A blockchain-based vehicle-road collaborative data security sharing method and system

By adopting a two-layer encryption mechanism and the authentication, consensus and shard storage mechanism of blockchain nodes in the vehicle-road collaboration system, the problems of data leakage, tampering and privacy protection in the existing technology are solved, and data sharing efficiency and system efficiency are improved.

CN119743243BActive Publication Date: 2025-05-23LINGSHU TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510251968.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-05
Publication Date
2025-05-23
Estimated Expiration
2045-03-05

AI Technical Summary

Technical Problem

The existing blockchain-based vehicle-road collaborative data security sharing method has difficulties in data leakage, tampering and privacy protection during the data sharing process, and the throughput and latency of the blockchain network affects system efficiency and user experience.

Method used

The real-time data is encrypted by a two-layer encryption mechanism, a two-layer encrypted data packet is generated, and the data security and reliability are ensured through the authentication, consensus and sharded storage mechanism of blockchain nodes.

Benefits of technology

It enhances data privacy protection, improves data sharing efficiency, ensures the security and integrity of data during transmission and storage, and meets the needs of real-time data processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119743243B_ABST
    Figure CN119743243B_ABST
Patent Text Reader

Abstract

The present invention discloses a vehicle-road collaborative data security sharing method and system based on blockchain, which relates to the field of blockchain data sharing technology, including obtaining real-time data of vehicles and road infrastructure, encrypting the real-time data, generating a double-layer encrypted data packet, uploading it to the blockchain node, verifying the uploading node according to a preset identity authentication algorithm, verifying the double-layer encrypted data packet after the identity authentication is passed, and reaching a consensus after the verification is passed; slicing the double-layer encrypted data packet and storing it on multiple blockchain nodes; and securely sharing the sliced ​​double-layer encrypted data packet through a data sharing algorithm. By slicing and storing the double-layer encrypted data packet on multiple blockchain nodes, the integrity and reliability of the data are ensured; by collecting the status data of the blockchain nodes in real time, the storage capacity, network bandwidth and load factor of each node are dynamically calculated, and data storage and computing resources are reasonably allocated to optimize system performance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of blockchain data sharing, and specifically to a vehicle-road collaborative data security sharing method and system based on blockchain. Background Art

[0002] With the development of intelligent transportation systems, Vehicle-to-Everything (V2X) technology, as an emerging traffic management method, is gradually being applied in actual road environments. The core of V2X technology lies in the information exchange and collaboration between vehicles, infrastructure and other road participants, thereby improving traffic safety, fluidity and efficiency. However, with the popularization of V2X technology, data security and privacy protection have become urgent issues to be addressed.

[0003] At present, there are many methods for secure sharing of vehicle-road cooperative data based on blockchain. These methods mainly use the decentralized, tamper-proof and traceable characteristics of blockchain to ensure the security and integrity of data. For example, by recording the real-time data of vehicles and road infrastructure on the blockchain, and realizing automatic processing and sharing of data through smart contracts. However, although the existing technology uses blockchain encryption technology in the process of data sharing, the data encryption mechanism is relatively simple and can be easily cracked by malicious attackers, resulting in data leakage and tampering. At the same time, there is a risk of interception and theft during the transmission and storage of data between multiple nodes, especially in the public blockchain environment, where data privacy is difficult to be fully guaranteed. The decentralized nature of blockchain requires data to be transmitted and verified between multiple nodes, resulting in a relatively slow data sharing process that cannot meet the needs of real-time data processing. When processing large-scale data, the throughput and latency problems of the blockchain network are prominent in the existing methods, affecting the efficiency of the overall system and user experience. Summary of the invention

[0004] Based on the above-mentioned shortcomings of the prior art, the purpose of the present invention is to provide a blockchain-based vehicle-road collaborative data security sharing method and system to solve the above-mentioned technical problems.

[0005] To achieve the above purpose, the present invention provides the following technical solution: a method for secure sharing of vehicle-road cooperative data based on blockchain, comprising:

[0006] Acquire real-time data of vehicles and road infrastructure, encrypt the real-time data, and generate a double-layer encrypted data packet;

[0007] The double-layer encrypted data packet is uploaded to the blockchain node, and the uploading node is verified according to a preset identity authentication algorithm. After the identity authentication is passed, the double-layer encrypted data packet is verified, and after the verification is passed, a consensus is reached on the double-layer encrypted data packet;

[0008] Fragment the double - encrypted data packet and store it on multiple blockchain nodes;

[0009] Securely share the fragmented double - encrypted data packet through a data sharing algorithm.

[0010] The present invention is further configured to encrypt the real - time data to generate a double - encrypted data packet, including:

[0011] According to the encryption timestamp and the uploading node Use a symmetric encryption algorithm to initially encrypt the real - time data to generate initially encrypted data, and generate a first hash value of the initially encrypted data according to the hash algorithm;

[0012] Encrypt the first hash value of the initially encrypted data according to the asymmetric encryption algorithm to generate mixed - encrypted data;

[0013] Package the initially encrypted data and the mixed - encrypted data to generate a double - encrypted data packet.

[0014] The present invention is further configured that the verification of the uploading node according to the preset authentication algorithm includes:

[0015] The uploading node generates a random number , and calculates the commitment value , where the calculation logic of the commitment value is: , is a large prime number pre - selected for modular arithmetic, is a pre - selected value belonging to a large prime number as a generator;

[0016] The blockchain node generates a random challenge , and sends the random challenge to the uploading node;

[0017] The uploading node calculates the response value according to the random challenge , and sends the response value to the blockchain node, where the calculation logic of the response value is: , is the private key of the uploading node for generating the response value; is another large prime number pre - selected for modular arithmetic;

[0018] The blockchain node verifies the uploading node according to the response value , where the calculation logic of the response value verification is: , is the public key of the uploading node, is the private key of the uploading node The corresponding public key is calculated as follows: When the equation is true, the identity authentication of the uploading node is passed; when the equation is not true, the identity authentication of the uploading node is failed.

[0019] The present invention is further configured that the verification of the double-layer encrypted data packet comprises:

[0020] Decrypt the initial encrypted data according to the symmetric key of the symmetric encryption algorithm to obtain real-time data;

[0021] Decrypt the mixed encrypted data using the private key of the blockchain node to obtain a first hash value;

[0022] A second Hash value of the received initial encrypted data is regenerated according to the Hash algorithm. When the first Hash value is equal to the second Hash value, the double-layer encrypted data packet is verified to be successful.

[0023] The present invention is further configured to reach a consensus on the double-layer encrypted data packet, including:

[0024] The blockchain node sends the double-layer encrypted data packet to all consensus blockchain nodes and broadcasts the first hash value of the initial encrypted data;

[0025] Each consensus blockchain node verifies the received double-layer encrypted data packet and sends the verification result and signature to all consensus blockchain nodes, wherein the verification result includes the first hash value and signature of the initial encrypted data;

[0026] When the number of verification results and signatures received by the consensus blockchain node is greater than the preset threshold, consensus is completed.

[0027] The present invention is further configured to fragment the double-layer encrypted data packet and store it on multiple blockchain nodes, including:

[0028] The double-layer encrypted data packet is divided into fragmented packets and generate A check block;

[0029] Obtain the status data of all consensus blockchain nodes, calculate the comprehensive status index of all consensus blockchain nodes based on the status data, and sort them in descending order;

[0030] Arrange in order Each shard data packet is stored in sequence on the consensus blockchain node.

[0031] The present invention is further configured to obtain status data of all consensus blockchain nodes, the status data including storage capacity, network bandwidth capacity and load factor, wherein the calculation logic of storage capacity is: , For the The storage capacity of consensus blockchain nodes, For the The available storage space of consensus blockchain nodes, It is the maximum available storage space among all consensus blockchain nodes. The calculation logic of network bandwidth capacity is: , For the The network bandwidth capacity of each consensus blockchain node, For the The available network bandwidth of consensus blockchain nodes, The maximum available network bandwidth among all consensus blockchain nodes. The calculation logic of the load factor is: , For the The load factor of the consensus blockchain nodes, , and Respectively The CPU utilization, memory utilization, and disk utilization of each consensus blockchain node.

[0032] The present invention is further configured to calculate the comprehensive status index of all consensus blockchain nodes based on the status data, and the calculation logic is: ,in, For the The comprehensive status index of consensus blockchain nodes, , and They are the correction coefficients for storage capacity, network bandwidth capacity and load factor respectively.

[0033] The present invention is further configured to securely share the fragmented double-layer encrypted data packets through a data sharing algorithm, including:

[0034] Use a secret sharing algorithm to split the key into shard keys, distributed to nodes, set the threshold , when getting When the shard key is shared, the secret sharing algorithm is used to recover the key;

[0035] When a user requests to access data, the consensus blockchain node verifies the user's authority. After the verification is passed, the consensus blockchain node sends the shard key and shard data packet to the user. When the shard key is shared, the secret sharing algorithm is used to recover the key, and all shard data packets are obtained, reassembled to obtain double-layer encrypted data packets, and decrypted with the key to obtain real-time data, thus completing data sharing.

[0036] The present invention also provides a vehicle-road cooperative data security sharing system based on blockchain, the system comprising:

[0037] Acquisition module: acquires real-time data of vehicles and road infrastructure, encrypts the real-time data, and generates a double-layer encrypted data packet;

[0038] Verification module: upload the double-layer encrypted data packet to the blockchain node, verify the uploading node according to a preset identity authentication algorithm, and after the identity authentication is passed, verify the double-layer encrypted data packet. After the verification is passed, consensus is reached on the double-layer encrypted data packet;

[0039] Sharding module: Sharding the double-layer encrypted data packet and storing it on multiple blockchain nodes;

[0040] Sharing module: The fragmented double-layer encrypted data packets are securely shared through the data sharing algorithm.

[0041] The present invention provides a vehicle-road cooperative data security sharing method and system based on blockchain. The method acquires real-time data of vehicles and road infrastructure, encrypts the real-time data, and generates a double-layer encrypted data packet; uploads the double-layer encrypted data packet to a blockchain node, verifies the uploading node according to a preset identity authentication algorithm, verifies the double-layer encrypted data packet after the identity authentication is passed, and reaches a consensus on the double-layer encrypted data packet after the verification is passed; fragments the double-layer encrypted data packet and stores it on multiple blockchain nodes; and securely shares the fragmented double-layer encrypted data packet through a data sharing algorithm, and the beneficial effects produced include:

[0042] 1. Enhanced data privacy protection: Double-layer encryption of real-time data makes data more secure during transmission and storage. Even if the data packet is intercepted or leaked, the double-layer encryption mechanism can effectively prevent the data from being maliciously parsed and tampered with, protecting user privacy; before uploading the data to the blockchain node, the uploader is authenticated through a preset authentication algorithm to ensure that only legitimate users can upload data, eliminating the injection of illegal data from the source.

[0043] 2. Improve data sharing efficiency: Store double-layer encrypted data packets in multiple blockchain nodes in fragments, and use Reed-Solomon coding technology to ensure data integrity and reliability. Fragmented storage not only improves the efficiency of data upload and storage, but also enhances the system's anti-attack and disaster recovery capabilities. By collecting blockchain node status data in real time, dynamically calculating each node's storage capacity, network bandwidth, and load factor, reasonably allocating data storage and computing resources, and optimizing system performance, it can significantly improve the speed of data sharing and processing while ensuring data security.

[0044] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. In the drawings:

[0046] Figure 1 A flowchart of a method for secure sharing of vehicle-road cooperative data based on blockchain is shown as an exemplary embodiment of the present invention;

[0047] Figure 2 A schematic structural diagram of a vehicle-road collaborative data security sharing system based on blockchain is shown as an exemplary embodiment of the present invention. DETAILED DESCRIPTION

[0048] The following will describe the embodiments of the present invention with reference to the accompanying drawings and preferred embodiments. Those skilled in the art can easily understand other advantages and effects of the present invention from the contents disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present invention. It should be understood that the preferred embodiments are only for illustrating the present invention, not for limiting the scope of protection of the present invention.

[0049] It should be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present invention, and thus the drawings only show components related to the present invention rather than being drawn according to the number, shape and size of components in actual implementation. In actual implementation, the type, quantity and proportion of each component may be changed arbitrarily, and the component layout may also be more complicated.

[0050] In the following description, numerous details are discussed to provide a more thorough explanation of the embodiments of the present invention. However, it is obvious to those skilled in the art that the embodiments of the present invention can be implemented without these specific details. In other embodiments, well-known structures and devices are shown in the form of block diagrams rather than in detail to avoid making the embodiments of the present invention difficult to understand.

[0051] Embodiment 1

[0052] A secure sharing method of vehicle-road cooperative data based on blockchain, such as Figure 1 As shown, including:

[0053] Acquire real-time data of vehicles and road infrastructure, encrypt the real-time data, and generate a double-layer encrypted data packet;

[0054] The double-layer encrypted data packet is uploaded to the blockchain node, and the uploading node is verified according to a preset identity authentication algorithm. After the identity authentication is passed, the double-layer encrypted data packet is verified, and after the verification is passed, a consensus is reached on the double-layer encrypted data packet;

[0055] The double-layer encrypted data packet is fragmented and stored on multiple blockchain nodes;

[0056] The fragmented double-layer encrypted data packets are securely shared through a data sharing algorithm.

[0057] Specifically, the real-time data of vehicles and road infrastructure include vehicle location, status, environment and driving behavior data, as well as traffic lights, roadside units, traffic monitoring and road status data. In the vehicle-road cooperative system, by analyzing the real-time data of vehicles and road infrastructure, it is possible to improve traffic management efficiency, improve road safety and realize intelligent transportation.

[0058] The present invention is further configured to encrypt the real-time data to generate a double-layer encrypted data packet, including:

[0059] Based on the encrypted timestamp and upload node The real-time data is initially encrypted using a symmetric encryption algorithm to generate initial encrypted data, and a first hash value of the initial encrypted data is generated using a hash algorithm; specifically, the encryption formula is: ,in, It is based on encrypted timestamp and upload node The generated symmetric key, For real-time data, is the initial encrypted data, It is the AES symmetric encryption algorithm. Other symmetric encryption algorithms can also be used here without limitation. The hash formula is: ,in, For dynamic values ​​generated based on data type and content, It is a hash algorithm.

[0060] The first hash value of the initial encrypted data is encrypted according to an asymmetric encryption algorithm to generate mixed encrypted data; specifically, the encryption formula is: ,in, To mix and encrypt data, is the encryption public key, for Asymmetric encryption algorithm, which may be other asymmetric encryption algorithms, is not limited to this.

[0061] The initial encrypted data and the mixed encrypted data are packaged to generate a double-layer encrypted data packet.

[0062] The present invention is further configured such that the verifying the uploading node according to a preset identity authentication algorithm comprises:

[0063] The upload node generates a random number , and calculate the commitment value , where the commitment value The calculation logic is: , is a pre-selected large prime number for modular operations, is a pre-selected value that is a large prime number A generator of; specifically, a generator refers to an element in a group that can generate all the elements in the group. In the present invention, the generator is used to generate a large prime number. The values ​​required for encryption and verification are generated from the modular operation group of and random numbers , a unique commitment value commitment is generated, and the commitment value commitment ensures the security of the encryption process through group operations.

[0064] The blockchain node generates a random challenge , and the random challenge Send to the upload node;

[0065] The uploading node is based on the random challenge Calculate the response value , and the response value Sent to the blockchain node, where the response value The calculation logic is: , The private key of the uploading node, used to generate the response value; is another large prime number selected in advance for modular operations;

[0066] The blockchain node responds to the Verify the upload node, where the calculation logic of the response value verification is: , is the public key of the uploading node, is the private key of the uploading node The corresponding public key is calculated as follows: When the equation is true, the upload node identity authentication is passed; when the equation is not true, the upload node identity authentication is failed; specifically, the above authentication method ensures that the upload node private key is not exposed. In this case, the blockchain node can confirm the identity authenticity of the uploading node, taking into account security and unpredictability, ensuring the security and reliability of the identity authentication process.

[0067] The present invention is further configured that the verification of the double-layer encrypted data packet comprises:

[0068] Decrypt the initial encrypted data according to the symmetric key of the symmetric encryption algorithm to obtain real-time data; specifically, the decryption formula is: ,because It is based on encrypted timestamp and upload node The generated symmetric key can therefore verify the validity of the timestamp and the legitimacy of the node ID.

[0069] Use the private key of the blockchain node to decrypt the mixed encrypted data and obtain the first hash value; specifically, the decryption formula is: ,in, For the private key.

[0070] The second hash value of the received initial encrypted data is regenerated according to the hash algorithm. When the first hash value is equal to the second hash value, the double-layer encrypted data packet is verified. Specifically, the same hash algorithm and dynamic parameters are used to recalculate The hash value of is: ,Compare and consistency.

[0071] The present invention is further configured to reach a consensus on the double-layer encrypted data packet, including:

[0072] The blockchain node sends the double-layer encrypted data packet to all consensus blockchain nodes and broadcasts the first hash value of the initial encrypted data; specifically, the blockchain node sends the double-layer encrypted data packet to all blockchain nodes participating in the consensus and broadcasts the hash value of the initial encrypted data so that other nodes can verify the integrity and consistency of the data.

[0073] Each consensus blockchain node verifies the received double-layer encrypted data packet and sends the verification result and signature to all consensus blockchain nodes, where the verification result includes the first hash value and signature of the initial encrypted data; specifically, after receiving the double-layer encrypted data packet, each consensus node uses a pre-set verification algorithm to check the validity and integrity of the data packet. This includes verifying whether the data packet has been tampered with and whether it conforms to the expected format and content. After the verification is completed, the consensus node generates a verification result and a signature. The signature is an identifier that encrypts the verification result using the node's private key to ensure the authenticity and immutability of the verification result. The verification result and signature are sent to other consensus nodes to ensure that all nodes can participate in consensus decision-making.

[0074] When the number of verification results and signatures received by the consensus blockchain node is greater than the preset threshold, the consensus is completed. Specifically, each node collects the verification results and signatures sent by other nodes and records this information. A threshold is set in the consensus protocol. Only when the number of verification results and signatures received exceeds the threshold, the consensus is considered to be reached. When the number of verification results and signatures reaches or exceeds the preset threshold, the data packet is considered to have passed the verification and consensus has been reached. The data packet is officially recorded on the blockchain. The threshold here is set according to specific needs and is not restricted here.

[0075] The present invention is further configured to fragment the double-layer encrypted data packet and store it on multiple blockchain nodes, including:

[0076] The double-layer encrypted data packet is divided into fragmented packets and generate Specifically, Reed-Solomon coding is a widely used error correction coding technology that can divide data into multiple fragments and generate redundant check blocks, so that even if some fragments are lost or damaged, the original data can still be restored.

[0077] The status data of all consensus blockchain nodes are obtained, and the comprehensive status index of all consensus blockchain nodes is calculated according to the status data, and the comprehensive status index of all consensus blockchain nodes is arranged in descending order. The present invention is further configured to obtain the status data of all consensus blockchain nodes, and the status data includes storage capacity, network bandwidth capacity and load factor, wherein the calculation logic of storage capacity is: , For the The storage capacity of consensus blockchain nodes, For the The available storage space of consensus blockchain nodes, It is the maximum available storage space among all consensus blockchain nodes. The calculation logic of network bandwidth capacity is: , For the The network bandwidth capacity of each consensus blockchain node, For the The available network bandwidth of consensus blockchain nodes, The maximum available network bandwidth among all consensus blockchain nodes. The calculation logic of the load factor is: , For the The load factor of the consensus blockchain nodes, , and Respectively The present invention is further configured to calculate the comprehensive status index of all consensus blockchain nodes based on the status data, and the calculation logic is: ,in, For the The comprehensive status index of consensus blockchain nodes, , and They are the correction coefficients of storage capacity, network bandwidth capacity and load factor. Specifically, the storage capacity correction coefficient is determined according to the importance of the node's storage space in the entire system. If the system has a high demand for data storage, a higher weight is given to the storage capacity, and the value range is 0.3-0.5. In data storage-intensive applications, the storage capacity correction coefficient can take the upper limit value; while in computing-intensive applications, it can take the lower limit value; the network bandwidth correction coefficient is determined according to the importance of the node's network transmission speed in the data transmission and consensus process. If the system has a high requirement for data transmission speed, a higher weight is given to the network bandwidth, and the value range is 0.3-0.5. In applications with high requirements for real-time data transmission, the network bandwidth correction coefficient can take the upper limit value; while in applications with relatively low requirements for data transmission, the lower limit value can be taken; the load factor correction coefficient is determined according to the impact of the node's CPU, memory and disk utilization on the overall performance of the node. If the system has a high requirement for computing performance, a higher weight is given to the load factor, and the value range is 0.2-0.4. In computing-intensive applications, the load factor correction coefficient can take the upper limit value; while in applications with high requirements for data storage or transmission, the lower limit value can be taken.

[0078] Arrange in order The shard data packets are stored in the consensus blockchain nodes in sequence. Through the above steps, the comprehensive status index of each consensus blockchain node can be calculated, and the nodes can be sorted according to the index, so as to select the node with the best status to store data, ensuring efficient and secure storage of data and optimizing resource utilization.

[0079] The present invention is further configured to securely share the fragmented double-layer encrypted data packets through a data sharing algorithm, including:

[0080] Use a secret sharing algorithm to split the key into shard keys, distributed to nodes, set the threshold , when getting When a shard key is obtained, a secret sharing algorithm is used to recover the key; specifically, such as Shamir's secret sharing algorithm, the key is divided into several shares, each of which is held by a different node. The original key can only be recovered when enough shard keys are obtained.

[0081] When a user requests to access data, the consensus blockchain node verifies the user's authority. After the verification is passed, the consensus blockchain node sends the shard key and shard data packet to the user. When a shard key is obtained, the secret sharing algorithm is used to restore the key, and all shard data packets are obtained, reassembled to obtain a double-layer encrypted data packet, and decrypted by the key to obtain real-time data, thereby completing data sharing; specifically, when a user requests access to data, the consensus blockchain node needs to verify the user's identity and authority to ensure that only authorized users can access the data. After the verification is passed, the consensus blockchain node sends the required shard key and shard data packet to the user. After the user collects enough shard keys, the secret sharing algorithm is used to restore the original key, and the restored key is used to decrypt the shard data packet, which is reassembled into a double-layer encrypted data packet, and then decrypted to obtain the actual data, thereby completing data sharing.

[0082] Embodiment 2

[0083] See also Figure 2 , the exemplary blockchain-based vehicle-road cooperative data security sharing system includes:

[0084] Acquisition module: acquires real-time data of vehicles and road infrastructure, encrypts the real-time data, and generates a double-layer encrypted data packet;

[0085] Verification module: upload the double-layer encrypted data packet to the blockchain node, verify the uploading node according to a preset identity authentication algorithm, and after the identity authentication is passed, verify the double-layer encrypted data packet. After the verification is passed, consensus is reached on the double-layer encrypted data packet;

[0086] Sharding module: Sharding the double-layer encrypted data packet and storing it on multiple blockchain nodes;

[0087] Sharing module: The fragmented double-layer encrypted data packets are securely shared through the data sharing algorithm.

[0088] It should be noted that the vehicle-road collaborative data security sharing system based on blockchain provided in the above embodiment and the vehicle-road collaborative data security sharing method based on blockchain provided in the above embodiment belong to the same concept, wherein the specific manner in which each module and unit performs the operation has been described in detail in the method embodiment and will not be repeated here. In actual application, the vehicle-road collaborative data security sharing system based on blockchain provided in the above embodiment can distribute the above functions to different functional modules as needed, that is, divide the internal structure of the system into different functional modules to complete all or part of the functions described above, and this is not limited here.

[0089] The above embodiments can be implemented in whole or in part by software, hardware, firmware or any other combination. When implemented by software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website site, computer, server or data center to another website site, computer, server or data center by wired (e.g., infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state hard disk.

[0090] It should be understood that the term "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. A and B can be singular or plural. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship, but it may also indicate an "and / or" relationship. Please refer to the context for specific understanding.

[0091] In this application, "at least one" means one or more, and "more than one" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can be represented by: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple.

[0092] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0093] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0094] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0095] In the several embodiments provided in the present application, it should be understood that the disclosed system can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0096] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0097] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0098] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage media include: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks or optical disks.

[0099] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims

1. A method for secure sharing of vehicle-road cooperative data based on blockchain, characterized in that: include: Acquire real-time data of vehicles and road infrastructure, encrypt the real-time data, and generate a double-layer encrypted data packet, including: using a symmetric encryption algorithm to initially encrypt the real-time data according to the encryption timestamp and the upload node ID to generate initial encrypted data, and generating a first hash value of the initial encrypted data according to a hash algorithm; encrypting the first hash value of the initial encrypted data according to an asymmetric encryption algorithm to generate mixed encrypted data; and packaging the initial encrypted data and the mixed encrypted data to generate a double-layer encrypted data packet; The double-layer encrypted data packet is uploaded to the blockchain node, and the uploading node is verified according to a preset identity authentication algorithm. After the identity authentication is passed, the double-layer encrypted data packet is verified, and after the verification is passed, a consensus is reached on the double-layer encrypted data packet; The double-layer encrypted data packet is fragmented and stored on multiple blockchain nodes; The fragmented double-layer encrypted data packets are securely shared through a data sharing algorithm.

2. According to the method for secure sharing of vehicle-road cooperative data based on blockchain in claim 1, it is characterized in that: The verifying the upload node according to a preset identity authentication algorithm includes: The uploading node generates a random number r and calculates the commitment value commitment, where the calculation logic of the commitment value commitment is: commitment = g r mod p, p is a pre-selected large prime number used for modular operation, g is a pre-selected value, which is a generator of the large prime number p; The blockchain node generates a random challenge c and sends the random challenge c to the uploading node; The uploading node calculates a response value s according to the random challenge c, and sends the response value s to the blockchain node, wherein the calculation logic of the response value s is: s = r + c * x mod q, x is the private key of the uploading node, which is used to generate the response value; q is another pre-selected large prime number, which is used for modular operation; The blockchain node verifies the uploading node according to the response value s, where the calculation logic of the response value verification is: g s mod p = commitment * y c mod p, y is the public key of the uploading node, which is the public key corresponding to the private key x of the uploading node. The calculation formula is y = g x mod p, when the equation holds true, the upload node identity authentication passes; when the equation does not hold true, the upload node identity authentication fails.

3. According to the blockchain-based vehicle-road cooperative data security sharing method of claim 1, it is characterized in that: The verifying the double-layer encrypted data packet includes: Decrypt the initial encrypted data according to the symmetric key of the symmetric encryption algorithm to obtain real-time data; Decrypt the mixed encrypted data using the private key of the blockchain node to obtain a first hash value; A second Hash value of the received initial encrypted data is regenerated according to the Hash algorithm. When the first Hash value is equal to the second Hash value, the double-layer encrypted data packet is verified to be successful.

4. According to the method of claim 3, the method is characterized in that: A consensus is reached on the double-layer encrypted data packet, including: The blockchain node sends the double-layer encrypted data packet to all consensus blockchain nodes and broadcasts the first hash value of the initial encrypted data; Each consensus blockchain node verifies the received double-layer encrypted data packet and sends the verification result and signature to all consensus blockchain nodes, wherein the verification result includes the first hash value and signature of the initial encrypted data; When the number of verification results and signatures received by the consensus blockchain node is greater than the preset threshold, consensus is completed.

5. According to the method for secure sharing of vehicle-road cooperative data based on blockchain in claim 1, it is characterized in that: The double-layer encrypted data packet is fragmented and stored on multiple blockchain nodes, including: Using Reed-Solomon coding, the double-layer encrypted data packet is divided into n fragmented data packets, and k check blocks are generated; Obtain the status data of all consensus blockchain nodes, calculate the comprehensive status index of all consensus blockchain nodes based on the status data, and sort them in descending order; The n shard data packets are stored in sequence on the consensus blockchain nodes in the order of arrangement.

6. According to the method of claim 5, the method is characterized in that: Obtain the status data of all consensus blockchain nodes. The status data includes storage capacity, network bandwidth capacity and load factor. The calculation logic of storage capacity is: SS i is the storage capacity of the i-th consensus blockchain node, SC i is the available storage space of the i-th consensus blockchain node, and max(SC) is the maximum available storage space among all consensus blockchain nodes; the calculation logic of network bandwidth capacity is: BWS i is the network bandwidth capacity of the i-th consensus blockchain node, BW i is the available network bandwidth of the ith consensus blockchain node, max(BW) is the maximum available network bandwidth among all consensus blockchain nodes, and the calculation logic of the load factor is: LF i is the load factor of the i-th consensus blockchain node, UC i UM i and UD i are the CPU utilization, memory utilization, and disk utilization of the i-th consensus blockchain node, respectively.

7. According to claim 6, a method for secure sharing of vehicle-road cooperative data based on blockchain is characterized in that: The comprehensive status index of all consensus blockchain nodes is calculated based on the status data. The calculation logic is: Among them, NOS i is the comprehensive status index of the ith consensus blockchain node, and α, β, and δ are the correction coefficients of storage capacity, network bandwidth capacity, and load factor, respectively.

8. According to the blockchain-based vehicle-road cooperative data security sharing method of claim 5, it is characterized in that: The fragmented double-layer encrypted data packets are securely shared through a data sharing algorithm, including: Use the secret sharing algorithm to divide the key into j shard keys, distribute them to j nodes, set a threshold k, and use the secret sharing algorithm to restore the key when k shard keys are obtained; When a user requests to access data, the user's authority is verified by the consensus blockchain node. After the verification is passed, the consensus blockchain node sends the shard key and shard data packet to the user. When the user obtains k shard keys, the secret sharing algorithm is used to restore the key, and all shard data packets are obtained. The double-layer encrypted data packet is reassembled and decrypted with the key to obtain real-time data, completing data sharing.

9. A blockchain-based vehicle-road cooperative data security sharing system, characterized in that: A method for securely sharing vehicle-road cooperative data based on blockchain for implementing any one of claims 1 to 8, comprising: Acquisition module: acquires real-time data of vehicles and road infrastructure, encrypts the real-time data, and generates a double-layer encrypted data packet; Verification module: upload the double-layer encrypted data packet to the blockchain node, verify the uploading node according to a preset identity authentication algorithm, and after the identity authentication is passed, verify the double-layer encrypted data packet. After the verification is passed, consensus is reached on the double-layer encrypted data packet; Sharding module: Sharding the double-layer encrypted data packet and storing it on multiple blockchain nodes; Sharing module: The fragmented double-layer encrypted data packets are securely shared through the data sharing algorithm.

Citation Information

Patent Citations

  • Data encryption evidence storage and sharing method based on blockchain

    CN113364576A

  • File encryption transmission method based on block chain and IPFS, medium and equipment

    CN117424696A