Document security access method and device based on block chain, equipment and storage medium

By storing document identification information and encrypted data features on the blockchain and setting access permission policies, the problems of data tampering and unauthorized access in traditional document storage systems are solved, and secure access and reliable storage of documents are achieved.

CN120744969APending Publication Date: 2025-10-03SHANGHAI DONGPU INFORMATION TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510778434.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-11
Publication Date
2025-10-03

Smart Images

  • Figure CN120744969A_ABST
    Figure CN120744969A_ABST
Patent Text Reader

Abstract

The invention relates to the field of data access, and discloses a document security access method and device based on a block chain, equipment and a storage medium. The method comprises the following steps: storing identification information and encrypted data characteristics of a document in the block chain; setting a permission configuration strategy of the document through a preset configuration logic of the block chain; performing identity and permission verification on the user based on the permission configuration strategy, and storing verification-related interaction information in the block chain; and performing data recovery or integrity verification on the document based on the encrypted data features and the identification information stored in the block chain. According to the document security access method based on the block chain provided by the invention, the security and reliability of document storage are improved and auditing and recovery processes are simplified by utilizing the characteristics of decentralization, tampering resistance and transparency of the block chain.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data access technology, and in particular to a blockchain-based document security access method, device, equipment and storage medium. Background Art

[0002] With the rapid development of information technology, the secure storage of electronic documents has become a focus of attention across various industries. Traditional document storage methods rely primarily on centralized servers, which present numerous security risks. On the one hand, if centralized servers are attacked by hackers or malware, the vast amount of stored document data could be stolen, tampered with, or lost, causing significant losses to businesses and individuals. On the other hand, the lack of effective control mechanisms for data access and management permissions makes it easy for insiders to violate regulations and leak sensitive information.

[0003] Therefore, the existing technology still needs to be improved and developed. Summary of the Invention

[0004] This paper proposes a blockchain-based document security access method, which aims to solve the problems of data tampering, unauthorized access, data loss, etc. in traditional document storage systems.

[0005] A first aspect of the present invention provides a blockchain-based document security access method, comprising: storing the identification information and encrypted data features of a document in a blockchain; setting an access permission configuration policy for the document through a preset configuration logic of the blockchain; upon receiving a user access request, obtaining the user's identity information, performing identity and permission verification on the identity information based on the access permission configuration policy, and allowing access after passing the verification, and storing verification-related interaction information in the blockchain.

[0006] Optionally, in a first implementation method of the first aspect of the present invention, metadata of the document is extracted as identification information, the metadata including document title data, creation time data and author information data; the document content of the document is encrypted to generate encrypted data, and a hash operation is performed on the encrypted data to obtain encrypted data features; the identification information and encrypted data features are packaged into transaction data, security authentication and consensus verification are performed on the transaction data, and the transaction data that has passed security authentication and consensus verification is stored in the blockchain.

[0007] Optionally, in a second implementation of the first aspect of the present invention, a symmetric key is generated in advance, and the document content of the document is encrypted in blocks based on the symmetric key and using an encryption algorithm to obtain encrypted document content; an asymmetric public-private key pair is generated in advance, and the symmetric key is encrypted using an asymmetric encryption algorithm based on the public key in the asymmetric public-private key pair to obtain an encrypted symmetric key; and the encrypted document content and the encrypted symmetric key are integrated to obtain encrypted data.

[0008] Optionally, in a third implementation of the first aspect of the present invention, a preset configuration logic is deployed on the blockchain, and the preset configuration logic is used to clarify the user identity and the permission set corresponding to the user identity; based on the preset configuration logic, different user identities and different user identities' operation permissions for the document are set to obtain an access permission configuration policy including identity authentication rules and operation permission verification rules, and the operation permissions include reading, modifying, deleting and restoring.

[0009] Optionally, in a fourth implementation of the first aspect of the present invention, when a user access request is received, the user's identity information is obtained; the identity information is authenticated based on the identity authentication rules included in the access permission configuration policy to obtain identity authentication information; when the identity authentication information indicates that the identity authentication is passed, the identity information is authorized to be confirmed according to the operation permission verification rules included in the access permission configuration policy to obtain permission confirmation information; after obtaining the identity authentication information and the permission confirmation information, the user is allowed to perform corresponding permission operations; the identity information, the identity authentication information and the permission confirmation information are stored in the blockchain.

[0010] Optionally, in a fifth implementation of the first aspect of the present invention, when a user data recovery request is received, whether the data recovery operation can be performed is determined based on the authority confirmation information; when the data recovery operation can be performed, identification information associated with the document to be recovered is obtained from the blockchain, and based on the identification information, the encrypted data characteristics, the encrypted symmetric key, the asymmetric public-private key pair and the encrypted document content of the document to be recovered are obtained; the encrypted symmetric key is decrypted by the private key in the asymmetric public-private key pair to obtain the decrypted symmetric key; the encrypted document content is decrypted by the decrypted symmetric key to obtain the decrypted document content; a hash operation is performed on the decrypted document content to obtain a first encrypted data characteristic, and the first encrypted data characteristic is compared and verified with the encrypted data characteristic; if the values ​​of the first encrypted data characteristic and the encrypted data characteristic are consistent, the data recovery operation is completed.

[0011] Optionally, in a sixth implementation of the first aspect of the present invention, when a user integrity verification request is received, whether the integrity verification operation can be performed is determined based on the authority confirmation information; when the integrity verification operation can be performed, identification information associated with the document to be verified is obtained from the blockchain, and the encrypted data feature of the document to be verified is obtained based on the identification information; a hash operation is performed on the content of the document to be verified to obtain a second encrypted data feature, and the second encrypted data feature is compared and verified with the encrypted data feature; if the values ​​of the second encrypted data feature and the encrypted data feature are consistent, the integrity verification operation is completed.

[0012] The second aspect of the present invention provides a document security access device based on blockchain, including: a storage module for storing the identification information and encrypted data characteristics of a document in a blockchain; a setting module for setting the access permission configuration policy of the document through the preset configuration logic of the blockchain; a verification module for obtaining the user's identity information when receiving a user access request, performing identity and permission verification on the identity information based on the access permission configuration policy, and allowing access after passing the verification, and storing the verification-related interaction information in the blockchain.

[0013] Optionally, in a first implementation manner of the second aspect of the present invention, the storage module includes: an extraction unit for extracting metadata of a document as identification information, wherein the metadata includes document title data, creation time data, and author information data; an encryption unit for encrypting the document content of the document to generate encrypted data, and performing a hash operation on the encrypted data to obtain encrypted data features; an integration unit for packaging the identification information and encrypted data features into transaction data, performing security authentication and consensus verification on the transaction data, and storing the transaction data that has passed security authentication and consensus verification in a blockchain.

[0014] Optionally, in a second implementation of the second aspect of the present invention, the encryption unit is specifically used to pre-generate a symmetric key, and based on the symmetric key and using an encryption algorithm, encrypt the document content of the document in blocks to obtain encrypted document content; pre-generate an asymmetric public-private key pair, and based on the public key in the asymmetric public-private key pair, use an asymmetric encryption algorithm to encrypt the symmetric key to obtain an encrypted symmetric key; and integrate the encrypted document content and the encrypted symmetric key to obtain encrypted data.

[0015] Optionally, in a third implementation of the second aspect of the present invention, the setting module includes: a deployment unit for deploying preset configuration logic on the blockchain, the preset configuration logic being used to clarify the user identity and the permission set corresponding to the user identity; a setting unit for setting different user identities and the operation permissions of different user identities for the document based on the preset configuration logic, and obtaining an access permission configuration policy including identity authentication rules and operation permission verification rules, wherein the operation permissions include reading, modifying, deleting and restoring.

[0016] Optionally, in a fourth implementation of the second aspect of the present invention, the verification module includes: a first acquisition unit, used to obtain the user's identity information when receiving a user access request; a judgment unit, used to authenticate the identity information based on the identity authentication rules included in the access permission configuration policy to obtain identity authentication information; when the identity authentication information indicates that the identity authentication is passed, the identity information is authorized to be confirmed according to the operation permission verification rules included in the access permission configuration policy to obtain permission confirmation information; a permission unit, used to allow the user to perform corresponding permission operations after obtaining the identity authentication information and the permission confirmation information; a storage unit, used to store the identity information, the identity authentication information and the permission confirmation information in the blockchain.

[0017] Optionally, in a fifth implementation of the second aspect of the present invention, the blockchain-based document security access device further includes: a first judgment unit, for judging whether a data recovery operation can be performed based on authority confirmation information when a user data recovery request is received; a second acquisition unit, for obtaining identification information associated with the document to be recovered from the blockchain when the data recovery operation can be performed, and obtaining the encrypted data features, encrypted symmetric keys, asymmetric public-private key pairs and encrypted document content of the document to be recovered based on the identification information; a decryption unit, for decrypting the encrypted symmetric key using the private key in the asymmetric public-private key pair to obtain a decrypted symmetric key; decrypting the encrypted document content using the decrypted symmetric key to obtain decrypted document content; a first comparison unit, for performing a hash operation on the decrypted document content to obtain a first encrypted data feature, and comparing and verifying the first encrypted data feature with the encrypted data feature; if the values ​​of the first encrypted data feature and the encrypted data feature are consistent, the data recovery operation is completed.

[0018] Optionally, in a sixth implementation of the second aspect of the present invention, the blockchain-based document security access device further includes: a second judgment unit, for judging whether the integrity verification operation can be performed based on the authority confirmation information when a user integrity verification request is received; a third acquisition unit, for obtaining identification information associated with the document to be verified from the blockchain when the integrity verification operation can be performed, and obtaining the encrypted data feature of the document to be verified based on the identification information; a second comparison unit, for performing a hash operation on the content of the document to be verified to obtain a second encrypted data feature, and comparing and verifying the second encrypted data feature with the encrypted data feature; if the values ​​of the second encrypted data feature and the encrypted data feature are consistent, the integrity verification operation is completed.

[0019] The third aspect of the present invention provides a blockchain-based document security access device, comprising: a memory and at least one processor, wherein the memory stores computer-readable instructions, and the memory and the at least one processor are interconnected via a line; the at least one processor calls the computer-readable instructions in the memory so that the blockchain-based document security access device executes the various steps of the blockchain-based document security access method as described above.

[0020] A fourth aspect of the present invention provides a computer-readable storage medium, which stores computer-readable instructions. When the computer-readable storage medium is run on a computer, it enables the computer to execute the various steps of the blockchain-based document security access method as described above.

[0021] Beneficial Effects: In the technical solution of the present invention, the identification information and encrypted data features of the document are stored in the blockchain, and its tamper-proof characteristics are used to prevent data loss and theft; the access permission configuration policy is set through the preset configuration logic of the blockchain, the user identity and operation permissions are verified, and the interactive information is uploaded to the blockchain to achieve refined management of permissions and operation traceability; based on the stored information on the blockchain, the document is restored by comparing the decrypted and encrypted data features, or the integrity is verified by directly comparing the encrypted data features, and it is possible to quickly determine whether the data has been tampered with without decryption. The present invention provides a document security access method based on blockchain, which improves the security and reliability of document storage by utilizing the decentralized, tamper-proof and transparent characteristics of the blockchain. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Figure 1 A first flow chart of a blockchain-based document security access method provided in an embodiment of the present invention;

[0023] Figure 2 A second flow chart of the blockchain-based document security access method provided in an embodiment of the present invention;

[0024] Figure 3 A third flow chart of the blockchain-based document security access method provided in an embodiment of the present invention;

[0025] Figure 4 A fourth flow chart of a blockchain-based document security access method provided in an embodiment of the present invention;

[0026] Figure 5 A fifth flow chart of the blockchain-based document security access method provided in an embodiment of the present invention;

[0027] Figure 6 A sixth flow chart of a blockchain-based document security access method provided by an embodiment of the present invention;

[0028] Figure 7 A seventh flow chart of a blockchain-based document security access method provided in an embodiment of the present invention;

[0029] Figure 8 A schematic diagram of the structure of a blockchain-based document security access device provided by an embodiment of the present invention;

[0030] Figure 9 Another structural diagram of a blockchain-based document security access device provided by an embodiment of the present invention;

[0031] Figure 10 A schematic diagram of the structure of a blockchain-based document security access device provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0032] Embodiments of the present invention provide a blockchain-based document security access method, apparatus, device, and storage medium. In the technical solution of the present invention, the identification information and encrypted data features of a document are stored in a blockchain, and its storage and change history is recorded. The document content is encrypted using symmetric and asymmetric encryption technologies, and the encrypted data features of the encrypted information are recorded. Document access rights are set through the blockchain's preset configuration logic to ensure that only authorized users can access or modify the document. At the same time, access and operation logs are stored in the blockchain to implement audit tracking. The encrypted data features pre-stored in the blockchain are used to support document recovery and reconstruction, and verify the integrity and consistency of the document. The storage, access, and change rules are automatically executed through the blockchain's preset configuration logic, and document version information and change records are recorded. The present invention provides a blockchain-based document security access method that improves the security and reliability of document storage by utilizing the decentralized, tamper-proof, and transparent characteristics of the blockchain, and solves the problems of data tampering, unauthorized access, data loss, etc. existing in traditional document storage systems.

[0033] The terms "first," "second," "third," "fourth," and the like (if any) in the description and claims of the present invention and in the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate so that the embodiments described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "including" or "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product, or apparatus that includes a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to these processes, methods, products, or apparatus.

[0034] For ease of understanding, the specific process of the embodiment of the present invention is described below. Figure 1 The first embodiment of the blockchain-based document security access method in the embodiment of the present invention includes:

[0035] S100, storing the identification information and encrypted data features of the document in the blockchain;

[0036] In this embodiment, the document's identifying information is metadata extracted from the document. This metadata typically includes, but is not limited to, the document title, author name, creation time, modification time, document type (e.g., Word, PDF), and the document's Universally Unique Identifier (UUID). The encrypted data signature is first generated through the following process: a random numeric string is generated, the document content is split into small blocks of a certain number of bits, and an initialization vector (IV) of the same size is randomly generated. Each block of data is encrypted using a cipher block chaining mode combined with the randomly generated VIV to obtain the encrypted document content. A pair of asymmetric public and private keys is then generated, each consisting of a public key that can be made public and a private key that must be kept secret. The generated random numeric string is then encrypted using the public key to obtain an encrypted symmetric key. Finally, a secure hash operation is performed on the encrypted document content to generate a unique encrypted data signature, i.e., a hash value. A hash value is a unique and deterministic way of representing data signatures.

[0037] For example, when a user uploads a text document, the system automatically reads the file header to obtain information such as the title and author, and structures it into a lightweight data exchange format (JSON, JavaScript Object Notation), such as "Title: Financial Report, Author: Zhang San", and sends it to the blockchain through the blockchain development toolkit together with encrypted data features. It is stored after verification by the consensus mechanism and the storage timestamp is recorded.

[0038] S200: Setting the access permission configuration policy for the document using the preset configuration logic of the blockchain;

[0039] In this embodiment, the preset configuration logic refers to a blockchain smart contract that is used to set the access permission configuration policy for a document. The access permission configuration policy includes users such as administrators, editors, and viewers, as well as corresponding operation permissions such as read, modify, delete, and restore. The preset configuration logic defines, but is not limited to, a table of user identities, the set of operations allowed for each identity, and the rules for changing permissions. For example, editors can read and modify documents but not delete them, while administrators can read, modify, delete, and restore them. After the document access permission configuration policy is set using the preset configuration logic, the permission configuration policy can automatically verify user permissions according to the set rules and execute the corresponding operations, ensuring that document access and operations comply with the set rules while ensuring the security, transparency, and traceability of the entire process.

[0040] For example, a document owner calls a pre-configured logic interface, known as a smart contract interface, and enters the target user's blockchain address, a designated identity, and the permitted operation types. The pre-configured logic automatically verifies the document owner's permissions and stores the permission information, such as the user address, identity, and operation permissions, on the blockchain. It also generates an immutable record of permission changes, thereby generating an access permission configuration policy for the document. All subsequent user access requests to the document will trigger the access permission configuration policy to verify their permissions. For example, user A is configured as an editor, allowing them to read and modify the document but prohibiting deletion. The relevant permission information is permanently stored as key-value pairs to ensure that it cannot be tampered with.

[0041] S300. When a user access request is received, the user's identity information is obtained, and the identity and authority verification of the identity information is performed based on the access permission configuration policy, and access is allowed after passing the verification, and the verification-related interaction information is stored in the blockchain.

[0042] In this embodiment, identity information includes the user's blockchain address, digital certificate, or the hash value of their username and password. When a user access request is received, identity verification is performed first. If the user uses a digital certificate, the access rights configuration policy verifies the issuing authority, validity period, and signature of the digital certificate. If the user uses a username and password, the access rights configuration policy compares the hash value of the input password with the hash value stored on the blockchain to ensure consistency. After identity verification is successful, permission verification is performed: the access rights configuration policy queries the set of operation permissions corresponding to the user identity to determine whether the requested operation type, such as read or download, is included.

[0043] For example, when a user initiates a document access request, the system extracts the blockchain address and digital certificate from the user's identity information. After verifying the validity of the digital certificate through the access rights configuration policy, the system then checks that the identity corresponding to the blockchain address is a "viewer," granting read-only access to the document's encrypted content. The interactive information generated during the verification process, such as the user address, verification time (May 29, 2025, 14:30), operation type (read), and result (pass), is packaged into transaction data in a lightweight data exchange format (JSON, JavaScript Object Notation). After security authentication and consensus verification, the transaction data is stored on the blockchain, forming a traceable audit log.

[0044] Furthermore, if identity verification fails, the access rights configuration policy will directly deny the user's access request without performing any permission verification. The policy will also store the denial information, such as the time of denial, user ID, and reason for denial, on the blockchain as an audit record. For example, if the digital certificate submitted by the user is invalid (e.g., expired, incorrectly signed, or the username and password hash values ​​are inconsistent with those recorded on the blockchain), the access rights configuration policy will determine that the authentication failed. This configuration prevents unauthorized users from bypassing permission verification, strengthening the security of document storage. Furthermore, all denial records cannot be tampered with, meeting compliance audit requirements.

[0045] This embodiment provides a blockchain-based document security access method that stores a document's identifying information and encrypted data features on the blockchain, leveraging its tamper-proof properties to prevent data loss and theft. Access rights configuration policies are set using the blockchain's pre-configured configuration logic to verify user identities and operational permissions, and interactive information is uploaded to the blockchain, enabling refined permission management and operation traceability. Based on the stored information on the blockchain, document recovery is accomplished by comparing decrypted and encrypted data features, or by directly comparing encrypted data features to verify integrity, enabling rapid determination of data tampering without the need for decryption. The present invention provides a blockchain-based document security access method that improves the security and reliability of document storage by leveraging the blockchain's decentralized, tamper-proof, and transparent properties.

[0046] Reference Figure 2 The second embodiment of the blockchain-based document security access method in the embodiment of the present invention includes:

[0047] S110, extracting metadata of the document as identification information, wherein the metadata includes document title data, creation time data, and author information data;

[0048] S120: Encrypt the document content to generate encrypted data, and perform a hash operation on the encrypted data to obtain encrypted data features;

[0049] S130: Pack the identification information and encrypted data features into transaction data, perform security authentication and consensus verification on the transaction data, and store the transaction data that has passed security authentication and consensus verification in the blockchain.

[0050] In this embodiment, the system parses metadata based on document type as identifying information. When categorizing documents into text, image, and table documents, text documents use the file header to obtain information such as the document title, author, and creation time as identifying information. Image documents use image metadata standards to extract information such as the shooting device, shooting time, and resolution as identifying information. Table documents use document properties or a data dictionary to obtain information such as the table name, column name, and data source as identifying information.

[0051] The extracted metadata is structured into key-value pairs using a lightweight data exchange format (JSON, JavaScript Object Notation); a 256-bit random symmetric key is generated, the document content is split into 128-bit blocks, and each block of data is encrypted using a cipher block chaining mode combined with a randomly generated 128-bit initialization vector to obtain the encrypted document content. An asymmetric public-private key pair is generated, and the public key is used to encrypt the symmetric key to obtain the encrypted symmetric key. The encrypted document content is subjected to a 256-bit secure hash operation to obtain the encrypted data features.

[0052] The identification information and encrypted data features are packaged into transaction data, signed with the user's private key, and sent to the blockchain network through the blockchain platform's software development kit (SDK). After verification by the consensus mechanism, it is stored in the blockchain and the storage timestamp is recorded.

[0053] Reference Figure 3 The third embodiment of the blockchain-based document security access method in the embodiment of the present invention includes:

[0054] S121. Generate a symmetric key in advance, and encrypt the document content in blocks using an encryption algorithm based on the symmetric key to obtain encrypted document content;

[0055] S122. Pre-generate an asymmetric public-private key pair, and encrypt the symmetric key using an asymmetric encryption algorithm based on the public key in the asymmetric public-private key pair to obtain an encrypted symmetric key;

[0056] S123: Integrate the encrypted document content and the encrypted symmetric key to obtain encrypted data.

[0057] In this embodiment, a 256-bit random symmetric key is pre-generated, and the document content is encrypted in blocks of 128 bits using the Advanced Encryption Standard algorithm based on the symmetric key. A cipher block chaining mode is used in combination with a random initialization vector, and each data block is first XORed with the previous encrypted block, and then encrypted using the symmetric key to obtain the encrypted document content. An asymmetric public-private key pair is pre-generated, and the symmetric key is encrypted using an asymmetric encryption algorithm based on the public key to obtain an encrypted symmetric key. The encrypted document content and the encrypted symmetric key are integrated to obtain encrypted data.

[0058] It should be understood that the length of the generated random symmetric key can be selected as 128 bits, 192 bits or 256 bits according to the requirements of the Advanced Encryption Standard algorithm, which is used to encrypt the document content. The block size of the Advanced Encryption Standard algorithm is fixed at 128 bits, so the document content needs to be divided into blocks of 128-bit blocks; the randomly generated initialization vector is a 128-bit byte sequence with the same block size. When cipher block chaining mode is used for encryption, the first data block is first XORed with the randomly generated 128-bit initialization vector, and then encrypted using the symmetric key. Each subsequent data block It first performs an XOR operation with the previous encrypted block, and then uses the symmetric key to encrypt. In this way, the encryption result of each data block depends on the encryption state of the previous block. Even the "same plaintext block" will generate different ciphertext blocks, thereby enhancing the encryption security. The random symmetric key determines the encryption key rule, and the randomly generated 128-bit initialization vector ensures that the initial state of each data block encryption is unique. The 128-bit block data is the basic unit of encryption processing. The combination of the randomly generated symmetric key, the randomly generated initialization vector, and the 128-bit block data realizes the secure block encryption of the document content.

[0059] "Identical plaintext blocks" refer to data blocks with exactly the same content in a document, such as repeated character sequences. Through the cipher block chaining mode, each plaintext block needs to be XORed with the previous encrypted block and then encrypted with a symmetric key. This allows the same plaintext block to generate different ciphertext blocks due to different XOR objects, thereby improving encryption security.

[0060] Reference Figure 4 The fourth embodiment of the blockchain-based document security access method in the embodiments of the present invention includes:

[0061] S210: Deploy a preset configuration logic on the blockchain, wherein the preset configuration logic is used to clarify the user identity and the permission set corresponding to the user identity;

[0062] S220. Based on the preset configuration logic, different user identities and their operation permissions for the document are set to obtain an access permission configuration policy including identity authentication rules and operation permission verification rules. The operation permissions include reading, modifying, deleting and restoring.

[0063] In this embodiment, a smart contract is deployed on the blockchain as pre-configured logic. This pre-configured logic defines user identities and the corresponding permission sets, creating a user identity table. Each identity is assigned different access rights. For example, administrators have full read, modify, delete, and restore permissions; editors are allowed to read and modify documents but not delete them; and viewers are only allowed to read documents. Based on this pre-configured logic, different user identities and their respective document operation permissions are set, resulting in an access rights configuration policy that includes identity authentication rules and operation permission verification rules. Operation permissions include read, modify, delete, and restore. Simultaneously, this permission configuration information is stored on the blockchain as key-value pairs.

[0064] For example, user Zhang San's identity is "User ID001", which is set as an administrator and granted a complete set of operation permissions; user Li Si's identity is "User ID002", which is set as an editor and granted read and modify permissions; user Wang Wu's identity is "User ID003", which is set as a viewer and granted only read permissions. When a user initiates an operation request for a document, the access permission configuration policy will read the corresponding permission configuration information from the blockchain based on the user's identity and perform permission verification. For example, if user Li Si (editor) initiates a request to modify a document, the access permission configuration policy will verify whether its permission set contains the "modify" permission. After verification, the operation will be allowed and the operation log will be recorded in the blockchain; if Li Si initiates a request to delete a document, the access permission configuration policy will verify that its permission set does not contain the "delete" permission, reject the operation and record the rejection log.

[0065] Reference Figure 5 The fifth embodiment of the blockchain-based document security access method in the embodiment of the present invention includes:

[0066] S310: When receiving a user access request, obtain the user's identity information;

[0067] S320: Authenticate the identity information based on the identity authentication rules included in the access permission configuration policy to obtain identity authentication information;

[0068] S330: When the identity authentication information indicates that the identity authentication is passed, the identity identification information is subjected to permission confirmation according to the operation permission verification rules included in the access permission configuration policy to obtain permission confirmation information;

[0069] S340. After obtaining the identity authentication information and permission confirmation information, the user is allowed to perform operations with corresponding permissions;

[0070] S350: Storing the identity information, the authentication information, and the authority confirmation information in the blockchain.

[0071] In this embodiment, when a user access request is received, the user's blockchain address, digital certificate, or a hash value of their username and password is obtained as identification information. For example, if the user initiates the request through a blockchain wallet, their blockchain address is obtained as identification; if the user accesses the system through a client application, their digital certificate is obtained; if the user accesses the system through a webpage, the hash value of their username and password is obtained. For example, if user Zhang San accesses the system through a blockchain wallet, their blockchain address is "Wallet Address 123456"; if user Li Si accesses the system through a client application, their digital certificate contains information such as the issuing authority "Security Certification Center" and the certificate serial number "Certificate Number 789012"; if user Wang Wu logs in through a webpage, enters his username "Wang Wu" and password, and the system hashes the password to obtain the hash value "Hash Value 345678."

[0072] Based on the authentication rules in the access rights configuration policy, the digital certificate is verified for its issuing authority, validity period, signature, and other aspects. The user name and password are compared with the encrypted information hash value stored on the blockchain to obtain authentication information. For example, for a digital certificate, the system first verifies whether its issuing authority is a trusted certification center, such as checking whether the issuing authority of Li Si's digital certificate is a "Security Certification Center"; then verifies the certificate's validity period, determining whether the current time is within the certificate's valid start and end dates; and finally verifies whether the certificate's signature is valid by comparing it with the public key of the certification center. For the hash value of the username and password, the system reads the user's pre-stored encrypted information hash value from the blockchain. For example, Wang Wu's pre-stored hash value is "hash value 345678" and compares it with the currently calculated hash value. If they are consistent, the authentication is successful.

[0073] When the authentication information indicates that the authentication is successful, the permission set corresponding to the user identity is queried according to the operation permission verification rules in the access permission configuration policy to determine whether the requested operation permission is granted, and permission confirmation information is obtained. For example, Zhang San's blockchain address is associated with the administrator identity, and its permission set is "read, modify, delete, and restore"; Li Si's digital certificate is associated with the editor identity, and its permission set is "read, modify"; Wang Wu's username is associated with the viewer identity, and its permission set is "read". The system determines whether the operation permission requested by the user is included in its permission set. For example, if Zhang San requests to delete a document, the system queries its permission set to include the "delete" permission and obtains permission confirmation information indicating that the operation is allowed; if Li Si requests to modify a document, its permission set includes the "modify" permission and the confirmation information indicates that the operation is allowed; if Li Si requests to delete a document, its permission set does not include the "delete" permission and the confirmation information indicates that the operation is denied.

[0074] After obtaining authentication information and permission confirmation, the user is allowed to perform the corresponding permission operation; this information is stored on the blockchain. For example, if Zhang San successfully deletes a document, the system records the operation log; if Li Si successfully modifies a document, the system updates the document content and records the modification log; if Wang Wu successfully reads a document, the system records the access log. After the operation is completed, the system stores the user's identity information, authentication information, and permission confirmation information on the blockchain in the form of a transaction. For example, information such as "Time: 3:00 PM, May 30, 2025, User: Wallet Address 123456, Operation: Delete Document, Permission: Allowed, Result: Success" may be recorded to ensure that all operations are traceable and cannot be tampered with.

[0075] Reference Figure 6 The sixth embodiment of the blockchain-based document security access method in the embodiments of the present invention includes:

[0076] S410: When receiving a user data recovery request, determining whether a data recovery operation can be performed based on the authority confirmation information;

[0077] S420: When a data recovery operation is executable, obtain identification information associated with the document to be recovered from the blockchain, and obtain the encrypted data characteristics, the encrypted symmetric key, the asymmetric public-private key pair, and the encrypted document content of the document to be recovered based on the identification information;

[0078] S430. Decrypt the encrypted symmetric key using the private key in the asymmetric public-private key pair to obtain a decrypted symmetric key.

[0079] S440: Decrypt the encrypted document content using the decrypted symmetric key to obtain the decrypted document content;

[0080] S450: Perform a hash operation on the decrypted document content to obtain a first encrypted data feature, and compare and verify the first encrypted data feature with the encrypted data feature;

[0081] S460: If the values ​​of the first encrypted data feature and the encrypted data feature are consistent, the data recovery operation is completed.

[0082] It's important to understand that traditional storage methods have limitations when it comes to recovery. When a document is damaged or lost, the recovery process is complex and may not guarantee complete data recovery. To overcome these issues, this embodiment uses identifying information to locate the stored data on the chain and perform decryption and comparison operations when a document needs to be restored due to accidental deletion or damage.

[0083] In this embodiment, when the system receives a data recovery request from a user, it first determines the user's permissions based on the permission confirmation information. For example, user Zhang San (administrator identity) initiates a recovery request for the "Financial Report" document. The access permission configuration policy queries its permission set and contains the "Restore" permission, allowing the recovery operation to be performed. The system obtains the identification information associated with the "Financial Report" document from the blockchain. The identification information includes the document's unique identifier "Document ID 123". Based on the document's unique identifier "Document ID 123", the encrypted data feature "Hash value 456789" of the "Financial Report" document, the encrypted symmetric encryption key "Encryption key 789", the private key "Private key 101" in the asymmetric encryption public-private key pair, and the encrypted document content "Ciphertext content 123" are obtained.

[0084] The encrypted symmetric encryption key "Encryption Key 789" is decrypted using the private key "Private Key 101" from the asymmetric public-private key pair. The decrypted symmetric encryption key "Symmetric Key 456" is then obtained through the inverse operation of the asymmetric encryption algorithm. The decrypted symmetric encryption key "Symmetric Key 456" is then used to decrypt the encrypted document content "Ciphertext Content 123." It should be noted that due to the cipher block chaining mode used for encryption, decryption requires the inverse of the encryption process, using the initial vector "Vector 789," to decrypt the document block by block, yielding the decrypted document content, such as "Original Content: Financial Report Data..."

[0085] A 256-bit secure hash operation is performed on the decrypted document content, resulting in the first encrypted data signature, "Hash value 456789." This first encrypted data signature, "Hash value 456789," is then compared bit by bit with the encrypted data signature, "Hash value 456789," stored on the blockchain. Upon comparison, the two hash values ​​are identical, confirming the document's integrity and successful recovery. The system then returns the recovered "Financial Report" document to user Zhang San and records the recovery operation log: "Time: 4:00 PM, May 30, 2025, User: Zhang San, Operation: Restore Document, Result: Success," completing the data recovery operation.

[0086] Reference Figure 7 The seventh embodiment of the blockchain-based document security access method in the embodiments of the present invention includes:

[0087] S510: When receiving a user integrity verification request, determine whether the integrity verification operation can be performed based on the authority confirmation information;

[0088] S520: When an integrity verification operation can be performed, obtain identification information associated with the document to be verified from the blockchain, and obtain encrypted data features of the document to be verified based on the identification information;

[0089] S530: Perform a hash operation on the content of the document to be verified to obtain a second encrypted data feature, and compare and verify the second encrypted data feature with the encrypted data feature;

[0090] S540: If the values ​​of the second encrypted data feature and the encrypted data feature are consistent, the integrity verification operation is completed.

[0091] It's important to understand that traditional storage methods have shortcomings in verifying data integrity, often lacking reliable means and making it difficult to accurately determine in real time whether a document has been tampered with. These issues seriously impact the security and reliability of electronic document storage. To overcome these issues, this embodiment performs regular integrity checks without decrypting the document. Instead, the system directly hashes the current version of the document and compares it with the on-chain record, quickly determining document integrity. If a hash value inconsistency is detected, an early warning mechanism is triggered.

[0092] In this embodiment, when the system receives a user's integrity verification request, it also determines the user's permissions based on the permission confirmation information. For example, user Li Si (editor) initiates an integrity verification request for the "Technical Proposal" document. The system queries its permission set and finds that it includes the "Read" permission, allowing the verification operation to be performed. It should be understood that integrity verification operations are allowed for administrators, editors, and viewers, but not for temporary users without explicit permissions or unauthorized users. The system obtains the identifying information associated with the "Technical Proposal" document from the blockchain, such as the document's unique identifier "Document ID 456." Based on the document's unique identifier "Document ID 456," it obtains the encrypted data feature "Hash Value 789012" of the "Technical Proposal" document.

[0093] A 256-bit secure hash operation is performed on the contents of the "Technical Proposal" document, resulting in a second encrypted data signature, "Hash value 789012." This second encrypted data signature, "Hash value 789012," is then compared bit by bit with the encrypted data signature, "Hash value 789012," pre-stored on the blockchain. Upon comparison, the two hash values ​​are identical, confirming the document's integrity and integrity, and that it has not been tampered with. The system returns the verification result, "Document 'Technical Proposal' Document Integrity Verification Passed," to user Li Si, and records the verification operation log, "Time: 5:00 PM, May 30, 2025, User: Li Si, Operation: Verify Document Integrity, Result: Passed."

[0094] If the comparison reveals a discrepancy in the hash values, for example, when user Wang Wu (viewer identity) verifies the "Product Manual" document, the calculated hash value is "hash value 345678", while the pre-stored hash value on the blockchain is "hash value 901234", the system confirms that the document content is incomplete or has been tampered with, and immediately triggers the exception handling mechanism. The system marks the document as "suspected tampering", notifies the administrator, and records a detailed log: "Time: 18:00, May 30, 2025, User: Wang Wu, Operation: Verify document integrity, Result: Failed, suspected tampering", while retaining both hash values ​​for auditing purposes.

[0095] It should be noted that the hash value can be thought of as a kind of "digital fingerprint." If a document is damaged or lost, the encrypted data and hash value in the blockchain need to be decrypted and restored to the original content, and then checked to see if it is the same as the original (comparing the hash value). After the document is modified normally, the new version information (modified content, modification time) is recorded and compared with the hash value to ensure that the modified document has not been maliciously tampered with (even if it is not damaged, it is still necessary to check whether it has been illegally modified). Therefore, it is only necessary to compare the encrypted "digital fingerprint" (hash value) with the "digital fingerprint" stored in the blockchain to see if they are consistent to determine whether the document data has been tampered with.

[0096] The above describes the document security access method based on blockchain in the embodiment of the present invention. The following describes the document security access device based on blockchain in the embodiment of the present invention. Figure 8 In one embodiment of the present invention, a device for secure document access based on blockchain includes:

[0097] Storage module 10, used to store the identification information and encrypted data features of the document in the blockchain;

[0098] A setting module 20, configured to set the access permission configuration policy of the document through the preset configuration logic of the blockchain;

[0099] The verification module 30 is used to obtain the user's identity information when receiving a user access request, perform identity and authority verification on the identity information based on the access permission configuration policy, and allow access after passing the verification, and store the verification-related interaction information in the blockchain.

[0100] In this embodiment, the security and reliability of document storage are improved by utilizing the decentralization, immutability and transparency characteristics of blockchain.

[0101] In this embodiment, the storage module 10 includes:

[0102] An extraction unit 11 is used to extract metadata of a document as identification information, wherein the metadata includes document title data, creation time data, and author information data;

[0103] The encryption unit 12 is configured to encrypt the document content of the document to generate encrypted data, and perform a hash operation on the encrypted data to obtain encrypted data features;

[0104] The integration unit 13 is used to package the identification information and the encrypted data features into transaction data, perform security authentication and consensus verification on the transaction data, and store the transaction data that has passed security authentication and consensus verification in the blockchain.

[0105] In this embodiment, the encryption unit 12 is specifically used to pre-generate a symmetric key, and based on the symmetric key and using an encryption algorithm, the document content of the document is encrypted in blocks to obtain encrypted document content; pre-generate an asymmetric public-private key pair, and based on the public key in the asymmetric public-private key pair, use an asymmetric encryption algorithm to encrypt the symmetric key to obtain an encrypted symmetric key; after integrating the encrypted document content and the encrypted symmetric key, encrypted data is obtained.

[0106] In this embodiment, the setting module 20 includes:

[0107] A deployment unit 21 is configured to deploy a preset configuration logic on the blockchain, wherein the preset configuration logic is used to specify a user identity and a set of permissions corresponding to the user identity;

[0108] The setting unit 22 is used to set different user identities and the operation permissions of different user identities for the document based on the preset configuration logic, and obtain an access permission configuration policy including identity authentication rules and operation permission verification rules. The operation permissions include reading, modifying, deleting and restoring.

[0109] In this embodiment, the verification module 30 includes:

[0110] The first acquiring unit 31 is configured to acquire the user's identity information when receiving a user access request;

[0111] The judgment unit 32 is configured to authenticate the identity information based on the authentication rules included in the access permission configuration policy to obtain authentication information; when the authentication information indicates that the identity information has been authenticated, perform permission confirmation on the identity information according to the operation permission verification rules included in the access permission configuration policy to obtain permission confirmation information;

[0112] The permission unit 33 is used to allow the user to perform corresponding permission operations after obtaining identity authentication information and permission confirmation information;

[0113] The storage unit 34 is used to store the identity information, the authentication information, and the permission confirmation information in the blockchain.

[0114] In this embodiment, the blockchain-based document security access device further includes: a data recovery module 40, and the data recovery module 40 includes:

[0115] The first determination unit 41 is configured to determine whether a data recovery operation can be performed based on the permission confirmation information when a user data recovery request is received;

[0116] A second acquisition unit 42 is configured to, when a data recovery operation is executable, obtain identification information associated with the document to be recovered from the blockchain, and obtain, based on the identification information, the encrypted data characteristics, the encrypted symmetric key, the asymmetric public-private key pair, and the encrypted document content of the document to be recovered;

[0117] The decryption unit 43 is configured to decrypt the encrypted symmetric key using the private key in the asymmetric public-private key pair to obtain a decrypted symmetric key; and decrypt the encrypted document content using the decrypted symmetric key to obtain a decrypted document content.

[0118] The first comparison unit 44 is used to perform a hash operation on the decrypted document content to obtain a first encrypted data feature, and compare and verify the first encrypted data feature with the encrypted data feature; if the values ​​of the first encrypted data feature and the encrypted data feature are consistent, the data recovery operation is completed.

[0119] In this embodiment, the blockchain-based document security access device further includes: an integrity verification module 50, and the integrity verification module 50 includes:

[0120] The second judgment unit 51 is configured to, upon receiving a user integrity verification request, determine whether the integrity verification operation can be performed based on the authority confirmation information;

[0121] A third obtaining unit 52 is configured to obtain identification information associated with the document to be verified from the blockchain when the integrity verification operation can be performed, and obtain encrypted data features of the document to be verified based on the identification information;

[0122] The second comparison unit 53 is used to perform a hash operation on the content of the document to be verified to obtain a second encrypted data feature, and compare and verify the second encrypted data feature with the encrypted data feature; if the values ​​of the second encrypted data feature and the encrypted data feature are consistent, the integrity verification operation is completed.

[0123] above Figure 8 and Figure 9 The blockchain-based document security access device in the embodiment of the present invention is described in detail from the perspective of modular functional entities. The blockchain-based document security access device in the embodiment of the present invention is described in detail from the perspective of hardware processing.

[0124] Figure 10Figure 1 is a schematic diagram of the structure of a blockchain-based secure document access device provided by an embodiment of the present invention. This blockchain-based secure document access device 1000 may vary significantly depending on configuration or performance. It may include one or more central processing units (CPUs) 1100 (e.g., one or more processors), memory 1200, and one or more storage media 1300 (e.g., one or more mass storage devices) storing applications 1310 or data 1320. The memory 1200 and storage medium 1300 may be either ephemeral or persistent storage. The program stored in the storage medium 1300 may include one or more modules (not shown), each of which may include a series of instructions for operating on the blockchain-based secure document access device 1000. Furthermore, the processor 1100 may be configured to communicate with the storage medium 1300, executing the series of instructions stored in the storage medium 1300 on the blockchain-based secure document access device 1000.

[0125] The blockchain-based document security access device 1000 may also include one or more power supplies 1400, one or more wired or wireless network interfaces 1500, one or more input and output interfaces 1600, and / or one or more operating systems 1330 such as Windows Server, Mac OS X, Unix, Linux, FreeBSD, etc. It will be understood by those skilled in the art that Figure 10 The device structure shown does not constitute a limitation of the blockchain-based document security access device 1000, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0126] The present invention also provides a computer-readable storage medium, which may be a non-volatile computer-readable storage medium or a volatile computer-readable storage medium. The computer-readable storage medium stores instructions, which, when executed on a computer, cause the computer to execute the steps of a blockchain-based document security access method.

[0127] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0128] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, etc., various media that can store program code.

[0129] As described above, the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that the technical solutions described in the above embodiments can still be modified, or some of the technical features thereof can be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for secure document access based on blockchain, characterized in that: include: Storing the document’s identifying information and encrypted data features in the blockchain; Setting the access permission configuration policy of the document through the preset configuration logic of the blockchain; When a user access request is received, the user's identity information is obtained, and the identity and authority verification of the identity information is performed based on the access permission configuration policy. After passing the verification, access is allowed, and the verification-related interaction information is stored in the blockchain.

2. The method for secure document access based on blockchain according to claim 1, characterized in that: The storing of the document's identifying information and encrypted data features in the blockchain includes: Extracting metadata of the document as identification information, wherein the metadata includes document title data, creation time data, and author information data; Encrypting the document content to generate encrypted data, and performing a hash operation on the encrypted data to obtain encrypted data features; The identification information and encrypted data features are packaged into transaction data, security authentication and consensus verification are performed on the transaction data, and the transaction data that passes security authentication and consensus verification is stored in the blockchain.

3. The method for secure document access based on blockchain according to claim 2, characterized in that: The step of encrypting the document content to generate encrypted data includes: Generate a symmetric key in advance, and encrypt the document content of the document in blocks using an encryption algorithm based on the symmetric key to obtain encrypted document content; Pre-generating an asymmetric public-private key pair, and encrypting the symmetric key using an asymmetric encryption algorithm based on the public key in the asymmetric public-private key pair to obtain an encrypted symmetric key; After integrating the encrypted document content and the encrypted symmetric key, encrypted data is obtained.

4. The method for secure document access based on blockchain according to claim 3 is characterized in that: The step of setting the access permission configuration policy for the document through the preset configuration logic of the blockchain includes: Deploying preset configuration logic on the blockchain, wherein the preset configuration logic is used to clarify the user identity and the permission set corresponding to the user identity; Based on the preset configuration logic, different user identities and their operation permissions for the document are set to obtain an access permission configuration policy including identity authentication rules and operation permission verification rules. The operation permissions include reading, modifying, deleting and restoring.

5. The method for secure document access based on blockchain according to claim 4 is characterized in that: When receiving a user access request, obtaining the user's identity information, performing identity and authority verification on the identity information based on the access permission configuration policy, and allowing access after passing the verification, and storing verification-related interaction information in the blockchain, including: When receiving a user access request, obtain the user's identity information; authenticating the identity information based on the identity authentication rules included in the access permission configuration policy to obtain identity authentication information; When the identity authentication information indicates that the identity authentication is passed, the identity identification information is subjected to permission confirmation according to the operation permission verification rules included in the access permission configuration policy to obtain permission confirmation information; After obtaining identity authentication information and permission confirmation information, the user is allowed to perform operations with corresponding permissions; The identity identification information, the identity verification information, and the authority confirmation information are stored in the blockchain.

6. The method for secure document access based on blockchain according to any one of claims 1 to 5, characterized in that: The method further comprises: When receiving a user data recovery request, determine whether the data recovery operation can be performed based on the permission confirmation information; When a data recovery operation is available, identifying information associated with the document to be recovered is obtained from the blockchain, and based on the identifying information, the encrypted data features, the encrypted symmetric key, the asymmetric public-private key pair, and the encrypted document content of the document to be recovered are obtained; Decrypting the encrypted symmetric key using the private key in the asymmetric public-private key pair to obtain a decrypted symmetric key; Decrypting the encrypted document content using the decrypted symmetric key to obtain the decrypted document content; Performing a hash operation on the decrypted document content to obtain a first encrypted data feature, and comparing and verifying the first encrypted data feature with the encrypted data feature; If the values ​​of the first encrypted data feature and the encrypted data feature are consistent, the data recovery operation is completed.

7. The method for secure document access based on blockchain according to any one of claims 1 to 5, characterized in that: The method further comprises: When receiving a user integrity verification request, determine whether the integrity verification operation can be performed based on the permission confirmation information; When an integrity verification operation is executable, obtaining identification information associated with the document to be verified from the blockchain, and obtaining encrypted data features of the document to be verified based on the identification information; Performing a hash operation on the content of the document to be verified to obtain a second encrypted data feature, and comparing and verifying the second encrypted data feature with the encrypted data feature; If the values ​​of the second encrypted data feature and the encrypted data feature are consistent, the integrity verification operation is completed.

8. A document security access device based on blockchain, characterized in that: include: A storage module, used to store the identification information and encrypted data features of the document in the blockchain; A setting module, configured to set the access permission configuration policy of the document through the preset configuration logic of the blockchain; The verification module is used to obtain the user's identity information when receiving a user access request, perform identity and authority verification on the identity information based on the access permission configuration policy, and allow access after passing the verification, and store the verification-related interaction information in the blockchain.

9. A document security access device based on blockchain, characterized in that: comprising a memory and at least one processor, wherein the memory has computer-readable instructions stored therein; The at least one processor calls the computer-readable instructions in the memory to execute the various steps of the blockchain-based document security access method as described in any one of claims 1 to 7.

10. A computer-readable storage medium having computer-readable instructions stored thereon, characterized in that: When the computer-readable instructions are executed by a processor, the steps of the blockchain-based document security access method as described in any one of claims 1 to 7 are implemented.

Citation Information

Cited By

  • Method and device for controlling cross-subject interaction between digital subjects, equipment and medium

    CN122204507A