CN109327456A - A kind of cluster method for authenticating, clustered node and the electronic equipment of decentralization - Google Patents

A kind of cluster method for authenticating, clustered node and the electronic equipment of decentralization Download PDF

Info

Publication number
CN109327456A
CN109327456A CN201811310871.8A CN201811310871A CN109327456A CN 109327456 A CN109327456 A CN 109327456A CN 201811310871 A CN201811310871 A CN 201811310871A CN 109327456 A CN109327456 A CN 109327456A
Authority
CN
China
Prior art keywords
user terminal
cluster
user
text information
key
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201811310871.8A
Other languages
Chinese (zh)
Inventor
陈剑
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Knownsec Information Technology Co Ltd
Original Assignee
Beijing Knownsec Information Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Knownsec Information Technology Co Ltd filed Critical Beijing Knownsec Information Technology Co Ltd
Priority to CN201811310871.8A priority Critical patent/CN109327456A/en
Publication of CN109327456A publication Critical patent/CN109327456A/en
Pending legal-status Critical Current

Links

Classifications

    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00—Network architectures or network communication protocols for network security
    • H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0876—Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00—Network architectures or network communication protocols for network security
    • H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/108—Network architectures or network communication protocols for network security for controlling access to devices or network resources when the policy decisions are valid for a limited amount of time
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00—Network arrangements or protocols for supporting network services or applications
    • H04L67/01—Protocols
    • H04L67/10—Protocols in which an application is distributed across nodes in the network
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3236—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3247—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Power Engineering (AREA)
  • Storage Device Security (AREA)

Abstract

The present invention provides cluster method for authenticating, clustered node and the electronic equipments of a kind of decentralization, and applied to cluster to the authentication of user terminal, cluster is made of multiple clustered nodes.The described method includes: receive that user terminal sends includes the authentication request of the text information through user's signature, whether effective the text information through user's signature is verified;If verified, the signing messages is effective, responds the authentication request of the user terminal, grants the permission of cluster described in the user terminal access.The present invention overcomes in the prior art in the cluster using the disadvantage for easily causing authentication operations unstable when authenticating the unstable networks between low efficiency and server existing for the authentication server of centralization.It the composite can be widely applied to distributed system deployment or block chain technical field.

Description

A kind of cluster method for authenticating, clustered node and the electronic equipment of decentralization
Technical field
The present invention relates to field of communication technology more particularly to a kind of cluster method for authenticating of decentralization, clustered node and Electronic equipment.
Background technique
Cluster, refer to one group it is mutually independent, by high speed network interconnect computer, it constitutes a group, and with list The mode of one system is managed.For accessing the user terminal of cluster, usual cluster is authentication behaviour to be carried out to user terminal Make, to judge whether user terminal has the permission of access group system, existing cluster is to the authentication mode of user terminal, usually It is by the way of password authentification, but the following operations need to be performed for this verification mode, first at the beginning of clustered deploy(ment), needs specially Door builds special authentication server, is accessed control by authentication server to all user terminals, every increase by one in cluster Platform equipment needs to re-start configuration to the configuration information of authentication server, using the authentication server mode of this centralization There are following inconvenience, are that authentication low efficiency will affect the effective of authentication secondly when the unstable networks between server first Property.
Summary of the invention
For the above problem existing for authentication operations in the prior art, the present invention provides one kind and is intended to avoid in authentication operations The heart reduces complementary cluster method for authenticating, clustered node and electronic equipment between cluster.
According to the first aspect of the invention, a kind of cluster method for authenticating of decentralization is provided, be applied to cluster to The authentication of family terminal, the cluster are made of multiple clustered nodes.The described method includes: receive user terminal send include warp Whether effective the authentication request of the text information of user's signature verifies the text information through user's signature;If verifying institute It states that signing messages is effective, responds the authentication request of the user terminal, grant the permission of cluster described in the user terminal access.
Preferably, first key and second key opposite with the first key are pre-generated;It is described to be signed through user The text information of name, is pre-created text information by user terminal, the first key signs the text information Name processing obtains;The whether effective step of the verifying text information through user's signature, further comprises by described Whether signing messages described in the second key pair is verified, effective to verify the text information through user's signature.
Preferably, the whether effective step of the verifying text information through user's signature further comprises: using Signing messages described in second key pair is decrypted to obtain one first summary info;Described in the access request Text information is requested to carry out Hash operation, to obtain one second summary info;First summary info is plucked with described second Information is wanted to be compared;Judge that the signing messages verifies whether effectively according to the comparison result.
Preferably, the validity period information of User ID and access authority is included at least in the text information.
Preferably, the first key is the private key of cipher key pair, and second key is the public key of cipher key pair.
Preferably, second key is imported during initialization in advance.
Preferably, if described verify that the signing messages is effective, the authentication request of the user terminal is responded, grants institute The permission for stating cluster described in user terminal access further comprises: judging that the User ID in the text information is corresponding described Whether the validity period of access authority exceeds the time limit;If validity period does not exceed the time limit, the authentication request of the user terminal is responded, described in permission The permission of cluster described in user terminal access;If validity period has exceeded the time limit, refuse the authentication request of the user terminal.
According to another aspect of the present invention, a kind of clustered node of decentralization is provided, comprising: receiving module, to connect Receive the authentication request comprising the text information through user's signature that user terminal is sent;Authentication module, to according to Whether the authentication request of user terminal verifies the text information through user's signature effective;Respond module, it is described to verify When signing messages is effective, the authentication request of the user terminal is responded, grants the permission of cluster described in the user terminal access.
Another aspect of the invention also provides a kind of electronic equipment, comprising: memory and processor, the memory and institute State processor coupling;The memory is for storing program;The processor is for calling the journey being stored in the memory Sequence code, to execute the cluster method for authenticating of decentralization above-mentioned.
Another aspect of the invention also provides a kind of computer readable storage medium for storing one or more programs, described One or more programs include instruction, described instruction when executed by a computing apparatus so that the calculatings equipment execute basis before State the cluster method for authenticating of decentralization.
Above-mentioned each technical solution of the invention has the following advantages that or the utility model has the advantages that overcomes in the prior art in the cluster Low efficiency is authenticated existing for authentication server using centralization, and easily causes authentication to grasp when unstable networks between server The stability of work.This scheme can be widely applied to distributed system deployment or block chain technical field.
Detailed description of the invention
With reference to appended attached drawing, more fully to describe the embodiment of the present invention.However, appended attached drawing be merely to illustrate and It illustrates, and is not meant to limit the scope of the invention.
Fig. 1 is a kind of flow chart of the cluster method for authenticating embodiment of decentralization of the present invention;
Fig. 2 is to verify A.L.S. about clustered node in a kind of cluster method for authenticating embodiment of decentralization of the present invention Breath whether the flow chart of effective method;
Fig. 3 is a kind of structural schematic diagram of the cluster right discriminating system embodiment of decentralization of the present invention;
Fig. 4 is the structural schematic diagram of one embodiment of a kind of electronic equipment of the present invention.
Specific embodiment
Following will be combined with the drawings in the embodiments of the present invention, and technical solution in the embodiment of the present invention carries out clear, complete Site preparation description, it is clear that described embodiments are only a part of the embodiments of the present invention, instead of all the embodiments.It is based on Embodiment in the present invention, those of ordinary skill in the art without creative labor it is obtained it is all its His embodiment, shall fall within the protection scope of the present invention.
It should be noted that in the absence of conflict, the feature in embodiment and embodiment in the present invention can phase Mutually combination.
The present invention will be further explained below with reference to the attached drawings and specific examples, but not as the limitation of the invention.
The present invention includes a kind of cluster method for authenticating of decentralization.
A kind of cluster method for authenticating of decentralization, applied to cluster to the authentication of user terminal, the cluster is by multiple Clustered node is constituted, wherein as shown in Figure 1, comprising the following steps:
Step S1, receive that user terminal sends includes the authentication request of the text information through user's signature, described in verifying Whether the text information through user's signature is effective;
If step S2, verified, the signing messages is effective, responds the authentication request of the user terminal, grants the use The permission of cluster described in the terminal access of family.
In above-mentioned technical proposal, cluster removes the authentication server of centralization, is being connect by each clustered node in cluster After the authentication request for receiving one or more user terminals transmission, each clustered node itself carries out authentication verification to authentication request, Wherein in order to realize the purpose of decentralization, the text information in authentication request is encrypted to be formed for user terminal first Signing messages, then signing messages and text information are sent to some in cluster or multiple cluster sections by user terminal together Point, by receive user terminal authentication information one or more clustered nodes to signing messages carry out verification processing, and The permission of current user terminal access cluster is granted after signing messages verifying effectively.
Itself is all disposed due to clustered node each in cluster and realizes subscriber terminal authority, so that it not only authenticates efficiency more Height, and it is higher to overcome dependence between the authentication server in the prior art using centralization and each clustered node, When the problem of unstable Timing authentication operations occurs in network.
In a kind of preferably embodiment, provide an Encryption Tool, by Encryption Tool generate first key and with The second opposite key of first key;
User terminal is encrypted to form signing messages request text information by first key;
The signing messages in authentication request that clustered node passes through user terminal described in the second key pair is decrypted With the decrypted result of acquisition.
In above-mentioned technical proposal, it is freely that GPG application software (GPG, GNU Privacy Guard), which can be used, in Encryption Tool A part of the GNU plan of software foundation.It is a kind of cipher mode based on key, used a pair of secret keys to message into Row encryption and decryption, to guarantee the safe transmission of message.
Encryption Tool software is first passed through in advance and produces a pair of of public key and private key, i.e., above-mentioned first key is private key, corresponding The second above-mentioned key is public key.
It should be noted that each clustered node of colony terminal import during initialization it is close as the second of public key Key.
In a kind of preferably embodiment, as shown in Fig. 2, clustered node verifies the whether effective method packet of signing messages Include following steps:
Step S11, the second key pair signing messages is used to be decrypted to obtain one first summary info;
Step S12, Hash operation is carried out again to the text information in authentication request, to obtain one second summary info;
Step S13, the first summary info is compared with the second summary info, to obtain comparison result;
Step S14, judge that signing messages verifies whether effectively according to comparison result;
If comparison result is consistent, verifying effectively, is authenticated successfully, grants the SS later access;
If comparison result is inconsistent, authentication failed, authentication is unsuccessful, to refuse the user terminal access.
In a kind of preferably embodiment, above-mentioned text information includes at least the effective of User ID and access authority Phase.
In a kind of preferably embodiment, Encryption Tool Software Create key pair, the first key of cipher key pair is private Key, the second key are public key.
Wherein, each clustered node equipment in cluster is initialized, imports described during initialization in advance Two keys.
In clustered node after verifying user's signature is effective, the corresponding access authority of current User ID is further judged Whether validity period exceeds the time limit;
If validity period does not exceed the time limit, clustered node responds the authentication request of user terminal, grant user terminal access cluster Permission;
If validity period has exceeded the time limit, denied access request.
It is illustrated below with a kind of specific embodiment:
Firstly, user terminal sends the access authority that authentication request obtains cluster to cluster;
Then, after one or more clustered nodes in cluster receive the authentication request of the user terminal, to the use The authentication request of family terminal carries out authentication process;
The operation that clustered node is authenticated mainly comprises the steps that
Parse the text information and signing messages after user's signature for including in authentication request;
Use public key that signing messages is decrypted to obtain one first summary info, to the text information in authentication request Hash operation is carried out, to obtain one second summary info;
First summary info is compared with the second summary info, to obtain comparison result;
Judge that the signing messages of user verifies whether effectively according to comparison result;
If comparison result is consistent, verifying is effective:
When verifying effective, clustered node continues to judge the User ID for including in text information and corresponding access right Whether the validity period of limit exceeds the time limit;
If validity period does not exceed the time limit, which responds the authentication request of user terminal, grant user terminal access cluster Permission;
If validity period has exceeded the time limit, refuse the authentication request of the user terminal.
As shown in figure 3, further including a kind of cluster right discriminating system of decentralization, wherein including user terminal 1, Yi Jiyou The cluster 2 that multiple clustered nodes 21 are constituted, user terminal 1 is to send authentication request to cluster 2;
User terminal 1 includes:
First encryption/decryption module 11 generates signing messages to carry out encryption to the request text information in authentication request;
Terminal communication module 12, will include that the authentication request of text information and signing messages is requested to be sent to cluster 2;
It include multiple clustered nodes 21,22 ... in cluster 2, each clustered node 21,22 ... can be according to distribution It is disposed
According to modes such as distributed principle or heat sources, authentication request is sent to a certain in cluster 2 by user terminal 1 Clustered node 21;
Clustered node 21 includes:
Receiving module 211, to receive user terminal send described in include the text information through user's signature authentication Request;
Authentication module 212, to verify the text envelope through user's signature according to the authentication request of the user terminal It whether effective ceases;
Respond module 213, to verify the signing messages it is effective when, respond the authentication request of the user terminal, it is quasi- Give the permission of cluster described in the user terminal access.
In a kind of preferably embodiment, an Encryption Tool is provided, it is close by this Encryption Tool Software Create key pair Key centering includes first key and second key opposite with first key;
User terminal 1 is encrypted text information by first key to form user's signature information;
After clustered node 21 receives the authentication request that user terminal is sent, pass through the signature in the second key pair authentication request The decrypted result that information is decrypted with acquisition.
It wherein, include the validity period of User ID and access authority in text information.
In a kind of preferably embodiment, authentication module further include:
Second encryption/decryption module 211, to use the second key pair user's signature information to be decrypted to obtain one first Summary info;
Hash operation is carried out to the text information in authentication request, to obtain one second summary info;
Authentication module 212 further include:
Comparing unit 2121, the first summary info to be compared with the second summary info, to obtain comparison result;
First judging unit 2122, to judge that signing messages verifies whether effectively according to comparison result;
First processing units 2123 then indicate verifying when comparison result is consistent effectively, when comparison result is inconsistent, table Show authentication failed, denied access request.
In a kind of preferably embodiment, respond module 213 includes:
Second judgment unit 2131, further to judge current User ID after user's signature Information Authentication is effective Before the deadline whether the validity period of corresponding access authority;
The second processing unit 2132, to when exceeding the time limit the validity period of access authority, denied access is requested.
It is illustrated below with a kind of specific embodiment;
Firstly, user terminal 1 is by the first encryption/decryption module 11 to the text comprising User ID and access authority validity period Information carries out signature and generates signing messages, then will be comprising signing messages and through user's signature mistake by terminal communication module 12 The authentication request of text information be sent to cluster 2;
It is as follows that a certain clustered node 21 in cluster 2 carries out authentication operations to the authentication request of the received user terminal:
By the authentication module 212 in clustered node, the authentication request of the user terminal is verified, described in verifying Whether the text information through user's signature is effective;
It further comprise that the second encryption/decryption module 211 first uses the second key pair signing messages to be decrypted to obtain One first summary info;
Hash operation further is carried out to the text information in authentication request, to obtain one second summary info;
After obtaining the first summary info and the second summary info:
By the comparing unit 2121 in authentication module 212, the first summary info is compared with the second summary info, To obtain comparison result;
First judging unit 2122 judges that signing messages verifies whether effectively according to comparison result;
First processing units 2123 then indicate verifying when comparison result is consistent effectively, when comparison result is inconsistent, table Show authentication failed, refuses the access request of this user terminal.
Respond module 213 gives the user terminal 1 to respond the authentication request of this user terminal after verifying effectively The permission of cluster 2 is accessed, in addition, can also further sentence by second judgment unit 2131 after signing messages verifying is effective The validity period of the User ID and corresponding access authority of breaking current whether before the deadline, such as before the deadline, respond module 213, just give the permission that user terminal 1 accesses cluster 2;
If the validity period of access authority exceeds the time limit, refuse the access request of user terminal 1.
Each example scheme in this specification can be widely applied to distributed system deployment or block chain technical field, It overcomes and authenticates low efficiency using the authentication server of centralization is existing in the cluster in the prior art, substantially increase authentication The stability of operation reduces the authentication lower deployment cost of large batch of clustered node.Provided herein algorithm and display not with appoint What certain computer, virtual bench or other equipment are inherently related.Various fexible units can also be with teaching based on this It is used together.As described above, it is obvious for constructing structure required by this kind of device.In addition, the present invention is not yet For any certain programmed language.It should be understood that can use various programming languages realizes summary of the invention described herein, And the description done above to language-specific is in order to disclose the best mode of carrying out the invention.
In the instructions provided here, numerous specific details are set forth.It is to be appreciated, however, that implementation of the invention Example can be practiced without these specific details.In some instances, well known method, structure is not been shown in detail And technology, so as not to obscure the understanding of this specification.
Similarly, it should be understood that in order to simplify the disclosure and help to understand one or more of the various inventive aspects, Above in the description of exemplary embodiment of the present invention, each feature of the invention is grouped together into single implementation sometimes In example, figure or descriptions thereof.However, the disclosed method should not be interpreted as reflecting the following intention: i.e. required to protect Shield the present invention claims features more more than feature expressly recited in each claim.More precisely, as following Claims reflect as, inventive aspect is all features less than single embodiment disclosed above.Therefore, Thus the claims for following specific embodiment are expressly incorporated in the specific embodiment, wherein each claim itself All as a separate embodiment of the present invention.
Those skilled in the art will understand that can be carried out adaptively to the module in the equipment in embodiment Change and they are arranged in one or more devices different from this embodiment.It can be the module or list in embodiment Member or component are combined into a module or unit or component, and furthermore they can be divided into multiple submodule or subelement or Sub-component.Other than such feature and/or at least some of process or unit exclude each other, it can use any Combination is to all features disclosed in this specification (including adjoint claim, abstract and attached drawing) and so disclosed All process or units of what method or apparatus are combined.Unless expressly stated otherwise, this specification is (including adjoint power Benefit requires, abstract and attached drawing) disclosed in each feature can be by providing identical, equivalent, or similar purpose alternative features come generation It replaces.
In addition, it will be appreciated by those of skill in the art that although some embodiments described herein include other embodiments In included certain features rather than other feature, but the combination of the feature of different embodiments mean it is of the invention Within the scope of and form different embodiments.For example, in the following claims, embodiment claimed is appointed Meaning one of can in any combination mode come using.
Various component embodiments of the invention can be implemented in hardware, or to run on one or more processors Software module realize, or be implemented in a combination thereof.It will be understood by those of skill in the art that can be used in practice Microprocessor or digital signal processor (DSP) realize the typing dress of taking pictures of word content according to an embodiment of the present invention Set, calculate some or all functions of some or all components in equipment and computer readable storage medium.The present invention Be also implemented as executing method as described herein some or all device or device program (for example, Computer program and computer program product).It is such to realize that program of the invention can store on a computer-readable medium, Or it may be in the form of one or more signals.Such signal can be downloaded from an internet website to obtain, or It is provided on the carrier signal, or is provided in any other form.
For example, Fig. 4 shows a kind of calculating device structure schematic diagram provided according to an embodiment of the present invention.The calculating Equipment 300 includes: processor 310, and is stored with the memory for the computer program that can be run on the processor 310 320.Processor 310, for executing each step of method in the present invention when executing the computer program in the memory 320 Suddenly.Memory 320 can be such as flash memory, EEPROM (electrically erasable programmable read-only memory), EPROM, hard disk or ROM Etc electronic memory.Memory 320 has the computer journey stored for executing any method and step in the above method The memory space 330 of sequence 331.Computer program 331 can read or write from one or more computer program product Enter into this one or more computer program product.These computer program products include such as hard disk, compact-disc (CD), The program code carrier of storage card or floppy disk etc.

Claims (10)

1. a kind of cluster method for authenticating of decentralization, applied to cluster to the authentication of user terminal, the cluster is by multiple collection Group node is constituted characterized by comprising
Receive that user terminal sends includes the authentication request of the text information through user's signature, is verified described through user's signature Whether text information is effective;
If verified, the signing messages is effective, responds the authentication request of the user terminal, grants the user terminal access The permission of the cluster.
2. the cluster method for authenticating of decentralization according to claim 1, which is characterized in that pre-generated first key with And second key opposite with the first key;
The text information through user's signature, is pre-created text information by user terminal, by the first key to institute It states text information and carries out signature and handle to obtain;
The whether effective step of the verifying text information through user's signature, further comprises by second key The signing messages is verified, it is whether effective to verify the text information through user's signature.
3. the cluster method for authenticating of decentralization according to claim 2, which is characterized in that the verifying is described through user The whether effective step of the text information of signature further comprises:
Signing messages described in second key pair is used to be decrypted to obtain one first summary info;
Hash operation is carried out to the request text information in the access request, to obtain one second summary info;
First summary info is compared with second summary info;
Judge that the signing messages verifies whether effectively according to the comparison result.
4. the cluster method for authenticating of decentralization according to claim 1, which is characterized in that in the text information at least Validity period information including User ID and access authority.
5. the cluster method for authenticating of decentralization according to claim 2 or 3, which is characterized in that
The first key is the private key of cipher key pair, and second key is the public key of cipher key pair.
6. the cluster method for authenticating of decentralization according to claim 2 or 3, which is characterized in that
Import second key during initialization in advance.
7. the cluster method for authenticating of decentralization according to claim 4, which is characterized in that if described verify the label Name information is effective, responds the authentication request of the user terminal, grants the permission of cluster described in the user terminal access, into one Step includes:
Judge whether the validity period of the corresponding access authority of the User ID in the text information exceeds the time limit;
If validity period does not exceed the time limit, the authentication request of the user terminal is responded, grants cluster described in the user terminal access Permission;
If validity period has exceeded the time limit, refuse the authentication request of the user terminal.
8. a kind of clustered node of decentralization characterized by comprising
Receiving module, to receive user terminal send described in include the text information through user's signature authentication request;
Authentication module, to verify whether the text information through user's signature has according to the authentication request of the user terminal Effect;
Respond module, to verify the signing messages it is effective when, respond the authentication request of the user terminal, grant the use The permission of cluster described in the terminal access of family.
9. a kind of electronic equipment characterized by comprising memory and processor, the memory and processor coupling;
The memory is for storing program;
The processor is for calling the program code being stored in the memory, to execute as any in claim 1-7 Method described in.
10. a kind of computer readable storage medium for storing one or more programs, one or more of programs include instruction, Described instruction when executed by a computing apparatus so that the calculating equipment executes according to claim 1 described in any one of -7 The cluster method for authenticating of decentralization.
CN201811310871.8A 2018-11-06 2018-11-06 A kind of cluster method for authenticating, clustered node and the electronic equipment of decentralization Pending CN109327456A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201811310871.8A CN109327456A (en) 2018-11-06 2018-11-06 A kind of cluster method for authenticating, clustered node and the electronic equipment of decentralization

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201811310871.8A CN109327456A (en) 2018-11-06 2018-11-06 A kind of cluster method for authenticating, clustered node and the electronic equipment of decentralization

Publications (1)

Publication Number Publication Date
CN109327456A true CN109327456A (en) 2019-02-12

Family

ID=65260639

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201811310871.8A Pending CN109327456A (en) 2018-11-06 2018-11-06 A kind of cluster method for authenticating, clustered node and the electronic equipment of decentralization

Country Status (1)

Country Link
CN (1) CN109327456A (en)

Cited By (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2019228557A3 (en) * 2019-07-02 2020-04-30 Alibaba Group Holding Limited System and method for decentralized-identifier authentication
US10685099B2 (en) 2019-07-02 2020-06-16 Alibaba Group Holding Limited System and method for mapping decentralized identifiers to real-world entities
US10728042B2 (en) 2019-07-02 2020-07-28 Alibaba Group Holding Limited System and method for blockchain-based cross-entity authentication
US10938562B2 (en) 2019-07-02 2021-03-02 Advanced New Technologies Co., Ltd. System and method for creating decentralized identifiers
US10938569B2 (en) 2019-07-02 2021-03-02 Advanced New Technologies Co., Ltd. System and method for verifying verifiable claims
CN114039688A (en) * 2021-11-03 2022-02-11 上海寰创通信科技股份有限公司 Station area broadcasting method based on handheld station
CN114844648A (en) * 2022-04-25 2022-08-02 北京市商汤科技开发有限公司 Data verification method, data processing method and device
CN115203724A (en) * 2022-07-25 2022-10-18 上海壁仞智能科技有限公司 Software verification method, device, electronic device and storage medium

Citations (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1283827A (en) * 2000-08-18 2001-02-14 郝孟一 Universal electronic information network authentication system and method
CN102710605A (en) * 2012-05-08 2012-10-03 重庆大学 Information security management and control method under cloud manufacturing environment
CN103190129A (en) * 2009-11-25 2013-07-03 安全第一公司 System and method for protecting data in motion
CN105338526A (en) * 2014-07-31 2016-02-17 成都鼎桥通信技术有限公司 Distributed authentication system, method and device based on cluster users
CN105551138A (en) * 2015-12-08 2016-05-04 腾讯科技(深圳)有限公司 Method and system for processing service voucher
CN106357648A (en) * 2016-09-21 2017-01-25 海能达通信股份有限公司 Core network system, system and method for trunking service registration of trunking terminal
CN106657152A (en) * 2017-02-07 2017-05-10 腾讯科技(深圳)有限公司 Authentication method, server and access control device
CN106850654A (en) * 2017-02-23 2017-06-13 布比(北京)网络技术有限公司 The mandate access method and system of a kind of distributed information
CN108234515A (en) * 2018-01-25 2018-06-29 中国科学院合肥物质科学研究院 A kind of Self-certified digital identity management system and its method based on intelligent contract

Patent Citations (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1283827A (en) * 2000-08-18 2001-02-14 郝孟一 Universal electronic information network authentication system and method
CN103190129A (en) * 2009-11-25 2013-07-03 安全第一公司 System and method for protecting data in motion
CN102710605A (en) * 2012-05-08 2012-10-03 重庆大学 Information security management and control method under cloud manufacturing environment
CN105338526A (en) * 2014-07-31 2016-02-17 成都鼎桥通信技术有限公司 Distributed authentication system, method and device based on cluster users
CN105551138A (en) * 2015-12-08 2016-05-04 腾讯科技(深圳)有限公司 Method and system for processing service voucher
CN106357648A (en) * 2016-09-21 2017-01-25 海能达通信股份有限公司 Core network system, system and method for trunking service registration of trunking terminal
CN106657152A (en) * 2017-02-07 2017-05-10 腾讯科技(深圳)有限公司 Authentication method, server and access control device
CN106850654A (en) * 2017-02-23 2017-06-13 布比(北京)网络技术有限公司 The mandate access method and system of a kind of distributed information
CN108234515A (en) * 2018-01-25 2018-06-29 中国科学院合肥物质科学研究院 A kind of Self-certified digital identity management system and its method based on intelligent contract

Cited By (23)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10938569B2 (en) 2019-07-02 2021-03-02 Advanced New Technologies Co., Ltd. System and method for verifying verifiable claims
US10938562B2 (en) 2019-07-02 2021-03-02 Advanced New Technologies Co., Ltd. System and method for creating decentralized identifiers
US10700851B2 (en) 2019-07-02 2020-06-30 Alibaba Group Holding Limited System and method for implementing a resolver service for decentralized identifiers
US10708060B2 (en) 2019-07-02 2020-07-07 Alibaba Group Holding Limited System and method for blockchain-based notification
US10728042B2 (en) 2019-07-02 2020-07-28 Alibaba Group Holding Limited System and method for blockchain-based cross-entity authentication
US10756885B2 (en) 2019-07-02 2020-08-25 Alibaba Group Holding Limited System and method for blockchain-based cross entity authentication
US10917246B2 (en) 2019-07-02 2021-02-09 Advanced New Technologies Co., Ltd. System and method for blockchain-based cross-entity authentication
US11038883B2 (en) 2019-07-02 2021-06-15 Advanced New Technologies Co., Ltd. System and method for decentralized-identifier creation
US11025435B2 (en) 2019-07-02 2021-06-01 Advanced New Technologies Co., Ltd. System and method for blockchain-based cross-entity authentication
US10938551B2 (en) 2019-07-02 2021-03-02 Advanced New Technologies Co., Ltd. System and method for implementing a resolver service for decentralized identifiers
US10685099B2 (en) 2019-07-02 2020-06-16 Alibaba Group Holding Limited System and method for mapping decentralized identifiers to real-world entities
WO2019228557A3 (en) * 2019-07-02 2020-04-30 Alibaba Group Holding Limited System and method for decentralized-identifier authentication
US10924284B2 (en) 2019-07-02 2021-02-16 Advanced New Technologies Co., Ltd. System and method for decentralized-identifier authentication
US11082233B2 (en) 2019-07-02 2021-08-03 Advanced New Technologies Co., Ltd. System and method for issuing verifiable claims
US11159526B2 (en) 2019-07-02 2021-10-26 Advanced New Technologies Co., Ltd. System and method for decentralized-identifier authentication
US11165576B2 (en) 2019-07-02 2021-11-02 Advanced New Technologies Co., Ltd. System and method for creating decentralized identifiers
US11171789B2 (en) 2019-07-02 2021-11-09 Advanced New Technologies Co., Ltd. System and method for implementing a resolver service for decentralized identifiers
US11477032B2 (en) 2019-07-02 2022-10-18 Advanced New Technologies Co., Ltd. System and method for decentralized-identifier creation
US11277268B2 (en) 2019-07-02 2022-03-15 Advanced New Technologies Co., Ltd. System and method for verifying verifiable claims
US11316697B2 (en) 2019-07-02 2022-04-26 Advanced New Technologies Co., Ltd. System and method for issuing verifiable claims
CN114039688A (en) * 2021-11-03 2022-02-11 上海寰创通信科技股份有限公司 Station area broadcasting method based on handheld station
CN114844648A (en) * 2022-04-25 2022-08-02 北京市商汤科技开发有限公司 Data verification method, data processing method and device
CN115203724A (en) * 2022-07-25 2022-10-18 上海壁仞智能科技有限公司 Software verification method, device, electronic device and storage medium

Similar Documents

Publication Publication Date Title
EP3075099B1 (en) Secure proxy to protect private data
CN101227468B (en) Method, device and system for authenticating user to network
US9805185B2 (en) Disposition engine for single sign on (SSO) requests
ES2819192T3 (en) Identification of an anonymous entity as part of a group
CN113872932B (en) SGX-based micro-service interface authentication method, system, terminal and storage medium
CN110099048B (en) Cloud storage method and equipment
KR20160138063A (en) Techniques to operate a service with machine generated authentication tokens
CN106302606B (en) Across the application access method and device of one kind
CN109361508B (en) Data transmission method, electronic device and computer readable storage medium
CN110266518B (en) SDN-based IPv6 address traceability method, device and electronic equipment
CN101527634B (en) System and method for binding account information with certificates
CN110771087B (en) Private key update
CN111901342A (en) Authority application verification method, device, equipment and storage medium
CN112367664A (en) Method and device for safely accessing external equipment to intelligent electric meter
Tuan et al. A blockchain-based authentication and access control for smart devices in SDN-enabled networks for metaverse
TW201430608A (en) Single-sign-on system and method
CN105430649B (en) WIFI cut-in method and equipment
CN103905390B (en) Permission acquisition method, device, electronic equipment and system
CN108574657B (en) Method, apparatus, system, and computing device and server for accessing a server
CN105071941A (en) Method and device for identity authentication of nodes of distributed system
CN110830507B (en) Resource access method, device, electronic equipment and system
KR102534012B1 (en) System and method for authenticating security level of content provider
CN106789079A (en) Identity identifying method, disposal password electronic installation and system
CN105471579A (en) Trusted login method and device
US20260095336A1 (en) Integrated trust platform modules, device attestation, and device management for live zero trust network access

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
CB02 Change of applicant information
CB02 Change of applicant information

Address after: Room 311501, Unit 1, Building 5, Courtyard 1, Futong East Street, Chaoyang District, Beijing 100102

Applicant after: BEIJING KNOWNSEC INFORMATION TECHNOLOGY Co.,Ltd.

Address before: Room 311501, Unit 1, Building 5, Courtyard 1, Futong East Street, Chaoyang District, Beijing 100102

Applicant before: BEIJING KNOWNSEC INFORMATION TECHNOLOGY Co.,Ltd.

RJ01 Rejection of invention patent application after publication
RJ01 Rejection of invention patent application after publication

Application publication date: 20190212