Zero-trust and block chain-based multi-level data sharing anti-fraud method and system
By introducing zero trust and blockchain technology into multi-level data sharing technology, the access control tree and index tree structure are built, and data is encrypted and shared, and security, efficiency and compliance issues in the existing technology are solved, and efficient and secure data sharing and access control are achieved.
Patent Information
- Application Number
- CN202510075054.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-17
- Publication Date
- 2025-05-02
- Estimated Expiration
- 2045-01-17
AI Technical Summary
The existing multi-level data sharing technology has security, efficiency, flexibility and compliance issues, and it is difficult to effectively prevent data fraud and meet differentiated security needs in different scenarios.
Using a multi-level data sharing method based on zero trust and blockchain, the access control tree and index tree structure are constructed, and the superior and subordinate data are encrypted and uploaded to the blockchain, realizing the index-based cross-verification method to share subordinate data.
It improves the security and processing efficiency of data sharing, has the advantages of high flexibility and high compliance, effectively prevents data abuse, and ensures the security, integrity and traceability of data during the sharing process.
Smart Images

Figure CN119921940A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer network information security technology, and in particular to a multi-level data sharing anti-fraud method and system based on zero trust and blockchain. Background Art
[0002] With the rapid development of the digital economy, multi-level data sharing has become a key strategy for various industries to improve operational efficiency and innovate business models. This sharing involves data interaction at different levels, allowing information to be smoothly transmitted between different levels within the organization, thereby optimizing the decision-making process and business processes. At present, the mainstream multi-level data sharing technologies mainly include the following aspects: First, the traditional centralized data sharing model, specifically, the data is stored in a centralized data center, which is responsible for data collection and management. Data exchange is usually achieved through API interfaces or direct database access rights. In order to ensure data security, this model relies on traditional authentication mechanisms and access control measures; second, privacy computing technologies such as federated learning, which allow data to be shared without leaving the local area, and realize the sharing of data value through model training. These technologies use cryptographic methods such as homomorphic encryption and secure multi-party computing to protect data privacy and security, and are particularly suitable for machine learning scenarios that need to protect data privacy; third, the data sharing solution of basic blockchain technology, the core of which is to use the tamper-proof characteristics of blockchain to record logs of all data operations, and smart contracts are used to manage who can access the data and under what conditions, thereby ensuring the transparency and traceability of the data sharing process.
[0003] The existing technology has the following problems: First, security issues. Due to the risk of single point failure in the centralized architecture, once it is breached, all data may be exposed. At the same time, the traditional access control mechanism is incapable of dealing with complex unauthorized access and internal cheating risks. In addition, the authenticity of the data is difficult to guarantee, and it is easy to be tampered with or forged, thus causing fraud risks. Secondly, the efficiency problem. The existing blockchain solutions generally face performance bottlenecks, resulting in slow transaction processing speeds. Privacy computing technology is difficult to apply in scenarios that require high real-time performance due to its large computing overhead. In addition, the cross-organizational identity authentication and authority management processes are complex, which also seriously affects the efficiency of inter-organizational collaboration. In addition, there are also flexibility and compliance issues. Most of the existing data sharing solutions use a preset trust model, which limits the ability to dynamically adjust the trust relationship. At the same time, due to the lack of uniformity in data formats and interface standards, the interoperability between systems is poor, making it difficult to achieve seamless docking between different systems. In addition, these solutions often fail to meet differentiated security requirements in different scenarios and lack the flexibility to adapt to changing business environments. In terms of data ownership and usage control, the existing mechanisms are still imperfect, making it difficult to achieve full auditability of data usage, which increases compliance risks. At the same time, there is a lack of effective data abuse prevention and accountability mechanisms, which may lead to legal and ethical risks in the process of data sharing and affect the security and reliability of data sharing. Summary of the invention
[0004] In view of this, the present invention provides a multi-level data sharing anti-fraud method and system based on zero trust and blockchain, which encrypts the superior data and subordinate data with a subordinate relationship and uploads them to the blockchain respectively, and shares the subordinate data through an index-based cross-validation method, thereby effectively improving the security and processing efficiency of data sharing. It has the advantages of high flexibility and high compliance, and can effectively prevent data abuse.
[0005] The technical solution adopted by the embodiment of the present invention to solve the technical problem is:
[0006] A multi-level data sharing fraud prevention method based on zero trust and blockchain, including:
[0007] Step S1, initializing the system, the participants in the system include the data owner, the data sender, the data receiver, the certificate authority CA and the attribute authority;
[0008] Step S2, constructing an access control tree and performing attribute encryption on the upper-level data D to be shared to obtain a ciphertext C, wherein the access control tree is composed of an organization classification subtree and a business-related subtree;
[0009] Step S3, upload the ciphertext C to the blockchain and obtain the transaction code Tx1 for sharing the upper-level data D; establish an index tree structure, encrypt the lower-level data Di of the upper-level data D based on the index code R to obtain encrypted data C_Di, upload the encrypted data C_Di to the blockchain and obtain the transaction code Tx2_i for sharing the lower-level data Di, so as to realize the index-based multi-level data sharing mechanism;
[0010] Step S4, after the data recipient requests to share the subordinate data Di, it obtains the transaction code Tx1 corresponding to the upper-level data D to which the subordinate data Di belongs provided by the data sender, obtains the index code R from the blockchain using the transaction code Tx1, obtains the encrypted data C_Di from the blockchain using the index code R, decrypts the encrypted data C_Di to obtain the subordinate data Di, and realizes data reception and decryption.
[0011] Preferably, the data sender includes an organization or an individual, the data owner includes an organization or an individual, the data receiver includes one or more organizations or individuals, the certificate authority CA includes one organization, and the attribute authority includes multiple organizations;
[0012] The step S1 comprises:
[0013] Step S11, defining the participants in the system;
[0014] Step S12, calculating the public key and private key of each participant in the system: selecting a random number as the private key of the participant, and using the elliptic curve encryption algorithm and the random number to calculate the public key of the participant;
[0015] Step S13, defining the business classification and access control attributes of the data, establishing an organization attribute set and a business attribute set, and defining attribute inheritance relationships and constraint rules; wherein the attribute inheritance relationships and constraint rules are mappings and rules between each of the organization attribute sets and each of the business attribute sets;
[0016] Step S14, the system is initialized, and the certificate authority CA uses a multi-authorization attribute encryption key generation algorithm to generate a system master key MSK, a public parameter PP and a key SK of the authorized institution.
[0017] Preferably, the step S2 comprises:
[0018] Step S21, constructing an access control tree based on the organization attribute set and the business attribute set, defining an organization classification subtree and a business-related subtree, and setting a threshold value; the organization classification subtree is a tree structure representing an organizational structure, and the nodes in the organization classification subtree represent departments or teams under the organization; the business-related subtree is a tree structure of business operations or processes, and the nodes in the business-related subtree are business roles or responsibilities; the threshold value is the number of conditions for granting access rights;
[0019] Step S22, converting the sequence of the upper-level data D into hexadecimal data, and calculating the ciphertext C using the public parameter PP, the access control tree and the multi-authority attribute encryption algorithm;
[0020] Step S23, the data sender performs a hash function calculation based on the hexadecimal data to obtain a first digital summary; and uses the private key of the data sender and a digital signature algorithm to generate a signature S1 of the first digital summary;
[0021] Step S24, the data sender sends the ciphertext C and the signature S1 to the data owner;
[0022] Step S25, the data owner uses the key SK to decrypt the ciphertext C to obtain the upper-level data D, performs a hash function calculation based on the hexadecimal data of the upper-level data D to obtain a second digital summary; and uses the private key of the data owner and a digital signature algorithm to generate a signature S2 of the second digital summary;
[0023] Step S26: the data owner sends the signature S2 to the data sender.
[0024] Preferably, the step S3 comprises:
[0025] Step S31, the data sender generates an index code for the subordinate data Di to be sent, and serializes the subordinate data Di, wherein D={Di}, the subordinate data Di and the superior data D are in a subordinate relationship, i∈[1,+∞);
[0026] Step S32, the data sender initializes the index tree structure locally, generates a root node random number root and the index code R of the upper-level data D, and establishes an index tree hierarchy according to the business process rules, wherein the business process rules are steps for departments to execute business types, the first layer of the index tree is business type, the second layer is department, and the third layer is time;
[0027] Step S33, the data sender uses the public parameter PP, the root node random number root, the access control tree and a multi-authority attribute encryption algorithm to calculate the ciphertext Cr of the root node random number root;
[0028] Step S34, the data sender uploads the ciphertext C, the signature S1, the signature S2, the ciphertext Cr, and the index code R to the blockchain, and obtains the transaction code Tx1;
[0029] Step S35, the data sender encodes all nodes of the index tree according to their positions to obtain node position codes, wherein the node position codes of the leaf nodes of the index tree are used as the position codes of the subordinate data Di;
[0030] Step S36, the data sender generates an initial key KR using the node position code, the root node random number root and a key derivation algorithm;
[0031] Step S37, the data sender uses the initial key KR and the symmetric encryption algorithm to encrypt the position code of each of the subordinate data Di to obtain an encrypted code C_i, i∈[1,+∞);
[0032] Step S38, the data sender uses the index code R, the encryption code C_i, and the initial key KR to generate a shared key K_i, and uses the shared key K_i and a symmetric encryption algorithm to encrypt the serialized subordinate data Di to obtain encrypted data C_Di;
[0033] Step S39, the data sender uses a hash function to calculate the serialized subordinate data Di to obtain a third digital summary Dig_i; and uses the private key of the data sender and a digital signature algorithm to generate a signature S3_i of each of the third digital summaries Dig_i;
[0034] Step S310, the data sender uploads the encrypted data C_Di, the signature S3_i, the encryption code C_i, and the index code R to the blockchain, and obtains the transaction code Tx2_i.
[0035] Preferably, the step S4 comprises:
[0036] Step S41, the data recipient sends a request to share the subordinate data Di and an organization code to the system;
[0037] Step S42, the attribute authorization agency uses multi-authority attribute encryption and the agency code to generate a key SK1 and sends it to the data recipient using a secure channel;
[0038] Step S43, the data sender searches out the upper-level data D to which the lower-level data Di belongs, and sends the transaction code Tx1 corresponding to the upper-level data D to the data receiver;
[0039] Step S44, the data receiver queries the transaction code Tx1 and obtains the ciphertext C, the signature S1, the signature S2, the ciphertext Cr, and the index code R from the blockchain, uses the key SK1 in S4.2 to decrypt the ciphertext C and the ciphertext Cr, and uses the public key and signature verification algorithm of the data sender to verify the signature S1, and uses the public key and signature verification algorithm of the data owner to verify the signature S2;
[0040] Step S45, the data receiving party establishes the same index tree as in step S32 and uses the node position code of the leaf node as the position code of the subordinate data Di;
[0041] Step S46, the data receiving party uses the position code of the subordinate data Di, the root and the key derivation algorithm to derive the initial key KR;
[0042] Step S47, the data recipient searches the blockchain for the data corresponding to the index code R to obtain the encrypted data C_Di, the corresponding signature S3_i, and the encrypted code C_i;
[0043] Step S48, the data recipient uses the initial key KR, the encryption code C_i, and the symmetric encryption and decryption algorithm to calculate the shared key K_i;
[0044] Step S49, the data receiving party uses the shared key K_i, the encrypted data C_Di and the symmetric encryption and decryption algorithm to calculate Di;
[0045] Step S410: The data receiver verifies the signature S3_i using the public key of the data sender and a signature verification algorithm.
[0046] Preferably, during the execution of step S42, when there is an organization classification subtree corresponding to the organization code, the attribute authorization agency generates the key SK1; if there is no organization classification subtree corresponding to the organization code, the attribute authorization agency generates null and sends it to the data recipient using a secure channel, and terminates the execution of step S4.
[0047] A multi-level data sharing anti-fraud system based on zero trust and blockchain, used to execute the method described in any one of claims 1 to 6, wherein the participants in the system include data owners, data senders, data receivers, certificate authorities CA and attribute authorization agencies.
[0048] Preferably, the data sender includes an organization or an individual, the data owner includes an organization or an individual, the data recipient includes one or more organizations or individuals, the certificate authority CA includes one organization, and the attribute authority includes multiple organizations.
[0049] It can be seen from the above technical solution that the embodiment of the present invention provides a multi-level data sharing anti-fraud method based on zero trust and blockchain. First, the system is initialized. The participants in the system include the data owner, the data sender, the data receiver, the certificate authority CA and the attribute authorization agency; an access control tree is constructed and the attribute of the upper-level data D to be shared is encrypted to obtain the ciphertext C, where the access control tree is composed of an organization classification subtree and a business-related subtree; the ciphertext C is uploaded to the blockchain and the transaction code Tx1 corresponding to the upper-level data D is obtained; an index tree structure is established, and the lower-level data Di of the upper-level data D is encrypted based on the index code R to obtain the encrypted data C_Di, and the encrypted data C_Di is uploaded to the blockchain and the transaction code Tx2_i for sharing the lower-level data Di is obtained to realize the index-based multi-level data sharing mechanism; after the data receiver requests to share the lower-level data Di, the transaction code Tx1 corresponding to the upper-level data D to which the lower-level data Di belongs provided by the data sender is obtained, and the index code R is obtained from the blockchain using the transaction code Tx1, and the encrypted data C_Di is obtained from the blockchain using the index code R, and the encrypted data C_Di is decrypted to obtain Di, thereby realizing data reception and decryption. The present invention encrypts the superior data and subordinate data with a subordinate relationship and uploads them to the blockchain respectively, and shares the subordinate data through an index-based cross-validation method, which effectively improves the security and processing efficiency of data sharing. It has the advantages of high flexibility and high compliance, effectively prevents data abuse, and can ensure the security, integrity and traceability of data during the sharing process, thereby realizing efficient data sharing and access control. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] Figure 1 Flowchart of a multi-level data sharing fraud prevention method based on zero trust and blockchain. DETAILED DESCRIPTION
[0051] The technical scheme and technical effects of the present invention are further elaborated in detail below in conjunction with the accompanying drawings of the present invention.
[0052] The present invention provides a multi-level data sharing anti-fraud system based on zero trust and blockchain, the architecture is as follows Figure 1As shown, the participants in the system include data owners, data senders, data receivers, certificate authorities CA and attribute authorization agencies, and data is shared through blockchain. Among them, the data sender includes an organization or individual, the data owner includes an organization or individual, the data receiver includes one or more organizations or individuals, the certificate authority CA includes an organization, and the attribute authorization agency includes multiple organizations (multiple means at least 2).
[0053] The system uses blockchain technology for data storage, which ensures that the data cannot be tampered with and can be traced. Based on the zero-trust principle, the system builds a "identity + data" dual verification framework: on the one hand, a strict identity authentication and authorization process is implemented for each access request, and attribute encryption and anonymization are performed; on the other hand, signature verification is implemented for various types of data to enhance data integrity and credibility and resist fraud risks. After encryption, the data is shared through the blockchain network to ensure the security and efficiency of data transmission.
[0054] This system supports multi-level data sharing and can meet the data interaction needs between different levels and different roles. Specifically, the system builds the relationship between multi-level data and uses different encryption algorithms for encryption in different levels. For data at different levels, a combination of symmetric encryption algorithms and asymmetric encryption algorithms can be used to balance security and performance. In addition, the system uses indexes to calculate encryption keys, uses index trees to generate indexes, and then calculates encryption keys based on indexes, thereby reducing the complexity of key management while ensuring data security. In this way, the number of key exchanges can be reduced and the efficiency of data sharing can be improved.
[0055] The specific implementation process of multi-level data sharing includes:
[0056] Step S1, initializing the system, the participants in the system include the data owner, data sender, data receiver, certificate authority CA and attribute authority;
[0057] Step S2, constructing an access control tree and encrypting the attributes of the upper-level data D to be shared to obtain a ciphertext C, wherein the access control tree consists of an organization classification subtree and a business-related subtree;
[0058] Step S3, upload the ciphertext C to the blockchain and obtain the transaction code Tx1 for sharing the upper-level data D; establish an index tree structure, encrypt the lower-level data Di of the upper-level data D based on the index code R to obtain the encrypted data C_Di, upload the encrypted data C_Di to the blockchain and obtain the transaction code Tx2_i for sharing the lower-level data Di, so as to realize the index-based multi-level data sharing mechanism;
[0059] Step S4: After the data recipient requests to share the subordinate data Di, it obtains the transaction code Tx1 corresponding to the upper-level data D to which the subordinate data Di belongs provided by the data sender, uses the transaction code Tx1 to obtain the index code R from the blockchain, uses the index code R to obtain the encrypted data C_Di from the blockchain, decrypts the encrypted data C_Di to obtain the subordinate data Di, and realizes data reception and decryption.
[0060] As an optional implementation, the specific implementation of step S1 includes:
[0061] Step S11, defining the participants in the system;
[0062] Step S12, calculating the public key and private key of each participant in the system: selecting a random number as the private key of the participant, and using the elliptic curve encryption algorithm and the random number to calculate the public key of the participant;
[0063] Step S13, defining the business classification and access control attributes of the data, establishing the organization attribute set and the business attribute set, and defining the attribute inheritance relationship and constraint rules; wherein the attribute inheritance relationship and constraint rules are the mapping and rules between each organization attribute set and each business attribute set;
[0064] Step S14, the system is initialized, and the certificate authority CA uses a multi-authorization attribute encryption key generation algorithm to generate a system master key MSK, a public parameter PP and a key SK of the authorized institution.
[0065] As an optional implementation, the specific implementation of step S2 includes:
[0066] Step S21, construct an access control tree based on the organization attribute set and the business attribute set, define the organization classification subtree and the business-related subtree, and set a threshold value; the organization classification subtree is a tree structure representing the organizational structure, and the nodes in the organization classification subtree represent the departments or teams under the organization (the data owner, data sender, and data receiver are all nodes in the organization classification subtree); the business-related subtree is a tree structure of business operations or processes, and the nodes in the business-related subtree are business roles or responsibilities (business roles refer to the business involved in the department, and responsibilities refer to the members who manage the business); the threshold value is the number of conditions for granting access rights, and the main forms include or, and, a / b (a, b are numbers, a represents the number of conditions that need to be met, and b is the total number of conditions);
[0067] Step S22, converting the sequence of the upper-level data D into hexadecimal data by hexadecimal data operation, and calculating the ciphertext C using the public parameter PP, access control tree and multi-authority attribute encryption algorithm of the above S14;
[0068] Step S23, the data sender performs a hash function calculation based on the hexadecimal data to obtain a first digital summary; and uses the private key of the data sender and a digital signature algorithm to generate a signature S1 of the first digital summary;
[0069] Step S24, the data sender sends the ciphertext C and signature S1 to the data owner;
[0070] Step S25, the data owner uses the key SK of step S14 to decrypt the ciphertext C to obtain the upper-level data D, and performs a hash function calculation based on the hexadecimal data of the upper-level data D to obtain a second digital summary; and uses the private key of the data owner and the digital signature algorithm to generate a signature S2 of the second digital summary;
[0071] Step S26: The data owner sends the signature S2 to the data sender.
[0072] As an optional implementation, the specific implementation of step S3 includes:
[0073] Step S31, the data sender generates an index code for the subordinate data Di to be sent, and serializes the subordinate data Di, where D = {Di}, the subordinate data Di and the superior data D are in a subordinate relationship, i∈[1,+∞);
[0074] Step S32, the data sender initializes the index tree structure locally, generates a root node random number root and an index code R of the parent data D, and establishes an index tree hierarchy according to the business process rules, wherein the business process rules are steps for departments to perform business types, the first level of the index tree is business type, the second level is department, and the third level is time;
[0075] Step S33, the data sender uses the public parameter PP of S14, the root node random number root of S32, the access control tree and the multi-authority attribute encryption algorithm to calculate the ciphertext Cr of the root node random number root;
[0076] Step S34, the data sender uploads the ciphertext C of S22, the signature S1 of S23, the signature S2 of S25, the ciphertext Cr of S33, and the index code R of S32 to the blockchain, and obtains the transaction code Tx1;
[0077] Step S35, the data sender encodes all nodes of the index tree of S32 according to their positions to obtain node position codes, wherein the node position codes of the leaf nodes of the index tree are used as the position codes of the subordinate data Di;
[0078] Step S36, the data sender generates an initial key KR using the position code of each node, the root node random number root of S32 and the key derivation algorithm;
[0079] Step S37, the data sender uses the initial key KR of S36 and the symmetric encryption algorithm to encrypt the position code of each subordinate data Di to obtain the encrypted code C_i, i∈[1,+∞);
[0080] Step S38, the data sender uses the index code R of S32, the encryption code C_i of S37, and the initial key KR of S36 to generate a shared key K_i, and uses the shared key K_i and the symmetric encryption algorithm to encrypt the serialized subordinate data Di of S31 to obtain the encrypted data C_Di;
[0081] Step S39, the data sender uses a hash function to calculate the serialized subordinate data Di to obtain a third digital summary Dig_i; the data sender's private key and digital signature algorithm are used to generate a signature S3_i of each third digital summary Dig_i;
[0082] In step S310, the data sender uploads the encrypted data C_Di of S38, the signature S3_i of S39, the encryption code C_i of S37, and the index code R of S32 to the blockchain, and obtains the transaction code Tx2_i.
[0083] As an optional implementation, the specific implementation of step S4 includes:
[0084] Step S41, the data receiver sends a request for sharing the subordinate data Di and an organization code to the system, where the organization code is used to indicate the organization classification subtree in the access control tree;
[0085] Step S42, the attribute authorization agency uses multi-authority attribute encryption and the organization code to generate the key SK1 and uses a secure channel to send it to the data recipient; during the execution of step S42, when there is an organization classification subtree corresponding to the organization code, the attribute authorization agency generates the key SK1; if there is no organization classification subtree corresponding to the organization code, the attribute authorization agency generates null and uses a secure channel to send it to the data recipient, and terminates the execution of step S4;
[0086] Step S43, the data sender searches out the upper-level data D to which the lower-level data Di belongs, and sends the transaction code Tx1 corresponding to the upper-level data D in S34 to the data receiver;
[0087] Step S44, the data receiver queries the transaction code Tx1 and obtains the ciphertext C, signature S1, signature S2, ciphertext Cr, and index code R of S34 from the blockchain, uses the S4.2 key SK1 to decrypt the ciphertext C and ciphertext Cr, and uses the public key and signature verification algorithm of the data sender to verify the signature S1, and uses the public key and signature verification algorithm of the data owner to verify the signature S2;
[0088] Step S45, the data receiving party refers to the process of step S32 to establish the same index tree as in step S32 and uses the node position code of the leaf node as the position code of the subordinate data Di;
[0089] Step S46, the data receiver uses the position code of the subordinate data Di, root and the key derivation algorithm to derive the initial key KR;
[0090] Step S47, the data recipient searches the blockchain for the data corresponding to the index code R of S44, and obtains the encrypted data C_Di of S310, the corresponding signature S3_i, and the encrypted code C_i;
[0091] Step S48, the data receiver uses the initial key KR of S47, the encryption code C_i of S47, and the symmetric encryption and decryption algorithm to calculate the shared key K_i;
[0092] Step S49, the data receiver uses the shared key K_i of S48, the encrypted data C_Di of S47 and the symmetric encryption and decryption algorithm to calculate Di;
[0093] Step S410, the data receiver uses the public key and signature verification algorithm of the data sender to verify the signature S3_i of S47. When the signature S3_i is successfully verified, the subordinate data Di is regarded as data that has not been tampered with, and the data sharing process ends.
[0094] The multi-authority attribute encryption algorithm used in the present invention is an attribute-based encryption technology that combines multiple authorization agencies to achieve fine-grained control over data access. In this algorithm, data encryption is based on predefined attribute sets that are assigned and managed by different authorization agencies. Each attribute represents a specific access control policy or user attribute, such as the user's role, department, or security level. During the encryption process, the data is labeled as a combination of these attributes, and only when the user's attribute set matches the attribute label of the encrypted data can they decrypt and access the data. The multi-authority attribute encryption algorithm includes: a key generation algorithm, an encryption algorithm, and a decryption algorithm. Algorithm reference: Rousselakis Y, Waters B. Efficient statically-secure large-universe multi-authority attribute-based encryption [C] / / International Conference on Financial Cryptography and Data Security. Berlin, Heidelberg: Springer Berlin Heidelberg, 2015: 315-332.
[0095] In the present invention, multi-level data is defined as: Let D1 and D2 be two types of data, where D1 is a set of data instances The relationship between D1 and D2 can be described as a mapping f:D1→D2.
[0096] The solution of the present invention has the following technical effects:
[0097] First, efficient key management:
[0098] The index tree structure simplifies the key management process, reduces the number of key exchanges, and supports the incremental key update mechanism to improve the efficiency and security of key management.
[0099] Second, optimized storage efficiency:
[0100] A unified storage model is used to process similar data, reduce redundant storage, and support fast retrieval to improve the efficiency and response speed of the storage system.
[0101] Third, flexible access control:
[0102] Implement fine-grained permission management, allow dynamic adjustment of access control policies, and provide multi-level security protection to meet the security needs of different users and scenarios.
[0103] Fourth, scalable architecture design:
[0104] It supports multi-party data sharing, the architecture is easy to integrate and expand, and has strong adaptability.
[0105] Fifth, a data sharing mechanism based on zero trust is proposed to ensure the security, integrity and traceability of data during the sharing process.
[0106] Sixth, a multi-level data sharing mechanism based on index is proposed, which realizes efficient data sharing and access control by generating codes for data, building index tree hierarchy, generating initial keys and shared keys, etc. This mechanism can support fast retrieval and access of large-scale data while ensuring data security.
[0107] What is disclosed above is only a preferred embodiment of the present invention, which certainly cannot be used to limit the scope of rights of the present invention. A person skilled in the art can understand that all or part of the processes of the above embodiments and equivalent changes made according to the claims of the present invention still fall within the scope of the invention.
Claims
1. A multi-level data sharing anti-fraud method based on zero trust and blockchain, characterized in that: include: Step S1, initializing the system, the participants in the system include the data owner, the data sender, the data receiver, the certificate authority CA and the attribute authority; Step S2, constructing an access control tree and performing attribute encryption on the upper-level data D to be shared to obtain a ciphertext C, wherein the access control tree is composed of an organization classification subtree and a business-related subtree; Step S3, upload the ciphertext C to the blockchain and obtain the transaction code Tx1 for sharing the upper-level data D; establish an index tree structure, encrypt the lower-level data Di of the upper-level data D based on the index code R to obtain encrypted data C_Di, upload the encrypted data C_Di to the blockchain and obtain the transaction code Tx2_i for sharing the lower-level data Di, so as to realize the index-based multi-level data sharing mechanism; Step S4, after the data recipient requests to share the subordinate data Di, it obtains the transaction code Tx1 corresponding to the upper-level data D to which the subordinate data Di belongs provided by the data sender, obtains the index code R from the blockchain using the transaction code Tx1, obtains the encrypted data C_Di from the blockchain using the index code R, decrypts the encrypted data C_Di to obtain the subordinate data Di, and realizes data reception and decryption.
2. The multi-level data sharing anti-fraud method based on zero trust and blockchain as claimed in claim 1, characterized in that: The data sender includes an organization or an individual, the data owner includes an organization or an individual, the data receiver includes one or more organizations or individuals, the certificate authority CA includes one organization, and the attribute authority includes multiple organizations; The step S1 comprises: Step S11, defining the participants in the system; Step S12, calculating the public key and private key of each participant in the system: selecting a random number as the private key of the participant, and using the elliptic curve encryption algorithm and the random number to calculate the public key of the participant; Step S13, defining the business classification and access control attributes of the data, establishing an organization attribute set and a business attribute set, and defining attribute inheritance relationships and constraint rules; wherein the attribute inheritance relationships and constraint rules are mappings and rules between each of the organization attribute sets and each of the business attribute sets; Step S14, the system is initialized, and the certificate authority CA uses a multi-authorization attribute encryption key generation algorithm to generate a system master key MSK, a public parameter PP and a key SK of the authorized institution.
3. The multi-level data sharing anti-fraud method based on zero trust and blockchain as claimed in claim 2 is characterized in that: The step S2 comprises: Step S21, constructing an access control tree based on the organization attribute set and the business attribute set, defining an organization classification subtree and a business-related subtree, and setting a threshold value; the organization classification subtree is a tree structure representing an organizational structure, and the nodes in the organization classification subtree represent departments or teams under the organization; the business-related subtree is a tree structure of business operations or processes, and the nodes in the business-related subtree are business roles or responsibilities; the threshold value is the number of conditions for granting access rights; Step S22, converting the sequence of the upper-level data D into hexadecimal data, and calculating the ciphertext C using the public parameter PP, the access control tree and the multi-authority attribute encryption algorithm; Step S23, the data sender performs a hash function calculation based on the hexadecimal data to obtain a first digital summary; and uses the private key of the data sender and a digital signature algorithm to generate a signature S1 of the first digital summary; Step S24, the data sender sends the ciphertext C and the signature S1 to the data owner; Step S25, the data owner uses the key SK to decrypt the ciphertext C to obtain the upper-level data D, performs a hash function calculation based on the hexadecimal data of the upper-level data D to obtain a second digital summary; and uses the private key of the data owner and a digital signature algorithm to generate a signature S2 of the second digital summary; Step S26: the data owner sends the signature S2 to the data sender.
4. The multi-level data sharing anti-fraud method based on zero trust and blockchain as claimed in claim 3 is characterized in that: The step S3 comprises: Step S31, the data sender serializes the subordinate data Di to be sent, wherein D={Di}, the subordinate data Di and the superior data D are in a subordinate relationship, i∈[1,+∞); Step S32, the data sender initializes the index tree structure locally, generates a root node random number root and the index code R of the upper-level data D, and establishes an index tree hierarchy according to the business process rules, wherein the business process rules are steps for departments to execute business types, the first layer of the index tree is business type, the second layer is department, and the third layer is time; Step S33, the data sender uses the public parameter PP, the root node random number root, the access control tree and a multi-authority attribute encryption algorithm to calculate the ciphertext Cr of the root node random number root; Step S34, the data sender uploads the ciphertext C, the signature S1, the signature S2, the ciphertext Cr, and the index code R to the blockchain, and obtains the transaction code Tx1; Step S35, the data sender encodes all nodes of the index tree according to their positions to obtain node position codes, wherein the node position codes of the leaf nodes of the index tree are used as the position codes of the subordinate data Di; Step S36, the data sender generates an initial key KR using the node position code, the root node random number root and a key derivation algorithm; Step S37, the data sender uses the initial key KR and the symmetric encryption algorithm to encrypt the position code of each of the subordinate data Di to obtain an encrypted code C_i, i∈[1,+∞); Step S38, the data sender uses the index code R, the encryption code C_i, and the initial key KR to generate a shared key K_i, and uses the shared key K_i and a symmetric encryption algorithm to encrypt the serialized subordinate data Di to obtain encrypted data C_Di; Step S39, the data sender uses a hash function to calculate the serialized subordinate data Di to obtain a third digital summary Dig_i; and uses the private key of the data sender and a digital signature algorithm to generate a signature S3_i of each of the third digital summaries Dig_i; Step S310, the data sender uploads the encrypted data C_Di, the signature S3_i, the encryption code C_i, and the index code R to the blockchain, and obtains the transaction code Tx2_i.
5. The multi-level data sharing anti-fraud method based on zero trust and blockchain as claimed in claim 4 is characterized in that: The step S4 comprises: Step S41, the data recipient sends a request to share the subordinate data Di and an organization code to the system; Step S42, the attribute authorization agency uses multi-authority attribute encryption and the agency code to generate a key SK1 and sends it to the data recipient using a secure channel; Step S43, the data sender searches out the upper-level data D to which the lower-level data Di belongs, and sends the transaction code Tx1 corresponding to the upper-level data D to the data receiver; Step S44, the data receiver queries the transaction code Tx1 and obtains the ciphertext C, the signature S1, the signature S2, the ciphertext Cr, and the index code R from the blockchain, uses the key SK1 in S4.2 to decrypt the ciphertext C and the ciphertext Cr, and uses the public key and signature verification algorithm of the data sender to verify the signature S1, and uses the public key and signature verification algorithm of the data owner to verify the signature S2; Step S45, the data receiving party establishes the same index tree as in step S32 and uses the node position code of the leaf node as the position code of the subordinate data Di; Step S46, the data receiving party uses the position code of the subordinate data Di, the root and the key derivation algorithm to derive the initial key KR; Step S47, the data recipient searches the blockchain for the data corresponding to the index code R to obtain the encrypted data C_Di, the corresponding signature S3_i, and the encrypted code C_i; Step S48, the data recipient uses the initial key KR, the encryption code C_i, and the symmetric encryption and decryption algorithm to calculate the shared key K_i; Step S49, the data receiving party uses the shared key K_i, the encrypted data C_Di and the symmetric encryption and decryption algorithm to calculate Di; Step S410: The data receiver verifies the signature S3_i using the public key of the data sender and a signature verification algorithm.
6. The multi-level data sharing anti-fraud method based on zero trust and blockchain as claimed in claim 5, characterized in that: During the execution of step S42, when there is an institution classification subtree corresponding to the institution code, the attribute authorization agency generates the key SK1; if there is no institution classification subtree corresponding to the institution code, the attribute authorization agency generates null and sends it to the data recipient using a secure channel, and terminates the execution of step S4.
7. A multi-level data sharing anti-fraud system based on zero trust and blockchain, characterized in that: Used to execute the method described in any one of claims 1 to 6, the participants in the system include a data owner, a data sender, a data receiver, a certificate authority CA and an attribute authority.
8. The multi-level data sharing anti-fraud system based on zero trust and blockchain as claimed in claim 7, characterized in that: The data sender includes an organization or an individual, the data owner includes an organization or an individual, the data receiver includes one or more organizations or individuals, the certificate authority CA includes an organization, and the attribute authority includes multiple organizations.
Citation Information
Patent Citations
Intelligent medical data storage method based on multi-level blockchain system architecture
CN110727737A
Medical record sharing method and system based on zero trust principle and block chain technology
CN114567491A
Multistage controllable data sharing authorization method and device and block chain system
CN117056983A
Method of managing access in a collaborative data sharing platform
US20210081557A1