Data sharing authorization information management method and system based on block chain
Through identity-based irreversible private key generation and elliptic curve digital signature, combined with ring signature and reputation value management, the security and efficiency issues in blockchain data sharing are solved, and efficient and secure management of data sharing authorization information is achieved.
Patent Information
- Application Number
- CN202510792570.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-13
- Publication Date
- 2025-09-09
AI Technical Summary
Existing blockchain technology has security risks when sharing data, such as data leakage and illegal modification, and its consensus efficiency is low, which affects the efficiency of data sharing.
An identity-based irreversible private key generator is used to generate user private keys. Combined with elliptic curve digital signatures and ring signatures, blockchain node behavior indicators are counted to calculate reputation values. Consensus nodes are selected in layers, and abnormal nodes are dynamically adjusted through communication voting. Smart contracts are deployed to manage reputation values.
It improves the security and efficiency of data sharing, prevents the leakage of public key certificates, automatically eliminates dangerous nodes, and improves the management effect of data sharing authorization information.
Smart Images

Figure CN120614129A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of blockchain data sharing technology, and in particular to a blockchain-based data sharing authorization information management method and system. Background Art
[0002] Traditional data sharing methods present numerous security risks, such as data leakage and unauthorized modification, which often result in significant losses for businesses and institutions. Furthermore, data sharing requires ensuring efficient consensus among all participants. This means that during data exchange, all parties must reach a consensus to ensure data accuracy and consistency. Blockchain technology, a recently emerging distributed ledger technology, offers decentralized, trustworthy, and tamper-proof features, making it an effective means of addressing data sharing security and consensus efficiency.
[0003] However, when using blockchain technology for data sharing, there are still some problems in sharing security and efficiency. For example, the data sharing authorization information management method is easily attacked by hackers, resulting in data leakage or illegal modification, or when communicating between nodes, information exchange takes a long time to reach a consensus, affecting data sharing efficiency. Summary of the Invention
[0004] In response to the problems existing in the prior art, embodiments of the present invention provide a data sharing authorization information management method and system based on blockchain.
[0005] An embodiment of the present invention provides a data sharing authorization information management method based on blockchain, the method comprising: Configuring a private key generator, wherein the private key generator is an irreversible function that generates a private key based on an identity identifier; Receive a user identity, generate a user private key through the private key generator, bind the user private key to the user identity, and generate a digital signature based on the user private key; Comprehensively collecting behavioral indicator information of the blockchain nodes, calculating node reputation values of the blockchain nodes based on the behavioral indicator information of the blockchain nodes, stratifying the blockchain nodes based on the node reputation values, and selecting consensus nodes in each stratum, wherein the behavioral indicator information includes at least one type of associated behavioral data of the blockchain nodes with respect to the digital signature; When an abnormality is detected in the consensus node, communication voting is performed through the blockchain nodes of the corresponding layer, and the consensus node is dynamically adjusted according to the voting results.
[0006] In one embodiment, the digital signature includes a user digital signature and a ring signature; The generating of a digital signature based on the user's private key includes: Calculate the hash value based on the target data to obtain a fixed-length summary value; Combining a generator point in the elliptic curve with a randomly generated temporary key, generating a first part of the user digital signature using the generator point and the temporary key, and combining a calculation result of the user private key and the digest value to generate a second part of the user digital signature; Select multiple target users, superimpose their digital signatures, assign a random number, and generate a ring signature.
[0007] In one embodiment, the calculation formula of the ring signature includes: in, is the ring signature, m is the target data, t is the number of target users, For target user i j The user digital signature is r, a random number, and G is a fixed point on the elliptic curve.
[0008] In one embodiment, the method further comprises: Obtain blockchain reputation rules, compare behavioral indicator information of blockchain nodes, perform normalized scoring and weight assignment on each associated behavioral data in the behavioral indicator information, and calculate the node reputation value, wherein the behavioral indicator information includes at least one associated behavioral data selected from the number of successful signature verifications of the digital signature by the blockchain node, the signature verification response time, and signature-related violation data.
[0009] In one embodiment, the method further comprises: Randomly select any node from each layer of nodes as a voting set, collect the communication voting results of the voting set, and detect whether the pass rate in the communication voting results exceeds a preset threshold; When the pass rate in the communication voting result exceeds a preset threshold, the consensus node is dynamically adjusted based on the voting target.
[0010] An embodiment of the present invention provides a data sharing authorization information management system based on blockchain, the system comprising: A configuration module, configured to configure a private key generator, wherein the private key generator is an irreversible function that generates a private key based on an identity identifier; A private key module, configured to receive a user identity, generate a user private key through the private key generator, bind the user private key to the user identity, and generate a digital signature based on the user private key; a stratification module, configured to comprehensively collect behavioral indicator information of blockchain nodes, calculate node reputation values of blockchain nodes based on the behavioral indicator information of blockchain nodes, stratify blockchain nodes based on the node reputation values, and select consensus nodes in each stratum, wherein the behavioral indicator information includes at least one type of associated behavioral data of the blockchain nodes with respect to the digital signature; The adjustment module is used to detect that an abnormality exists in the consensus node, conduct communication voting through the blockchain nodes of the corresponding layer, and dynamically adjust the consensus node according to the voting results.
[0011] In one embodiment, the system further comprises: A calculation module is used to calculate a hash value based on the target data to obtain a summary value of a fixed length; A user digital signature module, configured to combine a generator point in an elliptic curve with a randomly generated temporary key to generate a first portion of the user digital signature using the generator point and the temporary key, and to generate a second portion of the user digital signature using a calculation result of the user private key and the digest value; The ring signature module is used to select multiple target users, superimpose the user digital signatures of the multiple target users, and assign a random number to generate a ring signature.
[0012] In one embodiment, the system further comprises: The reputation value module is used to obtain blockchain reputation rules, compare the behavioral indicator information of blockchain nodes, perform normalized scoring and weight assignment on each associated behavioral data in the behavioral indicator information, and calculate the node reputation value. The behavioral indicator information includes at least one associated behavioral data selected from the number of successful signature verifications of the blockchain node for the digital signature, the signature verification response time, and signature-related violation data.
[0013] An embodiment of the present invention provides an electronic device, including a processor and a memory; The processor is connected to the memory; The memory is used to store executable program code; The processor reads the executable program code stored in the memory to run a program corresponding to the executable program code, so as to execute the method described in one or more embodiments.
[0014] An embodiment of the present invention provides a non-transitory computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the steps of the above-mentioned blockchain-based data sharing authorization information management method are implemented.
[0015] In view of the above, in one or more embodiments of this specification, a private key generator is configured, and the key generator is an irreversible function that generates a private key for an identity identifier; a user identity identifier is received, a user private key is generated by the private key generator, the user private key is bound to the user identity identifier, and a digital signature is generated based on the user private key; the behavior indicators of the blockchain nodes are comprehensively counted, the node reputation value is calculated, and the blockchain nodes are layered based on the node reputation value, and the consensus nodes in each layer are selected, and the behavior indicators include the associated behavior for the digital signature; when an abnormality is detected in the consensus node, communication voting is performed through the layered nodes, and the consensus node is dynamically adjusted according to the voting results. In this way, data sharing authorization information can be encrypted, and the encryption adopts an identity-based digital signature algorithm, and a private key generator is introduced into the algorithm to avoid the disadvantage of easy leakage of public key certificates. At the same time, smart contracts are deployed in the blockchain network to realize reputation value management, and management and intelligent adjustment are realized through consensus nodes. The consensus nodes improve data sharing efficiency while automatically eliminating dangerous nodes. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0017] Figure 1 This is a flowchart of a blockchain-based data sharing authorization information management method provided by an embodiment of this specification.
[0018] Figure 2 This is a structural diagram of a blockchain-based data sharing authorization information management system provided by an embodiment of this specification.
[0019] Figure 3 This is a structural diagram of an electronic device provided by an embodiment of this specification. DETAILED DESCRIPTION
[0020] The subject matter described herein will now be discussed with reference to example embodiments. It should be understood that these embodiments are discussed only to enable those skilled in the art to better understand and implement the subject matter described herein, and are not intended to limit the scope of protection, applicability, or examples set forth in the claims. The functions and arrangements of the elements discussed may be changed without departing from the scope of protection of this specification. Various examples may omit, replace, or add various processes or components as needed. For example, the described method may be performed in an order different from the order described, and various steps may be added, omitted, or combined. In addition, features described relative to some examples may also be combined in other examples.
[0021] As used herein, the term "including" and its variations are open terms meaning "including but not limited to". The term "based on" means "based at least in part on". The terms "one embodiment" and "an embodiment" mean "at least one embodiment". The term "another embodiment" means "at least one other embodiment". The terms "first", "second", etc. may refer to different or the same objects. Other definitions may be included below, whether explicit or implicit. Unless the context clearly indicates otherwise, the definition of a term is consistent throughout the specification.
[0022] like Figure 1 As shown, an embodiment of the present invention provides a data sharing authorization information management method based on blockchain, including: Step S102: configuring a private key generator, wherein the private key generator is an irreversible function that generates a private key based on an identity identifier.
[0023] Specifically, a private key generator is an irreversible function in a blockchain whose input is an identity identifier (IDi) and whose output is the corresponding private key (SKi). This irreversible function can be a cryptographically secure function, such as a hash-based function. The private key can only be calculated from the input, or identity identifier (IDi), and cannot be calculated or derived from the private key. Furthermore, the private key generator can be split into multiple nodes (for example, five), with at least three nodes collaborating to generate the private key, preventing single-point leakage. Using a private key generator avoids the vulnerability of public key certificates to leaks, thereby improving data security.
[0024] Step S104: receiving a user identity, generating a user private key through the private key generator, binding the user private key to the user identity, and generating a digital signature based on the user private key.
[0025] Specifically, when the blockchain receives a user ID, it triggers the private key generator, which generates the user's private key and returns it to the user. The user ID can be a unique credential representing the user's identity, such as an organization name, number, or other unique string. The ID is then processed using a hash function (such as SHA3-256) to generate a fixed-length value that serves as the private key. When generating the private key, each independent node of the private key generator only participates in a partial calculation, and the final result is aggregated through a secure protocol to generate the complete private key. The user's private key is then stored in a linked state with the user ID.
[0026] Furthermore, a corresponding public key can be generated locally based on the private key, using the Elliptic Curve Digital Signature Algorithm (ECDSA). ECDSA is based on an elliptic curve over a finite field, typically denoted E(Fp), where p is a prime number and Fp is a finite field. Point P on this curve is called a generator point and can be used to generate all other points. Elliptic curves have special properties, such as the difficulty of determining the location of points on the curve, which makes ECDSA highly secure and computationally efficient. ECDSA uses a key pair for signing and verification. The key pair consists of a private key and a public key. The private key is typically denoted d, and the public key is a point Q based on the private key and the generator point P. The public key Q = dP, where d is the private key and P is the generator point.
[0027] Furthermore, a digital signature is generated for the data that needs to be authorized or shared based on the user's private key, where the digital signature includes the user's digital signature and the ring signature. The process of generating the user's digital signature can use the elliptic curve digital signature algorithm, including: ECDSA first requires calculating a hash value. A hash value is a fixed-length summary of a message, typically generated using a hash function such as SHA-256 or SHA-512. The ECDSA signing process involves a random number, k, which is used only during the signature generation process and is therefore called a temporary private key.
[0028] The process of generating a user digital signature is as follows: 1) Randomly select an integer k (1≤k≤n-1), where n is the order of the generator point P (i.e., n=ord(P)). 2) Calculation point R = kP; 3) Convert the x-coordinate of R to an integer r (if R is at infinity, reselect k and repeat step 1); 4) Calculate s = k^-1 (z + rd) mod n, where z is the hash value of the message, r is the integer calculated in 3), and d is the private key; 5) If s = 0, reselect k and repeat 1); otherwise, the signature is (r, s).
[0029] Note that k must be different for each signature to prevent an attacker from deriving the private key from the signature using the same k.
[0030] After generating the user digital signature, select the target user, superimpose the target user's digital signature, and assign a random number to generate a ring signature. The specific steps include: Assume that n users want to sign the same message m, and t of them can form a ring signature. The ring signature process is as follows: (1) Select t users i1, i2, i3…i t , and a random number r.
[0031] (2) For j = 1, 2, 3, ..., t, user ij calculates his own digital signature SIG ij (m). If user i1 calculates the ring signature σ, the specific calculation method is as follows: Where G is a fixed generator, which can be a point on the elliptic curve.
[0032] The total length of a ring signature can be expressed as O(tk+1) or O(t), where t is the size of the ring and the constant portion is negligible. Compared to traditional digital signatures, this significantly shortens the length, thereby improving signature efficiency. Ring signatures also offer enhanced security, as only t users know the source of each digital signature within the signature, preventing others from deciphering the specific signature. The introduction of ring signatures reduces signature length, improves signature efficiency, and further enhances the security of data sharing authorization information.
[0033] Step S106, comprehensively count the behavioral indicator information of the blockchain nodes, and calculate the node reputation value of the blockchain nodes based on the behavioral indicator information of the blockchain nodes, and layer the blockchain nodes based on the node reputation value, and select the consensus nodes in each layer, wherein the behavioral indicator information includes at least one associated behavioral data of the blockchain node for the digital signature.
[0034] Specifically, the behavioral indicators of blockchain nodes can include the number of successful signature verifications. The higher the verification contribution, the greater the role of the node in maintaining network security and consistency; the signature verification response time. The faster the response, the stronger the node's performance and the more it can support an efficient consensus process; signature-related violations, including double-signature attacks, malicious denial of service, etc. The more violations, the greater the penalty for the node's reputation value, and other data related to the security and efficiency of the node's digital signature processing.
[0035] Furthermore, a smart contract on the blockchain collects the node's behavioral indicators and the reputation rules for each indicator. Each indicator is then normalized and weighted to calculate the node's reputation. The weighting of behavioral indicators can be adjusted based on the specific data content or based on the relative importance of the indicator. For example, verification contribution is given a higher weight (e.g., 40%) because it is the node's core responsibility, while response speed is second (e.g., 30%), reflecting the node's performance level. Violations are also given a higher weight (e.g., 30%) because they directly impact network security. Each indicator is then normalized and weighted to produce the final reputation value.
[0036] Furthermore, nodes are divided into different tiers based on their reputation. The division strategy can be based on node location, node entry order, or reputation, such as assigning high-reputation nodes to the first tier, medium-reputation nodes to the second tier, and low-reputation nodes to the third tier. This hierarchy is dynamically adjusted based on changes in node reputation. Within each tier, the node with the highest reputation is selected as the consensus node through a blockchain smart contract, responsible for consensus tasks within that tier.
[0037] Step S108: When an abnormality is detected in the consensus node, communication voting is performed through the blockchain nodes of the corresponding layer, and the consensus node is dynamically adjusted according to the voting results.
[0038] Specifically, consensus node behavior is monitored in real time. When a consensus node encounters an issue, such as downtime, loss of connection, illegal operation, or performance degradation, adjustments are made to the consensus node. For example, each node can periodically send a heartbeat signal to a designated target to indicate that it is in good condition. If a consensus node fails to send a heartbeat signal on time, or its behavior is reported by other nodes, the anomaly detection process is triggered.
[0039] Furthermore, the communication voting process can use a Byzantine fault tolerance mechanism to reach a communication consensus between nodes. The specific steps of the Byzantine fault tolerance mechanism include: 1) Each layer of nodes randomly selects t nodes to form a committee, which must include the consensus node p.
[0040] 2) Committee members communicate with each other, get each other's opinions, and then vote to reach the final decision.
[0041] 3) If the voting result exceeds a certain threshold, such as more than two-thirds t, consensus is considered to have been reached; otherwise, consensus is considered to have failed.
[0042] If the voting result exceeds the threshold, the consensus node is considered to be abnormal; otherwise, it is considered normal and continues to perform the duties of the consensus node.
[0043] Furthermore, dynamic adjustments to abnormal consensus nodes can include reducing their reputation and delegating them to regular nodes, followed by re-election of consensus nodes within the corresponding tier. If an abnormal node engages in malicious behavior (such as a double-signature attack), the system will confiscate its staked tokens as a penalty through a smart contract.
[0044] The embodiment of the present invention provides a data sharing authorization information management method based on blockchain, which configures a private key generator, which is an irreversible function that generates a private key for an identity identifier; receives a user identity identifier, generates a user private key through the private key generator, binds the user private key to the user identity identifier, and generates a digital signature based on the user private key; comprehensively counts the behavioral indicators of blockchain nodes, calculates the node reputation value, and hierarchizes the blockchain nodes based on the node reputation value, selects consensus nodes in each layer, and the behavioral indicators include associated behaviors for digital signatures; when an abnormality is detected in the consensus node, communication voting is performed through the hierarchical nodes, and the consensus node is dynamically adjusted according to the voting results. In this way, data sharing authorization information can be encrypted, and the encryption adopts an identity-based digital signature algorithm, and a private key generator is introduced into the algorithm to avoid the disadvantage that the public key certificate is easily leaked. At the same time, smart contracts are deployed in the blockchain network to realize reputation value management, promote the interaction of data sharing authorization information between nodes, and improve data sharing efficiency.
[0045] See Figure 2 , Figure 2 This is a structural diagram of a data sharing authorization information management system based on blockchain provided by an embodiment of the present application. Figure 2 As shown, the system includes: Configuration module S202, configured to configure a private key generator, wherein the private key generator generates an irreversible function of a private key for an identity identifier; The private key module S204 is configured to receive a user identity, generate a user private key through the private key generator, bind the user private key to the user identity, and generate a digital signature based on the user private key; a stratification module S206 for comprehensively collecting behavioral indicator information of blockchain nodes, calculating node reputation values of blockchain nodes based on the behavioral indicator information of blockchain nodes, stratifying blockchain nodes based on the node reputation values, and selecting consensus nodes in each stratum, wherein the behavioral indicator information includes at least one type of associated behavioral data of the blockchain nodes with respect to the digital signature; The adjustment module S208 is used to detect that an abnormality exists in the consensus node, conduct communication voting through the blockchain nodes of the corresponding layer, and dynamically adjust the consensus node according to the voting results.
[0046] In another embodiment, a blockchain-based data sharing authorization information management system further includes: A calculation module is used to calculate a hash value based on the target data to obtain a summary value of a fixed length; A user digital signature module, configured to combine a generator point in an elliptic curve with a randomly generated temporary key to generate a first portion of the user digital signature using the generator point and the temporary key, and to generate a second portion of the user digital signature using a calculation result of the user private key and the digest value; The ring signature module is used to select multiple target users, superimpose the user digital signatures of the multiple target users, and assign a random number to generate a ring signature.
[0047] In another embodiment, a blockchain-based data sharing authorization information management system further includes: The reputation value module is used to obtain blockchain reputation rules, compare the behavioral indicator information of blockchain nodes, perform normalized scoring and weight assignment on each associated behavioral data in the behavioral indicator information, and calculate the node reputation value. The behavioral indicator information includes at least one associated behavioral data selected from the number of successful signature verifications of the blockchain node for the digital signature, the signature verification response time, and signature-related violation data.
[0048] Those skilled in the art will clearly understand that the technical solutions of the embodiments of the present application can be implemented with the help of software and / or hardware. "Unit" and "module" in this specification refer to software and / or hardware that can independently perform or cooperate with other components to perform specific functions, where the hardware can be, for example, a field-programmable gate array (FPGA) or an integrated circuit (IC).
[0049] Each processing unit and / or module in the embodiments of the present application may be implemented by an analog circuit that implements the functions described in the embodiments of the present application, or may be implemented by software that executes the functions described in the embodiments of the present application.
[0050] See also Figure 3 , which shows a schematic diagram of the structure of an electronic device involved in an embodiment of the present application, the electronic device can be used to implement Figure 1 The method in the embodiment shown. Figure 3As shown, the electronic device 300 may include: at least one processor 301 , at least one network interface 304 , a user interface 303 , a memory 305 , and at least one communication bus 302 .
[0051] The communication bus 302 is used to implement the connection and communication between these components.
[0052] The user interface 303 may include a display screen (Display) and a camera (Camera). Optionally, the user interface 303 may also include a standard wired interface and a wireless interface.
[0053] The network interface 304 may optionally include a standard wired interface or a wireless interface (such as a WI-FI interface).
[0054] The processor 301 may include one or more processing cores. The processor 301 utilizes various interfaces and circuits to connect various components within the electronic device 300. It executes instructions, programs, code sets, or instruction sets stored in the memory 305 and accesses data stored in the memory 305 to perform various functions and process data within the electronic device 300. Optionally, the processor 301 may be implemented using at least one of the following hardware forms: a digital signal processing (DSP), a field-programmable gate array (FPGA), or a programmable logic array (PLA). The processor 301 may integrate one or a combination of a central processing unit (CPU), a graphics processing unit (GPU), and a modem. The CPU primarily processes the operating system, user interface, and application programs; the GPU is responsible for rendering and drawing content displayed on the display; and the modem handles wireless communications. It is understood that the modem may also be implemented independently of the processor 301 and implemented on a separate chip.
[0055] Among them, the memory 305 may include a random access memory (RAM) or a read-only memory (Read-Only Memory). Optionally, the memory 305 includes a non-transitory computer-readable storage medium. The memory 305 can be used to store instructions, programs, codes, code sets or instruction sets. The memory 305 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area may store data involved in the above-mentioned various method embodiments, etc. The memory 305 may also be optionally at least one storage device located away from the aforementioned processor 301. As Figure 3 As shown, the memory 305 as a computer storage medium may include an operating system, a network communication module, a user interface module, and program instructions.
[0056] exist Figure 3 In the electronic device 300 shown, the user interface 303 is mainly used to provide an input interface for the user and obtain the data input by the user; and the processor 301 can be used to call the image-generated interactive application stored in the memory 305, and specifically perform the following operations: configure a private key generator, and the key generator is an irreversible function that generates a private key for an identity identifier; receive a user identity identifier, generate a user private key through the private key generator, bind the user private key to the user identity identifier, and generate a digital signature based on the user private key; comprehensively count the behavioral indicators of the blockchain nodes, calculate the node reputation value, and layer the blockchain nodes based on the node reputation value, select the consensus nodes in each layer, and the behavioral indicators include the associated behavior for the digital signature; when an abnormality is detected in the consensus node, communication voting is carried out through the layered nodes, and the consensus nodes are dynamically adjusted according to the voting results.
[0057] The present application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the above method. The computer-readable storage medium may include, but is not limited to, any type of disk, including a floppy disk, an optical disk, a DVD, a CD-ROM, a microdrive, a magneto-optical disk, a ROM, a RAM, an EPROM, an EEPROM, a DRAM, a VRAM, a flash memory device, a magnetic card or an optical card, a nanosystem (including a molecular memory IC), or any type of medium or device suitable for storing instructions and / or data.
[0058] It should be noted that for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by this application.
[0059] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0060] In the several embodiments provided in this application, it should be understood that the disclosed devices can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some service interface, and the indirect coupling or communication connection of the device or unit can be electrical or other forms.
[0061] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0062] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0063] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a memory and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned memory includes: U disk, read-only memory (ROM), random access memory (RAM), mobile hard disk, magnetic disk, or optical disk, etc., various media that can store program code.
[0064] Those skilled in the art will appreciate that all or part of the steps in the various methods of the above embodiments may be completed by instructing related hardware through a program, and the program may be stored in a computer-readable memory, which may include a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, etc.
[0065] The foregoing description of this specification describes specific embodiments. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different from that described in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order shown or the sequential order to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
Claims
1. A data sharing authorization information management method based on blockchain, the method comprising: Configuring a private key generator, wherein the private key generator is an irreversible function that generates a private key based on an identity identifier; Receive a user identity, generate a user private key through the private key generator, bind the user private key to the user identity, and generate a digital signature based on the user private key; Comprehensively collecting behavioral indicator information of the blockchain nodes, calculating node reputation values of the blockchain nodes based on the behavioral indicator information of the blockchain nodes, stratifying the blockchain nodes based on the node reputation values, and selecting consensus nodes in each stratum, wherein the behavioral indicator information includes at least one type of associated behavioral data of the blockchain nodes with respect to the digital signature; When an abnormality is detected in the consensus node, communication voting is performed through the blockchain nodes of the corresponding layer, and the consensus node is dynamically adjusted according to the voting results.
2. The method according to claim 1, characterized in that The digital signature includes a user digital signature and a ring signature; The generating of a digital signature based on the user's private key includes: Calculate the hash value based on the target data to obtain a fixed-length summary value; Combining a generator point in the elliptic curve with a randomly generated temporary key, generating a first part of the user digital signature using the generator point and the temporary key, and combining a calculation result of the user private key and the digest value to generate a second part of the user digital signature; Select multiple target users, superimpose their digital signatures, assign a random number, and generate a ring signature.
3. The method according to claim 2, characterized in that The calculation formula of the ring signature includes: in, is the ring signature, m is the target data, t is the number of target users, For target user i j The user digital signature is r, a random number, and G is a fixed point on the elliptic curve.
4. The method according to claim 1, wherein The comprehensive statistics of blockchain node behavior indicators and calculation of node reputation values include: Obtain blockchain reputation rules, compare behavioral indicator information of blockchain nodes, perform normalized scoring and weight assignment on each associated behavioral data in the behavioral indicator information, and calculate the node reputation value, wherein the behavioral indicator information includes at least one associated behavioral data selected from the number of successful signature verifications of the digital signature by the blockchain node in the zone, the signature verification response time, and signature-related violation data.
5. The method according to claim 4, characterized in that The communication voting is performed through the hierarchical nodes, and the consensus nodes are dynamically adjusted according to the voting results, including: Randomly select any node from each layer of nodes as a voting set, collect the communication voting results of each layer of voting sets, and detect whether the pass rate in the communication voting results exceeds a preset threshold; When the pass rate in the communication voting result exceeds a preset threshold, the consensus node is dynamically adjusted based on the voting target.
6. A data sharing authorization information management system based on blockchain, characterized in that: The system comprises: A configuration module, configured to configure a private key generator, wherein the private key generator is an irreversible function that generates a private key based on an identity identifier; A private key module, configured to receive a user identity, generate a user private key through the private key generator, bind the user private key to the user identity, and generate a digital signature based on the user private key; a stratification module, configured to comprehensively collect behavioral indicator information of blockchain nodes, calculate node reputation values of blockchain nodes based on the behavioral indicator information of blockchain nodes, stratify blockchain nodes based on the node reputation values, and select consensus nodes in each stratum, wherein the behavioral indicator information includes at least one type of associated behavioral data of the blockchain nodes with respect to the digital signature; The adjustment module is used to detect that an abnormality exists in the consensus node, conduct communication voting through the blockchain nodes of the corresponding layer, and dynamically adjust the consensus node according to the voting results.
7. The system according to claim 6, characterized in that The system further comprises: A calculation module is used to calculate a hash value based on the target data to obtain a summary value of a fixed length; A user digital signature module, configured to combine a generator point in an elliptic curve with a randomly generated temporary key to generate a first portion of the user digital signature using the generator point and the temporary key, and to generate a second portion of the user digital signature using a calculation result of the user private key and the digest value; The ring signature module is used to select multiple target users, superimpose the user digital signatures of the multiple target users, and assign a random number to generate a ring signature.
8. The system according to claim 6, wherein: The system further comprises: The reputation value module is used to obtain blockchain reputation rules, compare the behavioral indicator information of blockchain nodes, perform normalized scoring and weight assignment on each associated behavioral data in the behavioral indicator information, and calculate the node reputation value. The behavioral indicator information includes at least one associated behavioral data selected from the number of successful signature verifications of the blockchain node for the digital signature, the signature verification response time, and signature-related violation data.
9. An electronic device comprising a processor and a memory; The processor is connected to the memory; The memory is used to store executable program code; The processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to execute the method according to any one of claims 1 to 5.
10. A computer-readable storage medium having a computer program stored thereon, wherein the computer program implements the method according to any one of claims 1 to 5 when executed by a processor.