A LAN blockchain tamper-proof method and system based on a trusted execution environment

By deploying a trusted execution environment in the LAN and the blockchain interaction between the regulatory network and the regulated network, the problems of tampering and leakage of LAN data are solved, and data immutability and traceability supervision are realized.

CN114186285BActive Publication Date: 2025-09-02HANGZHOU WEIMING XINKE TECH CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111296020.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-03
Publication Date
2025-09-02
Estimated Expiration
2041-11-03

AI Technical Summary

Technical Problem

The existing LAN data supervision methods cannot effectively ensure the authenticity and immutability of data, and blockchain technology has the risk of data leakage in LAN applications.

Method used

Deploy a trusted execution environment in the regulated LAN, use the blockchain interaction between the regulated network and the regulated network to generate a blockchain with a public key mark, confirm the integrity of the blockchain data through the public key mark, and prevent internal tampering in the trusted execution environment.

Benefits of technology

It realizes immutable supervision of LAN data, reduces the risk of data leakage, and ensures data traceability and transparency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114186285B_ABST
    Figure CN114186285B_ABST
Patent Text Reader

Abstract

The embodiment of the present invention provides a tamper-proof method and system for a local area network blockchain based on a trusted execution environment (TEE). The method includes: a supervisory network sequentially generates at least one supervisory network block to form a supervisory network blockchain; a TEE is deployed in a supervised local area network and its public key is obtained from trusted hardware; at a first supervisory network block, the supervised network opens a connection to the supervisory network, and the supervisory network blockchain receives a transaction request from the supervised network, the transaction request including the public key; the supervisory network blockchain confirms the transaction and begins generating a supervisory network block marked with the public key; the supervisory network block marked with the public key is copied to the supervised network; at least one supervised network block is sequentially generated according to the transaction to form a supervised network blockchain; at the end of the supervised network blockchain, the supervised network opens a connection with the supervisory network at the last supervised network block and merges it with the supervisory network data to generate a second supervisory network block; the supervisory network blockchain confirms whether a block in the supervised network is generated by a supervisory network block marked with the public key through the public key mark, so as to determine whether the supervised network data has been tampered with.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to a local area network blockchain tamper-proofing method and system based on a trusted execution environment. Background Art

[0002] Blockchain is essentially a distributed database that organizes data into blocks in chronological order and sequentially links them into a chain-like data structure. Cryptography ensures that the data cannot be tampered with or forged. Broadly speaking, blockchain also refers to distributed accounting technologies based on blockchain structures, including distributed consensus, privacy and security protections, peer-to-peer communication technologies, network protocols, and smart contracts. Blockchain technology utilizes an encrypted chain-like block structure to verify and store data and a distributed node consensus algorithm to generate and update data. Consensus algorithms are mathematical algorithms that establish trust and acquire rights between different nodes in a blockchain system. Blockchains can be categorized into three types based on the different participants: public chains, consortium chains, and private chains. Public chains are open to the public; any node connected to the public network can join and read data, such as Ethereum. Consortium chains have access control mechanisms, limiting access to data to authorized users. Private chains are open only to a specific organization or entity.

[0003] A Trusted Execution Environment (TEE) ensures that computing is not interfered with by the regular operating system, thus ensuring a "trusted" computing process. This is achieved by creating a small operating system that can run independently in a "secure world." This operating system directly provides computing services through system calls (handled directly by the kernel). The TEE consists of two components: trusted hardware and trusted software. The trusted hardware provides a completely isolated operating environment from the outside world, protecting the internal software from attacks.

[0004] Existing LAN data supervision relies primarily on regulated parties regularly exporting data from the LAN and providing it to regulators. Regulated parties can modify data before final submission, making it impossible to ensure data authenticity and immutability. While blockchain technology can provide data traceability and supervision, it requires the regulated party's system to be connected to the supervisory network, which poses the risk of data leakage. Currently, no blockchain technology exists to effectively monitor LAN data. While blockchain technology has been widely and maturely applied in regulatory scenarios, its application in regulatory LANs has received limited attention and faces numerous challenges due to the unique characteristics of LANs. Summary of the Invention

[0005] In view of this, the purpose of the present invention is to propose a local area network blockchain tamper-proof method based on a trusted execution environment, which can specifically solve the existing problems.

[0006] Based on the above objectives, according to a first aspect of the present invention, the present invention proposes a tamper-proof method for a local area network blockchain based on a trusted execution environment, comprising:

[0007] The supervisory network sequentially generates at least one supervisory network block to form a supervisory network blockchain;

[0008] Deploy a trusted execution environment in the regulated party's local area network and obtain its public key from the trusted hardware;

[0009] The supervised network opens a connection to the supervised network at the first supervised network block, and the supervised network blockchain receives a transaction request from the supervised network, wherein the transaction request includes the public key;

[0010] The regulatory network blockchain confirms the transaction and begins generating regulatory network blocks marked with public keys;

[0011] Copying the supervisory network block with the public key mark to the supervised network;

[0012] Generate at least one regulated network block in sequence according to the transactions to form a regulated network blockchain;

[0013] When the supervised network blockchain ends, the supervised network opens a connection with the supervisory network at the last supervised network block and merges it with the supervisory network data to generate a second supervisory network block;

[0014] The supervisory network blockchain uses public key marking to confirm whether the blocks in the supervised network are generated by supervisory network blocks with public key markings to determine whether the data in the supervised network has been tampered with.

[0015] Furthermore, when at least one supervised network block is generated sequentially according to transactions to form a supervised network blockchain, the supervisory network also generates a supervisory network block normally at the same time.

[0016] Furthermore, in the regulated network blockchain, each block includes a summary of the previous block and transaction information.

[0017] Furthermore, the supervisor synchronizes the information of the supervised party.

[0018] Furthermore, when at least one supervised network block is generated sequentially according to the transaction to form a supervised network blockchain, the supervisory network obtains the current block status of the supervised party, writes the status into the latest supervisory network block, and continues to generate supervisory network blocks.

[0019] Furthermore, when at least one regulated network block is generated sequentially according to the transaction to form a regulated network blockchain, the data information is encrypted and stored in the regulated network block.

[0020] Furthermore, both the supervised network block and the supervisory network block carry the public key mark.

[0021] Furthermore, there are one or more supervised networks.

[0022] Furthermore, the regulatory network and the regulated network form a directed acyclic graph blockchain system.

[0023] Based on the above objectives, according to a second aspect of the present invention, the present invention proposes a local area network blockchain tamper-proof system based on a trusted execution environment, comprising:

[0024] Supervisory network;

[0025] At least one supervised party's local area network;

[0026] The supervisory network and at least one supervised local area network execute the method described in the first aspect to form a directed acyclic graph blockchain system.

[0027] In general, the advantages of the present invention and the experience it brings to users are:

[0028] (1) Utilize the traceability and immutability of blockchain to record and track data operations.

[0029] (2) By designing the interactive interface between the supervisory network and the supervised network, the supervised network periodically connects to the supervisory network and ensures that the internal data of the supervised network cannot be tampered with, thereby ensuring that the supervisory network monitors the supervised network and greatly reducing the risk of data leakage within the supervised network.

[0030] (3) Ensure the credibility of the blockchain within the regulated network by deploying a trusted execution environment in the regulated network. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] In the accompanying drawings, unless otherwise specified, the same reference numerals throughout the multiple drawings represent the same or similar components or elements. These drawings are not necessarily drawn to scale. It should be understood that these drawings only depict some embodiments disclosed herein and should not be construed as limiting the scope of the invention.

[0032] Figure 1 A schematic diagram of the blockchain-based local area network data supervision principle of the present invention is shown.

[0033] Figure 2 The flowchart of the blockchain-based local area network data supervision method of the present invention is shown.

[0034] Figure 3 A schematic diagram of the tamper-proof principle of a local area network blockchain based on a trusted execution environment of the present invention is shown.

[0035] Figure 4 The flowchart of the local area network blockchain tamper-proof method based on a trusted execution environment of the present invention is shown. DETAILED DESCRIPTION

[0036] The present invention will be further described in detail below with reference to the accompanying drawings and examples. It should be understood that the specific embodiments described herein are intended only to illustrate the invention and are not intended to limit the invention. It should also be noted that, for ease of description, only portions relevant to the invention are shown in the accompanying drawings.

[0037] It should be noted that, in the absence of conflict, the embodiments and features of the embodiments of the present invention can be combined with each other. The present invention will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0038] like Figure 1 As shown in the figure, the principle of the local area network data supervision system based on blockchain in the present invention, the part in the dotted box represents the supervised network, and the rest represents the supervision network.

[0039] When the blockchain of the supervisory network is generated to block A, the supervised network 1 will temporarily open access to the blockchain, and a new block B will be generated in the supervised network 1. After that, the connection between the supervised network 1 and the supervisory network will be closed. The blockchain in the supervised network 1 will be generated downward along block B. While generating the block, the data information will be encrypted and stored in the block.

[0040] Within the supervised network 1 or 2, a trusted execution environment is used to prevent internal data tampering.

[0041] When the supervisory network's blockchain reaches block C, supervised network 2 temporarily opens access to that blockchain, generating a new block D within supervised network 2. Afterward, the connection between supervised network 2 and the supervisory network is closed, and the blockchain within supervised network 2 continues to grow downwards from block D. As blocks are generated, data is encrypted and stored within them. The supervisory system of the present invention supports data supervision across multiple supervised network environments.

[0042] When the block of regulated network 1 is generated to block G, the regulator needs to obtain relevant data for supervision. Regulated network 1 temporarily opens the connection with the regulatory network and merges it with the regulatory network data to generate block H, which is incorporated into the regulatory network blockchain. After that, regulated network 1 closes the connection with the regulatory network.

[0043] When the blockchain of regulated network 2 generates block E, the regulator needs to obtain relevant data for supervision. Regulated network 2 temporarily opens the connection with the regulatory network and merges it with the regulatory network data to generate block F, which is incorporated into the blockchain of the regulatory network. After that, regulated network 2 closes the connection with the regulatory network.

[0044] The above process can be repeated continuously to form a directed acyclic graph blockchain system.

[0045] The blockchain-based local area network data supervision system of the present invention cannot tamper with the data in the blockchain due to the immutability of the blockchain, thereby achieving the supervision effect.

[0046] like Figure 2 As shown in the figure, the flowchart of the local area network data supervision method based on blockchain includes the following steps:

[0047] A1. The regulator begins generating regulatory network blocks;

[0048] A2. The supervisory blockchain generates block A;

[0049] A3. The regulated network begins connecting to the regulatory network blockchain;

[0050] A4. The blockchain on the regulated network begins generating blocks within the regulated network, using block A as its root block. Simultaneously, the blockchain on the regulating network also generates blocks normally, and the regulating network and the regulated network are disconnected.

[0051] A5. Each node in the regulated network accepts the transaction and gradually generates new blocks. Each block includes a summary of the previous block and transaction information, forming a chain.

[0052] A6. Supervisors need to synchronize information with those supervised parties;

[0053] A7. The regulated party opens a local area network and connects to the regulatory blockchain.

[0054] A8. The supervisory network blockchain obtains the current block status of the supervised network, writes this status into the latest supervisory network block, and continues to generate supervisory network blocks;

[0055] A9. The supervisory network blockchain completes supervision of the regulated network, and the regulated network is disconnected from the supervisory network blockchain.

[0056] A10. Since each block records a summary of the previous block, once it is written into the regulatory network blockchain, the blockchain information within the regulatory network cannot be tampered with, thus achieving regulatory effectiveness.

[0057] A11. The regulated party obtains the latest block on the current regulated network blockchain and uses it as the root block to continue generating a new chain within the regulated network, i.e. repeating A4, A5, A6, and A7.

[0058] The inventive point of the present invention is that, based on the above blockchain-based local area network data supervision system and method, a trusted execution environment is deployed in the supervised network to prevent data tampering within the supervised network. Figure 3 A schematic diagram of the tamper-proof principle of a local area network blockchain based on a trusted execution environment of the present invention is shown.

[0059] When the supervisory network's blockchain reaches a certain block, the supervised network will temporarily open access to that blockchain. Within the supervised network, a trusted execution environment (TEE) is used to prevent internal data tampering. The supervised party deploys a TEE in its local area network and obtains its public key from trusted hardware. When the supervised network opens its connection to the supervisory network, the supervisory network blockchain receives a transaction request from the supervised network, which includes the public key. The supervisory network blockchain confirms the transaction and begins generating supervisory network blocks marked with the public key.

[0060] The supervisory network block marked with the public key is copied to the supervised network, and then at least one supervised network block is generated in sequence according to the transaction to form the supervised network blockchain; when the supervised network block is generated to the sixth block, the supervisor needs to obtain the relevant data of the supervision, the supervised network temporarily opens the connection with the supervisory network, and merges the data with the supervisory network to generate a block, which is incorporated into the supervisory network blockchain.

[0061] The supervisory network blockchain then uses public key marking to confirm whether the blocks in the supervised network are generated by supervisory network blocks with public key markings to determine whether the data in the supervised network has been tampered with.

[0062] The above process can be repeated continuously to form a directed acyclic graph blockchain system.

[0063] The blockchain-based local area network data supervision system of the present invention cannot tamper with the data in the blockchain due to the immutability of the blockchain, thereby achieving the supervision effect.

[0064] Figure 4 The flowchart of the LAN blockchain anti-tampering method based on a trusted execution environment of the present invention is shown, which includes the following steps:

[0065] B1. Deploy a Trusted Execution Environment (TEE) in the supervised local area network.

[0066] B2. Obtain its public key (P) from the trusted hardware.

[0067] B3. When the regulated network interface is opened to the regulated network blockchain, the regulated network blockchain receives a transaction request (the transaction information includes the public key).

[0068] B4. The regulatory network blockchain confirms the transaction.

[0069] B5. The regulatory network blockchain begins to generate blocks marked with public keys.

[0070] B6. The block marked with the public key is copied to the supervised network.

[0071] B7. Disconnect the supervision network and the supervised network, and start generating blocks in the supervised network. All newly generated blocks in the supervised network are marked with public keys.

[0072] B8. The last block in the Regulated Network is merged into the Regulated Network blockchain. Both the Regulated Network block and the Regulated Network block are marked with the public key.

[0073] B9. The supervisory network blockchain uses public key marking to confirm whether the blocks in the supervised network are generated from the original blocks, so as to determine whether the data in the supervised network has been tampered with.

[0074] B10. The connection with the supervisory network is disconnected by the supervisory network.

[0075] The blockchain-based data supervision system and method for supervised networks utilizes the traceability and transparency of blockchain to record and track data operations. By designing an interface between the supervisory network and the supervised network, the supervised network periodically accesses the supervisory network, ensuring that data within the supervised network cannot be tampered with. This ensures that the supervisory network monitors the supervised network and prevents data leakage within the supervised network. Data tampering within the supervised network is prevented by deploying a trusted execution environment within the supervised network.

[0076] It should be noted that:

[0077] The algorithms and displays provided herein are not inherently related to any particular computer, virtual system, or other device. Various general-purpose systems may also be used together with the teachings herein. Based on the above description, it is apparent that the structure required for constructing such systems is suitable. In addition, the present invention is not directed to any specific programming language. It should be understood that various programming languages ​​can be utilized to implement the present invention described herein, and the description of specific languages ​​above is intended to disclose the best mode of implementation of the present invention.

[0078] In the description provided herein, numerous specific details are described. However, it is understood that embodiments of the present invention may be practiced without these specific details. In some instances, well-known methods, structures, and techniques are not shown in detail so as not to obscure the understanding of this description.

[0079] Similarly, it should be understood that in order to streamline the present invention and aid in understanding one or more of the various inventive aspects, in the above description of exemplary embodiments of the present invention, various features of the present invention are sometimes grouped together into a single embodiment, figure, or description thereof. However, this disclosed method should not be interpreted as reflecting an intention that the claimed invention requires more features than are expressly recited in each claim. Rather, as reflected in the claims below, inventive aspects lie in less than all the features of the individual embodiments disclosed above. Accordingly, the claims following the detailed description are hereby expressly incorporated into this detailed description, with each claim standing on its own as a separate embodiment of the present invention.

[0080] Those skilled in the art will appreciate that the modules in the devices in the embodiments may be adaptively changed and arranged in one or more devices different from the embodiments. The modules or units or components in the embodiments may be combined into one module or unit or component, and in addition may be divided into multiple submodules or subunits or subcomponents. All features disclosed in this specification (including the accompanying claims, abstracts and drawings) and all processes or units of any method or device disclosed herein may be combined in any combination, except that at least some of such features and / or processes or units are mutually exclusive. Unless expressly stated otherwise, each feature disclosed in this specification (including the accompanying claims, abstracts and drawings) may be replaced by an alternative feature providing the same, equivalent or similar purpose.

[0081] Furthermore, those skilled in the art will appreciate that although some embodiments described herein include certain features included in other embodiments but not other features, combinations of features from different embodiments are intended to be within the scope of the present invention and to form different embodiments. For example, in the claims below, any of the claimed embodiments may be used in any combination.

[0082] The various component embodiments of the present invention can be implemented in hardware, or in software modules running on one or more processors, or in a combination thereof. It should be understood by those skilled in the art that a microprocessor or digital signal processor can be used in practice to implement some or all of the functions of some or all of the components in the creation system of the virtual machine according to an embodiment of the present invention. The present invention can also be implemented as a device or system program (e.g., a computer program and a computer program product) for executing part or all of the methods described herein. Such a program implementing the present invention can be stored on a computer-readable medium, or can have the form of one or more signals. Such a signal can be downloaded from an Internet website, or provided on a carrier signal, or provided in any other form.

[0083] It should be noted that the above embodiments illustrate rather than limit the invention, and that those skilled in the art may devise alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between brackets should not be construed as limiting the claims. The word "comprising" does not exclude the presence of elements or steps not listed in the claims. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present invention may be implemented by means of hardware comprising several different elements and by means of suitably programmed computers. In a unit claim enumerating several systems, several of these systems may be embodied by the same item of hardware. The use of the words first, second, and third etc. does not indicate any order. These words may be interpreted as names.

[0084] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various modifications and substitutions within the technical scope disclosed in the present invention, and such modifications and substitutions are intended to be within the scope of protection of the present invention. Therefore, the scope of protection of the present invention shall be subject to the scope of protection of the claims.

Claims

1. A tamper-proof method for a local area network blockchain based on a trusted execution environment, characterized in that: include: The supervision network sequentially generates at least one supervision network block to form a supervision network blockchain; Deploy a trusted execution environment in the regulated party's local area network and obtain its public key from the trusted hardware; The supervised network opens a connection to the supervised network at the first supervised network block, and the supervised network blockchain receives a transaction request from the supervised network, wherein the transaction request includes the public key; The regulatory network blockchain confirms the transaction and begins generating regulatory network blocks marked with public keys; Copying the supervisory network block with the public key mark to the supervised network; Generate at least one regulated network block in sequence according to the transactions to form a regulated network blockchain; When the supervised network blockchain ends, the supervised network opens a connection with the supervisory network at the last supervised network block and merges it with the supervisory network data to generate a second supervisory network block; The supervisory network blockchain uses public key marking to confirm whether the blocks in the supervised network are generated by supervisory network blocks with public key markings to determine whether the data in the supervised network has been tampered with.

2. The method according to claim 1, characterized in that When at least one supervised network block is generated sequentially according to the transaction to form a supervised network blockchain, the supervisory network also generates a supervisory network block normally at the same time.

3. The method according to claim 1 or 2, characterized in that: The supervision network can be a public network or a local area network.

4. The method according to claim 1 or 2, characterized in that: The regulatory network blockchain can be a public chain, a consortium chain or a private chain.

5. The method according to claim 1 or 2, characterized in that: The supervised network is a local area network.

6. The method according to claim 1 or 2, characterized in that In the regulated network blockchain, each block includes a summary of the previous block and transaction information.

7. The method according to claim 1 or 2, characterized in that The supervisor synchronizes the information of the supervised party.

8. The method according to claim 1 or 2, characterized in that When at least one supervised network block is generated sequentially according to the transaction to form a supervised network blockchain, the supervisory network obtains the current block status of the supervised party, writes the status into the latest supervisory network block, and continues to generate supervisory network blocks.

9. The method according to claim 1 or 2, characterized in that When at least one regulated network block is generated sequentially according to the transaction to form a regulated network blockchain, the data information is encrypted and stored in the regulated network block.

10. The method according to claim 1 or 2, characterized in that Both the supervised network block and the supervisory network block are marked with the public key.

11. The method according to claim 1 or 2, characterized in that There are one or more supervised networks.

12. The method according to claim 1 or 2, characterized in that The regulatory network and the regulated network form a directed acyclic graph blockchain system.

13. A local area network blockchain anti-tampering system based on a trusted execution environment, characterized in that: include: Supervisory network; At least one supervised party's local area network; The supervisory network and at least one supervised local area network execute the method described in any one of claims 1 to 12 to form a directed acyclic graph blockchain system.

Citation Information

Patent Citations

  • Local area network data supervision method and system based on block chain

    CN113726819A