Data verification method, device, storage medium, electronic device and blockchain node

By building a Merkel tree in an IoT system and storing data on a blockchain network, and using blockchain to verify data legitimacy, the problems of data security and privacy protection in the IoT network are solved, and the system's security protection capabilities and data management reliability are improved.

CN113590617BActive Publication Date: 2025-07-11NEUSOFT CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110814054.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-07-19
Publication Date
2025-07-11
Estimated Expiration
2041-07-19

AI Technical Summary

Technical Problem

The Internet of Things network lacks communication and data security means for massive devices, lack of privacy protection measures, and lacks connection and data credibility mechanisms in complex environments.

Method used

By building a Merkel tree in the Internet of Things system and storing the original root node on the blockchain network, the blockchain network is used to verify the consistency between the root node and the original root node, judge the legitimacy of the data to be verified, and combine the collaboration between the off-chain Internet of Things equipment and the on-chain blockchain network to ensure data security.

Benefits of technology

It improves the security protection capabilities of the Internet of Things system, ensures the security and privacy of data, solves the problem of easy attack and tampering in traditional data storage mode, and meets the needs of high-concurrency application scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113590617B_ABST
    Figure CN113590617B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a data verification method, apparatus, storage medium, electronic device, and blockchain node, and relates to the field of communication technologies. The data verification method sends data to be verified and a Merkle path to a blockchain network through a first Internet of Things device, and receives a verification result feedback by the blockchain network to determine whether the data to be verified is legal according to the verification result. The verification result is the result of the blockchain network verifying the reconstructed root node obtained according to the data to be verified and the Merkle path with the corresponding original root node. The beneficial effects of the present disclosure are as follows: The security of Internet of Things data is jointly ensured by the Internet of Things devices in the off-chain part and the blockchain network in the on-chain part, which can greatly improve the security protection ability of the Internet of Things system. It ensures the confirmation of rights, traceability, and protection of relevant information in the data management process, and can meet the application scenarios of high concurrency of Internet of Things data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of communication technologies, and in particular, to a data verification method, apparatus, storage medium, electronic device, and blockchain node. Background Art

[0002] With the development of the Internet of Things (IoT) networks and services, there is an increasing demand for the access of IoT devices. The IoT networks and service platforms based on centralized trust management in the related art are facing more and more challenges. The main problems they face are the lack of communication and data security means for a large number of IoT devices, as well as privacy protection measures, and the lack of a connection and data trust mechanism for solving a large number of IoT devices in a complex environment. Summary of the Invention

[0003] The purpose of the present disclosure is to provide a data verification method, apparatus, storage medium, electronic device, and blockchain node to partially or fully solve the above technical problems.

[0004] According to a first aspect of an embodiment of the present disclosure, a data verification method is provided, which is applied to an IoT device in an IoT system and includes:

[0005] A first IoT device in the IoT system obtains data to be verified from an IoT database and a Merkle path of the data to be verified stored in the IoT database, where the Merkle path is a path of a Merkle tree constructed based on IoT data generated by the IoT system;

[0006] The first IoT device sends the data to be verified and the Merkle path to a blockchain network;

[0007] The first IoT device receives a verification result fed back by the blockchain network, where the verification result is a result obtained by the blockchain network verifying a reconstructed root node with an original root node of the Merkle tree stored on a blockchain in the blockchain network, and the reconstructed root node is a root node calculated by the blockchain network based on the data to be verified and the Merkle path;

[0008] The first IoT device determines whether the data to be verified belongs to IoT data generated by the IoT system according to the verification result.

[0009] In some embodiments, the method further includes:

[0010] A second IoT device in the IoT system constructs a Merkle tree according to IoT data generated within a preset duration to obtain an original root node of the Merkle tree;

[0011] The second Internet of Things device sends the original root node to the blockchain network so that the blockchain network stores the original root node on the blockchain; and

[0012] The second Internet of Things device stores the Internet of Things data generated within the preset duration and the Merkle tree in the Internet of Things database.

[0013] In some embodiments, the second Internet of Things device sending the original root node to the blockchain network includes:[[]]

[0014] The second Internet of Things device digitally signs the original root node based on the private key of the second Internet of Things device to obtain the signed original root node;

[0015] The second Internet of Things device sends the signed original root node to the blockchain network so that the blockchain network verifies the signed original root node based on the public key of the second Internet of Things device and stores the original root node when the verification passes.

[0016] In some embodiments, the Merkle tree is obtained by the second Internet of Things device performing Merkle calculation on the Internet of Things data in a trusted execution environment based on a trusted computing service.

[0017] According to a second aspect of the embodiments of the present disclosure, a data verification method is provided, which is applied to a blockchain node in a blockchain network and includes:[[]]

[0018] Receiving the data to be verified and the Merkle path sent by a first Internet of Things device in the Internet of Things system, where the data to be verified and the Merkle path are obtained by the first Internet of Things device from the Internet of Things database, and the Merkle path is the path of a Merkle tree constructed by a second Internet of Things device based on the Internet of Things data generated by the Internet of Things device corresponding to the data to be verified;

[0019] Calculating a reconstructed root node based on the data to be verified and the Merkle path;

[0020] Verifying the reconstructed root node with the original root node corresponding to the Merkle tree stored on the blockchain network to obtain a verification result;

[0021] Sending the verification result to the first Internet of Things device so that the first Internet of Things device determines whether the data to be verified belongs to the Internet of Things data generated by the Internet of Things system according to the verification result.

[0022] In some embodiments, the method further includes:[[]]

[0023] Receive the original root node sent by the second Internet of Things device, where the original root node is the root node of a Merkle tree constructed by the second Internet of Things device based on the Internet of Things data generated within a preset duration;

[0024] Store the original root node.

[0025] In some embodiments, the receiving the original root node sent by the second Internet of Things device includes:

[0026] Receive the signed original root node sent by the second Internet of Things device, where the signed original root node is obtained by the second Internet of Things device digitally signing the original root node based on the private key of the second Internet of Things device;

[0027] The storing the original root node includes:

[0028] Verify the signature of the signed original root node based on the public key of the second Internet of Things device;

[0029] In the case where the signature verification passes, store the original root node.

[0030] According to a third aspect of the embodiments of the present disclosure, there is provided a data verification device applied to an Internet of Things device in an Internet of Things system, including:

[0031] An acquisition module configured to control a first Internet of Things device in the Internet of Things system to acquire data to be verified from an Internet of Things database and a Merkle path of the data to be verified stored in the Internet of Things database, where the Merkle path is a path of a Merkle tree constructed based on the Internet of Things data generated by the Internet of Things system;

[0032] A first sending module configured to control the first Internet of Things device to send the data to be verified and the Merkle path to a blockchain network;

[0033] A first receiving module configured to control the first Internet of Things device to receive a verification result feedback by the blockchain network, where the verification result is a result obtained by the blockchain network verifying a reconstructed root node with an original root node of the Merkle tree stored on a blockchain in the blockchain network, and the reconstructed root node is a root node calculated by the blockchain network based on the data to be verified and the Merkle path;

[0034] A verification module configured to control the first Internet of Things device to determine whether the data to be verified belongs to the Internet of Things data generated by the Internet of Things system according to the verification result.

[0035] According to a fourth aspect of the embodiments of the present disclosure, a data verification device is provided, which is applied to a blockchain node in a blockchain network and includes:

[0036] A second receiving module, configured to receive the data to be verified and the Merkle path sent by a first Internet of Things (IoT) device in the IoT system, where the data to be verified and the Merkle path are obtained by the first IoT device from an IoT database, and the Merkle path is a path of a Merkle tree constructed by a second IoT device based on IoT data generated by an IoT device corresponding to the data to be verified;

[0037] A calculation module, configured to calculate a reconstructed root node based on the data to be verified and the Merkle path;

[0038] A second verification module, configured to verify the reconstructed root node with an original root node corresponding to the Merkle tree stored on the blockchain network to obtain a verification result;

[0039] A second sending module, configured to send the verification result to the first IoT device, so that the first IoT device determines whether the data to be verified belongs to the IoT data generated by the IoT system according to the verification result.

[0040] According to a fifth aspect of the embodiments of the present disclosure, a non-transitory computer-readable storage medium is provided, on which a computer program is stored, and when the program is executed by a processor, the method steps executed by the first IoT device and the second IoT device in the data verification method described in the first aspect of the present disclosure are implemented, or the steps of the data verification method described in the second aspect of the present disclosure are implemented.

[0041] According to a sixth aspect of the embodiments of the present disclosure, an electronic device is provided, including:

[0042] A memory, on which a computer program is stored;

[0043] A processor, configured to execute the computer program in the memory to implement the method steps of the method executed by the first IoT device and the second IoT device in the data verification method described in the first aspect of the present disclosure.

[0044] According to a seventh aspect of the embodiments of the present disclosure, a blockchain node is provided, including:

[0045] A memory, on which a computer program is stored;

[0046] A processor, configured to execute the computer program in the memory to implement the steps of the data verification method described in the second aspect of the present disclosure.

[0047] Through the above technical solution, the original root node is stored on the blockchain network. When data verification is required, the reconstructed root node is rebuilt based on the data to be verified and the corresponding Merkle path, and the reconstructed root node is verified against the corresponding original root node on the blockchain network, thereby determining whether the data to be verified is legal. By the cooperation of the off-chain Internet of Things devices and the on-chain blockchain network to ensure the security of Internet of Things data, the security protection ability of the Internet of Things system can be greatly improved, and the security and privacy of Internet of Things data are guaranteed. At the same time, by using blockchain technology for data storage management, problems such as centralization and vulnerability to attack and tampering in the traditional data storage mode are solved, the confirmation of rights, traceability, and protection of relevant information in the data management process are ensured, and the high-concurrency application scenarios of Internet of Things data can be satisfied.

[0048] Other features and advantages of the present disclosure will be described in detail in the following specific implementation section. Brief Description of the Drawings

[0049] The drawings are used to provide a further understanding of the present disclosure, and constitute a part of the specification, and are used to explain the present disclosure together with the following specific implementation manners, but do not constitute a limitation to the present disclosure. In the drawings:

[0050] Figure 1 is a schematic structural diagram of a data verification system shown according to an exemplary embodiment;

[0051] Figure 2 is a flowchart of a data verification method shown according to an exemplary embodiment;

[0052] Figure 3 is a schematic diagram of a Merkle tree shown according to an exemplary embodiment;

[0053] Figure 4 is a flowchart of a data verification method shown according to another exemplary embodiment;

[0054] Figure 5 is a flowchart of obtaining an original root node shown according to an exemplary embodiment;

[0055] Figure 6 is a flowchart of a data verification device shown according to an exemplary embodiment;

[0056] Figure 7 is a flowchart of a data verification device shown according to another exemplary embodiment;

[0057] Figure 8 is a block diagram of an electronic device shown according to an exemplary embodiment. Detailed Description of the Invention

[0058] Exemplary embodiments will be described in detail herein, and examples thereof are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present disclosure as detailed in the appended claims.

[0059] Figure 1 is a schematic structural diagram of a data verification system shown according to an exemplary embodiment. The data verification method proposed by the present disclosure can be applied to a data verification system as shown in Figure 1 The data verification system includes a second Internet of Things device 104, an Internet of Things database 102, a blockchain network 103, and a first Internet of Things device 101. Among them, the second Internet of Things device 104 constructs a Merkle tree based on the Internet of Things data generated by the Internet of Things system, stores the Merkle tree and the Internet of Things data in the Internet of Things database 102, and stores the original root node of the Merkle tree in the blockchain network 103. When the first Internet of Things device 101 needs to verify whether the data is legal, it obtains the data to be verified and the Merkle path corresponding to the data to be verified from the Internet of Things database 102, and sends the data to be verified and the Merkle path to the blockchain network 103. After receiving the data to be verified and the Merkle path, the blockchain network 103 obtains the corresponding Merkle tree according to the Merkle path, obtains a reconstructed root node based on the Merkle tree and the data to be verified, verifies the reconstructed root node and the corresponding original root node, obtains a verification result, and sends the verification result to the first Internet of Things device 101, so that the first Internet of Things device 101 can determine whether the data to be verified is legal according to the verification result.

[0060] Figure 2 is a flowchart of a data verification method shown according to an exemplary embodiment. As shown in Figure 2 The data verification method can be applied to Internet of Things devices in the Internet of Things system and includes the following steps.

[0061] In step 110, the first Internet of Things device in the Internet of Things system obtains the data to be verified from the Internet of Things database, and the Merkle path of the data to be verified stored in the Internet of Things database, where the Merkle path is the path of the Merkle tree constructed based on the Internet of Things data generated by the Internet of Things system.

[0062] Here, the first Internet of Things device in the Internet of Things system can be a device for verifying whether the Internet of Things data has been tampered with. For example, the device can be a computer, a supervision platform, etc.

[0063] The data to be verified refers to the IoT data that needs to be verified for tampering. For example, the data generated by IoT vehicles is stored in the IoT database. When the supervision platform needs to verify whether the data in a certain time period has been tampered with, the data in that time period is obtained as the data to be verified.

[0064] The Merkel path refers to the storage path of the Merkel tree constructed from the IoT data generated by the IoT system in the IoT database. Among them, the Merkel path of the data to be verified obtained from the first IoT data refers to the storage path corresponding to the Merkel tree corresponding to the data to be verified. For example, if the data to be verified is the data generated by IoT device A at the time point "2121 / 6 / 30 16:42:50", the Merkel path is the storage path of the Merkel tree constructed based on the IoT data generated by IoT device A in the time period including the time point "2121 / 6 / 30 16:42:50". Among them, the relevant calculation methods for the Merkel tree will be described in detail in the subsequent embodiments.

[0065] It should be understood that when the first IoT device needs to verify whether the specific data stored in the IoT database has been tampered with, the first IoT device obtains the data to be verified and the Merkel path corresponding to the data to be verified from the IoT database.

[0066] In some embodiments, the second IoT device in the IoT system constructs a Merkel tree based on the IoT data generated within a preset duration, and obtains the original root node of the Merkel tree. Then, the second IoT device sends the original root node to the blockchain network to store the original root node in the blockchain of the blockchain network. At the same time, the second IoT device stores the IoT data generated within the preset duration and the constructed Merkel tree in the IoT database.

[0067] Among them, the second IoT device in the IoT system may refer to IoT devices such as smart home devices and smart wearable devices, such as smart watches, smart air purifiers, smart socket strips, etc., or may refer to a data collection device for collecting the data of IoT devices. The IoT devices such as smart home devices and smart wearable devices are connected to the data collection device to upload the data of the IoT devices to the data collection device.

[0068] It should be understood that the process of the second Internet of Things device constructing a Merkle tree can be as follows: According to the Internet of Things data within a preset time period, combined with the Merkle tree algorithm, a Merkle tree is constructed. The working principle of the Merkle tree algorithm is to sequentially take the hash values of the Internet of Things data through SHA-2 (Secure Hash Algorithm 2) or MD5 (Message-Digest Algorithm), then combine two adjacent hash values into a string, and then calculate the hash of the string through the hash algorithm to obtain a Merkle tree composed of hashes.

[0069] Figure 3 is a schematic diagram of a Merkle tree shown according to an exemplary embodiment. As Figure 3 shown, the Internet of Things data generated by the Internet of Things system within a preset time period sequentially includes D0, D1, D2, D3, D4, D5, D6, D7, and D8. The Merkle tree algorithm respectively takes the hashes of D0, D1, D2, D3, D4, D5, D6, D7, and D8 to obtain N0, N1, N2, N3, N4, N5, N6, N7, and N8. Then, based on the two adjacent data N0 and N1, N8 is calculated. Based on the two adjacent data N2 and N3, N9 is calculated. Based on the two adjacent data N4 and N5, N10 is calculated. Based on the two adjacent data N6 and N7, N11 is calculated. Then, based on the two adjacent data N8 and N9, N12 is calculated. Based on the two adjacent data N10 and N11, N13 is calculated. Finally, based on N12 and N13, the original root node Root of the Merkle tree is calculated.

[0070] After the second Internet of Things device calculates the Merkle tree, it stores the Merkle tree and the corresponding Internet of Things data in the Internet of Things database. In some examples, the Internet of Things data and the corresponding Merkle tree are stored using the Internet of Things device number that generated the Internet of Things data and the time when the Internet of Things data was generated as an index. For example, the Internet of Things data generated by Internet of Things device A in the time period "2121 / 6 / 30 16:42:50 - 2121 / 6 / 30 17:42:50" and the Merkle tree constructed based on this data are stored in the Internet of Things database. When it is necessary to call the corresponding Merkle tree or search for Internet of Things data, the corresponding Merkle tree or Internet of Things data can be located according to the number of the Internet of Things device and the time point.

[0071] In some implementable embodiments, when the second Internet of Things device sends the original root node to the blockchain network, it can digitally sign the original root node based on the private key of the second Internet of Things device to obtain the signed original root node. Then, the signed original root node is sent to the blockchain network so that the blockchain network verifies the signature of the signed original root node based on the public key of the second Internet of Things device and stores the original root node when the verification passes.

[0072] Here, the second Internet of Things device can register its own information on the blockchain network to generate a pair of public key / private key. Among them, the private key is stored in the second Internet of Things device, and the public key is uploaded to the blockchain network. The original root node sent to the blockchain network is digitally signed with the private key stored in the second Internet of Things device, and the blockchain network verifies the signature of the signed original root node according to the stored public key. When the verification passes, it indicates that the original root node has not been tampered with and is stored on the blockchain network. When the verification fails, it indicates that the original root node is illegal, and a result indicating that the original root node is illegal is returned to the second Internet of Things device. It can ensure the security between off-chain and on-chain calculations and avoid data being tampered with.

[0073] In some implementable embodiments, the Merkle tree is obtained by the second Internet of Things device performing Merkle calculation on Internet of Things data in a trusted execution environment based on a trusted computing service.

[0074] Here, the trusted computing service refers to a trusted computing platform supported by a hardware security module, which can improve the overall security of the system. The trusted execution environment (TEE) can ensure that the second Internet of Things device is not interfered by the conventional operating system, which can be specifically implemented by creating a small operating system that can run independently in the secure world (TrustZone). The second Internet of Things device running in the trusted execution environment can ensure the authenticity of the data obtained in the off-chain part to avoid the data sent to the blockchain network for storage being tampered with.

[0075] In step 120, the first Internet of Things device sends the data to be verified and the Merkle path to the blockchain network.

[0076] Here, after the first Internet of Things device obtains the data to be verified and the Merkle path, the first Internet of Things device sends the data to be verified and the Merkle tree path to the blockchain network.

[0077] It should be understood that the complete structure of the Merkle tree is maintained in the Internet of Things database. After the blockchain network receives the Merkle path, it accesses the Internet of Things database according to the Merkle path to obtain the corresponding Merkle tree. This can avoid performance bottlenecks in the blockchain network and also facilitate data verification.

[0078] In step 130, the first Internet of Things device receives the verification result fed back by the blockchain network, where the verification result is the result obtained by the blockchain network verifying the reconstructed root node with the original root node of the Merkle tree stored on the blockchain in the blockchain network, and the reconstructed root node is the root node calculated by the blockchain network based on the data to be verified and the Merkle path.

[0079] Here, the first Internet of Things device receives the verification result fed back by the blockchain network. Among them, the verification result is the result obtained by the blockchain network verifying the reconstructed root node calculated according to the data to be verified and the Merkle path with the original root node corresponding to the Merkle path stored on the blockchain network.

[0080] For example, if the data to be verified A is the data generated by the Internet of Things device A at the time point "2121 / 6 / 30 16:42:55" in the time period [2121 / 6 / 30 16:42:50, 2121 / 6 / 30 17:42:50], then the first Internet of Things device sends the data to be verified A and the storage path of the Merkle tree corresponding to the Internet of Things device A in the time period [2121 / 6 / 30 16:42:50, 2121 / 6 / 30 17:42:50] stored in the Internet of Things data to the blockchain network. After receiving the data to be verified A and the corresponding Merkle path, the blockchain network obtains the hash values of each node of the Merkle tree stored in the Internet of Things database according to the Merkle path based on the smart contract, and then recalculates the root node based on the data to be verified A and the hash values of each node of the Merkle tree to obtain the reconstructed root node. As Figure 3 shown, when the data to be verified A is the data at the "D5" position, the hash value of the data to be verified A is used to replace the hash value of "D5", and the Merkle tree is reconstructed to obtain the reconstructed root node.

[0081] It should be understood that if the data of a leaf node in the Merkle tree is modified, the hash value corresponding to the leaf node will also change, resulting in a change in the finally calculated root node, thereby ensuring the authenticity of the data.

[0082] In step 140, the first Internet of Things device determines whether the data to be verified belongs to the Internet of Things data generated by the Internet of Things system according to the verification result.

[0083] Here, if the verification result indicates that the reconstructed root node is consistent with the original root node, it means that the data to be verified belongs to the IoT data generated by this IoT system and the data to be verified has not been tampered with. If the verification result indicates that the reconstructed root node is inconsistent with the original root node, it means that the data to be verified does not belong to the IoT data generated by this IoT system and the data to be verified has been tampered with.

[0084] Thus, through the cooperation of the off-chain IoT devices and the on-chain blockchain network to ensure the security of IoT data, the security protection ability of the IoT system can be greatly improved, ensuring the security and privacy of IoT data. At the same time, by using blockchain technology for data storage management, problems such as centralization and vulnerability to attack and tampering in the traditional data storage mode are solved, ensuring the rights confirmation, traceability and protection of relevant information in the data management process, and moreover, it can meet the high-concurrency application scenarios of IoT data.

[0085] Figure 4 is a flowchart of a data verification method shown according to another exemplary embodiment. As Figure 4 shown, this data verification method can be applied to a blockchain node in a blockchain network and includes the following steps.

[0086] In step 410, receive the data to be verified and the Merkle path sent by the first IoT device in the IoT system, where the data to be verified and the Merkle path are obtained by the first IoT device from the IoT database, and the Merkle path is the path of the Merkle tree constructed by the second IoT device based on the IoT data generated by the IoT device corresponding to the data to be verified.

[0087] Here, the blockchain network receives the data to be verified and the Merkle path sent by the first IoT device in the IoT system. It should be understood that the related concepts of the first IoT device, the data to be verified, and the Merkle path have been described in detail in the above embodiments and will not be elaborated here.

[0088] In step 420, based on the data to be verified and the Merkle path, calculate the reconstructed root node.

[0089] Here, after the blockchain network receives the data to be verified and the Merkle path, the blockchain node in the blockchain network, based on a pre-set smart contract, accesses the Merkle tree corresponding to the IoT database according to this Merkle path, and based on this data to be verified and the corresponding Merkle tree, reshapes the construction process of the Merkle tree based on the Merkle algorithm to obtain the reconstructed root node.

[0090] It should be understood that the specific calculation method of the reconstructed root node has been described in detail in the above embodiments and will not be elaborated here.

[0091] In step 430, the reconstructed root node is verified against the original root node corresponding to the Merkle tree stored on the blockchain network to obtain a verification result.

[0092] Here, the original root node corresponding to the Merkle tree stored on the blockchain network is verified against the reconstructed root node. If the reconstructed root node is consistent with the original root node, a verification result indicating that the data to be verified is legal is obtained. If the reconstructed root node is inconsistent with the original root node, a verification result indicating that the data to be verified is illegal is obtained.

[0093] Figure 5 is a flowchart showing the acquisition of the original root node according to an exemplary embodiment. As Figure 5 shown, in some implementable embodiments, the blockchain nodes in the blockchain network obtain the original root node through the following steps.

[0094] In step 510, the original root node sent by the second Internet of Things device is received, where the original root node is the root node of the Merkle tree constructed by the second Internet of Things device based on the Internet of Things data generated within a preset time period.

[0095] Here, after the second Internet of Things device calculates the Merkle tree, it stores the Merkle tree and the corresponding Internet of Things data in the Internet of Things database. At the same time, the second Internet of Things device uploads the original root node of the Merkle tree to the blockchain network.

[0096] It should be understood that the process of the second Internet of Things device constructing the Merkle tree has been described in detail in the above embodiments and will not be repeated here.

[0097] It is worth noting that the second Internet of Things device performs Merkle calculation on the Internet of Things data in the trusted execution environment based on the trusted computing service, which can ensure the authenticity of the data obtained in the off-chain part to avoid the data sent to the blockchain network for storage from being tampered with.

[0098] In step 520, the original root node is stored.

[0099] Here, it is the root node of the Merkle tree that is stored on the blockchain network, rather than the complete Merkle tree. For example, based on the IoT data generated by IoT device A during the time period "2121 / 6 / 30 16:42:50 - 2121 / 6 / 30 17:42:50", Merkle tree A is constructed, and then the root node of Merkle tree A is stored on the blockchain network. Among them, the root node of the Merkle tree can be stored on the blockchain network in the format of the IoT device number corresponding to the IoT data used to generate the Merkle tree and the time information. For example, the storage format can be "IoT device number---time period---root node". When verifying the reconstructed root node and the original root node, the blockchain network locates the corresponding original root node according to the timestamp of the data to be verified and the corresponding IoT device number.

[0100] In some embodiments, in step 510, receiving the original root node sent by the second IoT device may include:

[0101] Receiving the signed original root node sent by the second IoT device, where the signed original root node is obtained by the second IoT device digitally signing the original root node based on the private key of the second IoT device;

[0102] In step 520, storing the original root node may include:

[0103] Verifying the signature of the signed original root node based on the public key of the second IoT device;

[0104] Storing the original root node in the case where the signature verification passes.

[0105] Here, after the blockchain network receives the original root node digitally signed based on the private key of the second IoT device, it verifies the signature of the signed original root node based on the public key of the second IoT device, and stores the original root node in the case where the signature verification passes.

[0106] Among them, the blockchain network receives the registration information of the second Internet of Things device and generates a pair of public and private keys. Among them, the private key is stored in the second Internet of Things device, and the public key is stored in the blockchain network. When the second Internet of Things device uploads the original root node to the blockchain network, it digitally signs the original root node sent to the blockchain network with the private key stored in the second Internet of Things device. The blockchain network verifies the signed original root node with the corresponding public key stored. In the case where the verification passes, it indicates that the original root node has not been tampered with, and then stores the original root node on the blockchain network. In the case where the verification fails, it indicates that the original root node is illegal, and returns a result indicating that the original root node is illegal to the second Internet of Things device. It can ensure the security between off-chain and on-chain computations and avoid data tampering.

[0107] In step 440, the verification result is sent to the first Internet of Things device so that the first Internet of Things device determines whether the data to be verified belongs to the Internet of Things data generated by the Internet of Things system according to the verification result.

[0108] Here, the blockchain network can send the verification result to the first Internet of Things device through the communication module so that the first Internet of Things device determines whether the data to be verified is legal according to the verification result. Among them, if the verification result indicates that the reconstructed root node is consistent with the original root node, it means that the data to be verified belongs to the Internet of Things data generated by the Internet of Things system and the data to be verified has not been tampered with. If the verification result indicates that the reconstructed root node is inconsistent with the original root node, it means that the data to be verified does not belong to the Internet of Things data generated by the Internet of Things system and the data to be verified has been tampered with.

[0109] Thus, through the cooperation of the blockchain network in the on-chain part and the Internet of Things devices in the off-chain part to ensure the security of Internet of Things data, the security protection ability of the Internet of Things system can be greatly improved, and the security and privacy of Internet of Things data are guaranteed. At the same time, by using blockchain technology for data storage management, problems such as centralization and vulnerability to attack and tampering in the traditional data storage mode are solved, the confirmation of rights, traceability, and protection of relevant information in the data management process are guaranteed, and the high-concurrency application scenarios of Internet of Things data can be satisfied.

[0110] Figure 6 It is a flowchart of a data verification device shown according to an exemplary embodiment. As Figure 6 shown, the embodiments of the present disclosure provide a data verification device applied to an Internet of Things device in an Internet of Things system, including:

[0111] An acquisition module 601, configured to control a first Internet of Things device in the Internet of Things system to acquire data to be verified from an Internet of Things database and a Merkle path of the data to be verified stored in the Internet of Things database, where the Merkle path is a path of a Merkle tree constructed based on Internet of Things data generated by the Internet of Things system;

[0112] A first sending module 602, configured to control the first Internet of Things device to send the data to be verified and the Merkle path to a blockchain network;

[0113] A first receiving module 603, configured to control the first Internet of Things device to receive a verification result fed back by the blockchain network, where the verification result is a result obtained by the blockchain network verifying a reconstructed root node with an original root node of the Merkle tree stored on a blockchain in the blockchain network, and the reconstructed root node is a root node calculated by the blockchain network based on the data to be verified and the Merkle path;

[0114] A verification module 604, configured to control the first Internet of Things device to determine whether the data to be verified belongs to Internet of Things data generated by the Internet of Things system according to the verification result.

[0115] In some embodiments, the apparatus further includes:

[0116] A Merkle tree construction module, configured to control a second Internet of Things device in the Internet of Things system to construct a Merkle tree based on Internet of Things data generated within a preset duration, and obtain an original root node of the Merkle tree;

[0117] A third sending module, configured to control the second Internet of Things device to send the original root node to the blockchain network, so that the blockchain network stores the original root node on the blockchain;

[0118] A data storage module, configured to control the second Internet of Things device to store the Internet of Things data generated within the preset duration and the Merkle tree in the Internet of Things database.

[0119] In some embodiments, the third sending module includes:

[0120] A digital signature unit, configured to control the second Internet of Things device to perform digital signature on the original root node based on a private key of the second Internet of Things device, and obtain a signed original root node;

[0121] A data sending unit, configured to enable the second Internet of Things device to send the signed original root node to the blockchain network, so that the blockchain network verifies the signature of the signed original root node based on the public key of the second Internet of Things device, and stores the original root node when the signature verification passes.

[0122] In some embodiments, the Merkle tree is obtained by the second Internet of Things device performing Merkle calculation on the Internet of Things data in a trusted execution environment based on a trusted computing service.

[0123] Regarding the device in the above embodiments, the specific manners in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated herein.

[0124] Figure 7 It is a flowchart of a data verification device shown according to another exemplary embodiment. As Figure 7 shown, an embodiment of the present disclosure provides a data verification device, which is applied to a blockchain node in a blockchain network, and includes:

[0125] A second receiving module 801, configured to receive the data to be verified and the Merkle path sent by a first Internet of Things device in an Internet of Things system, where the data to be verified and the Merkle path are obtained by the first Internet of Things device from an Internet of Things database, and the Merkle path is a path of a Merkle tree constructed by a second Internet of Things device based on Internet of Things data generated by an Internet of Things device corresponding to the data to be verified;

[0126] A calculation module 802, configured to calculate a reconstructed root node based on the data to be verified and the Merkle path;

[0127] A second verification module 803, configured to verify the reconstructed root node with the original root node corresponding to the Merkle tree stored on the blockchain network to obtain a verification result;

[0128] A second sending module 804, configured to send the verification result to the first Internet of Things device, so that the first Internet of Things device determines whether the data to be verified belongs to Internet of Things data generated by the Internet of Things system according to the verification result.

[0129] In some embodiments, the device further includes:

[0130] A fourth receiving module, configured to receive the original root node sent by the second Internet of Things device, where the original root node is the root node of a Merkle tree constructed by the second Internet of Things device based on Internet of Things data generated within a preset time period;

[0131] A root node storage module, configured to store the original root node.

[0132] In some embodiments, the fourth receiving module includes:

[0133] An encryption unit, configured to receive the signed original root node sent by the second Internet of Things device, where the signed original root node is obtained by the second Internet of Things device performing digital signature on the original root node based on the private key of the second Internet of Things device;

[0134] The root node storage module includes:

[0135] A signature verification unit, configured to verify the signature of the signed original root node based on the public key of the second Internet of Things device;

[0136] A storage subunit, configured to store the original root node in the case where the signature verification passes.

[0137] Regarding the device in the above embodiments, the specific manners in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated here.

[0138] According to an embodiment of the present disclosure, there is provided an electronic device, including:

[0139] A memory, on which a computer program is stored;

[0140] A processor, configured to execute the computer program in the memory to implement the steps of the methods performed by the first Internet of Things device and the second Internet of Things device in the data verification method described in the above embodiments.

[0141] Figure 8 is a block diagram of an electronic device shown according to an exemplary embodiment. As Figure 8 shown, the electronic device 700 may include: a processor 701, a memory 702. The electronic device 700 may further include one or more of a multimedia component 703, an input / output (I / O) interface 704, and a communication component 705.

[0142] Among them, the processor 701 is used to control the overall operation of the electronic device 700 to complete all or part of the steps in the above data verification method. The memory 702 is used to store various types of data to support the operation of the electronic device 700. Such data may include, for example, instructions for any application or method operating on the electronic device 700, as well as application-related data, such as contact data, received and sent messages, pictures, audio, video, and so on. The memory 702 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk, or optical disc. The multimedia component 703 may include a screen and an audio component. The screen can be, for example, a touch screen, and the audio component is used to output and / or input audio signals. For example, the audio component may include a microphone for receiving external audio signals. The received audio signal can be further stored in the memory 702 or sent through the communication component 705. The audio component also includes at least one speaker for outputting audio signals. The I / O interface 704 provides an interface between the processor 701 and other interface modules, and the above other interface modules can be a keyboard, a mouse, buttons, etc. These buttons can be virtual buttons or physical buttons. The communication component 705 is used for wired or wireless communication between the electronic device 700 and other devices. Wireless communication, such as Wi-Fi, Bluetooth, near field communication (NFC), 2G, 3G, 4G, NB-IoT, eMTC, or other 5G, etc., or a combination of one or more of them, is not limited herein. Therefore, the corresponding communication component 705 may include: a Wi-Fi module, a Bluetooth module, an NFC module, and so on.

[0143] In an exemplary embodiment, the electronic device 700 may be implemented by one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components, and is used to execute the above data verification method.

[0144] In another exemplary embodiment, there is also provided a computer-readable storage medium including program instructions. When the program instructions are executed by a processor, the method steps performed by the first Internet of Things device and the second Internet of Things device in the above data verification method are implemented, or the steps of the above data verification method are implemented. For example, the computer-readable storage medium may be the above-mentioned memory 702 including program instructions, and the above program instructions may be executed by the processor 701 of the electronic device 700 to complete the above data verification method.

[0145] In another exemplary embodiment, there is also provided a blockchain node, including:

[0146] A memory storing a computer program thereon;

[0147] A processor configured to execute the computer program in the memory to perform the steps of the data verification method in the above embodiments.

[0148] The preferred embodiments of the present disclosure have been described in detail above in conjunction with the accompanying drawings. However, the present disclosure is not limited to the specific details in the above embodiments. Within the scope of the technical concept of the present disclosure, various simple modifications can be made to the technical solutions of the present disclosure, and these simple modifications all fall within the protection scope of the present disclosure.

[0149] In addition, it should be noted that, in the above specific embodiments, the various specific technical features described can be combined in any suitable manner without conflict. To avoid unnecessary repetition, the present disclosure does not separately describe various possible combination manners.

[0150] Furthermore, any combination can be made between various different embodiments of the present disclosure as long as it does not violate the idea of the present disclosure, and it should also be regarded as the content disclosed by the present disclosure.

Claims

1. A data verification method, characterized in that, An Internet of Things device applied to an Internet of Things system, including: The first Internet of Things device in the Internet of Things system obtains the data to be verified from the Internet of Things database, and the Merkle path of the data to be verified stored in the Internet of Things database, where the Merkle path is the path of the Merkle tree constructed based on the Internet of Things data generated by the Internet of Things system; The first Internet of Things device sends the data to be verified and the Merkle path to the blockchain network; The first Internet of Things device receives the verification result feedback by the blockchain network, where the verification result is the result obtained by the blockchain network verifying the reconstructed root node with the original root node of the Merkle tree stored on the blockchain in the blockchain network, and the reconstructed root node is the root node calculated by the blockchain network based on the data to be verified and the Merkle path; The first Internet of Things device determines whether the data to be verified belongs to the Internet of Things data generated by the Internet of Things system according to the verification result; The method further includes: The second Internet of Things device in the Internet of Things system constructs a Merkle tree based on the Internet of Things data generated within a preset duration to obtain the original root node of the Merkle tree; The second Internet of Things device sends the original root node to the blockchain network so that the blockchain network stores the original root node on the blockchain; and The second Internet of Things device stores the Internet of Things data generated within the preset duration and the Merkle tree in the Internet of Things database.

2. The data verification method according to claim 1, wherein The second Internet of Things device sending the original root node to the blockchain network includes: The second Internet of Things device digitally signs the original root node based on the private key of the second Internet of Things device to obtain the signed original root node; The second Internet of Things device sends the signed original root node to the blockchain network so that the blockchain network verifies the signed original root node based on the public key of the second Internet of Things device and stores the original root node when the verification passes.

3. The data verification method according to claim 1 or 2, characterized in that The Merkle tree is obtained by the second Internet of Things device performing Merkle calculation on the Internet of Things data in a trusted execution environment based on a trusted computing service.

4. A data verification method, characterized in that, A blockchain node applied to a blockchain network, including: Receive the data to be verified and the Merkle path sent by the first Internet of Things device in the Internet of Things system. The data to be verified and the Merkle path are obtained by the first Internet of Things device from the Internet of Things database, and the Merkle path is the path of the Merkle tree constructed by the second Internet of Things device based on the Internet of Things data generated by the Internet of Things device corresponding to the data to be verified. The second Internet of Things device constructs a Merkle tree based on the Internet of Things data generated within a preset duration, obtains the original root node of the Merkle tree, and the second Internet of Things device sends the original root node to the blockchain network so that the blockchain network stores the original root node on the blockchain, and the second Internet of Things device stores the Internet of Things data generated within the preset duration and the Merkle tree in the Internet of Things database; Calculate a reconstructed root node based on the data to be verified and the Merkle path; Verify the reconstructed root node with the original root node of the corresponding Merkle tree stored on the blockchain network to obtain a verification result; Send the verification result to the first Internet of Things device so that the first Internet of Things device determines whether the data to be verified belongs to the Internet of Things data generated by the Internet of Things system according to the verification result.

5. The data verification method according to claim 4, wherein The receiving the original root node sent by the second Internet of Things device includes: Receive the signed original root node sent by the second Internet of Things device, where the signed original root node is obtained by the second Internet of Things device digitally signing the original root node based on the private key of the second Internet of Things device; The storing the original root node includes: Verify the signature of the signed original root node based on the public key of the second Internet of Things device; Store the original root node when the signature verification passes.

6. A data verification device, characterized in that, Applied to the Internet of Things device in the Internet of Things system, it includes: An acquisition module configured to control the first Internet of Things device in the Internet of Things system to obtain the data to be verified from the Internet of Things database and the Merkle path of the data to be verified stored in the Internet of Things database, where the Merkle path is the path of the Merkle tree constructed based on the Internet of Things data generated by the Internet of Things system; A first sending module configured to control the first Internet of Things device to send the data to be verified and the Merkle path to the blockchain network; A first receiving module configured to control the first Internet of Things device to receive the verification result fed back by the blockchain network, where the verification result is the result obtained by the blockchain network verifying the reconstructed root node with the original root node of the Merkle tree stored on the blockchain in the blockchain network, and the reconstructed root node is the root node calculated by the blockchain network based on the data to be verified and the Merkle path; A verification module configured to control the first Internet of Things device to determine whether the data to be verified belongs to the Internet of Things data generated by the Internet of Things system according to the verification result; The device further includes: A Merkle tree construction module, configured to construct a Merkle tree by a second Internet of Things device in the Internet of Things system according to Internet of Things data generated within a preset duration, and obtain an original root node of the Merkle tree; A third sending module, configured to send the original root node by the second Internet of Things device to the blockchain network, so that the blockchain network stores the original root node on the blockchain; A data storage module, configured to store the Internet of Things data generated within the preset duration and the Merkle tree by the second Internet of Things device in the Internet of Things database.

7. A data verification device, characterized in that, Applied to a blockchain node in a blockchain network, including: A second receiving module, configured to receive data to be verified and a Merkle path sent by a first Internet of Things device in the Internet of Things system, wherein the data to be verified and the Merkle path are obtained by the first Internet of Things device from the Internet of Things database, and the Merkle path is a path of a Merkle tree constructed by the second Internet of Things device based on Internet of Things data generated by the Internet of Things device corresponding to the data to be verified; the second Internet of Things device constructs a Merkle tree according to Internet of Things data generated within a preset duration, obtains an original root node of the Merkle tree, the second Internet of Things device sends the original root node to the blockchain network, so that the blockchain network stores the original root node on the blockchain, and the second Internet of Things device stores the Internet of Things data generated within the preset duration and the Merkle tree in the Internet of Things database; A calculation module, configured to calculate and obtain a reconstructed root node based on the data to be verified and the Merkle path; A second verification module, configured to verify the reconstructed root node with the original root node of the corresponding Merkle tree stored on the blockchain network to obtain a verification result; A second sending module, configured to send the verification result to the first Internet of Things device, so that the first Internet of Things device determines whether the data to be verified belongs to Internet of Things data generated by the Internet of Things system according to the verification result.

8. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, it implements the method steps executed by the first Internet of Things device and the second Internet of Things device in the data verification method described in any one of claims 1-3, or implements the steps of the data verification method described in any one of claims 4-5.

9. An electronic device, characterized in that, Including: A memory, on which a computer program is stored; A processor, configured to execute the computer program in the memory to implement the steps of the method executed by the first Internet of Things device and the second Internet of Things device in the data verification method described in any one of claims 1-3.

10. A blockchain node, characterized in that, Including: A memory, on which a computer program is stored; A processor, configured to execute the computer program in the memory to implement the steps of the data verification method described in any one of claims 4-5.

Citation Information

Patent Citations

  • Block chain privacy protection method, device and system

    CN106899412A

  • Verification method and device applied to block chain

    CN110351297A