Power data privacy sharing method and system based on PUF and block chain
By combining Physically Unclonable Functions (PUFs) and blockchain technology, a power data privacy sharing system was built, which solved the problems of authenticity, privacy and integrity in power data sharing, realized secure sharing and automated management across institutions, and reduced trust risks.
Patent Information
- Application Number
- CN202511873364.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-12
- Publication Date
- 2026-05-15
AI Technical Summary
Existing power data sharing schemes are inadequate in ensuring data authenticity and privacy, and lack a long-term data integrity auditing mechanism, resulting in single-point trust risks and high computational complexity.
By combining Physically Unclonable Functions (PUFs) with blockchain, a power data privacy sharing system is constructed through modules such as device registration and fingerprint generation, data collection and trusted signature, on-chain evidence storage and index mapping, privacy sharing and computational invocation, continuous auditing and consistency verification, and data forgetting and verifiable destruction, to ensure the authenticity, privacy and integrity of data.
It ensures the authenticity and privacy of power data, enables secure sharing and automated management across institutions, guarantees the long-term integrity and compliance of data, and reduces the risks of centralized trust.
Smart Images

Figure CN122053074A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of secure sharing technology for power data, and in particular to a method and system for privacy sharing of power data based on PUF and blockchain. Background Technology
[0002] Currently, research on secure sharing and trusted exchange of power data mainly focuses on blockchain-based data storage and sharing mechanisms, privacy-preserving computation-based data protection methods, and digital signature-based integrity verification technologies. Blockchain-based solutions typically utilize their distributed ledger and immutability to achieve trusted storage and shared access to power data; privacy-preserving computation methods (such as homomorphic encryption, federated learning, and secure multi-party computation) are used to conduct cross-institutional collaborative analysis without exposing the original data; digital signature and encrypted transmission schemes emphasize ensuring communication integrity and tamper resistance along the data transmission link. These solutions, to a certain extent, achieve the goals of "data traceability, encrypted transmission, and controllable access," and represent the mainstream implementation path in the industry.
[0003] However, existing solutions still have several limitations in engineering applications. First, most blockchain sharing mechanisms only achieve logical-level trust and do not guarantee the authenticity and trustworthiness of the data collection devices at the physical layer, making them susceptible to issues such as false terminal reporting or data forgery. Second, while privacy-preserving computation schemes can protect data privacy, their high computational complexity and latency make them difficult to apply in resource-constrained environments such as power edge nodes. Third, blockchain-based evidence storage systems lack long-term data integrity auditing mechanisms and cannot cope with scenarios such as node failure, data expiration, and privacy oversight. Furthermore, most systems still rely on centralized platforms for access control and permission verification, posing a single point of trust risk and violating the original intention of decentralized security and autonomy. Summary of the Invention
[0004] In view of this, this application provides a method and system for sharing electricity data privacy based on PUF and blockchain to solve at least one of the problems mentioned above.
[0005] To achieve the above objectives, this application adopts the following approach:
[0006] According to a first aspect of this application, a power data privacy sharing system based on PUF and blockchain is provided, the system comprising:
[0007] The device registration and fingerprint generation module is configured to enable the power acquisition terminal to generate PUF challenge-response pairs, record the binding relationship between the device DID and the PUF fingerprint in the registration contract, and register it to the blockchain;
[0008] The data acquisition and trusted signature module is configured to acquire power data and use PUF response as a dynamic random source to participate in data signature calculation to generate a signature.
[0009] The on-chain evidence storage and index mapping module is configured to store the hash digest of the data packet containing the signature and power data, as well as the index information pointing to the off-chain distributed storage address on the chain, and to store the power data in an off-chain distributed manner.
[0010] The privacy sharing and computation call module is configured to enable data users to authenticate themselves through smart contracts based on the registered device DID, request access and trigger privacy computation, use the hash digest stored on the chain to verify the integrity of the data, ensure that the data is not tampered with during the sharing process, and realize cross-institutional data sharing and joint analysis.
[0011] The continuous auditing and consistency verification module is configured to periodically perform Merkle tree audits to check whether the data stored on the chain is complete.
[0012] The data forgetting and verifiable destruction module is configured to perform an encrypted deletion operation and record a destruction certificate on the blockchain when the power data reaches its retention period.
[0013] In one embodiment of this application, the data acquisition and trusted signature module is further configured as follows:
[0014] During the data acquisition phase, the PUF response R is calculated based on the PUF challenge C, where R = PUF(C).
[0015] Concatenate the power data D, PUF response R, and timestamp T into message M, where M = D || R || T;
[0016] The signature digest of message M is calculated using SHA256 to generate a signature digest H, where H = SHA256(M);
[0017] Generate a signature Sig = H and form a data packet {D, Sig, T}.
[0018] In one embodiment of this application, the aforementioned privacy sharing and computation invocation module is further configured as follows:
[0019] By using on-chain smart contracts for task allocation, identity verification, and key distribution, we can ensure the credibility of data users and the reasonableness of task allocation.
[0020] This enables data users to collaboratively perform privacy-preserving computations off-chain. The privacy-preserving computation process utilizes homomorphic encryption technology to complete function calculations on power data without exposing the original data.
[0021] The results of privacy-preserving computations are encrypted and then uploaded to the blockchain.
[0022] In one embodiment of this application, the aforementioned continuous auditing and consistency verification module is further configured as follows:
[0023] Calculate the hash value for each storage block under the distributed storage address;
[0024] The calculated hash values are combined in pairs to generate upper-level nodes, until the root hash is calculated;
[0025] Compare the root hashes within the corresponding time periods in adjacent time periods;
[0026] If a difference in the comparison results is detected, the data recovery process will be automatically triggered.
[0027] The audit results and log hashes are uploaded to the blockchain to form permanent evidence.
[0028] In one embodiment of this application, the aforementioned data forgetting and verifiable destruction module is further configured as follows:
[0029] When the power data reaches its retention period, the off-chain storage node performs an encrypted deletion operation on the power data, destroys the corresponding ciphertext, and generates a destruction certificate;
[0030] The destruction certificate and destruction time will be stored on the blockchain as evidence.
[0031] The power data has been permanently deleted by verifying the hash consistency of the destruction proof through a regulatory node.
[0032] In one embodiment of this application, the device registration and fingerprint generation module is further configured as follows:
[0033] In the process of generating PUF challenge-response pairs in the power acquisition terminal, multiple sets of different challenge values are used to generate multiple sets of PUF responses;
[0034] The multiple PUF responses are combined or transformed to generate the final PUF fingerprint, thereby improving the uniqueness and security of the PUF fingerprint.
[0035] In one embodiment of this application, the privacy sharing and computation invocation module is further configured as follows:
[0036] During off-chain collaborative execution of privacy computation, differential privacy technology is used to add noise to the computation results to prevent the original data from being inferred from the computation results.
[0037] According to a second aspect of this application, a method for privacy-sharing electricity data based on PUF and blockchain is provided, the method comprising:
[0038] The power acquisition terminal generates a PUF challenge-response pair, records the binding relationship between the device DID and the PUF fingerprint in the registration contract, and registers it to the blockchain;
[0039] The power acquisition terminal collects power data and uses the PUF response as a dynamic random source to participate in the data signature calculation to generate a signature;
[0040] The power acquisition terminal stores the hash digest of the data packet containing the signature and power data, as well as the index information pointing to the off-chain distributed storage address on the chain, and stores the power data in an off-chain distributed manner.
[0041] Data users authenticate themselves through smart contracts based on the registered device DID, request access and trigger privacy calculations, and use hash digests stored on the chain to verify the integrity of the data, ensuring that the data is not tampered with during the sharing process, thus enabling cross-institutional data sharing and joint analysis.
[0042] The data auditing unit periodically performs Merkle tree audits to check the integrity of the data stored on the chain.
[0043] When the power data reaches its retention period, the data destruction unit performs an encrypted deletion operation and records the destruction certificate on the blockchain.
[0044] In one embodiment of this application, the power acquisition terminal collects power data and uses the PUF response as a dynamic random source to participate in data signature calculation to generate a signature. This further includes: during the data acquisition phase, the power acquisition terminal calculates the PUF response R based on the PUF challenge C, R = PUF(C); concatenates the power data D, the PUF response R, and the timestamp T into a message M, M = D || R || T; performs a signature digest calculation on the message M using SHA256 to generate a signature digest H, H = SHA256(M); generates a signature Sig = H, and forms a data packet {D, Sig, T}.
[0045] In one embodiment of this application, the data user authenticates themselves through a smart contract based on the registered device DID, requests access, and triggers privacy computation. This includes: assigning tasks, authenticating the user, and distributing keys through an on-chain smart contract to ensure the data user's identity is trustworthy and the task assignment is reasonable; enabling each data user to collaboratively perform privacy computation off-chain, wherein the privacy computation process utilizes homomorphic encryption technology to complete the function calculation of the power data without exposing the original data; and uploading the privacy computation result to the blockchain after encryption.
[0046] In one embodiment of this application, the data auditing unit periodically performs Merkle tree audits to detect whether the data stored on the chain is complete. This includes: the data auditing unit calculating the hash value of each storage block under the distributed storage address; combining the calculated hash values in pairs to generate upper-level nodes until the root hash is calculated; comparing the root hashes in adjacent time periods; if a difference in the comparison results is detected, the data recovery process is automatically triggered; and uploading the audit results and log hashes to the blockchain to form permanent evidence.
[0047] In one embodiment of this application, when the power data reaches its retention period, the data destruction unit performs an encrypted deletion operation and records a destruction certificate on the blockchain, including: when the power data reaches its retention period, the data destruction unit controls the off-chain storage node to perform an encrypted deletion operation on the power data, destroying the corresponding ciphertext and generating a destruction certificate; storing the destruction certificate and destruction time on the blockchain; and confirming that the power data has been permanently deleted by verifying the hash consistency of the destruction certificate through a supervisory node.
[0048] In one embodiment of this application, the method further includes: during the PUF challenge-response pair generation process, the power acquisition terminal uses multiple sets of different challenge values to generate multiple sets of PUF responses; and combines or transforms the multiple sets of PUF responses to generate the final PUF fingerprint, so as to improve the uniqueness and security of the PUF fingerprint.
[0049] In one embodiment of this application, the method further includes: during the off-chain collaborative execution of privacy computation, the data user uses differential privacy technology to add noise to the computation results to prevent the original data from being inferred from the computation results.
[0050] According to a third aspect of this application, an electronic device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the method described above.
[0051] According to a fourth aspect of this application, a computer-readable storage medium is provided, on which a computer program is stored, which, when executed by a processor, implements the steps of the above-described method.
[0052] According to a fifth aspect of this application, a computer program product is provided, comprising a computer program / instructions that, when executed by a processor, implement the steps of the above-described method.
[0053] The proposed method and system for privacy-preserving power data sharing based on PUF and blockchain in this application cleverly integrates PUF (Physically Unclonable Function), blockchain, privacy computing, and data auditing technologies to construct a secure and reliable power data sharing system. It guarantees data authenticity at the hardware level, utilizes smart contracts to automate the management and auditing of the sharing process, and employs privacy computing technology to achieve "usable but invisible" data, thus protecting data privacy while enabling cross-institutional data sharing. Furthermore, the Merkle tree auditing mechanism ensures long-term data integrity and consistency, while the verifiable forgetting mechanism meets data privacy compliance requirements. Attached Figure Description
[0054] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. In the drawings:
[0055] Figure 1 This is a schematic diagram of the structure of a power data privacy sharing system based on PUF and blockchain provided in an embodiment of this application;
[0056] Figure 2 This is a flowchart of data acquisition and trusted signature provided in an embodiment of this application;
[0057] Figure 3 This is a flowchart of privacy sharing and computation invocation provided in the embodiments of this application;
[0058] Figure 4 This is a flowchart of the continuous auditing and consistency verification provided in the embodiments of this application;
[0059] Figure 5 This is a flowchart of data forgetting and verifiable destruction provided in the embodiments of this application;
[0060] Figure 6 This is a flowchart illustrating a method for sharing electricity data privacy based on PUF and blockchain, as provided in an embodiment of this application.
[0061] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0062] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the embodiments of this application will be further described in detail below with reference to the accompanying drawings. Here, the illustrative embodiments and descriptions of this application are used to explain this application, but are not intended to limit this application.
[0063] The following is a brief explanation of the technical terms used in this application:
[0064] PUF (Physical Unclonable Function): A PUF is a unique physical fingerprint generated using random microscopic differences during chip manufacturing. Its output response is unique and uncopyable for each chip under the same input stimulus (Challenge). In this invention, PUF is used to achieve unique authentication and trusted signature for data acquisition in power terminal equipment, providing a physical layer security root of trust for the system.
[0065] DID (Decentralized Identifier): DID is a decentralized identification mechanism used in blockchain systems to identify entity identities. Unlike traditional centralized identity systems, DID allows each device or node to have its own independently verifiable identity, without relying on a central certification authority. In this invention, DID is used for device registration, access authorization, and on-chain identity binding.
[0066] SMC (Secure Multi-party Computation): SMC is a cryptographic technique that allows multiple participants to jointly compute the output of a function without revealing their individual input data. In this invention, SMC is used to achieve joint statistical and modeling analysis of cross-departmental power data, enabling data value sharing while ensuring privacy.
[0067] Homomorphic Encryption (HE): Homomorphic encryption is a special encryption method that allows arithmetic or logical operations to be performed directly on the ciphertext, with the decrypted result matching the plaintext calculation. In this invention, HE is used for off-chain secure computation of power privacy data to prevent data leakage during analysis.
[0068] Merkle Tree: A Merkle tree is a tree-like data structure based on a hash function, capable of quickly verifying the integrity and consistency of large-scale datasets. This invention employs a Merkle tree structure to achieve continuous integrity auditing and anomaly recovery for blockchain storage nodes.
[0069] Smart Contract: A smart contract is an automatically executed program deployed on a blockchain, used to automatically trigger rules and record events. In this invention, the smart contract undertakes functions such as data registration, access control, incentives, and auditing, realizing fully automated and trusted management of the data sharing process.
[0070] Hash (hash function): An irreversible function that maps an input of arbitrary length to an output of fixed length. In this invention, the hash function is used for data digest generation, signature verification, Merkle tree calculation, and integrity verification.
[0071] like Figure 1 The diagram shown is a schematic representation of a power data privacy sharing system based on PUF and blockchain, according to an embodiment of this application. The system includes:
[0072] The device registration and fingerprint generation module 110 is configured to enable the power acquisition terminal to generate a PUF challenge-response pair, record the binding relationship between the device DID and the PUF fingerprint in the registration contract, and register it to the blockchain.
[0073] The data acquisition and trusted signature module 120 is configured to acquire power data and use the PUF response as a dynamic random source to participate in the data signature calculation to generate a signature.
[0074] The on-chain evidence storage and index mapping module 130 is configured to store the hash digest of the data packet containing the signature and power data, as well as the index information pointing to the off-chain distributed storage address on the chain, and to store the power data in an off-chain distributed manner.
[0075] The privacy sharing and computation call module 140 is configured to enable data users to authenticate themselves through a smart contract based on the registered device DID, request access and trigger privacy computation, use the hash digest stored on the chain to verify the integrity of the data, ensure that the data is not tampered with during the sharing process, and realize cross-institutional data sharing and joint analysis.
[0076] The continuous audit and consistency verification module 150 is configured to periodically perform Merkle tree audits to check whether the data stored on the chain is complete.
[0077] The data forgetting and verifiable destruction module 160 is configured to perform an encrypted deletion operation and record a destruction certificate on the chain when the power data reaches the retention period.
[0078] As described above, the power data privacy sharing system based on PUF and blockchain proposed in this application cleverly integrates PUF (Physically Unclonable Function), blockchain, privacy computing, and data auditing technologies to construct a secure and reliable power data sharing system. It guarantees data authenticity at the hardware level, utilizes smart contracts to automate the management and auditing of the sharing process, and employs privacy computing technology to achieve "usable but invisible" data, thus protecting data privacy while enabling cross-institutional data sharing. Furthermore, the Merkle tree auditing mechanism ensures the long-term integrity and consistency of the data, while the verifiable forgetting mechanism meets the requirements of data privacy compliance.
[0079] In one embodiment of this application, the aforementioned data acquisition and trusted signature module can be further configured to perform the following: Figure 2 The steps described are as follows:
[0080] Step S201: During the data acquisition phase, calculate the PUF response R based on the PUF challenge C, R = PUF(C).
[0081] In this embodiment, the power data terminal equipment has a hardware-level PUF module, capable of providing a unique and unpredictable response R to an external challenge signal C. The challenge signal C can be one or more bit sequences, used cyclically or gradually transformed to improve robustness and anti-replay capability. The selected challenge C is fed into the PUF module to obtain the response R. This embodiment can also preprocess the PUF response R (such as denoising, normalization, truncation, etc.) to improve the stability and consistency of the subsequent signature process. The output PUF response R serves as a dynamic, device-specific random source used to bind the physical identity information of the data source.
[0082] The uniqueness and unpredictability of PUF are key to the anti-counterfeiting data in this application, ensuring that the physical layer is difficult to clone, copy, or predict.
[0083] Step S202: Concatenate the power data D, PUF response R, and timestamp T into message M, M = D || R || T.
[0084] In the above steps, "||" represents a splicing operation. The power data D is the raw data collected by the power acquisition terminal, which may be a sampled value, a statistical quantity, or a packaged power data fragment. R is the PUF response generated in step S201, and T is the current timestamp, which represents the time point when the data was generated. It is usually provided by a precise clock source.
[0085] In this embodiment, a deterministic concatenation method can be used: D, R, and T are connected one by one in binary or byte sequence form to form a new message M. The concatenation order must ensure that the boundaries of D, R, and T are identifiable to avoid ambiguity caused by concatenating different fields (if necessary, a separator or fixed-length field can be added in this embodiment).
[0086] The length of message M is equal to the sum of the lengths of D, R, and T. The length can be fixed in the protocol or described through fields. R, as a dynamic fingerprint embedded in the message, enhances the ability to present differences in the same data at different points in time, strengthening non-repudiation. The timestamp T provides temporal evidence, aiding in subsequent traceability and replay attack protection. Message M will be used as input for the hash signature digest calculation in step S203.
[0087] Step S203: Calculate the signature digest of message M using SHA256 to generate a signature digest H, where H = SHA256(M).
[0088] This step uses the SHA-256 hash function to perform a single hash operation on message M, obtaining a fixed-length 256-bit (32-byte) hash value H (signature digest). The signature digest H serves as a fingerprint binding data integrity and origin. SHA256 is a widely accepted strong hash algorithm with an extremely low probability of resisting common hash collision attacks, making it suitable for use as a message fingerprint. The uniqueness and determinism of the signature digest H are crucial for subsequent signature and data packet integrity verification.
[0089] Step S204: Generate a signature Sig = H and form a data packet {D, Sig, T}.
[0090] In this step, the signature field is directly appended to the data packet with Sig = H, forming a structured data packet {D, Sig, T}, which together constitute a triple binding structure of "data-device-time". The data packet transmits or uploads D, Sig, and T together, facilitating subsequent integrity verification on or off the chain. Since Sig = SHA256(D || R || T), any modification to D, R, or T will cause Sig to no longer match, thus making tampering easy to detect.
[0091] In another embodiment of this application, the aforementioned privacy sharing and computation invocation module may be further configured to perform, as follows: Figure 3 The steps described are as follows:
[0092] Step S301: Task allocation, identity verification, and key distribution are performed through on-chain smart contracts to ensure the trustworthiness of data users and the reasonable allocation of tasks.
[0093] Data users invoke smart contracts related to registration / authorization on the blockchain to perform identity verification and binding: for example, verifying whether the data user's identity and permissions meet the conditions for executing specific privacy computing tasks; and / or verifying the validity and revocation status of the input party's public key / certificate chain; and / or verifying the timeliness and credibility of all parties (such as certificate validity period, signature validity).
[0094] This embodiment can allocate the computation task to a suitable set of participants based on their roles, data availability, computing resources, trust levels, and compliance requirements; generate task descriptions and input / output constraints; form an executable task token and write it on the blockchain.
[0095] This embodiment can also trigger the key distribution process through on-chain smart contracts based on a pre-agreed key management strategy; distribute symmetric keys, public key pairs or auxiliary key materials (such as temporary session keys, key rotation information), and record the hash fingerprint and timestamp of the key distribution to ensure that the evidence chain is auditable.
[0096] This embodiment reduces the risk of centralized trust through decentralized identity authentication. The verifiability and non-repudiation of task allocation come from on-chain records and hash binding. Key distribution adopts the principle of least privilege, key rotation and access control strategies, avoiding the risks brought by long-term static keys.
[0097] After this step, the output includes the set of authenticated participants, a description of the assigned privacy computation task, access permissions for the relevant keys, and key distribution credentials (Token / Evidence Chain). The output task credentials and key information will be used for the off-chain privacy computation in step S302 and for the on-chain results in step S303.
[0098] Step S302: Enable each data user to collaboratively perform privacy computation off-chain. The privacy computation process utilizes homomorphic encryption technology to complete the function computation of the power data without exposing the original data.
[0099] This embodiment can first establish a trusted off-chain computation zone (such as Secure Multi-Party Computation (SMC) or a protected execution environment) to ensure that participating parties cannot read the original data of other parties.
[0100] Each data user performs privacy computation off-chain, computing the function f(x1, x2, ..., xn); in homomorphic encryption mode, Enc(D1 + D2) = Enc(D1) ⊕ Enc(D2).
[0101] Step S303: Upload the privacy calculation results to the blockchain after encryption.
[0102] In this step, the privacy-preserving computation result and necessary contextual information are packaged into a standardized data structure (such as a result package, ResultPack) to ensure consistency in field order and encoding format among the participants. The result package is then hashed to obtain a non-repudiable fingerprint, H_result. Finally, a smart contract writes H_result, result metadata, timestamps, and necessary access control information into the blockchain, forming an immutable audit trail. This embodiment can also include verifiable cryptographic proofs (such as zero-knowledge proofs or verifiable computational proofs) to verify the correctness of the computation without exposing the original data.
[0103] In another embodiment of this application, the aforementioned continuous auditing and consistency verification module may be further configured to perform, as follows: Figure 4 The steps described are as follows:
[0104] Step S401: Calculate the hash value for each storage block under the distributed storage address.
[0105] In a distributed storage system, a set of data blocks {b1, b2, ..., bn} is defined, where each block represents a raw or encrypted fragment of data within a storage unit. The hash value Hi = Hash(bi) is calculated for each storage block bi. This process can be parallelized to improve performance and ensure the consistency and idempotency of the hash calculation.
[0106] Step S402: Combine the calculated hash values in pairs to generate upper-level nodes until the root hash is calculated.
[0107] Based on the leaf node hash set {Hi} generated in step S401, and the set hash combination rules (e.g., binary concatenation followed by hashing: Hi ⊕ Hj then hashing, or Hash(Hi || Hj)), adjacent hash values at the same level are combined in pairs to generate the node set of the next level. This process is repeated until the root hash Hroot(t) is generated. When processing large-scale data, parallelization or segmented construction can be used to improve performance and control memory usage. Simultaneously, sufficient boundary information can be retained at each level to trace back to the specific leaf node hash.
[0108] The root hash is a consistent fingerprint of the distributed storage structure, which is crucial for subsequent auditing and recovery. It can ensure that the integrity of the tree structure has not been tampered with.
[0109] Step S403: Compare the root hashes within the corresponding time periods in adjacent time periods.
[0110] The root hashes for different time periods are Hroot(t) and Hroot(t) 1) Compare the root hashes of adjacent time periods. If they are the same, it indicates that the overall status of distributed storage remains consistent within that time period; if they are different, it indicates that the data distribution or content is inconsistent or potentially corrupted within that time period. When a difference is found, trigger the anomaly handling branch, record the reason for the difference, and locate and diagnose possible abnormal partitions. If a difference exists, proceed to the data recovery process in step S404; if there is no difference, proceed to the on-chain evidence recording in step S405.
[0111] Step S404: If a difference in the comparison results is detected, the data recovery process is automatically triggered.
[0112] When the aforementioned steps detect discrepancies in the comparison results, a data recovery process is initiated to repair inconsistencies in the distributed storage. This can be achieved by locating the affected blocks and recovering them from the correct replicas, based on redundant replicas, checksums, and the original data source. Alternatively, the hashes of the relevant blocks can be recalculated and verified to align them with the root hash that has been confirmed as consistent. After the repair is complete, proceed to step S405, where the audit results and log hashes are uploaded to the blockchain.
[0113] Step S405: Upload the audit results and log hash to the blockchain to form permanent evidence.
[0114] In this embodiment, the results summary of this audit, the root hash and its timestamp, necessary log hashes, recovery operation records (if any), and participant signatures can be uploaded to the blockchain. Specifically, the root hash, timestamp, difference information, recovery actions, and log hashes can be packaged into an audit evidence structure, and then the hash fingerprint of the audit evidence is calculated. The hash fingerprint, timestamp, and necessary metadata are written to the blockchain via a smart contract, forming an immutable and permanent record. If necessary, verifiable computational proofs, log snapshots, or externally compared hashes can be attached to enhance credibility.
[0115] In another embodiment of this application, the aforementioned data forgetting and verifiable destruction module may be further configured to perform the following: Figure 5 The steps described are as follows:
[0116] Step S501: When the power data reaches the retention period, the off-chain storage node performs an encrypted deletion operation on the power data, destroys the corresponding ciphertext, and generates a destruction certificate.
[0117] In this embodiment, the data is confirmed to enter the destruction phase based on the data retention strategy and the trigger timing for destruction. When the power data reaches its retention period, the corresponding ciphertext data Enc(D) will be irreversibly deleted to ensure that the plaintext cannot be recovered in off-chain storage. If the system uses symmetric encryption or a key hierarchy structure, the relevant encryption keys can be destroyed simultaneously to fundamentally make the data undecryptable.
[0118] This embodiment also generates a destruction certificate, which is calculated as follows:
[0119] ProofDel = Hash(DataID || timestamp);
[0120] DataID uniquely identifies the destroyed data block, and timestamp is the destruction timestamp.
[0121] Step S502: Upload the destruction certificate and destruction time to the blockchain for storage.
[0122] The destruction event is encapsulated into a standardized notarized record, including: a data identifier (DataID), a destruction time (ts), the hash value of the destruction proof (ProofDel), information about the executing node and operator, a timestamp, and necessary access control signatures. This destruction notarization is then written to the blockchain using a smart contract, forming an immutable and permanent notarized entry. This provides an irrefutable evidentiary basis for subsequent verification by oversight nodes, supporting the integrity of the verifiable destruction.
[0123] Step S503: Verify the hash consistency of the destruction proof through the supervisory node to confirm that the power data has been permanently deleted.
[0124] The regulatory node obtains the corresponding destruction record and ProofDel on the blockchain, recalculates the Hash(DataID||timestamp), and compares it with the ProofDel Hash value recorded in the record to confirm their consistency. If the hashes match, it confirms that the data has been permanently deleted as required, and the record is valid; if they do not match, an alarm is triggered and an investigation process begins.
[0125] This embodiment forms a complete closed loop of "destruction-evidence storage-regulatory verification"; if verification fails, an exception handling and investigation mechanism must be triggered.
[0126] In another embodiment of this application, the device registration and fingerprint generation module is further configured to: generate multiple sets of PUF responses using multiple different challenge values during the PUF challenge-response pair generation process of the power acquisition terminal; combine or transform the multiple sets of PUF responses to generate the final PUF fingerprint, so as to improve the uniqueness and security of the PUF fingerprint.
[0127] In this embodiment, multiple sets of challenge values C1, C2, ..., Ck are introduced to generate multiple sets of PUF responses R1 = PUF(C1), R2 = PUF(C2), ..., Rk = PUF(Ck). These responses are then combined or transformed to obtain a single, more robust, and unique final PUF fingerprint FPUF, which is used for device registration, authentication, and subsequent data signature binding.
[0128] The above combination or transformation strategies are optional, including but not limited to:
[0129] The hash after direct concatenation is: FPUF = SHA256(R1 || R2 || ... || Rk);
[0130] Level-by-level Merkle hash tree: Using Ri as the leaf node, construct a Merkle tree and take the root hash as the FPUF;
[0131] Weighted fusion: Apply a unified zero-latency fusion function to Ri, such as FPUF = FUSE(R1, R2, ..., Rk), where FUSE is a hash of Ri after performing byte-by-byte XOR, weighted summation and modulo operation;
[0132] Error correction and alignment followed by hashing: Ri is aligned or normalized before being combined to reduce the impact of length differences.
[0133] The final fingerprint FPUF is bound to the device DID, PUF basic parameters, and chip uniqueness information. This fingerprint is then written into the blockchain's registration contract or trust management layer as part of the device registration process for subsequent authentication, access control, and auditing.
[0134] In another embodiment of this application, the privacy sharing and computation invocation module can also be configured to: add noise to the computation results using differential privacy technology during the off-chain collaborative execution of privacy computation, so as to prevent the original data from being inferred from the computation results.
[0135] In this embodiment, during the off-chain privacy computation phase, controllable noise is added to the computation results. This ensures that no single output can be used to infer individual data from the results, achieving a measurable level of privacy protection while maintaining statistical validity and modeling usefulness. Specifically, this embodiment applies differential privacy noise to the output results after off-chain computation but before uploading to the blockchain. The noise intensity is determined by the task's privacy budget parameters. Then, an appropriate privacy-preserving (DP) strategy is selected based on the computation type (such as adding independent noise to the overall result, distributed noise to multi-dimensional vectors, or noise-enhancing aggregated statistics). Simultaneously, the privacy budget and noise parameters are recorded to ensure auditability and repeatability.
[0136] like Figure 6 The diagram shown is a flowchart illustrating a method for sharing electricity data privacy based on PUF and blockchain, according to an embodiment of this application. The method includes:
[0137] Step S601: The power acquisition terminal generates a PUF challenge-response pair, records the binding relationship between the device DID and the PUF fingerprint in the registration contract, and registers it to the blockchain.
[0138] Step S602: The power acquisition terminal acquires power data and uses the PUF response as a dynamic random source to participate in the data signature calculation to generate a signature.
[0139] Step S603: The power acquisition terminal stores the hash digest of the data packet containing the signature and power data, as well as the index information pointing to the off-chain distributed storage address on the chain, and stores the power data in an off-chain distributed manner.
[0140] Step S604: The data user authenticates the identity based on the registered device DID through a smart contract, requests access and triggers privacy computation, uses the hash digest stored on the chain to verify the integrity of the data, ensures that the data has not been tampered with during the sharing process, and realizes cross-institutional data sharing and joint analysis.
[0141] Step S605: The data auditing unit periodically performs Merkle tree audits to check whether the data stored on the chain is complete.
[0142] Step S606: When the power data reaches the retention period, the data destruction unit performs an encrypted deletion operation and records the destruction certificate on the chain.
[0143] In one embodiment of this application, the power acquisition terminal collects power data and uses the PUF response as a dynamic random source to participate in data signature calculation to generate a signature. This further includes: during the data acquisition phase, the power acquisition terminal calculates the PUF response R based on the PUF challenge C, R = PUF(C); concatenates the power data D, the PUF response R, and the timestamp T into a message M, M = D || R || T; performs a signature digest calculation on the message M using SHA256 to generate a signature digest H, H = SHA256(M); generates a signature Sig = H, and forms a data packet {D, Sig, T}.
[0144] In one embodiment of this application, the data user authenticates themselves through a smart contract based on the registered device DID, requests access, and triggers privacy computation. This includes: assigning tasks, authenticating the user, and distributing keys through an on-chain smart contract to ensure the data user's identity is trustworthy and the task assignment is reasonable; enabling each data user to collaboratively perform privacy computation off-chain, wherein the privacy computation process utilizes homomorphic encryption technology to complete the function calculation of the power data without exposing the original data; and uploading the privacy computation result to the blockchain after encryption.
[0145] In one embodiment of this application, the data auditing unit periodically performs Merkle tree audits to detect whether the data stored on the chain is complete. This includes: the data auditing unit calculating the hash value of each storage block under the distributed storage address; combining the calculated hash values in pairs to generate upper-level nodes until the root hash is calculated; comparing the root hashes in adjacent time periods; if a difference in the comparison results is detected, the data recovery process is automatically triggered; and uploading the audit results and log hashes to the blockchain to form permanent evidence.
[0146] In one embodiment of this application, when the power data reaches its retention period, the data destruction unit performs an encrypted deletion operation and records a destruction certificate on the blockchain, including: when the power data reaches its retention period, the data destruction unit controls the off-chain storage node to perform an encrypted deletion operation on the power data, destroying the corresponding ciphertext and generating a destruction certificate; storing the destruction certificate and destruction time on the blockchain; and confirming that the power data has been permanently deleted by verifying the hash consistency of the destruction certificate through a supervisory node.
[0147] In one embodiment of this application, the method further includes: during the PUF challenge-response pair generation process, the power acquisition terminal uses multiple sets of different challenge values to generate multiple sets of PUF responses; and combines or transforms the multiple sets of PUF responses to generate the final PUF fingerprint, so as to improve the uniqueness and security of the PUF fingerprint.
[0148] In one embodiment of this application, the method further includes: during the off-chain collaborative execution of privacy computation, the data user uses differential privacy technology to add noise to the computation results to prevent the original data from being inferred from the computation results.
[0149] The proposed electricity data privacy-preserving sharing method based on PUF and blockchain in this application cleverly integrates PUF (Physically Unclonable Function), blockchain, privacy computing, and data auditing technologies to construct a secure and reliable electricity data sharing system. It guarantees data authenticity at the hardware level, utilizes smart contracts to automate the management and auditing of the sharing process, and employs privacy computing technology to achieve "usable but invisible" data, thus protecting data privacy while enabling cross-institutional data sharing. Furthermore, the Merkle tree auditing mechanism ensures long-term data integrity and consistency, while the verifiable forgetting mechanism meets data privacy compliance requirements.
[0150] Figure 7 This is a schematic diagram of the electronic device provided in the embodiments of this application. Figure 7 The illustrated electronic device is a general-purpose data processing apparatus, comprising a general-purpose computer hardware architecture, including at least a processor 801 and a memory 802. The processor 801 and memory 802 are connected via a bus 803. The memory 802 is adapted to store one or more instructions or programs executable by the processor 801. These instructions or programs are executed by the processor 801 to implement the steps in the aforementioned PUF-based blockchain-based electricity data privacy sharing method.
[0151] The processor 801 described above can be a standalone microprocessor or a collection of one or more microprocessors. Thus, the processor 801 executes commands stored in the memory 802, thereby performing the method flow described in the embodiments of this application to process data and control other devices. The bus 803 connects the aforementioned components together, and also connects these components to the display controller 804, the display device, and the input / output (I / O) device 805. The input / output (I / O) device 805 can be a mouse, keyboard, modem, network interface, touch input device, motion-sensing input device, printer, and other devices known in the art. Typically, the input / output (I / O) device 805 is connected to the system via an input / output (I / O) controller 806.
[0152] The memory 802 can store software components, such as an operating system, a communication module, an interaction module, and application programs. Each of the modules and application programs described above corresponds to a set of executable program instructions that perform one or more functions and the methods described in the embodiments of the invention.
[0153] This application also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps of the above-described method for sharing electricity data privacy based on PUF and blockchain.
[0154] The proposed method and system for privacy-preserving power data sharing based on PUF and blockchain in this application cleverly integrates PUF (Physically Unclonable Function), blockchain, privacy computing, and data auditing technologies to construct a secure and reliable power data sharing system. It guarantees data authenticity at the hardware level, utilizes smart contracts to automate the management and auditing of the sharing process, and employs privacy computing technology to achieve "usable but invisible" data, thus protecting data privacy while enabling cross-institutional data sharing. Furthermore, the Merkle tree auditing mechanism ensures long-term data integrity and consistency, while the verifiable forgetting mechanism meets data privacy compliance requirements.
[0155] Preferred embodiments of this application have been described above with reference to the accompanying drawings. Many features and advantages of these embodiments are apparent from this detailed description, and therefore the claims are intended to cover all such features and advantages of these embodiments that fall within their true spirit and scope. Furthermore, since many modifications and alterations will readily occur to those skilled in the art, the embodiments of this application are not intended to be limited to the precise structures and operations illustrated and described, but rather to encompass all suitable modifications and equivalents falling within their scope.
[0156] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0157] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0158] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0159] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0160] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of this application. It should be understood that the above descriptions are merely specific embodiments of this application and are not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. A power data privacy sharing system based on PUF and blockchain, characterized in that, The system includes: The device registration and fingerprint generation module is configured to enable the power acquisition terminal to generate PUF challenge-response pairs, record the binding relationship between the device DID and the PUF fingerprint in the registration contract, and register it to the blockchain; The data acquisition and trusted signature module is configured to acquire power data and use PUF response as a dynamic random source to participate in data signature calculation to generate a signature. The on-chain evidence storage and index mapping module is configured to store the hash digest of the data packet containing the signature and power data, as well as the index information pointing to the off-chain distributed storage address on the chain, and to store the power data in an off-chain distributed manner. The privacy sharing and computation invocation module is configured to enable data users to authenticate themselves through smart contracts based on the registered device DID, request access and trigger privacy computation, use the hash digest stored on the chain to verify the integrity of the data, ensure that the data is not tampered with during the sharing process, and realize cross-institutional data sharing and joint analysis. The continuous auditing and consistency verification module is configured to periodically perform Merkle tree audits to check whether the data stored on the chain is complete. The data forgetting and verifiable destruction module is configured to perform an encrypted deletion operation and record a destruction certificate on the blockchain when the power data reaches its retention period.
2. The power data privacy sharing system based on PUF and blockchain as described in claim 1, characterized in that, The data acquisition and trusted signature module is further configured as follows: During the data acquisition phase, the PUF response R is calculated based on the PUF challenge C, where R = PUF(C). Concatenate the power data D, PUF response R, and timestamp T into message M, where M = D || R || T; The signature digest of message M is calculated using SHA256, resulting in a signature digest H, where H = SHA256(M). Generate a signature Sig = H and form a data packet {D, Sig, T}.
3. The power data privacy sharing system based on PUF and blockchain as described in claim 2, characterized in that, The privacy sharing and computation invocation module is further configured as follows: On-chain smart contracts are used for task allocation, identity verification, and key distribution to ensure the credibility of data users and the reasonableness of task allocation. This enables data users to collaboratively perform privacy-preserving computations off-chain. The privacy-preserving computation process utilizes homomorphic encryption technology to complete function calculations on power data without exposing the original data. The results of privacy-preserving computations are encrypted and then uploaded to the blockchain.
4. The power data privacy sharing system based on PUF and blockchain as described in claim 1, characterized in that, The continuous auditing and consistency verification module is further configured as follows: Calculate the hash value for each storage block under the distributed storage address; The calculated hash values are combined in pairs to generate upper-level nodes, until the root hash is calculated; Compare the root hashes within the corresponding time periods in adjacent time periods; If a difference in the comparison results is detected, the data recovery process will be automatically triggered. The audit results and log hashes are uploaded to the blockchain to form permanent evidence.
5. The power data privacy sharing system based on PUF and blockchain as described in claim 1, characterized in that, The data forgetting and verifiable destruction module is further configured as follows: When the power data reaches its retention period, the off-chain storage node performs an encrypted deletion operation on the power data, destroys the corresponding ciphertext, and generates a destruction certificate; The destruction certificate and destruction time will be stored on the blockchain as evidence. The power data has been permanently deleted by verifying the hash consistency of the destruction proof through a regulatory node.
6. The power data privacy sharing system based on PUF and blockchain as described in claim 1, characterized in that, The device registration and fingerprint generation module is also configured as follows: In the process of generating PUF challenge-response pairs in the power acquisition terminal, multiple sets of different challenge values are used to generate multiple sets of PUF responses; The multiple PUF responses are combined or transformed to generate the final PUF fingerprint, thereby improving the uniqueness and security of the PUF fingerprint.
7. The power data privacy sharing system based on PUF and blockchain as described in claim 3, characterized in that, The privacy sharing and computation invocation module is also configured as follows: During off-chain collaborative execution of privacy computation, differential privacy technology is used to add noise to the computation results to prevent the original data from being inferred from the computation results.
8. A method for privacy-sharing electricity data based on PUF and blockchain, characterized in that, The method includes: The power acquisition terminal generates a PUF challenge-response pair, records the binding relationship between the device DID and the PUF fingerprint in the registration contract, and registers it to the blockchain; The power acquisition terminal collects power data and uses the PUF response as a dynamic random source to participate in the data signature calculation to generate a signature; The power acquisition terminal stores the hash digest of the data packet containing the signature and power data, as well as the index information pointing to the off-chain distributed storage address on the chain, and stores the power data in an off-chain distributed manner. Data users authenticate themselves through smart contracts based on the registered device DID, request access and trigger privacy calculations, and use hash digests stored on the chain to verify the integrity of the data, ensuring that the data is not tampered with during the sharing process, thus enabling cross-institutional data sharing and joint analysis. The data auditing unit periodically performs Merkle tree audits to check the integrity of the data stored on the chain. When the power data reaches its retention period, the data destruction unit performs an encrypted deletion operation and records the destruction certificate on the blockchain.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method of claim 8.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method of claim 8.