A data tracing method based on blockchain
By using hash functions and blockchain technology in the cloud storage platform, establishing a data association model and generating block credentials, the security and traceability problems in the data sharing process in the cloud storage platform are solved, data immutability and traceability are realized, and the effectiveness of user access control is improved.
Patent Information
- Application Number
- CN202411459908.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-18
- Publication Date
- 2025-08-08
- Estimated Expiration
- 2044-10-18
AI Technical Summary
In a cloud storage platform with multi-user access control and data sharing, there are problems of data corruption, stealing, illegal sharing and privacy leakage during the data sharing process, and the illegal behavior of users is difficult to trace, resulting in difficult to ensure data security and recovery.
By hashing the user's identity information using hash functions in the cloud storage platform, a data association model is established, and a blockchain storage hash value is used to generate block credentials to realize data traceability and ensure that the data is not tampered with and traceable.
It realizes the immutability and traceability of data in the cloud storage platform, improves data security and user access control effectiveness, and solves the problem of difficult to track user illegal sharing behavior.
Smart Images

Figure CN119691783B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data tracing technology, and in particular to a data tracing method based on blockchain. Background Art
[0002] Enterprise systems with multi-user access control and data sharing functions are remotely accessed and shared through cloud storage platforms with remote service features. Therefore, data on the cloud storage platform is transmitted between different systems and network components. Data transmission occurs within a single data control center and between multiple data control centers. This leads to damage to cloud storage data during sharing due to software and hardware incompatibility. In order to further ensure data recoverability, a variety of data sharing and storage paths are built. This diversity leads to security issues such as data theft, illegal sharing, and privacy leakage in the cloud storage platform. Among these security issues, it is difficult to trace the source of illegal user behavior due to its sharing nature, which increases the difficulty of maintaining data security in the cloud storage platform. When a data leak occurs, it is difficult to determine which untrusted user's behavior caused the data leak and the impact of such a data leak within a limited time period. As a result, the cloud storage platform with remote service features loses physical control over the diverse data. Therefore, it is necessary to design a blockchain-based data tracing method to improve the data security of user access and the effectiveness of data tracing. Summary of the Invention
[0003] The purpose of the present invention is to provide a data tracing method based on blockchain to solve the problems raised in the above background technology.
[0004] In order to solve the above technical problems, the present invention provides the following technical solutions: a data tracing method based on blockchain, comprising the following steps:
[0005] Step 1: The cloud storage platform of the enterprise system provides remote services based on cloud data, and uses the recording terminal of the cloud storage platform to record and store the source information data of user access control and operation behavior;
[0006] Step 2: The cloud storage platform uses a hash function to perform a hash operation on the user identity information in the source information data, and establishes a data association model based on the access control and operation process description information data recorded in the storage;
[0007] Step 3: Use blockchain to store the hash value of the cloud storage source information data in the block, and generate a block certificate for tracing the cloud storage source information data;
[0008] Step 4: When a data traceability request is generated, the blockchain-based cloud storage source information data is triggered to enter the verification and traceability mechanism to trace the source information data.
[0009] According to the above technical solution, the step of using the recording terminal of the cloud storage platform to record and store the source information data of the user's access control and operation behavior includes:
[0010] The recording terminal of the cloud storage platform monitors the access control and operation behaviors performed by users on the cloud data in the remote server;
[0011] Set up a source data record trigger mechanism for user-side operations on cloud data. Operations on cloud data include: adding, deleting, modifying, copying, moving and sharing cloud data;
[0012] When a user performs the above operations based on cloud data, the recording mechanism will be triggered;
[0013] The recording terminal of the cloud storage platform records the corresponding execution operations of the user end and converts them into cloud data source information data. The source information data in the cloud data records all operations performed by the current user on the cloud data, including the user identity information of the operation, the execution time data and the attributes of the cloud data;
[0014] The first step is to encrypt all source information data recorded by the recording terminal of the cloud storage platform through a searchable encryption algorithm. Other terminal users without the decryption key cannot perform corresponding operations on the source information data.
[0015] According to the above technical solution, the step of using a hash function to perform a hash operation on the user identity information in the source information data includes:
[0016] The user identity information data in the source information data includes the user's ID identity data and the real identity data for entering the cloud storage platform. The user identity information data in the cloud storage source information data is hashed using a hash function. Then the cloud storage platform uses the key center to hash the user identity information through a secure hash algorithm to generate an identity unique identifier, and selects security parameters and system property sets to generate a master key pair for the cloud storage platform, and generates an attribute private key corresponding to the user identity information.
[0017] According to the above technical solution, the step of establishing a data association model based on the recorded and stored descriptive information data of access control and operation processes includes:
[0018] The key center uses the data association model to obtain the user attribute set based on the generated user identity unique identifier. When the user who has hashed the user identity information data joins the blockchain network as a node, the ECDSA signature algorithm is used to assign a public key and a private key to the user. The key center assigns an identification ID to each hashed user and concatenates the user's identification ID with the descriptive information data generated by the user during the access control operation using the established source information data association model.
[0019] The Keccak algorithm is used simultaneously for further hash operations, and the hash value is encrypted with the user's public key to form a user authentication credential. The user credential is mapped to the user ID, and the key center writes this mapping relationship into the blockchain through the user identity information confidentiality contract. This mapping relationship is the user's identity authentication credential. The verification of user identity is based on the generation of the identity authentication credential, so that other shared terminal users in the data source information and participating users in the blockchain cannot tamper with the cloud storage data source information and the privacy information of a specific user.
[0020] According to the above technical solution, the step of storing the hash value of the cloud storage source information data in the block using the blockchain includes:
[0021] The blockchain stores the hash value of the cloud storage source information data in the block. Each source information data in the cloud platform has a unique block certificate corresponding to it in the blockchain. The cloud storage source information data is verified through the block certificate, forming a traceability mechanism for the corresponding source information data.
[0022] After the source information data is published on the blockchain, the block containing the hash value of the cloud data source information data is added to the blockchain. The hash value representing the cloud storage source information data is further stored in the leaf node of the block. The flow source information data generated by the access control operation performed by each user is added to the blockchain network as a node. The traceability information is stored in each block of the blockchain. The execution action between the flow source information data nodes generated by the user's execution operation is used as the carrier for storage. Each node in the blockchain network will back up all the execution information on the chain.
[0023] That is, the traceability information recorded on the blockchain is jointly maintained by each node. At the same time, each node in the blockchain network can obtain the traceability information of any source information data. Then the cloud storage platform stores the cloud storage source information data in the source information database, where the on-chain storage content specifically includes the execution hash value of each traceability information and the additional traceability information. The mapping relationship between the source information data ID and the execution hash value of the traceability information corresponding to the attached data ID is written on the chain through the traceability information verification mechanism. By setting the attribute set or access structure for the user's private key or ciphertext, it can only be correctly decrypted when the attribute set matches the access structure. The specific execution operation information, data transfer information and data attribute information of the source information data entity are also written in detail on the blockchain through the corresponding smart contract, completing the on-chain verification of the cloud storage source information data based on the block certificate of the source information data.
[0024] According to the above technical solution, the step of generating a data tracing request and tracing the source information data includes:
[0025] When a data traceability request is generated, the source information data traceability verification terminal in the cloud storage platform sends a request to the blockchain to obtain the cloud storage source information data block certificate;
[0026] The blockchain generates a block certificate for the cloud storage source information data by accessing the block resource manager and sends it to the cloud storage source information data verification and tracing terminal. The block certificate contains the hash value of the source information data and a tree certificate for verifying the hash value of the source information data's origin. The tree certificate is the path from the leaf node storing the hash value of the cloud data source information data to the root node of the tree. The source information data tracing and verification terminal verifies the cloud storage source information data by reconstructing the tree using the block certificate.
[0027] When the source information data tracing verification terminal reconstructs the tree successfully, the source information data in the source information database is true. By tracing the source information through the data associated with the source information data row, if the source information data tracing verification terminal reconstructs the tree failure, the source information data in the source information database is judged to be false, and further judged whether the cloud storage source information data in the source information database has been tampered with.
[0028] Obtain the corresponding traceability information storage and flow hash through the identification ID corresponding to the traceability data, obtain the data identification ID to be traced, and obtain the blockchain execution hash value of the latest traceability information of this data through the data ID, and judge whether the execution hash value exists. If not, it means that this data has no relevant traceability information. If it exists, proceed to the next step, and obtain the specific information data of the execution operation from the blockchain according to the execution hash value, and obtain the traceability information of this data from the attached data. Whether this traceability information has execution operation data, the source information data tracing verification terminal uses the block certificate to verify the specific information of the source information data. If it exists, directly obtain the result set of the traceability information storage, and add the result set to the source information database in the data traceability request.
[0029] According to the above technical solution, the blockchain-based data tracing system includes:
[0030] The source information data recording and storage module is used to record and store source information data of user access control and operation behaviors using the recording terminal of the cloud storage platform;
[0031] The source information data encryption and chain verification module is used to encrypt the source information data and verify the block chain;
[0032] The source information data verification and tracing module is used to perform block certificate verification and tracing on the source information data that generates the data tracing request.
[0033] Compared with the prior art, the beneficial effects achieved by the present invention are as follows: the present invention provides remote services based on cloud data through the cloud storage platform of the enterprise system, utilizes the recording terminal of the cloud storage platform to record and store the source information data of user access control and operation behavior, and uses a hash function to perform hash operations on the user identity information in the source information data, and establishes a data association model based on the descriptive information data of the access control and operation process recorded and stored, and further utilizes the blockchain to store the hash value of the cloud storage source information data in the block, and generates a block certificate for tracing the cloud storage source information data. Therefore, when a data tracing request is generated, the cloud storage source information data based on the blockchain is triggered to enter the verification and tracing mechanism to trace the source information data, ensuring the immutability of the cloud storage source information data while realizing the effective traceability of the source information data of the cloud data execution operations based on the sharing platform, realizing the accountability and evidence of the execution operations based on the cloud data, solving the problem that it is difficult to track the illegal sharing behavior of users, and improving the security of the cloud storage platform with remote sharing services. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:
[0035] Figure 1 A flowchart of a blockchain-based data tracing method provided in Example 1 of the present invention;
[0036] Figure 2 A schematic diagram of the module composition of a blockchain-based data tracing system provided in Example 2 of the present invention. DETAILED DESCRIPTION
[0037] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0038] Example 1: Figure 1 This is a flowchart of a data tracing method based on blockchain provided in Example 1 of the present invention. This embodiment can be applied to the scenario of data tracing on a remote sharing platform. This method can be executed by a data tracing system based on blockchain provided in this embodiment. Figure 1 As shown, the method specifically includes the following steps:
[0039] Step 1: The cloud storage platform of the enterprise system provides remote services based on cloud data, and uses the recording terminal of the cloud storage platform to record and store the source information data of user access control and operation behavior;
[0040] In an embodiment of the present invention, after the cloud storage platform of the enterprise system generates a remote service, the recording terminal of the cloud storage platform is used to record and store the source data. The recorded source information data includes: the source data that generates the current data state and the operation process data, that is, the read and write operation data including the addition, deletion, modification, query, copy, and move, the descriptive information data of the access control and operation process, and the status data of the different data states of each data during the access control and operation behavior process;
[0041] Exemplarily, the recording terminal of the cloud storage platform monitors the access control and operation behaviors performed by the user on the cloud data in the remote server, and sets a source data recording trigger mechanism for the user-side operations on the cloud data. The operations performed on the cloud data include the addition, deletion, modification, copying and mobile sharing of the cloud data by the user. When the user generates the above-mentioned execution operations based on the cloud data, the recording mechanism will be triggered. The recording terminal of the cloud storage platform records the corresponding execution operations of the user side and converts them into cloud data source information data. The source information data in the cloud data records all operations performed by the current user on the cloud data, including the user identity information of the operation, the time data of the execution and the attributes of the cloud data, and performs the first step of encryption processing on all source information data recorded by the recording terminal of the cloud storage platform through a searchable encryption algorithm. Other terminal users without the decryption key cannot perform corresponding execution operations on the source information data.
[0042] Step 2: The cloud storage platform uses a hash function to perform a hash operation on the user identity information in the source information data, and establishes a data association model based on the access control and operation process description information data recorded in the storage;
[0043] In an embodiment of the present invention, the user identity information data in the source information data includes the user's ID identity data and the real identity data for entering the cloud storage platform. The user identity information data in the cloud storage source information data is hashed by using a hash function. Then, the cloud storage platform uses a key center to hash the user identity information using a secure hash algorithm to generate an identity unique identifier, and selects a security parameter and a system attribute set to generate a master key pair for the cloud storage platform, thereby generating an attribute private key corresponding to the user identity information.
[0044] Exemplarily, the key center obtains a user attribute set based on the generated unique identifier of the user identity using a data association model. When the user whose identity information data is hashed joins the blockchain network as a node, the ECDSA signature algorithm is used to assign a public key and a private key to the user. The key center assigns an identification ID to each hashed user, and concatenates the identification ID of the user with the descriptive information data generated by the user during the access control operation using the established source information data association model.
[0045] Exemplarily, the Keccak algorithm is used for further hash operations, and the hash value is encrypted with the user's public key to form a user authentication credential. The user credential is mapped to the user ID, and the key center writes this mapping relationship into the blockchain through the user identity information confidentiality contract. This mapping relationship is the user's identity authentication credential. The verification of the user's identity is based on the generation of the identity authentication credential, so that other shared terminal users in the data source information and participating users in the blockchain cannot tamper with the cloud storage data source information and the private information of a specific user, thereby ensuring the privacy and authenticity of the cloud storage user identity;
[0046] Step 3: Use blockchain to store the hash value of the cloud storage source information data in the block, and generate a block certificate for tracing the cloud storage source information data;
[0047] In an embodiment of the present invention, the blockchain stores the hash value of the cloud storage source information data in a block. By using the blockchain, the source information data of the cloud storage data is reinforced to be tamper-proof. Each source information data in the cloud platform has a unique copyright block IP corresponding to it in the blockchain. By generating a block certificate related to the cloud storage source information data, the cloud storage source information data is verified, forming a traceability mechanism for the corresponding source information data.
[0048] For example, after the source information data is published on the blockchain, the block containing the hash value of the cloud data source information data is first added to the blockchain, and the hash value representing the cloud storage source information data is further stored in the leaf node of the block, and the flow source information data generated by the access control operation performed by each user is added to the blockchain network as a node. The traceability information is stored in each block of the blockchain and is stored in a series of execution actions between the flow source information data nodes generated by the user. Each node in the blockchain network will back up all the on-chain execution information, that is, the traceability information recorded on the blockchain is jointly maintained by each node, and each node in the blockchain network can obtain any The cloud storage platform stores the cloud storage source information data in the source information database, where the on-chain storage content specifically includes the execution hash value of each traceability information and the additional traceability information. The mapping relationship between the source information data ID and the execution hash value of the traceability information corresponding to the attached data ID is written on the chain through the traceability information verification mechanism. By setting the attribute set or access structure for the user's private key or ciphertext, it can only be correctly decrypted when the attribute set matches the access structure. The specific execution operation information, data transfer information and data attribute information of the source information data entity are also written in detail on the blockchain through the corresponding smart contract, completing the on-chain verification of the cloud storage source information data based on the block certificate of the source information data.
[0049] Step 4: When a data traceability request is generated, the blockchain-based cloud storage source information data is triggered to enter the verification and traceability mechanism to trace the source information data.
[0050] In an embodiment of the present invention, when a data tracing request is generated, a source information data tracing verification terminal in a cloud storage platform sends a request to the blockchain to obtain a block certificate of the cloud storage source information data. The blockchain generates a block certificate of the cloud storage source information data by accessing a block resource manager and sends it to the cloud storage source information data tracing verification terminal. The block certificate includes a hash value of the source information data and a tree certificate for verifying the hash value of the source information of the source information data. The tree certificate is the path from the leaf node storing the hash value of the cloud data source information data to the root node of the tree. The source information data tracing verification terminal reconstructs the tree using the block certificate to verify the cloud storage source information data. When the source information data tracing verification terminal successfully reconstructs the tree, the source information data in the source information database is true. By tracing the data associated with the source information data row, if the source information data tracing verification terminal fails to reconstruct the tree, the source information data in the source information database is judged to be false.
[0051] Exemplarily, further determine whether the cloud storage source information data in the source information database has been tampered with, obtain the corresponding traceability information storage flow hash through the identification ID corresponding to the traceability data, obtain the data identification ID to be traced, and obtain the blockchain execution hash value of the latest traceability information of this data through the data ID, and determine whether the execution hash value exists. If not, it means that this data has no relevant traceability information. If it exists, proceed to the next step, obtain the specific information data of the execution operation from the blockchain according to the execution hash value, and obtain the traceability information of this data from the attached data. Whether this traceability information exists in the execution operation data, the source information data tracing verification terminal uses the block certificate to verify the specific information of the source information data. If it exists, directly obtain the result set of the traceability information storage, and add the result set to the source information database in the data traceability request.
[0052] Example 2: Example 2 of the present invention provides a data tracing system based on blockchain. Figure 2 A schematic diagram of the module composition of a blockchain-based data tracing system provided in Example 2 of the present invention is shown in FIG. Figure 2 As shown, the system includes:
[0053] The source information data recording and storage module is used to record and store source information data of user access control and operation behaviors using the recording terminal of the cloud storage platform;
[0054] The source information data encryption and chain verification module is used to encrypt the source information data and verify the block chain;
[0055] The source information data verification and tracing module is used to perform block certificate verification and tracing on the source information data that generates the data tracing request.
[0056] In some embodiments of the present invention, the source information data record storage module includes:
[0057] Remote service generation module, used for the cloud storage platform of the enterprise system to generate remote services based on the platform cloud data;
[0058] The cloud data execution operation monitoring module is used by the recording terminal of the cloud storage platform to monitor the access control and operation behavior of users on the cloud data in the remote server;
[0059] The recording trigger mechanism setting module is used to set the source data recording trigger mechanism for the user end to perform operations on cloud data.
[0060] In some embodiments of the present invention, the source information data encryption and chain verification module includes:
[0061] The hash function module is used by the cloud storage platform to perform hash operations on user identity information in the source information data using a hash function;
[0062] A data association model building module is used to build a data association model based on the access control and operation process description information data stored in the record;
[0063] A block storage hash value module is used to store the hash value of the cloud storage source information data in a block using the blockchain;
[0064] The block credential generation module is used to generate block credentials related to cloud storage source information data.
[0065] In some embodiments of the present invention, the source information data verification and tracing module includes:
[0066] Verification and tracing mechanism triggering module, used to trigger the verification and tracing mechanism of cloud storage source information data based on blockchain;
[0067] The traceability verification terminal is used for the source information data traceability verification terminal to send a request to the blockchain to obtain the cloud storage source information data block certificate;
[0068] The block certificate tracing module is used by the blockchain to trace the source information data by accessing the block resource manager to generate the block certificate of the cloud storage source information data.
[0069] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus.
[0070] Finally, it should be noted that the above descriptions are merely preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art will be able to modify the technical solutions described in the aforementioned embodiments or substitute equivalents for some of the technical features. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.
Claims
1. A data tracing method based on blockchain, characterized by: The method comprises the following steps: Step 1: The cloud storage platform of the enterprise system provides remote services based on cloud data, and uses the recording terminal of the cloud storage platform to record and store the source information data of the user's access control and operation behavior; Step 2: The cloud storage platform uses a hash function to perform a hash operation on the user identity information in the source information data, and establishes a data association model based on the access control and operation process description information data recorded in the storage; Step 3: Use blockchain to store the hash value of the cloud storage source information data in the block, and generate a block certificate for tracing the cloud storage source information data; Step 4: When a data traceability request is generated, the blockchain-based cloud storage source information data is triggered to enter the verification and traceability mechanism to trace the source information data; including: When a data traceability request is generated, the source information data traceability verification terminal in the cloud storage platform sends a request to the blockchain to obtain the cloud storage source information data block certificate; The blockchain generates a block certificate for the cloud storage source information data by accessing the block resource manager and sends it to the cloud storage source information data verification and tracing terminal. The block certificate contains the hash value of the source information data and a tree certificate for verifying the hash value of the source information data's origin. The tree certificate is the path from the leaf node storing the hash value of the cloud data source information data to the root node of the tree. The source information data tracing and verification terminal verifies the cloud storage source information data by reconstructing the tree using the block certificate. When the source information data tracing verification terminal reconstructs the tree successfully, the source information data in the source information database is true. By using the source information data to perform data tracing for the associated operation, if the source information data tracing verification terminal reconstructs the tree failure, the source information data in the source information database is judged to be false, and further judgment is made as to whether the cloud storage source information data in the source information database has been tampered with. Obtain the corresponding traceability information storage and flow hash through the identification ID corresponding to the traceability data, obtain the data identification ID to be traced, and obtain the blockchain execution hash value of the latest traceability information of this data through the data ID, and judge whether the execution hash value exists. If not, it means that this data has no relevant traceability information. If it exists, proceed to the next step, and obtain the specific information data of the execution operation from the blockchain according to the execution hash value, and obtain the traceability information of this data from the attached data. Whether this traceability information has execution operation data, the source information data tracing verification terminal uses the block certificate to verify the specific information of the source information data. If it exists, directly obtain the result set of the traceability information storage, and add the result set to the source information database in the data traceability request.
2. A blockchain-based data tracing method according to claim 1, characterized in that: The step of using the recording terminal of the cloud storage platform to record and store source information data of user access control and operation behavior includes: The recording terminal of the cloud storage platform monitors the access control and operation behaviors performed by users on the cloud data in the remote server; Set up a source data record trigger mechanism for user-side operations on cloud data. Operations on cloud data include: adding, deleting, modifying, copying, moving and sharing cloud data; When a user performs the above operations based on cloud data, the recording mechanism will be triggered; The recording terminal of the cloud storage platform records the corresponding execution operations of the user end and converts them into cloud data source information data. The source information data in the cloud data records all operations performed by the current user on the cloud data, including the user identity information of the operation, the execution time data and the attributes of the cloud data; The first step is to encrypt all source information data recorded by the recording terminal of the cloud storage platform through a searchable encryption algorithm. Other terminal users without the decryption key cannot perform corresponding operations on the source information data.
3. The data tracing method based on blockchain according to claim 2 is characterized in that: The step of using a hash function to perform a hash operation on the user identity information in the source information data includes: The user identity information data in the source information data includes the user's ID identity data and the real identity data for entering the cloud storage platform. The user identity information data in the cloud storage source information data is hashed using a hash function. Then the cloud storage platform uses the key center to hash the user identity information through a secure hash algorithm to generate an identity unique identifier, and selects security parameters and system property sets to generate a master key pair for the cloud storage platform, and generates an attribute private key corresponding to the user identity information.
4. The data tracing method based on blockchain according to claim 3 is characterized in that: The step of establishing a data association model based on the recorded and stored descriptive information data of access control and operation processes includes: The key center uses the data association model to obtain the user attribute set based on the generated user identity unique identifier. When the user who has hashed the user identity information data joins the blockchain network as a node, the ECDSA signature algorithm is used to assign a public key and a private key to the user. The key center assigns an identification ID to each hashed user and concatenates the user's identification ID with the descriptive information data generated by the user during the access control operation using the established source information data association model. The Keccak algorithm is used simultaneously for further hash operations, and the hash value is encrypted with the user's public key to form a user authentication credential. The user credential is mapped to the user ID, and the key center writes this mapping relationship into the blockchain through the user identity information confidentiality contract. This mapping relationship is the user's identity authentication credential. The verification of user identity is based on the generation of the identity authentication credential, so that other shared terminal users in the data source information and participating users in the blockchain cannot tamper with the cloud storage data source information and the user's privacy information.
5. The data tracing method based on blockchain according to claim 4 is characterized in that: The step of storing the hash value of the cloud storage source information data in the block using the blockchain includes: The blockchain stores the hash value of the cloud storage source information data in the block. Each source information data in the cloud platform has a unique block certificate corresponding to it in the blockchain. The cloud storage source information data is verified through the block certificate, forming a traceability mechanism for the corresponding source information data. After the source information data is published on the blockchain, the block containing the hash value of the cloud data source information data is added to the blockchain. The hash value representing the cloud storage source information data is further stored in the leaf node of the block. The flow source information data generated by the access control operation performed by each user is added to the blockchain network as a node. The traceability information is stored in each block of the blockchain. The execution action between the flow source information data nodes generated by the user's execution operation is used as the carrier for storage. Each node in the blockchain network will back up all the execution information on the chain. That is, the traceability information recorded on the blockchain is jointly maintained by each node. At the same time, each node in the blockchain network can obtain the traceability information of any source information data. Then the cloud storage platform stores the cloud storage source information data in the source information database, where the on-chain storage content specifically includes the execution hash value of each traceability information and the additional traceability information. The mapping relationship between the source information data ID and the execution hash value of the traceability information corresponding to the attached data ID is written on the chain through the traceability information verification mechanism. By setting the attribute set or access structure for the user's private key or ciphertext, it can only be correctly decrypted when the attribute set matches the access structure. The specific execution operation information, data flow information and data attribute information of the source information data entity are also written in detail on the blockchain through the corresponding smart contract, completing the on-chain verification of the cloud storage source information data based on the block certificate of the source information data.
6. The blockchain-based data tracing method according to claim 5, applied to a blockchain-based data tracing system, is characterized in that: The system comprises: The source information data recording and storage module is used to record and store the source information data of the user's access control and operation behavior using the recording terminal of the cloud storage platform; The source information data encryption and chain verification module is used to encrypt the source information data and verify the block chain; The source information data verification and tracing module is used to perform block certificate verification and tracing on the source information data that generates the data tracing request.
7. The blockchain-based data tracing system according to claim 6, characterized in that: The source information data recording and storage module includes: Remote service generation module, used for the cloud storage platform of the enterprise system to generate remote services based on the platform cloud data; The cloud data execution operation monitoring module is used by the recording terminal of the cloud storage platform to monitor the access control and operation behavior of users on the cloud data in the remote server; The recording trigger mechanism setting module is used to set the source data recording trigger mechanism for the user end to perform operations on cloud data.
8. The blockchain-based data tracing system according to claim 7, characterized in that: The source information data encryption and chain verification module includes: The hash function module is used by the cloud storage platform to perform hash operations on user identity information in the source information data using a hash function; A data association model building module is used to build a data association model based on the access control and operation process description information data stored in the record; A block storage hash value module is used to store the hash value of the cloud storage source information data in a block using the blockchain; The block credential generation module is used to generate block credentials related to cloud storage source information data.
9. The blockchain-based data tracing system according to claim 8, characterized in that: The source information data verification and tracing module includes: Verification and tracing mechanism triggering module, used to trigger the verification and tracing mechanism of cloud storage source information data based on blockchain; The traceability verification terminal is used for the source information data traceability verification terminal to send a request to the blockchain to obtain the cloud storage source information data block certificate; The block certificate tracing module is used by the blockchain to trace the source information data by accessing the block resource manager to generate the block certificate of the cloud storage source information data.
Citation Information
Patent Citations
Dangerous chemical supply chain tracing method based on tracing block chain
CN114612117A