A method and system for controllable data flow

By combining blockchain technology with data portals, proxy servers and storage, the secure and controllable flow of data can be achieved, solving the security and privacy issues in the data flow process, ensuring the security and integrity of data during transmission and storage, and providing data traceability and legal rights protection.

CN119766456BActive Publication Date: 2025-09-05ELECTRIC POWER RESEARCH INSTITUTE OF STATE GRID SHANDONG ELECTRIC POWER COMPANY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411841991.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-13
Publication Date
2025-09-05
Estimated Expiration
2044-12-13

AI Technical Summary

Technical Problem

During the data circulation process, how to ensure the security, privacy and controllability of data, prevent data leakage and privacy infringement, and promote the healthy development of the data circulation industry.

Method used

Blockchain technology is combined with data portals, proxy servers and storage, and data fingerprints and ciphertexts are generated through hash calculations. Proxy servers and blockchain nodes are used to encrypt, store and re-encrypt data to achieve secure and controllable data flow, and smart contracts and consensus mechanisms are used to ensure the immutability and traceability of data.

Benefits of technology

It achieves the security and controllability of data during the circulation process, ensures the confidentiality and integrity of data, prevents unauthorized access and leakage, and provides data traceability and legal rights protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119766456B_ABST
    Figure CN119766456B_ABST
Patent Text Reader

Abstract

The present application provides a method and system for controllable data flow, which is applicable to data flow systems, covering data portals, proxy servers, storage devices and blockchain nodes. The method steps include: the data portal obtains user data, performs hash calculation to generate data fingerprints and encrypts them into data ciphertext, and uploads them to the proxy server; the proxy server stores the data ciphertext and obtains the storage code, uploads the data fingerprint to the blockchain node and obtains the transaction code. The data portal receives the subscription application, generates a re-encryption key based on the subscriber's public key, and sends it to the proxy server; the proxy server uploads the subscription application to the blockchain, retrieves the data ciphertext from the storage device, re-encrypts it with the re-encryption key, and sends it to the subscriber. The subscriber uses the private key to decode and obtain the user data. The present application uses re-encryption technology to achieve secure and controllable data flow.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data transfer, and in particular to a method and system for controllable data transfer. Background Art

[0002] With the rapid development of information technology and the deepening of digital transformation, data has become a core element of modern society and economic activities. However, ensuring the security, privacy, and controllability of data during its circulation has become a critical issue that needs to be addressed. Currently, the data circulation sector faces numerous challenges, such as data leaks, privacy violations, and illegal transactions. These issues not only threaten personal privacy and corporate security, but also hinder the healthy development of the data circulation industry.

[0003] To address these issues, the industry has begun exploring the use of advanced technologies to achieve secure and controllable data transfer. Blockchain, an emerging distributed ledger technology, offers a novel solution for data transfer with its decentralized, tamper-proof, and transparent features. Blockchain technology can record every step of the data flow, ensuring its authenticity and integrity while also safeguarding the legitimacy and fairness of rights such as data ownership, processing, use, and operation rights. Summary of the Invention

[0004] The purpose of this application is to overcome the above-mentioned defects in the prior art and provide a method and system for controllable data flow.

[0005] The present application provides a method for controllable data transfer, characterized in that it is applied to a data transfer system, wherein the data transfer system includes a data portal, a proxy server, a storage device, and a blockchain node. The method includes:

[0006] The data portal obtains user data from the user, performs hash calculation on the user data to generate a data fingerprint, and encrypts the user data to generate a data ciphertext;

[0007] The data portal uploads the data fingerprint and the data ciphertext to the proxy server;

[0008] The proxy server stores the data ciphertext in a memory and obtains a storage code, uploads the data fingerprint to a blockchain node and obtains a first transaction code;

[0009] The data portal obtains a subscription application from a subscriber, generates a re-encryption key according to a public key of the subscriber, and sends the re-encryption key and the subscription application to the proxy server;

[0010] The proxy server uploads the subscription application to the blockchain node to obtain a second transaction code;

[0011] The proxy server retrieves the data ciphertext from the memory, re-encrypts the data ciphertext using the re-encryption key, and sends the re-encrypted data ciphertext to the subscriber;

[0012] The subscriber uses its own private key to decode the data ciphertext to obtain the user data.

[0013] Optionally, it also includes:

[0014] The data portal obtains a data tracing request, constructs a query message using the data fingerprint after receiving the data tracing request, and uploads the query message to the proxy server;

[0015] The proxy server queries the traceability metadata from the blockchain node according to the query message, and returns the traceability metadata to the data portal.

[0016] Optionally, performing a hash calculation on the user data to generate a data fingerprint includes:

[0017] SM3 is used for hash calculation to generate data fingerprint.

[0018] Optionally, before the proxy server stores the encrypted data in a memory and obtains a storage code, the method further includes:

[0019] Performing integrity check on the data ciphertext.

[0020] Optionally, the data portal uploads the data fingerprint and the data ciphertext to the proxy server, including:

[0021] The blockchain nodes store the data ciphertext through a consensus mechanism.

[0022] Optionally, the proxy server retrieves the ciphertext data from the memory and re-encrypts the ciphertext data using the re-encryption key. The method further includes:

[0023] Sign the re-encrypted user data.

[0024] Optionally, the data transfer system includes an application layer, a data service layer and a blockchain layer;

[0025] The application layer includes the data portal;

[0026] The data service layer includes the memory and the proxy server;

[0027] The blockchain layer includes the blockchain node.

[0028] The present application also provides a data controllable flow system for executing the steps of the above-mentioned data controllable flow method, including: a data portal, a proxy server, a storage device, and a blockchain node:

[0029] The data portal includes a plurality of user-side data portals and a plurality of subscriber-side data portals;

[0030] The data portal is connected to the proxy server;

[0031] The proxy server connects the storage and the blockchain node;

[0032] The proxy server sends and receives data information and data ciphertext of the data portal and re-encrypts the data ciphertext;

[0033] The proxy server interacts with the storage and the blockchain node on the data information and the data ciphertext to complete data storage, subscription and tracing.

[0034] Optionally, the proxy server includes a data flow information uplink service module;

[0035] The data flow information chain service module is used to store data fingerprints, subscription applications, and data flow information on the chain, and receive the evidence transaction number from the blockchain node.

[0036] Optionally, the proxy server includes a data re-encryption service module;

[0037] The data re-encryption service module is used to generate a re-encryption key based on the subscriber's public key, and use the re-encryption key to re-encrypt the data ciphertext read from the memory to generate data re-encrypted ciphertext for the subscriber to decrypt using the private key.

[0038] Optionally, the blockchain node includes a consensus module;

[0039] The consensus module is used to reach consensus on data flow information and generate a transaction number for evidence storage.

[0040] Optionally, the blockchain node includes a traceability query module;

[0041] The traceability query module is used to construct query information based on the data fingerprint submitted by the user, send a traceability query message to the blockchain node, receive and verify the Merkle root constructed by the traceability metadata returned by the blockchain node, and finally return the traceability metadata to the user to achieve data traceability.

[0042] Optionally, the user's data portal includes: a data encryption module, which uses the user's public key to encrypt the data ciphertext and generate a data fingerprint.

[0043] Optionally, the data encryption module includes:

[0044] The regulator's agent re-encryption key is generated based on the regulator's public key, and the encrypted data, data fingerprint, evidence transaction number, data storage code and regulator's agent re-encryption key are stored to complete data release.

[0045] Optionally, the proxy server includes an access control module:

[0046] The access control module is used to control access rights to the data stored in the storage module according to a subscription request from the subscriber's data portal.

[0047] Optionally, the blockchain node includes a smart contract module:

[0048] The smart contract module is used to define the rules and processes for data storage, subscription, and tracing.

[0049] The beneficial effects of this application are:

[0050] The present application provides a method for controllable data flow, characterized in that it is applied in a data flow system, wherein the data flow system includes a data portal, a proxy server, a memory and a blockchain node, and the method includes: the data portal obtains the user data of the user party, performs a hash calculation on the user data to generate a data fingerprint, and encrypts the user data to generate a data ciphertext; the data portal uploads the data fingerprint and the data ciphertext to the proxy server; the proxy server stores the data ciphertext in the memory and obtains a storage code, uploads the data fingerprint to the blockchain node and obtains a first transaction code; the data portal obtains the subscription application of the subscriber, generates a re-encryption key based on the public key of the subscriber, and sends the re-encryption key and the subscription application to the proxy server; the proxy server uploads the subscription application to the blockchain node to obtain a second transaction code; the proxy server retrieves the data ciphertext from the memory, re-encrypts the data ciphertext using the re-encryption key, and sends it to the subscriber; the subscriber uses its own private key to decode the data ciphertext to obtain the user data. The present application realizes the secure and controllable flow of data through re-encryption technology. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1 This is a schematic diagram of the controllable flow of data in this application;

[0052] Figure 2 This is a schematic diagram of the controllable data flow and data upload in this application;

[0053] Figure 3This is a diagram of the data controllable flow subscription process in this application;

[0054] Figure 4 This is a schematic diagram of the controllable data flow and traceability process in this application;

[0055] Figure 5 Schematic diagram of the controllable data flow system in this application. DETAILED DESCRIPTION

[0056] The following describes exemplary embodiments of the present disclosure in more detail with reference to the accompanying drawings. Although exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that various forms of implementing the present disclosure are not limited by the embodiments set forth herein. Rather, the embodiments are provided to provide a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art.

[0057] The present application provides a controllable data flow method, which is applied in a data flow system, wherein the data flow system includes a data portal, a proxy server, a storage device and a blockchain node.

[0058] Please refer to Figures 1 to 3 As shown, the controllable data flow method includes:

[0059] Data Release:

[0060] S101. The data portal obtains user data of a user, performs hash calculation on the user data to generate a data fingerprint, and encrypts the user data to generate a data ciphertext.

[0061] Users first need to upload the data they wish to publish to the data portal. The data portal serves as the interface between users and the blockchain system, responsible for receiving and processing submitted data. During the upload process, the data portal must ensure data security, such as encrypted transmission via the HTTPS protocol.

[0062] After receiving uploaded data, the data portal encrypts it using the user's public key to ensure confidentiality. Furthermore, the data portal uses a hashing algorithm (such as SM3) to calculate a unique fingerprint (hash value) for the data, which is then used for subsequent data verification and traceability. Encryption ensures data security during transmission and storage, while hashing provides a means of verifying data integrity.

[0063] S102: The data portal uploads the data fingerprint and the data ciphertext to the proxy server.

[0064] The encrypted data and its fingerprint are sent to the blockchain proxy service.

[0065] The blockchain proxy service acts as a bridge between data and the blockchain network, responsible for delivering data to other nodes in the blockchain network. Data should remain encrypted during transmission to prevent unauthorized access.

[0066] S103. The proxy server stores the data ciphertext in a memory and obtains a storage code, uploads the data fingerprint to a blockchain node and obtains a first transaction code.

[0067] The blockchain proxy service stores the received encrypted data in a reliable data storage service and generates a unique data storage code. This storage code is used for subsequent data retrieval and access.

[0068] The blockchain proxy service uploads the calculated data fingerprint as evidence to the blockchain network. The blockchain's immutability ensures the authenticity and credibility of this evidence. This evidence should be secure and traceable on the blockchain through smart contracts or other blockchain technologies.

[0069] Nodes in the blockchain network perform consensus verification on uploaded evidence to ensure its authenticity and validity. Once verified, the blockchain network generates a data evidence transaction number and returns it to the blockchain proxy service. The consensus mechanism ensures the authenticity and credibility of the evidence, while the transaction number serves as a unique identifier for the evidence.

[0070] The blockchain proxy service returns the received evidence transaction number and data storage code to the data portal. This data will be used for subsequent data management and access control.

[0071] To meet regulatory requirements, the data portal uses the regulator's public key to generate a proxy re-encryption key. This key allows the regulator to perform specific operations or access data without decrypting the original data. Proxy re-encryption ensures that regulators can access and operate data while adhering to privacy protection principles.

[0072] The data portal stores all of the above key information (including data fingerprint, evidence transaction number, data storage code, and supervisory agent re-encryption key) in a secure location to complete the data release process. This information will be used for subsequent data retrieval, access control, and regulatory audits.

[0073] Data subscription:

[0074] S104. The data portal obtains a subscription application from the subscriber, generates a re-encryption key according to the public key of the subscriber, and sends the re-encryption key and the subscription application to the proxy server.

[0075] The subscriber (i.e., the subscribing user) submits a data subscription request to the data owner through the data portal or other designated channels. The request should include information such as the description, purpose, and usage period of the required data.

[0076] After receiving the subscription request, the data owner will review the request. The review content includes but is not limited to the identity authentication of the subscriber, the rationality of the data use, and the compliance of the usage period.

[0077] If the subscription request is approved, the data owner will use the subscriber's public key to generate a proxy re-encryption key. This key allows the data to be encrypted during transmission, but can only be decrypted by the subscriber using their private key. The data owner then sends the subscription information (including data description, expiration date, proxy re-encryption key, etc.) to the blockchain proxy service.

[0078] S105. The proxy server uploads the subscription application to the blockchain node to obtain a second transaction code.

[0079] After receiving the subscription information, the blockchain proxy service uploads it to the blockchain network as evidence. The blockchain's immutability ensures the authenticity and credibility of this evidence. This evidence should be secure and traceable on the blockchain through smart contracts or other blockchain technologies.

[0080] Nodes in the blockchain network perform consensus verification on uploaded evidence to ensure its authenticity and validity. Once verified, the blockchain network generates a transaction number and returns it to the blockchain proxy service. This transaction number uniquely identifies the evidence. The consensus mechanism ensures the authenticity and credibility of the evidence, while the transaction number serves as a unique identifier for the evidence, facilitating subsequent data management and access control.

[0081] S106. The proxy server retrieves the data ciphertext from the memory, re-encrypts the data ciphertext using the re-encryption key, and sends the re-encrypted data to the subscriber.

[0082] The blockchain proxy service retrieves the corresponding data from the data storage service based on the data storage code in the subscription information. The data storage code is a unique identifier generated when the data is stored and is used for subsequent data retrieval and access. The data storage service should be highly available and secure to ensure data reliability and integrity. Furthermore, the blockchain proxy service should ensure the security of data transmission when reading data.

[0083] After receiving the data, the blockchain proxy node re-encrypts it using the previously generated proxy re-encryption key. This ensures that the data remains encrypted during transmission and can only be decrypted by the subscriber using their private key. Proxy re-encryption ensures data security during transmission, preventing unauthorized access and leakage.

[0084] S107: The subscriber uses its own private key to decode the data ciphertext to obtain the user data.

[0085] The blockchain proxy node returns the transaction number and re-encrypted data to the subscriber. The transaction number uniquely identifies the stored information, allowing the subscriber to verify the authenticity and credibility of the data. The integrity and security of the transaction number and re-encrypted data must be ensured during data transmission.

[0086] After receiving the transaction number and re-encrypted data, the subscriber uses its private key to decrypt the data. The decrypted data can then be processed and analyzed by the subscriber.

[0087] Please refer to Figure 4 As shown, it also includes data tracing process.

[0088] The data portal obtains a data tracing request, constructs a query message through the data fingerprint after receiving the data tracing request, and uploads the query message to the proxy server.

[0089] When a subscriber (also known as a tracer user) needs to trace the history of a piece of data, they first construct a query based on the known data fingerprint (a hash value that uniquely identifies the data). The data fingerprint is generated when the data is generated or first stored to ensure its uniqueness and integrity.

[0090] The traceability user sends the query information constructed to the blockchain proxy service through a secure channel (such as HTTPS). The blockchain proxy service serves as the interface between the blockchain network and the user and is responsible for processing the user's query request.

[0091] The proxy server queries the traceability metadata from the blockchain node according to the query message, and returns the traceability metadata to the data portal.

[0092] After receiving the user's query information, the blockchain proxy service parses the data fingerprint and sends a traceability query message to the nodes in the blockchain network. Blockchain nodes are the entities that store data evidence and traceability metadata.

[0093] After receiving a provenance query message, a blockchain node searches for the provenance metadata associated with the data fingerprint in local or distributed storage based on the data fingerprint. This metadata records the history of data generation, storage, transmission, processing, and use. Once found, the blockchain node organizes the multiple metadata pieces into a Merkle tree structure and calculates the Merkle root. The Merkle root is a short hash value that uniquely represents the structure and content of the entire Merkle tree (i.e., all metadata).

[0094] After receiving the Merkle root from the blockchain node, the blockchain proxy service first verifies its authenticity. This verification can be achieved through consensus verification with other nodes in the blockchain network or through other trusted mechanisms. Once verified, the blockchain proxy service requests complete traceability metadata from the blockchain node and returns this metadata to the traceability user.

[0095] After receiving the traceability metadata returned by the blockchain proxy service, the traceability user can parse this metadata to understand the complete history of the data. This metadata includes information such as the data's generation time, storage location, transmission path, processing process, and final use.

[0096] Please refer to Figure 5 As shown, the present application provides a controllable data flow system, including: a data portal, a proxy server, a storage device and a blockchain node.

[0097] Data portal: This includes a data encryption module that encrypts data using the user's public key and generates a unique data fingerprint. The encrypted data, along with the data fingerprint, a transaction ID (generated later), a data storage code (which uniquely identifies the data in storage), and a proxy re-encryption key generated for the regulator (if the regulator needs to access it) are stored or sent to other system components.

[0098] It is also used to submit subscription requests, receive the data re-encrypted ciphertext sent by the proxy server (data re-encrypted according to the subscriber's public key), and decrypt it using its own private key.

[0099] The proxy server includes a data flow information uplink service module, and the proxy server includes a data flow information uplink service module and an access control module.

[0100] Data Flow Information Uploading Service Module: This module is responsible for uploading data fingerprints, subscription information, and other key information in the data flow process to the blockchain for storage, ensuring the immutability and traceability of the information. It also receives the storage transaction number from the blockchain node as the unique identifier for the data storage.

[0101] Data re-encryption service module: Generates a proxy re-encryption key based on the public key of the subscriber (or subscribers), and uses this key to re-encrypt the data ciphertext read from the storage to generate data re-encrypted ciphertext. In this way, only the subscriber with the corresponding private key can decrypt and access the data.

[0102] Access control module: controls access rights to data stored in the storage based on the subscriber's subscription request and data flow rules, ensuring that data can only be accessed by authorized users or subscribers.

[0103] The blockchain node includes a consensus module, a traceability query module, and a smart contract module.

[0104] Consensus module: This module processes data flow information through consensus to ensure its authenticity and consistency. The consensus process may involve the collaboration and verification of multiple blockchain nodes, ultimately generating a transaction number for storage.

[0105] Provenance Query Module: This module constructs query information based on the data fingerprint submitted by the user and sends a provenance query message to the blockchain node. It receives and verifies the Merkle root (or other verification mechanism) constructed from the provenance metadata returned by the blockchain node, and ultimately returns the complete provenance metadata to the user, achieving data traceability.

[0106] Smart Contract Module: Defines the rules and processes for data storage, subscription, and traceability. Smart contracts can automatically execute various operations during the data flow process, such as data notarization, access control, and data re-encryption, thereby improving the automation and intelligence level of the system.

[0107] The memory is used to store encrypted data, data fingerprints, transaction IDs, data storage codes, and other relevant data. The memory can be a distributed storage system to improve data reliability and availability.

[0108] A workflow of a controllable data flow system:

[0109] Users encrypt their data through the data encryption module of the data portal and generate a data fingerprint. The encrypted data, data fingerprint, evidence transaction number (subsequently generated by the proxy server and uploaded to the blockchain), data storage code, and the supervisory agent's re-encryption key (if necessary) are stored in the memory.

[0110] Subscribers submit subscription requests through the data portal to request access to specific data.

[0111] The data flow information chain service module of the proxy server stores key information such as data fingerprints and subscription information on the chain and receives the transaction number of the evidence.

[0112] The access control module of the proxy server controls the access rights to the data stored in the memory according to the subscription request of the subscriber and the data flow rules.

[0113] The proxy server's data re-encryption service module generates a proxy re-encryption key based on the subscriber's public key and re-encrypts the ciphertext. The re-encrypted ciphertext is then sent to the subscriber's data portal.

[0114] The subscriber uses his or her own private key to decrypt the received data and obtain the original data.

[0115] When users or subscribers need to trace the source and flow of data, they can submit data fingerprints through the data portal. The blockchain node's traceability query module constructs query information based on the data fingerprint and returns complete traceability metadata.

[0116] Although the present invention is disclosed above with reference to the embodiments, it is not intended to limit the scope of protection of the present invention. Any changes and modifications made by any technician familiar with the technology without departing from the concept and scope of the present invention should fall within the scope of protection of the present invention.

Claims

1. A method for controllable data transfer, characterized in that: Applied in a data flow system comprising a data portal, a proxy server, a storage device, and a blockchain node, the method comprises: The data portal obtains user data from the user, performs hash calculation on the user data to generate a data fingerprint, and encrypts the user data to generate a data ciphertext; The data portal uploads the data fingerprint and the data ciphertext to the proxy server; The proxy server stores the data ciphertext in a memory and obtains a storage code, uploads the data fingerprint to a blockchain node and obtains a first transaction code; The data portal obtains a subscription application from a subscriber, generates a re-encryption key according to a public key of the subscriber, and sends the re-encryption key and the subscription application to the proxy server; The proxy server uploads the subscription application to the blockchain node to obtain a second transaction code; The proxy server retrieves the data ciphertext from the memory, re-encrypts the data ciphertext using the re-encryption key, and sends the re-encrypted data ciphertext to the subscriber; The subscriber uses its own private key to decode the data ciphertext to obtain the user data.

2. A method for controllable data transfer according to claim 1, characterized in that: Also includes: The data portal obtains a data tracing request, constructs a query message using the data fingerprint after receiving the data tracing request, and uploads the query message to the proxy server; The proxy server queries the traceability metadata from the blockchain node according to the query message, and returns the traceability metadata to the data portal.

3. A method for controllable data transfer according to claim 1, characterized in that: Performing hash calculation on the user data to generate a data fingerprint includes: SM3 is used for hash calculation to generate data fingerprint.

4. A method for controllable data transfer according to claim 1, characterized in that: Before the proxy server stores the encrypted data in a memory and obtains a storage code, the method further includes: Performing integrity check on the data ciphertext.

5. A method for controllable data transfer according to claim 1, characterized in that: The data portal uploads the data fingerprint and the data ciphertext to the proxy server, including: The blockchain nodes store the data ciphertext through a consensus mechanism.

6. A method for controllable data transfer according to claim 1, characterized in that: The proxy server retrieves the data ciphertext from the memory and re-encrypts the data ciphertext using the re-encryption key. The method further includes: Sign the re-encrypted user data.

7. A method for controllable data transfer according to claim 1, characterized in that: The data transfer system includes an application layer, a data service layer, and a blockchain layer; The application layer includes the data portal; The data service layer includes the memory and the proxy server; The blockchain layer includes the blockchain node.

8. A data controllable flow system, characterized in that: The method for executing the controllable data transfer method according to any one of claims 1 to 7 includes: a data portal, a proxy server, a storage device, and a blockchain node: The data portal includes a plurality of user-side data portals and a plurality of subscriber-side data portals; The data portal is connected to the proxy server; The proxy server connects the storage and the blockchain node; The proxy server sends and receives data information and data ciphertext of the data portal and re-encrypts the data ciphertext; The proxy server interacts with the storage and the blockchain node on the data information and the data ciphertext to complete data storage, subscription and tracing.

9. A data controllable flow system according to claim 8, characterized in that: The proxy server includes a data flow information uplink service module; The data flow information chain service module is used to store data fingerprints, subscription applications, and data flow information on the chain, and receive the evidence transaction number from the blockchain node.

10. A data controllable flow system according to claim 8, characterized in that: The proxy server includes a data re-encryption service module; The data re-encryption service module is used to generate a re-encryption key based on the subscriber's public key, and use the re-encryption key to re-encrypt the data ciphertext read from the memory to generate data re-encrypted ciphertext for the subscriber to decrypt using the private key.

11. A data controllable flow system according to claim 10, characterized in that: The blockchain node includes a consensus module; The consensus module is used to reach consensus on data flow information and generate a transaction number for evidence storage.

12. A data controllable flow system according to claim 8, characterized in that: The blockchain node includes a traceability query module; The traceability query module is used to construct query information based on the data fingerprint submitted by the user, send a traceability query message to the blockchain node, receive and verify the Merkle root constructed by the traceability metadata returned by the blockchain node, and finally return the traceability metadata to the user to achieve data traceability.

13. A data controllable flow system according to claim 8, characterized in that: The user's data portal includes: a data encryption module, which uses the user's public key to encrypt the data ciphertext and generate a data fingerprint.

14. A data controllable flow system according to claim 13, characterized in that: The data encryption module includes: The regulator's agent re-encryption key is generated based on the regulator's public key, and the encrypted data, data fingerprint, evidence transaction number, data storage code and regulator's agent re-encryption key are stored to complete data release.

15. The data controllable flow system according to claim 8, characterized in that: The proxy server includes an access control module: The access control module is used to control access rights to the data stored in the storage module according to a subscription request from the subscriber's data portal.

16. A data controllable flow system according to claim 8, characterized in that: The blockchain node includes a smart contract module: The smart contract module is used to define the rules and processes for data storage, subscription, and tracing.

Citation Information

Patent Citations

  • Digital content subscription method based on block chain and decentralized storage

    CN118101239A

  • Consensus and resource transmission methods, device, and storage medium

    WO2021254029A1