Data security calculation method, system, computer device, storage medium and terminal

By building a trust computing model and hardware chip based on blockchain, the problems of untrustworthy data sources, cumbersome rights confirmation, difficult traceability and unreliable calculations in blockchain technology are solved, and the trustworthy collection, storage and joint computing of data are realized, ensuring data privacy and simplifying the flow process, and supporting interaction with the physical world.

CN113946877BActive Publication Date: 2025-07-11ANHUI ZHIJI TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111035914.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-04
Publication Date
2025-07-11
Estimated Expiration
2041-09-04

AI Technical Summary

Technical Problem

In terms of data privacy protection and secure computing, existing blockchain technology has problems such as untrustworthy data sources, cumbersome data rights confirmation, difficult traceability, difficult data privacy control, easy leakage of data joint computing, and unreliable computing processes. Moreover, the deployment of blockchain nodes is complex and difficult to interact with the physical world.

Method used

Build a trust computing model based on blockchain, realize trustworthy collection and verification of data sources through hardware chips, combine the plaintext computing space of distributed multi-mode trust and a real-time verifiable contract execution mechanism to provide a distributed trustworthy execution environment to ensure the security and trustworthy interaction of data throughout the life cycle.

Benefits of technology

It realizes trusted data collection, rights confirmation, storage and joint computing, ensures data privacy without leakage, simplifies the data flow process, improves the credibility of calculation results, and supports interaction with the physical world.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113946877B_ABST
    Figure CN113946877B_ABST
Patent Text Reader

Abstract

The present invention belongs to the field of information security technology, and discloses a data security calculation method, system, computer device, storage medium and terminal. The data security calculation method includes: constructing a trust calculation model based on blockchain; proposing a plaintext calculation trusted space for distributed multi-mode trust based on blockchain; determining a real-time verifiable contract execution mechanism based on a hardware chip. The data security calculation system includes: a data management module, a data processing module, and an intelligent interaction module. The data security calculation system provided by the present invention ensures data ownership through one-key data right confirmation and on-chain traceability; breaks through the barriers of data from the source to use by simplifying the data flow process; easily controls privacy data through distributed encrypted storage; mines data value through secure multi-party calculation to ensure that the data calculation process is not leaked; the calculation result is consensus-trusted and the on-chain result is verifiable; and the intelligent contract preset instructions are used to control the interaction between the hardware device and the physical world.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of information security, and particularly relates to a data security calculation method, system, computer device, storage medium and terminal. Background Art

[0002] Currently, people use data extremely frequently. While the processing and sharing of digital information have brought about rapid economic development, they have also triggered people's concerns about data abuse and privacy issues. Exploring a solution that can protect personal data privacy while enabling data to play its maximum role and conforming to the interests of multiple parties has become an urgent problem to be solved. Due to its characteristics such as traceability, difficulty in tampering, and distributed consensus, blockchain technology has attracted much attention in building trust systems and privacy protection, and is a good solution to the above problems. However, since blockchain technology and real-world scenarios are still in the running-in stage, there are still some problems in using it to solve privacy problems in big data circulation. To solve this problem, people have hardwareized blockchain nodes, realized automatic data collection and processing with the help of Internet of Things technology, and utilized the characteristics of fast hardware device computing, module integration, and convenient deployment to accelerate the implementation of blockchain in privacy protection scenarios in a software-hardware integrated manner.

[0003] The blockchain all-in-one machine developed by Ant Chain has developed a blockchain cryptographic card, which provides high-level security and reliable key management for nodes, improves the efficiency of cryptographic algorithms through hardware acceleration, and generates identity keys for the all-in-one machine through a password generation module. In addition, the blockchain encryption chip card developed by Yulian Technology places the chip in device terminals such as the encapsulation circuit board and external devices at the source, and all data will be signed and encrypted by the blockchain chip and uploaded to the blockchain. No matter how many links it goes through in the middle, it will be monitored to prevent data from being tampered with.

[0004] Generally speaking, the participation of blockchain chipization in the form of software-hardware integration in data privacy protection work is becoming increasingly perfect. However, most of them stay at the stage of data storage and hash on-chain, and there are still challenges in truly combining blockchain technology for process-trusted privacy security calculation.

[0005] With blockchain as the platform, combined with software and hardware technologies, and using cryptographic principles to address privacy protection issues during data usage, there are still many challenges. First, the data source is untrustworthy. The data input into the smart contract from external sources is unprocessed and unverified, lacking credibility in terms of its origin. Second, data right confirmation is cumbersome and tracing is difficult. The ownership registration process for data subjects is complex and cumbersome, and traditional solutions lack an evidence chain, making tracing difficult. Third, data privacy is difficult to control and access. Privacy data is used without the user's knowledge, and data subjects have difficulty controlling their own data. Fourth, data joint computation is prone to leakage and difficult to trace. During the process of multi-party joint computation, data is easily leaked, and there are problems of fraud and unreliability in the joint computation process. In addition, most current blockchain projects only upload data results to the chain, unable to ensure the security and trustworthiness of the computation process, resulting in a reduced level of trust in the consensus process.

[0006] Currently, the blockchain nodes bring inconvenience to node deployment, raising the threshold for joining the blockchain and unable to provide services and benefits for those who do not understand networks or blockchains. Moreover, node users often need to maintain and configure computer devices, which further hinders the actual popularization of the blockchain. On the other hand, for smart contracts on the blockchain, the current approach is for users to input data themselves and initiate transactions by calling the smart contract interface deployed on the blockchain. This obviously has a major flaw, that is, it cannot guarantee the trustworthiness of the data source. Although oracle contracts have emerged currently, which can help smart contracts collect external data outside the chain, it still cannot guarantee whether the external information source is trustworthy. On the other hand, current multi-party secure computation plays an important role in aspects such as big data joint analysis, joint investigations by research institutions, and joint computations by various users. However, for privacy issues in data usage, existing solutions generally involve centralized management, leading to problems such as privacy leakage and data control. On the other hand, current smart contracts still remain in application scenarios such as data transactions and certifications, with a limited scope of use and unable to interact well with the physical world.

[0007] To address the above problems, blockchain anonymous computing hardware can achieve the integration of blockchain software and hardware, making blockchain deployment more convenient. By means of hardware acquisition and sealed call, it ensures the credibility of the data source of smart contracts. By embedding encryption modules such as homomorphic encryption, zero-knowledge proof, and secure multi-party computation, it provides a distributed trusted execution environment to ensure the security and privacy of data joint computation. Through the combination of preset instructions of smart contracts and hardware, it realizes simple interaction with the physical world.

[0008] Through the above analysis, the problems and defects existing in the prior art are as follows:

[0009] (1) Most of the existing methods that participate in data privacy protection in the form of software and hardware integration stay at the stage of data storage and hash chain - up. There are still challenges in truly conducting privacy - secure calculations with trusted processes by combining blockchain technology.

[0010] (2) For the existing methods that use cryptographic principles to solve privacy protection problems during data usage, the data input into the external intelligent contract is unprocessed and unverified, lacking credibility in terms of source; the ownership registration process of the data subject is complex and cumbersome, and traditional solutions lack an evidence chain, making traceability difficult.

[0011] (3) For the existing methods that use cryptographic principles to solve privacy protection problems during data usage, users' privacy data is used without their knowledge, and the data subject has difficulty controlling their own data; during the multi - party joint calculation process, data is prone to leakage, and there are problems of fraud and unreliability in the joint calculation process.

[0012] (4) Most current blockchain projects upload data results to the chain, unable to ensure the security and trustworthiness of the calculation process, resulting in a reduced level of trust in the consensus process.

[0013] (5) Blockchain nodes bring inconvenience to deployment nodes, increasing the threshold for joining the blockchain. It is unable to provide services and benefits for people who do not understand the network or blockchain, hindering the actual popularization of the blockchain.

[0014] (6) For the existing method of users inputting data by themselves and initiating transactions by calling the intelligent contract interface deployed on the blockchain, the credibility of the data source cannot be guaranteed. Although oracle contracts have emerged to help intelligent contracts collect external data off - chain, it still cannot guarantee whether the external information source is credible.

[0015] (7) Existing solutions are generally centralized management, leading to problems such as privacy leakage and data control. On the other hand, current intelligent contracts still stay in application scenarios such as data trading and evidence storage, and their scope of use is still limited, unable to interact well with the physical world.

[0016] The difficulty in solving the above problems and defects is as follows: First, the data source is unreliable. The data input into the smart contract from outside is not processed and verified, and lacks credibility in the source; second, data rights confirmation is cumbersome and difficult to trace. The ownership registration process of the data subject is complicated and cumbersome, and the traditional solution lacks a chain of evidence, making it difficult to trace the source; third, data privacy is difficult to control and access. The user's private data is used without knowing it, and the data subject has difficulty controlling their own data; fourth, data joint calculation is prone to leakage and difficult to track. Data is prone to leakage in the process of joint calculation by multiple parties, and there are problems of fraud and unreliability in the joint calculation process. In addition, most of the current blockchain projects are to upload data results to the chain, which cannot guarantee the security and reliability of the calculation process, resulting in a decrease in the trust of the consensus process.

[0017] The significance of solving the above problems and defects is: to establish a new trust system with blockchain as the basic trust facility for data processing, sharing and other circulation processes, which can accelerate the circulation of digital information and ensure the ownership of data rights and privacy storage. Furthermore, under the condition of protecting data privacy, multiple parties jointly conduct secure computing, explore the maximum value of data, and achieve win-win results for multiple parties. Summary of the invention

[0018] In response to the problems existing in the prior art, the present invention provides a data security calculation method, system, computer equipment, storage medium and terminal, and in particular, relates to a data security calculation method, system, computer equipment, storage medium and terminal based on blockchain.

[0019] The present invention is implemented as follows: a data security calculation method, the data security calculation method comprising the following steps:

[0020] Step 1: Build a trust computing model based on blockchain to improve the credibility of data collection, confirmation and use, allow other nodes to participate in the data verification process, and provide a theoretical model for consensus computing;

[0021] Step 2: Propose a blockchain-based distributed multi-mode trusted plaintext computing trusted space to improve the trust level of computing, reduce the trust dependence on hardware manufacturers, and realize data distributed trusted computing;

[0022] Step three: Determine a real-time and verifiable contract execution mechanism based on hardware chips to achieve trusted interaction with the physical world and promote the in-depth integration of blockchain applications and actual scenarios.

[0023] Further, in step 1, the construction of a trust computing model based on blockchain includes:

[0024] The blockchain-based trust computing model includes data status, data storage tree, and credential chain list.

[0025] Among them, the data status is divided into two types: one is the address of the data subject, and the other is the calculated retrieval address; the account address when the user stores data and represents an individual is the data subject address; the retrieval address automatically generated for this calculation during the joint calculation of data is the calculated retrieval address, which is used to retrieve this calculation and query the calculation process vouchers and calculation results generated during this calculation process.

[0026] The data status has the following fields: count, representing the data ownership; dataRoot, saving the root node hash value of the data storage tree; balance, representing the incentive value of the data subject; proofChain, saving the head node of the calculation process chain; among them, when the data status is the user, dataNode is an empty node, and when the data status is the calculated data, balance is a value of 0.

[0027] The data storage tree stores all the data under the user's name. The data storage tree saves all the data addresses stored in the cloud associated with the user. By pairing them two by two and merging them into parent nodes, and then recursively performing hash processing on each pair of nodes until reaching the root node, a data storage tree is formed.

[0028] The voucher linked list is used to store the generated voucher data during the data calculation process. Many vouchers will be generated during the calculation process. According to the calculation process, each newly generated voucher data will be added to the next node of the linked list; the first head node of the calculation process chain is saved in the data status. When consensus validates the data result, each node will verify the correctness of the voucher based on the head node in order to verify the correctness of the data calculation result.

[0029] The data right confirmation and the data calculation process can only be chained in the form of the model described in the present invention. According to the model described in the present invention, data right confirmation, sharing, and joint calculation can be performed.

[0030] When sending a transaction, it contains the following information: count, representing the current quantity of the data status; signature, ensuring the ownership and correctness of the data; v, r, s, the values used in the cryptographic signature of the transaction, which are used to determine the sender of the transaction; data, the transaction execution information to be sent, including the data hash value, IPFS address, vouchers generated during the calculation process, and satellite navigation information.

[0031] Before executing a transaction, the node will first verify whether the transaction meets the basic inherent rules; if it cannot even pass the basic rules, then each node will not execute the transaction.

[0032] After verifying that the transaction is correct, each node runs a consensus algorithm to package and execute the transaction; the consensus mechanism generates a verification proof after verifying the transaction, which is used to prove that the node verifies the transaction using the verification rules; according to the consensus mechanism, after verifying the transaction, the miner will package the legitimate transaction into a block and broadcast the block, and other nodes will add it to the end of the local blockchain ledger after receiving and verifying it.

[0033] The calculation process voucher is verifiable data generated during the joint calculation of data; by obtaining the voucher, the data calculation process and the calculation result are verified, which is used to prove the correctness of the calculation process or result; among them, the joint calculation process includes homomorphic ciphertext calculation and multi-party calculation, and the verifiable data includes zero-knowledge proof.

[0034] After the transaction is executed, the following changes occur to the on-chain state:

[0035] (1) When the data status is user, the amount of data count owned by the user is incremented by 1; when the data status is calculation data, the number of vouchers of the data count is incremented by 1;

[0036] (2) After verification passes, the execution result is packaged into the blockchain;

[0037] (3) If it is certified data, it is mapped to the user address and added to the corresponding data storage tree of the user; if it is voucher data, it is added to the end of the linked list as the next node of the calculation process chain;

[0038] (4) The miner node that packages the block gets the corresponding incentive;

[0039] (5) When the verification fails, the transaction will not be packaged into the block, the transaction is invalid, and the count value will not increase; among them, the transaction satisfies the transaction rules of the native chain, and the native chain is Ethereum.

[0040] Further, the inherent rules for verifying the transaction are as follows:

[0041] (1) Whether there is really data at the IPFS address and whether the hash value of the stored data is equal to the provided one;

[0042] (2) Whether the transaction has a legal signature;

[0043] (3) Whether the attached count value is equal to the count of the data status;

[0044] (4) When it is a data calculation process, check whether the transaction result is legal; verify the result according to the voucher generated by the calculation process.

[0045] Further, in step two, the proposed cleartext computing trusted space based on blockchain distributed multi-mode trust includes:

[0046] For complex data joint computing scenarios, a secure and independent computing space is opened in the anonymous computing box, and the difficult-to-compute part of the private ciphertext data is computed in this space in cleartext form. The computing process is invisible to any node, including:

[0047] According to different data types, data with large computational volume and complexity is computed in cleartext; the blockchain anonymous computing hardware provides a trusted isolation space, and this type of computing is performed in the trusted execution environment.

[0048] The box serves as a blockchain node and forms a trusted computing committee in the blockchain network; the "trusted computing committee" can achieve cross-node and cross-mechanism communication, and realize distributed joint computing and data sharing of data.

[0049] Within the trusted computing committee, each node contributes the trusted execution environment TEE of the blockchain anonymous computing hardware; since there are different trust roots among different hardware manufacturers, the TEE data between different manufacturers is made mutually trustworthy and interoperable through a consensus mechanism, and jointly forms a distributed and multi-mode trusted execution environment; the space size of the distributed trusted execution environment is the sum of the trusted execution memory sizes of each box.

[0050] A set of consensus mechanisms runs among committee members. When a user calls a smart contract to compute data, committee members reach a consensus based on the generated call request, and the consensus algorithm depends on the specific situation of the committee to uniformly obtain the correct contract call result.

[0051] Committee members who correctly execute the contract will receive gas rewards.

[0052] Further, in step three, the determination of the real-time verifiable contract execution mechanism based on the hardware chip includes:

[0053] The blockchain anonymous computing box provides the ability to interact with the physical world, and triggers the state to automatically execute preset instructions through a smart contract; following the principle and idea of "execute first, verify later", a reputation mechanism is introduced to consensus verify the execution result and update the corresponding reputation status.

[0054] For user operation scenarios, the blockchain anonymous computing box securely collects user information according to the descriptions in step one and step two; when the user makes corresponding behavioral operations, they are recorded on the blockchain through a smart contract; other nodes perform consensus and verification according to the historical data according to the trust computing model; according to the verification results, the reputation status of the user node is changed.

[0055] For an automated scenario, after the blockchain anonymous computing box processes data according to an external instruction or a preset program, if a preset condition is triggered, it will connect to an external device through a trusted hardware to execute a corresponding preset instruction, and store the execution behavior on the chain through a smart contract; other nodes verify and reach a consensus on the triggering condition of the instruction; according to the verification result, the reputation status of the box node is changed.

[0056] Another object of the present invention is to provide a data security computing system applying the data security computing method described above. The data security computing system includes:

[0057] A data management module, which is used to collect data of a data subject; encrypt the data and store it in a cloud distributed database specified by the user; the box does not store the plaintext of the data during the data collection and processing process;

[0058] A data processing module, which is used to implement the desensitization processing of data and perform joint computing on the data; during the data collection and encryption processing process, key voucher information is saved on the blockchain through a smart contract; other nodes perform consensus, verification, block generation, broadcasting, and persistence operations on the voucher information through the trust computing model;

[0059] An intelligent interaction module, which is used to achieve a trusted interaction between the blockchain and the physical world through an anonymous computing box.

[0060] Furthermore, in the data management module, the data includes privacy data generated by financial trade, medical insurance, smart energy, social media, and daily life; the cloud distributed database includes IPFS.

[0061] Another object of the present invention is to provide a computer device. The computer device includes a memory and a processor. When a computer program stored in the memory is executed by the processor, the processor performs the following steps:

[0062] Construct a blockchain-based trust computing model for data collection, storage rights confirmation, and joint computing; propose a plaintext computing trusted space based on blockchain-based distributed multi-mode trust; determine a real-time verifiable contract execution mechanism based on a hardware chip.

[0063] Another object of the present invention is to provide a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the processor performs the following steps:

[0064] Build a blockchain-based trusted computing model for data collection, storage rights confirmation, and joint computing; propose a plaintext computing trusted space for distributed multi-mode trust based on blockchain; determine a real-time verifiable contract execution mechanism based on a hardware chip.

[0065] Another object of the present invention is to provide an information data processing terminal, which is used to implement the above-mentioned data security computing system.

[0066] Combining all the above technical solutions, by proposing a trusted computing model, the industry pain point of only verifying data hashes in the industry and being unable to perform richer data verification is solved, filling the industry gap of on-chain trusted secure multi-party computing; through the combination of smart contracts and hardware, the industry gap of on-chain consensus and trusted interaction in the physical world is filled.

[0067] The advantages and positive effects of the present invention are as follows: The data security computing system provided by the present invention provides the following functions:

[0068] (1) One-click data rights confirmation, and on-chain traceability to guarantee data ownership.

[0069] Collect data, with the functions of uploading and signing data, ensuring that the data is difficult to tamper with and traceable. At the same time, the data location and time are also uploaded, further guaranteeing the reliability of data rights confirmation.

[0070] (2) Simplify the data flow process and break through the barriers from the data source to its use.

[0071] The box is of a sealed structure, and data is collected through Internet of Things devices to ensure the trusted collection of data sources.

[0072] (3) Distributed encrypted storage, and easy control of private data.

[0073] The box provides a homomorphic encryption function. After the encrypted data is seen, it is stored in a cloud platform (such as IPFS) or locally by calling a distributed storage interface. The data is stored distributively, and the address can be retrieved on the chain. The decryption key is self-preserved, and the whole process is completed with one click, and the data is easily controlled.

[0074] (4) Secure multi-party computing to mine data value and ensure that the data calculation process is not leaked.

[0075] Improve secure multi-party computing, and realize the joint use of data under the condition of ensuring that data privacy is not leaked. Provide a distributed trusted execution environment to realize the trusted computing of data.

[0076] (5) The calculation result consensus is trustworthy, and the on-chain result is verifiable.

[0077] Provide zero-knowledge proofs, and the data can be verified on the chain. Other nodes can obtain relevant vouchers from the chain to verify the process and results. The calculation process is traced on the chain, and the data privacy is protected throughout the life cycle.

[0078] (6) The smart contract presets instructions to control hardware devices and interact with the physical world.

[0079] The box has the ability to connect to the Internet of Things and controls physical devices through a preset program of the smart contract to achieve the ability to interact with the physical world.

[0080] Compared with other similar products and solutions, the present invention further enriches the usage methods of data in terms of data uploading to the chain and rights confirmation. The innovation points of the present invention are:

[0081] (1) Propose a blockchain-based trust computing model to support the distributed verification of data in terms of rights confirmation and usage.

[0082] (2) Propose a blockchain-based data security system to provide a distributed security house to protect the privacy and security of data throughout the life cycle.

[0083] (3) Propose an adaptive real-time verifiable contract execution mechanism based on the combination of blockchain and hardware to interact simply with the physical world. BRIEF DESCRIPTION OF THE DRAWINGS

[0084] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required to be used in the embodiments of the present invention. Obviously, the following described drawings are only some embodiments of the present invention, and those of ordinary skill in the art can also obtain other drawings based on these drawings without creative efforts.

[0085] Figure 1 It is a flowchart of the data security calculation method provided by the embodiment of the present invention.

[0086] Figure 2 It is a block diagram of the data security calculation system structure provided by the embodiment of the present invention;

[0087] In the figure: 1. Data management module; 2. Data processing module; 3. Intelligent interaction module.

[0088] Figure 3 It is a schematic diagram of the trust computing model provided by the embodiment of the present invention.

[0089] Figure 4 It is a schematic diagram of the data trading form provided by the embodiment of the present invention.

[0090] Figure 5 It is a schematic diagram of the process of data collection, encryption and key information uploading to the chain by the anonymous computing box provided by the embodiment of the present invention.

[0091] Figure 6 It is a schematic diagram of the process in which a user shares data using an anonymous computing box and performs homomorphic computation on ciphertext data provided by an embodiment of the present invention.

[0092] Figure 7 It is a schematic diagram of the architecture for secure multi-party computation by the anonymous computing box provided by an embodiment of the present invention.

[0093] Figure 8 It is a flowchart of secure multi-party computation by the anonymous computing box provided by an embodiment of the present invention.

[0094] Figure 9 It is a schematic diagram of the process in which blockchain hardware devices are distributed to form a trusted execution environment provided by an embodiment of the present invention.

[0095] Figure 10 It is a schematic diagram of the process in which a smart contract interacts with the physical world through blockchain hardware devices provided by an embodiment of the present invention.

[0096] Figure 11 It is a schematic diagram of the hardware structure of the anonymous computing box provided by an embodiment of the present invention. Detailed implementation manners

[0097] In order to make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below in conjunction with embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0098] In view of the problems existing in the prior art, the present invention provides a data security computing method, system, computer device, storage medium and terminal. The present invention will be described in detail below with reference to the accompanying drawings.

[0099] As Figure 1 shown, the data security computing method provided by the embodiment of the present invention includes the following steps:

[0100] S101, construct a trust computing model based on blockchain;

[0101] S102, propose a plaintext computing trusted space based on distributed multi-mode trust of blockchain;

[0102] S103, determine a real-time verifiable contract execution mechanism based on a hardware chip.

[0103] As Figure 2 shown, the data security computing system provided by the embodiment of the present invention includes:

[0104] The data management module 1 is used to collect the data of the data subject, encrypt the data, and store it in the cloud distributed database specified by the user. The box does not store the plaintext of the data during the data collection and processing process.

[0105] The data processing module 2 is used to implement the desensitization processing of the data and perform joint calculations on the data. During the data collection and encryption process, the key voucher information is saved on the blockchain through a smart contract. Other nodes perform consensus, verification, block generation, broadcasting, and persistence operations on the voucher information through the trust computing model.

[0106] The intelligent interaction module 3 is used to achieve the trusted interaction between the blockchain and the physical world through the anonymous computing box.

[0107] The technical solution of the present invention will be further described below in conjunction with specific embodiments.

[0108] Embodiment 1

[0109] In view of the problems existing in the prior art, the present invention provides a solution, a hardware device, a device, and an edge end for data right confirmation, encrypted storage, and privacy data security multi-party calculation based on blockchain chipization and software and hardware integration, so as to improve the privacy protection during the data flow and use process.

[0110] The blockchain anonymous computing hardware (platform) is a blockchain software and hardware integrated product developed in response to the needs of data right confirmation, secure storage, joint calculation, and trusted execution in the context of data sharing and use. The present invention proposes a trust computing model based on blockchain, relying on cryptography (such as secure multi-party, zero-knowledge proof, etc.) technologies to realize the manageability, usability, and verifiability of data under privacy protection. At the same time, the present invention provides a trusted distributed plaintext computing space for users in a multi-mode trust scenario, as well as a secure computing service with fast deployment and convenient use, and combines smart contract preset instructions and control components to ultimately achieve trusted interaction with the physical world.

[0111] The present invention constructs a data security system based on blockchain, that is, to provide security protection for the entire life cycle of data collection and transmission, storage and use, exchange and sharing, and destruction. The present invention provides a data security calculation method, a hardware device, and a platform based on blockchain, mainly including:

[0112] The "data management" module collects the data of the data subject (such as privacy data generated in financial trade, medical insurance, smart energy, social media, and daily life). Encrypt the data and store it in the cloud distributed database (such as IPFS) specified by the user. The box does not store the plaintext of the data during the data collection and processing process.

[0113] The "data processing" module realizes the desensitization processing of data and performs joint calculations on the data. Specifically: during the process of data collection and encryption processing, the key voucher information is saved on the blockchain through a smart contract. Other nodes will perform consensus, verification, block generation, broadcasting, and persistence operations on the voucher information through the trust calculation model in the first aspect above.

[0114] The "intelligent interaction" module realizes the trusted interaction between the blockchain and the physical world through the anonymous computing box described in the present invention.

[0115] To achieve the above object, according to the first aspect of one or more embodiments of this specification, a blockchain-based trust calculation model for data collection, storage rights confirmation, and joint calculation is proposed.

[0116] In the data model of the present invention, as Figure 3 shown, it includes data status, data storage tree, and voucher linked list. Specifically as described below:

[0117] The data status is divided into two types: one is the address of the data subject (user), and the other is the calculation retrieval address. The account address when the user stores data and represents an individual is the data subject address; while the retrieval address automatically generated for this calculation during the joint calculation of data is the calculation retrieval address, which is mainly used to retrieve this calculation and query the calculation process vouchers and calculation results generated during this calculation process.

[0118] The data status has the following fields: count, representing the data ownership; dataRoot, saving the root node hash value of the data storage tree; balance, representing the incentive value of the data subject; proofChain, saving the head node of the calculation process chain. Among them, when the data status is the user, dataNode is an empty node, and when the data status is the calculated data, balance is a value of 0.

[0119] The data storage tree stores all the data under the user's name. Similar to the Merkle tree, the data storage tree described in the present invention saves the data addresses of all data stored on the cloud (such as IPFS) associated with the user, pairs them up and merges them into parent nodes, and then recursively performs hash processing on each pair of nodes until reaching the root node to form the data storage tree.

[0120] The voucher linked list is used to store the generated voucher data during the calculation process of the data. Many vouchers will be generated during the calculation process. According to the calculation process, each newly generated voucher data will be added to the next node of the linked list. The first head node of the calculation process chain is saved in the data status. When consensus-verifying the data result, each node will verify the correctness of the vouchers based on the head node to verify the correctness of the data calculation result.

[0121] When sending a transaction, as Figure 4 shown, the following information should be included: count, representing the current quantity of the data status; signature, ensuring the ownership and correctness of the data; v, r, s, the values used in the cryptographic signature of the transaction, which can be used to determine the sender of the transaction; data, the transaction execution information to be sent (including but not limited to: data hash value, IPFS address, vouchers generated during the calculation process, satellite navigation information, etc.).

[0122] Before executing a transaction, the node will first verify whether the transaction meets some basic (inherent) rules. If it fails to pass even these basic rules, the nodes will not execute the transaction.

[0123] The inherent rules for verifying a transaction are as follows:

[0124] 1. Whether there is really data at the IPFS address and whether the hash value of the stored data is equal to the provided one;

[0125] 2. Whether the transaction has a legal signature;

[0126] 3. Whether the attached count value is equal to the count of the data status;

[0127] 4. If it is during the data calculation process, verify whether the transaction result is legal (verify the result based on the vouchers generated during the calculation process).

[0128] After verifying that the transaction is correct, each node runs a consensus algorithm to package and execute the transaction. The consensus mechanism described in the present invention will generate a verification proof after verifying the transaction to prove that the node has verified the transaction using the above verification rules. According to the consensus mechanism described in the present invention, after the miner verifies the transaction, it will package the legal transaction into a block and broadcast the block. After other nodes receive and verify it, they will add it to the end of the local blockchain ledger.

[0129] In addition, the calculation process vouchers described in the present invention are verifiable data (such as zero-knowledge proofs) generated during the joint calculation process (homomorphic ciphertext calculation, multi-party calculation) of the data. By obtaining the vouchers, the data calculation process and the calculation result can be verified to prove the correctness of the calculation process or result.

[0130] After the transaction is executed, the following changes will occur to the on-chain status:

[0131] 1. When the data status is for a user, the quantity count of the data owned by the user will increase by 1; when the data status is for calculation data, the count of the vouchers of the data will increase by 1;

[0132] 2. After verification passes, the result will be packaged into the blockchain;

[0133] 3. If it is the data for rights confirmation, it will be mapped under the user address and added to the corresponding data storage tree of the user; if it is the voucher data, it will be added to the end of the linked list as the next node of the calculation process chain.

[0134] 4. The miner node that packages the block will receive corresponding incentives.

[0135] 5. When the verification fails, the transaction will not be packaged into the block, the transaction is invalid, and the count value will not increase.

[0136] In addition, the transaction should comply with the transaction rules of the native blockchain (such as Ethereum).

[0137] According to the second aspect of one or more embodiments of this specification, a plaintext calculation trusted space for distributed multi-modal trust based on blockchain is proposed. Specifically, for complex data joint calculation scenarios, a secure and independent calculation space is opened in the anonymous calculation box, and the difficult-to-calculate part of the private ciphertext data is calculated in plaintext in this space. The calculation process is invisible to any node. Specifically:

[0138] According to the different data types, for the data with large amount of calculation and complex calculation, plaintext calculation is performed. The blockchain anonymous calculation hardware provides a trusted isolation space, and this type of calculation is performed in the trusted execution environment to ensure the confidentiality and integrity of the user's critical code and data.

[0139] The box acts as a blockchain node and forms a trusted calculation committee in the blockchain network. The "trusted calculation committee" can achieve cross-node and cross-mechanism communication and realize distributed joint calculation and data sharing of data.

[0140] Within the trusted calculation committee, each node contributes the trusted execution environment (TEE) of the blockchain anonymous calculation hardware. Since there are different trust roots among different hardware manufacturers, the TEE data interoperability and mutual trust among different manufacturers are realized through the consensus mechanism, and a distributed and multi-modal trusted execution environment is jointly formed. The space size of the distributed trusted execution environment is the sum of the trusted execution memory sizes of each box.

[0141] A set of consensus mechanisms is run among the committee members. When the user calls the smart contract to calculate data, the committee members will, according to the generated call request and through consensus (the consensus algorithm depends on the specific situation of the committee), unify the correct contract call result.

[0142] The committee members who correctly execute the contract will receive gas rewards.

[0143] According to the third aspect of one or more embodiments of this specification, a real-time verifiable contract execution mechanism based on a hardware chip is proposed. The method includes:

[0144] The blockchain anonymous computing box described in this specification provides the ability to interact with the physical world, and automatically executes preset instructions through a smart contract triggered by a state. According to the principle and idea of "execute first, verify later", a reputation mechanism is introduced to verify the execution result through consensus and update the corresponding reputation status.

[0145] For the user operation scenario, the blockchain anonymous computing box securely collects user information according to the descriptions in the above first and second aspects. When the user makes corresponding behavioral operations, they are recorded on the blockchain through a smart contract. Other nodes perform consensus and verification according to the trust calculation model in the first aspect based on historical data. According to the verification result, the reputation status of the user node is changed.

[0146] For the automation scenario, after the blockchain anonymous computing box processes data according to an external instruction or a preset program, if a preset condition is triggered, it will connect to external devices through a trusted hardware to execute corresponding preset instructions, and store this execution behavior on the chain through a smart contract. Other nodes verify and reach a consensus on the triggering condition of this instruction. According to the verification result, the reputation status of the box node is changed.

[0147] In summary, the present invention provides the following functions:

[0148] 1. One-key data right confirmation, and chain-based traceability to ensure data ownership.

[0149] The data is collected, with the functions of uploading and signing the data, ensuring that the data is difficult to tamper with and traceable. At the same time, the data location and time are also uploaded, further ensuring the reliability of data right confirmation.

[0150] 2. Simplify the data flow process and break through the barriers from the data source to its use.

[0151] The box is of a sealed structure, and data is collected through Internet of Things devices to ensure the trustworthy collection of the data source.

[0152] 3. Distributed encrypted storage, and easy control of private data.

[0153] The box provides a homomorphic encryption function. After the encrypted data is seen, it is stored in a cloud platform (such as IPFS) or locally by calling a distributed storage interface. The data is stored distributively, and the address can be retrieved through the chain. The decryption key is self-preserved, and the whole process is completed with one key, and the data is easily controlled.

[0154] 4. Secure multi-party computing to mine data value and ensure that the data calculation process is not leaked.

[0155] Improve secure multi-party computing to achieve the joint use of data under the condition of ensuring data privacy and non-disclosure. Provide a distributed trusted execution environment to achieve trusted computing of data.

[0156] 5. The consensus of the calculation results is credible, and the results on the chain are verifiable.

[0157] Provide zero-knowledge proofs, and the data can be verified on the chain. Other nodes can obtain relevant certificates from the chain to verify the process and results. The calculation process is traced on the chain, and the data privacy is protected throughout the life cycle.

[0158] 6. The smart contract presets instructions to control hardware devices and interact with the physical world.

[0159] The box has the ability to connect to the Internet of Things, and controls physical devices through the preset program of the smart contract to achieve the ability to interact with the physical world.

[0160] Compared with other similar products and solutions, the present invention further enriches the usage mode of data in terms of data uploading to the chain and rights confirmation. The innovation points are:

[0161] (1) Propose a trust computing model based on blockchain to support the distributed verification of data in terms of rights confirmation and use.

[0162] (2) Propose a data security system based on blockchain to provide distributed security houses to protect the privacy and security of data throughout the life cycle.

[0163] (3) Propose an adaptive real-time verifiable contract execution mechanism based on the combination of blockchain and hardware to interact simply with the physical world.

[0164] Example 2

[0165] The blockchain anonymous computing hardware can achieve the integration of software and hardware, and realize the trusted collection, encrypted storage, rights confirmation verification and joint use of data sources, etc. The blockchain anonymous computing hardware has built-in node public and private keys and a node startup program, and can build a private blockchain of its own or connect to the blockchain (Ethereum) network with one key.

[0166] In one embodiment, as Figure 5As shown, it is the general process of data collection and processing by the blockchain anonymous computing hardware. The blockchain anonymous computing hardware is embedded with an IoT chip and can collect automation data, status data, file data, etc. through technologies such as wireless networks (WIFI, 4G / 5G), sensors, wired connections, and radio frequency identification. In addition, the node is embedded with a GPS chip to enable location tracking of the data source. The blockchain anonymous computing hardware is in a sealed state, reducing manual operations during the data collection and processing process and achieving integrated protection. The collected data is homomorphically encrypted by the encryption module. For the encrypted data, there are multiple storage methods: one is that the user specifies the storage path and stores the encrypted data in a specified space (retrievable by the outside world); the other is to default to distributed cloud storage through the IPFS module and return a hash flag for the user to retrieve.

[0167] To better confirm the rights and trace the data, the blockchain anonymous computing hardware takes the hash value of the homomorphic ciphertext and digitally signs the data using the key embedded in the device. The calculated ciphertext hash, digital signature, IPFS storage address, GPS location, clock information, etc. are stored on the blockchain through a smart contract. In addition, the blockchain anonymous computing hardware is embedded with Decentralized Identifiers (DID), which are stored on the blockchain together with the above data through a smart contract to further protect the identity privacy and rights confirmation of the data subject.

[0168] Specifically, the process of verifying, reaching consensus, broadcasting, and persisting the data generated for rights confirmation on the chain through a smart contract is as follows:

[0169] If it is sent to the blockchain network in the form of a transaction and is consensus-reached by other nodes. Assume the address generated by the embedded private key of the box is 0xtest and the current user has x pieces of data. Then the form of sending the transaction is:

[0170] ①count(x + 1), indicating the current quantity of the data status;

[0171] ②signature (private key signature) to ensure the ownership and correctness of the data;

[0172] ③v, r, s (private key parameters);

[0173] ④data (storage address + hash of the data at the IPFS address).

[0174] Then after other nodes receive this transaction, they verify the transaction, and the verification rules are:

[0175] ①Whether count + 1 of user 0xtest is equal to x + 1 to avoid repeated calculations;

[0176] ② Whether the signature is correct;

[0177] ③ In Data, whether the content of the IPFS storage address is empty and whether its hash value is equal to the uploaded hash value.

[0178] When the verification passes, this transaction will be put into the transaction pool. After a period of time, the blockchain network nodes will run the consensus mechanism, elect miner nodes to package the transactions, and broadcast them to the whole network. After other nodes verify the block and pass, they will add the block containing this transaction to the local.

[0179] Since then, the data right confirmation and storage have been completed.

[0180] When the data owner needs to confirm the data right, he only needs to provide the path from the node to the dataRoot in the "data storage tree" corresponding to the user address to prove the owner and authenticity of the data.

[0181] Embodiment 3

[0182] The blockchain anonymous computing hardware can perform secure privacy computing between the data owner and the data requester. In one embodiment, as Figure 6 shown, is the process of joint computing between the data owner and the data requester. Through the blockchain anonymous computing hardware, between the data owner and the data requester, secure joint computing can be performed under the condition of protecting the privacy of the data subject.

[0183] Before describing the specific process of the calculation, an initialization description is given first. As described in the first aspect of the invention content, the following process will be sent to the blockchain network in the form of a transaction and be consensus by other nodes. The box generates a data address 0xdata_x for this data calculation, the count of this calculation is initialized to 0, the dataRoot is empty, the balance is empty, and the proofChain is initialized to the head node of this calculation process and will point to the next node.

[0184] The credentials generated during the data calculation process are verified, consensus, broadcast, and persisted on the chain through a smart contract. The specific process is as follows:

[0185] The first step is that the data owner uses the "partial disclosure" module to partially disclose the data information for data display. The partially disclosed data information, after being consensus verified, will be added to the next node of the proofChain.

[0186] In the second step, the data user needs to use the data and send a request to the data owner. After the data owner gives consent, the user obtains the homomorphically encrypted data according to the IPFS address and performs homomorphic calculations on the data inside the box (or locally) to obtain a calculation result. During the process of performing homomorphic calculations on the data, several calculation vouchers generated will be sequentially added to the next node of the proofChain.

[0187] In the embodiment of the present invention, the data during the calculation process is encrypted, and the calculation result is also encrypted. Only the private key of the data owner can decrypt it.

[0188] In the third step, the data owner decrypts the calculation result sent by the data user through the "verifiable encryption" module and sends it back to the user. The voucher data and decryption result used for decryption will both be added to the next node of the proofChain.

[0189] In the fourth step, the user verifies the correctness of the data.

[0190] As a node not participating in the calculation, by obtaining the proofChain head node of 0xdata_x and then sequentially traversing the entire calculation process linked list, the correctness of the calculation process and the calculation result can be verified.

[0191] Embodiment 4

[0192] The blockchain anonymous computing hardware can achieve secure multi-party computing among multiple institutions (multiple users) while protecting data privacy. In one embodiment, as Figure 7 and Figure 8 shown, it is the process of the blockchain anonymous computing box performing multi-party secure computing through a combination of software and hardware.

[0193] In the first step, through the blockchain smart contract, multiple nodes negotiate to reach an intention of joint calculation, and perform joint multi-party calculation on their respective private data. Through the consensus mechanism, a calculation retrieval address (such as, 0xcompute) is generated for this calculation;

[0194] In the second step, each node negotiates a joint public key for homomorphic encryption and its respective private key through secure multi-party calculation. The private key of each node can encrypt the data, and the ciphertext data can perform homomorphic operations through the joint public key. The decryption process is completed by the corresponding private key.

[0195] In the third step, each node performs secure multi-party computation based on its respective private data. For simple ciphertext computations, the ciphertext computation is directly carried out inside the chip, and the key publicly available information during the computation process is stored on the blockchain for later verification of the correctness of the computation process and results by each node using zero-knowledge proofs. For complex ciphertext computations, due to performance limitations, a secure external device needs to be connected, and the ciphertext (or plaintext) computation is performed on the external device. The verifiable data generated during the computation process is uploaded to the blockchain through the box for later verification. The generated vouchers, through the consensus mechanism, will be appended to the next node of the proofChain.

[0196] In the fourth step, each node finds the head node of the proofChain by calculating the retrieval address and sequentially verifies the correctness of the vouchers during the computation process, thereby achieving the authentication of the result's correctness.

[0197] Embodiment 5

[0198] Blockchain anonymous computing hardware can improve the distributed trusted execution environment. The trusted execution environment (TEE) is a secure area within the main processor. It runs in an independent environment and in parallel with the operating system. It ensures that the confidentiality and integrity of the code and data loaded in the TEE are protected. By using both hardware and software to protect data and code, this parallel system is more secure than traditional systems (Rich Execution Environment, REE). Trusted applications running in the TEE can access all the functions of the device's main processor and memory, while hardware isolation protects these components from being affected by user-installed applications running in the main operating system. The software and cryptographic isolation in the TEE protect different trusted applications from each other.

[0199] As Figure 9 shown, the anonymous computing boxes are distributed to form a trusted execution space. Each node (box) can create a trusted execution environment (TEE, Trusted Execution Environment) on the hardware device. However, since the TEE cannot fully guarantee availability (because the host can decide to terminate the TEE on its own), nor can it reliably access the network or persistent storage. At the same time, due to different trust roots of the TEEs among different hardware manufacturers, their TEE spaces cannot communicate with each other. Combining the distributed characteristics of the blockchain, each node forms a distributed multi-mode trusted trusted execution environment to reliably execute data. The blockchain anonymous computing hardware, as a blockchain node, forms a "trusted computing committee" through election. Inside the "trusted computing committee", a consensus mechanism is run to perform trusted computing on the data.

[0200] Specifically, within the "Trusted Computing Committee", each node contributes the Trusted Execution Environment (TEE) of the blockchain anonymous computing hardware. Through a consensus mechanism, data interoperability within the trusted execution environments under different trust roots is achieved, and a distributed trusted execution environment is jointly formed. The spatial size of the distributed trusted execution environment is the sum of the trusted execution memory sizes of each box.

[0201] A set of consensus mechanisms runs among committee members. When a user invokes a smart contract, a call request is generated. Among committee members, through consensus (the consensus algorithm depends on the specific situation of the committee), the correct contract call result is unified.

[0202] To incentivize nodes to provide trusted execution space and execute the computations required in smart contracts, gas is distributed to the corresponding nodes as an incentive based on the execution situation of the provided trusted execution space.

[0203] Embodiment 6

[0204] The blockchain anonymous computing hardware can interact with the physical world. For example, Figure 10 As shown, the blockchain anonymous computing hardware, as a blockchain node, realizes trusted interaction with the physical world connected to the hardware by integrating the preset instructions and hardware of the smart contract. A smart contract is a computer transaction protocol that requires no intermediary, self-verifies, and automatically executes the contract terms. With the decentralized infrastructure of the blockchain, it can play an important role in the trusted execution environment. In the present invention, a blockchain chip is embedded in the hardware facility to execute the preset instructions of the smart contract and interact with the physical world. Specifically:

[0205] The data input and collected from the outside interact with the blockchain through the anonymous computing box. By invoking and executing the contract trigger event, the smart contract outputs a status instruction. The instruction can control the hardware device through the anonymous computing box, and thus interact with the physical world. One scenario is as follows: In the vehicle networking, the blockchain hardware device of this discovery is loaded. When the car brakes suddenly multiple times or detects alcohol gas in the car, the data collected by the device is uploaded to the blockchain and triggers the smart contract. The smart contract outputs an instruction of "pull over". Through the interaction between the box and the car, the car automatically executes the command of pulling over.

[0206] Embodiment 7

[0207] Figure 11 It is a schematic diagram of the hardware structure of the blockchain anonymous computing box. Among them, the device interface and the sensor are used for data collection, the encryption circuit is used for data encryption, security computing, etc. The TEE trusted execution environment corresponds to the description of the safe house of the present invention, and the blockchain module is used to interact with the blockchain network. Generally speaking, the present invention is a software and hardware integrated product developed based on the blockchain for the needs of data right confirmation, secure storage, and joint computing, etc.

[0208] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented in whole or in part in the form of a computer program product, the computer program product includes one or more computer instructions. When the computer program instructions are loaded or executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more integrated available media. The available medium may be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)).

[0209] As described above, the above are only specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention shall be covered by the protection scope of the present invention.

Claims

1. A data security calculation method, characterized in that, The described data security calculation method includes the following steps: Step 1, construct a trust calculation model based on blockchain; Step 2, propose a plaintext calculation trusted space for distributed multi-mode trust based on blockchain; Step 3, determine a real-time verifiable contract execution mechanism based on a hardware chip; In Step 1, the construction of the trust calculation model based on blockchain includes: The trust calculation model based on blockchain includes a data state, a data storage tree, and a credential linked list; Among them, the data state is divided into two types: one is the address of the data subject, and the other is the calculation retrieval address; the account address when the user stores data and represents an individual is the data subject address; the retrieval address automatically generated for this calculation during joint data calculation is the calculation retrieval address, which is used to retrieve this calculation and query the calculation process credentials and calculation results generated during this calculation process; The data state has the following fields: count, indicating the data ownership; dataRoot, saving the root node hash value of the data storage tree; balance, indicating the incentive value of the data subject; proofChain, saving the head node of the calculation process chain; among them, when the data state is a user, dataNode is an empty node, and when the data state is the calculated data, balance is a value of 0; The data storage tree stores all the data under the user's name. The data storage tree saves all the data addresses stored in the cloud associated with the user, pairs them up two by two to merge into a parent node, and then recursively performs hash processing on each pair of nodes until reaching the root node to form the data storage tree; The credential linked list is used to store the generated credential data during the calculation process; many credentials will be generated during the calculation process. According to the calculation process, each newly generated credential data will be added to the next node of the linked list; the first head node of the calculation process chain is saved in the data state. When consensus validates the data result, each node will verify the correctness of the credentials based on the head node to verify the correctness of the data calculation result; When sending a transaction, it contains the following information: count, indicating the current quantity of the data state; signature, ensuring the ownership and correctness of the data; v, r, s, values used in the cryptographic signature of the transaction to determine the sender of the transaction; data, the transaction execution information to be sent, including the data hash value, IPFS address, credentials generated during the calculation process, and satellite navigation information; Before executing a transaction, the node will first verify whether the transaction meets the basic inherent rules; if it cannot even pass the basic rules, then each node will not execute the transaction; After verifying that the transaction is correct, each node runs a consensus algorithm to package and execute the transaction; the consensus mechanism generates a verification proof after verifying the transaction, which is used to prove that the node uses the verification rules to verify the transaction; according to the consensus mechanism, after the miner verifies the transaction, it will package the legal transaction into a block and broadcast the block. After other nodes receive and verify it, they will add it to the end of the local blockchain ledger; The computing process credential is verifiable data generated by the data during the joint computing process; by obtaining the credential, the data computing process and the computing result are verified to prove the correctness of the computing process or result; wherein the joint computing process includes homomorphic ciphertext computing and multi-party computing, and the verifiable data includes zero-knowledge proof; After the transaction is executed, the on-chain status changes as follows: (1) When the data status is user, the count of the amount of data owned by the user is increased by 1; when the data status is calculation data, the count of the number of data vouchers is increased by 1; (2) After verification, the execution results are packaged into the blockchain; (3) If it is ownership confirmation data, it is mapped to the user address and added to the data storage tree corresponding to the user; if it is credential data, it is added to the end of the linked list as the next node of the calculation process chain; (4) The miner nodes that package the blocks receive corresponding incentives; (5) If the verification fails, the transaction will not be packaged into the block, the transaction is invalid, and the count value will not increase; wherein the transaction satisfies the transaction rules of the protogenesis link, and the protogenesis link is Ethereum; In step 2, the proposed blockchain-based distributed multi-modal trust plaintext computing trusted space includes: For complex data joint computing scenarios, a secure and independent computing space is opened up in the anonymous computing box, and the difficult-to-compute parts of the private ciphertext data are calculated in the space in plain text. The computing process is invisible to any node, including: According to different data types, data with large amount of calculation and complex calculation are calculated in plain text; the anonymous computing hardware of the blockchain forms a committee to provide a distributed and trusted isolation space, and the calculation is carried out in a trusted execution environment; The box acts as a blockchain node and forms a trusted computing committee in the blockchain network; the trusted computing committee can realize cross-node and cross-mechanism communication, and realize distributed joint computing and data sharing of data; In the Trusted Computing Committee, each node contributes to the trusted execution environment TEE of the blockchain anonymous computing hardware; because there are different trust roots between different hardware manufacturers, the mutual trust and intercommunication of TEE data between different manufacturers is achieved through the consensus mechanism, and a distributed, multi-mode trusted trusted execution environment is jointly formed; the space size of the distributed trusted execution environment is the sum of the trusted execution memory size of each box; A consensus mechanism is run among the committee members. When a user calls a smart contract to calculate data, the committee members reach a consensus based on the call request. The consensus algorithm is determined according to the specific situation of the committee and the correct contract call result is unified. Committee members will receive gas rewards if they correctly execute the contract; In step 3, determining a real-time verifiable contract execution mechanism based on a hardware chip includes: The blockchain anonymous computing box provides the ability to interact with the physical world, automatically executing preset instructions through the triggering state of the smart contract; according to the principle and idea of ​​execution first and verification later, a reputation mechanism is introduced to verify the consensus of the execution results and update the corresponding reputation status; For the user operation scenario, the blockchain anonymous computing box securely collects user information according to the descriptions in Step 1 and Step 2; the user makes corresponding behavioral operations, which are recorded on the blockchain through smart contracts; other nodes perform consensus and verification according to the historical data according to the trust computing model; according to the verification results, the reputation status of the user node is changed. For the automation scenario, after the blockchain anonymous computing box processes the data according to external instructions or preset programs, if a preset condition is triggered, it will connect to external devices through trusted hardware to execute corresponding preset instructions, and store the execution behavior on the chain through smart contracts; other nodes verify and reach a consensus on the trigger conditions of the instruction; according to the verification results, the reputation status of the box node is changed.

2. The data security calculation method according to claim 1, characterized in that, The inherent rules for verifying transactions are as follows: (1) Whether there is really data at the IPFS address, and whether the hash value of the stored data is equal to the provided one; (2) Whether the transaction has a legal signature; (3) Whether the attached count value is equal to the count of the data status; (4) When it is a data calculation process, check whether the transaction result is legal; verify the result according to the vouchers generated during the calculation process.

3. A data security calculation system for implementing the data security calculation method according to any one of claims 1 to 2, characterized in that, The data security computing system includes: A data management module, which is used to collect data of the data subject; encrypt the data and store it in the cloud distributed database specified by the user; the box does not store the data in plaintext during the data collection and processing process; A data processing module, which is used to implement the desensitization processing of the data and perform joint calculation on the data; during the data collection and encryption process, the key voucher information is saved on the blockchain through smart contracts; other nodes perform consensus, verification, block production, broadcasting and persistence operations on the voucher information through the trust computing model; An intelligent interaction module, which is used to achieve a trusted interaction between the blockchain and the physical world through the anonymous computing box.

4. The data security computing system according to claim 3, wherein In the data management module, the data includes privacy data generated by financial trade, medical insurance, smart energy, social media and daily life; the cloud distributed database includes IPFS.

5. A computer device, characterized in that, The computer device includes a memory and a processor. When the computer program stored in the memory is executed by the processor, the processor executes the data security computing method according to any one of claims 1 to 2, including the following steps: Construct a blockchain-based trust computing model for data collection, storage rights confirmation and joint calculation; propose a plaintext computing trusted space based on blockchain-based distributed multi-mode trust; determine a real-time verifiable contract execution mechanism based on a hardware chip.

6. A computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the processor executes the data security computing method according to any one of claims 1 to 2, including the following steps: Construct a blockchain-based trust computing model for data collection, storage rights confirmation and joint calculation; propose a plaintext computing trusted space based on blockchain-based distributed multi-mode trust; determine a real-time verifiable contract execution mechanism based on a hardware chip.

7. An information data processing terminal, characterized in that, The information data processing terminal is used to implement the data security computing system described in any one of claims 3 to 4.

Citation Information

Patent Citations

  • Blockchain all-in-one machine, password accelerator card thereof, and key management method and device

    CN111541725A

  • Software and hardware implementation mode for getting through different system accounts by using block chain

    CN112036881A