Data right confirmation method based on data encapsulation body abstract uplink
Through the method of data encapsulation summary and on-chain, combined with blockchain technology, the flexible data segmentation and encapsulation are achieved, and the problems of single point failure risk and insufficient data application flexibility in traditional data rights confirmation methods are solved, ensuring the authenticity and traceability of data ownership.
Patent Information
- Application Number
- CN202510545007.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-28
- Publication Date
- 2025-08-01
AI Technical Summary
Traditional data rights confirmation methods have single point of failure risk, hidden dangers of data leakage, difficult to guarantee authenticity and integrity, are susceptible to malicious tampering and forgery, and do not support the refined segmentation and flexible application of data.
The method of data encapsulation summary is adopted to achieve flexible data segmentation and encapsulation through decentralized blockchain networks and smart contracts, and a hash digest is generated as a unique identifier to transfer ownership and confirm the security and traceability of the data.
It effectively solves the risk of single point of failure, enhances the authenticity and traceability of data ownership, improves the flexibility and security of data applications, prevents data tampering, and meets the needs of large-scale storage.
Smart Images

Figure CN120415682A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data ownership confirmation, and in particular to a data package ownership confirmation method based on uploading a data package summary to a chain. Background Art
[0002] With the advent of the digital age, the amount of information is growing exponentially, and data has become a core resource for value creation for businesses and individuals. However, security risks such as tampering, theft, and misuse are constantly emerging during the storage, circulation, and sharing of data. Traditional centralized data management models are no longer able to meet the demands of modern society for data privacy and security. Especially with the widespread application of cloud computing, big data, and artificial intelligence, ensuring data ownership, integrity, and tamper-proofing has become a critical issue that needs to be addressed.
[0003] Traditional data ownership verification methods typically rely on the authentication and auditing of data as a whole, relying primarily on centralized certification bodies. This lacks flexibility and makes it difficult to support refined data ownership verification. Centralized approaches also present a single point of failure risk. If the certification body is attacked or a data leak occurs, the authenticity and integrity of the data cannot be guaranteed. Furthermore, centralized management models are prone to malicious tampering and data forgery, which in turn affects data credibility and can even lead to legal and compliance issues.
[0004] With the rapid development of blockchain technology, its decentralized, tamper-proof, and transparent features offer a more secure and efficient solution for data ownership verification. Through distributed storage and smart contract technology, blockchain automates and bolsters the data ownership verification process, making data storage, transactions, and traceability more transparent and verifiable, reducing reliance on centralized institutions and enhancing data security and reliability. This has led to widespread application of blockchain technology in data ownership verification. However, the continued expansion of data volumes presents new challenges for blockchain storage and ownership verification. Directly storing and verifying complete data is not only prohibitively expensive, but also hinders flexible data segmentation and application.
[0005] Therefore, how to support refined data rights confirmation, prevent data leakage, ensure the authenticity and integrity of data, eliminate malicious tampering and falsification of data, meet the growing storage needs, and improve data application flexibility on the basis of solving the single point failure risk of traditional data rights confirmation methods is an important issue that needs to be urgently addressed in the current data rights confirmation field. Summary of the Invention
[0006] The technical problem to be solved by the present invention is to address the problems existing in traditional data rights confirmation methods, such as the risk of single-point failure, the potential for data leakage, the difficulty in ensuring authenticity and integrity, susceptibility to malicious tampering, forgery, and attacks, and the lack of flexibility in data applications due to the inability to support data segmentation for the growing amount of data. A data rights confirmation method based on the blockchain storage of data encapsulation body summaries is proposed. While realizing flexible data segmentation and encapsulation, it combines blockchain evidence storage technology to solve the single-point failure risk problem, effectively enhance the security of data rights confirmation, and ensure the authenticity and traceability of data ownership.
[0007] The present invention includes the following steps:
[0008] In the first step, a data encapsulation rights confirmation system is constructed. The data encapsulation rights confirmation system consists of a server side, multiple client sides, and a blockchain network.
[0009] The blockchain network is a decentralized system that eliminates the dependence on central nodes through a decentralized mechanism. The server side stores the encapsulation body on the blockchain network by calling the blockchain smart contract. The client side realizes the transfer and confirmation of the encapsulation body rights on the blockchain network by calling the blockchain smart contract through the server side.
[0010] The client side is installed with a data owner module and a data user module. When the data owner module of the client side works, the client side acts as a data owner. The data owner can publish the data it owns to the encapsulation body warehouse in the data user module in the form of a data encapsulation body through the server side for the data user to select, apply for, and use. When the data user module of the client side works, the client side acts as a data user. The data user can apply for the data encapsulation body it needs in the encapsulation body warehouse and use the data encapsulation body for data development and utilization after the application is approved. The data owner module is connected to the blockchain and the server side and encapsulates the owned structured data. The structured data is generally stored in structured databases such as MySQL, MongoDB, and PostgreSQL, or stored in the form of a csv file. When the data owner module needs to share data, it sends database connection information, data segmentation information, the decentralized identity DID (Decentralized ID) of the data owner, the application approval result, and the basic information of the encapsulation body to the server side and receives the encapsulation body application information, database name, table name, and field name from the server side. The data user module includes an encapsulation body warehouse, is connected to the blockchain and the server side, sends the encapsulation body application information to the server side, and receives the encapsulation body hash summary, the basic information of the encapsulation body, the ownership verification notice, and the application approval result notice from the server side and displays the basic information of the encapsulation body and the encapsulation body hash summary.
[0011] The server is installed with a data splitting module, a data encapsulation module, a hash digest module, an encapsulation body publishing module, an encapsulation body uploading module, an encapsulation body application module, and an encapsulation body rights confirmation module.
[0012] The data splitting module is connected to the data owner module of the data owner, receives the database connection information and data splitting information sent by the data owner module, obtains the data split body from the database or csv file pointed to by the database connection information according to the data splitting information, and sends the data split body to the data encapsulation module;
[0013] The data encapsulation module is connected to the data owner module of the data owner, the data splitting module, the hash digest module, and the encapsulation body publishing module. It receives the encapsulation body basic information from the data owner module, receives the data split body from the data splitting module, encapsulates the data split body according to the encapsulation body basic information to obtain the data encapsulation body, transfers the data in the data encapsulation body to a csv file to obtain the encapsulation body data csv file, sends the encapsulation body data csv file and the encapsulation body basic information to the hash digest module, and sends the encapsulation body basic information to the encapsulation body publishing module;
[0014] The hash digest module is connected to the data encapsulation module, the encapsulation body publishing module, and the encapsulation body uploading module. It receives the encapsulation body data csv file and the encapsulation body basic information from the data encapsulation module, generates the encapsulation body hash digest through the hash algorithm, and sends the encapsulation body hash digest to the encapsulation body publishing module and the encapsulation body uploading module;
[0015] The encapsulation body publishing module is connected to the data encapsulation module, the hash digest module, the encapsulation body uploading module, and the data user module of the data user. It receives the encapsulation body basic information from the data encapsulation module, receives the encapsulation body hash digest from the hash digest module, publishes the encapsulation body basic information and the encapsulation body hash digest to the encapsulation body repository in the data user module of the data user; and sends the encapsulation body basic information to the encapsulation body uploading module.
[0016] The encapsulation body uploading module is connected to the data owner module of the data owner, the encapsulation body publishing module, the hash digest module, and the blockchain. It receives the data owner's decentralized identity DID from the data owner module, receives the encapsulation body hash digest from the hash digest module, receives the encapsulation body basic information from the encapsulation body publishing module, calls the smart contract, uses the encapsulation body hash digest as the unique identifier of the encapsulation body, and stores it on the blockchain together with the DID and the encapsulation body basic information;
[0017] The encapsulation application module is connected to the data owner module of the data owner, the data user module of the data user, and the blockchain. It receives the encapsulation application information (including the hash digest of the data encapsulation body to be applied for, the application purpose, the application fields, and the DID of the data user) from the data user module, and sends the encapsulation application information to the data owner module of the data owner who created the data encapsulation body. It receives the application approval result from the data owner module of the data owner. If the application approval result is passed, the encapsulation application module calls the smart contract and passes the DID of the data owner, the DID of the data user, and the hash digest of the encapsulation body into the blockchain. The smart contract transfers the ownership of the data encapsulation body on the blockchain according to the DID of the data owner and the hash digest of the encapsulation body, and adds the DID of the data user to the ownership of the data encapsulation body, that is, allows the data user to use the data encapsulation body for data development.
[0018] The encapsulation ownership confirmation module is connected to the data user module of the data user and the blockchain. It receives the DID of the data user and the hash digest of the encapsulation body to be used from the data user module, calls the smart contract, and performs ownership verification on the blockchain according to the DID of the data user and the hash digest of the encapsulation body to be used to confirm whether the data user has the ownership of the data encapsulation body. It receives the encapsulation ownership confirmation result from the blockchain and sends an ownership verification notice to the data user module of the data user according to the encapsulation ownership confirmation result.
[0019] In the second step, the data owner module of the data owner sends the database connection information and data splitting information to the server-side data splitting module. The server-side data splitting module splits the data provided by the data owner module. The method is as follows:
[0020] 2.1 When the data owner module needs to share data, the data owner module sends the database connection information to the data splitting module; the database connection information includes the database connection address and port, the database connection name, and the database connection password (supporting MySQL, MongoDB, PostgreSQL, or csv files, and the csv files are uploaded in the file transfer protocol mode).
[0021] 2.2 The data owner module sends the data splitting information according to the content that can be shared, including the selected database name, the selected data table name, the selected data field name, and the row granularity restriction condition; the row granularity restriction condition refers to the restriction condition for the selected data field value when selecting data fields according to the selected data field name, that is, only the fields that meet the restriction condition are selected. The data splitting module receives the database connection information and the data splitting information from the data owner module, and splits the database or csv file pointed to by the database connection information to obtain the data split body. The method is as follows:
[0022] 2.2.1 The data splitting module receives the database connection information sent by the data owner module;
[0023] 2.2.2 The data splitting module obtains all the database names provided by the data owner module according to the database connection information, and returns all the database names to the data owner module;
[0024] 2.2.3 In all the database names, the data owner module selects databases according to the sharable database information, and returns the selected database names to the data splitting module;
[0025] 2.2.4 The data splitting module receives the selected database names from the data owner module, obtains the command through the database table name, obtains all the table names in the corresponding database according to the selected database names, and returns all the table names in the corresponding database to the data owner module;
[0026] 2.2.5 In all the table names provided by the data splitting module, the data owner module selects data tables according to the sharable data table information, and returns the selected data table names to the data splitting module;
[0027] 2.2.6 The data splitting module receives the selected data table names from the data owner module, obtains the command through the database field name, obtains all the field names in the data table corresponding to the selected data table names, and returns all the field names in the selected data table to the data owner module;
[0028] 2.2.7 In all the field names provided by the data splitting module, the data owner module selects data fields according to the sharable data field information, and returns the selected data field names to the data splitting module;
[0029] 2.2.8 The data owner module sets row granularity limit conditions for the fields according to the sharable data rows, and returns the row granularity limit conditions to the data splitting module;
[0030] 2.2.9 The data splitting module remotely connects according to the database connection information and the selected database name, selected data table name, selected data field name, and row granularity limit conditions in the data splitting information, and obtains the selected data table name, selected data field name, and corresponding data that meet the row granularity limit conditions from the database corresponding to the selected database name through the database data acquisition command, and obtains the data split body;
[0031] 2.3 The data splitting module sends the data split body to the data encapsulation module.
[0032] In the third step, the data encapsulation module encapsulates the data split body to obtain the data encapsulation body. The method is as follows:
[0033] 3.1 The data encapsulation module receives data chunks from the data splitting module and sends an application for basic information of the encapsulation body to the data owner module.
[0034] 3.2 The data owner module receives the application for basic information of the encapsulation body from the data encapsulation module and sends the basic information of the encapsulation body to the data encapsulation module. The basic information of the encapsulation body includes the id of the encapsulation body owner, the name of the encapsulation body, the privacy level of the fields in the encapsulation body, the category of the encapsulation body, the number of CPUs required for the encapsulation body, and the memory size required for the encapsulation body.
[0035] 3.3 The data encapsulation module receives the basic information of the encapsulation body from the data owner module.
[0036] 3.4 The data encapsulation module constructs a Docker container containing MongoDB; according to the number of CPUs required and the memory size required for the encapsulation body in the basic information of the encapsulation body, it allocates specified CPU and memory resources to the Docker container, and stores the data chunks in the MongoDB of the Docker container to obtain a data encapsulation body.
[0037] 3.5 The data encapsulation module transfers the data in the data encapsulation body to a csv file to obtain an encapsulated body data csv file, sends the encapsulated body data csv file and the basic information of the encapsulation body to the hash digest module, and sends the basic information of the encapsulation body to the encapsulation body publishing module.
[0038] In the fourth step, the hash digest module generates a hash digest of the data encapsulation body using a hash algorithm. The method is as follows:
[0039] 4.1 The hash digest module receives the encapsulated body data csv file and the basic information of the encapsulation body from the data encapsulation module.
[0040] 4.2 The hash digest module constructs a hash algorithm library, which contains three hash algorithms: SHA256, SHA-3, and BLAKE2b. Let the numbers of these three hash algorithms be 0, 1, and 2 respectively.
[0041] 4.3 The hash digest module splits the encapsulated body data csv file into N data blocks, and the size of each data block is M. represents the ceiling of the csv file size divided by M. Let the number of the data block be n, 1 ≤ n ≤ N, and M is 2 k KB, where k is a positive integer. Preferably, M is 4KB or 8KB.
[0042] 4.4 The hash digest module generates a data hash digest based on N data blocks: Taking the order of the N data blocks in the csv file, use the N data blocks as leaf nodes to grow upward to construct a full K-ary tree, such that the height of the full K-ary tree is 3, and generate the hash digest of the corresponding nodes during the upward construction of the full K-ary tree. When the full K-ary tree is constructed, obtain the hash digest of the root node as the data hash digest. The specific method is as follows:
[0043] 4.4.1 Calculate the value of K according to N,
[0044] 4.4.2 Taking the order of the N data blocks in the csv file, use the N data blocks as leaf nodes;
[0045] 4.4.3 Use the polling method hash digest generation method to sequentially select a hash algorithm from the hash algorithm library (that is, for SHA256, SHA-3, BLAKE2b, for the nth leaf node, use the hash algorithm numbered mod(n - 1, 3)), generate the hash digests of the N leaf nodes. The hash digests of these N leaf nodes are used as the values of the first N leaf nodes of the full K-ary tree with a height of 3, and supplement K 2 - N null value leaf nodes after the N leaf nodes to obtain K 2 leaf nodes, and let the number of the leaf nodes be k, 1 ≤ k ≤ K 2 ;
[0046] 4.4.4 Grow upward from the K 2 leaf nodes to generate a full K-ary tree and obtain the data hash digest. The method is as follows:
[0047] 4.4.4.1 Connect the values of the leaf nodes numbered 1 to K; connect the values of the leaf nodes numbered K + 1 to 2K; …; connect the values of the leaf nodes numbered (i - 1)K + 1 to iK; …; connect the values of the leaf nodes numbered (K - 1)K + 1 to K 2 to obtain K nodes on the second layer of the full K-ary tree;
[0048] 4.4.4.2 Use the polling method hash digest generation method described in 4.4.3 to generate the hash digests of the K nodes on the second layer of the full K-ary tree. These K hash digests are used as the values of the K nodes on the second layer of the full K-ary tree with a height of 3;
[0049] 4.4.4.3 Connect the values of the K nodes on the second layer of the full K-ary tree to obtain the root node of the third layer (i.e., the topmost root) of the full K-ary tree;
[0050] 4.4.4.4 Select the SHA256 hash algorithm from the hash algorithm library to generate the hash digest of the root node as the value of the root node of the full K-ary tree with a height of 3; use the value of the root node of the full K-ary tree as the data hash digest;
[0051] 4.5 The hash digest module uses the SHA256 hash algorithm to generate a hash digest of the basic information of the encapsulated body for the basic information of the encapsulated body.
[0052] 4.6 The hash digest module connects the hash digest of the basic information of the encapsulated body with the data hash digest, and after connection, performs hash calculation again using SHA256 to obtain the encapsulated body hash digest, and sends the encapsulated body hash digest to the encapsulated body publishing module and the encapsulated body blockchain module.
[0053] In the fifth step, the encapsulated body publishing module receives the basic information of the encapsulated body from the data encapsulation module, receives the encapsulated body hash digest from the hash digest module, and sends the basic information of the encapsulated body and the encapsulated body hash digest to the data user's data user module; the data user's data user module receives the basic information of the encapsulated body and the encapsulated body hash digest and displays them in the encapsulated body repository; the encapsulated body publishing module sends the basic information of the encapsulated body to the encapsulated body blockchain module; after receiving the basic information of the encapsulated body, the encapsulated body blockchain module sends a DID application to the data owner module.
[0054] In the sixth step, the server-side encapsulated body blockchain module uploads the encapsulated body hash digest, the DID of the data owner, and the basic information of the encapsulated body to the blockchain. The method is as follows:
[0055] 6.1 The data owner module receives the DID application from the encapsulated body blockchain module and sends the DID of the data owner to the encapsulated body blockchain module;
[0056] 6.2 The encapsulated body blockchain module receives the DID of the data owner from the data owner module, receives the basic information of the encapsulated body from the encapsulated body publishing module, and receives the encapsulated body hash digest from the hash digest module, and stores the encapsulated body hash digest, the DID of the data owner, and the basic information of the encapsulated body in the blockchain through a smart contract for on-chain evidence storage; among them, the encapsulated body hash digest is used as the unique identifier of the encapsulated body.
[0057] In the seventh step, the encapsulated body application module transfers the ownership of the encapsulated body. The method is as follows:
[0058] 7.1 If the encapsulated body application module receives the encapsulated body application information sent from the data user's data user module, go to 7.2; if it does not receive the encapsulated body application information sent from the data user's data user module, go back to 7.1 to continue monitoring. Among them, the encapsulated body application information includes the hash digest of the data encapsulated body applied for, the application purpose, the application fields, the DID of the data user, and the ID of the owner of the encapsulated body.
[0059] 7.2 The encapsulation application module finds the data owner corresponding to the data encapsulation according to the encapsulation owner ID, and sends the encapsulation application information to the data owner module that created the data owner corresponding to the data encapsulation;
[0060] 7.3 The data owner module receives the encapsulation application information from the encapsulation application module and conducts an approval based on the application information. If the application purpose and application fields meet the usage requirements of the data owner, the application is approved, and a "Approval result passed" notification and the DID of the data owner are sent to the encapsulation application module; if the application purpose or application fields do not meet the usage requirements of the data owner, the application is not approved, and a "Approval result not passed" notification is sent to the encapsulation application module;
[0061] 7.4 The encapsulation application module receives the approval result from the data owner module. If the approval result is passed, it calls the smart contract, passes in the DID of the data owner, the DID of the data user, and the encapsulation hash digest of the corresponding data encapsulation from the encapsulation application module, finds the corresponding data encapsulation on the blockchain based on the data owner DID and the encapsulation hash digest, and conducts a transfer of the ownership of the data encapsulation, transferring the ownership of the data encapsulation from the data owner to the data user corresponding to the DID of the data user, and sending a "Ownership transfer successful" message to the data user module; if the approval result is not passed, it sends an "Ownership transfer failed" to the client data user module;
[0062] 7.5 The data user module receives the ownership transfer result from the encapsulation application module. If the received message is "Ownership transfer successful", it means that the data user can use the data encapsulation, and proceeds to the eighth step; if it is an "Ownership transfer failed" message, it proceeds to 7.6;
[0063] 7.6 The data owner module fails to obtain the ownership of the data encapsulation. The data owner module displays "Failed to obtain the ownership of the data encapsulation" and proceeds to the ninth step.
[0064] In the eighth step, the server-side encapsulation ownership confirmation module confirms the ownership of the encapsulation. The method is as follows:
[0065] 8.1 The data user module sends the data encapsulation hash digest and the DID of the data user to the encapsulation ownership confirmation module;
[0066] 8.2 The encapsulation ownership confirmation module receives the encapsulation hash digest and the DID of the data user from the data user module, calls the smart contract, and verifies on the blockchain whether the DID owns the ownership of the data encapsulation; if it owns the ownership, that is, the encapsulation ownership confirmation result received from the blockchain is successful, it sends a "Ownership verification successful" notification to the data user module; if the encapsulation ownership confirmation result received from the blockchain is a failure, it sends an "Ownership verification failed" notification to the client data user module;
[0067] 8.3 The data user module receives a notification of ownership verification from the encapsulation body ownership confirmation module. If the received notification is "ownership verification successful", the data user module displays "It is possible to use the data encapsulation body to develop the encapsulated body data", and proceeds to the ninth step; if the received notification is "ownership verification failed", it proceeds to 8.4.
[0068] 8.4 The data owner module displays "The ownership confirmation of the data encapsulation body fails", and proceeds to the ninth step.
[0069] The ninth step, end.
[0070] Adopting the present invention can achieve the following technical effects:
[0071] 1. The present invention divides the data in the database through the data splitting module, and only selects certain databases, data tables, data fields, and data rows that the data owner wants to share and open for the complete data, splits to obtain the data split body, and encapsulates the data split body into a data encapsulation body through the data encapsulation module; divides the large data into small data, enhances the flexible application ability of the data, thereby solving the problems that the traditional method is difficult to support large-scale data ownership confirmation and the application flexibility is insufficient.
[0072] 2. The present invention generates the hash digest of the encapsulation body through the hash digest module, and generates the hash digest using a tree structure, preventing the memory overflow problem caused by excessive data volume, and effectively reducing the time overhead; the generated encapsulation body hash digest is used as the unique identifier of the data encapsulation body, transfers ownership on the blockchain based on the encapsulation body hash digest in the seventh step, and confirms ownership on the blockchain based on the encapsulation body hash digest in the eighth step, effectively avoiding the risk of single point of failure, while enhancing the security of data ownership confirmation, and ensuring the authenticity and traceability of data ownership. Description of the Drawings
[0073] Figure 1 is the logical structure diagram of the data ownership confirmation system constructed in the first step of the present invention;
[0074] Figure 2 is the overall flow chart of the present invention.
[0075] Figure 3 is the schematic diagram of the full K-ary tree and encapsulation body digest generation formed in the fourth step of the embodiment. Detailed Embodiment
[0076] The present invention will be further described below in conjunction with the drawings and embodiments. In order to verify the effect of the present invention, the confirmation of the student achievement database is used as an example for description.
[0077] As Figure 2 shown, the present invention includes the following steps:
[0078] In the first step, a data encapsulation and rights confirmation system is constructed. As shown in Figure 1 Figure, it consists of a server side, multiple client sides, and a blockchain network.
[0079] The blockchain network is a decentralized system that eliminates the dependence on central nodes through a decentralized mechanism. The server side stores the encapsulation body on the blockchain network by calling the blockchain smart contract, and the client side realizes the transfer and confirmation of the ownership of the encapsulation body on the blockchain network by calling the blockchain smart contract through the server side.
[0080] In the embodiment, the server runs in the CentOS 7.8.2003 operating system environment, is equipped with dual Intel Xeon E5-2609 v2 processors (8 cores, main frequency 2.5 GHz), has 188.68 GB of memory, and the storage configuration includes a 1.6 TB system disk and a 44 T data disk, which can provide hardware guarantee for the deployment and use of data encapsulation. The container environment uses the Docker 19.03.0 version, and the blockchain network is built based on the Hyperledger Fabric 2.5 version. The tests of the data user module and the data owner module in the client are both carried out on the Windows system, and the front-end functions are visually tested through the Google Chrome browser (version 135.0.7049.97). In terms of the shared data source, the MySQ database, version 8.0, is used for the management and
[0081] access of structured data. The id obtained by the encapsulation body owner registering an account is 69, the DID provided by the data owner is did:sov:2pD3i91jUzE2FcjHQ9Q5t7A4Q1HRbbgWq2DTVVX46t7g, and the DID provided by the data user is did:sov:WRfXPg8dJ1vE7XYfP8F1aHpLJPtn51UGy41E5FhEKkj5.
[0082] The client is installed with a data owner module and a data user module. When the data owner module of the client works, the client acts as a data owner. The data owner can publish the data it owns to the package repository in the data user module in the form of data packages through the server, for the data user to select, apply for and use. When the data user module of the client works, the client acts as a data user. The data user can apply for the data packages it needs in the package repository and use the data packages for data development and utilization after the application is approved. The data owner module is connected to the blockchain and the server, and encapsulates the structured data it owns. The structured data is generally stored in structured databases such as MySQL, MongoDB, PostgreSQL, or stored in the form of csv files. When the data owner module needs to share data, it sends database connection information, data segmentation information, the decentralized identity DID of the data owner, application approval results, and basic package information to the server, and receives package application information, database name, table name, and field name from the server. The data user module contains a package repository, is connected to the blockchain and the server, sends package application information to the server, and receives the package hash digest, basic package information, ownership verification notice, and application approval result notice from the server, and displays the basic package information and the package hash digest.
[0083] The server is installed with a data segmentation module, a data encapsulation module, a hash digest module, a package publishing module, a package on-chain module, a package application module, and a package right confirmation module.
[0084] The data segmentation module is connected to the data owner module of the data owner, receives the database connection information and data segmentation information sent by the data owner module, obtains the data segments from the database or csv file pointed to by the database connection information according to the data segmentation information, and sends the data segments to the data encapsulation module;
[0085] The data encapsulation module is connected to the data owner module of the data owner, the data segmentation module, the hash digest module, and the package publishing module. It receives the basic package information from the data owner module, receives the data segments from the data segmentation module, encapsulates the data segments according to the basic package information to obtain the data package, saves the data in the data package as a csv file to obtain the package data csv file, sends the package data csv file and the basic package information to the hash digest module, and sends the basic package information to the package publishing module;
[0086] The hash digest module is connected to the data encapsulation module, the encapsulation body publishing module, and the encapsulation body blockchain-uploading module. It receives the encapsulation body data csv file and the basic information of the encapsulation body from the data encapsulation module, generates the hash digest of the encapsulation body through a hash algorithm, and sends the hash digest of the encapsulation body to the encapsulation body publishing module and the encapsulation body blockchain-uploading module;
[0087] The encapsulation body publishing module is connected to the data encapsulation module, the hash digest module, the encapsulation body blockchain-uploading module, and the data user module of the data user. It receives the basic information of the encapsulation body from the data encapsulation module and the hash digest of the encapsulation body from the hash digest module, and publishes the basic information of the encapsulation body and the hash digest of the encapsulation body to the encapsulation body repository in the data user module of the data user; it sends the basic information of the encapsulation body to the encapsulation body blockchain-uploading module.
[0088] The encapsulation body blockchain-uploading module is connected to the data owner module of the data owner, the encapsulation body publishing module, the hash digest module, and the blockchain. It receives the decentralized identity DID of the data owner from the data owner module, the hash digest of the encapsulation body from the hash digest module, and the basic information of the encapsulation body from the encapsulation body publishing module, calls the smart contract, uses the hash digest of the encapsulation body as the unique identifier of the encapsulation body, and stores it together with the DID and the basic information of the encapsulation body on the blockchain;
[0089] The encapsulation body application module is connected to the data owner module of the data owner, the data user module of the data user, and the blockchain. It receives the encapsulation body application information (including the hash digest of the data encapsulation body to be applied for, the application purpose, the application fields, and the DID of the data user) from the data user module, sends the encapsulation body application information to the data owner module of the data owner who created the data encapsulation body, and receives the application approval result from the data owner module of the data owner. If the application approval result is passed, the encapsulation body application module calls the smart contract, passes the DID of the data owner, the DID of the data user, and the hash digest of the encapsulation body into the blockchain. The smart contract transfers the ownership of the data encapsulation body on the blockchain according to the DID of the data owner and the hash digest of the encapsulation body, and adds the DID of the data user to the ownership of the data encapsulation body, that is, allows the data user to use the data encapsulation body for data development;
[0090] The encapsulation body ownership confirmation module is connected to the data user module of the data user and the blockchain. It receives the DID of the data user and the hash digest of the encapsulation body to be used from the data user module, calls the smart contract, performs ownership verification on the blockchain according to the DID of the data user and the hash digest of the encapsulation body to be used, confirms whether the data user owns the ownership of the data encapsulation body, receives the ownership confirmation result from the blockchain, and sends an ownership verification notice to the data user module of the data user according to the ownership confirmation result.
[0091] Step 2: The data owner module of the data owner sends database connection information and data splitting information to the server-side data splitting module. The server-side data splitting module splits the data provided by the data owner module as follows:
[0092] 2.1 When the data owner module needs to share data, it sends database connection information to the data splitting module. The database connection information includes the database connection address and port, the database connection name, and the database connection password (supporting MySQL, MongoDB, PostgreSQL, or csv files, and the csv files are uploaded via the file transfer protocol).
[0093] 2.2 The data owner module sends data splitting information according to the content that can be shared, including the selected database name, the selected data table name, the selected data field name, and the row granularity restriction condition. The row granularity restriction condition refers to the restriction condition on the selected data field value when selecting data fields based on the selected data field name, that is, only the fields that meet the restriction condition are selected. The data splitting module receives the database connection information and data splitting information from the data owner module and splits the database or csv file pointed to by the database connection information as follows:
[0094] 2.2.1 The data splitting module receives the database connection information sent by the data owner module.
[0095] 2.2.2 The data splitting module obtains all the database names provided by the data owner module according to the database connection information and returns all the database names to the data owner module.
[0096] 2.2.3 Among all the database names, the data owner module selects a database according to the shareable database information and returns the selected database name to the data splitting module. For example, for the student achievement database connection, there are 3 databases, namely the seventh-grade student database (including 3 tables, namely the seventh-grade student information table, the seventh-grade course information table, and the seventh-grade student achievement table), the eighth-grade student database, and the ninth-grade student database (including 3 tables, namely the ninth-grade student information table, the ninth-grade course information table, and the ninth-grade student achievement table). The shareable database information is only the seventh-grade student database and the ninth-grade student database. Therefore, the data owner module selects the seventh-grade student database and the ninth-grade student database and returns the selected database names (i.e., the seventh-grade student database name and the ninth-grade student database name) to the data splitting module.
[0097] 2.2.4 The data segmentation module receives the selected database names (i.e., the seventh-grade student database name and the ninth-grade student database name) from the data owner module, obtains the command through the database table name, and obtains all the table names in the corresponding database according to the selected database names (in this embodiment, the names of the six tables are the seventh-grade student information table, the seventh-grade course information table, the seventh-grade student achievement table, the ninth-grade student information table, the ninth-grade course information table, and the ninth-grade student achievement table), and returns all the table names in the corresponding database to the data owner module;
[0098] 2.2.5 In all the table names provided by the data segmentation module, the data owner module selects the data tables according to the shareable data table information and returns the selected data table names to the data segmentation module; for example, in the seventh-grade student database and the ninth-grade student database, the only shareable data table information is the seventh-grade student achievement table (as shown in Table 1) and the ninth-grade student achievement table (as shown in Table 2). Therefore, the data owner module selects the seventh-grade student achievement table and the ninth-grade student achievement table and returns the selected data table names (i.e., the names of the seventh-grade student achievement table and the ninth-grade student achievement table) to the data segmentation module;
[0099]
[0100]
[0101]
[0102]
[0103] 2.2.6 The data segmentation module receives the selected data table names from the data owner module, obtains the command through the database field name, and obtains all the field names in the corresponding data table according to the selected data table names (in this embodiment, there are 5 fields, namely the field primary key id, student number, student name, selected course, and achievement), and returns all the field names in the selected data table to the data owner module;
[0104] 2.2.7 In all the field names provided by the data segmentation module, the data owner module selects the data fields according to the shareable data field information and returns the selected data field names to the data segmentation module; for example, among the 5 fields of the seventh-grade student achievement table and the ninth-grade student achievement table, the shareable data field information is the three fields of primary key id, selected course, and achievement. Then the data owner module selects the three fields of primary key id, selected course, and achievement of the seventh-grade student achievement table and the ninth-grade student achievement table and returns the selected data field names to the data segmentation module;
[0105] 2.2.8 The data owner module sets row-level restriction conditions for fields according to the data rows that can be shared, and returns the row-level restriction conditions to the data splitting module; for example, in the embodiment, for the score field (which is of floating-point value type), the restriction condition "score value > 80" is set and returned to the data splitting module;
[0106] 2.2.9 The data splitting module remotely connects according to the database connection information and the selected database name, selected data table name, selected data field name, and row-level restriction conditions in the data splitting information, and obtains the corresponding data that meets the row-level restriction conditions for the selected data table name and selected data field name from the database corresponding to the selected database name through the database data acquisition command, obtaining a data split body; for example, in the embodiment, according to the above-mentioned selected database name, selected data table name, selected data field name, and row-level restriction conditions, the seventh-grade student score table in the seventh-grade student database and the ninth-grade student score table in the ninth-grade student database are finally obtained. Both the seventh-grade student score table and the ninth-grade student score table contain three fields: the primary key id, the selected course, and the score, and only the rows with a score greater than 80 are obtained. The obtained data split bodies are shown in Tables 3 and 4;
[0107]
[0108]
[0109]
[0110] 2.3 The data splitting module sends the data split body (Tables 3 and 4 in the embodiment) to the data encapsulation module, and sends an application for basic encapsulation body information to the data owner module. The basic encapsulation body information includes the encapsulation body owner id, encapsulation body name, field privacy level in the encapsulation body, encapsulation body category, the number of CPUs required for the encapsulation body, and the memory size required for the encapsulation body (in the embodiment, the encapsulation body owner id is 69, the encapsulation body name is the data encapsulation body of seventh-grade and ninth-grade scores greater than 80, the field privacy levels in the encapsulation body are all medium privacy levels, the encapsulation body category is the education category, the number of CPUs required for the encapsulation body is 2, and the memory size required for the encapsulation body is 4).
[0111] The third step, the data encapsulation module encapsulates the data split body to obtain a data encapsulation body. The method is as follows:
[0112] 3.1 The data encapsulation module receives the data split body (Tables 3 and 4 in the embodiment) from the data splitting module;
[0113] 3.2 The data owner module receives the application for basic encapsulation body information from the data splitting module and sends the basic encapsulation body information to the data encapsulation module;
[0114] 3.3 The data encapsulation module receives the basic information of the encapsulation body from the data owner module and receives the data split bodies from the data splitting module.
[0115] 3.4 The data encapsulation module constructs a Docker container containing MongoDB, allocates specified CPU and memory resources to the Docker container according to the required CPU quantity and required memory size in the basic information of the encapsulation body, and stores the data split bodies into the MongoDB of the Docker container to obtain the data encapsulation body.
[0116] 3.5 The data encapsulation module transfers the data in the data encapsulation body to a csv file to obtain the encapsulated body data csv file, sends the encapsulated body data csv file and the basic information of the encapsulation body to the hash digest module, and sends the basic information of the encapsulation body to the encapsulation body publishing module. In the embodiment, Table 3 becomes the grade table of seventh - grade students with grades greater than 80.csv, and Table 4 becomes the grade table of ninth - grade students with grades greater than 80.csv.
[0117] The fourth step, the hash digest module generates the hash digest of the data encapsulation body by using a hash algorithm. The method is as follows:
[0118] 4.1 The hash digest module receives the encapsulated body data csv file and the basic information of the encapsulation body from the data encapsulation module.
[0119] 4.2 The hash digest module constructs a hash algorithm library, which contains three hash algorithms: SHA256, SHA - 3, and BLAKE2b. Let the numbers of these three hash algorithms be 0, 1, and 2 respectively.
[0120] 4.3 The hash digest module splits the encapsulated body data csv file into N data blocks, and the size of each data block is M. represents the ceiling of the csv file size divided by M. Let the number of the data block be n, 1 ≤ n ≤ N. In the embodiment, the csv file sizes are 10.7KB and 12KB respectively, M is 4KB, and N is 6.
[0121] 4.4 The hash digest module generates the data hash digest according to the N data blocks: taking the N data blocks in the order in which they appear in the csv file, using the N data blocks as leaf nodes to grow upward to construct a full K - ary tree, making the height of the full K - ary tree be 3, and generating the hash digest of the corresponding nodes during the upward construction of the full K - ary tree. When the full K - ary tree is constructed, the hash digest of the root node is obtained as the data hash digest. The specific method is as follows:
[0122] 4.4.1 Calculate the K value according to N. In the embodiment, K = 3.
[0123] 4.4.2 Take the N data blocks in the order in which they appear in the csv file as leaf nodes;
[0124] 4.4.3 Use a polling method for the hash digest generation method to sequentially select a hash algorithm from the hash algorithm library (that is, for SHA256, SHA-3, BLAKE2b, for the nth leaf node, use the hash algorithm numbered mod(n - 1, 3)) to generate the hash digests of the N leaf nodes. The hash digests of these N leaf nodes are used as the values of the first N leaf nodes of a full K-ary tree of height 3, and K 2 - N null value leaf nodes are added after the N leaf nodes to obtain K 2 leaf nodes, and let the number of the leaf nodes be k, where 1 ≤ k ≤ K 2 ;
[0125] 4.4.4 Grow upwards from the K 2 leaf nodes to generate a full K-ary tree and obtain the data hash digest. The method is as follows:
[0126] 4.4.4.1 Concatenate the values of the leaf nodes numbered 1 to K; concatenate the values of the leaf nodes numbered K + 1 to 2K; …; concatenate the values of the leaf nodes numbered (i - 1)K + 1 to iK; …; concatenate the values of the leaf nodes numbered (K - 1)K + 1 to K 2 to obtain K nodes on the second layer of the full K-ary tree;
[0127] 4.4.4.2 Use the polling method for the hash digest generation method described in 4.4.3 to generate the hash digests of the K nodes on the second layer of the full K-ary tree. These K hash digests are used as the values of the K nodes on the second layer of the full K-ary tree of height 3;
[0128] 4.4.4.3 Concatenate the values of the K nodes on the second layer of the full K-ary tree to obtain the root node of the third layer (i.e., the topmost root) of the full K-ary tree. As Figure 3 shown, in this embodiment, the left subtree of the hash digest node of the encapsulation body is a full K-ary tree, that is, the data hash digest tree. The leaf nodes are located on the third layer and come from the hash digests of 6 data blocks generated after the two csv files are chunked, and 3 null value hash digests are added. After the hash digest values of every three leaf nodes are concatenated, the hash digest of its parent node is generated through a hash algorithm to form the nodes on the second layer. Subsequently, the hash digest values of the three nodes on the second layer are concatenated again, and the hash digest of its parent node is generated through a hash algorithm to finally obtain the data hash digest. Finally, the data hash digest is concatenated with the hash digest of the basic information of the encapsulation body, and after SHA256 hash operation, the encapsulation body hash digest is generated. Figure 3 In, since the number of bits of the hash digest string is relatively long, only the first three bits and the last five bits of the hash digest of each node are shown, and the middle part is represented by an ellipsis.
[0129] 4.4.4.4 Select the SHA256 hash algorithm from the hash algorithm library to generate the hash digest of the root node, which is used as the value of the root node of the full K-ary tree with height 3; use the value of the root node of the full K-ary tree as the data hash digest. In the embodiment, the value of the root node of the full K-ary tree is 62a770abe041d5fc8cdac71a95fd4ce309f90593e3ed55ce49963cf343577b5e, so the data hash digest is 62a770abe041d5fc8cdac71a95fd4ce309f90593e3ed55ce49963cf343577b5e.
[0130] 4.5 The hash digest module uses the SHA256 hash algorithm to generate the hash digest of the basic information of the package body for the basic information of the package body. In the embodiment, the hash digest of the basic information of the package body is d0e9ad3d07e05ee7753c24a83216d87c0a3d7b676393d73abf6cd03c5a28ec66.
[0131] 4.6 The hash digest module concatenates the hash digest of the basic information of the package body with the data hash digest, and then uses SHA256 to perform hash calculation again to obtain the package body hash digest, and sends the package body hash digest to the package body publishing module and the package body on-chain module. In the embodiment, the package body hash digest is e66d3ad003b3a1dc9ccff68b5b5fc64b130f66d7fd56a01628b2a2e2b9c64717. Since the package body hash digest is too long, Figure 3 the middle value of the package body hash digest in the figure is replaced by “…”.
[0132] In the fifth step, the package body publishing module receives the basic information of the package body from the data encapsulation module and the package body hash digest from the hash digest module, and sends the basic information of the package body and the package body hash digest to the data user module of the data user; the data user module of the data user receives the basic information of the package body and the package body hash digest and displays them in the package body repository; the package body publishing module sends the basic information of the package body to the package body on-chain module; after receiving the basic information of the package body, the package body on-chain module sends a DID application to the data owner module.
[0133] In the sixth step, the server-side package body on-chain module uploads the package body hash digest to the blockchain. The method is as follows:
[0134] 6.1 The data owner module receives the DID application from the package body on-chain module and sends the DID of the data owner to the package body on-chain module.
[0135] 6.2 The encapsulation body on-chain module receives the DID of the data owner from the data owner module, receives the basic information of the encapsulation body from the encapsulation body publishing module, and receives the encapsulation body hash digest from the hash digest module. It stores the encapsulation body hash digest, the DID of the data owner, and the basic information of the encapsulation body on the blockchain through a smart contract for on-chain evidence storage; among them, the encapsulation body hash digest serves as the unique identifier of the encapsulation body.
[0136] Step 7, the encapsulation body application module transfers the ownership of the encapsulation body. The method is as follows:
[0137] 7.1 If the encapsulation body application module receives the encapsulation body application information sent by the data user module of the data user, it proceeds to 7.2; if it does not receive the encapsulation body application information sent by the data user module of the data user, it continues to monitor in 7.1. Among them, the encapsulation body application information includes the hash digest of the data encapsulation body applied for, the application purpose, the application fields, the DID of the data user, and the ID of the owner of the encapsulation body. In the embodiment, in the encapsulation body application information, the encapsulation body hash digest is e66d3ad003b3a1dc9ccff68b5b5fc64b130f66d7fd56a01628b2a2e2b9c64717, the application purpose is to count the number of people and subjects with scores above 80 in the seventh and ninth grades, the application fields are the selected course fields and score fields in the seventh-grade student achievement table and the selected course fields and score fields in the ninth-grade student achievement table, the DID of the data user is did:sov:2pD3i91jUzE2FcjHQ9Q5t7A4Q1HRbbgWq2DTVVX46t7g, and the ID of the owner of the encapsulation body is 69.
[0138] 7.2 The encapsulation body application module finds the data owner corresponding to the data encapsulation body according to the owner ID, and sends the encapsulation body application information to the data owner module of the data owner who created the corresponding data encapsulation body;
[0139] 7.3 The data owner module receives the encapsulation body application information from the encapsulation body application module and conducts approval according to the application information. If the application purpose and application fields meet the usage requirements of the data owner, the application is approved, and the "approval result passed" notice and the DID of the data owner are sent to the encapsulation body application module; if the application purpose or application fields do not meet the usage requirements of the data owner, the application is not approved, and the "approval result not passed" notice is sent to the encapsulation body application module; in the embodiment, since the data owner accepts the application fields and application purpose in the encapsulation body application information, the application is approved, and the "approval result passed" notice and the DID of the data owner are sent to the encapsulation body application module.
[0140] 7.4 The encapsulation application module receives the approval result from the data owner module. If the approval result is passed, it calls the smart contract and transfers the DID of the data owner, the DID of the data user, and the encapsulation hash digest of the corresponding data encapsulation from the encapsulation application module to the blockchain. On the blockchain, it finds the corresponding data encapsulation based on the data owner's DID and the encapsulation hash digest, and conducts the transfer of the ownership of the data encapsulation, transferring the ownership of the data encapsulation from the data owner to the data user corresponding to the DID of the data user, and sending a "successful ownership transfer" message to the data user module; if the approval result is not passed, it sends a "failed ownership transfer" to the client data user module; in the embodiment, since the approval result is passed, the ownership transfer is successful, and a "successful ownership transfer" message is sent to the data user module.
[0141] 7.5 The data user module receives the ownership transfer result from the encapsulation application module. If the received message is "successful ownership transfer", it means that the data user can use the data encapsulation, and it proceeds to the eighth step; if it is a "failed ownership transfer" message, it proceeds to 7.6; in the embodiment, since the "successful ownership transfer" message, it proceeds to the eighth step.
[0142] 7.6 The data owner module fails to obtain the ownership of the data encapsulation. The data owner module displays "failed to obtain the ownership of the data encapsulation" and proceeds to the ninth step.
[0143] In the eighth step, the server-side encapsulation ownership confirmation module confirms the ownership of the encapsulation. The method is as follows:
[0144] 8.1 The data user module sends the data encapsulation hash digest and the DID of the data user to the encapsulation ownership confirmation module.
[0145] 8.2 The encapsulation ownership confirmation module receives the data encapsulation hash digest and the DID of the data user from the data user module, calls the smart contract, and verifies on the blockchain whether the DID owns the ownership of the data encapsulation; if it owns the ownership, that is, the encapsulation ownership confirmation result received from the blockchain is successful, it sends a "successful ownership verification" notification to the data user module; if the encapsulation ownership confirmation result received from the blockchain is failed, it sends a "failed ownership verification" notification to the client data user module; in the embodiment, since the data user owns the ownership of the data encapsulation, the ownership verification is successful, and a "successful ownership verification" notification is sent to the data user module.
[0146] 8.3 The data user module receives the ownership verification notification from the encapsulation ownership confirmation module. If the received notification is "successful ownership verification", the data user module displays "can use the data encapsulation to develop the encapsulation data" and proceeds to the ninth step; if the received notification is "failed ownership verification", it proceeds to 8.4.
[0147] 8.4 The data owner module displays "Data package ownership confirmation failed", go to step 9.
[0148] Step 9. End.
[0149] From the above examples, it can be seen that:
[0150] 1. The present invention segments the data in the database through the data segmentation module. Taking the student score database connection as an example, the connection includes three databases for the seventh grade, eighth grade and ninth grade. The data owner can select the student score tables in the seventh grade student database and the ninth grade student database according to the sharing intention, and further specify the shared fields (such as primary key ID, selected subjects, scores) and set row granularity restriction conditions ("score>80"), extract only the records that meet the conditions, form a data segment body, and encapsulate the data segment body into a data encapsulation body through the data encapsulation module; segment large data into small data, enhance the flexible application ability of data, and confirm the rights based on the data encapsulation body, thereby solving the problem that traditional methods are difficult to support large-scale data rights confirmation and lack application flexibility.
[0151] 2. The present invention generates a hash summary of the encapsulation through a hash summary module. Taking the data encapsulation of grades greater than 80 in seventh and ninth grades as an example, a CSV file is generated based on the data therein, and the CSV file is processed in blocks. Each block is used as a leaf node to calculate the hash summary, and a hash summary of the root node is generated through a full ternary tree structure in a bottom-up manner as the data hash summary; the data hash summary and the encapsulation basic information hash summary are used to generate an encapsulation hash summary through the SHA256 algorithm as the unique identifier of the data encapsulation. Generating the hash summary of the entire encapsulation through a tree structure not only effectively prevents the memory overflow problem, but also significantly reduces the time overhead through parallel computing. In the seventh step, ownership is transferred on the blockchain based on the encapsulated hash digest, and in the eighth step, ownership is confirmed on the blockchain based on the encapsulated hash digest. For example, for seventh- and ninth-grade score data encapsulations with scores greater than 80, ownership transfer on the blockchain can only be completed with approval from the encapsulated owner. Data users who do not obtain ownership of the encapsulated data will not be able to pass the ownership verification on the blockchain and thus cannot carry out subsequent data development. Conversely, data users who do obtain ownership of the data encapsulated data will pass the ownership verification and can carry out data development for the encapsulated data. The introduction of blockchain effectively guarantees the accuracy of ownership confirmation, avoids the risk of single points of failure, and ensures the authenticity and traceability of data ownership.
Claims
1. A data rights confirmation method based on the chain - up of data encapsulation body summaries, characterized in that It includes the following steps: In the first step, construct a data encapsulation and rights confirmation system, which consists of a server side, multiple client sides, and a blockchain network; The server side stores the encapsulation body on the blockchain network by calling the blockchain smart contract, and the client side realizes the transfer and confirmation of the ownership of the encapsulation body on the blockchain network by calling the blockchain smart contract through the server side; The client side is installed with a data owner module and a data user module. When the data owner module of the client side works, this client side acts as a data owner. The data owner publishes the data it owns to the encapsulation body warehouse in the data user module in the form of a data encapsulation body through the server side for the data user to select, apply for, and use; when the data user module of the client side works, this client side acts as a data user. The data user applies for the data encapsulation body it needs in the encapsulation body warehouse and uses the data encapsulation body for data development and utilization after the application is approved; the data owner module is connected to the blockchain and the server side; the data user module includes an encapsulation body warehouse and is connected to the blockchain and the server side; The server side is installed with a data splitting module, a data encapsulation module, a hash digest module, an encapsulation body publishing module, an encapsulation body on-chain module, an encapsulation body application module, and an encapsulation body rights confirmation module; In the second step, the data owner module of the data owner sends database connection information and data splitting information to the data splitting module of the server side. The data splitting module of the server side splits the data provided by the data owner module. The method is as follows: 2.1 When the data owner module needs to share data, the data owner module sends database connection information to the data splitting module; the database connection information includes the database connection address and port, the database connection name, and the database connection password; 2.2 The data owner module sends data splitting information according to the shared content, including the selected database name, the selected data table name, the selected data field name, and the row granularity restriction condition; The row granularity restriction condition refers to the restriction condition for the selected data field value when selecting data fields according to the selected data field name, that is, only the fields that meet the restriction condition are selected; the data splitting module receives the database connection information and data splitting information from the data owner module and splits the database or csv file indicated by the database connection information to obtain a data split body; 2.3 The data splitting module sends the data split body to the data encapsulation module; In the third step, the data encapsulation module encapsulates the data split body to obtain a data encapsulation body. The method is as follows: 3.1 The data encapsulation module receives the data split body from the data splitting module and sends an application for basic encapsulation body information to the data owner module; 3.2 The data owner module receives the application for basic encapsulation body information from the data encapsulation module and sends the basic encapsulation body information to the data encapsulation module. The basic encapsulation body information includes the encapsulation body owner id, the encapsulation body name, the field privacy level in the encapsulation body, the encapsulation body category, the required CPU quantity of the encapsulation body, and the required memory size of the encapsulation body; 3.3 The data encapsulation module receives the basic encapsulation body information from the data owner module; 3.4 The data encapsulation module constructs a Docker container containing MongoDB; according to the required number of CPUs and the required memory size in the basic information of the encapsulation body, it allocates specified CPU and memory resources to the Docker container, and stores the data split body into the MongoDB of the Docker container to obtain the data encapsulation body; 3.5 The data encapsulation module transfers the data in the data encapsulation body to a csv file to obtain the encapsulation body data csv file, sends the encapsulation body data csv file and the basic information of the encapsulation body to the hash digest module, and sends the basic information of the encapsulation body to the encapsulation body publishing module; Fourth step, the hash digest module generates the hash digest of the data encapsulation body by using a hash algorithm. The method is as follows: 4.1 The hash digest module receives the encapsulation body data csv file and the basic information of the encapsulation body from the data encapsulation module; 4.2 The hash digest module constructs a hash algorithm library, which contains three hash algorithms, SHA256, SHA-3, and BLAKE2b. Let the numbers of these three hash algorithms be 0, 1, and 2 respectively; 4.3 The hash digest module splits the encapsulation body data csv file into N data blocks, where N is a positive integer, and let the number of the data block be n, 1 ≤ n ≤ N; 4.4 The hash digest module generates the data hash digest according to the N data blocks: taking the N data blocks in the order in the csv file, using the N data blocks as leaf nodes to grow upward to construct a full K-ary tree, making the height of the full K-ary tree 3, and generating the hash digest of the corresponding node during the upward construction of the full K-ary tree. When the full K-ary tree is constructed, the hash digest of the root node is obtained as the data hash digest; 4.5 The hash digest module uses the SHA256 hash algorithm to generate the hash digest of the basic information of the encapsulation body; 4.6 The hash digest module concatenates the hash digest of the basic information of the encapsulation body with the data hash digest, and performs hash calculation again using SHA256 after concatenation to obtain the encapsulation body hash digest, and sends the encapsulation body hash digest to the encapsulation body publishing module and the encapsulation body on-chain module; Fifth step, the encapsulation body publishing module receives the basic information of the encapsulation body from the data encapsulation module, receives the encapsulation body hash digest from the hash digest module, and sends the basic information of the encapsulation body and the encapsulation body hash digest to the data user module of the data user; the data user module of the data user receives the basic information of the encapsulation body and the encapsulation body hash digest and displays them in the encapsulation body repository; the encapsulation body publishing module sends the basic information of the encapsulation body to the encapsulation body on-chain module; after receiving the basic information of the encapsulation body, the encapsulation body on-chain module sends a DID application to the data owner module; Sixth step, the server-side encapsulation body on-chain module uploads the encapsulation body hash digest, the DID of the data owner, and the basic information of the encapsulation body to the blockchain. The encapsulation body hash digest is used as the unique identifier of the encapsulation body; Seventh step, the encapsulation body application module transfers the ownership of the encapsulation body. The method is as follows: 7.1 If the encapsulation application module receives the encapsulation application information sent from the data user's data user module, go to 7.2; if it does not receive the encapsulation application information sent from the data user's data user module, continue to monitor in 7.1; the encapsulation application information includes the hash digest of the data encapsulation body applied for, the application purpose, the application fields, the DID of the data user, and the id of the encapsulation body owner. 7.2 The encapsulation application module finds the data owner corresponding to the data encapsulation body according to the id of the encapsulation body owner, and sends the encapsulation application information to the data owner module that created the data owner corresponding to the data encapsulation body. 7.3 The data owner module receives the encapsulation application information from the encapsulation application module and conducts approval according to the application information. If the application purpose and application fields meet the usage requirements of the data owner, the application is approved, and a "approval result passed" notice and the DID of the data owner are sent to the encapsulation application module; if the application purpose or application fields do not meet the usage requirements of the data owner, the application is not approved, and a "approval result not passed" notice is sent to the encapsulation application module. 7.4 The encapsulation application module receives the approval result from the data owner module. If the approval result is passed, it calls the smart contract, passes the DID of the data owner, the DID of the data user, and the hash digest of the corresponding data encapsulation body from the encapsulation application module into the blockchain, finds the corresponding data encapsulation body on the blockchain according to the data owner DID and the encapsulation body hash digest, and conducts the transfer of the ownership of the data encapsulation body, transfers the ownership of the data encapsulation body from the data owner to the data user corresponding to the DID of the data user, and sends a "ownership transfer successful" message to the data user module; if the approval result is not passed, send a "ownership transfer failed" to the client data user module. 7.5 The data user module receives the ownership transfer result from the encapsulation application module. If the received message is "ownership transfer successful", it means that the data user can use the data encapsulation body, go to the eighth step; if it is a "ownership transfer failed" message, go to 7.
6. 7.6 The data owner module fails to obtain the ownership of the data encapsulation body. The data owner module displays "failed to obtain the ownership of the data encapsulation body" and goes to the ninth step. In the eighth step, the server-side encapsulation body right confirmation module confirms the ownership of the encapsulation body. The method is as follows: 8.1 The data user module sends the hash digest of the data encapsulation body and the DID of the data user to the encapsulation body right confirmation module. 8.2 The encapsulation body right confirmation module receives the hash digest of the encapsulation body and the DID of the data user from the data user module, calls the smart contract, and verifies on the blockchain whether the DID owns the ownership of the data encapsulation body. If it has the ownership, that is, the encapsulation body right confirmation result received from the blockchain is successful, a "right verification successful" notice is sent to the data user module; if the encapsulation body right confirmation result received from the blockchain is failed, a "right verification failed" notice is sent to the client data user module. 8.3 The data user module receives a right verification notice from the encapsulation body right confirmation module. If the received notice is "right verification successful", the data user module displays "It is possible to use the data encapsulation body to develop the encapsulated body data", and proceeds to the ninth step; if the received notice is "right verification failed", it proceeds to 8.4; 8.4 The data owner module displays "The right confirmation of the data encapsulation body failed", and proceeds to the ninth step; The ninth step, end.
2. The data right confirmation method based on the blockchain of data encapsulation body abstract as claimed in claim 1, wherein The blockchain network is a decentralized system that eliminates the dependence on central nodes through a decentralized mechanism; the data owner module is connected to the blockchain and the server side, and encapsulates the structured data it owns; when the data owner module needs to share data, it sends database connection information, data segmentation information, the decentralized identity DID of the data owner, the application approval result, and the basic information of the encapsulation body to the server side, and receives the encapsulation body application information, database name, table name, and field name from the server side; the data user module includes an encapsulation body repository, is connected to the blockchain and the server side, sends the encapsulation body application information to the server side, and receives the encapsulation body hash digest, the basic information of the encapsulation body, the right verification notice, and the application approval result notice from the server side, and displays the basic information of the encapsulation body and the encapsulation body hash digest; The data segmentation module is connected to the data owner module of the data owner, receives the database connection information and data segmentation information sent by the data owner module, obtains the data segments from the database or csv file indicated by the database connection information according to the data segmentation information, and sends the data segments to the data encapsulation module; The data encapsulation module is connected to the data owner module of the data owner, the data segmentation module, the hash digest module, and the encapsulation body publishing module. It receives the basic information of the encapsulation body from the data owner module, receives the data segments from the data segmentation module, encapsulates the data segments according to the basic information of the encapsulation body to obtain the data encapsulation body, saves the data in the data encapsulation body as a csv file to obtain the encapsulated body data csv file, sends the encapsulated body data csv file and the basic information of the encapsulation body to the hash digest module, and sends the basic information of the encapsulation body to the encapsulation body publishing module; The hash digest module is connected to the data encapsulation module, the encapsulation body publishing module, and the encapsulation body chain - up module. It receives the encapsulated body data csv file and the basic information of the encapsulation body from the data encapsulation module, generates the encapsulation body hash digest through a hash algorithm, and sends the encapsulation body hash digest to the encapsulation body publishing module and the encapsulation body chain - up module; The encapsulation body publishing module is connected to the data encapsulation module, the hash digest module, the encapsulation body chain - up module, and the data user module of the data user. It receives the basic information of the encapsulation body from the data encapsulation module and the encapsulation body hash digest from the hash digest module, publishes the basic information of the encapsulation body and the encapsulation body hash digest to the encapsulation body repository in the data user module of the data user; sends the basic information of the encapsulation body to the encapsulation body chain - up module; The encapsulation body on-chain module is connected to the data owner module, the encapsulation body publishing module, the hash digest module, and the blockchain of the data owner. It receives the decentralized identity DID of the data owner from the data owner module, the encapsulation body hash digest from the hash digest module, and the basic information of the encapsulation body from the encapsulation body publishing module. It calls the smart contract, uses the encapsulation body hash digest as the unique identifier of the encapsulation body, and stores it together with the DID and the basic information of the encapsulation body on the blockchain. The encapsulation body application module is connected to the data owner module of the data owner, the data user module of the data user, and the blockchain. It receives the encapsulation body application information from the data user module and sends the encapsulation body application information to the data owner module of the data owner who created the data encapsulation body. The encapsulation body application information includes the hash digest of the data encapsulation body to be applied for, the application purpose, the application fields, and the DID of the data user. It receives the application approval result from the data owner module of the data owner. If the application approval result is passed, the encapsulation body application module calls the smart contract, passes the DID of the data owner, the DID of the data user, and the hash digest of the encapsulation body into the blockchain. The smart contract transfers the ownership of the data encapsulation body on the blockchain according to the DID of the data owner and the hash digest of the encapsulation body, and adds the DID of the data user to the ownership of the data encapsulation body, that is, allows the data user to use the data encapsulation body for data development. The encapsulation body ownership confirmation module is connected to the data user module of the data user and the blockchain. It receives the DID of the data user and the hash digest of the encapsulation body to be used from the data user module, calls the smart contract, performs ownership verification on the blockchain according to the DID of the data user and the hash digest of the encapsulation body to be used, confirms whether the data user has the ownership of the data encapsulation body, receives the encapsulation body ownership confirmation result from the blockchain, and sends an ownership verification notice to the data user module of the data user according to the encapsulation body ownership confirmation result.
3. The data rights confirmation method based on uploading the data encapsulation body summary to the blockchain according to claim 2, characterized in that The structured data owned by the data owner module is stored in the structured databases MySQL, MongoDB, PostgreSQL, or stored in the form of a csv file.
4. The data right confirmation method based on the upper chain of the data encapsulation body summary according to claim 1, characterized in that The database connection password in step 2.1 supports MySQL, MongoDB, PostgreSQL, or csv file, and the csv file is uploaded in the form of a file transfer protocol.
5. The data right confirmation method based on the data encapsulation body summary being chained as claimed in claim 1, wherein The data splitting module in step 2.2 receives the database connection information and data splitting information from the data owner module. The method of splitting the database or csv file pointed to by the database connection information is as follows: 2.2.1 The data splitting module receives the database connection information sent by the data owner module. 2.2.2 The data splitting module obtains all the database names provided by the data owner module according to the database connection information, and returns all the database names to the data owner module. 2.2.3 The data owner module selects a database from all the database names according to the shareable database information, and returns the selected database name to the data splitting module. 2.2.4 The data segmentation module receives the selected database name from the data owner module, obtains commands through the database table name, retrieves all table names in the corresponding database according to the selected database name, and returns all table names in the corresponding database to the data owner module; 2.2.5 The data owner module selects data tables based on the shareable data table information among all the table names provided by the data segmentation module, and returns the selected data table names to the data segmentation module; 2.2.6 The data segmentation module receives the selected data table names from the data owner module, obtains commands through the database field name, retrieves all field names in the corresponding data table according to the selected data table names, and returns all field names in the selected data table to the data owner module; 2.2.7 The data owner module selects data fields based on the shareable data field information among all the field names provided by the data segmentation module, and returns the selected data field names to the data segmentation module; 2.2.8 The data owner module sets row granularity limit conditions for the fields according to the shareable data rows, and returns the row granularity limit conditions to the data segmentation module; 2.2.9 The data segmentation module remotely connects according to the database connection information, and based on the selected database name, selected data table name, selected data field name, and row granularity limit conditions in the data segmentation information, obtains the selected data table name, selected data field name, and the corresponding data that meets the row granularity limit conditions from the database corresponding to the selected database name through the database data acquisition command, to obtain the data segmentation body.
6. The data rights confirmation method based on the data encapsulation body summary being chained as claimed in claim 1, wherein As described in step 4.3 represents rounding up the size of the csv file divided by M, where M is 2 k KB, where k is a positive integer.
7. The data rights confirmation method based on the data encapsulation body summary being uploaded to the blockchain according to claim 1, characterized in that The M is 4KB or 8KB.
8. The data right confirmation method based on the data encapsulation body summary being chained as claimed in claim 1, wherein The method by which the hash digest module in step 4.4 generates a data hash digest based on N data blocks is: 4.4.1 Calculate the value of K based on N 4.4.2 Taking the N data blocks in the order they appear in the csv file as leaf nodes; 4.4.3 The hash digest generation method using the polling method sequentially selects a hash algorithm from the hash algorithm library. That is, for SHA256, SHA-3, and BLAKE2b, for the nth leaf node, the hash algorithm numbered mod(n - 1, 3) is used to generate the hash digests of N leaf nodes. The hash digests of these N leaf nodes are used as the values of the first N leaf nodes of a full K-ary tree with a height of 3, and K 2 - N null value leaf nodes are added after the N leaf nodes to obtain K 2 leaf nodes, and the leaf nodes are numbered k, where 1 ≤ k ≤ K 2 ; 4.4.4 Growing upward from K 2 leaf nodes to generate a full K-ary tree and obtain the data hash digest. The method is as follows: 4.4.4.1 Connect the values of the leaf nodes numbered from 1 to K; connect the values of the leaf nodes numbered from K + 1 to 2K;...; connect the values of the leaf nodes numbered from (i - 1)K + 1 to iK;...; connect the values of the leaf nodes numbered from (K - 1)K + 1 to K 2 to obtain K nodes on the second layer of the full K-ary tree; 4.4.4.2 Using the polling-based hash digest generation method described in 4.4.3, generate the hash digests of the K nodes on the second layer of the full K-ary tree. These K hash digests serve as the values of the K nodes on the second layer of the full K-ary tree with a height of 3; 4.4.4.3 Connect the values of the K nodes on the second layer of the full K-ary tree; to obtain the root node of the third layer, i.e., the topmost root, of the full K-ary tree; 4.4.4.4 Select the SHA256 hash algorithm from the hash algorithm library, generate the hash digest of the root node, which serves as the value of the root node of the full K-ary tree with a height of 3; take the value of the root node of the full K-ary tree as the data hash digest.
9. The data rights confirmation method based on the data encapsulation body summary being chained as claimed in claim 1, wherein The method by which the server-side encapsulation body blockchain uploading module in the sixth step uploads the encapsulation body hash digest to the blockchain is: 6.1 The data owner module receives the DID application from the encapsulation body blockchain uploading module and sends the DID of the data owner to the encapsulation body blockchain uploading module; 6.2 The encapsulation body blockchain uploading module receives the DID of the data owner from the data owner module, receives the encapsulation body basic information from the encapsulation body publishing module, and receives the encapsulation body hash digest from the hash digest module, and stores the encapsulation body hash digest, the DID of the data owner, and the encapsulation body basic information on the blockchain through a smart contract for blockchain-based evidence storage.
Citation Information
Cited By
File data complete encryption storage method and system and medium
CN121502805A
A file data integrity encryption storage method, system and medium
CN121502805B