Data security sharing method based on block chain
By building a hierarchical access tree model on the blockchain and using encryption technology, the security and rate of data sharing in the existing technology are solved, and more efficient and secure data sharing is achieved.
Patent Information
- Application Number
- CN202510305033.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-03-14
AI Technical Summary
The existing blockchain-based data security sharing method has the problems of risk of leakage and slow response speed, and cannot effectively improve the security and speed of data sharing.
By storing shared data into the blockchain, a hierarchical access tree model is built, and public security parameters are generated based on this, the authoritative center generates the master key and public key, encrypts the data, constructs a data access sharing model, and builds a public contract in the blockchain to achieve data decryption and sharing.
Improve the security and rate of data sharing, optimize storage paths and access permissions through attribute encryption and hierarchical access tree model, reduce sharing time, and enhance data security.
Smart Images

Figure CN120223283A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of blockchain and data sharing, and particularly relates to a method for secure data sharing based on blockchain. Background Art
[0002] In the Internet, online sharing of data has become a popular trend, and blockchain is a form of storage solution that stores data in the form of blocks and uses cryptographic algorithms to protect the security of financial data. Since the blocks can be connected together, it is called blockchain. The biggest difference between blockchain and traditional centralized storage solutions is that it realizes distributed storage of data, alleviating the pressure of big data storage. In addition, the core technologies inherent in blockchain ensure the immutability of blockchain and improve data security. Blockchain includes several core technologies, such as cryptographic technology, sharing mechanism, access control, smart contracts, etc. In terms of hardware, blockchain technology provides a large amount of storage space for data storage; however, problems such as privacy leakage often occur during data sharing, and access control and encryption of shared data have become a highly concerned issue.
[0003] Therefore, in order to reduce possible security problems during data sharing within a server, a sharing method for ensuring data security based on blockchain has emerged. The data sharing sender encrypts the data to be shared in the system through an encryption algorithm, and then stores the encrypted data on the blockchain through the sharing system. After receiving a data acquisition request sent by the data sharing recipient (i.e., the user), the description information is sent to the server, and its permissions are judged. According to the description information and its permissions, it is judged whether the user can obtain the data it needs to obtain, and the corresponding ciphertext is decrypted and sent according to the judgment result. However, in this sharing process based on cryptographic technology, risks of leakage often occur due to problems such as single-point failures, and the response speed of existing blockchain data security sharing is relatively slow, unable to provide users with the required data results in a timely manner.
[0004] Therefore, there is an urgent need to provide a method for secure data sharing based on blockchain that can further improve the security of shared data and increase the data sharing rate. Summary of the Invention
[0005] The purpose of the present invention is to provide a method for secure data sharing based on blockchain to solve the above problems existing in the prior art.
[0006] To achieve the above purpose, the present invention adopts the following technical solutions:
[0007] In the first aspect, the present invention provides a method for secure data sharing based on blockchain, which includes:
[0008] Store the shared data into the blockchain to form a shared database, classify the data in the shared database, and construct a hierarchical access tree model based on the classification results. The hierarchical access tree model includes multiple levels, each level includes at least one child node, and each child node has a unique attribute position. Generate a fixed hash value h for each child node;
[0009] Filter the data in the shared database to obtain the target data set G, and set the public security parameter H according to the hierarchical access tree model par ;
[0010] Based on the public security parameter H par , generate the master key and public key through the authoritative center, and calculate the public key security parameter h of the public key using the hash function p ;
[0011] Based on the public key and the public key security parameter h p , encrypt each child node to obtain the encrypted data;
[0012] Based on the target data set G, the master key and the public key, construct a data access sharing model, and generate a user private key according to the data access sharing model to calculate the user private key security parameter f of the user private key using the hash function t ;
[0013] Build a public contract in the blockchain to output the ciphertext of the encrypted data, and decrypt the data based on the user private key security parameter f t to complete the sharing.
[0014] In a possible design, storing the shared data into the blockchain to form a shared database, classifying the data in the shared database, and constructing a hierarchical access tree model includes:
[0015] Classify the data in the shared database in a key - escrow - free mode to obtain the data types in the shared database;
[0016] Based on the data types in the shared database, and use a hierarchical structure to construct a hierarchical access tree model. The hierarchical access tree model includes at least four levels, each level includes at least one child node, each child node corresponds to a type of data. The attribute position of each child node is uniquely identified by the node identifier R and the coordinates (x mn , y mn ), where x is used to represent the main classification of the data, y is used to represent the sub - classification of the data, m is used to represent the horizontal level serial number, and n is used to represent the vertical child node serial number;
[0017] Use the irreversible hash function h = Hash(xmn , y mn ) Map the coordinates of each child node to generate a fixed hash value h.
[0018] In a possible design, filter the data in the shared database to obtain the target data set G, and set the public security parameter H according to the hierarchical access tree model par , including:
[0019] Obtain the existing keywords g in the blockchain, and perform data retrieval on the shared database based on the existing keywords g to determine the target data set G = {g|g ∈ θ}, where θ is used to represent the data set in the shared database;
[0020] Based on the hierarchical structure of the hierarchical access tree model, according to H par = (F1, T g , f g , K 1, K2, P) Initialize and set the public security parameter H par , where F1 represents the generator of the public security parameter, T g represents the order of the generator, f g represents the total number of generators, K1 and K2 respectively represent the shared polynomial components of the hash function, and P represents the number of authoritative centers.
[0021] In a possible design, after setting the public security parameter H according to the hierarchical access tree model par , it further includes:
[0022] Associate the hash value h of each child node in the hierarchical access tree model with the public security parameter H par to generate a permission label for each child node respectively, where the hash value h of each child node corresponds to the access permission of a certain type of data;
[0023] Perform collision resistance verification on the permission labels of each child node. If the permission labels of each child node are the same, it is considered that there is a collision between the permission labels of each child node. Then, add a unique identifier to the child node with a collision, and recalculate the hash value h of the child node with a collision, and generate the corresponding permission label, and perform verification again until there is no collision between the permission labels of each child node; if the permission labels of each child node are different, it is considered that there is no collision between the permission labels of each child node, then write the public security parameter H par into the blockchain smart contract.
[0024] In a possible design, based on the public security parameter H par , the authoritative center generates the master key and the public key, and calculates the public key security parameter h of the public key using the hash function p , including:
[0025] Based on the public security parameter H par , the authority center generates the master key;
[0026] Based on the public security parameter H par , the authority center generates the public key;
[0027] Define the encryption hash function H1, and use the encryption hash function H1 to calculate the public key security parameter h of the public key p .
[0028] In a possible design, based on the public key and the public key security parameter h p , each child node is encrypted to obtain encrypted data, including:
[0029] According to the attribute encryption method, access policies for each child node are generated respectively;
[0030] According to the public key, with the public key security parameter h p as the generator, embed the hash value h of each child node into the ciphertext, and encrypt each child node according to the access policy of each child node to form pre-encrypted data;
[0031] Use the public key security parameter h p to complete the security verification of the encryption process, and use the pre-encrypted data passed the verification as the encrypted data;
[0032] Write the encrypted data into the blockchain to complete the data uploading to the chain.
[0033] In a possible design, based on the target data set G, the master key and the public key, construct a data access sharing model, and generate a user private key according to the data access sharing model, so as to calculate the user private key security parameter f of the user private key by using the hash function t , including:
[0034] Based on the target data set G, use the access policies of the respective child nodes to construct a data access sharing model;
[0035] According to the data access sharing model, randomly generate a pre-user private key based on the user ID;
[0036] Based on the master key, verify the legitimacy of the pre-user private key, and distribute the pre-user private key passed the verification according to the user ID;
[0037] Use the blockchain smart contract to record the key distribution process to prevent key leakage;
[0038] Define the decryption hash function H2, and use the decryption hash function H2 to calculate the user private key security parameter f of the user private keyt 。
[0039] In a possible design, a public contract is constructed in the blockchain to output ciphertext for encrypted data and implement data decryption and sharing based on the user private key security parameter f t including:
[0040] According to the public key security parameter h p and the user private key security parameter f t , a public contract is constructed in the blockchain;
[0041] Based on the public contract constructed in the blockchain, when receiving the description information sent by the user, the encrypted data corresponding to the description information sent by the user is submitted to the endorsement node;
[0042] In the endorsement node, the encrypted data corresponding to the description information sent by the user is improved to form returned encrypted data, and the returned encrypted data is processed for uploading to the chain;
[0043] Based on the user private key security parameter f t , the returned encrypted data after being uploaded to the chain is decrypted through the data access sharing model to form a sharing result;
[0044] Using the blockchain smart contract, the sharing result is returned to the user to complete the sharing.
[0045] In a second aspect, the present invention provides an electronic device, including a memory, a processor, and a transceiver that are communicatively connected in sequence. Among them, the memory is used to store computer programs, the transceiver is used to send and receive messages, and the processor is used to read the computer program and execute the blockchain-based data security sharing method as described in the first aspect or any possible design of the first aspect.
[0046] In a third aspect, the present invention provides a computer program product containing instructions, which when run on a computer, causes the computer to execute the blockchain-based data security sharing method as described in the first aspect or any possible design of the first aspect.
[0047] Beneficial effects: The present invention provides a blockchain-based data security sharing method. Specifically, first, the shared data is stored in the blockchain to form a shared database, the data in the shared database is classified, and a hierarchical access tree model is constructed based on the classification result; secondly, the shared database is screened for data to obtain a target data set G, and a public security parameter H is set according to the hierarchical access tree model par ; then based on the public security parameter H par , the master key and the public key are generated by the authoritative center, and the public key security parameter h of the public key is calculated using the hash function p; then, based on the public key and the public key security parameter h p , encrypt each child node to obtain encrypted data; subsequently, based on the target data set G, the master key, and the public key, construct a data access sharing model, and according to the data access sharing model, generate a user private key, and use a hash function to calculate the user private key security parameter f of the user private key t ; finally, construct a public contract in the blockchain to perform ciphertext output on the encrypted data, and based on the user private key security parameter f t realize data decryption and complete sharing. Through this method, the data is classified by using the attribute encryption method and then encrypted according to the data type, which further improves the security of the shared data; and a hierarchical access tree model is formed according to the data type, optimizing the storage path and forming an access level corresponding to the access permission, which makes the data acquisition path of the user more reasonable, greatly reduces the sharing time, and improves the data sharing rate. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] Figure 1 is a flowchart of the data security sharing method based on blockchain in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0049] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the present invention will be briefly introduced below with reference to the drawings and the description of the embodiments or the prior art. Obviously, the following description of the structure of the drawings is only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts. It should be noted here that the description of these embodiment modes is used to help understand the present invention, but does not constitute a limitation to the present invention.
[0050] It should be understood that although terms such as first and second may be used herein to describe various units, these units should not be limited by these terms. These terms are only used to distinguish one unit from another. For example, the first unit can be called the second unit, and similarly, the second unit can be called the first unit, without departing from the scope of the exemplary embodiments of the present invention.
[0051] It should be understood that for the term "and / or" that may appear in this text, it is merely a relational expression describing the associated objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, B exists alone, and both A and B exist simultaneously. For the term " / and" that may appear in this text, it describes another relational expression of associated objects, indicating that there can be two relationships. For example, A / and B can represent two situations: A exists alone, and both A and B exist. Additionally, for the character " / " that may appear in this text, it generally indicates that the associated objects before and after are in an "or" relationship.
[0052] Embodiment:
[0053] As Figure 1 shown, this embodiment provides a data security sharing method based on blockchain, which includes:
[0054] S100. Store the shared data into the blockchain to form a shared database, classify the data in the shared database, and construct a hierarchical access tree model based on the classification result. Among them, the hierarchical access tree model contains multiple levels, each level includes at least one child node, and each child node has a unique attribute position, and generate a fixed hash value h for each child node;
[0055] In a possible implementation manner, in step S100, storing the shared data into the blockchain to form a shared database, classifying the data in the shared database, and constructing a hierarchical access tree model based on the classification result includes:
[0056] S1001. Classify the data in the shared database in a key - free custody mode to obtain the data types in the shared database;
[0057] S1002. Based on the data types in the shared database, construct a hierarchical access tree model in a hierarchical structure manner, and the hierarchical access tree model includes at least four levels, each level includes at least one child node, each child node corresponds to a type of data, and the attribute position of each child node is uniquely identified by the node identifier R and coordinates (x mn , y mn ), where x is used to represent the main classification of the data, y is used to represent the sub - classification of the data, m is used to represent the horizontal level serial number, and n is used to represent the vertical child node serial number;
[0058] S1003. Use the irreversible hash function h = Hash(x mn , y mn ) to map the coordinates of each child node to generate a fixed hash value h.
[0059] Among them, the initial hierarchical access tree model consists of at least four levels. Each level uniquely identifies the attribute position of the child node through the node identifier R and the coordinates (x, y). For example, the first level is the root node, the second level is the first-level child node, and so on; in the coordinates (x mn ,y mn ), m is used to represent the horizontal level serial number, and n is used to represent the vertical child node serial number. For example, (x 12 ,y 12 ) represents the second child node of the first level. Moreover, in the actual data storage of the initial hierarchical access tree model, the hierarchical access tree model can be dynamically updated according to the addition and expansion of new data. The newly added data type can be dynamically expanded by adjusting the coordinate definition without reconstructing the overall structure, ensuring the flexibility of the entire hierarchical access tree model. And through the hash function h = Hash(x mn ,y mn ), the coordinates of each child node are irreversibly mapped to generate a hash value h of a fixed length. Then, the fixed hash value h can be used as the basis for access permission verification in the data sharing process; moreover, for the hierarchical access tree model, using the hierarchical file reading technology can optimize the storage space utilization rate. And in the data sharing process, the transmission path of the node data is pre-allocated through the hierarchical access tree model, reducing the data sharing delay and the sharing time.
[0060] It should be noted that using an irreversible hash function to map the coordinates of each child node to generate a hash value of a fixed length largely ensures the uniqueness and anti-collision property of the hash value.
[0061] S200. Screen the data in the shared database to obtain the target data set G, and set the public security parameter H according to the hierarchical access tree model par ;
[0062] In a possible implementation manner, in step S200, screening the data in the shared database to obtain the target data set G, and setting the public security parameter H according to the hierarchical access tree model par , including:
[0063] S2001. Obtain the existing keywords g in the blockchain, and perform data retrieval on the shared database based on the existing keywords g to determine the target data set G = {g|g ∈ θ}, where θ is used to represent the data set in the shared database;
[0064] S2002. Based on the hierarchical structure of the hierarchical access tree model, according to H par =(F1,T g ,f g ,K 1,K2, P) Initialize and set the public security parameter H par , where F1 represents the generator of the public security parameter; T g represents the order of the generator, and f g represents the total number of generators. K1 and K2 respectively represent the shared polynomial components of the hash function, and P represents the number of authoritative centers.
[0065] Among them, F1, as the generator of the public security parameter, is actually the generator of the bilinear mapping hash function. The corresponding bilinear mapping vector interval can define a multi-dimensional vector according to the number of levels of the hierarchical access tree model (for example: four levels correspond to a four-dimensional vector) for the weight assignment of permission labels; while T g represents the order of the generator, which can be set to a large prime number (256 bits) to ensure the ability of the encryption algorithm to resist quantum attacks; K1 and K2 can be extended and generated based on the hash value h of the child nodes in the hierarchical access tree model; P represents the number of authoritative centers, and multiple authoritative centers forming a consortium blockchain can ensure that there will be no leakage due to a single point of failure.
[0066] And, in step S200, after setting the public security parameter H according to the hierarchical access tree model par , it further includes:
[0067] Associate the hash value h of each child node in the hierarchical access tree model with the public security parameter H par to generate permission labels for each child node respectively, where the hash value h of each child node corresponds to the access permission of a certain type of data;
[0068] Perform anti-collision verification on the permission labels of each child node. If the permission labels of each child node are the same, it is considered that there is a collision between the permission labels of each child node. Then, add a unique identifier to the child node with a collision, recalculate the hash value h of the child node with a collision, and generate the corresponding permission label, and perform verification again until there is no collision between the permission labels of each child node; if the permission labels of each child node are different, it is considered that there is no collision between the permission labels of each child node, then write the public security parameter H par into the blockchain smart contract.
[0069] Among them, associate the hash value h of each child node in the hierarchical access tree model with the public security parameter H par to generate permission labels for each child node respectively, write the public security parameter H par into the blockchain smart contract, and in the subsequent sharing process, the blockchain smart contract uses H par to parse the access policy and verify whether the user's permission meets the conditions for obtaining the corresponding shared data.
[0070] It should be noted that if a collision occurs in the permission tag (hash value h) generated by the hash function, that is, the same hash value is generated by different node coordinates, it may lead to permission verification errors or data leakage. In fact, although the hash function has strong collision resistance and the probability of collision is extremely low, in practical applications, especially in large-scale data sharing systems, there are still certain risks. Therefore, it is necessary to perform collision resistance verification on the permission tags of each child node to ensure sharing security and data integrity.
[0071] S300. Based on the public security parameter H par , generate the master key and public key through the authoritative center, and calculate the public key security parameter h of the public key using the hash function p ;
[0072] In a possible implementation manner, in step S300, based on the public security parameter H par , generate the master key and public key through the authoritative center, and calculate the public key security parameter h of the public key using the hash function p , including:
[0073] S3001. Based on the public security parameter H par , generate the master key through the authoritative center;
[0074] S3002. Based on the public security parameter H par , generate the public key through the authoritative center;
[0075] S3003. Define the encryption hash function H1, and calculate the public key security parameter h of the public key using the encryption hash function H1 p .
[0076] S400. Encrypt each child node based on the public key and the public key security parameter h p , to obtain the encrypted data;
[0077] In a possible implementation manner, in step S400, encrypt each child node based on the public key and the public key security parameter h p , to obtain the encrypted data, including:
[0078] S4001. Generate access policies for each child node respectively according to the attribute encryption method;
[0079] S4002. According to the public key, using the public key security parameter h p as the generator, embed the hash value h of each child node into the ciphertext, and encrypt each child node according to the access policy of each child node to form pre-encrypted data;
[0080] S4003. Use the public key security parameter hp Complete the security verification of the encryption process and use the pre-encrypted data that passes the verification as encrypted data;
[0081] S4004. Write the encrypted data into the blockchain to complete the data on-chain.
[0082] S500. Based on the target data set G, the master key, and the public key, construct a data access sharing model, and according to the data access sharing model, generate a user private key to calculate the user private key security parameter f of the user private key using a hash function t ;
[0083] In a possible implementation manner, in step S500, based on the target data set G, the master key, and the public key, construct a data access sharing model, and according to the data access sharing model, generate a user private key to calculate the user private key security parameter f of the user private key using a hash function t , including:
[0084] S5001. Based on the target data set G, use the access policies of the respective child nodes to construct a data access sharing model;
[0085] S5002. According to the data access sharing model, randomly generate a pre-user private key based on the user ID;
[0086] S5003. Based on the master key, verify the legitimacy of the pre-user private key and distribute the pre-user private key that passes the verification according to the user ID;
[0087] S5004. Use the blockchain smart contract to record the key distribution process to prevent key leakage;
[0088] S5005. Define a decryption hash function H2 and calculate the user private key security parameter f of the user private key using the decryption hash function H2 t 。
[0089] Among them, the data access sharing model is actually a model used to retrieve and decrypt encrypted data according to the access policy. By combining with the attribute encryption algorithm and using the hierarchical access tree model, the data access sharing model can achieve: permission allocation according to the user ID, attributes dynamically, etc. to improve the security of sharing, and through attribute encryption and blockchain smart contract for dynamic update of new data, performance optimization is completed to achieve sharing of larger-scale data.
[0090] S600. Build a public contract in the blockchain to perform ciphertext output on the encrypted data and realize data decryption based on the user private key security parameter f t to complete sharing.
[0091] In a possible implementation, in step S600, a public contract is constructed in the blockchain to output ciphertext for the encrypted data and perform data decryption based on the user private key security parameter f to complete sharing, including: t The implementation of data decryption and completion of sharing includes:
[0092] S6001. Construct a public contract in the blockchain according to the public key security parameter h p and the user private key security parameter f t .
[0093] S6002. Based on the public contract constructed in the blockchain, when receiving the description information sent by the user, submit the encrypted data corresponding to the description information sent by the user to the endorsement node;
[0094] S6003. Improve the encrypted data corresponding to the description information sent by the user in the endorsement node to form returned encrypted data, and perform on-chain processing on the returned encrypted data;
[0095] S6004. Based on the user private key security parameter f t , decrypt the returned encrypted data after being on-chain through the data access sharing model to form a sharing result;
[0096] S6005. Use the blockchain smart contract to return the sharing result to the user to complete sharing.
[0097] It should be noted that the integrity of the shared data is verified by the endorsement node and the result is returned to the client; the client can listen to the blockchain network to trigger the smart contract to return the sharing result to the user after confirming that the data is successfully on-chain; a sorting node is introduced in the process to globally sort the transactions to ensure the temporal consistency of data sharing.
[0098] This embodiment also provides an electronic device, including a memory, a processor, and a transceiver that are communicatively connected in sequence. Among them, the memory is used to store computer programs, the transceiver is used to send and receive messages, and the processor is used to read the computer programs and execute the blockchain-based data security sharing method in any of the above embodiments.
[0099] This embodiment also provides a computer program product containing instructions, which when running on a computer, implements the blockchain-based data security sharing method in any of the above embodiments.
[0100] Finally, it should be noted that the above are only the preferred embodiments of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A data security sharing method based on blockchain, characterized in that: include: The shared data is stored in the blockchain to form a shared database, the data in the shared database is classified and processed, and a hierarchical access tree model is constructed based on the classification results, wherein the hierarchical access tree model includes multiple levels, each level includes at least one child node, and each child node has a unique attribute position, and a fixed hash value h is generated for each child node; Screen the shared database to obtain the target data set G, and set the public security parameter H according to the hierarchical access tree model. par ; Based on the public safety parameter H par , generate the master key and public key through the authoritative center, and use the hash function to calculate the public key security parameter h of the public key p ; Based on the public key and public key security parameter h p , encrypt each child node to obtain encrypted data; Based on the target data set G, the master key and the public key, a data access sharing model is constructed, and according to the data access sharing model, the user private key is generated, so as to calculate the user private key security parameter f of the user private key by using the hash function. t ; Build a public contract in the blockchain to ciphertext the encrypted data and use the user's private key security parameter f t Realize data decryption and complete sharing.
2. The data security sharing method based on blockchain according to claim 1 is characterized in that: The shared data is stored in the blockchain to form a shared database, the data in the shared database is classified and processed, and a hierarchical access tree model is constructed based on the classification results, including: Classify and process the data in the shared database in a keyless escrow mode to obtain the data types in the shared database; Based on the data types in the shared database, a hierarchical access tree model is constructed in a hierarchical structure, and the hierarchical access tree model includes at least four levels, each level includes at least one child node, each child node corresponds to a type of data, and is identified by a node identifier R and a coordinate (x mn ,y mn ) uniquely identifies the attribute position of each child node, where x is used to represent the main category of the data, y is used to represent the subcategory of the data, m is used to represent the horizontal level number, and n is used to represent the vertical child node number; Using irreversible hash function h = Hash (x mn ,y mn ) maps the coordinates of each child node to generate a fixed hash value h.
3. The data security sharing method based on blockchain according to claim 1 is characterized in that: Screen the shared database to obtain the target data set G, and set the public security parameter H according to the hierarchical access tree model. par ,include: Obtain the existing keyword g in the blockchain, and perform data retrieval on the shared database based on the existing keyword g to determine the target data set G = {g|g∈θ}, where θ is used to represent the data set in the shared database; Based on the hierarchical structure of the hierarchical access tree model, according to H par =(F1,T g ,f g ,K 1, K2, P) initializes and sets the public safety parameter H par , where F1 represents the generator of public safety parameters; T g represents the order of the generator, f g represents the total number of generators, K1 and K2 represent the shared multinomial components of the hash function, and P represents the number of authoritative centers.
4. The data security sharing method based on blockchain according to claim 1 is characterized in that: In setting the public safety parameter H according to the hierarchical access tree model par After that, it also includes: The hash value h of each child node in the hierarchical access tree model is compared with the public security parameter H par Association is performed to generate permission labels for each child node, where the hash value h of each child node corresponds to the access permission of a type of data; The permission labels of each child node are verified against collision. If the permission labels of each child node are the same, it is considered that there is a collision between the permission labels of each child node. A unique identifier is added to the child node where the collision occurs, and the hash value h of the child node where the collision occurs is calculated again, and the corresponding permission label is generated, and verification is performed again until there is no collision between the permission labels of each child node; if the permission labels of each child node are different, it is considered that there is no collision between the permission labels of each child node, and the public security parameter H is added. par Write to blockchain smart contracts.
5. The data security sharing method based on blockchain according to claim 1 is characterized in that: Based on the public safety parameter H par , generate the master key and public key through the authoritative center, and use the hash function to calculate the public key security parameter h of the public key p ,include: Based on the public safety parameter H par , generate the master key through the authoritative center; Based on the public safety parameter H par , generate a public key through an authoritative center; Define the cryptographic hash function H1, and use the cryptographic hash function H1 to calculate the public key security parameter h of the public key p .
6. The data security sharing method based on blockchain according to claim 1 is characterized in that: Based on the public key and public key security parameter h p , encrypt each child node to obtain encrypted data, including: According to the attribute encryption method, the access strategy for each sub-node is generated respectively; According to the public key, with the public key security parameter h p As a generator, the hash value h of each child node is embedded in the ciphertext, and each child node is encrypted according to the access policy of each child node to form pre-encrypted data; Using the public key security parameter h p Complete security verification of the encryption process and use the verified pre-encrypted data as encrypted data; Write the encrypted data into the blockchain to complete the data on-chain.
7. The data security sharing method based on blockchain according to claim 6 is characterized in that: Based on the target data set G, the master key and the public key, a data access sharing model is constructed, and according to the data access sharing model, the user private key is generated, so as to calculate the user private key security parameter f of the user private key by using the hash function. t ,include: Based on the target data set G, a data access sharing model is constructed using the access strategies of each sub-node; According to the data access sharing model, a pre-user private key is randomly generated based on the user ID; Based on the master key, verify the legitimacy of the pre-user private key, and distribute the verified pre-user private key according to the user ID; Use blockchain smart contracts to record the key distribution process to prevent key leakage; Define the decryption hash function H2, and use the decryption hash function H2 to calculate the user private key security parameter f of the user private key t .
8. The data security sharing method based on blockchain according to claim 1 is characterized in that: Build a public contract in the blockchain to ciphertext the encrypted data and use the user's private key security parameter f t Decrypt data and complete sharing, including: According to the public key security parameter h p and user private key security parameter f t , building public contracts in the blockchain; A public contract is constructed based on the blockchain, so that upon receiving the description information sent by the user, the encrypted data corresponding to the description information sent by the user is submitted to the endorsement node; In the endorsement node, the encrypted data corresponding to the description information sent by the user is improved to form the returned encrypted data, and the returned encrypted data is processed on the chain; Based on the user's private key security parameter f t , decrypt the returned encrypted data after uploading to the chain through the data access sharing model to form a shared result; Using blockchain smart contracts, the sharing results are returned to the user to complete the sharing.
9. An electronic device, characterized in that: It includes a memory, a processor and a transceiver which are communicatively connected in sequence, wherein the memory is used to store a computer program, the transceiver is used to send and receive messages, and the processor is used to read the computer program to execute the blockchain-based data security sharing method as described in any one of claims 1 to 8.
10. A computer program product comprising a computer program or instructions, characterized in that When the computer program or the instruction is executed by a computer, the blockchain-based data security sharing method is implemented as described in any one of claims 1 to 8.
Citation Information
Patent Citations
Role-based complete access control method under intelligent contract
CN112543105A
Private data sharing and retrieval method, system and equipment based on block chain
CN116663046A
Data security sharing method and system based on multi-permission attribute-based encryption
CN116668072A
Electronic government affair data security sharing method based on block chain
CN116680241A
Office data security sharing system based on block chain and attribute encryption
CN117763573A
Cited By
Encrypted data security synchronization sharing method and transmission system
CN120856302A