WO2020119506A1 - 一种基于联盟链的身份认证方法及终端设备 - Google Patents

一种基于联盟链的身份认证方法及终端设备 Download PDF

Info

Publication number
WO2020119506A1
WO2020119506A1 PCT/CN2019/122453 CN2019122453W WO2020119506A1 WO 2020119506 A1 WO2020119506 A1 WO 2020119506A1 CN 2019122453 W CN2019122453 W CN 2019122453W WO 2020119506 A1 WO2020119506 A1 WO 2020119506A1
Authority
WO
WIPO (PCT)
Prior art keywords
blockchain node
alliance chain
node
name
item information
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2019/122453
Other languages
English (en)
French (fr)
Inventor
冯承勇
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
OneConnect Smart Technology Co Ltd
Original Assignee
OneConnect Smart Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by OneConnect Smart Technology Co Ltd filed Critical OneConnect Smart Technology Co Ltd
Publication of WO2020119506A1 publication Critical patent/WO2020119506A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/33User authentication using certificates

Definitions

  • the present application relates to the field of blockchain technology, and in particular, to an identity authentication method and terminal device based on alliance chain.
  • digital certificates are usually used for trusted identity authentication (digital certificates are issued by electronic certification authorities (CA, Certificate Authority)).
  • CA electronic certification authorities
  • the commonly adopted scheme is to build a separate root CA for each organization to represent an organization in the alliance chain, and this The root CA issues digital certificates for each node in the organization to prove the identity of the node in the organization.
  • the alliance chain determines which organization the node belongs to by verifying the effective issuing root CA of the node's digital certificate.
  • An organization may participate in multiple different alliance chains, that is, an organization may have multiple root CAs, then each node in the organization will have different digital certificates issued by the root CA, that is, each node corresponds to multiple Digital certificates, which will lead to a higher error rate in the identity authentication of the nodes in the organization, which in turn leads to lower reliability of identity authentication.
  • One of the objectives of the embodiments of the present application is to provide an identity authentication method and terminal device based on the alliance chain, to solve the problem of low reliability of the existing identity authentication method based on the alliance chain.
  • the first aspect of the embodiments of the present application provides an identity authentication method based on alliance chain, which may include [0008] Submit the identity identification data of the first blockchain node and a join request to the genesis block in the alliance chain, where the join request is used to instruct the genesis block to verify A blockchain node performs identity authentication, and returns authentication pass information to the blockchain node after the identity authentication is passed, where the authentication pass information is used to indicate that the genesis block has used the identity identification data to The first blockchain node joins the corresponding alliance chain organization;
  • the identity identification data of the second blockchain node is obtained from the communication request, and according to the identity identification of the second blockchain node The data authenticates the identity of the second blockchain node;
  • an identity authentication device based on an alliance chain includes:
  • a submission unit for submitting the identity identification data of the first blockchain node and a join request to the genesis block in the alliance chain, where the join request is used to instruct the genesis block according to the identity
  • the data authenticates the identity of the first blockchain node, and returns the authentication passed information to the blockchain node after the identity authentication is passed, where the authentication passed information is used to indicate that the genesis block has based on the identity
  • the identification data adds the first blockchain node to the corresponding alliance chain organization
  • a monitoring unit configured to monitor whether a communication request of a second blockchain node is received if the authentication passing information returned by the genesis block is received;
  • the authentication unit is configured to, if a communication request of the second blockchain node is received, acquire the identification data of the second blockchain node from the communication request, and according to the second block The identity identification data of the chain node authenticates the second blockchain node;
  • a return unit configured to return data corresponding to the communication request to the second blockchain node if the identity authentication of the second blockchain node is passed.
  • a third aspect of the embodiments of the present application provides a computer-readable storage medium, the computer-readable
  • the storage medium stores computer-readable instructions, which when executed by the processor implement the following steps:
  • the identity identification data of the second blockchain node is acquired from the communication request, and according to the identity identification of the second blockchain node The data authenticates the identity of the second blockchain node;
  • a fourth aspect of the embodiments of the present application provides a terminal device, including a memory, a processor, and computer-readable instructions stored in the memory and executable on the processor, the processor The following steps are realized when the computer-readable instructions are executed:
  • the identity identification data of the second blockchain node is obtained from the communication request, and according to the identity identification of the second blockchain node The data authenticates the identity of the second blockchain node;
  • FIG. 1 is a schematic diagram of an implementation process of an identity authentication method based on alliance chain provided by an embodiment of the present application
  • FIG. 2 is a schematic diagram of an identity authentication device based on alliance chain provided by an embodiment of the present application
  • FIG. 3 is a schematic diagram of a terminal device provided by an embodiment of the present application.
  • the term “if” may be interpreted as “when” or “once” or “in response to a determination” or “in response to” detected”.
  • the phrase “if determined” or “if [described condition or event] is detected” can be interpreted in the context to mean “once determined” or “in response to determination” or “once detected [described condition or event ]” or “In response to detection of [the described condition or event]”.
  • FIG. 1 is a schematic diagram of an implementation process of a federation chain-based identity authentication method provided by an embodiment of the present application. As shown in the figure, the method may include the following steps:
  • Step S101 Submit the identity identification data of the first blockchain node and a join request to the genesis block in the alliance chain, where the join request is used to instruct the genesis block to match the identity data according to the identity data
  • the first blockchain node performs identity authentication, and returns authentication passed information to the blockchain node after the identity authentication is passed, where the authentication passed information is used to indicate that the genesis block has based on the identity identification data Add the first blockchain node to the corresponding alliance chain organization.
  • Blockchain node A sends a join request to join the alliance chain to the alliance chain system. After the alliance chain system genesis block receives the join request, it acquires the identity identification data of the blockchain node A and records it with the alliance chain genesis block. The authentication rules are correct.
  • the identity identification data of the blockchain node A may be a digital certificate issued by a CA structure representing the membership of the alliance chain organization, and the node identification data may be placed in a digital certificate DN project or a custom digital certificate Extensions.
  • the identity identification data is extended item information in the digital certificate of the blockchain node.
  • the extended item information includes:
  • the name of the alliance chain indicates the alliance chain network to which the blockchain node belongs
  • the identity of the alliance chain organization indicates the alliance chain organization to which the blockchain node belongs
  • the name of the blockchain node indicates that the blockchain node is in the organization
  • the type of blockchain node indicates the type of transaction that the blockchain node can handle. For example, blockchain node A can perform payment transactions and blockchain node B can perform payment transactions.
  • other digital certificate extensions can also be added, as long as the information that can be used to explain the identity of the blockchain node can be used as an extension.
  • a legal CA organization cannot create a legal root CA without restriction, but there is no requirement for extension item information. Therefore, the identity identification data of the blockchain node is placed in the digital certificate extension. When an organization has multiple root CAs, only one digital certificate is required for the nodes in the organization.
  • This digital certificate extension can be Including the information of all root CAs to which this node belongs, which is beneficial to the management of blockchain nodes.
  • the genesis block performs identity authentication on the first blockchain node according to the identity identification data, including:
  • the name of the alliance chain in the identity identification data is the same as the name of the alliance chain corresponding to the genesis block, it is determined whether the identity identification data exists in the preset organization member list stored in the genesis block The logo of the China Alliance Chain Organization.
  • the genesis block performs identity authentication on the first blockchain node, which is the first identity authentication based on the alliance chain. Only after being authenticated by the genesis block can the first blockchain node be added to the alliance chain to which the genesis block belongs, and only if the first blockchain node is added to the alliance chain can it be linked to each block in the alliance chain Chain nodes perform data interaction.
  • Step S102 If the authentication passing information returned by the genesis block is received, monitor whether a communication request of the second blockchain node is received.
  • the first blockchain node After the genesis block passes the identity authentication of the first blockchain node, the first blockchain node can join the alliance chain to which the genesis block belongs, and then the first blockchain node can contact the alliance The other nodes in the chain, the second blockchain nodes, perform data interaction. However, before performing data interaction, the first blockchain node needs to perform identity authentication on the second blockchain node, that is, second identity authentication.
  • Step S103 If a communication request of the second blockchain node is received, acquire the identification data of the second blockchain node from the communication request, and according to the second blockchain node ID identification data of the second blockchain node for identity authentication.
  • the identity authentication of the second blockchain node according to the identity identification data of the second blockchain node includes:
  • S1031 Verify whether the name of the alliance chain in the extension item information of the second blockchain node is the same as the name of the alliance chain in the extension item information of the first blockchain node.
  • This step is used to verify whether the first blockchain node and the second blockchain node belong to the same alliance chain.
  • the verifying whether the name of the alliance chain in the extension item information of the second blockchain node is the same as the name of the alliance chain in the extension item information of the first blockchain node includes:
  • each character of the first character string is the same as the corresponding character in the second character string, it is determined that the name of the alliance chain and the first The name of the alliance chain in the expansion item information of a blockchain node is the same.
  • This step is used to verify whether the first blockchain node and the second blockchain node belong to the same alliance chain organization.
  • This step is used to verify whether the request behavior currently initiated by the second blockchain node is consistent with its own node behavior. For example, assuming that the node type of blockchain node B is a payment transaction, but blockchain node B initiates a payment transaction to blockchain node A, then the behavior of blockchain node B does not match its node type, it is not allowed transaction.
  • the judging whether the behavior of the node corresponding to the communication request conforms to the second blockchain node includes:
  • the request code exists in the behavior list, it is determined that the node behavior corresponding to the communication request conforms to the node behavior corresponding to the type of the blockchain node in the extension information of the second blockchain node.
  • the request information corresponding to the payment transaction is 002
  • the behavior list of the blockchain node B is only 001, indicating that the blockchain node B is not allowed to initiate payment transactions .
  • Step S104 If the identity authentication of the second blockchain node is passed, return the data corresponding to the communication request to the second blockchain node.
  • the embodiment of the present application submits identity identification data to the genesis block in the alliance chain through the first blockchain node and requests to join the alliance chain, so as to realize the authentication of the genesis block on the first blockchain node; After the block authentication is passed, the communication request of the second blockchain node in the alliance chain is monitored, and the identity authentication of the second blockchain node is performed according to the identity identification data of the second blockchain node to realize the first blockchain node Authentication of the second blockchain node; after the authentication is passed, the data is returned to the second blockchain node.
  • the data interaction between the first blockchain node and the second blockchain node can be realized after double authentication, which effectively improves the reliability of the identity authentication method based on the alliance chain.
  • FIG. 2 is a schematic diagram of an identity authentication device based on a federation chain provided by an embodiment of the present application. For ease of description, only parts related to the embodiment of the present application are shown.
  • the identity authentication device based on the alliance chain shown in FIG. 2 may be software built into an existing terminal device
  • the unit, the hardware unit, or the unit combining hardware and software may also be integrated into the terminal device as an independent pendant, or may exist as an independent terminal device.
  • the identity authentication device 2 based on the alliance chain includes:
  • the submitting unit 21 is configured to submit the identity identification data of the first blockchain node and a join request to the genesis block in the alliance chain, where the join request is used to instruct the genesis block according to the identity
  • the identification data performs identity authentication on the first blockchain node, and returns authentication passing information to the blockchain node after the identity authentication is passed, where the authentication passing information is used to indicate that the genesis block has
  • the identification data adds the first blockchain node to the corresponding alliance chain organization.
  • the monitoring unit 22 is configured to, if receiving the authentication passing information returned by the genesis block, monitor whether a communication request of the second blockchain node is received.
  • the authentication unit 23 is configured to obtain the identification data of the second blockchain node from the communication request if a communication request of the second blockchain node is received, and according to the second area
  • the identity identification data of the blockchain node authenticates the identity of the second blockchain node.
  • the return unit 24 is configured to return data corresponding to the communication request to the second blockchain node if the identity authentication of the second blockchain node is passed.
  • the identity identification data is extended item information in the digital certificate of the blockchain node.
  • the extended item information includes:
  • the authentication unit 23 includes:
  • the first verification module is configured to verify whether the name of the alliance chain in the extension item information of the second blockchain node is the same as the name of the alliance chain in the extension item information of the first blockchain node.
  • a second verification module configured to verify if the name of the alliance chain in the extension item information of the second blockchain node is the same as the name of the alliance chain in the extension item information of the first blockchain node Whether the identifier of the alliance chain organization in the extended item information of the second blockchain node exists in the preset organization member list stored in the genesis block.
  • a third verification module configured to determine the communication if the identity of the alliance chain organization in the extension item information of the second blockchain node exists in the preset organization member list stored in the genesis block Whether the corresponding node behavior of the request corresponds to the type of the blockchain node in the extension information of the second blockchain node Node behavior.
  • the first passing module is configured to: if the node behavior corresponding to the communication request matches the node behavior corresponding to the type of blockchain node in the extension item information of the second blockchain node, The identity authentication of the blockchain node is passed.
  • the first verification module includes:
  • a conversion submodule configured to convert the name of the alliance chain in the extension item information of the first blockchain node into a first character string, and convert the alliance item information in the extension item information of the second blockchain node The name of the chain is converted to the second string.
  • a comparison submodule configured to compare each character in the first character string with the corresponding character in the second character string, respectively.
  • a first determination submodule configured to determine the extension item information of the second blockchain node if each character of the first character string is the same as the corresponding character in the second character string
  • the name of the alliance chain is the same as the name of the alliance chain in the expansion item information of the first blockchain node.
  • the third verification submodule includes:
  • an acquisition submodule configured to acquire a behavior list corresponding to the type of the blockchain node in the extension item information of the second blockchain node, and acquire the request code included in the communication request.
  • a search submodule configured to search whether the request code exists in the behavior list.
  • a second determination submodule configured to determine that the behavior of the node corresponding to the communication request conforms to the blockchain in the extension item information of the second blockchain node if the request code exists in the behavior list The node behavior corresponding to the type of node.
  • the submission unit 21 includes:
  • the first judgment module is used to judge whether the name of the alliance chain in the identity identification data is the same as the name of the alliance chain corresponding to the genesis block.
  • a second judgment module for judging the list of preset organization members stored in the genesis block if the name of the alliance chain in the identity identification data is the same as the name of the alliance chain corresponding to the genesis block Whether the ID of the alliance chain organization in the ID data exists in.
  • a second passing module is used to authenticate the identity of the first blockchain node if the identity of the alliance chain organization in the identity identification data exists in the preset organization member list stored in the genesis block by.
  • the above integrated unit may use hardware It can also be implemented in the form of software functional units.
  • the specific names of the functional units and modules are only for the purpose of distinguishing each other, and are not used to limit the protection scope of the present application.
  • FIG. 3 is a schematic diagram of a terminal device provided by an embodiment of the present application.
  • the terminal device 3 of this embodiment includes: a processor 30, a memory 31, and computer-readable instructions 32 stored in the memory 31 and executable on the processor 30.
  • the processor 30 executes the computer-readable instruction 32
  • the steps in the above embodiments of the alliance chain-based identity authentication method are implemented, for example, steps S101 to S104 shown in FIG. 1.
  • the processor 30 executes the computer-readable instructions 32
  • the functions of the modules/units in the foregoing device embodiments are realized, for example, the functions of the modules 21 to 24 shown in FIG. 2.
  • the computer-readable instructions 32 may be divided into one or more modules/units, the one or more modules/units are stored in the memory 31, and are processed by the processor 30 execute to complete this application.
  • the one or more modules/units may be an instruction segment of a series of computer-readable instructions capable of performing specific functions, and the instruction segment is used to describe the execution process of the 32 in the terminal device 3.
  • the computer-readable instruction 32 may be divided into a submission unit, a monitoring unit, an authentication unit, and a return unit. The specific functions of each unit are as follows:
  • the submission unit is used to submit the identity identification data of the first blockchain node and a join request to the genesis block in the alliance chain, where the join request is used to instruct the genesis block according to the identity
  • the data authenticates the identity of the first blockchain node, and returns the authentication passed information to the blockchain node after the identity authentication is passed, where the authentication passed information is used to indicate that the genesis block has based on the identity
  • the identification data adds the first blockchain node to the corresponding alliance chain organization.
  • a monitoring unit configured to monitor whether the received authentication information returned by the genesis block is received The communication request of the second blockchain node.
  • the authentication unit is configured to, if a communication request of the second blockchain node is received, acquire the identification data of the second blockchain node from the communication request, and according to the second block The identity identification data of the chain node authenticates the identity of the second blockchain node.
  • a returning unit configured to return data corresponding to the communication request to the second blockchain node if the identity authentication of the second blockchain node is passed.
  • the identity identification data is extended item information in the digital certificate of the blockchain node.
  • the extended item information includes:
  • the authentication unit includes:
  • the first verification module is used to verify whether the name of the alliance chain in the extension item information of the second blockchain node is the same as the name of the alliance chain in the extension item information of the first blockchain node.
  • a second verification module configured to verify if the name of the alliance chain in the extension item information of the second blockchain node is the same as the name of the alliance chain in the extension item information of the first blockchain node Whether the identifier of the alliance chain organization in the expansion item information of the second blockchain node exists in the list of preset organization members stored in the genesis block.
  • a third verification module configured to determine the communication if the identity of the alliance chain organization in the extension item information of the second blockchain node exists in the preset organization member list stored in the genesis block Whether the corresponding node behavior of the request conforms to the node behavior corresponding to the type of the blockchain node in the extension item information of the second blockchain node.
  • a first passing module configured to: if the node behavior corresponding to the communication request matches the node behavior corresponding to the type of blockchain node in the extension item information of the second blockchain node, The identity authentication of the blockchain node is passed.
  • the first verification module includes:
  • a conversion submodule configured to convert the name of the alliance chain in the extension item information of the first blockchain node into a first character string, and convert the alliance item information in the extension item information of the second blockchain node The name of the chain is converted to the second string.
  • a comparison sub-module for respectively comparing each character in the first character string with the second character string The characters should be compared.
  • a first determination submodule configured to determine the extension item information of the second blockchain node if each character of the first character string is the same as the corresponding character in the second character string
  • the name of the alliance chain is the same as the name of the alliance chain in the expansion item information of the first blockchain node.
  • the third verification submodule includes:
  • an acquisition submodule configured to acquire a behavior list corresponding to the type of the blockchain node in the extension item information of the second blockchain node, and acquire the request code included in the communication request.
  • a search submodule configured to search whether the request code exists in the behavior list.
  • a second determination sub-module for determining that the behavior of the node corresponding to the communication request complies with the blockchain in the extension item information of the second blockchain node if the request code exists in the behavior list The node behavior corresponding to the type of node.
  • the submission unit includes:
  • the first judgment module is used to judge whether the name of the alliance chain in the identity identification data is the same as the name of the alliance chain corresponding to the genesis block.
  • a second judgment module for judging the list of preset organization members stored in the genesis block if the name of the alliance chain in the identity identification data is the same as the name of the alliance chain corresponding to the genesis block Whether the ID of the alliance chain organization in the ID data exists in.
  • a second pass module for identifying the identity of the first blockchain node if the identity of the alliance chain organization in the identity identification data exists in the preset organization member list stored in the genesis block by.
  • the terminal device 3 may be a computing device such as a desktop computer, a notebook, a palmtop computer and a cloud server.
  • the terminal device may include, but is not limited to, the processor 30 and the memory 31.
  • FIG. 3 is only an example of the terminal device 3, and does not constitute a limitation on the terminal device 3, and may include more or less components than the illustration, or a combination of certain components, or different components.
  • the terminal device may further include an input and output device, a network access device, a bus, and so on.
  • the processor 30 may be a central processing unit (Central Processing Unit, CPU), or may be other general-purpose processors, digital signal processors (Digital Signal Processor, DSP), and application specific integrated circuits (Application Specific Integrated Circuit, ASIC), ready-made programmable gate array
  • CPU Central Processing Unit
  • DSP Digital Signal Processor
  • ASIC Application Specific Integrated Circuit
  • the general-purpose processor may be a microprocessor or the processor may be any conventional processor or the like.
  • the memory 31 may be an internal storage unit of the terminal device 3, such as a hard disk or a memory of the terminal device 3.
  • the memory 31 may also be an external storage device of the terminal device 3, for example, a plug-in hard disk equipped on the terminal device 3, a smart memory card (Smart Media Card,
  • the memory 31 may also include both an internal storage unit of the terminal device 3 and an external storage device.
  • the memory 31 is used to store the computer-readable instructions and other programs and data required by the terminal device.
  • the memory 31 can also be used to temporarily store data that has been or will be output.
  • the disclosed device/terminal device and method may be implemented in other ways.
  • the device/terminal device embodiments described above are only schematic.
  • the division of the module or unit is only a logical function division, and in actual implementation, there may be another division manner, such as multiple units Or components can be combined or integrated into another system, or some features can be ignored, or not implemented.
  • the displayed or discussed mutual coupling or direct coupling or communication connection may be indirect coupling or communication connection through some interfaces, devices or units, and may be in electrical, mechanical or other forms.
  • each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist alone physically, or two or more units may be integrated into one unit.
  • the above integrated unit may be implemented in the form of hardware, or in the form of a software functional unit.
  • the integrated module/unit is implemented in the form of a software functional unit and sold or used as an independent product, it may be stored in a computer-readable storage medium.
  • the present application implements all or part of the processes in the methods of the foregoing embodiments, and can also be completed by instructing relevant hardware through computer-readable instructions, which can be stored in a computer-readable storage medium
  • the computer readable instructions include computer readable instruction codes
  • the computer readable instruction codes may be in source code form, object code form, executable file or some intermediate form, etc.
  • the computer-readable medium may include: any entity or device capable of carrying the computer-readable instruction code, a recording medium, a USB flash drive, a mobile hard disk, a magnetic disk, an optical disc, a computer memory, a read-only memory (R OM, Read- Only Memory), Random Access Memory (RAM, Random Access Memory), electrical carrier signals, telecommunication signals, and software distribution media.
  • R OM Read- Only Memory
  • RAM Random Access Memory
  • electrical carrier signals telecommunication signals
  • software distribution media software distribution media.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Telephonic Communication Services (AREA)

Abstract

本申请适用于区块链技术领域,提供了一种基于联盟链的身份认证方法及终端设备,包括:向联盟链中的创世块提交所述第一区块链节点的身份标识数据和加入请求;若接收到所述创世块返回的认证通过信息,则监测是否接收到第二区块链节点的通信请求;如果接收到第二区块链节点的通信请求,则从所述通信请求中获取所述第二区块链节点的身份标识数据,并根据所述第二区块链节点的身份标识数据对所述第二区块链节点进行身份认证;若对所述第二区块链节点的身份认证通过,则将与所述通信请求对应的数据返回给所述第二区块链节点。通过上述方法,有效提高了基于联盟链的身份认证方法的可靠性。

Description

一种基于联盟链的身份认证方法及终端设备
[0001] 本申请要求于 2018年 12月 14日提交中国专利局、 申请号为 201811529919.4、 发 明名称为“一种基于联盟链的身份认证方法及终端设备”的中国专利申请的优先权 , 其全部内容通过引用结合在本申请中。
技术领域
[0002] 本申请涉及区块链技术领域, 尤其涉及一种基于联盟链的身份认证方法及终端 设备。
背景技术
[0003] 在联盟链中, 通常使用数字证书来进行可信身份认证 (数字证书是由电子认证 机构 (CA, Certificate Authority) 颁发的) 。 为了区分联盟链中多个参与组织, 以及每个组织中参与的多个联盟链节点, 通常采用的方案是为每个组织建设一 个单独的根 CA来代表联盟链中的一个组织, 并由这个根 CA为该组织中的每个节 点签发数字证书以证明节点在组织的身份。 联盟链在认证节点身份的时候, 通 过验证节点的数字证书的有效签发根 CA来判断该节点属于哪个组织。
[0004] 一个组织可能参加多个不同的联盟链, 即一个组织可能有多个根 CA, 那么该 组织内的每个节点都会有不同的根 CA签发的数字证书, 即每个节点对应多个数 字证书, 这将导致在对组织内的节点进行身份认证时出现较高的错误率, 进而 导致身份认证的可靠性较低。
发明概述
技术问题
[0005] 本申请实施例的目的之一在于: 提供了一种基于联盟链的身份认证方法及终端 设备, 以解决现有的基于联盟链的身份认证方法可靠性较低的问题。
问题的解决方案
技术解决方案
[0006] 为解决上述技术问题, 本申请实施例采用的技术方案是:
[0007] 本申请实施例的第一方面, 提供了一种基于联盟链的身份认证方法, 可以包括 [0008] 向联盟链中的创世块提交所述第一区块链节点的身份标识数据和加入请求, 所 述加入请求用于指示所述创世块根据所述身份标识数据对所述第一区块链节点 进行身份认证, 并在身份认证通过后向所述区块链节点返回认证通过信息, 所 述认证通过信息用于表示所述创世块已经根据所述身份标识数据将所述第一区 块链节点加入到相应的联盟链组织中;
[0009] 若接收到所述创世块返回的认证通过信息, 则监测是否接收到第二区块链节点 的通信请求;
[0010] 如果接收到第二区块链节点的通信请求, 则从所述通信请求中获取所述第二区 块链节点的身份标识数据, 并根据所述第二区块链节点的身份标识数据对所述 第二区块链节点进行身份认证;
[0011] 若对所述第二区块链节点的身份认证通过, 则将与所述通信请求对应的数据返 回给所述第二区块链节点。
[0012] 本申请实施例的第二方面, 提供链一种基于联盟链的身份认证装置, 所述装置 包括:
[0013] 提交单元, 用于向联盟链中的创世块提交所述第一区块链节点的身份标识数据 和加入请求, 所述加入请求用于指示所述创世块根据所述身份标识数据对所述 第一区块链节点进行身份认证, 并在身份认证通过后向所述区块链节点返回认 证通过信息, 所述认证通过信息用于表示所述创世块已经根据所述身份标识数 据将所述第一区块链节点加入到相应的联盟链组织中;
[0014] 监测单元, 用于若接收到所述创世块返回的认证通过信息, 则监测是否接收到 第二区块链节点的通信请求;
[0015] 认证单元, 用于如果接收到第二区块链节点的通信请求, 则从所述通信请求中 获取所述第二区块链节点的身份标识数据, 并根据所述第二区块链节点的身份 标识数据对所述第二区块链节点进行身份认证;
[0016] 返回单元, 用于若对所述第二区块链节点的身份认证通过, 则将与所述通信请 求对应的数据返回给所述第二区块链节点。
[0017] 本申请实施例的第三方面, 提供了一种计算机可读存储介质, 所述计算机可读 存储介质存储有计算机可读指令, 所述计算机可读指令被处理器执行时实现如 下步骤:
[0018] 向联盟链中的创世块提交所述第一区块链节点的身份标识数据和加入请求, 所 述加入请求用于指示所述创世块根据所述身份标识数据对所述第一区块链节点 进行身份认证, 并在身份认证通过后向所述区块链节点返回认证通过信息, 所 述认证通过信息用于表示所述创世块已经根据所述身份标识数据将所述第一区 块链节点加入到相应的联盟链组织中;
[0019] 若接收到所述创世块返回的认证通过信息, 则监测是否接收到第二区块链节点 的通信请求;
[0020] 如果接收到第二区块链节点的通信请求, 则从所述通信请求中获取所述第二区 块链节点的身份标识数据, 并根据所述第二区块链节点的身份标识数据对所述 第二区块链节点进行身份认证;
[0021] 若对所述第二区块链节点的身份认证通过, 则将与所述通信请求对应的数据返 回给所述第二区块链节点。
[0022] 本申请实施例的第四方面, 提供了一种终端设备, 包括存储器、 处理器以及存 储在所述存储器中并可在所述处理器上运行的计算机可读指令, 所述处理器执 行所述计算机可读指令时实现如下步骤:
[0023] 向联盟链中的创世块提交所述第一区块链节点的身份标识数据和加入请求, 所 述加入请求用于指示所述创世块根据所述身份标识数据对所述第一区块链节点 进行身份认证, 并在身份认证通过后向所述区块链节点返回认证通过信息, 所 述认证通过信息用于表示所述创世块已经根据所述身份标识数据将所述第一区 块链节点加入到相应的联盟链组织中;
[0024] 若接收到所述创世块返回的认证通过信息, 则监测是否接收到第二区块链节点 的通信请求;
[0025] 如果接收到第二区块链节点的通信请求, 则从所述通信请求中获取所述第二区 块链节点的身份标识数据, 并根据所述第二区块链节点的身份标识数据对所述 第二区块链节点进行身份认证;
[0026] 若对所述第二区块链节点的身份认证通过, 则将与所述通信请求对应的数据返 回给所述第二区块链节点。
发明的有益效果
对附图的简要说明
附图说明
[0027] 为了更清楚地说明本申请实施例中的技术方案, 下面将对实施例或示范性技术 描述中所需要使用的附图作简单地介绍, 显而易见地, 下面描述中的附图仅仅 是本申请的一些实施例, 对于本领域普通技术人员来讲, 在不付出创造性劳动 的前提下, 还可以根据这些附图获得其它的附图。
[0028] 图 1是本申请实施例提供的基于联盟链的身份认证方法的实现流程示意图;
[0029] 图 2是本申请实施例提供的基于联盟链的身份认证装置的示意图;
[0030] 图 3是本申请实施例提供的终端设备的示意图。
发明实施例
本发明的实施方式
[0031] 以下描述中, 为了说明而不是为了限定, 提出了诸如特定系统结构、 技术之类 的具体细节, 以便透彻理解本申请实施例。 然而, 本领域的技术人员应当清楚 , 在没有这些具体细节的其它实施例中也可以实现本申请。 在其它情况中, 省 略对众所周知的系统、 装置、 电路以及方法的详细说明, 以免不必要的细节妨 碍本申请的描述。
[0032] 应当理解, 当在本说明书和所附权利要求书中使用时, 术语“包括”指示所描述 特征、 整体、 步骤、 操作、 元素和 /或组件的存在, 但并不排除一个或多个其它 特征、 整体、 步骤、 操作、 元素、 组件和 /或其集合的存在或添加。
[0033] 还应当理解, 在此本申请说明书中所使用的术语仅仅是出于描述特定实施例的 目的而并不意在限制本申请。 如在本申请说明书和所附权利要求书中所使用的 那样, 除非上下文清楚地指明其它情况, 否则单数形式的“一”、 “一个”及“该”意 在包括复数形式。
[0034] 还应当进一步理解, 在本申请说明书和所附权利要求书中使用的术语“和 /或”是 指相关联列出的项中的一个或多个的任何组合以及所有可能组合, 并且包括这 些组合。
[0035] 如在本说明书和所附权利要求书中所使用的那样, 术语“如果”可以依据上下文 被解释为“当 ...时”或“一旦”或“响应于确定”或“响应于检测到”。 类似地, 短语“如 果确定”或“如果检测到[所描述条件或事件]”可以依据上下文被解释为意指“一旦 确定”或“响应于确定”或“一旦检测到[所描述条件或事件]”或“响应于检测到[所描 述条件或事件]”。
[0036] 为了说明本申请所述的技术方案, 下面通过具体实施例来进行说明。
[0037] 图 1是本申请实施例提供的基于联盟链的身份认证方法的实现流程示意图, 如 图所示, 所述方法可以包括以下步骤:
[0038] 步骤 S101, 向联盟链中的创世块提交所述第一区块链节点的身份标识数据和加 入请求, 所述加入请求用于指示所述创世块根据所述身份标识数据对所述第一 区块链节点进行身份认证, 并在身份认证通过后向所述区块链节点返回认证通 过信息, 所述认证通过信息用于表示所述创世块已经根据所述身份标识数据将 所述第一区块链节点加入到相应的联盟链组织中。
[0039] 在实际应用中, 某个区块链节点 A想要加入一个联盟链 B, 首先需要通过该联 盟链 B的创世块中记录的身份认证规则。 区块链节点 A向联盟链系统发送加入联 盟链的加入请求, 联盟链系统创世块接收到加入请求后, 获取区块链节点 A的身 份标识数据, 并与联盟链创世块中记录的身份认证规则相比对。
[0040] 这里, 区块链节点 A的身份标识数据可以是由代表联盟链组织成员身份的 CA 构签发的数字证书, 节点的身份标识数据可以放置于数字证书 DN项目中或自定 义的数字证书扩展项中。
[0041] 其中, 所述身份标识数据为区块链节点的数字证书中的扩展项信息。
[0042] 所述扩展项信息包括:
[0043] 联盟链的名称、 联盟链组织的标识、 区块链节点的名称和区块链节点的类型。
[0044] 联盟链的名称即表示区块链节点所属的联盟链网络, 联盟链组织的标识即表示 区块链节点所属的联盟链组织, 区块链节点名称即表示区块链节点在该组织内 的唯一标识名称, 区块链节点的类型表示区块链节点能够处理的事务类型, 例 如, 区块链节点 A可以执行付款交易, 区块链节点 B可以执行收款交易。 [0045] 当然, 还可以增加其他的数字证书的扩展项, 只要能够用于说明区块链节点的 身份的信息都可以作为扩展项。 一个合法的 CA机构不能无限制地创建合法的根 CA, 但是对于扩展项信息却没有要求。 所以, 将区块链节点的身份标识数据放 置于数字证书扩展项中, 当一个组织有多个根 CA时, 组织内的节点的只需一张 数字证书, 这张数字证书的扩展项中可以包括该节点所属的所有根 CA的信息, 这样有利于区块链节点的管理。
[0046] 在一个实施例中, 所述创世块根据该身份标识数据对所述第一区块链节点进行 身份认证, 包括:
[0047] 判断该身份标识数据中联盟链的名称是否与所述创世块对应的联盟链的名称相 同。
[0048] 若所述身份标识数据中联盟链的名称与所述创世块对应的联盟链的名称相同, 则判断所述创世块中存储的预设组织成员列表中是否存在该身份标识数据中联 盟链组织的标识。
[0049] 若所述创世块中存储的预设组织成员列表中存在该身份标识数据中联盟链组织 的标识, 则对所述第一区块链节点的身份认证通过。
[0050] 创世块对第一区块链节点进行身份认证, 是基于联盟链的第一重身份认证。 只 有经过了创世块的认证, 第一区块链节点才能够加入到创世块所属的联盟链中 , 第一区块链节点只有加入到了联盟链中, 才能与该联盟链中的各区块链节点 进行数据交互。
[0051] 步骤 S102, 若接收到所述创世块返回的认证通过信息, 则监测是否接收到第二 区块链节点的通信请求。
[0052] 在创世块通过了对第一区块链节点的身份认证后, 第一区块链节点可以加入到 创世块所属的联盟链中, 进而第一区块链节点可以与该联盟链中的其他节点即 第二区块链节点进行数据交互。 但是, 在进行数据交互之前, 第一区块链节点 需要对第二区块链节点进行身份认证, 即第二重身份认证。 如下述步骤。
[0053] 步骤 S103 , 如果接收到第二区块链节点的通信请求, 则从所述通信请求中获取 所述第二区块链节点的身份标识数据, 并根据所述第二区块链节点的身份标识 数据对所述第二区块链节点进行身份认证。 [0054] 在一个实施例中, 所述根据所述第二区块链节点的身份标识数据对所述第二区 块链节点进行身份认证, 包括:
[0055] S1031, 验证所述第二区块链节点的扩展项信息中联盟链的名称是否与所述第 一区块链节点的扩展项信息中联盟链的名称相同。
[0056] 这一步骤用于验证第一区块链节点与第二区块链节点是否属于相同的联盟链。
[0057] 可选的, 所述验证所述第二区块链节点的扩展项信息中联盟链的名称是否与所 述第一区块链节点的扩展项信息中联盟链的名称相同, 包括:
[0058] 将所述第一区块链节点的扩展项信息中联盟链的名称转换为第一字符串, 并将 所述第二区块链节点的扩展项信息中联盟链的名称转换为第二字符串。
[0059] 分别将所述第一字符串中的每个字符与所述第二字符串中对应的字符进行比对
[0060] 若所述第一字符串的每个字符与所述第二字符串中对应的字符相同, 则判定所 述第二区块链节点的扩展项信息中联盟链的名称与所述第一区块链节点的扩展 项信息中联盟链的名称相同。
[0061] S1032, 若所述第二区块链节点的扩展项信息中联盟链的名称与所述第一区块 链节点的扩展项信息中联盟链的名称相同, 则验证所述创世块中存储的预设组 织成员列表中是否存在所述第二区块链节点的扩展项信息中联盟链组织的标识
[0062] 这一步骤用于验证第一区块链节点和第二区块链节点是否属于相同的联盟链组 织。
[0063] S1033 , 若所述创世块中存储的预设组织成员列表中存在所述第二区块链节点 的扩展项信息中联盟链组织的标识, 则判断所述通信请求对应的节点行为是否 符合所述第二区块链节点的扩展项信息中区块链节点的类型对应的节点行为。
[0064] 这一步骤用于验证第二区块链节点当前发起的请求行为是否符合其自身的节点 行为。 例如, 假设区块链节点 B的节点类型为收款交易, 但是区块链节点 B向区 块链节点 A发起的是支付交易, 那么区块链节点 B的行为与其节点类型不符, 则 不允许交易。
[0065] 可选的, 所述判断所述通信请求对应的节点行为是否符合所述第二区块链节点 的扩展项信息中区块链节点的类型对应的节点行为, 包括:
[0066] 获取所述第二区块链节点的扩展项信息中区块链节点的类型对应的行为列表, 并获取所述通信请求中包含的请求码。
[0067] 查找所述行为列表中是否存在所述请求码。
[0068] 若所述行为列表中存在所述请求码, 则判定所述通信请求对应的节点行为符合 所述第二区块链节点的扩展项信息中区块链节点的类型对应的节点行为。
[0069] 示例性的, 假设区块链节点 B发起支付交易, 支付交易对应的请求信息为 002, 而区块链节点 B的行为列表中只有 001, 说明区块链节点 B不允许发起支付交易。
[0070] S1034, 若所述通信请求对应的节点行为符合所述第二区块链节点的扩展项信 息中区块链节点的类型对应的节点行为, 则对所述第二区块链节点的身份认证 通过。
[0071] 到这一步, 完成了第一区块链节点对第二区块链节点的身份认证, 即完成了第 二重认证。
[0072] 步骤 S104, 若对所述第二区块链节点的身份认证通过, 则将与所述通信请求对 应的数据返回给所述第二区块链节点。
[0073] 本申请实施例通过第一区块链节点向联盟链中的创世块提交身份标识数据并请 求加入联盟链, 以实现创世块对第一区块链节点的认证; 在创世块认证通过后 , 监测联盟链中第二区块链节点的通信请求, 并根据第二区块链节点的身份标 识数据对第二区块链节点进行身份认证, 以实现第一区块链节点对第二区块链 节点的认证; 认证通过后向第二区块链节点返回数据。 通过上述方法, 经过双 重认证才能实现第一区块链节点与第二区块链节点之间的数据交互, 有效提高 了基于联盟链的身份认证方法的可靠性。
[0074] 应理解, 上述实施例中各步骤的序号的大小并不意味着执行顺序的先后, 各过 程的执行顺序应以其功能和内在逻辑确定, 而不应对本申请实施例的实施过程 构成任何限定。
[0075] 图 2是本申请实施例提供的基于联盟链的身份认证装置的示意图, 为了便于说 明, 仅示出与本申请实施例相关的部分。
[0076] 图 2所示的基于联盟链的身份认证装置可以是内置于现有的终端设备内的软件 单元、 硬件单元、 或软硬结合的单元, 也可以作为独立的挂件集成到所述终端 设备中, 还可以作为独立的终端设备存在。
[0077] 所述基于联盟链的身份认证装置 2包括:
[0078] 提交单元 21, 用于向联盟链中的创世块提交所述第一区块链节点的身份标识数 据和加入请求, 所述加入请求用于指示所述创世块根据所述身份标识数据对所 述第一区块链节点进行身份认证, 并在身份认证通过后向所述区块链节点返回 认证通过信息, 所述认证通过信息用于表示所述创世块已经根据所述身份标识 数据将所述第一区块链节点加入到相应的联盟链组织中。
[0079] 监测单元 22, 用于若接收到所述创世块返回的认证通过信息, 则监测是否接收 到第二区块链节点的通信请求。
[0080] 认证单元 23 , 用于如果接收到第二区块链节点的通信请求, 则从所述通信请求 中获取所述第二区块链节点的身份标识数据, 并根据所述第二区块链节点的身 份标识数据对所述第二区块链节点进行身份认证。
[0081] 返回单元 24, 用于若对所述第二区块链节点的身份认证通过, 则将与所述通信 请求对应的数据返回给所述第二区块链节点。
[0082] 其中, 所述身份标识数据为区块链节点的数字证书中的扩展项信息。
[0083] 所述扩展项信息包括:
[0084] 联盟链的名称、 联盟链组织的标识、 区块链节点的名称和区块链节点的类型。
[0085] 可选的, 所述认证单元 23包括:
[0086] 第一验证模块, 用于验证所述第二区块链节点的扩展项信息中联盟链的名称是 否与所述第一区块链节点的扩展项信息中联盟链的名称相同。
[0087] 第二验证模块, 用于若所述第二区块链节点的扩展项信息中联盟链的名称与所 述第一区块链节点的扩展项信息中联盟链的名称相同, 则验证所述创世块中存 储的预设组织成员列表中是否存在所述第二区块链节点的扩展项信息中联盟链 组织的标识。
[0088] 第三验证模块, 用于若所述创世块中存储的预设组织成员列表中存在所述第二 区块链节点的扩展项信息中联盟链组织的标识, 则判断所述通信请求对应的节 点行为是否符合所述第二区块链节点的扩展项信息中区块链节点的类型对应的 节点行为。
[0089] 第一通过模块, 用于若所述通信请求对应的节点行为符合所述第二区块链节点 的扩展项信息中区块链节点的类型对应的节点行为, 则对所述第二区块链节点 的身份认证通过。
[0090] 可选的, 所述第一验证模块包括:
[0091] 转换子模块, 用于将所述第一区块链节点的扩展项信息中联盟链的名称转换为 第一字符串, 并将所述第二区块链节点的扩展项信息中联盟链的名称转换为第 二字符串。
[0092] 比对子模块, 用于分别将所述第一字符串中的每个字符与所述第二字符串中对 应的字符进行比对。
[0093] 第一判定子模块, 用于若所述第一字符串的每个字符与所述第二字符串中对应 的字符相同, 则判定所述第二区块链节点的扩展项信息中联盟链的名称与所述 第一区块链节点的扩展项信息中联盟链的名称相同。
[0094] 可选的, 所述第三验证子模块包括:
[0095] 获取子模块, 用于获取所述第二区块链节点的扩展项信息中区块链节点的类型 对应的行为列表, 并获取所述通信请求中包含的请求码。
[0096] 查找子模块, 用于查找所述行为列表中是否存在所述请求码。
[0097] 第二判定子模块, 用于若所述行为列表中存在所述请求码, 则判定所述通信请 求对应的节点行为符合所述第二区块链节点的扩展项信息中区块链节点的类型 对应的节点行为。
[0098] 可选的, 所述提交单元 21包括:
[0099] 第一判断模块, 用于判断该身份标识数据中联盟链的名称是否与所述创世块对 应的联盟链的名称相同。
[0100] 第二判断模块, 用于若所述身份标识数据中联盟链的名称与所述创世块对应的 联盟链的名称相同, 则判断所述创世块中存储的预设组织成员列表中是否存在 该身份标识数据中联盟链组织的标识。
[0101] 第二通过模块, 用于若所述创世块中存储的预设组织成员列表中存在该身份标 识数据中联盟链组织的标识, 则对所述第一区块链节点的身份认证通过。 [0102] 所属领域的技术人员可以清楚地了解到, 为了描述的方便和简洁, 仅以上述各 功能单元、 模块的划分进行举例说明, 实际应用中, 可以根据需要而将上述功 能分配由不同的功能单元、 模块完成, 即将所述装置的内部结构划分成不同的 功能单元或模块, 以完成以上描述的全部或者部分功能。 实施例中的各功能单 元、 模块可以集成在一个处理单元中, 也可以是各个单元单独物理存在, 也可 以两个或两个以上单元集成在一个单元中, 上述集成的单元既可以采用硬件的 形式实现, 也可以采用软件功能单元的形式实现。 另外, 各功能单元、 模块的 具体名称也只是为了便于相互区分, 并不用于限制本申请的保护范围。 上述系 统中单元、 模块的具体工作过程, 可以参考前述方法实施例中的对应过程, 在 此不再赘述。
[0103] 图 3是本申请实施例提供的终端设备的示意图。 如图 3所示, 该实施例的终端设 备 3包括: 处理器 30、 存储器 31以及存储在所述存储器 31中并可在所述处理器 30 上运行的计算机可读指令 32。 所述处理器 30执行所述计算机可读指令 32时实现 上述各个基于联盟链的身份认证方法实施例中的步骤, 例如图 1所示的步骤 S101 至 S104。 或者, 所述处理器 30执行所述计算机可读指令 32时实现上述各装置实 施例中各模块 /单元的功能, 例如图 2所示模块 21至 24的功能。
[0104] 示例性的, 所述计算机可读指令 32可以被分割成一个或多个模块 /单元, 所述 一个或者多个模块 /单元被存储在所述存储器 31中, 并由所述处理器 30执行, 以 完成本申请。 所述一个或多个模块 /单元可以是能够完成特定功能的一系列计算 机可读指令的指令段, 该指令段用于描述所述 32在所述终端设备 3中的执行过程 。 例如, 所述计算机可读指令 32可以被分割成提交单元、 监测单元、 认证单元 、 返回单元, 各单元具体功能如下:
[0105] 提交单元, 用于向联盟链中的创世块提交所述第一区块链节点的身份标识数据 和加入请求, 所述加入请求用于指示所述创世块根据所述身份标识数据对所述 第一区块链节点进行身份认证, 并在身份认证通过后向所述区块链节点返回认 证通过信息, 所述认证通过信息用于表示所述创世块已经根据所述身份标识数 据将所述第一区块链节点加入到相应的联盟链组织中。
[0106] 监测单元, 用于若接收到所述创世块返回的认证通过信息, 则监测是否接收到 第二区块链节点的通信请求。
[0107] 认证单元, 用于如果接收到第二区块链节点的通信请求, 则从所述通信请求中 获取所述第二区块链节点的身份标识数据, 并根据所述第二区块链节点的身份 标识数据对所述第二区块链节点进行身份认证。
[0108] 返回单元, 用于若对所述第二区块链节点的身份认证通过, 则将与所述通信请 求对应的数据返回给所述第二区块链节点。
[0109] 其中, 所述身份标识数据为区块链节点的数字证书中的扩展项信息。
[0110] 所述扩展项信息包括:
[0111] 联盟链的名称、 联盟链组织的标识、 区块链节点的名称和区块链节点的类型。
[0112] 可选的, 所述认证单元包括:
[0113] 第一验证模块, 用于验证所述第二区块链节点的扩展项信息中联盟链的名称是 否与所述第一区块链节点的扩展项信息中联盟链的名称相同。
[0114] 第二验证模块, 用于若所述第二区块链节点的扩展项信息中联盟链的名称与所 述第一区块链节点的扩展项信息中联盟链的名称相同, 则验证所述创世块中存 储的预设组织成员列表中是否存在所述第二区块链节点的扩展项信息中联盟链 组织的标识。
[0115] 第三验证模块, 用于若所述创世块中存储的预设组织成员列表中存在所述第二 区块链节点的扩展项信息中联盟链组织的标识, 则判断所述通信请求对应的节 点行为是否符合所述第二区块链节点的扩展项信息中区块链节点的类型对应的 节点行为。
[0116] 第一通过模块, 用于若所述通信请求对应的节点行为符合所述第二区块链节点 的扩展项信息中区块链节点的类型对应的节点行为, 则对所述第二区块链节点 的身份认证通过。
[0117] 可选的, 所述第一验证模块包括:
[0118] 转换子模块, 用于将所述第一区块链节点的扩展项信息中联盟链的名称转换为 第一字符串, 并将所述第二区块链节点的扩展项信息中联盟链的名称转换为第 二字符串。
[0119] 比对子模块, 用于分别将所述第一字符串中的每个字符与所述第二字符串中对 应的字符进行比对。
[0120] 第一判定子模块, 用于若所述第一字符串的每个字符与所述第二字符串中对应 的字符相同, 则判定所述第二区块链节点的扩展项信息中联盟链的名称与所述 第一区块链节点的扩展项信息中联盟链的名称相同。
[0121] 可选的, 所述第三验证子模块包括:
[0122] 获取子模块, 用于获取所述第二区块链节点的扩展项信息中区块链节点的类型 对应的行为列表, 并获取所述通信请求中包含的请求码。
[0123] 查找子模块, 用于查找所述行为列表中是否存在所述请求码。
[0124] 第二判定子模块, 用于若所述行为列表中存在所述请求码, 则判定所述通信请 求对应的节点行为符合所述第二区块链节点的扩展项信息中区块链节点的类型 对应的节点行为。
[0125] 可选的, 所述提交单元包括:
[0126] 第一判断模块, 用于判断该身份标识数据中联盟链的名称是否与所述创世块对 应的联盟链的名称相同。
[0127] 第二判断模块, 用于若所述身份标识数据中联盟链的名称与所述创世块对应的 联盟链的名称相同, 则判断所述创世块中存储的预设组织成员列表中是否存在 该身份标识数据中联盟链组织的标识。
[0128] 第二通过模块, 用于若所述创世块中存储的预设组织成员列表中存在该身份标 识数据中联盟链组织的标识, 则对所述第一区块链节点的身份认证通过。
[0129] 所述终端设备 3可以是桌上型计算机、 笔记本、 掌上电脑及云端服务器等计算 设备。 所述终端设备可包括, 但不仅限于, 处理器 30、 存储器 31。 本领域技术 人员可以理解, 图 3仅仅是终端设备 3的示例, 并不构成对终端设备 3的限定, 可 以包括比图示更多或更少的部件, 或者组合某些部件, 或者不同的部件, 例如 所述终端设备还可以包括输入输出设备、 网络接入设备、 总线等。
[0130] 所称处理器 30可以是中央处理单元 (Central Processing Unit, CPU) , 还可以是其 他通用处理器、 数字信号处理器 (Digital Signal Processor, DSP)、 专用集成电路 (Application Specific Integrated Circuit, ASIC)、 现成可编程门阵列
(Field-Programmable Gate Array, FPGA)或者其他可编程逻辑器件、 分立门或者 晶体管逻辑器件、 分立硬件组件等。 通用处理器可以是微处理器或者该处理器 也可以是任何常规的处理器等。
[0131] 所述存储器 31可以是所述终端设备 3的内部存储单元, 例如终端设备 3的硬盘或 内存。 所述存储器 31也可以是所述终端设备 3的外部存储设备, 例如所述终端设 备 3上配备的插接式硬盘, 智能存储卡 (Smart Media Card,
SMC) 安全数字 (Secure Digital, SD) 卡, 闪存卡 (Flash Card) 等。 进一步 地, 所述存储器 31还可以既包括所述终端设备 3的内部存储单元也包括外部存储 设备。 所述存储器 31用于存储所述计算机可读指令以及所述终端设备所需的其 他程序和数据。 所述存储器 31还可以用于暂时地存储已经输出或者将要输出的 数据。
[0132] 在上述实施例中, 对各个实施例的描述都各有侧重, 某个实施例中没有详述或 记载的部分, 可以参见其它实施例的相关描述。
[0133] 本领域普通技术人员可以意识到, 结合本文中所公开的实施例描述的各示例的 单元及算法步骤, 能够以电子硬件、 或者计算机软件和电子硬件的结合来实现 。 这些功能究竟以硬件还是软件方式来执行, 取决于技术方案的特定应用和设 计约束条件。 专业技术人员可以对每个特定的应用来使用不同方法来实现所描 述的功能, 但是这种实现不应认为超出本申请的范围。
[0134] 在本申请所提供的实施例中, 应该理解到, 所揭露的装置 /终端设备和方法, 可以通过其它的方式实现。 例如, 以上所描述的装置 /终端设备实施例仅仅是示 意性的, 例如, 所述模块或单元的划分, 仅仅为一种逻辑功能划分, 实际实现 时可以有另外的划分方式, 例如多个单元或组件可以结合或者可以集成到另一 个系统, 或一些特征可以忽略, 或不执行。 另一点, 所显示或讨论的相互之间 的耦合或直接耦合或通讯连接可以是通过一些接口, 装置或单元的间接耦合或 通讯连接, 可以是电性, 机械或其它的形式。
[0135] 所述作为分离部件说明的单元可以是或者也可以不是物理上分开的, 作为单元 显示的部件可以是或者也可以不是物理单元, 即可以位于一个地方, 或者也可 以分布到多个网络单元上。 可以根据实际的需要选择其中的部分或者全部单元 来实现本实施例方案的目的。 [0136] 另外, 在本申请各个实施例中的各功能单元可以集成在一个处理单元中, 也可 以是各个单元单独物理存在, 也可以两个或两个以上单元集成在一个单元中。 上述集成的单元既可以采用硬件的形式实现, 也可以采用软件功能单元的形式 实现。
[0137] 所述集成的模块 /单元如果以软件功能单元的形式实现并作为独立的产品销售 或使用时, 可以存储在一个计算机可读取存储介质中。 基于这样的理解, 本申 请实现上述实施例方法中的全部或部分流程, 也可以通过计算机可读指令来指 令相关的硬件来完成, 所述的计算机可读指令可存储于一计算机可读存储介质 中, 该计算机可读指令在被处理器执行时, 可实现上述各个方法实施例的步骤 。 其中, 所述计算机可读指令包括计算机可读指令代码, 所述计算机可读指令 代码可以为源代码形式、 对象代码形式、 可执行文件或某些中间形式等。 所述 计算机可读介质可以包括: 能够携带所述计算机可读指令代码的任何实体或装 置、 记录介质、 U盘、 移动硬盘、 磁碟、 光盘、 计算机存储器、 只读存储器 (R OM, Read-Only Memory) 、 随机存取存储器 (RAM, Random Access Memory ) 、 电载波信号、 电信信号以及软件分发介质等。 需要说明的是, 所述计算机 可读介质包含的内容可以根据司法管辖区内立法和专利实践的要求进行适当的 增减, 例如在某些司法管辖区, 根据立法和专利实践, 计算机可读介质不包括 是电载波信号和电信信号。
[0138] 以上所述实施例仅用以说明本申请的技术方案, 而非对其限制; 尽管参照前述 实施例对本申请进行了详细的说明, 本领域的普通技术人员应当理解: 其依然 可以对前述各实施例所记载的技术方案进行修改, 或者对其中部分技术特征进 行等同替换; 而这些修改或者替换, 并不使相应技术方案的本质脱离本申请各 实施例技术方案的精神和范围, 均应包含在本申请的保护范围之内。

Claims

权利要求书
[权利要求 i] 一种基于联盟链的身份认证方法, 其特征在于, 应用于第一区块链节 点, 所述方法包括:
向联盟链中的创世块提交所述第一区块链节点的身份标识数据和加入 请求, 所述加入请求用于指示所述创世块根据所述身份标识数据对所 述第一区块链节点进行身份认证, 并在身份认证通过后向所述区块链 节点返回认证通过信息, 所述认证通过信息用于表示所述创世块已经 根据所述身份标识数据将所述第一区块链节点加入到相应的联盟链组 织中;
若接收到所述创世块返回的认证通过信息, 则监测是否接收到第二区 块链节点的通信请求;
如果接收到第二区块链节点的通信请求, 则从所述通信请求中获取所 述第二区块链节点的身份标识数据, 并根据所述第二区块链节点的身 份标识数据对所述第二区块链节点进行身份认证; 若对所述第二区块链节点的身份认证通过, 则将与所述通信请求对应 的数据返回给所述第二区块链节点。
[权利要求 2] 如权利要求 1所述的基于联盟链的身份认证方法, 其特征在于, 所述 身份标识数据为区块链节点的数字证书中的扩展项信息;
所述扩展项信息包括:
联盟链的名称、 联盟链组织的标识、 区块链节点的名称和区块链节点 的类型。
[权利要求 3] 如权利要求 2所述的基于联盟链的身份认证方法, 其特征在于, 所述 根据所述第二区块链节点的身份标识数据对所述第二区块链节点进行 身份认证, 包括:
验证所述第二区块链节点的扩展项信息中联盟链的名称是否与所述第 一区块链节点的扩展项信息中联盟链的名称相同; 若所述第二区块链节点的扩展项信息中联盟链的名称与所述第一区块 链节点的扩展项信息中联盟链的名称相同, 则验证所述创世块中存储 的预设组织成员列表中是否存在所述第二区块链节点的扩展项信息中 联盟链组织的标识;
若所述创世块中存储的预设组织成员列表中存在所述第二区块链节点 的扩展项信息中联盟链组织的标识, 则判断所述通信请求对应的节点 行为是否符合所述第二区块链节点的扩展项信息中区块链节点的类型 对应的节点行为;
若所述通信请求对应的节点行为符合所述第二区块链节点的扩展项信 息中区块链节点的类型对应的节点行为, 则对所述第二区块链节点的 身份认证通过。
[权利要求 4] 如权利要求 3所述的基于联盟链的身份认证方法, 其特征在于, 所述 验证所述第二区块链节点的扩展项信息中联盟链的名称是否与所述第 一区块链节点的扩展项信息中联盟链的名称相同, 包括:
将所述第一区块链节点的扩展项信息中联盟链的名称转换为第一字符 串, 并将所述第二区块链节点的扩展项信息中联盟链的名称转换为第 二字符串;
分别将所述第一字符串中的每个字符与所述第二字符串中对应的字符 进行比对;
若所述第一字符串的每个字符与所述第二字符串中对应的字符相同, 则判定所述第二区块链节点的扩展项信息中联盟链的名称与所述第一 区块链节点的扩展项信息中联盟链的名称相同。
[权利要求 5] 如权利要求 3所述的基于联盟链的身份认证方法, 其特征在于, 所述 判断所述通信请求对应的节点行为是否符合所述第二区块链节点的扩 展项信息中区块链节点的类型对应的节点行为, 包括:
获取所述第二区块链节点的扩展项信息中区块链节点的类型对应的行 为列表, 并获取所述通信请求中包含的请求码; 查找所述行为列表中是否存在所述请求码;
若所述行为列表中存在所述请求码, 则判定所述通信请求对应的节点 行为符合所述第二区块链节点的扩展项信息中区块链节点的类型对应 的节点行为。
[权利要求 6] 如权利要求 2所述的基于联盟链的身份认证方法, 其特征在于, 所述 创世块根据该身份标识数据对所述第一区块链节点进行身份认证, 包 括:
判断该身份标识数据中联盟链的名称是否与所述创世块对应的联盟链 的名称相同;
若所述身份标识数据中联盟链的名称与所述创世块对应的联盟链的名 称相同, 则判断所述创世块中存储的预设组织成员列表中是否存在该 身份标识数据中联盟链组织的标识;
若所述创世块中存储的预设组织成员列表中存在该身份标识数据中联 盟链组织的标识, 则对所述第一区块链节点的身份认证通过。
[权利要求 7] —种基于联盟链的身份认证装置, 其特征在于, 所述装置包括: 提交单元, 用于向联盟链中的创世块提交所述第一区块链节点的身份 标识数据和加入请求, 所述加入请求用于指示所述创世块根据所述身 份标识数据对所述第一区块链节点进行身份认证, 并在身份认证通过 后向所述区块链节点返回认证通过信息, 所述认证通过信息用于表示 所述创世块已经根据所述身份标识数据将所述第一区块链节点加入到 相应的联盟链组织中;
监测单元, 用于若接收到所述创世块返回的认证通过信息, 则监测是 否接收到第二区块链节点的通信请求;
认证单元, 用于如果接收到第二区块链节点的通信请求, 则从所述通 信请求中获取所述第二区块链节点的身份标识数据, 并根据所述第二 区块链节点的身份标识数据对所述第二区块链节点进行身份认证; 返回单元, 用于若对所述第二区块链节点的身份认证通过, 则将与所 述通信请求对应的数据返回给所述第二区块链节点。
[权利要求 8] 如权利要求 7所述的基于联盟链的身份认证装置, 其特征在于, 所述 身份标识数据为区块链节点的数字证书中的扩展项信息;
所述扩展项信息包括: 联盟链的名称、 联盟链组织的标识、 区块链节点的名称和区块链节点 的类型。
[权利要求 9] 如权利要求 8所述的基于联盟链的身份认证装置, 其特征在于, 所述 认证单元包括:
第一验证模块, 用于验证所述第二区块链节点的扩展项信息中联盟链 的名称是否与所述第一区块链节点的扩展项信息中联盟链的名称相同 第二验证模块, 用于若所述第二区块链节点的扩展项信息中联盟链的 名称与所述第一区块链节点的扩展项信息中联盟链的名称相同, 则验 证所述创世块中存储的预设组织成员列表中是否存在所述第二区块链 节点的扩展项信息中联盟链组织的标识;
第三验证模块, 用于若所述创世块中存储的预设组织成员列表中存在 所述第二区块链节点的扩展项信息中联盟链组织的标识, 则判断所述 通信请求对应的节点行为是否符合所述第二区块链节点的扩展项信息 中区块链节点的类型对应的节点行为;
第一通过模块, 用于若所述通信请求对应的节点行为符合所述第二区 块链节点的扩展项信息中区块链节点的类型对应的节点行为, 则对所 述第二区块链节点的身份认证通过。
[权利要求 10] 如权利要求 9所述的基于联盟链的身份认证装置, 其特征在于, 所述 第一验证模块包括:
转换子模块, 用于将所述第一区块链节点的扩展项信息中联盟链的名 称转换为第一字符串, 并将所述第二区块链节点的扩展项信息中联盟 链的名称转换为第二字符串;
比对子模块, 用于分别将所述第一字符串中的每个字符与所述第二字 符串中对应的字符进行比对;
第一判定子模块, 用于若所述第一字符串的每个字符与所述第二字符 串中对应的字符相同, 则判定所述第二区块链节点的扩展项信息中联 盟链的名称与所述第一区块链节点的扩展项信息中联盟链的名称相同
[权利要求 11] 如权利要求 9所述的基于联盟链的身份认证装置, 其特征在于, 所述 第三验证子模块包括:
获取子模块, 用于获取所述第二区块链节点的扩展项信息中区块链节 点的类型对应的行为列表, 并获取所述通信请求中包含的请求码; 查找子模块, 用于查找所述行为列表中是否存在所述请求码; 第二判定子模块, 用于若所述行为列表中存在所述请求码, 则判定所 述通信请求对应的节点行为符合所述第二区块链节点的扩展项信息中 区块链节点的类型对应的节点行为。
[权利要求 12] 如权利要求 8所述的基于联盟链的身份认证装置, 其特征在于, 所述 提交单元包括:
第一判断模块, 用于判断该身份标识数据中联盟链的名称是否与所述 创世块对应的联盟链的名称相同;
第二判断模块, 用于若所述身份标识数据中联盟链的名称与所述创世 块对应的联盟链的名称相同, 则判断所述创世块中存储的预设组织成 员列表中是否存在该身份标识数据中联盟链组织的标识;
第二通过模块, 用于若所述创世块中存储的预设组织成员列表中存在 该身份标识数据中联盟链组织的标识, 则对所述第一区块链节点的身 份认证通过。
[权利要求 13] 一种计算机可读存储介质, 所述计算机可读存储介质存储有计算机可 读指令, 其特征在于, 所述计算机可读指令被处理器执行时实现如下 步骤:
向联盟链中的创世块提交所述第一区块链节点的身份标识数据和加入 请求, 所述加入请求用于指示所述创世块根据该身份标识数据对所述 第一区块链节点进行身份认证、 在身份认证通过后向所述区块链节点 返回认证通过信息, 所述认证通过信息用于表示所述创世块已经根据 所述身份标识数据将所述第一区块链节点加入到相应的联盟链组织中 若接收到所述创世块返回的认证通过信息, 则监测是否接收到第二区 块链节点的通信请求;
如果接收到第二区块链节点的通信请求, 则从所述通信请求中获取所 述第二区块链接节点的身份标识数据, 并根据所述第二区块链节点的 身份标识数据对所述第二区块链节点进行身份认证;
若对所述第二区块链节点的身份认证通过, 则将与所述通信请求对应 的数据返回给所述第二区块链节点。
[权利要求 14] 如权利要求 13所述的计算机可读存储介质, 其特征在于, 所述身份标 识数据为区块链节点的数字证书中的扩展项信息; 所述扩展项信息包括:
联盟链的名称、 联盟链组织的标识、 区块链节点的名称、 区块链节点 的类型。
[权利要求 15] —种终端设备, 包括存储器、 处理器以及存储在所述存储器中并可在 所述处理器上运行的计算机可读指令, 其特征在于, 所述处理器执行 所述计算机可读指令时实现如下步骤:
向联盟链中的创世块提交所述第一区块链节点的身份标识数据和加入 请求, 所述加入请求用于指示所述创世块根据该身份标识数据对所述 第一区块链节点进行身份认证、 在身份认证通过后向所述区块链节点 返回认证通过信息, 所述认证通过信息用于表示所述创世块已经根据 所述身份标识数据将所述第一区块链节点加入到相应的联盟链组织中 若接收到所述创世块返回的认证通过信息, 则监测是否接收到第二区 块链节点的通信请求;
如果接收到第二区块链节点的通信请求, 则从所述通信请求中获取所 述第二区块链接节点的身份标识数据, 并根据所述第二区块链节点的 身份标识数据对所述第二区块链节点进行身份认证;
若对所述第二区块链节点的身份认证通过, 则将与所述通信请求对应 的数据返回给所述第二区块链节点。
[权利要求 16] 如权利要求 15所述的终端设备, 其特征在于, 所述身份标识数据为区 块链节点的数字证书中的扩展项信息;
所述扩展项信息包括:
联盟链的名称、 联盟链组织的标识、 区块链节点的名称、 区块链节点 的类型。
[权利要求 17] 如权利要求 16所述的终端设备, 其特征在于, 所述根据所述第二区块 链节点的身份标识数据对所述第二区块链节点进行身份认证, 包括: 验证所述第二区块链节点的扩展项信息中联盟链的名称是否与所述第 一区块链节点的扩展项信息中联盟链的名称相同; 若所述第二区块链节点的扩展项信息中联盟链的名称与所述第一区块 链节点的扩展项信息中联盟链的名称相同, 则验证所述创世块中存储 的预设组织成员列表中是否存在所述第二区块链节点的扩展项信息中 联盟链组织的标识;
若所述创世块中存储的预设组织成员列表中存在所述第二区块链节点 的扩展项信息中联盟链组织的标识, 则判断所述通信请求对应的节点 行为是否符合所述第二区块链节点的扩展项信息中区块链节点的类型 对应的节点行为;
若所述通信请求对应的节点行为符合所述第二区块链节点的扩展项信 息中区块链节点的类型对应的节点行为, 则对所述第二区块链节点的 身份认证通过。
[权利要求 18] 如权利要求 17所述的终端设备, 其特征在于, 所述验证所述第二区块 链节点的扩展项信息中联盟链的名称是否与所述第一区块链节点的扩 展项信息中联盟链的名称相同, 包括:
将所述第一区块链节点的扩展项信息中联盟链的名称转换为第一字符 串, 并将所述第二区块链节点的扩展项信息中联盟链的名称转换为第 二字符串;
分别将所述第一字符串中的每个字符与所述第二字符串中对应的字符 进行比对; 若所述第一字符串的每个字符与所述第二字符串中对应的字符相同, 则判定所述第二区块链节点的扩展项信息中联盟链的名称与所述第一 区块链节点的扩展项信息中联盟链的名称相同。
[权利要求 19] 如权利要求 17所述的终端设备, 其特征在于, 所述判断所述通信请求 对应的节点行为是否符合所述第二区块链节点的扩展项信息中区块链 节点的类型对应的节点行为, 包括:
获取所述第二区块链节点的扩展项信息中区块链节点的类型对应的行 为列表, 并获取所述通信请求中包含的请求码; 查找所述行为列表中是否存在所述请求码;
若所述行为列表中存在所述请求码, 则判定所述通信请求对应的节点 行为符合所述第二区块链节点的扩展项信息中区块链节点的类型对应 的节点行为。
[权利要求 20] 如权利要求 16所述的终端设备, 其特征在于, 所述创世块根据该身份 标识数据对所述第一区块链节点进行身份认证, 包括:
判断该身份标识数据中联盟链的名称是否与所述创世块对应的联盟链 的名称相同;
若所述身份标识数据中联盟链的名称与所述创世块对应的联盟链的名 称相同, 则判断所述创世块中存储的预设组织成员列表中是否存在该 身份标识数据中联盟链组织的标识;
若所述创世块中存储的预设组织成员列表中存在该身份标识数据中联 盟链组织的标识, 则对所述第一区块链节点的身份认证通过。
PCT/CN2019/122453 2018-12-14 2019-12-02 一种基于联盟链的身份认证方法及终端设备 Ceased WO2020119506A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201811529919.4 2018-12-14
CN201811529919.4A CN109815657B (zh) 2018-12-14 2018-12-14 基于联盟链的身份认证方法、装置、计算机可读存储介质及终端设备

Publications (1)

Publication Number Publication Date
WO2020119506A1 true WO2020119506A1 (zh) 2020-06-18

Family

ID=66602943

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2019/122453 Ceased WO2020119506A1 (zh) 2018-12-14 2019-12-02 一种基于联盟链的身份认证方法及终端设备

Country Status (2)

Country Link
CN (1) CN109815657B (zh)
WO (1) WO2020119506A1 (zh)

Cited By (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112633878A (zh) * 2020-08-31 2021-04-09 上海添玑网络服务有限公司 一种不动产联盟链终端应用平台及应用方法
CN112733121A (zh) * 2021-01-13 2021-04-30 京东数科海益信息科技有限公司 数据获取方法、装置、设备及存储介质
CN113225736A (zh) * 2021-03-24 2021-08-06 湖南宸瀚信息科技有限责任公司 无人机集群节点认证方法、装置、存储介质及处理器
CN113972991A (zh) * 2020-07-23 2022-01-25 南京理工大学 一种基于多级联盟链的跨域身份认证方法
CN114095246A (zh) * 2021-11-18 2022-02-25 国网河北省电力有限公司电力科学研究院 配电终端的入网身份认证方法
CN114090995A (zh) * 2021-11-22 2022-02-25 大连华信计算机技术股份有限公司 基于联盟链和生物特征的合同签约方法、系统及存储介质
CN115601053A (zh) * 2022-12-16 2023-01-13 山东浪潮质量链科技有限公司(Cn) 一种背对背原产地证明安全可信防护方法及设备

Families Citing this family (18)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109815657B (zh) * 2018-12-14 2022-10-28 深圳壹账通智能科技有限公司 基于联盟链的身份认证方法、装置、计算机可读存储介质及终端设备
CN110177109B (zh) * 2019-06-04 2020-05-12 北京理工大学 一种基于标识密码和联盟链的双代理跨域认证系统
CN110278255B (zh) * 2019-06-13 2021-10-15 深圳前海微众银行股份有限公司 一种基于区块链的物联网iot设备间通信的方法及装置
CN110430235B (zh) * 2019-06-28 2020-11-03 创新先进技术有限公司 跨链发送可认证消息的方法、装置、存储介质和计算设备
CN112003703B (zh) 2019-06-28 2023-08-22 创新先进技术有限公司 一种跨链发送可认证消息的方法和装置
US11251966B2 (en) 2019-06-28 2022-02-15 Advanced New Technologies Co., Ltd. Sending cross-chain authenticatable messages
US11356282B2 (en) 2019-06-28 2022-06-07 Advanced New Technologies Co., Ltd. Sending cross-chain authenticatable messages
CN110602051B (zh) * 2019-08-15 2022-03-29 深圳壹账通智能科技有限公司 基于共识协议的信息处理方法及相关装置
CN110620776B (zh) * 2019-09-24 2021-11-26 腾讯科技(深圳)有限公司 一种数据转移信息传输方法及其装置
CN113206817B (zh) * 2020-02-03 2022-07-12 中移物联网有限公司 一种设备连接确认方法和区块链网络
CN111294356B (zh) * 2020-02-11 2022-09-06 深圳壹账通智能科技有限公司 基于区块链的组织节点上链方法和系统
CN111737707B (zh) * 2020-05-14 2022-09-27 云南云烁巴克云科技有限公司 基于区块链的验证包生成、验证方法、服务器和电子设备
CN111985929A (zh) * 2020-09-03 2020-11-24 深圳壹账通智能科技有限公司 区块链中的交易验证方法、装置、节点设备及存储介质
CN112287361A (zh) * 2020-09-11 2021-01-29 杭州鸽子蛋网络科技有限责任公司 数据治理方法、系统、电子设备和存储介质
CN112861090B (zh) * 2021-03-18 2023-01-31 深圳前海微众银行股份有限公司 信息处理方法、装置、设备、存储介质及计算机程序产品
CN113114634A (zh) * 2021-03-24 2021-07-13 武汉卓尔信息科技有限公司 一种基于联盟链的可信数据管理方法及联盟链
CN114978529A (zh) * 2022-05-10 2022-08-30 平安国际智慧城市科技股份有限公司 基于区块链的身份核验方法及相关设备
CN114640475B (zh) * 2022-05-19 2022-09-06 广东省绿算技术有限公司 去中心化的身份认证方法、装置、计算机设备及存储介质

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050114447A1 (en) * 2003-10-24 2005-05-26 Kim Cameron Method and system for identity exchange and recognition for groups and group members
CN106789920A (zh) * 2016-11-25 2017-05-31 深圳前海微众银行股份有限公司 区块链的节点连接方法及装置
CN108389130A (zh) * 2018-03-02 2018-08-10 合肥学院 一种多交易模式联盟链
CN108416589A (zh) * 2018-03-08 2018-08-17 深圳前海微众银行股份有限公司 区块链节点的连接方法、系统及计算机可读存储介质
CN109815657A (zh) * 2018-12-14 2019-05-28 深圳壹账通智能科技有限公司 一种基于联盟链的身份认证方法及终端设备

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CA3027741C (en) * 2016-06-17 2020-07-21 Jonathan WEIMER Blockchain systems and methods for user authentication
CN107426157B (zh) * 2017-04-21 2020-04-17 杭州趣链科技有限公司 一种基于数字证书以及ca认证体系的联盟链权限控制方法
CN107592292B (zh) * 2017-07-26 2019-08-09 阿里巴巴集团控股有限公司 一种区块链节点间通信方法及装置
CN107733855B (zh) * 2017-08-31 2019-11-05 中国科学院信息工程研究所 一种可同时支持公有链、联盟链及私有链的区块链系统及应用方法

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050114447A1 (en) * 2003-10-24 2005-05-26 Kim Cameron Method and system for identity exchange and recognition for groups and group members
CN106789920A (zh) * 2016-11-25 2017-05-31 深圳前海微众银行股份有限公司 区块链的节点连接方法及装置
CN108389130A (zh) * 2018-03-02 2018-08-10 合肥学院 一种多交易模式联盟链
CN108416589A (zh) * 2018-03-08 2018-08-17 深圳前海微众银行股份有限公司 区块链节点的连接方法、系统及计算机可读存储介质
CN109815657A (zh) * 2018-12-14 2019-05-28 深圳壹账通智能科技有限公司 一种基于联盟链的身份认证方法及终端设备

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
JIANYI ZHAMG ET AL: "A Regulatable Digital Currency Model Based on Blockchain", JOURNAL OF COMPUTER RESEARCH AND DEVELOPMENT, vol. 55, no. 10, 15 October 2018 (2018-10-15), pages 2219 - 2232, XP009521511, ISSN: 1000-1239 *
WENTONG WANG ET AL: "BlockCAM: A Blockchain-based Cross-domain Authentication Model", 2018 IEEE THIRD INTERNATIONAL CONFERENCE ON DATA SCIENCE IN CYBERSPACE (DSC), 18 June 2018 (2018-06-18), pages 896 - 901, XP033375463, DOI: 10.1109/DSC.2018.00143 *

Cited By (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113972991A (zh) * 2020-07-23 2022-01-25 南京理工大学 一种基于多级联盟链的跨域身份认证方法
CN112633878A (zh) * 2020-08-31 2021-04-09 上海添玑网络服务有限公司 一种不动产联盟链终端应用平台及应用方法
CN112733121A (zh) * 2021-01-13 2021-04-30 京东数科海益信息科技有限公司 数据获取方法、装置、设备及存储介质
US12321436B2 (en) 2021-01-13 2025-06-03 Jingdong Technology Information Technology Co., Ltd. Method and apparatus for data acquisition, device and storage medium
CN113225736A (zh) * 2021-03-24 2021-08-06 湖南宸瀚信息科技有限责任公司 无人机集群节点认证方法、装置、存储介质及处理器
CN113225736B (zh) * 2021-03-24 2024-02-02 湖南宸瀚信息科技有限责任公司 无人机集群节点认证方法、装置、存储介质及计算机设备
CN114095246A (zh) * 2021-11-18 2022-02-25 国网河北省电力有限公司电力科学研究院 配电终端的入网身份认证方法
CN114095246B (zh) * 2021-11-18 2024-01-23 国网河北省电力有限公司电力科学研究院 配电终端的入网身份认证方法
CN114090995A (zh) * 2021-11-22 2022-02-25 大连华信计算机技术股份有限公司 基于联盟链和生物特征的合同签约方法、系统及存储介质
CN115601053A (zh) * 2022-12-16 2023-01-13 山东浪潮质量链科技有限公司(Cn) 一种背对背原产地证明安全可信防护方法及设备
CN115601053B (zh) * 2022-12-16 2023-08-22 浪潮云洲工业互联网有限公司 一种背对背原产地证明安全可信防护方法及设备

Also Published As

Publication number Publication date
CN109815657B (zh) 2022-10-28
CN109815657A (zh) 2019-05-28

Similar Documents

Publication Publication Date Title
WO2020119506A1 (zh) 一种基于联盟链的身份认证方法及终端设备
US12363169B2 (en) Data access policies
CN110543545B (zh) 基于区块链的档案管理方法、装置及存储介质
CN110753944B (zh) 用于基于区块链的数据管理的系统和方法
CN111709860B (zh) 遗嘱处理方法、装置、设备及存储介质
WO2020155761A1 (zh) 登录多个服务集群的方法、装置、计算机设备及存储介质
US11258771B2 (en) Systems and methods for sending user data from a trusted party to a third party using a distributed registry
US20150101059A1 (en) Application License Verification
CN112712452A (zh) 基于区块链的审批信息处理方法和装置
US11190519B2 (en) Dock administration using a token
CN109446788A (zh) 一种设备的身份认证方法及装置、计算机存储介质
CN112837023A (zh) 机构的业务协同平台、方法、装置及电子设备
CN111310166A (zh) 权限管理方法、装置、设备及存储介质
CN112445841B (zh) 账户查询方法、装置、系统、服务器及介质
CN111817859A (zh) 基于零知识证明的数据共享方法、装置、设备及存储介质
CN116737221A (zh) 配置治理方法、装置、计算机设备及存储介质
US20250291912A1 (en) Selecting data interactions to be performed by an Internet of Things (IoT) device
WO2024217351A1 (zh) 一种基于区块链的身份认证方法及装置
US12204634B2 (en) Secure device tracking via device ownership service
CN116033022A (zh) 数据中心访问方法、装置、网关及存储介质
CN114331661A (zh) 数据核验方法、装置、电子设备及存储介质
CN113592645A (zh) 数据验证的方法和装置
CN112507395A (zh) 信息验证方法、系统、装置、服务器及介质
US12259925B2 (en) Secure data interactions performed by an internet of things (IoT) device
US12425243B2 (en) Resolving failed data interactions performed by an internet of things (IoT) device

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 19895578

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 29/09/2021)

122 Ep: pct application non-entry in european phase

Ref document number: 19895578

Country of ref document: EP

Kind code of ref document: A1