Decentralized archive data security management method and system based on block chain

The decentralized architecture built by the Fabric consortium chain enables encryption, authorized access, and regulatory records of archival data, solving the problem of easy data tampering under a centralized architecture and improving the transparency, security, and compliance of the archival system.

CN120832682AActive Publication Date: 2025-10-24XINJI INFORMATION TECH GRP CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511327932.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-17
Publication Date
2025-10-24
Estimated Expiration
2045-09-17

AI Technical Summary

Technical Problem

The existing archive system adopts a centralized architecture, and data is easily tampered with and difficult to trace, making it impossible to prove the time of tampering and the person responsible.

Method used

Adopting a decentralized architecture based on the Fabric consortium chain, through the division of labor among archiving nodes, access nodes, approval nodes and supervision nodes, the whole process of encryption of archival data, authorized access and supervision records is digitized and managed on the chain, ensuring data confidentiality and operational auditability.

Benefits of technology

It improves the transparency, security and compliance of the archive system, ensures that every data access and operation can be traced back, prevents tampering and improves the accuracy and security of access control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120832682A_ABST
    Figure CN120832682A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data security, in particular to a decentralized archive data security management method and system based on a block chain, and the method comprises the steps: constructing an archive building node, an access node, an approval node and a supervision node based on a Fabric alliance chain; when the archive data is uploaded, the archive establishing node encrypts the archive data by adopting an encryption algorithm and sends an encryption key to the supervision node, and the encryption key is used for decrypting the archive data; when the file data is requested to be accessed, the access node sends an access request to the approval node; if the access authority exists, the approval node sends a decryption request to the supervision node; and the approval node sends a downloading request to the filing node. The confidentiality of the data is guaranteed through file encryption processing, and even if the data in the database is read, original information cannot be interpreted; and the secret key escrow and operation record uplink of the supervision node ensure that the file use process is audible and tamper-proof.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data security, in particular to a decentralized archive data security management method and system based on a block chain. BACKGROUND

[0002] With the development of e-government, smart personnel and professional credit system, more and more government agencies, enterprises and institutions, colleges and universities and human resource platforms begin to build personnel digital archive systems to collect and manage electronic information such as education, resume, title, assessment, rewards and punishments, and training of individuals. The security, integrity and credibility of these archive data are directly related to the fairness and compliance of key businesses such as cadre management, public servant employment and professional qualification assessment.

[0003] However, the existing archive system generally adopts a centralized architecture, that is, a database and a management background are deployed by a master control platform, and archive data are often stored in a traditional database. If a system administrator or a hacker has the database permission, he or she can directly modify the archive content. Once the archive is modified, it is difficult to restore the original version, and it is also impossible to prove when and who tampered with the information. SUMMARY

[0004] The present application aims to at least solve one of the problems in the prior art or related art.

[0005] To this end, the present application provides a decentralized archive data security management method based on a block chain, which realizes the full-process digitization and on-chain management of archive uploading, encryption, authorized access and supervision records through alliance chain technology and node division. The archive encryption processing guarantees the confidentiality of the data, and even if the data in the database is read, the original information cannot be interpreted. The key management of the supervision node and the on-chain operation record ensure that the archive use process is auditable and tamper-proof. The permission judgment mechanism of the approval node improves the precision and security of access control. At the same time, each operation path is fixed through the block chain account book, ensuring that each data access and operation can be traced back, effectively improving the transparency, security and compliance of the archive system.

[0006] The present application also provides a decentralized archive data security management system based on a block chain, an electronic device and a storage medium comprising the above-mentioned decentralized archive data security management method based on a block chain.

[0007] According to the decentralized archive data security management method based on a block chain of the first aspect of the present application, the method comprises: Based on the Fabric consortium chain, we build archiving nodes, access nodes, approval nodes, and supervision nodes. The archiving nodes are used by archival units to upload archival data, the access nodes are used by requesting units to initiate access requests to the archival data, the approval nodes are used to approve access requests, and the supervision nodes are used to record the operation records of uploading and accessing the archival data. When uploading archive data, the archiving node encrypts the archive data using an encryption algorithm and sends the encryption key to the supervision node, where the encryption key is used to decrypt the archive data; When requesting to access the archive data, the access node sends an access request to the approval node; the approval node determines whether there is access permission; If there is access permission, the approval node sends a decryption request to the supervision node, where the decryption request is used to request the encryption key of the archive data from the supervision node; the approval node sends a download request to the filing node, where the download request is used to request the download address of the archive data from the filing node, where the download address is used to download the archive data; the approval node sends the encryption key and download address of the archive data to the access node.

[0008] Optionally, the steps for uploading archive data include: dividing the archive data into sub-blocks based on a preset segmentation template; Using a hash algorithm to process each of the archive data sub-blocks after segmentation, generating a digest fingerprint corresponding to each archive data sub-block, wherein the digest fingerprint is used to verify whether the data has been tampered with; Encrypting each archive data sub-block using an encryption algorithm and sending the encryption key to the supervision node; Upload the encrypted archive data sub-blocks to the distributed storage system, and record and return the storage address corresponding to each archive data sub-block as the download address; Construct an archive index item and register it in the blockchain account book; the archive index item includes at least the main identifier of the archive, the sub-identifier of each archive data sub-block, the summary fingerprint and the download address.

[0009] Optionally, the step of encrypting each archive data sub-block using an encryption algorithm includes: Based on the confidentiality level of each archive data sub-block, the archiving node uses encryption algorithms of different levels to encrypt each archive data sub-block.

[0010] Optionally, the step of the approval node determining whether access rights are granted includes: The approval node receives an access request from the access node, and the access request at least includes a requester identity, time limit information, a main identifier of a requested archive, and a sub-identifier of an archive data sub-block; An access permission is obtained based on the main identifier of the requested archive and the sub-identifier of the archive data sub-block. It is judged whether the access permission is met based on the requester identity and the time limit information. If yes, it is determined that there is an access permission.

[0011] Optionally, the archiving node, the access node, and the approval node share a first channel; the archiving node and the supervision node share a second channel; and the approval node and the supervision node share a third channel.

[0012] Optionally, when the archive data is uploaded, the supervision node records an operation record of the uploading of the archive data to a blockchain ledger of the second channel.

[0013] Optionally, when the archive data is requested to be accessed, the supervision node records an operation record of the access of the archive data to a blockchain ledger of the third channel.

[0014] According to a second aspect of the present application, a decentralized archive data security management system based on a blockchain includes: A construction module is configured to construct an archiving node, an access node, an approval node, and a supervision node based on a Fabric consortium chain; the archiving node is configured to upload archive data by an archive unit, the access node is configured to initiate an access request for the archive data by a requesting unit, the approval node is configured to approve the access request, and the supervision node is configured to record operation records of the uploading and access of the archive data. An uploading module is configured to, when the archive data is uploaded, encrypt the archive data by the archiving node using an encryption algorithm, and send an encryption key to the supervision node, the encryption key being used to decrypt the archive data. A requesting module is configured to, when the archive data is requested to be accessed, send an access request to the approval node by the access node; and the approval node is configured to judge whether there is an access permission. If there is an access permission, the approval node sends a decryption request to the supervision node, the decryption request being used to request the encryption key of the archive data from the supervision node; the approval node sends a download request to the archiving node, the download request being used to request a download address of the archive data from the archiving node, the download address being used to download the archive data; and the approval node sends the encryption key and the download address of the archive data to the access node.

[0015] An electronic device according to a third aspect of the present application comprises: A processor and a memory, the memory being configured to store a computer program, and the processor being configured to invoke and run the computer program stored in the memory to execute the method of the first aspect.

[0016] A computer readable storage medium according to a fourth aspect of the present application is configured to store a computer program, and the computer program causes a computer to execute the method of the first aspect.

[0017] One of the above technical solutions has at least the following advantages or beneficial effects: A blockchain-based decentralized archive data security management method according to an embodiment of the present application comprises: based on a Fabric consortium chain, building an archiving node, an access node, an approval node, and a supervision node; the archiving node is configured to upload archive data by an archive unit, the access node is configured to initiate an access request for the archive data by a requesting unit, the approval node is configured to approve the access request, and the supervision node is configured to record operation records of uploading and accessing the archive data; when the archive data is uploaded, the archiving node encrypts the archive data using an encryption algorithm and sends an encryption key to the supervision node, the encryption key is used to decrypt the archive data; when the archive data is requested to be accessed, the access node sends an access request to the approval node; the approval node judges whether there is access permission; if there is access permission, the approval node sends a decryption request to the supervision node, the decryption request is used to request the encryption key of the archive data from the supervision node; the approval node sends a download request to the archiving node, the download request is used to request a download address of the archive data from the archiving node, the download address is used to download the archive data; and the approval node sends the encryption key and the download address of the archive data to the access node. Through the consortium chain technology and the node division, the whole process of archive uploading, encryption, authorized access, and supervision record is digitized and managed on the chain. The archive encryption processing guarantees the confidentiality of the data, even if the data in the database is read, the original information cannot be interpreted; the key escrow and operation record on the chain of the supervision node ensure that the archive use process is auditable and tamper-proof; the permission judgment mechanism of the approval node improves the precision and security of access control; at the same time, each operation path is fixed through the blockchain ledger, ensuring that each data access and operation can be traced back, effectively improving the transparency, security, and compliance of the archive system.

[0018] The blockchain-based decentralized archive data security management system, the electronic device and the storage medium provided by the embodiment of the present application are provided with the above-mentioned blockchain-based decentralized archive data security management method. Since the blockchain-based decentralized archive data security management method has the above-mentioned technical effects, the blockchain-based decentralized archive data security management system, the electronic device and the storage medium provided with the blockchain-based decentralized archive data security management method should also have corresponding technical effects. BRIEF DESCRIPTION OF DRAWINGS

[0019] In order to more clearly illustrate the technical solutions of the present application, the drawings needed in the embodiments will be briefly introduced as follows. Obviously, for those skilled in the art, other drawings can also be obtained without creative labor on the basis of these drawings.

[0020] Figure 1 A schematic diagram of a blockchain-based decentralized archive data security management method provided by the embodiment of the present application; Figure 2 A schematic diagram of channel construction in a blockchain-based decentralized archive data security management method provided by the embodiment of the present application; Figure 3 A flowchart of uploading archive data in a blockchain-based decentralized archive data security management method provided by the embodiment of the present application; Figure 4 A schematic diagram of a blockchain-based decentralized archive data security management system provided by the embodiment of the present application is shown; Figure 5 A schematic diagram of an electronic device provided by the embodiment of the present application is shown. DETAILED DESCRIPTION

[0021] The embodiments will be described in detail below, and examples are shown in the drawings. When the following description refers to the drawings, the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The implementation described in the following embodiments does not represent all the implementations consistent with the present application. It is only an example of the system and method consistent with some aspects of the present application as described in detail in the claims.

[0022] The blockchain-based decentralized archive data security management method and system according to some embodiments provided by the present application will be described below with reference to the drawings.

[0023] Referring to Figures 1 to 5 The blockchain-based decentralized archive data security management method provided by the first aspect embodiment of the present application comprises: Based on the Fabric alliance chain, a filing node, an access node, an approval node and a supervision node are constructed; the filing node is used for an archive unit to upload archive data, the access node is used for a requesting unit to initiate an access request for the archive data, the approval node is used for approving the access request, and the supervision node is used for recording operation records of uploading and accessing the archive data; When the archive data is uploaded, the filing node encrypts the archive data by using an encryption algorithm, and sends an encryption key to the supervision node, the encryption key being used for decrypting the archive data; When the archive data is requested to be accessed, the access node sends an access request to the approval node; the approval node judges whether there is an access permission or not; If there is the access permission, the approval node sends a decryption request to the supervision node, the decryption request being used for requesting the encryption key of the archive data from the supervision node; the approval node sends a download request to the filing node, the download request being used for requesting a download address of the archive data from the filing node, the download address being used for downloading the archive data; the approval node sends the encryption key and the download address of the archive data to the access node.

[0024] The Fabric alliance chain is a kind of permissioned blockchain based on the Hyperledger Fabric architecture, the Hyperledger Fabric is an open source blockchain project led by the Linux Foundation, belongs to the flagship project in the Hyperledger alliance, is specially designed for enterprise-level applications, supports pluggable architecture, privacy protection, strong identity management and other characteristics, and its main characteristics are that a blockchain network is composed of multiple trusted organizations, and all participants need to be authorized and authenticated to join and interact. In the Fabric alliance chain, the core components include a Peer node, an Orderer node, an MSP module and a channel (Channel), wherein the Peer node is used for saving an account book and running a chain code (smart contract); the Orderer node is responsible for ordering and packaging transactions into blocks; the MSP module manages organization member identity authentication and permission verification; and the channel mechanism allows different organizations to establish isolated account books for specific businesses, so as to realize data isolation and fine controllable permission.

[0025] In the embodiment, the filing node, the access node, the approval node and the supervision node are respectively deployed as Peer nodes of different organizations to build a distributed archive data management network with multi-channel support. The filing node is the Peer node of the archive unit, i.e., the archive provider, which is responsible for segmenting and encrypting the original archive data, uploading the encrypted data to the distributed storage system, and writing the generated summary fingerprint and index item to the blockchain ledger. The access node is the Peer node of the requesting unit, such as the employing unit, which initiates an archive access request to the approval node. The approval node is the Peer node of the approval department, which determines the access permission according to the chain code logic and, after approval, links the filing node and the supervision node to process the decryption key and the download address. The supervision node is the Peer node of the supervisory agency, which saves the encryption key and records the operation records of archive uploading and access, and writes them to the dedicated channel ledger. Through this distributed deployment, each functional node runs independently in logic, realizing a distributed governance system with clear responsibilities, mutually exclusive permissions and compliant processes on the chain. It effectively utilizes the architectural advantages of the multi-organization and multi-channel Fabric consortium chain to realize on-chain trusted division of labor for archive data uploading, authorization, access and auditing behavior, and improves the data security, permission controllability and supervision visibility of the archive management system in a multi-organization environment, which is significantly superior to traditional centralized or bilateral docking architecture solutions.

[0026] In an illustrative embodiment, as shown in Figure 2 the filing node, the access node and the approval node share a first channel; the filing node and the supervision node share a second channel; and the approval node and the supervision node share a third channel.

[0027] In the Hyperledger Fabric consortium chain architecture, a channel is a core design for supporting private communication and data isolation. Each channel is an independent ledger space, and only Peer nodes that join the channel can read and write transaction data. In the embodiment, the first channel is used to realize the transmission of access requests initiated by the access node and the issuance of data access credentials (such as encryption keys and download addresses) by the approval node; the second channel is used for the filing node to send operation records of uploading behavior to the supervision node when uploading archives, and for the supervision node to record operation records in the blockchain ledger to realize traceability of the archive filing process; and the third channel is used for the approval node to apply for encryption keys for decryption from the supervision node after approval, and for the supervision node to record operation records of archive access to realize a supervision closed loop of the access process.

[0028] In an illustrative embodiment, as shown in Figure 3 the step of uploading the archive data includes: S110: segmenting the archive data into sub-blocks based on a preset segmentation template.

[0029] In the present embodiment, the archiving node logically divides the original archive file according to a system preset segmentation template, such as basic information, education experience, work history, and reward and punishment record. The segmentation template can be dynamically configured according to different archive types, use scenarios, or access requirements to ensure that the sub-block granularity meets the principle of minimum accessible unit. Each sub-block is assigned a unique sub-identifier (Sub-ID) for subsequent index management and permission control. For example, the archive main identifier is A123456, and the segmentation generates sub-blocks: Sub-ID 001: basic information, Sub-ID 002: education experience, Sub-ID 003: work history, Sub-ID 004: reward and punishment record, and the like.

[0030] S120: Each archive data sub-block after segmentation is processed using a hash algorithm to generate a digest fingerprint corresponding to each archive data sub-block, which is used to verify whether the data has been tampered with.

[0031] Each sub-block after segmentation is subjected to hash processing, such as using the SHA-256 algorithm, to generate a fixed-length digest value, referred to as a digest fingerprint. The digest fingerprint is written into the blockchain ledger as a unique identifier of the sub-block content, which is used to verify whether the content has been tampered with during storage and transmission. Hash processing is performed before the original data is encrypted to ensure that data authenticity verification is independent of the ciphertext state. For example: Sub-ID 001 hash value: 0x7f3ae..., Sub-ID 002 hash value: 0x9ad5b...

[0032] S130: Each archive data sub-block is encrypted using an encryption algorithm, and the encryption key is sent to the supervisory node.

[0033] In an illustrative embodiment, the step of encrypting each archive data sub-block using an encryption algorithm includes: Based on the confidentiality level of each archive data sub-block, the archiving node encrypts each archive data sub-block using different levels of encryption algorithms.

[0034] According to the security level of each sub-block, the archiving node uses different encryption algorithms with different strengths, such as AES (AES, Advanced Encryption Standard), ECC (Elliptic Curve Cryptography), etc., to encrypt it. The encryption process should generate independent symmetric keys or use controlled asymmetric key pairs to ensure that the ciphertext of each sub-block cannot be recovered even if it is intercepted. The encryption key is not stored with the archive, but is sent to the regulatory node through the second channel, and is saved by the regulatory node, ensuring that data and keys are stored separately. For example: Sub-ID001 uses AES-128 encryption, and the key is sent to the regulatory node; Sub-ID 002 uses ECC encryption, and the key is sent to the regulatory node for storage.

[0035] S140: Upload the encrypted archive data sub-blocks to the distributed storage system and record the storage addresses corresponding to each archive data sub-block as the download address.

[0036] All encrypted archive data sub-blocks are uploaded to distributed object storage systems such as IPFS, Storj, Filecoin, etc. through the interface. The storage system returns a unique storage address, such as CID (Content Identifier), URL (Uniform Resource Locator), etc., as the download address for the archive data sub-block. The archiving node binds these download addresses with the corresponding sub-identifiers (Sub-ID) and digest fingerprints, which are used to locate the sub-block content in subsequent access requests. Since the data has been encrypted, the download address will not cause security risks even if it is leaked.

[0037] S150: Build an archive index item and register it to the blockchain ledger; the archive index item at least includes the main identifier of the archive, the sub-identifier of each archive data sub-block, the digest fingerprint and the download address.

[0038] The archiving node generates a unified archive index item according to the data structure of each archive, including the archive main identifier (used to uniquely identify the archive), sub-identifier (used to identify the archive data sub-block), digest fingerprint and download address, etc. Form a structured index object. Call the chain code method to write the archive index item to the ledger of the first channel, realizing the on-chain right protection and traceable registration of the archive data. The archive index item serves as the basis for approval and download in the access process and can be called by a smart contract.

[0039] In an illustrative embodiment, the step of determining whether the approval node has access rights includes: The approval node receives an access request from the access node, and the access request at least includes: a requester identity, time limit information, a main identifier of a requested archive, and a sub-identifier of an archive data sub-block; An access permission is obtained based on the main identifier of the requested archive and the sub-identifier of the archive data sub-block. It is judged whether the access permission is met based on the requester identity and the time limit information. If yes, it is determined that there is an access permission.

[0040] In the embodiment, the access node sends an access request to the approval node, and the access request can be encapsulated as a chain code calling parameter or a chain off-line HTTP / SDK calling interface, and at least includes: a requester identity, for example, an organization identifier of an access initiating unit, a public key signature, a logged account, and the like; time limit information, for example, an access start and end time window: 2025-07-01 00:00 to 2025-07-01 23:59; a main identifier of a requested archive, used for determining an archive to be accessed; and a sub-identifier, used for determining an archive data sub-block to be accessed, such as basic information, education experience, work record, and the like.

[0041] The approval node queries a permission rule set related to the main identifier of the requested archive and the sub-identifier of the archive data sub-block, and obtains an access permission, for example, an authorized organization / role set. It is checked whether the requester identity is included in the authorized organization / role set, for example, an HR account can access the basic information, education experience, work record, and the like. An ordinary employee account can only access the basic information sub-block. At the same time, the time limit information in the access request is compared with an effective time period in the permission rule set, and it is considered that there is no permission if the time range is exceeded.

[0042] If all conditions in the access permission are met, the approval node updates the access request state to authorized, and can trigger subsequent key extraction, address issuance, and the like. If any condition is not met, the approval node returns an access rejection state, and sends an access operation record to a supervision node.

[0043] If there is access permission, i.e. the approval node confirms that the identity of the requester, time limit information, etc. meet the permission rules, the approval node will enter the authorized execution phase to call the encryption key and download address, and return to the access node. The approval node sends a decryption request through the third channel, and the decryption request content includes the archive main identifier, sub-identifier, approval voucher, etc. The supervision node extracts the corresponding encryption key from the key record it saves after verifying the legality of the decryption request, and returns it to the approval node, while recording this access operation record to the blockchain ledger of the third channel. The approval node sends a download request to the archiving node through the first channel, and the archiving node extracts the download address of the corresponding encrypted sub-block from the on-chain archive index item after confirming the legality of the download request, and sends it to the approval node. The approval node encapsulates the received encryption key and download address into an access credential and forwards it to the access node through the first channel. The access node downloads the encrypted archive data accordingly and uses the encryption key to complete the decryption operation.

[0044] The embodiment realizes the decoupling of the functions of approval authorization, data address acquisition and key management, prevents any single node from independently completing authorization and data control operations, and improves the security and trust level of the overall system. By having the supervision node independently host the key, the archiving node centrally maintain the index, and the approval node only act as a coordinating intermediary, the compliance and controllability of the permission path are further strengthened. All requests, responses and key calling behaviors are registered in the blockchain ledger, making the entire access chain have pre-controllable, in-process verifiable and post-searchable full-process credibility, meeting the authorized access requirements of archive data under high security requirements.

[0045] In an illustrative embodiment, when the archive data is uploaded, the supervision node records the operation record of the uploading of the archive data to the blockchain ledger of the second channel.

[0046] In the present embodiment, after the archiving node completes the chunk encryption and distributed storage upload of the archive data, it sends the encryption key to the supervision node. The supervision node, as an independent Peer node deployed in the second channel, immediately writes the operation record of this upload behavior into the blockchain ledger of the second channel in the form of on-chain transaction after receiving the encryption key information. The upload operation record at least includes the archive main identifier, sub-identifier, upload agency identifier, upload timestamp, encryption algorithm type, key number and digest fingerprint, etc. The supervision node does not process plaintext archives, only records behavior metadata, and verifies and records through chain code contract, realizing the non-tamperability and traceability of the data upload process.

[0047] By recording the file uploading operation record to the second channel ledger by the supervision node, it can ensure that the filing behavior has non-repudiation and timestamp authority ability. Compared with the traditional system which relies on logs for post-recording, this mechanism realizes uploading and notarization at the same time, ensuring the complete record chain of the file life cycle. At the same time, the supervision node can query the file uploading details at any time through the blockchain ledger, improving the transparency and real-time of supervision and audit, and facilitating the superior authorities and industry organizations to complete compliance review without touching the original data. In addition, this record also constitutes the basis for subsequent file access authorization and key request, providing support for forming a complete traceability chain in the permission approval process.

[0048] In an illustrative embodiment, when requesting access to the file data, the supervision node records an operation record of the access of the file data to the third channel blockchain ledger.

[0049] In this embodiment, the access node initiates a file data access request to the approval node, the approval node submits a decryption request to the supervision node after completing the permission verification and authorization, and the supervision node immediately writes the operation record of the access behavior into the third channel blockchain ledger in the form of on-chain transaction after receiving the decryption request. The access operation record at least includes the file main identifier, the sub-identifier, the access organization ID, the access role, the approval unit identifier, the access time, the authorized time window, the operation type, the request purpose description and the like.

[0050] By recording the access operation record in the third channel by the supervision node, a trusted audit chain of file access behavior can be established without touching the original data. All access processes are automatically chained, preventing access logs from being deleted or modified, greatly improving the compliance and responsibility traceability of the system. At the same time, this mechanism has the ability to identify security risks such as unauthorized access and frequent abnormal calls in real time, providing on-chain behavior analysis basis for regulatory agencies. Since the supervision node only receives operation record information, it meets the compliance regulatory requirements of the minimum available disclosure, and also protects the privacy of the file content, especially suitable for high-sensitivity information environments such as personnel files and government data. This mechanism also forms a closed-loop tracking system with the uploading behavior record, providing strong technical support for transparent supervision and responsibility division of the entire life cycle of the file.

[0051] As shown in Figure 4 The second aspect embodiment of the present application provides a decentralized file data security management system based on blockchain, which comprises: A construction module is used to build a filing node, an access node, an approval node, and a supervision node based on the Fabric consortium chain; the filing node is used for the filing unit to upload the archival data, the access node is used for the requesting unit to initiate an access request for the archival data, the approval node is used to approve the access request, and the supervision node is used to record the operation records of uploading and accessing the archival data; An uploading module, configured to encrypt the archival data using an encryption algorithm at the archival creation node when uploading the archival data, and to send an encryption key to the supervision node, wherein the encryption key is used to decrypt the archival data; A request module, configured to, when requesting access to the archive data, cause the access node to send an access request to the approval node; and the approval node to determine whether there is access authority; If there is access permission, the approval node sends a decryption request to the supervision node, where the decryption request is used to request the encryption key of the archive data from the supervision node; the approval node sends a download request to the filing node, where the download request is used to request the download address of the archive data from the filing node, where the download address is used to download the archive data; the approval node sends the encryption key and download address of the archive data to the access node.

[0052] like Figure 5 As shown, the third embodiment of the present application provides an electronic device, including: A memory and a processor, wherein the memory is used to store a computer program and transmit the program code to the processor. In other words, the processor can call and run the computer program from the memory to implement the method in the embodiment of the present application.

[0053] For example, the processor may be configured to execute the above method embodiments according to instructions in the computer program.

[0054] In some embodiments of the present application, the processor may include but is not limited to: General-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.

[0055] In some embodiments of the present application, the memory includes but is not limited to: The non-volatile memory can be a Read-Only Memory (ROM), a Programmable ROM (PROM), an Erasable PROM (EPROM), an Electrically EPROM (EEPROM), or a flash memory. The volatile memory can be a Random Access Memory (RAM) used as an external cache. By way of example, and not limitation, many forms of RAM are available, such as Static RAM (SRAM), Dynamic RAM (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced SDRAM (ESDRAM), Synch link DRAM (SLDRAM), and Direct Rambus RAM (DR RAM).

[0056] In some embodiments of the present application, the computer program can be divided into one or more modules, which are stored in the memory and executed by the processor to complete the method provided by the present application. The one or more modules can be a series of computer program instruction segments capable of completing a specific function, which are used to describe the execution process of the computer program in the controller.

[0057] The electronic device can further include: The transceiver can be connected to the processor or the memory.

[0058] The processor can control the transceiver to communicate with other devices, specifically, can send data or data to other devices, or receive data or data sent by other devices. The transceiver can include a transmitter and a receiver. The transceiver can further include an antenna, and the number of antennas can be one or more.

[0059] It should be understood that various components in the electronic device are connected through a bus system, wherein the bus system includes a data bus, a power supply bus, a control bus, and a state signal bus in addition to the data bus.

[0060] The fourth aspect of the embodiments of the present application further provides a computer storage medium, which stores a computer program. The computer program is executed by a computer to enable the computer to perform the method of the above method embodiments. Alternatively, one of the embodiments of the present application further provides a computer program product containing instructions. The instructions are executed by a computer to enable the computer to perform the method of the above method embodiments.

[0061] When implemented using software, the embodiments of the present application can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the flow or function according to the embodiments of the present application is wholly or partially generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable apparatus. The computer instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center through a wired (for example, coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (for example, infrared, wireless, microwave, etc.) manner. The computer-readable storage medium can be any available medium accessible by a computer or a data storage device such as a server, data center, etc. integrated with one or more available media sets. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a digital video disc (DVD)), or a semiconductor medium (for example, a solid state disk (SSD)), etc.

[0062] Those of ordinary skill in the art can realize that the modules and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether the functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those of ordinary skill in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0063] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other manners. For example, the described device embodiment is merely illustrative. For example, the division of the modules is only a logical function division. There can be another division manner for the actual implementation, for example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between different modules can be indirect couplings or communication connections through some interfaces, devices or modules, and can be in electrical, mechanical or other forms.

[0064] It should be noted that the terms "first", "second", "third", "fourth", etc. (if any) in the description, claims and above drawings of the present application are used to distinguish similar objects, and do not necessarily indicate a specific order or a chronological sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "comprise" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a list of steps or units is not necessarily limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to such processes, methods, products or devices.

[0065] In the description of the present specification, the description of the terms "one embodiment", "some embodiments", "embodiment", "exemplary embodiment", "example", "specific example" or "some examples" means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In the present specification, the illustrative description of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any appropriate manner in any one or more embodiments or examples. In addition, the person skilled in the art can combine and combine the different embodiments or examples described in the present specification and the features of the different embodiments or examples without contradiction.

[0066] Although the embodiments of the present application have been shown and described above, it should be understood that the above embodiments are exemplary and should not be construed as limiting the present application, and the person skilled in the art can make changes, modifications, replacements and variations to the above embodiments within the scope of the present application.

Claims

1. A blockchain-based decentralized archive data security management method, characterized in that, The application relates to a file management system based on a Fabric alliance chain. The system comprises a file building node, an access node, an approval node and a supervision node. The file building node is used for uploading file data by a file unit, the access node is used for initiating an access request for the file data by a requesting unit, the approval node is used for approving the access request, and the supervision node is used for recording operation records of uploading and accessing the file data. When the file data is uploaded, the file building node encrypts the file data by using an encryption algorithm and sends an encryption key to the supervision node, the encryption key being used for decrypting the file data. When the file data is requested, the access node sends an access request to the approval node. The approval node judges whether there is an access right. If there is an access right, the approval node sends a decryption request to the supervision node, the decryption request being used for requesting the encryption key of the file data from the supervision node. The approval node sends a download request to the file building node, the download request being used for requesting a download address of the file data from the file building node, the download address being used for downloading the file data. The approval node sends the encryption key and the download address of the file data to the access node. 2.The blockchain-based decentralized archive data security management method of claim 1, wherein, The step of uploading the file data comprises the following steps. The file data is divided into sub-blocks based on a preset segmentation template. Each file data sub-block after being divided is processed by using a hash algorithm to generate a digest fingerprint corresponding to each file data sub-block, the digest fingerprint being used for verifying whether the data is tampered. Each file data sub-block is encrypted by using an encryption algorithm, and an encryption key is sent to the supervision node. The encrypted file data sub-blocks are uploaded to a distributed storage system, and a storage address corresponding to each file data sub-block is recorded as a download address. An archive index item is constructed and registered to a block chain ledger, the archive index item at least comprising a main identifier of an archive, a sub-identifier of each file data sub-block, a digest fingerprint and a download address. 3.The blockchain-based decentralized archive data security management method of claim 2, wherein, The step of encrypting each file data sub-block by using an encryption algorithm comprises the following steps. Based on a security level of each file data sub-block, the file building node encrypts each file data sub-block by using different levels of encryption algorithms. 4.The blockchain-based decentralized archive data security management method of claim 2, wherein, The step of judging whether there is an access right by the approval node comprises the following steps. The approval node receives an access request from the access node, the access request at least comprising a requester identity, time limit information, a main identifier of a requested archive and a sub-identifier of a file data sub-block. An access right is obtained based on the main identifier of the requested archive and the sub-identifier of the file data sub-block. Whether the access right is met is judged based on the requester identity and the time limit information. If yes, it is judged that there is an access right. 5.The blockchain-based decentralized archive data security management method of claim 1, wherein, The file building node, the access node and the approval node share a first channel, and the file building node and the supervision node share a second channel. The approval node and the supervision node share a third channel.

6. The blockchain-based decentralized archive data security management method of claim 5, wherein, When the file data is uploaded, the supervision node records an operation record of uploading the file data to a block chain ledger of the second channel. 7.The blockchain-based decentralized archive data security management method of claim 5, wherein, When the access to the archive data is requested, the supervisory node records the operation record of the access of the archive data to the blockchain ledger of the third channel. 8.A blockchain-based decentralized archival data security management system, characterized in that, The method comprises the following steps: a construction module, configured to construct an archiving node, an access node, an approval node and a supervisory node based on a Fabric consortium chain; the archiving node is configured to upload archive data by an archive unit, the access node is configured to initiate an access request for the archive data by a requesting unit, the approval node is configured to approve the access request, and the supervisory node is configured to record the operation record of the uploading and access of the archive data; an uploading module, configured to, when the archive data is uploaded, encrypt the archive data by the archiving node using an encryption algorithm, and send an encryption key to the supervisory node, the encryption key being used to decrypt the archive data; a requesting module, configured to, when the access to the archive data is requested, send an access request to the approval node by the access node; the approval node judges whether there is access permission; if there is access permission, the approval node sends a decryption request to the supervisory node, the decryption request being used to request the encryption key of the archive data from the supervisory node; the approval node sends a download request to the archiving node, the download request being used to request a download address of the archive data from the archiving node, the download address being used to download the archive data; the approval node sends the encryption key and the download address of the archive data to the access node.

9. An electronic device, comprising: The method comprises the following steps: a processor and a memory, the memory being configured to store a computer program, and the processor being configured to call and run the computer program stored in the memory to execute the method of any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, A computer program for storing a computer program, the computer program enabling a computer to execute the method of any one of claims 1-7.

Citation Information

Patent Citations

  • File management method and device based on alliance blockchain

    CN111475836A

  • Case money management method based on block chain

    CN116091189A

  • Data encryption and authorization management method based on Hyperledger Fabric alliance chain

    CN116827653A

  • Block chain data management method and system

    CN119397578A

  • Authentication method and apparatus for blockchain access, and storage medium and electronic apparatus

    WO2019205849A1