Internet of Things data access method and device based on blockchain
By using blockchain smart contracts in IoT devices for data access management, the problem of data access permission management in IoT devices during the dynamic life cycle is solved, and a more secure and transparent data access process is achieved.
Patent Information
- Application Number
- CN202110263970.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-03-08
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2041-03-08
AI Technical Summary
In the dynamic and diverse life cycle of IoT devices, existing centralized access control systems have difficulty effectively managing their data access rights, especially when devices are mobile or managed by different organizations.
Data access management is managed through blockchain-based smart contracts, data visitors are authenticated through blockchain smart contracts, data access tokens are generated and verified, and data is obtained from resource servers based on permissions.
It improves the security of the IoT data access process, ensures the transparency and traceability of data access, and adapts to the dynamics and diversity of IoT devices.
Smart Images

Figure CN113792301B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of computer technology, and specifically to a blockchain-based Internet of Things data access method and device. Background Art
[0002] The IoT is envisioned as a ubiquitous computing service that digitizes and interconnects the real world to achieve intelligent identification and management. Data plays a central role in the transformation of digitization and interconnection, involving data connection, computing, and control. Both network strategies and business strategies are determined based on the information provided by data. Centralized access control systems are designed for traditional Internet scenarios, and IoT devices require centralized access management within the same trust domain. However, in some scenarios, IoT devices may be mobile and highly dynamic. There may be stages in the life cycle of IoT devices where they are unmanaged, self-managed, or managed by different organizations. Summary of the invention
[0003] The embodiments of the present application propose a method and device for accessing IoT data based on blockchain.
[0004] In a first aspect, an embodiment of the present application provides a blockchain-based IoT data access method, comprising: authenticating a first access request issued by a data accessor through a smart contract of the blockchain, and determining a data access token corresponding to the data accessor, so that the data accessor can request data from a resource server according to the data access token within the validity period of the data access token; receiving a second access request carrying the data access token issued by the data accessor, and verifying the data access token through a smart contract; in response to successful verification, determining the data accessor's request data from the resource server based on the permissions set for the data accessor by the smart contract.
[0005] In some embodiments, the above method further includes: multiple encryption of the data based on public keys in multiple asymmetric key pairs corresponding to multiple objects associated with the data in the resource server.
[0006] In some embodiments, in response to successful verification, based on the permissions set for the data accessor by the smart contract, determining the request data of the data accessor from the resource server includes: in response to successful verification, determining the private key of multiple asymmetric key pairs corresponding to the request data according to the permissions set for the data accessor by the smart contract; and decrypting the encrypted request data in the resource server based on the private key to obtain the decrypted request data.
[0007] In some embodiments, the above-mentioned authentication of the first access request issued by the data accessor through the smart contract of the blockchain and determining the data access token corresponding to the data accessor include: formatting the first access request through the management center corresponding to the data accessor to obtain the converted access request; establishing a communication connection between the management center and the proxy node, so that the proxy node calls the smart contract of the blockchain, authenticates the first access request, and determines the permissions set for the data accessor; and determining the data access token according to the permissions through the management center.
[0008] In some embodiments, the above method also includes: tracing the operations of data accessors based on the recording function of the blockchain.
[0009] In the second aspect, an embodiment of the present application provides an Internet of Things data access device based on blockchain, including: a first determination unit, configured to authenticate a first access request issued by a data accessor through a smart contract of the blockchain, and determine a data access token corresponding to the data accessor, so that the data accessor can request data from a resource server according to the data access token within the validity period of the data access token; a verification unit, configured to receive a second access request carrying the data access token issued by the data accessor, and verify the data access token through a smart contract; a second determination unit, configured to determine the requested data of the data accessor from the resource server in response to the verification being passed, based on the permissions set for the data accessor by the smart contract.
[0010] In some embodiments, the apparatus further comprises: an encryption unit configured to perform multiple encryption on the data based on public keys in multiple asymmetric key pairs corresponding to multiple objects associated with the data in the resource server.
[0011] In some embodiments, the second determination unit is further configured to: in response to passing the verification, determine the private key in multiple asymmetric key pairs corresponding to the request data according to the permission setting of the data accessor by the smart contract; decrypt the encrypted request data in the resource server based on the private key to obtain the decrypted request data.
[0012] In some embodiments, the first determination unit is further configured to: convert the format of the first access request through the management center corresponding to the data accessor to obtain a converted access request; establish a communication connection between the management center and the proxy node, so that the proxy node calls the smart contract of the blockchain, authenticates the first access request, and determines the permissions set for the data accessor; and determines the data access token according to the permissions through the management center.
[0013] In some embodiments, the above-mentioned device also includes: a traceability unit, which is configured to trace the operations of the data accessor based on the recording function of the blockchain.
[0014] In a third aspect, an embodiment of the present application provides a computer-readable medium having a computer program stored thereon, wherein when the program is executed by a processor, the method described in any implementation manner of the first aspect is implemented.
[0015] In a fourth aspect, an embodiment of the present application provides an electronic device, comprising: one or more processors; a storage device on which one or more programs are stored, and when the one or more programs are executed by one or more processors, the one or more processors implement the method described in any implementation manner of the first aspect.
[0016] The blockchain-based IoT data access method and device provided in the embodiment of the present application authenticates a first access request issued by a data accessor through a blockchain smart contract, determines a data access token corresponding to the data accessor, so that the data accessor can request data from a resource server according to the data access token within the validity period of the data access token; receives a second access request carrying the data access token issued by the data accessor, and verifies the data access token through a smart contract; in response to successful verification, determines the request data of the data accessor from the resource server based on the permissions set for the data accessor by the smart contract, thereby providing a blockchain-based IoT data access method and improving the security of the data access process. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Other features, objects and advantages of the present application will become more apparent by reading the detailed description of non-limiting embodiments made with reference to the following drawings:
[0018] Figure 1 is an exemplary system architecture diagram in which an embodiment of the present application may be applied;
[0019] Figure 2 It is a flowchart of an embodiment of a blockchain-based IoT data access method according to the present application;
[0020] Figure 3 is a schematic diagram of an application scenario of the blockchain-based IoT data access method according to this embodiment;
[0021] Figure 4 is a flowchart of another embodiment of the blockchain-based IoT data access method according to the present application;
[0022] Figure 5 It is a structural diagram of an embodiment of a blockchain-based IoT data access device according to the present application;
[0023] Figure 6 It is a structural diagram of a computer system suitable for implementing the embodiments of the present application. DETAILED DESCRIPTION
[0024] The present application will be further described in detail below in conjunction with the accompanying drawings and embodiments. It is to be understood that the specific embodiments described herein are only used to explain the relevant invention, rather than to limit the invention. It should also be noted that, for ease of description, only the parts related to the relevant invention are shown in the accompanying drawings.
[0025] It should be noted that, in the absence of conflict, the embodiments and features in the embodiments of the present application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0026] Figure 1 An exemplary architecture 100 to which the blockchain-based IoT data access method and device of the present application can be applied is shown.
[0027] like Figure 1 As shown, the system architecture 100 may include IoT devices 101, 102, 103, a network 104, and a server 105. The IoT devices 101, 102, 103 are connected to form a topological network, and the network 104 is used to provide a medium for the communication link between the IoT devices 101, 102, 103 and the server 105. The network 104 may include various connection types, such as wired, wireless communication links, or optical fiber cables, etc.
[0028] The IoT devices 101, 102, 103 may be hardware devices or software that support network connection for data interaction and data processing. When the IoT devices 101, 102, 103 are hardware, they may be various electronic devices that support network connection, information acquisition, interaction, display, processing and other functions, including but not limited to smart home devices, smart wearable devices, etc. When the IoT devices 101, 102, 103 are software, they may be installed in the electronic devices listed above. It may be implemented as multiple software or software modules for providing distributed services, or it may be implemented as a single software or software module. No specific limitation is made here.
[0029] The server 105 may be a server that provides various services, such as a background processing server that verifies the authority of a data accessor to access the IoT data collected by the IoT devices 101, 102, 103, and a resource server that stores the IoT data collected by the IoT devices 101, 102, 103. As an example, the server 105 may be a cloud server.
[0030] It should be noted that the server can be hardware or software. When the server is hardware, it can be implemented as a distributed server cluster consisting of multiple servers, or it can be implemented as a single server. When the server is software, it can be implemented as multiple software or software modules (for example, software or software modules used to provide distributed services), or it can be implemented as a single software or software module. No specific limitation is made here.
[0031] It should also be noted that the blockchain-based IoT data access method provided by the embodiments of the present disclosure can be executed by a server, or by a server and an IoT device in cooperation with each other. Accordingly, the various parts (such as various units) included in the blockchain-based IoT data access device can be all set in the server, or can be set in the server and the IoT device respectively.
[0032] It should be understood that Figure 1 The number of IoT devices, networks, and servers in the example is merely illustrative. Any number of IoT devices, networks, and servers may be provided as required. When the electronic device on which the blockchain-based IoT data access method is running does not need to perform data transmission with other electronic devices, the system architecture may only include the electronic device (e.g., server or IoT device) on which the blockchain-based IoT data access method is running.
[0033] Continue to refer Figure 2 , a process 200 of an embodiment of a blockchain-based IoT data access method is shown, comprising the following steps:
[0034] Step 201, authenticate the first access request issued by the data accessor through the smart contract of the blockchain, and determine the data access token corresponding to the data accessor, so that the data accessor can request data from the resource server according to the data access token within the validity period of the data access token.
[0035] In this embodiment, the execution subject of the blockchain-based IoT data access method (for example Figure 1 The server in the data accessor can authenticate the first access request issued by the data accessor through the smart contract of the blockchain, and determine the data access token corresponding to the data accessor, so that the data accessor can request data from the resource server according to the data access token within the validity period of the data access token.
[0036] Blockchain is a distributed shared ledger and database with the characteristics of decentralization, immutability, full traceability, traceability, collective maintenance, openness and transparency. This embodiment applies blockchain technology to the field of the Internet of Things to combine the above-mentioned characteristics of blockchain with the access process of IoT data. Blockchain includes public blockchain, alliance blockchain and private blockchain. This embodiment can use an alliance blockchain, which can only be written by specific permission nodes (for example, IoT devices), but can be read by anyone.
[0037] A smart contract is a computer protocol designed to disseminate, verify or execute contracts in an information-based manner. Smart contracts in blockchain are unique in that the rules are open and transparent, all transactions are publicly visible, and there are no false or hidden transactions. This ensures that when transactions are written to the blockchain in digital form, the entire process of storage, reading and execution is transparent, traceable and tamper-proof. Therefore, the permissions and operations of all data accessors to access data can be defined in smart contracts and triggered through transactions on the blockchain. Once an operation in a smart contract is triggered, the blockchain node will maintain accessibility to the transaction information, which means that the smart contract and its operations can also be accessed.
[0038] Data accessors can be IoT devices, service providers or third parties. IoT devices are communication network devices that are designed to sense, collect and process information about objects within their network coverage area. Resources such as CPU (central processing unit), memory and battery in IoT devices are generally limited.
[0039] Service providers are entities responsible for collecting and managing data collected by IoT devices and implementing business-related operating rules under the GDPR (General Data Protection Regulation). In general, service providers play the roles of both data controller and data processor. Service providers store data collected by IoT devices in resource servers.
[0040] In order to accurately identify IoT devices in the IoT, it is necessary to provide a globally unique identifier for all IoT devices. As an example, a public key generator can generate a unique random number similar to a unique identifier, so the public key generated by the public key generator for the IoT device can be used as the unique identifier of the IoT device. This means that through the current IoT encryption technology, a public key can be provided for each IoT device to provide a unique identification by enforcing an encrypted connection.
[0041] It should be noted that, in this embodiment, the IoT data collected by the IoT device is not stored in the blockchain, but in the resource server. The blockchain stores data pointers corresponding to the data in the resource server.
[0042] Data pointers are stored on the blockchain in the form of strings, hash values corresponding to the data, identifiers of referenced data sets, or absolute paths. The specific form depends on the resource server used. As an example, the resource server can be deployed with a decentralized storage system, a cloud storage service system, and a traditional DBMS (Database Management System). Among them, the decentralized storage system is, for example, IPFS (InterPlanetary File System) or Storj. The DBMS can be, for example, Oracle or MongoDB.
[0043] In this embodiment, the above-mentioned execution entity can determine the token corresponding to the set permissions based on the permissions set for the data accessor in the smart contract, and grant the token to the data accessor, so that within the validity period of the token, subsequent data access requests can directly carry the token to request data from the resource server.
[0044] In this embodiment, the system architecture applicable to the above-mentioned blockchain-based IoT data access method may include a management center and proxy nodes in addition to the above-mentioned blockchain, smart contracts, IoT devices, service providers, and third parties.
[0045] The computing power and energy utilization of most IoT devices are very limited, and they cannot save a complete copy of the blockchain, and they cannot become part of the blockchain network. Therefore, in this embodiment, a management hub is added to the system architecture, which converts access requests encoded in CoAP (Constrained Application Protocol) format into JSON RPC format for use by the proxy nodes of the blockchain directly connected to it. IoT devices in multiple IoT networks can be directly connected to a management hub, and the IoT devices can only request data access permissions from the blockchain through the management hub. Among them, the correspondence between the IoT network and the management center can be pre-set so that the IoT devices in the IoT network can determine the corresponding management hub. The management hub has relatively sufficient computing and storage resources. In the current centralized IoT system, it can be a cloud server or a fog node, which has high performance characteristics to accommodate as many concurrent requests as possible.
[0046] In simple scenarios, any IoT device can directly connect to and access the blockchain platform without authentication. However, in most scenarios, access control is required. At this time, the IoT device can only connect to its corresponding management hub. Once a new IoT device joins the blockchain platform, the management hub can obtain the credentials of the IoT device, and the IoT device will also obtain the location of the management hub node, thereby establishing a connection between the IoT device and the management hub.
[0047] The proxy node is responsible for deploying smart contracts in the blockchain platform. During the life cycle of the proxy node, the proxy node can call the smart contract in the blockchain platform. As long as the IoT device joins the blockchain network through the proxy node, the address of the smart contract will be broadcasted, and data interaction can be carried out based on the smart contract.
[0048] Specifically, for the case where the data accessor is an IoT device, the execution subject may perform step 201 in the following manner:
[0049] First, the management center corresponding to the data accessor performs format conversion on the first access request to obtain a converted access request.
[0050] Second, establish a communication connection between the management center and the proxy node so that the proxy node can call the smart contract of the blockchain, authenticate the first access request, and determine the permissions set for the data accessor.
[0051] As an example, the management hub can establish a communication connection with the proxy node closest to the management hub, so that the proxy node calls the smart contract of the blockchain, authenticates the first access request, and determines the permissions set for the data accessor.
[0052] Third, through the management hub, determine the data access token based on permissions.
[0053] Among them, the permissions of the data accessor correspond to the access token.
[0054] Step 202: Receive a second access request carrying a data access token from a data accessor, and verify the data access token through a smart contract.
[0055] In this embodiment, the above-mentioned execution entity can receive a second access request carrying a data access token issued by a data accessor, and verify the data access token through a smart contract.
[0056] After obtaining the access token based on the first access request, within the validity period of the access token, the data accessor can request data in the resource server based on the second access request carrying the access token. After receiving the second access request, the resource server can send a verification request to the blockchain to verify the access token and feedback the verification result to the resource server.
[0057] Step 203, in response to the verification being successful, based on the permissions set for the data accessor by the smart contract, the request data of the data accessor is determined from the resource server.
[0058] In this embodiment, the above-mentioned execution entity can determine the request data of the data accessor from the resource server in response to the verification being passed based on the permissions set for the data accessor by the smart contract.
[0059] As an example, when the permission representation corresponding to the access token has the access right to the data, the request data requested by the data accessor in the resource server can be fed back to the data accessor.
[0060] In some optional implementations of this embodiment, the execution subject may perform multiple encryption on the data based on public keys in multiple asymmetric key pairs corresponding to multiple objects associated with the data in the resource server.
[0061] The above-mentioned multiple objects can be specifically set according to actual conditions. As an example, the multiple objects include: data accessor, data itself and data pointer. For each piece of data in the resource server, the data can be triple-encrypted by the public key in the asymmetric key pair corresponding to the data accessor, the data itself and the data pointer.
[0062] As an example, for each piece of data in the resource server, a data identity is set for it. For example, the data identity is composed of the asymmetric key of the data pointer, the asymmetric key of the data itself, and the asymmetric key of the data accessor. For another example, the data accessor can be further divided into data controllers and data processors according to their authority over the data. Then the data identity is composed of the asymmetric key of the data pointer, the asymmetric key of the data itself, the asymmetric key of the data controller, and the asymmetric key of the data processor.
[0063] Among them, the data identity of the data can be generated and managed through the digital signature algorithm. The digital signature algorithm is represented as a probabilistic polynomial time algorithm (G, S, V), where G represents the key generator of the asymmetric key pair (pk, sk), where pk is the public key and sk is the private key; S represents the signature algorithm that takes the message x and the private key sk as input and generates t = S (sk, x) as output; V represents the signature verification algorithm that takes t, x, and pk as input and outputs the verification result as rejection or acceptance. Among them, for all (pk, sk) and x, V (S (sk, x), x, pk) = Accept. When the data accessor has the control and processing authority of the requested data, he can obtain the corresponding private key, decrypt it through the private key based on the data signature verification algorithm, and obtain the decrypted request data.
[0064] Specifically, the execution subject may execute step 203 in the following manner:
[0065] First, in response to passing the verification, according to the permission setting of the smart contract for the data accessor, a private key in a plurality of asymmetric key pairs corresponding to the requested data is determined.
[0066] Continuing with the example of multiple objects associated with the above data including: data accessor, data itself and data pointer, the private key is the private key in the asymmetric key pair corresponding to the data accessor, data itself and data pointer. It can be understood that the public key and private key in the asymmetric key pair are one-to-one corresponding, and the data encrypted by the public key can only be decrypted by the private key corresponding to the public key.
[0067] Second, the encrypted request data in the resource server is decrypted based on the private key to obtain the decrypted request data.
[0068] In this implementation, multiple private keys in multiple asymmetric key pairs corresponding to multiple objects must be used to decrypt the multiply encrypted request data.
[0069] Continue to see Figure 3 , Figure 3 FIG3 is a schematic diagram 300 of an application scenario of the blockchain-based IoT data access method according to this embodiment. Figure 3In the application scenario, the data accessor 301 sends a first access request to the blockchain platform 302. The blockchain platform 302 authenticates the first access request issued by the data accessor 301 through the smart contract, and determines the data access token corresponding to the data accessor, so that the data accessor 301 can request data from the resource server 303 according to the data access token within the validity period of the data access token. Then, the data accessor 301 sends a second access request carrying the data access token to the resource server 303. The resource server 303 receives the second access request carrying the data access token issued by the data accessor 301, and sends a token verification request to the blockchain platform 302. The blockchain platform verifies the data access token through the smart contract and feeds back the verification result to the resource server 303. In response to the verification being passed, based on the permissions set for the data accessor 301 by the smart contract, the request data requested by the data accessor 301 in the resource server 303 is fed back to the data accessor 301.
[0070] The method provided by the above-mentioned embodiments of the present disclosure authenticates a first access request issued by a data accessor through a smart contract of a blockchain, determines a data access token corresponding to the data accessor, so that the data accessor can request data from a resource server according to the data access token within the validity period of the data access token; receives a second access request carrying the data access token issued by the data accessor, and verifies the data access token through a smart contract; in response to successful verification, determines the request data of the data accessor from the resource server based on the permissions set for the data accessor by the smart contract, thereby providing an IoT data access method based on blockchain and improving the security of the data access process.
[0071] In some optional implementations of this embodiment, the above-mentioned execution entity can also trace the operations of the data accessor based on the recording function of the blockchain.
[0072] Continue to refer Figure 4 , shows a schematic process 400 of an embodiment of a blockchain-based IoT data access method according to the present application, comprising the following steps:
[0073] Step 401, authenticate the first access request issued by the data accessor through the smart contract of the blockchain, and determine the data access token corresponding to the data accessor, so that the data accessor can request data from the resource server according to the data access token within the validity period of the data access token.
[0074] The data is encrypted multiple times based on public keys in multiple asymmetric key pairs corresponding to multiple objects associated with the data in the resource server.
[0075] Step 402: Receive a second access request carrying a data access token from a data accessor, and verify the data access token through a smart contract.
[0076] Step 403, in response to passing the verification, according to the permission setting of the smart contract for the data accessor, determine the private key of the multiple asymmetric key pairs corresponding to the requested data.
[0077] Step 404: decrypt the encrypted request data in the resource server based on the private key to obtain the decrypted request data.
[0078] It can be seen from this embodiment that Figure 2 Compared with the corresponding embodiments, the process 400 of the blockchain-based IoT data access method in this embodiment specifically describes the encryption and decryption process of data, further improving the security of IoT data.
[0079] Continue to refer Figure 5 As an implementation of the methods shown in the above figures, the present disclosure provides an embodiment of an IoT data access device based on blockchain. Figure 2 Corresponding to the method embodiment shown, the device can be specifically applied to various electronic devices.
[0080] like Figure 5 As shown, the blockchain-based IoT data access device includes: a first determination unit 501, configured to authenticate a first access request issued by a data accessor through a smart contract of the blockchain, and determine a data access token corresponding to the data accessor, so that the data accessor can request data from a resource server according to the data access token within the validity period of the data access token; a verification unit 502, configured to receive a second access request carrying the data access token issued by the data accessor, and verify the data access token through a smart contract; a second determination unit 503, configured to determine the requested data of the data accessor from the resource server in response to the verification being passed, based on the permissions set for the data accessor by the smart contract.
[0081] In some embodiments, the apparatus further includes: an encryption unit (not shown in the figure), configured to perform multiple encryption on the data based on public keys in multiple asymmetric key pairs corresponding to multiple objects associated with the data in the resource server.
[0082] In some embodiments, the second determination unit 503 is further configured to: in response to passing the verification, determine the private key in multiple asymmetric key pairs corresponding to the request data according to the permission setting of the smart contract for the data accessor; decrypt the encrypted request data in the resource server based on the private key to obtain the decrypted request data.
[0083] In some embodiments, the first determination unit 501 is further configured to: convert the format of the first access request through the management center corresponding to the data accessor to obtain the converted access request; establish a communication connection between the management center and the agent node, so that the agent node calls the smart contract of the blockchain, authenticates the first access request, and determines the permissions set for the data accessor; and determines the data access token according to the permissions through the management center.
[0084] In some embodiments, the above-mentioned device also includes: a traceability unit (not shown in the figure), which is configured to trace the operations of the data accessor based on the recording function of the blockchain.
[0085] In this embodiment, the first determination unit in the blockchain-based Internet of Things data access device authenticates the first access request issued by the data accessor through the blockchain's smart contract, and determines the data access token corresponding to the data accessor, so that the data accessor can request data from the resource server according to the data access token within the validity period of the data access token; the verification unit receives the second access request carrying the data access token issued by the data accessor, and verifies the data access token through the smart contract; the second determination unit responds to the verification success, and determines the request data of the data accessor from the resource server based on the permissions set for the data accessor by the smart contract, thereby providing a blockchain-based Internet of Things data access device and improving the security of the data access process.
[0086] Reference below Figure 6 , which shows a device suitable for implementing the embodiments of the present application (eg Figure 1 Schematic diagram of the structure of a computer system 600 of the devices 101, 102, 103, 105 shown. Figure 6 The device shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.
[0087] like Figure 6 As shown, the computer system 600 includes a processor (e.g., CPU, central processing unit) 601, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage part 608 into a random access memory (RAM) 603. Various programs and data required for the operation of the system 600 are also stored in the RAM 603. The processor 601, the ROM 602, and the RAM 603 are connected to each other via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0088] The following components are connected to the I / O interface 605: an input section 606 including a keyboard, a mouse, etc.; an output section 607 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 608 including a hard disk, etc.; and a communication section 609 including a network interface card such as a LAN card, a modem, etc. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the I / O interface 605 as needed. A removable medium 611, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 610 as needed, so that a computer program read therefrom is installed into the storage section 608 as needed.
[0089] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through the communication part 609, and / or installed from a removable medium 611. When the computer program is executed by the processor 601, the above-mentioned functions defined in the method of the present application are executed.
[0090] It should be noted that the computer-readable medium of the present application may be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution system, device or device. In the present application, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries a computer-readable program code. This propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, which may send, propagate or transmit a program for use by or in conjunction with an instruction execution system, apparatus or device. The program code contained on the computer-readable medium may be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.
[0091] Computer program code for performing the operations of the present application may be written in one or more programming languages or a combination thereof, including object-oriented programming languages, such as Java, Smalltalk, C++, and conventional procedural programming languages, such as "C" or similar programming languages. The program code may be executed entirely on the client computer, partially on the client computer, as a separate software package, partially on the client computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the client computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0092] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the device, method and computer program product according to various embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0093] The units involved in the embodiments described in the present application may be implemented by software or by hardware. The described units may also be set in a processor, for example, may be described as: a processor comprising a first determination unit, a verification unit, and a second determination unit. Among them, the names of these units do not constitute a limitation on the unit itself under certain circumstances. For example, the first determination unit may also be described as "a unit that authenticates the first access request issued by the data accessor through the smart contract of the blockchain, determines the data access token corresponding to the data accessor, so that the data accessor can request data from the resource server according to the data access token within the validity period of the data access token."
[0094] As another aspect, the present application also provides a computer-readable medium, which may be included in the device described in the above embodiment; or it may exist independently without being assembled into the device. The above computer-readable medium carries one or more programs. When the above one or more programs are executed by the device, the computer device: authenticates the first access request issued by the data accessor through the smart contract of the blockchain, determines the data access token corresponding to the data accessor, so that the data accessor requests data from the resource server according to the data access token within the validity period of the data access token; receives the second access request issued by the data accessor carrying the data access token, and verifies the data access token through the smart contract; in response to the verification being passed, determines the request data of the data accessor from the resource server based on the permissions set for the data accessor by the smart contract.
[0095] The above description is only a preferred embodiment of the present application and an explanation of the technical principles used. Those skilled in the art should understand that the scope of the invention involved in the present application is not limited to the technical solution formed by a specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above invention concept. For example, the above features are replaced with the technical features with similar functions disclosed in this application (but not limited to) by each other to form a technical solution.
Claims
1. A blockchain-based IoT data access method, comprising: Authenticating a first access request issued by a data accessor through a smart contract of the blockchain, and determining a data access token corresponding to the data accessor, so that the data accessor can request data from a resource server according to the data access token within the validity period of the data access token; Receiving a second access request carrying the data access token sent by the data accessor, and verifying the data access token through the smart contract; In response to the verification being passed, determining the request data of the data accessor from the resource server based on the authority set by the smart contract for the data accessor; The step of authenticating the first access request issued by the data accessor through the smart contract of the blockchain and determining the data access token corresponding to the data accessor includes: Performing format conversion on the first access request by the management center corresponding to the data accessor to obtain a converted access request; Establishing a communication connection between the management center and the proxy node, so that the proxy node calls the smart contract of the blockchain, authenticates the converted access request, and determines the authority set for the data accessor; The data access token is determined according to the authority through the management hub.
2. The method according to claim 1, further comprising: The data is multiply encrypted based on public keys in multiple asymmetric key pairs corresponding to multiple objects associated with the data in the resource server.
3. The method according to claim 2, wherein: In response to the verification being successful, determining the request data of the data accessor from the resource server based on the authority set for the data accessor by the smart contract includes: In response to passing the verification, determining a private key in a plurality of asymmetric key pairs corresponding to the requested data according to the permission setting of the smart contract for the data accessor; The encrypted request data in the resource server is decrypted based on the private key to obtain the decrypted request data.
4. The method according to claim 1, further comprising: Based on the recording function of the blockchain, the operations of the data accessor are traced.
5. A blockchain-based IoT data access device, comprising: A first determining unit is configured to authenticate a first access request issued by a data accessor through a smart contract of a blockchain, and determine a data access token corresponding to the data accessor, so that the data accessor requests data from a resource server according to the data access token within a validity period of the data access token; a verification unit, configured to receive a second access request carrying the data access token issued by the data accessor, and verify the data access token through the smart contract; A second determination unit is configured to determine the request data of the data accessor from the resource server based on the authority set by the smart contract for the data accessor in response to the verification being passed; Wherein, the first determining unit is further configured to: The management center corresponding to the data accessor performs format conversion on the first access request to obtain a converted access request; a communication connection is established between the management center and the proxy node, so that the proxy node calls the smart contract of the blockchain, authenticates the converted access request, and determines the authority set for the data accessor; The data access token is determined according to the authority through the management hub.
6. The apparatus according to claim 5, further comprising: The encryption unit is configured to perform multiple encryption on the data based on public keys in multiple asymmetric key pairs corresponding to multiple objects associated with the data in the resource server.
7. The device according to claim 6, wherein: The second determining unit is further configured to: In response to passing the verification, according to the permission setting of the smart contract for the data accessor, a private key in a plurality of asymmetric key pairs corresponding to the request data is determined; based on the private key, the encrypted request data in the resource server is decrypted to obtain the decrypted request data.
8. The apparatus according to claim 5, further comprising: The traceability unit is configured to trace the operation of the data accessor based on the recording function of the blockchain.
9. A computer readable medium having a computer program stored thereon, wherein: When the program is executed by a processor, the method according to any one of claims 1 to 4 is implemented.
10. An electronic device comprising: one or more processors; a storage device having one or more programs stored thereon, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Blockchain-based data authority control method and device and computer equipment
CN111767527A
Medical information attribute encryption access control method based on block chain
CN111901302A