A sharing and circulation method and mechanism based on hydropower data elements

Through key management and blockchain technology, combined with proxy signature and encryption methods, the security and mechanism limitation issues in hydropower data sharing are solved, safe and efficient data circulation and access control are achieved, and cross-domain sharing is supported.

CN119363322BActive Publication Date: 2025-09-26GUODIAN DADU RIVER POWER ENG
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411487154.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-24
Publication Date
2025-09-26
Estimated Expiration
2044-10-24

AI Technical Summary

Technical Problem

Hydropower data sharing faces problems such as data complexity and sensitivity, limitations of sharing mechanisms, and immature security sharing solutions, which lead to restricted data circulation and make it difficult to achieve efficient and secure sharing across industries and platforms.

Method used

A key management server is used to define mathematical parameters and hash functions. Combined with the blockchain platform, proxy signature and encryption technology are used to achieve the secure sharing and circulation of hydropower data, including data encryption, uploading, access and compliance review, to build a secure and efficient data sharing ecosystem.

Benefits of technology

It achieves secure transmission and access control of hydropower data, ensures data confidentiality and integrity, improves the efficiency and transparency of data sharing, provides flexible access policies and compliance reviews, and supports cross-domain data sharing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119363322B_ABST
    Figure CN119363322B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and mechanism for sharing and circulating hydropower data elements. The method comprises: Step 1, parameter setting; Step 2, user authorization: a key management server authorizes each system participant through key distribution and records relevant information on a blockchain platform; Step 3, data transfer authorization: a data user generates a proxy file, sets an access structure, and sends a portion of the proxy signature key component to another user; Step 4, encrypted upload of hydropower data elements: the hydropower data owner encrypts the hydropower data file, generates a ciphertext index, uploads it to the blockchain platform, and stores it on the hydropower data cloud platform; Step 5, trapdoor generation; Step 6, data search and access; Step 7, verification and decryption; and Step 8, compliance review and user rights deprivation. The mechanism comprises: hydropower data resourceization; hydropower data componentization; and hydropower data productization. The present invention enables the sharing and circulation of hydropower data in a secure, efficient, and compliant manner.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of hydropower data sharing, and in particular to a sharing and circulation method and mechanism based on hydropower data elements. Background Art

[0002] Amidst the accelerating transformation of the global energy structure and the rapid advancement of smart grid technology, the sharing and circulation of hydropower data, a key pillar of renewable energy, has become a crucial driver of change and development in the power industry. Hydropower data, including but not limited to real-time hydropower station operating data, water resource calculation parameters, and key equipment status monitoring information, is not only a key indicator for measuring hydropower station operational efficiency and safety, but also an essential foundation for precisely regulating energy supply and demand and optimizing resource allocation.

[0003] However, the current sharing and circulation of hydropower data elements faces a series of technical bottlenecks and severe challenges, which are specifically reflected in the following aspects:

[0004] 1. Data complexity and sensitivity coexist: Hydropower data is highly complex and sensitive, involving multiple dimensions and types, and requires extremely high real-time performance. This data often contains core commercial secrets of hydropower stations and user privacy information. How to ensure efficient data circulation while effectively preventing data leakage and misuse has become a pressing challenge.

[0005] 2. Sharing mechanisms are limited: Existing hydropower data sharing mechanisms are generally confined to the power system, lacking cross-industry and cross-platform data exchange and sharing channels. This closed data circulation model restricts the full release of data value, makes it difficult to meet the needs of collaborative operations and joint development between the power industry and other industries, and hinders the maximum utilization of data resources.

[0006] 3. Secure sharing solutions are not yet mature: Although advanced technologies such as big data, cloud computing, and blockchain have achieved remarkable success in data security and privacy protection, secure sharing solutions tailored to the unique characteristics of hydropower data are still under development and development. Designing mechanisms that combine the specific characteristics of hydropower data to ensure secure data transmission and promote efficient data sharing remains a key challenge in current technological research and development. Summary of the Invention

[0007] In view of this, the present invention proposes a sharing and circulation method and mechanism based on hydropower data elements to solve the problems in the prior art that hydropower data sharing is subject to security and circulation restrictions and lacks mature sharing solutions.

[0008] The specific technical solutions of the present invention are as follows:

[0009] A shared circulation method based on hydropower data elements, including:

[0010] Step 1: The key management server defines mathematical parameters, bilinear mapping, and hash functions to generate the system master key and public parameters.

[0011] Step 2: The key management server authorizes each system participant through key distribution and records relevant information on the blockchain platform;

[0012] Step 3: The data user generates a proxy file, sets up an access structure, and sends a portion of the proxy signature key component to another user to allow them to access or operate data on their behalf.

[0013] Step 4: The hydropower data owner encrypts the hydropower data file, generates a ciphertext index, and uploads it to the blockchain platform, which then stores it on the hydropower data cloud platform.

[0014] Step 5: The data user generates a trapdoor and submits an access request to the hydropower data cloud platform;

[0015] Step 6: Data users search and access data through the blockchain platform and the hydropower data cloud platform, verify the trapdoor, and obtain ciphertext or pre-decrypted ciphertext;

[0016] Step 7: The data user verifies the ciphertext signature and decrypts it to confirm the ciphertext source and restore the hydropower data file for access;

[0017] In step eight, the blockchain platform reviews the authenticity of the data. If false data is found, it calculates a revocation request and notifies the hydropower data cloud platform. The hydropower data cloud platform sets the relevant outsourced keys to invalid to deprive the user of their rights.

[0018] Furthermore, in step 2, when the key management server authorizes the user, it also includes calculating and verifying the user's public key, private key, search key and decryption key, and sending the user's decryption key through a secure channel. At the same time, the outsourced key and the corresponding user attribute set are sent to the hydropower data cloud platform, and the user identity together with the search key are sent to the blockchain platform for record, thereby achieving data security protection by issuing keys.

[0019] Furthermore, step three also includes: the data user generates a proxy file and sets an access structure, calculates part of the proxy signature key component through the LSSS matrix and mapping function, and sends the proxy file, access structure and part of the key to another user. After the recipient verifies the specific equation, it calculates the complete proxy signature key component to generate a complete proxy signature key, thereby realizing a dynamic data circulation strategy through user agency.

[0020] Furthermore, in step four, when the hydropower data owner encrypts the hydropower data file, it also includes constructing ciphertext intermediate values, ciphertext components and ciphertext indexes, and signing the ciphertext to ensure the confidentiality and integrity of the data, the traceability of data circulation and the standardization of data processing, and then uploading the ciphertext and ciphertext index to the blockchain platform and the hydropower data cloud platform.

[0021] Furthermore, in step four, the hydropower data owner performs encryption operations, defines the access structure through the LSSS matrix and mapping function, calculates the secret value and ciphertext components, constructs random matrices and polynomials to generate ciphertext intermediate values ​​and ciphertext indexes, signs the ciphertext using the identity private key and proxy signature key, and generates a keyword ciphertext index. Finally, the ciphertext and index are uploaded to the blockchain platform, which stores the data tuples and transmits the ciphertext to the hydropower data cloud platform to achieve traceability of data circulation.

[0022] Furthermore, in step five, when the data user generates and submits an access request, he or she uses the verification key to construct a trapdoor component to facilitate efficient search and access on the blockchain platform and the hydropower data cloud platform, thereby achieving secure data transmission and circulation.

[0023] Furthermore, the search in step six includes two modes: search mode one verifies and pre-decrypts the ciphertext through the blockchain platform and the hydropower data cloud platform, and search mode two directly returns the search results through the blockchain platform to adapt to different access requirements and data sensitivity.

[0024] Furthermore, search mode 1 in step 6 allows data users to send trapdoors to the blockchain platform. Blockchain nodes perform equation operations through smart contracts to filter ciphertexts. The hydropower data cloud platform constructs pre-decrypted ciphertexts based on the satisfaction of the user attribute set and sends them together with the ciphertext to the data user to achieve data sharing and access control.

[0025] Furthermore, the search mode 2 in step 6 includes: the data user sends a trapdoor to the blockchain platform, and the blockchain node executes the equation operation through the smart contract. If the equation is established, the search result is directly returned to the data user, thereby achieving traceability of data circulation.

[0026] A shared circulation mechanism based on hydropower data elements, including:

[0027] Hydropower data resourceization includes: collecting raw hydropower-related data through sensors, logging systems, and user input; preliminarily organizing the collected raw data; identifying and correcting errors, outliers, and missing values ​​in the data; aggregating, classifying, and sorting the data according to business needs, and converting it into data resources with specific structures and formats; and storing the processed data resources in data storage systems to ensure data accessibility and persistence.

[0028] Componentization of hydropower data includes: protecting sensitive information to prevent data leakage; selecting relevant fields and modeling data features based on market and application scenario requirements; organizing processed data into data sets according to a specific structure, forming data components with specific structures and functions as intermediate states in data circulation and transactions;

[0029] The productization of hydropower data includes: clarifying the product user groups, the problems it solves and the value it brings, and conducting data resource assessments and technical feasibility assessments. Among them, data resource assessments are to fully understand and evaluate the hydropower-related data owned, including data integrity, accuracy, and update frequency, and output data resource catalogs and quality assessment reports. Based on the assessment results and in response to customer needs, hydropower data components are packaged into data products and circulated using a shared circulation method based on hydropower data elements.

[0030] The beneficial effects of the present invention are:

[0031] 1. Secure Data Flow and Access Control: This invention innovatively integrates attribute encryption and identity encryption technologies to provide dual security for hydropower data. This approach not only ensures data security during transmission and sharing, but also implements refined access control, effectively solving the challenges of secure data flow and access, laying a solid foundation for secure data sharing and achieving secure data transmission, protection, secure data flow, sharing, and access control.

[0032] 2. Flexible and Efficient Secure Sharing Mechanism: Leveraging the immutability and distributed nature of blockchain technology, this invention enables full authentication and traceability of hydropower data throughout its circulation, sharing, and access. This mechanism not only improves the efficiency of data sharing but also enhances the transparency and credibility of the system, ensuring the flexible and efficient operation of the secure sharing mechanism and enabling traceability of data circulation, data access control, and standardized data processing.

[0033] 3. Optimizing Ciphertext Access Flexibility: To address the need for flexible ciphertext access, this paper designs two efficient ciphertext data search methods. One method reduces communication traffic and improves data transmission efficiency through algorithm optimization; the other method significantly reduces the computational burden on data users, making data access more convenient and faster, further improving user experience and data utilization efficiency, and implementing a dynamic data circulation strategy.

[0034] 4. Strengthening Data Compliance Review: To ensure the compliant use of hydropower data, this invention also introduces a rigorous data compliance review method. This method automatically identifies and processes non-compliant data and deprives data owners of their rights. This measure effectively ensures the legality and standardization of data circulation, enables data quality monitoring and assessment, and manages data compliance, providing a solid legal foundation for the digital transformation and sustainable development of the power industry. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments or descriptions of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0036] Figure 1 This is a flow chart of the shared circulation mechanism based on hydropower data elements of the present invention;

[0037] Figure 2 Schematic diagram of the flow of the shared circulation method based on hydropower data elements of the present invention;

[0038] Figure 3 It is a schematic diagram of the framework of the shared circulation method based on hydropower data elements of the present invention. DETAILED DESCRIPTION

[0039] In order to make the technical problems, technical solutions and beneficial effects to be solved by the present invention more clearly understood, the present invention is further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0040] This invention proposes a sharing and circulation mechanism based on hydropower data elements, such as Figure 1 As shown:

[0041] Raw data, as direct records of information, comes in various forms, including structured (such as numbers and text in databases), semi-structured (such as data in XML or JSON format), and unstructured (such as video, audio, and images). This data contains rich information but has not yet been transformed into directly usable resources.

[0042] The resourceization of hydropower data is to process the original data of the data source to form data resources.

[0043] The first step in the data resourceization process is data collection: collecting raw data through various technical means (such as sensors, log systems, user input, etc.). The second step is data organization: preliminary organization of the collected raw data, including data cleaning, deduplication, format conversion, etc. Remove invalid or erroneous data to improve data quality. The third step is data cleaning: identify and correct errors, outliers and missing values ​​in the data through algorithms and manual means. Ensure the accuracy and reliability of the data and provide strong support for subsequent data analysis. The fourth step is data processing: aggregate, classify, sort and other processing of data according to business needs. Convert raw data into data resources with a specific structure and format to facilitate subsequent data storage and analysis. The fifth step is data storage: store the processed data resources in appropriate data storage systems (such as databases, data warehouses, etc.). Ensure the accessibility and persistence of data to provide support for subsequent data analysis and application.

[0044] Componentization of hydropower data refers to the process of converting data into data units with specific structures and functions, or data components, through a series of processing steps. This process transforms raw data into data components with specific structures and functions, providing strong support for the compliant circulation and trading of data. Data components are desensitized data, formed by combining several related fields based on market needs and application scenarios, or data features formed by modeling related fields. They serve as an "intermediate state" in data circulation and trading, decoupling raw data from data applications.

[0045] The first step in data componentization is data desensitization: protecting sensitive information and preventing data leaks. The second step is field selection and modeling: selecting relevant fields based on market and application scenario requirements and generating data features through modeling. The third step is data component formation: organizing the processed data into datasets according to a specific structure.

[0046] The productization of hydropower data is a process of converting data into value. It involves effectively using data analysis to extract valuable information from massive amounts of data, and providing business support and services for user decision-making in an intuitive and effective manner.

[0047] The first step in data productization is product planning: that is, clarifying the product goals, including the user groups, the problems to be solved, and the value to be brought. Conduct data resource assessments and technical feasibility assessments to understand the data resources owned by the enterprise and their quality, and evaluate the capabilities of the data processing platform. The second step is data resource assessment: understand the data owned, including product data, customer data, transaction data, and financial and equipment-related data. Assess the quality of the data, such as completeness, accuracy, and update frequency. Output a data resource catalog and a data quality assessment report. The third step is product incubation and circulation: data components are packaged for customers and transformed into data products for circulation, with the focus on the security and compliance of the data product circulation method.

[0048] The focus of this invention is to address the key technical issues such as security, authorization and access control faced by hydropower data in the process of sharing and circulation, and to design a sharing and circulation method based on hydropower data elements, such as Figure 2 and Figure 3 As shown, it includes steps 1, parameter setting: the key management server defines security parameters; step 2, user authorization: the key management server authorizes each system participant through key distribution to achieve data security protection and record relevant information on the blockchain platform; step 3, data flow authorization: the data user generates a proxy file, sets the access structure, and sends part of the proxy signature key component to another user to implement a dynamic data flow strategy; step 4, encrypted upload of hydropower data elements: the hydropower data owner encrypts the hydropower data file, generates a ciphertext index, and uploads it to the blockchain platform for storage and then to the hydropower data cloud platform, achieving data flow traceability and data processing standardization; step 5, trapdoor generation: the data user generates a trapdoor and submits an access request; step 6, data search and access, achieving secure data transmission and circulation; step 7, verification and decryption, achieving data sharing and access control; step 8, compliance review and user permission deprivation, achieving data quality monitoring and assessment and data compliance management. This shared circulation and distribution ensures the security of hydropower data, an important production factor, during circulation.

[0049] This method aims to achieve safe, efficient and controllable sharing and circulation of hydropower data by building a system in which five entities work together, including a key management server, hydropower data owners, a blockchain platform, a hydropower data cloud platform and data users.

[0050] In practice, the key management server plays a crucial role. It not only generates and manages various encryption keys (such as symmetric and asymmetric keys) and allocates user access rights, but also ensures the secure storage and distribution of keys, providing a solid foundation for data encryption and decryption. Hydropower data owners use these keys to encrypt sensitive hydropower data and upload the encrypted data, along with its access control policies, via the blockchain platform and the hydropower data cloud platform, ensuring the security and integrity of the data during transmission and storage.

[0051] As the core trust layer, the blockchain platform leverages its decentralized and tamper-proof nature to record key information such as hydropower data metadata, access control policies, and user permissions. This provides strong support for data authenticity, traceability, and access request verification. Furthermore, through the automated execution of smart contracts, the blockchain platform efficiently processes data access requests, enabling rapid verification and authorization of permissions, significantly improving the system's responsiveness and automation.

[0052] The hydropower data cloud platform serves as a hub for data storage and access. It stores encrypted hydropower data and its index information, and provides data access services to data users based on authorization from the blockchain platform. Data users submit access requests to the cloud platform, which are then verified by the blockchain platform. They can then securely retrieve and decrypt the required hydropower data, enabling on-demand access and efficient utilization of data.

[0053] Through close collaboration and data interaction among five types of entities, this invention builds a safe, reliable and efficient hydropower data sharing and circulation ecosystem, effectively solving key technical problems in the sharing and circulation of hydropower data, and providing strong technical support for the digital transformation and intelligent upgrading of the hydropower industry.

[0054] The method of the present invention specifically comprises the following steps:

[0055] Step 1 (Parameter Setting): This step is performed by the key management server and defines Define bilinear mappings for two prime number p-factorial cyclic groups respectively. Indicates that two groups can be The elements in are mapped to a group Elements in .

[0056] Define g as a group A generator in . For the p-order integer group, define five hash functions Respectively represent mapping a bit string of arbitrary length to a group On an element of The elements in and a bit string of arbitrary length are mapped to the group On an element of An element in is mapped to a bit string of arbitrary length, and a bit string of arbitrary length is mapped to the group On an element of , a bit string of arbitrary length is mapped to a constant length l H The bit string.

[0057] Draw a set of random numbers On this basis, the common parameter middleware g is calculated α , g β , g c and e(g,g) γ On this basis, the system master key MSK=(α, β, g γ , c) and system common parameters

[0058] Step 2 (user authorization): This step is performed by the key management server, which grants access or operation permissions to each participant of the system based on the shared circulation method of hydropower data elements by issuing keys.

[0059] First, the identity identifier GID of any entity in the system x , calculate the identity public key IPK x =H1(GID x ) and identity private key ISK x =(IPK x ) α .

[0060] Then the search key and decryption key are calculated for the data user. Assume that S is the attribute set of the data user, and the key management server extracts a random number. Calculate the partial attribute key component AKP1 = g t and Among them Att i is the i-th attribute. Composition attribute key AKP = (AKP1, {AKP i}) and sent to the data user.

[0061] The identity identifier is GID x The user draws a random number from the data And let the verification private key component be VSK1=z. The outsourcing key is Calculate the outsourced key components ODK1 and ODK i , where ODK1 = VSK2 = (AKP1) z , The user verification public key is VPK = (VPK1, VPK2), and the user verification public key components VPK1 and VPK2 are calculated, where VPK1 = g z , The user verification private key is VSK=(VSK1, VSK2), and the user verification private key components VSK1 and VSK2 are calculated.

[0062] Data User GID x Outsource the key The user verification public key VPK=(VPK1, VPK2) is sent to the key management server, and the user verification private key VSK=(VSK1, VSK2) is secretly stored locally.

[0063] The key management server calculates the verification factor t′=H4(VPK1||GID x ||ODK1||{ODK i}) and verify the following equation:

[0064] e(g,VPK2)=e(g α , H1(GID x ) t′ )·e(g α , VPK1)

[0065] If the above equation holds true, then calculate the user decryption key DK = (VPK1) γ (VPK1) c·t , and the user search key And calculate the user's second search key Finally, the key management server sends the user decryption key DK to the data user through a secure channel, sends the outsourced key ODK and the corresponding user attribute set S to the hydropower data cloud platform, and sends the user identity GID x Together with the user search key SK and the user second search key SK′, it is sent to the blockchain platform, and then the blockchain node records them in the distributed ledger.

[0066] Step 3 (Data transfer authorization): This step is performed by the data user GID a Execute, assuming PxFile is the data user GID a The generated proxy file sets the access structure to in is a LSSS matrix, and ρ is a mapping function.

[0067] Then, a random number is drawn And calculate the partial proxy signature key component PK1=g v , Data User GID aPxFile, Sent to another user GID along with the partial proxy signature key PK=(PK1, PK2) p .

[0068] User GID p First verify the following equation:

[0069]

[0070] If the above formula is true, the user GID p Calculate the complete proxy signature key component PxK1=PK1, On this basis, a complete proxy signature key PxK=(PxK1, PxK2) is generated.

[0071] Step 4 (encrypted upload of hydropower data elements): This step is performed by the hydropower data owner. Suppose a hydropower data file is File = {0, 1} * , the access structure is in is an LSSS matrix with r rows and l columns, and ρ is a mapping function that can transform the matrix The i-th row Mapped to an attribute.

[0072] Then, the hydropower data owner draws a random number And calculate the secret value s = H2(SyK.File), and calculate the ciphertext component based on this:

[0073] C0=g s , C1=SyK·e(g,g) γs ,

[0074] The owner of the hydropower data constructs a random matrix For subscript i∈[1, r], calculate the intermediate value of the ciphertext Then draw a random number And calculate the ciphertext components:

[0075]

[0076] Assuming the current timestamp is T, the owner of the hydropower data uses his identity private key ISK p And the complete proxy signature key PxK signs the ciphertext: σ1=H2(e(g,ISK p ) s , C0||C1||C2||T),

[0077] The owner of hydropower data generates a set of keywords KW for File = {kw1, ..., kw n}, then draw a random number And construct the polynomial f(x)=a(x-H4(kw1))(x-H4(kw2))...(x-H4(kw n ))+b=a n x n +a n-1 x n-1 +...+a1x+a0. Based on this, the ciphertext index Ix1=g is calculated. s ·g b , Ix2=g βs ,

[0078] The owner of the hydropower data generates the ciphertext CT = (S, C0, C1, C2, {C i , C′ i} i∈[1,r] , r = σ1, σ2, T) and ciphertext index Ix = (Ix1, Ix2, {Ix i} i∈[0,n] ) and upload them to the blockchain platform. Subsequently, the blockchain platform stores the data tuple [Ix1|H5(σ1,σ2)] and uploads the ciphertext CT to the hydropower data cloud platform.

[0079] Step 5 (Access Request): Assume data user GID x The set of keywords of interest is KW′=(kw′1,...,kw′ m ) Use the verification key to construct the following trapdoor component:

[0080]

[0081] Data user generates trapdoor TD=(td1,{td j} j∈[0,n] ) and submit an access request Req=(GID x , TD).

[0082] Step 6 (Data Search and Access): Data users search and access data in the following two access modes.

[0083] Search mode 1: The data user first sends the trapdoor TD to the blockchain platform, and then the blockchain node executes the following equation through the smart contract:

[0084]

[0085] If the above formula is true, the ciphertext will be added to the search result set Rst sThen, the hydropower data cloud platform detects whether the user's attribute set S satisfies the access structure If it is not satisfied, the data user’s access request is directly rejected. Otherwise, the hydropower data cloud platform defines I as the set of all rows i that satisfy ρ(i)∈S. Subsequently, the hydropower data cloud platform constructs a constant set So that ∑ i′∈I w i λ i =s, where λ i is a fragment of the secret value s. The hydropower data cloud platform then performs the following calculation to generate the pre-decrypted ciphertext:

[0086]

[0087] Finally, the hydropower data cloud platform sends the pre-decrypted ciphertext PreCT together with the ciphertext CT to the data user.

[0088] Search mode 2: The data user first sends the trapdoor TD to the blockchain platform, and then the blockchain node

[0089] The contract can perform the following equation:

[0090]

[0091] If the equation holds, the search result, i.e., the ciphertext CT, is directly returned to the data user.

[0092] Step 7 (Verification and Decryption): The data user first verifies whether the signature in the ciphertext is issued by the hydropower data owner himself, that is, first calculate the following signature verification intermediate value:

[0093]

[0094] Then verify whether the following equation holds:

[0095] σ1=H2(Rst v , C0||C1||C2||T)

[0096] If the above formula is not true, the user refuses to receive the ciphertext, otherwise continue to execute the following procedure.

[0097] Based on the pre-decrypted ciphertext PreCT, the data user recovers the random number SyK, the hydropower data file File, and the secret value s according to the following formula, and then accesses the hydropower data file:

[0098]

[0099] s=H2(SyK,File)

[0100] Step 8 (Compliance Review and User Rights Removal): The blockchain platform can It is used as input to judge whether the owner of hydropower data has released false data. If it is confirmed, the blockchain platform calculates the revocation request H1(GID p ) and sent to the hydropower data cloud platform. Then the hydropower data cloud platform will send all the data related to H1 (GID p )The related outsourcing key is set to "invalid".

[0101] The beneficial effects of the present invention are:

[0102] 1. Enabling secure circulation and efficient sharing of hydropower data: This invention effectively addresses the security issues associated with sharing hydropower data by integrating data encryption technologies (including a fusion of attribute and identity encryption), ensuring data confidentiality, integrity, and availability. This enables secure communication, sharing, and refined access control of hydropower data. This innovative solution significantly enhances the security of data circulation and lays a solid foundation for cross-domain and cross-platform data sharing.

[0103] 2. Improve the flexibility and efficiency of sharing mechanisms: Leveraging blockchain technology, this invention not only ensures the authenticity and traceability of hydropower data throughout its circulation, sharing, and access, but also automates data exchange rules through mechanisms like smart contracts, significantly improving the flexibility and efficiency of data sharing. The decentralized nature of blockchain eliminates the risk of a single point of trust, making data sharing more reliable and manageable.

[0104] 3. Optimizing the Access Experience for Confidential Data: To address the complexity and inefficiency of confidential data access, this paper innovatively proposes two confidential data search methods. One method effectively reduces communication traffic and accelerates data retrieval through optimized algorithm design; the other method focuses on reducing the computational burden on data users, significantly improving the convenience and efficiency of confidential data access. This improvement directly promotes the optimized allocation and efficient utilization of hydropower data resources.

[0105] 4. Strengthening Data Compliance Review and Supervision: This invention also incorporates a comprehensive data compliance review mechanism that automatically conducts compliance reviews of data sources, content, and formats, ensuring that shared hydropower data complies with relevant laws, regulations, and industry standards. The system automatically deprives data owners of access to non-compliant data, effectively curbing the circulation of non-compliant data and maintaining a healthy and orderly data ecosystem. The implementation of this mechanism provides a solid compliance guarantee for the digital transformation and sustainable development of the power industry.

[0106] In summary, the present invention proposes a sharing and circulation mechanism and method based on hydropower data elements. Through a series of innovative technical means, it realizes the widespread sharing and circulation of hydropower data under the premise of safety, efficiency and compliance, injecting strong impetus into the digital transformation and sustainable development of the power industry.

[0107] The above are only preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A shared circulation method based on hydropower data elements, characterized in that: include: Step 1: The key management server defines mathematical parameters, bilinear mapping, and hash functions to generate the system master key and public parameters. Step 2: The key management server authorizes each system participant through key distribution and records relevant information on the blockchain platform; In step three, the data user generates a proxy file, sets an access structure, and sends a partial proxy signature key component to another user to allow the user to access or operate data on their behalf. Step three includes: the data user generates a proxy file and sets an access structure, calculates the partial proxy signature key component using the linear secret sharing scheme (LSSS) matrix and mapping function, and sends the proxy file, access structure, and partial key to the other user. The recipient verifies a specific equation and calculates the complete proxy signature key component to generate a complete proxy signature key, thereby implementing a dynamic data circulation strategy through user proxy. Step 4: The hydropower data owner encrypts the hydropower data file, generates a ciphertext index, and uploads it to the blockchain platform, which then stores it on the hydropower data cloud platform. Step 5: The data user generates a trapdoor and submits an access request to the hydropower data cloud platform; Step 6: Data users search and access data through the blockchain platform and the hydropower data cloud platform, verify the trapdoor, and obtain ciphertext or pre-decrypted ciphertext; Step 7: The data user verifies the ciphertext signature and decrypts it to confirm the ciphertext source and restore the hydropower data file for access; In step eight, the blockchain platform reviews the authenticity of the data. If false data is found, the calculation request will be revoked and the hydropower data cloud platform will be notified. The hydropower data cloud platform will set the relevant outsourced keys to invalid to deprive the user of their rights.

2. The method for sharing and circulating water and electricity data elements according to claim 1, characterized in that: In step 2, when authorizing the user, the key management server also calculates and verifies the user's public key, private key, search key and decryption key, and sends the user's decryption key through a secure channel. At the same time, the outsourced key and the corresponding user attribute set are sent to the hydropower data cloud platform, and the user identity together with the search key are sent to the blockchain platform for record, thereby achieving data security protection by issuing keys.

3. The method for sharing and circulating water and electricity data elements according to claim 1, characterized in that: In the fourth step, when the hydropower data owner encrypts the hydropower data file, it also includes constructing ciphertext intermediate values, ciphertext components and ciphertext indexes, and signing the ciphertext to ensure the confidentiality and integrity of the data, the traceability of data circulation and the standardization of data processing, and then uploading the ciphertext and ciphertext index to the blockchain platform and the hydropower data cloud platform.

4. The method for sharing and circulating water and electricity data elements according to claim 3, characterized in that: In step 4, the hydropower data owner performs encryption operations, defines the access structure through the LSSS matrix and mapping function, calculates the secret value and ciphertext components, constructs random matrices and polynomials to generate ciphertext intermediate values ​​and ciphertext indexes, signs the ciphertext using the identity private key and proxy signature key, and generates a keyword ciphertext index. Finally, the ciphertext and index are uploaded to the blockchain platform, which stores the data tuples and transmits the ciphertext to the hydropower data cloud platform to achieve traceability of data circulation.

5. The method for sharing and circulating water and electricity data elements according to claim 1, characterized in that: In step five, when generating and submitting an access request, the data user uses the verification key to construct a trapdoor component to enable efficient search and access on the blockchain platform and the hydropower data cloud platform, thereby achieving secure data transmission and circulation.

6. The method for sharing and circulating water and electricity data elements according to claim 1, characterized in that: The search in step six includes two modes. Search mode one verifies and pre-decrypts the ciphertext through the blockchain platform and the hydropower data cloud platform, and search mode two directly returns the search results through the blockchain platform to adapt to different access requirements and data sensitivity.

7. The method for sharing and circulating water and electricity data elements according to claim 6, characterized in that: Search mode 1 in step 6 allows data users to send trapdoors to the blockchain platform. The blockchain nodes perform equation operations through smart contracts to filter ciphertexts. The hydropower data cloud platform constructs pre-decrypted ciphertexts based on whether the user attribute set is satisfied, and sends them together with the ciphertexts to the data users to achieve data sharing and access control.

8. The method for sharing and circulating water and electricity data elements according to claim 6, characterized in that: Search mode 2 in step 6 includes: the data user sends a trapdoor to the blockchain platform, and the blockchain node executes an equation operation through a smart contract. If the equation is true, the search result is directly returned to the data user, thereby achieving traceability of data circulation.

Citation Information

Patent Citations

  • Attribute-based searchable encrypted block chain medical data sharing method

    CN112765650A

  • Attribute-based searchable encrypted data sharing method based on block chain

    CN115834200A