A User Data Integrity Verification Method Based on Ethereum Smart Contracts
By using smart contracts on the Ethereum blockchain for data integrity verification, the problem of data tampering detection in centralized databases is solved, and high reliability and security data verification is achieved.
Patent Information
- Application Number
- CN202210698029.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-20
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2042-06-20
AI Technical Summary
The existing technology is difficult to effectively detect and prevent data tampering in centralized databases, and third-party verification platforms may have centralized vulnerabilities and are easily exploited maliciously.
The user data integrity verification method based on Ethereum smart contract is adopted to generate and store verification data on the blockchain through smart contracts, use the immutability of blockchain to ensure data integrity, and use smart contracts to perform verification operations to avoid the risks of centralized verification platforms.
It effectively avoids the malicious provision of false verification information that may be caused by centralized verification platforms, ensures that any tampered data behavior in the centralized database can be detected, and improves the security and reliability of the data.
Smart Images

Figure CN115314215B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of Ethereum smart contracts and data storage security, and specifically provides a method for verifying the integrity of user data based on Ethereum smart contracts. Background Art
[0002] A centralized database is a database that locates, stores, and maintains data in a single location. This location is usually a central computer or database system, such as a desktop computer or server CPU or other large computer. Since the advent of centralized databases, they have been applied in the vast majority of organizations (such as commercial companies) or institutions (such as universities) on the market. Centralized databases have advantages such as high throughput, good data portability, and easy management. However, their high degree of centralization makes it impossible for users to detect malicious data tampering in private by the database. In traditional solutions, a third-party data verification platform is usually introduced to help detect malicious behavior. However, the third-party verification platform itself is also a centralized system and may collude with the service provider to produce false verification results.
[0003] With the emergence of blockchain, it has become possible to decentralize a centralized system; the immutability inherent in blockchain itself can also ensure that the data stored on the blockchain cannot be randomly tampered with by outsiders or hackers. The introduction of the concept of smart contracts in the Ethereum blockchain has made application development on the blockchain much more flexible. Therefore, using Ethereum smart contracts as a decentralized third-party verification platform to ensure the reliability of data integrity verification results has become a direction worthy of our research and solution. For this reason, we propose a method for verifying the integrity of user data based on Ethereum smart contracts. Summary of the Invention
[0004] (1) Technical Problems to be Solved
[0005] In view of the deficiencies of the prior art, the present invention provides a method for verifying the integrity of user data based on Ethereum smart contracts to solve the above problems.
[0006] (2) Technical Solutions
[0007] To achieve the above object, the present invention provides the following technical solutions:
[0008] A method for verifying the integrity of user data based on Ethereum smart contracts includes the following steps:
[0009] S1: The data user sends a request to update data to the service provider and sends an update command set to the service provider. The service provider sends an address set to the data user;
[0010] S2: After receiving the database address set, the data user constructs a set of tuples based on the update command set and the address set, and finally sends the set of tuples to the smart contract;
[0011] S3: After receiving the set of tuples, the smart contract generates a seed value and a hash value, constructs an array of quadruples for future verification, and stores the array of quadruples in the smart contract;
[0012] S4: The user extracts the database address of the data to be verified from the smart contract, constructs an array of tuples A, constructs an array of tuples B based on the array of tuples A, and finally sends the array of tuples B to the smart contract;
[0013] S5: Perform verification, and finally store the verification result in a bool-type array Result. The user can access the array Result to know the verification result;
[0014] S6: The smart contract randomly generates a seed value for the update result corresponding to each database address in the verified array of tuples A, then calls the hash encryption function to generate a new hash value, constructs a new quadruple, and finally replaces the corresponding quadruple element in the array of quadruples with this new quadruple.
[0015] Preferably, the method for obtaining the address set in S1 is as follows: The service provider constructs an address set for each database address corresponding to each update command after all the update commands in the corresponding update command set are executed.
[0016] Preferably, the content of obtaining the set of tuples in S2 is as follows: First, select the update commands that are considered important and need to be verified multiple times in the future from the update command set to construct a subset of update commands, and then select the corresponding addresses from the address set according to the commands in the subset of update commands to construct a set of tuples.
[0017] Preferably, the content of obtaining the array of quadruples in S3 is as follows: First, extract the corresponding update results of the update commands in each tuple in the set, randomly generate a seed value for each update result, then call the hash encryption function to generate a separate hash value for each update result, and finally collect all four elements: the update command, the database address, the seed value, and the corresponding generated hash value to construct the array of quadruples.
[0018] Preferably, the obtaining content of the binary tuple array B in S4 is as follows: extract the seed value corresponding to each database address in the quadruple array to construct the binary tuple array A, send the binary tuple array A to the service party, extract the data in the database address of each binary tuple in the binary tuple array A, and call the hash encryption function to generate a hash value for each data to construct the binary tuple array B.
[0019] Preferably, the verification content in S5 is as follows: the smart contract finds the quadruple corresponding to the address in the quadruple array according to the address in each binary tuple in the binary tuple array B, and compares the hash value in the quadruple in the quadruple array with the hash value in the binary tuple in the binary tuple array. If the two are equal, it means that the data in this address is complete and has not been tampered with. Otherwise, it means that the data has been tampered with.
[0020] (III) Beneficial effects
[0021] Compared with the prior art, the user data integrity verification method based on Ethereum smart contract provided by the present invention has the following beneficial effects:
[0022] 1. For the user data integrity verification method based on Ethereum smart contract, the Ethereum blockchain is used as a third-party verification platform, and the smart contract deployed on the blockchain is used for verification operations, effectively avoiding the problem of maliciously providing false verification information brought by the centralized verification party, and ensuring that any data tampering behavior in the centralized database can be detected. In addition, the present invention only needs to provide a smart contract call interface and a communication interface with the data user to complete the verification, and has no requirements for the internal operation mechanism and underlying architecture of the centralized database platform, so it has good portability and scalability.
[0023] 2. For the user data integrity verification method based on Ethereum smart contract, compared with the traditional blockchain, the Ethereum blockchain does not store the user's custom data in the block, but can use the smart contract to store the custom data in the database of the Ethereum node. Its database supports dynamic operations such as insertion, modification, and deletion by users, and the usage efficiency is higher than that of the traditional blockchain.
[0024] 3. For the user data integrity verification method based on Ethereum smart contract, the Ethereum blockchain uses the PoA consensus protocol (Proof-of-Authority), rather than the PoW consensus protocol (Proof-of-Work); compared with the PoW consensus protocol, the basic idea of the PoA consensus protocol is to select a central authoritative node elected by all nodes to unify the node status, so there is no need for mining operations and no computing power consumption, and it is superior to the PoW consensus protocol in terms of performance and scalability.
[0025] 4. The user data integrity verification method based on Ethereum smart contract replaces the third-party verification platform in the traditional solution with a smart contract running on the Ethereum blockchain, avoiding the problem that the third-party verification platform colludes with malicious service providers to tamper with user data and generate false data integrity verification results. At the same time, it also avoids the problem that the third-party verification platform collects user information during the verification process, greatly improving security and privacy.
[0026] 5. In the user data integrity verification method based on Ethereum smart contract, the data user stores the hash value of the update result in the smart contract. Due to the immutability of the blockchain, the service provider cannot tamper with the original hash value, so it has high verification reliability.
[0027] 6. In the user data integrity verification method based on Ethereum smart contract, when the data in a certain database address has been verified, the corresponding seed value will be sent to the service provider. Therefore, after the verification is completed, the service provider actually already knows the seed value and hash value corresponding to the data. If the same data is verified multiple times, then the service provider is very likely to send the pre-prepared hash value to the smart contract to deceive the user. Therefore, after the verification of a certain data is completed, it is necessary to reset the original seed value and hash value of this data to ensure the reliability of the next verification. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] Figure 1 is the flowchart of the steps of the verification method in the embodiment of the present invention;
[0029] Figure 2 is the network system diagram of the embodiment of the present invention;
[0030] Figure 3 is the interaction diagram of three parties in the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0031] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0032] Embodiment
[0033] Please refer to Figures 1-3 , the user data integrity verification method based on Ethereum smart contract provided by the embodiment of the present invention includes the following steps:
[0034] S1: The data user C sends a request to update data to the service provider S and sends an update command set M = (m1, m2,..., mn) to the service provider S. The service provider S executes all the update commands in the received update command set M according to the corresponding requirements. After all the update commands are executed, the service provider S constructs an address set D = (d1, d2,..., dn) from the database addresses d corresponding to each update command and sends D to the data user C;
[0035] S2: After receiving the database address set D, the data user C first selects the update commands that it deems important and needs to be verified multiple times in the future from the update command set M to construct an update command subset M' = (m'1, m'2,..., m'k). Then, according to the commands in the subset, the data user C selects the corresponding addresses d'k from the address set D to construct a binary tuple set R = [(m'1, d'1), (m'2, d'2),...,(m'k, d'k)]. Finally, the data user C sends R to the smart contract;
[0036] S3: After receiving the binary tuple set R, the smart contract first extracts the corresponding update results q of the update commands in each binary tuple in the set, and randomly generates a seed value s for each update result q. Then, the smart contract calls the hash encryption function Hash(x1, x2) to generate a separate hash value h for each update result q (the input parameters of the hash encryption function are two, the first is the update result q, and the second is the corresponding seed value s). Among them, the principle of the Hash(x1, x2) encryption function is: convert the input parameters x1 and x2 into strings and concatenate them, and then call the SHA256 (Secure Hash Algorithm) hash encryption function, using the concatenated parameter xz as the input parameter of this function to obtain the resulting hash value h. Finally, the smart contract collects all four elements: the update command m, the database address d, the seed value s, and the corresponding generated hash value h, and constructs a quadruple array L = [(m'1, d'1, s1, h1), (m'2, d'2, s2, h2),...,(m'k, d'k, sk, hk)] for future verification and stores L in the smart contract;
[0037] S4: The user extracts the database addresses of the data to be verified from the smart contract, and extracts the corresponding seed values s in the quadruple array L for each database address, constructs a binary tuple array H’ = [(d’1, s1), (d’2, s2),..., (d’p, sp)], and sends this binary tuple array H’ to the service provider S. After receiving the binary tuple array H’, the service provider S extracts the data in the database address d’p of each binary tuple in H’, calls the hash encryption function Hash(x1, x2) to generate a hash value h’ for each data, constructs a binary tuple array G = [(d’1, h’1), (d’2, h’2),..., (d’p, h’p)], and finally sends G to the smart contract;
[0038] S5: After receiving the binary tuple array G, the smart contract finds the quadruple corresponding to the address d’1 in the quadruple array L according to the address d’1 in each binary tuple in G, and compares the hash value h in the quadruple in L with the hash value h’ in the binary tuple in G. If the two are equal, it means that the data at this address is complete and has not been tampered with. Otherwise, it means that the data has been tampered with. Finally, the verification result is stored in a bool-type array Result, and the user can access the array Result to know the verification result;
[0039] S6: The smart contract randomly generates a seed value s’ for the update result q corresponding to each database address in the verified binary tuple array H’, then calls the hash encryption function Hash(x1, x2) to generate a new hash value h”, and constructs a new quadruple (m’, d’, s’, h”), and finally replaces the corresponding quadruple element in the quadruple array L with this new quadruple.
[0040] In the above embodiments of the present invention, the Ethereum blockchain is used as a third-party verification platform, and the smart contract deployed on the blockchain is used to perform verification operations, effectively avoiding the problem of maliciously providing false verification information brought by the centralized verification party, and ensuring that any data tampering behavior in the centralized database can be detected. In addition, the present invention only needs to provide the smart contract call interface and the communication interface with the data user to complete the verification, and has no requirements for the internal operation mechanism and underlying architecture of the centralized database platform, so it has good portability and scalability.
[0041] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principle and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A method for verifying the integrity of user data based on Ethereum smart contracts, characterized in that, It includes the following steps: S1: The data user sends a request to update data to the service provider and sends a set of update commands to the service provider. The service provider sends the address set to the data user; S2: After receiving the database address set, the data user constructs a set of tuples based on the set of update commands and the address set, and finally sends the set of tuples to the smart contract; S3: After receiving the set of tuples, the smart contract generates a seed value and a hash value, constructs an array of quadruples for future verification, and stores the array of quadruples in the smart contract; S4: The user extracts the database address of the data to be verified from the smart contract, constructs an array of tuples A, constructs an array of tuples B based on the array of tuples A, and finally sends the array of tuples B to the smart contract; S5: Perform verification, and finally store the verification result in an array Result of bool type. The user can access the array Result to know the verification result; S6: The smart contract randomly generates a seed value for the update result corresponding to each database address in the verified array of tuples A, then calls the hash encryption function to generate a new hash value, and constructs a new quadruple. Finally, replace the corresponding quadruple element in the array of quadruples with this new quadruple; The said S4 includes: The array of tuples A, which is expressed by the formula as follows: H’ = [(d’1, s1), (d’2, s2),..., (d’p, sp)]; The array of tuples B, which is expressed by the formula as follows: G = [(d’1, h’1), (d’2, h’2),..., (d’p, h’p)]; After receiving the array of tuples A, the service provider extracts the data in the database address d’p of each tuple in A, calls the hash encryption function Hash(x1, x2) to generate a hash value h’ for each data, constructs an array of tuples B, and finally sends the array of tuples B to the smart contract. s is the seed value corresponding to each database address in the array of quadruples; The said S5 includes: After receiving the array of tuples B, the smart contract finds the quadruple corresponding to the address d’1 in the array of quadruples according to the address d’1 in each tuple in the array of tuples B, and compares the hash value h in the array of quadruples with the hash value h’ in the array of tuples B. If the two are equal, it means that the data at this address is complete and has not been tampered with. Otherwise, it means that the data has been tampered with. Finally, store the verification result in an array Result of bool type. The user can access the array Result to know the verification result; The said S6 includes: The smart contract randomly generates a seed value s’ for the update result q corresponding to each database address in the verified array of tuples A, then calls the hash encryption function Hash(x1, x2) to generate a new hash value h’’, and constructs a new quadruple. Finally, replace the corresponding quadruple element in the original array of quadruples with this new quadruple.
2. The user data integrity verification method based on Ethereum smart contract according to claim 1, wherein: The method for obtaining the address set in S1 is as follows: The service party constructs an address set by the database addresses corresponding to each update command after all the update commands in the corresponding update command set are executed.
3. The user data integrity verification method based on Ethereum smart contract according to claim 1, wherein: The content for obtaining the binary tuple set in S2 is as follows: First, select the update commands that are considered important and need to be verified multiple times in the future from the update command set to construct an update command subset, and then select the corresponding addresses from the address set according to the commands in the update command subset to construct a binary tuple set.
4. The user data integrity verification method based on Ethereum smart contract according to claim 1, characterized in that: The content for obtaining the quadruple array in S3 is as follows: First, extract the corresponding update results of the update commands in each binary tuple in the set, and randomly generate a seed value for each update result. Then, call the hash encryption function to generate a separate hash value for each update result. Finally, collect all four elements: the update command, the database address, the seed value, and the corresponding generated hash value to construct a quadruple array.
Citation Information
Patent Citations
Cloud data integrity verification scheme based on blockchain
CN113556322A
Data storage method and apparatus, and system
WO2022052042A1