Privacy protection method, system and device for block chain network node auditing management
By generating node anonymous credentials and privacy authentication, combined with cryptographic hash values and differential privacy mechanisms, the security and efficiency of blockchain node audit management are improved, the problem of easy leakage of node identity information is solved, GDPR compliance requirements are met, and the risk of collusion and the possibility of data leakage are reduced.
Patent Information
- Application Number
- CN202510817548.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-18
- Publication Date
- 2025-10-17
AI Technical Summary
In the existing blockchain node audit, node identity information is vulnerable to Sybil attacks and identity association analysis, with a high risk of privacy leakage. In addition, existing technologies lack specific specifications for blockchain node privacy management, resulting in node joining delays and increased risk of identity leakage.
By generating anonymous node credentials and performing privacy authentication, using cryptographic hash values and threshold signatures to shard and store sensitive information, adopting verifiable random functions and BLS elliptic curve pairing technology for aggregate signatures, and combining differential privacy mechanisms and ring signature technology for fine-grained access control and reward and punishment management, cross-chain identity authentication and node roaming between heterogeneous networks are achieved.
It improves the security and efficiency of blockchain node audit management, reduces identity-related risks, meets GDPR compliance requirements, ensures real-time binding of node reputation levels and data access rights, and reduces collusion risks and the possibility of data leakage.
Smart Images

Figure CN120805170A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the field of blockchain privacy protection, and particularly relates to a privacy protection method, system and device for blockchain network node audit management. BACKGROUND
[0002] Current blockchain node audit mainly relies on consensus mechanisms such as proof of work (PoW) or proof of stake (PoS), but node identity information is usually stored in plaintext or hash form, which is vulnerable to Sybil attacks and identity association analysis. The segmented blockchain technology proposed by micro cloud holography can reduce the storage burden, but it does not solve the privacy leakage risk in the node audit process. Although the ISO / IEC 27001:2022 standard adds cloud service security controls, it lacks specific specifications for blockchain node privacy management.
[0003] In existing solutions, zero-knowledge proof (ZKP) can achieve anonymous authentication, but the generation of proof takes a long time, resulting in a significant increase in node joining delay; homomorphic encryption supports ciphertext calculation, but key management vulnerabilities may lead to node identity leakage. The trusted execution environment (TEE) hardware has strong dependence and is vulnerable to side-channel attacks, and the patent shows that its consortium chain application needs to pre-store a member list, which weakens the decentralized feature.
[0004] Problems of existing technologies: Existing blockchain storage media mostly use plaintext or simple encrypted node credentials. Patent analysis shows that ciphertext receipt data lacks a dynamic update mechanism and is not deeply coupled with the consensus process. Although the privacy protection patents of Tencent and other enterprises involve blockchain identity authentication, they do not solve the node audit consistency problem in cross-chain scenarios. SUMMARY
[0005] The application provides a privacy protection method, system and device for blockchain network node audit management to solve the problems in the prior art.
[0006] To solve the above technical problems, the application adopts the following technical solutions: A privacy protection method for blockchain network node audit management, comprising the following steps: Generating node anonymous credentials for candidate nodes and performing privacy authentication; Obtaining sensitive information of the candidate nodes after privacy authentication and obtaining a cryptographic hash value through mapping, and storing the cryptographic hash value in distributed key management nodes through a threshold signature scheme, wherein the sensitive information includes physical device fingerprints and IP addresses; Selecting a verification node from the candidate nodes using a verifiable random function, performing aggregated signature on the cryptographic hash value of the verification node, and storing the aggregated signature on a chain for evidence, to obtain a node aggregated signature; wherein the aggregated signature includes signature verification and aggregation, and is implemented by BLS using an elliptic curve pairing technology based on bilinear mapping. The node behavior data of the verification node is calculated by privacy aggregation based on the node aggregation signature, and audit score ciphertext is generated, wherein the node behavior data includes block propagation delay and transaction verification accuracy; The node aggregation signature and the audit score ciphertext are controlled by attribute-based encryption for fine-grained access control, and the node reputation level of the verification node is obtained based on the audit strategy; The adaptive noise is added to the node reputation level by the differential privacy mechanism to obtain the reputation noise level, wherein the noise amount of the adaptive noise is dynamically adjusted by the node network topology density and meets the ε-differential privacy constraint condition; Based on ring signature and stealth address technology, rewards and punishments are given to the corresponding verification node through the reputation noise level to obtain the corresponding reward and punishment record.
[0007] As an implementable manner, the node anonymous credential contains a timestamp constraint, which prevents long-term association attacks by periodic rotation, and realizes cross-chain identity verification by using bilinear, supporting node roaming between heterogeneous blockchain networks.
[0008] As an implementable manner, the node behavior data of the verification node is calculated by privacy aggregation based on the node aggregation signature, and audit score ciphertext is generated, including the following steps: Based on fully homomorphic encryption, the node behavior data is extracted for feature extraction in an encrypted state to obtain node feature data; The federated learning framework is introduced, the node feature data is trained to obtain a lightweight anomaly detection model, and the node feature data is detected by the anomaly detection model; The corresponding node behavior data and node aggregation signature after anomaly detection are used to generate audit score ciphertext and upload to the aggregation server.
[0009] As an implementable manner, the adaptive noise is added to the node reputation level to obtain the reputation noise level, including the following steps: The direct identifier in the node reputation level is added with Laplace noise; The quasi-identifier in the node reputation level is disturbed by the exponential mechanism; A privacy budget dynamic allocation model is established, which queries the node reputation level by the differential privacy mechanism and automatically adjusts the ε value according to the historical query frequency.
[0010] As an implementable manner, it further includes: A quantum security backup channel is deployed, and the NTRU lattice cryptography algorithm is used to encrypt the node behavior data to generate an encrypted audit log; The encrypted audit log is stored by IPFS, and only a content addressing hash is saved on the chain. When accessing the encrypted audit log, a space-time constraint condition needs to be met, wherein the space-time constraint condition includes double-factor authentication of geographical location and time period.
[0011] As an implementable manner, the reward and punishment execution stage combines ring signature and stealth address technology, including the following steps: The reward and punishment proposal is generated by a smart contract, and a threshold number is set. If there are more than the threshold number of verification nodes, the reward and punishment record is obtained after voting by ring signature and taking effect. Before the reward and punishment record is chained, the specific value of the reward and punishment record is hidden by Pedersen commitment, and only the validity proof is disclosed.
[0012] As an implementable manner, it also includes: Built-in cross-chain communication relay, reduce cross-chain verification data volume through adaptive compression algorithm, relay node uses oblivious transfer protocol to forward messages; Set up an emergency fuse mechanism, automatically switch to BFT consensus mode when a witch attack is detected.
[0013] A privacy protection system for blockchain network node audit management, including a privacy authentication module, an information mapping module, an aggregated signature module, an audit scoring module, a node reputation module, a dynamic adjustment module, and a reward and punishment record module; The privacy authentication module generates node anonymous credentials for candidate nodes and performs privacy authentication; The information mapping module obtains the sensitive information of the candidate nodes after privacy authentication and obtains a cryptographic hash value through mapping. The sensitive information includes physical device fingerprints and IP addresses. The cryptographic hash value is stored in distributed key management nodes through a threshold signature scheme; The aggregated signature module selects verification nodes from candidate nodes using a verifiable random function, and stores the cryptographic hash values of the verification nodes after aggregated signature on-chain, to obtain node aggregated signature; wherein the aggregated signature includes signature verification and aggregation, and is realized by BLS using elliptic curve pairing technology based on bilinear mapping; The audit scoring module performs privacy aggregation calculation on the node behavior data of the verification nodes based on the node aggregated signature, generates audit scoring ciphertext, and the node behavior data includes block propagation delay and transaction verification accuracy; The node reputation module performs fine-grained access control on the node aggregated signature and audit scoring ciphertext through attribute-based encryption, and obtains the node reputation level of the verification nodes based on the audit strategy; The dynamic adjustment module adds adaptive noise to the node reputation level using a differential privacy mechanism to obtain a reputation noise level, and the noise amount of the adaptive noise is dynamically adjusted according to the node network topology density and satisfies an ε-differential privacy constraint condition. The reward and punishment recording module rewards and punishes the corresponding verification node through the reputation noise level based on ring signature and stealth address technology to obtain the corresponding reward and punishment record.
[0014] A computer-readable storage medium stores a computer program, and the computer program is executed by a processor to implement the method described below: A node anonymous credential is generated for a candidate node and privacy authentication is performed. Sensitive information of the candidate node after privacy authentication is obtained, and a cryptographic hash value is obtained through mapping and stored in a distributed key management node through a threshold signature scheme, wherein the sensitive information includes a physical device fingerprint and an IP address. A verifiable random function is used to select a verification node from the candidate nodes, and a node aggregation signature is obtained by aggregating and signing the cryptographic hash value of the verification node and then storing it on a chain; wherein the aggregation signature includes signature verification and aggregation, and the elliptic curve pairing technology based on bilinear mapping is realized through BLS. Based on the node aggregation signature, the node behavior data of the verification node is privacy-aggregated to generate an audit score ciphertext, and the node behavior data includes block propagation delay and transaction verification accuracy. The node aggregation signature and the audit score ciphertext are subjected to fine-grained access control through attribute-based encryption, and the node reputation level of the verification node is obtained based on an audit strategy. The differential privacy mechanism is used to add adaptive noise to the node reputation level to obtain a reputation noise level, and the noise amount of the adaptive noise is dynamically adjusted according to the node network topology density and satisfies an ε-differential privacy constraint condition. Based on ring signature and stealth address technology, the corresponding verification node is rewarded and punished through the reputation noise level to obtain the corresponding reward and punishment record.
[0015] A privacy protection device for blockchain network node audit management, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the processor implements the method described below when executing the computer program: A node anonymous credential is generated for a candidate node and privacy authentication is performed. Sensitive information of the candidate node after privacy authentication is obtained, and a cryptographic hash value is obtained through mapping and stored in a distributed key management node through a threshold signature scheme, wherein the sensitive information includes a physical device fingerprint and an IP address. The verifiable random function is used to select a verification node from the candidate nodes, and the cryptographic hash value of the verification node is aggregated and signed and then chained and stored for evidence to obtain a node aggregated signature; wherein the aggregated signature includes signature verification and aggregation, and the elliptic curve pairing technology based on bilinear mapping is realized by BLS; The node behavior data of the verification node is calculated by privacy aggregation based on the node aggregated signature to generate an audit score ciphertext, and the node behavior data includes block propagation delay and transaction verification accuracy; The node aggregated signature and the audit score ciphertext are controlled in a fine-grained manner by attribute-based encryption, and the node reputation level of the verification node is obtained based on an audit strategy; The adaptive noise is added to the node reputation level by using the differential privacy mechanism to obtain a reputation noise level, and the noise amount of the adaptive noise is dynamically adjusted by the node network topology density and satisfies the epsilon-differential privacy constraint condition; Based on ring signature and stealth address technology, the corresponding verification node is rewarded or punished by the reputation noise level to obtain the corresponding reward and punishment record.
[0016] Compared with the prior art, the application realizes a breakthrough in security and efficiency in the blockchain node audit management by using the above technical solutions and combining multi-dimensional privacy protection technology; the application eliminates the trusted setting link, and sensitive information such as physical device fingerprints is realized after being processed by a hash to be irreversible desensitization; the threshold signature fragmentation storage avoids the risk of single-point leakage, and the node access audit only needs to satisfy the threshold number of fragments to reconstruct the key, which balances security and availability; the verification group election based on BLS signature ensures that the process is unpredictable and verifiable, and the attacker cannot predict the composition of the audit node, which significantly reduces the collusion risk; the hardware-level security guarantee behavior data analysis process is tamper-proof, and the ciphertext aggregation calculation makes the score result available but invisible to the original data; the node reputation level and the data access permission are real-time bound to realize the hierarchical management and control under the principle of "minimum necessary information"; the noise injection mechanism related to the network topology density optimizes the data utility loss while guaranteeing the epsilon-privacy constraint; the application realizes the combination of ring signature and stealth address technology to realize the decoupling of reward and punishment records and real identity, and the supervisory party can trace back through the master key, and the ordinary node can only verify the validity of the transaction. The application reduces the identity association risk compared with the prior art, meets the compliance requirements of GDPR and other regulations, and has significant technical effects. BRIEF DESCRIPTION OF DRAWINGS
[0017] Figure 1 The figure is a flowchart of the method of the application; Figure 2 The figure is a schematic diagram of the system of the application. DETAILED DESCRIPTION
[0018] For the sake of clearly illustrating the present application, making the purpose, technical scheme and advantages of the embodiments of the present application more clear, the technical scheme in the embodiments of the present application is described clearly and completely below with reference to the drawings in the embodiments of the present application, so that the person skilled in the art can implement according to the description. The drawings combined with the specific implementation will be described in detail below.
[0019] Embodiment 1: A privacy protection method for blockchain network node audit management, as shown in Figure 1 , comprising the following steps: S100, generating a node anonymous credential for a candidate node and performing privacy authentication; S200, obtaining sensitive information of the candidate node after privacy authentication and obtaining a cryptographic hash value through mapping, and storing the cryptographic hash value in a distributed key management node through a threshold signature scheme, wherein the sensitive information includes a physical device fingerprint and an IP address; S300, selecting a verification node from the candidate node using a verifiable random function, performing an aggregated signature on the cryptographic hash value of the verification node, and storing the aggregated signature on a chain for evidence, to obtain a node aggregated signature; wherein the aggregated signature includes signature verification and aggregation, and is realized by BLS using an elliptic curve pairing technology based on a bilinear mapping; S400, performing privacy aggregation calculation on node behavior data of the verification node based on the node aggregated signature to generate an audit score ciphertext, wherein the node behavior data includes block propagation delay and transaction verification accuracy; S500, performing fine-grained access control on the node aggregated signature and the audit score ciphertext through attribute-based encryption, and obtaining a node reputation level of the verification node based on an audit strategy; S600, adding adaptive noise to the node reputation level using a differential privacy mechanism to obtain a reputation noise level, wherein the noise amount of the adaptive noise is dynamically adjusted by the node network topology density and satisfies an ε-differential privacy constraint condition; S700, based on ring signature and stealth address technology, rewarding and punishing the corresponding verification node through the reputation noise level to obtain the corresponding reward and punishment record.
[0020] Step 1: In this embodiment, a node anonymous credential is generated through a zero-knowledge proof protocol (zk-STARKs), wherein the generation of the node anonymous credential includes the following steps: Step 1-1: The anonymous credential contains a timestamp constraint, and periodic rotation prevents long-term association attacks; Step 1-2: Cross-chain identity verification is realized using a bilinear pair operation, supporting node roaming between heterogeneous blockchain networks.
[0021] Step 2: Obtain the sensitive information of the candidate nodes after privacy authentication, which includes physical device fingerprints and IP addresses in this embodiment. Map the sensitive information to obtain a cryptographic hash value, and store it in the distributed key management node through a threshold signature scheme.
[0022] Step 3: Construct a dynamic trusted audit group, select verification nodes from the candidate nodes using a verifiable random function, and store the aggregated signature of the cryptographic hash value of the verification nodes on the chain after aggregation signature. The aggregated signature includes signature verification and aggregation, which is realized by BLS (Boneh-Lynn-Shacham) using an elliptic curve pairing technology based on bilinear mapping. Step 4: Deploy a secure multi-party computation (MPC) module in a trusted execution environment (TEE) to perform privacy-preserving aggregation calculation on the behavior data of the verification nodes (including block propagation delay and transaction verification accuracy), and generate audit score ciphertext. The privacy-preserving aggregation calculation includes the following steps: Step 4-1: Design a behavior data preprocessing process based on FHE (fully homomorphic encryption) to extract node feature data in an encrypted state. Step 4-2: Introduce a federated learning framework, train a lightweight anomaly detection model locally on each audit node, and perform anomaly detection on the node feature data using the anomaly detection model. Step 4-3: Generate audit score ciphertext and upload it to the aggregation server by combining the corresponding node behavior data after anomaly detection and the node aggregated signature.
[0023] Step 5: Perform fine-grained access control on the node aggregated signature and audit score ciphertext using attribute-based encryption, and obtain the node reputation level of the verification nodes based on the audit strategy. Different levels of nodes obtain different views of the data. Step 6: Add adaptive noise to the audit results using the differential privacy (DP) mechanism, and dynamically adjust the noise amount according to the node network topology density to meet the ε-differential privacy constraint condition. The ε-differential privacy constraint condition is a mathematical guarantee that makes the sensitivity of the query result of the data set to any single record not exceed the boundary of the exponential function with the natural constant e as the base, thereby strictly limiting the privacy leakage risk under the premise of statistical availability. The adaptive noise added to the audit results further includes the following steps: Step 6-1: Use a hierarchical injection strategy to add Laplace noise to direct identifiers (such as device IDs) and use an exponential mechanism to perturb quasi-identifiers (such as geographic location). random noise generated and added to the data query result by differential privacy mechanism to mathematically limit the influence of a single record on the output (sensitivity ), so as to maintain statistical usability while protecting privacy (controlled by parameter ).
[0024] Step 6-2: Establish a dynamic allocation model of privacy budget, and automatically adjust the value of epsilon according to the historical query frequency.
[0025] Step 7: The reward and punishment execution stage combines ring signature and stealth address technology to decouple the reward and punishment record from the real identity of the node, while ensuring the traceability of the transaction. Stealth address technology is a blockchain privacy protection scheme that generates a unique one-time receiving address for each transaction (derived from the public key of the receiving party used by the sender), ensuring that external observers cannot associate transactions with the real identity of the receiver through on-chain data, thereby achieving strong anonymity of the receiving party.
[0026] Among them, the reward and punishment execution stage combines ring signature and stealth address technology, and further includes the following: Step 7-1: Design a two-stage reward and punishment confirmation mechanism: first, the smart contract generates a reward and punishment proposal, and the proposal takes effect after being voted by more than a threshold number of verification nodes through ring signature; Step 7-2: The specific value of the reward and punishment record is hidden by Pedersen commitment before being recorded on the chain, and only the validity proof is disclosed. The hiding property of Pedersen commitment means that the commitment value C = g v h r (where g, h, g , h are generators, v is the message, r is a random blinding factor) under the discrete logarithm assumption, even if the attacker has unlimited computing power, it is impossible to extract the original message C from v , because its information-theoretic security depends on the randomness of the blinding factor r to completely mask the message.
[0027] Among them, the implementation of the above step scheme further includes the following steps: Deploy a quantum-safe backup channel and use the NTRU lattice cryptography algorithm to encrypt key audit parameters; NTRU lattice cryptography algorithm is a post-quantum public key encryption scheme based on polynomial ring and lattice cryptography shortest vector problem (SVP), which generates key by short polynomial , and uses random polynomialr Confuse plaintext m Implement encryption whose security relies on the quantum-resistant nature of mathematical problems over lattices; Store encrypted audit logs through IPFS, only save content addressing hash on chain, log access needs to meet space-time constraint conditions (such as geographic location + time period two-factor authentication). IPFS storage is a decentralized distributed file storage system based on peer-to-peer (P2P) network, through content addressing (file hash value as unique identifier CID) instead of traditional location addressing (such as URL), the file is divided into encrypted data blocks and stored in global nodes, realizing data tamper resistance, efficient retrieval and permanent preservation, while avoiding the risk of single point failure of centralized server.
[0028] Embodiment 2: A privacy protection system for audit management of a blockchain network node, comprising a privacy authentication module 100, an information mapping module 200, an aggregated signature module 300, an audit scoring module 400, a node reputation module 500, a dynamic adjustment module 600, and a reward and punishment record module 700; The privacy authentication module 100 generates node anonymous credentials for candidate nodes and performs privacy authentication; The information mapping module 200 obtains the sensitive information of the candidate nodes after privacy authentication and obtains the cryptographic hash value through mapping, and stores it in distributed key management nodes through a threshold signature scheme, wherein the sensitive information includes physical device fingerprint, IP address; The aggregated signature module 300 selects verification nodes from candidate nodes using a verifiable random function, performs aggregated signature on the cryptographic hash value of the verification nodes, and stores it on the chain for evidence, to obtain node aggregated signature; wherein the aggregated signature includes signature verification and aggregation, which is realized by BLS using elliptic curve pairing technology based on bilinear mapping; The audit scoring module 400 performs privacy aggregation calculation on the node behavior data of the verification nodes based on the node aggregated signature, generates audit scoring ciphertext, and the node behavior data includes block propagation delay and transaction verification accuracy; The node reputation module 500 performs fine-grained access control on the node aggregated signature and audit scoring ciphertext through attribute-based encryption, and obtains the node reputation level of the verification nodes based on the audit strategy; The dynamic adjustment module 600 adds adaptive noise to the node reputation level using differential privacy mechanism, obtains reputation noise level, and the noise amount of the adaptive noise is dynamically adjusted by the node network topology density and meets the ε-differential privacy constraint condition; The reward and punishment record module 700 rewards and punishes the corresponding verification nodes through the reputation noise level based on ring signature and secret address technology, and obtains the corresponding reward and punishment record.
[0029] Embodiment 3 A privacy protection device for blockchain network node audit management, which can be a server or a mobile terminal. The computer device includes a processor, a memory, a network interface and a database connected by a system bus. Wherein, the processor of the computer device is used to provide computing and control ability. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database is used for all data of the computer device. The network interface of the computer device is used for communication with the external terminal through the network connection. The computer program is executed by the processor to realize the privacy protection method for blockchain network node audit management: A machine learning model with verifiable security is stored for node behavior pattern analysis; The medium partition is divided into a public area and a secure area, and the access permission of the secure area is controlled by a physical write protection switch.
[0030] For the device embodiment, it is basically similar to the method embodiment, so the description is relatively simple, and the related parts are referred to the part of the method embodiment.
[0031] The above description of the embodiments is for the convenience of the ordinary skilled in the art to understand and apply the present application. Those skilled in the art can easily make various modifications to the above embodiments, and apply the general principles described herein to other embodiments without creative labor. Therefore, the present application is not limited to the above embodiments, and the improvements and modifications of the present application made by those skilled in the art according to the disclosure of the present application should be within the scope of protection of the present application.
Claims
1. A privacy protection method for blockchain network node audit management, characterized in that: The following steps are involved: Generate node anonymous credentials for candidate nodes and perform privacy authentication; Acquire sensitive information of privacy-certified candidate nodes and obtain cryptographic hash values through mapping. The hash values are then sharded and stored in distributed key management nodes using a threshold signature scheme. Sensitive information includes physical device fingerprints and IP addresses. A verifiable random function is used to select a verification node from the candidate nodes. The cryptographic hash value of the verification node is aggregated and signed and then stored on the chain to obtain the node aggregate signature. The aggregate signature includes signature verification and aggregation, which is implemented through BLS using elliptic curve pairing technology based on bilinear mapping. Perform privacy-aware aggregation calculations on the verification node’s behavior data based on the node aggregate signature to generate an audit score ciphertext. The node behavior data includes block propagation delay and transaction verification accuracy. Fine-grained access control is performed on the node aggregation signature and audit score ciphertext through attribute-based encryption, and the node reputation level of the verification node is obtained based on the audit policy; Adaptive noise is added to the node reputation level using a differential privacy mechanism to obtain a reputation noise level. The amount of the adaptive noise is dynamically adjusted according to the node network topology density and satisfies the ε-differential privacy constraint. Based on ring signature and stealth address technology, corresponding verification nodes are rewarded or punished according to the reputation noise level, and corresponding reward and punishment records are obtained.
2. The privacy protection method for blockchain network node audit management according to claim 1 is characterized in that: The node anonymous credentials contain timestamp constraints, prevent long-term association attacks through regular rotation, and use bilinearity to achieve cross-chain identity authentication, supporting node roaming between heterogeneous blockchain networks.
3. The privacy protection method for blockchain network node audit management according to claim 1 is characterized in that: The method of performing privacy-enhanced aggregate calculation on the node behavior data of the verification node based on the node aggregate signature to generate the audit score ciphertext includes the following steps: Based on fully homomorphic encryption, feature extraction is performed on node behavior data in the encrypted state to obtain node feature data; A federated learning framework is introduced to train node feature data to obtain a lightweight anomaly detection model. This model can then be used to detect anomalies in node feature data. After anomaly detection, the corresponding node behavior data and node aggregation signature are used to generate the audit score ciphertext and upload it to the aggregation server.
4. The privacy protection method for blockchain network node audit management according to claim 1 is characterized in that: Adding adaptive noise to the node reputation level to obtain the reputation noise level includes the following steps: Add Laplace noise to the direct identifier in the node reputation level; An exponential mechanism is used to perturb the quasi-identifiers in the node reputation level; A privacy budget dynamic allocation model is established. The privacy budget dynamic allocation model queries the node reputation level through the differential privacy mechanism and automatically adjusts the ε value according to the historical query frequency.
5. The privacy protection method for blockchain network node audit management according to claim 1 is characterized in that: Also includes: Deploy a quantum-safe backup channel, use the NTRU lattice cryptography algorithm to encrypt node behavior data, and generate encrypted audit logs; Encrypted audit logs are stored through IPFS, and only content-addressed hashes are saved on the chain. When accessing the encrypted audit logs, time and space constraints must be met, where the time and space constraints include two-factor authentication of geographic location and time period.
6. The privacy protection method for blockchain network node audit management according to claim 1 is characterized in that: The reward and punishment execution phase combines ring signature and stealth address technology and includes the following steps: Generate reward and punishment proposals through smart contracts and set a threshold number. If there are more than the threshold number of verification nodes, the proposal will take effect after voting through ring signatures, and the reward and punishment records will be obtained; Before the reward and punishment records are uploaded to the chain, the specific values of the reward and punishment records are hidden through Pedersen commitments, and only the proof of validity is made public.
7. The privacy protection method for blockchain network node audit management according to claim 1 is characterized in that: Also includes: Built-in cross-chain communication relay, using adaptive compression algorithm to reduce the amount of cross-chain verification data, and relay nodes using oblivious transfer protocol to forward messages; Set up an emergency circuit breaker mechanism to automatically switch to BFT consensus mode when a Sybil attack is detected.
8. A privacy protection system for blockchain network node audit management, characterized by: Including privacy authentication module, information mapping module, aggregate signature module, review and scoring module, node reputation module, dynamic adjustment module and reward and punishment record module; The privacy authentication module generates node anonymous credentials for candidate nodes and performs privacy authentication; The information mapping module obtains the sensitive information of the candidate node after privacy authentication and obtains a cryptographic hash value through mapping. The cryptographic hash value is stored in a distributed key management node through a threshold signature scheme. The sensitive information includes physical device fingerprints and IP addresses. The aggregate signature module uses a verifiable random function to select a verification node from the candidate nodes, performs an aggregate signature on the cryptographic hash value of the verification node, and then stores it on the chain to obtain a node aggregate signature; wherein, the aggregate signature includes signature verification and aggregation, and is implemented by BLS using elliptic curve pairing technology based on bilinear mapping; The audit scoring module performs privacy-enhanced aggregate calculations on the verification node behavior data based on the node aggregate signature to generate an audit scoring ciphertext. The node behavior data includes block propagation delay and transaction verification accuracy. The node reputation module performs fine-grained access control on the node aggregate signature and audit score ciphertext through attribute-based encryption, and obtains the node reputation level of the verification node based on the audit policy; The dynamic adjustment module uses a differential privacy mechanism to add adaptive noise to the node reputation level to obtain a reputation noise level. The noise amount of the adaptive noise is dynamically adjusted according to the node network topology density and satisfies the ε-differential privacy constraint. The reward and punishment record module, based on ring signature and stealth address technology, rewards and punishes corresponding verification nodes according to the reputation noise level, and obtains corresponding reward and punishment records.
9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
10. A privacy protection device for blockchain network node audit management, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Cited By
Intelligent marketing terminal electric power data communication security protection method and system
CN121000528A
Communication data security encryption transmission method
CN121012695A
Internet of Things edge server data security storage and privacy protection management system
CN122247674A
Blockchain node identity authentication method and system based on multi-stage signature chain
CN122533825A