A blockchain supervision method and system supporting privacy protection
Through the committee mechanism and double asymmetric encryption technology, combined with blockchain smart contracts, the problem of balancing supervision and privacy protection in blockchain supervision is solved, and efficient and secure cloud computing data processing and transmission are achieved.
Patent Information
- Application Number
- CN202211649227.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-21
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2042-12-21
AI Technical Summary
Existing blockchain regulatory technologies are unable to balance regulation and privacy protection, and there are risks of single point failures and privacy data leakage, which cannot meet the needs of cloud computing.
Adopting a committee mechanism and double asymmetric encryption technology, privacy compliance checks are conducted through the Supervision and Privacy Protection Committee to ensure data privacy, and blockchain smart contracts are used for supervision and privacy protection to achieve secure data processing and transmission.
It achieves efficient supervision and privacy protection, reduces the risk of single point failure, ensures that data cannot be tampered with and is traceable, and improves the security and reliability of cloud computing.
Smart Images

Figure CN116232652B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of blockchain security, and in particular to a blockchain supervision method and system that supports privacy protection. Background Art
[0002] In the digital economy era, high-tech, represented by information technology, is advancing by leaps and bounds. Competition in comprehensive national strength, primarily measured by the level of informatization and the information industry, is becoming increasingly fierce. Information technology has become a fundamental driving force for economic and social development and transformation. As a new computing model, cloud computing, based on open collaboration among multiple cloud service entities, deeply integrates multi-party cloud resources, enabling developers to customize cloud services and create cloud value through a "software-defined" approach. This provides an effective technical means for promoting the building of a collaborative and mutually beneficial digital economy.
[0003] While informatization improves development models and enhances work efficiency, it also creates significant risks. In cloud computing, the involvement of multiple parties introduces complexity and uncertainty. Data falsification or tampering can lead to adverse consequences such as loss of profitability and a breakdown in trust. Leakage of critical data can severely impact the core competitiveness of service providers and infringe on the privacy rights of users. Therefore, all parties involved in cloud computing require both ongoing regulatory scrutiny and necessary privacy protections.
[0004] Traditional regulatory approaches typically rely on a centralized information exchange model based on simple and double-entry ledgers, with verification performed by a trusted third party. This approach has two major drawbacks: First, collusion. Third parties and service providers may collude for profit, allowing false certificates produced by service providers to pass verification. This makes it difficult for users to determine whether collusion exists. Second, single points of failure. Relying on an always-on third party is vulnerable to failures caused by unforeseen events, such as regional power outages and hacker attacks.
[0005] Blockchain is a decentralized, distributed information system that generates and stores data in blocks, linked end-to-end in chronological order. Cryptography ensures secure transmission and access, enabling consistent data storage and a decentralized, distributed record of information that is resistant to tampering, forgery, and repudiation. Applying blockchain technology to cloud computing can transform interactive sequences across stakeholders into "digital evidence" that is tamper-resistant, traceable, and supports regulation. This creates continuous transaction constraints and has the potential to support the development of efficient and reliable regulatory mechanisms for cloud computing. However, blockchain-based regulation is currently still in the theoretical research and practical exploration stages. While it allows for real-time and public verification, each participant must upload and download transaction data to verify integrity, at the expense of privacy. This is unacceptable for organizations that require confidentiality or comply with privacy regulations. Therefore, there is a need to explore blockchain technology that balances regulation and privacy protection.
[0006] Blockchain technologies that balance regulation and privacy protection can be divided into two categories: the first is to keep private data off-chain. This has the advantage that system functionality is not limited by blockchain performance bottlenecks, resulting in better scalability and higher efficiency. The disadvantage is that the storage and transmission of private data are centralized, relying on the strong assumption that key institutions do not act maliciously, and thus presenting a single point of failure. The second category is to keep private data on-chain. This has the advantage of a high degree of decentralization, allowing for the use of on-chain mechanisms such as committees to further balance decentralization and centralization, minimizing the impact of single points of failure. The disadvantage is that on-chain data requires strong encryption and introduces more on-chain load. Due to the significant performance bottlenecks of current blockchain technology, scalability and efficiency are constrained. Summary of the Invention
[0007] Technical problem to be solved by the present invention: In response to the above-mentioned problems of the prior art, a blockchain supervision method and system that supports privacy protection are provided. The present invention can realize the functions of supervision audit and privacy protection, and has the advantages of being difficult to tamper with, traceable, risk-resistant, and privacy-enhanced. It is of great significance for taking into account the needs of supervision and privacy protection and building an efficient and reliable cloud computing supervision mechanism.
[0008] In order to solve the above technical problems, the technical solution adopted by the present invention is:
[0009] A privacy-preserving blockchain governance approach that includes:
[0010] S101, the cloud service consumer CSC will encrypt the data d C ', encrypted private key sk C " and privacy requirements pr on the chain, where the encrypted private key sk C " is your own private key sk C Perform secondary asymmetric encryption to obtain;
[0011] S102, the cloud service provider CSP puts the privacy policy pp on the chain, and the cloud service provider CSP issues a request for encryption data d to the Supervision and Privacy Protection Committee C 'Decryption request;
[0012] S103, the blockchain runs a smart contract to perform a privacy compliance check based on the privacy requirement pr and the privacy policy pp;
[0013] S104, the Supervision and Privacy Protection Committee performs privacy control based on the results of the privacy compliance check. If the privacy compliance check passes, the encrypted private key sk C "Decrypted to the first encrypted private key sk C 'And send it to the cloud service provider CSP, jump to the next step; otherwise, return the problem of privacy policy pp to the cloud service provider CSP, jump to step S102;
[0014] S105, the cloud service provider CSP uses the first encryption private key sk C 'Encrypt the data d C 'Decrypted to data d C , for data d C Perform specified data processing to obtain processed data d P , and process the data d P Encryption is the encryption process data d P 'After uploading to the chain, the specified data processing refers to storage or calculation;
[0015] S106, cloud service consumer CSC downloads encrypted processed data through blockchain P ', decrypt to get the processed data d P .
[0016] Optionally, the encrypted data d in step S101 C 'Use your own public key pk for the cloud service consumer CSC C For data d C Encrypted to obtain.
[0017] Optionally, the encrypted private key sk in step S101 C "For cloud service consumers CSC, first use the public key pk of cloud service provider CSP P Your own private key sk C Perform the first encryption to obtain the first encrypted private key sk C '; then use the public key pk of the Regulatory and Privacy Protection Committee R The first encryption private key sk C 'Perform the second encryption to obtain.
[0018] Optionally, the privacy requirement pr in step S101 includes the cloud service consumer CSC’s explicit requirements for data d C your privacy interests and preferences.
[0019] Optionally, in step S103, the blockchain running smart contract performs a privacy compliance check based on the privacy requirement pr and the privacy policy pp, which means comparing the privacy requirement pr and the privacy policy pp. If the two match, the privacy compliance check is determined to be passed; otherwise, the privacy compliance check is determined to be failed.
[0020] Optionally, in step S104, the approval of the decryption request of the cloud service provider CSP includes: the Supervision and Privacy Protection Committee uses its own private key sk R Decrypt the encrypted private key sk C "Get the first encryption private key sk C ', and the first encrypted private key sk C 'Return to the cloud service provider CSP.
[0021] Optionally, in step S105, the encrypted data d P ' refers to the cloud service provider CSP using the public key pk of the cloud service consumer CSC C Processing data d P Encrypt and obtain encrypted data d P '; In step S106, decryption is performed to obtain the processed data d P It means that the cloud service consumer CSC uses the private key sk of the cloud service consumer CSC C Decrypt encrypted data d P 'Get data processing data d P .
[0022] Optionally, it also includes the digital space evidence formed by the Regulatory and Privacy Protection Committee based on the blockchain, which conducts regular supervision of the behavior of each participant through smart contracts, or conducts targeted audits of the behavior of specific parties as needed, and the results of supervision and audits are stored on the chain; the participants include cloud service consumers CSC and cloud service providers CSP.
[0023] In addition, the present invention also provides a blockchain supervision system that supports privacy protection, including a cloud service consumer CSC, a cloud service provider CSP, a supervision and privacy protection committee, and blockchain nodes composed of interconnected computer devices. The blockchain supervision system that supports privacy protection is programmed or configured to execute the steps of the blockchain supervision method that supports privacy protection.
[0024] In addition, the present invention also provides a computer-readable storage medium, which stores a computer program programmed or configured to execute the blockchain supervision method that supports privacy protection.
[0025] Compared with the prior art, the present invention mainly has the following advantages:
[0026] 1. This invention adopts a committee mechanism, through which the supervision and privacy protection committee compromises the centralization and decentralization of the system, and strikes a balance between the pursuit of efficient decision-making and the avoidance of single points of failure. At the same time, it makes full use of the characteristics of blockchain such as being difficult to tamper with and traceable, to improve the reliability of supervision and privacy protection.
[0027] 2. This invention supports cloud service consumers (CSC) and cloud service providers (CSP) to customize privacy requirements or privacy policies, and performs privacy compliance checks through on-chain smart contracts to achieve more accurate and efficient privacy protection.
[0028] 3. This invention adopts a "double encryption" approach to perform secondary asymmetric encryption on the key private key information on the chain, which ensures strong security while reducing the implementation difficulty compared to other complex encryption technologies. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] Figure 1 Schematic diagram of the principle of the method of embodiment 1 of the present invention. DETAILED DESCRIPTION
[0030] Example 1:
[0031] like Figure 1 As shown, the blockchain supervision method supporting privacy protection in this embodiment includes:
[0032] S101, the cloud service consumer CSC will encrypt the data d C ', encrypted private key sk C " and privacy requirements pr on the chain, where the encrypted private key sk C " is your own private key sk C Perform secondary asymmetric encryption to obtain;
[0033] S102, the cloud service provider CSP puts the privacy policy pp on the chain, and the cloud service provider CSP issues a request for encryption data d to the Supervision and Privacy Protection Committee C The cloud service provider (CSP) specifies the privacy permissions it needs to process data, expresses them in a standardized format in the privacy policy (pp), and submits the upstream privacy compliance check to the regulatory and privacy protection committee through a write transaction. It then sends a decryption request to the regulatory and privacy protection committee.
[0034] S103, the blockchain runs a smart contract to perform a privacy compliance check based on the privacy requirement pr and the privacy policy pp;
[0035] S104, the Supervision and Privacy Protection Committee performs privacy control based on the results of the privacy compliance check. If the privacy compliance check passes, the encrypted private key sk C "Decrypted to the first encrypted private key sk C 'And send it to the cloud service provider CSP, jump to the next step; otherwise, return the problem of privacy policy pp to the cloud service provider CSP, jump to step S102;
[0036] S105, the cloud service provider CSP uses the first encryption private key sk C 'Encrypt the data d C 'Decrypted to data d C , for data d C Perform specified data processing to obtain processed data d P , and process the data d P Encryption is the encryption process data d P 'After uploading to the chain, the specified data processing refers to storage or calculation;
[0037] S106, cloud service consumer CSC downloads encrypted processed data through blockchain P ', decrypt to get the processed data d P .
[0038] See also Figure 1 The privacy-supporting blockchain governance model involved in this embodiment comprises cloud service consumers (CSCs), cloud service providers (CSPs), a blockchain, and a governance and privacy committee. Cloud service consumers (CSCs) are the consumer side of cloud services, possessing raw data and requiring subscriptions to cloud services for processing (e.g., storage and computing). Cloud service providers (CSPs) are the supply side of cloud services, comprised of numerous cloud service providers. They provide consumers with the required cloud services under the unified scheduling and allocation of cloud computing. The blockchain in this embodiment is a consortium chain within cloud computing, comprised of qualified, identity-verified nodes. It implements transaction recording, data storage, and data flow, creating traceable, tamper-resistant, and traceable digital evidence. The governance and privacy committee is elected from blockchain nodes and is responsible for analyzing and making decisions regarding governance and privacy protection.
[0039] In this embodiment, the encrypted data d in step S101 C 'Use your own public key pk for the cloud service consumer CSC C For data d C Encrypted to obtain.
[0040] In this embodiment, the encrypted private key sk in step S101 C "For cloud service consumers CSC, first use the public key pk of cloud service provider CSP P Your own private key sk C Perform the first encryption to obtain the first encrypted private key sk C '; then use the public key pk of the Regulatory and Privacy Protection Committee R The first encryption private key sk C 'Perform the second encryption to obtain.
[0041] In this embodiment, the privacy requirement pr in step S101 includes the cloud service consumer CSC’s explicit request for data d C your privacy interests and preferences.
[0042] In this embodiment, in step S103, the blockchain-based smart contract performs a privacy compliance check based on the privacy requirement pr and the privacy policy pp. This means comparing the privacy requirement pr with the privacy policy pp. If they match, the privacy compliance check is considered passed; otherwise, the privacy compliance check is considered failed. The privacy requirement pr and privacy policy pp are described as follows: Consider a mobile phone user using a sports app as an example. The sports app cloud service provider (CSP) acts as the sports app, and the mobile phone user (user) acts as the cloud service consumer (CSC). Data interaction and a service supply-demand relationship exist between the two. Specifically, through a terminal device such as a smartwatch or wristband, the user provides the sports app with personal information, which may include sensitive private information, including location information, physical data such as heart rate and BMI, communication records and content, and order information. The sports app collects the user's personal information, performs statistical analysis, and other processing to provide the user with services such as exercise reports and health guidance. Regarding the sensitive personal private information involved in the interaction between the user and the sports app, the user and the sports app may have different requirements or policies for handling and managing the information, including but not limited to the purpose of use, retention period, and sharing scope of the private information. In order to protect user privacy and avoid service disputes, users can express their requirements for the processing and management of privacy information as privacy requirements pr, and sports software can express their strategies for the processing and management of privacy information as privacy policies pp, which will serve as the basis for privacy compliance checks, regulatory audits, etc.
[0043] In this embodiment, the approval of the decryption request of the cloud service provider CSP in step S104 includes: the Supervision and Privacy Protection Committee uses its own private key sk R Decrypt the encrypted private key sk C "Get the first encryption private key sk C ', and the first encrypted private key sk C'Return to the cloud service provider CSP. The Regulatory and Privacy Protection Committee receives the decrypted data from the cloud service provider CSP. C ' request, and then query the privacy compliance check results of the cloud service provider CSP through the blockchain. When the privacy policy pp of the cloud service provider CSP is compliant, the Supervision and Privacy Protection Committee restores the private key sk based on the threshold cryptographic mechanism R , then use sk R Decrypt the double-encrypted private key sk C "Get a double encryption private key sk C ', and encrypt the private key sk C 'Return to the cloud service provider CSP; when the privacy policy pp of the cloud service provider CSP is not compliant, the Supervision and Privacy Protection Committee returns the problems with the privacy policy pp to the cloud service provider CSP. The cloud service provider CSP modifies and forms a new privacy policy pp and re-submits an application to the Supervision and Privacy Protection Committee, that is, jumping to step S102. In addition, it can also directly exit this round of processing.
[0044] In this embodiment, the Supervision and Privacy Protection Committee restores its own private key sk based on the threshold cryptographic mechanism R It should be noted that the threshold cryptographic mechanism adopts a (t,n) secret sharing scheme, that is, the secret s (private key sk R ) is invisible to any single custodian and is jointly maintained by n custodians. Each custodian holds a separate copy of the information, and at least t custodians need to cooperate to restore the secret s. Therefore, based on the threshold cryptographic mechanism, in the supervision and privacy protection committee composed of n committee nodes, the committee's private key sk is jointly maintained by n committee nodes. R , it can resist the risk of leaks from up to t-1 committee nodes and withstand offline failures from up to nt committee nodes. The setting of the threshold t can be flexibly adjusted according to actual needs. This embodiment only involves the basic application of the threshold cryptographic mechanism and does not involve algorithmic improvements to the threshold cryptographic mechanism. Therefore, the specific algorithm of the threshold cryptographic mechanism will not be described in detail here.
[0045] In this embodiment, the encrypted data d in step S105 is encrypted. P ' refers to the cloud service provider CSP using the public key pk of the cloud service consumer CSC C Processing data d P Encrypt and obtain encrypted data d P '; If the cloud service provider CSP successfully passes the privacy compliance check, it will obtain the first encryption private key sk from the Regulatory and Privacy Protection Committee C ', then use the private key sk P Decryption sk C'Get the private key sk of the cloud service consumer CSC C ; Cloud service provider CSP uses sk C Decryption C 'Get data d C ; Cloud service provider CSP has data d C Process (such as storage, calculation, etc.) to obtain the result data d P ; The cloud service provider CSP uses the public key pk of the cloud service consumer CSC C For data d P Encrypt and get the encrypted data d P ', and the data d P 'On the chain. It should be noted that in order to ensure security, the cloud service provider CSP is prevented from using the obtained private key sk C Perform long-term illegal operations, private key sk C It is time-sensitive and can be updated regularly or urgently by the cloud service consumer CSC.
[0046] In step S106, decryption is performed to obtain the processed data d P It means that the cloud service consumer CSC uses the private key sk of the cloud service consumer CSC C Decrypt encrypted data d P 'Get data processing data d P , thus completing the data closed loop between the cloud service provider CSP. To ensure security, the cloud service consumer CSC has a private key sk C to update.
[0047] like Figure 1 As shown, this embodiment also includes the Supervision and Privacy Protection Committee relying on the digital space evidence formed by the blockchain to conduct regular supervision of the behavior of each participant through smart contracts, or conduct targeted audits of the behavior of specific parties as needed, and the results of supervision and auditing are stored on the chain; the participants include cloud service consumers CSC and cloud service providers CSP.
[0048] It should be noted that the establishment and maintenance of the Supervision and Privacy Protection Committee can be implemented in any manner as needed. For example, as a preferred implementation, this embodiment specifies qualified active nodes in the blockchain as candidate nodes. A number of nodes (the number is adjustable) are randomly selected from these candidate nodes to form the Supervision and Privacy Protection Committee. The committee's member nodes reach consensus on regulatory and privacy analysis and decision-making based on the PBFT consensus mechanism to prevent the impact of individual member nodes tampering with intermediate information. After the Supervision and Privacy Protection Committee is established, it needs to be adjusted and maintained as necessary. Regularly re-electing the committee's member nodes can prevent certain nodes from serving as members for a long period of time and improve the load balance of nodes in the blockchain. For example, in this embodiment, the committee members are re-elected every 10 days to renew their term. Furthermore, to enhance the reliability and security of the committee, this embodiment includes a step for detecting faults and malicious behavior on the member nodes. If any faulty or malicious member nodes are present in the committee, they are removed and a by-election is held. Among them, malicious behavior refers to when the committee is performing regulatory and privacy protection analysis activities, a committee member node deliberately modifies intermediate information, affecting the determination of the final decision, and is discovered by other nodes in the committee.
[0049] In this embodiment, the data d in step 1) C The data belongs to the cloud service consumer CSC and needs to be processed by the cloud service provider CSP (such as storage, computing, etc.). The cloud service consumer CSC has no control over the data. C With privacy interests and privacy preferences, cloud service consumers CSC need to C After encryption, it is sent to the cloud service provider CSP, and the Regulatory and Privacy Protection Committee decides whether the cloud service provider CSP has the right to obtain the original data. C Based on the asymmetric key encryption mechanism, a public-private key pair is generated for each participant. Among them, the public key of the cloud service consumer CSC is pk C , the private key is sk C , the public key of the cloud service provider CSP is pk P , the private key is sk P , the public key of the Supervision and Privacy Protection Committee is pk R , the private key is sk R In particular, to prevent committee nodes from leaking or illegally using the committee’s private key sk R , the internal supervision and privacy protection committee has a private key sk R For distributed hosting, for example, as an optional implementation, the threshold password mechanism is adopted in this embodiment, and the committee private key sk RIt is not visible to a single committee node, and the private key sk can only be restored through the cooperation of a sufficient number of committee nodes (reaching the threshold number) R The specific activities of the cloud service consumer CSC are as follows: First, use the public key pk C For data d C Encrypt and get the encrypted data d C '; Then the private key sk C Perform "double encryption", that is, first use the public key pk of the cloud service provider CSP P Against SK C Perform the first encryption to obtain the first encrypted private key sk C ', and then use the public key pk of the Regulatory and Privacy Protection Committee R Against SK C 'Perform the second encryption to obtain the double encryption private key sk C "; then make it clear that the data d C The privacy rights and privacy preferences are expressed in the privacy requirements pr in a standard format; finally, the encrypted data d C ', double encryption private key sk C "And privacy requires pr to be on the chain by writing transactions.
[0050] In summary, the blockchain supervision method supporting privacy protection in this embodiment includes the following: the cloud service consumer CSC uploads encrypted data, encrypted private keys, and privacy requirements to the blockchain; the cloud service provider CSP obtains encrypted data through the blockchain, uploads the privacy policy to the blockchain, and issues a data decryption request to the Supervision and Privacy Protection Committee; the blockchain runs a smart contract to perform a privacy compliance check; the Supervision and Privacy Protection Committee decides whether to approve the data decryption request of the cloud service provider CSP based on the privacy compliance check results; the cloud service provider CSP processes the data after successfully decrypting the data and encrypts the processed data to the blockchain; the cloud service consumer CSC obtains the processed data through the blockchain; the Supervision and Privacy Protection Committee relies on the digital space evidence formed by the blockchain to conduct supervision and audit of the behavior of each participant through smart contracts and store the evidence on the chain. The blockchain supervision method supporting privacy protection in this embodiment is based on the following design principles: (1) based on an asymmetric key encryption mechanism; (2) based on a blockchain consensus mechanism; (3) based on a threshold cryptographic mechanism. This embodiment supports a privacy-preserving blockchain supervision method, which helps to improve the application barriers and performance deficiencies of existing blockchain technologies in cloud computing. It can rely on blockchain and smart contract technologies to achieve supervisory auditing and privacy protection functions, and has the advantages of being difficult to tamper with, traceable, risk-resistant, and privacy-enhanced. It is of great significance for balancing supervision and privacy protection needs and building an efficient and reliable cloud computing supervision mechanism.
[0051] See also Figure 1This embodiment also provides a privacy-preserving blockchain supervision system, comprising a cloud service consumer (CSC), a cloud service provider (CSP), a supervision and privacy protection committee, and interconnected computer devices constituting blockchain nodes. The privacy-preserving blockchain supervision system is programmed or configured to execute the steps of the aforementioned privacy-preserving blockchain supervision method. Furthermore, this embodiment also provides a computer-readable storage medium storing a computer program programmed or configured to execute the aforementioned privacy-preserving blockchain supervision method.
[0052] Example 2:
[0053] This embodiment is a further improvement on the first embodiment. After the regular re-election of the member nodes of the Supervision and Privacy Protection Committee, this embodiment also includes rewards for the member nodes of the previous committee. These rewards recognize the committee nodes that expended additional computing resources to complete analysis and decision-making work related to supervision and privacy protection, and serve as an incentive for all nodes to actively participate in and maintain the privacy-preserving blockchain supervision mechanism. Rewards can take the form of bonuses, virtual currency, points, or other forms of contribution-measurable rewards. Furthermore, this embodiment provides a privacy-preserving blockchain supervision system, comprising a cloud service consumer (CSC), a cloud service provider (CSP), a Supervision and Privacy Protection Committee, and interconnected computer devices forming blockchain nodes. The privacy-preserving blockchain supervision system is programmed or configured to perform the steps of the aforementioned privacy-preserving blockchain supervision method. Furthermore, this embodiment provides a computer-readable storage medium storing a computer program programmed or configured to perform the aforementioned privacy-preserving blockchain supervision method.
[0054] Example 3:
[0055] This embodiment is a further improvement on Example 2. Based on Example 2, this embodiment further incorporates reward records for committee members into the re-election of committee members of the Supervision and Privacy Protection Committee. During re-election, nodes with fewer reward records are prioritized among active nodes of the same level. This ensures a more even and reasonable distribution of committee members, preventing the problem of some active nodes being overly involved in supervision and privacy protection analysis and decision-making, leading to unfair allocation of computing resources. Furthermore, this embodiment provides a privacy-preserving blockchain supervision system, comprising a cloud service consumer (CSC), a cloud service provider (CSP), a supervision and privacy protection committee, and interconnected computer devices forming blockchain nodes. The privacy-preserving blockchain supervision system is programmed or configured to execute the steps of the aforementioned privacy-preserving blockchain supervision method. Furthermore, this embodiment provides a computer-readable storage medium storing a computer program programmed or configured to execute the aforementioned privacy-preserving blockchain supervision method.
[0056] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present application may take the form of a computer program product implemented on one or more computer-readable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code. The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, may be implemented by computer program instructions. These computer program instructions may be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 These computer program instructions can also be stored in a computer-readable memory that can guide a computer or other programmable data processing device to work in a specific way, so that the instructions stored in the computer-readable memory produce a product including the instruction device, which implements the function specified in the process. Figure 1 a process or multiple processes and / or boxes Figure 1These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0057] The above description is merely a preferred embodiment of the present invention. The scope of protection of the present invention is not limited to the above embodiment. All technical solutions based on the concept of the present invention are within the scope of protection of the present invention. It should be noted that for those skilled in the art, various improvements and modifications that do not depart from the principles of the present invention should also be considered within the scope of protection of the present invention.
Claims
1. A blockchain supervision method supporting privacy protection, characterized in that: include: S101, the cloud service consumer CSC will encrypt the data d C ', encrypted private key sk C " and privacy requirements pr on the chain, where the encrypted private key sk C " is your own private key sk C Perform secondary asymmetric encryption to obtain; S102, the cloud service provider CSP puts the privacy policy pp on the chain, and the cloud service provider CSP issues a request for encryption data d to the Supervision and Privacy Protection Committee C 'Decryption request; S103, the blockchain runs a smart contract to perform a privacy compliance check based on the privacy requirement pr and the privacy policy pp; S104, the Supervision and Privacy Protection Committee performs privacy control based on the results of the privacy compliance check. If the privacy compliance check passes, the encrypted private key sk C "Decrypted to the first encrypted private key sk C 'And send it to the cloud service provider CSP, jump to the next step; otherwise, return the problem of privacy policy pp to the cloud service provider CSP, jump to step S102; S105, the cloud service provider CSP uses the first encryption private key sk C 'Encrypt the data d C 'Decrypted to data d C , for data d C Perform specified data processing to obtain processed data d P , and process the data d P Encryption is the encryption process data d P 'After uploading to the chain, the specified data processing refers to storage or calculation; S106, cloud service consumer CSC downloads encrypted processed data through blockchain P ', decrypt to get the processed data d P .
2. The method for blockchain supervision supporting privacy protection according to claim 1, characterized in that: The encrypted data d in step S101 C 'Use your own public key pk for the cloud service consumer CSC C For data d C Encrypted to obtain.
3. The method for blockchain supervision supporting privacy protection according to claim 2, characterized in that: The encrypted private key sk in step S101 C "For cloud service consumers CSC, first use the public key pk of cloud service provider CSP P Your own private key sk C Perform the first encryption to obtain the first encrypted private key sk C '; then use the public key pk of the Regulatory and Privacy Protection Committee R The first encryption private key sk C 'Perform the second encryption to obtain.
4. The method for blockchain supervision supporting privacy protection according to claim 3, characterized in that: The privacy requirement pr in step S101 includes the cloud service consumer CSC’s explicit requirements for data d C your privacy interests and preferences.
5. The method for blockchain supervision supporting privacy protection according to claim 1, characterized in that: In step S103, the blockchain running smart contract performs a privacy compliance check based on the privacy requirement pr and the privacy policy pp, which means comparing the privacy requirement pr and the privacy policy pp. If the two match, the privacy compliance check is determined to be passed; otherwise, the privacy compliance check is determined to be failed.
6. The method for blockchain supervision supporting privacy protection according to claim 1, characterized in that: The approval of the decryption request of the cloud service provider CSP in step S104 includes: the Regulatory and Privacy Protection Committee uses its own private key sk R Decrypt the encrypted private key sk C "Get the first encryption private key sk C ', and the first encrypted private key sk C 'Return to the cloud service provider CSP.
7. The method for blockchain supervision supporting privacy protection according to claim 1, characterized in that: In step S105, the encrypted data d P ' refers to the cloud service provider CSP using the public key pk of the cloud service consumer CSC C For processing data d P Encrypt and obtain encrypted data d P '; In step S106, decryption is performed to obtain the processed data d P It means that the cloud service consumer CSC uses the private key sk of the cloud service consumer CSC C Decrypt encrypted data d P 'Get data processing data d P .
8. The method for blockchain supervision supporting privacy protection according to claim 1, characterized in that: It also includes the digital space evidence formed by the Regulatory and Privacy Protection Committee based on the blockchain, which conducts regular supervision of the behavior of each participant through smart contracts, or conducts targeted audits of the behavior of specific parties according to needs, and the results of supervision and auditing are stored on the chain; the participants include cloud service consumers CSC and cloud service providers CSP.
9. A blockchain regulatory system supporting privacy protection, comprising a cloud service consumer (CSC), a cloud service provider (CSP), a regulatory and privacy protection committee, and blockchain nodes consisting of interconnected computer devices, characterized in that: The privacy-preserving blockchain supervision system is programmed or configured to perform the steps of the privacy-preserving blockchain supervision method described in any one of claims 1 to 8.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program that is programmed or configured to execute the blockchain supervision method supporting privacy protection as described in any one of claims 1 to 8.
Citation Information
Patent Citations
Hierarchical optimization encryption lossless privacy protection method
CN112989375A
Secure system and method for enforcement of privacy policy and protection of confidentiality
US20040054918A1