Zero-Trust Security Data Processing Method, System, Electronic Device, and Storage Medium
By building a tree-shaped data structure and blockchain technology in a zero-trust intelligent network, encrypted processing and fine-grained access control, the problem of secure transmission and accurate migration of multi-source heterogeneous data in the field of intelligent driving is solved, the security and privacy of data retrieval is achieved, and the data in the intelligent driving system is protected.
Patent Information
- Application Number
- CN202510390278.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-03-31
AI Technical Summary
In a zero-trust intelligent network, how to effectively integrate multi-source heterogeneous data, enhance the reliability, complementarity and adaptability of data or information, and ensure the secure transmission and accurate migration of data information, especially in the field of intelligent driving, how to protect data from attacks and tampering in an open system.
The zero-trust secure data processing method based on blockchain technology is adopted, and the tree-shaped data structure and index data are constructed, and the secure index information and trap gate are generated by encrypting the process, which realizes fine-grained access control, and combines B+ tree structure and predicate encryption to search ciphertext intervals to ensure the security and privacy of data retrieval.
It improves the security and privacy of data retrieval on the blockchain, ensures that only users with corresponding permissions can access specific data, improves the efficiency and accuracy of data retrieval, and protects network resources and data in the intelligent driving system.
Smart Images

Figure CN119885284B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular, to a zero-trust security data processing method, system, electronic device, and storage medium. Background Art
[0002] The zero-trust intelligent network has characteristics such as an open communication environment, rapid movement of nodes, and random access and networking of a large number of sensing devices. The characteristics of "authenticating at any time and never trusting" are becoming increasingly prominent. For example, in the field of intelligent driving, as vehicles become increasingly intelligent, networked, and shared, the vehicle itself has changed from a closed system to an open system, and security issues have become increasingly prominent.
[0003] In a multi-source heterogeneous data element environment, the means of attacking data are diverse, resulting in defects such as over-collection, leakage, theft, and tampering of environmental data. Especially restricted by the balance bottleneck between risk and trust in the zero-trust architecture, how to effectively integrate the massive data stored in the cloud of the multi-source heterogeneous zero-trust intelligent network, enhance the reliability, complementarity, and self-adaptability of data or information conversion, and ensure the secure transmission and accurate migration of data information is a problem that needs to be further studied in depth at present.
[0004] Therefore, there is an urgent need for a zero-trust security data processing method, system, electronic device, and storage medium to solve the above problems. Summary of the Invention
[0005] Aiming at the problems existing in the prior art, the present invention provides a zero-trust security data processing method, system, electronic device, and storage medium.
[0006] The present invention provides a zero-trust security data processing method, including:
[0007] According to the target keyword information in the data retrieval task, determine the set of data tree nodes to be queried, where the set of data tree nodes to be queried is the set of all tree nodes in the tree-shaped data structure that contain the target keyword information; the tree-shaped data structure is constructed from keyword information and index data; the index data is the index corresponding to the data already on the chain in the target blockchain;
[0008] According to the target retrieval range in the data retrieval task, determine the set of target query range tree nodes, where the set of target query range tree nodes is the set of tree nodes in the tree-shaped data structure that contain the target keyword information within the target retrieval range; the target retrieval range represents the retrieval range corresponding to the data retrieval task in the tree-shaped data structure;
[0009] Perform a first encryption process on the set of data tree nodes to be queried to obtain the security index information corresponding to the data retrieval task; perform a second encryption process on the vector representations of the elements in the target query range tree node set to obtain the trapdoors corresponding to the elements in the target query range tree node set.
[0010] Determine the query permission of the data retrieval task on the target blockchain according to the security index information and the trapdoors.
[0011] According to a zero-trust security data processing method provided by the present invention, the tree-shaped data structure is constructed through the following steps:
[0012] Construct corresponding key-value pairs according to the keyword information and the index data;
[0013] Use the key-value pairs as tree nodes, and construct the corresponding tree-shaped data structure of the B+ tree structure or the R tree structure according to the parent node relationship between the tree nodes.
[0014] According to a zero-trust security data processing method provided by the present invention, the performing a first encryption process on the set of data tree nodes to be queried to obtain the security index information corresponding to the data retrieval task includes:
[0015] Generate a corresponding key based on a preset security parameter;
[0016] Construct a data query polynomial according to the difference between each element in the set of data tree nodes to be queried and the target data vector, where the target data vector is the encrypted representation of the data to be retrieved in the target blockchain for the data retrieval task;
[0017] Generate a corresponding coefficient vector set according to the polynomial coefficients in the data query polynomial;
[0018] Encrypt the coefficient vector set based on the private key in the key to obtain the security index information corresponding to the data retrieval task;
[0019] The performing a second encryption process on the vector representations of the elements in the target query range tree node set to obtain the trapdoors corresponding to the elements in the target query range tree node set includes:
[0020] Perform trapdoor calculation according to the vector representations of the elements in the target query range tree node set and the key to obtain the trapdoors corresponding to the elements in the target query range tree node set.
[0021] A zero-trust security data processing method provided by the present invention, determining the query permission of the data retrieval task on the target blockchain according to the security index information and the trapdoor, includes:
[0022] Obtain the inner product result between the security index information and the trapdoor;
[0023] If the inner product result belongs to the elements in the target query range tree node set, determine that the data retrieval task has query permission on the target blockchain;
[0024] If the inner product result does not belong to the elements in the target query range tree node set, determine that the data retrieval task does not have query permission on the target blockchain.
[0025] A zero-trust security data processing method provided by the present invention, after determining the query permission of the data retrieval task on the target blockchain according to the security index information and the trapdoor, the method further includes:
[0026] After determining that the data retrieval task has query permission on the target blockchain, based on the oblivious transfer process, send the data to be queried corresponding to the data retrieval task on the target blockchain to the target end, where the target end is the user terminal that generates the data retrieval task.
[0027] A zero-trust security data processing method provided by the present invention, the target blockchain is a blockchain with a single main chain and multiple side chains constructed based on a hash graph, and the consensus algorithm in the target blockchain is a Byzantine fault-tolerant consensus algorithm, where the main chain and side chains of the target blockchain are used for tasks of storing different types of data.
[0028] A zero-trust security data processing method provided by the present invention, the method further includes:
[0029] Perform data encryption processing on the data to be uploaded through a lattice-based encryption algorithm to obtain the encrypted data to be uploaded and the digital signature corresponding to the encrypted data to be uploaded;
[0030] After determining that the encrypted data to be uploaded and the digital signature pass the consensus verification, add the encrypted data to be uploaded and the digital signature to the target blockchain, and construct the tree node corresponding to the encrypted data to be uploaded in the tree-shaped data structure according to the preset field information in the encrypted data to be uploaded.
[0031] The present invention also provides a zero-trust security data processing system, including:
[0032] The first retrieval module is used to determine a set of data tree nodes to be queried according to the target keyword information in the data retrieval task. Among them, the set of data tree nodes to be queried is a set of all tree nodes containing the target keyword information in the tree - shaped data structure; the tree - shaped data structure is constructed from keyword information and index data; the index data is the index corresponding to the data already on the chain in the target blockchain.
[0033] The second retrieval module is used to determine a set of target query range tree nodes according to the target retrieval range in the data retrieval task. Among them, the set of target query range tree nodes is a set of tree nodes that contain the target keyword information within the target retrieval range in the tree - shaped data structure; the target retrieval range represents the retrieval range corresponding to the data retrieval task in the tree - shaped data structure.
[0034] The encryption module is used to perform a first encryption process on the set of data tree nodes to be queried to obtain the security index information corresponding to the data retrieval task; perform a second encryption process on the vector representation of each element in the set of target query range tree nodes to obtain the trapdoor corresponding to each element in the set of target query range tree nodes.
[0035] The access control module is used to determine the query permission of the data retrieval task on the target blockchain according to the security index information and the trapdoor.
[0036] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the zero - trust security data processing method as described in any one of the above.
[0037] The present invention also provides a non - transitory computer - readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the zero - trust security data processing method as described in any one of the above.
[0038] The zero - trust security data processing method, system, electronic device, and storage medium provided by the present invention organize keyword information and index data by constructing a tree - shaped data structure, determine the sets of tree nodes for the data to be queried and the target query range according to the data retrieval task, and then generate security index information and trapdoors through encryption processing of these sets of tree nodes, thereby realizing fine - grained access control for data retrieval tasks, improving the security and privacy of data retrieval on the blockchain, and ensuring that only users with corresponding query permissions can access specific data. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] To more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0040] Figure 1 Schematic flowchart of the zero-trust security data processing method provided by the present invention;
[0041] Figure 2 Schematic structural diagram of the zero-trust security data processing system provided by the present invention;
[0042] Figure 3 Schematic structural diagram of the electronic device provided by the present invention. Detailed implementation manners
[0043] To make the objectives, technical solutions and advantages of the present invention clearer, the following will clearly and completely describe the technical solutions in the present invention with reference to the accompanying drawings in the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Based on the embodiments in the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present invention.
[0044] Network security technology refers to the use of various technical means and methods to protect the hardware, software and data in the system from being damaged, changed or leaked due to accidental or malicious reasons, to ensure the continuous, reliable and normal operation of the system, and to prevent the interruption of services.
[0045] Trusted data refers to data that can be trusted, reliable and accurate. During the processes of generation, collection, storage, transmission, processing and use of this data, it can meet specific quality standards and security requirements. Its core elements include data credibility, identity, environmental credibility, application credibility and flow credibility. Data credibility refers to the ability of data to maintain accuracy, integrity, consistency and reliability throughout its life cycle.
[0046] As a distributed shared data model, blockchain has information technology advantages such as peer-to-peer transmission, multi-party consensus, structured coding, intelligent scripting and cryptographic support. Its features such as automation, anti-tampering, anti-forgery, fine-grained, traceability and weak centralization can enable each decentralized entity to jointly create and operate a highly reliable data system with consistency and sharing, while having the advantages of both security and high efficiency. With the Internet as the underlying infrastructure, blockchain builds a more trusted management and control platform for the efficient circulation of information, and can fully solve the security problems in each link of data collection, transmission, storage and execution.
[0047] As an emerging network security architecture and concept, the zero-trust intelligent network can effectively protect network resources and data in the intelligent driving system through mandatory verification and authorization, as well as fine-grained access control. For example, in an intelligent driving vehicle, the zero-trust intelligent network can assign reasonable permissions to each component and perform access control on each data interaction between components, thus effectively protecting the internal applications of the vehicle from connections by unauthorized users.
[0048] In the field of intelligent driving, in the face of a complex environment of multi-source heterogeneous data elements, the means of data attacks emerge in an endless stream, resulting in risks such as over-collection, leakage, theft, and tampering of environmental data. Especially under the zero-trust architecture, the balance between risk and trust has become a major bottleneck. Therefore, how to effectively integrate heterogeneous data from different sources, enhance the reliability, complementarity, and self-adaptability of data conversion in the vast amounts of data stored in the zero-trust intelligent network cloud, and at the same time ensure the security and accuracy of data information during the transmission process is an urgent problem to be solved in the field of intelligent driving.
[0049] Aiming at the problems existing in the above-mentioned prior art, the present invention provides a method for transmitting zero-trust security information based on blockchain encryption. This method relies on blockchain technology and integrates information technologies such as peer-to-peer transmission, multi-party consensus, structured coding, smart contracts, and cryptography, showing remarkable features such as automated operation, anti-tampering, anti-counterfeiting ability, fine-grained control, traceability, and weak centralization. These features enable decentralized parties to jointly build and operate a reliable data system with high consistency and sharing, while ensuring the security and operating efficiency of the system. The present invention is based on the Internet infrastructure, and blockchain technology provides a more trustworthy management and control platform for the efficient circulation of information, effectively solving the security problems in the links of data collection, transmission, storage, and execution, and being able to effectively overcome problems such as lagging information transmission, imperfect open trust environment, and inconsistent coordination of control instructions in the traditional management system, and providing strong support for multi-level, multi-region, and multi-center standardized control and system management through reliable data flow management, efficient cooperation mechanisms, and scientific decision-making and analysis capabilities.
[0050] Figure 1 The flow schematic diagram of the zero-trust security data processing method provided by the present invention is as Figure 1 shown. The present invention provides a zero-trust security data processing method, including:
[0051] Step 101: Determine the set of data tree nodes to be queried according to the target keyword information in the data retrieval task. The set of data tree nodes to be queried is the set of all tree nodes in the tree-shaped data structure that contain the target keyword information. The tree-shaped data structure is constructed from keyword information and index data. The index data is the index corresponding to the data that has been uploaded to the target blockchain.
[0052] In the present invention, the data retrieval task includes one or more target keyword information, which are used to find the data that matches them in the data set.
[0053] In the present invention, the set of data tree nodes to be queried refers to the set of all tree nodes that contain the target keyword information in the tree-shaped data structure. This set is a direct manifestation of the retrieval result and contains all data nodes that meet the query conditions. The tree-shaped data structure is a hierarchical data organization method, where each node can have zero or more child nodes, forming a tree-like hierarchical structure. In the present invention, the tree-shaped data structure is constructed jointly by "keyword information" and "index data", indicating that each tree node contains some keyword information to identify or describe the data content of the node. At the same time, these nodes are also associated with other nodes through index data.
[0054] In the present invention, the index data is the index corresponding to the data that has been uploaded to the target blockchain. In blockchain technology, once the data is uploaded to the chain, it is difficult to modify or delete. Therefore, in order to efficiently retrieve this data, an index needs to be established to accelerate the query process. The index data can be regarded as the "address" or "pointer" of the data, which points to the specific data location on the blockchain, enabling quick positioning to the nodes that contain the target keyword information in the tree-shaped data structure.
[0055] The present invention combines the tree - shaped data structure with blockchain technology, which can achieve an efficient and secure data retrieval mechanism. Blockchain provides the immutability of data, while the tree - shaped data structure provides hierarchical organization and fast retrieval ability of data. Under this combination, data retrieval tasks can be completed more efficiently and accurately, especially in scenarios where a large amount of data needs to be processed and high requirements for data security are imposed. For example, in the field of intelligent driving, a large amount of road condition information, vehicle status information, pedestrian behavior information, etc. need to be retrieved and analyzed in real - time. By constructing a data retrieval system based on the tree - shaped data structure and blockchain technology, fast and accurate retrieval of this information can be achieved. Specifically, road condition information, vehicle status information, etc. can be used as keyword information to construct a tree - shaped data structure; at the same time, blockchain technology is used to record the process of these information being uploaded to the chain and generate corresponding index data. In this way, when an autonomous vehicle needs to make a decision, the required information can be quickly retrieved through the tree - shaped data structure, thereby improving the accuracy and efficiency of decision - making. In addition, the immutability of blockchain also ensures the authenticity and reliability of data, providing strong technical support for intelligent driving.
[0056] Step 102: Determine a set of target query range tree nodes according to the target retrieval range in the data retrieval task, where the set of target query range tree nodes is a set of tree nodes in the tree - shaped data structure that contain the target keyword information within the target retrieval range; the target retrieval range represents the retrieval range corresponding to the data retrieval task in the tree - shaped data structure.
[0057] In the present invention, the target retrieval range represents a specific range that needs to be retrieved in the tree - shaped data structure specified by the user - end or the system in the data retrieval task. This range can be a part, a certain level, or some specific branches in the tree - shaped data structure. The determination of the target retrieval range is usually based on the specific requirements and background of the retrieval task. For example, the user - end may only be interested in certain specific types or categories of data in the tree - shaped data structure.
[0058] The set of target query range tree nodes refers to the set of all tree nodes that contain the target keyword information within the target retrieval range. This set is a direct manifestation of the search results of the retrieval task within the specified range and contains all tree nodes that match the query keyword within the target retrieval range.
[0059] When performing a data retrieval task, the tree - shaped data structure enables the system to locate and access data according to levels and branches, thereby improving the retrieval efficiency.
[0060] Specifically, in the present invention, first, according to the requirements of the data retrieval task, the target retrieval range is determined; then, in the tree - shaped data structure, all tree nodes within the target retrieval range are traversed, and for each tree node, it is checked whether it contains the target keyword information; if it does, the tree node is added to the set of tree nodes in the target query range. For example, in the field of intelligent driving, it is necessary to retrieve and analyze the road conditions, traffic signals, pedestrians, and the dynamics of other vehicles around the vehicle in real - time. To efficiently process this large amount of real - time changing data, different target retrieval ranges can be set according to the requirements of the autonomous driving system, such as only focusing on the road conditions within a certain distance in front of the vehicle, or only focusing on specific types of traffic signals.
[0061] Step 103, perform a first encryption process on the set of tree nodes of the data to be queried to obtain the secure index information corresponding to the data retrieval task; perform a second encryption process on the vector representations of the elements in the set of tree nodes in the target query range to obtain the trapdoors corresponding to the elements in the set of tree nodes in the target query range.
[0062] In the present invention, the set of tree nodes of the data to be queried is encrypted for the first time using a private key, thereby converting the set of tree nodes of the data to be queried into an encrypted form, that is, secure index information. This encrypted form protects the content of the original data, making it impossible for unauthorized users to directly access or understand this data, and it can be used for verifying or retrieving the encrypted data when needed.
[0063] For each element (i.e., tree node) in the set of target query range tree nodes, it can be represented in a vector form, and this vector representation may include keyword information, location information, or other relevant features of the node. In the present invention, a second encryption process is performed on these vector representations using a secret key. Through the second encryption process, the vector representation of each element in the set of target query range tree nodes is converted into an encrypted form, i.e., a trapdoor. A trapdoor is a special encrypted output that allows a user with the corresponding decryption key to verify or retrieve specific encrypted data without decrypting the entire data set. For example, in map data in the field of intelligent driving, it may contain sensitive route information, landmark locations, or user behavior data. To protect this data, the above encryption processing method can be used. Specifically, during the first encryption process, key nodes (such as intersections, important landmarks, etc.) in the map data can be encrypted to generate secure index information. In this way, even if the map data is illegally obtained, the attacker cannot directly understand the specific information of these key nodes. During the second encryption process, environmental data collected in real time by the autonomous driving system can be encrypted, such as the positions of other vehicles around the vehicle, pedestrian dynamics, etc. By generating a trapdoor, the system can verify or retrieve specific environmental information without exposing the original data, thus ensuring the safety and privacy of the driving process.
[0064] Step 104, determine the query permission of the data retrieval task on the target blockchain according to the secure index information and the trapdoor.
[0065] In the present invention, when a data retrieval task needs to be executed on the target blockchain, it is first checked whether the task has the corresponding query permission. The determination of the query permission is based on the matching degree between the secure index information and the trapdoor. Specifically, the present invention calculates the predicate relationship between the secure index information and the trapdoor according to the inner product. If the inner product result corresponding to the keyword is within the interval corresponding to the set of target query range tree nodes, it can be determined that the data retrieval task has the permission to query on the target blockchain.
[0066] The zero-trust security data processing method provided by the present invention organizes keyword information and index data by constructing a tree-shaped data structure, determines the set of tree nodes to be queried and the target query range according to the data retrieval task, and then generates secure index information and a trapdoor by encrypting these sets of tree nodes, thereby realizing fine-grained access control for data retrieval tasks, improving the security and privacy of data retrieval on the blockchain, and ensuring that only users with the corresponding query permission can access specific data.
[0067] Based on the above embodiments, the tree-shaped data structure is constructed through the following steps:
[0068] Construct corresponding key-value pairs according to the keyword information and the index data;
[0069] Use the key-value pairs as tree nodes, and construct the corresponding tree data structure of the B+ tree structure or the R tree structure according to the parent node relationship between each tree node.
[0070] To improve the security of retrieving and accessing encrypted data, the present invention establishes a complete encrypted index between the consensus node and the service node to ensure the comprehensiveness and security of data traceability. At the same time, a local data index is constructed among the mobile terminal nodes to improve the efficiency and flexibility of data retrieval. At the same time, to achieve efficient linear range retrieval, the present invention combines predicate encryption and tree data structure technology. This combination method not only ensures the accuracy of retrieval, but also greatly improves the retrieval speed, enabling users to quickly find the required data.
[0071] In the present invention, keyword information is used to identify or search for information of specific data items, usually provided by the user side during query or used by the system internally as an identifier for data classification and retrieval.
[0072] Index data is data associated with keyword information, which provides information about the location, attributes, or other relevant information of the data item, and is used to quickly locate or access the data.
[0073] Furthermore, according to the keyword information and the index data, pair them to form key-value pairs. Among them, the key is the keyword information, which is used to uniquely identify the data item; the value is the index data, which provides information associated with the key. In the tree data structure, a node is the basic unit that constitutes the tree, and each node contains some data (i.e., key-value pairs) and pointers or links that may point to other nodes.
[0074] Use the key-value pairs as tree nodes: We use the previously constructed key-value pairs as nodes in the tree data structure. This means that each node stores a keyword and its corresponding index data, providing a basis for subsequent data retrieval and access.
[0075] When constructing the B+ tree or the R tree, the present invention determines the parent node of each node based on the sequential or spatial position relationship of the keyword information. By recursively or iteratively adding nodes and adjusting the tree structure according to the parent node relationship, a complete B+ tree or R tree is finally constructed. It should be noted that in the present invention, storing the B+ tree in an encrypted form can protect the key value and the retrieval interval information, but the structure itself determines that it is difficult to hide the sorting characteristics of the data. To further improve data security, the tree data structure in the present invention adopts the representation form of the R tree to further protect the key value order in the tree and construct a multi-dimensional interval retrieval function.
[0076] Based on the above embodiments, after determining the query permission of the data retrieval task on the target blockchain according to the security index information and the trapdoor, the method further includes:
[0077] After determining that the data retrieval task has query permission on the target blockchain, based on the oblivious transfer process, send the data to be queried corresponding to the data retrieval task on the target blockchain to the target end, where the target end is the user terminal that generates the data retrieval task.
[0078] In the present invention, in order to protect the user's query intention and data security, on the premise of determining query authorization, perform oblivious transfer (OT for short) on the retrieved data, so that even if the data is intercepted during the data transmission process, the original query content cannot be restored, thus ensuring the confidentiality, integrity, and security of the access mode of the data.
[0079] Moreover, in terms of access control, the present invention adopts the BLP (Bell-LaPadula) mandatory access control framework, which quantifies risks through information entropy and can more accurately evaluate the security of access requests. At the same time, the present invention also uses collaborative filtering technology to dynamically adjust access quotas, strictly control the relationship between access boundaries and system risks according to the access behavior of the user terminal and the system risk status, and ensure the security of the data and the compliance of the access.
[0080] Based on the above embodiments, the first encryption process for the set of data tree nodes to be queried to obtain the security index information corresponding to the data retrieval task includes:
[0081] Generate a corresponding key based on a preset security parameter;
[0082] Construct a polynomial of data to be queried according to the difference between each element in the set of data tree nodes to be queried and the target data vector, where the target data vector is the encrypted representation of the data to be retrieved in the target blockchain corresponding to the data retrieval task;
[0083] Generate a corresponding set of coefficient vectors according to each polynomial coefficient in the polynomial of data to be queried;
[0084] Encrypt the set of coefficient vectors based on the private key in the key to obtain the security index information corresponding to the data retrieval task;
[0085] The second encryption process for the vector representation of each element in the set of target query range tree nodes to obtain the trapdoor corresponding to each element in the set of target query range tree nodes includes:
[0086] Perform trapdoor calculation based on the vector representations of the elements in the target query range tree node set and the secret key to obtain the trapdoors corresponding to the elements in the target query range tree node set.
[0087] In the present invention, the process of combining predicate encryption and B+ tree structure is described to achieve ciphertext interval retrieval. Among them, predicate encryption is mainly based on inner product calculation, that is, a data vector to be retrieved (i.e., the target data vector) and a retrieval vector are respectively given. Only when , the predicate is satisfied. Considering that using only predicate encryption for ciphertext retrieval requires constructing indexes for each record separately, resulting in the computational amount of nodes growing linearly with the number of records and the above vector length, its efficiency cannot meet the requirements of network real-time performance. Therefore, the present invention uses a B+ tree structure to store key-value pairs in an encrypted form on each node of the tree in an orderly manner, and also uses predicate encryption to judge whether the interval query condition is satisfied through inner product, so that the data holder can independently retrieve the encrypted B+ tree structure, not only reducing the number of comparisons to the logarithmic level, but also effectively avoiding additional interaction overhead.
[0088] Specifically, assume that the retrieval condition (i.e., the target retrieval range) is . Judging the magnitudes of the two extreme values and the keyword in the B+ tree node is equivalent to determining whether belongs to the interval or , where is the maximum value within the interval.
[0089] Furthermore, define as all B+ tree nodes containing the keyword , that is, the set of B+ tree nodes of the data to be queried, as the B+ tree node in the set of B+ tree nodes of the data to be queried; as the minimum node set that covers and only covers the retrieval condition , that is, the set of target query range tree nodes, as the node in the set of target query range tree nodes.
[0090] If , it means that the intersection of and is not empty and there is an intersecting node. Furthermore, map to a polynomial, that is, the polynomial of the data to be queried:
[0091] ;
[0092] Among them, is the polynomial coefficient; is the variable. When , there must exist satisfying . Based on this, the present invention can transform the interval judgment of keywords into the zero-value judgment problem of multiple vector inner products, and thus construct the following related functions for the ciphertext interval retrieval process:
[0093] Function : Generate a key according to the preset security parameters, where the preset security parameters can be security parameters such as key length and key update period.
[0094] Function : According to the difference between each element in the set of nodes of the data tree to be queried and the target data vector, construct the polynomial of the data to be queried, and thus construct the corresponding coefficient vector set according to each polynomial coefficient in the polynomial of the data to be queried, and further encrypt the coefficient vector set using the private key to obtain the secure index information . .
[0095] Function : Perform vector representation on the elements in the set of nodes of the target query range , that is, , and then perform trapdoor calculation according to the key and to obtain the trapdoor of predicate encryption, where , , and can be calculated through the trapdoor function.
[0096] Based on the above embodiments, determining the query permission of the data retrieval task on the target blockchain according to the secure index information and the trapdoor includes:
[0097] Obtain the inner product result between the secure index information and the trapdoor;
[0098] If the inner product result belongs to the elements in the set of nodes of the target query range, it is determined that the data retrieval task has query permission on the target blockchain;
[0099] If the inner product result does not belong to the elements in the set of nodes of the target query range, it is determined that the data retrieval task does not have query permission on the target blockchain.
[0100] In the present invention, the secure index information and the trapdoor are regarded as vectors, and the result of their inner product is a scalar value. By calculating the inner product between the secure index information and the trapdoor, a specific numerical result, i.e., the inner product result, can be obtained. By determining whether the inner product result belongs to the elements in the target query range tree node set, it can be determined whether the data retrieval task meets the query conditions. If the inner product result belongs to the elements in the target query range tree node set, it is determined that the data retrieval task has query permission on the target blockchain, indicating that the client or the system can access and retrieve specific data items stored on the blockchain.
[0101] If the inner product result does not belong to the elements in the target query range tree node set, it is determined that the data retrieval task does not have query permission on the target blockchain, indicating that the client or the system cannot access and retrieve specific data items stored on the blockchain. Further, the present invention constructs the following related functions for the ciphertext interval permission judgment process:
[0102] Function : According to the inner product result, determine the predicate relationship between the secure index information and the trapdoor . If the inner product result corresponding to the keyword falls within the interval of the target query range tree node set corresponding to the tree node , then return 1, indicating that the data retrieval task has query permission on the target blockchain.
[0103] Function : Call the function for judgment. If there exists such that , then it indicates that the range of the keyword is the exponent corresponding to the target query range tree node set , and accordingly output 1.
[0104] According to the above functions, the present invention can use to encrypt the upper and lower bounds of the key-value pairs corresponding to each tree node respectively on the B+ tree structure, and maintain the logical order relationship between the tree nodes through the tree structure. During actual retrieval, use to encrypt the interval and the interval respectively to generate the trapdoor corresponding to the interval and the corresponding to the interval , so that the data holder can perform ciphertext comparison on the B+ tree structure through the function, find the next tree node to be retrieved, iterate in turn, and finally locate the subtree or leaf node that meets the retrieval conditions, and batch obtain the data to be read.
[0105] Based on the above embodiments, the target blockchain is a blockchain with a single main chain and multiple side chains constructed based on a HashGraph, and the consensus algorithm in the target blockchain is the Practical Byzantine Fault Tolerance (PBFT) consensus algorithm. Among them, the main chain and side chains of the target blockchain are used for tasks of storing different types of data.
[0106] In the present invention, the target blockchain adopts a single main chain and multiple side chains structure, which is constructed based on the HashGraph technology. Based on the characteristic of the HashGraph that supports parallel creation of multiple chains, it can significantly improve the throughput of the system and support the interaction of cross-chain smart contracts. In the present invention, the main chain is responsible for task assignment and trust backtracking, while the side chains are used to handle specific business logics and data storage. This structure not only ensures the overall stability and security of the system, but also improves the flexibility and scalability of the business.
[0107] Furthermore, in the present invention, the consensus algorithm adopted by the target blockchain is the Practical Byzantine Fault Tolerance (PBFT) consensus algorithm, which includes two core processes: mutual voting and virtual voting.
[0108] Mutual voting: Taking events as basic block units, each event contains an information set, a timestamp, a signature, and a reference hash to the parent event. Transaction nodes randomly select multiple reachable nodes to send the event to be confirmed. The receiving nodes sign the event and pack it into a new event, and then continue to send it randomly. Through this gossip propagation mechanism, events can be quickly known to most nodes, ensuring the universality of consensus.
[0109] Virtual voting: Nodes conduct multiple rounds of voting based on the recorded events, and elect the holder whose event set is consistent with that of most nodes as a well-known witness. The well-known witness is responsible for determining the order of events and generating multi-chain blocks. This mechanism not only ensures the correctness of consensus, but also improves the efficiency of the system.
[0110] Based on the above single main chain and multiple side chains structure, combined with the Practical Byzantine Fault Tolerance consensus algorithm, the communication complexity can be reduced to O(n), and multi-chain block fusion and local consensus are supported. Even in extreme environments such as network isolation or congestion, some nodes can still establish a local HashGraph with a 1 / 3 fault tolerance ability and reach an agreement with the main chain after the network is restored, ensuring data consistency.
[0111] In the present invention, the main chain and side chains in the target blockchain undertake the storage tasks of different types of data. The multi-centralized nodes on the main chain are responsible for task assignment and trust backtracking, and store the core data and metadata of the system, such as user identity authentication information, transaction history records, smart contract codes and execution results, etc. These data are crucial for the security and stability of the system. Therefore, the main chain adopts a highly secure design to ensure the immutability and traceability of the data.
[0112] The side chains are used to process specific business logics and data storage. According to the business requirements, multiple side chains can be created to store different types of data, such as user personal information, specific transaction details, smart contract state variables, etc. The design of the side chains is more flexible and scalable, and can meet the requirements of different business scenarios. On this basis, a smart contract between the main chain and the side chains is written, and an efficient Byzantine fault-tolerant consensus algorithm supporting multi-chain integration is designed to realize the integration of the main chain and the side chains, and finally form a standardized graph-structured blockchain.
[0113] Taking the intelligent driving scenario as an example, vehicles need to exchange a large amount of data in real time, such as location, speed, direction, etc. These data are crucial for driving safety. Therefore, it is necessary to ensure the authenticity and reliability of the data. Through the main chain and side chain structure of the target blockchain, the core data such as vehicle identity authentication information and driving data can be stored on the main chain to ensure the security and immutability of the data. At the same time, the sensitive data such as vehicle personalized settings and driving habits can be stored on the side chain to protect the privacy of users. In the intelligent driving scenario, vehicles need to exchange information and make decisions in real time, such as following the vehicle in front, changing lanes and overtaking, etc. Through the mechanisms of mutual voting and virtual voting, vehicles can quickly reach a consensus and take corresponding actions, improving driving safety and efficiency.
[0114] In the present invention, to support the efficient execution of smart contracts, the reputation, instructions, and physical objects in the management transaction are respectively mapped to corresponding structured digital abstractions. Based on the entity relationship theory and Word2Vec (Word to Vector) technology, the storage structure and logical relationship are defined to ensure the efficiency, verifiability, and scalability of data transmission and processing. By equipping a Turing-complete intelligent script on the main chain and a non-complete stack machine script on the side chain, it is possible to prevent low-level nodes from overstepping their authority to execute tasks, while meeting the performance requirements of low-end mobile devices. Through the weak central node's verification of the data source and endorsement of the execution results, it is ensured that the business processes and rules are consistent.
[0115] Based on the above embodiments, the method further includes:
[0116] Through a lattice-based encryption algorithm, the data to be uploaded to the chain is encrypted to obtain the encrypted data to be uploaded to the chain and the digital signature corresponding to the encrypted data to be uploaded to the chain;
[0117] After determining that the encrypted data to be uploaded to the chain and the digital signature pass the consensus verification, add the encrypted data to be uploaded to the chain and the digital signature to the target blockchain, and construct the corresponding tree node of the encrypted data to be uploaded to the chain in the tree data structure according to the preset field information in the encrypted data to be uploaded to the chain.
[0118] In the present invention, to resist quantum attacks and balance data confidentiality and processability, a lattice-based NTRU (Number Theory Research Unit) encryption algorithm is used to implement a semantically secure encryption and signature protocol. At the same time, the present invention optimizes the plaintext encoding method, algebraic structure and execution efficiency of the NTRU algorithm, suppresses noise by combining the self-sampling method (Bootstrap) and the relinearization technique, and constructs a fully homomorphic encryption scheme that supports arithmetic and logical calculations. Further, the use of the evaluation key is eliminated through the smoothing technique and modular reduction, reducing the computational, communication and storage overheads, ensuring the indistinguishability of fresh ciphertexts and computed ciphertexts, and realizing the fully homomorphic security processing of ciphertexts in a multi-key environment. Finally, security mechanisms such as hash algorithms, homomorphic calculations and digital signatures are integrated to construct a unified chain security system, realizing an efficient, secure and reliable information management platform to meet the diverse needs in complex scenarios.
[0119] In the present invention, based on the NTRU quantum-resistant encryption working on the convolutional polynomial ring above, its encryption and decryption operations only need to perform simple polynomial multiplications, so its performance is significantly better than other public-key cryptosystems. At the same time, the NTRU algorithm can be strictly reduced to the shortest vector in the lattice (GapSVP) problem, has a strong ability to resist quantum attacks, and is very suitable for blockchain applications with sensitive information. Its basic encryption and decryption structure is as follows:
[0120] : According to the security parameter generate the modulus and the polynomial order , and at the same time select two small-variance Gaussian distributions and as public variables. Subsequently, sample from order random polynomials and , calculate as the private key, and output as the public key.
[0121] : Encryption, that is, encode the plaintext data as a polynomial , from Randomly select a noise vector from the distribution and , and output the ciphertext .
[0122] : Decryption, that is, calculate , and the output is the plaintext before encryption.
[0123] Based on the above encryption and decryption processes, it can be seen that the NTRU algorithm is very simple. Since its security is mainly based on Ring-LWE (Learning With Errors), short polynomials and small moduli can prevent it from being attacked by various algorithms such as Shor's algorithm and Schmidt orthogonalization, and it can be implemented on most devices with low storage and computational costs.
[0124] In the blockchain, since there are more than one user of information and their rights and responsibilities are different, different data may be encrypted under different key controls. Therefore, the present invention considers implementing basic multi-key homomorphism based on the following decryption structure, where, homomorphic addition:
[0125] ;
[0126] Homomorphic multiplication:
[0127] .
[0128] Furthermore, the present invention adopts a smoothing technique to represent the ciphertext in a more easily representable and processable form, and makes the decryption process no longer depend on the number of times the key is used. Specifically, also using the NTRU algorithm, encrypt the data in the form of a vector as:
[0129] .
[0130] Subsequently, define function to expand the ciphertext vector into a matrix , and stipulate that the smoothing function is:
[0131] .
[0132] It can be seen from the above process that for the first element perform operation, the plaintext can be recovered, where function represents rounding. And for different ciphertexts and perform and Through operations, the ciphertext matrix corresponding to the exclusive OR and AND operations can also be obtained. To further improve performance, the present invention also expands the basis of the function according to the ratio of , so that the ciphertext size decreases in the scale of while meeting the accuracy requirements.
[0133] Regarding the blockchain technology under the existing zero-trust architecture, it does not achieve complete decentralization, but adopts the strategy of centralized decision-making and decentralized execution. To overcome the limitations of existing consensus mechanisms such as PoW (Proof of Work) and DPoS (Delegated Proof of Stake) in terms of throughput, scalability, and energy consumption, and to better fit the hierarchical authorization and multilateral collaboration models in large-scale system management, the present invention provides a method for constructing and consensus of a blockchain based on a graph structure. This method uses HashGraph as the core framework, and around the main chain, corresponding side chains are connected to different functional modules such as data storage and scheduling, so as to achieve a reliable consensus mechanism and ensure an efficient block generation speed and task confirmation timeliness. At the same time, the present invention maps various smart contracts to the side chains at different levels and links of system behavior, which not only ensures that complex upper-layer tasks can be executed through Turing-complete scripts, but also makes it difficult for lower-level tasks to overstep their authority due to the non-complete nature of the scripts, and at the same time adapts to the performance requirements of resource-constrained large-scale low-end mobile devices (such as Internet of Things devices).
[0134] Furthermore, based on the chained block data, under the premise of data encryption protection, the present invention constructs a complete index on service nodes and consensus nodes, and a partial index on verification nodes. These indexes are stored in ciphertext form and meet the indistinguishability requirement, ensuring that even without the key, attackers cannot obtain any valuable information through the indexes. On this basis, combining predicate encryption technology and tree data structures (such as B+ tree structures), the present invention constructs a linear multi-dimensional ciphertext interval retrieval method, which not only has high retrieval performance and fewer interaction rounds, but also can effectively hide the sorting characteristics of the data. In terms of access control, the BLP model is used as the underlying framework, appropriate credit quotas are assigned to authorized entities, and the determination of access rights is realized through a dynamic collaborative filtering mechanism, which can dynamically adjust the risk benchmark according to the changes in the overall user behavior of the system, so as to better balance the relationship between system risk and availability.
[0135] Moreover, to address key requirements such as information protection, digital signatures, and integrity verification in blockchain technology, the present invention employs lattice-based cryptographic algorithms to resist threats such as data leakage, information forgery, and block tampering that may be caused by quantum computing. The NTRU algorithm exhibits strong resistance to lattice basis reduction or Shor period calculation while maintaining high computational efficiency because it can be reduced to the GapSVP (Gap Shortest Vector Problem) on the lattice through quantum proof. In view of this, the present invention constructs an encryption, decryption, and digital signature scheme that combines the NTRU algorithm with polynomial encoding over the Galois field, aiming to meet the strict requirements of the blockchain for data authenticity, confidentiality, and real-time performance.
[0136] In addition, considering that blockchain data may involve various complex calculations during the fusion and processing process, and the data must remain hidden during the processing, the present invention extends the homomorphic property of NTRU to an environment with multiple participants to achieve a privacy calculation and processing method for ciphertexts encrypted with different keys, ensuring the security and privacy of the data during the processing.
[0137] The beneficial effects of the present invention compared with the prior art are mainly reflected in the following three points:
[0138] First, to give full play to the advantages of weak centralization and high security of the blockchain, the underlying physical architecture needs to be implemented using a distributed structure. Based on the actual management logic and functional requirements, differences in interface definitions, communication modes, and physical performance of underlying networks such as the Internet of Things, mobile Internet, and backbone network are shielded to ensure that the implementation of the blockchain data structure, information processing method, and security protocol has unified and clear specifications.
[0139] Second, a load-balanced trust dependence mechanism is constructed using reliable high-performance service nodes and low-end idle computing power in the network. On this basis, by combining the advantages of the Delegated Proof of Stake (DPoS) and Practical Byzantine Fault Tolerance (PBFT) algorithms, and using the Hyperledger as the information exchange carrier, an efficient consensus algorithm with (n - 1) / 3 fault tolerance is constructed. This algorithm can effectively resist various active attacks such as collusion among block producers, abuse of low voting rates, and distributed denial of service within the threshold range.
[0140] Third, a quantum-resistant NTRU algorithm based on lattices is adopted to implement data encryption and digital signature functions respectively. To balance the contradiction between confidentiality and system functionality, through the Flattering technology, the encryption mechanism supports fully homomorphic calculation in a multi-key environment. Combining zero-knowledge proof technology, it is ensured that smart contracts, information fusion, and verification can be executed on semantically secure ciphertexts, further enhancing the security and functionality of the system.
[0141] The zero-trust security data processing system provided by the present invention will be described below. The zero-trust security data processing system described below can be correspondingly referred to the zero-trust security data processing method described above.
[0142] Figure 2 It is a schematic structural diagram of the zero-trust security data processing system provided by the present invention. As Figure 2 shown, the present invention provides a zero-trust security data processing system, including a first retrieval module 201, a second retrieval module 202, an encryption module 203, and an access control module 204. Among them, the first retrieval module 201 is used to determine a set of data tree nodes to be queried according to the target keyword information in the data retrieval task. Among them, the set of data tree nodes to be queried is a set of all tree nodes containing the target keyword information in the tree-shaped data structure; the tree-shaped data structure is constructed from keyword information and index data; the index data is an index corresponding to the data already on the chain in the target blockchain; the second retrieval module 202 is used to determine a set of target query range tree nodes according to the target retrieval range in the data retrieval task. Among them, the set of target query range tree nodes is a set of tree nodes containing the target keyword information within the target retrieval range in the tree-shaped data structure; the target retrieval range represents the retrieval range corresponding to the data retrieval task in the tree-shaped data structure; the encryption module 203 is used to perform a first encryption process on the set of data tree nodes to be queried to obtain the security index information corresponding to the data retrieval task; perform a second encryption process on the vector representation of each element in the set of target query range tree nodes to obtain a trapdoor corresponding to each element in the set of target query range tree nodes; the access control module 204 is used to determine the query permission of the data retrieval task on the target blockchain according to the security index information and the trapdoor.
[0143] The zero-trust security data processing system provided by the present invention organizes keyword information and index data by constructing a tree-shaped data structure, determines the sets of tree nodes to be queried and the target query range according to the data retrieval task, and then generates security index information and trapdoors by encrypting these sets of tree nodes, thereby realizing fine-grained access control for data retrieval tasks, improving the security and privacy of data retrieval on the blockchain, and ensuring that only users with corresponding query permissions can access specific data.
[0144] The system provided in the embodiments of the present invention is used to execute the above method embodiments. For the specific process and detailed content, please refer to the above embodiments and will not be repeated here.
[0145] Figure 3 It is a schematic structural diagram of the electronic device provided by the present invention. As Figure 3As shown in the figure, the electronic device may include: a processor (Processor) 301, a communications interface (Communications Interface) 302, a memory (Memory) 303, and a communication bus 304. Among them, the processor 301, the communications interface 302, and the memory 303 complete communication with each other through the communication bus 304. The processor 301 may call the logical instructions in the memory 303 to execute a zero-trust security data processing method, which includes: determining a set of data tree nodes to be queried according to the target keyword information in the data retrieval task, where the set of data tree nodes to be queried is a set of all tree nodes containing the target keyword information in a tree-shaped data structure; the tree-shaped data structure is constructed from keyword information and index data; the index data is an index corresponding to the data that has been uploaded to the blockchain in the target blockchain; determining a set of target query range tree nodes according to the target retrieval range in the data retrieval task, where the set of target query range tree nodes is a set of tree nodes containing the target keyword information within the target retrieval range in the tree-shaped data structure; the target retrieval range represents the retrieval range corresponding to the data retrieval task in the tree-shaped data structure; performing a first encryption process on the set of data tree nodes to be queried to obtain security index information corresponding to the data retrieval task; performing a second encryption process on the vector representation of each element in the set of target query range tree nodes to obtain a trapdoor corresponding to each element in the set of target query range tree nodes; determining the query permission of the data retrieval task on the target blockchain according to the security index information and the trapdoor.
[0146] In addition, when the logical instructions in the above-mentioned memory 303 can be implemented in the form of software functional units and sold or used as an independent product, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk, or an optical disc that can store program codes.
[0147] On the other hand, the present invention also provides a computer program product. The computer program product includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the zero-trust security data processing method provided by each of the above methods. The method includes: determining a set of data tree nodes to be queried according to the target keyword information in the data retrieval task, where the set of data tree nodes to be queried is a set of all tree nodes in the tree-shaped data structure that contain the target keyword information; the tree-shaped data structure is constructed from keyword information and index data; the index data is an index corresponding to the data already on the chain in the target blockchain; determining a set of target query range tree nodes according to the target retrieval range in the data retrieval task, where the set of target query range tree nodes is a set of tree nodes in the tree-shaped data structure that contain the target keyword information within the target retrieval range; the target retrieval range represents the retrieval range corresponding to the data retrieval task in the tree-shaped data structure; performing a first encryption process on the set of data tree nodes to be queried to obtain security index information corresponding to the data retrieval task; performing a second encryption process on the vector representation of each element in the set of target query range tree nodes to obtain a trapdoor corresponding to each element in the set of target query range tree nodes; determining the query permission of the data retrieval task on the target blockchain according to the security index information and the trapdoor.
[0148] In another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it is configured to execute the zero-trust security data processing method provided in the above embodiments. The method includes: determining a set of data retrieval task target keyword information-based query data tree nodes, where the set of query data tree nodes is a set of all tree nodes in a tree-shaped data structure that contain the target keyword information; the tree-shaped data structure is constructed from keyword information and index data; the index data is an index corresponding to the data already on the chain in the target blockchain; determining a set of target query range tree nodes based on the target retrieval range in the data retrieval task, where the set of target query range tree nodes is a set of tree nodes in the tree-shaped data structure that contain the target keyword information within the target retrieval range; the target retrieval range represents the retrieval range corresponding to the data retrieval task in the tree-shaped data structure; performing a first encryption process on the set of query data tree nodes to obtain security index information corresponding to the data retrieval task; performing a second encryption process on the vector representation of each element in the set of target query range tree nodes to obtain a trapdoor corresponding to each element in the set of target query range tree nodes; and determining the query permission of the data retrieval task on the target blockchain based on the security index information and the trapdoor.
[0149] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative effort.
[0150] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solution, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0151] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A zero-trust security data processing method, characterized in that, Including: Determine a set of data tree nodes to be queried according to the target keyword information in the data retrieval task. Among them, the set of data tree nodes to be queried is a set of all tree nodes containing the target keyword information in the tree-shaped data structure; the tree-shaped data structure is constructed from keyword information and index data; the index data is the index corresponding to the data already on the chain in the target blockchain. Determine a set of target query range tree nodes according to the target retrieval range in the data retrieval task. Among them, the set of target query range tree nodes is a set of tree nodes containing the target keyword information within the target retrieval range in the tree-shaped data structure; the target retrieval range represents the retrieval range corresponding to the data retrieval task in the tree-shaped data structure. Perform a first encryption process on the set of data tree nodes to be queried to obtain the security index information corresponding to the data retrieval task; perform a second encryption process on the vector representation of each element in the set of target query range tree nodes to obtain the trapdoor corresponding to each element in the set of target query range tree nodes. Determine the query permission of the data retrieval task on the target blockchain according to the security index information and the trapdoor. The performing a first encryption process on the set of data tree nodes to be queried to obtain the security index information corresponding to the data retrieval task includes: Generate a corresponding key based on a preset security parameter. Construct a polynomial of data to be queried according to the difference between each element in the set of data tree nodes to be queried and the target data vector, where the target data vector is the encrypted representation corresponding to the data to be retrieved in the target blockchain for the data retrieval task. Generate a corresponding coefficient vector set according to each polynomial coefficient in the polynomial of data to be queried. Encrypt the coefficient vector set based on the private key in the key to obtain the security index information corresponding to the data retrieval task. The performing a second encryption process on the vector representation of each element in the set of target query range tree nodes to obtain the trapdoor corresponding to each element in the set of target query range tree nodes includes: Perform trapdoor calculation according to the vector representation of each element in the set of target query range tree nodes and the key to obtain the trapdoor corresponding to each element in the set of target query range tree nodes.
2. The zero-trust security data processing method according to claim 1, wherein The tree-shaped data structure is constructed through the following steps: Construct corresponding key-value pairs according to the keyword information and the index data. Use the key-value pairs as tree nodes, and construct the corresponding tree-shaped data structure of the B+ tree structure or R tree structure according to the parent node relationship between each tree node.
3. The zero-trust security data processing method according to claim 1, characterized in that The determining the query permission of the data retrieval task on the target blockchain according to the security index information and the trapdoor includes: Obtain the inner product result between the security index information and the trapdoor. If the inner product result belongs to the elements in the set of target query range tree nodes, determine that the data retrieval task has query permission on the target blockchain. If the inner product result does not belong to the elements in the target query range tree node set, it is determined that the data retrieval task does not have query permission on the target blockchain.
4. The zero-trust security data processing method according to claim 3, wherein After determining the query permission of the data retrieval task on the target blockchain according to the security index information and the trapdoor, the method further includes: After determining that the data retrieval task has query permission on the target blockchain, based on the oblivious transfer process, the data to be queried corresponding to the data retrieval task on the target blockchain is sent to the target end, where the target end is the user terminal that generates the data retrieval task.
5. The zero-trust security data processing method according to claim 1, characterized in that The target blockchain is a blockchain with a single main chain and multiple side chains constructed based on a hashgraph, and the consensus algorithm in the target blockchain is the Byzantine fault tolerance consensus algorithm, where the main chain and side chains of the target blockchain are used for tasks of storing different types of data.
6. The zero-trust security data processing method according to claim 5, wherein The method further includes: Performing data encryption processing on the data to be uploaded to the chain through a lattice-based encryption algorithm to obtain the encrypted data to be uploaded to the chain and the digital signature corresponding to the encrypted data to be uploaded to the chain; After determining that the encrypted data to be uploaded to the chain and the digital signature pass the consensus verification, adding the encrypted data to be uploaded to the chain and the digital signature to the target blockchain, and constructing a tree node corresponding to the encrypted data to be uploaded to the chain in the tree data structure according to the preset field information in the encrypted data to be uploaded to the chain.
7. A zero-trust security data processing system, characterized in that Includes: A first retrieval module, configured to determine a set of tree nodes of data to be queried according to the target keyword information in the data retrieval task, where the set of tree nodes of data to be queried is a set of all tree nodes in the tree data structure that contain the target keyword information; the tree data structure is constructed from keyword information and index data; the index data is the index corresponding to the data already uploaded to the chain in the target blockchain; A second retrieval module, configured to determine a set of target query range tree nodes according to the target retrieval range in the data retrieval task, where the set of target query range tree nodes is a set of tree nodes in the tree data structure that contain the target keyword information within the target retrieval range; the target retrieval range represents the retrieval range corresponding to the data retrieval task in the tree data structure; An encryption module, configured to perform a first encryption process on the set of tree nodes of data to be queried to obtain the security index information corresponding to the data retrieval task; perform a second encryption process on the vector representation of each element in the set of target query range tree nodes to obtain a trapdoor corresponding to each element in the set of target query range tree nodes; An access control module, configured to determine the query permission of the data retrieval task on the target blockchain according to the security index information and the trapdoor; The encryption module is specifically configured to: Generate a corresponding key based on a preset security parameter; Construct a polynomial of data to be queried according to the differences between the elements in the set of data tree nodes to be queried and the target data vector, where the target data vector is the encrypted representation of the data to be retrieved in the target blockchain for the data retrieval task; Generate a corresponding set of coefficient vectors according to the polynomial coefficients in the polynomial of data to be queried; Encrypt the set of coefficient vectors based on the private key in the key to obtain the security index information corresponding to the data retrieval task; The second encryption process for the vector representations of the elements in the set of target query range tree nodes to obtain the trapdoors corresponding to the elements in the set of target query range tree nodes includes: Perform trapdoor calculation according to the vector representations of the elements in the set of target query range tree nodes and the key to obtain the trapdoors corresponding to the elements in the set of target query range tree nodes.
8. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the zero-trust secure data processing method according to any one of claims 1 to 6.
9. A non-transitory computer-readable storage medium storing a computer program thereon, characterized in that, When the computer program is executed by the processor, it implements the zero-trust secure data processing method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Attribute set-based searchable encryption method with forward and backward privacy
CN117596085A