Block chain evidence storage system of confidential-level optical disc all-in-one machine

By using data processing based on DICOM and HL7 standards, combined with high-strength encryption algorithms and smart contract technology, the problems of data security and access control in blockchain notarization are solved, achieving high data security and transparent access control, providing a detailed audit trail mechanism, and supporting cross-institutional data sharing.

CN120850307APending Publication Date: 2025-10-28TAICANG NUWA VALLEY DIGITAL TECHNOLOGY CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510698789.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-28
Publication Date
2025-10-28

AI Technical Summary

Technical Problem

Existing blockchain-based evidence storage technologies lack sufficient encryption measures when processing sensitive information, leading to data leaks and tampering, imprecise access management, difficulty in achieving effective access control, and a lack of detailed log records, making it difficult to trace data access history.

Method used

The DICOM and HL7 standards are used to standardize electronic medical records and image data. Multi-layered encrypted data packets are generated by combining AES-256, SHA-256 and RSA encryption algorithms. Access control rules are configured through smart contracts, access logs are recorded to the blockchain, and tamper-proof data records are generated.

Benefits of technology

It achieves high data security and trustworthiness, ensures data integrity and transparent access control, provides a detailed audit trail mechanism, prevents data tampering, and supports cross-organizational data sharing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120850307A_ABST
    Figure CN120850307A_ABST
Patent Text Reader

Abstract

The invention discloses a block chain evidence storage system of a secret-related level optical disc all-in-one machine, which comprises an acquisition module, an encryption module, an authority management module, a data verification module, an audit tracking module, a decryption module and a data sharing module, and is characterized in that the acquisition module is used for acquiring electronic medical records and image data to generate original data; the encryption module is used for encryption processing; the authority management module is used for performing access control rule configuration on the encrypted data and generating a corresponding access credential; the data verification module is used for generating a digital fingerprint for the encrypted data by adopting a hash function and generating a block chain record; the audit tracking module is used for recording log information of all data access behaviors to form an audit track; the decryption module carries out decryption operation by adopting a decryption algorithm and outputs original data; and the data sharing module is used for realizing cross-mechanism data transmission and generating and outputting a shared data packet.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of blockchain evidence storage technology, and in particular to a blockchain evidence storage system for a classified optical disc drive. Background Technology

[0002] Blockchain-based evidence storage technology is a technique based on blockchain principles used to ensure the authenticity and immutability of data. Therefore, how to utilize advanced technologies to improve the intelligence and security of blockchain-based evidence storage has become one of the most pressing issues to be addressed.

[0003] In the field of blockchain-based evidence storage, existing technologies lack sufficient encryption measures to protect sensitive information from unauthorized access and tampering, leading to patient privacy leaks or malicious data modification. Furthermore, existing access control systems struggle to accurately configure access based on user roles, permission levels, and data sensitivity, thus limiting effective access control to specific datasets. Additionally, existing systems often lack detailed and immutable logging capabilities, making it difficult to trace data access history and hindering the detection of potential security threats or abnormal behavior. Summary of the Invention

[0004] The purpose of this invention is to provide a blockchain-based evidence storage system for classified optical disc drives, in order to solve the problems mentioned in the background art.

[0005] To achieve the above-mentioned objectives, this invention provides a blockchain-based evidence storage system for classified optical disc drives, comprising a data acquisition module, an encryption module, an access control module, a data verification module, an audit tracking module, a decryption module, and a data sharing module, wherein:

[0006] The acquisition module is used to acquire and process electronic medical records and image data to generate raw data;

[0007] The encryption module uses a high-strength encryption algorithm to encrypt the original data to obtain encrypted data;

[0008] The permission management module uses smart contract technology to configure access control rules for encrypted data, enabling authenticated users to request access to specific datasets and generate corresponding access credentials.

[0009] The data verification module is used to generate a digital fingerprint from the encrypted data using a hash function, and upload the digital fingerprint and the original data together to the blockchain network to generate a blockchain record.

[0010] The audit trail module is used to record log information of all data access behaviors and save the log information to the blockchain to form an audit trail;

[0011] The decryption module is used to decrypt encrypted data using an optimized decryption algorithm and output the original data when there is a legitimate access request.

[0012] The data sharing module is used to realize cross-organizational data transmission based on the raw data provided by the decryption module, and to generate and output shared data packets.

[0013] Furthermore, the processing procedure of the acquisition module includes:

[0014] The acquired electronic medical records and image data were standardized using the DICOM (Digital Imaging and Communications in Medicine) protocol to obtain preliminary standardized data.

[0015] The preliminary standardized data was converted using the HL7 (Health Information Exchange) standard to obtain the raw data.

[0016] Furthermore, the encryption process of the encryption module includes the following steps:

[0017] Step S101: The original data with timestamp and unique identifier is initially encrypted using the AES-256 encryption algorithm, and the initial encrypted ciphertext is generated using the preset key to obtain the initial encrypted data.

[0018] Step S102: Calculate the hash value of the initial encrypted data using a secure hash algorithm to generate a unique digital fingerprint and obtain the hash value of the initial encrypted data;

[0019] Step S103: The hash value of the initial encrypted data is encrypted a second time using the asymmetric encryption algorithm RSA, and the public key of the receiver is used for encryption to obtain the hash value of the second encryption.

[0020] Step S104: Use data packet encapsulation technology to combine the initial encrypted data with the hash value of the secondary encryption into a complete encrypted data packet;

[0021] Step S105: Randomize the complete encrypted data packet to obtain a randomized encrypted data packet, and set conditions to verify it to obtain the final encrypted data.

[0022] Furthermore, the process of generating corresponding access credentials in the permission management module includes the following steps:

[0023] Step S201: Define the basic framework and functional modules of the smart contract;

[0024] Step S202: Set specific access control rules in the smart contract, and configure user access permissions based on user roles, permission levels, and data sensitivity factors;

[0025] Step S203: The smart contract verifies whether the user's authentication status is valid and checks whether the user's access permissions comply with the preset access control rules.

[0026] Step S204: If the user's authentication status is valid and their access permissions comply with the access control rules, the smart contract generates a unique access credential, which includes an access timestamp, a user identifier, and a dataset identifier.

[0027] Step S205: Associate the generated access credentials with the data access log record and store them on the blockchain.

[0028] Furthermore, the process of generating a blockchain record in the data verification module includes the following steps:

[0029] Step S301: The encrypted data is processed using the SHA-256 hash function to generate a unique digital fingerprint;

[0030] Step S302: Combine the generated digital fingerprint with the relevant information of the original data into a complete data packet;

[0031] Step S303: Add timestamps to data packets using a timestamp service to enhance data credibility;

[0032] Step S304: Upload the complete data packet containing the timestamp to the blockchain network;

[0033] In step S305, nodes in the blockchain network verify the uploaded data packets through a consensus mechanism. When the verification is successful, the data packets are recorded in the blockchain ledger to form a blockchain record.

[0034] Furthermore, the process by which the audit trail module generates the audit trail includes the following steps:

[0035] Step S401: Automatically record relevant information about the request and generate initial log records. The relevant information about the request includes timestamp, user identifier, dataset identifier, and access type.

[0036] Step S402: The initial log record is processed using the SHA-256 hash function to generate a unique digital fingerprint;

[0037] Step S403: Combine the generated log records and their corresponding digital fingerprints into a complete log package;

[0038] Step S404: Use a timestamp service to add timestamps to the log packets to enhance the reliability of log records;

[0039] Step S405: Upload the complete log package containing the timestamp to the blockchain network;

[0040] In step S406, nodes in the blockchain network verify the uploaded log packets through a consensus mechanism. When the verification is successful, the log packets are recorded in the blockchain ledger to form an audit trail.

[0041] Furthermore, the decryption process of the decryption module includes the following steps:

[0042] Step S501: Verify the validity of the user's access credentials to ensure that the user has legitimate access rights;

[0043] Step S502: Using the same AES-256 key and the corresponding RSA private key as the initial encryption, the initial encrypted data in the encrypted data packet is initially decrypted to generate initially decrypted data;

[0044] Step S503: The hash value of the initially decrypted data is calculated using the SHA-256 hash function and compared with the secondary encrypted hash value stored on the blockchain to verify the integrity and authenticity of the data.

[0045] Step S504: If the data integrity verification is successful, the preliminary decrypted data is subjected to randomization padding removal processing, the random padding bytes are removed, the original data structure is restored, and the final decrypted data is generated.

[0046] Step S505: Separate the final decrypted data from the metadata information and extract the original data with timestamps and unique identifiers.

[0047] Furthermore, the process by which the data sharing module generates and outputs shared data packets includes the following steps:

[0048] Step S601: Use data classification technology to perform sensitivity assessment on the raw data provided by the decryption module, and classify the data into categories according to the data sensitivity level;

[0049] Step S602: According to the security policy of the target recipient, the classified data is encrypted to generate encrypted shared data;

[0050] Step S603: Using blockchain anchoring technology, the hash value of the bound data packet is written into the blockchain network to generate an immutable data record;

[0051] Step S604: Generate a temporary access token for the target recipient, which includes a session key, timestamp, and permission scope, and send it to the recipient through a secure channel;

[0052] Step S605: After the target receiver successfully receives and verifies the shared data packet, log information of this cross-institutional data transmission is recorded and uploaded to the blockchain network to form a complete audit trail. The log information includes sender information, receiver information and transmission time.

[0053] Compared with existing technologies, this system has the following advantages:

[0054] 1. By adopting the DICOM protocol to standardize the electronic medical records and image data acquired by medical devices, and then using the HL7 standard for further conversion, the standardization and initial integration of data are achieved. The application of the HL7 standard enables the raw data to more accurately adapt to the data structure requirements of the system, improving the efficiency and accuracy of subsequent data processing.

[0055] 2. The original data is initially encrypted using a high-strength encryption algorithm, and a digital fingerprint is generated using SHA-256. The hash value is then encrypted a second time using the RSA asymmetric encryption algorithm to form a complete encrypted data packet. This packet is then randomized to enhance security. The generation of the digital fingerprint and the uploading of the blockchain record ensure that any attempt to tamper with the data can be detected, greatly improving the credibility of the data.

[0056] 3. By configuring access control rules through smart contract technology, authenticated users can request access to specific datasets and generate corresponding access credentials. These credentials are then linked to data access logs and stored on the blockchain, ensuring that all access behaviors are traceable and increasing the transparency and auditability of operations. Attached Figure Description

[0057] Figure 1 This is a schematic diagram of a blockchain-based evidence storage system for a classified optical disc drive. Detailed Implementation

[0058] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0059] like Figure 1 The diagram shown illustrates the system structure of this invention. This invention provides a blockchain-based evidence storage system for a classified optical disc drive, comprising a data acquisition module, an encryption module, an access control module, a data verification module, an audit tracking module, a decryption module, and a data sharing module.

[0060] The acquisition module is used to acquire electronic medical records and imaging data to obtain raw data. The DICOM protocol is used to standardize the electronic medical records and imaging data acquired by the medical device, resulting in preliminarily standardized data. The HL7 standard is then used to convert the preliminarily standardized data to obtain the original data.

[0061] It should be noted that by adopting the DICOM protocol and HL7 standard to standardize electronic medical records and imaging data, not only is the consistency and compatibility of data formats ensured, but the exchangeability and interoperability of data between different systems are also improved. This lays a solid foundation for subsequent data encryption, access control and audit trails, enabling the entire system to process and manage data from various medical devices more efficiently.

[0062] The encryption module is used to encrypt the original data using a high-strength encryption algorithm, resulting in encrypted data. The processing includes the following steps:

[0063] Step S101: Initially encrypt the original data containing the timestamp and unique identifier using the AES-256 encryption algorithm, generate the initial encrypted ciphertext using a preset key, and obtain the initial encrypted data, expressed as:

[0064] ;

[0065] in, This is the initial ciphertext encrypted using the AES-256 encryption algorithm. For raw data with timestamps and unique identifiers, This is the preset key used for AES-256 encryption.

[0066] Step S102: Using the secure hash algorithm, SHA-256 (256-bit output length), calculate the hash value of the initial encrypted data to generate a unique digital fingerprint, obtaining the hash value of the initial encrypted data. The expression is:

[0067] ;

[0068] in, This is the hash value of the initial encrypted data calculated using the SHA-256 algorithm.

[0069] Step S103: The hash value of the initial encrypted data is obtained by using the asymmetric encryption algorithm RSA. Perform secondary encryption using the recipient's public key to obtain the hash value of the secondary encryption, expressed as:

[0070] ;

[0071] in, The hash value obtained by encrypting using the RSA algorithm. The hash value of the initial encrypted data. This is the recipient's public key.

[0072] Step S104: Use data packet encapsulation technology to encapsulate the initial encrypted data. With the hash value of secondary encryption The complete encrypted data packet can be assembled using the following expression:

[0073] ;

[0074] in, For a complete encrypted data packet, For the initial encrypted data, The hash value is a double-encrypted value. Metadata information including encryption time and sender information. This indicates a data connection operation.

[0075] Step S105, encrypt the complete data packet Randomization is performed to obtain a randomized encrypted data packet. Conditions are then set to verify this packet, resulting in the final encrypted data, expressed as:

[0076] ;

[0077] in, For the finally confirmed encrypted data, For encrypted data packets that have undergone randomization, The check value is calculated using CRC32 cyclic redundancy check. The calculated check value is the expected value. If the calculated check value does not match the expected value, it needs to be re-encrypted until the check is successful.

[0078] It should be noted that the AES-256 encryption algorithm used in this invention, combined with the SHA-256 hash function and RSA asymmetric encryption technology, provides a multi-layered security mechanism. This combination not only protects the confidentiality of the data but also ensures its integrity and authenticity. Furthermore, the application of randomization padding technology and CRC32 checksum further enhances the security of data packets, preventing potential tampering and attacks, and ensuring the security of data throughout its entire lifecycle.

[0079] The access control module uses smart contract technology to configure access control rules for encrypted data, enabling authenticated users to generate corresponding access credentials when requesting access to specific datasets. This includes the following steps:

[0080] Step S201: Define the basic framework and functional modules of the smart contract.

[0081] Step S202: Set specific access control rules in the smart contract, and configure which users can access which specific datasets based on user roles, permission levels, and data sensitivity factors.

[0082] Step S203: When an authenticated user initiates a data access request, the smart contract first verifies whether the user's authentication status is valid, and then checks whether the user's access permissions comply with the preset access control rules, expressed as:

[0083] ;

[0084] ;

[0085] in, For the user's authentication status, For the user who initiated the request, For data access requests;

[0086] Step S204, when the user's authentication status It is valid and its access permissions comply with the access control rules. The smart contract then generates a unique access credential. The access credential includes an access timestamp, a user identifier, and a dataset identifier.

[0087] Step S205: Associate the generated access credentials with the data access log record and store them on the blockchain.

[0088] It should be noted that the application of smart contract technology not only simplifies the configuration process of access control rules, but also provides a highly flexible and transparent permission management system. Access rules set based on factors such as user roles, permission levels, and data sensitivity can be dynamically adjusted to adapt to different application scenarios. At the same time, linking access credentials with log records on the blockchain not only increases the transparency of the system, but also enhances the system's credibility and compliance, which helps to establish a more secure and reliable data access environment.

[0089] The data verification module uses a hash function to generate a digital fingerprint from the encrypted data, and then uploads the digital fingerprint along with the original data to the blockchain network to obtain a blockchain record. This includes the following steps:

[0090] Step S301: Use the SHA-256 hash function to encrypt the data. The process is performed to generate a unique digital fingerprint.

[0091] Step S302: Combine the generated digital fingerprint with the original data. The relevant information is combined into a complete data packet. .

[0092] Step S303: Add a timestamp to the data packet using a timestamp service to enhance data reliability. The expression is:

[0093] ;

[0094] in, The timestamp of the data packet. For timestamp services, A packet containing digital fingerprints and raw data.

[0095] Step S304: Upload the complete data packet containing the timestamp to the blockchain network. By utilizing the immutability of the blockchain, it is ensured that all uploaded data packets and their states can be permanently recorded and traced.

[0096] Step S305: Nodes in the blockchain network verify the uploaded data packets through a consensus mechanism. If verification is successful, the data packet is recorded in the blockchain ledger, forming a blockchain record, expressed as:

[0097] ;

[0098] in, For blockchain records, For consensus mechanism, This is the complete data packet containing timestamps.

[0099] It should be noted that using SHA-256 to generate digital fingerprints and uploading them to the blockchain network along with the original data not only ensures the immutability of the data but also provides strong proof of the data's authenticity and integrity. The introduction of timestamp services further enhances the time dimension attribute of the data, enabling each data packet to be accurately located to a specific point in time, which not only improves the credibility of the data but also facilitates subsequent data auditing and tracking.

[0100] The audit trail module records log information for all data access activities and saves this log information to the blockchain, forming an audit trail. This includes the following steps:

[0101] In step S401, when a user initiates a data access request, the system automatically records the relevant information of the request and generates an initial log record; the relevant information of the request includes timestamp, user identifier, dataset identifier and access type.

[0102] Step S402: Process the initial log records using the SHA-256 hash function to generate a unique digital fingerprint. .

[0103] Step S403: Record the generated log. and its corresponding digital fingerprint The complete log package can be assembled using the following expression:

[0104] ;

[0105] in, In preparation for uploading the log package to the blockchain, For initial log recording, A digital fingerprint for log entries.

[0106] Step S404: Use the timestamp service to add timestamps to the log packets to enhance the reliability of log records.

[0107] Step S405: Upload the complete log package containing timestamps to the blockchain network. By leveraging the immutability of the blockchain, all uploaded log records and their states can be permanently recorded and traced.

[0108] Step S406: Nodes in the blockchain network verify the uploaded log packets through a consensus mechanism. When verification is successful, the log packets are recorded in the blockchain ledger, forming an audit trail. .

[0109] It should be noted that logging all data access behaviors and saving this information on the blockchain to form an audit trail ensures that every data access request is traceable. The application of unique digital fingerprints and timestamp services generated by the SHA-256 hash function greatly enhances the immutability and accuracy of log records. This not only improves the transparency and auditability of the system, but also helps to detect and respond to any possible security threats or abnormal behaviors in a timely manner.

[0110] The decryption module is used to decrypt encrypted data using an optimized decryption algorithm when a legitimate access request is received, outputting the original data. This includes the following steps:

[0111] Step S501: When the system receives a legitimate access request, it verifies whether the user's access credentials are valid to ensure that the user has legitimate access rights.

[0112] Step S502: Using the same AES-256 key and corresponding RSA private key as the initial encryption, perform preliminary decryption of the initial encrypted data in the encrypted data packet to generate preliminary decrypted data, expressed as:

[0113] ;

[0114] in, To initially decrypt the data, For the initial encrypted data, This is the preset key used for AES-256 encryption.

[0115] Step S503: Calculate the hash value of the initially decrypted data using the SHA-256 hash function, and compare it with the secondary encrypted hash value stored on the blockchain to verify the integrity and authenticity of the data. The expression is:

[0116] ;

[0117] ;

[0118] in, To initially decrypt the hash value of the data, To initially decrypt the data, The hash value is a double-encrypted value. This is the RSA private key.

[0119] Step S504: If the data integrity verification is successful, continue to perform randomization padding removal processing on the preliminary decrypted data, remove random padding bytes, restore the original data structure, and generate the final decrypted data.

[0120] Step S505: Separate the final decrypted data from the metadata information and extract the original data with timestamps and unique identifiers.

[0121] It should be noted that during the decryption process, the validity of the user's access credentials is first verified. Then, the same AES-256 key and RSA private key as the initial encryption are used for preliminary decryption. Finally, random padding bytes are removed to restore the original data structure. This method not only ensures the security and accuracy of the decryption process but also guarantees the integrity and authenticity of the data. By comparing the decrypted data with the secondary encryption hash value stored on the blockchain, the authenticity of the decrypted data is further verified, providing legitimate users with a safe and reliable way to obtain the original data.

[0122] The data sharing module is used to achieve cross-organizational data transmission based on the raw data provided by the decryption module, generating and outputting shared data packets. This includes the following steps:

[0123] Step S601: Use data classification technology to perform sensitivity assessment on the raw data provided by the decryption module, and classify the data into categories according to the data sensitivity level.

[0124] Step S602: According to the security policy of the target recipient, the classified data is encrypted to generate encrypted shared data.

[0125] Step S603: Using blockchain anchoring technology, the hash value of the bound data packet is written into the blockchain network to generate an immutable data record.

[0126] Step S604: Generate a temporary access token for the target recipient, which includes a session key, timestamp, and permission scope, and send it to the recipient through a secure channel.

[0127] In step S605, after the target recipient successfully receives and verifies the shared data packet, the system automatically records the log information of this cross-institutional data transmission and uploads the log information to the blockchain network, forming a complete audit trail. The log information includes sender information, receiver information, and transmission time.

[0128] It should be noted that employing data classification technology and encrypting data according to the target recipient's security policy not only meets the security requirements for data transmission between different institutions but also improves the flexibility and efficiency of data sharing. By recording the hash value of the bound data packets through blockchain anchoring technology and generating temporary access tokens for the target recipient, the security of data transmission is guaranteed, and the traceability of the data sharing process is achieved. This approach not only promotes efficient cooperation between institutions but also provides strong support for data privacy protection.

[0129] In summary, this invention standardizes electronic medical records and image data acquired by medical devices using the DICOM protocol, and then further transforms them using the HL7 standard, achieving data standardization and initial integration. The application of the HL7 standard allows the raw data to more accurately adapt to the system's internal data structure requirements, improving the efficiency and accuracy of subsequent data processing. A high-strength encryption algorithm is used for initial encryption of the raw data, and SHA-256 is used to generate a digital fingerprint. The hash value is then encrypted a second time using the RSA asymmetric encryption algorithm, ultimately forming a complete encrypted data packet and randomizing it to enhance security. The generation of the digital fingerprint and the uploading of blockchain records ensure that any attempt to tamper with the data can be detected, greatly improving data credibility. Smart contract technology is used to configure access control rules, enabling authenticated users to request access to specific datasets and generate corresponding access credentials. These credentials are associated with data access logs and stored on the blockchain, ensuring that all access activities are traceable and increasing operational transparency and auditability.

[0130] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. A blockchain-based evidence storage system for a classified optical disc drive, characterized in that, It includes a data acquisition module, an encryption module, an access control module, a data verification module, an audit trail module, a decryption module, and a data sharing module, among which: The acquisition module is used to acquire and process electronic medical records and image data to generate raw data; The encryption module uses a high-strength encryption algorithm to encrypt the original data to obtain encrypted data; The permission management module uses smart contract technology to configure access control rules for encrypted data, enabling authenticated users to request access to specific datasets and generate corresponding access credentials. The data verification module is used to generate a digital fingerprint from the encrypted data using a hash function, and upload the digital fingerprint and the original data together to the blockchain network to generate a blockchain record. The audit trail module is used to record log information of all data access behaviors and save the log information to the blockchain to form an audit trail; The decryption module is used to decrypt encrypted data using an optimized decryption algorithm and output the original data when there is a legitimate access request. The data sharing module is used to realize cross-organizational data transmission based on the raw data provided by the decryption module, and to generate and output shared data packets.

2. The blockchain evidence storage system for a classified optical disc drive according to claim 1, characterized in that, The data acquisition module processing procedure includes: The acquired electronic medical records and image data were standardized using the DICOM protocol to obtain preliminary standardized data. The HL7 standard was used to transform the initially standardized data to obtain the original data.

3. The blockchain evidence storage system for a classified optical disc drive according to claim 1, characterized in that, The encryption process of the encryption module includes the following steps: Step S101: The original data with timestamp and unique identifier is initially encrypted using the AES-256 encryption algorithm, and the initial encrypted ciphertext is generated using the preset key to obtain the initial encrypted data. Step S102: Calculate the hash value of the initial encrypted data using a secure hash algorithm to generate a unique digital fingerprint and obtain the hash value of the initial encrypted data; Step S103: The hash value of the initial encrypted data is encrypted a second time using the asymmetric encryption algorithm RSA, and the public key of the receiver is used for encryption to obtain the hash value of the second encryption. Step S104: Use data packet encapsulation technology to combine the initial encrypted data with the hash value of the secondary encryption into a complete encrypted data packet; Step S105: Randomize the complete encrypted data packet to obtain a randomized encrypted data packet, and set conditions to verify it to obtain the final encrypted data.

4. The blockchain evidence storage system for a classified optical disc drive according to claim 1, characterized in that, The process of generating corresponding access credentials in the permission management module includes the following steps: Step S201: Define the basic framework and functional modules of the smart contract; Step S202: Set specific access control rules in the smart contract, and configure user access permissions based on user roles, permission levels, and data sensitivity factors; Step S203: The smart contract verifies whether the user's authentication status is valid and checks whether the user's access permissions comply with the preset access control rules. Step S204: If the user's authentication status is valid and their access permissions comply with the access control rules, the smart contract generates a unique access credential, which includes an access timestamp, a user identifier, and a dataset identifier. Step S205: Associate the generated access credentials with the data access log record and store them on the blockchain.

5. The blockchain evidence storage system for a classified optical disc drive according to claim 1, characterized in that, The data verification module includes the following steps in generating blockchain records: Step S301: The encrypted data is processed using the SHA-256 hash function to generate a unique digital fingerprint; Step S302: Combine the generated digital fingerprint with the relevant information of the original data into a complete data packet; Step S303: Add timestamps to data packets using a timestamp service to enhance data credibility; Step S304: Upload the complete data packet containing the timestamp to the blockchain network; In step S305, nodes in the blockchain network verify the uploaded data packets through a consensus mechanism. When the verification is successful, the data packets are recorded in the blockchain ledger to form a blockchain record.

6. The blockchain evidence storage system for a classified optical disc drive according to claim 1, characterized in that, The process by which the audit trail module generates the audit trail includes the following steps: Step S401: Automatically record relevant information about the request and generate initial log records. The relevant information about the request includes timestamp, user identifier, dataset identifier, and access type. Step S402: The initial log record is processed using the SHA-256 hash function to generate a unique digital fingerprint; Step S403: Combine the generated log records and their corresponding digital fingerprints into a complete log package; Step S404: Use a timestamp service to add timestamps to the log packets to enhance the reliability of log records; Step S405: Upload the complete log package containing the timestamp to the blockchain network; In step S406, nodes in the blockchain network verify the uploaded log packets through a consensus mechanism. When the verification is successful, the log packets are recorded in the blockchain ledger to form an audit trail.

7. The blockchain evidence storage system for a classified optical disc drive according to claim 1, characterized in that, The decryption module's decryption process includes the following steps: Step S501: Verify the validity of the user's access credentials to ensure that the user has legitimate access rights; Step S502: Using the same AES-256 key and the corresponding RSA private key as the initial encryption, the initial encrypted data in the encrypted data packet is initially decrypted to generate initially decrypted data; Step S503: The hash value of the initially decrypted data is calculated using the SHA-256 hash function and compared with the secondary encrypted hash value stored on the blockchain to verify the integrity and authenticity of the data. Step S504: If the data integrity verification is successful, the preliminary decrypted data is subjected to randomization padding removal processing, the random padding bytes are removed, the original data structure is restored, and the final decrypted data is generated. Step S505: Separate the final decrypted data from the metadata information and extract the original data with timestamps and unique identifiers.

8. The blockchain evidence storage system for a classified optical disc drive according to claim 1, characterized in that, The process by which the data sharing module generates and outputs shared data packets includes the following steps: Step S601: Use data classification technology to perform sensitivity assessment on the raw data provided by the decryption module, and classify the data into categories according to the data sensitivity level; Step S602: According to the security policy of the target recipient, the classified data is encrypted to generate encrypted shared data; Step S603: Using blockchain anchoring technology, the hash value of the bound data packet is written into the blockchain network to generate an immutable data record; Step S604: Generate a temporary access token for the target recipient, which includes a session key, timestamp, and permission scope, and send it to the recipient through a secure channel; Step S605: After the target receiver successfully receives and verifies the shared data packet, log information of this cross-institutional data transmission is recorded and uploaded to the blockchain network to form a complete audit trail. The log information includes sender information, receiver information and transmission time.

Citation Information

Cited By

  • Cross-domain data security sharing method and system

    CN121396658A