Blockchain-based digital product access method and device, electronic equipment and computer readable storage medium

Through blockchain technology and zero-knowledge proof, combined with smart contracts and decentralized storage, it solves the security and privacy protection issues of user key management in a decentralized environment, realizes the trusted storage and rapid access of user keys, and is suitable for digital copyright and financial business processing.

CN115865447BActive Publication Date: 2025-10-10INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211479709.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-24
Publication Date
2025-10-10
Estimated Expiration
2042-11-24

AI Technical Summary

Technical Problem

In a decentralized environment of distrust, existing user key management methods pose security risks, centralized systems are prone to single point failures, and third-party hosting poses privacy and security risks, making it difficult to effectively protect the security and privacy of user keys.

Method used

Using blockchain technology, through smart contracts and zero-knowledge proof, a decentralized key security operation framework is established. By utilizing the multi-party sharing and trusted evidence storage characteristics of blockchain, user identity authentication and permission control are carried out to ensure the secure storage and privacy protection of user keys.

Benefits of technology

It realizes the secure storage and privacy protection of user keys in a decentralized environment, ensures the credible evidence and rapid response of user key access rights, solves the security and privacy protection problems of user key management, and is suitable for digital copyright and financial business processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115865447B_ABST
    Figure CN115865447B_ABST
Patent Text Reader

Abstract

The application provides a kind of based on blockchain digital product access method and device, can be used in blockchain technical field, method includes: in response to the digital product access request sent by user, according to the identity identifier of this user, judge whether it has access authority;When the user has the access authority, the storage directory corresponding to the digital product access request is inquired in the decentralized storage network;The digital product is stored in the decentralized storage network;Query result is sent to the user by the decentralized storage network.The based on blockchain digital product access method and device provided by the application effectively solve the security and privacy protection problem of decentralized distributed user key access and operation, can be widely applied in digital copyright, financial business processing and other business scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer data processing, in particular to the field of blockchain technology, and more particularly to a digital product access method and device based on blockchain. BACKGROUND

[0002] With the increasing emphasis on the security of data usage by all sectors, users publishing digital works and self-disposing have gradually become a new development trend. The management of user digital works mainly involves the copyright and security management of data in a decentralized environment. The core technology is how to ensure the secure management and privacy protection of user keys in an untrusted environment to meet the copyright and security management needs of user digital work authentication, transfer and right seeking. In recent years, there are generally two ways to manage user keys. One is for users to manage keys by themselves through mobile devices. This method is simple to use and flexible, but the keys are not easy to recover after being lost, and the privacy protection effect is poor. The other is to entrust user keys to a third-party agency. This method has good privacy and scalability, but there is a risk of misuse of user keys. Therefore, it is urgent to propose a more secure and efficient user key management method for a decentralized untrusted environment.

[0003] The third-party agency key management technology generally adopts a centralized system to build a closed and trusted key storage environment. In order to obtain key access services, users first authenticate their identities to the third party, and then the third party manipulates user keys to handle digital works on behalf of the users. The disadvantage of this technology is that there is a high security risk. First, centralized processing is prone to system single points, and once the system crashes, it will affect user services. Second, the key management agency has complete control authority, and may illegally operate user digital works or steal them without the user's permission.

[0004] In summary, in a decentralized untrusted environment, there are not many user self-management key management methods. In order to achieve enterprise-level trusted user key security functions, there is still a lot of room for improvement in the privacy and security of key management. SUMMARY

[0005] The digital product access method and device based on blockchain provided by the present application effectively solve the security and privacy protection problems of decentralized and dispersed user key access and operation, and can be widely applied in business scenarios such as digital copyright and financial business processing.

[0006] In order to achieve the above purpose, one aspect of the present application discloses a digital product access method suitable for a blockchain network, which comprises:

[0007] In response to a digital product access request sent by a user, it is judged whether the user has access rights according to the user's identity identifier;

[0008] When the user has the access right, querying a storage directory corresponding to the digital product access request in a decentralized storage network; the decentralized storage network stores the digital product;

[0009] The query result is sent to the user through the decentralized storage network.

[0010] In one embodiment, determining whether the user has access rights based on the user's identity identifier includes:

[0011] Generate a user certificate based on the identity identifier and upload the user certificate to the local blockchain network;

[0012] It is determined whether the user has the access authority according to the access request and the user certificate.

[0013] In one embodiment, generating a user certificate based on the identity identifier includes:

[0014] A smart contract execution unit is used to execute the smart contract corresponding to the identity identifier according to the security parameters uploaded by the user to generate the user certificate.

[0015] In one embodiment, the user's identity identifier, the user's secret key's identity identifier, and the local blockchain node's identity identifier are unique within the local blockchain network.

[0016] On the other hand, the present invention also provides a method for accessing digital products applicable to a user terminal, the method comprising:

[0017] Send a digital product access request to the blockchain network;

[0018] Receiving a result of the blockchain network processing the request for access to the digital product;

[0019] When the processing result is that the user has access rights to the digital product, the user accesses the digital product on the decentralized storage network according to the storage directory sent by the blockchain network.

[0020] In one embodiment, the blockchain-based digital product access method further includes:

[0021] Generate public and private keys based on your own identity identifier;

[0022] Generate security parameters based on the public key and private key, and upload the security parameters to the blockchain network.

[0023] Correspondingly, the present invention also discloses a blockchain-based digital product access device applicable to a blockchain network, the device comprising:

[0024] an access rights determination module, configured to respond to a digital product access request sent by a user and determine whether the user has access rights based on the user's identity identifier;

[0025] a storage directory query module, configured to query a storage directory corresponding to the digital product access request in a decentralized storage network when the user has the access authority; the decentralized storage network stores the digital product;

[0026] The query result sending module is used to send the query result to the user through the decentralized storage network.

[0027] In one embodiment, the access permission determination module includes:

[0028] A user certificate generating unit, configured to generate a user certificate based on the identity identifier and upload the user certificate to a local blockchain network;

[0029] The access permission determination unit is configured to determine whether the user has the access permission according to the access request and the user certificate.

[0030] In one embodiment, the user certificate generation unit includes:

[0031] The smart contract corresponding to the identity identifier is executed according to the security parameters uploaded by the user to generate the user certificate.

[0032] In one embodiment, the user's identity identifier, the user's secret key's identity identifier, and the local blockchain node's identity identifier are unique within the local blockchain network.

[0033] Correspondingly, the present invention also discloses a blockchain-based digital product access device applicable to a user terminal, the device comprising:

[0034] An access request sending module, used to send digital product access requests to the blockchain network;

[0035] A processing result receiving module, configured to receive a processing result of the blockchain network for the digital product access request;

[0036] A digital product access module is configured to access the digital product on a decentralized storage network according to a storage directory sent by the blockchain network when the processing result indicates that the user has access rights to the digital product.

[0037] In one embodiment, the blockchain-based digital product access device applicable to a user terminal further includes:

[0038] The key generation module is used to generate public and private keys based on its own identity identifier;

[0039] A security parameter generation module is used to generate security parameters based on the public key and the private key, and upload the security parameters to the blockchain network.

[0040] The present invention also discloses a blockchain node, which is configured to respond to a digital product access request sent by a user and determine whether the user has access rights based on the user's identity identifier; when the user has the access rights, query the storage directory corresponding to the digital product access request in a decentralized storage network; the decentralized storage network stores the digital product; and send the query result to the user via the decentralized storage network.

[0041] The present invention also discloses an electronic device, comprising a memory, a processor, and a computer program stored in the memory and runnable on the processor. When the processor executes the program, the steps of the blockchain-based digital product access method are implemented.

[0042] The present invention also discloses a computer-readable medium on which a computer program is stored. When the program is executed by a processor, the method described above is implemented.

[0043] From the above description, it can be seen that, first, an embodiment of the present invention provides a blockchain-based digital product access method applicable to a blockchain network, the method comprising: first, responding to a digital product access request sent by a user, determining whether the user has access rights based on the user's identity identifier; then, when the user has access rights, querying the storage directory corresponding to the digital product access request in a decentralized storage network; the decentralized storage network stores the digital product; and finally, sending the query result to the user through the decentralized storage network.

[0044] Secondly, an embodiment of the present invention also provides a blockchain-based digital product access method applicable to a user terminal, the method comprising: first, sending a digital product access request to a blockchain network; then, receiving a processing result of the blockchain network for the digital product access request; finally, when the processing result is that the user has access rights to access the digital product, accessing the digital product in a decentralized storage network according to the storage directory sent by the blockchain network.

[0045] The present invention solves the problems of secure storage and privacy protection of user keys in decentralized systems, establishes a decentralized key security operation framework, and introduces zero-knowledge proof and digital authentication to verify user identity and operation processing based on blockchain technology. When a user makes a digital product operation request, the blockchain smart contract is called to perform user authority control and identity verification, and the operation proof is verified with the zero-knowledge proof algorithm on the blockchain, so that the access operation is executed according to the authentication result. By utilizing the characteristics of blockchain multi-party sharing, trusted evidence storage and zero-knowledge proof, user key access rights are stored on the blockchain network to ensure that the permission table can be obtained and accessed by the nearest storage node. The present invention innovatively introduces zero-knowledge proof and distributed user identity, and verifies the operation of user keys, effectively solving the security and privacy protection problems of decentralized and distributed user key access and operation, and can be widely used in business scenarios such as digital copyright and financial business processing. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0047] Figure 1 Schematic diagram of the flow of a blockchain-based digital product access method in an embodiment of the present invention (applicable to blockchain networks);

[0048] Figure 2 This is a flowchart of step 200 of the blockchain-based file transmission method in an embodiment of the present invention;

[0049] Figure 3 This is a flowchart of step 201 of the blockchain-based file transmission method in an embodiment of the present invention;

[0050] Figure 4 Schematic diagram of the process of the blockchain-based digital product access method in an embodiment of the present invention Figure 1 (applicable to user side);

[0051] Figure 5 Schematic diagram of the process of the blockchain-based digital product access method in an embodiment of the present invention Figure 2 (applicable to user side);

[0052] Figure 6 This is a scenario structure diagram of a blockchain-based digital product access system in a specific embodiment of the present invention;

[0053] Figure 7This is a hierarchical structure diagram of a blockchain-based digital product access system in a specific embodiment of the present invention.

[0054] Figure 8 This is a diagram showing the service gateway node structure of a blockchain-based digital product access system in a specific embodiment of the present invention;

[0055] Figure 9 This is a DS node structure diagram based on blockchain in a specific embodiment of the present invention

[0056] Figure 10 A block chain node structure diagram based on a block chain in a specific embodiment of the present invention;

[0057] Figure 11 This is a flowchart of a blockchain-based digital product access system in a specific embodiment of the present invention;

[0058] Figure 12 A diagram of a blockchain-based digital product access device in an embodiment of the present invention (applicable to a blockchain network);

[0059] Figure 13 This is a block diagram of the access permission determination module 30 of the blockchain-based digital product access device in an embodiment of the present invention;

[0060] Figure 14 This is a block diagram of a user proof generation unit 301 of a blockchain-based digital product access device in an embodiment of the present invention;

[0061] Figure 15 A digital product access device based on blockchain in an embodiment of the present invention Figure 1 (applicable to user side);

[0062] Figure 16 A digital product access device based on blockchain in an embodiment of the present invention Figure 2 (applicable to user side);

[0063] Figure 17 Schematic diagram of the structure of an electronic device in an embodiment of the present invention. DETAILED DESCRIPTION

[0064] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0065] It should be noted that the blockchain-based digital product access method and device disclosed in this application can be used in the field of artificial intelligence technology, and can also be used in any field other than the field of artificial intelligence technology. The application field of the blockchain-based digital product access method and device disclosed in this application is not limited.

[0066] To facilitate understanding of the technical solutions provided by this application, the relevant contents of the technical solutions of this application are first described below. The blockchain-based digital product access method provided by the embodiment of the present invention establishes a decentralized key security operation framework, introduces zero-knowledge proof and digital authentication user identity and operation processing based on blockchain technology. When a user makes a digital product operation request, the blockchain smart contract is called to perform user authority control and identity verification, and the operation proof is verified with the zero-knowledge proof algorithm on the blockchain, so that the access operation is executed according to the authentication result. Utilizing the characteristics of blockchain multi-party sharing, trusted evidence storage and zero-knowledge proof, user key access rights are stored on the blockchain network to ensure that the permission table can be obtained and accessed by the nearest storage node. The present invention innovatively introduces zero-knowledge proof and distributed user identity, and verifies the operation of user keys, effectively solving the security and privacy protection problems of decentralized and distributed user key access and operation, and can be widely used in business scenarios such as digital copyright and financial business processing.

[0067] The acquisition, storage, use, and processing of data in this application's technical solution comply with relevant national laws and regulations.

[0068] According to one aspect of the present invention, this embodiment discloses a blockchain-based digital product access method applicable to a blockchain network. Figure 1 As shown, in this embodiment, the method includes:

[0069] Step 100: In response to a digital product access request sent by a user, determining whether the user has access rights based on the user's identity identifier;

[0070] In the present invention, all blockchain nodes, users, and key entities (fragments) have a globally unique digital identity identifier (ID), which refers to the identifiable portrayal of an individual through digital information, and the condensation of real identity information into a public / private key in the form of a digital code, so that the individual's behavior information can be bound, queried, and verified.

[0071] Step 200: When the user has the access authority, query the storage directory corresponding to the digital product access request in the decentralized storage network; the decentralized storage network stores the digital product;

[0072] First, digital products are stored across multiple independent devices in a decentralized, untrusted network environment. This breaks the monopoly of centralized storage, addresses the bottleneck of single storage servers becoming system performance bottlenecks, and meets the need for more secure, reliable, and controllable storage. Furthermore, decentralized storage networks are responsible for decentralized file reading and writing, and transaction information is stored on blockchain nodes.

[0073] Step 300: Send the query result to the user via the decentralized storage network.

[0074] The decentralized storage network in step 300 is responsible for configuring parameters, data, business logic, etc. through distributed storage logic according to the upload (download), query and other requests submitted by the client, and encrypting the file block data at the same time, and broadcasting its hash value to the blockchain network.

[0075] In one embodiment, see Figure 2 , step 200 includes:

[0076] Step 201: Generate a user certificate based on the identity identifier and upload the user certificate to the local blockchain network;

[0077] Specifically, the embodiment of the present invention uses the GenWitness function to generate user proof: GenWitness is a function that generates user proof, which is formally expressed as:

[0078] GenWitness(Params,v,C)→w

[0079] Where v∈C represents the operation that the user wants to prove, C is the set of user operations, and w represents the generated proof. Formally:

[0080] w=Accumulate(Params,C\{v})

[0081] C\{v} represents the set of C operations that exclude v.

[0082] Step 202: Determine whether the user has the access permission based on the access request and the user certificate.

[0083] Specifically, the embodiment of the present invention uses the Verify function to determine whether the user has access rights:

[0084] Verify represents a function that verifies user proof, in the form of:

[0085] Verify(Params,A,v,w)→{0,1}

[0086] Where, Params = (N,u), if the calculated value A′≡A=w v, then output 1, indicating that the verification of the user certificate is successful, otherwise output 0, indicating that the verification failed.

[0087] In one embodiment, see Figure 3 , step 201 includes:

[0088] Step 2011: Execute the smart contract corresponding to the identity identifier according to the security parameters uploaded by the user to generate the user certificate.

[0089] First, the user generates security parameters according to the following method and uploads them to the blockchain. The blockchain executes the corresponding smart contract to generate user proof

[0090] Setup is a function that initializes and sets security parameters. In form:

[0091] Setup(λ)→Params

[0092] The input is a security parameter, and the output is a global public parameter params. The public parameters in this case are Params = (p, q, u), where p and q are large prime numbers, and u≠1 represents a rational integer less than N.

[0093] In one embodiment, the user's identity identifier, the user's secret key's identity identifier, and the local blockchain node's identity identifier are unique within the local blockchain network.

[0094] In a blockchain network, all nodes, users, and key entities (fragments) have a globally unique digital identity identifier (DID). DID complies with the W3C DID specification and is formally represented as:

[0095] DID={id|id="did":"method-name":"{0,1} * "}

[0096] Where method-name indicates the domain where the DID is located, {0,1} * A 256-bit identification number, a globally unique string calculated from the method-name field. DIDs are the digital identities of nodes and users within a blockchain network. They are synchronized to consensus nodes and stored in blocks. Blockchain networks offer smart contracts and interactive services for users.

[0097] In a preferred embodiment, Figure 4 As shown, the present invention also provides a blockchain-based digital product access method applicable to a user terminal, which includes:

[0098] Step A: Send a digital product access request to the blockchain network;

[0099] It should be noted that in steps 100 to 300 and steps A to B, client A and client B respectively access the DS node through service gateway 1, and will issue a file reading request through the DS node and receive the file reading result.

[0100] Step B: receiving the processing result of the digital product access request of the blockchain network;

[0101] Step C: when the processing result is that the access right to access the digital product is possessed, according to the storage directory sent by the blockchain network, the digital product is accessed in the decentralized storage network.

[0102] In step B and step C, the blockchain executes the smart contract to query the file directory list related to the user identifier (DID), and returns the client, then the DS node executes the query file directory list operation and returns the user file directory list. The client displays the file directory list, and the client receives the successful return of the file directory list information.

[0103] In an embodiment, referring to Figure 5 , the user-end-based blockchain-based digital product access method further comprises:

[0104] Step D: generating a public key and a private key according to the own identifier;

[0105] Specifically, the user end calls the key generation sdk to generate asymmetric user public key and private key (pk u ,sk u ), and the private key sk u is stored in the local storage of the client.

[0106] Step E: generating a security parameter according to the public key and the private key, and uploading the security parameter to the blockchain network.

[0107] On the basis of step E, the public key pk u is processed for on-chain. Then, a security parameter is generated according to the public key and the private key, and the security parameter is uploaded to the blockchain network. The user public key pk u , distributed digital identity DID, call the blockchain smart contract interface to initialize the security parameter. Receive and check the initialization security parameter request. Execute the Setup smart contract to realize the security parameter setting, and generate params, in form:

[0108] Setup (λ)→Params

[0109] The input is the security parameter, and the output is the global public parameter params. In this case, the public parameters are Params = (p, q, u), where p and q are large prime numbers, and u≠1 represents a rational integer less than N. Finally, Params = (N, u) is stored on the chain as the global security parameter, where N = pq.

[0110] In a specific embodiment, the present invention also provides a specific embodiment of a blockchain-based digital product access method, which specifically includes the following contents.

[0111] Brief introduction to terminology:

[0112] Blockchain: A shared accounting solution that uses cryptography to ensure access security, P2P communication technology to achieve peer-to-peer communication, a consensus mechanism to ensure the legitimacy of accounting, and a chain structure to store data to achieve tamper-proof common accounting.

[0113] Zero-knowledge proof: A protocol involving two or more parties, specifically a series of steps taken by two or more parties to complete a task. The prover proves to the verifier that they know or possess a certain piece of information, but the proof cannot reveal any information about the information being proven to the verifier.

[0114] Digital Identity: refers to the use of digital information to depict an individual's identifiable identity, condensing real identity information into public / private keys in the form of digital codes, so that the individual's behavioral information can be bound, queried, and verified.

[0115] Decentralized storage: refers to the storage of data on multiple independent devices in a decentralized, untrusted network environment, breaking the monopoly of centralized storage, solving the problem of a single storage server becoming a bottleneck for system performance, and meeting the needs of more secure, reliable, and controllable storage.

[0116] See also Figure 6 The specific embodiment of the present invention first provides a digital product access system based on blockchain, which includes: client 0, service gateway 1, DS node 2, blockchain node 3, holder 4, and receiver 5.

[0117] Client 0: Mainly responsible for initiating smart contract deployment requests, decentralized storage transaction requests, decentralized storage query requests, etc.

[0118] Service Gateway 1: Mainly responsible for providing smart contract APIs, implementing current limiting and circuit breaking, security detection, user operation permission verification and access, identity authentication and security parameter settings, etc.

[0119] DS Node 2: This is a decentralized storage node responsible for receiving file read and write requests from Service Gateway 1, performing distributed file read and write operations, and storing transaction information on the blockchain node. Client A and Client B of the present invention each access the DS node through Service Gateway 1, issuing file read requests through the DS node and receiving file read results.

[0120] Blockchain Node 3 performs transaction broadcasting, transaction execution, transaction verification, consensus, and storage. It possesses the general characteristics of a blockchain. File read commands are initiated by the client, and transaction records after the execution of the smart contract that stores file read and write evidence are also stored on the blockchain.

[0121] Holder 4: Initiates security parameter initialization, holds user keys, registers digital identity DID on the blockchain network, uploads digital files as the digital copyright owner, and provides digital file rights confirmation operations.

[0122] Receiver 5: The recipient of the digital file, who makes an access request to the holder 4 to obtain access rights, and receives and accesses the digital file.

[0123] On the other hand, the hierarchical structure diagram of the blockchain-based digital product access system is as follows: Figure 7 As shown, it includes a client access layer 20, a service gateway layer 21, a decentralized file storage network 22, and a blockchain network 23.

[0124] Client Access Layer 20: Responsible for providing operator access to client software, facilitating the initiation of distributed storage requests and the receipt of distributed storage results. Clients can publish smart contracts (chaincodes) on the blockchain platform. After generating upload or download behavior data, clients can invoke chaincodes to initiate transaction requests, upload the behavior data to the chain, and submit it to the corresponding channels for each scenario based on the client's usage scenario. (Clients can directly upload customer behavior data without processing; the specific data processing logic can be implemented by the scenario provider.) Providers can also publish chaincodes to query data belonging to their own channels and perform data processing and analysis on their own channels.

[0125] Gateway Service Layer 21: Responsible for providing blockchain smart contract service APIs to clients, implementing transaction flow limiting and circuit breaking, user operation submission and verification, DS node file upload and download, CID (content identifier) ​​generation, and implementing DID (decentralized digital identity) registration, verification, directory query and update, and other smart contract function calls.

[0126] Decentralized File Storage Network 22: Based on client upload (download) and query requests, it configures parameters, data, and business logic through distributed storage logic. It also encrypts the file blocks and broadcasts their hash values ​​to the blockchain network 23. Scenario providers can also publish joint operation chaincodes, which invoke DS node services. Each blockchain node has a corresponding DS node service, and the chaincode specifies which DS services are required for joint computation. Scenario providers initiate joint computation requests through chaincodes. Providers in other channels are previously inaccessible to each other's data. DS allows for decentralized data storage without leaking any of their own data.

[0127] Blockchain Network 23: Responsible for receiving and decrypting distributed file storage messages, triggering pre-defined smart contract logic, and generating distributed storage log results. The blockchain network provides managed nodes and, for capable providers, local node deployment. Each scenario provider has its own channel on the blockchain, and scenario providers cannot access data from other channels, or from other providers.

[0128] See also Figure 8 The service gateway node structure diagram of the blockchain-based digital product access system is shown in the figure. Its main technical structure includes a communication module 31, a current limiting and fuse module 32, a security authentication module 33, and an API service interface 34.

[0129] Communication module 31: responsible for establishing a secure channel for the service gateway node to realize the sending and receiving of messages such as decentralized file storage, user operation requests, and initialization of security parameters.

[0130] Current limiting and circuit breaker module 32: responsible for transaction current limiting and circuit breaker control based on transaction throughput configuration.

[0131] Security authentication module 33: responsible for keeping the user's private key and symmetric key, managing the user's digital identity DID; responsible for calling the security interface API provided by the blockchain network to realize user identity registration, authentication, and encryption and decryption of confidential files.

[0132] API service interface 34: Responsible for providing a series of smart contract API interface services such as blockchain DS storage and privacy security processing, including the encapsulation interface of 4 functions (Setup, Accumulate, Genwitness, Verify):

[0133] Third, if Figure 9 As shown, the present invention also provides a DS node structure diagram, whose main technical structure includes a communication module 41, a content generation module 42, a DAG module 43, and a Chunk module 44.

[0134] Communication module 21: responsible for establishing a secure channel for DS node 2 to realize distributed storage message sending and receiving.

[0135] Content generation module 22: responsible for generating CID processing for decentralized file content.

[0136] Set FileLink M The data format indicating the link to file M is:

[0137] FileLink M =(Cid,Size,FileObj{Links,data M},chksum)

[0138] Among them, Size represents the size of file M, FileObj represents the file object structure, Links represents the link array of file fragments, data M Indicates the data content of M, Cid indicates the content address information, in the form:

[0139] Cid=h(M,Did1,...,Did n )

[0140] Where h is the hash function, Did1, Did2, ...., Did n Indicates the digital identity group that owns file M.

[0141] DAG module 44: responsible for performing Merkle check on the content address Cid to ensure that the Cid of the root node is equal to the calculated digest hash.

[0142] Chunk module 45: Chunks the file object data content and ensures that the fragmented data are connected to each other to form a file object tree.

[0143] The blockchain node structure diagram involved in the present invention is as follows Figure 10 As shown, the technical structure of the blockchain node 5 includes: a communication module 51, a transaction processing module 52, a smart contract module 53, and a consensus verification module 54.

[0144] Communication module 51: responsible for the communication interaction between nodes, completing general blockchain node communication information, including transaction information broadcast, consensus-related information, block synchronization information, network status information, etc.

[0145] Transaction processing module 52: responsible for receiving transaction requests, generating a unique transaction identifier, assembling the unique transaction identifier, contract unique identifier and call parameters into a transaction, and broadcasting it to other nodes in the blockchain.

[0146] Smart Contract Module 53: Responsible for receiving transaction requests from Communication Module 52, obtaining calculation results through distributed storage, making judgments based on preset business logic, and submitting the final transaction instructions to Transaction Processing Module 52 for execution via Communication Module 51. The service gateway of the present invention invokes smart contract transactions, receives information from Transaction Processing Module 52, and stores it in the blockchain network. The main operations performed include four functions (Setup, Accumulate, Genwitness, Verify):

[0147] 1. Setup

[0148] Setup is a function that initializes and sets security parameters. In form:

[0149] Setup(λ)→Params

[0150] The input is a security parameter, and the output is a global public parameter params. The public parameters in this case are Params = (p, q, u), where p and q are large prime numbers, and u≠1 represents a rational integer less than N.

[0151] 2. Accumulate

[0152] The accumulation function is used to define the function that generates a set of secret state operations. In form:

[0153] Accumulate(Params,C)→A

[0154] Among them, Params is a security parameter, C = (transfer, download, prove, empower..) represents the user's operation set, transfer represents uploading (digital works), download represents downloading (digital works), prove represents confirmation of ownership, and empower represents empowerment. For the convenience of calculation, the above operation set is assigned a large prime value, which is less than N. Therefore, C is formally expressed as: C = {c1, c2, ..., c i |c i <pq=N}. A is the result of the dense state calculation, in the form:

[0155] A=u c1c2...ci mod N

[0156] 3. GenWitness

[0157] GenWitness is a function that generates user proofs, which is formally expressed as:

[0158] GenWitness(Params,v,C)→w

[0159] Where v∈C represents the operation that the user wants to prove, C is the set of user operations, and w represents the generated proof. Formally:

[0160] w=Accumulate(Params,C\{v})

[0161] C\{v} represents the set of C operations that exclude v.

[0162] 4. Verify

[0163] Verify represents a function that verifies user proof, in the form of:

[0164] Verify(Params,A,v,w)→{0,1}

[0165] Where, Params = (N,u), if the calculated value A′≡A=w v , then output 1, indicating that the verification of the user certificate is successful, otherwise output 0, indicating that the verification failed.

[0166] Consensus verification module 54: responsible for consensus processing of received transaction requests. If consensus is reached, it calls the smart contract module 53, executes the smart contract, and finally forms a record for future audit tracing or verification.

[0167] See also Figure 11 Based on the above-mentioned blockchain-based digital product access system and its internal sub-module structure, the blockchain-based digital product access method provided by the specific embodiment of the present invention includes the following steps: initializing security parameters, uploading file data, and accessing file data in three stages:

[0168] Phase 1: Initialize security parameters.

[0169] Step S601: The user submits a request for initializing security parameters through the client;

[0170] Step S602: After receiving the request, the client calls the key generation SDK to generate an asymmetric user public key and private key (pk u ,sk u ), private key sk u Stored locally on the client, the public key pk u Upload to the service gateway and process it on the chain through the service gateway.

[0171] Step S603: Enter the user's public key pk u , distributed digital identity DID, calls the blockchain smart contract interface to initialize security parameters.

[0172] Step S604: The transaction processing module receives and checks the request for initializing security parameters.

[0173] Step S605: Execute the Setup smart contract to implement security parameter settings and generate params, which is formally:

[0174] Setup(λ)→Params

[0175] The input is a security parameter, and the output is a global public parameter params. The public parameters in this case are Params = (p, q, u), where p and q are large prime numbers, and u≠1 represents a rational integer less than N.

[0176] Step S606: Store Params = (N,u) as the global security parameter on the chain, where N = pq.

[0177] Step S607: Send the security parameters back to the client.

[0178] Step S608: The security parameters are stored locally on the client.

[0179] Step S609: Return a message indicating that the security parameters have been successfully initialized.

[0180] Phase 2: Generate user proof.

[0181] Step S701: The user initiates a request to generate a user certificate through the client.

[0182] Step S702: Initiate a request to call a GenWitness function.

[0183] Step S703: Call the GenWitness API to upload security parameters (Params, v, C). Params is the security parameter, C = (transfer, download, prove, empower...) represents the user's operation set, transfer represents uploading (digital works), download represents downloading (digital works), prove represents the confirmation of ownership, and empower represents the empowerment. For the convenience of calculation, the above operation set is assigned a large prime value, which is less than N. Therefore, C is formally expressed as: C = {c1, c2, ..., c i |c i <pq=N}.

[0184] Step S704: The transaction processing module receives a request for initializing security parameters.

[0185] Step S705: Execute the GenWitness smart contract to generate a user certificate. This can be formally represented as:

[0186] GenWitness(Params,v,C)→w

[0187] Where v∈C represents the operation that the user wants to prove, C is the set of user operations, and w represents the generated proof. Formally:

[0188] w=Accumulate(Params,C\{v})

[0189] C\{v} represents the set of C operations that exclude v. Accumulate is an accumulation function used to define a function that generates a set of secret state operations. In form:

[0190] Accumulate(Params,C)→A

[0191] Among them, Params is a security parameter, C = (transfer, download, prove, empower..) represents the user's operation set, transfer represents uploading (digital works), download represents downloading (digital works), prove represents confirmation of ownership, and empower represents empowerment. For the convenience of calculation, the above operation set is assigned a large prime value, which is less than N. Therefore, C is formally expressed as: C = {c1, c2, ..., c i |c i <pq=N}. A is the result of the dense state calculation, in the form:

[0192] A=u c1c2...ci mod N

[0193] Step S706: Store the user certificate w on the chain.

[0194] Step S707: Send the return result indicating successful file upload to the client.

[0195] Phase 3: Verify user credentials.

[0196] Step S801: The user submits a file directory query access request through the client.

[0197] Step S802: The client extracts security parameters Params = (N, u) and submits a user certification verification application through the service gateway.

[0198] Step S803: The service gateway calls the blockchain smart contract API (Verify) to verify the legitimacy of the user certificate.

[0199] Step S804: The transaction processing module receives a request for initializing security parameters.

[0200] Step S805: Execute the Verify smart contract to verify whether the user certificate is legal.

[0201] Verify(Params,A,v,w)→{0,1}

[0202] Where, Params = (N,u), if the calculated value A′≡A=w v , then output 1, indicating that the verification of the user certificate is successful, otherwise output 0, indicating that the verification failed.

[0203] Step S806: Check whether the user certification verification is successful.

[0204] Step S807: If it fails, the client returns a verification failure message.

[0205] Step S808: System execution ends.

[0206] Step S809: Execute the smart contract to query the file directory list related to the user DID and return it to the client.

[0207] Step S810: The DS node performs a file directory list query operation and returns a user file directory list.

[0208] Step S811: The client displays a file directory list.

[0209] Step S812: The client successfully receives and returns the file directory list information.

[0210] From the above description, it can be seen that, first, an embodiment of the present invention provides a blockchain-based digital product access method applicable to a blockchain network, the method comprising: first, responding to a digital product access request sent by a user, determining whether the user has access rights based on the user's identity identifier; then, when the user has access rights, querying the storage directory corresponding to the digital product access request in a decentralized storage network; the decentralized storage network stores the digital product; and finally, sending the query result to the user through the decentralized storage network.

[0211] Secondly, an embodiment of the present invention also provides a blockchain-based digital product access method applicable to a user terminal, the method comprising: first, sending a digital product access request to a blockchain network; then, receiving a processing result of the blockchain network for the digital product access request; finally, when the processing result is that the user has access rights to access the digital product, accessing the digital product in a decentralized storage network according to the storage directory sent by the blockchain network.

[0212] In the present invention, by distributing digital products in a distributed storage file directory system, the data owner is responsible for the authenticity of the uploaded data files and can authorize the target user's access rights, and unauthorized users cannot access the data files. Specifically, the present invention introduces zero-knowledge proof and digital authentication based on blockchain technology to verify the identity and operation of users. When a user makes a digital product operation request, the blockchain smart contract is called to perform user authority control and identity verification, and the operation proof is verified with the zero-knowledge proof algorithm on the blockchain, so that the access operation is performed according to the authentication result. Utilizing the characteristics of blockchain multi-party sharing, trusted evidence storage and zero-knowledge proof, the user key access rights are stored on the blockchain network to ensure that the permission table can be obtained and accessed by the nearest storage node. The present invention innovatively introduces zero-knowledge proof and distributed user identity, and verifies the operation of user keys, effectively solving the security and privacy protection problems of decentralized and distributed user key access and operation, and can be widely used in business scenarios such as digital copyright and financial business processing. The beneficial effects of the present invention include:

[0213] 1. A blockchain-based key management system framework is proposed. This framework, combined with the blockchain network, supports data owners to initiate digital product operations using zero-knowledge proofs and provides users with a hosting mechanism for secure file upload and access.

[0214] 2. A user operation method based on zero-knowledge proof is proposed, which provides data owners with a series of secure and privacy-protected digital product operation services, and realizes security and privacy protection such as uploading, downloading, verification, and authorization of digital products.

[0215] 3. A trusted storage key management method is proposed. This method relies on the service gateway to store the user's private key. It does not directly expose the user's private key, but checks the legality of the operation based on the user's proof. It has the characteristics of high security and fast response speed.

[0216] Based on the same principle, see Figure 12 This embodiment further discloses a blockchain-based digital product access device applicable to a blockchain network, the device comprising:

[0217] The access permission determination module 10 is configured to respond to a digital product access request sent by a user and determine whether the user has access permission based on the user's identity identifier;

[0218] a storage directory query module 20, configured to query a storage directory corresponding to the digital product access request in a decentralized storage network when the user has the access authority; the decentralized storage network stores the digital product;

[0219] The query result sending module 30 is used to send the query result to the user through the decentralized storage network.

[0220] In one embodiment, see Figure 13 The access authority determination module 30 includes:

[0221] A user certificate generating unit 301 is configured to generate a user certificate based on the identity identifier and upload the user certificate to the local blockchain network;

[0222] The access permission determination unit 302 is configured to determine whether the user has the access permission according to the access request and the user certificate.

[0223] In one embodiment, see Figure 14 , the user certificate generation unit 301 includes:

[0224] The smart contract execution unit 3011 is used to execute the smart contract corresponding to the identity identifier according to the security parameters uploaded by the user to generate the user certificate.

[0225] In one embodiment, the user's identity identifier, the user's secret key's identity identifier, and the local blockchain node's identity identifier are unique within the local blockchain network.

[0226] For corresponding reference, see Figure 15 The present invention also discloses a blockchain-based digital product access device applicable to a user terminal, the device comprising:

[0227] Access request sending module A, used to send digital product access requests to the blockchain network;

[0228] A processing result receiving module B is used to receive the processing result of the blockchain network for the digital product access request;

[0229] The digital product access module C is configured to access the digital product on a decentralized storage network according to the storage directory sent by the blockchain network when the processing result indicates that the user has access rights to the digital product.

[0230] In one embodiment, see Figure 16 , the blockchain-based digital product access device applicable to the user side also includes:

[0231] The key generation module D is used to generate a public key and a private key based on its own identity identifier;

[0232] The security parameter generation module E is used to generate security parameters based on the public key and the private key, and upload the security parameters to the blockchain network.

[0233] Since the principle of solving the problem of the device is similar to the above method, the implementation of the device can be referred to the implementation of the method, which will not be repeated here.

[0234] From the above description, first of all, the embodiment of the application provides a blockchain-based digital product access device suitable for a blockchain network: first, in response to a digital product access request sent by a user, it is judged whether the user has access rights according to the user's identity identifier; then, when the user has access rights, the storage directory corresponding to the digital product access request is queried in the decentralized storage network; the decentralized storage network stores digital products; finally, the query result is sent to the user through the decentralized storage network.

[0235] Secondly, the embodiment of the application also provides a blockchain-based digital product access device suitable for a user end: first, send a digital product access request to a blockchain network; then, receive the processing result of the digital product access request by the blockchain network; finally, when the processing result is that the user has access rights to access the digital product, access the digital product in the decentralized storage network according to the storage directory sent by the blockchain network.

[0236] The application solves the problem of secure storage and privacy protection of user keys in a decentralized system, establishes a set of decentralized key security operation framework, introduces zero-knowledge proof and digital identity authentication based on blockchain technology to verify the identity and operation of the user. When the user proposes a digital product operation request, the blockchain smart contract is called for user permission control and identity verification, and the operation proof verification is performed with the zero-knowledge proof algorithm on the blockchain, so as to execute the access operation according to the authentication result. By using the characteristics of multi-party sharing, trusted evidence storage and zero-knowledge proof of the blockchain, the user key access permission is stored on the blockchain network, and it is ensured that the permission table can be obtained and accessed by the nearest storage node. The application innovatively introduces zero-knowledge proof and distributed user identity, and verifies the operation of the user key, effectively solves the security and privacy protection problem of decentralized and distributed user key access and operation, and can be widely applied in digital copyright, financial business processing and other business scenarios.

[0237] The system, device, module or unit illustrated in the above embodiments can be specifically implemented by a computer chip or entity, or by a product with certain functions. A typical implementation device is a computer device, specifically, the computer device may, for example, be a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0238] In a typical example, a computer device specifically includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, the method executed by the client as described above is implemented, or when the processor executes the program, the method executed by the server as described above is implemented.

[0239] Reference below Figure 17 , which shows a structural schematic diagram of a computer device suitable for implementing an embodiment of the present application.

[0240] like Figure 17 As shown, the computer device includes a central processing unit (CPU) 601, which can perform various appropriate tasks and processes according to the program stored in the read-only memory (ROM) 602 or the program loaded from the storage part 608 into the random access memory (RAM) 603. Various programs and data required for system operation are also stored in the RAM 603. The CPU 601, ROM 602, and RAM 603 are connected to each other via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.

[0241] The following components are connected to the I / O interface 605: an input section 606 including a keyboard, a mouse, and the like; an output section 607 including devices such as a cathode ray tube (CRT), a liquid crystal display (LCD), and a speaker; a storage section 608 including devices such as a hard disk; and a communication section 609 including a network interface card such as a LAN card or a modem. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the I / O interface 605 as needed. Removable media 611, such as a magnetic disk, an optical disk, a magneto-optical disk, or a semiconductor memory, is installed in the drive 610 as needed, so that computer programs read therefrom can be installed in the storage section 608 as needed.

[0242] In particular, according to embodiments of the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present invention include a computer program product comprising a computer program tangibly embodied on a machine-readable medium, the computer program including program code for executing the methods illustrated in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication portion 609 and / or installed from removable media 611.

[0243] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.

[0244] For the convenience of description, the above devices are described as being divided into various units according to their functions. Of course, when implementing this application, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0245] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0246] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0247] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0248] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.

[0249] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0250] The present application may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communications network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.

[0251] The various embodiments in this specification are described in a progressive manner. Similar parts between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences between the other embodiments. In particular, the system embodiments are generally similar to the method embodiments, so the description is relatively simple. For relevant parts, refer to the description of the method embodiments.

[0252] The foregoing is merely an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.

Claims

1. A blockchain-based digital product access method, characterized in that: include: In response to a digital product access request sent by a user, determining whether the user has access rights based on the user's identity identifier; When the user has the access right, querying a storage directory corresponding to the digital product access request in a decentralized storage network; the decentralized storage network stores the digital product; Sending the query results to the user via the decentralized storage network; Among them, the user's identity identifier, the user's secret key's identity identifier, and the local blockchain node's identity identifier are unique in the local blockchain network; Determining whether the user has access rights according to the user's identity identifier includes: Execute the smart contract corresponding to the user identity identifier based on the security parameters uploaded by the user to generate a user certificate, and upload the user certificate to the local blockchain network; determining whether the user has the access permission according to the access request and the user certificate; The security parameters are generated by the user according to his / her own identity identifier, and are obtained based on the public key and private key.

2. A blockchain-based digital product access method, characterized in that: include: Send a digital product access request to the blockchain network; Receiving a result of the blockchain network processing the request for access to the digital product; When the processing result indicates that the user has access rights to the digital product, the user accesses the digital product on the decentralized storage network according to the storage directory sent by the blockchain network; Among them, the user's identity identifier, the user's secret key's identity identifier, and the local blockchain node's identity identifier are unique in the local blockchain network; The method further comprises: Generate public and private keys based on your own identity identifier; Security parameters are generated based on the public key and the private key, and the security parameters are uploaded to the blockchain network, so that the blockchain network executes the smart contract corresponding to the user identity identifier according to the security parameters uploaded by the user to generate a user certificate, and determines whether the user has the access right based on the access request and the user certificate.

3. A digital product access device based on blockchain, characterized in that: include: an access rights determination module, configured to respond to a digital product access request sent by a user and determine whether the user has access rights based on the user's identity identifier; a storage directory query module, configured to query a storage directory corresponding to the digital product access request in a decentralized storage network when the user has the access authority; the decentralized storage network stores the digital product; A query result sending module, configured to send the query result to the user via the decentralized storage network; Among them, the user's identity identifier, the user's secret key's identity identifier, and the local blockchain node's identity identifier are unique in the local blockchain network; The device is further configured to execute a smart contract corresponding to a user identity identifier based on security parameters uploaded by the user to generate a user certificate, and upload the user certificate to a local blockchain network; and determine whether the user has the access rights based on the access request and the user certificate; The security parameters are generated by the user according to his / her own identity identifier, and are obtained based on the public key and private key.

4. A digital product access device based on blockchain, characterized in that: include: An access request sending module, used to send digital product access requests to the blockchain network; A processing result receiving module, configured to receive a processing result of the blockchain network for the digital product access request; a digital product access module, configured to, when the processing result indicates that the user has access rights to the digital product, access the digital product on a decentralized storage network according to the storage directory sent by the blockchain network; Among them, the user's identity identifier, the user's secret key's identity identifier, and the local blockchain node's identity identifier are unique in the local blockchain network; The device also includes: The key generation module is used to generate public and private keys based on its own identity identifier; A security parameter generation module is used to generate security parameters based on the public key and the private key, and upload the security parameters to the blockchain network, so that the blockchain network executes the smart contract corresponding to the user identity identifier based on the security parameters uploaded by the user to generate a user certificate, and determines whether the user has the access right based on the access request and the user certificate.

5. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the steps of the blockchain-based digital product access method according to any one of claims 1 to 2 are implemented.

6. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the blockchain-based digital product access method described in any one of claims 1 to 2 are implemented.

Citation Information

Patent Citations

  • Access authority control system and method based on block chain and SGX

    CN114465815A

  • File processing method and device, storage medium and electronic equipment

    CN115086337A

  • KR20220070921A