A blockchain cross-chain data penetration supervision method and system based on attribute encryption

By combining the attribute encryption method of the off-chain collaborative encryption module OC-ABE, the computational burden, dynamic permission management, privacy protection and audit traceability problems in cross-chain data supervision are solved, and efficient and secure cross-chain data sharing and supervision are achieved, which is suitable for multi-chain environments.

CN119646091BActive Publication Date: 2025-10-03TIANJIN UNIVERSITY OF TECHNOLOGY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411723099.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-28
Publication Date
2025-10-03
Estimated Expiration
2044-11-28

AI Technical Summary

Technical Problem

Existing cross-chain data supervision technologies have shortcomings in terms of computing burden, dynamic permission management, privacy protection, and audit traceability, and are unable to meet the scenarios of frequent access, compliance requirements, and high computing demands in multi-chain environments.

Method used

Combined with the attribute encryption method OC-ABE of the off-chain collaborative encryption module, by performing encryption and decryption, permission management and audit tracing off-chain, it realizes the controlled circulation and secure sharing of data in a multi-chain environment, uses zero-knowledge proof technology to protect user privacy, and supports dynamic permission management and complex calculations.

Benefits of technology

It significantly reduces on-chain computing and storage pressure, improves system performance, realizes dynamic permission management, enhances data privacy protection, supports complex calculations and comprehensive audit traceability, and adapts to efficient and secure data sharing in multi-chain environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119646091B_ABST
    Figure CN119646091B_ABST
Patent Text Reader

Abstract

This invention discloses a blockchain cross-chain data penetration supervision method based on attribute encryption, including the following steps: monitoring data access requests in a cross-chain environment and passing the received requests to a collaborative encryption module; a data verification module receiving attribute vectors and comparing them with verification tags stored on the chain to ensure that the user meets the access conditions; using zero-knowledge proof technology to further verify user permissions; off-chain data encryption and decryption; transmitting the decrypted data to the user end via a secure transmission channel to ensure data security during transmission; and dynamic adjustment of permission policies. This application, combined with OC-ABE, not only improves system efficiency, but also enhances the flexibility of permission management, data privacy, and compliance transparency, making it an ideal choice for achieving efficient and secure cross-chain data supervision in a multi-chain environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of blockchain technology, and in particular to a blockchain cross-chain data penetration supervision method and system based on attribute encryption. Background Art

[0002] Cross-chain data-penetrating supervision technology aims to enable data sharing across different blockchains while ensuring the security, compliance, and privacy of data flows. With the increasing use of blockchain, data is often distributed across different chains. Penetrating supervision technology integrates a variety of innovative methods to help regulators achieve comprehensive control over data flows in a multi-chain environment. Among these methods, attribute-based encryption (ABE) provides a key access control mechanism to ensure the security and compliance of data sharing.

[0003] Attribute-based encryption is a public key encryption method that binds user attributes to access rights policies, ensuring that data can only be decrypted by users who meet specific attribute conditions. A cross-chain data governance solution based on attribute-based encryption provides fine-grained permission management across multiple blockchain systems, ensuring that data access complies with regulatory requirements. For example, in sensitive industries such as finance and healthcare, regulators on different chains can define data access rights based on user attributes such as role and department, thereby achieving controlled cross-chain data circulation.

[0004] To enable secure cross-chain data sharing, standard attribute encryption technology typically performs on-chain permission management and attribute verification. Specifically, when a blockchain receives a data access request, it verifies the requester's permissions based on the attribute policy set during data encryption. This decentralized on-chain verification eliminates reliance on centralized trust mechanisms, ensuring that data is only accessible to authorized parties. This mechanism maintains the distributed architecture advantages of blockchain while enabling compliant access control in a multi-chain environment.

[0005] In a cross-chain environment, attribute-based encryption, a method for on-chain verification, provides a foundation for access control of data across different chains. By defining access conditions for cross-chain data through attribute-based encryption, the system enables refined control and sharing of data based on user attributes. For example, regulators can define different encryption policies for different types of users or organizations on the blockchain based on regulatory requirements, ensuring that cross-chain data transmission meets security and compliance requirements.

[0006] Attribute-based encryption offers privacy protection in blockchain data sharing. Because access conditions are embedded in the data encryption process, only qualified users can decrypt the data, preventing unauthorized parties from viewing its contents. This adds a layer of security to cross-chain data flows. In multi-chain collaboration, attribute-based encryption allows data owners to control data access rights on-chain, integrating data privacy protection with permission control. This feature ensures the isolation and controlled access of sensitive information during cross-chain data transfer, providing fundamental support for blockchain's penetrating oversight.

[0007] By combining blockchain's immutability with the promise of tamper-proofing, attribute encryption also enables auditability and transparency of cross-chain data access. Every data access and permission verification process is recorded on-chain, allowing regulators to review data access records across various chains and ensure that all access complies with pre-defined permission policies. This mechanism provides compliance support for cross-chain data oversight, enabling regulators to effectively track and manage data flows in a multi-chain environment.

[0008] The application of attribute encryption in cross-chain data monitoring within blockchains provides a foundational guarantee for fine-grained control of data access and privacy protection. Through on-chain permission management and attribute verification, regulators can effectively control the flow and access of data in a multi-chain environment, ensuring that cross-chain data sharing is secure and compliant with permission requirements. This background technology holds broad potential for cross-chain data monitoring within blockchains.

[0009] In cross-chain data penetration monitoring on blockchains, attribute-based encryption (ABE) technology does provide fundamental support for fine-grained access control of data. However, conventional attribute-based encryption has certain shortcomings in terms of performance, privacy protection, and flexibility, mainly manifested in the following aspects:

[0010] First, on-chain computing and storage pressures are high. Standard attribute encryption performs encryption, decryption, and permission verification on-chain, requiring blockchain nodes to handle significant computing and storage tasks. As cross-chain data volumes increase, on-chain resource consumption rises significantly. Especially in scenarios with frequent access, on-chain loads can lead to degraded system performance, increased latency, and increased on-chain congestion. This model struggles to adapt to the high-frequency data access demands of a multi-chain environment.

[0011] Second, it lacks dynamic permission management capabilities. Conventional attribute encryption typically employs static permission policies. Once data is encrypted, access conditions are fixed. In cross-chain regulatory scenarios, regulatory requirements can change at any time, and static permission policies struggle to respond promptly. For example, when user permissions change or regulatory rules are updated, traditional attribute encryption struggles to adjust permission management in real time. This can lead to access that doesn't meet current requirements or hinder compliant data sharing.

[0012] Third, privacy protection is limited. In standard attribute encryption, some attribute verification and encryption processes are completed on-chain, potentially exposing sensitive information to the blockchain, increasing the risk of privacy breaches. In cross-chain data sharing involving multiple parties, exposing user or node permissions could pose a security risk to sensitive data.

[0013] Fourth, there are limitations in audit traceability and support for complex computations. Standard attribute encryption faces limitations in cross-chain data oversight. Limited on-chain resources limit the recording capacity of standard attribute encryption, making it unable to meet regulators' needs for detailed operation logs and comprehensive tracking. Furthermore, standard attribute encryption only supports basic permission control, making it difficult to perform complex computations and multi-party collaborative data processing in a multi-chain environment. In scenarios such as finance and big data, regulators may require cross-chain joint computing and data analysis, and standard attribute encryption cannot meet these demanding computational requirements.

[0014] Therefore, existing cross-chain data supervision technologies have shortcomings in terms of computational burden, dynamic permission management, privacy protection, and audit traceability, making them difficult to meet the needs of frequent access, compliance requirements, and high computational demands in multi-chain environments. Current technologies urgently need an optimized solution that can flexibly adjust permission policies, enable efficient collaborative computing on and off-chain, and enhance privacy protection and audit transparency to better support the secure sharing and efficient supervision of cross-chain data. Summary of the Invention

[0015] In response to the shortcomings in cross-chain data supervision identified in the aforementioned background technology, the present invention aims to propose a blockchain cross-chain data penetration supervision method and system based on attribute encryption. By combining the attribute encryption method OC-ABE (Off-chain Collaborative Attribute-Based Encryption) with the off-chain collaborative encryption module, the present invention aims to achieve data security, privacy protection, and dynamic rights management in a multi-chain blockchain environment. The present invention's solution covers off-chain encryption and decryption, rights management, data verification, and audit traceability, enabling controlled data circulation and secure sharing in a multi-chain environment, ensuring that all data remains authentic and untampered during the supervision process.

[0016] To achieve the above objectives, the present invention provides the following technical solutions:

[0017] First aspect

[0018] The present invention provides a blockchain cross-chain data penetration supervision method based on attribute encryption, comprising the following steps:

[0019] Step 1: Monitor data access requests in the cross-chain environment and pass the received requests to the off-chain collaborative encryption module of OC-ABE; the collaborative encryption module parses the user attribute information and converts it into the attribute vector A i =(a1, a2, ...a n ), and compare it with the preset permission rules according to its attributes;

[0020] Step 2: The data validation module receives the attribute vector A i , call the verification mark stored on the chain for comparison to ensure that the user meets the access conditions;

[0021] Step 3: OC-ABE uses zero-knowledge proof technology to further verify user permissions in OC-ABE;

[0022] Step 4: Off-chain data encryption and decryption;

[0023] Step 5: The decrypted data is transmitted to the user end through a secure transmission channel to ensure the security of the data during transmission. After the transmission is completed, the system automatically clears the decrypted data in the temporary storage off-chain to prevent data leakage or unauthorized repeated access.

[0024] Step 6: Dynamic adjustment of permission policy;

[0025] Step 7: The system records detailed information about each data access and encryption / decryption operation in the off-chain log management module. All log files are managed in the off-chain distributed storage to ensure the integrity and immutability of the records and facilitate auditing.

[0026] Step 8: Generate a log snapshot and lock it;

[0027] Step 9: The system uploads the encrypted log snapshot to the blockchain to store evidence on the chain and ensure that the log cannot be tampered with; the evidence information is recorded on the chain for use in compliance checks:

[0028] Step 10: After each review, a snapshot of the audit records is generated and uploaded to the blockchain to ensure transparency and compliance of the data access process.

[0029] Second aspect

[0030] The present invention provides a blockchain cross-chain data penetration supervision system based on attribute encryption, which executes the above method.

[0031] Compared with the prior art, the present invention has the following beneficial effects:

[0032] In the cross-chain data penetration supervision of blockchain, the attribute encryption scheme combined with OC-ABE shows significant advantages compared with the traditional attribute encryption scheme, which corresponds to the aforementioned shortcomings one by one and effectively solves the shortcomings of the traditional scheme.

[0033] First, it significantly reduces on-chain computing and storage pressure, improving system performance. Traditional attribute encryption schemes require on-chain encryption, decryption, or permission verification operations, placing high demands on the computing and storage resources of on-chain nodes. Especially in cross-chain environments, frequent data access can lead to a surge in on-chain resource consumption, impacting system performance. However, with OC-ABE, the computationally demanding tasks of attribute encryption can be performed off-chain, while only verification tags or lightweight attribute condition information need to be stored on-chain, significantly reducing the on-chain burden. By moving these computationally intensive operations off-chain, the system reduces on-chain latency and congestion, making it particularly suitable for the frequent data exchange requirements of cross-chain environments. This simplified on-chain verification process makes the system more responsive, easily capable of handling large-scale, multi-chain data flows, and achieving more efficient resource utilization and operational efficiency.

[0034] Second, it enables dynamic permission management, flexibly responding to changing regulatory requirements. Traditional attribute encryption schemes typically employ static policies for permission management. Once data encryption is complete, access conditions are fixed, making them difficult to adapt to dynamic regulatory requirements. However, in a multi-chain and cross-chain regulatory environment, user permissions and regulatory rules on different chains may change frequently, making static permission policies difficult to respond to these needs in a timely manner. With the integration of OC-ABE, permission management is no longer limited to static settings. Off-chain modules can rapidly verify and adjust permission conditions based on real-time regulatory requirements, ensuring that permission requirements across different blockchains can flexibly respond to changes. The system can more intelligently manage permissions and promptly respond to the complex and ever-changing scenarios of cross-chain data sharing. This dynamic permission management mechanism is particularly suitable for multi-party collaboration and multi-chain environments, providing regulators with a high degree of adaptability and flexibility, significantly improving the system's scalability and management efficiency.

[0035] Third: Improve data privacy and prevent the leakage of sensitive information. Traditional attribute-based encryption schemes, when performing partial encryption and permission verification on-chain, may expose sensitive information on the blockchain, increasing the risk of data leakage. This is particularly true in cross-chain data sharing involving multiple parties. Once a user's permission attributes are exposed on-chain, data privacy can be compromised. With OC-ABE, encryption and decryption of sensitive data are performed entirely off-chain, with only lightweight verification information or zero-knowledge proofs stored on-chain, preventing direct data exposure. This design effectively enhances data privacy, better preventing the risk of sensitive information leakage in multi-chain data sharing scenarios, and ensuring the secure flow of cross-chain data between different regulators. Furthermore, with the help of privacy protection mechanisms such as zero-knowledge proofs, the requester's permissions can be verified on-chain without exposing specific attributes, further enhancing data privacy.

[0036] Fourth: Support for complex computations and comprehensive audit and traceability meets compliance requirements. Conventional attribute encryption (ACE) faces audit and traceability limitations in cross-chain data oversight, and also falls short in complex data processing and multi-party collaborative computing. The OC-ABE solution, combined with the OC-ABE protocol, not only supports basic encryption and decryption operations but also handles a variety of complex computational tasks, such as data sharding, statistical analysis, and multi-party collaboration. On-chain verification only requires verification of off-chain processing results, reducing excessive on-chain resource consumption and meeting the high cross-chain computing demands of finance and big data scenarios. Furthermore, OC-ABE logs every data access and operation in detail and regularly uploads snapshots of verification results to the chain, enabling comprehensive audit and traceability. Through distributed log management and on-chain evidence storage, regulators can track every data access and usage, ensuring system compliance and operational transparency. This approach is particularly suitable for scenarios such as finance and healthcare, which require rigorous audits.

[0037] This application's solution, combining attribute encryption with OC-ABE, offers significant advantages in four key areas: on-chain resource utilization, dynamic permissions management, privacy protection, and audit traceability. This solution addresses the shortcomings of traditional attribute encryption in cross-chain governance. Combined with OC-ABE, it not only improves system efficiency but also enhances the flexibility of permissions management, data privacy, and compliance transparency, making it an ideal choice for efficient and secure cross-chain data governance in a multi-chain environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] Figure 1 A schematic diagram of a method flow chart adopted by an embodiment of the present invention;

[0039] Figure 2 A user query graph in an embodiment of the present invention;

[0040] Figure 3 A flowchart of data usage in an embodiment of the present invention;

[0041] Figure 4 This is a diagram of the computing environment structure of an embodiment of the present invention. DETAILED DESCRIPTION

[0042] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0043] See also Figures 1-4 As shown, a blockchain cross-chain data penetration supervision method based on attribute encryption includes the following steps:

[0044] Step 1: The system monitors data access requests in the cross-chain environment and passes the received requests to the off-chain collaborative encryption module of OC-ABE. The collaborative encryption module parses the user attribute information and converts it into the attribute vector A i =(a1, a2, ...a n ) and compares its attributes with the preset permission rules.

[0045] Step 2: The data validation module receives the attribute vector A i , calling the verification mark stored on the chain for comparison to ensure that the user meets the access conditions.

[0046] The verification token determines permissions based on the following formula:

[0047]

[0048] Among them, w j Where is the weight of each attribute, and T is the minimum verification threshold. When the conditions are met, the preliminary verification results are recorded. The results are logged to the off-chain log system for further review.

[0049] It should be noted that the collaborative encryption module and data verification module are located in a virtualized isolation environment off-chain to ensure the security protection of user privacy and compliance of the verification process.

[0050] Step 3: To protect user privacy, OC-ABE uses zero-knowledge proof technology to further verify user permissions in OC-ABE. During the verification process, the system generates a hash value H(A i ) and determine whether it belongs to the valid hash set V. It is determined to be passed when the following conditions are met: H(A i)∈V. If the verification fails, the system returns insufficient authority; if the verification passes, the verification result is recorded and the system enters the data processing stage.

[0051] The details are as follows:

[0052] Step 3.1 The permission verification module initiates zero-knowledge proof to further verify user permissions and ensure that access conditions are met.

[0053] During the verification process in step 3.2, the module protects the privacy of user attributes through on-chain marking to ensure that sensitive information is not exposed on the chain.

[0054] If the verification in step 3.3 is successful, the verification result is recorded in the log; if it fails, access is denied and the process returns to step 1.

[0055] Step 4: Off-chain data encryption and decryption

[0056] Step 4.1: Based on the verification results, the system performs data encryption or decryption off-chain.

[0057] Step 4.2: If it is an encryption operation, the system uses symmetric encryption to generate the ciphertext: C = E key (D);

[0058] Among them, D is the original data, E key It is a symmetric encryption operation, and the encrypted data is stored off-chain, with only the verification mark stored on the chain.

[0059] Step 4.3: If it is a decryption operation, the decrypted data is temporarily stored off-chain and prepared for transmission.

[0060] For requests that pass verification, the encryption / decryption submodule encrypts or decrypts the data based on the permissions policy. If the requested data is already encrypted, the decryption module decrypts it and temporarily stores it off-chain. The decrypted data can only be transmitted to the user off-chain. If the user requests new data, the encryption module generates an encryption key and stores the encrypted data off-chain, saving only the verification mark on-chain.

[0061] Step 5: The decrypted data is transmitted to the user via a secure transmission channel to ensure data security during transmission. After the transmission is completed, the system automatically clears the decrypted data from the temporary off-chain storage to prevent data leakage or unauthorized repeated access.

[0062] Step 6: Dynamically adjust the permission policy

[0063] Step 6.1: In the system permission management module, monitor the changes in the permission policy on the chain in real time. If the permission conditions change, the permission management module updates the OC-ABE verification rules according to the new policy.

[0064] Step 6.2: The updated permission policy is applied to all subsequent data access requests to ensure that each verification meets the latest compliance requirements.

[0065] It should be noted that the permission management module also runs in a virtualized isolation environment to adjust permission policies in real time, and all permission update records are stored in the off-chain data storage system;

[0066] Step 7: The system records detailed information about each data access and encryption / decryption operation in the off-chain log management module. All log files are managed in off-chain distributed storage to ensure the integrity and immutability of the records and facilitate auditing.

[0067] It should be noted that the log management module is deployed in the distributed log file system under the chain, and regularly generated log snapshots are uploaded to the blockchain to form on-chain evidence to ensure the security and compliance of operation records and facilitate subsequent audits.

[0068] Step 8: Generate a log snapshot and lock it;

[0069] Step 8.1: The audit module periodically generates log snapshots and hashes the snapshots to ensure the integrity of the log content.

[0070] Step 8.2: The hashed log snapshot is stored off-chain and is prepared to be uploaded to the blockchain periodically for evidence storage.

[0071] Step 9: The system uploads the encrypted log snapshot to the blockchain for on-chain evidence storage, ensuring that the log cannot be tampered with. This evidence is recorded on-chain for compliance checks.

[0072] Step 10: After each review, a snapshot of the audit records is generated and uploaded to the blockchain to ensure transparency and compliance of the data access process.

[0073] Before a user requests data access, OC-ABE extracts the data's hash value from the blockchain for integrity verification and compares it with the data stored off-chain. If the verification result indicates that the data has not been tampered with, the off-chain module authorizes the user to access the requested data using the decryption key and performs data processing or analysis in a designated off-chain environment to generate the required model or results. If the verification fails, the data access request will be denied, ensuring the security and reliability of data use.

[0074] Through these specific implementation steps, a cross-chain data penetration supervision solution with on-chain and off-chain collaboration is realized in the OC-ABE system, which can ensure the security, compliance and privacy protection of cross-chain data in each process node.

[0075] The above shows and describes the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The above embodiments and descriptions are merely preferred examples of the present invention and are not intended to limit the present invention. Various changes and improvements may be made to the present invention without departing from the spirit and scope of the present invention. Such changes and improvements fall within the scope of the present invention. The scope of protection claimed in the present invention is defined by the appended claims and their equivalents.

Claims

1. A blockchain cross-chain data penetration supervision method based on attribute encryption, characterized in that: The following steps are involved: Step 1: Monitor data access requests in the cross-chain environment and pass the received requests to the off-chain collaborative encryption module of OC-ABE; the collaborative encryption module parses the user attribute information and converts it into the attribute vector A i =(a1,a2,...a n ), and compare it with the preset permission rules according to its attributes; Step 2: The data validation module receives the attribute vector A i , call the verification mark stored on the chain for comparison to ensure that the user meets the access conditions; Step 3: OC-ABE uses zero-knowledge proof technology to further verify user permissions in OC-ABE; Step 4: Off-chain data encryption and decryption; Step 5: The decrypted data is transmitted to the user end through a secure transmission channel to ensure the security of the data during transmission. After the transmission is completed, the system automatically clears the decrypted data in the temporary storage off-chain to prevent data leakage or unauthorized repeated access. Step 6: Dynamic adjustment of permission policy; Step 7: The system records detailed information about each data access and encryption / decryption operation in the off-chain log management module. All log files are managed in the off-chain distributed storage to ensure the integrity and immutability of the records and facilitate auditing. Step 8: Generate a log snapshot and lock it; Step 9: The system uploads the encrypted log snapshot to the blockchain to store evidence on the chain and ensure that the log cannot be tampered with; the evidence information is recorded on the chain for use in compliance checks: Step 10: After each review, a snapshot of the audit records is generated and uploaded to the blockchain to ensure transparency and compliance of the data access process.

2. A blockchain cross-chain data penetration supervision method based on attribute encryption according to claim 1, characterized in that: In step 2, the verification token determines the permissions based on the following formula: Among them, w j is the weight of each attribute, T is the minimum verification threshold, and when the conditions are met, the preliminary verification results are recorded; the results are recorded in the off-chain log system for further review.

3. A blockchain cross-chain data penetration supervision method based on attribute encryption according to claim 2, characterized in that: In step 3, during the verification process, the system generates a hash value H(A i ) and determine whether it belongs to the valid hash set V. It is determined to be passed when the following conditions are met: H(A i )∈V; if the verification fails, the system returns insufficient authority; if the verification passes, the verification result is recorded and the data processing phase begins.

4. A blockchain cross-chain data penetration supervision method based on attribute encryption according to claim 3, characterized in that: Step 4 includes the following: Step 4.1: Based on the verification results, the system performs data encryption or decryption off-chain; Step 4.2: If it is an encryption operation, the system uses symmetric encryption to generate the ciphertext: C = E key (D); Among them, D is the original data, E key It is a symmetric encryption operation, and the encrypted data is stored off-chain, with only the verification mark stored on-chain; Step 4.3: If it is a decryption operation, the decrypted data is temporarily stored off-chain and prepared for transmission.

5. The blockchain cross-chain data penetration supervision method based on attribute encryption according to claim 4 is characterized in that: Step 6 includes the following: Step 6.1: In the system permission management module, monitor the changes in the permission policy on the chain in real time. If the permission conditions change, the permission management module updates the OC-ABE verification rules according to the new policy; Step 6.2: The updated permission policy is applied to all subsequent data access requests to ensure that each verification meets the latest compliance requirements.

6. A blockchain cross-chain data penetration supervision method based on attribute encryption according to claim 5, characterized in that: Step 8 includes the following: Step 8.1: The audit module periodically generates log snapshots and hashes the snapshots to ensure the integrity of the log content. Step 8.2: The hashed log snapshot is stored off-chain and is prepared to be uploaded to the blockchain periodically for evidence storage.

7. A blockchain cross-chain data penetration supervision system based on attribute encryption, characterized by: The system executes the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Database access authority management system and method based on block chain

    CN117971980A

  • Blockchain cross-chain regulation method for governance of chain by chain

    WO2023201927A1