Full-life-cycle data security management method for block chain development platform

Through the blockchain development platform's full life cycle data security management method, data storage, transmission and environmental information is obtained and evaluated, and security early warning signals are generated, which solves the storage and transmission risks in traditional data security management and achieves more accurate security assessment and risk reduction.

CN120597339AActive Publication Date: 2025-09-05KARAMAY OIL CITY DATA CO LTD +1

Patent Information

Application Number
CN202510677424.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-26
Publication Date
2025-09-05
Estimated Expiration
2045-05-26

AI Technical Summary

Technical Problem

Traditional data security management faces the problems of high data storage security risks and high data transmission security risks. Especially under centralized storage and API interface attacks, data is at risk of loss or leakage.

Method used

Through the blockchain development platform, the storage, transmission and environmental information of data in the blockchain is obtained, the storage security characteristic index, transmission security characteristic index and environmental security characteristic index are calculated, security warning signals for data files are generated, and security threats to data throughout its life cycle are comprehensively assessed.

Benefits of technology

It realizes multi-dimensional security assessment of data storage, transmission and environment, reduces the data security risk of blockchain development platform, improves data stability and reliability, and avoids security vulnerabilities caused by one-sided analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120597339A_ABST
    Figure CN120597339A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data security management, in particular to a full-life-cycle data security management method for a block chain development platform. The method comprises the steps of obtaining storage information of a file where data is located in a block chain, and calculating a storage security feature index of the file where the data is located based on the storage information; acquiring transmission information of the file where the data is located in the block chain, and calculating a transmission security feature index of the file where the data is located based on the transmission information; environment information of the file where the data is located in the block chain is obtained, the environment information comprises an environment risk value and a constraint influence value, and an environment security feature index of the file where the data is located is calculated based on the environment information; and generating a security early warning signal of the file where the data is located based on the storage security feature index, the transmission security feature index and the environment security feature index. The storage security risk and the data transmission risk of data security management of the block chain development platform can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security management, and in particular to a full life cycle data security management method for a blockchain development platform. Background Art

[0002] As a distributed ledger technology, blockchain offers new solutions for data management throughout its lifecycle, thanks to its decentralization, distributed storage, immutability, and smart contracts. By leveraging cryptographic algorithms and consensus mechanisms to ensure the authenticity, integrity, and credibility of data, blockchain technology provides a powerful tool for addressing traditional data management challenges.

[0003] Traditional data security management faces the following challenges:

[0004] On the one hand, there are security risks associated with data storage: Traditional centralized storage not only faces storage capacity bottlenecks but also data security risks. Once the storage center fails or is attacked, data is at risk of being lost or leaked.

[0005] On the other hand, there are security risks associated with data transmission and the security of the environment in which it occurs: hackers can exploit system attacks to obtain business and user data for malicious purposes. When data flows and is used in large quantities, external malicious attackers may exploit APIs to obtain sensitive data in bulk. This increases the fluidity of core business data and personal identity information transmitted via APIs, posing a greater risk of leakage.

[0006] Therefore, a full life cycle data security management method for blockchain development platforms is urgently needed to solve the above problems. Summary of the Invention

[0007] The purpose of this invention is to provide a full life cycle data security management method for a blockchain development platform: to solve the technical problems of high data storage security risks and high data transmission security risks existing in traditional data security management.

[0008] The full life cycle data security management method of the blockchain development platform includes:

[0009] Obtain the storage information of the file containing the data in the blockchain, and calculate the storage security feature index of the file containing the data based on the storage information;

[0010] Obtain the transmission information of the file containing the data in the blockchain, and calculate the transmission security feature index of the file containing the data based on the transmission information;

[0011] Obtain the environmental information of the file containing the data in the blockchain, where the environmental information includes the environmental risk value and the constraint impact value, and calculate the environmental security characteristic index of the file containing the data based on the environmental information;

[0012] Generate security warning signals for the files where the data is located based on the storage security feature index, transmission security feature index and environmental security feature index.

[0013] Furthermore, calculating the storage security feature index of the file where the data is located based on the storage information specifically includes the following process:

[0014] Based on the storage information, obtain the public and private key pair (pk, sk) of the file where the data is located, where pk is the public key and sk is the private key. Based on (pk, sk), generate a capacity file S with N data pk , and the capacity file S pk Stored in the current blockchain node;

[0015] Generate the challenge c of the corresponding block through the challenge generation algorithm and historical block parameters;

[0016] The current blockchain node is based on the challenge c and the local storage capacity file S pk Generate capacity characteristic value;

[0017] The storage security characteristic index of the file where the data is located is calculated based on the capacity characteristic value.

[0018] Furthermore, based on (pk, sk), a capacity file S of N data is generated. pk The specific process includes the following:

[0019] p(x,sk), is a set of collision-resistant hash functions, where x, A hash table data structure consisting of N pieces of data;

[0020] Calculate the capacity file S based on the public-private key pair (pk, sk) pk The unique identifier hash(pk), where hash(pk) represents a hash operation on the public key pk;

[0021] For data x: calculate the corresponding key y from 1 to N: y = p(x, hash(pk)); create a hash table A with y as the key and data x as the value;

[0022] Data Count the corresponding keys from 1 to N Look up a key in hash table A The corresponding value of x;

[0023] Calculate the key z: With z as key, The capacity file S pk .

[0024] Furthermore, generating the challenge c of the corresponding block through the challenge generation algorithm and historical block parameters specifically includes the following process:

[0025] Get the current block height h and historical block parameters Δ based on the stored information;

[0026] If the current block height h is an integer multiple of Δ, then a hash operation is performed on the capacity proof of the (h-Δ)th block to obtain challenge c; if the current block height h is not an integer multiple of Δ, then a hash operation is performed on the capacity proof of the (hk)th block k times in a row to obtain challenge c.

[0027] Furthermore, according to the challenge c and the locally stored capacity file S pk Generating the capacity characteristic value specifically includes the following process:

[0028] From the locally stored capacity file S pk Query the items that meet the conditions

[0029]

[0030] Where ℃(z|y) means that the last n digits of z and y are equal;

[0031] For those who meet the conditions Calculate its mass Q:

[0032] Q=(hash(sig / 2 bl )) 1 / N ;

[0033] Among them, sig is the signature of the file where the data is located, and bl is the parameter for initializing the capacity space;

[0034] Get the block difficulty parameter corresponding to the file where the data is located, and record the difference between the quality Q and the difficulty parameter as the capacity characteristic value.

[0035] Furthermore, calculating the storage security characteristic index of the file where the data is located based on the capacity characteristic value specifically includes the following process:

[0036] Generate a management cycle, divide the management cycle into several sub-periods, obtain the capacity characteristic values ​​of all sub-periods, establish a rectangular coordinate system with the execution time of the sub-period as the X-axis and the capacity characteristic value as the Y-axis, draw a data storage safety curve by plotting points, and then obtain the number of line segments whose capacity characteristic values ​​exceed the preset capacity characteristic threshold from the data storage safety curve. At the same time, draw two perpendicular line segments from the two endpoints to the X-axis to obtain two perpendicular line segments. A graph is formed by the data storage safety curve, the two perpendicular line segments and the X-axis, and the area of ​​the graph is calculated. The area of ​​the graph and the number of line segments are normalized and then the ratio is calculated. The obtained ratio is recorded as the storage safety characteristic index of the file where the data is located.

[0037] Furthermore, obtaining the transmission information of the file containing the data in the blockchain and calculating the transmission security feature index of the file containing the data based on the transmission information specifically includes the following process:

[0038] Generate a management cycle, divide the management cycle into several sub-periods, obtain the data transmission frequency of the file containing the data in the blockchain within the sub-period based on the transmission information of the file containing the data in the blockchain, establish a rectangular coordinate system with the execution time of the sub-period as the X-axis and the data transmission frequency as the Y-axis, draw a data transmission security curve by plotting points, obtain the number of all rising segments and the number of falling segments of the curve from the data transmission security curve, and record the ratio of the number of rising segments to the number of falling segments of the curve as the transmission excellence ratio; obtain the value obtained after data normalization between the lengths of the line segments above the preset data transmission security curve on the data transmission security curve, multiply the transmission excellence ratio and the value to obtain the product value, construct a set of transmission performance values ​​with the product value, and then obtain the maximum subset and the minimum subset in the set, and mark the difference between the maximum subset and the minimum subset in the set as the transmission security feature index.

[0039] Furthermore, calculating the environmental safety characteristic index of the file containing the data based on the environmental information specifically includes the following process:

[0040] Generate a management cycle and divide the management cycle into several sub-periods;

[0041] Obtain the environmental risk value of the file containing the data in each sub-time period. The environmental risk value represents the sum of the portions of the characteristic curve change trend value of the environmental information that are greater than a preset threshold. The environmental information includes the average file upload rate and the file download rate. The environmental risk value is compared and analyzed with the stored preset environmental risk value threshold. If the environmental risk value is greater than the preset environmental risk value threshold, the number of sub-time periods corresponding to the environmental risk value greater than the preset environmental risk value threshold is marked as the first risk value HJ;

[0042] Obtain the constraint impact value of the file containing the data within the preset time threshold. The constraint impact value represents the number of times the file containing the data fails when broadcasting to other nodes through the blockchain. Compare and analyze the constraint impact value with the stored preset constraint impact value threshold. If the constraint impact value is greater than the preset constraint impact value threshold, mark the portion of the constraint impact value that is greater than the preset constraint impact value threshold as the second risk value YS.

[0043] Substitute the first risk value HJ and the second risk value YS into the environmental safety characteristic index calculation formula to obtain the environmental safety characteristic index HA:

[0044] Among them, α and β are weight coefficients respectively.

[0045] Furthermore, generating a security warning signal for the file where the data is located based on the storage security feature index, the transmission security feature index, and the environment security feature index specifically includes the following process:

[0046] Loading the storage security feature index threshold, transmission security feature index threshold, and environment security feature index threshold, determining whether the storage security feature index exceeds the storage security feature index threshold; if so, determining that the file containing the data has a storage risk and generating a warning signal; if not, determining that the file containing the data has no storage risk and not generating a warning signal;

[0047] Determine whether the transmission security feature index exceeds the transmission security feature index threshold. If so, determine that the file containing the data has a transmission risk and generate a warning signal. If not, determine that the file containing the data does not have a transmission risk and do not generate a warning signal.

[0048] Determine whether the environmental safety characteristic index exceeds the environmental safety characteristic index threshold. If so, it is determined that the file where the data is located has an environmental safety risk and a warning signal is generated. If not, it is determined that the file where the data is located does not have an environmental safety risk and no warning signal is generated.

[0049] Compared with the existing solutions, the present invention achieves the following beneficial effects:

[0050] The present invention obtains storage information of the file containing data in the blockchain, and calculates a storage security characteristic index of the file containing data based on the storage information; obtains transmission information of the file containing data in the blockchain, and calculates a transmission security characteristic index of the file containing data based on the transmission information; obtains environmental information of the file containing data in the blockchain, wherein the environmental information includes an environmental risk value and a constraint impact value, and calculates an environmental security characteristic index of the file containing data based on the environmental information; generates a security warning signal for the file containing data based on the storage security characteristic index, the transmission security characteristic index, and the environmental security characteristic index, thereby reducing the storage security risk and data transmission risk of data security management of the blockchain development platform.

[0051] Furthermore, by analyzing three key aspects, storage, transmission, and environment, we comprehensively capture various information about the data files within the blockchain. Storage information analysis reveals the storage status and stability of data on blockchain nodes, transmission information analysis provides insight into the security of data flow within the blockchain network, and environmental information analysis considers the impact of external risk factors and constraints on data security. This multi-dimensional, comprehensive assessment approach more accurately identifies potential security threats to data throughout its lifecycle, avoiding security vulnerabilities caused by one-sided analysis. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments described in the present invention. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.

[0053] Figure 1 This is a workflow diagram of a full life cycle data security management method for a first blockchain development platform according to an embodiment of the present invention;

[0054] Figure 2 This is a workflow diagram of a full life cycle data security management method for a second blockchain development platform according to an embodiment of the present invention;

[0055] Figure 3 This is a workflow diagram of a full life cycle data security management method for a third blockchain development platform according to an embodiment of the present invention. DETAILED DESCRIPTION

[0056] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0057] In addition, the described features, structures or characteristics can be combined in any suitable manner in one or more example embodiments. In the following description, many specific details are provided to provide a full understanding of the example embodiments of the present disclosure. However, those skilled in the art will appreciate that the technical solutions of the present disclosure can be practiced while omitting one or more of the specific details, or other methods, components, steps, etc. can be adopted. In other cases, well-known structures, methods, implementations or operations are not shown or described in detail to avoid obscuring various aspects of the present disclosure.

[0058] This embodiment provides a full life cycle data security management method for a blockchain development platform. Figure 1 This is a workflow diagram of the first method for managing data security throughout the life cycle of a blockchain development platform according to an embodiment of the present invention. Figure 1 As shown, the method includes the following steps:

[0059] Step S101: Obtain storage information of the file containing the data in the blockchain, and calculate the storage security feature index of the file containing the data based on the storage information;

[0060] Step S102: Obtain transmission information of the file containing the data in the blockchain, and calculate the transmission security feature index of the file containing the data based on the transmission information;

[0061] Step S103: Obtaining environmental information of the file containing the data in the blockchain, where the environmental information includes an environmental risk value and a constraint impact value, and calculating the environmental security characteristic index of the file containing the data based on the environmental information;

[0062] Step S104: Generate a security warning signal for the file where the data is located based on the storage security feature index, the transmission security feature index, and the environment security feature index.

[0063] In summary, this method comprehensively captures various blockchain-related information about data files, focusing on three key aspects: storage, transmission, and environment. Storage information analysis reveals the storage status and stability of data on blockchain nodes, transmission information analysis provides insight into the security of data flow within the blockchain network, and environmental information analysis considers the impact of external risk factors and constraints on data security. This multi-dimensional, comprehensive assessment approach more accurately identifies potential security threats to data throughout its lifecycle, avoiding security vulnerabilities caused by one-sided analysis.

[0064] In some embodiments, calculating the storage security feature index of the file containing the data based on the storage information specifically includes the following process:

[0065] Based on the storage information, obtain the public and private key pair (pk, sk) of the file where the data is located, where pk is the public key and sk is the private key. Based on (pk, sk), generate a capacity file S with N data pk , and the capacity file S pk Stored in the current blockchain node;

[0066] Specifically, based on (pk, sk) a capacity file S of N pieces of data is generated. pk The specific process includes the following:

[0067] p(x,sk), is a set of collision-resistant hash functions, where x, A hash table data structure consisting of N pieces of data;

[0068] Calculate the capacity file S based on the public-private key pair (pk, sk) pk The unique identifier hash(pk), where hash(pk) represents a hash operation on the public key pk;

[0069] For data x: calculate the corresponding key y from 1 to N: y = p(x, hash(pk)); create a hash table A with y as the key and data x as the value;

[0070] Data Count the corresponding keys from 1 to N Look up a key in hash table A The corresponding value of x;

[0071] Calculate the key z: With z as key, The capacity file S pk .

[0072] Generate the challenge c of the corresponding block through the challenge generation algorithm and historical block parameters;

[0073] Specifically, the current block height h and historical block parameters Δ are obtained based on the stored information;

[0074] If the current block height h is an integer multiple of Δ, then a hash operation is performed on the capacity proof of the (h-Δ)th block to obtain challenge c; if the current block height h is not an integer multiple of Δ, then a hash operation is performed on the capacity proof of the (hk)th block k times in a row to obtain challenge c.

[0075] The current blockchain node is based on the challenge c and the local storage capacity file S pk Generate capacity characteristic value;

[0076] According to the challenge c and the capacity of the local storage file S pk Generating the capacity characteristic value specifically includes the following process:

[0077] From the locally stored capacity file S pk Query the items that meet the conditions

[0078]

[0079] Where ℃(z|y) means that the last n digits of z and y are equal;

[0080] For those who meet the conditions Calculate its mass Q:

[0081] Q=(hash(sig / 2 bl )) 1 / N ;

[0082] Among them, sig is the signature of the file where the data is located, and bl is the parameter for initializing the capacity space;

[0083] Get the block difficulty parameter corresponding to the file where the data is located, and record the difference between the quality Q and the difficulty parameter as the capacity characteristic value.

[0084] Calculate the storage security characteristic index of the file where the data is located based on the capacity characteristic value:

[0085] Figure 2 This is a workflow diagram of the full life cycle data security management method of the second blockchain development platform according to an embodiment of the present invention. Figure 2 As shown, the calculation of the storage security characteristic index of the file where the data is located based on the capacity characteristic value specifically includes the following process:

[0086] Step S201: Generate a management cycle, divide the management cycle into several sub-periods, obtain the capacity characteristic values ​​of all sub-periods, establish a rectangular coordinate system with the execution time of the sub-period as the X-axis and the capacity characteristic value as the Y-axis, and draw a data storage security curve by plotting points;

[0087] Step S202: obtaining the number of line segments whose capacity characteristic values ​​exceed a preset capacity characteristic threshold from the data storage safety curve;

[0088] Step S203: Draw a perpendicular line from the two endpoints to the X-axis to obtain two perpendicular line segments. The data storage security curve, the two perpendicular line segments, and the X-axis form a graph. The area of ​​the graph is calculated, and the area of ​​the graph and the number of line segments are normalized and then ratioed. The obtained ratio is recorded as the storage security feature index of the file where the data is located.

[0089] In summary, by generating a management cycle and dividing it into sub-periods, data capacity characteristic values ​​can be dynamically and in real time captured during different time periods. A data storage security curve is plotted with sub-period execution time as the X-axis and capacity characteristic value as the Y-axis, visually demonstrating the changing trend of data storage capacity over time. This allows security managers to clearly observe fluctuations in data storage capacity and promptly identify potential storage security risks. For example, abnormal capacity growth may indicate malicious attacks or data redundancy, enabling them to quickly take countermeasures to ensure data storage stability and security. Obtaining the number of segments from the data storage security curve where capacity characteristic values ​​exceed a preset threshold accurately identifies periods of data storage anomalies. The preset threshold can be appropriately set based on actual business needs and data storage characteristics. When the capacity characteristic value exceeds this threshold, it indicates that the data storage may be in an unsafe state. By counting the number of segments, the frequency of anomalies can be quantified, providing strong support for further analysis of the causes and the development of response strategies. Quantifying the degree of storage security risk: Draw two perpendicular line segments from the two endpoints to the X-axis. A graph is formed from the data storage security curve, the two perpendicular line segments, and the X-axis, and the area of ​​the graph is calculated. This innovative area calculation method comprehensively considers the fluctuation range and duration of data storage capacity during the abnormal period, transforming the abstract concept of storage security risk into a concrete quantitative indicator. The larger the graph area, the more severe and prolonged the fluctuation in data storage capacity during the abnormal period, and the higher the storage security risk. This quantitative method allows security managers to more intuitively understand the severity of data storage security risks, providing a basis for formulating scientific and reasonable security policies.

[0090] In some embodiments, obtaining transmission information of the file containing the data in the blockchain and calculating the transmission security feature index of the file containing the data based on the transmission information specifically includes the following process:

[0091] Generate a management cycle, divide the management cycle into several sub-periods, obtain the data transmission frequency of the file containing the data in the blockchain within the sub-period based on the transmission information of the file containing the data in the blockchain, establish a rectangular coordinate system with the execution time of the sub-period as the X-axis and the data transmission frequency as the Y-axis, draw a data transmission security curve by plotting points, obtain the number of all rising segments and the number of falling segments of the curve from the data transmission security curve, and record the ratio of the number of rising segments to the number of falling segments of the curve as the transmission excellence ratio; obtain the value obtained after data normalization between the lengths of the line segments above the preset data transmission security curve on the data transmission security curve, multiply the transmission excellence ratio and the value to obtain the product value, construct a set of transmission performance values ​​with the product value, and then obtain the maximum subset and the minimum subset in the set, and mark the difference between the maximum subset and the minimum subset in the set as the transmission security feature index.

[0092] In summary, by dynamically capturing transmission fluctuation characteristics, quantitatively evaluating transmission dynamic performance, comprehensively considering transmission security margins, and integrating multi-dimensional information for precise evaluation, a comprehensive, in-depth, and scientific evaluation method is provided for blockchain data transmission security, which helps to improve the security and reliability of data transmission and ensure the stable operation of the blockchain system.

[0093] In some embodiments, Figure 3 This is a workflow diagram of the full life cycle data security management method of the third blockchain development platform in an embodiment of the present invention, such as Figure 3 As shown, the calculation of the environmental safety characteristic index of the file containing the data based on the environmental information specifically includes the following process:

[0094] Step S301: Generate a management cycle and divide the management cycle into several sub-periods;

[0095] Step S302: Obtain the environmental risk value of the file containing the data in each sub-time period. The environmental risk value represents the sum of the portion of the characteristic curve change trend value of the environmental information that is greater than a preset threshold. The environmental information includes the average file upload rate and the file download rate. The environmental risk value is compared and analyzed with the stored preset environmental risk value threshold. If the environmental risk value is greater than the preset environmental risk value threshold, the number of sub-time periods corresponding to the environmental risk value greater than the preset environmental risk value threshold is marked as a first risk value HJ.

[0096] Step S303: Obtain the constraint impact value of the file containing the data within the preset time threshold. The constraint impact value represents the number of times the file containing the data fails when broadcasting to other nodes through the blockchain. The constraint impact value is compared with the stored preset constraint impact value threshold. If the constraint impact value is greater than the preset constraint impact value threshold, the portion of the constraint impact value that is greater than the preset constraint impact value threshold is marked as a second risk value YS.

[0097] Step S304: Substitute the first risk value HJ and the second risk value YS into the environmental safety characteristic index calculation formula to calculate the environmental safety characteristic index HA:

[0098] Among them, α and β are weight coefficients respectively.

[0099] Furthermore, generating a security warning signal for the file where the data is located based on the storage security feature index, the transmission security feature index, and the environment security feature index specifically includes the following process:

[0100] Loading the storage security feature index threshold, transmission security feature index threshold, and environment security feature index threshold, determining whether the storage security feature index exceeds the storage security feature index threshold; if so, determining that the file containing the data has a storage risk and generating a warning signal; if not, determining that the file containing the data has no storage risk and not generating a warning signal;

[0101] Determine whether the transmission security feature index exceeds the transmission security feature index threshold. If so, determine that the file containing the data has a transmission risk and generate a warning signal. If not, determine that the file containing the data does not have a transmission risk and do not generate a warning signal.

[0102] Determine whether the environmental security characteristic index exceeds the environmental security characteristic index threshold. If so, it is determined that the file where the data is located has an environmental security risk and a warning signal is generated. If not, it is determined that the file where the data is located does not have an environmental security risk and no warning signal is generated.

[0103] The above embodiments can be implemented in whole or in part by software, hardware, firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0104] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0105] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0106] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is only for some logical functions. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0107] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0108] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. The full life cycle data security management method of the blockchain development platform is characterized by: Methods include: Obtain the storage information of the file containing the data in the blockchain, and calculate the storage security feature index of the file containing the data based on the storage information; Obtain the transmission information of the file containing the data in the blockchain, and calculate the transmission security feature index of the file containing the data based on the transmission information; Obtain the environmental information of the file containing the data in the blockchain, where the environmental information includes the environmental risk value and the constraint impact value, and calculate the environmental security characteristic index of the file containing the data based on the environmental information; Generate security warning signals for the files where the data is located based on the storage security feature index, transmission security feature index and environmental security feature index.

2. The full life cycle data security management method of the blockchain development platform according to claim 1 is characterized in that: Calculate the storage security feature index of the file where the data is located based on the storage information The following processes are included: Based on the storage information, obtain the public and private key pair (pk, sk) of the file where the data is located, where pk is the public key and sk is the private key. Based on (pk, sk), generate a capacity file S with N data pk , and the capacity file S pk Stored in the current blockchain node; Generate the challenge c of the corresponding block through the challenge generation algorithm and historical block parameters; The current blockchain node is based on the challenge c and the local storage capacity file S pk Generate capacity characteristic value; The storage security characteristic index of the file where the data is located is calculated based on the capacity characteristic value.

3. The full life cycle data security management method of the blockchain development platform according to claim 2 is characterized in that: Generate N data capacity files S based on (pk, sk) pk The specific process includes the following: is a set of collision-resistant hash functions, where x, A hash table data structure consisting of N pieces of data; Calculate the capacity file S based on the public-private key pair (pk, sk) pk The unique identifier hash(pk), where hash(pk) represents a hash operation on the public key pk; For data x: calculate the corresponding key y from 1 to N: y = px, hash(pk); create a hash table A with y as the key and data x as the value; Data Count the corresponding keys from 1 to N Look up a key in hash table A The corresponding value of x; Calculate the key z: With z as key, The capacity file S pk .

4. The full life cycle data security management method of the blockchain development platform according to claim 3 is characterized in that: The challenge generation algorithm and historical block parameters are used to generate the corresponding block challenge c, which specifically includes the following process: Get the current block height h and historical block parameters Δ based on the stored information; If the current block height h is an integer multiple of Δ, then a hash operation is performed on the capacity proof of the (h-Δ)th block to obtain challenge c; if the current block height h is not an integer multiple of Δ, then a hash operation is performed on the capacity proof of the (hk)th block k times in a row to obtain challenge c.

5. The full life cycle data security management method of the blockchain development platform according to claim 3 is characterized in that: According to the challenge c and the capacity of the local storage file S pk Generate capacity characteristic value specific The following processes are included: From the locally stored capacity file S pk Query the items that meet the conditions Where ℃(z|y) means that the last n digits of z and y are equal; For those who meet the conditions Calculate its mass Q: Q=hash(sig / 2 bl ) 1 / N ; Among them, sig is the signature of the file where the data is located, and bl is the parameter for initializing the capacity space; Get the block difficulty parameter corresponding to the file where the data is located, and record the difference between the quality Q and the difficulty parameter as the capacity characteristic value.

6. The full life cycle data security management method of the blockchain development platform according to claim 1 is characterized in that: Calculating the storage security characteristic index of the file containing the data based on the capacity characteristic value specifically includes the following process: Generate a management cycle, divide the management cycle into several sub-periods, obtain the capacity characteristic values ​​of all sub-periods, establish a rectangular coordinate system with the execution time of the sub-period as the X-axis and the capacity characteristic value as the Y-axis, draw a data storage safety curve by plotting points, and then obtain the number of line segments whose capacity characteristic values ​​exceed the preset capacity characteristic threshold from the data storage safety curve. At the same time, draw two perpendicular line segments from the two endpoints to the X-axis to obtain two perpendicular line segments. A graph is formed by the data storage safety curve, the two perpendicular line segments and the X-axis, and the area of ​​the graph is calculated. The area of ​​the graph and the number of line segments are normalized and then the ratio is calculated. The obtained ratio is recorded as the storage safety characteristic index of the file where the data is located.

7. The full life cycle data security management method of the blockchain development platform according to claim 1 is characterized in that: Obtain the transmission information of the file containing the data in the blockchain, and calculate the transmission security feature index of the file containing the data based on the transmission information. The following processes are included: Generate a management cycle, divide the management cycle into several sub-periods, obtain the data transmission frequency of the file containing the data in the blockchain within the sub-period based on the transmission information of the file containing the data in the blockchain, establish a rectangular coordinate system with the execution time of the sub-period as the X-axis and the data transmission frequency as the Y-axis, draw a data transmission security curve by plotting points, obtain the number of all rising segments and the number of falling segments of the curve from the data transmission security curve, and record the ratio of the number of rising segments to the number of falling segments of the curve as the transmission excellence ratio; obtain the value obtained after data normalization between the lengths of the line segments above the preset data transmission security curve on the data transmission security curve, multiply the transmission excellence ratio and the value to obtain the product value, construct a set of transmission performance values ​​with the product value, and then obtain the maximum subset and the minimum subset in the set, and mark the difference between the maximum subset and the minimum subset in the set as the transmission security feature index.

8. The full life cycle data security management method of the blockchain development platform according to claim 1 is characterized in that: The specific environmental safety characteristic index of the file where the environmental information data is calculated is The following processes are included: Generate a management cycle and divide the management cycle into several sub-periods; Obtain the environmental risk value of the file containing the data in each sub-time period. The environmental risk value represents the sum of the portions of the characteristic curve change trend value of the environmental information that are greater than a preset threshold. The environmental information includes the average file upload rate and the file download rate. The environmental risk value is compared and analyzed with the stored preset environmental risk value threshold. If the environmental risk value is greater than the preset environmental risk value threshold, the number of sub-time periods corresponding to the environmental risk value greater than the preset environmental risk value threshold is marked as the first risk value HJ; Obtain the constraint impact value of the file containing the data within the preset time threshold. The constraint impact value represents the number of times the file containing the data fails when broadcasting to other nodes through the blockchain. Compare and analyze the constraint impact value with the stored preset constraint impact value threshold. If the constraint impact value is greater than the preset constraint impact value threshold, mark the portion of the constraint impact value that is greater than the preset constraint impact value threshold as the second risk value YS. Substitute the first risk value HJ and the second risk value YS into the environmental safety characteristic index calculation formula to obtain the environmental safety characteristic index HA: Among them, α and β are weight coefficients respectively.

9. The full life cycle data security management method of the blockchain development platform according to claim 1 is characterized in that: Generate security warning signals for the files where the data is located based on the storage security feature index, transmission security feature index, and environmental security feature index. The following processes are included: Loading the storage security feature index threshold, transmission security feature index threshold, and environment security feature index threshold, determining whether the storage security feature index exceeds the storage security feature index threshold; if so, determining that the file containing the data has a storage risk and generating a warning signal; if not, determining that the file containing the data has no storage risk and not generating a warning signal; Determine whether the transmission security feature index exceeds the transmission security feature index threshold. If so, determine that the file containing the data has a transmission risk and generate a warning signal. If not, determine that the file containing the data does not have a transmission risk and do not generate a warning signal. Determine whether the environmental safety characteristic index exceeds the environmental safety characteristic index threshold. If so, it is determined that the file where the data is located has an environmental safety risk and a warning signal is generated. If not, it is determined that the file where the data is located does not have an environmental safety risk and no warning signal is generated.

Citation Information

Patent Citations

  • Secret-related document security control method based on block chain

    CN117131534A

  • Method and system for storing internet advertisement data on block chain and storage medium

    CN118427272A

  • Network security early warning method and system

    CN118646569A

  • Credible block chain data conditional security sharing method and system for cloud side end

    CN119109578A

  • System for monitoring information security and network security based on network connection and method thereof

    KR102531376B1

Cited By

  • Homomorphic encryption cross-border compliance medical data sharing privacy protection system and method

    CN121644247A