识别该标识信息的区块中保存的每个未经变换的每个数字证书的有效期,验证节点可以根据自身保存的该标识信息的区块中每个数字证书的有效期是否均过期,确定该标识信息的区块中每个数字证书是否均无效;当然了,也可以根据自身保存的该标识信息的区 块中每个数字证书的状态是否均为吊销,确定该标识信息的区块中每个数字证书是否均无效。
可选地,可以同时根据自身保存的该标识信息的区块中每个数字证书的有效期是否过期和该数字证书是否已吊销,确定该标识信息的区块中每个数字证书是否均无效。如果针对该标识信息的区块中每个数字证书均满足该数字证书的有效期过期和/或该数字证书的状态为吊销,确定该标识信息的区块中每个数字证书均无效。在本公开实施例实施例中,针对每个数字证书,如果该数字证书的有效期为过期,或者该数字证书的状态为吊销,则确定该数字证书无效。
例如:备份节点发送的删除消息包含的区块的标识信息为00003,验证节点自身标识信息为00003的区块C中保存有数字证书5、数字证书6,其中数字证书5的有效期为2015年7月5日-2016年7月5日,状态为未吊销,数字证书6的有效期为2016年7月5日-2017年7月5日,状态为吊销,当前时间为2017年3月29日,数字证书5的有效期过期,数字证书6的证书状态为吊销,确定自身标识信息为00003的区块C中每个数字证书均无效。
另外,如果为了保证区块链中每个验证节点保存的数字证书数据安全性,针对验证节点预先设定,验证节点对每个区块中保存的每个数字证书使用预设的算法进行变换,因数字证书的有效期记录在数字证书中,验证节点不能识别该标识信息的区块保存的每个变换后的数字证书的有效期,为了使验证节点判断自身保存的该标识信息的区块中每个数字证书是否均无效,在本公开实施例实施例中,如果验证节点针对备份节点发送的每个备份数字证书,判断自身针对所述标识信息的区块中保存的每个数字证书均与该备份数字证书变换后的数字证书对应匹配,验证节点根据接收到的备份节点发送的所述备份节点针对所述标识信息的区块保存的每个备份数 字证书及自身保存的每个数字证书的状态信息,判断自身保存的该标识信息的区块中每个数字证书是否均无效。
可选地,验证节点根据该标识信息的区块中每个数字证书是否已吊销和/或接收到的每个备份数字证书的有效期是否过期,确定该标识信息的区块中每个数字证书是否均无效。如果该标识信息的区块中每个数字证书均满足该数字证书的状态为吊销和/或接收到的每个备份数字证书为有效期过期,确定该标识信息的区块中每个数字证书均无效。在本公开实施例实施例中,针对每个数字证书,如果该数字证书的状态信息为吊销,或与该数字证书对应匹配的备份数字证书为有效期过期,则确定该数字证书无效。
例如:区块链中的每个验证节点的每个区块中保存的每个数字证书使用散列算法进行变化,备份节点确定针对标识信息为00005的区块E保存的每个备份数字证书均无效,备份节点向区块链中每个验证节点发送包括标识信息00005的删除消息后,并将自身针对标识信息为00005的区块E保存的每个备份数字证书发送给区块链中的每个验证节点。
验证节点接收到包含标识信息00005的删除消息和针对标识信息00005的区块保存的每个备份数字证书后,根据标识信息00005识别自身标识信息为00005的区块E,采用预设的散列算法将备份节点针对标识信息00005的区块保存的每个备份数字证书进行散列运算,判断自身区块E中保存的每个数字证书是否均与散列运算后的备份数字证书对应匹配,如果对应匹配,确定所述备份节点针对区块E保存的每个备份数字证书未被篡改,每个备份数字证书正确,根据自身区块E中保存的数字证书8的状态信息为吊销、数字证书9的状态信息为未吊销,与数字证书8对应匹配的备份数字证书8的有效期为2016年7月5日-2017年7月5日、与数字证书9对应匹配的备份数字证书9的有效期为2015年8月5日-2016年8月5日,当前时间为2017年3月29日,确定数字证书8的状态信息为吊销,与数 字证书9对应匹配的备份数字证书9的有效期过期,确定自身区块E中保存的每个数字证书均无效。
实施例7:
图5为本公开实施例提供的一种基于区块链的数字证书删除装置结构示意图,该装置包括:
确定模块51,配置为根据自身针对每个区块保存的每个备份数字证书的信息,确定针对该区块保存的每个备份数字证书是否均无效;
发送模块52,配置为如果确定针对该区块保存的每个备份数字证书均无效,向区块链中的每个验证节点发送包含该区块的标识信息的删除消息,使每个验证节点判断自身该标识信息的区块中每个数字证书是否均无效,并在确定该标识信息的区块中每个数字证书均无效时,删除该标识信息的区块的区块体。
所述确定模块51,配置为根据自身针对每个区块保存的每个备份数字证书的信息,确定针对该区块保存的每个备份数字证书的有效期是否过期和/或备份数字证书是否已吊销;如果针对该区块保存的每个备份数字证书为有效期过期和/或备份数字证书已吊销,确定针对该区块保存的每个备份数字证书均无效。
所述发送模块52,还配置为如果所述区块链中的每个验证节点的每个区块中保存的每个数字证书使用预设的算法进行变换,将自身针对所述标识信息的区块保存的每个备份数字证书发送给每个验证节点。
在本公开实施例中,如图5所示的基于区块链的数字证书删除装置,应用于区块链中的任一备份节点,其中所述区块链中包含多个验证节点和至少一个备份节点。
实施例8:
图6为本公开实施例提供的一种基于区块链的数字证书删除装置结构 示意图,该装置包括:
接收模块61,配置为接收区块链中备份节点发送的包含区块的标识信息的删除消息,其中所述删除消息为区块链中的备份节点根据其自身针对每个区块保存的每个备份数字证书的信息,确定针对该区块保存的每个备份数字证书均无效后发送的;
判断模块62,配置为判断自身保存的该标识信息的区块中每个数字证书是否均无效;
删除模块63,配置为如果确定该标识信息的区块中每个数字证书均无效,删除该区块的区块体。
所述接收模块61,还配置为如果对每个区块保存的每个数字证书使用预设的算法进行变换,接收所述备份节点发送的所述备份节点针对所述标识信息的区块保存的每个备份数字证书;
所述装置还包括:
匹配模块64,配置为采用所述预设的算法对所述每个备份数字证书进行变换;针对所述标识信息的区块中保存的每个数字证书,判断自身保存的每个数字证书是否均与该备份数字证书变换后的数字证书对应匹配;如果匹配结果为是,触发判断模块。
所述判断模块62,配置为获取自身保存的该标识信息的区块中每个数字证书的有效期及状态信息;判断该标识信息的区块中每个数字证书的有效期是否过期和/或数字证书是否已吊销;如果该标识信息的区块中每个数字证书为有效期过期和/或数字证书的状态为吊销,确定该标识信息的区块中每个数字证书均无效。
在本公开实施例中,如图6所示的基于区块链的数字证书删除装置,应用于区块链中的任一验证节点,其中所述区块链中包含多个验证节点和至少一个备份节点。
实施例9:
图7为本公开实施例实施例提供的一种基于区块链的数字证书删除系统结构示意图,该删除系统包括至少一个应用于备份节点71的基于区块链的数字证书删除装置,及多个应用于验证节点72的基于区块链的数字证书删除装置。
本公开实施例公开了一种基于区块链的数字证书删除方法、装置及系统,所述区块链中包含多个验证节点和至少一个备份节点,所述删除方法应用于区块链中的任一备份节点,所述方法包括:根据自身针对每个区块保存的每个备份数字证书的信息,确定针对该区块保存的每个备份数字证书是否均无效;如果确定针对该区块保存的每个备份数字证书均无效,向区块链中的每个验证节点发送包含该区块的标识信息的删除消息,使每个验证节点判断自身该标识信息的区块中每个数字证书是否均无效,并在确定该标识信息的区块中每个数字证书均无效时,删除该标识信息的区块的区块体。由于在本公开实施例中,如果备份节点判断针对某一区块保存的每个备份数字证书均无效,向区块链中的每个验证节点发送包含该区块的标识信息的删除消息,使每个验证节点判断自身该标识信息的区块中每个数字证书是否均无效,并在确定该标识信息的区块中每个数字证书均无效时,删除该标识信息的区块的区块体,减少了数据证书存储过程中占用的存储空间,节约了验证节点的存储和计算资源,提高了验证节点的运行效率和用户的体验。
对于系统/装置实施例而言,由于其基本相似于方法实施例,所以描述的比较简单,相关之处参见方法实施例的部分说明即可。
本公开实施例还公开了一种计算机存储介质,所述计算机存储介质存储有计算可执行指令;所述计算机可执行指令被执行后,能够实现应用于备份节点的基于区块链的数字证书删除方法中的一个或多个,或实现应用 于验证节点的基于区块链的数字证书删除方法中的一个或多个,例如,执行如图2和/或图4所示的方法。本申请实施例中提到的计算机存储介质可为各种类型的存储介质,可选为非瞬间存储介质。
本领域内的技术人员应明白,本申请的实施例可提供为方法、系统、或计算机程序产品。因此,本申请可采用完全硬件实施例、完全软件实施例、或结合软件和硬件方面的实施例的形式。而且,本申请可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器、CD-ROM、光学存储器等)上实施的计算机程序产品的形式。
本申请是参照根据本申请实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的 功能的步骤。
尽管已描述了本申请的优选实施例,但本领域内的技术人员一旦得知了基本创造性概念,则可对这些实施例做出另外的变更和修改。所以,所附权利要求意欲解释为包括优选实施例以及落入本申请范围的所有变更和修改。
显然,本领域的技术人员可以对本公开实施例进行各种改动和变型而不脱离本公开实施例的精神和范围。这样,倘若本公开实施例的这些修改和变型属于本公开实施例权利要求及其等同技术的范围之内,则本公开实施例也意图包含这些改动和变型在内。
本公开实施例中若一个备份节点发现自身存储的一个区域上的所有备份数字证书中的每个备份数字证书均无效时,会生成删除消息,从而可以使得所有存储该区块的验证节点至少可以删除该区块的区块体,一方面减少存储的数据量,从而减少所消耗的存储资源,另一方面减少后续区块链在生成过程中的校验数据量,从而节省校验所需的计算资源,提升校验效率,故具有积极的工业效果。与此同时,本公开实施例提供的技术方案具有实现简便的特点,可在工业上广泛实施。
Claims (14)
- 一种基于区块链的数字证书删除方法,所述区块链中包含多个验证节点和至少一个备份节点,所述删除方法应用于区块链中的任一备份节点,所述方法包括:根据自身针对每个区块保存的每个备份数字证书的信息,确定针对该区块保存的每个备份数字证书是否均无效;如果确定针对该区块保存的每个备份数字证书均无效,向区块链中的每个验证节点发送包含该区块的标识信息的删除消息,其中,所述删除消息,用于使每个验证节点判断自身该标识信息的区块中每个数字证书是否均无效,并在确定该标识信息的区块中每个数字证书均无效时,删除该标识信息的区块的区块体。
- 如权利要求1所述的方法,其中,所述根据自身针对每个区块保存的每个备份数字证书的信息,确定针对该区块保存的每个备份数字证书是否均无效包括:根据自身针对每个区块保存的每个备份数字证书的信息,确定针对该区块保存的每个备份数字证书的有效期是否过期和/或备份数字证书是否已吊销;如果针对该区块保存的每个备份数字证书为有效期过期和/或备份数字证书已吊销,确定针对该区块保存的每个备份数字证书均无效。
- 如权利要求1所述的方法,其中,如果所述区块链中的每个验证节点的每个区块中保存的每个数字证书使用预设的算法进行变换,所述向区块链中的每个验证节点发送包含该区块的标识信息的删除消息后,所述方法还包括:将自身针对所述标识信息的区块保存的每个备份数字证书发送给每个 验证节点。
- 一种基于区块链的数字证书删除方法,所述区块链中包含多个验证节点和至少一个备份节点,所述删除方法应用于区块链中的任一验证节点,所述方法包括:接收区块链中备份节点发送的包含区块的标识信息的删除消息,其中所述删除消息为:区块链中的备份节点根据其自身针对每个区块保存的每个备份数字证书的信息,确定针对该区块保存的每个备份数字证书均无效后发送的;判断自身保存的该标识信息的区块中每个数字证书是否均无效;如果确定该标识信息的区块中每个数字证书均无效,删除该区块的区块体。
- 如权利要求4所述的方法,其中,如果对每个区块保存的每个数字证书使用预设的算法进行变换,所述接收区块链中备份节点发送的包含区块的标识信息的删除消息后,所述方法还包括:接收所述备份节点发送的所述备份节点针对所述标识信息的区块保存的每个备份数字证书;所述方法还包括:采用所述预设的算法对所述每个备份数字证书进行变换;针对所述标识信息的区块中保存的每个数字证书,判断自身保存的每个数字证书是否均与该备份数字证书变换后的数字证书对应匹配;所述判断自身保存的该标识信息的区块中每个数字证书是否均无效,包括:如果自身保存的每个数字证书均与该备份数字证书变换后的数字证书对应匹配,判断自身保存的该标识信息的区块中每个数字证书是否均无效。
- 如权利4或5所述的方法,其中,所述判断自身保存的该标识信息 的区块中每个数字证书是否均无效包括:获取自身保存的该标识信息的区块中每个数字证书的有效期及状态信息;判断该标识信息的区块中每个数字证书的有效期是否过期和/或数字证书是否已吊销;如果该标识信息的区块中每个数字证书为有效期过期和/或数字证书的状态为吊销,确定该标识信息的区块中每个数字证书均无效。
- 一种基于区块链的数字证书删除装置,所述装置包括:确定模块,配置为根据自身针对每个区块保存的每个备份数字证书的信息,确定针对该区块保存的每个备份数字证书是否均无效;发送模块,配置为如果确定针对该区块保存的每个备份数字证书均无效,向区块链中的每个验证节点发送包含该区块的标识信息的删除消息,使每个验证节点判断自身该标识信息的区块中每个数字证书是否均无效,并在确定该标识信息的区块中每个数字证书均无效时,删除该标识信息的区块的区块体。
- 如权利要求7所述的装置,其中,所述确定模块,配置为根据自身针对每个区块保存的每个备份数字证书的信息,确定针对该区块保存的每个备份数字证书的有效期是否过期和/或备份数字证书是否已吊销;如果针对该区块保存的每个备份数字证书为有效期过期和/或备份数字证书已吊销,确定针对该区块保存的每个备份数字证书均无效。
- 如权利要求7所述的装置,其中,所述发送模块,还配置为如果所述区块链中的每个验证节点的每个区块中保存的每个数字证书使用预设的算法进行变换,将自身针对所述标识信息的区块保存的每个备份数字证书发送给每个验证节点。
- 一种基于区块链的数字证书删除装置,所述装置包括:接收模块,配置为接收区块链中备份节点发送的包含区块的标识信息的删除消息,其中所述删除消息为区块链中的备份节点根据其自身针对每个区块保存的每个备份数字证书的信息,确定针对该区块保存的每个备份数字证书均无效后发送的;判断模块,配置为判断自身保存的该标识信息的区块中每个数字证书是否均无效;删除模块,配置为如果确定该标识信息的区块中每个数字证书均无效,删除该区块的区块体。
- 如权利要求10所述的装置,其中,所述接收模块,还配置为于如果对每个区块保存的每个数字证书使用预设的算法进行变换,接收所述备份节点发送的所述备份节点针对所述标识信息的区块保存的每个备份数字证书;所述装置还包括:匹配模块,配置为采用所述预设的算法对所述每个备份数字证书进行变换;针对所述标识信息的区块中保存的每个数字证书,判断自身保存的每个数字证书是否均与该备份数字证书变换后的数字证书对应匹配;如果匹配结果为是,触发判断模块。
- 如权利要求10所述的装置,其中,所述判断模块,配置为获取自身保存的该标识信息的区块中每个数字证书的有效期及状态信息;判断该标识信息的区块中每个数字证书的有效期是否过期和/或数字证书是否已吊销;如果该标识信息的区块中每个数字证书为有效期过期和/或数字证书的状态为吊销,确定该标识信息的区块中每个数字证书均无效。
- 一种基于区块链的数字证书删除系统,其中,所述删除系统包括至少一个如权利要求7-9任一项所述的应用于备份节点的基于区块链的数字证书删除装置,及多个如权利要求10-12任一项所述的应用于验证 节点的基于区块链的数字证书删除装置。
- 一种计算机存储介质,所述计算机存储介质存储有计算可执行指令;所述计算机可执行指令被执行后,能够实现权利要求1-3或4-6任一项提供的基于区块链的数字证书删除方法。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201710218253.XA CN108696356B (zh) | 2017-04-05 | 2017-04-05 | 一种基于区块链的数字证书删除方法、装置及系统 |
| CN201710218253.X | 2017-04-05 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2018184447A1 true WO2018184447A1 (zh) | 2018-10-11 |
Family
ID=63711997
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2018/078888 Ceased WO2018184447A1 (zh) | 2017-04-05 | 2018-03-13 | 基于区块链的数字证书删除方法、装置及系统、存储介质 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN108696356B (zh) |
| WO (1) | WO2018184447A1 (zh) |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2020093565A1 (zh) * | 2018-11-08 | 2020-05-14 | 深圳壹账通智能科技有限公司 | 区块链区块删除方法、装置以及终端设备 |
| CN111783133A (zh) * | 2020-06-02 | 2020-10-16 | 广东科学技术职业学院 | 一种基于区块链技术的网络资源管理方法 |
Families Citing this family (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN110264187B (zh) * | 2019-01-23 | 2021-06-04 | 腾讯科技(深圳)有限公司 | 数据处理方法、装置、计算机设备及存储介质 |
| CN109981586B (zh) * | 2019-02-27 | 2021-09-07 | 北京柏链基石科技有限公司 | 一种节点标记方法及装置 |
| CN112153085B (zh) * | 2019-06-26 | 2022-05-17 | 华为技术有限公司 | 一种数据处理方法、节点及区块链系统 |
| CN110598482B (zh) * | 2019-09-30 | 2023-09-15 | 腾讯科技(深圳)有限公司 | 基于区块链的数字证书管理方法、装置、设备及存储介质 |
| CN111027974B (zh) * | 2019-12-12 | 2025-04-04 | 腾讯科技(深圳)有限公司 | 一种标识码的验证方法、装置、设备及存储介质 |
| CN111737766B (zh) * | 2020-08-03 | 2020-12-04 | 南京金宁汇科技有限公司 | 一种在区块链中判断数字证书签名数据合法性的方法 |
| CN120281590B (zh) * | 2025-06-11 | 2025-11-25 | 北京火山引擎科技有限公司 | 边缘计算设备的认证信息存储方法、系统、设备及产品 |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20150206106A1 (en) * | 2014-01-13 | 2015-07-23 | Yaron Edan Yago | Method for creating, issuing and redeeming payment assured contracts based on mathemematically and objectively verifiable criteria |
| CN105790954A (zh) * | 2016-03-02 | 2016-07-20 | 布比(北京)网络技术有限公司 | 一种构建电子证据的方法和系统 |
| CN106385315A (zh) * | 2016-08-30 | 2017-02-08 | 北京三未信安科技发展有限公司 | 一种数字证书管理方法及系统 |
Family Cites Families (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN104202159B (zh) * | 2014-09-28 | 2018-09-11 | 网易有道信息技术(北京)有限公司 | 密钥分发方法和设备 |
| US20170091726A1 (en) * | 2015-09-07 | 2017-03-30 | NXT-ID, Inc. | Low bandwidth crypto currency transaction execution and synchronization method and system |
| CN106504091B (zh) * | 2016-10-27 | 2018-06-29 | 深圳壹账通智能科技有限公司 | 区块链上交易的方法及装置 |
-
2017
- 2017-04-05 CN CN201710218253.XA patent/CN108696356B/zh active Active
-
2018
- 2018-03-13 WO PCT/CN2018/078888 patent/WO2018184447A1/zh not_active Ceased
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20150206106A1 (en) * | 2014-01-13 | 2015-07-23 | Yaron Edan Yago | Method for creating, issuing and redeeming payment assured contracts based on mathemematically and objectively verifiable criteria |
| CN105790954A (zh) * | 2016-03-02 | 2016-07-20 | 布比(北京)网络技术有限公司 | 一种构建电子证据的方法和系统 |
| CN106385315A (zh) * | 2016-08-30 | 2017-02-08 | 北京三未信安科技发展有限公司 | 一种数字证书管理方法及系统 |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2020093565A1 (zh) * | 2018-11-08 | 2020-05-14 | 深圳壹账通智能科技有限公司 | 区块链区块删除方法、装置以及终端设备 |
| CN111783133A (zh) * | 2020-06-02 | 2020-10-16 | 广东科学技术职业学院 | 一种基于区块链技术的网络资源管理方法 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN108696356B (zh) | 2020-08-18 |
| CN108696356A (zh) | 2018-10-23 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2018184447A1 (zh) | 基于区块链的数字证书删除方法、装置及系统、存储介质 | |
| US11601268B2 (en) | Device attestation including attestation-key modification following boot event | |
| KR102856751B1 (ko) | 블록체인에 기반하는 암호화 통신 시스템 및 암호화 통신 방법 | |
| CN100561916C (zh) | 一种更新认证密钥的方法和系统 | |
| US8392709B1 (en) | System and method for a single request—single response protocol with mutual replay attack protection | |
| CN112583596B (zh) | 一种基于区块链技术的完全跨域身份认证方法 | |
| CN106878009B (zh) | 密钥更新方法及系统 | |
| JP6154413B2 (ja) | ルート証明書の無効化 | |
| CN112866242B (zh) | 一种基于区块链的数字身份验证方法、设备及存储介质 | |
| CN108696358B (zh) | 数字证书的管理方法、装置、可读存储介质及服务终端 | |
| CN112887282A (zh) | 一种身份认证方法、装置、系统及电子设备 | |
| CN110781140B (zh) | 区块链中数据签名的方法、装置、计算机设备及存储介质 | |
| WO2017140358A1 (en) | Method for storing data on a storage entity | |
| CN108647964A (zh) | 一种区块链数据处理方法、装置及计算机可读存储介质 | |
| CN110826092A (zh) | 一种文件签名处理系统 | |
| CN104392185B (zh) | 在云环境日志取证中实现数据完整性验证的方法 | |
| WO2020073314A1 (zh) | 密钥生成方法、获取方法、私钥更新方法、芯片和服务器 | |
| CN109543456A (zh) | 区块生成方法及计算机存储介质 | |
| KR20150135032A (ko) | Puf를 이용한 비밀키 업데이트 시스템 및 방법 | |
| CN116415227A (zh) | 密钥更新方法、服务器、客户端及存储介质 | |
| CN110545285A (zh) | 一种基于安全芯片的物联网终端安全认证方法 | |
| CN108768975A (zh) | 支持密钥更新和第三方隐私保护的数据完整性验证方法 | |
| CN113703911A (zh) | 一种虚拟机迁移方法、装置、设备、存储介质 | |
| CN114049121B (zh) | 基于区块链的账户重置方法和设备 | |
| KR20180046593A (ko) | 펌웨어 서명 검증과 보안키 관리를 위한 사물인터넷 디바이스의 펌웨어 업데이트 시스템 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 18780331 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 31/01/2020) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 18780331 Country of ref document: EP Kind code of ref document: A1 |