Data storage and certification method and device for fire-fighting equipment
By generating public and private keys in fire-fighting equipment, using hash processing and blockchain technology, the problems of immutability and data integrity of fire-fighting equipment data records are solved, and data immutable storage and trusted operation traceability are realized.
Patent Information
- Application Number
- CN202510355035.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-25
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2045-03-25
AI Technical Summary
The data recording method of existing fire-fighting equipment has the problem that data recording is poorly unchangeable and it is difficult to retain all operating data.
By obtaining the operation data and operation records of fire-fighting equipment, generating public and private keys, using hash processing and blockchain technology, data is stored in off-chain servers and encrypted, and a storage block identification is generated to ensure the immutability and integrity of the data.
It realizes the complete storage of fire equipment operation data and the immutability of operation records, solves the problem that data is easily modified, and provides credible operation traceability and responsibility division.
Smart Images

Figure CN119865307B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data storage and verification, and in particular to a data storage and verification method for fire-fighting equipment. Background Art
[0002] Fire-fighting equipment plays a very important role in fire prevention and control. With the continuous development of Internet of Things technology, fire-fighting equipment has become diversified and intelligent, such as intelligent smoke sensing systems, automatic fire sprinkler nozzles, etc. These devices have many sensors, and the sensing accuracy of these sensors is affected not only by the performance of the sensors themselves, but also by the standardization degree of use and maintenance by users. When a fire occurs, the fire-fighting equipment may fail to work. During the investigation, the responsibility for equipment failure is often attributed to the equipment manufacturer, which ignores the impact of non-standard use factors on equipment performance. Therefore, data recording should be carried out for all links in the use of fire-fighting equipment, whether it is for the division of equipment responsibility or the tracing of the cause of the fire.
[0003] Regarding the data recording of the use process of fire-fighting equipment, the existing methods mainly record the use process through database storage or manual recording. These two methods have the same problem, that is, the immutability of the recording results is poor. The reason for the poor immutability of manual recording is obvious. As long as one masters the record book or the way to obtain the record book, the recording results in it can be changed. For the database type of recording method, the results can be changed by brute-forcing the database administrator account password and SQL injection. Both methods have the possibility of data tampering. In addition, fire-fighting equipment will generate a large amount of operation data. Due to storage performance reasons, the existing technology can only store part of the data and cannot retain all the characteristics of the operation data. Summary of the Invention
[0004] Therefore, the present invention provides a data storage and verification method for fire-fighting equipment, which helps to solve the problems that the existing data recording methods for fire-fighting equipment have poor immutability of data recording and it is difficult to retain all the operation data of the fire-fighting equipment in storage.
[0005] In a first aspect, the present invention provides a data storage and verification method for fire-fighting equipment, including:
[0006] Obtain the operation data and operation records of the fire-fighting equipment, generate a public key and a private key, and form a first data pair with the operation data, operation records and public key;
[0007] Perform a hash process on the operation records in the first data pair to obtain an original hash code H, and recombine the original hash code H with the first data pair to form a second data pair;
[0008] Deposit the second data pair into the off-chain server, and encrypt the original hash code H in the second data pair using the public key to obtain an operation ciphertext;
[0009] Generate a storage block identifier using group operations under a generator and a random number of steps;
[0010] Create a storage block on the blockchain based on the storage block identifier, and deposit the operation ciphertext into the storage block.
[0011] Further, the obtaining the operation data and operation records of the fire protection equipment, and generating a public key and a private key, and forming a first data pair with the operation data, operation records, and public key includes:
[0012] Collect the operation data of the fire protection equipment, where the operation data includes external environment data and equipment data;
[0013] Generate a public key pk and a private key sk for data encryption and decryption according to a preset asymmetric algorithm;
[0014] Real-time record the operation data of the user on the fire protection equipment to obtain an operation record R, where the operation record R includes the user's usage operation A, operation time T, and an equipment identity code including manufacturer information;
[0015] Perform data combination on the operation data, public key pk, and operation record R within a preset time period to obtain a first data pair (data, pk, R).
[0016] Further, the generating a storage block identifier using group operations under a generator and a random number of steps includes:
[0017] Obtain the generator g and group operation G set by the fire protection equipment manufacturer;
[0018] Generate an initial data block b0, and determine the identifier of the initial data block b0 ;
[0019] Starting from the identifier perform group operation G with a random number of steps using the generator g to generate a storage block identifier .
[0020] Further, the creating a storage block on the blockchain based on the storage block identifier, and depositing the operation ciphertext into the storage block includes:
[0021] Create a storage block for storing the operation ciphertext on the blockchain based on the storage block identifier, connect the storage block to the previous storage block in the form of a linked list to form a storage chain, and record the connection time of the storage blocks;
[0022] After the storage block is created, upload the operation ciphertext to the blockchain and store it in the corresponding storage block.
[0023] Furthermore, the data deposit method further includes:
[0024] Randomly select n storage blocks in the storage chain, and perform maximum step group operations on the storage block identifiers corresponding to the randomly selected n storage blocks respectively, and determine whether the maximum step group operation results of the n storage blocks are all equal;
[0025] If they are equal, it is determined that the data storage is correct; if they are not equal, it is determined that the data storage is incorrect.
[0026] Furthermore, the data deposit method further includes:
[0027] Extract the operation ciphertext from the specified storage block on the blockchain, decrypt the operation ciphertext with the private key to obtain the corresponding original hash code, and use this original hash code as the data verification hash code H';
[0028] Perform original hash code matching in the off-chain server according to the data verification hash code H'. If the corresponding original hash code H can be matched, it is considered that the operation ciphertext in the storage block is correct; if the corresponding original hash code H cannot be matched, it is considered that the operation ciphertext in the storage block is incorrect.
[0029] Furthermore, the data deposit method further includes:
[0030] Retrieve the storage blocks on the blockchain according to the query time period t specified by the user to obtain a storage block group within the query time period t;
[0031] Verify the storage correctness and data correctness of the storage block group. If the verification fails, generate a non-passing deposit and issue it to the user;
[0032] If the verification passes, decrypt the operation ciphertext stored in each storage block in the storage block group with the private key to obtain the corresponding original hash code H, and query the corresponding second data pair in the off-chain server according to the original hash code H;
[0033] Extract the operation record R from the second data pair, and calculate the secondary hash code of the operation record using the hash function in the hands of the fire equipment manufacturer ;
[0034] Perform a consistency comparison between the secondary hash code and the original hash code H. If they are consistent, it is determined that the user operation corresponding to the operation record R within the query time period t has credibility, and issue a deposit with passed authentication to the user; if they are not consistent, issue a deposit with failed authentication to the user.
[0035] In a second aspect, the present application provides a data deposit and certification device for fire-fighting equipment, including:
[0036] A data acquisition module, configured to obtain the operation data and operation records of the fire-fighting equipment, generate a public key and a private key, and form a first data pair with the operation data, operation records, and public key;
[0037] A data recombination module, which performs a hashing process on the operation records in the first data pair to obtain an original hash code H, and recombines the original hash code H with the first data pair into a second data pair;
[0038] An off-chain storage module, configured to store the second data pair in an off-chain server, and encrypt the original hash code H in the second data pair using the public key to obtain an operation ciphertext;
[0039] An identification generation module, configured to generate a storage block identification using group operations under a generator and a random number of steps;
[0040] An on-chain storage module, configured to create a storage block on the blockchain according to the storage block identification, and store the operation ciphertext in the storage block.
[0041] Further, the data deposit and certification device further includes a data verification module, and the data verification module includes a storage verification unit and a data verification unit; wherein,
[0042] The storage verification unit is configured to randomly extract n storage blocks from the storage chain, perform group operations with the maximum number of steps on the storage block identifications corresponding to the randomly extracted n storage blocks respectively, and determine whether the results of the group operations with the maximum number of steps of the n storage blocks are all equal. If they are equal, it is determined that the data storage is correct; if not, it is determined that the data storage is incorrect;
[0043] The data verification unit is configured to extract the operation ciphertext from a specified storage block on the blockchain, decrypt the operation ciphertext using the private key to obtain the corresponding original hash code, and use this original hash code as the data verification hash code H', and perform an original hash code matching in the off-chain server according to the data verification hash code H'. If the corresponding original hash code H can be matched, it is considered that the operation ciphertext in the storage block is correct; if the corresponding original hash code H cannot be matched, it is considered that the operation ciphertext in the storage block is incorrect.
[0044] Further, the data deposit and certification device further includes a deposit and certification generation module, and the deposit and certification generation module is configured to generate a deposit and certification of the credibility of user operations, specifically including:
[0045] Retrieving the storage blocks on the blockchain according to the query time period t specified by the user to obtain a storage block group within the query time period t;
[0046] Verify the storage correctness and data correctness of the storage block group. If the verification fails, generate a failed deposit certificate and issue it to the user;
[0047] If the verification passes, use the private key to decrypt the operation ciphertext stored in each storage block of the storage block group to obtain the corresponding original hash code H, and query the corresponding second data pair in the off-chain server according to the original hash code H;
[0048] Extract the operation record R from the second data pair, and calculate the secondary hash code of the operation record using the hash function in the hands of the fire equipment manufacturer ;
[0049] For the secondary hash code Perform a consistency comparison with the original hash code H. If they are consistent, it is determined that the user operation corresponding to the operation record R within the query time period t has credibility, and issue a deposit certificate with passed authentication to the user. If they are inconsistent, issue a deposit certificate with failed authentication to the user.
[0050] The beneficial effect of the present invention is reflected in that the present invention performs data deposit through a combined on-chain and off-chain storage method, stores the complete operation data and operation records of the fire equipment in the off-chain server, and stores the original hash code corresponding to the operation record as a data proof in the block of the blockchain. It can store all the operation data of the fire equipment, and the characteristics of the blockchain ensure the immutability of the operation records of the fire equipment, solving the problem that the data storage result of the fire equipment in the prior art is easily modified. Brief Description of the Drawings
[0051] Figure 1 It is a flowchart of a data deposit method for fire equipment provided by the present invention;
[0052] Figure 2 It is a schematic diagram of the combination process of the first data pair of the present invention;
[0053] Figure 3 It is a schematic diagram of the storage block identifier generation process of the present invention;
[0054] Figure 4 It is a schematic diagram of the operation ciphertext storage process of the present invention;
[0055] Figure 5 It is a module diagram of a data deposit device for fire equipment provided by the present invention. Detailed Embodiment
[0056] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts belong to the scope of protection of the present application.
[0057] At present, the data recording results of fire-fighting equipment have poor immutability. The reason for the poor immutability of manual records is obvious. As long as one masters the record book or the way to obtain the record book, the record results therein can be changed. And it is often impossible to verify the data after it is changed. Moreover, the manual recording method has low efficiency. When facing a large amount of fire-fighting data, it is impossible to completely record all the operation data of fire-fighting equipment, and it is difficult to trace the faults of fire-fighting equipment. At the same time, when using a database to record data, when an external party cracks the database permissions by brute force or masters the database account password, the recorded data can also be modified, and the data security cannot be truly guaranteed.
[0058] In view of this, the present invention proposes a data deposit method and device for fire-fighting equipment to solve the technical problems existing in the above-mentioned existing recording methods of fire-fighting equipment operation data. The detailed implementation process of the present invention is shown in the following embodiments.
[0059] Embodiment 1:
[0060] Refer to Figure 1 As shown, this embodiment provides a data deposit method for fire-fighting equipment, and the method includes the following steps:
[0061] S1: Obtain the operation data and operation records of the fire-fighting equipment, generate a public key and a private key, and form a first data pair with the operation data, operation records and public key;
[0062] S2: Perform a hash process on the operation records in the first data pair to obtain an original hash code H, and reorganize the original hash code H and the first data pair into a second data pair;
[0063] S3: Store the second data pair in an off-chain server, and encrypt the original hash code H in the second data pair with the public key to obtain an operation ciphertext;
[0064] S4: Generate a storage block identifier by performing group operations under a generator and a random number of steps;
[0065] S5: Create a storage block on the blockchain according to the storage block identifier, and store the operation ciphertext in the storage block.
[0066] Further, in the embodiment of the present invention, refer to Figure 2As shown in the figure, in step S1, the operation data and operation records of the fire-fighting equipment are obtained, and a public key and a private key are generated. The operation data, operation records, and public key are combined into a first data pair, including but not limited to the following sub-steps:
[0067] S11: Collect the operation data of the fire-fighting equipment. The operation data includes external environment data and equipment data. Among them, the external environment data includes environmental data such as temperature, smoke concentration, and humidity. The equipment data includes data such as current, voltage, and water pressure when the fire-fighting equipment is working.
[0068] S12: Generate a public key pk and a private key sk for data encryption and decryption according to a preset asymmetric algorithm.
[0069] Among them, the asymmetric encryption algorithm can adopt existing algorithms, such as RSA algorithm, DSA algorithm, ECC algorithm, and DH algorithm, and can be specifically selected according to the actual situation. This will not be elaborated in the embodiments of the present invention.
[0070] S13: Real-time record the operation data of the user on the fire-fighting equipment to obtain an operation record R. Among them, the operation record R includes the user's usage operation A, operation time T, and the equipment identity identification code including manufacturer information.
[0071] S14: Combine the operation data, public key pk, and operation record R within a preset time period to obtain a first data pair (data, pk, R).
[0072] Specifically, in one embodiment, when real-time recording the operation data of the user on the fire-fighting equipment, the user's operation can be sensed through a sensor or a data acquisition device. For example, the operation video or operation picture of the user is collected through an image sensor, and at the same time, the operation time and the data such as the information of the fire-fighting equipment operated by the user are recorded through a computer terminal.
[0073] The embodiments of the present invention can facilitate the subsequent operation traceability and fault troubleshooting of the fire-fighting equipment by collecting the operation data of the fire-fighting equipment within a preset time period and the operation data of the user using the fire-fighting equipment.
[0074] Specifically, in one embodiment, the process of obtaining the original hash code H by performing a hash process on the operation record in the first data pair in step S2 specifically includes: performing a hash process on the operation record R in the first data pair (data, pk, R) by using a preset hash function provided by the fire-fighting equipment manufacturer to calculate the corresponding original hash code H.
[0075] Among them, a hash function, also known as a hashing function, can transform an input of any length into an output of a fixed length. This fixed-length output is called the hash of the original message or the message mapping. The preset hash function in the embodiments of the present invention can adopt existing hash functions such as MD5, SHA-1, SHA-256, and CRC32, or other hash functions that can calculate the hash value of data. The specific selection is made according to the actual situation and will not be elaborated herein in the embodiments of the present invention.
[0076] Specifically, after calculating the original hash code H, the original hash code H and the first data pair (data, pk, R) are recombined into a second data pair, which is specifically expressed as (data, pk, H, R).
[0077] Specifically, in one embodiment, in step S3 of the present invention, storing the second data pair (data, pk, H, R) in the off-chain server can retain all the characteristics of the running data, realize the storage of the complete device running data of the fire-fighting equipment, and provide data support for subsequent data traceability, data verification, etc., solving the problem that the existing data recording method is vulnerable to the influence of the device storage performance and cannot retain all the running data.
[0078] Further, in the embodiments of the present invention, as shown in Figure 3 generating the storage block identifier by using the group operation under the generator and the random number of steps in step S4 includes, but is not limited to, the following sub-steps:
[0079] S41: Obtain the generator g and the group operation G set by the fire-fighting equipment manufacturer. Among them, the generator g and the group operation G are usually set by the manufacturer. The generator is a mathematical term. The elements in the group can be generated by the product of the minimum number of group elements, and this group of group elements is called the generator of the group. The number of generators is the rank of the finite group. The generator refers to all the group elements that can be obtained through the group operation of one or more elements, and the group operation G refers to the operation of the non-empty set group G, such as "multiplication" operation, "addition" operation, etc.
[0080] S42: Generate the initial data block b0 and determine the identifier of the initial data block b0 . Among them, the identifier can be designed to be composed of all numbers, and the initial data block b0 is an empty data block and does not store any information.
[0081] S43: Starting from the identifier perform the group operation G with a random number of steps through the generator g to generate the storage block identifier . The random number of steps is limited by the maximum value K.
[0082] Among them, when storing for the first time, it starts from the identifier Generate a storage block identifier starting from For the second storage, the identifier is used as the starting point to generate a storage block identifier And so on. In subsequent storage processes, the previous storage block identifier is used as the starting point, and a new storage block identifier can be obtained by performing a group operation G with a random number of steps on the generating element g.
[0083] In the embodiment of the present invention, the storage block identifier is generated through the generating element and the group operation sequence, which is convenient for sequentially constructing a storage chain on the blockchain and ensuring that the data storage order on the chain is consistent with the storage order of the off-chain server.
[0084] Further, in the embodiment of the present invention, referring to Figure 4 as shown, in step S5, creating a storage block on the blockchain according to the storage block identifier and storing the operation ciphertext in the storage block includes, but is not limited to, the following sub-steps:
[0085] S51: Create a storage block for storing the operation ciphertext on the blockchain according to the storage block identifier, connect the storage block to the previous storage block in the form of a linked list to form a storage chain, and record the connection time of the storage blocks.
[0086] S52: After the storage block is created, upload the operation ciphertext to the blockchain and store it in the corresponding storage block.
[0087] In the embodiment of the present invention, by storing the operation ciphertext in the storage block on the blockchain, the immutability of the operation ciphertext can be improved by using the immutability feature of the blockchain, and secure storage of the data on the chain can be achieved.
[0088] Further, in one embodiment, the data deposit method of the embodiment of the present invention further includes verifying the correctness of data storage, specifically:
[0089] Randomly select n storage blocks from the storage chain, perform a maximum number of steps group operation on the storage block identifiers corresponding to the randomly selected n storage blocks respectively, and determine whether the maximum number of steps group operation results of the n storage blocks are all equal.
[0090] If they are equal, it is determined that the data storage is correct and the storage chain has not been illegally modified. If they are not equal, it is determined that the data storage is incorrect, and at this time, a data anomaly prompt can be sent to the user.
[0091] In the embodiment of the present invention, the correctness of data storage is verified by randomly selecting storage blocks, ensuring that the data on the chain has not been illegally tampered with, improving the security of data storage on the chain, and solving the problem that the existing data storage results of fire-fighting equipment are easily modified and have low security.
[0092] Further, in one embodiment, the data storage and certification method of the embodiments of the present invention further includes verifying the correctness of the data, specifically:
[0093] Extract the operation ciphertext from the specified storage block on the blockchain, and use the private key to decrypt the operation ciphertext to obtain the corresponding original hash code, and use this original hash code as the data verification hash code H'.
[0094] Perform an original hash code matching in the off-chain server according to the data verification hash code H'. If the corresponding original hash code H can be matched, it is considered that the operation ciphertext in the storage block is correct. If the corresponding original hash code H cannot be matched, it is considered that the operation ciphertext in the storage block is incorrect.
[0095] The embodiments of the present invention ensure that the data in the off-chain server corresponds to the operation ciphertext stored in the on-chain server by obtaining the original hash code from the on-chain storage block and performing data matching in the off-chain server.
[0096] In addition, it is also possible to verify whether the operation record R in the second data pair (data, pk, H, R) in the off-chain server is tampered with according to the operation ciphertext in the on-chain storage block. Specifically: First, decrypt the operation ciphertext E to obtain the original hash code H stored on the chain. Then, calculate the hash code of the operation record R, that is, the data verification hash code, using the preset hash function provided by the fire equipment manufacturer. Compare the original hash code with the data verification hash code for consistency. According to the comparison result, it can be judged whether the operation record R stored in the off-chain server is correct. If the two are consistent, it means that the operation record R has not been changed. If they are inconsistent, it means that the operation record R has been changed.
[0097] Further, in one embodiment, the data storage and certification method of the embodiments of the present invention proposes a user operation authentication mechanism to authenticate the user's operation record and generate corresponding vouchers for responsibility division and fire cause tracing after a fire. The specific process of voucher generation is as follows:
[0098] Retrieve the storage blocks on the blockchain according to the query time period t specified by the user to obtain a group of storage blocks within the query time period t. The group of storage blocks specifically refers to a series of storage blocks ( ,..., ).
[0099] Verify the storage correctness and data correctness of the group of storage blocks. If the verification fails, generate a failed certification and issue it to the user. Among them, the verification process of the storage correctness and data correctness of the group of storage blocks is implemented with reference to the data storage correctness verification process and the data correctness verification process in the above embodiments, and will not be elaborated in this embodiment.
[0100] If the verification passes, use the private key to decrypt the operation ciphertext stored in each storage block of the storage block group to obtain the corresponding original hash code H, and query the corresponding second data pair (data, pk, H, R) in the off-chain server according to the original hash code H.
[0101] Extract the operation record R from the second data pair (data, pk, H, R), and calculate the secondary hash code of the operation record using the hash function in the hands of the fire equipment manufacturer. ;
[0102] Perform a consistency comparison on the secondary hash code and the original hash code H. If they are consistent, it is determined that the user operation corresponding to the operation record R within the query time period t has credibility, and a certified deposit is issued to the user. If they are inconsistent, a non-certified deposit is issued to the user.
[0103] By authenticating the operation records of the user within the specified query time period, the embodiments of the present invention can prove the credibility of the user's operations, realize the traceability of the operation data of the fire equipment, and solve the problem that the prior art lacks the credible authentication of the user's operations.
[0104] The embodiments of the present invention perform data deposit through a combined on-chain and off-chain storage method. The complete operation data and operation records of the fire equipment are stored in the off-chain server, and the original hash code corresponding to the operation record is stored as data proof in the blocks of the blockchain. All the operation data of the fire equipment can be stored, and the immutability of the operation records of the fire equipment is ensured through the characteristics of the blockchain, solving the problem that the storage results of the fire equipment data in the prior art are easily modified.
[0105] Embodiment 2
[0106] Refer to Figure 5 As shown, on the basis of the above Embodiment 1, the embodiments of the present invention further provide a data deposit device for fire equipment, and the device includes:
[0107] A data acquisition module, configured to obtain the operation data and operation records of the fire equipment, generate a public key and a private key, and form a first data pair with the operation data, operation records, and public key;
[0108] A data recombination module, which performs hash processing on the operation records in the first data pair to obtain an original hash code H, and recombines the original hash code H with the first data pair into a second data pair;
[0109] An off-chain storage module, configured to store the second data pair in the off-chain server, and encrypt the original hash code H in the second data pair using the public key to obtain an operation ciphertext;
[0110] An identification generation module, which is used to generate a storage block identification by using group operations under a generator and a random number of steps;
[0111] A blockchain storage module, which is used to create a storage block on the blockchain according to the storage block identification and store the operation ciphertext in the storage block.
[0112] Furthermore, the data deposit and verification device according to the embodiment of the present invention further includes a data verification module, and the data verification module includes a storage verification unit and a data verification unit. Among them,
[0113] The storage verification unit is responsible for verifying the correctness of data storage. Specifically, n storage blocks are randomly selected from the storage chain, and the group operations with the maximum number of steps are respectively performed on the storage block identifications corresponding to the randomly selected n storage blocks, and it is judged whether the results of the group operations with the maximum number of steps of the n storage blocks are all equal. If they are equal, it is determined that the data storage is correct; if they are not equal, it is determined that the data storage is incorrect. The storage verification unit can ensure that the storage chain has not been illegally modified.
[0114] The data verification unit is responsible for verifying the correctness of the data. Specifically, the operation ciphertext is extracted from the specified storage block on the blockchain, and the private key is used to decrypt the operation ciphertext to obtain the corresponding original hash code, and this original hash code is used as the data verification hash code H'. And according to the data verification hash code H', the original hash code matching is performed in the off-chain server. If the corresponding original hash code H can be matched, it is considered that the operation ciphertext in the storage block is correct; if the corresponding original hash code H cannot be matched, it is considered that the operation ciphertext in the storage block is incorrect. The data verification unit can ensure that the data in the off-chain server corresponds to the operation ciphertext stored in the on-chain server.
[0115] Furthermore, the data deposit and verification device according to the embodiment of the present invention further includes a deposit and verification generation module, and the deposit and verification generation module is used to generate a deposit and verification of the credibility of user operations, specifically including:
[0116] Retrieve the storage blocks on the blockchain according to the query time period t specified by the user to obtain a storage block group within the query time period t;
[0117] Verify the storage correctness and data correctness of the storage block group. If the verification fails, generate a failed deposit and verification and issue it to the user;
[0118] If the verification passes, use the private key to decrypt the operation ciphertext stored in each storage block in the storage block group to obtain the corresponding original hash code H, and query the corresponding second data pair (data, pk, H, R) in the off-chain server according to the original hash code H;
[0119] Extract the operation record R from the second data pair (data, pk, H, R), and use the hash function in the hands of the fire equipment manufacturer to calculate the secondary hash code of the operation record ;
[0120] For the secondary hash code A consistency comparison is performed with the original hash code H. If they are consistent, it is determined that the user operation corresponding to the operation record R within the query time period t is credible, and a certificate of authentication is issued to the user. If they are inconsistent, a certificate of authentication failure is issued to the user.
[0121] In addition, in other embodiments of the present invention, when performing trusted authentication on data operations, the specific operation data in the second data pair (data, pk, H, R) can also be analyzed to determine how to check the operation behavior in the user operation record according to the preset operation standard, and determine whether the user operation meets the preset operation standard, and then determine whether the user operation violates the regulations, etc., thereby further improving the credibility of the user operation authentication.
[0122] The data evidence storage device provided by the embodiment of the present invention adopts a storage method based on blockchain, and in order to improve storage performance, the form of joint storage on the chain and off the chain is adopted to store the complete device operation data in the off-chain storage server, and the proof of the data is stored in the on-chain block. For the on-chain storage that is open to all participants, the corresponding storage block identifier is generated by the group operation G under the generator g and the random step number, and the storage blocks are connected in the form of a linked list according to the time when the storage blocks were generated, so that the information such as the generation time of the storage blocks can be traced back.
[0123] In addition, for the correctness verification of on-chain storage, the embodiment of the present invention randomly extracts n storage blocks from a storage chain, performs a maximum step group operation on the identifiers of the extracted storage blocks, and determines whether the identifiers of the storage blocks are equal after the operation is completed. If they are equal, it is considered that the storage is correct and the storage chain has not been illegally modified. For data correctness verification, the embodiment of the present invention extracts the ciphertext data in the specified storage block, that is, the operation ciphertext, decrypts the operation ciphertext with a private key to obtain the original hash code H, and searches the off-chain server for a matching original hash code H. If so, the data is considered correct. In addition, the embodiment of the present invention also authenticates the user's operation records and generates corresponding credentials for the division of responsibilities after a fire and tracing the cause of the fire, further reducing the impact of irregular use factors on device performance.
[0124] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A data deposit and certification method for fire-fighting equipment, characterized in that, Including: Obtain the operation data and operation records of the fire-fighting equipment, generate a public key and a private key, and form a first data pair with the operation data, operation records and public key; Perform a hash process on the operation records in the first data pair to obtain an original hash code H, and reorganize the original hash code H and the first data pair into a second data pair; Store the second data pair in an off-chain server, and encrypt the original hash code H in the second data pair using the public key to obtain an operation ciphertext; Generate a storage block identifier using group operations under a generator and a random number of steps, including: Obtain the generator g and group operation G set by the fire-fighting equipment manufacturer; Generate an initial data block b0 and determine the identifier of the initial data block b0 ; With the identifier as the starting point, perform the group operation G of random steps with the generator g to generate the storage block identifier ; Create a storage block on the blockchain according to the storage block identifier, and store the operation ciphertext in the storage block, including: Create a storage block for storing the operation ciphertext on the blockchain according to the storage block identifier, connect the storage block to the previous storage block in the form of a linked list to form a storage chain, and record the connection time of the storage blocks; After the storage block is created, upload the operation ciphertext to the blockchain and store it in the corresponding storage block; Retrieve the storage blocks on the blockchain according to the query time period t specified by the user to obtain a group of storage blocks within the query time period t; Verify the storage correctness and data correctness of the storage block group. If the verification fails, generate a failed notarization and issue it to the user; If the verification passes, decrypt the operation ciphertext stored in each storage block in the storage block group using the private key to obtain the corresponding original hash code H, and query the corresponding second data pair in the off-chain server according to the original hash code H; Extract the operation record R from the second data pair, and calculate the secondary hash code of the operation record using the hash function in the hands of the fire equipment manufacturer ; Perform a consistency comparison on the secondary hash code and the original hash code H. If they are consistent, it is determined that the user operation corresponding to the operation record R within the query time period t has credibility, and a certified deposit is issued to the user. If they are inconsistent, a deposit with failed certification is issued to the user.
2. The data deposit method for fire-fighting equipment according to claim 1, characterized in that The obtaining the operation data and operation records of the fire-fighting equipment, generating a public key and a private key, and forming a first data pair with the operation data, operation records and public key includes: Collect the operation data of the fire-fighting equipment, where the operation data includes external environment data and equipment data; Generate a public key pk and a private key sk for data encryption and decryption according to a preset asymmetric algorithm; Real-time record the operation data of the user on the fire-fighting equipment to obtain an operation record R, where the operation record R includes the user's usage operation A, operation time T, and the equipment identity identification code including manufacturer information; Perform data combination on the operation data, public key pk, and operation record R within a preset time period to obtain a first data pair (data, pk, R).
3. The data deposit method for fire-fighting equipment according to claim 1, characterized in that Also including: Randomly select n storage blocks in the storage chain, perform group operations with the maximum number of steps on the storage block identifiers corresponding to the randomly selected n storage blocks respectively, and determine whether the results of the group operations with the maximum number of steps of the n storage blocks are all equal; If they are equal, it is determined that the data storage is correct. If they are not equal, it is determined that the data storage is incorrect.
4. The data storage and certification method for fire-fighting equipment according to claim 1, characterized in that, Also including: Extract the operation ciphertext from the specified storage block on the blockchain, decrypt the operation ciphertext using the private key to obtain the corresponding original hash code, and use this original hash code as the data verification hash code H'. Perform an original hash code matching for the data verification hash code H' in the off-chain server. If the corresponding original hash code H can be matched, it is considered that the operation ciphertext in the storage block is correct. If the corresponding original hash code H cannot be matched, it is considered that the operation ciphertext in the storage block is incorrect.
5. A data deposit and certification device for fire-fighting equipment, characterized in that, Including: A data acquisition module, configured to obtain the operation data and operation records of the fire-fighting equipment, generate a public key and a private key, and form a first data pair with the operation data, operation records, and public key; A data recombination module, which performs a hash process on the operation records in the first data pair to obtain an original hash code H, and recombines the original hash code H with the first data pair into a second data pair; An off-chain storage module, configured to store the second data pair in the off-chain server, and encrypt the original hash code H in the second data pair with the public key to obtain an operation ciphertext; An identification generation module, configured to generate a storage block identification by using group operations under a generator and a random number of steps, including: Obtain the generator g and group operation G set by the fire-fighting equipment manufacturer; Generate an initial data block b0 and determine the identifier of the initial data block b0 ; With the identifier as the starting point, perform the group operation G of random steps through the generator g to generate the storage block identifier ; An on-chain storage module, configured to create a storage block on the blockchain according to the storage block identification, and store the operation ciphertext in the storage block, including: Create a storage block for storing the operation ciphertext on the blockchain according to the storage block identification, connect the storage block to the previous storage block in the form of a linked list to form a storage chain, and record the connection time of the storage blocks; After the storage block is created, upload the operation ciphertext to the blockchain and store it in the corresponding storage block; An evidence generation module, configured to generate evidence of the credibility of user operations, specifically including: According to the query time period t specified by the user, retrieve the storage blocks on the blockchain to obtain a storage block group; verify the storage correctness and data correctness of the storage block group. If the verification fails, generate a failed evidence and issue it to the user; If the verification passes, use the private key to decrypt the operation ciphertext stored in each storage block in the storage block group to obtain the corresponding original hash code H, and query the corresponding second data pair in the off-chain server according to the original hash code H; Extract the operation record R from the second data pair, and calculate the secondary hash code of the operation record by using the hash function in the hands of the fire-fighting equipment manufacturer; Perform a consistency comparison on the secondary hash code and the original hash code H. If they are consistent, it is determined that the user operation corresponding to the operation record R within the query time period t has credibility, and issue an authenticated evidence to the user. If they are inconsistent, issue an unauthenticated evidence to the user.
6. The data storage and evidence device for fire-fighting equipment according to claim 5, wherein It further includes a data verification module, and the data verification module includes a storage verification unit and a data verification unit; wherein, The storage verification unit is configured to randomly extract n storage blocks from the storage chain, perform a maximum number of steps group operation on the storage block identifications corresponding to the randomly extracted n storage blocks respectively, and determine whether the maximum number of steps group operation results of the n storage blocks are all equal. If they are equal, it is determined that the data storage is correct. If they are not equal, it is determined that the data storage is incorrect; The data verification unit is used to extract the operation ciphertext from the specified storage block on the blockchain, decrypt the operation ciphertext using the private key to obtain the corresponding original hash code, and use this original hash code as the data verification hash code H'. Then, it performs an original hash code matching in the off-chain server based on the data verification hash code H'. If the corresponding original hash code H can be matched, it is considered that the operation ciphertext in the storage block is correct. If the corresponding original hash code H cannot be matched, it is considered that the operation ciphertext in the storage block is incorrect.
Citation Information
Patent Citations
Cross-alliance chain-oriented privacy protection data element transaction auditing method
CN118940312A