A blockchain-based multi-backup searchable encryption system and method for data

By using a multi-backup searchable encryption system based on blockchain and smart contracts, the risk of data loss and trust issues between transacting parties are resolved through single-server storage. This enables the integrity verification of search results and fair transactions, prevents fraudulent activities, and ensures the security of user data and the fairness of transactions.

CN116305188BActive Publication Date: 2026-03-17CHENGDU UNIVERSITY OF TECHNOLOGY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202310062011.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-01-16
Publication Date
2026-03-17
Estimated Expiration
2043-01-16

AI Technical Summary

Technical Problem

Existing searchable encryption technologies suffer from risks of data loss due to single-server storage, lack of trust between transacting parties, challenges in verifying the integrity of search results, and a lack of effective oversight of fraudulent activities.

Method used

It adopts a blockchain-based multi-backup searchable encryption system, and through Byzantine fault tolerance mechanism and smart contracts, it realizes multi-server backup, deposit mechanism and equality judgment algorithm to ensure transaction fairness and the integrity of search results.

Benefits of technology

It effectively prevents data loss, ensures fair flow of funds between trading parties, prevents fraudulent activities, and provides integrity verification of search results to ensure the fairness and effectiveness of the user's search process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116305188B_ABST
    Figure CN116305188B_ABST
Patent Text Reader

Abstract

This invention discloses a blockchain-based multi-backup searchable encryption system and method, comprising: a system administrator for executing system initialization, approving registration requests from data providers and users, deploying blockchain contracts and corresponding nodes, and distributing keys; a data provider for generating data tags, encrypting data, uploading it to the blockchain, and holding servers accountable for malicious fraud; a user for sending search requests and pre-paying search fees; a cloud server consisting of multiple cloud servers; and a blockchain consisting of smart contracts and corresponding deployment nodes to ensure fair transactions between users and the cloud server. Compared with existing technologies, by employing multiple servers to back up data and using the internal fairness and non-repudiation of blockchain and smart contracts to punish fraudulent behavior by users and servers, this invention ensures the fair flow of funds between the transacting parties, avoids the problem of single-data storage failures, and guarantees the fairness of the user search process and the effectiveness of search results.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of searchable encryption technology, and in particular to a blockchain-based searchable encryption system and method for multiple backups of data. Background Technology

[0002] Cloud data storage saves users local storage space, but it also exposes users' sensitive privacy to cloud service providers. The most common solution to protect user privacy is to encrypt data before outsourcing it to cloud servers. For searching encrypted data, researchers have introduced keyword-searchable encryption technology. In traditional cloud-based searchable encryption, data is often stored on a single server by the cloud service provider, but this outsourced storage method introduces risks and weaknesses such as access instability, data intrusion, and data corruption. Multi-server data backup allows for real-time storage of multiple copies of data, and the consistency of data can be maintained between servers through data communication.

[0003] In multi-client cloud searchable encryption technology, clients use their own keys to encrypt data and transmit it to the cloud server for storage. Therefore, on the cloud server, even if the encrypted documents contain the same keyword, the document index still presents different data forms. The equality test technology allows checking whether two ciphertexts encrypted with different public keys contain the same keyword, but cannot know any information about the ciphertext.

[0004] Existing searchable encryption technologies present several challenges: First, user data is stored on a single server, which risks loss or theft if the server is attacked or damaged. Second, current searchable encryption technologies only consider honest transactions between the two parties. In real-world production environments, fraudulent activities may occur between clients and servers. Clients might deny sending search requests or claiming the results received were incorrect, thus refusing to pay search fees. Servers might match incorrect or incomplete search results to deceive clients into paying search fees. Third, search results require integrity verification to ensure their authenticity and validity. Therefore, researching how to deploy a verifiable and fair searchable encryption technology on the blockchain to guarantee fairness and reliability for both parties in a transaction is essential. Summary of the Invention

[0005] The purpose of this invention is to provide a searchable encryption system and method based on blockchain with verifiable and multiple backup functions, aiming to solve the problems of single-server storage defects, lack of trust between transacting parties, verification of search result integrity, and protection of search result privacy.

[0006] To achieve the above objectives, the technical solution adopted by this invention is as follows: it comprises five parts: a system administrator for executing system initialization, approving registration requests from data providers and users, deploying blockchain contracts and corresponding nodes, and distributing keys; a data provider for generating data tags, encrypting data and uploading it to the server, and holding servers accountable for malicious fraud; a user for sending search requests and pre-paying search fees; a cloud server consisting of multiple cloud servers for storing data, providing search operations, collecting deposits, matching search results according to user search requests, and further processing search results to form encrypted data and authorized search tokens; and a blockchain consisting of smart contracts and corresponding deployment nodes for ensuring fair transactions between users and the cloud server.

[0007] Furthermore, the cloud server is composed of various cloud servers, which have Byzantine fault tolerance and use an equality test key. id The search and matching results are encrypted and reprocessed using the server's identity ID to generate reprocessed encrypted data, `result`. id Equality determination of authorization token td id .

[0008] Furthermore, the blockchain includes a search and distribution contract module, an equality determination contract module, a deposit transaction reward and punishment module, data nodes, and determination nodes.

[0009] Furthermore, the search distribution contract module consists of a search distribution contract and a search request queue; the search distribution contract distributes user search requests based on the Ethernet addresses of various cloud servers on the cloud server side; and calls the deposit transaction reward and punishment module;

[0010] The search request queue records search requests sent to the blockchain by different users and the time of receiving the requests, using a first-in, first-out (FIFO) model.

[0011] Furthermore, the deposit transaction reward and punishment module is used to record the contract addresses of both parties to ensure the fairness of the transaction. It consists of a transaction contract, a deposit freezing contract, a deposit reward and punishment contract, a status list, a deposit pool, and a T-time automatic triggering function.

[0012] The transaction contract refers to recording the identity ID of the transaction initiator, the amount of deposit, and the time of the transaction request initiation in the status list, while writing the status list into the blockchain data node, and calling the deposit reward and punishment contract. If the user is the transaction initiator, the user's frozen deposit refers to the user's prepaid search fee.

[0013] The deposit transaction reward and punishment module is used to ensure the fairness of fund transactions between users and servers. It monitors and deters dishonest behavior by deducting deposits and provides accountability services for data providers.

[0014] The deposit freeze contract refers to deducting the corresponding deposit amount from the transaction initiator's contract account and freezing it in the deposit pool, while simultaneously triggering a T-time automatic trigger function;

[0015] The deposit pool refers to a contract account registered on Ethereum for the deposit reward and punishment module on the blockchain.

[0016] The T-time automatic trigger function refers to a delayed deposit refund function. That is, if the function is not terminated by any contract within time T, the function will unfreeze the deposit of the transaction initiator after time T and automatically refund it to the contract account of the transaction initiator.

[0017] The deposit reward and penalty contract is based on the judgment result of the equality judgment contract module to pay, refund or deduct the deposit.

[0018] Furthermore, the equality determination contract module includes an equality determination contract list, an equality determination contract, an equality determination result voting contract, a result list 1, a result list 2, and a determination node.

[0019] Furthermore, the equality contract determination list records the server identity ID and the encryption result (result). id Authorization token td id The determination node executes an equality determination algorithm to determine the equality of the received list data and writes the determination result into the result list.

[0020] The equality determination contract uses an authorization token (TD) to determine whether the encrypted data from each cloud service belongs to the same keyword. id and encrypted data result id The pairs of items are distributed to the decision nodes for equality comparison.

[0021] The equal determination result voting contract votes to select the search results of the cloud server with the highest votes to determine the real and valid search results, and then determines which cloud servers have malicious behavior through secondary determination.

[0022] The result list 1 records the judgment results of the judgment nodes after the equality judgment contract distributes the list elements for the first time, which helps to identify real and valid search results;

[0023] Result list 2 records the judgment results of the second judgment node, which helps to identify malicious servers;

[0024] The decision node is used to process the encrypted data result returned by each server. id Authorization token td id Perform the decision-making algorithm and write the decision result into the result list.

[0025] Furthermore, the data nodes in the deposit transaction reward and punishment module and the equality determination contract module are used to write the encrypted data result returned by the server. id The transaction history of both parties is compiled into a public ledger;

[0026] Furthermore,

[0027] This invention also provides a blockchain-based method for searching and encrypting multiple backups of data, comprising the following steps:

[0028] Step 1: The system administrator initializes and obtains system parameter K, then calculates the data administrator key using the system parameter. m The key for determining cloud server equality is calculated using system parameters and the identity IDs of each cloud server. id ; through system parameters, data administrator key m Calculate the user's authorized search key. u and key m ,key id ,key u Data is distributed to the corresponding data providers, cloud servers, and users via secure channels.

[0029] Step 2: The data provider generates encrypted data and tags; the data provider uses the data manager's key. m The data's keywords 'w' generate search tags (index); the key 'key' is used. m Encrypt the data by packaging the search tag index and the encrypted data and uploading them to various cloud servers on the cloud service side;

[0030] Step 3: The user executes a search request; the user uses system parameters and the authorized search key. u And query keywords w2 generate search traps td st The search will include the trap and the amount of the prepaid deposit (money1), and the user's ID. C As a search request sent to the search distribution contract on the blockchain, the user's prepaid deposit money1 refers to the search fee that the user prepays for the server to perform the search operation;

[0031] Step 4: The search distribution contract on the blockchain receives the user's search request; the search distribution contract records the user's search request in the search request queue and sets the user's search trap (td). stDistribute the data to various cloud servers on the cloud server side to invoke the transaction contract;

[0032] Step 5: The transaction contract records the current transaction user status list C; the transaction contract records the user's identity ID, deposit amount money1, and transaction initiation time t1 based on the user's search request, and writes the status list into the data node on the blockchain, and calls the deposit freeze contract;

[0033] Step 6: Deposit Freeze Contract deducts a deposit of money1 from the user's contract account according to the status list C table, freezes it in the deposit pool, and triggers a T-time automatic trigger function T1. Here, the deposit pool is a publicly verifiable contract account on the blockchain.

[0034] Step 7: Each cloud server receives the user's search trap and sends its own identity ID and prepaid deposit amount money2 to the transaction contract on the blockchain. The server prepaid deposit refers to the deposit paid in advance by the cloud server to perform honest operation.

[0035] Step 8: Record the status list S of various cloud servers on the blockchain transaction contract: <S1、S2......S N At the same time, the status list is written into the data nodes on the blockchain. Each cloud server status list includes the server identity ID, the amount of prepaid deposit money2, the transaction initiation time t2, and the deposit freeze contract is invoked.

[0036] Step 9: Deposit Freeze Contract deducts a deposit of money2 from the cloud server contract account according to the status list set S, freezes it in the deposit pool, and triggers an automatic trigger function T2 at time T.

[0037] Step 10: Each cloud server uses the user's search trapdoor to execute a matching algorithm in its local storage. After obtaining the matching search results, it processes them and sends them to the equality determination contract on the blockchain. The cloud server uses system parameters, search tag index, and search trapdoor td. st The search matching algorithm performs a search. If keyword w1 = w2, the algorithm outputs True, indicating that the encrypted data tag and data are the user's desired data. The cloud server then adds this data to the result. Otherwise, the algorithm outputs False, and the server matches the next set of encrypted data. The cloud server then encrypts the obtained result using an equality determination key to obtain a reprocessed encrypted result. id Equality determination of authorization token td id Package and send it to the blockchain for equality determination contract;

[0038] Step 11: The equality determination contract on the blockchain verifies the integrity of the server's search results; the equality determination contract records the server's identity ID and the encrypted result in the equality determination contract list. id Authorization token td id The server identity and ID are then encrypted to obtain the result. id Write data to data nodes on the blockchain, combine list elements in pairs, and distribute them to decision nodes on the blockchain.

[0039] Step 12: The determining node on the blockchain executes the equality determination algorithm and writes the determination result into result list 1; the determining node uses the encrypted data result from the list element. id and authorization token td id The algorithm executes a judgment algorithm. If two encrypted data sets are encrypted data sets under the same key, the algorithm outputs the identity IDs of the two servers and the judgment result 1. <id s1 :1; id s2 :1>, if the algorithm determines that the data returned by the two cloud servers is encrypted with the same keyword, otherwise it outputs the identity IDs of the two servers and 0, such as <id s1 :0; id s2 :0>, it is determined that the search results returned by the two servers are encrypted with different keywords. The judgment node writes the judgment result into result list 1. After the judgment is completed, the voting contract with equal judgment results is called.

[0040] Step 13: The equality determination result voting contract votes on the determination results in result list 1, selects the server result with the highest number of votes as the true and valid result, and calls the equality determination contract; the equality determination result voting contract, based on the determination results in result list 1, counts the server IDs with the highest determination result of 1 and the highest number of votes. st encrypt the result of this server idst The search results will be returned to the equal judgment contract and the user as true and valid results;

[0041] Step 14: The equality determination contract performs a second determination; the equality determination contract uses the true and valid search result returned by the voting contract. idst Based on this, the encrypted results of the servers whose judgment result is 0 in result list 1 are selected as the comparison, and then combined and distributed to the judgment nodes for equality judgment.

[0042] Step 15: The decision node performs a second decision and writes the decision result into result list 2;

[0043] Step 16: The equality judgment contract identifies dishonest servers; the equality judgment contract reads the contents of result list 2, identifies the servers with a judgment result of 0 in result list 2 as dishonest servers, and calls the deposit reward and punishment contract.

[0044] Step 17: The deposit reward and penalty agreement executes the payment, refund, or deduction of the deposit and provides accountability services for the data provider; if the server is deemed an honest server, the deposit reward and penalty agreement unfreezes the honest server's deposit money2 from the deposit pool, refunds it to the server's contract account, and simultaneously refunds the user's prepaid fee money1. Payments are made to honest cloud servers. The deposit reward and penalty agreement deducts the deposit (money2) from the deposit pool for dishonest cloud servers and refunds the user's pre-paid deposit (money1). To the user's contract account, stop the automatic triggering functions T1 and T2 during the T-time period of this transaction, and simultaneously transfer the server identity ID. SQ The deposit (money2) is provided to the data provider for accountability purposes.

[0045] Furthermore, steps 1-17 need to be completed within time T. If the above steps are not completed within time T, the user's search process will terminate, the deposits of both parties will be returned to their respective contract accounts, and the user will need to re-execute the search request.

[0046] Compared with the prior art, the present invention has the following beneficial effects:

[0047] (1) In this invention, multiple servers are used to back up client data to prevent failures caused by single data; the internal fairness and non-repudiation of blockchain and smart contracts are used to punish fraudulent behavior by users and servers, ensuring the fair flow of funds between the two parties; the method of pre-submitting deposits by both parties strongly supervises and deters potential fraudulent behavior between the two parties; encrypted data is stored on the blockchain to prevent the server from denying the returned search results; the integrity verification of search results is provided to ensure the fairness of the user's search process and the validity of the search results. Attached Figure Description

[0048] Figure 1 This is a schematic diagram of the overall system framework in this invention;

[0049] Figure 2 This is a schematic diagram of the contract structure in this invention;

[0050] Figure 3 This is a schematic diagram of the contract call relationship in this invention;

[0051] Figure 4This is a schematic diagram of the overall process of the method in this invention; Detailed Implementation

[0052] The present invention will be further described below with reference to the accompanying drawings and embodiments. The embodiments of the present invention include, but are not limited to, the following embodiments.

[0053] Example 1

[0054] refer to Figure 1 As shown in this embodiment, a blockchain-based search encryption system with verifiable functionality comprises five parts:

[0055] System Administrator: Responsible for performing system initialization operations; the system administrator first assigns identity IDs to data providers, users, and cloud servers registered with the system administrator; then generates data management keys for each data provider, user, and cloud server. m Authorized search key u Equality determination key id Each entity distributes its identity ID and key through a secure channel; finally, the system administrator deploys a smart contract on the blockchain to record the contract accounts and Ethernet addresses of the data provider, user, and cloud server.

[0056] Data provider: Responsible for encrypting and uploading the data; the data provider first uses the data management key. m The data is preprocessed to generate encrypted data tags (index) and encrypted data, which are then uploaded to various cloud servers.

[0057] User: Provides a search request. The user generates a search query request using the authorized search key and search keyword W, and sends their prepaid search fee money1 and identity ID to the smart contract on the blockchain;

[0058] Cloud server side: Composed of various cloud servers, responsible for processing search requests; each cloud server executes a matching algorithm on the received search request in its local storage, and after obtaining the search results, the cloud server uses its own identity ID and equality judgment key. id The data is reprocessed to generate an equal authorization judgment token and encrypted reprocessed data;

[0059] Blockchain: Composed of a search and distribution contract module, an equality determination contract module, a deposit transaction reward and punishment module, data nodes, and determination nodes, it ensures fair transactions between users and cloud servers, provides accountability services for data providers, and provides integrity verification of results.

[0060] All cloud servers receive encrypted data from the data provider, and data consistency across all cloud servers is achieved through data sharing; they all execute search matching algorithms to obtain search results that match the search request; and they all use their own server identity ID and equality verification key. id Process the search result to obtain encrypted data result. id and authorization token td id Send it to the smart contract on the blockchain.

[0061] like Figure 2 and Figure 3 As shown, the search distribution contract module that makes up the blockchain consists of a search distribution contract and a search request queue. The search distribution contract uses the search request queue to record the search requests sent by the client and the client status list. The search distribution contract distributes the search requests to each cloud server in a first-in-first-out manner. The search request queue records search requests from different users and the time when the requests are received.

[0062] The deposit transaction reward and punishment module consists of a transaction contract, a deposit freeze contract, a deposit reward and punishment contract, a status list, a deposit pool, a T-time automatic trigger function, and data nodes. This module ensures the fairness of fund transactions between users and the server, monitors and deters dishonest behavior by deducting deposits, and provides accountability services for data providers. The transaction contract records the user's or cloud server's identity ID, request time t1, and deposit amount money1 in the status list. The user's deposit amount refers to the search fee prepaid by the user when requesting the server to perform a search operation, and this amount is simultaneously written into the blockchain data. Within the node, to prevent client or server denial, a deposit reward / penalty contract is invoked. If the user is the transaction initiator, the frozen deposit refers to the user's prepaid search fees. The deposit reward / penalty contract deducts the corresponding deposit amount from the transaction initiator's contract account and freezes it in a deposit pool. Simultaneously, a T-time auto-trigger function is triggered. The deposit pool refers to a contract account registered on Ethereum for the deposit reward / penalty module. The T-time auto-trigger function is a delayed auto-trigger function deployed within the deposit reward / penalty contract module, specifying that the user's or server's deposit will be frozen in the deposit pool for a maximum of T time. If the function is not interrupted by any contract after T time, the deposit in the deposit pool is automatically returned to the corresponding contract account.

[0063] The deposit reward and penalty agreement determines whether the deposit will be paid, refunded, or deducted based on the judgment result of the equal judgment agreement module.

[0064] The equality contract determination module includes an equality determination contract list, equality determination contracts, equality determination result voting contracts, result list 1, result list 2, determination node, and data node;

[0065] Equality determination contract list: records the identity ID and encryption result sent by each cloud server. id Equality determination of authorization token td id And write it into the blockchain data node;

[0066] Equality determination contract: First, the elements in the equality determination contract list are paired and distributed to the determination nodes to obtain result list 1. Then, the equality determination result voting contract is called to obtain the real and valid encrypted result. id The encrypted result is then used to perform a second equality check to determine which servers have malicious behavior.

[0067] The equality determination contract provides integrity verification for search results and evidence for holding data providers accountable. The equality determination contract list records the equality determination authorization list, which includes the server identity ID and the authorization determination token td. id The result of reprocessing data sent to the cloud id The equality determination contract will use the cloud server's identity ID and the reprocessed data result sent by the cloud server. id The data is written to the data nodes to prevent the cloud server from denying or tampering with the data it sends; at the same time, the equality judgment contract combines the data in the list and distributes them to the judgment nodes in pairs.

[0068] Judgment Node: The judgment node uses an equality judgment algorithm to judge the list elements, records the result in result list 1, and sends result list 1 to the equality judgment result voting contract on the blockchain. In the equality judgment algorithm, if the data is equal, the equality judgment algorithm outputs 1, otherwise it outputs 0. According to the equality summary voting rules on the contract and the result list, the number of votes obtained by each server is counted, and the search result of the server with the highest number of votes is taken as the real and valid result and sent to the user. At the same time, the server with a result of 0 in result list 1 and the real and valid result data are distributed to the judgment node again for secondary judgment, and the secondary judgment result is written into result list 2. The resulting result list 2 will be sent to the deposit reward and punishment contract for the data provider to handle accountability.

[0069] The results list consists of the server identity ID and the corresponding judgment result;

[0070] Result List 1: Records the equality determination results obtained when the equality determination contract first distributes list elements;

[0071] Result List 2: Records the equality determination results obtained when the equality determination contract distributes list elements for the second time;

[0072] Result List 1 and Result List 2 include server identity identifiers and the results of the equality determination algorithm. Result List 1 is obtained by the determination node running the equality determination algorithm for the first time using all data in the authorization list, and is used to obtain real and valid server search results. Result List 2 is obtained by the determination node running the determination algorithm again using the server data in Result List 1 with a determination result of 0 and real and valid search results.

[0073] Equality Judgment Result Voting Contract: Based on the judgment results in Result List 1, if the result corresponding to the server identity ID is 1, then the server is voted on; the equality judgment contract counts the result with the highest number of votes, and sends the encrypted result corresponding to its server as the real and valid result to the equality judgment contract.

[0074] The accountability service uses two result lists (List 1 and List 2) obtained from the equal judgment contract for fund transactions and accountability processing; the deposit reward / penalty contract receives List 1 and List 2 and determines the flow of funds according to the judgment results in List 1 and List 2; the deposit reward / penalty contract pre-divides the client's deposit into N parts according to the number of servers, meaning each server can only receive... The search fee; if the judgment result corresponding to the server in result list 1 is 1 or the judgment result corresponding to the server in result list 1 is 0, but the judgment result corresponding to the server in result list 2 is 1, then the T-time automatic trigger function of the server is stopped, the deposit of the server in the deposit pool is unfrozen and returned to the contract account of the cloud server, and at the same time... The search fee is unfrozen from the deposit pool and returned to the contract account of the cloud server; if the judgment result corresponding to the server in result list 2 is 0, the T-time automatic trigger function is stopped, and the client's deposit is unfrozen from the deposit pool. The search deposit is refunded to the client's contract account, and the corresponding deposit for the cloud service is deducted from the deposit pool. The cloud server's corresponding identity identifier and deposit are returned to the data provider for the data provider's accountability.

[0075] refer to Figure 4 As shown, the specific implementation method and steps for a complete privacy data upload and search are as follows:

[0076] 1. System initialization:

[0077] Step 1: The system administrator initializes and obtains system parameter K, then calculates the data administrator key using the system parameter. m The key for determining cloud server equality is calculated using system parameters and the identity IDs of each cloud server.id ; through system parameters, data administrator key m Calculate the user's authorized search key. u and key m ,key id ,key u Data is distributed to the corresponding data providers, cloud servers, and users via secure channels.

[0078] 2. Generate data labels:

[0079] Step 2: The data provider generates encrypted data and tags; the data provider uses the data manager's key. m The data's keywords 'w' generate search tags (index); the key 'key' is used. m Encrypt the data by packaging the search tag index and the encrypted data and uploading them to various cloud servers on the cloud service side;

[0080] 3. Data search query:

[0081] Step 3: The user executes a search request; the user uses system parameters and the authorized search key. u And query keywords w2 generate search traps td st The search will include the trap and the amount of the prepaid deposit (money1), and the user's ID. C As a search request sent to the search distribution contract on the blockchain, the user's prepaid deposit money1 refers to the search fee that the user prepays for the server to perform the search operation;

[0082] Step 4: The search distribution contract on the blockchain receives the user's search request; the search distribution contract records the user's search request in the search request queue and sets the user's search trap (td). st Distribute the data to various cloud servers on the cloud server side to invoke the transaction contract;

[0083] Step 5: The transaction contract records the current transaction user status list C; the transaction contract records the user's identity ID, deposit amount money1, and transaction initiation time t1 based on the user's search request, and writes the status list into the data node on the blockchain, and calls the deposit freeze contract;

[0084] Step 6: Deposit Freeze Contract deducts a deposit of money1 from the user's contract account according to the status list C table, freezes it in the deposit pool, and triggers a T-time automatic trigger function T1. Here, the deposit pool is a publicly verifiable contract account on the blockchain.

[0085] 4. Search matching test:

[0086] Step 7: Each cloud server receives the user's search trap and sends its own identity ID and prepaid deposit amount money2 to the transaction contract on the blockchain. The server prepaid deposit refers to the deposit paid in advance by the cloud server to perform honest operation.

[0087] Step 8: Record the status list S of various cloud servers on the blockchain transaction contract: <S1、S2......S N At the same time, the status list is written into the data nodes on the blockchain. Each cloud server status list includes the server identity ID, the amount of prepaid deposit money2, the transaction initiation time t2, and the deposit freeze contract is invoked.

[0088] Step 9: Deposit Freeze Contract deducts a deposit of money2 from the cloud server contract account according to the status list set S, freezes it in the deposit pool, and triggers an automatic trigger function T2 at time T.

[0089] Step 10: Each cloud server uses the user's search trapdoor to execute a matching algorithm in its local storage. After obtaining the matching search results, it processes them and sends them to the equality determination contract on the blockchain. The cloud server uses system parameters, search tag index, and search trapdoor yd. st The search matching algorithm performs a search. If keyword w1 = w2, the algorithm outputs True, indicating that the encrypted data tag and data are the user's desired data. The cloud server then adds this data to the result. Otherwise, the algorithm outputs False, and the server matches the next set of encrypted data. The cloud server then encrypts the obtained result using an equality determination key to obtain a reprocessed encrypted result. id Equality determination of authorization token td id Package and send it to the blockchain for equality determination contract;

[0090] 5. Arbitration:

[0091] Step 11: The equality determination contract on the blockchain verifies the integrity of the server's search results; the equality determination contract records the server's identity ID and the encrypted result in the equality determination contract list. id Authorization token td id The server identity and ID are then encrypted to obtain the result. id Write data to data nodes on the blockchain, combine list elements in pairs, and distribute them to decision nodes on the blockchain.

[0092] Step 12: The determining node on the blockchain executes the equality determination algorithm and writes the determination result into result list 1; the determining node uses the encrypted data result from the list element. id and authorization token tdid The algorithm executes a judgment algorithm. If two encrypted data sets are encrypted data sets under the same key, the algorithm outputs the identity IDs of the two servers and the judgment result 1. <id s1 :1; id s2 :1>, if the algorithm determines that the data returned by the two cloud servers is encrypted with the same keyword, otherwise it outputs the identity IDs of the two servers and 0, such as <id s1 :0; id s2 :0>, it is determined that the search results returned by the two servers are encrypted with different keywords. The judgment node writes the judgment result into result list 1. After the judgment is completed, the voting contract with equal judgment results is called.

[0093] Step 13: The equality determination result voting contract votes on the determination results in result list 1, selects the server result with the highest number of votes as the true and valid result, and calls the equality determination contract; the equality determination result voting contract, based on the determination results in result list 1, counts the server IDs with the highest determination result of 1 and the highest number of votes. st encrypt the result of this server idst The search results will be returned to the equal judgment contract and the user as true and valid results;

[0094] Step 14: The equality determination contract performs a second determination; the equality determination contract uses the true and valid search result returned by the voting contract. idst Based on this, the encrypted results of the servers whose judgment result is 0 in result list 1 are selected as the comparison, and then combined and distributed to the judgment nodes for equality judgment.

[0095] Step 15: The decision node performs a second decision and writes the decision result into result list 2;

[0096] Step 16: The equality judgment contract identifies dishonest servers; the equality judgment contract reads the contents of result list 2, identifies the servers with a judgment result of 0 in result list 2 as dishonest servers, and calls the deposit reward and punishment contract.

[0097] Step 17: The deposit reward and penalty agreement executes the payment, refund, or deduction of the deposit and provides accountability services for the data provider; if the server is deemed an honest server, the deposit reward and penalty agreement unfreezes the honest server's deposit money2 from the deposit pool, refunds it to the server's contract account, and simultaneously refunds the user's prepaid fee money1. Payments are made to honest cloud servers. The deposit reward and penalty agreement deducts the deposit (money2) from the deposit pool for dishonest cloud servers and refunds the user's pre-paid deposit (money1). To the user's contract account, stop the automatic triggering functions T1 and T2 during the T-time period of this transaction, and simultaneously transfer the server identity ID. SQ The deposit of money2 is provided to the data provider for accountability purposes;

[0098] All of the above steps need to be completed within time T. If the above steps are not completed within time T, the user's search process will be terminated, and the deposits of both parties will be returned to their respective contract accounts. The user will then need to re-execute the search request.

[0099] The above embodiments are merely one of the preferred embodiments of the present invention. Any modifications or refinements made to the main design concept and spirit of the present invention that are not of substantial significance, but which still solve the same technical problem as the present invention, should be included within the protection scope of the present invention.

Claims

1. A blockchain-based data multi-backup searchable encryption system, characterized in that: The system includes five parts: a system administrator for performing system initialization, approving registration requests of data providers and users, deploying blockchain contracts and corresponding nodes, and distributing keys; a data provider for generating data labels, encrypting data, and uploading to the server, and for holding the server accountable for malicious fraudulent behavior; a user for sending search requests and prepaying search fees; a cloud server composed of multiple cloud servers for storing data, providing search operations, submitting deposits, matching search results according to user search requests, and processing search results to form encrypted data and authorized search tokens; a search distribution contract module composed of a search distribution contract and a search request queue; the search distribution contract distributes user search requests according to the Ethernet addresses of the cloud servers on the cloud server side; and the search request queue records search requests sent to the blockchain from different users and records the time of receiving the requests, using a first-in, first-out mode. The deposit transaction reward and punishment module is used to ensure the fairness of the fund transactions between the user and the server, supervise and deter dishonest behavior of the transaction parties by deducting the deposit, and provide a service for holding the data provider accountable. The blockchain composed of a smart contract and a corresponding deployment node is used to ensure a fair transaction between a user and a cloud server, wherein the cloud server is composed of various cloud servers, the cloud server has a Byzantine fault tolerance mechanism, and an equal judgment test key is used and the server identity The search matching result encryption reprocessing is implemented to generate reprocessed encrypted data and the equal judgment authorization token The blockchain includes a search distribution contract module, an equal judgment contract module, a deposit transaction reward and punishment module, a data node and a judgment node. The deposit pool refers to a contract account registered by the deposit reward and punishment module on the Ethereum blockchain. The deposit reward and punishment contract is used to pay, return, or deduct the deposit according to the determination results of the equality determination contract module. The equality determination result voting contract votes to select the search result of the cloud server with the highest number of votes as the real and valid search result, and determines which cloud servers have malicious behavior through secondary determination. The deposit transaction reward and punishment module is used for recording the contract addresses of the two parties of a transaction, ensuring the fairness of the transaction between the two parties, comprising a transaction contract, a deposit freezing contract, a deposit reward and punishment contract, a state list, a deposit pool and - a time automatic trigger function The transaction contract refers to the one that records the identity of the transaction initiator in the status list. The system records the amount of the deposit, the time the transaction request was initiated, and writes its status list into the blockchain data node. It also calls the deposit reward and punishment contract. If the user is the transaction initiator, the user's frozen deposit refers to the user's prepaid search fee. The result list 1 records the determination results of the determination nodes after the first distribution of the list elements by the equality determination contract, and helps to identify real and valid search results. The margin freeze in combination refers to the deduction of the corresponding margin amount in the transaction initiator's contract account And freeze in the margin pool, while triggering a - Time automatic trigger function; The result list 2 records the determination results of the determination nodes in the second execution of the determination algorithm, and helps to identify malicious servers. The - Time auto trigger function refers to a time deposit refund function, that is, if the function is not terminated by any contract within , the function will unfreeze the deposit of the transaction initiator after , and automatically refund to the contract account of the transaction initiator; 2. A blockchain-based data multi-backup searchable encryption method, characterized by: Step 2: The data provider generates encrypted data and labels. The equal judgment contract list records the server identity , the encryption result , the authorization token ; the judgment node executes an equal judgment algorithm, judges the received list data for equality, and writes the judgment result into the result list; The equality determination contract determines whether the data encrypted by each cloud service is data under the same keyword, and the equality determination contract uses an authorization token and encrypted data , and the two are combined and distributed to the determination node for equality determination; Step 15: The determination node performs secondary determination and writes the determination results into the result list 2. Step 16: The equality determination contract identifies dishonest servers; the equality determination contract reads the contents of the result list 2, identifies servers with a determination result of 0 in the result list 2 as dishonest servers, and calls the deposit reward and punishment contract. ​ The decision node is used to encrypt data returned by each server , authorization token Execute the decision algorithm and write the decision result to the result list; The data nodes in the margin trading reward and punishment module and the equal determination contract module are used for writing the encrypted data returned by the server , transaction history of the two parties, forming a public ledger. ​ Step 1: System administrator initializes system parameters Data manager key is computed from system parameters ; The cloud server equal determination key is calculated through the system parameters and the identities of the cloud servers of the cloud service end. ;​ By system parameters, data manager key , calculate the authorized search key of the user , and distribute , , to the corresponding data provider, cloud server and user through a secure channel; ​ Data provider uses data manager key , data's keyword Generate search label ; using key Encrypt data, upload search label and encrypted data to each cloud server of cloud server side; Step 3: User performs search request; User uses system parameters, authorized search key and query keywords generates search trapdoor ; search trap and the prepayment amount , user identity as a search request to a search distribution contract on the blockchain, wherein the user pre-pays a deposit refers to the search cost that the user pre-pays for the server to perform a search operation; Step 4: The search distribution contract on the blockchain receives the search request of the user; the search distribution contract records the search request of the user in the search request queue and distributes the search trapdoor of the user Distribute to each cloud server of the cloud server end, call the transaction contract; Step 5: The transaction contract records the current transaction user state list ; The transaction contract records the user identity according to the search request of the user , the number of the deposit , the time of the transaction initiation , and writes the state list into the data node on the blockchain, and calls the deposit freezing contract; Step 6: Bond freeze combined with state-dependent list The table deducts the number of bonds from the user contract account, freezes them in the bond pool, and triggers an - time automatic trigger function Here, the bond pool is a publicly searchable contract account on the blockchain; Step 7: Each cloud server of the cloud service end receives the user search trapdoor, and sends its own identity , the number of prepayment deposit to the transaction contract on the blockchain, wherein the server prepayment deposit refers to the prepayment deposit of the cloud server for performing honest operation; Step 8: The transaction contract records on the blockchain record the state list set of each cloud server in the cloud At the same time, write the state list into the data node on the blockchain, wherein each cloud server state list includes server identity , the number of pre-paid deposit , transaction initiation time , call the deposit freezing contract; Step 9: Deposit freeze combined with state list collection Table deducts the number of deposits in the contract account of the cloud server , freezes in the deposit pool, and triggers an - time automatic trigger function ; Step 10: Each cloud server uses the user search trapdoor to perform a matching algorithm in the local storage, and after obtaining the matching search result, it processes and sends it to the equality judgment contract on the blockchain; the cloud server uses the system parameters, search label and search trapdoor to perform a search matching algorithm. If the keyword , the algorithm outputs , which is the encrypted data label and data that the user wants. The cloud server puts this data into the result , otherwise the algorithm outputs , and the server matches the next set of encrypted data again; the cloud server uses the equality judgment key to encrypt the obtained result , obtains the reprocessed encrypted result and equality judgment authorization token , and sends them to the equality judgment contract on the blockchain; Step 11: The equality judgment contract on the blockchain performs integrity verification on the search result of the server; the equality judgment contract records the server identity in the equality judgment contract list , the encryption result , the authorization token , and the server identity and corresponding encryption result Write to the data node on the blockchain, combine the list elements two by two, and distribute them to the judgment nodes on the blockchain; Step 12: The judge node on the blockchain executes the equality judgment algorithm and writes the judgment result into the result list 1; the judge node uses the encrypted data in the list element and the authorized token , executes the judgment algorithm, and if the two encrypted data are encrypted data under the same keyword, the algorithm outputs the identities of the two servers and the judgment result 1, such as , it is determined that the data returned by the two cloud servers is the encryption of the same keyword, otherwise the algorithm outputs the identities of the two servers and the judgment result 0, such as , it is determined that the search results returned by the two servers are the encryption of different keywords, the judge node writes the judgment result into the result list 1, and after the judgment is completed, the equality judgment result voting contract is called; Step 13: The equal judgment result voting contract votes for the judgment results in the result list 1, selects the server result with the highest votes as the real and valid result, and calls the equal judgment contract; the equal judgment result voting contract counts the server with the highest votes and the judgment result of 1 in the judgment results in the result list 1 , and returns the encryption result of this server to the equal judgment contract and the user as the real and valid search result. Step 14: The equality determination contract performs the second determination; the equality determination contract returns the valid search results returned by the voting contract As a basis, the encryption result of the server with the determination result of 0 in the selection result list 1 is taken as a reference, and the combination is distributed to the determination node again for equality determination; ​ ​ Step 17: The Deposit Reward and Penalty Agreement executes the payment, refund, or deduction of the deposit and provides accountability services for the data provider; if the server is deemed an honest server, the Deposit Reward and Penalty Agreement unfreezes the deposit of the honest server from the deposit pool. The money will be refunded to the server's contract account, and the user's prepaid fees will also be refunded. of Payments are made to honest cloud servers; the deposit-based reward and penalty agreement deducts the deposits of dishonest cloud servers from the deposit pool. Refund the user's prepaid deposit of Transfer to the user's contract account to stop the current transaction process. - Automatic time trigger function and At the same time, the server identity ,deposit Provided to data providers for accountability purposes. 3.The blockchain-based data multi-backup searchable encryption method of claim 2, wherein: The steps 1-17 all need to be completed within a time period, if the time period is not completed, the user search process is terminated, the transaction parties' deposits are returned to their respective contract accounts, and the user needs to re-execute the search request.