Multi-level privacy protection data sharing method and system based on block chain
Through dynamic DNA encoding and AES key expansion methods combined with blockchain and IPFS distributed storage systems, the existing blockchain system has solved the shortcomings in multi-level privacy protection and security improvement, and achieved efficient and secure data sharing and management, which is suitable for precise permission control and rapid retrieval of large-scale data.
Patent Information
- Application Number
- CN202510477919.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-16
- Publication Date
- 2025-07-25
AI Technical Summary
The existing blockchain system has shortcomings in multi-level privacy protection and security improvement, and the cost of providing adaptive optimization for complex business scenarios is too high. Traditional centralized data exchange methods have the risk of single point of failure and data security risks.
Dynamic DNA coding sequences are used to generate encryption keys in combination with AES key expansion method, and upload them to the IPFS distributed storage system through SHA-256 hash function. Dynamic hybrid consensus mechanism and space-time dual attenuation permission control are used, and data access management is managed in combination with smart contracts, and quantum security technology is used to deal with potential quantum computing attacks.
It realizes highly dynamic encryption key generation, improves system security and precise permission management of data access, ensures efficient and secure sharing and rapid retrieval of data in large-scale management, and prevents unauthorized access and data abuse.
Smart Images

Figure CN120372655A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical fields of blockchain and data security, and in particular relates to a multi-level privacy protection data sharing method and system based on blockchain. Background Art
[0002] In today's digital age, the generation, transmission, and storage of data have become increasingly widespread and common. However, with the increase in data, the issues of data privacy and security have become increasingly prominent. Especially in fields involving sensitive information, business secrets, or personal privacy, such as industrial manufacturing, healthcare, and the financial industry, it is crucial to protect data from the risks of unauthorized access, tampering, and leakage.
[0003] Currently, the main data exchange and sharing methods mainly include cloud computing, cloud storage, and cloud sharing. These traditional methods are mostly based on the design concept of a centralized server, which results in insufficient decentralization of the entire system, making data vulnerable to theft and damage. Moreover, there is a risk of single-point failure and high maintenance costs. Blockchain is a technical solution that collectively maintains a reliable database in a decentralized and trustless manner. It is a distributed ledger technology that is anti-tampering, shared, and traceable, with advantages such as decentralization, openness, transparency, immutability, consensus among all parties, smart contract capabilities, authenticity, auditability, and traceability. It has been widely applied in fields such as finance, securities, insurance, commerce, and logistics. Through its decentralized and immutable characteristics, it provides a more secure, transparent, and efficient way for information exchange and value transfer. With the popularization of blockchain technology, various blockchain systems with different characteristics and suitable for different application scenarios have gradually matured. Although existing blockchain systems provide distributed data storage, they have deficiencies in providing multi-level privacy protection and security enhancement functions for users, and there are problems of excessively high costs when providing adaptability optimization for complex business scenarios. Summary of the Invention
[0004] In order to solve the above problems, the purpose of the present invention is to provide a multi-level privacy protection data sharing method and system based on blockchain.
[0005] To achieve the above invention purpose, the present invention adopts the following technical solutions:
[0006] A multi-level privacy protection data sharing method based on blockchain, which includes the following steps:
[0007] S1. Collect original data and upload it; generate an encryption key by using a dynamic DNA coding sequence combined with the AES key expansion method, encrypt the collected data with the generated encryption key to obtain an encrypted file, and store the encrypted file in a local repository; including the following sub-steps:
[0008] S1.1. The initial key is used as the first 4 round key words, which are respectively defined as W[0], W[1], W[2] and W[3]. The W array is expanded through the AES algorithm to generate multiple rounds of round keys. The round keys are selected from the multiple rounds of round keys and used for each round of the AES algorithm. For the key round number i≥4, when i is a multiple of 4, the formula W[i] = W[i - 4] ⊕ SubWord(RotWord(W[i - 1])) ⊕ Rcon[i / 4] is used for expansion, where W[i] represents the i-th word in the expanded key sequence; W[i - 4] represents the (i - 4)-th word in the expanded key sequence; W[i - 1] represents the (i - 1)-th word in the expanded key sequence; RotWord means circularly shifting each byte in a 32-bit word to the left by one bit; SubWord means performing S-box substitution on each byte; Rcon[i / 4] is a predefined round constant; otherwise, the formula W[i] = W[i - 4] ⊕ W[i - 1] is used to generate the expanded key.
[0009] The key is updated by dynamically adjusting the DNA mutation rate. The operation is as follows: The dynamic DNA mutation rate is based on the number of data sharing times N and the sensitivity coefficient S. The mutation rate satisfies μ = 0.05·S·e 0.1N , where N represents the number of data sharing times, S represents the data sensitivity coefficient, and e represents the base of the natural logarithm. A random number is generated through a quantum true random number generator, and the random number is compared with the calculated mutation rate μ. When the random number is lower than the mutation rate μ, a predefined base substitution operation in the DNA coding sequence is triggered, and the base substitution of the DNA coding sequence is dynamically updated according to the predefined rules.
[0010] S1.2. The multiple rounds of round keys obtained in step S1.1 are segmented, and the DNA hash fragment is non-linearly coupled with the round key, and the exclusive OR operation is performed on the segmented left and right key elements to obtain the final encryption key.
[0011] S1.3. The random DNA sequence is converted into a binary string of a fixed length, and at the same time, the final encryption key obtained in step S1.2 is converted into a binary sequence of the same length. Then, the exclusive OR operation is performed bit by bit on these two groups of binary data, that is, each bit uses the exclusive OR operation, and the formula is C[h] = D[h] ⊕ K[h], where D[h] is the h-th bit of the conversion result of the random DNA sequence, and K[h] is the h-th bit of the conversion result of the final encryption key, to obtain the encrypted file.
[0012] S2. The encrypted file in step S1 is uploaded to the distributed hash table of the IPFS distributed storage system through the SHA-256 hash function, and a dynamic hybrid consensus mechanism is used to verify and confirm the block.
[0013] S3. The user accesses the blockchain through a smart contract to execute time and space dual-decay permission control;
[0014] S4. After the permission verification is passed, a decryption key is provided to the user, and the user uses the AES decryption algorithm and DNA reverse coding to decrypt the data.
[0015] Furthermore, the above step S1.2 includes the following sub-steps:
[0016] S1.21. Evenly divide the entire key sequence into left and right parts, denoted as the left half L and the right half R;
[0017] S1.22. Use the SHA3-256 algorithm to generate a 256-bit DNA hash fragment H for the predefined DNA sequence data, and divide H into several substrings {H1, H2,..., H k} according to a predetermined rule, where K represents the total number of substrings, and the length of each substring H j matches the length of the corresponding key block L j in the left half L;
[0018] S1.23. Process each key block L j in the left half L using a non-linear coupling function F, and the function is defined as: F(L j , H j ) = S-box((L j ⊕ H j ) ⊕ Rotl(L j , r)), where "⊕" represents the bitwise exclusive OR operation, Rotl(L j , r) represents circularly shifting the key block L j to the left by r bits, r represents a preset parameter, and S-box represents the standard non-linear substitution function;
[0019] S1.24. Perform an exclusive OR operation on the non-linearly coupled left half L and the corresponding blocks of the right half R block by block to obtain the final encryption key K_final, that is, for a positive integer index j, there is K_final,j = F(L j , H j ) ⊕ R j , where R j represents the key block in the right half R corresponding to the corresponding key block L j in the left half L.
[0020] Further, in the above step S2, the dynamic hybrid consensus mechanism adaptively switches between the PBFT consensus algorithm, the PoS consensus algorithm, and the PoW consensus algorithm according to the current network state and latency; the operation is as follows: when the latency is low and the number of nodes is small, the PBFT consensus algorithm is used to quickly reach a consensus; when the network latency is high or the node reputation is good, switch to the PoS consensus algorithm; when the network state is abnormal or there are high risks, switch to the PoW consensus algorithm.
[0021] Furthermore, in the above step S2, when a quantum computing node is detected to be connected, the following operations are triggered:
[0022] S2.1. DNA sequence Cas12a enzymatic cleavage reaction: Using DNA editing technology, at least 3 base sites are directionally mutated within an extremely short time to generate a DNA code;
[0023] S2.2. IPFS hash address conversion to a quantum-safe format: The IPFS hash address is encrypted and converted using the format QHash = SHA3-256(Hash) || BLAKE2s(Hash), where both SHA3-256 and BLAKE2s are hash algorithms with quantum-resistant properties, and "||" means concatenating the two;
[0024] S2.3. Enable NTRU lattice cryptography for encryption: In a quantum computing environment, enable NTRU lattice cryptography to perform secondary encryption on the metadata.
[0025] Further, in the above step S3, the permission value calculation formula is:
[0026]
[0027] where x and y are the spatial coordinates of the access request respectively; t is the time of access; in 450 = 2σ 2 , when σ is set to 15 pixels, that is, 2×152 = 450, and σ is the spatial attenuation factor.
[0028] Furthermore, in the above step S3, the verification standard for the permission value P(x, y, t) is:
[0029] Set a minimum permission threshold P min , when the calculated permission value P(x, y, t) satisfies P(x, y, t) ≥ P min , the user has the data access permission; otherwise, the access request is rejected;
[0030] The determination method of the minimum permission threshold P min is any one of the following three methods:
[0031] (1) Set spatial constraints based on the access radius:
[0032] Set the maximum allowable access radius R max , that is, only when x 2 +y 2 ≤R max will the user be authorized. Combining with the permission value calculation formula, we get:
[0033]
[0034] Among them, the maximum allowable access radius R max is set by the data manager according to the sensitivity of the data and the access scope requirements;
[0035] (2) Set time decay constraints based on time decay:
[0036] Set the maximum allowable access time t max , that is, when t≥t max the permission value will decay to the extent that access is not allowed; at this time, the lowest permission threshold P min satisfies:
[0037]
[0038] Among them, the maximum allowable access time t max is determined by the data manager to ensure that unauthorized access requests cannot be authorized;
[0039] (3) Dynamic adjustment mechanism:
[0040] The lowest permission threshold P min is dynamically adjusted according to factors such as access frequency and data sensitivity.
[0041] Furthermore, in the above step S3, the following operations are performed:
[0042] S3.1. Destroy the current DNA-AES key: The encryption key generated by using the dynamic DNA coding sequence combined with the AES key expansion method is the DNA-AES key; after detecting the quantum attack characteristics, immediately call the key destruction module and use the memory clearing algorithm to completely destroy the current DNA-AES key used for encrypting data;
[0043] S3.2. Distribute EPR entangled pairs through the quantum channel: Use the quantum channel to distribute EPR pairs to achieve quantum key distribution, including preparing entangled state particles, transmitting through the quantum channel, and generating a shared key at the sending end and the receiving end through the quantum key distribution protocol;
[0044] S3.3. Reconstruct the quantum teleportation encryption channel: Through quantum teleportation technology, reconstruct a new encryption channel. The operations are as follows: First, generate entangled pairs; then, jointly measure the data to be transmitted and the local entangled state, and transmit the measurement results to the remote end through a classical channel; finally, use the entangled state shared at the remote end to reconstruct the original data state.
[0045] Further, step S4 above includes the following sub-steps:
[0046] S4.1. Permission verification and decryption key acquisition
[0047] When the access request submitted by the user meets the permission control conditions, that is, the calculated permission value P(x, y, t) meets the following conditions:
[0048] P(x, y, t) ≥ P min
[0049] where P min is the lowest permission threshold;
[0050] After meeting the above conditions, the smart contract triggers the key management module to provide the user with the decryption key K dec ; The decryption key K dec is derived from the encryption key generated in step S1 and is encrypted and transmitted using a secure transmission protocol;
[0051] S4.2. AES decryption process
[0052] After the user receives the decryption key K dec , use the AES inverse operation to decrypt the encrypted file C to restore the DNA coding sequence D enc ; The decryption formula is as follows:
[0053] D enc = AES -1 (C, K dec )
[0054] where AES -1 represents the AES inverse transformation;
[0055] S4.3. DNA reverse decoding
[0056] Convert the decrypted DNA coding sequence D enc into the original binary data B rec ;
[0057] S4.4. Data integrity verification and recovery
[0058] Use a hash function to perform integrity verification on the original binary data B rec .
[0059] Furthermore, step S4.2 above includes the following sub-steps:
[0060] S4.21. Round key restoration
[0061] Reverse the key expansion process using the round keys generated in step S1.1 to obtain each round key required for decryption; Apply step S1.2 in reverse for non-linear coupling decryption, i.e., perform an exclusive OR operation between the DNA hash fragment and the round key block in reverse to restore the original AES round key;
[0062] S4.22. AES inverse transformation
[0063] Successively perform inverse byte substitution, inverse row shift, and inverse round key addition operations to finally restore the DNA-encoded sequence D enc .
[0064] Furthermore, step S4.3 above includes the following sub-steps:
[0065] S4.31. DNA base mapping
[0066] Map the DNA base sequence back to the binary data B using a predetermined DNA encoding rule rec ,
[0067] B rec = DNA -1 (D enc )
[0068] S4.32. DNA base mutation correction
[0069] Perform inverse mutation correction during decoding, and correct according to the shared DNA mutation rate μ and mutation rule to restore the correct binary data.
[0070] Furthermore, step S4.4 above includes the following sub-steps:
[0071] S4.41. Calculate the hash value of the decrypted data
[0072] H(B rec ) = SHA256(B rec )
[0073] S4.42. Compare with the original hash value
[0074]
[0075] Among them, H(B orig ) is the hash value of the data before encryption;
[0076] S4.43. Judge integrity
[0077] If H(B rec) = H(B orig ), indicating that the data is complete and the system outputs the final decryption result B orig ;
[0078] If H(B rec ) ≠ H(B orig ), it indicates that the data has been tampered with or the decryption is incorrect. The system terminates the data output and issues a warning to the user.
[0079] A multi - level privacy - protected data sharing system based on blockchain, which includes a collection layer, a transmission layer, a storage layer, a blockchain service layer, and a user layer. Among them,
[0080] The collection layer includes collection devices and sensors, and is used to collect raw data;
[0081] The transmission layer is used to transmit the collected data to the storage layer by using the RPL routing protocol;
[0082] The operations performed by the storage layer are as follows: receiving the data uploaded by the transmission layer, generating an encryption key by using a dynamic DNA coding sequence combined with the AES key expansion method, encrypting the data by using the generated encryption key to obtain an encrypted file, and storing the encrypted file in the local storage repository; the data owner generates a key pair by using an asymmetric encryption algorithm, including a public key and a private key, for digitally signing the encrypted file; the data user submits a data access request through a smart contract on the blockchain and executes a spatio - temporal double - decay permission control mechanism for permission verification; after the data owner agrees, the encrypted file is uploaded to the IPFS distributed storage system and the corresponding IPFS hash address is obtained, and this hash address is linked to the blockchain network after calculation and encryption conversion;
[0083] The blockchain service layer includes a dynamic hybrid consensus engine and a quantum attack detection module. Among them,
[0084] The dynamic hybrid consensus engine is used to adaptively select the optimal consensus mechanism among the PBFT consensus algorithm, the PoS consensus algorithm, and the PoW consensus algorithm, and combine the spatio - temporal double - decay permission control mechanism to dynamically adjust the consensus strategy;
[0085] The quantum attack detection module is used to collect the quantum bit error rate data on the quantum communication link in real - time and input the quantum bit error rate data into an LSTM model composed of 128 hidden layers for time - series analysis; when the predicted quantum bit error rate data exceeds the preset security threshold, the system automatically triggers the quantum key distribution technology;
[0086] The user layer is used to enable users to access the blockchain service layer through smart contracts, perform spatio-temporal double-decay permission control; and after the permission verification is passed, the smart contract triggers the key management module to provide the decryption key to the user; enable the user to decrypt the data using the AES decryption algorithm and DNA reverse coding, and at the same time perform data integrity verification.
[0087] Due to the above-mentioned technical solution, the present invention has the following advantages:
[0088] The multi-level privacy protection data sharing method and system based on blockchain of the present invention, by using the method of generating encryption keys by combining dynamic DNA coding sequences with the AES key expansion method, not only retains the standard process of AES key expansion, but also combines dynamic DNA coding technology, realizing the high dynamics and unpredictability of the encryption key generation process, significantly improving the overall security; using DNA hash fragments to introduce additional randomness and non-linear characteristics, disrupting the linear structure of the round keys through non-linear coupling, and combining the exclusive OR operation of the left and right parts, significantly enhancing the anti-linear and differential analysis capabilities of the key scheduling; the spatio-temporal double-decay mechanism adopts the dual mechanisms of spatial decay and time decay, making the access permission gradually decrease with the increase of distance and the prolongation of access duration, thus effectively improving the security of the system while ensuring the data access efficiency, and providing more precise permission management.
[0089] The multi-level privacy protection data sharing method and system based on blockchain of the present invention uses optimized data encryption and decryption algorithms to enable the system to maintain high efficiency when processing encrypted files of different sizes. The encryption and decryption times increase linearly with the file size, which is suitable for the management of large-scale data; at the same time, the architecture based on blockchain and IPFS ensures the rapid sharing and accurate retrieval of data, improving the service efficiency; using four smart contracts to achieve user registration verification, dynamic access permission management and access behavior monitoring, ensuring that only authorized users can access the data under specified conditions, effectively preventing unauthorized access and data abuse, and improving the security and compliance of data access. BRIEF DESCRIPTION OF THE DRAWINGS
[0090] Figure 1 is the flowchart of the multi-level privacy protection data sharing method based on blockchain of the present invention;
[0091] Figure 2 is the block diagram of the multi-level privacy protection data sharing system based on blockchain of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0092] The technical solution of the present invention will be further described in detail below with reference to the drawings and embodiments.
[0093] As Figure 1As shown in the figure, a multi-level privacy protection data sharing method based on blockchain includes the following steps:
[0094] S1. Collect the original data and transmit the data using the RPL routing protocol; generate an encryption key by combining a dynamic DNA coding sequence with a 128-bit AES key expansion method, and use the generated encryption key to encrypt the collected data to obtain an encrypted file, and store the encrypted file in a local repository; the specific operation is as follows:
[0095] S1.1. The initial key is used as the first 4 round key words, which are respectively defined as W[0], W[1], W[2] and W[3]. The W array is expanded through the AES algorithm to generate multiple rounds of round keys, and a round key is selected from the multiple rounds of round keys for each round of the AES algorithm; for the key round number i≥4, when i is a multiple of 4, the formula W[i] = W[i - 4] ⊕ SubWord(RotWord(W[i - 1])) ⊕ Rcon[i / 4] is used for expansion, where W[i] represents the i-th word in the expanded key sequence; W[i - 4] represents the i - 4-th word in the expanded key sequence; W[i - 1] represents the i - 1-th word in the expanded key sequence; RotWord means cyclically shifting each byte in a 32-bit word to the left by one bit; SubWord means performing S-box substitution on each byte; Rcon[i / 4] is a predefined round constant; and when i is not a multiple of 4, the formula W[i] = W[i - 4] ⊕ W[i - 1] is used to generate the expanded key;
[0096] The key is updated by dynamically adjusting the DNA mutation rate. The operation is as follows: The dynamic DNA mutation rate is based on the data sharing times N and the data sensitivity coefficient S, and the mutation rate satisfies μ = 0.05·S·e 0.1N , where N represents the data sharing times, S represents the data sensitivity coefficient, and e represents the base of the natural logarithm; a random number is generated by a quantum true random number generator (QRNG), and the random number is compared with the calculated mutation rate μ; when the random number is lower than the mutation rate μ, a predefined base substitution operation in the DNA coding sequence is triggered, and a specific base is replaced with another base according to a predefined rule, so as to dynamically update the DNA coding sequence and further adjust the generated encryption key;
[0097] S1.2. Split the multiple rounds of round keys obtained in step S1.1, perform non-linear coupling on the DNA hash fragment and the round key, and perform an exclusive OR operation on the split left and right key elements to obtain the final encryption key; the operation is as follows:
[0098] S1.21. Divide the entire key sequence evenly into two parts, denoted as the left part L and the right part R. Subsequently, use the SHA3-256 algorithm to generate a 256-bit DNA hash fragment H for the predefined DNA sequence data, and divide H into several substrings {H1, H2, …, H k}, where K represents the total number of substrings, and the length of each substring H j matches the length of the corresponding key block L j in the left part L;
[0099] S1.22. Process each key block L j in the left part L using a non-linear coupling function F, which is defined as: F(L j , H j ) = S-box((L j ⊕ H j ) ⊕ Rotl(L j , r)), where "⊕" represents the bitwise exclusive OR operation, Rotl(L j , r) represents circularly shifting the key block L j to the left by r bits. r is a preset parameter determined based on cryptographic security analysis (resistance to differential / linear attacks, avalanche effect). Empirically, non-trivial values such as 3, 5, 7, 11 are preferred. S-box represents a standard non-linear substitution function used to introduce confusion effects;
[0100] S1.23. Perform an exclusive OR operation on each corresponding block of the non-linearly coupled left part L and the right part R to obtain the final encryption key K_final. That is, for a positive integer index j, K_final,j = F(L j , H j ) ⊕ R j , where R j represents the key block in the right part R corresponding to the corresponding key block L j in the left part L;
[0101] S1.3. Convert the random DNA sequence into a fixed-length binary string, and at the same time convert the final encryption key K_final obtained in step S1.12 into a binary sequence of the same length. If necessary, pad or truncate to make their lengths consistent, and then perform a bitwise exclusive OR operation on these two sets of binary data, that is, each bit uses the exclusive OR operation. The formula is C[h] = D[h] ⊕ K[h], where D[h] is the h-th bit of the conversion result of the random DNA sequence, and K[h] is the h-th bit of the conversion result of the final key, thereby obtaining the encrypted file;
[0102] The above encryption process makes full use of the randomness of the random DNA sequence and the encryption strength of the final key to achieve secure encryption of data. Finally, the generated encrypted file is stored in the local repository to ensure that only authorized users with corresponding decryption conditions can restore the original data;
[0103] S2. Upload the encrypted file in step S1 to the distributed hash table of the IPFS (InterPlanetary File System) distributed storage system through the SHA-256 hash function, and use the dynamic hybrid consensus mechanism to verify and confirm the block; the dynamic hybrid consensus mechanism adaptively switches between the PBFT (Practical Byzantine Fault Tolerance) consensus algorithm, the PoS (Proof of Stake) consensus algorithm, and the PoW (Proof of Work) consensus algorithm according to the current network status and latency; specifically, when the latency is low, that is, the network latency t < 50ms and the number of nodes is small, the PBFT consensus algorithm is used to quickly reach a consensus to improve the efficiency and speed of block verification; when the network latency is high, that is, the network latency t ≥ 50ms, or the node reputation is good, switch to the PoS consensus algorithm, and use the reputation score of the node to select the validator to ensure the security, stability, and efficiency of the system in high-latency or congested situations; in abnormal network states or high-risk situations, switch to the PoW consensus algorithm to increase the security of the system; the dynamic hybrid consensus mechanism is dynamically adjusted to jointly optimize efficiency and security; when a quantum computing node is detected to be connected, trigger the following operations to ensure the quantum security of the data:
[0104] S2.1. DNA sequence Cas12a enzymatic cleavage reaction: Using DNA editing technology (CRISPR-Cas12a), within an extremely short time of 300 - 600 milliseconds, preferably 500 milliseconds, directionally mutate at least 3 base sites to generate a more complex and unpredictable DNA code, enhancing the security of the encryption key and the ability to resist quantum attacks;
[0105] S2.2. Convert the IPFS hash address to a quantum-secure format: Encrypt and convert the IPFS hash address using the QHash = SHA3-256(Hash))||BLAKE2S(Hash)) format, where both SHA3-256 and BLAKE2s are hash algorithms with quantum-resistant characteristics, and "||" means concatenating the two to ensure that the IPFS hash address can still maintain high security in a quantum computing environment;
[0106] S2.3. Enable NTRU lattice cryptography for encryption: In a quantum computing environment, enable NTRU lattice cryptography to perform secondary encryption on metadata to ensure that the data can still maintain high security when faced with quantum computing attacks;
[0107] S3. The user accesses the blockchain through a smart contract and executes spatio-temporal double decay permission control: The permission value calculation formula is:
[0108]
[0109] where x and y are the spatial coordinates of the access request, for example, the distance between the visitor and the data storage location; t is the time of access, that is, the duration since the start of access; in 450 = 2σ 2 when σ is set to 15 pixels, that is, 2×15 2 = 450, and σ is the spatial decay factor, which is used to quantify the effective range of the access request;
[0110] The above permission value P(x, y, t) verification standard is:
[0111] Set a minimum permission threshold P min When the calculated permission value P(x, y, t) satisfies P(x, y, t) ≥ P min the user has the data access permission; otherwise, the access request is rejected;
[0112] The minimum permission threshold P min should be set to ensure that only access requests that meet specific spatio-temporal conditions are authorized, while avoiding unauthorized users from obtaining sensitive data; Since the permission value P(x, y, t) is only related to the spatial coordinates (x, y) and time t of the access request, the determination method of the minimum permission threshold P min is any one of the following three methods:
[0113] (1). Set spatial constraints based on the access radius:
[0114] Set the maximum allowable access radius R max that is, only when x 2 +y 2 ≤R max the user may be authorized; Therefore, combined with the permission value calculation formula, we get:
[0115]
[0116] where R max is set by the data manager according to the sensitivity of the data and the access range requirements;
[0117] (2). Set time limit constraints based on time decay:
[0118] The access permission decays over time, and the maximum allowed access time t is set max , that is, when t ≥ t max , the permission value decays to the extent that access is not allowed; at this time, the lowest permission threshold P min satisfies:
[0119]
[0120] where t max is determined by the data manager to ensure that unauthorized access requests cannot be authorized;
[0121] (3) Dynamic adjustment mechanism:
[0122] In practical applications, the lowest permission threshold P min is dynamically adjusted according to factors such as access frequency and data sensitivity; for example, if the access frequency is too high, the lowest permission threshold P is increased min to increase access restrictions; if the data security requirements are reduced, the lowest permission threshold P is appropriately relaxed min to improve usability;
[0123] To cope with potential quantum attack threats, in step S3 above, the following operations are performed:
[0124] S3.1 Destroy the current DNA-AES key: The encryption key generated by combining the dynamic DNA coding sequence with the AES key expansion method is the DNA-AES key; after detecting the quantum attack characteristics, the system immediately calls the key destruction module and uses a high-security memory clearing algorithm, such as zero padding and multiple random rewrites, to completely destroy the current DNA-AES key used to encrypt data, thus preventing the key from being reverse-engineered or cracked by a quantum computer;
[0125] S3.2 Distribute EPR entangled pairs through a quantum channel: The system uses a quantum channel to distribute EPR (entangled particles) pairs to achieve Quantum Key Distribution (QKD); the quantum key distribution process includes preparing entangled state particles, transmitting through a quantum channel, and generating a shared key at the sender and receiver through the quantum key distribution protocol to ensure that the key exchange reaches quantum-level security;
[0126] S3.3. Reconstruct the quantum teleportation encryption channel: The system reconstructs a new encryption channel through quantum teleportation technology. The specific operation is as follows: First, generate entangled pairs; then jointly measure the data to be transmitted and the local entangled state, and send the measurement results to the remote end through a classical channel; finally, use the entangled state shared at the remote end to reconstruct the original data state, thereby realizing secure data transmission and ensuring high security of data transmission under quantum attack conditions;
[0127] S4. After the permission verification is passed, provide the decryption key to the user, and the user decrypts the data using the AES decryption algorithm and DNA reverse coding. The operation is as follows:
[0128] S4.1. Permission verification and decryption key acquisition
[0129] When the access request submitted by the user meets the permission control conditions, that is, the calculated permission value P(x, y, t) meets the following conditions:
[0130] P(x, y, t) ≥ P min
[0131] where P min is the lowest permission threshold;
[0132] After meeting the above conditions, the smart contract triggers the key management module to provide the decryption key K dec to the user; the decryption key K dec is derived from the encryption key generated in step S1 and is encrypted and transmitted using a secure transmission protocol, such as Elliptic Curve Cryptography ECC or Quantum Key Distribution QKD, to ensure the security of the key;
[0133] S4.2. AES decryption process
[0134] After the user receives the decryption key K dec , decrypt the encrypted file C using the AES inverse operation to restore the DNA coding sequence D enc ; the decryption formula is as follows:
[0135] D enc = AES -1 (C, K dec )
[0136] where AES -1 represents the AES inverse transformation;
[0137] The above AES decryption process includes the following sub-steps:
[0138] S4.21. Round key restoration
[0139] Reverse the key expansion process using the round keys generated in step S1.1 to obtain each round key required for decryption; apply step S1.2 in reverse for non-linear coupling decryption, i.e., perform an XOR operation on the DNA hash fragments and the round key blocks in reverse to restore the original AES round keys.
[0140] S4.22, AES inverse transformation
[0141] Successively perform inverse byte substitution, inverse row shift, inverse column mixing (if applicable), and inverse round key addition operations to finally restore the DNA-encoded sequence D enc ;
[0142] S4.3, DNA reverse decoding
[0143] The DNA-encoded sequence D obtained by decryption enc is further converted into the original binary data. The specific steps are as follows:
[0144] S4.31, DNA base mapping
[0145] Using a predetermined DNA encoding rule, map the DNA base sequence back to the binary data B rec ; For example, if the following binary-DNA mapping rule is adopted:
[0146] A → 00
[0147] T → 01
[0148] C → 10
[0149] G → 11
[0150] The DNA-encoded sequence D enc is converted into the binary data B according to the above rule rec :
[0151] B rec = DNA -1 (D enc )
[0152] S4.32, DNA base mutation correction
[0153] Since step S1 adopts a dynamic DNA mutation mechanism, inverse mutation correction is performed during decoding; correction is made according to the shared DNA mutation rate μ and the mutation rule to restore the correct binary data B rec ;
[0154] S4.4, Data integrity verification and restoration
[0155] To ensure the integrity and untampered nature of the decrypted data, a hash function is used to perform integrity verification on the original binary data B rec ; The specific steps are as follows:
[0156] S4.41. Calculate the hash value of the decrypted data
[0157] H(B rec ) = SHA256(B rec )
[0158] S4.42. Compare the original hash value
[0159]
[0160] Among them, H(B orig ) is the hash value of the data before encryption (stored on the blockchain);
[0161] S4.43. Judge the integrity
[0162] If H(B rec ) = H(B orig ), it indicates that the data is complete, and the system outputs the final decryption result B orig ;
[0163] If H(B rec ) ≠ H(B orig ), it indicates that the data may have been tampered with or decrypted incorrectly. The system terminates the data output and issues a warning to the user;
[0164] Through the above decryption process, users can safely and accurately restore the original data and ensure that the data has not been modified or accessed without authorization.
[0165] As Figure 2 shown, a multi-level privacy protection data sharing system based on blockchain includes a collection layer, a transmission layer, a storage layer, a blockchain service layer, and a user layer. Among them,
[0166] The collection layer includes collection devices and sensors for collecting original data;
[0167] The transmission layer is used to transmit the collected data to the storage layer using the RPL routing protocol;
[0168] The storage layer is used to perform the following operations: receive the data uploaded by the transport layer, generate an encryption key by using the dynamic DNA coding sequence combined with the AES key expansion method, encrypt the data with the generated encryption key to obtain an encrypted file, and store the encrypted file in the local repository; the data owner (i.e., the user with data management authority or authorized user) generates a key pair, including a public key and a private key, by using an asymmetric encryption algorithm to digitally sign the encrypted file to ensure the authenticity and non-repudiation of the data source; the data user submits a data access request through the smart contract on the blockchain and executes the time-space double decay permission control mechanism for permission verification; after the data owner agrees, the encrypted file is uploaded to the IPFS distributed storage system, and the corresponding IPFS hash address is obtained. This hash address undergoes SHA-256 hash calculation and is quantum-securely encrypted and transformed in the format of QHash = SHA3-256(Hash) || BLAKE2s(Hash) to enhance the anti-quantum attack ability of the hash address. Finally, the IPFS hash address is linked to the blockchain network to realize the association of data between distributed storage and the blockchain; when a quantum computing node is detected to be connected, the system automatically triggers the DNA sequence Cas12a enzymatic cleavage reaction, and uses DNA editing technology to directionally mutate at least 3 base sites in a very short time to dynamically update the DNA coding sequence to enhance the security of the data encryption key; at the same time, the NTRU lattice cryptography algorithm is enabled to perform secondary encryption on the IPFS hash address and metadata to ensure that the data can still be kept secure in the quantum computing environment;
[0169] The blockchain service layer includes a dynamic hybrid consensus engine and a quantum attack detection module, where,
[0170] The dynamic hybrid consensus engine is used to adaptively select the optimal consensus mechanism among the PBFT consensus algorithm, the PoS consensus algorithm, and the PoW consensus algorithm according to the network latency factor, and combine the time-space double decay permission control mechanism to dynamically adjust the consensus strategy to ensure that the blockchain system can operate efficiently and stably in different network environments; specifically, when the latency is low and the number of nodes is small, the PBFT consensus algorithm is used to quickly reach a consensus; when the network latency is relatively high or the node reputation is good, switch to the PoS consensus algorithm; when in an abnormal network state or high risk, switch to the PoW consensus algorithm;
[0171] The quantum attack detection module is used to collect the quantum bit error rate (QBER) data on the quantum communication link in real time, and input the quantum bit error rate data into an LSTM (Long Short-Term Memory Network) model composed of 128 hidden layers for time series analysis to capture the long-term dependence relationship and dynamic change trend of the data, so as to accurately predict the error rate at future moments; when the predicted quantum bit error rate data exceeds the preset security threshold, the system automatically triggers the quantum key distribution technology, distributes EPR entangled pairs through the quantum channel to implement quantum key distribution, and uses the quantum teleportation technology to reconstruct a new encryption channel to ensure the confidentiality and integrity of the communication process, thereby effectively identifying and coping with the potential quantum computing attack risk and continuously enhancing the overall quantum security of the system;
[0172] The user layer is used to enable users to access the blockchain service layer through smart contracts, perform spatio-temporal double decay permission control, and after the permission verification is passed, the smart contract triggers the key management module to provide the decryption key to the user; the user receives the decryption key using the secure transmission protocol, and performs data decryption using the AES decryption algorithm and DNA reverse coding, and at the same time performs data integrity verification to ensure the accuracy and security of the decryption result.
[0173] The smart contract includes, but is not limited to, a verification contract (VAC), an access acquisition contract (GACC), a grant contract (GRC), and a revocation contract (REC), which respectively implement user registration verification, access control, permission management, and access revocation to ensure the security and compliance of data access.
[0174] (1), Verification contract (VAC) - Identity verification and access log management:
[0175] During the user registration process, the verification contract is responsible for the following tasks:
[0176] Identity verification:
[0177] Verify the public key hash addresses of the owner, creator, and requester of the encrypted file to ensure the authenticity of the user identity; use the SHA-256 hash function to encrypt and store the user identity information to prevent tampering;
[0178] Access request log management:
[0179] Record the time t and spatial coordinates (x, y) of each access request for permission value calculation;
[0180] Calculate the user permission value P(x, y, t) and compare it with the minimum permission threshold P minCompare: If P(x,y,t)≥P min , then forward the access request to the Get Access Contract (GACC); if P(x,y,t) <P min , then call the revocation contract (REC) to revoke its access rights and record the log;
[0181] (2) Get Access Contract (GACC) - Access Control and Anomaly Detection:
[0182] The access contract mainly manages the access control protocol to ensure the security and compliance of data access:
[0183] Access Rights Management:
[0184] Set access criteria to clarify access rights for different users; set access time periods max , restricting users from accessing data within a specific time; using a dynamic hybrid consensus mechanism (PBFT, PoS, PoW) to verify and confirm blocks to ensure the legitimacy of access rights, see step S2 in the multi-level privacy protection data sharing method based on blockchain of the present invention for details;
[0185] Anomaly Detection and Access Revocation:
[0186] Monitor user behavior to prevent unauthorized access, data tampering, or malicious operations.
[0187] If the following exceptions are detected, the RevokeAccess() function is called immediately to trigger the revocation contract (REC):
[0188] The access permission has timed out, that is, t>t max ; The visitor attempts to modify the hash value of the data stored in the blockchain; The access frequency is abnormal (multiple visits in a short period of time);
[0189] (3) Grant Contract (GRC) - Dynamic Authorization and Access Time Management:
[0190] When the requester meets all access requirements set by the Gain Access Contract (GACC), the Grant Contract performs the following tasks:
[0191] Permissions granted:
[0192] Grant the requester access to the data within a specified time; start the access timer Timer() to monitor the access time; after the access time expires, automatically call the revocation contract (REC) to terminate the requester's access rights, ensuring the timeliness and security of data access;
[0193] Encryption Key Management:
[0194] Generate an encryption key by combining a dynamic DNA coding sequence with the AES key expansion method. For details, see step S1.1 in the blockchain-based multi-level privacy protection data sharing method of the present invention;
[0195] For sensitive data, a DNA mutation rate mechanism is used to dynamically update the key. The mutation rate μ:
[0196] μ = 0.05·S·e 0.1N
[0197] where N represents the number of data sharing times, S represents the data sensitivity coefficient, and e is the base of the natural logarithm;
[0198] Provide the decryption key to the user through a secure channel (ECC encryption or quantum key distribution QKD);
[0199] (4), Revoke Contract (REC) - Permission Revocation and Data Security Protection:
[0200] When the requester violates the access control policy (such as attempting unauthorized access, malicious operation) or RevokeAccess() is called, the revoke contract performs the following operations:
[0201] Access Permission Revocation:
[0202] Delete the public key hash address of the violating requester to ensure that it cannot continue to access the data; update the access control status in the smart contract to prevent abuse of permissions;
[0203] Security Protection Measures:
[0204] Destroy the current DNA-AES key: After detecting a quantum attack, call the key destruction module to completely destroy the current DNA-AES key used to encrypt data using a memory clearing algorithm;
[0205] Quantum-secure conversion of the IPFS hash address. For details, see step S2.2 in the blockchain-based multi-level privacy protection data sharing method of the present invention: Use SHA3-256 and BLAKE2s format encryption conversion to improve the quantum attack resistance of the IPFS hash address;
[0206] NTRU lattice cryptography secondary encryption. For details, see step S2.3 in the blockchain-based multi-level privacy protection data sharing method of the present invention: In a quantum computing environment, enable NTRU lattice cryptography to perform secondary encryption on the metadata to enhance security.
[0207] On the other hand, the present invention also provides a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the steps of the above-mentioned blockchain-based multi-level privacy protection data sharing method.
[0208] On the other hand, the present invention also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above-mentioned multi-level privacy protection data sharing method based on blockchain are implemented.
[0209] The above are only the preferred embodiments of the present invention, and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included in the protection scope of the present invention.
Claims
1. A multi-level privacy protection data sharing method based on blockchain, characterized in that: It includes the following steps: S1. Collect the original data and upload it; Generate an encryption key by using a dynamic DNA coding sequence combined with the AES key expansion method, encrypt the collected data with the generated encryption key to obtain an encrypted file, and store the encrypted file in the local repository; It includes the following sub-steps: S1.
1. The initial key is used as the first 4 round key words, which are respectively defined as W[0], W[1], W[2] and W[3]. Expand the W array through the AES algorithm to generate multiple rounds of round keys, and select the round keys from the multiple rounds of round keys for each round of the AES algorithm; For the key round number \(i\geq4\), when \(i\) is a multiple of 4, the formula is used for expansion, where \(W[i]\) represents the \(i\)-th word in the expanded key sequence; \(W[i - 4]\) represents the \((i - 4)\)-th word in the expanded key sequence; \(W[i - 1]\) represents the \((i - 1)\)-th word in the expanded key sequence; RotWord means cyclically shifting each byte in a 32-bit word to the left by one bit; SubWord means performing S-box substitution on each byte; \(Rcon[i / 4]\) is a predefined round constant; otherwise, the formula is used to generate the expanded key. Key update is achieved by dynamically adjusting the DNA mutation rate. The operation is as follows: The dynamic DNA mutation rate is based on the number of data sharing times N and the data sensitivity coefficient S, and the mutation rate satisfies μ = 0.05·S·e 0.1N , where N represents the number of data sharing times, S represents the data sensitivity coefficient, and e represents the base of the natural logarithm; A random number is generated by a quantum true random number generator, and the random number is compared with the calculated mutation rate μ; When the random number is lower than the mutation rate μ, a predefined base substitution operation in the DNA coding sequence is triggered, and the base substitution of the DNA coding sequence is dynamically updated according to the predetermined rules; S1.
2. Split the multiple rounds of round keys obtained in step S1.1, perform a non-linear coupling of the DNA hash fragment with the round key, and perform an exclusive OR operation on the split left and right key elements to obtain the final encryption key; S1.
3. Convert the random DNA sequence into a binary string of a fixed length, and at the same time convert the final encryption key obtained in step S1.2 into a binary sequence of the same length. Then perform an exclusive OR operation on these two sets of binary data bit by bit, that is, perform an exclusive OR operation on each bit. The formula is where D[h] is the h-th bit of the conversion result of the random DNA sequence, and K[h] is the h-th bit of the conversion result of the final encryption key, to obtain the encrypted file; S2. Upload the encrypted file in step S1 to the distributed hash table of the IPFS distributed storage system through the SHA-256 hash function, and use a dynamic hybrid consensus mechanism to verify and confirm the block; S3. The user accesses the blockchain through a smart contract and executes time-space double decay permission control; S4. After the permission verification is passed, provide the decryption key to the user, and the user decrypts the data by using the AES decryption algorithm and DNA reverse coding.
2. The multi-level privacy protection data sharing method based on blockchain according to claim 1, wherein: The step S1.2 includes the following sub-steps: S1.
21. Uniformly divide the entire key sequence into left and right parts, denoted as the left half L and the right half R; S1.
22. Generate a 256-bit DNA hash fragment H for the predefined DNA sequence data using the SHA3-256 algorithm, and split H into several substrings {H1, H2, …, H k} according to a predetermined rule, where K represents the total number of substrings, and the length of each substring H j matches the length of the corresponding key block L j in the left half L; S1.
23. For each key block L of the left half L j , it is processed using the non-linear coupling function F, and the function is defined as: where represents the bitwise exclusive OR operation, Rotl(L j , r) represents circularly shifting the key block L j to the left by r bits, r represents a preset parameter, and S-box represents the standard non-linear substitution function; S1.
24. Perform an exclusive OR operation on each corresponding block of the left half L and the right half R after non - linear coupling to obtain the final encryption key K_final. That is, for a positive integer index j, K_final,j = F(L j ,H j ) ⊕ R j , where R j represents the key block in the right half R corresponding to the corresponding key block L j in the left half L.
3. The multi-level privacy protection data sharing method based on blockchain according to claim 1, characterized in that: In the step S2, the dynamic hybrid consensus mechanism adaptively switches between the PBFT consensus algorithm, the PoS consensus algorithm, and the PoW consensus algorithm according to the current network state and latency; the operation is as follows: when the latency is low and the number of nodes is small, use the PBFT consensus algorithm to quickly reach a consensus; when the network latency is high or the node reputation is good, switch to the PoS consensus algorithm; when the network state is abnormal or there is high risk, switch to the PoW consensus algorithm.
4. The multi-level privacy protection data sharing method based on blockchain according to claim 1, wherein: In the step S2, when it is detected that a quantum computing node accesses, trigger the following operations: S2.
1. DNA sequence Cas12a enzyme digestion reaction: Use DNA editing technology to directionally mutate at least 3 base sites in a very short time to generate a DNA code; S2.
2. Convert the IPFS hash address to a quantum-safe format: Encrypt and convert the IPFS hash address in the format of QHash = SHA3-256(Hash)||BLAKE2s(Hash)), where SHA3-256 and BLAKE2s are both hash algorithms with quantum-resistant characteristics, and "||" means concatenating the two; S2.
3. Enable the NTRU lattice cipher for encryption: In the quantum computing environment, enable the NTRU lattice cipher to perform secondary encryption on the metadata.
5. The multi-level privacy protection data sharing method based on blockchain according to claim 1, characterized in that: In the step S3, the permission value calculation formula is: where x and y are the spatial coordinates of the access request respectively; t is the time of access; in 450 = 2σ 2 when σ is set to 15 pixels, that is, 2×15² = 450, and σ is the spatial attenuation factor.
6. The multi-level privacy protection data sharing method based on blockchain according to claim 5, characterized in that: In the step S3, the verification standard of the permission value P(x, y, t) is: Set a minimum permission threshold P min , when the calculated permission value P(x, y, t) satisfies P(x, y, t) ≥ P min , the user has the data access permission; otherwise, the access request is rejected; Determination method of the minimum privilege threshold P min is any one of the following three methods: (1). Set spatial constraints based on the access radius: Set the maximum allowable access radius R max , that is, only when x 2 +y 2 ≤R max will the user be authorized. Combining with the permission value calculation formula, we get: Among them, the maximum allowable access radius R max is set by the data manager according to the sensitivity of the data and the requirements of the access scope; (2). Set time limit constraints based on time decay: Set the maximum allowable access time t max , that is, when t ≥ t max , the permission value decays to the extent that access is not possible; at this time, the lowest permission threshold P min satisfies: Among them, the maximum allowable access time t max is determined by the data manager to ensure that unauthorized access requests cannot be authorized; (3). Dynamic adjustment mechanism: Minimum privilege threshold P min Dynamically adjusted according to access frequency and data sensitivity factors.
7. The multi-level privacy protection data sharing method based on blockchain according to claim 1, characterized in that: In the step S3, perform the following operations: S3.
1. Destroy the current DNA-AES key: The encryption key generated by the method of combining the dynamic DNA coding sequence with the AES key expansion method is the DNA-AES key. After detecting the quantum attack characteristics, immediately call the key destruction module and use the memory clearing algorithm to completely destroy the current DNA-AES key used for encrypting data. S3.
2. Distribute EPR entangled pairs through the quantum channel: Use the quantum channel to distribute EPR pairs to achieve quantum key distribution, including preparing entangled state particles, transmitting through the quantum channel, and generating a shared key at the sender and receiver through the quantum key distribution protocol. S3.
3. Reconstruct the quantum teleportation encryption channel: Through the quantum teleportation technology, reconstruct a new encryption channel. The operations are as follows: First, generate an entangled pair; then perform a joint measurement on the data to be transmitted and the local entangled state, and transmit the measurement result to the remote end through the classical channel; finally, use the entangled state shared at the remote end to reconstruct the original data state.
8. The multi-level privacy protection data sharing method based on blockchain according to claim 6, characterized in that: The step S4 includes the following sub-steps: S4.
1. Permission verification and decryption key acquisition When the access request submitted by the user meets the permission control conditions, that is, the calculated permission value P(x, y, t) meets the following conditions: P(x, y, t) ≥ P min where P min is the lowest privilege threshold; After meeting the above conditions, the smart contract triggers the key management module to provide the decryption key K to the user dec ; The decryption key K dec is derived from the encryption key generated in step S1 and encrypted and transmitted using a secure transmission protocol; S4.
2. AES decryption process The user receives the decryption key K dec and then uses the inverse operation of AES to decrypt the encrypted file C and recover the DNA coding sequence D enc ; the decryption formula is as follows: D enc = AES -1 (C, K dec ) Among them, AES -1 represents the inverse AES transformation; S4.
3. DNA reverse decoding Convert the decrypted DNA coding sequence D enc to the original binary data B rec ; S4.
4. Data integrity verification and recovery Use a hash function to perform integrity verification on the original binary data B rec for integrity verification.
9. The multi-level privacy protection data sharing method based on blockchain according to claim 8, characterized in that: The step S4 also includes any one or more of the following features: (1). The step S4.2 includes the following sub-steps: S4.
21. Round key restoration Reverse the key expansion process using the round key generated in step S1.1 to obtain each round key required for decryption; apply the nonlinear coupling decryption in step S1.2 reversely, that is, perform an exclusive OR operation on the DNA hash fragment and the round key block in reverse to restore the original AES round key. S4.
22. AES inverse transformation Perform the inverse byte substitution, inverse row shift, and inverse round key addition operations in sequence, and finally restore the DNA coding sequence D enc ; (2). The step S4.3 includes the following sub-steps: S4.
31. DNA base mapping Map the DNA base sequence back to the binary data B using a predetermined DNA coding rule rec , B rec = DNA -1 (D enc ) S4.
32. DNA base mutation correction During decoding, perform inverse mutation correction, and correct according to the shared DNA mutation rate μ and mutation rules to restore the correct binary data. (3). The step S4.4 includes the following sub-steps: S4.
41. Calculate the hash value of the decrypted data H(B rec ) = SHA256(B rec ) S4.
42. Compare with the original hash value Among them, H(B orig ) is the hash value of the data before encryption; S4.
43. Judge integrity If H(B rec ) = H(B orig ), it indicates that the data is complete, and the system outputs the final decryption result B orig ; If H(B rec ) ≠ H(B orig ), it means that the data has been tampered with or decrypted incorrectly. The system terminates the data output and issues a warning to the user.
10. A multi-level privacy protection data sharing system based on blockchain, which applies the multi-level privacy protection data sharing method based on blockchain described in any one of claims 1 to 9, and is characterized in that: It includes a collection layer, a transmission layer, a storage layer, a blockchain service layer, and a user layer. Among them, The collection layer includes collection devices and sensors for collecting raw data. The transmission layer is used to transmit the collected data to the storage layer using the RPL routing protocol. The storage layer is used to perform the following operations: receive the data uploaded by the transport layer, generate an encryption key by using the dynamic DNA coding sequence combined with the AES key expansion method, encrypt the data by using the generated encryption key to obtain an encrypted file, and store the encrypted file in the local repository; the data owner generates a key pair, including a public key and a private key, by using an asymmetric encryption algorithm for digital signature of the encrypted file; the data user submits a data access request through a smart contract on the blockchain and executes a spatio-temporal double decay permission control mechanism for permission verification; after the data owner agrees, the encrypted file is uploaded to the IPFS distributed storage system, and the corresponding IPFS hash address is obtained, and this hash address is linked to the blockchain network after being calculated and encrypted and transformed; The blockchain service layer includes a dynamic hybrid consensus engine and a quantum attack detection module, where, The dynamic hybrid consensus engine is used to adaptively select the optimal consensus mechanism among the PBFT consensus algorithm, the PoS consensus algorithm, and the PoW consensus algorithm, and combine it with the spatio-temporal double decay permission control mechanism to dynamically adjust the consensus strategy; The quantum attack detection module is used to collect the quantum bit error rate data on the quantum communication link in real time and input the quantum bit error rate data into an LSTM model composed of 128 hidden layers for time series analysis; when the predicted quantum bit error rate data exceeds the preset security threshold, the system automatically triggers the quantum key distribution technology; The user layer is used to enable users to access the blockchain service layer through a smart contract and execute the spatio-temporal double decay permission control; and after the permission verification is passed, the smart contract triggers the key management module to provide the decryption key to the user; enable the user to decrypt the data by using the AES decryption algorithm and DNA reverse coding, and at the same time perform data integrity verification.
Citation Information
Cited By
Sequencing data processing method, device, equipment, medium and product
CN121281643A
Sequencing data processing method, apparatus, device, medium, and product
CN121281643B