A Blockchain-Based Distributed Data Security Storage Method for Satellite Clusters
By adopting Raft consensus protocol and a two-layer storage architecture in satellite clusters, combining cloud computing platform and container technology, the single point of failure and deployment complexity of satellite cluster data storage is solved, distributed secure storage and efficient data retrieval are realized, and user-friendly data storage and query interface are provided.
Patent Information
- Application Number
- CN202111402149.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-19
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2041-11-19
AI Technical Summary
There are problems in the satellite cluster system with single point of failure of data storage, low security, large overhead, complex deployment of blockchain nodes and low consensus protocol efficiency, which cannot meet the real-time requirements of the satellite cluster system.
The random consensus protocol based on Raft and a two-layer storage architecture are adopted, combined with blockchain and cloud computing platforms, and the blockchain system and client platform are adapted and deployed on the cloud computing platform through container technology to achieve rapid deployment and dynamic expansion of blockchain nodes. The underlying blockchain stores data changes and increments, and the top-level database stores the final state, providing a visual client platform interface.
It realizes distributed secure storage in a satellite cluster environment, reduces node computing energy consumption, improves consensus protocol efficiency, optimizes the data retrieval process, solves the high overhead and complex deployment problems of traditional blockchain storage, and provides a user-friendly data storage and query interface.
Smart Images

Figure CN114116899B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of cloud computing security, and particularly relates to a method for distributed data secure storage of a satellite cluster based on a blockchain. Background Art
[0002] Since the 20th century, the development of the infrastructure construction of satellite cluster systems has gradually become the main goal of competition among major space powers. With the development of space technology, it is urgent to build a distributed computing system based on a satellite cluster network. At present, from the development trend of satellite cluster networks, the amount of data collected by satellites is gradually increasing, and the security of data information is becoming more and more sensitive. However, the traditional architecture based on centralized storage services has certain limitations and cannot provide distributed, multi-level, and load-balanced data storage services, so it is not suitable for the distributed system architecture of satellite clusters. In addition, in the field of traditional relational databases, taking the representative MySQL as an example, although this database can achieve efficient operations for storing data, because its centralized architecture is prone to single-point failure problems, it is not suitable for satellite cluster systems with sensitive data.
[0003] As a new technology for highly secure distributed computing and storage, the blockchain's characteristics such as decentralization, immutability, and traceability provide the possibility for realizing secure backup and disaster recovery of space-based network data, sharing among heterogeneous groups, and maximizing multilateral interests. However, in the field of traditional blockchain digital ledgers, taking Ethereum that supports smart contracts as an example, although this database can achieve functions such as anti-single-point failure and data tampering prevention, its data operation efficiency is low and cannot meet the real-time requirements of satellite cluster systems; on the other hand, in the existing blockchain technology development, the deployment of blockchain nodes is relatively cumbersome and complex, and it is necessary to statically set the parameter information in the configuration file in advance, which does not adapt to the dynamic requirements of the addition of blockchain nodes in satellite clusters.
[0004] As the world's first database application platform based on a blockchain, ChainSQL is the first blockchain software product in China to obtain a commercial cryptography product model certificate issued by the State Cryptography Administration. This platform combines the advantages of blockchain technology and traditional databases. It not only has the distributed, decentralized, and auditable characteristics of the blockchain, but also has the characteristics of fast query and beautiful data structure of traditional databases. However, its efficiency in the consensus node selection stage is low and cannot meet the requirements of high-concurrency business scenarios of data volume in satellite cluster systems.
[0005] In summary, in the prior art, there are problems such as single-point failures, low data storage security, and high overhead costs in the data storage of satellite clusters; in the case of distributed data storage based on a blockchain, the existing solutions do not consider the dynamics of the addition of blockchain nodes, the efficiency of consensus protocols, and the real-time nature of data storage and retrieval. Summary of the Invention
[0006] The object of the present invention is to overcome the security problems easily generated by the centralized storage of data in a satellite cluster, and to provide a distributed data security storage method for a satellite cluster based on blockchain. By combining blockchain and a cloud computing platform, it is ensured that in a satellite cluster environment without the participation of a trusted third party, the stable and rapid deployment of blockchain nodes and the distributed security storage of spatial cluster data are guaranteed.
[0007] In order to achieve the above object, the technical solution adopted by the present invention is as follows:
[0008] A distributed data security storage method for a satellite cluster based on blockchain, comprising the following steps:
[0009] S1, generate a blockchain system, determine a random consensus protocol based on Raft, and the content of the random consensus protocol based on Raft includes that while generating a new block in each round, the accounting proxy node in this round randomly selects the accounting node in the next round;
[0010] S2, generate blockchain nodes, select at least three nodes as blockchain master nodes in intelligent cluster embedded nodes, deploy the blockchain system on the blockchain master nodes, and the blockchain master nodes after deploying the blockchain system are used to obtain the transaction on-chain request of the client platform. The blockchain master nodes can store the data in the transaction in the database of the master nodes through the random consensus protocol, and deploy the client platform;
[0011] S3, insert data into the blockchain system deployed on the satellite cluster nodes through the client platform or by calling the API interface provided by the blockchain system.
[0012] In S1, the specific method for determining the random consensus protocol based on Raft is as follows:
[0013] Step 1, the blockchain node j decrypts the secret information field Nx_M of the block Block(n - 1) in the (n - 1)th round with its own public key Kpub and determines whether it is the accounting blockchain node in the nth round. If so, execute Step 2;
[0014] Step 2, the blockchain node j generates the accounting blockchain node x in the next round through the Raft random function Raft(.), and fills its own signature Sig, public key certificate Cert, the secret information Nx_M of the blockchain node x, timestamp Tamp, and the transaction data collected within a current period of time into the block Blockn;
[0015] Step 3: The blockchain node j broadcasts the newly generated block Blockn to the remaining blockchain nodes in the cluster, and then waits for data feedback from other blockchain nodes. It counts the number of received feedback data. When node j receives more than two-thirds of the total number of consensus nodes in the entire blockchain network, it will write the block Blockn into the local blockchain;
[0016] Step 4: When other blockchain nodes within the cluster receive Blockn, they first verify the hash chain relationship before and after the block, and then use the public key certificate Cert of node j to verify whether the signature field Sig in the block header is valid. Subsequently, they obtain the secret information fields Pr_M and Nx_M in the Blockn block header to verify the authenticity of the identities of the nth round accounting node and the (n + 1)th round accounting node;
[0017] Step 5: If all verifications pass, the node sends an acceptance message true to the current packaging node j and writes the block Blockn into the local blockchain.
[0018] In S1, the blockchain system includes a bottom-layer blockchain and a top-layer database. The data writing of the blockchain system includes the writing of the bottom-layer blockchain and the writing of the top-layer database;
[0019] The bottom-layer blockchain is the incremental data changes stored using the blockchain data structure. The top-layer database is the final state set of data obtained from the bottom-layer data changes; the bottom-layer blockchain is structurally stored using a relational database, and the top-layer database uses the database type required by the business;
[0020] The bottom-layer blockchain is the incremental data changes stored using the blockchain data structure. The bottom-layer blockchain uses a chained data structure with high tail writing performance; the bottom-layer blockchain accepts the user's on-chain request through the API, broadcasts the on-chain request in the form of a transaction to be chained among nodes. When the consensus block time arrives, the node packages the current transaction to be chained into a block and stores it in the database of the bottom-layer blockchain following the blockchain data structure;
[0021] The top-layer database is the final state set of data obtained from the bottom-layer data changes. The top-layer database is stored using a block structure and uses a B+ tree to establish an index; whenever each proxy node obtains a consistent block using the consensus protocol, it will reproduce the data changes increment in the new block into the top-layer state database. The top-layer state database is the latest state and uses a B+ tree to establish an index.
[0022] In S1, the blockchain system is designed based on a javascript web client platform.
[0023] In S2, the client platform is adaptively deployed in the cloud computing platform, and can initiate an on-chain request transaction to the blockchain system inside the intelligent cluster.
[0024] In S2, the specific method for generating blockchain nodes is as follows:
[0025] The blockchain system is encapsulated into a container image using container technology. The container image includes a blockchain image and a database image, and the blockchain system image is uploaded to the image repository of the satellite cluster;
[0026] Declare a Deployment container application, pull the blockchain image and the database image from the image repository into the container; then mount the config configuration file into the container volume; subsequently, declare the application label name to distinguish each Deployment container application; finally, set the pod port number to receive or send data information;
[0027] Declare a Service container application, map the port numbers of each Deployment container application to the port numbers of the service to receive data from other services inside the cluster, use a fixed IP number for the Service container application, and set the clusterIP parameter under the Service to None;
[0028] Add and start the yaml file of the blockchain system and the yaml file of the blockchain service in the cloud computing platform.
[0029] In S2, the specific method for deploying the client platform is as follows:
[0030] The client platform is encapsulated into a container image using container technology, and then the client platform image is uploaded to the image repository of the satellite cluster;
[0031] Declare a Deployment container application, pull the client platform image from the image repository into the container; then declare the application label name to distinguish each Deployment container application; finally, set the pod port number to receive or send data information;
[0032] Declare a Service container application, map the port numbers of each Deployment container application to the port numbers of the service to receive data from other services inside the cluster. Then set the Service to the NodePort type to ensure data access to the blockchain system inside the cluster by external users of the cluster;
[0033] Add the yaml file of the client platform container and the yaml file of the client platform service to the yaml file set of the cloud computing platform, and start the client platform through the control line command.
[0034] When inserting data into the blockchain system deployed on satellite cluster nodes through the client platform, the user directly launches the interface, selects the data insertion option, and enters the SQL insertion statement in the corresponding window to complete the data insertion into the blockchain system deployed on satellite cluster nodes.
[0035] When the user selects to insert data into the blockchain system deployed on satellite cluster nodes through the API interface provided by the blockchain system, the specific method is as follows:
[0036] Call the blockchain data on-chain request interface. The blockchain data on-chain request interface, as the gateway of the blockchain system, is responsible for receiving the on-chain requests of new data.
[0037] Use container technology to compile the application program independently written by the user into an image file and upload it to the image repository.
[0038] Design and write a yaml file to adapt and deploy the application program independently written by the user on the cloud computing platform. When the yaml file is started, the data will be automatically stored in the blockchain system deployed on satellite cluster nodes according to the program process.
[0039] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0040] The present invention uses blockchain technology to distribute and store sensitive data in the satellite cluster, realizing the distributed and secure storage of data in the satellite cluster environment, and solving problems such as single point of failure easily generated by traditional centralized storage services; adopts a secure and efficient Raft-based random consensus protocol, which greatly reduces the computing energy consumption of nodes while ensuring the randomness and verifiability of the selection of proxy accounting nodes, and improves the efficiency of the consensus protocol; adopts a two-layer storage architecture, which solves problems such as large storage overhead and slow data retrieval in traditional blockchains; adapts and deploys the blockchain system and the client platform on the cloud computing platform, solving problems such as complex deployment and difficult compatibility in the development of traditional blockchain systems; adopts a client platform based on the front-end interface to provide a visual interface for the storage and query processes of the blockchain database, facilitating users to use the distributed data storage system based on blockchain for satellite clusters.
[0041] Furthermore, the present invention adopts a two-layer storage architecture of the underlying blockchain and the top-level database. The underlying blockchain is used to store the data increment in the transaction, and the top-level database is used to store the final state of the data, optimizing the data query and retrieval process while ensuring the secure storage of data within the cluster.
[0042] Furthermore, the present invention deploys the blockchain system and the client platform adaptively on the cloud computing platform. By designing the yaml configuration file, the rapid deployment and horizontal expansion of blockchain nodes are ensured, thus facilitating the dynamic migration of blockchain nodes and enhancing the startup process of the blockchain system. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] Figure 1 It is the blockchain data structure diagram of the present invention;
[0044] Figure 2 It is the flowchart of the consensus algorithm of the blockchain system in the present invention;
[0045] Figure 3 It is the interface display of the client platform of the present invention;
[0046] Figure 4 It is the flowchart of the adaptation stage of the blockchain system in the present invention;
[0047] Figure 5 It is the flowchart of the data storage and query stage of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0048] The present invention will be further described below with reference to the accompanying drawings.
[0049] In the information age, satellites and weaponry are developing towards the direction of group intelligence of networking and clustering. They are supported by technical platforms such as embedded and Internet technologies, connecting devices or systems with different functions into an interconnected and interactive whole, making the connections between resource elements at different levels closer, and being able to form a three-dimensional, efficient, and fully functional whole with all-round attack and all-dimensional defense to improve the cooperation efficiency. However, in the intelligent cluster scenario, it has the characteristics of dispersed resources, mixed heterogeneity, and high dynamic changes in network topology. In order to ensure the security and reliability of information sharing among cluster devices, there is an urgent need for a decentralized and highly available distributed data sharing solution to rationally utilize the information resources in the entire cluster and provide reliable and feature-rich services for upper-layer applications.
[0050] The present invention conducts innovation and research on these problems and proposes a blockchain-based distributed data security storage method for satellite clusters. In order to ensure the security of data storage among satellite devices in the distributed space cluster network environment, it is necessary to use blockchain as the key technology for data security storage in the intelligent cluster network.
[0051] The present invention is a method for distributed data secure storage in a satellite cluster based on blockchain. The intelligent cluster is composed of multiple satellite nodes distributed in different spaces. Any node in the cluster is connected to at least two lines. When any one line fails, communication can be completed via other links, with high security and reliability. Blockchain is a distributed ledger architecture jointly maintained by multiple parties and capable of achieving consistent data storage. The data in this ledger does not require a trusted third party for maintenance, but is jointly verified and maintained by each blockchain node in the intelligent cluster network. The distributed data storage based on blockchain for the satellite cluster in the present invention is carried out in three stages: the first stage is the blockchain system generation stage, the second stage is the blockchain system deployment stage, and the third stage is the data storage and query stage, which specifically includes the following steps:
[0052] To more conveniently and clearly describe the activity process of data storage among satellite devices in the satellite cluster network. It is assumed that the satellite nodes within the cluster have all previously registered public-private key pairs (Kpub, Kpri) at the CA.
[0053] 1. Blockchain system generation stage:
[0054] (1.1) Construct the blockchain data structure:
[0055] Refer to Figure 1 , the data stored by the satellite cluster devices designed in the present invention is stored in the blockchain in the form of transaction bills, and adjacent blocks form a blockchain in a hash chain manner. At the same time, considering that the huge storage overhead of the blockchain is not suitable for the limited storage space of the space cluster nodes, the present invention adopts a sliding window mechanism to only retain the data of the most recent period. The specific data structure of the blockchain is as follows:
[0056] Block header: Hash value of the previous blockchain P_Hash; number of the current block Num. Specifically, the number of the nth block Blockn is n; current timestamp Tamp; public key certificate Cert of the current bookkeeping node; information Pr_M of the current bookkeeping node; hash root value Hash of the block body; secret information Nx_M of the next bookkeeping node; signature Sig of the current bookkeeping node for the entire block information.
[0057] Block body: Contains the transaction request information obtained by the whole network within the current period, and calculates the hash root value Hash in the current block header through hashing.
[0058] Sliding window mechanism: To achieve lightweight data storage in the satellite cluster environment, the present invention adopts a sliding window mechanism, that is, only retains all the blocks within the window and the genesis block Block0, and deletes the block body data in the remaining historical blocks outside the window.
[0059] (1.2) Design consensus protocol:
[0060] The consensus algorithm is a key technology to ensure the consistent sharing of stored data in the satellite cluster environment, and it runs on the blockchain nodes. The present invention adopts a secure and efficient random consensus protocol based on Raft. The core idea is that while generating a new block in each round, the accounting blockchain node in this round randomly selects the accounting blockchain node in the next round. Taking the consensus in the nth round as an example (assuming that the accounting blockchain node i in the (n - 1)th round selects the accounting blockchain node j in the nth round), the steps of this consensus protocol are specifically described as follows:
[0061] (1.21) Refer to Figure 2 , the blockchain node j decrypts the secret information field Nx_M of the block Block(n - 1) in the (n - 1)th round with its public key Kpub and determines whether it is the accounting blockchain node in the nth round. If so, it executes step (1.22);
[0062] (1.22) The blockchain node j generates the accounting blockchain node x in the next round through the Raft random function Raft(.), and fills its signature Sig, public key certificate Cert, the secret information Nx_M of the blockchain node x, timestamp Tamp, and the transaction data collected within a current period of time into the block Blockn;
[0063] (1.23) The blockchain node j broadcasts the generated new block Blockn to the remaining blockchain nodes in the cluster, and then waits for the data feedback from other blockchain nodes, and counts the number of received feedback data. When the node j receives more than two-thirds of the number of consensus nodes in the entire blockchain network, it writes the block Blockn into the local blockchain;
[0064] (1.24) When other blockchain nodes in the cluster receive Blockn, they first verify the hash chain relationship before and after the block, and then verify whether the signature field Sig in the block header is valid with the public key certificate Cert of the node j. Subsequently, they obtain the secret information fields Pr_M field and Nx_M field in the Blockn block header to verify the authenticity of the identities of the accounting node in the nth round and the accounting node in the (n + 1)th round;
[0065] (1.25) If all verifications pass, the node sends an acceptance message true to the current packaging node j and writes the block Blockn into the local blockchain.
[0066] (1.3) Generate a two-layer database storage architecture:
[0067] The present invention adopts a double - layer blockchain database architecture of a bottom - layer blockchain and a top - layer database, and the writing of data is completed from bottom to top. It includes a hierarchical blockchain database, the writing of the bottom - layer blockchain, and the writing of the top - layer database, which are specifically described as the following steps:
[0068] (1.31) Divide the data into two layers through hierarchical design; the bottom layer is the incremental change of data stored using the blockchain data structure, and the top layer is the final state set of data obtained from the incremental change of the bottom - layer data. The bottom layer uses a relational database for structured storage, and the top layer can use the database type required by the business.
[0069] (1.32) The bottom layer is the incremental change of data stored using the blockchain data structure. The chained data structure has high write performance at the tail; accept the user's on - chain request through the API, broadcast the on - chain request in the form of a transaction to be chained among nodes. When the consensus block time arrives, the node packages the current transaction to be chained into a block and stores it in the bottom - layer blockchain database following the blockchain data structure.
[0070] (1.33) The top layer is the final state set of data obtained from the incremental change of the bottom - layer data, which is stored in a block structure and an index is established using a B + tree; whenever each proxy node obtains a consistent block using the consensus protocol, it will reproduce the incremental change of data in the new block to the top - layer state database. The top - layer state database is the latest state, and an index is established using a B + tree.
[0071] (1.4) Build a client platform:
[0072] See Figure 3 , in order to ensure the fast insertion of blockchain data and the visual data query, the present invention develops a client website platform based on the blockchain server system. In this platform, users can initiate an on - chain transaction request to the blockchain node in the form of a domain name. At the same time, users can also query the block data of the most recent blocks (within the window) and the record content under a specific table name.
[0073] The present invention applies blockchain technology to the satellite cluster scenario and realizes secure storage among satellite clusters in a distributed environment. The present invention adopts an efficient consensus protocol and a sliding window mechanism, which greatly reduces the computing energy consumption and storage consumption during the operation of the blockchain system. The double - layer storage architecture optimizes the retrieval time consumption of user data query while ensuring the secure storage of internal cluster data. At the same time, users can insert sensitive data into the satellite cluster and query relevant records in a user - friendly manner.
[0074] 2. Blockchain system deployment stage
[0075] (2.1) Generate blockchain nodes:
[0076] Select at least three nodes in the intelligent cluster embedded nodes as blockchain master nodes and deploy the blockchain system on them to obtain the transaction on-chain requests of the client platform. Then, the blockchain master nodes can store the data in the transaction in the database of the master nodes through the consensus protocol. To ensure the efficient deployment and rapid horizontal expansion of subsequent blockchain nodes, this solution adapts and deploys the blockchain system in the cloud computing platform to facilitate the startup and load balancing of the blockchain system.
[0077] In step (2.1), the blockchain system is adapted and deployed in the cloud computing platform and blockchain nodes are generated. To facilitate the efficient deployment of the blockchain system and the rapid startup of blockchain nodes, it is necessary to deploy the cloud computing platform on each space cluster node in advance so that the space nodes can easily deploy and manage containerized applications (blockchain system), see Figure 4 , and the specific deployment process is as follows:
[0078] (2.11) Compile the blockchain system image file. The present invention uses container technology to encapsulate the blockchain system into a container image, including a blockchain image and a database image. Then, the blockchain system image is uploaded to the image repository of the satellite cluster for subsequent use in distributed secure storage application services based on the blockchain.
[0079] (2.12) Configure the blockchain system yaml file. Since the blockchain system involved in the present invention includes a blockchain image, a database image, and a config configuration file, it is necessary to design, configure, and add a yaml file to adapt and deploy the blockchain system in the cloud computing platform. The specific description is as follows:
[0080] (2.12a) Design the yaml file of the blockchain system. First, declare the Deployment container application, pull the blockchain image and the database image from the image repository into the container; then mount the config configuration file into the container volume; then declare the application label name to distinguish each Deployment container application; finally, set the pod port number to receive or send data information;
[0081] (2.12b) Design the YAML file for the blockchain service. First, declare the Service container application, map the port numbers of each Deployment container application to the port numbers of the service, which is used to receive data from other services within the cluster. Since the podIP value changes during each system restart, the present invention uses the Service container application to fix the IP number. Other services or containers within the cluster only need to access the fixed IP of the service and the port number of the container to access the container under this service. Then, set the clusterIP parameter under the Service to None to facilitate access between blockchain nodes in the way of "domain name + port number".
[0082] (2.12c) Add and start the YAML file of the blockchain system and the YAML file of the blockchain service in the cloud computing platform. At this time, it can be seen that the blockchain system has been randomly deployed on the satellite cluster nodes, and this node has become a blockchain node.
[0083] The present invention adapts and deploys the blockchain system in the cloud computing platform. By configuring the YAML file, it ensures the rapid deployment of the blockchain system in the satellite cluster and the horizontal expansion of blockchain nodes. Moreover, the cloud computing platform supports functions such as container automated management, load balancing, and log query. Therefore, the deployment and operation process of the present invention in the satellite cluster environment will be more efficient and stable.
[0084] (2.2) Deploy the client platform:
[0085] In order to initiate an on-chain request transaction to the blockchain system within the intelligent cluster, the client platform is adapted and deployed in the cloud computing platform.
[0086] In step (2.2), in order to achieve the rapid and secure storage of data in the blockchain system in the cloud computing platform, the client platform also needs to be deployed in the cloud computing platform. The specific deployment process is as follows:
[0087] (2.21) Compile the client image file. Also using container technology, encapsulate the client platform into a container image, and then upload the client platform image to the image repository of the satellite cluster.
[0088] (2.22) Configure the YAML file of the client platform. In order to ensure that users can quickly and conveniently insert, store, and query sensitive data into the satellite cluster, it is necessary to design, configure, and add the YAML file of the client platform to adapt and deploy the client platform in the cloud computing platform. The specific description is as follows:
[0089] (2.22a) Design the YAML file for the client platform container. First, declare the Deployment container application to pull the client platform image from the image repository into the container. Then, declare the application label name to distinguish each Deployment container application. Finally, set the pod port number to receive or send data information.
[0090] (2.22b) Design the YAML file for the client platform service. First, declare the Service container application to map the port numbers of each Deployment container application to the service port number for receiving data from other services within the cluster. Then, set the Service to the NodePort type to ensure data access to the blockchain system inside the cluster by external users of the cluster.
[0091] (2.22c) Add the YAML file of the client platform container and the YAML file of the client platform service to the YAML file set of the cloud computing platform. The client platform can be started through the control line command. At this time, users can access the client interface outside the cluster and perform data storage and data query operations.
[0092] The present invention deploys the client platform developed based on JavaScript web in the cloud computing platform. While ensuring that users store sensitive data in the satellite cluster, it vividly displays the specific data content stored inside the space cluster in a visual form.
[0093] 3. Data storage and query phase
[0094] (3.1) Data storage and query:
[0095] This system can insert data into the satellite cluster through the client platform or by calling the API interface provided by the blockchain system. At the same time, this system can query and obtain the data content stored in the satellite cluster through the client platform.
[0096] In step (3.1), the user can insert data into the satellite cluster through the client platform or by writing a program to call the API interface provided by the blockchain system. See Figure 5 , which specifically includes the following steps:
[0097] (3.11) The present invention provides two data storage methods, and users can choose according to their own needs. If the user needs to quickly insert a limited amount of data into the blockchain system, the user can start the client platform to complete the data storage process. If the user needs to insert a large amount of data into the blockchain, the user can write a data insertion program by himself / herself and complete the process of storing a large amount of data by calling the API interface provided by the blockchain system.
[0098] (3.12) If the user chooses to insert data into the blockchain system through the client platform, the user can directly launch the interface, select the data insertion option, and enter the SQL insertion statement in the corresponding window to insert sensitive data into the blockchain system deployed on the satellite cluster nodes.
[0099] (3.13) If the user chooses to insert data into the blockchain system by writing an application program and calling an interface, the data storage process is as follows:
[0100] (3.13a) When writing the data storage function module, call the blockchain data uploading request interface. This interface, as the gateway of the blockchain system, is responsible for receiving the uploading requests of new data. It should be noted that when the user sets the destination address of data transmission, the domain name and port number of the blockchain node need to be filled in.
[0101] (3.13b) Adopt container technology to compile the application program independently written by the user into an image file and upload it to the image repository.
[0102] (3.13c) Design and write a yaml file to adapt and deploy the application program independently written by the user on the cloud computing platform. After starting this yaml file, its massive data will be automatically stored in the blockchain system according to the program process.
[0103] (3.14) The user can query the table records and block information in the database through the client platform.
[0104] The above description does not constitute any limitation to the present invention. Obviously, for professionals in the field, after understanding the content and principle of the present invention, various modifications and changes in form and details may be made without departing from the principle and structure of the present invention. However, these modifications and changes based on the idea of the present invention are within the scope of protection of the claims of the present invention.
[0105] In short, the present invention discloses a blockchain-based distributed data security storage method for satellite clusters. It mainly solves the security problems easily generated by the centralized storage of data in existing satellite clusters. By combining blockchain and cloud computing platforms, it ensures the stable and rapid deployment of blockchain nodes and the distributed security storage of cluster data in a satellite cluster environment without the participation of a trusted third party. The implementation scheme is as follows: 1. In the blockchain system generation stage, the decentralized storage function and front-end interface display function of the blockchain system are realized by designing the blockchain data structure, consensus algorithm, and database storage architecture; 2. In the blockchain system adaptation stage, in combination with container technology, the blockchain system and the client platform are compiled into image files; 3. By designing and writing a yaml file, the blockchain system and the client platform are adapted and deployed on the cloud computing platform; 4. In the data storage and query stage, users insert sensitive data into the blockchain system through the client platform or by writing their own storage programs; 5. Users query the specific record information stored in the database within the satellite cluster through the client platform.
Claims
1. A blockchain-based distributed data security storage method for satellite clusters, characterized in that, It includes the following steps: S1. Generate a blockchain system, determine a random consensus protocol based on Raft. The content of the random consensus protocol based on Raft includes that while generating a new block in each round, the accounting proxy node in this round randomly selects the accounting node for the next round; The blockchain system includes a bottom-layer blockchain and a top-layer database. The data writing of the blockchain system includes the writing of the bottom-layer blockchain and the writing of the top-layer database; The bottom-layer blockchain is the incremental data change stored in the blockchain data structure. The top-layer database is the final state set of data obtained from the bottom-layer data change increment. The bottom-layer blockchain is structurally stored using a relational database, and the top-layer database uses the database type required by the business; S2. Generate blockchain nodes. Select at least three nodes from the intelligent cluster embedded nodes as the blockchain master nodes. Deploy the blockchain system on the blockchain master nodes. After the deployment of the blockchain system, the blockchain master nodes are used to obtain the transaction on-chain requests from the client platform. The blockchain master nodes can store the data in the transaction in the database of the master nodes through the random consensus protocol and deploy the client platform. The specific method for generating blockchain nodes is as follows: Use container technology to package the blockchain system into a container image. The container image includes a blockchain image and a database image. Upload the blockchain system image to the image repository of the satellite cluster; Declare the Deployment container application, pull the blockchain image and the database image from the image repository into the container; then mount the config configuration file into the container volume; subsequently declare the application label name to distinguish each Deployment container application; finally set the pod port number to receive or send data information; Declare the Service container application, map the port numbers of each Deployment container application to the port numbers of the service to receive data from other services within the cluster. Use a fixed IP number for the Service container application and set the clusterIP parameter under the Service to None; Add and start the yaml file of the blockchain system and the yaml file of the blockchain service in the cloud computing platform; S3. Insert data into the blockchain system deployed on the satellite cluster nodes through the client platform or by calling the API interface provided by the blockchain system.
2. The satellite cluster distributed data security storage method based on blockchain according to claim 1, characterized in that, In S1, the specific method for determining the random consensus protocol based on Raft is as follows: Step 1. The blockchain node j decrypts the secret information field Nx_M of the block Block(n - 1) in the (n - 1)-th round with its own public key Kpub and determines whether it is the accounting blockchain node in the n-th round. If so, execute Step 2; Step 2. The blockchain node j generates the accounting blockchain node x for the next round through the Raft random function Raft(.), and fills its own signature Sig, public key certificate Cert, the secret information Nx_M of the blockchain node x, the timestamp Tamp, and the transaction data collected within a current period of time into the block Blockn; Step 3: The blockchain node j broadcasts the newly generated block Blockn to the remaining blockchain nodes in the cluster, and then waits for data feedback from other blockchain nodes, and counts the number of received feedback data. When node j receives more than two-thirds of the number of consensus nodes in the entire blockchain network, it will write the block Blockn into the local blockchain; Step 4: When other blockchain nodes within the cluster receive Blockn, they first verify the hash chain relationship before and after the block, and then use the public key certificate Cert of node j to verify whether the signature field Sig in the block header is valid. Subsequently, they obtain the secret information fields Pr_M and Nx_M in the Blockn block header, and verify the authenticity of the identities of the nth round accounting node and the (n + 1)th round accounting node; Step 5: If all verifications pass, the node sends an acceptance message true to the current packaging node j and writes the block Blockn into the local blockchain.
3. A method for distributed data security storage of a satellite cluster based on blockchain according to claim 1, characterized in that, In S1, the underlying blockchain is the incremental data change stored using the blockchain data structure. The underlying blockchain uses a chained data structure with high tail writing performance; the underlying blockchain accepts the user's on-chain request through the API, broadcasts the on-chain request in the form of a transaction to be chained among nodes, and when the consensus block time arrives, the node packages the current transaction to be chained into a block and stores it in the database of the underlying blockchain following the blockchain data structure; The top-level database is the final state set of data obtained from the underlying data change increment. The top-level database is stored in a block structure and uses a B+ tree to build an index; whenever each proxy node obtains a consistent block using the consensus protocol, it will reproduce the data change increment in the new block into the top-level state database, and the top-level state database is the latest state and uses a B+ tree to build an index.
4. A method for distributed data security storage of a satellite cluster based on blockchain according to claim 1, characterized in that, In S1, the blockchain system is designed based on a javascript web client platform.
5. A method for distributed data security storage of a satellite cluster based on blockchain according to claim 1, characterized in that, In S2, the client platform is adaptively deployed in the cloud computing platform and can initiate an on-chain request transaction to the blockchain system within the intelligent cluster.
6. A satellite cluster distributed data security storage method based on blockchain according to claim 1, characterized in that, In S2, the specific method for deploying the client platform is as follows: Use container technology to encapsulate the client platform into a container image, and then upload the client platform image to the image repository of the satellite cluster; Declare the Deployment container application, pull the client platform image from the image repository into the container; then declare the application label name to distinguish each Deployment container application; finally, set the pod port number to receive or send data information; Declare the Service container application, map the port numbers of each Deployment container application to the port number of the service to receive data from other services within the cluster; Then set the Service to the NodePort type to ensure data access by external users of the cluster to the blockchain system within the cluster; Add the yaml file of the client platform container and the yaml file of the client platform service to the yaml file set of the cloud computing platform, and start the client platform through the control line command.
7. A method for distributed data security storage of a satellite cluster based on blockchain according to claim 1, characterized in that, When inserting data into the blockchain system deployed on satellite cluster nodes through the client platform, the user directly launches the interface, selects the data insertion option, and enters the SQL insertion statement in the corresponding window to complete the data insertion into the blockchain system deployed on satellite cluster nodes.
8. A method for distributed data security storage of a satellite cluster based on blockchain according to claim 1, characterized in that, When the user chooses to insert data into the blockchain system deployed on satellite cluster nodes through the API interface provided by the blockchain system, the specific method is as follows: Call the blockchain data on-chain request interface. The blockchain data on-chain request interface, as the gateway of the blockchain system, is responsible for receiving the on-chain requests of new data; Use container technology to compile the application program independently written by the user into an image file and upload it to the image repository; Design and write a yaml file to adapt the application program independently written by the user for deployment on the cloud computing platform. When the yaml file is launched, the data will be automatically stored in the blockchain system deployed on satellite cluster nodes according to the program process.
Citation Information
Patent Citations
Blockchain construction method and system, storage medium, computer equipment and application
CN112118124A
Blockchain network deployment method, electronic device, and computer-readable storage medium
WO2021098140A1