A blockchain-based data processing method, device, equipment and computer storage medium

By implementing a dual authentication mechanism and spatial stamp information traceability on the blockchain, the problem of low storage and query efficiency in data product transactions has been solved, and accurate traceability and secure transmission of data information have been achieved.

CN114528582BActive Publication Date: 2026-02-03CHINA MOBILE INFORMATION TECHNOLOGY CO LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011323730.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-11-23
Publication Date
2026-02-03
Estimated Expiration
2040-11-23

AI Technical Summary

Technical Problem

Existing blockchain traceability systems suffer from low storage and retrieval efficiency in data product transactions, and cannot guarantee the accuracy and security of data information, making it difficult to achieve precise traceability.

Method used

By implementing a two-factor authentication mechanism on the blockchain, access records are generated and traceability is performed based on spatial stamp information. Combined with smart contracts to manage access periods and identity information, data transmission security is ensured, enabling verification from both spatial and temporal dimensions.

Benefits of technology

It effectively avoids the possibility of data being counterfeited or illegally disseminated during transmission, enables accurate traceability of data, and improves the security of data transmission and query efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114528582B_ABST
    Figure CN114528582B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a kind of data processing method, device and equipment based on blockchain and computer storage medium, it is related to data processing field, to realize the accurate tracing of data on blockchain.The method comprises: first target access node sends data transmission request to data node, after the authentication of target access node passes, allow first target access node and data node carry out data transmission, and generate the access record of first target access node, first target access node is any node in multiple access nodes;According to the access record of multiple second target access nodes, determine the space stamp information of multiple data transmitted, second target access node is the access node of first target access node for completing data transmission;Based on space stamp information, trace multiple data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of blockchain, and in particular relates to a data processing method, apparatus, device and computer storage medium based on blockchain. Background Technology

[0002] In the era of big data, the data trading industry has developed rapidly, but it also faces many problems. Because data is a reproducible and tamper-proof trading product, and the industry lacks unified standards, data trading suffers from a series of issues such as unlimited resale, continuously decreasing market value, unclear ownership, and poor data reliability. Therefore, data traceability is urgently needed.

[0003] Because of its characteristics of trustworthiness, decentralization, immutability, and information transparency, blockchain has become the preferred technology for building traceability systems. Blockchain-based traceability systems will inevitably greatly promote the development of the data trading industry, making traceability more valuable in the process of data product transactions. However, with the development of blockchain technology, the massive amounts of data stored on the blockchain lead to low storage and retrieval efficiency, making it difficult to trace the source of data information on the blockchain. Furthermore, the transmission of data between multiple nodes on the blockchain cannot guarantee the accuracy of the traceable data.

[0004] In summary, existing blockchain technologies make it difficult to trace the source of data on the blockchain and cannot guarantee the accuracy of the traced data. Summary of the Invention

[0005] This invention provides a data processing method, apparatus, device, and computer storage medium based on blockchain, which can achieve accurate traceability of data information on the blockchain.

[0006] In a first aspect, embodiments of the present invention provide a data processing method based on blockchain, the method comprising:

[0007] The first target access node sends a data transmission request to the data node. After the target access node is authenticated, the first target access node is allowed to transmit data with the data node and an access record of the first target access node is generated. The first target access node can be any node among multiple access nodes.

[0008] Based on the access records of multiple second target access nodes, determine the spatial stamp information of the multiple transmitted data. The second target access node is the access node that completed the data transmission among the first target access nodes.

[0009] Based on spatial stamp information, multiple data can be traced.

[0010] Secondly, embodiments of the present invention provide a blockchain-based data processing device, the device comprising:

[0011] The generation module is used to send a data transmission request to the data node through the first target access node. After the target access node is authenticated, the first target access node is allowed to transmit data with the data node, and an access record of the first target access node is generated. The first target access node can be any node among multiple access nodes.

[0012] The determination module is used to determine the spatial stamp information of multiple transmitted data based on the access records of multiple second target access nodes, wherein the second target access node is the access node that completed the data transmission among the first target access nodes.

[0013] The traceability module is used to trace the source of multiple data information transmitted on the blockchain based on spatial stamp information.

[0014] Thirdly, embodiments of the present invention provide a blockchain-based data processing device, the device comprising:

[0015] A processor, and a memory storing computer program instructions; the processor reads and executes the computer program instructions to implement the blockchain-based data processing method provided in the first aspect of the present invention.

[0016] Fourthly, embodiments of the present invention provide a computer storage medium storing computer program instructions, which, when executed by a processor, implement the blockchain-based data processing method provided in the first aspect of the present invention.

[0017] The blockchain-based data processing method, apparatus, device, and computer storage medium of this invention ensure the security of data transmission between data nodes and access nodes by employing an authentication mechanism that verifies the identity information of the access node corresponding to the access node when the access node sends a data transmission request to the data node. Combined with the authentication results of the aforementioned identity authentication, an access record of the access node is generated. Simultaneously, based on the access records of multiple access nodes that have completed data transmission, spatial stamp information of the transmitted data is determined. Based on the spatial stamp information, the data information is traced back to its source. Compared to existing technologies, this method verifies data from both spatial and temporal dimensions, effectively preventing identity impersonation or transfer by other access nodes, while reducing the possibility of illegal dissemination or leakage of data information during transmission, thus achieving accurate traceability of data information. Attached Figure Description

[0018] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments of the present invention will be briefly introduced below. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0019] Figure 1 This is a flowchart illustrating a data processing method based on blockchain provided in an embodiment of the present invention;

[0020] Figure 2 This is a flowchart illustrating a blockchain-based data processing system provided in an embodiment of the present invention.

[0021] Figure 3 This is a schematic diagram of the structure of a private blockchain block provided in an embodiment of the present invention;

[0022] Figure 4 This is a schematic diagram of the structure of a consortium blockchain block provided in an embodiment of the present invention;

[0023] Figure 5 This is a schematic diagram of a spatial stamp granularity visualization structure provided by an embodiment of the present invention;

[0024] Figure 6 This is a schematic diagram of the structure of a blockchain external database provided in an embodiment of the present invention;

[0025] Figure 7 This is a schematic diagram of the structure of a blockchain-based data processing device provided in an embodiment of the present invention;

[0026] Figure 8 This is a schematic diagram of the structure of a blockchain-based data processing device provided in an embodiment of the present invention. Detailed Implementation

[0027] The features and exemplary embodiments of various aspects of the present invention will now be described in detail. To make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are merely intended to explain the present invention and not to limit the present invention. For those skilled in the art, the present invention can be practiced without some of these specific details. The following description of the embodiments is merely to provide a better understanding of the present invention by illustrating examples of the invention.

[0028] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes said element.

[0029] In the era of big data, the data trading industry has developed rapidly, but it also faces many problems. Because data products are replicable and tamper-proof, and the industry lacks unified standards, data product transactions suffer from a series of issues such as unlimited resale, continuously decreasing market value, unclear ownership, and poor data reliability. Therefore, the traceability of data products is urgently needed.

[0030] Blockchain, with its characteristics of trustworthiness, decentralization, immutability, and information transparency, has naturally become the preferred technology for building traceability systems. Blockchain-based traceability systems will inevitably greatly promote the development of the data trading industry, making traceability more valuable in the process of data product transactions.

[0031] Existing blockchain traceability systems include the following:

[0032] (1) Waltonchain is a traceability system that combines RFID and blockchain technologies. It can prevent the information in the traceability system from being tampered with and prevent tag duplication through RFID. It realizes the traceability function through a parent chain and sub-chains. Different smart contracts can be developed on the sub-chains to meet the needs of different application scenarios, while the parent chain is mainly used to manage the sub-chains.

[0033] (2) Eximchain is a consortium blockchain system built on a hybrid public, permissioned blockchain. It provides a smart contract ecosystem, forked from Ethereum, that supports information privacy, enabling businesses to create personalized supply chain finance products for their upstream and downstream supply chains. The consensus protocol uses Quadratic Voting (QVEC) to achieve time-limited security. From supply chain finance to procurement process management, smart contracts help buyers, sellers, and funding providers optimize their supply chain systems.

[0034] (3) The Traceability System Using Public and Private Blockchain (TSPPB) is a dual-blockchain anti-counterfeiting and traceability system. It includes two blockchains: a public blockchain and a private blockchain. It utilizes the high efficiency and large capacity storage of the private blockchain and the high credibility of the public blockchain to store data of each stage of the product on the private blockchain and the label information of each product on the public blockchain. This ensures that the traceability information obtained is authentic, reliable and tamper-proof, and solves the problems of product label duplication, abuse and product quality problems and difficulty in locating the relevant responsible persons in the traditional product traceability system. At the same time, it ensures efficient operation and maintains low cost.

[0035] (4) Ant Blockchain Traceability As a Service (TaaS) utilizes blockchain and IoT technologies to track and record the circulation chain of tangible goods, and immutably registers data on the characteristics of goods, such as quality information, logistics information, and quality inspection information, on the blockchain. From the perspective of basic goods, it allows for flexible configuration of brand owners, products, batches, traceability links, and traceability information, thereby realizing traceability management.

[0036] (5) VeChain provides end-to-end product information traceability in various fields such as agriculture, electronic document archives, automotive industry, new retail, and logistics transportation. Its basic method is to store process information on the blockchain and provide it for sharing by participants and end users. JD SmartChain also provides BaaS services. Its solutions in the traceability field include: assigning a unique identifier to the smallest package of each product according to a unified coding mechanism, enabling consumers to verify authenticity online. Combining information on product production, processing, packaging, and delivery with JD's warehousing inbound and outbound, order, and logistics information, it achieves end-to-end traceability of product quality information.

[0037] However, the aforementioned blockchain-based product traceability systems primarily focus on tracing transactions of physical products, lacking a traceability mechanism for data products. Furthermore, directly applying existing traceability mechanisms to data product traceability has the following shortcomings:

[0038] (1) Low storage and query efficiency. Although blockchain-based traceability systems have broad application prospects and value due to their functions such as ensuring product authenticity and reliability, ensuring transparency and openness in each production process, and implementing accountability, storing large amounts of information on the blockchain and frequent queries pose a significant challenge to query efficiency. In particular, for data products, it is difficult to achieve query and traceability by storing all data on the blockchain.

[0039] (2) The precise traceability mechanism for data product transactions is inadequate. Existing traceability systems are mainly for physical products, such as milk powder, agricultural products, industrial supplies, and archival information. Relevant information is easily obtained and recorded at each stage of the transaction and circulation. However, in the process of data product transactions, once the data is obtained, it can be copied and used multiple times by different people, which poses challenges to data security and intellectual property protection. It is difficult to carry out precise traceability when data is illegally disseminated or leaked.

[0040] To address the shortcomings of existing technologies, embodiments of the present invention provide a data processing method, apparatus, device, and computer storage medium based on blockchain, which reduces the possibility of data information being illegally disseminated or leaked during transmission and enables accurate traceability of data information.

[0041] The following section first introduces a blockchain-based data processing method provided by an embodiment of the present invention.

[0042] Figure 1 A schematic flowchart of a blockchain-based data processing method according to an embodiment of the present invention is shown. Figure 1 As shown, the method may include the following steps:

[0043] S101, the first target access node sends a data transmission request to the data node. After the target access node is authenticated, the first target access node is allowed to transmit data with the data node and an access record of the first target access node is generated. The first target access node can be any node among multiple access nodes.

[0044] In some embodiments, a blockchain includes at least a private blockchain and a consortium blockchain;

[0045] Multiple access nodes include at least one first access node and at least one second access node;

[0046] A private blockchain consists of data nodes and at least one first access node;

[0047] A consortium blockchain consists of a data node and at least one second access node.

[0048] Optionally, the first access node can be used to provide data to the data node and / or download data from the data node, and the second access node can be used to provide data to the data node and / or download data from the data node. The present invention does not limit either of these.

[0049] In some embodiments, the first target access node sends a data transmission request to the data node. After successful authentication of the target access node, the first target access node is allowed to transmit data with the data node, and an access record for the first target access node is generated. This may include:

[0050] The first target access node sends a data transmission request to the data node and performs identity authentication on the first target access node;

[0051] Identity authentication includes checking the key information, geographical location information, and IP address of the first target access node. If the key information, geographical location information, and IP address are correct, data transmission between the first target access node and the data node is allowed; otherwise, the data transmission request is rejected.

[0052] Based on the authentication result, an access record for the first target access node is generated.

[0053] In some embodiments, when the first target access node is a second access node on the consortium blockchain, the node authentication of the first target access node before identity authentication may further include:

[0054] The access period of the first target access node is checked. If it is determined that the data transmission request is within the access period, the identity of the first target access node is authenticated. If the access period is exceeded, the access is rejected. The access period is determined according to the smart contract established between the first target access node and the data node.

[0055] Optionally, the key information authentication for the first target access node can be performed in the following ways:

[0056] During system initialization, the access node inputs a security parameter K, thereby generating the public parameter Param and the master private key s of the PKG system in the key generation center. At the same time, the PKG system stores the master private key s.

[0057] After the access node completes registration in the blockchain system, PKG generates a private key based on the access node ID. d ID At the same time, use the private key d ID For public key ( P ID =ID) to generate S( P ID ), the public key and signature ( P ID S( P ID Put it into the blockchain and make it public.

[0058] When the accessing node is a node on a consortium blockchain, key information authentication may also include:

[0059] Session key management: When the session key is updated, the system generates a new session private key s based on the publicly available system parameter param. d ID and session public key sP ID Use the session private key to sign the session public key to generate S(s) P ID ), and the session public key and its signature (S( P ID ), S(s P ID Stored in the blockchain and made public;

[0060] To enable sessions, when node A wants to share data with node B, it queries node B's latest session public key s on the blockchain. P IDB and signature S(s) P ID ) B , and at the same time use s P IDB Verify signature S(s) P ID ) B To ensure the correctness of the session public key, node A can obtain the session private key SPEAK. A =(s P IDB ) sdIDA Similarly, node B can obtain the session key SPEAK. B =(s P IDA ) sdIDB And SPEAK A =SPEAK B .

[0061] Optionally, the IP address authentication of the first target access node can be performed in the following ways:

[0062] When an access node registers for the first time, the system will assign the access node an identity ID, bind its IP address, record it on the blockchain, and add it to the whitelist.

[0063] When accessing a node for login authentication, check if the access node is in the whitelist. This means authenticating the access node's identity ID, private key, and bound IP address simultaneously. If they match correctly, authentication is successful and identity authentication information is generated. Otherwise, authentication fails. If the number of failures exceeds a preset number, the node is added to the blacklist.

[0064] In some embodiments, generating an access record for the first target access node based on the authentication result may include:

[0065] If authentication fails for any of the key information, geographical location information, or IP address, an access denial record will be generated.

[0066] If the key information, geographical location information, and IP address are all successfully authenticated, an access record that allows access is generated.

[0067] The access record must include at least one of the following information about the accessing node: key information, geographical location information, IP address, and transmission time information.

[0068] Optionally, data transmission between access nodes and data nodes is based on smart contracts. The access period for access nodes is determined through smart contracts, and access records are also generated based on smart contracts. The construction and execution of smart contracts can include:

[0069] Access nodes submit a contract construction request to the smart contract server, generate a contract, and the server publishes it to the blockchain to take effect, thus forming a blockchain smart contract between the access node and the data node.

[0070] Once the smart contract begins execution, it will authenticate the accessing node before each access, that is, check whether the accessing node's key information, geographical location information, and IP address are correct. If they are correct, the smart contract allows the accessing node to access the data node; otherwise, it will refuse access and store the access record in the blockchain.

[0071] When a smart contract expires, the smart contract server generates a contract record and publishes it to the blockchain, thus terminating the contract execution.

[0072] Optionally, when the aforementioned access node is the second access node on the consortium blockchain, after the smart contract is formed but before the access node submits the contract construction request to the smart contract server, the following may also be included:

[0073] The data node provides its own bank account number MA to the smart contract server, and the access node pays a certain fee to the smart contract server through its own bank account number MB.

[0074] Optionally, when the aforementioned access node is the second access node on the consortium blockchain, after the smart contract begins execution but before authenticating the access node, the following may also be included:

[0075] The access period of the access node is checked. When it is determined that the data transmission request is within the access period, the identity of the first target access node is authenticated. If the access period is exceeded, the access is rejected. The access period is determined by the smart contract.

[0076] The entire execution process of the aforementioned smart contract is monitored by all participants, and all participants can query the execution status of the smart contract through the blockchain.

[0077] Identity authentication is a crucial technology in blockchain systems. A node's identity determines its corresponding permissions, user privacy, and real-world role. This is typically achieved using an identity-based public-key cryptography system. Therefore, strict key management is essential. Losing a key prevents synchronization across the entire blockchain, causing significant challenges to identity authentication and trust among nodes. In data product blockchains, where different data security levels correspond to different levels of identity permissions, it is even more necessary to bind public and private keys to node identities and utilize smart contracts for key updates and distribution to enhance the security of node authentication.

[0078] S102, based on the access records of multiple second target access nodes, determine the spatial stamp information of the multiple data to be transmitted, wherein the second target access node is the access node that completed the data transmission among the first target access nodes.

[0079] In some embodiments, determining the spatial stamp information of the transmitted data based on the access records of multiple second target access nodes may include:

[0080] Based on the access records of multiple secondary target access nodes, perform identity authentication on multiple secondary target access nodes;

[0081] Once identity authentication is successful, the geographical location information of multiple second target access nodes and the transmission time information of multiple data are determined through the access records of multiple second target access nodes.

[0082] Based on the geographical location information of multiple second target access nodes and the transmission time information of multiple data, determine the spatial stamp information of the multiple transmitted data.

[0083] In some embodiments, determining the spatial stamp information of multiple data based on the geographical location information of multiple second target access nodes and the transmission time information of multiple data may include:

[0084] Based on the geographical location information of multiple second target access nodes, multiple geographical locations are expressed in multiple granularities to determine multiple spatial models with different spatial granularities;

[0085] Based on the transmission time information of multiple data, the multiple transmission times are expressed in multiple granularities to determine multiple discrete moments with different time granularities;

[0086] Based on geospatial information systems, spatial stamp information for multiple data points is determined according to spatial models with different spatial granularities and discrete times with different temporal granularities.

[0087] In some embodiments, determining the spatial stamp information of multiple data points based on multiple spatial models with different spatial granularities and multiple discrete moments with different temporal granularities may include:

[0088] Based on multiple spatial models with different spatial granularities and multiple discrete moments with different temporal granularities, the transmitted data are transformed onto a map with the same spatiotemporal granularity for analysis to determine the spatial stamp information of the multiple data; or,

[0089] Based on multiple spatial models with different spatial granularities and multiple discrete moments with different temporal granularities, the transmitted data are analyzed on maps with different spatiotemporal granularities to determine the spatial stamp information of the data.

[0090] In some embodiments, leveraging the transparency and immutability of blockchain, the concept of spatial stamps is added to the data transmission on the blockchain, enabling identity control from both the "time dimension" and the "space dimension," thereby reducing the occurrence of various problems such as identity fraud and identity transfer.

[0091] Data nodes acquire spatial stamps from each node in the blockchain and express the entities of both parties in the data transmission at different spatiotemporal locations in a multi-granularity manner (i.e., the location is divided according to different levels of detail, such as roads, communities, and cities). Data analysis is then performed through kernel density visualization operations using a geospatial information system (GIS).

[0092] In the time dimension, different time periods or moments are converted into a series of discrete time points with different time granularities. In the spatial dimension, a three-level space of "global-relative-object" with different spatial granularities is constructed, refining the granularity to a spatial module for precise location and traceability.

[0093] Based on the above discrete time points and spatial model, analyses can be conducted at different spatiotemporal granularities, or spatial location information at different spatiotemporal granularities can be converted to the same spatiotemporal granularity for analysis. This invention does not limit this.

[0094] The aforementioned data tracing method, which uses IP address restrictions and spatial stamp matching, effectively reduces the possibility of data being used by unauthorized third parties. Once data ownership is established, the right to use the data must be guaranteed to prevent users from illegally transferring the right to use the data to third parties, thereby compromising data security.

[0095] S103, based on spatial stamp information, traces the source of multiple data.

[0096] The blockchain-based data processing method, apparatus, device, and computer storage medium of this invention, when an access node sends a data transmission request to a data node, ensures the security of data transmission between the data node and the access node through a dual authentication mechanism that verifies the access period in the smart contract corresponding to the access node and the identity information of the access node. Based on the authentication results of the dual authentication, an access record of the access node is generated. Simultaneously, based on the access records of multiple access nodes that have completed data transmission, spatial stamp information of multiple data transmissions at the same spatiotemporal granularity is determined. Based on the spatial stamp information, the data information is traced. Compared with existing technologies, this method verifies data from both spatial and temporal dimensions, effectively avoiding the problem of identity impersonation or transfer by other access nodes, while reducing the possibility of illegal dissemination or leakage of data information during transmission, thus achieving accurate traceability of data information.

[0097] For ease of understanding, the blockchain-based data processing method provided by the embodiments of the present invention will be described in detail below with reference to the accompanying drawings, and specific embodiments will be used for detailed explanation.

[0098] like Figure 2 As shown, Company A is any one of at least one of the subsidiaries of Company A, which provides data to Company A, and at least one user downloads data from Company A. Figure 3 As shown, at least one of Company A's subsidiaries forms a private blockchain with Company A, such as... Figure 4 As shown, at least one user and Company A form a consortium blockchain. The following describes in detail the blockchain-based data processing method provided by this invention, focusing on data transmission and data traceability.

[0099] Example 1: Data Transmission Based on Blockchain

[0100] Optionally, the data provider in the private blockchain provides data to Company A to generate data products; the data user in the consortium blockchain downloads data from Company A to realize data transactions and use. The generation and use of the above data products are based on the construction of smart contracts, wherein the execution of smart contracts may include the following steps:

[0101] Step A1: Create a smart contract

[0102] Company A or a user submits a contract construction application to the smart contract server, which generates the contract and publishes it to the blockchain to take effect, thus forming a blockchain smart contract between Company A and the user.

[0103] When the node is a user, step A1 may also include:

[0104] Company A provides its bank account number MA to the smart contract server;

[0105] Users pay a certain fee to the smart contract server through their own bank account MB.

[0106] Step A2, using data based on smart contracts

[0107] Once the smart contract begins execution, it will authenticate company A or the user before each access. This involves checking whether company A or the user's key information, geographical location information, and IP address are correct. If correct, the smart contract allows company A or the user to access company A's database; otherwise, it denies access and stores the access record in the blockchain.

[0108] When the node is a user, after the smart contract begins execution but before authenticating the accessing node, step A2 may also include:

[0109] The system checks the user's access period. If the data transmission request is within the access period, the user is authenticated. If the access period is exceeded, the access is denied. The access period is determined by the smart contract.

[0110] Step A3, Regular checks on smart contracts

[0111] When a smart contract expires, the smart contract server generates a contract record and publishes it to the blockchain, thus terminating the contract execution.

[0112] The entire execution process of the aforementioned smart contract is monitored by all participants, and all participants can query the execution status of the smart contract through the blockchain.

[0113] During the execution period of the smart contract, Company A, as the data provider, uses real-time updates of public and private keys for identity verification while uploading data, ensuring the stability and security of the data upload process. After the data is approved, a digital watermark is added, and the data product is uploaded to Company A's database.

[0114] As data users, they also use the company's key to verify their identity while downloading data, ensuring stability and security during the download process. Users apply to join the consortium blockchain; after submission, their qualifications are reviewed, and those who pass become members. Regular users can access the blockchain database once, while VIP users can access and download as many times as they want within a year. During registration, user ID, IP address, and spatial stamp information are recorded in the blockchain in real time.

[0115] Users in a consortium blockchain can share data products in the database. During the sharing process, public and private keys are updated in real time to ensure the security of account keys. At the same time, session keys are added to ensure the security of data transmission. After successful sharing, the space stamp information, sharing records, and ownership certificates of both users will be recorded on the consortium blockchain to ensure data traceability in the future.

[0116] Optionally, uploading data from Company A to Company B may include the following steps:

[0117] Step B1: After identity authentication, Company A uses the identity authentication information as a public key based on the Identity Encryption Algorithm (IBE) and generates a private key corresponding to the public key through the Private Key Generation Center (PKG). At the same time, this public key is published on the network. After a specific period, the public key that is verified to be valid will be published in the latest block of the blockchain.

[0118] Step B2: When updating the key, the uploading device uses existing secure cryptographic algorithms to generate an updated public-private key pair, publishes the latest public key in the blockchain, and ensures the validity of the public key update through a signature algorithm.

[0119] Step B3: Obtain the latest public key corresponding to Company A from the blockchain and transmit data to Company A.

[0120] Through the above steps, the keys on the private blockchain are updated periodically, thereby preventing hackers from stealing keys and uploading forged data, and ensuring the authenticity and reliability of the data.

[0121] Optionally, a user downloading data from Company A may include the following steps:

[0122] Step C1: After the user completes identity authentication, the identity authentication information is used as the public key based on the Identity Encryption Algorithm (IBE), and a private key corresponding to the public key is generated through the Private Key Generation Center (PKG). At the same time, this public key is published on the network. After a specific period, the public key that is verified to be valid will be published in the latest block of the blockchain.

[0123] In step C2, when updating the key, the downloading device uses existing secure cryptographic algorithms to generate an updated public-private key pair and publishes the latest public key in the blockchain, ensuring the validity of the public key update through a signature algorithm.

[0124] Step C3: Obtain the latest public key corresponding to the user from the blockchain and download the data from Company A.

[0125] Step C4: The downloading device uses existing secure cryptographic algorithms to generate an updated session public-private key pair and publishes the latest session key on the blockchain. During session key negotiation, i.e. when a user obtains data from Company A, Company A queries the member's latest session public key and public key through the blockchain, calculates the session key, and allows the user to share data with other users.

[0126] Through the above steps, the keys on the consortium blockchain are updated at specific intervals to ensure the security of user-downloaded data. At the same time, asynchronous updates, queries, and negotiations of session keys between different users are enabled, and data transactions are encrypted to ensure secure and fast transmission.

[0127] Optionally, the generation, updating, and management of keys and session keys may include the following steps:

[0128] Step D1: System initialization. The user inputs a security parameter K, which in turn generates the public parameter Param and the PKG master private key s of the Key Generation Center (PKG) system. Simultaneously, the PKG system stores the master private key s.

[0129] Step D2, Key Extraction. After registering in the system, when a user requests data transmission with Company A, the PKG generates a user private key based on the user ID. d ID At the same time, use the private key d ID For public key ( P ID =ID) to generate S( P ID ), the public key and signature ( P ID S( P ID It should be put into the blockchain and made public.

[0130] Step D3, Session Key Management. When the session key is updated, the system generates a new session private key s based on the publicly available system parameter param. d ID and session public key s P ID Use the session private key to sign the session public key to generate S(s) P ID ), and the session public key and its signature (S( P ID ), S(s P ID It is stored in the blockchain and made public.

[0131] Step D4, Session Implementation. After the user's data transfer request to Company A is approved, when transmitting data with Company A, the user queries the latest session public key s of Company B on the blockchain.P IDB and signature S(s) P ID ) B , and at the same time use s P IDB Verify signature S(s) P ID ) B To ensure the correctness of the session public key, user A can obtain the session private key SPEAK. A =(s P IDB ) sdIDA Similarly, user B can obtain the session key SPEAK. B =(s P IDA ) sdIDB And SPEAK A = SPEAK B .

[0132] Optionally, the authentication of the user or company A in steps B1 and C1, and the acquisition of authentication information, may include the following steps:

[0133] In step E1, when a user or company A registers for the first time, the system will assign the user or company A an identity ID, and bind it with IP address and geographical location information, recording it on the blockchain.

[0134] Step E2: When a user or company A logs in for authentication, the user's or company A's identity ID, private key, and bound IP address and geographical location information are authenticated simultaneously. If the match is correct, the authentication is successful and identity authentication information is generated; otherwise, the authentication fails.

[0135] Example 2: Data Traceability Based on Blockchain

[0136] By leveraging the transparency and immutability of blockchain, the concept of spatial stamps is added to the data transmission on the blockchain, enabling identity control from both the "time dimension" and the "space dimension," thereby reducing the occurrence of various problems such as identity fraud and identity transfer.

[0137] Company A obtains the spatial stamps of each node in the blockchain and represents the entities involved in data transmission at different spatiotemporal locations using multi-granularity methods (i.e., dividing locations according to different levels of detail, such as roads, communities, and cities). It then uses a Geographic Information System (GIS) for kernel density visualization and data analysis. Each node includes all branch offices and users.

[0138] In the time dimension, different time periods or moments are converted into a series of discrete time points with different time granularities. In the spatial dimension, a three-level space of "global-relative-object" with different spatial granularities is constructed, refining the granularity to a spatial module for precise location and traceability.

[0139] The invention authenticates the IP addresses of each node and can perform analysis at different spatiotemporal granularities. It can also convert spatial location information at different spatiotemporal granularities to the same spatiotemporal granularity for analysis. This invention does not limit this.

[0140] Optionally, tracing data on the blockchain may include the following steps:

[0141] Step F1: Call the external database to obtain the spatial stamp information of each node.

[0142] Step F2: Import the spatial stamp information of each node into Excel and convert it into CSV data.

[0143] Step F3: Import the CSV data into the GIS and establish a geographic coordinate system so that the geographic information with latitude and longitude can be spatially located based on the established geographic coordinate system.

[0144] Step F4: Specify a geographic coordinate system.

[0145] Step F5 involves projecting and transforming the geographic information of multiple nodes with latitude and longitude coordinates to a specified geographic coordinate system.

[0146] Step F6 involves performing a precise location analysis of the spatial stamp information on the map using kernel density analysis.

[0147] Step F7, merge layers, the result is shown in the image below. Figure 5 As shown, this diagram will trace the spatial location of the two parties transmitting data and display it on the map.

[0148] It's important to note that there are two ways to query data on a blockchain: connecting to an external database and using an internal index. Both methods have their advantages and disadvantages. However, considering the frequent storage and query operations of the traceability system itself, this solution modifies the storage and query layer on top of the existing blockchain, maintaining the basic architecture while providing an interface to connect to an external database. The data is primarily stored in the external database, with metadata, such as the data storage location, stored on the blockchain. A typical example is the BigchainDB system, which delegates queries to the backend database, using the blockchain only to prevent tampering, ensure data security, and improve storage and query efficiency.

[0149] like Figure 6As shown, in this embodiment of the invention, the underlying blockchain uses an external database. This is a query layer designed outside the blockchain, synchronizing blockchain data to an external database and utilizing the functional interfaces provided by the external database to design the query layer. It incorporates a blockchain data monitoring system that replicates on-chain data to a distributed document storage database (MongoDB), and then uses MongoDB to perform analytical query operations. MongoDB is an open-source, cross-platform NoSQL database that supports flexible schemas and can be easily configured to achieve scalability. This method does not require modification of the original blockchain system; the query layer can be implemented directly on top of the blockchain system.

[0150] Figure 6 In this blockchain external database structure, three main parts are included: a data monitoring and parsing module, an external database, and an Application Programming Interface (API). The data monitoring and parsing module is responsible for real-time synchronization of data from the blockchain (key / value pairs from the underlying LevelDB database). The external database is a dedicated database designed for this system. During the blockchain system's operation, the data monitoring and parsing module listens for block data via the blockchain's API and imports it into the external database. Queries are primarily implemented using the query interface provided by the external database; the data monitoring module reads data through the API provided by Ethereum. The main advantage of research on query processing module design in blockchain systems lies in using an external database as a medium, achieving query efficiency and rich query functionality with a simple implementation.

[0151] The following is combined Figure 7 This invention provides a detailed description of the blockchain-based data processing device provided in the embodiments of the present invention.

[0152] Figure 7 A schematic diagram of a blockchain-based data processing device according to an embodiment of the present invention is shown. Figure 7 As shown, the blockchain-based data processing device 700 includes:

[0153] The generation module 701 is used to send a data transmission request to the data node through the first target access node. After the target access node is authenticated, the first target access node is allowed to transmit data with the data node, and an access record of the first target access node is generated. The first target access node can be any node among multiple access nodes.

[0154] The determining module 702 is used to determine the spatial stamp information of the multiple data transmitted based on the access records of multiple second target access nodes, wherein the second target access node is the access node that completed the data transmission among the first target access nodes.

[0155] The traceability module 703 is used to trace the source of multiple data based on spatial stamp information.

[0156] In some embodiments, the generation module 701 may include:

[0157] The request unit is used to send a data transmission request to the data node through the first target access node and to authenticate the identity of the first target access node.

[0158] The first authentication unit is used to authenticate the identity of the first target access node. The authentication includes detecting the key information, geographical location information and IP address of the first target access node. If the key information, geographical location information and IP address are correct, the first target access node is allowed to transmit data with the data node; otherwise, the data transmission request is rejected.

[0159] The generation unit is used to generate the access record of the first target access node based on the identity authentication result.

[0160] In some embodiments, the generating unit may include:

[0161] The first generation subunit is used to generate an access denial record if any one of the key information, geographical location information, or IP address fails to authenticate.

[0162] The second generation subunit is used to generate an access record that allows access if the key information, geographical location information and IP address are all successfully authenticated.

[0163] The access record shall include at least one of the following information of the accessing node: key information, geographical location information, IP address, and transmission time information.

[0164] In some embodiments, the determining module 702 may include:

[0165] The second authentication unit is used to authenticate the identity of multiple second target access nodes based on their access records.

[0166] The first determining unit is used to determine the geographical location information of multiple second target access nodes and the transmission time information of multiple data through the access records of multiple second target access nodes when the identity authentication is successful.

[0167] The second determining unit is used to determine the spatial stamp information of the multiple transmitted data based on the geographical location information of the multiple second target access nodes and the transmission time information of the multiple data.

[0168] In some embodiments, the second determining unit may include:

[0169] The first determining subunit is used to express multiple geographical locations at multiple granularities based on the geographical location information of multiple second target access nodes, and to determine multiple spatial models with different spatial granularities.

[0170] The second determining subunit is used to express multiple transmission times at multiple granularities based on the transmission time information of multiple data, and to determine multiple discrete moments at different time granularities.

[0171] The third determining subunit is used to determine the spatial stamp information of multiple data based on geoscientific information systems, according to multiple spatial models with different spatial granularities and multiple discrete times with different temporal granularities.

[0172] In some embodiments, the third determining subunit may specifically be used for:

[0173] Based on multiple spatial models with different spatial granularities and multiple discrete moments with different temporal granularities, the transmitted data are transformed onto a map with the same spatiotemporal granularity for analysis to determine the spatial stamp information of the multiple data; or,

[0174] Based on multiple spatial models with different spatial granularities and multiple discrete moments with different temporal granularities, the transmitted data are analyzed on maps with different spatiotemporal granularities to determine the spatial stamp information of the data.

[0175] In some embodiments, a blockchain includes at least a private blockchain and a consortium blockchain;

[0176] Multiple access nodes include at least one first access node and at least one second access node;

[0177] A private blockchain consists of data nodes and at least one first access node;

[0178] A consortium blockchain consists of a data node and at least one second access node.

[0179] Further details of the blockchain-based data processing apparatus provided in the embodiments of the present invention are combined with the above. Figures 1-6 The blockchain-based data processing method described in the embodiments of the present invention is similar and will not be repeated here.

[0180] Figure 8 A schematic diagram of the hardware structure for blockchain-based data processing provided in an embodiment of the present invention is shown.

[0181] Combination Figures 1-7 The blockchain-based data processing method and apparatus described in the embodiments of the present invention can be implemented by a blockchain-based data processing device. Figure 8 This is a schematic diagram illustrating the hardware structure 800 of a blockchain-based data processing device according to an embodiment of the invention.

[0182] A blockchain-based data processing device may include a processor 801 and a memory 802 storing computer program instructions.

[0183] Specifically, the processor 801 may include a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of the present invention.

[0184] Memory 802 may include mass storage for data or instructions. For example, and not limitingly, memory 802 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. In one instance, memory 802 may include removable or non-removable (or fixed) media, or memory 802 may be non-volatile solid-state memory. Memory 802 may be internal or external to the integrated gateway disaster recovery device.

[0185] In one instance, memory 802 may be read-only memory (ROM). In one instance, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically rewritable ROM (EAROM), or flash memory, or a combination of two or more of these.

[0186] The processor 801 reads and executes computer program instructions stored in the memory 802 to achieve... Figure 1 The method / steps S101 to S103 in the illustrated embodiment achieve the following: Figure 1 The technical effects achieved by executing the methods / steps shown in the examples are not elaborated here for the sake of brevity.

[0187] In one example, the blockchain-based data processing device may also include a communication interface 803 and a bus 810. For example, Figure 8 As shown, the processor 801, memory 802, and communication interface 803 are connected through bus 810 and complete communication with each other.

[0188] The communication interface 803 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of the present invention.

[0189] Bus 810 includes hardware, software, or both, that couples components of an online data traffic metering device together. For example, and not limitingly, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Extended Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a Hyper Transport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Microchannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 810 may include one or more buses. While specific buses are described and illustrated in embodiments of the invention, the invention contemplates any suitable bus or interconnect.

[0190] The blockchain-based data processing device provided in this invention adds spatial stamp information to the data transmission on the blockchain, thereby controlling the identity of nodes on the blockchain from both time and space dimensions. This effectively avoids the problem of identity being impersonated or transferred by other nodes, while reducing the possibility of data being illegally disseminated or leaked during transmission, and achieving accurate traceability of data information.

[0191] Furthermore, in conjunction with the blockchain-based data processing methods described in the above embodiments, this invention can be implemented using a computer storage medium. This computer storage medium stores computer program instructions; when these computer program instructions are executed by a processor, they implement any of the blockchain-based data processing methods described in the above embodiments.

[0192] It should be clarified that the present invention is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present invention is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of the present invention.

[0193] The functional blocks shown in the above-described structural diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this invention are programs or code segments used to perform the required tasks. The programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer networks such as the Internet, intranets, etc.

[0194] It should also be noted that the exemplary embodiments mentioned in this invention describe methods or systems based on a series of steps or apparatus. However, this invention is not limited to the order of the steps described above; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.

[0195] The aspects of this disclosure have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by special-purpose hardware performing the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.

[0196] The above description is merely a specific embodiment of the present invention. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and these modifications or substitutions should all be covered within the protection scope of the present invention.

Claims

1. A data processing method based on blockchain, characterized in that, The blockchain includes data nodes and multiple access nodes, and the method includes: The first target access node sends a data transmission request to the data node. If the data transmission request is within the access period corresponding to the first target access node and the data node, the first target access node is authenticated. After the authentication is successful, the first target access node is allowed to transmit data with the data node, and an access record of the first target access node is generated. The first target access node is any one of the plurality of access nodes. Based on the access records of multiple second target access nodes, the multiple second target access nodes are authenticated. If the authentication is successful, the geographical location information of the multiple second target access nodes and the transmission time information of multiple data are determined based on the access records of the multiple second target access nodes. Based on the geographical location information of the multiple second target access nodes, the multiple geographical locations are expressed in multiple granularities to determine multiple spatial models with different spatial granularities. Based on the transmission time information of the multiple data, the multiple transmission times are expressed in multiple granularities to determine multiple discrete moments with different time granularities. Based on the geospatial information system, based on the multiple spatial models with different spatial granularities and the multiple discrete moments with different time granularities, the transmitted multiple data are converted to a map with the same spatiotemporal granularity for analysis to determine the spatial stamp information of the multiple data; or, based on the multiple spatial models with different spatial granularities and the multiple discrete moments with different time granularities, the transmitted multiple data are analyzed on maps with different spatiotemporal granularities to determine the spatial stamp information of the transmitted multiple data, wherein the second target access node is the access node that completed the data transmission among the first target access nodes. Based on the spatial stamp information, the multiple data are traced back to their source; the step of tracing the multiple data based on the spatial stamp information includes: the data node generates a spatial stamp dataset for kernel density visualization operation based on the spatial stamp information, and sends the spatial stamp dataset to the geoscience information system for data analysis.

2. The method according to claim 1, characterized in that, After successful identity authentication, the first target access node is allowed to transmit data with the data node, and an access record for the first target access node is generated, including: The identity authentication includes detecting the key information, geographical location information, and IP address of the first target access node. If the key information, geographical location information, and IP address are correct, the first target access node is allowed to transmit data with the data node; otherwise, the data transmission request is rejected. Based on the authentication result of the identity authentication, an access record for the first target access node is generated.

3. The method according to claim 2, characterized in that, The step of generating the access record for the first target access node based on the authentication result of the identity authentication includes: If any of the key information, geographical location information, or IP address fails to authenticate, an access denial record will be generated. If the key information, geographical location information, and IP address are all successfully authenticated, an access record that allows access is generated. The access record shall include at least one of the following information of the accessing node: key information, geographical location information, IP address, and transmission time information.

4. The method according to claim 1, characterized in that, The blockchain includes at least private blockchains and consortium blockchains; The plurality of access nodes includes at least one first access node and at least one second access node; The private chain consists of the data node and the at least one first access node; The consortium blockchain consists of the data node and the at least one second access node.

5. A data processing device based on blockchain, characterized in that, The blockchain includes data nodes and multiple access nodes, and the device includes: The generation module is used to send a data transmission request to the data node through a first target access node; if the data transmission request is within the access period corresponding to the first target access node and the data node, the module performs identity authentication on the first target access node; after the identity authentication is successful, the module allows the first target access node to transmit data with the data node and generates an access record for the first target access node, wherein the first target access node is any one of the plurality of access nodes. The determination module is used to authenticate the multiple second target access nodes based on their access records; if the authentication is successful, it determines the geographical location information of the multiple second target access nodes and the transmission time information of multiple data based on their access records; based on the geographical location information of the multiple second target access nodes, it performs multi-granularity expression on the multiple geographical locations to determine multiple spatial models with different spatial granularities; based on the transmission time information of the multiple data, it performs multi-granularity expression on the multiple transmission times to determine multiple discrete moments with different time granularities; based on the geospatial information system, it analyzes the transmitted multiple data on a map with the same spatiotemporal granularity based on the multiple spatial models with different spatial granularities and the multiple discrete moments with different time granularities to determine the spatial stamp information of the multiple data; or, based on the multiple spatial models with different spatial granularities and the multiple discrete moments with different time granularities, it analyzes the transmitted multiple data on maps with different spatiotemporal granularities to determine the spatial stamp information of the transmitted multiple data, wherein the second target access node is the access node that completed the data transmission among the first target access nodes; The tracing module is used to trace the origin of the multiple data based on the spatial stamp information; the step of tracing the origin of the multiple data based on the spatial stamp information includes: the data node generating a spatial stamp dataset for kernel density visualization operation based on the spatial stamp information, and sending the spatial stamp dataset to the geoscience information system for data analysis.

6. The apparatus according to claim 5, characterized in that, The generation module includes: The first authentication unit is used for identity authentication, which includes detecting the key information, geographical location information and IP address of the first target access node. If the key information, geographical location information and IP address are correct, the first target access node is allowed to transmit data with the data node; otherwise, the data transmission request is rejected. The generation unit is used to generate the access record of the first target access node based on the authentication result of the identity authentication.

7. A data processing device based on blockchain, characterized in that, The device includes: a processor and a memory storing computer program instructions; the processor reads and executes the computer program instructions to implement the blockchain-based data processing method as described in any one of claims 1-4.

8. A computer storage medium, characterized in that, The computer storage medium stores computer program instructions, which, when executed by a processor, implement the blockchain-based data processing method as described in any one of claims 1-4.

Citation Information

Patent Citations

  • Space-time credible block chain generation method and device

    CN110460444A

  • Big data processing method and system based on blockchain

    CN111541790A