A blockchain-based cloud collaboration system
Through a blockchain-based cloud collaboration system, the encryption processing of public and private keys is used to solve the problem of file leakage and tampering in online collaboration, and the security and privacy of files are guaranteed.
Patent Information
- Application Number
- CN202211350309.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-31
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2042-10-31
AI Technical Summary
In the process of document reading, editing, saving and sharing of traditional online collaborative products, there are problems of file leakage, destruction or tampering, and the security and reliability of corporate documents cannot be guaranteed.
The blockchain-based cloud collaboration system is adopted to generate public and private keys through the blockchain module, and combine user modules, storage modules and encryption modules to realize the encryption and decryption of files to ensure the security and privacy of files.
It realizes the encryption processing of files, prevents browsing and tampering by non-related personnel, and ensures the privacy and security of corporate documents.
Smart Images

Figure CN115694808B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cloud collaboration, and particularly to a cloud collaboration system based on blockchain. Background Art
[0002] The state continuously promotes the innovation of information technology and accelerates the digitalization process of the economic society. With the continuous improvement of the digitalization level of enterprises and institutions, online collaboration has become increasingly popular and provides better collaboration and portability in the digital age. However, during the use process, there are a large number of operations such as reading, editing, saving, and sharing. In traditional online collaboration products, it is very easy to occur the leakage, damage, or tampering of enterprise files in these operation steps, and the security and reliability of enterprise files cannot be guaranteed. The occurrence of these situations will, at best, slow down the progress speed of the company's business, and at worst, lead to the leakage of company secrets. Therefore, the technical personnel in this field have provided a cloud collaboration system based on blockchain to solve the problems raised in the above background art. Summary of the Invention
[0003] To solve the above technical problems, the present invention provides a cloud collaboration system based on blockchain, including a blockchain module, a user module, a storage module, and an encryption module;
[0004] The blockchain module includes an algorithm unit, a public key generation unit, and a private key generation unit, which are used to generate a public key and a private key. The public key generation unit generates an article public key according to the first user identity identifier and the article identifier. The private key generation unit generates a private key according to the first user identity identifier, the article identifier, and the task identifier. The algorithm unit is called by the public key generation unit and the private key generation unit to perform a hash operation;
[0005] The user module includes an account verification unit, a decryption unit, and an editing unit, which are used to verify user information and corresponding operation permissions, and grant the user the editing ability after verification. After the user logs in, the account verification unit detects the user name, login password, and operation task of the user account, judges that the user account logs in correctly, rejects the login if the account is incorrect, and proceeds to the next step if it is correct. The decryption unit obtains the public key and the private key corresponding to the operation task from the storage module, and uses the public key and the private key to decrypt the private key encrypted file into a public key encrypted file in sequence, then decrypts the public key encrypted file to obtain a private key signed file, and finally decrypts the private key signed file to obtain a marked file that can be edited for operations. The editing unit can perform relevant editing operations on the marked file decrypted by the decryption unit;
[0006] The storage module includes storage units and transmission units, which are used to store and transfer data generated by other modules. The transmission unit receives the public key and private key generated by the blockchain module and sends them to the storage unit, receives the private key encrypted file generated by the private key encryption unit of the encryption module, and sends it to the storage unit, accepts the requirements of the user module and the blockchain module, obtains the user account login information and the public key and private key from the storage module and sends them. The storage unit accepts the public key and private key sent by the transportation unit and stores them, accepts the requirements of the transmission unit, sends the user account login information and the public key and private key, and stores the user's account login information and operation tasks;
[0007] The encryption module includes a marking unit, a signature unit, a public key encryption unit, and a private key encryption unit, which are used to encrypt articles. The marking unit can mark the articles created by the first user to generate a marking file. The signature unit obtains the private key from the storage module, signs the marked article to generate a private key signature file. The public key encryption unit processes the private key signature file with the public key to generate a public key encrypted file. The private key encryption unit encrypts the public key encrypted file with the private key to generate a private key encrypted file.
[0008] Preferably, the editing unit can create articles or assign tasks to invite the second user.
[0009] The technical effects and advantages of the present invention:
[0010] The present invention adopts blockchain technology, which can realize blockchain encryption of files created by users online, prevent unauthorized personnel from browsing and tampering with files, and ensure the privacy and security of enterprise files. Description of the Drawings
[0011] Figure 1 is a schematic diagram of the system structure of the present application;
[0012] Figure 2 is a schematic diagram of the process structure of the present application; Detailed Description of the Invention
[0013] The present invention will be further described in detail below with reference to the drawings and specific embodiments. The embodiments of the present invention are given for the purpose of illustration and description, and are not exhaustive or limit the present invention to the disclosed form. Many modifications and variations are obvious to those of ordinary skill in the art. The embodiments are selected and described to better illustrate the principles and practical applications of the present invention, and enable those of ordinary skill in the art to understand the present invention and thus design various embodiments with various modifications suitable for specific purposes.
[0014] Please refer to Figures 1-2, in this embodiment, a cloud collaboration system based on blockchain is provided, including a blockchain module, a user module, a storage module, and an encryption module;
[0015] The blockchain module includes an algorithm unit, a public key generation unit, and a private key generation unit, which are used to generate a public key and a private key. The public key generation unit generates an article public key according to the first user identity identifier and the article identifier. The private key generation unit generates a private key according to the first user identity identifier, the article identifier, and the task identifier. The algorithm unit is called by the public key generation unit and the private key generation unit to perform a hash operation;
[0016] The user module includes an account verification unit, a decryption unit, and an editing unit, which are used to verify user information and corresponding operation permissions, and grant the user the editing ability after verification. After the user logs in, the account verification unit detects the user name, login password, and operation task of the user account, judges that the user account logs in correctly, rejects the login if the account is incorrect, and proceeds to the next step if it is correct. The decryption unit obtains the public key and private key corresponding to the operation task from the storage module, and uses the public key and private key to decrypt the private key encrypted file into a public key encrypted file in sequence, then decrypts the public key encrypted file to obtain a private key signature file, and finally decrypts the private key signature file to obtain a mark file that can be edited for operation. The editing unit can perform relevant editing operations on the mark file decrypted by the decryption unit, and can also create an article or assign tasks to invite a second user;
[0017] The storage module includes a storage unit and a transmission unit, which are used to store and transfer data generated by other modules. The transmission unit receives the public key and private key generated by the blockchain module and sends them to the storage unit, receives the private key encrypted file generated by the private key encryption unit of the encryption module, and sends it to the storage unit, accepts the requirements of the user module and the blockchain module, obtains the user account login information and the public key and private key from the storage module and sends them. The storage unit accepts the public key and private key sent by the transportation unit and stores them, accepts the requirements of the transmission unit, sends the user account login information and the public key and private key, and stores the user's account login information and operation tasks;
[0018] The encryption module includes a marking unit, a signature unit, a public key encryption unit, and a private key encryption unit, which are used to encrypt the article. The marking unit can mark the article created by the first user to generate a mark file. The signature unit obtains the private key from the storage module and signs the marked article to generate a private key signature file. The public key encryption unit processes the private key signature file with the public key to generate a public key encrypted file. The private key encryption unit encrypts the public key encrypted file with the private key to generate a private key encrypted file.
[0019] The working principle of the present invention is:
[0020] The first user creates an article in the user module. After the creation is completed on the article creation page, the first user invites the second user and assigns the task to the specified second user.
[0021] The public key generation unit calls the algorithm unit to perform a hash operation to generate the article public key based on the first user identity identifier and the article identifier. The private key generation unit calls the algorithm unit to perform a hash operation to generate the private key based on the first user identity identifier, the article identifier, and the task identifier. Finally, the public key and the private key are saved in the storage module.
[0022] According to the article created by the first user module and the tasks assigned in the article, the article is encrypted. The marking unit can perform marking processing on the article created by the first user to generate a marking file. Here, the marking can include but is not limited to: watermark, user identifier, etc. The signature unit obtains the private key from the storage module and performs signature processing on the above marking file using the private key to generate a private key signature file. Here, the assigned tasks can include but are not limited to: editing paragraphs, deleting paragraphs, inserting pictures, inserting charts, inserting tables, inserting text, inserting paragraphs, etc.
[0023] The public key encryption unit encrypts the above private key signature file according to the public key of the article created by the first user to generate a public key encryption file corresponding to the above signature file. Finally, the private key encryption unit encrypts the public key encryption file generated by the public key encryption unit once again using the private key to generate a private key encryption file, and sends the private key encryption file to the storage module for storage.
[0024] The second user logs in to the account in the user module. The account verification unit detects the login information of the user account, including the user name, login password, and operation task. First, it determines whether the login password of the user account is consistent with the stored corresponding user name and password. After the account verification unit verifies that the account is correct, the decryption unit obtains the public key and private key corresponding to the operation task from the storage module, and then sends an application according to the private key to obtain the private key encryption file from the storage module and decrypt it to obtain the public key encryption file.
[0025] The decryption unit decrypts the public key encryption file using the public key it has. After successful decryption, it obtains the private key signature file and the reading permission of the file. The decryption unit uses its own private key to decrypt the private key signature file. After successful decryption, it obtains the marking file and the relevant operation permission of the file.
[0026] The second user operates on the article in the user module according to the tasks assigned by the first user. After the operation is completed, the article is sent to the encryption module. First, the signature unit encrypts the article on which the second user has completed the task according to the pre-set private key of the first user to generate a private key signature file, and the public key encryption unit.
[0027] According to the public key of the first user, the above-mentioned private key signature file is encrypted to generate a public key encrypted file corresponding to the above-mentioned signature file. The private key encryption unit encrypts the public key encrypted file generated by the public key encryption unit again according to the private key of the first user to generate a private key encrypted file, and sends the private key encrypted file to the storage module for storage.
[0028] Take the collaborative writing of a "September Talent Market Data Analysis Report" as an example:
[0029] (1) The first user logs in to his account and creates a new "September Talent Market Data Analysis Report" on the user side, and assigns the second user the task of uploading the September data analysis chart. Based on the task assigned by the first user to the second user to upload the September data analysis chart, the system grants the second user account the authority to obtain the relevant key according to the task;
[0030] (2) In the blockchain module of the system, the public key generation unit calls the algorithm unit to perform a hash operation to generate a public key of the article based on the identity identifier of the first user and the article identifier of the "September Talent Market Data Analysis Report". The private key generation unit calls the algorithm unit to perform a hash operation to generate a private key based on the identity identifier of the first user, the article identifier of the "September Talent Market Data Analysis Report" and the task identifier of the second user, and finally stores the two keys in the storage module;
[0031] (3) The encryption module in the system marks the "September Talent Market Data Analysis Report" created by the first user to generate a corresponding mark file, then signs the mark file using the private key to generate a private key signature file, then encrypts the signature file using the article public key of the "September Talent Market Data Analysis Report" to generate a public key encrypted file, and finally encrypts the public key encrypted file again using the private key to generate a private key encrypted file. The generated private key encrypted file is stored in the storage module of the system;
[0032] (4) The second user logs into the system, and the system will detect the second user's account information. First, confirm whether the name and password of the second user account are consistent with those stored in the system. After the second user account is verified, the corresponding key is obtained from the storage module according to its permission to obtain the key, and then the private key is used to obtain the private key encrypted file from the storage module, and the private key encrypted file is decrypted to obtain the public key encrypted file. The public key is then used to decrypt the public key encrypted file, and the private key signature file and the file reading permission are obtained after decryption. Finally, the decryption unit uses the private key to decrypt the private key signature file, and the second user obtains the marked "September Talent Market Data Analysis Report" and the permission to upload data analysis charts;
[0033] (5) The second user uploads the September data analysis chart to the "September Talent Market Data Analysis Report" in the user module and saves the completed "September Talent Market Data Analysis Report" of the upload task.
[0034] (6) The system sends the "September Talent Market Data Analysis Report" saved by the second user to the encryption module. The encryption module first calls the private key of the first user to encrypt the above "September Talent Market Data Analysis Report" to generate a private key signature file, then uses the public key of the first user to encrypt the generated signature file to generate a public key encrypted file, and finally calls the private key of the first user again to encrypt the public key encrypted file to generate a private key encrypted file and stores it in the storage module.
[0035] Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by those of ordinary skill in the art and related fields without creative efforts shall fall within the scope of protection of the present invention. The structures, devices, and operation methods not specifically described and explained in the present invention, unless otherwise specified and limited, are implemented according to the conventional means in the art.
Claims
1. A cloud collaboration system based on blockchain, characterized in that It includes a blockchain module, a user module, a storage module, and an encryption module; The blockchain module includes an algorithm unit, a public key generation unit, and a private key generation unit, which are used to generate a public key and a private key. The public key generation unit generates an article public key according to the first user identity identifier and the article identifier. The private key generation unit generates a private key according to the first user identity identifier, the article identifier, and the task identifier. The algorithm unit is called by the public key generation unit and the private key generation unit to perform a hashing operation; The user module includes an account verification unit, a decryption unit, and an editing unit, which are used to verify user information and corresponding operation permissions. After verification, the user is given the editing ability. After the user logs in, the account verification unit detects the user name, login password, and operation task of the user account, determines whether the user account logs in correctly, rejects the login if the account is incorrect, and proceeds to the next step if it is correct. The decryption unit obtains the public key and private key corresponding to the operation task from the storage module, and uses the public key and private key to decrypt the private key encrypted file into a public key encrypted file in sequence, then decrypts the public key encrypted file to obtain a private key signature file, and finally decrypts the private key signature file to obtain a marker file for editable operations. The editing unit can perform relevant editing operations on the marker file decrypted by the decryption unit; the editing unit can create an article or assign tasks to invite a second user; The storage module includes a storage unit and a transmission unit, which are used to store and transfer data generated by other modules. The transmission unit receives the public key and private key generated by the blockchain module and sends them to the storage unit, receives the private key encrypted file generated by the private key encryption unit of the encryption module, and sends it to the storage unit, accepts the requirements of the user module and the blockchain module, obtains the user account login information and the public key and private key from the storage module and sends them. The storage unit accepts the public key and private key sent by the transport unit and stores them, accepts the requirements of the transmission unit, sends the user account login information and the public key and private key, and stores the user's account login information and operation tasks; The encryption module includes a marking unit, a signature unit, a public key encryption unit, and a private key encryption unit, which are used to encrypt the article. The marking unit can mark the article created by the first user to generate a marker file. The signature unit obtains the private key from the storage module and signs the marked article to generate a private key signature file. The public key encryption unit processes the private key signature file with the public key to generate a public key encrypted file. The private key encryption unit encrypts the public key encrypted file with the private key to generate a private key encrypted file.
Citation Information
Patent Citations
Multi-person participation BIM drawing copyright protection system and method based on block chain
CN111581605A