A Fine-Grained Authentication Method for Hybrid Storage Blockchains
By using RSA accumulator to construct verification matrix or cube in hybrid storage blockchain, the problems of fine-grained query verification and mislocalization are solved, data availability is improved, and the storage and gas consumption of the blockchain is reduced, and the scalability of the system is enhanced.
Patent Information
- Application Number
- CN202310340101.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-03
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2043-04-03
AI Technical Summary
The existing hybrid storage blockchain solution lacks fine-grained authentication in query verification, which makes it difficult to distinguish between real data and forged data in query results, and the high storage cost and gas consumption of blockchain limit the scalability of the system.
The RSA accumulator is used to construct a verification matrix or cube, and data is stored and verified through a combination of on-chain and off-chain combination, supporting fine-grained query verification and error positioning, reducing the scale and gas consumption of ADS on-chain.
It realizes the distinction between real data and forged data after query verification fails, improves data availability, and enhances the scalability of the system by reducing on-chain storage costs and gas consumption.
Smart Images

Figure CN116582294B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to blockchain technology and cloud computing, and particularly to a fine-grained range query verification method for hybrid-storage blockchain. Background Art
[0002] Due to the large-scale application of distributed terminals, a huge amount of data streams are generated. More and more users choose to outsource their data to cloud service providers. However, once the data is outsourced to the cloud, the user loses physical control of the data. Cloud service providers are not fully trustworthy. Due to server failures and vulnerability to external attacks, etc., they pose a threat to the security of stored data. Therefore, query verification of outsourced data becomes very important.
[0003] Blockchain is an append-only distributed ledger built on a peer-to-peer network. Each node of the blockchain stores a complete transaction record. Blockchain has the characteristics of immutability and trustworthiness, so it has become an effective solution for secure data storage in decentralized applications such as the Internet of Things and data outsourcing. However, as the amount of data generated by terminal devices (such as Internet of Things devices) continues to increase, directly storing the original data on the blockchain lacks scalability, and the storage cost on the blockchain is high. Therefore, the hybrid-storage blockchain (HSB) that combines the blockchain and cloud servers has become a relatively ideal solution. The hybrid-storage blockchain combines the characteristics of low cloud storage cost and high blockchain trustworthiness, and perfectly solves the problems of untrustworthy cloud storage and high blockchain storage overhead. A typical HSB architecture is as Figure 1 shown, in which the data owner outsources a large amount of key-value data streams to the off-chain cloud service provider (SP), and only metadata (such as encrypted hashes) is stored in the blockchain. Since the SP is not fully trustworthy, existing solutions usually add an authenticated data structure (ADS) to the on-chain metadata. Users can then verify the integrity and correctness of the query results based on the ADS and the off-chain verification object (VO).
[0004] Although this solution can ensure the credibility of query results, previous research solutions only support fine-grained authentication, in which users can decide to accept or reject all query results based on the authentication results. In practice, the most common queries (such as range queries) retrieve a large number of matching objects, and only a small part of the data may be tampered with or incorrect, which makes most query results still valid after authentication fails. Therefore, fine-grained authentication that allows users to distinguish between real data and forged results is crucial for improving the data availability in the HSB environment. However, existing HSB solutions do not consider the fine-grained authentication problem and do not support locating data to improve data availability after query authentication fails.
[0005] In addition, in the hybrid storage blockchain, we should note that due to the need for transactions published on the blockchain to reach consensus and each node to save a complete copy of the transaction, the storage cost of the blockchain is very high. When storing data on the blockchain through smart contracts, it also consumes expensive gas costs. The higher the gas consumption, the more data is uploaded to the blockchain through smart contracts, increasing the storage overhead of the blockchain. Adopting a higher off-chain computing cost in exchange for a lower on-chain storage cost and reducing the fuel cost of storing data is a feasible solution. Summary of the Invention
[0006] To solve the above-mentioned defects existing in the prior art, the present invention proposes a new fine-grained query verification scheme supporting error location under the hybrid storage blockchain. The present invention proposes two multi-dimensional parity-based verification (MPV) schemes to balance the on-chain storage efficiency and off-chain computing efficiency. In the basic scheme, based on the RSA accumulator, we construct a verification matrix and propose a fine-grained authentication scheme supporting range query verification and error location. In the gas efficiency scheme, on the basis of the basic scheme, we reduce the size of the on-chain ADS, exchange a higher off-chain computing overhead for a lower storage cost on the blockchain, greatly reduce the gas consumption of the blockchain, and enhance scalability.
[0007] According to the first aspect of the present invention, there is provided a fine-grained authentication method for a hybrid storage blockchain, characterized in that the original data is stored in the cloud, the verifiable data structure ADS is stored in the blockchain, and the ADS stored in the blockchain and the verification information VO returned by the cloud are used to verify the integrity of the query results and, when the integrity verification fails, screen and locate the incorrect data. The method includes:
[0008] Step 110: ADS generation; including steps 111 - 114.
[0009] Step 111: The data owner constructs a sorted object set RO s ; For any keyword k s , according to its corresponding object set OBJ s , construct the sorted object set RO s = {(k s , a r , t r , r)}, r ∈ [1, d s , where (k s , a r , t r , r) represents the r-th version of the object of k s , with the value a r , the timestamp t r , and RO s is arranged in ascending order of timestamps, and the version number r increases in the order of 1, 2, 3,..., j,..., d s , and d s is the size of OBJ s .
[0010] Step 112: The data owner constructs a verification matrix M s of u s × u s according to the scale of RO s , where u s is the size of the verification matrix M s .
[0011] Step 113: The data owner executes the digest generation algorithm GenAcc(M s ) → θ, where the digest set θ = {θ1, θ2}, and θ1 and θ2 represent the sets of row digests and column digests respectively; for each row of data, execute GenAcc(M s [i][*]) → θ 1i , accumulate the data of the i-th row of M s based on the RSA accumulator, and generate a digest and store it in the i-th element θ 1i of θ1. For each column of data, execute GenAcc(M s [*][j]) → θ 2j , accumulate the data of the j-th column of M s based on the RSA accumulator, and generate a digest and store it in the j-th element θ 2j of θ2, where i, j ∈ [1, u s , and * represents all the data in that row or column.
[0012] Step 114: The data owner uploads RO s to the cloud server and uploads the digest set θ to the blockchain.
[0013] Step 120: Data query; The user sends a query request Q = (k s , [t l , t u ) to the cloud server, to query the data between the start time t l and the end time t u . The cloud server retrieves the search result SR = (k s , OBJ s ) and the boundary result BR that meet the query request, and generates the query result R = (SR, BR).
[0014] Step 130: VO construction; The cloud server executes the verification generation algorithm GenProof(R, M s ) → VO to generate the verification object VO, and sends R and VO to the user.
[0015] Among them, the verification generation algorithm GenProof(R, M s ) → VO includes: For each row of data, execute GenProof(L i , M s [i][*]) → Φ Li , that is, generate the verification proof Φ Li for the i-th row based on the RSA accumulator, where L i = R ∩ M s [i][*], which is the data jointly contained in the i-th row of the matrix M s and R. For each column of data, execute GenProof(C j , M s [*][j]) → Φ Cj , that is, generate the verification proof Φ Cj for the j-th column based on the RSA accumulator, where C j = R ∩ M s [*][j], which is the data jointly contained in the j-th column of the matrix M s and R. VO = {Φ L , Φ C}, Φ L is the verification proof set of row data, and Φ C is the verification proof set of column data.
[0016] Step 140: User verification; For the query Q = (k s , [t l , t u), the user first checks whether the query result R = SR ∪ BR meets the completeness requirements: (1) The objects in R have consecutive version numbers; (2) The objects in SR meet the query conditions; (3) Compared with SR, BR has the smallest and largest version numbers; (4) The objects in BR are not within the query range. After passing the verification, the user uses R and VO returned by the cloud server, and ADS retrieved from the blockchain, and executes the result verification algorithm VerProof(R, VO, θ) → (0, 1) to verify the integrity and correctness of the result, including: For each row of data, execute VerProof(L i , Φ Li , θ 1i ) → (0, 1), that is, verify whether the data in the i-th row is correct. If the verification is 1, the data in this row is verified correctly; if the verification is 0, the data in this row is verified incorrectly, and there is incorrect data in this row; When all rows are verified to be 1, it proves the integrity and correctness of R, otherwise, execute step 150.
[0017] Step 150, error location; For each column of data, execute VerProof(C j , Φ Li , θ 2j ) → (0, 1), that is, verify whether the data in the j-th column is correct. If the verification is 1, the data in this column is verified correctly; if the verification is 0, the data in this column is verified incorrectly, and there is incorrect data in this column. When VerProof(L i , Φ Li , θ 1i ) → 0 and VerProof(C j , Φ Li , θ 2j ) → 0, then the intersection point (i, j) of the row and column at this time is the position where the incorrect data is located, and this position is stored in the error position set EL.
[0018] Furthermore, the fine-grained identity authentication method of the hybrid storage blockchain provided by the present invention is characterized in that step 112 further includes: Each k s 's data stream is associated with u s ×u s 's verification matrix M s .
[0019] Furthermore, the fine-grained identity authentication method of the hybrid storage blockchain provided by the present invention is characterized in that step 113 further includes: The digest generation algorithm GenAcc(X) → acc(X) includes: Given a set X = {x1,..., x n}, when x i ∈ {0, 1}, the accumulated value generated by this algorithm is g is the generator of the cyclic group, and P(H(x i )) represents the prime number corresponding to the element x i , which is implemented through the universal hash function H.
[0020] Furthermore, the fine-grained authentication method of the hybrid storage blockchain provided by the present invention is characterized in that the method further includes: the verification generation algorithm GenProof(Y,X)→Φ includes: calculating the proof of the subset Y The result verification algorithm VerProof(Y,Φ,acc(X))→(0,1) includes: when , output 1, otherwise output 0.
[0021] According to the second aspect of the present invention, there is provided a fine-grained authentication method of a hybrid storage blockchain based on a gas efficiency structure, characterized in that the original data is stored in the cloud, the verifiable data structure ADS is stored in the blockchain, and the ADS stored in the blockchain and the verification information VO returned by the cloud are used to verify the integrity of the query result, and when the integrity verification fails, the error data is located and screened. The method includes:
[0022] Step 210: ADS generation; including steps 211-step 214.
[0023] Step 211: The data owner constructs a sorted object set RO s ; for any keyword k s , according to its corresponding object set OBJ s , construct a sorted object set RO s ={(k s ,a r ,t r ,r)}, r∈[1,d s , where (k s ,a r ,t r ,r) represents the r-th version of the object of k s , whose value is a r , the timestamp is t r , arranged in ascending order of the timestamp, and the version number r increases in the order of 1,2,3,...,j,...,d s , and d s is the size of OBJ s .
[0024] Step 212: The data owner constructs a verification cube Q s of v s ×v s ×v s , v s , v sTo verify the size of cube Q s The size of...
[0025] Step 213: The data owner executes the digest generation algorithm GenAcc(Q s ) → Δ s , where the digest set Δ s = {δ wh}, w ∈ {1, 2, 3}, h ∈ [1, v s , δ wh represents the digest value of the h-th face F s of the w-th dimension of the verification cube Q wh . The digest is calculated on a per-face basis. For each face of each dimension, execute GenAcc(Q s [w, h]) → δ wh . Accumulate all the data Q wh of face F s [w, h] based on the RSA accumulator, and generate the digest and store it in δ wh .
[0026] Step 214: The data owner uploads RO s to the cloud server and uploads the digest set Δs to the blockchain.
[0027] Step 220: Data query; The user sends a query request Q = (k s , [t l , t u ) to the cloud server to query the data between the start time t l and the end time t u . The cloud server retrieves the search result SR = (k s , OBJ s ) and the boundary result BR that meet the query request, and generates the query result R = (SR, BR).
[0028] Step 230: VO construction; The cloud server executes the verification generation algorithm GenProof(R, Q s ) → VO to generate the verification object VO, and sends R and VO to the user.
[0029] Among them, the verification generation algorithm GenProof(R, Q s ) → VO includes: obtaining the set F of faces in Q s that intersect with the query result R. The sub-block Z wh is the data jointly contained in R and face F wh . F wh ∈ F. Execute GenProof(Z wh , Q s [w, h]) → π wh, that is, generating F based on the RSA accumulator wh 's verification proof π wh , VO = {π wh}.
[0030] Step 240: User verification; For query Q = (k s , [t l , t u ), the user first checks whether the query result R = SR ∪ BR meets the completeness requirements: (1) The objects in R have consecutive version numbers; (2) The objects in SR meet the query conditions; (3) Compared with SR, BR has the smallest and largest version numbers; (4) The objects in BR are not within the query range. After passing the verification, the user uses the R and VO returned by the cloud server and the ADS retrieved from the blockchain to execute the result verification algorithm VerProof(R, VO, Δ s ) → (0, 1) to verify the integrity and correctness of the result, including: For each face F 3h ∈ F in the third dimension, run VerProof(Z 3h , π 3h , δ 3h ) → (0, 1) to verify whether the data in F 3h is correct. If the verification is 1, the data of this face is verified correctly; if the verification is 0, the data of this face is verified incorrectly and there is incorrect data on this face; When all the verifications of the third dimension faces are 1, it proves the integrity and correctness of R, otherwise, execute Step 250;
[0031] Step 250, Error localization; For each face F wh in the first and second dimensions, w = 1 or 2, F wh ∈ F, run VerProof(Z wh , π wh , δ wh ) → (0, 1) to verify whether the data in F wh is correct. If the verification is 1, the data of this face is verified correctly; if the verification is 0, the data of this face is verified incorrectly and there is incorrect data on this face; When VerProof(Z 1x , π 1x , δ 1x ) → 0, VerProof(Z 2y , π 2y , δ 2y ) → 0 and VerProof(Z 3z , π 3z , δ 3z ) → 0, the coordinates of the incorrect data in the verification cube are located as (x, y, z), and this position is stored in the error position set EL.
[0032] Further, the fine-grained identity authentication method for the hybrid storage blockchain provided by the present invention is characterized in that step 212 further includes: each k s data stream of and v s ×v s ×v s verification cube Q s is associated with
[0033] Further, the fine-grained identity authentication method for the hybrid storage blockchain provided by the present invention is characterized in that step 213 further includes: the digest generation algorithm GenAcc(X) → acc(X) includes: given a set X = {x1,..., x n}, when x i ∈{0,1}, the accumulated value generated by this algorithm is g is the generator of the cyclic group, P(H(x i )) represents the prime number corresponding to the element x i and is implemented through the universal hash function H.
[0034] Further, the fine-grained identity authentication method for the hybrid storage blockchain provided by the present invention is characterized in that the method further includes: the verification generation algorithm GenProof(Y,X) → Φ includes: calculating the proof of the subset Y The result verification algorithm VerProof(Y,Φ,acc(X)) → (0,1) includes: when is true, output 1, otherwise output 0.
[0035] According to the third aspect of the present invention, there is provided a computer device, characterized in that it includes: a memory for storing instructions; a processor for calling the instructions stored in the memory to execute the method of the first aspect or the second aspect.
[0036] According to the fourth aspect of the present invention, there is provided a computer-readable storage medium, characterized in that it stores instructions, and when the instructions are executed by a processor, the method of the first aspect or the second aspect is executed.
[0037] Compared with the prior art, the above technical solution conceived by the present invention has at least the following beneficial effects: The present invention is the first solution for fine-grained query verification in a hybrid storage blockchain. Compared with previous solutions, our solution supports users to distinguish real data from forged data after integrity verification fails, improving data availability. In traditional digital signature verification schemes, one data corresponds to one signature. By using an RSA accumulator to summarize the verifiable matrix, a row and a column of data can be mapped to a cumulative value, greatly reducing the scale of the ADS, and thus reducing the gas cost of uploading data to the blockchain through smart contracts. In addition, when generating the VO and the user performs verification based on the verification matrix of the RSA accumulator, verification can be performed in units of rows, that is, batch verification, reducing the size of the VO and the verification overhead of the user. When locating errors in the rows where verification fails, they can still be utilized. In the error location phase, only the columns need to be verified, and the intersection of rows and columns can locate the error data, reducing repeated calculations.
[0038] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] The accompanying drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present invention and, together with the specification, are used to explain the principles of the present invention.
[0040] Figure 1 is a diagram of the hybrid storage architecture
[0041] Figure 2 is a system model diagram
[0042] Figure 3 is a verification matrix shown according to an exemplary embodiment, where the key k s omitted
[0043] Figure 4 is a verification cube shown according to an exemplary embodiment, where the key k s omitted DETAILED DESCRIPTION OF THE EMBODIMENTS
[0044] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.
[0045] 1. RSA Accumulator
[0046] The RSA accumulator can provide a fixed-size digest for large data sets and provide concise proofs for (non-)membership tests. The RSA accumulator is used in the calculations of ADS and VO. Let N = p·q, φ(N) = (p - 1)(q - 1), where p and q are two large prime numbers. Let g be the generator of the cyclic group QR N and let H: {0, 1} * → {0, 1} λ be a collision-resistant hash function. Given the public key pk = {N, (g, QR N )} and the private key sk = {φ(N)}, the RSA accumulator consists of the following algorithms, which take pk as an implicit input.
[0047] GenAcc(X) → acc(X): Given a set X = {x1,..., x n}, when x i ∈ {0, 1} * , the accumulated value generated by this algorithm is P(x i ) represents the prime number corresponding to the element x i , which can be implemented by a universal hash function.
[0048] GenProof(Y, X) → Φ: This algorithm calculates the proof of the subset Y VerProof(Y, Φ, acc(X)) → {0, 1}: This algorithm detects the proof about , and outputs 1 only when . Based on the collision resistance of the hash function and the strong RSA assumption, it is difficult for an adversary to find a set Y' such that the above equation holds.
[0049] 2. Sorted object set
[0050] For each key, k s ∈ KEY, there is a sorted object set ROs = {(k s , v j , t j , j)} j∈[ds] , (k s , v j , t j , j) means that the object with value v j and timestamp t j is the j-th version of k s , arranged in ascending order of timestamps, and the version numbers increase in the order of 1, 2, 3,..., j,..., d s .
[0051] 3. Verification matrix
[0052] Each k s 's data stream is associated with u s ×u s 's verification matrix, where the element in the i-th row and j-th column is defined as M s [i][j], i, j ∈ [u s , and the sets of elements in the i-th row and j-th column are respectively denoted as M s [i][*] and M s [*][j].
[0053] 4. Verification Cube
[0054] Each k s 's data stream is associated with v s ×v s ×v s 's verification cube, The cube consists of a set of two-dimensional faces, denoted as {F wh}, w∈{1,2,3},h∈[1,vs] where F wh is the j-th face of the w-th dimension. For example, the three-dimensional faces of a 2×2×2 cube are represented as F1 = {F 11 , F 12}, F2 = {F 21 , F 22}, F3 = {F 31 , F 32}.
[0055]
[0056]
[0057] In the first aspect of the present invention, a fine-grained authentication scheme based on a hybrid storage blockchain is provided. The main idea is to let the ADS on the chain construct a verifiable matrix for each key, and verify the rationality of the result by testing whether the query result belongs to the matrix. The data owner constructs the verification matrix and discloses the construction method of the verification matrix, and then generates the ADS row by row and column by column and stores it in the blockchain. The user sends a query request to the cloud server, and the cloud server constructs the verification matrix and generates the VO row by row and column by column and returns it to the user. The user uses the VO, R, and ADS to verify row by row. If all rows pass the verification, all results pass the verification; otherwise, verify column by column, and locate the error according to the row-column intersection. The error location process is similar to the two-dimensional parity check method: if the verification of the i-th row and j-th column of M s [i][j] fails, it is considered that the query result located at M s [i][j] is false. The specific implementation is as follows:
[0058] Step 110: ADS Generation; including Step 111 - Step 114.
[0059] Step 111: The data owner constructs a sorted object set RO s ; For any keyword k s , according to its corresponding object set OBJ s , constructs a sorted object set RO s = {(k s , a r , t r , r)}, r ∈ [1, d s , where, (k s , a r , t r , r) represents the r-th version of the object of k s , with the value of a r , the timestamp of t r , and RO s is arranged in ascending order of timestamps, and the version number r increases in the order of 1, 2, 3,..., j,..., d s , and d s is the size of OBJ s .
[0060] Step 112: The data owner constructs a verification matrix M s of u s × u s according to the scale of RO s , where u s is the size of the verification matrix M s .
[0061] Step 113: The data owner executes the digest generation algorithm GenAcc(M s ) → θ, where the digest set θ = {θ1, θ2}, and θ1 and θ2 represent the sets of row digests and column digests respectively; for each row of data, execute GenAcc(M s [i][*]) → θ 1i , accumulate the data of the i-th row of M s based on the RSA accumulator, generate a digest and store it in the i-th element θ 1i of θ1, for each column of data, execute GenAcc(M s [*][j]) → θ 2j , accumulate the data of the j-th column of M s based on the RSA accumulator, generate a digest and store it in the j-th element θ 2j of θ2, i, j ∈ [1, u s , and * represents all the data in that row or that column.
[0062] Step 114: The data owner sends the RO s Upload to the cloud server and upload the summary set θ to the blockchain.
[0063] Step 120: Data query: The user initiates a query request Q to the cloud server. s ,[t l ,t u ]), query start time t l To end time t u The cloud server retrieves the search results that meet the query request SR = (k s ,OBJ s ) and boundary result BR, generate query result R = (SR, BR).
[0064] Among them, running the SetConstruct algorithm to obtain the matrix M s The set of rows I and columns J covered by the query result R = SR ∪ BR and the set of rows I and columns J in R located in the matrix M s The subinterval L of the i-th row and j-th column i and C j , i∈I and j∈J.
[0065] Step 130: VO construction; the cloud server executes the verification generation algorithm GenProof(R,M s )→VO generates a verification object VO and sends R and VO to the user.
[0066] Among them, the verification generation algorithm GenProof(R,M s )→VO includes: For each row of data, execute GenProof(L i ,M s [i][*])→Φ Li , that is, generate the verification proof Φ of the i-th row based on the RSA accumulator Li , where L i =R∩M s [i][*], is the matrix M s The data in row i and R are common. For each column of data, execute GenProof(C j ,M s [*][j])→Φ Cj , that is, generate the verification proof Φ of the jth row based on the RSA accumulator Cj , where C j =R∩M s [*][j], is the matrix M s The data contained in the jth column and R together, VO = {Φ L ,Φ C}, Φ LThe verification proof set for row data, Φ C is the verification proof set for column data.
[0067] Step 140: User verification; The user receives R and VO returned by the cloud server, and uses the ADS retrieved from the blockchain to execute the result verification algorithm VerProof(R, VO, θ) → (0, 1) to verify the integrity and correctness of the result, which includes: For each row of data, execute VerProof(L i , Φ Li , θ 1i ) → (0, 1), that is, verify whether the i-th row of data is correct. If the verification result is 1, the row of data is verified correctly; if the verification result is 0, the row of data is verified incorrectly, and there is incorrect data in this row. When all rows are verified as 1, it proves the integrity and correctness of R. Otherwise, execute Step 150.
[0068] Among them, the user first checks whether the query result R = SR ∪ BR meets the completeness requirements: (1) The objects in R have consecutive version numbers; (2) The objects in SR meet the query conditions; (3) Compared with SR, BR has the minimum and maximum version numbers; (4) The objects in BR are not within the query range. After passing the verification, the user runs VerProof(L i , Φ Li , θ 1i ) for i ∈ I to verify the authenticity of the elements in L i . Due to the security of the RSA accumulator, the algorithm VerProof only outputs 1 when . If all rows in I pass the verification, it means that all query results R are authentic, verifying the reliability of the results.
[0069] Step 150, Error location; For each column of data, execute VerProof(C j , Φ Li , θ 2j ) → (0, 1), that is, verify whether the j-th column of data is correct. If the verification result is 1, the column of data is verified correctly; if the verification result is 0, the column of data is verified incorrectly, and there is incorrect data in this column. When VerProof(L i , Φ Li , θ 1i ) → 0 and VerProof(C j , Φ Li , θ 2j ) → 0, then the point (i, j) where the row and column intersect is the location of the incorrect data, and this location is stored in the error location set EL.
[0070] To illustrate the problem, let's consider the following example:
[0071] Assume k s has a data flow form of OBJ s ={(v i , t i )} i∈
[24] , where t i = i + 100. The verifiable matrix M s with parameter μ s = 5 is shown as Figure 3 . Given query Q = (k s , [113, 114]), the search result SR = {(k s , v 13 , 113, 13), (k s , v 14 , 114, 14)} and the boundary result BR = {(k s , v 12 , 112, 12), (k s , v 15 , 115, 15)} are located in the I-th row = {3} and column J = {2, 3, 4, 5} of the matrix M s . The subset of R = SR ∪ BR (shown in blue) is in the 3rd row and extends from the 2nd column to the 5th column of the matrix M s : L3 = R, C2 = {(k s , v 12 , 112, 12)}, C3 = {(k s , v 13 , 113, 13)}, C4 = {(k s , v 14 , 114, 14)}, C5 = {(k s , v 15 , 115, 15)}. If SP returns a false result SR' = {(k s , v' 13 , 113, 13), (k s , v 14 , 114, 14)}, the algorithm verifies (L3, Φ L3 , θ 13 ) and verifies (C3, Φ C3 , θ 23 ) and outputs 0, and the user will know that the object located in M s [3][3] is false. If SP returns an incomplete result SR' = {(k s , v 14 , 114, 14)}, it must forge the boundary result BR' = {(k s , v 13 , 112, 13), (k s , v 15,115,15)}, to convince the user that the object in BR’ is not within the query range. However, due to the verification failure of M s [3][*] and M s [*][3], the user will know that the object located at M s [3][3] is false.
[0072] In some embodiments, step 112 further includes: for each data stream of k s and the verification matrix M s ×u s associated with s
[0073] In some embodiments, step 113 further includes: the digest generation algorithm GenAcc(X) → acc(X) includes: given a set X = {x1,…,x n}, when x i ∈ {0,1}, the accumulated value generated by this algorithm is where g is the generator of the cyclic group, and P(H(x i )) represents the prime number corresponding to the element x i , implemented through the universal hash function H.
[0074] In some embodiments, the method further includes: the verification generation algorithm GenProof(Y,X) → Φ includes: calculating the proof of the subset Y The result verification algorithm VerProof(Y,Φ,acc(X)) → (0,1) includes: when , output 1, otherwise output 0.
[0075] According to the second aspect of the present invention, a gas efficiency structure under a hybrid storage architecture is designed. For large-scale data sets, the first aspect of the invention requires a large amount of on-chain data and lacks scalability. To alleviate this problem, the two-dimensional verifiable matrix is extended to a three-dimensional verifiable cube, reducing the size of the ADS from O(2·μ s ) to O(3·ν s ), where u s 2 ≈ v s 3 . The main difference from the first aspect of the invention is that the ADS constructs a verifiable cube for each key, so the reliability of the result can be verified by testing whether the query result belongs to the cube. The specific implementation is as follows:
[0076] Step 210: ADS generation; including steps 211 - 214.
[0077] Step 211: The data owner constructs a sorted object set ROs ; For any keyword k s , construct a sorted object set RO s according to its corresponding object set OBJ s = {(k s , a r , t r , r)}, r ∈ [1, d s , where (k s , a r , t r , r) represents the r-th version of the object of k s , whose value is a r , and the timestamp is t r . It is arranged in ascending order of timestamps, and the version number r increases in the order of 1, 2, 3,..., j,..., d s , and d s is the size of OBJ s .
[0078] Step 212: The data owner constructs a verification cube Q s of v s × v s × v s according to RO s , where v s is the size of the verification cube Q s .
[0079] Step 213: The data owner executes the digest generation algorithm GenAcc(Qs) → Δ s , where the digest set Δ s = {δ wh}, w ∈ {1, 2, 3}, h ∈ [1, v s , and δ wh represents the digest value of the h-th face F s of the w-th dimension of the verification cube Q wh . Among them, the digest is calculated on a face-by-face basis. For each face of each dimension, execute GenAcc(Q s [w, h]) → δ wh . Accumulate all the data Q wh [w, h] of the face F s based on the RSA accumulator, and generate a digest and store it in δ wh .
[0080] Step 214: The data owner uploads RO s to the cloud server and uploads the digest set Δ s to the blockchain.
[0081] Step 220: Data Query; The user sends a query request Q=(k s ,[t l ,t u ) to the cloud server to query the data between the start time t l and the end time t u . The cloud server retrieves the search result SR=(k s ,OBJ s ) and the boundary result BR that meet the query request, and generates the query result R=(SR,BR).
[0082] Step 230: VO Construction; The cloud server executes the verification generation algorithm GenProof(R,Q s )→VO to generate the verification object VO, and sends R and VO to the user.
[0083] Among them, the verification generation algorithm GenProof(R,Q s )→VO includes: obtaining the set F of the faces in Q s that have an intersection with the query result R. The sub-block Z wh is the data jointly contained in R and the face F wh . For F wh ∈F, execute GenProof(Z wh ,Q s [w,h])→π wh , that is, generate the verification proof π wh of F wh based on the RSA accumulator, and VO={π wh}.
[0084] Step 240: User Verification; The user receives R and VO returned by the cloud server, and uses the ADS retrieved from the blockchain to execute the result verification algorithm VerProof(R,VO,Δ s )→(0,1) to verify the integrity and correctness of the result, including: for each face F 3h ∈F in the third dimension, run VerProof(Z 3h ,π 3h ,δ 3h )→(0,1) to verify whether the data in F 3h is correct. If the verification is 1, the data of this face is verified correctly; if the verification is 0, the data of this face is verified incorrectly, and there is incorrect data on this face. When all the verifications of the third dimension faces are 1, it proves the integrity and correctness of R, otherwise, execute Step 250.
[0085] When the verification meets the completeness requirements described in the first aspect of the invention, the user runs VerProof(Z 3h ,π 3h ,π3h , δ 3h ) Verify Z 3hj The elements in. Due to the security of the RSA accumulator, the algorithm verification only outputs 1 when . If all the faces in the third dimension of F pass the verification, it means that the query result R is true, verifying the rationality of the result. Otherwise, execute the next error localization algorithm.
[0086] Step 250, error localization; for each face F of the first dimension and the second dimension wh , w = 1 or 2, F wh ∈ F, run VerProof(Z wh , π wh , δ wh ) → (0, 1) to verify whether the data in F wh is correct. If the verification is 1, the data of this face is verified correctly; if the verification is 0, the data of this face is verified incorrectly and there is incorrect data on this face; when VerProof(Z 1x , π 1x , δ 1x ) → 0, VerProof(Z 2y , π 2y , δ 2y ) → 0 and VerProof(Z 3z , π 3z , δ 3z ) → 0, locate the coordinates of the incorrect data in the verification cube as (x, y, z), and store this position in the error position set EL.
[0087] Illustrate with an example:
[0088] For the sample data stream of keyword k s , that is, OBJ s = {(v i , i + 100)}. Using ν s = 3 as the input, construct a verifiable cube Q s as shown in Figure 4 . Given the query Q = (k s , [113, 114]), the search result SR = {(k s , v 13 , 113, 13), (k s , v 14 , 114, 14)} and the boundary result BR = {(k s , v 12 , 112, 12), (k s , v 15 , 115, 15)} are located on the face F s of the cube Q 1,1,F 1,2 ,F 1,3 ,F 2,1 ,F 2,2 ,F 3,2 . A subset of SR ∪ BR is marked in blue: {z 1,1 , z 1,2 , z 1,3 , z 2,1 , z 2,2 , z 3,2}. If SP returns a false result SR’ = {(k s , v’ 13 , 113, 13), (k s , v 14 , 114, 14)}, then the algorithms VerProof(Z 1,1 , π 1,1 , δ 1,1 ), VerProof(Z 2,2 , π 2,2 , δ 2,2 ), and VerProof(Z 3,2 , π 3,2 , δ 3,2 ) will output 0, and the user will know that the result at Q s [1,, 2, 2] is false. If SP returns an incomplete result SR’ = {(k s , v 14 , 114, 14)} and forges a false boundary result BR’ = {(k s , v 13 , 112, 13), (k s , v 15 , 115, 15)}, the user can still know that the object at Q s [1, 2, 2] is false because the verification of the opposite sides F 1,1 , F 2,2 and F 3,2 fails. Compared with the first aspect of the invention, the size Δ of the abstract set ADS sDecrease from 10 to 9. When the data volume increases to 1 million, for the first aspect of the invention, the matrix size is 1000*1000, the size of ADS is 2000, while the cube size is 100*100*100 and the size of ADS is 300. Assuming the range query ratio is 10%, that is, the scale of the query result is 100,000, the number of rows involved in the matrix is about 100 rows, and the number of faces involved in the cube is 10. This means that 100 VOs and validations are required in the matrix, while only 10 VOs and validations are required in the cube. The second aspect of the invention reduces the summary size from 2000 to 300, saving 85% of the storage space compared with the first aspect of the invention. Therefore, the second aspect of the invention is more suitable for the scenario of Internet of Things big data.
[0089] In some embodiments, step 212 further includes: each k s of the data stream and v s ×v s ×v s is associated with the verification cube Q s associated,
[0090] In some embodiments, step 213 further includes: the summary generation algorithm GenAcc(X)→acc(X) includes: given a set X = {x1,…,x n}, x i ∈{0,1}, the accumulated value generated by this algorithm is g is the generator of the cyclic group, P(H(x i )) represents the prime number corresponding to the element x i and is implemented through the universal hash function H.
[0091] In some embodiments, the method further includes: the verification generation algorithm GenProof(Y,X)→Φ includes: calculating the proof of the subset Y The result verification algorithm VerProof(Y,Φ,acc(X))→(0,1) includes: when output 1, otherwise output 0.
[0092] Those skilled in the art will readily conceive of other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present invention, which follow the general principles of the present invention and include known common knowledge or conventional technical means in the technical field not disclosed in this disclosure. The specification and embodiments are only regarded as exemplary, and the true scope and spirit of the present invention are pointed out by the following claims.
[0093] It should be understood that the present invention is not limited to the exact structures that have been described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present invention is only limited by the appended claims.
Claims
1. A fine-grained authentication method for a hybrid storage blockchain, characterized in that, The original data is stored in the cloud, and the verifiable data structure ADS is stored in the blockchain. The ADS stored in the blockchain and the verification information VO returned by the cloud are used to verify the integrity of the query result, and when the integrity verification fails, the error data is located and screened; The method includes: Step 110: ADS generation; including Step 111 - Step 114; Step 111: The data owner constructs a sorted object set RO s ; For any keyword k s , according to its corresponding object set OBJ s , construct a sorted object set RO s = {(k s , a r , t r , r)}, r ∈ [1, d s , where (k s , a r , t r , r) represents the r-th version of the object of k s , with the value a r , the timestamp t r , and RO s is sorted in ascending order of timestamps, and the version number r increases in the order of 1, 2, 3,..., j,..., d s , and d s is the size of OBJ s ; Step 112: The data owner constructs a verification matrix M of u × u according to the scale of RO s , where u s × u s is the size of the verification matrix M s , and u s is the dimension of the verification matrix M s ; Step 113: The data owner executes the digest generation algorithm GenAcc(M s ) → θ, where the digest set θ = {θ1, θ2}, and θ1 and θ2 represent the sets of row digest and column digest respectively; for each row of data, execute GenAcc(M s [i][*]) → θ 1i , accumulate the data of the i-th row of M s based on the RSA accumulator, and generate a digest and store it in the i-th element θ 1i of θ1. For each column of data, execute GenAcc(M s [*][j]) → θ 2j , accumulate the data of the j-th column of M s based on the RSA accumulator, and generate a digest and store it in the j-th element θ 2j of θ2, where i, j ∈ [1, u s , and * represents all the data in that row or column; Step 114: The data owner uploads the RO s to the cloud server and uploads the abstract set θ to the blockchain; Step 120: Data query; the user sends a query request Q = (k s , [t l , t u ) to the cloud server to query data between the start time t l and the end time t u . The cloud server retrieves the search result SR = (k s , OBJ s ) that meets the query request and the boundary result BR, and generates the query result R = (SR, BR); Step 130: VO construction; the cloud server executes the verification generation algorithm GenProof(R, M s ) → VO generates the verification object VO and sends R and VO to the user; Among them, the verification generation algorithm GenProof(R, M s ) → VO includes: for each row of data, execute GenProof(L i , M s [i][*]) → Φ Li , that is, generate the verification proof Φ Li of the i-th row based on the RSA accumulator, where L i = R ∩ M s [i][*], which is the data jointly contained in the i-th row of the matrix M s and R. For each column of data, execute GenProof(C j , M s [*][j]) → Φ Cj , that is, generate the verification proof Φ Cj of the j-th row based on the RSA accumulator, where C j = R ∩ M s [*][j], which is the data jointly contained in the j-th column of the matrix M s and R. VO = {Φ L , Φ C}, Φ L is the set of verification proofs for row data, and Φ C is the set of verification proofs for column data; Step 140: User verification; The user receives R and VO returned by the cloud server, and uses the ADS retrieved from the blockchain to execute the result verification algorithm VerProof(R, VO, θ) → (0, 1) to verify the integrity and correctness of the result, which includes: for each row of data, execute VerProof(L i , Φ Li , θ 1i ) → (0, 1), that is, verify whether the i-th row of data is correct. If the verification result is 1, the data in this row is verified correctly; if the verification result is 0, the data in this row is verified incorrectly, and there is incorrect data in this row. When all rows are verified to be 1, it proves the integrity and correctness of R. Otherwise, execute Step 150; Step 150, error location; for each column of data, execute VerProof(C j , Φ Li , θ 2j ) → (0, 1), that is, verify whether the data in the j-th column is correct. If the verification result is 1, the data in this column is verified correctly; if the verification result is 0, the data in this column is verified as incorrect, and there is incorrect data in this column. When VerProof(L i , Φ Li , θ 1i ) → 0 and VerProof(C j , Φ Li , θ 2j ) → 0, then the point (i, j) where the row and column intersect at this time is the location of the incorrect data, and store this location in the error location set EL.
2. The fine-grained authentication method for a hybrid storage blockchain according to claim 1, wherein Step 112 further includes: each k s data stream of s × u s associated verification matrix M s is associated with 3. The fine-grained authentication method for a hybrid storage blockchain according to claim 2, characterized in that, Step 113 further includes: The abstract generation algorithm GenAcc(X) → acc(X) includes: Given a set X = {x1,…,x n}, when x i ∈ {0,1}, the accumulated value generated by this algorithm is g is the generator of the cyclic group, P(H(x i )) represents the prime number corresponding to the element x i and is implemented through the universal hash function H.
4. The fine-grained authentication method for a hybrid storage blockchain according to claim 3, wherein The method further includes: The verification generation algorithm GenProof(Y, X) → Φ includes: calculating the proof of subset Y The result verification algorithm VerProof(Y, Φ, acc(X)) → (0, 1) includes: when it is the case, output 1, otherwise output 0.
5. A fine-grained authentication method for a hybrid storage blockchain based on a gas efficiency structure, characterized in that, The original data is stored in the cloud, and the verifiable data structure ADS is stored in the blockchain. The ADS stored in the blockchain and the verification information VO returned by the cloud are used to verify the integrity of the query result, and when the integrity verification fails, the error data is located and screened; The method includes: Step 210: ADS generation; including Step 211 - Step 214; Step 211: The data owner constructs a sorted object set RO s ; For any keyword k s , according to its corresponding object set OBJ s , construct the sorted object set RO s = {(k s , a r , t r , r)}, r ∈ [1, d s , where (k s , a r , t r , r) represents the r-th version of the object of k s , whose value is a r , the timestamp is t r , arranged in ascending order of the timestamp, and the version number r increases in the order of 1, 2, 3,..., j,..., d s , and d s is the size of OBJ s ; Step 212: The data owner receives the data according to the RO s Construct v s ×v s ×v s The verification cube Q s , v s To verify the cube Q s Size; Step 213: The data owner executes the digest generation algorithm GenAcc(Q s ) → Δ s , where the digest set Δ s = {δ wh}, w ∈ {1, 2, 3}, h ∈ [1, v s , δ wh represents the digest value of the h-th face F s of the w-th dimension of the verification cube Q wh . Among them, the digest is calculated on a face-by-face basis. For each face of each dimension, execute GenAcc(Q s [w, h]) → δ wh . Accumulate all the data Q wh of the face F s [w, h] based on the RSA accumulator, and generate a digest and store it in δ wh ; Step 214: The data owner uploads the RO s to the cloud server and uploads the abstract set Δ s to the blockchain; Step 220: Data query; The user sends a query request Q=(k s ,[t l ,t u ) to the cloud server to query data between the start time t l and the end time t u . The cloud server retrieves the search result SR=(k s , OBJ s ) that meets the query request and the boundary result BR, and generates the query result R=(SR, BR); Step 230: VO construction; the cloud server executes the verification generation algorithm GenProof(R, Q s ) → generate a verification object VO, and send R and VO to the user; Among them, the verification generation algorithm GenProof(R, Q s ) → VO includes: obtaining the set F of faces in Q s that have an intersection with the query result R, and the sub-block Z wh is the data jointly contained in R and the face F wh , for F wh ∈F, execute GenProof(Z wh , Q s [w, h]) → π wh , that is, generate the verification proof π wh of F based on the RSA accumulator wh , VO = {π wh}; Step 240: User verification; The user receives R and VO returned by the cloud server, and uses the ADS retrieved from the blockchain to execute the result verification algorithm VerProof(R, VO, Δ s ) → (0, 1) to verify the integrity and correctness of the verification result, including: for each face F 3h ∈F, run VerProof(Z 3h , π 3h , δ 3h ) → (0, 1) to verify whether the data in F 3h is correct. If the verification result is 1, the data of this face is verified correctly; if the verification result is 0, the data of this face is verified incorrectly and there is incorrect data on this face. When all the verifications of the third dimension faces are 1, it proves the integrity and correctness of R. Otherwise, execute Step 250; Step 250, error location; for each face F in the first dimension and the second dimension wh , where w = 1, 2, and F wh ∈F, run VerProof(Z wh , π wh , δ wh ) → (0, 1) to verify whether the data in F wh is correct. If the verification result is 1, the data of this face is verified correctly; if the verification result is 0, the data of this face is verified incorrectly and there is incorrect data on this face. When VerProof(Z 1x , π 1x , δ 1x ) → 0, VerProof(Z 2y , π 2y , δ 2y ) → 0 and VerProof(Z 3z , π 3z , δ 3z ) → 0, locate the coordinates of the incorrect data in the verification cube as (x, y, z), and store this position in the error location set EL.
6. The fine-grained authentication method for the hybrid storage blockchain according to claim 5, characterized in that, Step 212 further includes: each k s data stream of and v s × v s × v s verification cube Q of s associated with 7. The fine-grained authentication method for a hybrid storage blockchain according to claim 6, characterized in that, Step 213 further includes: The abstract generation algorithm GenAcc(X) → acc(X) includes: Given a set X = {x1, …, x n}, when x i ∈ {0, 1}, the accumulated value generated by this algorithm is g is the generator of the cyclic group, P(H(x i )) represents the prime number corresponding to the element x i and is implemented through the universal hash function H.
8. The fine-grained authentication method for a hybrid storage blockchain according to claim 7, characterized in that, The method further includes: The verification generation algorithm GenProof(Y, X) → Φ includes: calculating the proof of subset Y The result verification algorithm VerProof(Y, Φ, acc(X)) → (0, 1) includes: when it outputs 1, otherwise it outputs 0.
9. A computer device, characterized in that, Including: A memory for storing instructions; A processor for calling the instructions stored in the memory to execute the method according to any one of claims 1 - 8.
10. A computer-readable storage medium, characterized in that, Instructions are stored, and when the instructions are executed by the processor, the method according to any one of claims 1 - 8 is executed.