Technical Database Sharing and Verification Matching System and Method Based on Blockchain Technology
Through hash processing, encryption and permission verification based on blockchain technology, the problem of data leakage risk in traditional technology database sharing is solved, and safe and efficient data sharing and trust improvement are achieved.
Patent Information
- Application Number
- CN202411324009.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-20
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2044-09-20
AI Technical Summary
Traditional technical database sharing and verification matching methods pose a risk of data leakage, resulting in low trust between data providers and requesters.
Data sharing and verification matching methods based on blockchain technology are adopted to ensure the security and accurate matching of data sharing through hashing processing, metadata recording, encryption processing, permission verification mechanism and digital signatures.
Improves the security and efficiency of data sharing, enhances the level of trust between data providers and requesters, and ensures that data access is controlled and secure.
Smart Images

Figure CN119203233B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data sharing, and particularly to a technical database sharing and verification matching system and method based on blockchain technology. Background Art
[0002] Technical database sharing and verification matching refers to the process of sharing data resources among different users, systems or organizations, and ensuring the accuracy and consistency of the data so that it can be correctly used at the receiving end. By adopting technical database sharing and verification matching, effective sharing and utilization of data can be achieved while protecting data privacy and security. With the rapid development of information technology and the explosive growth of the global data volume, all walks of life have accumulated a vast amount of data resources. In order to improve the utilization efficiency of data resources, it is necessary to effectively store, manage and utilize these data.
[0003] Traditional technical database sharing and verification matching mainly realizes the utilization and management of database resources through a centralized storage system and a method of manually verifying data accuracy by humans. However, this method is prone to risks of data leakage or loss, resulting in a low level of trust between the data provider and the data requester. Summary of the Invention
[0004] To solve the above problems, the present invention provides a technical database sharing and verification matching system and method based on blockchain technology, which can ensure the security of data sharing and improve the level of trust between the data provider and the data requester.
[0005] In a first aspect, the present invention provides a technical database sharing and verification matching method based on blockchain technology, including:
[0006] Obtain the technical database to be shared, identify the data content in the technical database, perform hash processing on the data content to generate hash data, collect the metadata records of the technical database, and determine the shared data of the technical database based on the hash data and the metadata records;
[0007] Identify the data type of the shared data, analyze the data sensitivity level of the shared data, perform encryption processing on the shared data based on the data type and the data sensitivity level to obtain encrypted shared data, set the query verification method and query index of the encrypted shared data, and set the sharing rules of the shared data based on the query verification method and the query index;
[0008] Based on the sharing rules, identify the data sharing requests for the shared data, analyze the identity types corresponding to the data sharing requests, where the identity types include data requestors and data providers, extract the identity verification data corresponding to the identity types, and based on the identity verification data, set the permission verification mechanism for the data sharing requests;
[0009] Extract the digital signature of the shared data from the identity verification data, set the access level of the shared data according to the permission verification mechanism, and based on the digital signature and the access level, set the decryption interval of the shared data;
[0010] Extract the decryption data in the decryption interval and calculate the matching degree between the decryption data and the data sharing request. According to the matching degree, analyze the sharing verification result of the technical database.
[0011] In a possible implementation manner of the first aspect, the determining the shared data of the technical database based on the hash data and the metadata record includes:
[0012] Based on the hash data and the metadata record, identify the data trading pool of the technical database;
[0013] Extract the transaction data in the data trading pool and set the transaction block of the transaction data;
[0014] Calculate the hash value of the transaction data in the transaction block and set the satisfaction condition of the hash value;
[0015] Based on the satisfaction condition, set the block propagation mode of the transaction data;
[0016] According to the block propagation mode and the transaction block, create a blockchain copy of the transaction data;
[0017] Based on the blockchain copy, determine the shared data of the technical database.
[0018] In a possible implementation manner of the first aspect, the identifying the data type of the shared data includes:
[0019] Perform functional partitioning on the shared data to obtain classification functions;
[0020] Based on the classification functions, set the classification codes of the shared data;
[0021] Extract the metadata records in the shared data;
[0022] Based on the metadata records and the classification codes, identify the data type of the shared data.
[0023] In a possible implementation of the first aspect, analyzing the data sensitivity level of the shared data includes:
[0024] Extracting the data attributes corresponding to the shared data and setting the sensitivity scores corresponding to the data attributes;
[0025] Setting the hierarchical level of the shared data according to the sensitivity scores and the data attributes;
[0026] Based on the hierarchical level, analyzing the potential impacts corresponding to the data attributes;
[0027] Combining the sensitivity scores and the potential impacts to analyze the data sensitivity level of the shared data.
[0028] In a possible implementation of the first aspect, encrypting the shared data based on the data type and the data sensitivity level to obtain encrypted shared data includes:
[0029] Analyzing the applicable scenarios of the shared data based on the data type and the data sensitivity level;
[0030] Setting the encryption method of the shared data according to the applicable scenarios;
[0031] Identifying the key management mechanism corresponding to the encryption method;
[0032] Encrypting the shared data based on the encryption method and the key management mechanism to obtain encrypted shared data.
[0033] In a possible implementation of the first aspect, setting the query index of the encrypted shared data includes:
[0034] Classifying the encrypted shared data to obtain classified data;
[0035] Analyzing the query frequencies corresponding to the classified data and extracting the query fields of the classified data according to the query frequencies;
[0036] Creating an encrypted index of the query fields and identifying the query conditions of the query fields;
[0037] Setting the matching answers corresponding to the query conditions in the encrypted index;
[0038] Setting the verification method of the matching answers;
[0039] Setting the query index of the encrypted shared data based on the encrypted index and the verification method.
[0040] In a possible implementation manner of the first aspect, setting the sharing rule of the shared data based on the query verification method and the query index includes:
[0041] Based on the query verification method and the query index, identifying the access group and access content corresponding to the shared data;
[0042] Calculating the information carrying capacity of the access content in the shared data;
[0043] According to the information carrying capacity, setting the access permission of the access group;
[0044] Identifying the identity level of the access group, and setting the permission level of the access permission based on the identity level;
[0045] According to the permission level, defining the access condition of the shared data;
[0046] Combining the permission level and the access condition, setting the sharing rule of the shared data.
[0047] In a possible implementation manner of the first aspect, setting the permission verification mechanism of the data sharing request based on the identity verification data includes:
[0048] Based on the identity verification data, extracting the original voucher information of the data sharing request;
[0049] Identifying the input voucher of the data sharing request, and setting the number of error attempts of the input voucher;
[0050] Calculating the matching variable between the input voucher and the original voucher information;
[0051] Based on the matching variable, setting the access control permission of the data sharing request;
[0052] According to the number of error attempts and the access control permission, setting the permission verification mechanism of the data sharing request.
[0053] In a possible implementation manner of the first aspect, setting the decryption interval of the shared data based on the digital signature and the access level includes:
[0054] Authenticating the digital signature to obtain an authentication result;
[0055] According to the authentication result, determining the permission range of the access level;
[0056] Combining the authentication result and the permission range, analyzing the permission request of the shared data;
[0057] Set the decryption key corresponding to the permission request;
[0058] Based on the permission request and the decryption key, set the decryption interval of the shared data.
[0059] In a second aspect, the technical database sharing and verification matching system based on blockchain technology provided by the present invention is characterized in that the system includes:
[0060] A shared data generation module, configured to obtain a technical database to be shared, identify the data content in the technical database, perform a hashing process on the data content to generate hash data, collect metadata records of the technical database, and determine the shared data of the technical database based on the hash data and the metadata records;
[0061] A data encryption module, configured to identify the data type of the shared data, analyze the data sensitivity level of the shared data, and perform an encryption process on the shared data based on the data type and the data sensitivity level to obtain encrypted shared data, set the query verification method and query index of the encrypted shared data, and set the sharing rule of the shared data based on the query verification method and the query index;
[0062] A permission verification module, configured to identify a data sharing request for the shared data based on the sharing rule, analyze the identity type corresponding to the data sharing request, where the identity type includes a data requester and a data provider, extract the identity verification data corresponding to the identity type, and set a permission verification mechanism for the data sharing request based on the identity verification data;
[0063] A data decryption module, configured to extract a digital signature of the shared data from the identity verification data, set an access level of the shared data according to the permission verification mechanism, and set a decryption interval of the shared data based on the digital signature and the access level;
[0064] A verification matching module, configured to extract decryption data in the decryption interval, calculate a matching degree between the decryption data and the data sharing request, and analyze a sharing verification result of the technical database according to the matching degree.
[0065] Compared with the prior art, the technical principle and beneficial effects of this solution are as follows:
[0066] In the embodiments of the present invention, by obtaining a technical database to be shared and identifying the data content in the technical database, information such as the type, structure, and value of the data can be understood, providing a data source for subsequent data sharing, verification, and matching, and improving the efficiency and scalability of data sharing; in the embodiments of the present invention, by setting the sharing rules of the shared data based on the query verification method and the query index, accurate matching between the query request and the shared data can be ensured. During the data sharing process, through the sharing rules, orderly data exchange and sharing can be carried out between different data providers and users, breaking data islands, promoting data circulation and integration, and thus mining more data value; in the embodiments of the present invention, by setting the permission verification mechanism for the data sharing request based on the identity verification data, the trust degree inside and outside the system can be improved. Users can be convinced that the access and use of data are strictly controlled, thereby enhancing confidence in the system; further, in the embodiments of the present invention, by setting the decryption interval of the shared data based on the digital signature and the access level, the confidentiality of the data during transmission and storage can be ensured, preventing unauthorized access, and restricting the ways for potential attackers to obtain sensitive data, improving the security and user experience of data sharing; in the embodiments of the present invention, by extracting the decryption data in the decryption interval and calculating the matching degree between the decryption data and the data sharing request, it can be verified whether the decryption process is successful and whether the decrypted data is intact, enhancing data security; further, in the embodiments of the present invention, by analyzing the sharing verification result of the technical database according to the matching degree, the needs of the requester can be quickly responded to, the data required by the requesting party can be provided, the efficiency of data sharing can be improved, the immediate needs of users or the system can be met, and at the same time, data resources can be better managed and utilized, and the trust degree between the data provider and the requester can be improved. Therefore, the technical database sharing and verification matching method based on blockchain technology proposed in the embodiments of the present invention can ensure the security of data sharing and improve the trust degree between the data provider and the data requester. BRIEF DESCRIPTION OF THE DRAWINGS
[0067] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present invention and used together with the specification to explain the principles of the present invention.
[0068] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0069] Figure 1Schematic flowchart of a method for sharing, verifying, and matching a technology database based on blockchain technology provided by an embodiment of the present invention;
[0070] Figure 2 Schematic diagram of modules of a system for sharing, verifying, and matching a technology database based on blockchain technology provided by an embodiment of the present invention. Detailed implementation manners
[0071] It should be understood that the detailed implementation manners described herein are only used to explain the present invention and are not used to limit the present invention.
[0072] An embodiment of the present invention provides a method for sharing, verifying, and matching a technology database based on blockchain technology. The execution subject of the method for sharing, verifying, and matching a technology database based on blockchain technology includes, but is not limited to, at least one of electronic devices such as a server, a terminal, etc. that can be configured to execute the method provided by the embodiment of the present invention. In other words, the method for sharing, verifying, and matching a technology database based on blockchain technology can be executed by software or hardware installed on a terminal device or a server device, and the software can be a blockchain platform. The server includes, but is not limited to: a single server, a server cluster, a cloud server, or a cloud server cluster, etc. The server can be an independent server or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, Content Delivery Network (CDN), and big data and artificial intelligence platforms.
[0073] Refer to Figure 1 As shown, it is a schematic flowchart of a method for sharing, verifying, and matching a technology database based on blockchain technology provided by an embodiment of the present invention. Among them, Figure 1 The method for sharing, verifying, and matching a technology database based on blockchain technology described in
[0074] S1. Obtain the technology database to be shared, identify the data content in the technology database, perform a hashing process on the data content to generate hash data, collect the metadata records of the technology database, and determine the shared data of the technology database based on the hash data and the metadata records.
[0075] In an embodiment of the present invention, by obtaining the technology database to be shared and identifying the data content in the technology database, information such as the type, structure, and value of the data can be understood, providing a data source for subsequent data sharing, verification, and matching. The technology database refers to a data set used to store and manage technical information, data, and knowledge, and the data content refers to specific information or data items in the technology database, such as technical documents.
[0076] Optionally, the identification of the data content in the technical database can be obtained through a database management system, such as MySQL.
[0077] Furthermore, in the embodiment of the present invention, by performing hash processing on the data content to generate hash data, it can be ensured that the data on the blockchain cannot be tampered with, enhancing the integrity of the data. And by sharing the hash value of the data, the original data can be not shared, thereby improving the transparency and privacy of the data. The hash data refers to the data composed of the output values obtained by processing the original data through a hash function.
[0078] Optionally, the hash processing of the data content can be implemented by using a hash function, such as SHA-256.
[0079] In the embodiment of the present invention, by collecting the metadata records of the technical database, it can be used as the basis for data sharing, enabling different users or systems to more easily understand and use the data from different technical databases, thereby promoting cross-domain and cross-institutional sharing of data. The metadata records refer to the summary records describing the data content in the technical database, such as data attributes, data ownership, and data status.
[0080] Optionally, the collection of the metadata records of the technical database can be implemented by using a metadata warehouse.
[0081] Furthermore, in the embodiment of the present invention, by determining the shared data of the technical database based on the hash data and the metadata records, the integrity and security of the technical database can be improved, and the efficiency and scalability of data sharing can be enhanced. The shared data refers to various shared data recorded and verified in the blockchain network.
[0082] As an embodiment of the present invention, the determination of the shared data of the technical database based on the hash data and the metadata records includes: identifying the data transaction pool of the technical database based on the hash data and the metadata records; extracting the transaction data in the data transaction pool and setting the transaction block of the transaction data; calculating the hash value of the transaction data in the transaction block and setting the satisfaction condition of the hash value; setting the block propagation mode of the transaction data based on the satisfaction condition; creating a blockchain copy of the transaction data according to the block propagation mode and the transaction block; and determining the shared data of the technical database based on the blockchain copy.
[0083] Among them, the data trading pool refers to a place for temporarily storing transaction data waiting to be confirmed and incorporated into a block. The transaction data refers to the data waiting to be traded in the data trading pool. The transaction block refers to a structured data packet for storing and propagating transaction data. The hash value refers to a fixed-length output value generated by calculating input data of any length through a hash function. The condition to be met refers to the format requirements that the calculated hash value needs to conform to, such as the number of leading zeros of the hash value. The block propagation method refers to the propagation method of broadcasting newly created transaction blocks to all nodes in the entire blockchain network and being verified and accepted by each node. The blockchain copy refers to a data copy of the transaction data stored on each participating node in the blockchain network.
[0084] Optionally, based on the hash data and the metadata record, the identification of the data trading pool of the technical database can be obtained through the API interface provided by the node software. The setting of the transaction block of the transaction data can be implemented using client software, such as geth software. The setting of the condition to be met for the hash value can be obtained through the number of leading zeros of the hash value. Based on the condition to be met, the setting of the block propagation method of the transaction data can be implemented using blockchain broadcasting. The calculation of the hash value of the transaction data in the transaction block can be obtained through a hash algorithm, such as the MD5 algorithm.
[0085] S2. Identify the data type of the shared data, analyze the data sensitivity level of the shared data, and based on the data type and the data sensitivity level, perform encryption processing on the shared data to obtain encrypted shared data. Set the query verification method and query index of the encrypted shared data, and based on the query verification method and the query index, set the sharing rules of the shared data.
[0086] In the embodiment of the present invention, by identifying the data type of the shared data, the most suitable storage format and index mechanism can be adopted for each type of data, thereby improving the retrieval speed and processing efficiency of the shared data. The data type refers to the type or form of data stored and shared in the technical database, such as the blockchain data type.
[0087] As an embodiment of the present invention, the identification of the data type of the shared data includes: performing functional partitioning on the shared data to obtain classification functions; based on the classification functions, setting the classification codes of the shared data; extracting the metadata records in the shared data; and based on the metadata records and the classification codes, identifying the data type of the shared data.
[0088] Among them, the classification function refers to the ability to classify data according to its characteristics and uses for the convenience of shared data management, and the classification encoding refers to converting shared data into a specific format encoding, such as the binary format of shared data.
[0089] Optionally, based on the classification function, the classification encoding setting of the shared data can be implemented using a standardized encoding format, such as the JSON format.
[0090] Furthermore, in the embodiments of the present invention, by analyzing the data sensitivity level of the shared data, the risks that may be brought about by data leakage or improper handling can be evaluated, and appropriate security controls can be implemented to ensure the security of the shared data. The data sensitivity level refers to the level of confidentiality, importance, and the risks and impacts that may be brought about by leakage or improper handling of the data.
[0091] As an embodiment of the present invention, analyzing the data sensitivity level of the shared data includes: extracting the data attributes corresponding to the shared data and setting the sensitivity scores corresponding to the data attributes; setting the hierarchical levels of the shared data according to the sensitivity scores and the data attributes; analyzing the potential impacts corresponding to the data attributes based on the hierarchical levels; and analyzing the data sensitivity level of the shared data by combining the sensitivity scores and the potential impacts.
[0092] Among them, the data attributes refer to the classification of the data content included in the shared data, such as personal identity information, health information, and property information. The sensitivity score refers to the quantitative index score of the sensitive information included in the data classification attribute in the shared data. The hierarchical level refers to the importance level of the shared data set according to the data attributes and the sensitive scores. The potential impact refers to the risks and effects brought about by the leakage or sharing of the content corresponding to the importance level of the shared data.
[0093] Optionally, the setting of the sensitivity scores corresponding to the data attributes can be obtained through SAL i b in the Python library. Based on the hierarchical levels, the analysis of the potential impacts of the shared data can be implemented using the risk assessment results of the data content.
[0094] In the embodiments of the present invention, by encrypting the shared data based on the data type and the data sensitivity level, encrypted shared data is obtained, which can achieve fine-grained access control, ensure that only users with the correct permissions can decrypt and access specific data, and ensure that once the data is encrypted and uploaded to the blockchain, it cannot be modified, thereby enhancing the trust of all parties. The encrypted shared data refers to the data after encryption processing.
[0095] As an embodiment of the present invention, encrypting the shared data based on the data type and the data sensitivity level to obtain encrypted shared data includes: analyzing the applicable scenarios of the shared data based on the data type and the data sensitivity level; setting the encryption method for the shared data according to the applicable scenarios; identifying the key management mechanism corresponding to the encryption method; and encrypting the shared data based on the encryption method and the key management mechanism to obtain encrypted shared data.
[0096] Among them, the applicable scenario refers to the specific use of data sharing, such as data transmission, data storage, and data verification. The encryption method refers to the encryption algorithms and technologies used to protect data security. The key management mechanism refers to the measures for generating, storing, distributing, using, and destroying keys.
[0097] Optionally, the analysis of the applicable scenarios of the shared data based on the data type and the data sensitivity level can be obtained through the data processing requirements of the shared data. The setting of the encryption method for the shared data according to the applicable scenarios can be implemented using symmetric encryption, asymmetric encryption, and hybrid encryption methods. The identification of the key management mechanism corresponding to the encryption method can be obtained through an encryption library, such as OpenSSL.
[0098] Further, in the embodiment of the present invention, by setting the query verification method and query index of the encrypted shared data, the transparency of the shared data can be increased, the credibility of the data can be improved, and the trust among the participating parties within the system can be enhanced. The query verification method refers to the method used by the system to confirm the accuracy and integrity of the query result after the user submits a query request. The query index refers to a data structure created in the database to accelerate the data query speed.
[0099] Optionally, the setting of the query verification method for the encrypted shared data can be obtained through digital signature.
[0100] As an embodiment of the present invention, setting the query index of the encrypted shared data includes: classifying the encrypted shared data to obtain classified data; analyzing the query frequency corresponding to the classified data, and extracting the query fields of the classified data according to the query frequency; creating an encrypted index for the query fields and identifying the query conditions for the query fields; setting the matching answers corresponding to the query conditions in the encrypted index; setting the verification method for the matching answers; and setting the query index of the encrypted shared data based on the encrypted index and the verification method.
[0101] Among them, the classified data refers to different types of data obtained after the data classification process. The query frequency refers to the number of times a certain data field or data category is queried. The query field refers to a specific field that users often use to perform queries in the technical database. The encrypted index refers to an index with authentication created to improve query efficiency. The query condition refers to the conditions set by users when querying data. The matching answer refers to the data records or results filtered according to the query conditions. The verification method refers to the method of verifying the authenticity and integrity of the data answer, such as hash verification.
[0102] Optionally, the query frequency analysis corresponding to the classified data can be implemented using a log analysis tool, such as the PRTG Network Monitor tool. According to the query frequency, the query field extraction of the classified data can be obtained through a query optimizer. The creation of the encrypted index for the query field can be implemented using an encryption algorithm. The identification of the query conditions for the query field can be defined through the query language of the database, such as SQL. The verification method for the matching answer can be implemented using an authentication token.
[0103] In an embodiment of the present invention, by setting the sharing rules of the shared data based on the query verification method and the query index, it is possible to ensure an accurate match between the query request and the shared data. During the data sharing process, through the sharing rules, orderly data exchange and sharing can be carried out between different data providers and users, breaking data islands, promoting the circulation and integration of data, and thus mining more data value. The sharing rules refer to the regulations and conditions that clearly define how data is shared, accessed, and used, such as content usage specification rules.
[0104] As an embodiment of the present invention, setting the sharing rules of the shared data based on the query verification method and the query index includes: identifying the access group and access content corresponding to the shared data based on the query verification method and the query index; calculating the information carrying capacity of the access content in the shared data; setting the access permissions of the access group according to the information carrying capacity; identifying the identity level of the access group, and setting the permission level of the access permissions based on the identity level; defining the access conditions of the shared data according to the permission level; and setting the sharing rules of the shared data by combining the permission level and the access conditions.
[0105] Among them, the access group refers to the set of users authorized to access shared data, the access content refers to the data or information that the access group is authorized to access, the information carrying capacity refers to the effective information volume contained in the access content, the access permission refers to the operations that the access group can perform on the access content, such as data reading, the identity level refers to the level or status of the user or access group in the organization, the permission level refers to the data operation permission level set according to the user's identity level and the information carrying capacity of the data, and the access condition refers to the conditions that the user needs to meet when accessing data.
[0106] Optionally, based on the query verification method and the query index, the identification of the access group and access content corresponding to the shared data can be obtained through an identity authentication service. Based on the information carrying capacity, the access permission setting of the access group can be implemented using role-based access control. The definition of the access conditions for the shared data can be obtained through security policies, such as multi-factor authentication policies.
[0107] In an optional embodiment of the present invention, the following formula is used to calculate the information carrying capacity of the access content in the shared data:
[0108]
[0109] Among them, C represents the information carrying capacity of the access content, n represents the total number of access contents, x ij represents the value of the i-th access content on the j-th shared data evaluation index, represents the average value of the evaluation index corresponding to the j-th shared data, m represents the total number of shared data evaluation indexes, i represents the index of the access content, and j represents the index of the shared data corresponding evaluation index.
[0110] S3. Based on the sharing rule, identify the data sharing request of the shared data, analyze the identity type corresponding to the data sharing request, where the identity type includes a data requester and a data provider, extract the identity authentication data corresponding to the identity type, and based on the identity authentication data, set the permission verification mechanism for the data sharing request.
[0111] In the embodiment of the present invention, by identifying the data sharing request of the shared data based on the sharing rule, the identity and permission of the requester can be automatically verified according to the sharing rule, ensuring that only users who meet the regulations can access and share data, improving the efficiency of data sharing, and accelerating the speed of data circulation.
[0112] Optionally, based on the sharing rule, the identification of the data sharing request of the shared data can be obtained through an automated workflow tool, such as the Pabb l y Connect tool.
[0113] Furthermore, by analyzing the identity type corresponding to the data sharing request in the embodiments of the present invention, it is possible to determine whether the party has the right to access specific data, help implement an effective identity verification mechanism, and be able to trace back to the original data provider in case of data leakage or disputes, realizing the definition of responsibilities. The identity type refers to the roles and qualifications of the requester and the provider in the data sharing and verification matching system.
[0114] Optionally, the analysis of the identity type corresponding to the data sharing request can be implemented by using an identity verification mechanism, such as verifying the identity of an organization or an individual through an official channel.
[0115] In the embodiments of the present invention, by extracting the identity verification data corresponding to the identity type, the true identities of the data requester and the provider can be confirmed, preventing impersonation and fraud behaviors, and ensuring that only legitimate users can access the data. The identity verification data refers to the information used to verify the identities of the data requester and the provider.
[0116] Optionally, the extraction of the identity verification data corresponding to the identity type can be obtained through an identity verification tool, such as an OAuth 2.0 tool.
[0117] Furthermore, in the embodiments of the present invention, by setting a permission verification mechanism for the data sharing request based on the identity verification data, the trust level inside and outside the system can be improved. Users can be convinced that the access and use of data are strictly controlled, thereby enhancing their confidence in the system. The permission verification mechanism refers to a verification mechanism for confirming the identity of the user or entity requesting to share data.
[0118] As an embodiment of the present invention, setting the permission verification mechanism for the data sharing request based on the identity verification data includes: extracting the original credential information of the data sharing request based on the identity verification data; identifying the input credential of the data sharing request and setting the maximum number of incorrect attempt times for the input credential; calculating the matching variable between the input credential and the original credential information; setting the access control permission for the data sharing request based on the matching variable; and setting the permission verification mechanism for the data sharing request according to the incorrect attempt times and the access control permission.
[0119] Among them, the original credential information refers to the credentials provided by the user during the identity verification process, such as the username and password. The input credential refers to the credential input by the user when attempting to access the shared data. The incorrect attempt times refer to the maximum number of times that limit the user's incorrect credential input within a certain period of time. The matching variable refers to the matching result variable between the input credential and the original credential information. The access control permission refers to the restriction on whether to allow the user to access specific resources or services set based on the calculation result of the matching variable.
[0120] Optionally, based on the authentication data, the extraction of the original credential information of the data sharing request can be collected and obtained by the authentication system when the user logs in. The identification of the input credential of the data sharing request can be implemented using an API. The setting of the number of error attempts for the input credential can be obtained through the number of errors recorded by the system. Based on the matching variable, the setting of the access control permission for the data sharing request can be implemented using an access control list.
[0121] In an optional embodiment of the present invention, the matching variable between the input credential and the original credential information is calculated using the following formula:
[0122]
[0123] Where match represents the matching variable between the input credential and the original credential information, H(password) represents the hash value of the input credential, and stored_hash represents the hash value of the stored original credential information. When the hash values of the input credential and the original credential information are equal, it indicates that the input credential and the original credential information match successfully, and match is 1; otherwise, it indicates that the input credential and the original credential information do not match, and match is 0.
[0124] S4. Extract the digital signature of the shared data from the authentication data, set the access level of the shared data according to the permission verification mechanism, and set the decryption interval of the shared data based on the digital signature and the access level.
[0125] In the embodiment of the present invention, by extracting the digital signature of the shared data from the authentication data, it can help record and audit data access behaviors, ensuring the transparency and traceability of the data processing process. The digital signature refers to a technology for verifying the authenticity and integrity of data generated through cryptographic techniques.
[0126] Optionally, the extraction of the digital signature of the shared data in the authentication data can be implemented using an asymmetric encryption algorithm.
[0127] Furthermore, in the embodiment of the present invention, by setting the access level of the shared data according to the permission verification mechanism, it can more effectively manage data access permissions, ensuring that the data is used by the appropriate personnel when needed, thereby improving the utilization efficiency of the data. The access level refers to the permission level required for accessing a specific resource.
[0128] Optionally, according to the permission verification mechanism, the setting of the access level of the shared data can be obtained through the data sensitivity level and user identity information. For example, senior management personnel may have extensive access permissions to sensitive data, while ordinary employees may only have limited access permissions.
[0129] In an embodiment of the present invention, by setting a decryption interval for the shared data based on the digital signature and the access level, the confidentiality of the data during transmission and storage can be ensured, unauthorized access can be prevented, and the means for potential attackers to obtain sensitive data can be restricted, improving the security of data sharing and the user experience. The decryption interval refers to the range within which the data, after being encrypted, can be decrypted and accessed only under specific conditions or permissions.
[0130] As an embodiment of the present invention, setting the decryption interval for the shared data based on the digital signature and the access level includes: authenticating the digital signature to obtain an authentication result; determining the scope of permissions of the access level according to the authentication result; analyzing the permission request for the shared data in combination with the authentication result and the scope of permissions; setting a decryption key corresponding to the permission request; and setting the decryption interval for the shared data based on the permission request and the decryption key.
[0131] Among them, the authentication result refers to the user identity verification result obtained after the user passes the authentication. The scope of permissions refers to the range of data that the user can access or operations that the user can perform according to their access level. The permission request refers to the request for the user to access specific data. The decryption key refers to the key used to decrypt the encrypted data.
[0132] Optionally, the authentication of the digital signature can be obtained through biometric means. The determination of the scope of permissions of the access level according to the authentication result can be achieved by using the access control policy of the system. The setting of the decryption key corresponding to the permission request can be generated by a key management system.
[0133] S5. Extract the decrypted data in the decryption interval, calculate the matching degree between the decrypted data and the data sharing request, and analyze the sharing verification result of the technical database according to the matching degree.
[0134] In an embodiment of the present invention, by extracting the decrypted data in the decryption interval and calculating the matching degree between the decrypted data and the data sharing request, it can be verified whether the decryption process is successful and whether the decrypted data is intact, enhancing the security of the data. The decrypted data refers to the data that has been restored to its original state after being encrypted. The matching degree refers to the consistency or similarity in content, format, purpose, etc. between the decrypted data and the data sharing request.
[0135] Optionally, the extraction of the decrypted data in the decryption interval can be achieved through a decryption tool, such as the third-party tool Passware Kit.
[0136] In an alternative embodiment of the present invention, the matching degree between the decrypted data and the data sharing request is calculated using the following formula:
[0137]
[0138] where cos(q,z) represents the matching degree between the decrypted data and the data sharing request, q represents the feature vector of the decrypted data, z represents the feature vector of the data sharing request, q ’ represents the element of the decrypted data, and z' represents the element of the data sharing request.
[0139] Furthermore, by analyzing the sharing verification result of the technical database according to the matching degree, the embodiment of the present invention can quickly respond to the needs of the requester, provide the data required by the requesting party, improve the efficiency of data sharing, meet the immediate needs of users or systems, and at the same time can better manage and utilize data resources, and improve the trust level between the data provider and the requester. The sharing verification result refers to the conclusion or result obtained from a series of verification tests on the information in the technical database during the data sharing process.
[0140] Optionally, the analysis of the sharing verification result of the technical database according to the matching degree can be implemented using a multi-cloud data management platform, such as the NineData platform.
[0141] It can be seen that in the embodiments of the present invention, by obtaining the technical database to be shared and identifying the data content in the technical database, information such as the type, structure, and value of the data can be understood, providing a data source for subsequent data sharing, verification, and matching, and improving the efficiency and scalability of data sharing; in the embodiments of the present invention, by setting the sharing rules of the shared data based on the query verification method and the query index, accurate matching between the query request and the shared data can be ensured. During the data sharing process, through the sharing rules, orderly data exchange and sharing can be carried out between different data providers and users, breaking data islands, promoting data circulation and integration, and thus mining more data value; in the embodiments of the present invention, by setting the permission verification mechanism for the data sharing request based on the identity verification data, the trust degree inside and outside the system can be improved, and users can be convinced that the access and use of data are strictly controlled, thereby enhancing confidence in the system; further, in the embodiments of the present invention, by setting the decryption interval of the shared data based on the digital signature and the access level, the confidentiality of the data during transmission and storage can be ensured, preventing unauthorized access, and restricting the means for potential attackers to obtain sensitive data, improving the security and user experience of data sharing; in the embodiments of the present invention, by extracting the decryption data in the decryption interval and calculating the matching degree between the decryption data and the data sharing request, it can be verified whether the decryption process is successful and whether the decrypted data is intact, enhancing data security; further, in the embodiments of the present invention, by analyzing the sharing verification result of the technical database according to the matching degree, the needs of the requester can be quickly responded to, the data required by the requesting party can be provided, the efficiency of data sharing can be improved, the immediate needs of users or the system can be met, and at the same time, data resources can be better managed and utilized, and the trust degree between the data provider and the requestor can be improved. Therefore, the method for sharing, verifying, and matching a technical database based on blockchain technology proposed in the embodiments of the present invention can ensure the security of data sharing and improve the trust degree between the data provider and the data requestor.
[0142] As Figure 2 shown, it is the system functional module diagram of the sharing, verifying, and matching of the technical database based on blockchain technology of the present invention.
[0143] The technology database sharing and verification matching system 200 based on blockchain technology according to the present invention can be installed in an electronic device. According to the functions achieved, the technology database sharing and verification matching system based on blockchain technology may include a shared data generation module 201, a data encryption module 202, an authority verification module 203, a data decryption module 204, and a verification matching module 205. The modules in the present invention can also be referred to as units, which refer to a series of computer program segments that can be executed by a processor of an electronic device and can complete fixed functions, and are stored in the memory of the electronic device.
[0144] In the embodiments of the present invention, the functions of each module / unit are as follows:
[0145] The shared data generation module 201 is used to obtain the technology database to be shared, identify the data content in the technology database, perform hash processing on the data content to generate hash data, collect the metadata record of the technology database, and determine the shared data of the technology database based on the hash data and the metadata record;
[0146] The data encryption module 202 is used to identify the data type of the shared data, analyze the data sensitivity degree of the shared data, encrypt the shared data based on the data type and the data sensitivity degree to obtain encrypted shared data, set the query verification method and query index of the encrypted shared data, and set the sharing rule of the shared data based on the query verification method and the query index;
[0147] The authority verification module 203 is used to identify the data sharing request of the shared data based on the sharing rule, analyze the identity type corresponding to the data sharing request, where the identity type includes a data requestor and a data provider, extract the identity verification data corresponding to the identity type, and set the authority verification mechanism of the data sharing request based on the identity verification data;
[0148] The data decryption module 204 is used to extract the digital signature of the shared data from the identity verification data, set the access level of the shared data according to the authority verification mechanism, and set the decryption interval of the shared data based on the digital signature and the access level;
[0149] The verification matching module 205 is used to extract the decryption data in the decryption interval, calculate the matching degree between the decryption data and the data sharing request, and analyze the sharing verification result of the technology database according to the matching degree.
[0150] Specifically, each module in the technology database sharing and verification matching system 200 based on blockchain technology in the embodiments of the present invention adopts the same as the aboveFigure 1 The technical means are the same as those of the method for sharing and verifying matching of a technical database based on blockchain technology described in [reference], and can produce the same technical effects, which will not be elaborated here.
Claims
1. A method for sharing and verifying matching of a technical database based on blockchain technology, characterized in that the method Including: S1. Obtain the technical database to be shared, identify the data content in the technical database, perform hashing processing on the data content to generate hash data, collect the metadata records of the technical database, and determine the shared data of the technical database based on the hash data and the metadata records; the metadata record refers to the summary record describing the data content in the technical database, including data attributes, data ownership, and data status. S2. Identify the data type of the shared data, analyze the data sensitivity level of the shared data, and perform encryption processing on the shared data based on the data type and the data sensitivity level to obtain encrypted shared data. Set the query verification method and query index of the encrypted shared data, and set the sharing rules of the shared data based on the query verification method and the query index. S3. Based on the sharing rules, identify the data sharing requests of the shared data, analyze the identity types corresponding to the data sharing requests, where the identity types include data requestors and data providers, extract the identity verification data corresponding to the identity types, and set the permission verification mechanism for the data sharing requests based on the identity verification data. S4. Extract the digital signature of the shared data from the identity verification data, set the access level of the shared data according to the permission verification mechanism, and set the decryption interval of the shared data based on the digital signature and the access level. S5. Extract the decryption data in the decryption interval, calculate the matching degree between the decryption data and the data sharing request, and analyze the sharing verification result of the technical database according to the matching degree. In S2, it specifically includes: Perform functional partitioning on the shared data to obtain classified functions; set the classification code of the shared data based on the classified functions; extract the metadata records in the shared data; identify the data type of the shared data based on the metadata records and the classification code. Extract the data attributes corresponding to the shared data, and set the sensitivity score corresponding to the data attributes; set the hierarchical level of the shared data according to the sensitivity score and the data attributes; analyze the potential impact corresponding to the data attributes based on the hierarchical level; analyze the data sensitivity level of the shared data by combining the sensitivity score and the potential impact. Analyze the applicable scenarios of the shared data based on the data type and the data sensitivity level; set the encryption method of the shared data according to the applicable scenarios; identify the key management mechanism corresponding to the encryption method; perform encryption processing on the shared data based on the encryption method and the key management mechanism to obtain encrypted shared data. Perform data classification on the encrypted shared data to obtain classified data; analyze the query frequency corresponding to the classified data, and extract the query fields of the classified data according to the query frequency; create an encrypted index for the query fields, and identify the query conditions of the query fields; set the matching answers corresponding to the query conditions in the encrypted index; set the verification method for the matching answers; set the query index of the encrypted shared data based on the encrypted index and the verification method.
2. The method according to claim 1, characterized in that, Determine the shared data of the technical database based on the hash data and the metadata records, including: Identify the data trading pool of the technical database based on the hash data and the metadata records. Extract the trading data in the data trading pool, and set the trading block of the trading data. Calculate the hash value of the transaction data in the transaction block and set the satisfaction condition of the hash value; Based on the satisfaction condition, set the block propagation method of the transaction data; Create a blockchain copy of the transaction data according to the block propagation method and the transaction block; Based on the blockchain copy, determine the shared data of the technical database; 3. The method according to claim 1, wherein Based on the query verification method and the query index, set the sharing rules of the shared data, including: Based on the query verification method and the query index, identify the access group and access content corresponding to the shared data; Calculate the information carrying capacity of the access content in the shared data; According to the information carrying capacity, set the access permission of the access group; Identify the identity level of the access group, and based on the identity level, set the permission level of the access permission; According to the permission level, define the access condition of the shared data; Combine the permission level and the access condition to set the sharing rules of the shared data; 4. The method according to claim 1, wherein Based on the identity verification data, set the permission verification mechanism for the data sharing request, including: Based on the identity verification data, extract the original voucher information of the data sharing request; Identify the input voucher of the data sharing request and set the number of error attempts of the input voucher; Calculate the matching variable between the input voucher and the original voucher information; Based on the matching variable, set the access control permission of the data sharing request; According to the number of error attempts and the access control permission, set the permission verification mechanism of the data sharing request; 5. The method according to claim 1, wherein Based on the digital signature and the access level, set the decryption interval of the shared data, including: Authenticate the digital signature to obtain the identity verification result; According to the identity verification result, determine the permission range of the access level; Combine the identity verification result and the permission range to analyze the permission request of the shared data; Set the decryption key corresponding to the permission request; Based on the permission request and the decryption key, set the decryption interval of the shared data; 6. A technical database sharing and verification matching system based on blockchain technology, which implements the method described in claim 1, characterized in that, The system includes: A shared data generation module, configured to obtain the technical database to be shared, identify the data content in the technical database, perform hash processing on the data content to generate hash data, collect the metadata records of the technical database, and determine the shared data of the technical database based on the hash data and the metadata records; A data encryption module, configured to identify the data type of the shared data, analyze the data sensitivity of the shared data, and based on the data type and the data sensitivity, perform encryption processing on the shared data to obtain encrypted shared data, set the query verification method and the query index of the encrypted shared data, and set the sharing rules of the shared data based on the query verification method and the query index; A permission verification module, configured to identify the data sharing request of the shared data based on the sharing rules, analyze the identity type corresponding to the data sharing request, where the identity type includes a data requester and a data provider, extract the identity verification data corresponding to the identity type, and set the permission verification mechanism of the data sharing request based on the identity verification data; A data decryption module, configured to extract the digital signature of the shared data from the identity verification data, set the access level of the shared data according to the permission verification mechanism, and set the decryption interval of the shared data based on the digital signature and the access level; A verification matching module is used to extract the decrypted data in the decryption interval, calculate the matching degree between the decrypted data and the data sharing request, and analyze the sharing verification result of the technical database according to the matching degree.
Citation Information
Patent Citations
Civil air defense data sharing system and method based on block chain
CN112511599A
Identification analysis data security sharing system and method based on optimized Shiro framework
CN118611919A