A tamper-proof method and system for an integrated system based on blockchain
Through the tamper-proof method of integrated system based on blockchain, combined with hash encryption and signature technology, the Hfish honeypot chain network and data tamper detection model are deployed, which solves the security problems of data transmission and storage in the integrated system, and realizes efficient tamper-proof and reliable data transmission.
Patent Information
- Application Number
- CN202411363109.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-27
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2044-09-27
AI Technical Summary
The existing integrated systems have low practicality, low storage reliability and low transmission security in data transmission and storage, and lack effective protection measures.
The blockchain-based anti-tampering method is adopted, and the blockchain network, Hfish honeypot chain network and data tampering detection model are deployed through key generation and identity registration. The hash encryption and signature technology is combined to carry out encryption processing of data storage and transmission, and the network interception detection model is used for security monitoring.
It improves the security protection level of data storage and transmission, enhances the immutability of data and transmission security, and ensures data integrity.
Smart Images

Figure CN119210683B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data security, and particularly relates to a method and system for preventing tampering of an integrated system based on blockchain. Background Art
[0002] With the rapid development of information technology, data security has become the focus of attention for enterprises and individuals. In the existing integrated system, during the processes of data transmission, storage, and processing, it is vulnerable to malicious tampering and attacks, resulting in low data security and inability to guarantee data integrity. In order to ensure data security and integrity, it is necessary to study an effective method for preventing tampering of the integrated system.
[0003] The existing methods for preventing tampering of integrated systems have the following defects:
[0004] 1) In the prior art, only simple hash value verification technology is used for integrity verification, lacking more effective anti-tampering measures and having low practicality;
[0005] 2) During the data storage process of the integrated system, due to the low protection level of the local storage database, it is vulnerable to illegal intrusion, resulting in tampering of key data and low storage reliability;
[0006] 3) During the data transmission process of the integrated system, it is often in plain text form, which is easily intercepted maliciously, resulting in low transmission security. Summary of the Invention
[0007] In order to solve the problems of low practicality of the anti-tampering technology, low storage reliability, and low transmission security existing in the prior art, the purpose of the present invention is to provide a method and system for preventing tampering of an integrated system based on blockchain.
[0008] The technical solution adopted by the present invention is as follows:
[0009] A method for preventing tampering of an integrated system based on blockchain includes the following steps:
[0010] Based on a trusted institution, generate keys and perform identity registration for the integrated system to obtain the public-private key pair and signature information of the integrated system, send the private key in the public-private key pair and the signature information to the integrated system, and publish the public key in the public-private key pair to all data query terminals communicatively connected to the integrated system;
[0011] Based on the integrated system, divide the data storage area into an internal area and an external area, deploy a blockchain network in the internal area, deploy an Hfish honeypot chain network and a data tampering detection model in the external area, and deploy a network interception detection model according to the network channels through which the integrated system is communicatively connected to the data query terminals;
[0012] Generate the data hash value of the internal system data, and encrypt and sign the internal system data based on the data hash value, private key, and signature information to obtain the encrypted internal system data and signature data, and use the blockchain network to store the encrypted internal system data and data hash value on the chain;
[0013] Receive the query information sent by the data query terminal, obtain the query hash value of the query information, retrieve and match the corresponding target data hash value in the blockchain network, and extract the target encrypted internal system data corresponding to the target data hash value;
[0014] Use the Hfish honeypot chain network to collect the access behavior traffic of the data query terminal accessing the blockchain network, and use the data tampering detection model to detect the data tampering of the access behavior traffic to obtain the data tampering detection result;
[0015] Transmit the target data hash value, the target encrypted internal system data, and the corresponding target signature data to the data query terminal, collect the network transmission data of the network channel, and use the network interception detection model to detect the network interception of the network transmission data to obtain the network interception detection result;
[0016] Based on the data query terminal, call a trusted agency to verify the signature of the target signature data. After the signature verification passes, decrypt the target encrypted internal system data according to the target data hash value and the public key of the integrated system to obtain the decrypted internal system data;
[0017] Generate the decryption data hash value of the decrypted internal system data, verify the integrity of the decryption data hash value and the target data hash value, and perform a visual display of the decrypted internal system data after the integrity verification passes.
[0018] Furthermore, based on the integrated system, divide the data storage area into an internal area and an external area, deploy a blockchain network in the internal area, deploy an Hfish honeypot chain network and a data tampering detection model in the external area, and deploy a network interception detection model according to the network channel through which the integrated system communicates with the data query terminal, including the following steps:
[0019] Based on the integrated system, divide the data storage area into an internal area and an external area, and set up a firewall between the internal area and the external area;
[0020] In the internal area, connect several data servers distributively, set up an IPFS system and a smart contract, and deploy a blockchain network;
[0021] According to the system information of the data server, construct corresponding Hfish honeypots in the external area, deploy the Hfish honeypot management module, connect all Hfish honeypots, and deploy the Hfish honeypot chain network;
[0022] Deploy a data tampering detection model in the Hfish honeypot management module, set traffic probes in each Hfish honeypot, and connect all traffic probes to the data tampering detection model;
[0023] Deploy a network interception detection model in the external area, set data probes in the network channel where the integrated system communicates with the data query terminal, and connect all data probes to the network interception detection model.
[0024] Furthermore, generate the data hash value of the internal system data, and encrypt and sign the internal system data according to the data hash value, private key, and signature information to obtain the encrypted internal system data and signature data, and use the blockchain network to store the encrypted internal system data and data hash value on the chain, including the following steps:
[0025] Collect the internal system data based on the external area, and use the SHA-3 algorithm to generate the data hash value of the internal system data;
[0026] Concatenate the data hash value with the private key to obtain a mixed encryption key, and encrypt the internal system data using an asymmetric encryption algorithm according to the mixed encryption key to obtain the encrypted internal system data;
[0027] Sign the internal system data using digital identity signature technology according to the signature information to obtain the signature data of the encrypted internal system data;
[0028] Transmit the encrypted internal system data and data hash value to the internal area, and use the blockchain network to store the encrypted internal system data and data hash value on the chain.
[0029] Furthermore, transmit the encrypted internal system data and data hash value to the internal area, and use the blockchain network to store the encrypted internal system data and data hash value on the chain, including the following steps:
[0030] Transmit the encrypted internal system data and data hash value to the internal area, store the encrypted internal system data in the IPFS system of the blockchain network, and generate a storage address and a storage hash value;
[0031] Perform tampering verification on the storage hash value and the data hash value. After the tampering verification passes, use the smart contract of the blockchain network to generate a storage request and transaction data according to the data hash value and the storage address;
[0032] Store the data hash value and the corresponding storage address in the distributed ledger, and publish the distributed ledger to the blockchain network;
[0033] Send the storage request and transaction data to several nodes in the blockchain network, conduct consensus on the storage request, and after the consensus is passed, package the transaction data into a data block and link it to the chain.
[0034] Further, send the storage request and transaction data to several nodes in the blockchain network, use the PBFT consensus algorithm to conduct consensus on the storage request, and after the consensus is passed, package the transaction data into a data block and link it to the chain.
[0035] Further, receive the query information sent by the data query terminal, obtain the query hash value of the query information, and retrieve and match the corresponding target data hash value in the blockchain network according to the query hash value, and extract the target encrypted internal system data corresponding to the target data hash value, including the following steps:
[0036] Based on the data query terminal, encrypt the query information and user login information according to the public key of the integrated system to obtain the encrypted query information and encrypted user login information, and upload them to the integrated system;
[0037] Based on the integrated system, decrypt the encrypted query information and encrypted user login information according to the private key to obtain the decrypted query information and decrypted user login information;
[0038] Conduct login verification on the decrypted user login information. After the login verification is passed, use the SHA-3 algorithm to obtain the query hash value of the query information;
[0039] Retrieve and match in the distributed ledger of the blockchain network, obtain the Euclidean distance between the query hash value and each data hash value, and use the data hash value with the closest Euclidean distance as the target data hash value;
[0040] According to the target storage address corresponding to the target data hash value in the distributed ledger, extract the target encrypted internal system data corresponding to the target data hash value.
[0041] Further, the data tampering detection model includes N key dimension feature extraction modules constructed based on the GAN algorithm and a data tampering detection module constructed based on the MLP algorithm;
[0042] The network interception detection model includes a network signal dynamic module and a network interception detection module constructed based on the BiLSTM algorithm.
[0043] Further, use the Hfish honeypot chain network to collect the access behavior traffic of the data query terminal accessing the blockchain network, and use the data tampering detection model to perform data tampering detection on the access behavior traffic to obtain the data tampering detection result, including the following steps:
[0044] Use the traffic probe of the Hfish honeypot chain network to collect the access behavior traffic of the data query terminal accessing the blockchain network, and input the access behavior traffic into the data tampering detection model;
[0045] Use the key dimension feature extraction module of the data tampering detection model to extract N key dimension features of the access behavior traffic;
[0046] Use the data tampering detection module of the data tampering detection model to perform feature fusion on the N key dimension features to obtain the fusion feature;
[0047] Perform data tampering detection based on the fusion feature to obtain the data tampering detection result;
[0048] If the data tampering detection result indicates that there is a data tampering behavior, then close the firewall, disconnect the network channel, end the data storage, and add the data query terminal to the blacklist. Otherwise, enter the data transmission step.
[0049] Further, transmit the target data hash value, the target encrypted system internal data, and the corresponding target signature data to the data query terminal, collect the network transmission data of the network channel, and use the network interception detection model to perform network interception detection on the network transmission data to obtain the network interception detection result, including the following steps:
[0050] Transmit the target data hash value, the target encrypted system internal data, and the corresponding target signature data to the data query terminal through the corresponding network channel;
[0051] Use the data probe set in the network channel to collect the network transmission data of the network channel, and input the network transmission data into the network interception detection model;
[0052] Generate network signal dynamic data according to the network transmission data using the network signal dynamic module of the network interception detection model;
[0053] Perform network interception detection according to the network signal dynamic data using the network interception detection module of the network interception detection model to obtain the network interception detection result;
[0054] If the network interception detection result indicates that there is a network interception behavior, then disconnect the network channel and stop the data transmission. Otherwise, enter the signature verification step.
[0055] A tamper-proof system for an integrated system based on blockchain is used to implement a tamper-proof method for the integrated system. The tamper-proof system for the integrated system includes an integrated system, a trusted institution, and several data query terminals. Both the integrated system and the trusted institution are respectively communicatively connected to the several data query terminals, and the integrated system is communicatively connected to the trusted institution.
[0056] The beneficial effects of the present invention are as follows:
[0057] The present invention discloses a tamper-proof method and system for an integrated system based on blockchain, introducing the characteristics of decentralization and data immutability of blockchain technology, combining hash eigenvalues for integrity verification, and improving the practicality of tamper-proof technology; using the Hfish honeypot chain network and data tampering detection model for data tampering detection, and using the network interception detection model to perform network interception detection on the network channel, strengthening the security protection level of data storage and data transmission, and improving the reliability of storage and transmission; during the data transmission process, combining digital identity signature technology and asymmetric encryption algorithm, transmitting data in ciphertext form, and performing double encryption, improving the transmission security.
[0058] Other beneficial effects of the present invention will be further described in the specific implementation manner. Description of the Drawings
[0059] Figure 1 is a flowchart of the tamper-proof method for an integrated system based on blockchain in the present invention.
[0060] Figure 2 is a structural block diagram of the tamper-proof system for an integrated system based on blockchain in the present invention. Specific Embodiment
[0061] The following further explains the present invention in conjunction with the drawings and specific embodiments.
[0062] Embodiment 1:
[0063] As Figure 1 shown, this embodiment provides a tamper-proof method for an integrated system based on blockchain, including the following steps:
[0064] S1: Based on the trusted institution, generate keys and perform identity registration for the integrated system to obtain the public and private key pairs and signature information of the integrated system, send the private key in the public and private key pairs and the signature information to the integrated system, and publish the public key in the public and private key pairs to all data query terminals communicatively connected to the integrated system, including the following steps:
[0065] S1-1: Based on the trusted institution, perform key initialization to obtain public parameters, a master key, and an initial key;
[0066]
[0067] In the formula, is a common parameter; is the master key; is the initial key; is the integer domain random number; are all target hash functions; are all cyclic groups random numbers of the generators; is a random number bilinear mapping;
[0068] S1-2: Collect the attribute information of the integrated system , and according to the attribute information, common parameter, master key, and initial key, use the asymmetric encryption algorithm to generate keys for the integrated system to obtain the corresponding public and private key pairs;
[0069]
[0070] In the formula, is the integrated system private key; is the integer domain random number; is the private key parameter of the integrated system; is the common parameter target hash function; is the integrated system indicator; is the master key; is the initial key; is the integrated system public key; is the cyclic group random number of the generator; is the integrated system attribute information;
[0071] S1-3: According to the public and private key pairs and the entity ID of the integrated system , use the digital identity authentication method to perform identity registration to obtain the signature information of the integrated system;
[0072] The formula is:
[0073]
[0074] In the formula, is a random number; is the registration parameter of the integrated system ; is the registration ID of the integrated system ; and the corresponding constitute the signature information ; is the target hash function; is the integrated system entity ID; is the prime order; is the prime field base point;
[0075] S1-4: Send the private key in the public-private key pair and the signature information to the integrated system, and publish the public key in the public-private key pair to all data query terminals communicatively connected to the integrated system;
[0076] S2: Based on the integrated system, divide the data storage area into an internal area and an external area, deploy a blockchain network in the internal area, deploy an Hfish (a cross-platform multi-functional active induced open source honeypot framework system) honeypot chain network and a data tampering detection model in the external area, and deploy a network interception detection model according to the network channels through which the integrated system communicates with the data query terminals, including the following steps:
[0077] S2-1: Based on the integrated system, divide the data storage area into an internal area and an external area, and set up a firewall between the internal area and the external area;
[0078] S2-2: In the internal area, connect several data servers distributively, set up an IPFS system and a smart contract, and deploy a blockchain network;
[0079] S2-3: According to the system information of the data servers, construct corresponding Hfish honeypots in the external area, deploy an Hfish honeypot management module, and connect all Hfish honeypots to deploy an Hfish honeypot chain network;
[0080] S2-4: Deploy a data tampering detection model in the Hfish honeypot management module, set up traffic probes in each Hfish honeypot, and connect all traffic probes to the data tampering detection model;
[0081] The data tampering detection model includes N key dimension feature extraction modules constructed based on the Generative Adversarial Network (GAN) algorithm and a data tampering detection module constructed based on the Multilayer Perceptron (MLP) algorithm, where N is the total number of concerned dimensions;
[0082] The concerned dimensions include the access frequency dimension, the access time dimension, and the access behavior dimension, etc.;
[0083] The GAN network includes a generator and a discriminator. The generator is responsible for generating traffic data features from the latent space, and the discriminator is responsible for judging the authenticity of the traffic data features. By adding the recognition of traffic data to the discriminator, it can not only judge the authenticity of the traffic data, but also judge whether it conforms to the traffic data features. By extracting the features of traffic data from different dimensions, multi-angle analysis is achieved, improving the comprehensiveness of data tampering detection. The MLP network fuses the multi-angle traffic data features, improving the characterization ability of traffic data features for data information and the accuracy of data tampering detection;
[0084] S2-5: Deploy the network interception detection model in the external area, set data probes in the network channel where the integrated system is communicatively connected to the data query terminal, and connect all data probes to the network interception detection model;
[0085] The network interception detection model includes a network signal dynamic module and a network interception detection module constructed based on the Bidirectional Long Short-Term Memory (BiLSTM) algorithm;
[0086] The network signal dynamic module includes a signal quality dynamic sub-model, a data transmission rate dynamic sub-model, a network delay dynamic sub-model, and a network stability dynamic sub-model;
[0087] The formula of the signal quality dynamic sub-model is:
[0088]
[0089] In the formula, is the signal quality detection function; is the signal quality calculation function; is the received signal strength value;
[0090] The formula of the data transmission rate dynamic sub-model is:
[0091]
[0092] In the formula, is the data transmission detection function; is the amount of transmitted data; is the transmission time;
[0093] The formula of the network delay dynamic sub-model is:
[0094]
[0095] In the formula, is the network delay detection function; is the sending time; is the signal propagation time; is the signal processing time;
[0096] The formula of the network stability dynamic sub-model is:
[0097]
[0098] In the formula, is the network stability detection function; is the number of network interruptions; is the total number of connection attempts;
[0099] By collecting network transmission data such as the received signal strength value, transmitted data volume, transmission time, sending time, signal propagation time, signal processing time, number of network interruptions, and total number of connection attempts of the network channel, and using the above dynamic model, the corresponding network signal dynamic data is obtained. The network signal dynamic data can characterize the network quality and signal strength of the network channel, and implicitly contains the deep information of the network interception situation. The BiLSTM network learns the characteristics of the network signal dynamic data through the deep structure, mines the potential relationship between the data characteristics and the network interception situation, and realizes the detection and analysis of the network interception situation;
[0100] S3: Generate the data hash value of the system internal data, and encrypt and sign the system internal data according to the data hash value, private key, and signature information to obtain the encrypted system internal data and signature data, and use the blockchain network to store the encrypted system internal data and data hash value on the chain, including the following steps:
[0101] S3-1: Based on the external area, collect the system internal data, and use the SHA-3 (Secure Hash Algorithm 3) algorithm to generate the data hash value of the system internal data;
[0102] S3-2: Concatenate the data hash value with the private key to obtain the mixed encryption key , and encrypt the system internal data using the asymmetric encryption algorithm according to the mixed encryption key to obtain the encrypted system internal data;
[0103] The formula is:
[0104]
[0105] In the formula, is the encrypted system internal data; is the asymmetric encryption function; is the system internal data; is the integrated system The private key; is the data hash value; is the hybrid encryption key;
[0106] S3-3: According to the signature information, use the digital identity signature technology to sign the internal data of the system to obtain the signature data of the encrypted internal data of the system;
[0107]
[0108] In the formula, is a random number; is the prime order; is the prime field base point; is the target hash hash function; is the signature information in the integrated system registration parameters; is the signature information in the integrated system registration ID; is the integrated system entity ID; The signature data formed is ; Integrated system signature parameters;
[0109] S3-4: Transmit the encrypted internal data of the system and the data hash value to the internal area, and use the blockchain network to store the encrypted internal data of the system and the data hash value on the chain, including the following steps:
[0110] S3-4-1: Transmit the encrypted internal data of the system and the data hash value to the internal area, store the encrypted internal data of the system in the Inter Planetary File System (IPFS) of the blockchain network, and generate a storage address and a storage hash value;
[0111] S3-4-2: Perform tampering verification on the storage hash value and the data hash value. After the tampering verification passes, use the smart contract of the blockchain network to generate a storage request and transaction data according to the data hash value and the storage address;
[0112] If the storage hash value is consistent with the data hash value, the tampering verification passes, otherwise, it fails;
[0113] S3-4-3: Store the data hash value and the corresponding storage address in the distributed ledger, and publish the distributed ledger to the blockchain network;
[0114] S3-4-4: Send the storage request and transaction data to several nodes in the blockchain network, and use the Practical Byzantine Fault Tolerance (PBFT) consensus algorithm to conduct consensus on the storage request. After the consensus is passed, pack the transaction data into a data block and link it to the chain, including the following steps:
[0115] S3-4-4-1: Use an integrated hierarchical mechanism to divide all nodes in the blockchain network into a consensus layer, a confirmation layer, and a supervision layer;
[0116] S3-4-4-2: Send the storage request and transaction data to several consensus nodes in the consensus layer, and use the consensus nodes that receive the storage request and transaction data as the primary nodes;
[0117] S3-4-4-3: Based on the primary nodes, verify the correctness of the storage request. After the verification is successful, broadcast a pre-prepare message to other consensus nodes;
[0118] S3-4-4-4: Based on the consensus nodes, verify the validity of the received pre-prepare message, record the pre-prepare message locally. If the number of pre-prepare messages reaches 2 f +1, enter the prepare phase, and broadcast a prepare message to other consensus nodes, indicating acceptance of the sequence number request; where f is the number of Byzantine nodes;
[0119] S3-4-4-5: Based on the consensus nodes, if the number of prepare messages reaches 2 f +1, enter the commit phase, and broadcast a commit message to other consensus nodes to synchronize the states of all nodes within the consensus layer;
[0120] S3-4-4-6: Based on the consensus nodes, if the number of commit messages reaches 2 f +1, the first consensus is successful, enter the next step, otherwise, return a consensus failure signal and end the consensus;
[0121] S3-4-4-7: Based on the primary nodes, broadcast a pre-prepare message to all nodes in the confirmation layer and conduct a second consensus process. If the second consensus is successful, enter the next step, otherwise, return a consensus failure signal and end the consensus;
[0122] S3-4-4-8: Based on the primary nodes, pack the transaction data into a data block and link the data block to the chain;
[0123] S4: Receive the query information sent by the data query terminal, obtain the query hash value of the query information, and retrieve and match the corresponding target data hash value in the blockchain network according to the query hash value, and extract the target encrypted internal system data corresponding to the target data hash value, including the following steps:
[0124] S4-1: Based on the data query terminal, encrypt the query information and the user login information according to the public key of the integrated system to obtain the encrypted query information and the encrypted user login information, and upload them to the integrated system;
[0125] S4-2: Based on the integrated system, decrypt the encrypted query information and the encrypted user login information according to the private key to obtain the decrypted query information and the decrypted user login information;
[0126] S4-3: Perform login verification on the decrypted user login information. After the login verification passes, use the SHA-3 algorithm to obtain the query hash value of the query information;
[0127] S4-4: Retrieve and match in the distributed ledger of the blockchain network, obtain the Euclidean distance between the query hash value and each data hash value, and use the data hash value with the closest Euclidean distance as the target data hash value;
[0128] S4-5: According to the target storage address corresponding to the target data hash value in the distributed ledger, extract the target encrypted internal system data corresponding to the target data hash value;
[0129] S5: Use the Hfish honeypot chain network to collect the access behavior traffic of the data query terminal accessing the blockchain network, and use the data tampering detection model to perform data tampering detection on the access behavior traffic to obtain the data tampering detection result, including the following steps:
[0130] S5-1: Use the traffic probe of the Hfish honeypot chain network to collect the access behavior traffic of the data query terminal accessing the blockchain network, and input the access behavior traffic into the data tampering detection model;
[0131] S5-2: Use the key dimension feature extraction module of the data tampering detection model to extract N key dimension features of the access behavior traffic;
[0132] S5-3: Use the data tampering detection module of the data tampering detection model to perform feature fusion on the N key dimension features to obtain the fusion features;
[0133] S5-4: Perform data tampering detection according to the fusion features to obtain the data tampering detection result;
[0134] S5-5: If the data tampering detection result indicates that there is a data tampering behavior, then turn off the firewall, disconnect the network channel, end data storage, and add the data query terminal to the blacklist; otherwise, proceed to the data transmission step;
[0135] S6: Transmit the target data hash value, the target encrypted internal system data, and the corresponding target signature data to the data query terminal, collect the network transmission data of the network channel, and use the network interception detection model to perform network interception detection on the network transmission data to obtain the network interception detection result, including the following steps:
[0136] S6-1: Transmit the target data hash value, the target encrypted internal system data, and the corresponding target signature data to the data query terminal through the corresponding network channel;
[0137] S6-2: Use the data probe set in the network channel to collect the network transmission data of the network channel and input the network transmission data into the network interception detection model;
[0138] S6-3: Generate network signal dynamic data according to the network transmission data using the network signal dynamic module of the network interception detection model;
[0139] S6-4: Perform network interception detection according to the network signal dynamic data using the network interception detection module of the network interception detection model to obtain the network interception detection result;
[0140] S6-5: If the network interception detection result indicates that there is a network interception behavior, then disconnect the network channel and stop data transmission; otherwise, proceed to the signature verification step;
[0141] S7: Based on the data query terminal, call a trusted institution to perform signature verification on the target signature data. After the signature verification passes, decrypt the target encrypted internal system data according to the target data hash value and the public key of the integrated system to obtain the decrypted internal system data;
[0142] The formula is:
[0143]
[0144] In the formula, is the signature verification parameter of the integrated system ; is the public key of the integrated system ; if the left side of the equation is equal to the right side, then the signature verification passes; is the target encrypted internal system data;
[0145]
[0146] In the formula, is the internal data of the system after decryption; is the asymmetric decryption function; is the internal data of the target encrypted system; is the integrated system public key; is the hybrid decryption key; is the hash eigenvalue;
[0147] S8: Generate the decryption data hash value of the internal data of the decrypted system, verify the integrity of the decryption data hash value and the target data hash value. After the integrity verification passes, visually display the internal data of the decrypted system;
[0148] If the decryption data hash value is consistent with the target data hash value, the integrity verification passes; otherwise, it fails.
[0149] Embodiment 2:
[0150] As Figure 2 shown, this embodiment provides an anti-tampering system for an integrated system based on blockchain, which is used to implement the anti-tampering method of the integrated system. The anti-tampering system of the integrated system includes an integrated system, a trusted institution, and several data query terminals. The integrated system and the trusted institution are respectively communicatively connected to several data query terminals, and the integrated system is communicatively connected to the trusted institution;
[0151] The trusted institution is used to generate keys and register the identity of the integrated system, obtain the public and private key pairs and signature information of the integrated system, send the private key and signature information in the public and private key pairs to the integrated system, and publish the public key in the public and private key pairs to all data query terminals communicatively connected to the integrated system;
[0152] The data query terminal is used to call the trusted institution to verify the signature of the target signature data. After the signature verification passes, decrypt the target encrypted internal data of the system according to the target data hash value and the public key of the integrated system to obtain the internal data of the decrypted system; generate the decryption data hash value of the internal data of the decrypted system, verify the integrity of the decryption data hash value and the target data hash value. After the integrity verification passes, visually display the internal data of the decrypted system;
[0153] The integrated system includes an initialization unit, an on-chain storage unit, a data query unit, a data tampering detection unit, and a network interception detection unit connected in sequence;
[0154] An initialization unit, configured to divide a data storage area into an internal area and an external area, deploy a blockchain network in the internal area, deploy an Hfish honeypot chain network and a data tampering detection model in the external area, and deploy a network interception detection model according to the network channel through which the integrated system communicates with the data query terminal;
[0155] An on-chain storage unit, configured to generate a data hash value of the internal data of the system, and encrypt and sign the internal data of the system according to the data hash value, private key, and signature information to obtain the encrypted internal data of the system and the signature data, and use the blockchain network to store the encrypted internal data of the system and the data hash value on the chain;
[0156] A data query unit, configured to receive query information sent by the data query terminal, obtain the query hash value of the query information, retrieve and match the corresponding target data hash value in the blockchain network according to the query hash value, and extract the target encrypted internal data of the system corresponding to the target data hash value;
[0157] A data tampering detection unit, configured to use the Hfish honeypot chain network to collect the access behavior traffic of the data query terminal accessing the blockchain network, and use the data tampering detection model to perform data tampering detection on the access behavior traffic to obtain a data tampering detection result;
[0158] A network interception detection unit, configured to transmit the target data hash value, the target encrypted internal data of the system, and the corresponding target signature data to the data query terminal, collect the network transmission data of the network channel, and use the network interception detection model to perform network interception detection on the network transmission data to obtain a network interception detection result.
[0159] The present invention discloses an anti-tampering method and system for an integrated system based on blockchain, introducing the characteristics of decentralization and data immutability of blockchain technology, combining hash feature values for integrity verification, and improving the practicality of anti-tampering technology; using the Hfish honeypot chain network and the data tampering detection model to perform data tampering detection, and using the network interception detection model to perform network interception detection on the network channel, strengthening the security protection level of data storage and data transmission, and improving the reliability of storage and transmission; during the data transmission process, combining digital identity signature technology and asymmetric encryption algorithms to perform data transmission in ciphertext form and perform double encryption, improving the transmission security.
[0160] The present invention is not limited to the above optional implementation manners, and anyone can obtain other various forms of products under the inspiration of the present invention. The above specific implementation manners should not be construed as limiting the protection scope of the present invention, and the protection scope of the present invention should be defined by the claims, and the specification can be used to interpret the claims.
Claims
1. A method for preventing tampering of an integrated system based on blockchain, characterized in that: It includes the following steps: Based on a trusted institution, key generation and identity registration are performed on the integrated system to obtain the public-private key pair and signature information of the integrated system. The private key in the public-private key pair and the signature information are sent to the integrated system, and the public key in the public-private key pair is published to all data query terminals communicatively connected to the integrated system; Based on the integrated system, the data storage area is divided into an internal area and an external area. A blockchain network is deployed in the internal area, an Hfish honeypot chain network and a data tampering detection model are deployed in the external area, and a network interception detection model is deployed according to the network channels through which the integrated system is communicatively connected to the data query terminals. It includes the following steps: Based on the integrated system, the data storage area is divided into an internal area and an external area, and a firewall is set between the internal area and the external area; In the internal area, several data servers are distributively connected, an IPFS system and a smart contract are set, and a blockchain network is deployed; According to the system information of the data servers, corresponding Hfish honeypots are built in the external area, an Hfish honeypot management module is deployed, and all Hfish honeypots are connected to deploy an Hfish honeypot chain network; A data tampering detection model is deployed in the Hfish honeypot management module, a traffic probe is set in each Hfish honeypot, and all traffic probes are connected to the data tampering detection model; The data tampering detection model includes N key dimension feature extraction modules constructed based on the GAN algorithm and a data tampering detection module constructed based on the MLP algorithm; The concerned dimensions include the access frequency dimension, the access time dimension, and the access behavior dimension; A network interception detection model is deployed in the external area, data probes are set in the network channels through which the integrated system is communicatively connected to the data query terminals, and all data probes are connected to the network interception detection model; The network interception detection model includes a network signal dynamic module and a network interception detection module constructed based on the BiLSTM algorithm; The network signal dynamic module includes a signal quality dynamic sub-model, a data transmission rate dynamic sub-model, a network latency dynamic sub-model, and a network stability dynamic sub-model; The formula of the signal quality dynamic sub-model is: Q = f(RSSI) In the formula, Q is the signal quality detection function; f(*) is the signal quality calculation function; RSSI is the received signal strength value; The formula of the data transmission rate dynamic sub-model is: In the formula, C is the data transmission detection function; L is the amount of transmitted data; T is the transmission time; The formula of the network latency dynamic sub-model is: D = t send + t propagation + t process Where D is the network delay detection function; t send is the transmission time; t propagation is the signal propagation time; t process is the signal processing time; The formula of the network stability dynamic sub-model is: Wherein, PS is the network stability detection function; N c is the number of network interruptions; N s is the total number of connection attempts; Generate the data hash value of the internal system data, and encrypt and sign the internal system data according to the data hash value, the private key, and the signature information to obtain the encrypted internal system data and the signature data. Use the blockchain network to store the encrypted internal system data and the data hash value on the chain. It includes the following steps: Based on the external area, collect the internal system data, and use the SHA-3 algorithm to generate the data hash value of the internal system data; Concatenate the data hash value with the private key to obtain a mixed encryption key, and use the asymmetric encryption algorithm to encrypt the internal data of the system according to the mixed encryption key to obtain the encrypted internal data of the system; Sign the internal data of the system using the digital identity signature technology according to the signature information to obtain the signature data of the encrypted internal data of the system; Transmit the encrypted internal data of the system and the data hash value to the internal area, and use the blockchain network to store the encrypted internal data of the system and the data hash value on the chain, including the following steps: Transmit the encrypted internal data of the system and the data hash value to the internal area, store the encrypted internal data of the system in the IPFS system of the blockchain network, and generate a storage address and a storage hash value; Perform tampering verification on the storage hash value and the data hash value. After the tampering verification passes, use the smart contract of the blockchain network to generate a storage request and transaction data according to the data hash value and the storage address; Store the data hash value and the corresponding storage address in the distributed ledger and publish the distributed ledger to the blockchain network; Send the storage request and transaction data to several nodes in the blockchain network, conduct consensus on the storage request, and after the consensus passes, package the transaction data into a data block and link it to the chain; Receive the query information sent by the data query terminal, obtain the query hash value of the query information, and retrieve and match the corresponding target data hash value in the blockchain network, and extract the target encrypted internal data of the system corresponding to the target data hash value, including the following steps: Based on the data query terminal, encrypt the query information and the user login information according to the public key of the integrated system to obtain the encrypted query information and the encrypted user login information, and upload them to the integrated system; Based on the integrated system, decrypt the encrypted query information and the encrypted user login information according to the private key to obtain the decrypted query information and the decrypted user login information; Perform login verification on the decrypted user login information. After the login verification passes, use the SHA-3 algorithm to obtain the query hash value of the query information; Retrieve and match in the distributed ledger of the blockchain network, obtain the Euclidean distance between the query hash value and each data hash value, and use the data hash value with the closest Euclidean distance as the target data hash value; Extract the target encrypted internal data of the system corresponding to the target data hash value according to the target storage address corresponding to the target data hash value in the distributed ledger; Use the Hfish honeypot chain network to collect the access behavior traffic of the data query terminal accessing the blockchain network, and use the data tampering detection model to perform data tampering detection on the access behavior traffic to obtain the data tampering detection result, including the following steps: Use the traffic probe of the Hfish honeypot chain network to collect the access behavior traffic of the data query terminal accessing the blockchain network, and input the access behavior traffic into the data tampering detection model; Use the key dimension feature extraction module of the data tampering detection model to extract N key dimension features of the access behavior traffic; The data tampering detection module using the data tampering detection model performs feature fusion on N key dimension features to obtain fused features; Based on the fused features, data tampering detection is performed to obtain a data tampering detection result; If the data tampering detection result indicates that there is a data tampering behavior, the firewall is closed, the network channel is disconnected, data storage is ended, and the data query terminal is added to the blacklist. Otherwise, proceed to the data transmission step; Transmit the target data hash value, the target encrypted internal system data, and the corresponding target signature data to the data query terminal, collect the network transmission data of the network channel, and use the network interception detection model to perform network interception detection on the network transmission data. The steps are as follows: Transmit the target data hash value, the target encrypted internal system data, and the corresponding target signature data to the data query terminal through the corresponding network channel; Use the data probe set in the network channel to collect the network transmission data of the network channel and input the network transmission data into the network interception detection model; Based on the network transmission data, use the network signal dynamic module of the network interception detection model to generate network signal dynamic data; Based on the network signal dynamic data, use the network interception detection module of the network interception detection model to perform network interception detection to obtain a network interception detection result; If the network interception detection result indicates that there is a network interception behavior, disconnect the network channel and stop data transmission. Otherwise, proceed to the signature verification step; Based on the data query terminal, call a trusted institution to perform signature verification on the target signature data. After the signature verification passes, decrypt the target encrypted internal system data according to the target data hash value and the public key of the integrated system to obtain the decrypted internal system data; Generate a decrypted data hash value of the decrypted internal system data, perform integrity verification on the decrypted data hash value and the target data hash value. After the integrity verification passes, perform visual display on the decrypted internal system data.
2. A method for preventing tampering of an integrated system based on blockchain according to claim 1, characterized in that: Send the storage request and transaction data to several nodes in the blockchain network, use the PBFT consensus algorithm to perform consensus on the storage request. After the consensus passes, package the transaction data into a data block and link it to the chain.
3. A blockchain-based integrated system anti-tampering system for implementing the integrated system anti-tampering method as described in any one of claims 1-2, characterized in that: The described integrated system anti-tampering system includes an integrated system, a trusted institution, and several data query terminals. The integrated system and the trusted institution are respectively communicatively connected to several data query terminals, and the integrated system is communicatively connected to the trusted institution.
Citation Information
Patent Citations
Malicious user identification method based on honeypot system and related equipment
CN110324313A
Hierarchical storage method based on block chain and terminal
CN114691775A
Data encryption and authorization management method based on Hyperledger Fabric alliance chain
CN116827653A
Webpage tamper-proof data encryption method and system
CN117729041A