Distributed data transmission method, device and system
By storing a directory access permission table for evidence files on a blockchain network, combined with DPKI and distributed user identity, the problem of secure data file access and authentication in a decentralized storage environment is solved, enabling secure data sharing and financial business applications.
Patent Information
- Application Number
- CN202211034975.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-26
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2042-08-26
AI Technical Summary
In decentralized storage environments, secure access to data files and digital rights management present challenges, particularly in access control for distributed file storage, where effective permission management and authentication schemes are lacking.
By introducing DPKI and distributed user identity, and using a blockchain network to store document directory access permission tables, combined with digital identity embedded in the directory access permission tables, secure access and authentication are achieved.
It effectively solves the challenges of secure access and authentication for decentralized digital file storage, and provides a trusted storage solution for scenarios such as secure data sharing and financial transactions.
Smart Images

Figure CN115412568B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data processing, in particular to the technical field of blockchain, and more particularly to a distributed data transmission method, device and system. BACKGROUND
[0002] With the advent of the web3.0 era, the use of data security is increasingly valued by all parties, and data copyright and security management has become the most concerned topic on the Internet. In recent years, the development of blockchain applications has led to a geometric exponential growth in the size of on-chain data. Due to the limitations of the on-chain storage bottleneck, traditional blockchain technology generally uses decentralized storage technology to implement off-chain storage, effectively solving the problems of data multi-copy backup and sharing, and realizing decentralized multi-copy storage and sharding storage for a data file, but also putting forward higher requirements for data file access security and copyright management.
[0003] Decentralized storage technology is a point-to-point distributed file transmission system that saves content storage space and improves the transmission efficiency of the distributed file system by storing file fragments and multi-point concurrent transmission. However, it also brings new challenges in terms of access security. In a decentralized environment, user data files are fragmented and stored in different storage nodes, which poses a problem for secure file access and identity verification. There is no mature solution for ensuring secure access to data files and digital copyright management in a decentralized environment. Currently, in the field of decentralized file storage access control, PKI technology is mainly used for encryption authentication, and an authentication mechanism is established, but there is still little research on directory permission control for specific target users. In order to achieve enterprise-level trusted file evidence and sharing functions, there is still a lot of room for improvement in the service capabilities of decentralized file directory tree permission management and access control. SUMMARY
[0004] The present application provides a distributed data transmission method that utilizes the characteristics of blockchain multi-party sharing and trusted evidence storage to store a file directory access permission table on a blockchain network, ensuring that the permission table can be accessed and accessed by the nearest storage node. The present application innovatively introduces DPKI and distributed user identity, and embeds the digital identity into the directory access permission table, effectively solving the security access and identity verification problems of decentralized decentralized digital file access, and can be widely applied in secure data sharing, financial business and other business scenarios.
[0005] To achieve the above purpose, the present application discloses a distributed data transmission method suitable for a client, comprising:
[0006] receiving a data transmission request of a user, the data transmission request comprising a data upload request and a data access request;
[0007] when the data transmission request is the data upload request, encrypting a file to be transmitted according to the data transmission request to generate a ciphertext file, and sending the ciphertext file to a decentralized storage node, and uploading content address information corresponding to the ciphertext file and a digital identity of a user to a blockchain;
[0008] when the data transmission request is the data access request, forwarding the data access request to the decentralized storage node, receiving an encrypted file sent by the decentralized storage node in response to the data access request, decrypting the encrypted file, and uploading content address information corresponding to the decrypted encrypted file and the digital identity of the user to the blockchain.
[0009] In an embodiment, the encrypting a file to be transmitted according to the data transmission request to generate a ciphertext file comprises:
[0010] generating a symmetric key according to a preset symmetric key generation function and the digital identity;
[0011] encrypting the file to be transmitted according to the symmetric key to generate the ciphertext file.
[0012] In an embodiment, the distributed data transmission method further comprises:
[0013] performing transaction flow control and fuse control according to a number of data transmission requests.
[0014] The application further discloses a distributed data transmission method suitable for a decentralized storage node, comprising:
[0015] receiving a data transmission request sent by a client; the data transmission request comprises a data upload request and a data access request;
[0016] when the data transmission request is the data upload request, performing a fragmentation operation on a ciphertext file sent by the client, performing fragmented storage on the ciphertext file after the fragmentation operation, and uploading content address information of the fragmented ciphertext file and a digital identity of a user to a blockchain;
[0017] when the data transmission request is the data access request, performing a splicing operation on a file to be accessed by the client, sending the spliced file to the client, and uploading content address information of the spliced file and the digital identity of the user to the blockchain.
[0018] In an embodiment, the distributed data transmission method further comprises:
[0019] determining a number and a length of the ciphertext file after the fragmentation operation;
[0020] According to the number and length of the ciphertext files, a file object tree is established to query the ciphertext files.
[0021] In an embodiment, in the distributed data transmission method, before sending the merged file to the client, the method further comprises:
[0022] According to the user digital identity, the integrity of the merged file is verified.
[0023] Correspondingly, the application also discloses a distributed data transmission device suitable for a client, comprising:
[0024] The transmission request first receiving module is configured to receive a data transmission request of a user, wherein the data transmission request comprises a data upload request and a data access request.
[0025] The data upload first module is configured to, when the data transmission request is the data upload request, encrypt a file to be transmitted according to the data transmission request to generate a ciphertext file, send the ciphertext file to a decentralized storage node, and upload content address information corresponding to the ciphertext file and a digital identity of the user to a block chain.
[0026] The data access first module is configured to, when the data transmission request is the data access request, forward the data access request to the decentralized storage node, receive an encrypted file sent by the decentralized storage node in response to the data access request, decrypt the encrypted file, and upload content address information corresponding to the decrypted encrypted file and the digital identity of the user to the block chain.
[0027] In an embodiment, the data upload first module comprises:
[0028] The symmetric key generation unit is configured to generate a symmetric key according to a preset symmetric key generation function and the digital identity.
[0029] The ciphertext file generation unit is configured to encrypt the file to be transmitted according to the symmetric key to generate the ciphertext file.
[0030] In an embodiment, the distributed data transmission device further comprises:
[0031] The flow limiting module is configured to perform transaction flow limiting and fuse control according to the number of data transmission requests.
[0032] Correspondingly, the application also discloses a distributed data transmission device suitable for a decentralized storage node, comprising:
[0033] The transmission request second receiving module is configured to receive a data transmission request sent by a client, wherein the data transmission request comprises a data upload request and a data access request.
[0034] The data uploading second module is configured to, when the data transmission request is the data uploading request, perform a fragmentation operation on the ciphertext file sent by the client, perform fragmented storage on the ciphertext file after the fragmentation operation, and upload content address information of the fragmented ciphertext file and a user digital identity to a block chain.
[0035] The data accessing second module is configured to, when the data transmission request is the data accessing request, perform a file combining operation on the file to be accessed by the client, send the file after the combining operation to the client, and upload content address information of the file after the combining operation and the user digital identity to the block chain.
[0036] In an embodiment, the distributed data transmission device further comprises:
[0037] The length determining module is configured to determine the number and length of the ciphertext file after the fragmentation operation.
[0038] The object tree establishing module is configured to establish a file object tree according to the number and length of the ciphertext file, so as to query the ciphertext file.
[0039] In an embodiment, the distributed data transmission device further comprises:
[0040] The integrity checking module is configured to perform integrity checking on the file after the combining operation according to the user digital identity.
[0041] The application further discloses a decentralized storage node configured to receive a data transmission request sent by a client, wherein the data transmission request comprises a data uploading request and a data accessing request; when the data transmission request is the data uploading request, perform a fragmentation operation on a ciphertext file sent by the client, perform fragmented storage on the ciphertext file after the fragmentation operation, and upload content address information of the fragmented ciphertext file and a user digital identity to a block chain; and when the data transmission request is the data accessing request, perform a file combining operation on the file to be accessed by the client, send the file after the combining operation to the client, and upload content address information of the file after the combining operation and the user digital identity to the block chain.
[0042] The application also discloses a client configured to receive a data transmission request of a user, wherein the data transmission request comprises a data upload request and a data access request; when the data transmission request is the data upload request, encrypt a file to be transmitted according to the data transmission request to generate a ciphertext file, send the ciphertext file to a decentralized storage node, and upload content address information corresponding to the ciphertext file and a digital identity of the user to a blockchain; when the data transmission request is the data access request, forward the data access request to the decentralized storage node, receive an encrypted file sent by the decentralized storage node in response to the data access request, decrypt the encrypted file, and upload content address information corresponding to the decrypted encrypted file and the digital identity of the user to the blockchain.
[0043] The application also discloses a distributed data transmission system comprising a client, a decentralized storage network and a blockchain.
[0044] The client is configured to receive a data transmission request of a user, wherein the data transmission request comprises a data upload request and a data access request; when the data transmission request is the data upload request, encrypt a file to be transmitted according to the data transmission request to generate a ciphertext file, send the ciphertext file to a decentralized storage node, and upload content address information corresponding to the ciphertext file and a digital identity of the user to a blockchain; when the data transmission request is the data access request, forward the data access request to the decentralized storage node, receive an encrypted file sent by the decentralized storage node in response to the data access request, decrypt the encrypted file, and upload content address information corresponding to the decrypted encrypted file and the digital identity of the user to the blockchain.
[0045] The decentralized storage network comprises a plurality of decentralized storage nodes; the decentralized storage nodes are configured to receive a data transmission request sent by the client, wherein the data transmission request comprises a data upload request and a data access request; when the data transmission request is the data upload request, perform a fragmentation operation on a ciphertext file sent by the client, perform fragmented storage on the ciphertext file after the fragmentation operation, and upload content address information of the fragmented ciphertext file and a digital identity of a user to a blockchain; when the data transmission request is the data access request, perform a splicing operation on a file to be accessed by the client, send the spliced file to the client, and upload content address information of the spliced file and the digital identity of the user to the blockchain.
[0046] The application also discloses a computer device comprising a memory, a processor and a computer program stored in the memory and capable of running on the processor.
[0047] The processor implements the method as described above when executing the program.
[0048] The application further discloses a computer readable medium, which stores a computer program,
[0049] The program is executed by the processor to implement the method as described above.
[0050] From the above description, first, the embodiment of the application provides a distributed data transmission method suitable for a client, which comprises the following steps: receiving a data transmission request of a user, wherein the data transmission request comprises a data upload request and a data access request; when the data transmission request is the data upload request, encrypting a file to be transmitted according to the data transmission request to generate a ciphertext file, sending the ciphertext file to a decentralized storage node, and uploading content address information corresponding to the ciphertext file and a digital identity of the user to a block chain; when the data transmission request is the data access request, forwarding the data access request to the decentralized storage node, receiving an encrypted file sent by the decentralized storage node in response to the data access request, decrypting the encrypted file, and uploading content address information corresponding to the decrypted encrypted file and the digital identity of the user to the block chain.
[0051] Next, the embodiment of the application further provides a distributed data transmission method suitable for a decentralized storage node, which comprises the following steps: receiving a data transmission request sent by a client; the data transmission request comprises a data upload request and a data access request; when the data transmission request is the data upload request, performing a fragmentation operation on a ciphertext file sent by the client, performing fragmented storage on the ciphertext file after the fragmentation operation, and uploading content address information of the fragmented ciphertext file and a digital identity of a user to a block chain; when the data transmission request is the data access request, performing a splicing operation on a file to be accessed by the client, sending the file after the splicing operation to the client, and uploading content address information of the file after the splicing operation and the digital identity of the user to the block chain.
[0052] The application preferably solves the problems of secure storage and identity verification in a decentralized distributed file storage system, establishes a set of decentralized data security access and identity verification framework, and introduces a decentralized public key system (DPKI) and a distributed digital identity (DID) based on blockchain technology. When a user accesses a file, a blockchain smart contract is called to perform permission control and identity verification, and the permission verification is performed with the file access directory tree on the blockchain, so that the access operation is performed according to the authentication result. By using the characteristics of multi-party sharing and trusted evidence storage of the blockchain, the file directory access permission table is stored on the blockchain network to ensure that the permission table can be obtained and accessed by the nearest storage node. The application innovatively introduces the DPKI and the distributed user identity, and embeds the digital identity into the directory access permission table, effectively solves the problems of secure access and identity verification of decentralized distributed digital file access, and can be widely applied in business scenarios such as secure data sharing and financial business. BRIEF DESCRIPTION OF DRAWINGS
[0053] In order to more clearly illustrate the technical solutions in the embodiments of the application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description are only some embodiments of the application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of these drawings.
[0054] Figure 1 Flowchart of the distributed data transmission method in the embodiments of the application Figure 1 (Applicable to the client);
[0055] Figure 2 Flowchart of step 300 of the file transmission method based on the blockchain in the embodiments of the application
[0056] Figure 3 Flowchart of the distributed data transmission method in the embodiments of the application Figure 2 (Applicable to the client);
[0057] Figure 4 Flowchart of the distributed data transmission method in the embodiments of the application Figure 1 (Applicable to the decentralized storage node);
[0058] Figure 5 Flowchart of the distributed data transmission method in the embodiments of the application Figure 2 (Applicable to the decentralized storage node);
[0059] Figure 6 Flowchart of the distributed data transmission method in the embodiments of the application Figure 3 (Applicable to the decentralized storage node);
[0060] Figure 7 Block diagram of the distributed data transmission system in the embodiment of the present application;
[0061] Figure 8 Hierarchical structure diagram of the distributed data transmission system in the embodiment of the present application;
[0062] Figure 9 Block diagram of the service gateway node 3 in the embodiment of the present application;
[0063] Figure 10 Block diagram of the decentralized storage node 4 in the embodiment of the present application;
[0064] Figure 11 Block diagram of the blockchain node 5 in the embodiment of the present application;
[0065] Figure 12 Flowchart of the distributed data transmission method in the embodiment of the present application;
[0066] Figure 13 Distributed data transmission device in the embodiment of the present application Figure 1 (suitable for a client);
[0067] Figure 14 Block diagram of the data uploading first module 10 in the embodiment of the present application;
[0068] Figure 15 Distributed data transmission device in the embodiment of the present application Figure 2 (suitable for a client);
[0069] Figure 16 Distributed data transmission device in the embodiment of the present application Figure 1 (suitable for a decentralized storage node);
[0070] Figure 17 Distributed data transmission device in the embodiment of the present application Figure 2 (suitable for a decentralized storage node);
[0071] Figure 18 Distributed data transmission device in the embodiment of the present application Figure 3 (suitable for a decentralized storage node);
[0072] Figure 19 Structure diagram of an electronic device in the embodiment of the present application. DETAILED DESCRIPTION
[0073] With reference to the accompanying drawings, the technical solutions in the embodiments of the present application will be described clearly and completely. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all the other embodiments obtained by a person of ordinary skill in the art without creative effort are within the scope of the present application.
[0074] It should be noted that the distributed data transmission method, device and system disclosed in the present application can be used in the field of artificial intelligence technology, and can also be used in any field other than the field of artificial intelligence technology. The application field of the distributed data transmission method, device and system disclosed in the present application is not limited.
[0075] In the technical solutions of the present application, the acquisition, storage, use, processing and the like of data comply with the relevant provisions of national laws and regulations.
[0076] According to an aspect of the present application, the present embodiment discloses a distributed data transmission method suitable for a client. As shown in Figure 1 The method comprises the following steps:
[0077] Step 100: receiving a data transmission request of a user, the data transmission request comprising a data upload request and a data access request;
[0078] It can be understood that the data transmission herein includes two aspects, data upload and data access (data download).
[0079] Step 200: when the data transmission request is the data upload request, encrypting a file to be transmitted according to the data transmission request to generate a ciphertext file, and sending the ciphertext file to a decentralized storage node, and uploading content address information corresponding to the ciphertext file and a digital identity of the user to a blockchain;
[0080] It should be noted that in the blockchain network involved in the present application, all nodes, users and file entities (fragments) have a globally unique digital identity identifier DID. The DID complies with the W3C DID specification, and is formally expressed as:
[0081] DID={id|id="did":"method-name":"{0,1} * "}
[0082] Wherein, method-name represents the domain of the DID, {0,1} *The identifier 256 bits, indicating the address of the digital identity in the domain. The DID is the digital identity ID of the node and user in the blockchain network, which is synchronized to the consensus ledger node through the blockchain network and stored in the block. The blockchain network provides a smart contract to provide interactive services for visitors.
[0083] Step 300: When the data transmission request is the data access request, forwarding the data access request to the decentralized storage node, receiving the encrypted file sent by the decentralized storage node in response to the data access request, decrypting the encrypted file, and uploading the content address information corresponding to the decrypted encrypted file and the digital identity of the user to the blockchain.
[0084] It can be understood that the client is also responsible for keeping the user's private key and symmetric key, managing the user's digital identity DID; responsible for calling the security interface API provided by the blockchain network to realize user identity registration, authentication, and encryption and decryption of encrypted files.
[0085] In the preferred embodiment, as shown in Figure 2 The step of encrypting the file to be transmitted in step 200 according to the data transmission request to generate an encrypted file includes:
[0086] Step 201: generating a symmetric key according to a preset symmetric key generation function and the digital identity;
[0087] Specifically, the key processing smart contract is executed to generate the digital identity DID and the symmetric key sk b , formally:
[0088] sk b =GenSymKey(Did,P(1 k ))
[0089] Where GenSymKey is the symmetric key generation function, Did represents the user's distributed digital identity, and P(1 k ) represents a security parameter.
[0090] Step 202: encrypting the file to be transmitted according to the symmetric key to generate the encrypted file.
[0091] Encrypt the file with the symmetric key to generate the encrypted file, and sign the file M with the user's private key, and upload the signature, encrypted file and DID to the service gateway. Specifically:
[0092] The decrypted symmetric key sk b is restored: Encrypt the file M with the symmetric key to produce the ciphertext C M : CM = SymEncry(M, sk b ); sign C u with user private key sk M to produce signature Form a message to upload service gateway: Call decentralized file storage API to upload message P M .
[0093] In a preferred embodiment, as shown in Figure 3 , the distributed data transmission method for the client further comprises:
[0094] Step 400: transaction flow control and fuse control according to the number of data transmission requests.
[0095] Specifically, transaction flow control and fuse control are configured according to transaction throughput. Fuse is generally a protective measure taken to prevent the entire system from failing due to overload of the service for some reason. Service fuse is generally caused by failure of a certain service (downstream service). More specifically, fuse generally has the following three states:
[0096] Closed (closed): closed state of the fuse, accumulation of call failure times, and when the threshold (or a certain proportion) is reached, the fuse mechanism is started.
[0097] Open (open): open state of the fuse, at which time all downstream calls are returned directly internally with an error without going through the network. A clock option is designed, and the default clock reaches a certain time (usually set to the average fault handling time). When this time is reached, it enters a half-fuse state.
[0098] Half-Open (half-open): half-fuse state, allowing a certain number of service requests. If all calls are successful (or a certain proportion), it is considered to have recovered, and the fuse is closed. Otherwise, it is considered to have not recovered, and it returns to the open state of the fuse.
[0099] According to one aspect of the present application, the present embodiment discloses a distributed data transmission method suitable for a decentralized storage node. As shown in Figure 4 , in the present embodiment, the method comprises:
[0100] Step A: receiving a data transmission request sent by a client; the data transmission request comprises a data upload request and a data access request;
[0101] It can be understood that the data transmission request in step A is essentially initiated by a user and forwarded by a client. Similarly, similar to step 100, the data transmission in step A includes two aspects, data upload and data access (data download).
[0102] Step B: When the data transmission request is the data upload request, performing a fragmentation operation on the ciphertext file sent by the client, and storing the fragmented ciphertext file, and uploading the content address information and user digital identity of the fragmented ciphertext file to the blockchain;
[0103] First, generate a CID for the decentralized file content. Let FileLink M represent the data format of the file M link, formally:
[0104] FileLink M = (Cid, Size, FileObj{Links, data M}, chksum)
[0105] Where Size represents the size of the file M, FileObj represents the file object structure, Links represents the link array of the file fragments, data M represents the data content of M, CID represents the content address information, formally:
[0106] Cid = h(M, Did1,..., Did n )
[0107] Where h is a Hash function, Did1, Did2,...., Did n represents a group of digital identities that own the file M. The data format of the file block is shown in Table 1:
[0108] Table 1
[0109]
[0110] Step C: When the data transmission request is the data access request, performing a merging operation on the file to be accessed by the client, and sending the merged file to the client, and uploading the content address information and user digital identity of the merged file to the blockchain.
[0111] Collecting the fragmented data of the file from multiple storage nodes, summarizing the ciphertext file, and checking the integrity of the file.
[0112] In an embodiment, referring to Figure 5 , the distributed data transmission method suitable for decentralized storage nodes further comprises:
[0113] Step D: Determine the number and length of the fragmented ciphertext file;
[0114] Step E: Establishing a file object tree according to the number and length of the ciphertext files to query the ciphertext files.
[0115] In step D and step E, the file object data content is first fragmented, and meanwhile, the fragmented data is ensured to be connected with each other, and finally, a file object tree is formed. Specifically, a directory tree structure is constructed by content hash links, and the nodes of the directory tree are composed of a connection array and a length, and the connection array stores content hashes, which satisfy the verification condition of a DAG Merkle Tree.
[0116] In an embodiment, referring to Figure 6 Before sending the fragmented file to the client, it further includes:
[0117] Step F: Integrity checking the fragmented file according to the user digital identity.
[0118] Specifically, the integrity checking and signature verification of the ciphertext file are performed by inputting the user public key pk u , and the following signature verification function is executed:
[0119]
[0120] If is established, it indicates that the signature verification passes, and vice versa.
[0121] From the above description, it can be known that first, the embodiment of the present application provides a distributed data transmission method suitable for a client, which includes: receiving a data transmission request of a user, the data transmission request including a data upload request and a data access request; when the data transmission request is the data upload request, encrypting a file to be transmitted according to the data transmission request to generate a ciphertext file, and sending the ciphertext file to a decentralized storage node, and uploading content address information corresponding to the ciphertext file and a digital identity of the user to a blockchain; when the data transmission request is the data access request, forwarding the data access request to the decentralized storage node, receiving an encrypted file sent by the decentralized storage node in response to the data access request, decrypting the encrypted file, and uploading content address information corresponding to the decrypted encrypted file and the digital identity of the user to the blockchain.
[0122] Then, the embodiment of the present application also provides a distributed data transmission method suitable for a decentralized storage node, comprising: receiving a data transmission request sent by a client; the data transmission request comprises a data upload request and a data access request; when the data transmission request is the data upload request, performing a fragmentation operation on a ciphertext file sent by the client, and performing fragmented storage on the ciphertext file after the fragmentation operation, and uploading content address information and a user digital identity of the fragmented ciphertext file to a block chain; when the data transmission request is the data access request, performing a splicing operation on a file to be accessed by the client, and sending the spliced file to the client, and uploading content address information and a user digital identity of the spliced file to the block chain. Specifically, the present application has the following beneficial effects:
[0123] 1. A trusted storage data safe system framework based on a block chain is proposed, which combines a block chain network, supports distributed identity registration of a user initiated by a data owner, data file upload and file access transaction, and provides a hosting mechanism for file safe upload and access of the user.
[0124] 2. A decentralized file safe upload algorithm is proposed, which provides services such as secure encryption and identity authentication for a data owner, realizes on-chain binding of a digital identity DID and a content hash (Cid), and constructs a ciphertext content hash on-chain storage.
[0125] 3. A decentralized file safe access algorithm is proposed, which provides a safe access service for a data owner, first verifies a target user DID on-chain, and then respectively signs and decrypts a ciphertext file according to a user key and a symmetric key, and has the characteristics of high security and fast response speed.
[0126] 4. A credential and message format based on decentralized file directory authorization is proposed, which realizes DS storage node information sharing, block link directory access permission update and the like.
[0127] In a specific embodiment, the present application also provides a specific embodiment of a distributed data transmission method, which specifically comprises the following contents.
[0128] Term introduction:
[0129] Digital identity (Digital Identity): refers to the characterization of an individual through digital information, which condenses real identity information into a digital code form of public / private key, so as to bind, query and verify the behavior information of the individual.
[0130] Decentralized storage: refers to storing data in multiple independent devices in a decentralized and untrusted network environment, breaking the monopoly of centralized storage, solving the problem that a single storage server becomes a bottleneck of system performance, and meeting the demand for more secure, reliable and controllable storage.
[0131] Blockchain: a common record-keeping solution that uses cryptography to ensure access security, P2P communication technology to realize peer-to-peer communication, consensus mechanism to realize record legality, and chain structure to store data to realize non-tamperable record-keeping.
[0132] DAG Merkle Tree: a Merkle Tree generated by using the properties of Directed Acyclic Graph (DAG), the hash of the parent node is equal to the hash of all child nodes, and the child nodes may come from different lower layers but not appear in the same layer and higher layer, so the nodes of the DAG Merkle Tree may have multiple fathers but no loop.
[0133] Referring to Figure 7 , the embodiment of the application first provides a distributed data transmission system, which comprises: a client 0, a service gateway 1, a DS node 2, a blockchain node 3, a user 4 and an issuer 5.
[0134] The client 0 is mainly responsible for initiating smart contract deployment requests, decentralized storage transaction requests, decentralized storage query requests and the like.
[0135] The service gateway 1 is mainly responsible for providing smart contract API, realizing flow limiting and fusing, security detection, file storage and access, identity authentication and security parameter setting and the like.
[0136] The DS node 2 is a decentralized storage node, which is responsible for receiving file read / write requests of the service gateway 1, performing decentralized file read / write, and storing transaction information to the blockchain node. The client A and the client B of the application respectively access the DS node through the service gateway 1, publish file read requests through the DS node, and receive file read results.
[0137] The blockchain node 3 is a node that completes functions such as transaction broadcasting, transaction execution, transaction verification, consensus and storage. It has the general characteristics of a blockchain. Through the client, a file reading instruction is initiated, and the transaction record after the execution of the file read / write storage smart contract is also saved on the blockchain.
[0138] The user 4 initiates security parameter initialization, receives digital certificates issued by the issuer 5, registers a digital identity DID on the blockchain network, and uploads and accesses files as a file owner.
[0139] Issuer 5: identity verification of the user 4, and issuance of a digital certificate to the user 4.
[0140] Next, the hierarchical structure of the distributed data transmission system is shown in Figure 8 , which includes a client access layer 20, a gateway service layer 21, a decentralized file storage network 22, and a blockchain network 23.
[0141] The client access layer 20: used to provide client software for operator access, facilitate the initiation of decentralized storage requests, and receive decentralized storage results. The client can publish chaincode on the blockchain platform, and after the client generates behavior data for uploading or downloading, the chaincode can be called to initiate a transaction request, upload the behavior data to the chain, and according to the client use scenario, submit to the corresponding channel of each scenario (the client can directly upload the client behavior data without processing, and the specific data processing logic can be executed by the scenario provider). The provider can also publish chaincode, which can query data belonging to its own channel and process and analyze data of its own channel.
[0142] The gateway service layer 21: used to provide blockchain smart contract service API for clients, implement transaction flow control and fuse, DS node file upload and download, CID generation, DID registration, verification, directory query update, and other smart contract function calls.
[0143] The decentralized file storage network 22: used to submit upload (download), query, and other requests from the client, configure parameters, data, and business logic through decentralized storage logic, and form file block data through encryption, and its hash value is broadcast to the blockchain network 23. The scenario provider can also publish joint operation chaincode, which can call DS node services through chaincode, and each blockchain node has a corresponding DS node service. The chaincode can specify which DS services need to be jointly calculated. The scenario provider initiates a joint calculation request through the chaincode, and the data of other channel providers cannot access each other, but through DS, decentralized data storage can be performed without leaking each other's data.
[0144] The blockchain network 23: used to receive and decrypt file decentralized storage messages, trigger preset smart contract logic, and form decentralized storage log results. The blockchain network can provide hosting nodes, and capable providers can also provide local node deployment. Each scenario provider has its own channel on the blockchain, and the scenario provider cannot access the data information of other channels, i.e., other providers.
[0145] Referring to Figure 9 , the service gateway node 3 includes a communication module 31, a flow control and fuse module 32, a security authentication module 33, and an API service interface 34.
[0146] Communication module 31: responsible for establishing a secure channel for the service gateway node, realizing decentralized file storage request, initializing security parameters and other message transmission.
[0147] Current limiting and fusing module 32: responsible for transaction current limiting and fusing control according to transaction throughput configuration.
[0148] Security authentication module 33: responsible for keeping user's private key and symmetric key, managing user's digital identity DID; responsible for calling security interface API provided by the blockchain network, realizing user identity registration, authentication, and encryption and decryption of encrypted files.
[0149] API service interface 34: responsible for providing a series of smart contract API interface services such as blockchain DS storage and identity processing.
[0150] Next, referring to Figure 10 , the decentralized storage node 4 includes a communication module 41, a content generation module 42, a DAG module 43, and a Chunk module 44.
[0151] Communication module 41: responsible for establishing a secure channel for the DS node 2, realizing decentralized storage message transmission.
[0152] Content generation module 42: responsible for CID processing of decentralized file content generation.
[0153] DAG module 43: responsible for performing Merkle check on the content address CID, ensuring that the CID of the root node is equal to the calculated digest hash.
[0154] Chunk module 44: the file object data content is divided into fragments, and the fragments are connected to each other to form a file object tree.
[0155] Referring to Figure 11 , the blockchain node 5 includes a communication module 51, a transaction processing module 52, a smart contract module 53, and a consensus verification module 54.
[0156] Communication module 51: responsible for communication interaction between nodes, completing general blockchain node communication information, including transaction information broadcast, consensus related information, block synchronization information, network state information, etc.
[0157] Transaction processing module 52: responsible for receiving transaction requests, generating transaction unique identifiers, assembling transaction unique identifiers, contract unique identifiers and call parameters into transactions, and broadcasting to other nodes of the blockchain.
[0158] The smart contract module 53 receives the transaction request from the communication module 52, obtains the calculation result through the distributed storage, judges according to the preset business logic, and submits the final transaction instruction to the transaction processing module 52 for execution through the communication module 51. The DS node of the application calls the smart contract transaction, and the transaction processing module 52 receives the information and stores it in the blockchain network.
[0159] The consensus verification module 54 is responsible for consensus processing on the received transaction request, such as reaching a consensus, calling the smart contract module 53, executing the smart contract, and finally forming a record for future audit traceability or verification.
[0160] Referring to Figure 12 , based on the above-mentioned distributed data transmission system and the structure constructed by the same, the distributed data transmission method provided by the embodiment of the application includes the following contents, which are divided into three stages, but the second stage and the third stage have no sequence.
[0161] Stage one: initialization of security parameters. Specifically, stage one includes the following steps:
[0162] Step S601: The client receives the user's submitted initialization security parameter request;
[0163] Step S602: After receiving the request, the client calls the key generation sdk to generate asymmetric user public key and private key (pk u ,sk u ), the private key sk u is stored in the local storage of the client, and the public key pk u is uploaded to the service gateway and processed by the service gateway.
[0164] Step S603: Input the user public key pk u , distributed digital identity DID, and call the blockchain smart contract interface to initialize the security parameters.
[0165] Step S604: The transaction processing module receives and checks the initialization security parameter request.
[0166] Step S605: Execute the key processing smart contract to generate the digital identity DID and the symmetric key sk b , in the form of:
[0167] sk b =GenSymKey(Did,P(1 k ))
[0168] Wherein, GenSymKey is a symmetric key generation function, Did represents the user's distributed digital identity, and P(1 k ) represents the security parameter.
[0169] Step S606: store the digital identity DID and the user public key pk u row, and perform the following encryption function to encrypt the symmetric key to generate the ciphertext of the symmetric key pk b and return the ciphertext to the user:
[0170]
[0171] Step S607: return the security parameter to the client.
[0172] Step S608: store the symmetric private key to the client locally.
[0173] Step S609: return an initialization security parameter success message.
[0174] Phase two: upload file data, specifically, phase two includes the following steps:
[0175] Step S701: the user initiates a file upload request through the client.
[0176] Step S702: encrypt the file with the symmetric key, sign the file M with the user private key, and upload the signature, the encrypted file, and the DID to the service gateway. The processing procedure is as follows:
[0177] (1) decrypt the symmetric key sk b :
[0178] (2) encrypt the file M with the symmetric key to generate the ciphertext C M : C M = SymEncry(M, sk b );
[0179] (3) sign C u with the user private key sk M to generate the signature
[0180] (4) form a message to upload to the service gateway:
[0181] Step S703: call the decentralized file storage API to upload the message P M .
[0182] Step S704: parse the message P M , upload the encrypted file C M to the DS storage node, and generate the file content CID at the same time. The CID represents the content address information of the file M, which is in the form of:
[0183] Cid = h(M, Did1, Did2,..., Didn) n )
[0184] where h is a Hash function, Did1, Did2,..., Didn represent the digital identity group that owns the file M. n
[0185] Step S705: The service gateway checks whether the checking of the uploaded file and the generation of the CID are successful.
[0186] Step S706: If not, a return failure message is sent to the client.
[0187] Step S707: If yes, a blockchain smart contract is executed to chain store the correspondence between the CID and the user DID.
[0188] Step S708: A return result of successful file uploading is sent to the client.
[0189] Phase three: Accessing file data, specifically, phase three includes the following steps:
[0190] Step S801: The client receives a file directory query access request submitted by a user.
[0191] Step S802: After receiving the user request, the client first reads the user DID and sends a file directory list query application to the service gateway.
[0192] Step S803: The service gateway calls a blockchain smart contract API interface and inputs Did to query the file directory list.
[0193] Step S804: The smart contract is executed to query the on-chain corresponding record of the DID according to the input user Did, and if the record exists, the checking is successful.
[0194] Step S805: The file directory list related to the user DID is queried and returned to the client.
[0195] Step S806: The file directory list is displayed on the client.
[0196] Step S807: The user selects the file to be accessed according to the file directory displayed on the client and submits a file access request to the service gateway.
[0197] Step S808: After extracting the file CID, the client submits a file access request to the service gateway.
[0198] Step S809: The file CID and DID are input to call a blockchain storage smart contract API to obtain the encrypted file.
[0199] Step S810: execute the smart contract, collect the file M from the storage node DS, and aggregate the file C M , check the integrity of the file.
[0200] Step S811: call the blockchain smart contract to query the corresponding public key pk of the user DID on the chain u .
[0201] Step S812: integrity check and signature verification of the ciphertext file, specifically, input the user public key pk u , execute the following signature verification function:
[0202]
[0203] If is true, it means that the signature verification is passed, and vice versa.
[0204] Step S813: decrypt the ciphertext file C b according to the symmetric key sk M to generate the plaintext M, which is in the following form:
[0205] M = Decry(C M , sk b )
[0206] Step S814: the client receives the file information returned successfully.
[0207] The application preferably solves the security storage and identity verification problem in the decentralized distributed file storage system, establishes a set of decentralized data security access and identity verification framework, and introduces a decentralized public key system (DPKI) and a distributed digital identity (DID) based on blockchain technology. When the user accesses the file, the blockchain smart contract is called for permission control and identity verification, and the permission verification is performed with the file access directory tree on the blockchain, so that the access operation is performed according to the authentication result. By using the characteristics of multi-party sharing and trusted evidence of the blockchain, the file directory access permission table is stored on the blockchain network to ensure that the permission table can be accessed and accessed by the nearest storage node. The application innovatively introduces DPKI and distributed user identity, and embeds the digital identity into the directory access permission table, effectively solves the security access and identity verification problem of decentralized distributed digital file access, and can be widely applied in secure data sharing, financial business and other business scenarios.
[0208] Based on the same principle, referring to Figure 13 , the embodiment also discloses a distributed data transmission device suitable for a client, comprising:
[0209] The transmission request first receiving module 10 is configured to receive a data transmission request of a user, wherein the data transmission request comprises a data upload request and a data access request.
[0210] The data upload first module 20 is configured to, when the data transmission request is the data upload request, encrypt a file to be transmitted according to the data transmission request to generate a ciphertext file, send the ciphertext file to a decentralized storage node, and upload content address information corresponding to the ciphertext file and a digital identity of the user to a block chain.
[0211] The data access first module 30 is configured to, when the data transmission request is the data access request, forward the data access request to the decentralized storage node, receive an encrypted file sent by the decentralized storage node in response to the data access request, decrypt the encrypted file, and upload content address information corresponding to the decrypted encrypted file and the digital identity of the user to the block chain.
[0212] In an embodiment, referring to Figure 14 The data upload first module 10 comprises:
[0213] The symmetric key generation unit 101 is configured to generate a symmetric key according to a preset symmetric key generation function and the digital identity.
[0214] The ciphertext file generation unit 102 is configured to encrypt the file to be transmitted according to the symmetric key to generate the ciphertext file.
[0215] In an embodiment, referring to Figure 15 The distributed data transmission device further comprises:
[0216] The flow limiting module 40 is configured to perform transaction flow limiting and fuse control according to a number of data transmission requests.
[0217] Correspondingly, referring to Figure 16 The application further discloses a distributed data transmission device suitable for a decentralized storage node, comprising:
[0218] The transmission request second receiving module A is configured to receive a data transmission request sent by a client; the data transmission request comprises a data upload request and a data access request.
[0219] The data upload second module B is configured to, when the data transmission request is the data upload request, perform a fragmentation operation on a ciphertext file sent by the client, perform fragmented storage on the ciphertext file after the fragmentation operation, and upload content address information of the fragmented ciphertext file and a digital identity of the user to a block chain.
[0220] The data access second module C is configured to perform a splicing operation on the file to be accessed by the client when the data transmission request is the data access request, and send the spliced file to the client, and upload the content address information of the spliced file and the user digital identity to the blockchain.
[0221] In one embodiment, referring to Figure 17 The distributed data transmission device further comprises:
[0222] The length determination module D is configured to determine the number and length of the encrypted files after the splicing operation.
[0223] The object tree establishment module E is configured to establish a file object tree according to the number and length of the encrypted files, so as to query the encrypted files.
[0224] In one embodiment, referring to Figure 18 The distributed data transmission device further comprises:
[0225] The integrity verification module F is configured to perform integrity verification on the spliced file according to the user digital identity.
[0226] Since the principle of solving the problem of the device is similar to the above method, the implementation of the device can refer to the implementation of the method, which will not be repeated here.
[0227] Based on the same principle, the embodiment also discloses a distributed data transmission system. The distributed data transmission system comprises a client, a decentralized storage network and a blockchain, wherein:
[0228] The client is configured to receive a data transmission request of a user, the data transmission request comprising a data upload request and a data access request; and when the data transmission request is the data upload request, encrypt a file to be transmitted according to the data transmission request to generate an encrypted file, and send the encrypted file to a decentralized storage node, and upload content address information corresponding to the encrypted file and a digital identity of the user to the blockchain; and when the data transmission request is the data access request, forward the data access request to the decentralized storage node, receive an encrypted file sent by the decentralized storage node in response to the data access request, decrypt the encrypted file, and upload content address information corresponding to the decrypted encrypted file and the digital identity of the user to the blockchain.
[0229] The decentralized storage network comprises a plurality of decentralized storage nodes; the decentralized storage nodes are configured to receive a data transmission request sent by a client; the data transmission request comprises a data upload request and a data access request; when the data transmission request is the data upload request, the encrypted file sent by the client is subjected to a fragmentation operation, and the fragmented encrypted file is stored in pieces, and the content address information of the fragmented encrypted file and the user digital identity are uploaded to a block chain; and when the data transmission request is the data access request, the file to be accessed by the client is subjected to a merging operation, and the merged file is sent to the client, and the content address information of the merged file and the user digital identity are uploaded to the block chain.
[0230] Since the principle of solving problems of the system is similar to the above method, the implementation of the system can be referred to the implementation of the method, which will not be repeated here.
[0231] The system, device, module or unit illustrated in the above embodiments can be specifically implemented by a computer chip or entity, or by a product with certain functions. A typical implementation device is a computer device, and specifically, the computer device can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0232] In a typical example, the computer device specifically includes a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the method executed by the client as described above when executing the program, or the processor implements the method executed by the server as described above when executing the program.
[0233] Reference is made below to Figure 19 which shows a structural schematic diagram of a computer device suitable for implementing the embodiments of the present application.
[0234] As shown in Figure 19 , the computer device includes a central processing unit (CPU) 601, which can perform various appropriate operations and processes according to programs stored in a read-only memory (ROM) 602 or programs loaded from a storage portion 608 to a random access memory (RAM) 603. In the RAM 603, various programs and data required for system operation are also stored. The CPU 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0235] The following components are connected to the I / O interface 605: an input part 606 including a keyboard, a mouse, etc.; an output part 607 including a display such as a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage part 608 including a hard disk, etc.; and a communication part 609 including a network interface card such as a LAN card, a modem, etc. The communication part 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the I / O interface 605 as necessary. A removable medium 611 such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc. is attached to the drive 610 as necessary, so that a computer program read out therefrom is installed in the storage part 608 as necessary.
[0236] In particular, the processes described above with reference to the flowcharts can be implemented as a computer software program according to embodiments of the present application. For example, embodiments of the present application include a computer program product comprising a computer program tangibly embodied on a machine-readable medium, the computer program comprising program code for executing the methods illustrated by the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via the communication part 609, and / or installed from the removable medium 611.
[0237] Computer readable media includes permanent and non-permanent, removable and non-removable media implemented in any method or technology for storage of information. The information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read only memory (ROM), electrically erasable programmable read only memory (EEPROM), flash memory or other memory technology, compact disc read only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible to a computing device. According to the definition herein, computer readable media does not include transitory media such as modulated data signals and carriers.
[0238] For the convenience of description, the above apparatus is described in various units by function. Of course, the functions of the units can be implemented in the same or more software and / or hardware when implementing the present application.
[0239] The embodiments of the present application are described with reference to the flowchart illustrations and / or block diagrams of the methods, apparatus (systems) and computer program products according to the embodiments of the present application. It is understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams.
[0240] These computer program instructions can also be stored in a computer- readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams.
[0241] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams.
[0242] It should also be noted that the terms "comprising", "comprises", "including", "includes" or any other variation thereof are intended to cover a non-exclusive inclusion, such that a process, method, article or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article or apparatus. An element proceeded by "comprises a... " does not, without more constraints, exclude the existence of additional identical elements in the process, method, article or apparatus that comprises the element.
[0243] Those skilled in the art will appreciate that embodiments of the present application can be devised for a method, a system or a computer program product. Accordingly, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, the present application can take the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, etc.) embodying computer-readable program code thereon for use by or in connection with an instruction execution system, apparatus, or device.
[0244] The application can be described in the general context of computer-executable instructions, such as program modules, being executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform particular tasks or implement particular abstract data types. The application can also be practiced in distributed computing environments where tasks are performed by remote processing devices that are linked through a communications network. In a distributed computing environment, program modules can be located in local and remote computer storage media including memory storage devices.
[0245] Each of the embodiments in the specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the difference from other embodiments. In particular, the system embodiments are described simply because they are basically similar to the method embodiments, and the relevant parts can be referred to the description of the method embodiments.
[0246] The above only describes the embodiments of the application and is not intended to limit the application. The application can have various changes and modifications for those skilled in the art. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of the application shall be included in the scope of the claims of the application.
Claims
1. A distributed data transmission method, characterized in that, include: Receive user data transmission requests, including data upload requests and data access requests; When the data transmission request is the data upload request, the file to be transmitted is encrypted using a symmetric key to generate a encrypted file, and the encrypted file is signed using the user's private key to generate a signature. Based on the user's digital identity, the encrypted file, and the signature, a message for the upload service gateway is generated. By calling the application programming interface of the decentralized file storage, the message is uploaded to the service gateway, and the service gateway parses the message, sends the encrypted file to the decentralized storage node, and uploads the content address information corresponding to the encrypted file and the user's digital identity to the blockchain; When the data transmission request is the data access request, the system receives the file directory query access request submitted by the user, obtains the user's digital identity based on the file directory query access request, and calls the application programming interface of the blockchain storage smart contract through the service gateway to query the file directory list based on the digital identity and display the file directory list on the client. Based on the user's file selection operation in the file directory list, the content address information of the file to be accessed is obtained. Then, through the service gateway, the application programming interface of the blockchain storage smart contract is called to retrieve the encrypted file from the decentralized storage node, decrypt the encrypted file, and upload the content address information of the decrypted encrypted file and the user's digital identity to the blockchain.
2. The distributed data transmission method according to claim 1, characterized in that, Also includes: Transaction rate limiting and circuit breaker control are implemented based on the number of data transmission requests.
3. A distributed data transmission method, characterized in that, include: Receive data transmission requests sent by the client; the data transmission requests include data upload requests and data access requests; When the data transmission request is the data upload request, the encrypted file sent by the client is fragmented, the fragmented encrypted file is stored in fragments, and the content address information and user digital identity of the fragmented encrypted file are uploaded to the blockchain. When the data transmission request is a data access request, the file that the client wants to access is fragmented. The integrity of the fragmented file is verified based on the user's digital identity. If the integrity verification is successful, the public key corresponding to the fragmented file is obtained, and the fragmented file is signed and verified using a preset signature verification function based on the public key. If the signature verification is successful, the fragmented file is decrypted based on the symmetric key to generate a plaintext file, which is then sent to the client. The content address information of the fragmented file and the user's digital identity are uploaded to the blockchain.
4. The distributed data transmission method according to claim 3, characterized in that, Also includes: Determine the number and length of the encrypted files after the fragmentation operation; A file object tree is built based on the number and length of the encrypted files in order to query the encrypted files.
5. A distributed data transmission device, characterized in that, include: The first receiving module for transmission requests is used to receive data transmission requests from users, including data upload requests and data access requests. The first data upload module is used to encrypt the file to be transmitted using a symmetric key to generate a encrypted file when the data transmission request is the data upload request, and to sign the encrypted file using the user's private key to generate a signature, and to generate a message for the upload service gateway based on the user's digital identity, the encrypted file and the signature. By calling the application programming interface of the decentralized file storage, the message is uploaded to the service gateway, and the service gateway parses the message, sends the encrypted file to the decentralized storage node, and uploads the content address information corresponding to the encrypted file and the user's digital identity to the blockchain; The first data access module is used to receive a file directory query access request submitted by the user when the data transmission request is the data access request, obtain the user's digital identity according to the file directory query access request, call the application programming interface of the blockchain storage smart contract through the service gateway, query the file directory list according to the digital identity, and display the file directory list on the client. Based on the user's file selection operation in the file directory list, the content address information of the file to be accessed is obtained. Then, through the service gateway, the application programming interface of the blockchain storage smart contract is called to retrieve the encrypted file from the decentralized storage node, decrypt the encrypted file, and upload the content address information of the decrypted encrypted file and the user's digital identity to the blockchain.
6. A distributed data transmission device, characterized in that, include: The second receiving module for receiving data transmission requests is used to receive data transmission requests sent by the client. The data transmission request includes a data upload request and a data access request; The second data upload module is used to perform a fragmentation operation on the encrypted file sent by the client when the data transmission request is the data upload request, and to store the fragmented encrypted file in fragments, as well as to upload the content address information and user digital identity of the fragmented encrypted file to the blockchain. The second data access module is used to perform a file merging operation on the file that the client wants to access when the data transmission request is the data access request. It performs integrity verification on the merged file according to the user's digital identity. If the integrity verification is successful, it obtains the public key corresponding to the merged file and performs signature verification on the merged file according to the public key using a preset signature verification function. If the signature verification is successful, it decrypts the merged file according to the symmetric key to generate a plaintext file and sends the plaintext file to the client. It also uploads the content address information of the merged file and the user's digital identity to the blockchain.
7. A distributed data transmission system, characterized in that, This includes clients, decentralized storage networks, and blockchain, among which: The client is used to receive data transmission requests from users, including data upload requests and data access requests. When the data transmission request is a data upload request, the client encrypts the file to be transmitted using a symmetric key to generate a encrypted file, signs the encrypted file using the user's private key to generate a signature, and generates an upload message to the service gateway based on the user's digital identity, the encrypted file, and the signature. The client then uploads the message to the service gateway by calling the application programming interface of the decentralized file storage, and the service gateway parses the message, sends the encrypted file to the decentralized storage node, and uploads the content address information corresponding to the encrypted file and the user's digital identity to the blockchain. When the data transmission request is a data access request... When a user submits a file directory query access request, the system obtains the user's digital identity based on the request and calls the application programming interface of the blockchain storage smart contract through the service gateway to query the file directory list based on the digital identity and display the file directory list on the client. Based on the user's file selection operation in the file directory list, the system obtains the content address information of the file to be accessed and calls the application programming interface of the blockchain storage smart contract through the service gateway to obtain the encrypted file from the decentralized storage node, decrypt the encrypted file, and upload the content address information of the decrypted encrypted file and the user's digital identity to the blockchain. The decentralized storage network includes multiple decentralized storage nodes. These nodes receive data transmission requests from clients. These requests include data upload requests and data access requests. When the data transmission request is a data upload request, the encrypted file sent by the client is fragmented, and the fragmented encrypted file is stored in fragments. The content address information and user digital identity of the fragmented encrypted file are uploaded to the blockchain. When the data transmission request is a data access request, the file the client wants to access is merged. The integrity of the merged file is verified based on the user digital identity. If the integrity verification passes, the public key corresponding to the merged file is obtained, and a preset signature verification function is used to sign and verify the merged file based on the public key. If the signature verification passes, the merged file is decrypted using a symmetric key to generate a plaintext file, which is then sent to the client. The content address information and user digital identity of the merged file are also uploaded to the blockchain.
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the distributed data transmission method according to any one of claims 1 to 4.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the steps of the distributed data transmission method according to any one of claims 1 to 4.
Citation Information
Patent Citations
File sharing method and system based on block chain, electronic equipment and storage medium
CN114650144A
Electric energy data transmission method and device, storage medium and computer equipment
CN114697077A