A method for improving the security of blockchain-based cross-domain authentication
Lingrui Kong, Jizhi Wang, Yue Zhao, Tongtong Sui · 2024
At present, information security has become an indispensable technical foundation in the development of network security, and identity authentication is an important mechanism for guaranteeing network information security. Since the resources in an organizational domain are always limited, users need to make cross-domain access to resources. Most of the existing blockchain-based cross-domain authentication mechanisms require visitors to provide specific account passwords, which requires users to accurately remember the specific accounts and passwords of each organizational domain if they want to access multiple organizational domains for resource access, which brings a great deal of trouble to cross-domain access efforts. The traditional single sign-on (SSO) can log in multiple website systems through a single account password, but there is also the risk of account leakage, OAuth2.0 is a good solution to the problem of account password leakage. The difference between OAuth2.0 and traditional authorization methods is that it does not allow third parties to access information related to logged-in user accounts (such as user names and passwords), so OAuth2.0 is safe and reliable. In addition, the traditional border-based Internet network security architecture is weak in its ability to supervise the internal network security, and once the network security border has been breached, the internal information is very easy to be attacked and stolen, resulting in data leakage and loss. Based on blockchain combined with OAuth2.0 and risk assessment technology, we propose a method for improving the security of blockchain-based cross-domain authentication, which can solve the problem of leaking passwords of user-related accounts through OAuth2.0, and conduct risk assessment of users through a one-level fuzzy three-dimensional risk matrix method, and set a risk level for the user according to the assessment results, and assess the accounts that have risk threats. Face recognition is performed on users with risk threats, and the user's risk level is reduced if the recognition passes, and the user is forced to quit the domain if the recognition fails, which further strengthens the security of the system.