A completely decentralized on-chain system architecture

By setting up data segmentation, encryption and security detection units in the on-chain system architecture and enabling backup nodes when the block running node is invaded, the security problems of the existing decentralized system architecture are solved, and high security and reliability of data storage are achieved.

CN114117469BActive Publication Date: 2025-07-29MIDAS TECH (SHENZHEN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111306232.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-05
Publication Date
2025-07-29
Estimated Expiration
2041-11-05

AI Technical Summary

Technical Problem

The existing decentralized on-chain system architecture is poor in security, and the stored data is easily stolen by the outside world.

Method used

Design a completely decentralized on-chain system architecture, including block operation nodes, data relay chains and backup operation nodes, set up user login units, data allocation units, security detection units, data encryption units, backup encryption units and data storage units, improve data storage security through data segmentation, encryption and security detection, and enable backup operation nodes when block operation nodes are invaded.

Benefits of technology

It improves the security of data storage, makes it difficult for intruders to invade, and can automatically switch to the backup running node when the block running node is invaded to ensure normal data storage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114117469B_ABST
    Figure CN114117469B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of on-chain system architectures, and in particular to a completely decentralized on-chain system architecture, which includes block operation nodes, a data relay chain, and backup operation nodes. A user login unit and a data distribution unit are provided in the data relay chain. A security detection unit, a data encryption unit, and a data storage unit are provided in the block operation nodes. The backup operation nodes are provided with a backup encryption unit and a backup storage unit. Multiple groups of block operation nodes and backup operation nodes are provided, and the structure and operation process of the backup encryption unit are the same as those of the data encryption unit. The present invention can effectively solve the problem that the existing decentralized on-chain system architecture has poor security and the stored data is easily stolen by the outside world.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of on-chain system architectures, and specifically to a completely decentralized on-chain system architecture. Background Art

[0002] Decentralization (English: decentralization) is a social relationship form and content generation form formed during the development of the Internet. It is a new network content production process relative to "centralization". Compared with the early Internet (Web 1.0) era, Web 2.0 content is no longer generated by professional websites or specific groups of people, but is the result of the joint participation and creation of all Internet users with equal rights. Anyone can express their views or create original content on the Internet, jointly producing information. With the diversification of network service forms, the decentralized network model has become increasingly clear and more and more possible. After the rise of Web 2.0, the services provided by network service providers such as Wikipedia, Flickr, and Blogger are all decentralized. Any participant can submit content, and Internet users jointly carry out content collaborative creation or contribution. Subsequently, with the emergence of more simple and easy-to-use decentralized network services, the characteristics of Web2.0 have become more obvious. For example, the birth of services such as Twitter and Facebook, which are more suitable for ordinary Internet users, has made it easier and more diversified to produce or contribute content to the Internet, thereby enhancing the enthusiasm of Internet users to participate and contribute and lowering the threshold for producing content. Eventually, each Internet user has become a tiny and independent information provider, making the Internet more flat and content production more diversified.

[0003] Currently, the existing decentralized on-chain system architectures have poor security, and the stored data is easily stolen by the outside world.

[0004] In summary, the present invention solves the existing problems by designing a completely decentralized on-chain system architecture. Summary of the Invention

[0005] The purpose of the present invention is to provide a completely decentralized on-chain system architecture to solve the problems raised in the above background art.

[0006] To achieve the above purpose, the present invention provides the following technical solutions:

[0007] A completely decentralized on-chain system architecture, including block running nodes, a data relay chain, and backup running nodes. A user login unit and a data distribution unit are arranged in the data relay chain. A security detection unit, a data encryption unit, and a data storage unit are arranged in the block running nodes. A backup encryption unit and a backup storage unit are arranged in the backup running nodes. Multiple groups are arranged in both the block running nodes and the backup running nodes, and the structure and operation process of the backup encryption unit are the same as those of the data encryption unit;

[0008] The specific analysis steps of the data encryption unit are as follows: The data uploaded by the user is divided into s - 1 groups of data fragments, where s is the number of data storage nodes. The data encryption unit encrypts the data fragments one by one using the encrypted public and private keys, thereby obtaining s - 1 groups of encrypted data fragments Epk i (D i ). The data encryption unit calculates the data digest information T i (D i ) of the encrypted data fragment Epk brief (UID i ) according to the digest generation function. The s - 1 groups of encrypted data fragments Epk i (D i ) and their data digest information T brief (UID i ) are sequentially input into the data hash value calculation module, thereby calculating the hash value Hash(D i (D i ) corresponding to the data digest information T brief (UID i ) of the encrypted data fragment Epk i );

[0009] The specific analysis steps of the encryption process include: calculating the multi - base chain Tate pair, selecting the order of the torsion group on the elliptic curve as the parameter n, and expanding the n to m terms using the {2, 3, 5}-multi - base chain expansion algorithm, that is where a1≥a2≥a3≥...≥a m ≥0, b1≥b2≥b3≥...≥b m ≥0, c1≥c2≥c3≥...≥c m ≥0, d i ∈{-1, 1}, 1≤i≤m. Take the rational function f1 = 1, i = 1, and assign the coordinate values (x P , y P ) of the base point P on the elliptic curve to the point T(x1, y1), that is T(x1, y1) = P(x P , y P ). Then, according to the expansion of the order n of the torsion group, ai , b i , c i Using the polynomial expansion algorithm, the pseudo-multiplication algorithm, and the optimization of points, perform double-point calculation, triple-point calculation, five-fold point calculation, and point addition and subtraction calculation on f1 in sequence to obtain the rational function f1'. Increment i by 1, and let f1 = f1'. Determine whether i is less than or equal to m - 1. If so, proceed to the next step; otherwise, repeat this step. When i is less than or equal to m - 1, perform the power exponent operation on the finally obtained f1' to obtain the multi-radix chain Tate pair. Use the encrypted public and private keys input by the user and the multi-radix chain Tate pair to perform encryption calculation on the data segment to obtain the data ciphertext;

[0010] The formula of the described abstract generation function is:

[0011] T brief (UID i ) = (Des(D i ), Type(D i ), DT i (D i ), Sig sks , UID i , SP(UID i ))

[0012] where Des(D i ) is the description of the plaintext data, Type(D i ) is the data type, DT i (D i ) is the number of data entries, Sig sks is the data signature information, UID i is the unique identifier of the data, and SP(UID i ) is the storage proof of the data.

[0013] As a preferred solution of the present invention, the specific analysis steps of the user login unit include: the user inputs the login account and login password into the user login unit. The user login unit compares the input login account and login password with the previously recorded information. If the information matches, the user is allowed to upload data and the public and private keys for encryption. If the information does not match, the operator is prompted that the input information is incorrect. When the number of times the user inputs incorrect information is greater than 5 times, the user login unit is temporarily closed, and the operator is prompted to input again after 30 minutes.

[0014] As a preferred solution of the present invention, the specific analysis steps of the data distribution unit: The data distribution unit assigns a unique ID number to each block running node, selects an ID number using the random sampling method, and transmits the user-uploaded data and the public and private keys for encryption to the corresponding block running node.

[0015] As a preferred solution of the present invention, the specific analysis steps of the security detection unit include:

[0016] Collect network traffic data at the point to be detected, and classify and store the network traffic data into three symbolic features: Protocol_type, Service, and Flag. The three symbolic features of Protocol_type, Service, and Flag are binary processed,

[0017] so as to be converted into numerical features, and then use formula (1) to normalize the feature values:

[0018]

[0019] where x max and x min respectively represent the maximum and minimum values in the value range of the original feature value, x represents the original feature value, and x n is the normalized feature value. Train the GRU network. If the performance index of the GRU network after the training process meets the expected requirements, then the GRU network is a trained GRU network. Use the trained GRU network to detect the preprocessed network traffic data. If the detection data result shows normal data, allow the block running node to run normally. If the detection data result shows intrusion data, then shut down the block running node and start the standby running node.

[0020] As a preferred solution of the present invention, the specific analysis steps for training the GRU network are as follows: Randomly initialize the parameters of the GRU network using a Gaussian distribution. Select the cross-entropy loss function as the loss function, and use the backpropagation algorithm based on time series to update the weights. Select the intrusion detection standard dataset, use the intrusion detection standard dataset as the training set, and perform the above preprocessing on the training set. Input the preprocessed training set into the GRU network in the order of the time arrangement of the sample data to complete the network training process. Match the detected intrusion data with each sample data in the training set one by one. If the match is not successful, it indicates that the detected intrusion data is unknown intrusion data. Add the unknown intrusion data to the training set, and retrain the GRU network with the updated training set every preset time period.

[0021] As a preferred solution of the present invention, the expected requirements are specifically: the detection rate of the GRU network on the training set is higher than 99% and the false alarm rate is lower than 5%.

[0022] A method for using a fully decentralized on-chain system architecture, characterized in that the specific steps include the following:

[0023] S1. The user inputs the login account and login password into the user login unit. The user login unit compares the input login account and login password with the pre-recorded information. If the information matches, the user is allowed to upload data and the public-private key for encryption. If the information does not match, the operator is prompted that the input information is incorrect. When the number of times the user enters incorrect information exceeds 5 times, the user login unit is temporarily closed, and the operator is prompted to enter again after 30 minutes; S2. The data distribution unit assigns a unique ID number to each block running node, selects an ID number using the random sampling method, and transmits the user-uploaded data and the public-private key for encryption to the corresponding block running node;

[0024] S3. The data encryption unit divides the user-uploaded data into s - 1 groups of data segments, where s is the number of data storage nodes, calculates the multi-base chain Tate pair, selects the order of the torsion group on the elliptic curve as the parameter n, and expands the n to m terms using the {2, 3, 5}-multi-base chain expansion algorithm, that is where a1≥a2≥a3≥...≥a m ≥0, b1≥b2≥b3≥...≥b m ≥0, c1≥c2≥c3≥...≥c m ≥0, d i ∈{-1, 1}, 1≤i≤m. Take the rational function f1 = 1, i = 1, and assign the coordinate values (x P , y P ) of the base point P on the elliptic curve to the point T(x1, y1), that is, T(x1, y1) = P(x P , y P ). Then, according to the values of a i , b i , c i in the expansion of the order n of the torsion group, use the polynomial expansion algorithm, the pseudo-multiplication algorithm, and the point optimization to perform double-point calculation, triple-point calculation, five-fold point calculation, and point addition and subtraction calculation on f1 in turn to obtain the rational function f1'. Perform an increment operation on i, and let f1 = f1'. Determine whether i is less than or equal to m - 1. If so, proceed to the next step; otherwise, repeat this step. When i is less than or equal to m - 1, perform the power exponent operation on the finally obtained f1' to obtain the multi-base chain Tate pair. Use the user-input encrypted public-private key pair and the multi-base chain Tate pair to perform encryption calculation on the data segments, thereby obtaining s - 1 groups of encrypted data segments Epk i (D i ). The data encryption unit calculates the data digest information T i (D i ) of the encrypted data segment Epk brief (UID i) The s - 1 groups of encrypted data segments Epk obtained through processing are i (D i )'s data digest information T brief (UID i ) are sequentially input into the data hash value calculation module, thereby calculating the data digest information T of the encrypted data segment Epk(D i ) brief (UID i )'s corresponding hash value Hash(D i )

[0025] S4. The block running node stores the s - 1 groups of encrypted data segments Epk i (D i ), the data digest information T brief (UID i ), and the hash value Hash(D brief (UID i ) corresponding to the data digest information T in the data storage unit; i

[0026] S5. The security detection unit of the block running node collects the network traffic data entering the block running node, classifies and stores the network traffic data into three symbolic features: Protocol_type, Service, and Flag. The three symbolic features of Protocol_type, Service, and Flag are binary - processed, thereby converted into numerical features, and then the formula (1) is used to normalize the feature values:

[0027]

[0028] Among them, x max and x min respectively represent the maximum and minimum values in the original feature value range, x represents the original feature value, and x n is the normalized feature value. Train the GRU network. If the performance indicators of the GRU network after the training process meet the expected requirements, then the GRU network is a trained GRU network. Use the trained GRU network to detect the pre - processed network traffic data. If the detection data result shows normal data, allow the block running node to run normally. If the detection data result shows intrusion data, shut down the block running node and start the standby running node. The standby encryption unit in the standby running node encrypts the data to obtain s - 1 groups of encrypted data segments Epk i (D i ), the data digest information T brief (UID i ) and the data digest information Tbrief (UID i ) corresponding hash value Hash(D i ) and store it in the backup storage unit of the backup running node.

[0029] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0030] 1. In the present invention, by setting up a data encryption unit and a security detection unit, the data uploaded by the user is first decomposed into multiple groups of data fragments by a data segmentation module, and then the data encryption module encrypts the data fragments in sequence to obtain multiple groups of encrypted data fragments, and then stores the multiple groups of encrypted data fragments. An intruder needs to invade symmetrically to obtain all the encrypted data fragments, and the invasion difficulty is relatively high, thus improving the security of data storage. At the same time, the security detection unit can detect the security of the current block running node. If the current block running node is invaded by the outside world, the invaded block running node will be shut down, further improving the security of data storage.

[0031] 2. In the present invention, by setting up a backup running node, when the block running node is shut down due to invasion, the backup running node will be enabled, thus avoiding the situation that data cannot be normally stored after the block running node is shut down due to invasion. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] Figure 1 It is a schematic block diagram of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0033] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of the present invention.

[0034] For the convenience of understanding the present invention, the present invention will be described more comprehensively below with reference to the relevant drawings. Several embodiments of the present invention are given. However, the present invention can be implemented in many different forms and is not limited to the embodiments described herein. On the contrary, the purpose of providing these embodiments is to make the disclosure of the present invention more thorough and comprehensive.

[0035] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which the present invention belongs. The terms used in the description of the present invention in this specification are only for the purpose of describing specific embodiments and are not intended to limit the present invention. The term "and / or" used herein includes any and all combinations of one or more of the related listed items.

[0036] Please refer to Figure 1 , the present invention provides a technical solution:

[0037] A completely decentralized on-chain system architecture, including block running nodes, data relay chains, and backup running nodes, is characterized in that: a user login unit and a data distribution unit are arranged in the data relay chain, a security detection unit, a data encryption unit, and a data storage unit are arranged in the block running nodes, a backup encryption unit and a backup storage unit are arranged in the backup running nodes, multiple groups are arranged in both the block running nodes and the backup running nodes, and the structure and operation process of the backup encryption unit are the same as those of the data encryption unit.

[0038] Example, refer to Figure 1 , the specific analysis steps of the user login unit include: the user inputs a login account and a login password into the user login unit, and the user login unit compares the input login account and login password with the previously recorded information. If the information matches, the user is allowed to upload data and public-private keys for encryption. If the information does not match, the operator is prompted that the input information is incorrect. When the number of times the user inputs incorrect information is greater than 5 times, the user login unit is temporarily closed, and the operator is prompted to input again after 30 minutes.

[0039] Example, refer to Figure 1 , the specific analysis steps of the data distribution unit: the data distribution unit assigns a unique ID number to each block running node, selects an ID number by random sampling method, and transmits the user-uploaded data and public-private keys for encryption to the corresponding block running node.

[0040] Example, refer to Figure 1 , the specific analysis steps of the data encryption unit are: splitting the user-uploaded data into s - 1 groups of data segments, where s is the number of data storage nodes, calculating the multi-base chain Tate pair, selecting the order of the torsion group on the elliptic curve as the parameter n, and expanding the n to m terms using the {2, 3, 5}-multi-base chain expansion algorithm, that is where a1≥a2≥a3≥...≥a m ≥0, b1≥b2≥b3≥...≥b m ≥0, c1≥c2≥c3≥...≥c m ≥0, d i ∈{-1, 1}, 1≤i≤m, take the rational function f1 = 1, i = 1, and assign the coordinate values (x P , y P ) of the base point P on the elliptic curve to the point T(x1, y1), that is T(x1, y1) = P(x P , yP ), and then expand the values of a i , b i , c i in the expansion formula of the order n of the torsion group. Using the polynomial expansion algorithm, the pseudo-multiplication algorithm, and the optimization of points, perform double-point calculation, triple-point calculation, five-point calculation, and point addition and subtraction calculation on f1 in sequence to obtain the rational function f1'. Perform an increment operation of 1 on i, and let f1 = f1'. Determine whether i is less than or equal to m - 1. If so, proceed to the next step; otherwise, repeat this step. When i is less than or equal to m - 1, perform a power exponent operation on the finally obtained f1' to obtain the multi-base chain Tate pair. Use the encryption public and private keys input by the user and the multi-base chain Tate pair to perform encryption calculation on the data segment to obtain the data ciphertext, thereby obtaining s - 1 groups of encrypted data segments Epk i (D i ). The data encryption unit calculates the data digest information T i (D i ) of the encrypted data segment Epk brief (UID i ) according to the digest generation function. The formula of the digest generation function is:

[0041] T brief (UID i ) = (Des(D i ), Type(D i ), DT i (D i ), Sig sks , UID i , SP(UID i ))

[0042] where Des(D i ) is the description of the plaintext data, Type(D i ) is the data type, DT i (D i ) is the number of data entries, Sig sks is the data signature information, UID i is the unique identifier of the data, and SP(UID i ) is the storage proof of the data. Input the data digest information T i (D i ) of the s - 1 groups of encrypted data segments Epk brief (UID i ) into the data hash value calculation module in sequence, thereby calculating the data digest information T i (D i ) of the encrypted data segment Epk brief (UID i)The corresponding hash value Hash(D i ).

[0043] Example, refer to Figure 1 , the specific analysis steps of the security detection unit include: collecting network traffic data at the point to be detected, classifying and storing the network traffic data into three symbolic features of Protocol_type, Service, and Flag, and performing binary processing on the three symbolic features of Protocol_type, Service, and Flag,

[0044] so as to convert them into numerical features, and then normalizing the feature values using formula (1):

[0045]

[0046] where x max and x min respectively represent the maximum and minimum values in the range of the original feature value, x represents the original feature value, and x n is the normalized feature value. Randomly initialize the parameters of the GRU network using a Gaussian distribution, select the cross-entropy loss function as the loss function, and use the time-based backpropagation algorithm to update the weights. Select the intrusion detection standard dataset, use the intrusion detection standard dataset as the training set, and perform the above preprocessing on the training set. Input the preprocessed training set into the GRU network in the order of the time arrangement of the sample data in turn to complete the network training process. Match the detected intrusion data with each sample data in the training set one by one. If the match fails, it indicates that the detected intrusion data is unknown intrusion data. Add the unknown intrusion data to the training set, and retrain the GRU network with the updated training set every preset time period. If the performance indicators of the GRU network after completing the training process meet the expected requirements, the specific expected requirements are: the detection rate of the GRU network on the training set is higher than 99% and the false alarm rate is lower than 5%, then the GRU network is a trained GRU network. Use the trained GRU network to detect the preprocessed network traffic data. If the detection data result shows normal data, allow the block running node to run normally. If the detection data result shows intrusion data, then shut down the block running node and start the standby running node.

[0047] Specific implementation case:

[0048] The user inputs the login account and login password into the user login unit. The user login unit compares the input login account and login password with the pre-recorded information. If the information matches, the user is allowed to upload data and the public-private key for encryption. If the information does not match, the operator is prompted that the input information is incorrect. When the number of times the user enters incorrect information exceeds 5 times, the user login unit is temporarily closed, and the operator is prompted to enter again after 30 minutes;

[0049] The data distribution unit assigns a unique ID number to each block running node, selects an ID number using the random sampling method, and transmits the user-uploaded data and the public-private key for encryption to the corresponding block running node;

[0050] The data encryption unit divides the data uploaded by the user into s - 1 groups of data segments, where s is the number of data storage nodes (s is the number of data storage nodes), calculates the multi-base chain Tate pair, selects the order of the torsion group on the elliptic curve as the parameter n, and expands the n to m terms using the {2, 3, 5}-multi-base chain expansion algorithm, that is where a1≥a2≥a3≥...≥a m ≥0, b1≥b2≥b3≥...≥b m ≥0, c1≥c2≥c3≥...≥c m ≥0, d i ∈{-1, 1}, 1≤i≤m, take the rational function f1 = 1, i = 1, assign the coordinate values (x P , y P ) of the base point P on the elliptic curve to the point T(x1, y1), that is T(x1, y1) = P(x P , y P ), and then according to the values of a i , b i , c i in the expansion of the order n of the torsion group, use the polynomial expansion algorithm, the pseudo-multiplication algorithm and the point optimization to perform double-point calculation, triple-point calculation, five-fold point calculation and point addition and subtraction calculation on f1 in turn to obtain the rational function f1′, perform an increment operation on i, and let f1 = f1′, judge whether i is less than or equal to m - 1, if so, enter the next step, otherwise, repeat this step. When i is less than or equal to m - 1, perform the power exponent operation on the finally obtained f1′ to obtain the multi-base chain Tate pair, and use the encryption public-private key pair input by the user and the multi-base chain Tate pair to perform encryption calculation on the data segment to obtain s - 1 groups of encrypted data segments Epk i (D i ), the data encryption unit calculates the data digest information T of the encrypted data segment Epk i (D i ) according to the digest generation functionbrief (UID i ), the s - 1 groups of encrypted data segments Epk i (D i )'s data digest information T brief (UID i ) are sequentially input into the data hash value calculation module, so as to calculate the data digest information T i of the encrypted data segment Epk(D brief (UID i ) corresponding hash value Hash(D i );

[0051] The block running node stores the s - 1 groups of encrypted data segments Epk i (D i ), the data digest information T brief (UID i ) and the hash value Hash(D brief (UID i ) corresponding to the data digest information T i ) in the data storage unit;

[0052] The security detection unit of the block running node collects the network traffic data entering the block running node, classifies and stores the network traffic data into three symbolic features of Protocol_type, Service and Flag, performs binary processing on the three symbolic features of Protocol_type, Service and Flag, so as to convert them into numerical features, and then uses the formula

[0053] (1) to normalize the feature values:

[0054]

[0055] where, x max and x min respectively represent the maximum and minimum values on the value range of the original feature value, x represents the original feature value, and x n is the normalized feature value. Train the GRU network. If the performance indicators of the GRU network after the training process meet the expected requirements, then the GRU network is a trained GRU network. Use the trained GRU network to detect the pre - processed network traffic data. If the detection data result shows normal data, allow the block running node to run normally. If the detection data result shows intrusion data, then shut down the block running node and start the standby running node. The standby encryption unit in the standby running node encrypts the data to obtain s - 1 groups of encrypted data segments Epk i (D i) Data digest information T brief (UID i ) and data digest information T brief (UID i ) corresponding hash value Hash(D i ) and store it in the spare storage unit of the spare operating node.

[0056] Although embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A completely decentralized on-chain system architecture, including block running nodes, data relay chains, and backup running nodes, characterized in that: A user login unit and a data distribution unit are provided in the data relay chain. A security detection unit, a data encryption unit, and a data storage unit are provided in the block operation node. A backup encryption unit and a backup storage unit are provided in the backup operation node. Multiple groups of block operation nodes and backup operation nodes are provided, and the structure and operation process of the backup encryption unit are the same as those of the data encryption unit; The specific analysis steps of the data encryption unit are as follows: The data uploaded by the user is divided into s - 1 groups of data segments, where s is the number of data storage nodes. The data encryption unit encrypts the data segments one by one using the encrypted public and private keys, thereby obtaining s - 1 groups of encrypted data segments Epk i (D i ). The data encryption unit calculates the data digest information T i (D i ) of the encrypted data segments Epk brief (UID i ) according to the digest generation function. The s - 1 groups of encrypted data segments Epk i (D i ) with the processed data digest information T brief (UID i ) are sequentially input into the data hash value calculation module, thereby calculating the hash value Hash(D i (D i ) corresponding to the data digest information T brief (UID i ) of the encrypted data segments Epk i ); The specific analysis steps of the encryption process include: calculating to obtain a multi-base chain Tate pair, selecting the order of the torsion group on the elliptic curve as the parameter n, and expanding the n to m terms using the {2, 3, 5}-multi-base chain expansion algorithm, that is where a1≥a2≥a3≥...≥a m ≥0, b1≥b2≥b3≥...≥b m ≥0, c1≥c2≥c3≥...≥c m ≥0, d i ∈{-1, 1}, 1≤i≤m, take the rational function f1 = 1, i = 1, assign the coordinate values (x P , y P ) of the base point P on the elliptic curve to the point T(x1, y1), that is T(x1, y1) = P(x P , y P ), and then according to the values of a i , b i , c i in the expansion of the order n of the torsion group, use the polynomial expansion algorithm, the pseudo-multiplication algorithm and the point optimization to perform double-point calculation, triple-point calculation, five-fold point calculation and point addition and subtraction calculation on f1 in turn to obtain the rational function f1′, perform an increment operation of 1 on i, and let f1 = f1′, judge whether i is less than or equal to m - 1, if so, enter the next step, otherwise, repeat this step. When i is less than or equal to m - 1, perform the power exponent operation on the finally obtained f1′ to obtain the multi-base chain Tate pair, and use the encrypted public and private keys input by the user and the multi-base chain Tate pair to perform encryption calculation on the data segment to obtain the data ciphertext; The formula of the abstract generation function is: T brief (UID i ) = (Des(D i ), Type(D i ), DT i (D i ), Sig sks , UID i , SP(UID i )) Among them, Des(D i ) is the description of the plaintext data, Type(D i ) is the data type, DT i (D i ) is the number of data entries, Sig sks is the data signature information, UID i is the unique identifier of the data, and SP(UID i ) is the storage proof of the data.

2. The fully decentralized on-chain system architecture according to claim 1, characterized in that: The specific analysis steps of the user login unit include: The user inputs a login account and a login password into the user login unit. The user login unit compares the input login account and login password with the previously entered information. If the information matches, the user is allowed to upload data and the public-private key for encryption. If the information does not match, the operator is prompted that the input information is incorrect. When the number of times the user enters incorrect information is greater than 5 times, the user login unit is temporarily closed, and the operator is prompted to enter again after 30 minutes.

3. A completely decentralized on-chain system architecture according to claim 2, characterized in that: The specific analysis steps of the data distribution unit: The data distribution unit assigns a unique ID number to each block operation node, selects an ID number using the random sampling method, and transmits the user-uploaded data and the public-private key for encryption to the corresponding block operation node.

4. A completely decentralized on-chain system architecture according to claim 3, characterized in that: The specific analysis steps of the security detection unit include: collecting network traffic data at the points to be detected, classifying and storing the network traffic data into three symbolic features of Protocol_type, Service, and Flag, performing binary processing on the three symbolic features of Protocol_type, Service, and Flag to convert them into numerical features, and then normalizing the feature values using formula (1): where x max and x min represent the maximum and minimum values in the range of the original eigenvalue respectively, x represents the original eigenvalue, and x n is the normalized eigenvalue. Train the GRU network. If the performance metrics of the GRU network after the training process meet the expected requirements, then the GRU network is a trained GRU network. Use the trained GRU network to detect the preprocessed network traffic data. If the detected data result shows normal data, then allow the block running node to run normally. If the detected data result shows intrusion data, then shut down the block running node and start the standby running node.

5. A completely decentralized on-chain system architecture according to claim 4, characterized in that: The specific analysis steps for training the GRU network are as follows: Randomly initialize the parameters of the GRU network using a Gaussian distribution. Select the cross-entropy loss function as the loss function. Use the time-based backpropagation algorithm for weight update for the weight update rule. Select the intrusion detection standard dataset, use the intrusion detection standard dataset as the training set, and perform the preprocessing on the training set. Input the preprocessed training set into the GRU network in the order of the time arrangement of the sample data in sequence to complete the network training process. Match the detected intrusion data with each sample data in the training set one by one. If the match is not successful, it indicates that the detected intrusion data is unknown intrusion data. Add the unknown intrusion data to the training set, and retrain the GRU network using the updated training set every preset time period.

6. The completely decentralized on-chain system architecture according to claim 5, characterized in that: The specific requirements are as follows: The detection rate of the GRU network on the training set is higher than 99% and the false alarm rate is lower than 5%.

7. A method of using a completely decentralized on-chain system architecture according to claim 1, characterized in that The specific steps are as follows: S1. The user inputs a login account and a login password into the user login unit. The user login unit compares the input login account and login password with the previously entered information. If the information matches, the user is allowed to upload data and the public-private key for encryption. If the information does not match, the operator is prompted that the input information is incorrect. When the number of times the user enters incorrect information is greater than 5 times, the user login unit is temporarily closed, and the operator is prompted to enter again after 30 minutes; S2. The data distribution unit assigns a unique ID number to each block operation node, selects an ID number using the random sampling method, and transmits the user-uploaded data and the public-private key for encryption to the corresponding block operation node; S3, the data encryption unit divides the data uploaded by the user into s - 1 groups of data segments, where s is the number of data storage nodes, calculates the multi - base chain Tate pair, selects the order of the torsion group on the elliptic curve as the parameter n, and expands the n to m terms using the {2, 3, 5}-multi - base chain expansion algorithm, that is where a1≥a2≥a3≥...≥a m ≥0, b1≥b2≥b3≥...≥b m ≥0, c1≥c2≥c3≥...≥c m ≥0, d i ∈{-1, 1}, 1≤i≤m, take the rational function f1 = 1 when i = 1, assign the coordinate values (x P , y P ) of the base point P on the elliptic curve to the point T(x1, y1), that is T(x1, y1)=P(x P , y P ), and then according to the values of a i , b i , c i in the expansion of the order n of the torsion group, use the polynomial expansion algorithm, the pseudo - multiplication algorithm and the point optimization to perform double - point calculation, triple - point calculation, five - point calculation and point addition and subtraction calculation on f1 in turn to obtain the rational function f1′, perform an increment operation on i, and let f1 = f1′, judge whether i is less than or equal to m - 1, if so, enter the next step, otherwise, repeat this step. When i is less than or equal to m - 1, perform the power - exponent operation on the finally obtained f1′ to obtain the multi - base chain Tate pair. Use the encryption public and private keys input by the user and the multi - base chain Tate pair to perform encryption calculation on the data segments, so as to obtain s - 1 groups of encrypted data segments Epk i (D i ). The data encryption unit calculates the data digest information T i (D i ) of the encrypted data segment Epk brief using the digest generation function, and inputs the data digest information T i of the s - 1 groups of encrypted data segments Epk i (D i ) obtained by processing into the data hash value calculation module in turn, so as to calculate the hash value Hash(D brief ) corresponding to the data digest information T i of the encrypted data segment Epk(D i ) brief (UID i ) i ; At S4, the block running node stores the s-1 groups of encrypted data segments Epk processed by the data encryption unit i (D i ), the data digest information T brief (UID i ), and the hash value Hash(D brief (UID i ) corresponding to the data digest information T i ) in the data storage unit; S5. The security detection unit of the block running node collects the network traffic data entering the block running node, classifies and stores the network traffic data into three symbolic features: Protocol_type, Service, and Flag. The three symbolic features of Protocol_type, Service, and Flag are binary processed to be converted into numerical features, and then the formula (1) is used to normalize the feature values: where x max and x min represent the maximum and minimum values in the range of the original eigenvalue, respectively, x represents the original eigenvalue, and x n is the normalized eigenvalue. Train the GRU network. If the performance metrics of the GRU network after the training process meet the expected requirements, then the GRU network is a trained GRU network. Use the trained GRU network to detect the preprocessed network traffic data. If the detection data result shows normal data, allow the block running node to run normally. If the detection data result shows intrusion data, then shut down the block running node and start the standby running node. The standby encryption unit in the standby running node encrypts the data to obtain s - 1 groups of encrypted data segments Epk i (D i ), the data digest information T brief (UID i ), and the hash value Hash(D brief )(UID i ) corresponding to the data digest information T i ) and store them in the standby storage unit of the standby running node.

Citation Information

Patent Citations

  • Data backup method and device in block chain system

    CN113157494A

  • Data cross-blockchain access control method and system in multi-blockchain scene, equipment and terminal

    CN113364735A