Blockchain-based Data Fingerprint Generation Method, Device, and Storage Medium
By using multiple hashing operations in the blockchain data storage system to generate digital fingerprints, the risk vulnerability of hashing algorithms to generate collisions and conflicts in the blockchain is solved, and the secure storage and transmission of data is realized.
Patent Information
- Application Number
- CN202210297227.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-24
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2042-03-24
AI Technical Summary
The existing hashing algorithms have risk vulnerabilities in the blockchain to generate collisions, resulting in security risks in data storage and transmission.
By calling data files from the blockchain data storage system on the user side, obtaining the data to be encoded and determining its security level, selecting a suitable hashing algorithm for multiple hashing operations, and generating digital fingerprints to ensure the secure storage of data.
The digital fingerprint generated through multiple hashing operations can effectively prevent the collision and collision of hashing algorithms and ensure the secure storage and transmission of data on the blockchain.
Smart Images

Figure CN114880697B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of blockchain technology. Specifically, it relates to a method, apparatus, and storage medium for generating data fingerprints based on blockchain. Background Art
[0002] The hash algorithm is an algorithm in the field of blockchain. The hash algorithm is widely used in blockchain to build blocks and confirm the integrity of transactions. With the development of the times, it has also been found that the hash algorithm has a risk vulnerability of inevitable collision. For example, the MD5 and SHA1 algorithms in the hash algorithm have recently been proven to be insecure.
[0003] Since the length of the string output by the hash function corresponding to the hash algorithm is fixed, different inputs may produce the same hash value. If an attacker can deliberately cause a collision in the hash function, he can disguise malicious files or data as correct hash values and store them on the blockchain, and pass the malicious files or data to other users on the blockchain. That is, the existing hash algorithm has risk vulnerabilities.
[0004] However, currently, a large number of existing business systems are still using hash algorithms with risk vulnerabilities. And due to the characteristics of blockchain technology, the historical records stored in the existing business systems are immutable. Therefore, the business systems have security risks.
[0005] Regarding the problem of the risk vulnerability of hash algorithm generating collision conflicts in the related art, no effective solution has been proposed yet. Summary of the Invention
[0006] This application provides a method, apparatus, and storage medium for generating data fingerprints based on blockchain to solve the problem of the risk vulnerability of hash algorithm generating collision conflicts in the related art.
[0007] According to one aspect of this application, a method for generating data fingerprints based on blockchain is provided. The method includes: calling a data file from a data storage system through a user terminal, where the data storage system is a data storage system in a blockchain network; obtaining the data to be encoded in the data file and determining the security level of the data to be encoded, where the security level is used to represent the degree of confidentiality required for the data to be encoded in the current security scenario; determining the hash algorithm corresponding to the data to be encoded at the security level, and performing multiple hash operations on the data to be encoded according to the hash algorithm to obtain a digital fingerprint.
[0008] Optionally, the process of a client invoking a data file from a data storage system includes: verifying whether the blockchain node corresponding to the client has the data storage permission; if the blockchain node has the data storage permission, obtaining the access credential of the client, where the access credential is the credential for the client to access the blockchain network; accessing the data storage system in the blockchain network through the access credential and determining whether the data storage system stores the data file; if the data storage system stores the data file, determining the storage resource location information of the data file; and invoking the data file from the data storage system through the storage resource location information. Invoking the data file from the data storage system through the client is used to retrieve the file for which a digital fingerprint needs to be generated.
[0009] Optionally, obtaining the data to be encoded in the data file includes: converting the data under different storage protocols in the data file into the target data under a preset storage protocol; determining the data type of the target data and matching the data model corresponding to the data according to the data type, where the data model is used to represent the mapping relationship between the target data and the data to be encoded; and determining the data to be encoded corresponding to the target data according to the data model. By converting the storage protocol and matching the data model, data with different protocols and different data types can be converted into the data to be encoded under the same protocol.
[0010] Optionally, determining the hash algorithm corresponding to the data to be encoded at a security level includes: obtaining the historical hash algorithm of the data to be encoded from the data file and detecting whether the historical hash algorithm needs to be adjusted; if it is detected that the historical hash algorithm needs to be adjusted, adding a check bit to the hash value in the historical hash algorithm and determining the hash algorithm corresponding to the data to be encoded at the security level from multiple levels of hash algorithms, where the check bit is used to represent the invalidation of the hash value corresponding to the historical hash algorithm; if it is not detected that the historical hash algorithm needs to be adjusted, determining the historical hash algorithm as the hash algorithm corresponding to the data to be encoded at the security level. By determining the hash algorithm corresponding to the data to be encoded at the security level, the historical hash algorithm of the data can be adjusted to the hash algorithm of the data in the current application scenario.
[0011] Optionally, performing multiple hash operations on the data to be encoded according to the hash algorithm to obtain a digital fingerprint includes: dividing the data to be encoded into multiple first data blocks according to a preset rule; expanding each first data block into a data block of a preset length to obtain multiple second data blocks; and performing multiple hash operations on the multiple second data blocks according to a preset parallelism to obtain a digital fingerprint. By performing multiple hash operations on the data to be encoded to obtain a digital fingerprint, the collision conflict of the hash algorithm can be effectively prevented, enabling the data to be stored securely.
[0012] Optionally, after verifying whether the blockchain node corresponding to the client has the data storage permission, the method further includes: when the blockchain node has the data storage permission, obtaining the digital certificate of the client, and obtaining the private key and public key from the digital certificate; after determining the hash algorithm corresponding to the data to be encoded at the security level and performing a multi-hash operation on the data to be encoded according to the hash algorithm to obtain a digital fingerprint, the method further includes: encrypting the digital fingerprint with the private key to obtain the encrypted digital fingerprint; uploading the encrypted digital fingerprint, the public key, and the data to be encoded to the data storage system. By uploading the encrypted digital fingerprint, the public key, and the data to be encoded to the data storage system, the data can be stored in the data storage system of the blockchain.
[0013] Optionally, multiple digital fingerprints are stored in the data storage system in a preset tree structure. After uploading the encrypted digital fingerprint, the public key, and the data to be encoded to the data storage system, the method further includes: determining the hash security anchoring result corresponding to the digital fingerprint and returning the hash security anchoring result to the client, where the hash security anchoring result is used to locate the digital fingerprint in the preset tree structure. By determining the hash security anchoring result, the client can index the data it needs in the data storage system.
[0014] According to another aspect of the present application, there is provided a data fingerprint generation device based on a blockchain. The device includes: a calling unit for calling a data file from a data storage system through a client, where the data storage system is a data storage system in a blockchain network; an obtaining unit for obtaining the data to be encoded in the data file and determining the security level of the data to be encoded, where the security level is used to characterize the degree of confidentiality required for the data to be encoded in the current security scenario; a determining unit for determining the hash algorithm corresponding to the data to be encoded at the security level and performing a multi-hash operation on the data to be encoded according to the hash algorithm to obtain a digital fingerprint.
[0015] According to another aspect of the embodiments of the present invention, there is also provided a computer storage medium for storing a program, where the program, when running, controls a device where the computer storage medium is located to execute a data fingerprint generation method based on a blockchain.
[0016] According to another aspect of the embodiments of the present invention, there is also provided an electronic device including one or more processors and a memory; the memory stores computer-readable instructions, and the processor is used to run the computer-readable instructions, where the computer-readable instructions, when running, execute a data fingerprint generation method based on a blockchain.
[0017] Through this application, the following steps are adopted: calling a data file from a data storage system through a client, where the data storage system is a data storage system in a blockchain network; obtaining the data to be encoded in the data file and determining the security level of the data to be encoded, where the security level is used to represent the degree of confidentiality required for the data to be encoded in the current security scenario; determining the hash algorithm corresponding to the data to be encoded at the security level, and performing a multi-hash operation on the data to be encoded according to the hash algorithm to obtain a digital fingerprint, which solves the problem of the risk vulnerability of hash algorithm collision in the related technology. By performing a multi-hash operation on the data in the data file to obtain a digital fingerprint and using the multi-hash operation as the hash algorithm of the data, the effect that the hash algorithm in the blockchain technology has strong collision resistance is achieved. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] The accompanying drawings, which form a part of this application, are used to provide a further understanding of this application. The illustrative embodiments of this application and their descriptions are used to explain this application and do not constitute an improper limitation to this application. In the drawings:
[0019] Figure 1 is a flowchart of a blockchain-based data fingerprint generation method provided according to an embodiment of this application;
[0020] Figure 2 is a schematic structural diagram of obtaining data to be encoded provided according to an embodiment of this application;
[0021] Figure 3 is a schematic diagram of a digital fingerprint provided according to an embodiment of this application;
[0022] Figure 4 is a schematic structural diagram of a blockchain secure storage system provided according to an embodiment of this application;
[0023] Figure 5 is a schematic structural diagram of a trusted storage service subsystem provided according to an embodiment of this application;
[0024] Figure 6 is a node information interaction diagram of a blockchain secure storage system provided according to an embodiment of this application;
[0025] Figure 7 is a schematic structural diagram of a blockchain secure consensus accounting node system provided according to an embodiment of this application;
[0026] Figure 8 is a schematic diagram of a blockchain-based data fingerprint generation device provided according to an embodiment of this application;
[0027] Figure 9 is a schematic diagram of an electronic device provided according to an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0028] It should be noted that, without conflict, the embodiments in this application and the features in the embodiments may be combined with each other. The following will describe this application in detail with reference to the accompanying drawings and in combination with the embodiments.
[0029] In order to enable those skilled in the art to better understand the solution of this application, the following will clearly and completely describe the technical solutions in the embodiments of this application with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.
[0030] It should be noted that the terms "first", "second", etc. in the specification and claims of this application and the above-mentioned accompanying drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data used in appropriate cases can be interchanged so as to implement the embodiments of this application described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0031] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties.
[0032] For the convenience of description, the following explains some nouns or terms related to the embodiments of this application:
[0033] Collision resistance: It means that for two different inputs, two different outputs must be generated. If the same output is generated for two different inputs, it means that there is no collision resistance, or weak collision resistance.
[0034] Merkle Tree: A Merkle tree, a tree-shaped data structure, consists of a root node, a set of intermediate nodes, and a set of leaf nodes. Each leaf node is labeled with the hash value of a data block, and other nodes except leaf nodes are labeled with the cryptographic hash value of the labels of its child nodes.
[0035] According to an embodiment of this application, a method for generating a data fingerprint based on a blockchain is provided.
[0036] Figure 1 This is a flow chart of a data fingerprint generation method based on blockchain provided in an embodiment of the present application. Figure 1 As shown, the method comprises the following steps:
[0037] Step S102, calling a data file from a data storage system through a user terminal, wherein the data storage system is a data storage system in a blockchain network.
[0038] Specifically, the user end is the port corresponding to the user's node in the blockchain network, which is used to store data in the blockchain network. The data file is a file stored in the data storage system and uses a hash algorithm that has collision conflicts.
[0039] Step S104, obtaining the data to be encoded in the data file, and determining the security level of the data to be encoded, wherein the security level is used to characterize the degree to which the data to be encoded needs to be kept confidential in the current security scenario.
[0040] Specifically, the data to be encoded is the data that the user needs to store in the blockchain network. The security level is an artificially defined level corresponding to different hash algorithms. For example, MD5 and SHA-1 are hash algorithms with low security levels, and SHA-256 is a hash algorithm with high security levels. The level of hash algorithms is divided according to the strength of the collision resistance of the hash algorithms. MD5 and SHA-1 have weak collision resistance and are prone to collision conflicts. SHA-256 has stronger collision resistance than MD5 and SHA-1 and is not prone to collision conflicts.
[0041] Step S106, determining the hash algorithm corresponding to the data to be encoded under the security level, and performing multiple hash operations on the data to be encoded according to the hash algorithm to obtain a digital fingerprint.
[0042] Specifically, determine the security level of the data to be encoded in the current application scenario, and replace the hash algorithm with the corresponding security level. For example, data A of Bank X is non-core data, and the hash algorithm originally used is MD5. However, due to business adjustments recently, data A has been upgraded to core data, and the corresponding security level has been improved. At this time, the security level of the MD5 algorithm is relatively low and needs to be replaced with the SHA-256 hash algorithm with a higher security level.
[0043] The data fingerprint generation method based on blockchain provided by the embodiments of the present application calls a data file from a data storage system through a client, where the data storage system is a data storage system in a blockchain network; obtains the data to be encoded in the data file, and determines the security level of the data to be encoded, where the security level is used to characterize the degree of confidentiality required for the data to be encoded in the current security scenario; determines the hash algorithm corresponding to the data to be encoded at the security level, and performs a multi-hash operation on the data to be encoded according to the hash algorithm to obtain a digital fingerprint, which solves the problem of the risk vulnerability of hash algorithm collision in the related technology. By performing a multi-hash operation on the data in the data file to obtain a digital fingerprint and using the multi-hash operation as the hash algorithm of the data, the effect that the hash algorithm in the blockchain technology has strong collision resistance is achieved.
[0044] Before performing a multi-hash operation on the data for which a digital fingerprint is required, the corresponding data file needs to be called from the data storage system. Optionally, in the data fingerprint generation method based on blockchain provided by the embodiments of the present application, calling a data file from a data storage system through a client includes: verifying whether the blockchain node corresponding to the client has the data storage permission; in the case that the blockchain node has the data storage permission, obtaining the access credential of the client, where the access credential is the credential for the client to access the blockchain network; accessing the data storage system in the blockchain network through the access credential, and determining whether the data storage system stores the data file; in the case that the data storage system stores the data file, determining the storage resource location information of the data file; and calling the data file from the data storage system through the storage resource location information.
[0045] Specifically, before obtaining the required data from the data storage system of the blockchain, the identity of the user is verified. In the case that the user identity has the permission to store data in the blockchain network, the client obtains an access credential, which allows the user to access the data storage system. After the user accesses the data storage system, it can be determined whether the required data file exists and the location information of the data file in the storage system can be obtained, and then the data file is called. Calling the data file from the data storage system through the client can verify the identity of the client and ensure the secure storage and call of the data.
[0046] The data file contains data of different data types under different storage protocols. Optionally, in the data fingerprint generation method based on blockchain provided by the embodiments of the present application, obtaining the data to be encoded in the data file includes: converting the data under different storage protocols in the data file into target data under a preset storage protocol; determining the data type of the target data, and matching the data model corresponding to the data according to the data type, where the data model is used to characterize the mapping relationship between the target data and the data to be encoded; and determining the data to be encoded corresponding to the target data according to the data model.
[0047] Specifically, Figure 2 It is a schematic structural diagram of obtaining data to be encoded provided by an embodiment of the present application. As Figure 2 shown, the structure for obtaining data to be encoded includes a data input module 201 and a data unified model module 202. The data input module 201 is a storage network that supports the S3 protocol. Through storage protocol conversion, the data under different storage protocols in the data file is converted into target data under a preset storage protocol. The data unified model module 202 matches the corresponding data model for the target data according to the data type. The data types include Null, Boolean, Integer, Float, String, Bytes, List, Map, Link, etc., where List and Map are recursive types. The data model describes the data type and the string identifier path for indexing. The string identifier path follows the escape and segmentation rules and constraint construction similar to the URI path. The string identifier path defines the mapping from the data model layer to the data structure in the actual data file with a complex layout, realizing the serialization and deserialization functions of data of different data types in the data file. By converting the storage protocol and matching the data model for different protocols, the purpose of converting data of different data types into data to be encoded under the same protocol is achieved, thus laying a foundation for further data processing.
[0048] Since the historical hash algorithm of the data to be encoded may need to be adjusted, optionally, in the method for generating a data fingerprint based on a blockchain provided by an embodiment of the present application, determining the hash algorithm corresponding to the data to be encoded at a security level includes: obtaining the historical hash algorithm of the data to be encoded from the data file and detecting whether the historical hash algorithm needs to be adjusted; in the case where it is detected that the historical hash algorithm needs to be adjusted, adding a check bit to the hash value in the historical hash algorithm and determining the hash algorithm corresponding to the data to be encoded at the security level from multiple levels of hash algorithms, where the check bit is used to indicate the invalidation of the hash value corresponding to the historical hash algorithm; in the case where it is not detected that the historical hash algorithm needs to be adjusted, determining the historical hash algorithm as the hash algorithm corresponding to the data to be encoded at the security level.
[0049] Specifically, when there is a situation where the security level of the historical hash algorithm needs to adjust the hash algorithm in the current application scenario, due to the immutable characteristic of blockchain technology, it is impossible to directly adjust the historical hash algorithm. Therefore, in the case where the historical hash algorithm needs to be adjusted, a check bit is added to the hash value corresponding to the historical hash algorithm to indicate the invalidation of the historical hash algorithm. By determining the hash algorithm corresponding to the data to be encoded at the security level, the historical hash algorithm of the data can be adjusted to the hash algorithm of the data in the current application scenario, thus obtaining a hash algorithm adapted to the current application scenario.
[0050] After determining the hash algorithm corresponding to the data to be encoded at the security level, perform multiple hash operations on the data to be encoded according to the hash algorithm to obtain a digital fingerprint. Optionally, in the method for generating a digital fingerprint based on a blockchain provided in the embodiments of the present application, performing multiple hash operations on the data to be encoded according to the hash algorithm to obtain a digital fingerprint includes: dividing the data to be encoded into blocks according to a preset rule to obtain a plurality of first data blocks; expanding each first data block into a data block of a preset length to obtain a plurality of second data blocks; performing multiple hash operations on the plurality of second data blocks according to a preset parallelism to obtain a digital fingerprint.
[0051] Specifically, combining data chunking and the security levels of different data in a data file, use hash algorithms with different operation speeds and security levels for chunk hashing, and store the digital fingerprint by establishing the tree structure of a Merkle tree. By performing multiple hash operations on the data to be encoded to obtain a digital fingerprint, it is possible to effectively prevent hash algorithm collision conflicts and enable the data to be stored securely.
[0052] For example, the preset rule is the multiple hash algorithm H, and H is defined to process an integer number of second data blocks of size B bytes. The padding function in the preset rule is denoted as PadH(data, data length, block size B), and PadH uses a pre-determined pattern and the concatenation method of the message length to expand the first data block to the minimum length byte that is a multiple of B to obtain the second data block. For data M0 of length L hashed at a given parallelism S, the process of multiple hash operations is as follows (where the || symbol represents concatenation): Apply PadH(M0, L, B*S) to the data M0 to generate M0' of length L'. L' is the minimum length to which we can expand M0, that is, a multiple of B*S bytes; Divide M0' into S segments, each segment of length L' / S. M0' is divided in an interleaved manner so that each byte-sized W-bit word array of M0' is assigned to a different segment. Each segment is represented as a W-bit word array, and the representations of the segments are as follows:
[0053] Seg0 = M0'[0] || M0'[S] || M0'[2S] || …
[0054] Seg1 = M0'[1] || M0'[S + 1] || M0'[2S + 1] || …
[0055] …
[0056] SegS-1 = M0'[S - 1] || M0'[(2S - 1)] || M0'[(3S - 1)] || …
[0057] Where each M0'[n] is an index with a byte size of W for the filled data in each segment; S leaf-level digests are generated on the segments, such as Dk = H(Segk) for k = 0…(S - 1); a new data M1 is created by interleaving the word arrays of each leaf-level digest with a byte size of W bits. Let M1 = D0[0]||D1[0]…||D(S - 1)[0]||D1[1]…||D(S - 1)[(D / W) - 1]. Where each Dk[n] is an index with a byte size of W bits into the digest of a segment. M1 is generated as PadH(M1, S*D, B); the actual data file is placed in local storage, and the above H(M1) is uploaded to the blockchain storage; the metadata, the hash value and sub-hash values after multiple hashing operations are stored in the state data of the blockchain, and the root is stored in an isolated manner according to different business application scenarios and user permissions.
[0058] It should be noted that a digital fingerprint is obtained by using a multiple hashing algorithm and a TLV encoding method. Different from the format of a specific hashing algorithm, the digital fingerprint describes the hashing algorithm type and the corresponding hash value. The encoding of the data is determined by the TLV encoding method, and after encoding, the data type and metadata information of all stored data can be perceived in the blockchain storage system. Referring to the general BER (Basic Encoding Rule) encoding specification in the industry, the method of encoding the value of the ASNI type into a string of octets is described. The data of BER is composed of three fields: Tag field + Length field + Value field, referred to as the TLV format for short. TLV is a variable format, where: T can be understood as Tag or Type, used to identify the tag or encoding format information; L defines the length of the value; V represents the actual value. The lengths of T and L are fixed, generally 2 or 4 bytes, and the length of V is specified by Length. Figure 3 is a schematic diagram of the digital fingerprint provided according to the embodiment of the present application, as Figure 3 shown, the digital fingerprint is a self-describing hash, which itself contains the length value, hash value and hashing algorithm type describing the digital fingerprint. For example, the hashing algorithm type is sha2-256, the Tag of the digital fingerprint can be represented as 18 - 0x12, the length is the actual length of the hash (using sha2-256 it will be 256 bits, equal to 32 bytes), and the value is the hash value generated by the actual hashing algorithm. The digital fingerprint ensures the flexibility and scalability of data identification, which is jointly agreed upon and observed by the whole network. This agreement is made in the form of a blockchain smart contract and is managed on the blockchain.
[0059] The digital fingerprint needs to be uploaded to the data storage system in the blockchain network. Optionally, in the blockchain-based data fingerprint generation method provided in the embodiments of the present application, after verifying whether the blockchain node corresponding to the user terminal has the data storage permission, the method further includes: when the blockchain node has the data storage permission, obtaining the digital certificate of the user terminal, and obtaining the private key and public key from the digital certificate; after determining the hash algorithm corresponding to the data to be encoded at the security level and performing multiple hash operations on the data to be encoded according to the hash algorithm to obtain the digital fingerprint, the method further includes: encrypting the digital fingerprint with the private key to obtain the encrypted digital fingerprint; uploading the encrypted digital fingerprint, the public key, and the data to be encoded to the data storage system.
[0060] Specifically, the data in the data file undergoes multiple hash operations to obtain the digital fingerprint, and the digital fingerprint needs to be encrypted by the user terminal and then uploaded to the data storage system in the blockchain network. By uploading the encrypted digital fingerprint, the public key, and the data to be encoded to the data storage system, the security of the data is ensured through the immutability of the blockchain, and the data flow is facilitated through the data sharing mechanism of the blockchain.
[0061] After the user stores the digital fingerprint in the data storage system, it is also necessary to obtain the hash security anchoring result for indexing the required data. Optionally, in the blockchain-based data fingerprint generation method provided in the embodiments of the present application, multiple digital fingerprints are stored in the data storage system in a preset tree structure. After uploading the encrypted digital fingerprint, the public key, and the data to be encoded to the data storage system, the method further includes: determining the hash security anchoring result corresponding to the digital fingerprint and returning the hash security anchoring result to the user terminal, where the hash security anchoring result is used to locate the digital fingerprint in the preset tree structure.
[0062] Specifically, hash security anchoring is a method for indexing the digital fingerprints stored in the Merkle tree. When indexing the data, it is necessary to read the security anchoring result to obtain the location of the digital fingerprint corresponding to the data in the Merkle tree structure. The indexed digital fingerprint is obtained through the location, and then the digital fingerprint is verified. When verifying that the digital fingerprint is the digital fingerprint corresponding to the indexed data, the data corresponding to the digital fingerprint is obtained. By determining the hash security anchoring result, the user terminal can quickly index the required data in the data storage system.
[0063] It should be noted that when verifying digital fingerprints, the verification device must replace the current cryptographic hash algorithm (such as SHA-256) and use one of the most efficient compatible extended hash algorithms for computing verification. For example, if the verification device has a 128-bit SIMD data path execution unit in its processor core and needs to verify the digest of SHA-256, ideally the verification device would prefer SHA256x4 (because the SHA-256 algorithm is based on 32 bits, and based on the 128-bit SIMD execution unit, we can process 128 / 32 = 4 segments in parallel). Therefore, the verification device will not use one of the currently used 32-bit algorithms {MD5, SHA1, SHA256}, but will prefer {MD5 x8, SHA1 x4, SHA256 x4} respectively. MD5 is a bit unique. Although from the perspective of 128-bit SIMD we only need 4 segments, this algorithm has very limited data dependencies, which makes it difficult to obtain the best throughput of the execution unit without additional parallelism.
[0064] Since there are many verification devices with different computational intensities, and the digital fingerprint must find a parallel level suitable for most of its verification devices. Our solution does not require the server to estimate this very accurately because we can always create a higher level of parallelism during verification, and if the SIMD or hardware capabilities of the verification device cannot handle as many segments as possible, let the verification device perform multiple passes during verification. For example, the verification device can use a scheme that executes 4 times.
[0065] Due to managing multiple state variables of the digest, when multiple passes are required, it may cause some efficiency losses. Note that the data can still be effectively imported in a streaming manner once, however, the application will need to loop between sets of state variables. For example, assume that the client device has no SIMD unit at all and needs to perform simple scalar operations to process the SHA256x4 hash value. Instead of processing 1 set of SHA-256 state variables (32 bytes), it processes 4 such copies of state variables simultaneously (128 bytes), looping through them when processing fields from the data buffer. The increase in the size of this task set is very small. A possible problem is the increase in the task set size related to message scheduling of data blocks (for SHA). If this increase in the working set size is a problem, one can choose to store 4 data blocks and strictly process one interleaved block at a time.
[0066] According to another embodiment of the present application, a blockchain secure storage system is provided. Figure 4 It is a schematic structural diagram of the blockchain secure storage system provided according to the embodiments of the present application, as Figure 4As shown in the figure, the system includes a user terminal 401, a trusted storage service subsystem 402, a blockchain network 403, a storage smart contract 404, and a digital asset content identifier 405 that performs multiple hash encoding.
[0067] The blockchain security storage system of this embodiment realizes the secure storage of data files through the design of the multiple hash algorithm.
[0068] Among them, the user terminal 401 includes various terminals held by users, including PC terminals, mobile terminals, edge devices, cloud servers, etc. Users can have full permissions and control access permissions for other users. Based on this, users manage digital assets, create data asset files, and manage or store keys according to security scenarios.
[0069] The trusted storage service subsystem 402 is a blockchain-based decentralized trusted data storage system. This system is a decentralized, peer-to-peer distributed blockchain storage system that provides a high-throughput, content-addressable block storage model, supports flexible expansion of storage, multi-storage protocol adaptation support, peer-to-peer block security encryption, redundant object linking, an immutable data storage structure, and other features, and can provide a secure, efficient, open, and low-cost multi-party shared storage network.
[0070] Specifically, Figure 5 is a schematic structural diagram of the trusted storage service subsystem provided according to the embodiment of the present application. As Figure 5 shown, the trusted storage service subsystem 402 includes a service interface module 501, a core API module 502, an interactive operation module 503, a data service module 504, a multiple hash module 505, and a data routing module 506. The trusted storage service subsystem 402 provides an interactive interface and a service interface through the core API module 502 to manage data files and blockchain nodes; the data service module 504 includes a storage access gateway sub-module, a data operation sub-module, a data monitoring sub-module, and a data storage sub-module. It mainly realizes functions such as storage protocol conversion, data synchronization, data performance and capacity monitoring, and data persistent storage; the multiple hash module 505 includes a data classification sub-module, a multiple hash sub-module, an on-chain anchoring sub-module, and a certificate management sub-module. It mainly realizes functions such as data security level classification, multiple hash algorithm implementation, adaptation of multiple blockchain underlying products and smart contract interfaces, and generation and management of certificates; the data routing module 506 includes a security verification sub-module, a hash routing sub-module, a data block exchange sub-module, and a subscription and publication sub-module, and realizes functions such as hash security detection, hash indexing, data block exchange, and subscription and publication. Among them, hash routing is used for the search and routing of storage nodes and data files, and the interface is as follows:
[0071] type DataRouting interface{
[0072] FindPeer(node NodeId) / / Get the node address
[0073] SetValue(key[]bytes, value[]bytes)
[0074] GetValue(key[]bytes, value[]bytes)
[0075] ProvideValue(key Multihash)
[0076] FindValuePeers(key Multihash, min int)
[0077] }}。
[0078] The blockchain network 403 is a blockchain consortium chain network with characteristics such as multi - party efficient consensus, strong security contract engine, reliable privacy protection, cross - chain interconnection, etc. At the same time, it can support other open - source mainstream consortium chains and public chains that provide programmable smart contracts, etc., for providing multi - party data circulation and governance of data asset identifiers, while providing basic access authorization and authentication, and supporting different institutions in different business scenarios for physical and logical isolation of data assets, ensuring the security and trustworthiness of data, leaving traces for digital asset access and operations.
[0079] The smart contract 404 is the core implementation of the blockchain network, making the decentralized (distributed) blockchain system programmable. The smart contract defines the rules between different organizations in the executable code and is also a computer protocol designed to spread, verify, or execute contracts in an informatized manner. By generating transaction records into the blockchain ledger through the smart contract, transactions can be carried out without a third party, ensuring that transactions can be traced, tamper - proof, and irreversible.
[0080] The digital asset content identifier 405 is a self - descriptive content - addressed identifier. Based on the hash algorithm, messages of any length are compressed into a message digest of a fixed length. It is usually used for on - chain and off - chain collaborative storage of data assets in the blockchain field. The TLV encoding scheme is used to uniquely identify the digital assets stored in the blockchain. This identifier can self - describe the hash type, ensuring the uniqueness of the digital fingerprint of the digital asset identifier.
[0081] Figure 6 It is the node information interaction diagram of the blockchain secure storage system provided according to the embodiments of the present application.
[0082] Such as Figure 6As shown in the figure, the user device logs in to the blockchain management platform to obtain blockchain nodes and certificate configuration files, and holds the user certificate and private key for accessing and initiating transactions on the blockchain; authenticates the blockchain permissions by calling the blockchain nodes, and returns an access credential for storing resource access and data asset storage; calls the storage resource interface in the blockchain smart contract to confirm whether there is storage resource in the blockchain network. If so, returns the storage URL and storage credential for data asset storage; the user or application system initiates a data asset storage request to the trusted storage service, and the trusted storage service calls the multiple hash operation to perform a block hash security operation according to the data size and data security level, and returns the data fingerprint to the user; the user encrypts the data using the local private key, and calls the smart contract to store the metadata information, encrypted data fingerprint and public key certificate on the blockchain, and performs hash security anchoring. After the blockchain successfully records the storage operation, finally returns the storage success result to the user; other users, based on the permissions and credentials obtained in the blockchain, also request the blockchain to apply for data asset transfer or use. Thus, the full process of node - to - node interaction for blockchain - based secure storage using multiple hashes is completed.
[0083] According to another embodiment of the present application, a blockchain secure consensus accounting node system is provided. Figure 7 It is a schematic structural diagram of the blockchain secure consensus accounting node system provided by the embodiment of the present application.
[0084] As Figure 7 shown in the figure, the system includes a blockchain consensus accounting node 701 and a storage contract 702. The consensus accounting node 701 includes state data and block data. The state data includes the root hash A of the data asset generated by multiple hashes, the data asset content hash A, and indexes A1, A2, etc. of the hashes of each block. The block data adds a data hash check bit on the basis of the original Merkle data of the transaction block for hash algorithm verification. The storage contract 702 mainly realizes functions such as service access authentication, storage resource management access authorization management, data asset management, and user public key management.
[0085] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer - executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0086] The embodiment of the present application also provides a blockchain - based data fingerprint generation device. It should be noted that the blockchain - based data fingerprint generation device of the embodiment of the present application can be used to execute the blockchain - based data fingerprint generation method provided by the embodiment of the present application. The following introduces the blockchain - based data fingerprint generation device provided by the embodiment of the present application.
[0087] Figure 8 It is a schematic diagram of a blockchain-based data fingerprint generation device provided according to an embodiment of the present application. As Figure 8 shown, the device includes: a calling unit 10, configured to call a data file from a data storage system through a user terminal, where the data storage system is a data storage system in a blockchain network; an obtaining unit 20, configured to obtain data to be encoded in the data file and determine the security level of the data to be encoded, where the security level is used to characterize the degree of confidentiality required for the data to be encoded in the current security scenario; a determining unit 30, configured to determine a hash algorithm corresponding to the data to be encoded at the security level, and perform multiple hash operations on the data to be encoded according to the hash algorithm to obtain a digital fingerprint.
[0088] Optionally, in the blockchain-based data fingerprint generation device provided according to an embodiment of the present application, the calling unit 10 includes: a verification module, configured to verify whether the blockchain node corresponding to the user terminal has data storage permission; a first obtaining module, configured to obtain an access credential of the user terminal when the blockchain node has data storage permission, where the access credential is a credential for the user terminal to access the blockchain network; an access module, configured to access the data storage system in the blockchain network through the access credential and determine whether a data file is stored in the data storage system; a first determining module, configured to determine the storage resource location information of the data file when the data file is stored in the data storage system; a calling module, configured to call the data file from the data storage system through the storage resource location information.
[0089] Optionally, in the blockchain-based data fingerprint generation device provided according to an embodiment of the present application, the obtaining unit 20 includes: a conversion module, configured to convert data under different storage protocols in the data file into target data under a preset storage protocol; a matching module, configured to determine the data type of the target data and match the data model corresponding to the data according to the data type, where the data model is used to characterize the mapping relationship between the target data and the data to be encoded; a second determining module, configured to determine the data to be encoded corresponding to the target data according to the data model.
[0090] Optionally, in the blockchain-based data fingerprint generation device provided in the embodiments of the present application, the determination unit 30 includes: a second acquisition module, configured to acquire the historical hash algorithm of the data to be encoded from a data file and detect whether the historical hash algorithm needs to be adjusted; an addition module, configured to, when it is detected that the historical hash algorithm needs to be adjusted, add a check bit to the hash value in the historical hash algorithm and determine the hash algorithm corresponding to the data to be encoded at the security level from multiple levels of hash algorithms, where the check bit is used to indicate the invalidation of the hash value corresponding to the historical hash algorithm; a third determination module, configured to, when it is not detected that the historical hash algorithm needs to be adjusted, determine the historical hash algorithm as the hash algorithm corresponding to the data to be encoded at the security level.
[0091] Optionally, in the blockchain-based data fingerprint generation device provided in the embodiments of the present application, the determination unit 30 further includes: a chunking module, configured to chunk the data to be encoded according to a preset rule to obtain a plurality of first data chunks; an extension module, configured to extend each first data chunk to a data chunk of a preset length to obtain a plurality of second data chunks; an operation module, configured to perform multiple hash operations on the plurality of second data chunks according to a preset parallelism to obtain a digital fingerprint.
[0092] Optionally, in the blockchain-based data fingerprint generation device provided in the embodiments of the present application, the invocation unit 10 further includes: a third acquisition module, configured to, when the blockchain node has the data storage permission, acquire the digital certificate of the user terminal and acquire the private key and the public key from the digital certificate; the determination unit 30 further includes: an encryption module, configured to encrypt the digital fingerprint with the private key to obtain an encrypted digital fingerprint; an upload module, configured to upload the encrypted digital fingerprint, the public key, and the data to be encoded to a data storage system.
[0093] Optionally, in the blockchain-based data fingerprint generation device provided in the embodiments of the present application, the determination unit 30 further includes: a fourth determination module, configured to determine the hash security anchoring result corresponding to the digital fingerprint and return the hash security anchoring result to the user terminal, where the hash security anchoring result is used to locate the digital fingerprint in a preset tree structure.
[0094] The data fingerprint generation device based on blockchain provided by the embodiment of the present application includes a calling unit 10, which is used to call a data file from a data storage system through a client, where the data storage system is a data storage system in a blockchain network; an obtaining unit 20, which is used to obtain the data to be encoded in the data file and determine the security level of the data to be encoded, where the security level is used to represent the degree of confidentiality required for the data to be encoded in the current security scenario; and a determining unit 30, which is used to determine the hash algorithm corresponding to the data to be encoded at the security level and perform a multiple hash operation on the data to be encoded according to the hash algorithm to obtain a digital fingerprint, solving the problem of the risk vulnerability of hash algorithm collisions in the related art. By performing a multiple hash operation on the data in the data file to obtain a digital fingerprint and using the multiple hash operation as the hash algorithm of the data, the effect that the hash algorithm in blockchain technology has strong collision resistance is achieved.
[0095] The above-mentioned data fingerprint generation device based on blockchain includes a processor and a memory. The above-mentioned calling unit 10, obtaining unit 20, determining unit 30, etc. are all stored in the memory as program units, and the corresponding functions are realized by the processor executing the above program units stored in the memory.
[0096] The processor contains a kernel, and the kernel is used to retrieve the corresponding program unit from the memory. One or more kernels can be set, and by adjusting the kernel parameters, the effect that the hash algorithm in blockchain technology has strong collision resistance is achieved.
[0097] The memory may include non-permanent memory in a computer-readable medium, forms such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM), and the memory includes at least one storage chip.
[0098] The embodiment of the present application also provides a computer storage medium, which is used to store a program. When the program runs, it controls the device where the computer storage medium is located to execute a data fingerprint generation method based on blockchain.
[0099] As Figure 9 shown, the embodiment of the present application also provides an electronic device. The electronic device 901 includes a processor, a memory, and a program stored on the memory and executable on the processor. When the processor executes the program, the following steps are realized: data fingerprint generation based on blockchain. The device herein can be a server, a PC, a PAD, a mobile phone, etc.
[0100] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0101] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0102] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0103] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0104] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0105] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.
[0106] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0107] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0108] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included within the scope of the claims of the present application.
Claims
1. A method for generating data fingerprints based on blockchain, characterized in that, Including: Invoking a data file from a data storage system through a client, where the data storage system is a data storage system in a blockchain network; Obtaining the data to be encoded in the data file and determining the security level of the data to be encoded, where the security level is used to characterize the degree of confidentiality required for the data to be encoded in the current security scenario; Determining the hash algorithm corresponding to the data to be encoded at the security level and performing multiple hash operations on the data to be encoded according to the hash algorithm to obtain a digital fingerprint; Among them, determining the hash algorithm corresponding to the data to be encoded at the security level includes: obtaining the historical hash algorithm of the data to be encoded from the data file and detecting whether the historical hash algorithm needs to be adjusted; in the case where it is detected that the historical hash algorithm needs to be adjusted, adding a check bit to the hash value in the historical hash algorithm and determining the hash algorithm corresponding to the data to be encoded at the security level from multiple levels of hash algorithms, where the check bit is used to characterize the invalidation of the hash value corresponding to the historical hash algorithm; in the case where it is not detected that the historical hash algorithm needs to be adjusted, determining the historical hash algorithm as the hash algorithm corresponding to the data to be encoded at the security level; Performing multiple hash operations on the data to be encoded according to the hash algorithm to obtain a digital fingerprint includes: partitioning the data to be encoded according to a preset rule to obtain a plurality of first data blocks; expanding each of the first data blocks into a data block of a preset length to obtain a plurality of second data blocks; performing multiple hash operations on the plurality of second data blocks according to a preset parallelism to obtain the digital fingerprint.
2. The method according to claim 1, wherein Invoking a data file from a data storage system through a client includes: Verifying whether the blockchain node corresponding to the client has data storage permission; In the case where the blockchain node has data storage permission, obtaining the access credential of the client, where the access credential is the credential for the client to access the blockchain network; Accessing the data storage system in the blockchain network through the access credential and determining whether the data file is stored in the data storage system; In the case where the data file is stored in the data storage system, determining the storage resource location information of the data file; Invoking the data file from the data storage system through the storage resource location information.
3. The method according to claim 1, characterized in that, Obtaining the data to be encoded in the data file includes: Converting the data under different storage protocols in the data file into target data under a preset storage protocol; Determining the data type of the target data and matching the data model corresponding to the data according to the data type, where the data model is used to characterize the mapping relationship between the target data and the data to be encoded; Determining the data to be encoded corresponding to the target data according to the data model.
4. The method according to claim 2, characterized in that, After verifying whether the blockchain node corresponding to the client has data storage permission, the method further includes: When the blockchain node has the data storage permission, obtain the digital certificate of the client, and obtain the private key and public key from the digital certificate; After determining the hash algorithm corresponding to the data to be encoded at the security level and performing multiple hash operations on the data to be encoded according to the hash algorithm to obtain a digital fingerprint, the method further includes: Use the private key to encrypt the digital fingerprint to obtain an encrypted digital fingerprint; Upload the encrypted digital fingerprint, the public key, and the data to be encoded to the data storage system.
5. The method according to claim 4, wherein Multiple digital fingerprints are stored in the data storage system in a preset tree structure. After uploading the encrypted digital fingerprint, the public key, and the data to be encoded to the data storage system, the method further includes: Determine the hash security anchoring result corresponding to the digital fingerprint, and return the hash security anchoring result to the client, where the hash security anchoring result is used to locate the digital fingerprint in the preset tree structure.
6. A data fingerprint generation device based on blockchain, characterized in that, Includes: A calling unit, configured to call a data file from a data storage system through a client, where the data storage system is a data storage system in a blockchain network; An obtaining unit, configured to obtain the data to be encoded in the data file and determine the security level of the data to be encoded, where the security level is used to characterize the degree of confidentiality required for the data to be encoded in the current security scenario; A determining unit, configured to determine the hash algorithm corresponding to the data to be encoded at the security level and perform multiple hash operations on the data to be encoded according to the hash algorithm to obtain a digital fingerprint; Wherein, the determining unit includes: a second obtaining module, configured to obtain the historical hash algorithm of the data to be encoded from the data file and detect whether the historical hash algorithm needs to be adjusted; an adding module, configured to add a check bit to the hash value in the historical hash algorithm when it is detected that the historical hash algorithm needs to be adjusted, and determine the hash algorithm corresponding to the data to be encoded at the security level from multiple levels of hash algorithms, where the check bit is used to characterize the invalidation of the hash value corresponding to the historical hash algorithm; a third determining module, configured to determine the historical hash algorithm as the hash algorithm corresponding to the data to be encoded at the security level when it is not detected that the historical hash algorithm needs to be adjusted; The determining unit further includes: a chunking module, configured to chunk the data to be encoded according to a preset rule to obtain a plurality of first data chunks; an expanding module, configured to expand each of the first data chunks into a data chunk of a preset length to obtain a plurality of second data chunks; an operating module, configured to perform multiple hash operations on the plurality of second data chunks according to a preset parallelism to obtain the digital fingerprint.
7. A computer storage medium, characterized in that, The computer storage medium is used to store a program, where the program, when running, controls the device where the computer storage medium is located to execute the blockchain-based data fingerprint generation method according to any one of claims 1 to 5.
8. An electronic device, characterized in that, Comprising one or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the blockchain-based data fingerprint generation method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Data evidence obtaining method and device based on multiple Hash algorithms
CN107256243A
System for accelerating calculation of blockchain data
CN111768195A