Decentralized multi-role encrypted evidence storage method and device
Through decentralized content addressing technology and multi-role encrypted evidence storage methods, the problem of asset tampering and deletion in the digital asset evidence system is solved, the tamper-proofness and multi-role secure evidence storage of digital content are achieved, and the secure flow and value inheritance of multiple roles on public platforms are supported.
Patent Information
- Application Number
- CN202310514984.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2023-04-21
- Filing Date
- 2023-05-09
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2043-05-09
AI Technical Summary
In the existing digital asset notarization system, assets are centralized, tamper-proof, deletable, and copyable. Owners cannot truly own the assets, and the system cannot be widely used among multiple roles.
Decentralized content addressing technology is used to hash and slice digital content, combined with multi-role public and private key encryption and identity verification to generate encrypted evidence data and record it in the decentralized token ledger, achieving the tamper-proof nature of the content address and multi-role identity verification.
It realizes the immutability and multi-role secure storage of digital content, supports the secure transfer and value inheritance of multiple roles on public platforms, solves the problem of tampering and deletion of resources in traditional technologies, and ensures the public, trustworthy and tamper-proof inheritance and transfer of assets.
Smart Images

Figure CN116582245B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computers, and more particularly, to a method and apparatus for decentralized multi-role encrypted evidence storage. Background Art
[0002] In a narrow sense, blockchain is a chained data structure composed of data blocks linked by irreversible hash IDs, which uses cryptography to ensure tamper-proof and unforgeable security. In a broader sense, blockchain is a new distributed infrastructure and data generation method that uses hash block chain data structures to verify and store data, distributed node consensus algorithms to generate and update data, cryptography to ensure data security, and smart contracts composed of automated script code to program and manipulate data. Blockchain is essentially a new application model based on computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanisms, and encryption algorithms.
[0003] A smart contract is a decentralized, self-executing, coded contractual agreement based on blockchain technology that can be executed without third-party intervention. The core characteristic of smart contract technology is its decentralization, which eliminates the centralized risks of human intervention, thereby ensuring the contract's immutability, security, and reliability. The core function of smart contract technology is its ability to execute automatically without third-party intervention, ensuring security and reliability while also improving execution efficiency. Smart contract technology can also enable automated, decentralized multi-party collaboration.
[0004] In the field of informatics, an oracle machine, also known as an oracle, is an abstract computer used to study deterministic problems. It can be thought of as a Turing machine with an additional black box (the oracle), whose function is to answer specific questions within a single computation. In blockchain applications, an oracle's function is to feed external information into blockchain smart contracts, enabling data communication between blockchain smart contracts and the real world. Blockchain is a deterministic environment that does not tolerate uncertainty. Smart contracts must produce consistent results regardless of their execution time and location. Therefore, the operation of blockchain smart contracts cannot rely on the uncertain results of network calls to the external world. Oracle technology allows deterministic smart contracts to respond to the uncertain external world, enabling smart contracts to communicate with the real world.
[0005] Decentralized content addressing (DCA) is a content storage and access mechanism that uses a unique, immutable digital feature of the content itself as an address. This mathematically guarantees a one-to-one correspondence between content and addresses. The same content always has only one address; the same address always points to the same content. This revolutionizes traditional location-based addressing mechanisms like URLs on the internet. For example, next-generation decentralized file system networks like IPFS and Arweave use the Merkle-DAG hash of the content itself as the address (i.e., the content address), ensuring the immutable mapping between content and addresses. They also use algorithms like the distributed hash table (Kademlia) to distribute content slices across a decentralized network.
[0006] Decentralized content addressing technology allows any resource to self-verify its unique, immutable existence through its content address. However, all resources are sliced and distributed across a decentralized network, with no clear ownership or chronological order of uploads.
[0007] NFTs (Non-Fungible Tokens) are an emerging blockchain technology application hotspot. NFTs, or non-fungible tokens, are blockchain smart contracts that support the ERC-721 standard. An NFT token registers a resource ID and its owner's blockchain address. Through blockchain smart contract mechanisms, it is uploaded to the blockchain, thus decentrally and immutably binding the ownership relationship between the resource ID and its owner. It also supports on-chain transactions to transfer resource ownership. The resource ID in an NFT token is typically mapped to an internet URL, which points to an internet resource, typically an image. Currently, typical applications of NFTs are the minting, holding, and trading of image works.
[0008] However, the internet resources pointed to by URLs can be tampered with or deleted by the servers hosting them. The same URL can present different resources to different users at different times. Therefore, while decentralized on-chain NFTs are immutable, the underlying resources are centralized, tamper-proof, and removable. In a sense, purchasing an NFT simply means purchasing ownership of a string of characters on the blockchain, not actually owning the resource it points to.
[0009] Secondly, the resources that NFTs point to are accessible to anyone in today’s technology solutions and products. Even if one person purchases an NFT, they only become the owner on the chain in name only, and others can still copy and share the resource without hindrance.
[0010] Finally, NFTs only represent ownership and cannot reflect the diverse objects, rights, and responsibilities of the real world. Therefore, NFTs have only been used in the field of image ownership, such as digital collectibles.
[0011] To sum up, the existing digital asset notarization system has the problem that the corresponding assets are centralized, tamperable, deletable, and copyable. The so-called owner does not actually own the asset. The asset storage party can tamper with and delete the asset at will, and users can copy and share the asset without hindrance. This destroys the owner's ownership of the asset and the copyright of the original creator, and also hinders the relevant rights and interests of users and visitors, limiting the wider application of assets among more roles in the real and digital worlds. Summary of the Invention
[0012] The purpose of the present invention is to provide a method and device for decentralized multi-role encrypted evidence storage.
[0013] The present invention aims to solve the problems existing in the existing digital asset notarization system.
[0014] Compared with the prior art, the technical solution of the present invention and its beneficial effects are as follows:
[0015] In a first aspect of the present disclosure, a method for decentralized multi-role encrypted evidence storage is provided, comprising: storing digital content of an entity into a decentralized content-addressed storage system, performing a first hash addressing, and obtaining an entity content address; encrypting the entity content address with public and private keys by multiple roles to generate a multi-role encrypted address of the entity content; performing cryptographic processing related to identity authentication on the multiple roles to generate a multi-role identity authentication; storing encrypted evidence data consisting of the multi-role encrypted address and the multi-role identity authentication again into the decentralized content-addressed storage system, performing a second hash addressing, and obtaining an evidence content address; recording the evidence content address and its current owner in a decentralized token ledger; publicly retrieving any of the encrypted evidence data through the decentralized token ledger; reading the tamper-proof original content based on a known content address through the decentralized content-addressed storage system, but not retrieving or traversing the stored content; publicly verifying the multi-role identity authentication of the encrypted evidence by a third party; and decrypting and accessing the content encrypted by the multiple roles, as well as endorsing and transferring the encrypted evidence to role successors.
[0016] In a second aspect of the present disclosure, a device for decentralized multi-role encrypted evidence storage is provided, comprising: a decentralized content-addressed storage system, storing digital content in the decentralized content-addressed storage system, performing hash addressing, and obtaining a content address; an encryption casting system, performing a first hash addressing on the original body content through the decentralized content-addressed storage system to obtain a body content address; performing multi-role public-private key encryption on the body content address to generate encrypted evidence data; storing the encrypted evidence data again in the decentralized content-addressed storage system, performing a second hash addressing, and obtaining an encrypted evidence content address; an identity verification system, performing identity verification processing such as public-private key signatures and zero-knowledge proofs on the multi-role encrypted addresses, and making them public for identity verification by a third party; and a decentralized token ledger, recording the encrypted evidence content address and its current owner in the decentralized token ledger, and providing them to the public for query and retrieval.
[0017] The beneficial effects of the present invention are:
[0018] Using decentralized content addressing technology, the original digital content is hashed and sliced using a Merkle tree graph, and then distributedly stored in a decentralized network, ensuring that the digital content itself cannot be tampered with and will never be lost. Replacing centralized Internet URLs with decentralized content addresses fundamentally resolves the major vulnerability of traditional technologies, where resources corresponding to the address of the ontology can be tampered with or deleted.
[0019] By encrypting the public and private keys of the content address of the Ontology by multiple roles, an encrypted evidence is formed. The content is then addressed a second time and stored in a decentralized content addressing storage system. This mathematically and technically solves the contradiction between the need for public evidence and the need for privacy of the Ontology in an efficient and secure way. Ontology content is always visible to the multiple roles involved in the creation of the content on the public platform, but cannot be discovered or copied by any other user.
[0020] Through multi-role identity verification, Ontology can perform decentralized role verification and role inheritance operations under the premise of security, openness, and confidentiality, thereby ensuring the safe flow of value.
[0021] By registering the encrypted evidence and the current owner of the encrypted evidence in the token ledger, the public, credible, and tamper-proof inheritance and circulation of the evidence, the entity, and its value are realized. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figure 1 This is a schematic diagram of a decentralized multi-role encrypted evidence storage method provided by an embodiment of the present invention.
[0023] Figure 2 This is a schematic diagram of a device for decentralized multi-role encrypted evidence storage provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0024] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the invention claimed for protection, but merely represents selected embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0025] In the description of the present invention, the terms "first" and "second" are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of the technical features indicated. Therefore, a feature specified as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of the present invention, "plurality" means two or more, unless otherwise specifically defined.
[0026] Reference Figure 1 As shown, in the first aspect of the present disclosure, a method for decentralized multi-role encrypted evidence storage is provided, including: storing the digital content of the entity into a decentralized content addressing storage system, performing a first hash addressing, and obtaining the entity content address; multiple roles encrypt the entity content address with public and private keys to generate a multi-role encrypted address of the entity content; performing cryptographic processing related to identity authentication on the multiple roles to generate a multi-role identity authentication; storing the encrypted evidence data consisting of the multi-role encrypted address and the multi-role identity authentication again into the decentralized content addressing storage system, performing a second hash addressing, and obtaining the evidence content address; recording the evidence content address and its current owner in a decentralized token account book; and any of the encrypted evidence data can be publicly retrieved through the decentralized token account book.
[0027] The decentralized content-addressed storage system includes but is not limited to decentralized IPFS or Arweave; the decentralized content-addressed storage system can also be degraded to a relatively centralized Internet URL-addressed storage backend.
[0028] The implementation forms of the decentralized token ledger include but are not limited to decentralized blockchain ledgers and NFT smart contracts; the decentralized token ledger can also be downgraded to a relatively centralized database or even a traditional paper ledger.
[0029] The existence of the original digital content that cannot be tampered with can be publicly verified through the multi-role encrypted address in the encrypted evidence data;
[0030] The validity of the identities of the multiple roles can be publicly verified through the multi-role identity certification in the encrypted evidence data.
[0031] The ontology content address is encrypted with multiple public and private keys to generate encrypted address data, which includes but is not limited to: the encryption algorithm used; and the ontology content encrypted address obtained by encrypting the ontology content address.
[0032] The cryptographic processing related to identity verification of the multiple roles includes but is not limited to public and private key signatures, zero-knowledge proof, UTXO locking scripts, smart contracts, and other feasible identity verification methods for the multi-role encrypted addresses of the ontology content.
[0033] Different roles in the multiple roles select and use corresponding identity verification methods for the same entity.
[0034] Public users can query the decentralized token account book to obtain the address of the encrypted evidence content; the public users can also access the decentralized content addressing storage system to read the encrypted evidence data.
[0035] After reading the encrypted evidence data, the multi-role users participating in the evidence casting can decrypt the encrypted address in the evidence to obtain the address of the content, since the encrypted address in the evidence is encrypted with the public and private keys of the multi-role users. The multi-role users can access the decentralized content addressing storage system and read the content.
[0036] The multiple roles include but are not limited to owners, creators, agents, and more roles. The multiple roles can participate individually or jointly in encrypting the ontology content address to form the ontology content multi-role encrypted address, and can also participate individually or jointly in identity certification of the ontology content multi-role encrypted address to form a multi-role identity certification.
[0037] Any one or several of the multiple roles stores the digital content of the entity in the decentralized content-addressable storage system, mints the encrypted evidence data, and queries the token ledger; any one or several of the multiple roles can also access the decentralized content-addressable storage system, read the encrypted evidence data, decrypt it using the private key of this role, and then read the digital content of the entity.
[0038] The public queries the token ledger, accesses the decentralized content-addressed storage system, reads the encrypted evidence data, and verifies the multi-role identity proof.
[0039] The current holder of one or more of the multiple roles uses the private key of the current role to decrypt the original encrypted evidence data to obtain the content address of the ontology, and uses the private key of the current role to endorse and sign the role successor;
[0040] The role successor encrypts the ontology content address with public and private keys to generate the ontology content encrypted address of the role successor; the role successor uses its own private key to perform identity proof-related cryptographic processing on the ontology content encrypted address of the role successor to generate the identity proof of the role successor; the ontology content encrypted address of the role successor, the identity proof of the role successor, together with the endorsement signature of the current role holder on the role successor, form new encrypted evidence data, which is stored in the decentralized content addressing storage system and hashed to obtain a new evidence content address;
[0041] The token account book verifies the identity of the current role holder and the endorsement signature of the role successor for the original encrypted evidence data and the new encrypted evidence data. After the verification is passed, the new evidence content address is recorded in the token account book.
[0042] The encrypted evidentiary data consisting of the multi-role encrypted address and the multi-role identity proof includes but is not limited to: a one-way function hash value of the ontology content address; the old evidentiary content address of the ontology; the decentralized address of the multi-role itself; the ontology content multi-role encrypted address generated by the multi-role using their respective public and private keys to encrypt the ontology content address; the multi-role identity proof generated by the multi-role using their respective selected identity proof methods; other metadata such as the generation time, title, index, etc. of the encrypted evidentiary data; and the endorsement signature of the previous role.
[0043] The various role rights and related settings surrounding an ontology are formally registered as a decentralized multi-role rights contract, and the decentralized multi-role rights contract is stored together with the ontology's encrypted evidence data in the decentralized content-addressed storage system;
[0044] The multi-role rights include but are not limited to ownership, agency rights, usage rights, access rights, and more possible role rights types in reality;
[0045] The content of the decentralized multi-role equity contract is set by the equity-related stakeholders, including but not limited to any reasonable agreed elements such as the specified execution environment, price, time limit, limit, utility, logic, etc., using any effective formal method such as numbers, text, code scripts, smart contracts, etc.
[0046] An agent participates in the encryption and identity verification of the ontology content address, thereby being able to respond to requests from other role users anytime and anywhere to perform operations such as signing, storing, querying, reading, verifying, and executing equity contracts;
[0047] The agent machine is a public remote platform or a private local tool.
[0048] A notary machine responds to requests from the agent machine, other roles, or the public in real time, verifies the equity contract in an external environment, and returns the verification results to the requester;
[0049] The notary machine is a decentralized blockchain smart contract oracle, or a centralized traditional notary source.
[0050] The subsequent owner queries the token ledger through the proxy machine and obtains the address of the encrypted evidence content;
[0051] The subsequent owner accesses the decentralized content-addressable storage system through the proxy machine to read the encrypted evidence data;
[0052] The subsequent owner executes the ownership contract in an external environment according to the requirements of the ownership contract in the encrypted evidence data;
[0053] The subsequent owner sends a request to the notary via the agent, and the notary checks the external environment to confirm that the subsequent owner has reached the ownership contract;
[0054] The agent uses its own private key to decrypt the encrypted evidence data to obtain the original content address of the original entity, and directly or indirectly uses the public and private keys of the successor owner to encrypt and authenticate the original content address of the original entity, thus casting it into subsequent encrypted evidence data. The successor owner is recorded as the owner of the subsequent encrypted evidence data and stored in the token ledger, thus completing the transfer of ownership of the original entity.
[0055] The subsequent agent queries the token ledger through the current agent to obtain the encrypted content address;
[0056] The subsequent agent accesses the decentralized content-addressable storage system through the current agent to read the encrypted evidence data;
[0057] The subsequent agent executes the agency contract in an external environment according to the requirements of the agency contract in the encrypted evidence data;
[0058] The subsequent agent sends a request to the notary through the current agent, and the notary confirms that the subsequent agent has reached the agency contract by checking the external environment;
[0059] The current agent uses its own private key to decrypt the encrypted evidence data to obtain the original content address of the original entity, and directly or indirectly uses the public and private keys of the successor agent to encrypt and authenticate the original content address of the original entity, casting it into a subsequent encrypted evidence, which is stored in the decentralized token account book, completing the transfer of the agency rights of the original entity.
[0060] The visitor queries the decentralized token ledger through the proxy machine and obtains the encrypted content address of the certificate;
[0061] The visitor accesses the decentralized content-addressable storage system through the proxy machine and reads the encrypted evidence data;
[0062] The visitor executes the access right contract in an external environment according to the requirements of the access right contract in the encrypted evidence data;
[0063] The visitor requests verification of the visitor's rights and interests through the agent, and the agent sends a request to the notary, which confirms that the visitor has reached the access right contract by checking the external environment;
[0064] The proxy machine uses its own private key to decrypt the encrypted address in the encrypted evidence data to obtain the address of the main content, reads the main content from the decentralized content addressing storage system, and returns it to the visitor.
[0065] The user queries the decentralized token account book through the proxy machine and obtains the encrypted evidence content address;
[0066] The user accesses the decentralized content-addressable storage system through the proxy machine to read the encrypted evidence data;
[0067] The user executes the usage rights contract in an external environment according to the requirements of the usage rights contract in the encrypted evidence data;
[0068] The user requests verification of the user's rights and interests through the agent, and the agent sends a request to the notary. The notary confirms that the user has reached the usage rights agreement by checking the external environment, and the agent issues an authorization token to the user.
[0069] The user presents the authorization token to other third-party applications, and the third-party application then submits the authorization token to the agent. After the agent verifies that the authorization token is valid, it uses its own private key to decrypt the encrypted evidence data to obtain the main content, and returns the main content to the third-party application for use.
[0070] Digital content / digital existence refers to any digital content (e.g., text, images, videos) or digital twin of physical entities (handmade works, artworks, buildings, etc.), also known as resources or assets. Using decentralized content addressing technology, the entity itself undergoes multiple rounds of hashing, with slices distributed across a decentralized network. This replaces internet URLs with content addresses, fundamentally ensuring that the mapping chain from existence to evidence to tokens cannot be tampered with, resolving the issue of NFTs, which often result in tampering and deletion of corresponding resources.
[0071] Encrypted evidence storage involves encrypting the content address of the entity using an encryption algorithm and storing the encrypted address in a data structure called an evidence. Leveraging the irreversibility of hashing and encryption algorithms, this method efficiently and securely resolves the contradiction between fully public evidence and confidential resources, ensuring that the resource itself (within this decentralized system and to other unrelated users) is undiscoverable and uncopyable.
[0072] Multi-role refers to the fact that in reality, a digital entity often has multiple distinct roles, such as owner, user, agent, and so on. The multi-role encrypted evidence storage of this invention supports the collaborative participation of any role, such as minter, owner, user, lessee, and so on. Each participating role can use its own public and private keys to encrypt and decrypt the address of the stored content, and can operate independently or collaboratively.
[0073] Equity Contract: Traditional NFTs only have one type of permission, namely ownership, which greatly limits more practical applications. This invention proposes the concept of an equity contract. An equity contract defines the scope and conditions of an equity and its user role, including but not limited to price, puzzles, restrictions, codes, and all other forms that are recognized and accepted by users. Typical equity contracts include but are not limited to ownership contracts, access rights contracts, use rights contracts, lease rights contracts, etc. Multiple equity contracts are integrated into the encrypted evidence to form a public, indivisible, and tamper-proof mandatory contractual provision for the existence and evidence.
[0074] An ownership contract defines the terms of ownership, including acquisition, transfer, term, and profit sharing. For example, the simplest ownership contract is a price. A potential acquirer must pay the previous owner a corresponding amount to take over ownership of the asset.
[0075] A usage rights contract defines the acquisition, transfer, and duration of usage rights, and is sold to users in limited quantities for their own use. For example, the simplest usage rights contract might be a price. Anyone wishing to use the asset must pay the corresponding fee to obtain the right to own and use the asset.
[0076] In the real world, the right of use takes many forms. Park ticket sales / restaurant reservations / club memberships / painting copies / book printing / merchandising inventory / house rentals can all be implemented using a right of use contract.
[0077] Access Rights Contract: Defines decryption access rights. For example, the simplest example is a price. Anyone who wants to decrypt and access the entity must pay the corresponding fee to decrypt the evidence and access the digital content of the entity.
[0078] The agency contract defines the acquisition, transfer, term, and profit-sharing of agency rights. It accepts user entrustment and provides automated services anytime, anywhere for minting, encryption, decryption, use, trading, verification, and other behaviors. It also receives corresponding service fees according to the contract, thereby continuously providing better services to users.
[0079] Including but not limited to the above roles, more subdivided or extended roles can be defined around different categories of ontologies, such as operating rights contracts, disposal rights contracts, and so on.
[0080] Decentralized profit distribution: Equity contracts enable data assets and their market profits to be directly attributed to individuals. Through equity contracts, each role and each user directly possesses certain rights to the underlying asset and automatically obtains their share of profits according to the contract, thereby stimulating the market vitality of various equity roles, rather than passively accepting the distribution of traditional centralized (monopoly) intermediary platforms.
[0081] Application Agent: Many roles are backed by humans, who are unlikely to be online all the time, and manual decryption is inefficient. Therefore, a special agent role is proposed. This agent accepts commissions from other roles and provides automated services such as minting, querying, verification, execution, and trading anytime, anywhere, charging fees according to the agency contract. Following the principle of decentralization, the agent can be freely replaced by the current owner of the ontology within the entire system. The agent can be implemented as a decentralized application (Dapp) or downgraded to a traditional application platform on the Internet.
[0082] Equity Notarization: Whether a user has fulfilled the requirements of a certain equity contract requires a decentralized, trusted, and deterministic verification mechanism. A equity notarization is a facility responsible for verifying equity contracts, connecting to the world outside the ledger to provide public and reliable verification of equity contracts. This can be achieved using oracles or other decentralized verification technologies, or it can be downgraded to traditional centralized sources such as banks and public notary agencies.
[0083] Reference Figure 2 As shown, in a second aspect of the present disclosure, a device for decentralized multi-role encrypted evidence storage is provided, comprising:
[0084] The decentralized content addressable storage system 290 stores the digital content 240 in the decentralized content addressable storage system 290 and performs hash addressing to obtain the content address;
[0085] The encrypted evidence casting system 260 performs a first hash addressing on the original content through the decentralized content addressing storage system 290 to obtain the content address of the content; performs multi-role public and private key encryption and multi-role identity authentication on the content address to generate encrypted evidence data; stores the encrypted evidence data again in the decentralized content addressing storage system 290 and performs a second hash addressing to obtain the encrypted evidence content address;
[0086] The identity verification system 260 performs cryptographic processing related to identity verification based on the multi-role encrypted address, including but not limited to digital signatures, zero-knowledge proofs, etc.; the identity verification and the encrypted address are combined to form encrypted evidence data for third-party authentication;
[0087] The decentralized token ledger 270 records the encrypted content address and its current owner in the decentralized token ledger 270 and makes it available to the public for query and retrieval;
[0088] Equity contract 260, which formally registers the multi-role equity of the entity, specifies the equity itself and its execution environment, price, restrictions, utility, logic, and any other reasonable agreed elements, and uses any valid formal method such as numbers, text, code scripts, smart contracts, etc. to register;
[0089] Decentralized agent 250, which performs cryptographic evidence-related operations on behalf of other roles anytime and anywhere, including but not limited to storage, encryption, minting, decryption, authentication, and authorization;
[0090] The decentralized notary 280 connects the internal encrypted evidence storage system with the external environment to verify whether the user has reached an equity contract in the external environment.
[0091] The above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Those skilled in the art should understand that any modifications and equivalent substitutions that do not depart from the spirit and scope of the present invention should fall within the scope of protection of the claims of the present invention.
Claims
1. A decentralized multi-role encrypted evidence storage method, characterized in that: include: Store the Ontology digital content in a decentralized content-addressed storage system, perform the first hash addressing, and obtain the Ontology content address; The multiple roles encrypt the ontology content address with public and private keys to generate an ontology content multi-role encrypted address; Performing cryptographic processing related to identity verification on the multiple roles to generate multi-role identity verification; The encrypted evidence data composed of the multi-role encrypted address and the multi-role identity certificate is stored again in the decentralized content-addressed storage system, and a second hash addressing is performed to obtain the evidence content address; Record the address of the stored content and its current owner in the decentralized token ledger; The current holder of one or more of the multiple roles uses the private key of the current role to decrypt the original encrypted evidence data to obtain the content address of the ontology, and uses the private key of the current role to endorse and sign the role successor; The role successor encrypts the ontology content address with public and private keys to generate the ontology content encrypted address of the role successor; The role successor uses his / her own private key to perform cryptographic processing related to identity proof on the encrypted address of the role successor's content to generate the identity proof of the role successor; The encrypted content address of the role successor, the identity certificate of the role successor, and the endorsement signature of the current role holder on the role successor are used to form new encrypted evidence data, which is stored in the decentralized content addressing storage system and hashed to obtain a new evidence content address; The decentralized token account verifies the original encrypted evidence data and the new encrypted evidence data, the identity of the current role holder and the endorsement signature of the role successor. After the verification is passed, the new evidence content address is recorded in the decentralized token account.
2. A decentralized multi-role encrypted evidence storage method according to claim 1, characterized in that: Also includes: The multiple roles include owners, creators, agents, and more roles. The multiple roles can participate individually or jointly in encrypting the ontology content address to form the ontology content multi-role encrypted address, and can also participate individually or jointly in the identity certification of the ontology content multi-role encrypted address to form a multi-role identity certification.
3. A decentralized multi-role encrypted evidence storage method according to claim 1, characterized in that: Also includes: The cryptographic processing related to identity verification of the multiple roles includes public and private key signatures, zero-knowledge proofs, UTXO locking scripts, smart contracts, and other feasible identity verification methods for the multi-role encrypted addresses of the ontology content; Different roles in the multiple roles may choose to use different and compatible identity verification methods for the same entity.
4. A decentralized multi-role encrypted evidence storage method according to claim 1, characterized in that: The encrypted evidential data consisting of the multi-role encrypted address and the multi-role identity certificate includes: One-way function hash value of the ontology content address; The address of the old stored content of the entity; The decentralized address of the multi-role itself; The multiple roles use their respective public and private keys to encrypt the ontology content address to generate the ontology content multi-role encrypted address; The multiple roles use the identity verification methods selected by each role to generate a multiple role identity verification; Encrypt the generation time, title, index and other metadata of the evidence data; Endorsement signature of the previous character.
5. A decentralized multi-role encrypted evidence storage method according to claim 1, characterized in that: Also includes: The decentralized content-addressed storage system includes decentralized IPFS and Arweave, and can also be downgraded to a relatively centralized Internet URL-addressed storage backend and database; Through the decentralized content addressing storage system, any digital content can be stored in a decentralized manner; the original stored and tamper-proof digital content can also be read with the known content address; but the stored digital content cannot be retrieved or traversed.
6. A decentralized multi-role encrypted evidence storage method according to claim 1, characterized in that: Also includes: Decentralized token ledgers include decentralized blockchain ledgers and NFT smart contracts; they can also be downgraded to relatively centralized databases or traditional paper ledgers; Any of the encrypted evidence data can be publicly retrieved through the decentralized token ledger.
7. A decentralized multi-role encrypted evidence storage method according to claim 1, characterized in that: Also includes: Any one or more of the multiple roles stores the digital content of the entity in the decentralized content-addressable storage system, mints the encrypted evidence data, and registers it in the decentralized token ledger; Any one or several of the multiple roles can also query the decentralized token ledger, read the address of the encrypted evidence content, access the decentralized content addressing storage system, read the encrypted evidence data, decrypt it using the private key of this role, and then read the digital content of the entity.
8. A decentralized multi-role encrypted evidence storage method according to claim 1, characterized in that: Also includes: A third party can query the decentralized token ledger, access the decentralized content-addressed storage system, read the encrypted evidence data, and verify the multi-role identity proof.
9. A device for decentralized multi-role encrypted evidence storage, characterized in that: Used to perform the method according to any one of claims 1 to 8, comprising: A decentralized content addressing storage system stores the digital content in the decentralized content addressing storage system, performs hash addressing, and obtains the address of the content itself; The cryptographic casting system performs a first hash addressing on the original content through the decentralized content addressing storage system to obtain the content address; performs multi-role public and private key encryption and multi-role identity authentication on the content address; generates encrypted evidence data; stores the encrypted evidence data again in the decentralized content addressing storage system, performs a second hash addressing, and obtains the encrypted evidence content address; An identity verification system that performs cryptographic processing related to identity verification based on a multi-role encrypted address, including digital signatures and zero-knowledge proofs. The identity verification and the encrypted address together form encrypted evidence data for third-party authentication. The decentralized token account records the encrypted content address and its current owner in the decentralized token account and provides it to the public for query and retrieval.
Citation Information
Patent Citations
Identity certificate recording method based on block chain
CN106506467A
Data encryption evidence storage and sharing method based on blockchain
CN113364576A