Original data delivery method and device based on trusted execution environment and blockchain
By adopting a combination of a trusted execution environment and blockchain technology in the data delivery process, data security and privacy protection are achieved, solving the problems of data leakage and privacy in traditional data delivery methods, and ensuring the integrity and security of off-chain data delivery.
Patent Information
- Application Number
- CN202510090749.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-21
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2045-01-21
AI Technical Summary
Traditional data delivery methods have problems such as data leakage, tampering and privacy that cannot be guaranteed, and the prior art cannot effectively combine data security and blockchain availability.
The original data delivery method based on a trusted execution environment and blockchain is adopted to ensure the security and privacy of the data during transmission through secondary encryption of data, through data authorization protocols between DA, DP and TP, and data download protocols between DA and TP.
It realizes security and privacy guarantees of data during the delivery process, prevents unauthorized access and transactions, meets the performance requirements of blockchain, and ensures the integrity and security of off-chain delivered data.
Smart Images

Figure CN119520173B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of software engineering, and particularly to a method, device, and storage medium for delivering raw data based on a trusted execution environment and blockchain. Background Art
[0002] With the advent of the big data era, the security and privacy protection of data have become urgent problems to be solved. Traditional data delivery methods often rely on a third party for data transmission, posing risks of data leakage and tampering. At the same time, data may also be maliciously intercepted and copied during transmission, resulting in the inability to guarantee data privacy.
[0003] To address these challenges, researchers have begun to explore new data delivery methods. A trusted execution environment (TEE) provides a completely isolated environment that can prevent other software applications, operating systems, and host owners from tampering with or even understanding the state of the applications running in the TEE, thereby ensuring the security and privacy of data during the computing process. However, the availability of the TEE cannot be guaranteed, and it is unable to reliably access the network or persistent storage. Although blockchain technology can ensure the strong availability and persistence of data, its computing power is limited, and the entire state needs to be made public for verification.
[0004] Therefore, the present invention proposes a method for delivering raw data based on a trusted execution environment and blockchain. Summary of the Invention
[0005] Aiming at the defects in the prior art, the present invention provides a method for delivering raw data based on a trusted execution environment and blockchain, including the following steps:
[0006] S1: Data secondary encryption;
[0007] S2: Establish a data authorization protocol among DA, DP, and TP;
[0008] S3: Establish a data download protocol between DA and TP.
[0009] Preferably, the step S1 includes the following steps:
[0010] S11: DC transmits the data information related to DP into the enclave of the trusted hardware;
[0011] S12: Decrypt in the enclave to obtain the private key and use the private key to decrypt to obtain the plaintext data M, and use the key K generated in the enclave Y to perform secondary encryption on the data to obtain Forward the encrypted data encryption key and the private key of DP to TP for verification;
[0012] S13: After TP verifies the signature through the public key of DP, it confirms that the message comes from DC, and DC has completed the secondary encryption of the data.
[0013] Preferably: In the step S12, the message content is
[0014]
[0015] Preferably: In the step S13, the stored data content of DC is
[0016]
[0017] Preferably: In the step S2, define the data transaction request of DA as a tuple composed of a hash and an asymmetric key Define the transaction request initiated by DA as Define the authorization certificate granted by DP as requesting the signature of the private key of DP
[0018]
[0019] Preferably: In the step S2, it specifically includes the following steps:
[0020] S21:. DA locally generates a pair of asymmetric keys, Encrypt the private key using the trusted hardware bound public key, and upload the ciphertext and the transaction request to TP;
[0021] S22: After TP receives it, it hashes the request message and forwards it to the corresponding owner DP of the data;
[0022] S23: After DP receives the message, it verifies the signature of DA and the requested data using the public key of DA. After confirming the data content of the transaction request, it sends the authorization for the corresponding data to DS for transaction permission;
[0023] S24: After TP receives the message content, it confirms to initiate a transaction task, and forwards the corresponding authorization and the private key of the corresponding DP to DC;
[0024] S25: The enclave in DC verifies the legality of the request content using the received authorization. After passing the verification, it decrypts to obtain the private key of DP, decrypts using the private key to obtain the data encryption key, and then encrypts the encryption key using the public key of DA to obtain the ciphertext At this time, the algorithm output of the enclave in DC is Send the result hash and signature to the TP to verify the message legality, and then store the output together with the ciphertext of the double-encrypted data in the DC.
[0025] Preferably: In the step S23, the message content is
[0026] Preferably: In the step S24, the message content is
[0027]
[0028] Preferably: In the step S25, the message content is
[0029]
[0030] Preferably: The step S3 includes the following steps:
[0031] S31: The DC stores the ciphertext information of the double-encrypted data
[0032]
[0033] S32: As long as the DA requests to download the corresponding data ciphertext, the off-chain data delivery can be completed.
[0034] Based on the same inventive concept, an embodiment of the present invention provides a raw data delivery device based on a trusted execution environment and a blockchain, which is used to implement the foregoing method, including:
[0035] A data double-encryption module, which is used to implement the data double-encryption in the step S1;
[0036] A data authorization protocol establishment module, which is used to implement the establishment of the data authorization protocol among the DA, DP, and TP in the step S2;
[0037] A data download protocol establishment module, which is used to implement the establishment of the data download protocol between the DA and the TP in the step S3.
[0038] An embodiment of the present invention also provides a storage medium, which is used to store and read / write the foregoing method.
[0039] The beneficial effects of the present invention are reflected in:
[0040] 1. In the process of the platform party of the present invention realizing the delivery of the data content from the data owner to the data user, the platform has never obtained the data plaintext and the user's private key throughout the process, making it impossible for the platform to obtain the relevant content of the data, nor can it trade the data to the data user without the authorization of the data owner, which can ensure the security of the data during the delivery process.
[0041] 2. The present invention provides a secure and effective method for off-chain original data delivery, which can prevent unauthorized access and unauthorized transactions of data. At the same time, it can meet the limited performance requirements of the blockchain, ensure the integrity and security of the off-chain delivered data, realize the trusted transaction between data users and data owners, and effectively prevent malicious data forgery or unauthorized data use by participating parties. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the specific embodiments or the prior art. In all the drawings, similar elements or parts are generally identified by similar reference numerals. In the drawings, the elements or parts are not necessarily drawn to scale.
[0043] Figure 1 is the logical schematic diagram of the present invention;
[0044] Figure 2 is the flowchart of the present invention;
[0045] Figure 3 is the device architecture diagram of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0046] The following will describe in detail the embodiments of the technical solutions of the present invention with reference to the drawings. The following embodiments are only used to more clearly illustrate the technical solutions of the present invention, so they are only examples and cannot be used to limit the protection scope of the present invention.
[0047] It should be noted that unless otherwise specified, the technical terms or scientific terms used in this application should have the ordinary meaning understood by those skilled in the art to which the present invention belongs.
[0048] Please refer to Figure 1 and Figure 2 , the method for original data delivery based on a trusted execution environment and a blockchain provided by the embodiment of the present invention includes the following steps:
[0049] S1: Data secondary encryption;
[0050] S2: Establish a data authorization protocol among DA, DP, and TP;
[0051] S3: Establish a data download protocol between DA and TP.
[0052] The step S1 includes the following steps:
[0053] S11: DC transmits the data information related to DP into the enclave of the trusted hardware;
[0054] S12: Decrypt in the enclave to obtain the private key and use the private key to decrypt to obtain the plaintext data M, and use the key K generated in the enclave Y to encrypt the data a second time to obtain Forward the encrypted data encryption key and the private key of DP and send them to TP for verification;
[0055] S13: After TP verifies the signature through the public key of DP, it confirms that the message comes from DC, and DC has completed the second encryption of the data.
[0056] In the step S12, the message content is
[0057] In the step S13, the stored data content of DC is
[0058]
[0059] In the step S2, define the data transaction request of DA as a tuple composed of a hash and an asymmetric key Define the transaction request initiated by DA as Define the authorization certificate granted by DP as requesting the signature of DP's private key
[0060] In the step S2, it specifically includes the following steps:
[0061] S21:. DA locally generates a pair of asymmetric keys, encrypt the private key using the trusted hardware binding public key, and send the ciphertext and the transaction request to TP;
[0062] S22: After TP receives it, forward the hash of the request message to the corresponding owner DP of the data;
[0063] S23: After DP receives the message, verify DA's signature and the requested data using DA's public key. After confirming the data content of the transaction request, send the authorization for the corresponding data to DS for transaction permission;
[0064] S24: After TP receives the message content, confirm to initiate the transaction task, and forward the corresponding authorization and the private key of the corresponding DP to DC;
[0065] S25: In DC, the enclave verifies the legality of the request content using the received authorization. After passing the verification, decrypt to obtain DP's private key, and decrypt using the private key After obtaining the data encryption key, encrypt the encryption key using DA's public key to obtain the ciphertext At this time, the algorithm output of the enclave in the DC is Send the result hash and signature to the TP to verify the message legality, and then store the output together with the ciphertext of the double-encrypted data in the DC.
[0066] In the step S23, the message content is
[0067] In the step S24, the message content is
[0068] In the step S25, the message content is
[0069]
[0070] The step S3 includes the following steps:
[0071] S31: The DC stores the ciphertext information of the double-encrypted data
[0072]
[0073] S32: As long as the DA requests to download the corresponding data ciphertext, the off-chain data delivery can be completed.
[0074] In the above content, the symbol definitions involved are:
[0075] A pair of asymmetric keys that bind the trusted hardware in the DC. After the TP completes the trusted verification of the DC trusted hardware, it is used as the session key for encrypting another pair of asymmetric keys.
[0076] Binding: A pair of keys that bind the identity of the DP or DA, generated locally by the DP or DA, used to encrypt the data of the DP, or for digital signature.
[0077] K Y : The key used to encrypt the data M, generated by the enclave in the TEE of the DC, used for double-encrypting the data of the DP in the DC and decrypting the data by the DA.
[0078] The function used for private key forwarding of the keys of the DP and DA, where represents the private key to be forwarded, represents the public key used to encrypt the private key, and H(enclave) represents the hash of the enclave in the trusted hardware that generates the result.
[0079] DA: Data user.
[0080] DP: Data owner.
[0081] TP: Trusted Third Party.
[0082] DC: Computing Node.
[0083] As can be seen from the above description, in the process of the platform side of the present invention realizing the delivery of data content from the data owner to the data user, the platform has never obtained the clear text of the data and the private key of the user throughout the process, making it impossible for the platform to obtain the relevant content of the data, nor can it trade the data to the data user without the authorization of the data owner, and the security of the data can be guaranteed during the delivery process.
[0084] The present invention provides a secure and effective method for off-chain original data delivery, which can prevent unauthorized access and unauthorized transactions of data, and at the same time can meet the limited performance requirements of the blockchain, ensure the integrity and security of off-chain delivered data, realize trusted transactions between data users and data owners, and effectively prevent malicious data forgery or data overuse by participating parties.
[0085] Please refer to Figure 3 , an embodiment of the present invention provides an original data delivery device based on a trusted execution environment and a blockchain, which is used to implement the foregoing method, including:
[0086] A data secondary encryption module, which is used to implement the data secondary encryption in step S1;
[0087] A data authorization protocol establishment module, which is used to implement the establishment of the data authorization protocol among DA, DP, and TP in step S2;
[0088] A data download protocol establishment module, which is used to implement the establishment of the data download protocol between DA and TP in step S3.
[0089] An embodiment of the present invention also provides a storage medium, which is used to store and read / write the foregoing method.
[0090] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention, and they should all be covered by the scope of the claims and the description of the present invention.
Claims
1. A method for delivering raw data based on a trusted execution environment and blockchain, characterized in that: The following steps are involved: S1: Data secondary encryption; S2: Establish a data authorization agreement between the data user DA, the data owner DP and the trusted third party TP; S3: Establish data download protocol between DA and TP; The step S1 comprises the following steps: S11: The computing node DC sends the DP data information Passed into the trusted hardware enclave, is the encryption function; S12: Decrypt in enclave to obtain private key , and use the private key Decrypt to obtain plaintext data , using the key generated in the enclave Encrypt the data twice to obtain ; Send the encrypted data encryption key and DP's private key to TP for verification; S13: TP verifies the signature through DP's pivot public key and confirms that the message comes from DC. DC has completed the secondary encryption of the data. In the step S2, the data transaction request of DA is defined as a hash and asymmetric key. , The transaction request initiated by DA is defined as , H() is a hash function; the authorization certificate granted by DP is defined as the private key signature of the requesting DP , Authen is the authorization tag; The S2 step specifically includes the following steps: S21: DA locally generates a pair of asymmetric keys, , , use trusted hardware to bind the public key to encrypt the private key, and convert the ciphertext and transaction requests Upload to TP, sign is the signature mark; S22: TP receives the request message and hashes it Forward to the corresponding data owner DP; S23: After receiving the message, DP verifies DA's signature and requested data with DA's public key. After confirming the data content of the transaction request, DP sends the authorization for the corresponding data to DS for transaction permission. S24: After receiving the message content, TP confirms the initiation of the transaction task and forwards the corresponding authorization and the corresponding DP's private key to DC; S25: The enclave in the DC uses the received authorization to verify the legitimacy of the request content. After the verification is passed, it decrypts the private key of the DP and decrypts it with the private key Get Data Easy Key , De is the decryption function, using DA's public key to encrypt the easy key to obtain the ciphertext , the algorithm output of the enclave in DC is , the resulting hash and signature are sent to TP to verify the legitimacy of the message, and then the output is stored in DC together with the twice-encrypted data ciphertext; The step S3 comprises the following steps: S31: DC stores the encrypted data after double encryption ; S32: DA can complete the data chain delivery as long as it requests to download the corresponding data ciphertext; in: , : A pair of asymmetric keys bound to the trusted hardware in the DC. After the TP completes the trusted verification of the DC trusted hardware, it is used as a session key to encrypt another pair of asymmetric keys; : A pair of keys bound to the identity of DP or DA, generated locally by DP or DA, used to encrypt DP data or for digital signature; Data Easy Key: The key used to encrypt data M, generated by the enclave in the TEE of the DC, used for secondary encryption of DP's data in the DC and decryption of data by DA; : A function used to forward the private key of DP and DA, where Indicates the private key being forwarded, represents the public key used to encrypt the private key, A hash representing the enclave in the trusted hardware that produced the result; DA: data user; DP: data owner; TP: Trusted Third Party; DC: compute node.
2. The original data delivery method based on a trusted execution environment and blockchain according to claim 1, characterized in that: In the step S12, the message content is , Also known as a hash function.
3. The original data delivery method based on a trusted execution environment and blockchain according to claim 1, characterized in that: In step S13, the stored data content of DC is , Also known as a hash function.
4. The original data delivery method based on a trusted execution environment and blockchain according to claim 1, characterized in that: In the step S23, the message content is .
5. The original data delivery method based on a trusted execution environment and blockchain according to claim 1, characterized in that: In the step S24, the message content is .
6. The original data delivery method based on a trusted execution environment and blockchain according to claim 1, characterized in that: In the step S25, the message content is .
7. A device for delivering original data based on a trusted execution environment and blockchain, which is used to implement a method for delivering original data based on a trusted execution environment and blockchain as described in any one of claims 1 to 6, characterized in that: include: A data secondary encryption module, which is used to implement the data secondary encryption in step S1; A data authorization agreement establishment module, which is used to implement the establishment of a data authorization agreement between the DA, DP and TP in step S2; The data download protocol establishment module is used to implement the data download protocol establishment between the DA and TP in step S3.
Citation Information
Patent Citations
Block chain data protection system
CN113055376A
Block chain-based secondary data rapid encryption method
CN118041557A