Blockchain data privacy protection system and protection method thereof
By setting privacy risk levels and virtual verification nodes in the blockchain, the problem of user data privacy and security is solved, achieving efficient data privacy protection and reliable data transmission.
Patent Information
- Application Number
- CN202310457114.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-26
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2043-04-26
AI Technical Summary
Existing blockchain technologies pose risks to user data privacy and security, especially when node uncertainty exists, making it difficult to effectively protect users' private data.
By setting multiple privacy risk levels, the privacy risk classification module marks the data content, establishes virtual verification nodes, encrypts data communication and storage, generates secure privacy keys, and verifies and encrypts data transaction requests.
It achieves the goal of protecting private data without affecting the normal reading and interaction of other commonly used data, reducing system computing power waste and response speed reduction, and improving users' reliable execution rights over highly private data.
Smart Images

Figure CN116340428B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of data privacy security, and particularly relates to a blockchain data privacy protection system and a protection method thereof. BACKGROUND
[0002] The cross-chain technology is a widely used Internet technology at present. The cross-chain technology can effectively improve the security of data by using a chain type block storage mode. When the cross-chain technology is used, as long as a server in a chain type multi-node is in a normal working state, the security of the entire blockchain can be ensured.
[0003] The blockchain implementation manner in the prior art has a certain security risk for the data content of a user due to the uncertainty of nodes. Therefore, for some data content related to user privacy security, the chain type storage mode needs to be further optimized to improve the user experience. SUMMARY
[0004] The present application aims to provide a blockchain data privacy protection system and a protection method thereof to solve the problems in the background technology.
[0005] To achieve the above-mentioned purpose, the present application provides the following technical solutions.
[0006] A blockchain data privacy protection system comprises:
[0007] A privacy risk demarcation module is configured to mark the data content based on a plurality of preset privacy risk levels. Different privacy risk levels correspond to different secure privacy keys and corresponding privacy verification nodes. The secure privacy keys are used for data communication and data storage encryption between the privacy verification nodes.
[0008] An action response authentication module is configured to obtain and respond to a data transaction request, obtain a privacy risk level corresponding to a privacy mark of data content corresponding to the request, establish a verification communication channel according to the privacy risk level and a plurality of privacy verification nodes, obtain and judge the secure privacy key, and generate a node judgment result.
[0009] A virtual object authentication module is configured to establish a preset number of virtual verification nodes and virtual privacy verification nodes corresponding to the virtual verification nodes, respond to the data transaction request, and verify the request through the virtual privacy verification nodes. The virtual object authentication module is configured to obtain a virtual verification result from the virtual verification nodes.
[0010] The privacy data acquisition module is configured to respond based on the node judgment result and the virtual verification result, and if both represent that the verification is passed, acquire corresponding data content based on the data transaction request, establish a communication channel to exchange a secure privacy key, and forward the secure privacy key through the communication channel.
[0011] As a further scheme of the present application, the virtual object authentication module comprises:
[0012] A virtual device chain establishment unit is configured to generate a virtual object establishment request and output the request when a user sets a privacy mark for data content, receive a device link request from the user, establish a communication channel with the user device and acquire corresponding device hardware information, and set the user device as a virtual verification node.
[0013] A virtual node establishment unit is configured to establish a secure privacy key based on the device hardware information, establish a virtual privacy verification node based on the user device, and share the secure privacy key with the virtual verification node.
[0014] A node feedback judgment unit is configured to acquire a virtual verification result of the virtual privacy verification node for the data transaction request, and the virtual verification result is used to represent feedback of the data content belonging user for the data transaction request.
[0015] As a further scheme of the present application, a virtual node module is further included, and the virtual node module specifically comprises:
[0016] A node link verification unit is configured to acquire the corresponding secure privacy key, decode the secure privacy key, and compare the secure privacy key with the device hardware information, and if the comparison result represents consistency, establish a data communication channel between nodes.
[0017] A request privacy verification unit is configured to acquire the privacy risk level of the data content corresponding to the data transaction request, output the data transaction request and the privacy risk level through the user device, receive feedback from the user to generate a virtual verification result and forward the virtual verification result, and the data transaction request comprises request object information and requested data content information.
[0018] As a further scheme of the present application, a key generation unit is further included.
[0019] The key generation unit is configured to acquire a machine hardware code in the device hardware information, use the machine hardware code as an initial key, encrypt the device hardware information based on the initial key, generate a secure privacy key, and in the secure privacy key sharing process, the initial key is emptied and not used as a shared data object.
[0020] As a further scheme of the present application: when the data content is provided with a privacy mark, the virtual verification node is a non-substitutable node, and the virtual verification result is the highest basis for judgment in response to the data transaction request.
[0021] Embodiments of the present application aim to provide a blockchain data privacy protection method, comprising the steps of:
[0022] The data content is marked with privacy based on a plurality of preset privacy risk levels, different privacy risk levels correspond to different secure privacy keys and corresponding privacy verification nodes, and the secure privacy keys are used for data communication and data storage encryption between the privacy verification nodes;
[0023] A data transaction request is obtained and responded to, a privacy risk level corresponding to a privacy mark of the requested data content is obtained, a verification communication channel is established between the privacy risk level and a plurality of the privacy verification nodes, the secure privacy key is obtained and judged, and a node judgment result is generated;
[0024] A preset number of virtual verification nodes and virtual privacy verification nodes corresponding to the virtual verification nodes are established, the data transaction request is responded to and verified through the virtual privacy verification nodes, and a virtual verification result from the virtual verification nodes is obtained;
[0025] The node judgment result and the virtual verification result are responded to, if both represent verification pass, the corresponding data content is obtained based on the data transaction request, a communication channel is established to exchange the secure privacy key, and the secure privacy key is forwarded through the communication channel.
[0026] As a further scheme of the present application: the step of establishing a preset number of virtual verification nodes and virtual privacy verification nodes corresponding to the virtual verification nodes, responding to the data transaction request and verifying the request through the virtual privacy verification nodes, and obtaining a virtual verification result from the virtual verification nodes specifically comprises:
[0027] When a user sets a privacy mark on data content, a virtual object establishment request is generated and output, a device link request from the user is received, a communication channel with the user device is established and corresponding device hardware information is obtained, and the user device is set as a virtual verification node;
[0028] A secure privacy key is established based on the device hardware information, a virtual privacy verification node is established based on the user device, and the secure privacy key is shared with the virtual verification node;
[0029] Obtaining a virtual verification result of the virtual privacy verification node on the data transaction request, the virtual verification result being used to represent feedback of a data content attribution user on the data transaction request.
[0030] As a further scheme of the present application:
[0031] Obtaining the corresponding security privacy key, decoding the security privacy key, and comparing the security privacy key with the device hardware information, if the comparison result represents consistency, establishing a data communication channel between nodes;
[0032] Obtaining the privacy risk level of the data content corresponding to the data transaction request, outputting the data transaction request and the privacy risk level through a user device, receiving feedback from the user to generate a virtual verification result and forwarding, the data transaction request including request object information and requested data content information.
[0033] As a further scheme of the present application
[0034] Obtaining a machine hardware code in the device hardware information, taking the machine hardware code as an initial key, encrypting the device hardware information based on the initial key, generating a security privacy key, and in the security privacy key sharing process, the initial key is emptied and not used as a shared data object.
[0035] As a further scheme of the present application:
[0036] When the data content is provided with a privacy mark, the virtual verification node is a non-replaceable node, and the virtual verification result is the highest judgment basis for responding to the data transaction request.
[0037] Compared with the prior art, the present application has the beneficial effects that: by setting the privacy risk level of the data content, the user can divide the risk of different data content based on the actual privacy protection demand, can protect the privacy data to a certain extent without affecting the normal reading interaction of other commonly used data of the user, reduce the waste of system computing power and unnecessary response speed reduction of privacy protection, and through the establishment of a pseudo node stably controlled by the user to participate in the authentication process of data content transmission in the block chain, the user can have more reliable execution right for high privacy data content. BRIEF DESCRIPTION OF DRAWINGS
[0038] Figure 1 It is a component block diagram of a blockchain data privacy protection system.
[0039] Figure 2 It is a component block diagram of a virtual object authentication module in a blockchain data privacy protection system.
[0040] Figure 3 A block diagram of a virtual node module in a blockchain data privacy protection system.
[0041] Figure 4 A flowchart of a blockchain data privacy protection method. DETAILED DESCRIPTION
[0042] In order to make the purposes, technical solutions and advantages of the present application clearer, the present application is further described in detail below in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application.
[0043] The specific implementation of the present application is described in detail below in combination with specific embodiments.
[0044] As Figure 1 The blockchain data privacy protection system provided by an embodiment of the present application comprises:
[0045] The privacy risk demarcation module 100 is configured to mark the data content based on a plurality of preset privacy risk levels, wherein different privacy risk levels correspond to different secure privacy keys and corresponding privacy verification nodes, and the secure privacy keys are used for data communication and data storage encryption between the privacy verification nodes.
[0046] The action response authentication module 300 is configured to obtain and respond to a data transaction request, obtain a privacy risk level corresponding to a privacy mark of data content corresponding to the request, establish a verification communication channel according to the privacy risk level and a plurality of privacy verification nodes, obtain and judge the secure privacy key, and generate a node judgment result.
[0047] The virtual object authentication module 500 is configured to establish a preset number of virtual verification nodes and virtual privacy verification nodes corresponding to the virtual verification nodes, respond to the data transaction request and perform request verification through the virtual privacy verification nodes, and obtain a virtual verification result from the virtual verification nodes.
[0048] The privacy data acquisition module 700 is configured to respond based on the node judgment result and the virtual verification result, and if both represent that the verification is passed, acquire corresponding data content based on the data transaction request, establish a communication channel to exchange a secure privacy key, and forward the secure privacy key through the communication channel.
[0049] In this embodiment, a blockchain data privacy protection system is given. By setting the privacy risk level of data content, users can divide different data content based on their actual privacy protection needs. The system can protect privacy data to a certain extent without affecting the normal reading and interaction of other commonly used data of the user, reduce the waste of system computing power and unnecessary reduction of response speed, and enable users to have more reliable execution rights for high privacy data content. In specific use, the user sets multiple different privacy risk levels according to the privacy protection needs of the data. When the data is requested by others or actively forwarded to others, it will be verified by different virtual verification nodes in the blockchain based on the privacy risk level. In the verification process, the security of the request object (or forwarding object) is judged to determine whether the data can be safely given. For data content with a privacy risk level, a virtual verification node is also provided. The node is constructed by the user's device and added to the blockchain. It is used to make a decision on whether to give feedback to the data transaction request based on the security judgment of the request object or forwarding object and the data content that needs to be operated in the verification process. This can effectively reduce the leakage of privacy data caused by malicious attacks on data content devices.
[0050] As shown in Figure 2 As another preferred embodiment of the present application, the virtual object authentication module 500 includes:
[0051] The virtual device chain unit 501 is used to generate a virtual object establishment request and output when the user sets a privacy mark for the data content, receive a device link request from the user, establish a communication channel with the user device and obtain the corresponding device hardware information, and set the user device as a virtual verification node.
[0052] The virtual node establishment unit 502 is used to establish a secure privacy key based on the device hardware information, establish a virtual privacy verification node based on the user device, and share the secure privacy key with the virtual verification node.
[0053] The node feedback judgment unit 503 is used to obtain the virtual verification result of the virtual privacy verification node for the data transaction request. The virtual verification result is used to represent the feedback of the data content belonging user to the data transaction request.
[0054] In this embodiment, the virtual object authentication module 500 is further described. When performing the corresponding program steps, it mainly includes three aspects. First, the determination of the virtual verification node. When the user marks the data content as private, it indicates that the user has the demand for data privacy and security protection. At this time, the device information required by the user is obtained as the establishment of the virtual verification node to perform communication binding. Second, the establishment and generation of the security privacy key in this environment and the user device (i.e. the virtual verification node), mainly through the user's device hardware information for encryption processing, so as to avoid the exchange process of the key in use, and to prevent the leakage of the key to a certain extent. Third, the forwarding of the data transaction request information and the feedback information from the privacy verification node, that is, the feedback judgment from the user.
[0055] As shown in Figure 3 another preferred embodiment of the present application also includes a virtual node module 900, which specifically includes:
[0056] The node link verification unit 901 is used to obtain the corresponding security privacy key, decode the security privacy key, and compare it with the device hardware information. If the comparison result is consistent, a data communication channel between nodes is established.
[0057] The request privacy verification unit 902 is used to obtain the privacy risk level of the data content corresponding to the data transaction request, output the data transaction request and the privacy risk level through the user device, receive feedback from the user to generate a virtual verification result and forward it. The data transaction request includes request object information and requested data content information.
[0058] In this embodiment, the virtual node module corresponds to the virtual object authentication module 500, that is, the user's device, which is the virtual verification node proposed in the virtual object authentication module 500. Its main functions include the verification process of the security privacy key when connecting the data channel in the request process, and after verification, showing the user's demand and obtaining the user's judgment operation to forward, completing the user's privacy authentication process.
[0059] As another preferred embodiment of the present application, it also includes a key generation unit;
[0060] The key generation unit is used to obtain the machine hardware code in the device hardware information, take the machine hardware code as the initial key, encrypt the device hardware information based on the initial key, generate the security privacy key, and clear the initial key as shared data object in the sharing process of the security privacy key.
[0061] Further, when the data content is marked with a privacy mark, the virtual verification node is a non-substitutable node, and the virtual verification result is the highest basis for judging the response to the data transaction request.
[0062] In the embodiment, a key generation unit is supplemented, and the generation process and method of the secure privacy key are illustrated by the key generation unit. In this way, the bidirectional transmission and storage of the key can be avoided, and the data security can be effectively improved. Meanwhile, the authority of the virtual verification node is supplemented, and the virtual verification result of the virtual verification node is irreplaceable in the response process of the data transaction request of the system.
[0063] As shown in Figure 4 The application further provides a blockchain data privacy protection method, which comprises the following steps:
[0064] S200, privacy marking is performed on data content based on a plurality of preset privacy risk levels, different privacy risk levels correspond to different secure privacy keys and corresponding privacy verification nodes, and the secure privacy key is used for data communication and data storage encryption between the privacy verification nodes.
[0065] S400, a data transaction request is obtained and responded to, a privacy risk level corresponding to a privacy mark of corresponding data content of the request is obtained, a verification communication channel is established between the privacy risk level and a plurality of the privacy verification nodes, the secure privacy key is obtained and judged, and a node judgment result is generated.
[0066] S600, a preset number of virtual verification nodes and virtual privacy verification nodes corresponding to the virtual verification nodes are established, the data transaction request is responded to and verified through the virtual privacy verification nodes, and a virtual verification result from the virtual verification nodes is obtained.
[0067] S800, the node judgment result and the virtual verification result are responded to, if both represent verification passing, corresponding data content is obtained based on the data transaction request, a communication channel is established to exchange a secure privacy key, and the secure privacy key is forwarded through the communication channel.
[0068] As another preferred embodiment of the application, the step of establishing a preset number of virtual verification nodes and virtual privacy verification nodes corresponding to the virtual verification nodes, responding to the data transaction request, and verifying the request through the virtual privacy verification nodes to obtain a virtual verification result from the virtual verification nodes specifically comprises:
[0069] When a user sets a privacy mark on data content, a virtual object establishment request is generated and output, a device link request is received from the user, a communication channel is established with the user device and corresponding device hardware information is obtained, and the user device is set as a virtual verification node.
[0070] A secure privacy key is established based on the device hardware information, a virtual privacy verification node is established based on the user device, and the secure privacy key is shared with the virtual verification node.
[0071] The virtual privacy verification node obtains the virtual verification result of the data transaction request, which is used to represent the feedback of the data content belonging user to the data transaction request.
[0072] As another preferred embodiment of the present application, the steps further include:
[0073] The corresponding secure privacy key is obtained, decoded, and compared with the device hardware information. If the comparison result represents consistency, a data communication channel between nodes is established.
[0074] The privacy risk level of the data content corresponding to the data transaction request is obtained, the data transaction request and the privacy risk level are output through the user device, and the feedback from the user is received to generate a virtual verification result and forward it. The data transaction request includes request object information and requested data content information.
[0075] As another preferred embodiment of the present application, the steps further include:
[0076] The machine hardware code in the device hardware information is obtained, the machine hardware code is used as an initial key, the device hardware information is encrypted based on the initial key, a secure privacy key is generated, and the initial key is emptied and not used as shared data object during the sharing process of the secure privacy key.
[0077] As another preferred embodiment of the present application, the steps further include:
[0078] When the data content is set with a privacy mark, the virtual verification node is a non-replaceable node, and the virtual verification result is the highest judgment basis for responding to the data transaction request.
[0079] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The program can be stored in a non-volatile computer readable storage medium, and when the program is executed, the processes of the above-mentioned embodiments of the methods can be included. Any reference to memory, storage, databases, or other media in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration but not limitation, RAM is available in many forms such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), Synchlink DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct Rambus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0080] Other embodiments of the present disclosure will be apparent to those skilled in the art with the accomplishment of the present disclosure as reflected in the specification and embodiments. The present application is intended to cover any variations, uses, or adaptive changes of the present disclosure following the general principles of the present disclosure and including common knowledge or conventional technical means in the art not disclosed in the present disclosure. The specification and embodiments are only regarded as exemplary, and the true scope and spirit of the present disclosure are indicated by the claims.
[0081] It should be understood that the present disclosure is not limited to the precise structures described above and shown in the drawings, and various modifications and changes can be made without departing from the scope thereof. The scope of the present disclosure is limited only by the appended claims.
Claims
1. A blockchain data privacy protection system, characterized in that, The application relates to a privacy risk grading module for privacy marking of data content based on preset privacy risk grades, wherein different privacy risk grades correspond to different secure privacy keys and corresponding privacy verification nodes, the secure privacy keys are used for data communication and data storage encryption between the privacy verification nodes, an action response authentication module is used for obtaining and responding to a data transaction request, obtaining a privacy risk grade corresponding to a privacy mark of data content corresponding to the request, establishing a verification communication channel according to the privacy risk grade and a plurality of the privacy verification nodes, obtaining and judging the secure privacy key, and generating a node judgment result, a virtual object authentication module is used for establishing a preset number of virtual verification nodes and virtual privacy verification nodes corresponding to the virtual verification nodes, responding to the data transaction request and verifying the request through the virtual privacy verification nodes, and obtaining a virtual verification result from the virtual verification nodes, a privacy data obtaining module is used for responding based on the node judgment result and the virtual verification result, if both represent verification passing, corresponding data content is obtained based on the data transaction request, a communication channel is established to exchange secure privacy keys, and the secure privacy keys are forwarded through the communication channel, a virtual node module further comprises: a node link verification unit for obtaining the corresponding secure privacy key, decoding the secure privacy key and comparing the secure privacy key with device hardware information, if the comparison result represents consistency, a data communication channel between nodes is established, a request privacy verification unit for obtaining the privacy risk grade of data content corresponding to the data transaction request, outputting the data transaction request and the privacy risk grade through a user device, receiving feedback from the user to generate a virtual verification result and forward the virtual verification result, the data transaction request comprising request object information and requested data content information, the virtual object authentication module comprises: a virtual device chain setting unit for generating a virtual object establishment request and outputting the virtual object establishment request when a user sets a privacy mark for data content, receiving a device link request from the user, establishing a communication channel with the user device and obtaining corresponding device hardware information, and setting the user device as a virtual verification node, a virtual node establishment unit for establishing a secure privacy key based on the device hardware information, establishing a virtual privacy verification node based on the user device, and sharing the secure privacy key with the virtual verification node, and a node feedback judgment unit for obtaining a virtual verification result of the virtual privacy verification node for the data transaction request, the virtual verification result being used for representing feedback of the data transaction request of data content belonging to the user. The application further comprises a key generation unit, the key generation unit is used for obtaining a machine hardware code in the device hardware information, taking the machine hardware code as an initial key, encrypting the device hardware information based on the initial key, generating a secure privacy key, and emptying the initial key during sharing of the secure privacy key, so that the initial key is not used as a shared data object. 2. The system of claim 1, wherein, 3.The blockchain data privacy protection system of claim 1, wherein, When the data content is provided with a privacy mark, the virtual verification node is a non-substitutable node, and the virtual verification result is the highest basis for judging the response to the data transaction request. 4.A method for protecting data privacy of a blockchain, characterized in that, The method comprises the steps of: The data content is marked with a privacy mark based on a plurality of preset privacy risk levels, different privacy risk levels correspond to different secure privacy keys and corresponding privacy verification nodes, and the secure privacy key is used for data communication and data storage encryption between the privacy verification nodes; A data transaction request is obtained and responded to, a privacy risk level corresponding to the privacy mark of the requested data content is obtained, a verification communication channel is established between the privacy risk level and a plurality of privacy verification nodes, the secure privacy key is obtained and judged, and a node judgment result is generated; A plurality of virtual verification nodes and corresponding virtual privacy verification nodes are established, the data transaction request is responded to and verified through the virtual privacy verification nodes, and a virtual verification result from the virtual verification nodes is obtained; Based on the node judgment result and the virtual verification result, if both represent that the verification is passed, the corresponding data content is obtained based on the data transaction request, a communication channel is established to exchange the secure privacy key, and the secure privacy key is forwarded through the communication channel; The method further comprises the steps of: The corresponding secure privacy key is obtained, the secure privacy key is decoded, and the secure privacy key is compared with the device hardware information, if the comparison result represents consistency, a data communication channel between nodes is established; The privacy risk level of the data content corresponding to the data transaction request is obtained, the data transaction request and the privacy risk level are output through the user device, feedback from the user is received to generate a virtual verification result and forward, and the data transaction request includes request object information and requested data content information; The step of establishing a plurality of virtual verification nodes and corresponding virtual privacy verification nodes, responding to the data transaction request and verifying the request through the virtual privacy verification nodes, and obtaining a virtual verification result from the virtual verification nodes specifically comprises: When the user sets a privacy mark for the data content, a virtual object establishment request is generated and output, a device link request from the user is received, a communication channel with the user device is established and corresponding device hardware information is obtained, and the user device is set as a virtual verification node; Based on the device hardware information, a secure privacy key is established, based on the user device, a virtual privacy verification node is established, and the secure privacy key is shared with the virtual verification node; The virtual verification result of the virtual privacy verification node to the data transaction request is obtained, and the virtual verification result is used to represent the feedback of the data content to the data transaction request.
5. The method of claim 4, wherein, The method further comprises the steps of: Obtaining the machine hardware code in the device hardware information, taking the machine hardware code as an initial key, encrypting the device hardware information based on the initial key, generating a secure privacy key, and the initial key is emptied as a shared data object during the secure privacy key sharing process.
6. The method of claim 4, wherein, Also includes steps: When the data content is provided with a privacy mark, the virtual verification node is a non-substitutable node, and the virtual verification result is the highest judgment basis for responding to the data transaction request.
Citation Information
Patent Citations
Query method and device for account privacy information in blockchain
CN111008228A
Blockchain data privacy protection system and protection method thereof
CN113111364A