We use cookies to improve your experience with our site.

一种易于理解的云际计算跨链认证机制

An Understandable Cross-Chain Authentication Mechanism for JointCloud Computing

  • 摘要:
    研究背景 云际计算是一种新的计算范式,支持云服务实现互利共赢。云际计算的关键组成部分是云际分布账本——它通过提供数字空间证据,确保具有不同利益云主体间的信任。区块链构成了这一框架的基础,其应用正在各个领域中快速增长,用来优化工作流程。然而,区块链的互操作性和跨链数据认证方面的挑战尚未得到解决,阻碍了云主体间更广泛的信任建立。部分现有的跨链解决方案并不支持跨链数据认证场景,另一些则仅关注一般的跨链功能,未能针对数据认证问题提出特定解决方案,导致设计复杂且难以实施。此外,这些解决方案通常假定区块链本身就能提供可追溯性和问责机制,未能提供快速且自动化的特定场景解决方案。
    目的 本文设计的跨链数据互认证机制,旨在实现现实生活中的:一个系统上的数据能够得到另一个系统上节点的承认,保证完整且不被篡改;如果发生数据造假,能够追溯数据来源,问责对应的人。
    方法 本文聚焦数据互认证场景,由需要认证的区块链提供的节点构建一个联盟区块链。联盟区块链上传递互认证数据的加密摘要和链上证明。参与联盟的区块链自己选择加入联盟区块链的节点,当节点作恶时,仍然可以保证互认证数据的安全性。针对数据互认证场景中数据造假问题,智能合约能够在数据出现问题时,及时撤销数据,并追责相关数据的处理人。
    结果 实验验证了本工作相比于其他跨链方法,在性能相似的情况下的 安全性的巨大优势;本文的追溯问责机制,能够及时有效解决恶意节点问题,恶意节点初始下降和最终收敛速度远胜于其他方案;本文验证机制能够在同构和异构链运行,并行优化可以将运行时间减半。
    结论 本文运用区块链以及跨链技术,聚焦数据跨链的互认证问题,实现一种跨链数据认证机制。机制建立在云际计算背景上,打通不同云服务域的数据壁垒,使不同利益主体间能够做到跨域数据互信。同时利用智能合约,提供了追溯问责和高效惩罚的方法,让虚假数据的背书人及时得到惩罚,让所有节点能够及时撤销虚假数据并消除其影响。实验结果表明,该机制在保持相同性能的同时,提供了更高的安全性和稳定性。

     

    Abstract: JointCloud computing is a new computing paradigm that supports cloud services to achieve mutually beneficial outcomes. A key component of this model is the JointCloud computing distributed ledger, which ensures trust among cloud entities with diverse interests by providing digital space evidence. Blockchain forms the foundation of this framework, and its adoption is growing in various fields to optimize workflows. However, challenges related to blockchain interoperability and cross-chain data authentication remain unresolved, hindering the broader establishment of trust among cloud entities. This paper focuses on the specific scenario of cross-chain data authentication and provides a secure and easy-to-deploy solution. Drawing on the concepts of relay chain and notary mechanism in cross-chain methods, our solution leverages smart contracts and on-chain proofs to ensure security, thereby reducing the reliance on relay nodes. In cases of data falsification, our method offers mechanisms for accountability and data revocation, further enhancing security. Additionally, participating blockchains do not need to alter their data structures or network compositions for authentication, which makes the solution easy to deploy. Experimental results demonstrate that our design can be easily deployed on both homogeneous and heterogeneous blockchains. While maintaining performance comparable to existing solutions, it significantly enhances system security. In the event of data falsification, the solution can quickly hold individuals accountable and eliminate the impact of falsified data, reducing the time to mitigate the impact by half compared with other solutions.

     

/

返回文章
返回