Blockchain-based power grid it asset data management method and device
By generating and verifying ring signatures using blockchain technology, the efficiency and reliability issues in power grid IT asset data management are resolved, enabling efficient and secure data storage and management.
Patent Information
- Application Number
- CN202411735971.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-29
- Publication Date
- 2026-02-27
- Estimated Expiration
- 2044-11-29
AI Technical Summary
Power grid IT assets involve large amounts of data and require high security and reliability; existing technologies struggle to balance management efficiency and reliability.
A blockchain-based approach to power grid IT asset data management is adopted, which generates ring signatures through a data governance platform and verifies them on the blockchain platform to ensure data immutability and user privacy protection.
It enables efficient management and secure storage of power grid IT asset data, prevents data tampering, and ensures data integrity and reliability.
Smart Images

Figure CN119691061B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of power grid IT asset data management, in particular to a power grid IT asset data management method and device based on a block chain, computer equipment, a computer readable storage medium and a computer program product. BACKGROUND
[0002] The power grid IT asset management data is large, and the security and reliability of the asset data are very important to ensure the safe operation of the power grid. Therefore, in this scenario, the management efficiency and management reliability of the power grid IT asset data need to be considered. SUMMARY
[0003] Therefore, it is necessary to provide a power grid IT asset data management method, device, computer equipment, computer readable storage medium and computer program product based on a block chain, which can consider the management efficiency and data reliability of the power grid IT asset data.
[0004] In a first aspect, the present application provides a power grid IT asset data management method based on a block chain, applied to a power grid block chain architecture, the power grid block chain architecture comprising a business system, a data governance platform and a block chain platform, the data governance platform being in communication with the business system and the block chain platform, and the method comprising:
[0005] The data governance platform extracts IT asset data of each business system connected to the data governance platform according to a system set time;
[0006] The data governance platform generates two ring signatures;
[0007] The block chain platform verifies the ring signatures in response to a data on-chain request of the data governance platform;
[0008] If the verification is passed, the block chain platform and the data governance platform are linked to store the IT asset data on the chain.
[0009] In one embodiment, the step of generating two ring signatures by the data governance platform comprises:
[0010] Randomly selecting an integer t and calculating G'=tG; t R [1, q-1], G is a base point on an elliptic curve over a finite field, and q is a prime number meeting a security requirement;
[0011] Randomly selecting an integer k and calculating kG=Ts=(xs, ys), k R [1, q-1];
[0012] Randomly generating a sequence r i R [1, q-1], i = s+1, s+2, L, n, 1, L, s-1;
[0013] calculate c i = H(L, m, x i-1 , G'), (x i , y i ) = T i = r i G + c i pk i + G', where i = s+1, s+2, L, n, 1, L, s-1, and c1= H(L, m, x n , G'), p and H are public parameters;
[0014] calculate c s = H(L, m, x s-1 , G'), r s = k - dk s c s - t (mod q);
[0015] generate a first ring signature a1= (pk1, pk2, L, pk n , c1, r1, c2, L, G') and a second ring signature a2= (pk1', pk2', L, pk n ', c1', r1', c2', L, G').
[0016] In one embodiment, the step of verifying the ring signature comprises:
[0017] extracting ring signatures from the data chaining request, and calculating (x i , y i ) and c i +1; where (x i , y i ) = T i = r i G + c i pk i + G', c i +1 = H(L, m, x i , G'), i = 1, 2, L, n;
[0018] if c n+1 = c1, the ring signature verification is safe;
[0019] extracting element G' from the first ring signature and the second ring signature;
[0020] if the G' extracted from the two ring signatures are the same, it is determined that the two ring signatures are generated by the same signer, and the verification is passed.
[0021] In one embodiment, the method further includes:
[0022] If the verification fails, the connection between the blockchain platform and the data governance platform will be prohibited.
[0023] In one embodiment, the method further includes:
[0024] The business system receives IT asset data, which is the IT asset data obtained by the user terminal in response to the scanning operation of IT equipment. The IT asset data includes equipment category, equipment name, asset status, brand, model, supplier, equipment location, user organization, user department, responsible person, and user.
[0025] In one embodiment, the method further includes:
[0026] The blockchain platform responds to IT asset data adjustment operations by obtaining user login information through the data governance platform.
[0027] If the user login information is found to be inconsistent with the user organization, user department, user and responsible person in the IT asset data, then modification of the IT asset data on the chain is prohibited.
[0028] Secondly, a blockchain-based power grid IT asset data management device is provided, applied to a power grid blockchain architecture. The power grid blockchain architecture includes a business system, a data governance platform, and a blockchain platform. The data governance platform communicates with both the business system and the blockchain platform. The device includes:
[0029] The data extraction module is used to extract IT asset data from various business systems connected to the data governance platform according to the system's set time.
[0030] The ring signature generation module is used to generate two ring signatures;
[0031] The verification module is used to verify the ring signature in response to the data on-chain request from the data governance platform.
[0032] The on-chain execution module is used to link the blockchain platform and the data governance platform if the verification is successful, and store the IT asset data on the blockchain.
[0033] Thirdly, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the above-described blockchain-based power grid IT asset data management method.
[0034] In a fourth aspect, a computer-readable storage medium is provided, and the computer-readable storage medium stores a computer program. The computer program is executed by a processor to implement the steps of the blockchain-based power grid IT asset data management method.
[0035] In a fifth aspect, a computer program product is provided, and the computer program product comprises a computer program. The computer program is executed by a processor to implement the steps of the blockchain-based power grid IT asset data management method.
[0036] The blockchain-based power grid IT asset data management method, device, computer device, computer-readable storage medium, and computer program product have at least the following beneficial effects:
[0037] The data governance platform extracts the IT asset data of each business system connected to the data governance platform according to the system setting time, realizes the extraction of the IT asset data of multiple business systems, and generates a ring signature based on the ring signature. When the IT asset data is chained, the blockchain platform verifies the ring signature in response to the data chaining request of the data governance platform, and when the verification is passed, the blockchain platform and the data governance platform are linked to store the IT asset data on the chain. In the signature verification mode before chaining, the data is chained based on the blockchain between the blockchain platform and the data governance platform. The ring label is generated by selecting the shorthand, which can protect user privacy and prevent data tampering. The efficiency of the ring signature in this mode can be guaranteed, which is conducive to realizing the data governance efficiency of massive asset data management in the power grid scenario. BRIEF DESCRIPTION OF DRAWINGS
[0038] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related art, the drawings needed to be used in the description of the embodiments of the present application or the related art will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and those skilled in the art can obtain other related drawings without creative labor based on these drawings.
[0039] Figure 1 An application environment diagram of the blockchain-based power grid IT asset data management method in an embodiment;
[0040] Figure 2 A flowchart of the blockchain-based power grid IT asset data management method in an embodiment;
[0041] Figure 3 A flowchart of the step of generating two ring signatures by the data governance platform in an embodiment;
[0042] Figure 4 A flowchart of the step of verifying the ring signature in an embodiment;
[0043] Figure 5 Internal structure diagram of computer device in one embodiment
[0044] Figure 6 Internal structure diagram of computer device in another embodiment. DETAILED DESCRIPTION
[0045] In order to make the purpose, technical scheme and advantages of the present application clearer, the present application will be further described in detail below in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application.
[0046] The power grid IT asset data will pass through the asset management system, the IT asset operation and maintenance management mobile system, and the financial system during the entire cycle process. The data of the related business systems (asset management system, IT asset operation and maintenance management mobile system, and financial system) are extracted and integrated through the data governance platform, the power grid IT asset data is extracted, and the extracted data of the data governance platform is chained through the integrated blockchain to ensure that the data cannot be tampered with.
[0047] During the initial stage of the construction of the data governance platform, the power grid IT asset data needs to be extracted from the asset management system, the financial system, and the IT asset operation and maintenance management mobile system. The asset management system and the financial system push the IT asset data related to the power grid IT asset to the data governance platform through the data operation system. The data governance platform chains the data table structure and data batch to the blockchain system.
[0048] However, in the application scenario of massive power grid data, a method suitable for the management of massive power grid data needs to be provided.
[0049] The power grid IT asset data management method based on the blockchain provided in the embodiments of the present application can be applied in the application environment as shown in Figure 1 The business system 102 communicates with the data governance platform 104 through a network. The data storage system can store the IT asset data extracted by the data governance platform 104. The data storage system can be integrated on the data governance platform 104, and the data governance platform 104 can be a cloud server or other network server. The business system 102 can be, but is not limited to, various personal computers, servers, notebook computers, Internet of Things devices, and the like.
[0050] In one embodiment, the present application provides a power grid IT asset data management method based on a blockchain, which is applied to a power grid blockchain architecture. The power grid blockchain architecture includes a business system, a data governance platform, and a blockchain platform. The data governance platform communicates with the business system and the blockchain platform, as shown in Figure 2 The method includes:
[0051] The data governance platform extracts IT asset data from various business systems connected to it at pre-defined intervals. The data governance platform centrally manages and maintains the quality and security of IT asset data. It can automatically extract IT asset data from connected business systems at preset times (e.g., daily, weekly, or monthly). The platform performs preprocessing steps such as data cleaning and formatting on the extracted data to ensure accuracy and consistency. Furthermore, the platform may have data change monitoring capabilities, enabling it to detect changes in IT assets within business systems in real-time or periodically and update the extracted data accordingly.
[0052] The data governance platform generates two ring signatures. Ring signatures allow a member to anonymously sign a message within a group while ensuring the signature's unforgeability. The data governance platform generates two ring signatures for the IT asset data to be uploaded to the blockchain, which can be used for data integrity and source authentication, respectively. When generating ring signatures, the data governance platform can select other blockchain nodes as members of the ring to ensure the anonymity and security of the signature.
[0053] The blockchain platform responds to data upload requests from the data governance platform by verifying the ring signature. When the data governance platform is ready to upload IT asset data to the blockchain, it sends an upload request to the blockchain platform, which may include the previously generated ring signature. Upon receiving the request, the blockchain platform first verifies the validity of the ring signature.
[0054] The process of verifying ring signatures includes checking the signature format, verifying whether the signature was generated by the same member, and confirming that the data bound to the signature has not been tampered with during transmission, which is crucial for ensuring the security and integrity of data on the blockchain.
[0055] If the verification passes, the blockchain platform and the data governance platform will link together to store the IT asset data on the blockchain. If the blockchain platform successfully verifies the validity of the ring signature, it considers the data governance platform a trusted entity and establishes a link with it. Subsequently, the blockchain platform will store the IT asset data on the blockchain, making it part of the blockchain and ensuring the immutability and traceability of the data.
[0056] The process of storing IT asset data on the blockchain can involve dividing the data into smaller blocks (such as through sharding technology) to optimize storage efficiency and security, which is beneficial for improving the efficiency of storing massive amounts of IT asset data on the blockchain in power grid scenarios.
[0057] Specifically, based on the data governance platform, IT asset data of each business system connected with the data governance platform is extracted according to system setting time, the extraction of IT asset data of multiple business systems is realized, and ring signature generation is based on the ring signature generation. When the IT asset data is chained, the blockchain platform responds to the data chaining request of the data governance platform, verifies the ring signature, and when the verification is passed, the blockchain platform and the data governance platform are linked, and the IT asset data is chained and stored. In the signature verification mode before chaining, the data is chained based on the blockchain between the blockchain platform and the data governance platform. The ring label is generated by selecting the shorthand, which can protect user privacy and prevent data from being tampered with. The efficiency of the ring signature in this mode can be guaranteed, which is conducive to realizing the data governance efficiency of massive asset data management in the power grid scenario.
[0058] In one embodiment, the data governance platform generates two ring signatures, as shown in Figure 3 , including:
[0059] S301, randomly select an integer t and calculate G'=tG to create a transformation of a base point; t R [1, q-1], G is a base point on an elliptic curve over a finite field, and q is a prime number that meets the security requirements.
[0060] t R [1, q-1] indicates that t is a random integer between 1 and q-1, and q is a prime number that meets the security requirements. This range ensures the randomness and security of t.
[0061] G is a base point on an elliptic curve over a finite field: G is a fixed point on an elliptic curve, used to generate a public key L and a private key pair.
[0062] S302, randomly select an integer k and calculate kG=Ts=(xs, ys), k R [1, q-1].
[0063] k R [1, q-1] indicates that k is a random integer between 1 and q-1. Ts=(xs, ys) indicates that by point multiplication operation on the elliptic curve, k is multiplied by the base point G to obtain a point Ts on the elliptic curve, which is used as a temporary public key. Therefore, a temporary public key kG is generated through step S302.
[0064] S303, randomly generate a sequence r i ∈ R [1, q-1], i=s+1, s+2, L, n, 1, L, s-1.
[0065] This sequence r ifor the subsequent ring signature computation, where i runs through s+1 to n and then back to 1 to s-1, n is the number of public keys, and s is the index of the current public key (i.e. Ts). r i ∈ R [1, q-1] means that each r i is a random integer between 1 and q-1.
[0066] S304, compute c i =H(L, m, x i-1 , G'), (x i , y i )=T i =r i G+c i pk i +G', where i = s+1, s+2, L, n, 1, L, s-1, take c1=H(L, m, x n , G') to generate the challenge value c i for each public key, and p and H are public parameters.
[0067] where (x i , y i )=T i =r i G+c i pk i +G' means that for each i (not including s), compute T i as a point on the elliptic curve, which is a linear combination of r i , c i , k i , and G'. c i =H(L, m, x i-1 , G') means that the challenge value c i is computed by a hash function H, with inputs including the public key list L, the message m, the x-coordinate x i-1 of the previous point, and the transformed base point G'. c1 is the challenge value at the beginning of the sequence, and c i is computed by the x-coordinate x n of the last point.
[0068] S305, compute c s =H(L, m, x s-1 , G'), r s =k-dk s c s -t (mod q). For s (i.e. the index of the current public key), the challenge value c s is computed by the x-coordinate x s-1 of the previous point.
[0069] S306, Generate the first ring signature α1 = (pk1, pk2, L, pk n (c1, r1, c2, L, G') and the second ring signature α2 = (pk1', pk2', L, pk n ', c1', r1', c2', L, G').
[0070] These two ring signatures contain a list of public keys (pk1, pk2, ..., pk...). n and pk1', pk2', ..., pk n '), Challenge value sequence (c1, c2, ..., c n and c1', c2', ..., c n '), a portion of a random sequence (r1, r2, ..., r n and r1', r2', ..., r n The two ring signatures generated in this step, along with the transformed base point G', can be used for verification. This not only verifies security but also confirms whether the signatures were generated by the same person, enhancing user privacy and preventing data tampering.
[0071] In one embodiment, such as Figure 4 As shown, the steps for performing the ring signature verification include:
[0072] S401, extract the ring signature from the data on-chain request, and calculate (x i y i ) and c i +1; where (x i y i )=T i =r i G+c i pk i +G',c i+1 =H(L, m, x) i ,G'), i=1,2,L,n.
[0073] Ring signatures typically contain a series of public keys, challenge values (or hash values), random numbers, and points on an elliptic curve. The ring signature can be extracted by parsing the data upload request. The point (x) on the elliptic curve corresponding to each public key is calculated. i y i ) and the next challenge value c i+1 Calculate c i+1 When using a hash function H, the input includes a public key list L, a message m, the x-coordinate xi of the current point, and the transformed base point G'. That is, c i+1 =H(L, m, x) i ,G').
[0074] S402, if c n+1 =c1, the ring signature verification is safe.
[0075] By checking whether the last challenge value c n+1 is equal to the first challenge value c1, if equal, it means that the ring is closed, at this time it can be considered that the ring signature is valid.
[0076] S403, extracting element G' from the first ring signature and the second ring signature.
[0077] S404, if the G' extracted from the two ring signatures is the same, it is determined that the two ring signatures are generated by the same signer, and the verification is passed.
[0078] Extracting element G' from the first ring signature and the second ring signature, and comparing the G' extracted from the two ring signatures. If the same, it can be determined that the two ring signatures are generated by the same signer, because the generation of G' depends on the private key of the signer (but the private key is not disclosed, protecting the privacy of the user). Through this verification process, the validity of the signature and the double verification of the signer can be guaranteed, and the security in the process of IT asset data storage is improved.
[0079] In one embodiment, the blockchain-based power grid IT asset data management method further comprises:
[0080] If the verification fails, the blockchain platform and the data governance platform are prohibited from being linked.
[0081] When the verification fails, it means that there is a risk in the on-chain request of the IT asset data, at this time the blockchain platform and the data governance platform cannot be linked, avoiding uploading untrusted data or data security problems caused by attacks from other devices.
[0082] In one embodiment, the blockchain-based power grid IT asset data management method further comprises:
[0083] The business system receives IT asset data, the IT asset data being obtained by a user terminal in response to a scanning operation on an IT device, the IT asset data including device classification, device name, asset status, brand, model, supplier, device location, using organization, using department, responsible person, and user.
[0084] A two-dimensional code or a bar code can be attached to the IT device, and the code carries IT asset data. On this basis, scanning the code to input the product serial number is supported, and the product serial number is unique. If the scanning mode is used, the "IT asset data" carried by the two-dimensional code can be accessed.
[0085] In one embodiment, the blockchain-based power grid IT asset data management method further comprises:
[0086] The blockchain platform acquires user login information through the data governance platform in response to an IT asset data adjustment operation;
[0087] If it is detected that the user login information does not match the using organization, the using department, the user, and the responsible person in the IT asset data, modification of the IT asset data on the chain is prohibited.
[0088] After the asset information is stored on the chain, when subsequent operations such as modification and deletion of the IT asset data are performed, whether the logged-in user matches the responsible person and the user can be used to determine whether the user has the qualification to adjust the IT asset data. If the match fails, the user is not allowed to modify or delete the IT asset data.
[0089] In one embodiment, if it is found that a warning is needed based on comparison of the IT asset data on the chain, at this time, the warning information is sent to the corresponding "responsible person" and "user" to ensure that the relevant technical personnel know the message in the first time and arrange subsequent data security work.
[0090] In one embodiment, the IT asset operation and maintenance management mobile application system synchronously adds the IT asset data by invoking the data governance platform interface before saving the IT asset data to the database.
[0091] It should be understood that although each step in the flowchart involved in each embodiment described above is displayed in sequence according to the arrow, these steps are not necessarily executed in sequence according to the arrow. Unless otherwise stated herein, the execution of these steps is not strictly limited in sequence, and these steps can be executed in other sequences. Moreover, at least part of the steps in the flowchart involved in each embodiment described above can include multiple steps or stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution sequence of these steps or stages is not necessarily sequential, but can be executed in rotation or alternation with at least part of other steps or steps or stages in other steps.
[0092] Based on the same inventive concept, the present application also provides a blockchain-based power grid IT asset data management device for implementing the above-described blockchain-based power grid IT asset data management method. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme described in the above method, so the specific limitations in one or more blockchain-based power grid IT asset data management device embodiments provided below can refer to the limitations of the blockchain-based power grid IT asset data management method described above, which will not be repeated here.
[0093] In one example embodiment, a device applied to a power grid blockchain architecture is provided, the power grid blockchain architecture comprising a business system, a data governance platform, and a blockchain platform, the data governance platform being in communication with the business system and the blockchain platform respectively, the device comprising:
[0094] a data extraction module configured to extract IT asset data of each business system connected to the data governance platform at a system set time;
[0095] a ring signature generation module configured to generate two ring signatures;
[0096] a verification module configured to verify the ring signatures in response to a data on-chain request of the data governance platform;
[0097] an on-chain execution module configured to, if the verification is passed, link the blockchain platform and the data governance platform to store the IT asset data on-chain.
[0098] Each module in the above-described blockchain-based power grid IT asset data management device can be realized wholly or partially by software, hardware, and combinations thereof. Each module described above can be embedded in or independent of a processor in a computer device in hardware form, or can be stored in a memory in a computer device in software form, so as to be called and executed by a processor to perform operations corresponding to each module. Other units or modules can also be included to perform other steps in the above-described method embodiments, which are not described here.
[0099] In one example embodiment, a computer device is provided, which can be a server, and an internal structure diagram of the computer device can be as shown in Figure 5 The computer device comprises a processor, a memory, an input / output interface (I / O), and a communication interface. The processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is configured to provide computing and control capabilities. The memory of the computer device comprises a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operating system and the computer program in the non-volatile storage medium to run. The input / output interface of the computer device is configured to exchange information between the processor and external devices. The communication interface of the computer device is configured to communicate with external terminals through a network connection. The computer program is executed by the processor to implement the above-described method.
[0100] In one example embodiment, a computer device is provided, which can be a terminal, and an internal structure diagram of the computer device can be as shown inFigure 6 The computer device shown in the figure includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input device. Among them, the processor, the memory and the input / output interface are connected through a system bus, and the communication interface, the display unit and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capability. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operating system and the computer program in the non-volatile storage medium to run. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner. The wireless manner can be realized through WIFI, mobile cellular network, Near Field Communication (NFC) or other technologies. The computer program is executed by the processor to realize the above method.
[0101] Those skilled in the art can understand that, Figures 5-6 The structure shown in the figure is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device to which the scheme of the present application is applied. The specific computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different component arrangement.
[0102] In one exemplary embodiment, a computer device is provided, including a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the steps of the above method and achieve the corresponding beneficial effects.
[0103] In one embodiment, a computer readable storage medium is provided, which stores a computer program, and the computer program is executed by the processor to implement the steps of the above method and achieve the corresponding beneficial effects.
[0104] In one embodiment, a computer program product is provided, including a computer program, and the computer program is executed by the processor to implement the steps of the above method and achieve the corresponding beneficial effects.
[0105] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when executed, can include the processes of the above-mentioned embodiment methods. Any reference to memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile memory and volatile memory. The non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. The volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration but not limitation, the RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The database involved in the embodiments provided in the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in the embodiments provided in the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, an artificial intelligence (AI) processor, etc., without being limited thereto.
[0106] The technical features of the above embodiments can be combined in any manner. To make the description concise, all possible combinations of the technical features in the above embodiments are not described, but as long as the combinations of the technical features do not exist contradictions, they should be considered as the scope of the present application.
[0107] The above-described embodiments are merely illustrative of several embodiments of the present application, and the description is relatively specific and detailed, but should not be understood as a limitation on the scope of the patent. It should be noted that for those skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are all within the scope of the present application. Therefore, the scope of protection of the present application should be subject to the appended claims.
Claims
1. A blockchain-based power grid IT asset data management method, characterized in that, The method is applied to a power grid blockchain architecture, the power grid blockchain architecture comprises a business system, a data governance platform, and a blockchain platform, the data governance platform is in communication with the business system and the blockchain platform respectively, and the method comprises the following steps: The data governance platform extracts IT asset data of each business system connected to the data governance platform according to a system setting time; The data governance platform generates two ring signatures; The blockchain platform verifies the ring signatures in response to a data on-chain request of the data governance platform; If the verification is passed, the blockchain platform and the data governance platform are linked to store the IT asset data on the chain; The step of generating two ring signatures by the data governance platform comprises the following steps: Randomly select an integer t and calculate G' = tG; t e R [1, q-1], G is a base point on an elliptic curve over a finite field, used to generate a public key L and a private key pair; t e R [1, q-1] indicates that t is a random integer between 1 and q-1, q is a prime number that meets the security requirements, and G' is the transformed base point; Randomly select an integer k, and calculate kG=Ts=(xs, ys), k∈ R [1, q-1], k∈ R [1, q-1] indicates that k is a random integer between 1 and q-1, Ts=(xs, ys) indicates that k is multiplied by the base point G through the point multiplication operation on the elliptic curve to obtain a point Ts on the elliptic curve, and the point Ts serves as a temporary public key, and kG is a temporary public key. Randomly generate a sequence r i ∈ R [1, q-1], i = s + 1, s + 2, L, n, 1, L, s - 1; wherein i traverses s + 1 to n and then back to 1 to s - 1, n is the number of temporary public keys Ts, s is the index of the temporary public key Ts, r i ∈ R [1, q-1] indicates that each r i is a random integer between 1 and q-1; Compute c i = H(L, m, x i-1 , G'), (x i , y i ) = T i = r i G + c i pk i + G', where i = s + 1, s + 2, L, n, 1, L, s - 1, and c1= H(L, m, x n , G') is computed; p and H are public parameters; and (x i , y i ) = T i = r i G + c i pk i + G' means that for each i not including s, T i is computed as a point on an elliptic curve, which is based on a linear combination of r i , c i , k i , and G'; c i = H(L, m, x i-1 , G') means that the challenge value c i is computed by a hash function H, and the input of the challenge value c i includes the public key list L, the message m, the x-coordinate x i-1 of the previous point, and the transformed base point G'; c1 is the challenge value at the beginning of the sequence; and k i represents a sequence of multiple random integers k generated in the process of i traverses from s + 1 to n and then returns to 1 to s - 1. Compute c s = H(L, m, x s-1 , G'), r s = k - dk s c s = t (mod q); where the challenge value c s is computed from the x-coordinate x s-1 of the previous point, t (mod q) indicates t divided by q with the remainder, q is the modulus; k s represents a random integer when i = s; Generate the first ring signature α1 = (pk1, pk2, ..., pk n (c1, r1, c2, L, G') and the second ring signature α2 = (pk1', pk2', L, pk n (pk1, pk2 ... n ' represents k n The transformed parameters are: c1' represents the transformed parameter of c1, r1' represents the transformed parameter of r1, and c2' represents the transformed parameter of c2.
2. The method of claim 1, wherein, The step of verifying the ring signatures comprises the following steps: extract a ring signature from the data chaining request, and calculate (x i , y i ) and c i +1; wherein (x i , y i ) = T i = r i G + c i pk i + G', c i +1 = H(L, m, x i , G'), i = 1, 2, L, n; If c n+1 = c1, then the ring signature verification is secure. Extracting element G' from the first ring signature and the second ring signature; If the G' extracted from the two ring signatures is the same, it is determined that the two ring signatures are generated by the same signer, and the verification is passed.
3. The method according to any of claims 1-2, characterized in that, The method further comprises the following steps: If the verification is not passed, the blockchain platform and the data governance platform are prohibited from being linked.
4. The method according to any one of claims 1 to 2, characterized in that, The method further comprises the following steps: The business system receives IT asset data, the IT asset data is obtained by a user terminal in response to a code scanning operation on an IT device, and the IT asset data comprises device classification, device name, asset status, brand, model, supplier, device location, using organization, using department, responsible person, and user.
5. The method of claim 4, wherein, The method further comprises the following steps: The blockchain platform obtains user login information through the data governance platform in response to an IT asset data adjustment operation; If it is detected that the user login information does not match the using organization, using department, user, and responsible person in the IT asset data, the IT asset data on the chain is prohibited from being modified. 6.A blockchain-based power grid IT asset data management apparatus, characterized by, The method is applied to a power grid blockchain architecture, the power grid blockchain architecture comprises a business system, a data governance platform, and a blockchain platform, the data governance platform is in communication with the business system and the blockchain platform respectively, and the method comprises the following steps: A data extraction module is configured to extract IT asset data of each business system connected to the data governance platform according to a system setting time; A ring signature generation module is configured to generate two ring signatures; A verification module is configured to verify the ring signatures in response to a data on-chain request of the data governance platform; An on-chain execution module is configured to link the blockchain platform and the data governance platform to store the IT asset data on the chain if the verification is passed. The ring signature generation module is further configured to: Randomly select an integer t and calculate G' = tG; t e R [1, q-1], G is a base point on an elliptic curve over a finite field, used to generate a public key L and a private key pair; t e R [1, q-1] indicates that t is a random integer between 1 and q-1, q is a prime number that meets security requirements, and G' is a transformed base point. A random integer k is selected, and kG=Ts=(xs,ys) is calculated, k∈ R [1, q-1], k∈ R [1, q-1] indicates that k is a random integer between 1 and q-1, Ts=(xs,ys) indicates that a point Ts on the elliptic curve is obtained by multiplying k and the base point G through the point multiplication operation on the elliptic curve, the point Ts is used as a temporary public key, and kG is the temporary public key. Randomly generate a sequence r i ∈ R [1, q-1], i = s + 1, s + 2, L, n, 1, L, s - 1; wherein i traverses s + 1 to n and then back to 1 to s - 1, n is the number of temporary public keys Ts, s is the index of the temporary public key Ts, r i ∈ R [1, q-1] indicates that each r i is a random integer between 1 and q - 1; Compute c i = H(L, m, x i-1 , G'), (x i , y i ) = T i = r i G + c i p k i + G', where i = s + 1, s + 2, L, n, 1, L, s - 1, and c1= H(L, m, x n , G') is computed; p and H are public parameters; where (x i , y i ) = T i = r i G + c i p k i + G' indicates that for each i that does not include s, T i is computed as a point on an elliptic curve, which is based on a linear combination of r i , c i , k i , and G'; c i = H(L, m, x i-1 , G') indicates that the challenge value c i is computed by a hash function H, and the input of the challenge value c i includes the public key list L, the message m, the x-coordinate x i-1 of the previous point, and the transformed base point G'; c1 is the challenge value at the beginning of the sequence; k i indicates a sequence of multiple random integers k generated during the process in which i traverses s + 1 to n and then returns to 1 to s - 1; Compute c s = H(L, m, x s-1 , G'), r s = k - dk s c s = t (mod q); where the challenge value c s is computed from the x-coordinate x s-1 of the previous point, t (mod q) indicates t divided by q with the remainder, q is the modulus; k s represents a random integer when i = s; generating a first ring signature α1= (pk1, pk2, L, pk n , c1, r1, c2, L, G') and a second ring signature α2= (pk1', pk2', L, pk n ', c1', r1', c2', L, G'); pk1 represents a product between a public parameter p and k1 when i = 1; pk2 represents a product between a public parameter p and k2 when i = 2; r1 represents a random integer when i = 1, c2 represents a challenge value when i = 2, k1' represents a parameter after transformation of k1, k2' represents a parameter after transformation of k2, k n ' represents a parameter after transformation of k n , c1' represents a parameter after transformation of c1, r1' represents a parameter after transformation of r1, and c2' represents a parameter after transformation of c2. 7.A computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the computer device is configured to perform the method according to any one of claims 1-6 when the computer program is executed by the processor. The processor implements the steps of the power grid IT asset data management method based on a blockchain in any one of claims 1 to 5 when executing the computer program.
8. A computer-readable storage medium having stored thereon a computer program, characterized in that The computer program is executed by the processor to implement the steps of the power grid IT asset data management method based on a blockchain in any one of claims 1 to 5.
9. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the power grid IT asset data management method based on a blockchain in any one of claims 1 to 5.
Citation Information
Patent Citations
Method and device for generating and verifying linkable ring signature in block chain
CN111915298A
Method for protecting by adopting block chain technology based on existing IT domain asset data of power grid
CN112365362A