Data interaction security privacy protection method and system based on block chain

By adopting blockchain technology in the data management system, building the main chain-subchain architecture and cross-chain communication protocol, combined with smart contracts, the problem of difficulty in ensuring privacy and security in data interaction is solved, and high security and flexible data sharing and utilization are achieved.

CN119989406AActive Publication Date: 2025-05-13WUHAN CHAIN (WUHAN) TECHNOLOGY RESEARCH CO LTD +1

Patent Information

Application Number
CN202510061614.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-15
Publication Date
2025-05-13
Estimated Expiration
2045-01-15

AI Technical Summary

Technical Problem

Traditional data management systems are difficult to ensure data privacy and security during data interaction, especially in multi-party data collaboration scenarios, how to balance data privacy and data sharing and utilization has become a problem.

Method used

Using blockchain-based data interaction security and privacy protection method, we can build the main chain by deploying multiple blockchain consensus nodes on cloud servers, and deploying blockchain computing nodes in the dual-layer trusted execution environment hardware to build the sub-chain to form the main chain-sub-chain architecture, combining cross-chain communication protocols and cross-chain smart contracts to achieve security and privacy protection of data.

Benefits of technology

It effectively solves the problem that centralized systems are easily targeted by single-point attacks, improves data security and availability, realizes data isolation and flexibility, is suitable for multi-party data collaboration scenarios, and maximizes the value of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989406A_ABST
    Figure CN119989406A_ABST
Patent Text Reader

Abstract

The invention provides a data interaction security privacy protection method and system based on a block chain. The method comprises the following steps: deploying block chain consensus nodes in a cloud to construct a main chain, deploying computing nodes in double-layer trusted execution environment hardware, and constructing sub-chains according to service types. A main chain-subchain architecture is established through a cross-chain communication protocol, and a cross-chain smart contract is deployed. And receiving a user data interaction request, verifying the identity, and granting access or uploading authority. And generating a data fingerprint and an operation log, and organizing the data fingerprint and the operation log into a Merkle tree structure. A hierarchical storage architecture based on a DAG is adopted, and data and log Merkle trees are stored in a main chain-subchain architecture. In the whole process, data security, privacy protection and traceability are ensured, and an efficient and reliable block chain data management system is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of blockchain information protection, and specifically relates to a blockchain-based data interaction security and privacy protection method and system. Background Art

[0002] With the popularization of Internet technology and the deepening of informatization, data has become a key factor in driving economic growth and social development. In this context, all industries are actively promoting digital transformation, hoping to improve operational efficiency, optimize decision-making processes, and innovate business models through data collection, analysis, and utilization.

[0003] Traditional data management systems mostly adopt a centralized architecture. Although this architecture is more convenient in terms of management and control, it often becomes a bottleneck in the system when faced with large-scale, high-concurrency data interaction needs. Centralized systems are prone to become the source of single point failures. Once a problem occurs in the central node, the security and availability of the entire system will be seriously affected. Secondly, as the value of data becomes increasingly prominent, the demand for data security and privacy protection is increasing. However, traditional security measures such as simple encryption and access control mechanisms often seem powerless in the face of complex network attacks and internal threats. Especially in the scenario of multi-party data collaboration, how to achieve effective data sharing and utilization while protecting data privacy has become a difficult problem to balance. Summary of the invention

[0004] The present invention provides a data interaction security and privacy protection method and system based on blockchain to solve the problem that traditional data management systems are difficult to ensure data privacy security during data interaction.

[0005] In a first aspect, the present invention provides a data interaction security and privacy protection method based on blockchain, which is applied to a data interaction management system, wherein the data interaction management system includes a cloud server, a two-layer trusted execution environment hardware and a user-end server, wherein the user-end server and the two-layer trusted execution environment hardware are both connected to the cloud server through a secure communication channel created based on an end-to-end encryption mechanism, and the method includes the following steps: Deploy multiple blockchain consensus nodes in the cloud server, and build a blockchain main chain in the cloud server based on all the blockchain consensus nodes; Deploy multiple blockchain computing nodes for processing different business types in the two-layer trusted execution environment hardware, and build multiple blockchain sub-chains in the two-layer trusted execution environment hardware based on all the blockchain computing nodes and according to the business types; Based on the cross-chain communication protocol and through the secure communication channel, a communication connection is established between all the blockchain sub-chains and the blockchain main chain to form a main chain-sub-chain architecture, and a cross-chain smart contract is deployed in the main chain-sub-chain architecture; Receive a data interaction request from a target user through the user-side server, and verify the user authentication identity contained in the data interaction request, wherein the user authentication identity is authenticated and issued by the blockchain computing node; If the verification is successful, the target user is granted data access rights or data upload rights in the main chain-subchain architecture according to the request type of the data interaction request, so that the target user can use the data access rights to access the target data stored in the main chain-subchain architecture, or use the data upload rights to upload the target data in the main chain-subchain architecture; Generate a data fingerprint of the target data during the data interaction process, generate a data operation log of the target data in combination with the data fingerprint and the data interaction request, and organize the data operation log into a log Merkle tree structure; A hierarchical storage architecture based on a directed acyclic graph is used to store all the target data and the log Merkle tree structure in a hierarchical manner in the main chain-subchain architecture.

[0006] Optionally, before receiving the data interaction request sent by the target user through the user-side server, the method further includes the following steps: Deploy a neural network-based user information processing model in the dual-layer trusted execution environment hardware, wherein the user information processing model includes an information feature extraction module, an information integrity verification module, an information credibility verification module, a user type classification module, and a noise injection module; Obtaining, from the user client server, a user registration request sent by the user to be registered to the main chain-sub-chain architecture; Extracting user information from the user registration request, inputting the user information into the user information processing model for information verification, and outputting the user type of the user to be registered according to the user information that passes the information verification through the user information processing model; Randomly generate a user key of the user to be registered, and store the user key in the main chain-subchain architecture; Based on the user type, the user authentication identity of the user to be registered is generated through the cross-chain smart contract, and the user authentication identity is issued to the user to be registered using the blockchain computing node to complete the user registration of the user to be registered in the main chain-sub-chain architecture.

[0007] Optionally, the information feature extraction module is used to extract information field features and information anomaly association features from the user information, the last shared feature layer of the information feature extraction module is respectively connected to the information integrity verification module, the information credibility verification module and the user type classification module, the information integrity verification module is used to output the integrity probability of the user information according to the information field features, and the information credibility verification module is used to output the credibility score of the user information according to the information anomaly association features; The user information processing model also includes a decision unit and a gating unit. The output layer of the information integrity verification module is connected to the decision unit, and the output layer of the information credibility verification module is respectively connected to the decision unit and the user type classification module. The output layer of the decision unit is connected to the gating unit, and the output layer of the gating unit is connected to the user type classification module. The decision unit is used to output the verification result of the user information in combination with the integrity probability and the credibility score. The gating unit is used to determine whether to output a module activation signal to the user type classification module according to the verification result. After receiving the module activation signal, the user type classification module is used to identify and output the user type corresponding to the user information in combination with the credibility score and the information field feature. The output layer of the user type classification module is connected to the noise injection module. The noise injection module is used to inject noise into the output result of the user type classification module based on the Laplace mechanism and according to a preset privacy budget. The information integrity verification module and the information credibility verification module exchange information through a multi-head attention mechanism.

[0008] Optionally, storing the user key in the main chain-subchain architecture comprises the following steps: Using Shamir's secret sharing algorithm to split the user key into n key fragments; Encrypting each of the key fragments using a homomorphic encryption algorithm; Select m blockchain computing nodes as trusted computing nodes according to the node status of the blockchain computing nodes, 2≤m<n; Distribute and store the encrypted key fragments to each of the trusted computing nodes; A threshold signature-based key reconstruction protocol is created for all the trusted computing nodes, wherein the key reconstruction protocol constrains that at least t trusted computing nodes are required to collaborate in the user key reconstruction process, where t≤m.

[0009] Optionally, the generating the user authentication identity of the user to be registered based on the user type and through the cross-chain smart contract comprises the following steps: Execute the cross-chain smart contract based on the user type to generate a verifiable credential for the user to be registered; Based on the user information, the user attributes of the user to be registered are generated by using an attribute description language that supports multi-dimensional access policy definition, and the attribute encryption of the user attributes is completed by using a CP-ABE encryption algorithm; Combining the verifiable credential and the encrypted user attribute into the user identity of the user to be registered; Adding a zero-knowledge range proof-based authentication protocol for said user identity; The user key of the user to be registered is reconstructed from the main chain-subchain architecture, and the user identity is signed by the user key to obtain the user authentication identity of the user to be registered.

[0010] Optionally, the method further comprises the following steps: Counting the number of user authentication identities generated by the cross-chain smart contract; Whenever the generated quantity reaches a preset quantity threshold, the contract code of the cross-chain smart contract is parsed and semantically checked; The cross-chain smart contract is updated by combining the analysis and inspection results of the syntax analysis and the semantic inspection and by using preset adaptive update rules.

[0011] Optionally, granting the target user data access rights or data upload rights in the main chain-subchain architecture according to the request type of the data interaction request, so that the target user uses the data access rights to access the target data stored in the main chain-subchain architecture, or uses the data upload rights to upload the target data in the main chain-subchain architecture, includes the following steps: Determining whether the request type of the data interaction request is a data upload request or a data access request; If it is the data upload request, grant the target user the data upload permission in the main chain-subchain architecture, and obtain the target data of the target user and the data access policy preset by the target user for the target data; If the target data is encrypted by the target user through the user key, the target data and the data access policy are packaged and sent to the blockchain subchain, and the data upload process of the target data is completed through the blockchain computing node; If the target data is not encrypted, the target data and the data access policy are packaged and sent to the blockchain main chain, and the data upload process of the target data is completed through the blockchain consensus node; If it is the data access request, determining and granting the data access right of the target user based on the user authentication identity of the target user; In combination with the data access permission and the data access policy of the stored data in the main chain-subchain architecture, the data storage location of the target data accessible to the target user is fed back to the target user.

[0012] Optionally, the dual-layer trusted execution environment hardware includes a hardware security module and a trusted execution environment hardware.

[0013] In a second aspect, the present invention also provides a blockchain-based data interaction security and privacy protection system, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the computer program, the blockchain-based data interaction security and privacy protection method as described in the first aspect is implemented.

[0014] In a third aspect, the present invention also provides a computer-readable storage medium having instructions stored thereon, characterized in that when the instructions are executed by a processor, the processor is configured to execute the blockchain-based data interaction security and privacy protection method described in the first aspect.

[0015] The beneficial effects of the present invention are: The present invention adopts the blockchain architecture of main chain-subchain, which effectively solves the problem that centralized systems are prone to become single-point attack targets. By dispersing and storing data of different business types on subchains, the risk of the overall system being breached is greatly reduced, and the security of data is improved. The present invention uses a double-layer trusted execution environment hardware to deploy blockchain computing nodes, which provides an isolated security environment for sensitive data processing and effectively prevents data from being illegally accessed or tampered with during processing. This hardware-level security protection significantly improves the system's ability to resist advanced persistent threats and zero-day vulnerability attacks. The present invention realizes secure data interaction between different subchains through the deployment of cross-chain communication protocols and cross-chain smart contracts, which not only ensures the isolation of data, but also improves the flexibility and efficiency of data utilization. This mechanism is particularly suitable for scenarios of multi-party data collaboration, and can maximize the value of data while protecting data privacy. The present invention introduces a strict access control mechanism based on user authentication identity, combined with the refined management of data access rights and data upload rights, effectively preventing the risk of data being over-authorized for access. This not only enhances the system's defense capabilities against internal threats, but also provides technical guarantees for the compliant use of data. The present invention also innovatively introduces the concepts of data fingerprint and data operation log, and organizes them into a Merkle tree structure, which provides reliable technical support for the full life cycle tracking and auditing of data. Finally, the present invention adopts a hierarchical storage architecture based on a directed acyclic graph, which not only improves the efficiency of data storage, but also enhances the integrity and traceability of data. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 This is a schematic diagram of the system structure of a data interaction management system in one embodiment of the present application.

[0017] Figure 2 This is a flowchart of a blockchain-based data interaction security and privacy protection method in one of the implementation methods of the present application.

[0018] Figure 3 This is a schematic diagram of the model structure of a user information processing model in one implementation manner of the present application. DETAILED DESCRIPTION

[0019] The following will be combined with the drawings in the embodiments of the present application to clearly describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments in the present application belong to the scope of protection of this application.

[0020] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described here, and the objects distinguished by "first", "second", etc. are generally of one type, and the number of objects is not limited. For example, the first object can be one or more. In addition, "and / or" in the specification and claims represents at least one of the connected objects, and the character " / " generally indicates that the objects associated with each other are in an "or" relationship.

[0021] Reference Figure 1 The data interaction security and privacy protection method based on blockchain disclosed in the present invention is applied to the data interaction management system. The data interaction management system consists of three main components: a cloud server, a two-layer trusted execution environment hardware and a user-side server, which are interconnected through a secure communication channel based on an end-to-end encryption mechanism. As the hub of the system, the cloud server deploys multiple blockchain consensus nodes and builds a blockchain main chain, responsible for managing global information and coordinating various subsystems. The two-layer trusted execution environment hardware is the core security component of the system, including a hardware security module and a trusted execution environment hardware. The hardware security module provides basic hardware-level security protection, while the trusted execution environment hardware provides more advanced security functions; multiple blockchain computing nodes are deployed in this two-layer structure, organized into multiple blockchain subchains according to different business types, and each subchain specializes in processing specific types of business logic and data operations, greatly improving the parallel processing capability and security of the system. As the interface for users to interact with the system, the user-side server is responsible for receiving and preliminarily processing user requests. The entire system adopts a main chain-subchain hierarchical blockchain architecture. The main chain is deployed on a cloud server to be responsible for global consensus, and the subchain is deployed in a two-layer trusted execution environment hardware to handle specific business. This architecture not only ensures the overall consistency of the system, but also provides sufficient flexibility. In terms of storage, the system uses a hierarchical storage architecture based on a directed acyclic graph to store target data and operation logs (organized in a Merkle tree structure) in a hierarchical manner in the main chain-subchain architecture, which improves data access efficiency and system scalability.

[0022] Reference Figure 2 , Figure 2 The following is a flowchart of a data interaction security and privacy protection method based on blockchain in one embodiment. Figure 2 The steps in the flowchart are shown in sequence as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, Figure 2At least part of the steps in the above method may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least part of the sub-steps or stages of other steps. Figure 2 As shown, the data interaction security and privacy protection method based on blockchain disclosed in the present invention specifically includes the following steps: S101. Deploy multiple blockchain consensus nodes in the cloud server, and build a blockchain main chain in the cloud server based on all blockchain consensus nodes.

[0023] Among them, in this step, first select a suitable consensus algorithm, such as proof of work (PoW), proof of stake (PoS) or delegated proof of stake (DPoS). Taking PoS as an example, each node obtains a corresponding block weight according to the amount of cryptocurrency it holds and the holding time. Next, install the blockchain node software on the cloud server, such as Ethereum's Geth or Hyperledger's Fabric, and perform necessary configurations. The configuration includes setting network parameters, storage paths, key management, etc. Then, start these nodes and let them discover and connect with each other to form a P2P network. After the network is established, the nodes begin to generate, verify and synchronize blocks according to the consensus algorithm. For example, in PoS, the node with the highest weight has a greater probability of being selected as a block node, generating a new block and broadcasting it to other nodes for verification. After verification, the new block is added to the chain to achieve continuous growth of the blockchain. To ensure security, a multi-signature mechanism can be implemented, requiring each block to be confirmed by at least 2 / 3 of the nodes before it can be finally confirmed. In addition, it is also necessary to implement the deployment and execution environment of smart contracts, such as the Ethereum Virtual Machine (EVM). Such an architecture can provide a decentralized, tamper-proof and transparent data storage and interaction foundation, laying the foundation for subsequent sub-chain and cross-chain operations. The blockchain main chain built in this way can effectively manage the global state, handle cross-chain interactions, and provide security for the entire system.

[0024] S102. Deploy multiple blockchain computing nodes for processing different business types in the two-layer trusted execution environment hardware, and build multiple blockchain sub-chains in the two-layer trusted execution environment hardware based on all blockchain computing nodes and according to business types.

[0025] Among them, the two-layer trusted execution environment usually includes a hardware security module (HSM) and a trusted execution environment (TEE), which can provide an isolated execution space to protect sensitive data and computing processes from external interference. On this basis, the corresponding blockchain computing nodes are configured according to different business needs (such as financial transactions, medical data sharing, supply chain management, etc.). Each node needs to install specific blockchain software, such as Hyperledger Fabric for high-throughput transactions or Ethereum to support complex smart contracts. Next, create independent subchains for each business type. For example, the financial transaction subchain may adopt the PBFT consensus algorithm to achieve fast transaction confirmation, while the medical data sharing subchain may use zero-knowledge proof technology to protect patient privacy. The creation process of the subchain includes initializing the genesis block, configuring network parameters, deploying smart contracts, etc.

[0026] Each subchain has its own ledger structure and data model to adapt to specific business needs. In order to improve performance and privacy protection, sharding technology can be implemented to assign different types of transactions to different subchains for processing. In addition, a cross-chain communication interface needs to be implemented on each subchain to prepare for subsequent interactions with the main chain. The multi-chain structure constructed in this way can greatly improve the parallel processing capability and scalability of the system, while ensuring data isolation and security between different businesses. Each subchain can choose the most suitable consensus mechanism and data structure according to its own business characteristics, so as to maximize processing efficiency while ensuring security.

[0027] S103. Based on the cross-chain communication protocol and through a secure communication channel, establish communication connections between all blockchain sub-chains and the blockchain main chain to form a main chain-sub-chain architecture, and deploy cross-chain smart contracts in the main chain-sub-chain architecture.

[0028] Among them, first of all, it is necessary to design and implement a robust cross-chain communication protocol, such as a hash time lock contract (HTLC) or a relay chain solution. Taking HTLC as an example, it allows assets to be locked on different chains, and the atomicity of cross-chain transactions is ensured by hash locks and time locks. The establishment of a secure communication channel can adopt the TLS / SSL protocol, combined with asymmetric encryption and digital signature technology to ensure the confidentiality and integrity of cross-chain communication. On this basis, a connection bridge with the main chain is created for each subchain. This bridge is responsible for the encoding, decoding and routing of cross-chain messages. For example, when subchain A needs to interact with subchain B across chains, the message is first transmitted to the main chain, and then forwarded by the main chain to subchain B. In order to improve efficiency, a distributed message queue system, such as Apache Kafka, can be implemented to manage the asynchronous processing of cross-chain messages.

[0029] Next, deploy cross-chain smart contracts in the main chain-subchain architecture. These contracts need to be able to understand and process data formats and transaction types from different chains. For example, a cross-chain asset transfer contract may contain the following logic: verify the asset lock proof on the source chain, mint assets of equal value on the target chain, and record the status of the cross-chain transaction on the main chain. In order to handle potential cross-chain transaction failures, a rollback mechanism needs to be implemented to ensure the consistency of the system state. In addition, zero-knowledge proof technology, such as zk-SNARKs, can be introduced to enhance the privacy protection of cross-chain transactions. Through this complex cross-chain architecture, the system can achieve seamless interaction between different business domains while maintaining the independence and security of each sub-chain, greatly improving the functionality and flexibility of the entire blockchain network.

[0030] S104. Receive a data interaction request from the target user through the user-side server, and verify the user authentication identity included in the data interaction request.

[0031] Among them, the user-side server needs to implement a secure API interface that supports the HTTPS protocol and two-way authentication to prevent man-in-the-middle attacks and unauthorized access. When a user initiates a data interaction request, the request content usually includes the user ID, operation type, target data identifier, and user authentication identity token. This token is issued by the blockchain computing node when the user registers or logs in. It uses the JWT (JSON Web Token) format and contains the user's identity information, permission level, and expiration time. The verification process first parses the JWT token and checks whether its signature is valid (using an asymmetric encryption algorithm such as RSA or ECDSA). Then, verify whether the token is within the validity period and check whether the user information contained in it matches the user ID in the request. To prevent replay attacks, a nonce value can be added to the token and ensure that the nonce has not been used during verification.

[0032] Next, the user-side server needs to interact with the blockchain network to verify the user's current status and permissions. This can be achieved by calling the user management smart contract on the main chain, which maintains the latest status of all users. For example, check whether the user is disabled or whether their permissions have changed. To improve the efficiency of verification, a distributed cache system (such as a Redis cluster) can be implemented to cache commonly used user authentication information and set a reasonable expiration policy. In addition, behavioral analysis and risk assessment modules can be introduced to monitor user request patterns and identify potential abnormal behaviors. For example, if a user initiates a large number of requests in a short period of time, or the requested data is significantly inconsistent with their historical behavior, the system may require additional authentication steps, such as secondary factor authentication. Through this multi-level and dynamic authentication mechanism, the system can effectively prevent various attacks of identity forgery and unauthorized access, while providing a smooth access experience for legitimate users.

[0033] S105. If the verification is successful, the target user is granted data access rights or data upload rights in the main chain-subchain architecture according to the request type of the data interaction request, so that the target user can use the data access rights to access the target data stored in the main chain-subchain architecture, or use the data upload rights to upload the target data in the main chain-subchain architecture.

[0034] S106. Generate a data fingerprint of the target data during the data interaction process, generate a data operation log of the target data in combination with the data fingerprint and the data interaction request, and organize the data operation log into a log Merkle tree structure.

[0035] Among them, the generation of data fingerprints usually adopts cryptographic hash functions such as SHA-256 or Blake2. For large data sets, block hashing technology can be used to divide the data into blocks of fixed size (such as 4KB), calculate the hash values ​​separately, and then combine these hash values ​​again to calculate the final data fingerprint. This method not only reduces the computational complexity, but also supports partial updates of data. Data interaction requests usually contain information such as operation type (such as read, modify, delete), timestamp, user ID, etc. Combining this information with the data fingerprint, a complete data operation log entry can be constructed. For example, a log entry contains the following fields: {operation ID, user ID, operation type, timestamp, data fingerprint, data status before operation, data status after operation}. In order to ensure the immutability of the log, each log entry can be digitally signed by the user key.

[0036] There are multiple benefits to organizing these log entries into a Merkle tree structure. A Merkle tree is a binary tree where leaf nodes contain the hash value of the original data and non-leaf nodes contain the hash values ​​of their child nodes. The root node (Merkle root) of the tree represents a summary of the entire data set. The process of constructing a Merkle tree is as follows: First, all log entries are arranged in chronological order and the hash value of each entry is calculated as a leaf node. Then, the hash value of the parent node is calculated in pairs until the root node is obtained. This structure allows the integrity of a large amount of data to be verified efficiently, and only O(log n) computational complexity is required to prove whether a log entry is included in the tree. In addition, the Merkle tree also supports incremental updates. When a new log entry is added, only the hash value on the path from the new leaf node to the root node needs to be recalculated. To further improve security, the Merkle root can be recorded to the main chain regularly (such as every hour or every day), so that even if the entire subchain is tampered with, it can be detected through the records on the main chain. Through this complex log management mechanism, the system can accurately track every data operation, providing a reliable basis for subsequent auditing, dispute resolution and data recovery.

[0037] S107. A hierarchical storage architecture based on a directed acyclic graph is used to store all target data and log Merkle tree structures in a hierarchical manner in the main chain-subchain architecture.

[0038] Among them, the directed acyclic graph (DAG) structure can support parallel processing and higher throughput compared to traditional linear blockchains. In this architecture, each data item or transaction is represented as a node in the DAG, and the nodes are connected by edges to represent the relationship or dependency between the data. First, the target data is classified according to business type, timestamp or other standards, and each type of data forms an independent DAG subgraph. For example, financial transaction data may form a subgraph, while user identity information forms another subgraph. Each data node contains metadata such as the hash value, timestamp, creator information, etc. of the actual data. For large data, IPFS (InterPlanetary File System) can be used to store the actual content, while only the IPFS address is stored in the DAG. The log Merkle tree structure is also integrated into the DAG, and each Merkle tree root node is connected to the relevant data node as a special node in the DAG. This design allows for rapid verification of the data operation history within a specific time period. In order to optimize storage and query efficiency, a tiered storage strategy can be implemented. The latest and frequently accessed data is stored in the fast storage layer (such as SSD), while historical data is gradually migrated to the slow but large-capacity storage layer (such as HDD or cloud storage). This migration process can be automatically triggered and managed through smart contracts.

[0039] In the main chain-subchain architecture, the DAG structure is mainly deployed on the subchain to process specific business data. The subchain periodically synchronizes the state summary of its DAG (such as the DAG root node hash at a specific time point) to the main chain to form a cross-chain data index. This design not only ensures the independence and efficiency of subchain data processing, but also provides global consistency through the main chain. In order to support efficient data retrieval and verification, the system also needs to implement a complex indexing mechanism. Distributed indexing technology, such as ElasticSearch clusters, can be used to establish multidimensional indexes for nodes in the DAG. Indexes can be based on multiple dimensions such as time, data type, user ID, etc. to support complex query requirements. For example, quickly locate all data operations of a user in a specific time period.

[0040] In addition, in order to deal with the expansion problem that DAG may face, a regular compression mechanism can be implemented. For example, for data nodes before a certain time, multiple related nodes can be merged into a summary node while retaining the necessary verification information. This compression process requires a consensus mechanism to ensure that all nodes reach consensus. In terms of data consistency, an eventual consistency model is adopted. When new data or transactions are added to DAG, they are first quickly confirmed in the local subchain and then gradually propagated to the entire network. By setting an appropriate number of confirmation layers, a balance can be achieved between efficiency and security. Through this complex DAG-based storage architecture, the system is able to achieve high-throughput, low-latency data management while ensuring data integrity and security. It provides flexible storage and access modes for different types of data and operations, while ensuring global consistency of the entire system through regular synchronization with the main chain. This design is very suitable for handling large-scale, high-frequency data interaction scenarios, such as IoT data collection, financial transaction processing and other complex application scenarios.

[0041] In one embodiment, before receiving the data interaction request sent by the target user through the user-side server, the following steps are also included: A user information processing model based on a neural network is deployed in the dual-layer trusted execution environment hardware. The user information processing model includes an information feature extraction module, an information integrity verification module, an information credibility verification module, a user type classification module, and a noise injection module. Obtain the user registration request sent by the user to be registered to the main chain-subchain architecture from the user-side server; Extract the user information in the user registration request, input the user information into the user information processing model for information verification, and output the user type of the user to be registered according to the user information that has passed the information verification through the user information processing model; Randomly generate the user key of the user to be registered and store the user key in the main chain-subchain architecture; Based on the user type, the user authentication identity of the user to be registered is generated through a cross-chain smart contract, and the user authentication identity is issued to the user to be registered using the blockchain computing node to complete the user registration of the user to be registered in the main chain-sub-chain architecture.

[0042] In this embodiment, the two-layer trusted execution environment generally includes a hardware security module (HSM) and a trusted execution environment (TEE), such as Intel SGX or ARM TrustZone, to provide an isolated execution space. The user information processing model adopts a deep neural network architecture and includes multiple functional modules. The information feature extraction module uses a convolutional neural network (CNN) to extract key features of user information; the information integrity verification module uses a recurrent neural network (RNN) to check the coherence and integrity of the information; the information credibility verification module combines the attention mechanism and the graph neural network (GNN) to analyze the intrinsic relevance of the information; the user type classification module uses a multi-layer perceptron (MLP) for classification; the noise injection module adds random noise based on the principle of differential privacy. The model training adopts a federated learning method to ensure privacy and security. The deployment process includes model encryption, secure loading, and runtime integrity verification to ensure that the model itself is not tampered with or stolen.

[0043] The starting point of the user registration process is to obtain the registration request of the user to be registered from the user-side server. The user-side server receives the registration information submitted by the user through a secure API interface (such as HTTPS), including username, password hash, email, identity proof, etc. The server first performs basic format verification and protection measures, such as checking the legitimacy of the input and implementing rate limits to prevent brute force attacks. Then, the server encrypts the request (using an asymmetric encryption algorithm such as RSA) and adds a digital signature to ensure the confidentiality and integrity of the data during transmission. The request is sent to the access node of the main chain-subchain architecture through a predefined secure channel. The access node verifies the signature and source of the request, and forwards the request content to the corresponding processing module after decryption. The entire process adopts an asynchronous processing mechanism, using message queues (such as RabbitMQ) to manage a large number of concurrent requests to improve system throughput and response speed.

[0044] Next, the user information in the user registration request is extracted and input into the user information processing model for verification. Specifically, regular expressions and specific parsing algorithms are first used to extract structured user information from the request. The extracted information undergoes preliminary data cleaning and standardization, such as removing redundant spaces and unifying date formats. Then, the processed information is converted into a numerical vector suitable for neural network input, such as using word embedding technology to convert text information into dense vectors. These vectors are input into each module of the user information processing model in turn. The model runs in a trusted execution environment to ensure the security of the processing process. The information feature extraction module and the integrity verification module first process the input in parallel, and then pass the results to the credibility verification module. The credibility verification module synthesizes the outputs of the first two modules and uses the pre-trained knowledge graph for in-depth analysis. Finally, the user type classification module classifies users based on the outputs of the previous modules and combines historical data. The entire process uses batch processing to improve efficiency. The verification results include the integrity score, credibility score, and predicted user type of the information, which are used in the subsequent decision-making process.

[0045] The user key is then randomly generated and stored in the main chain-child chain architecture. The key generation process uses a cryptographically secure random number generator (CSPRNG), such as the Fortuna algorithm, to generate a random byte sequence with high entropy. This sequence is used as a seed to generate the actual user key pair through a key derivation function (KDF) such as HKDF. Typically, a pair of public and private keys (such as using the ECC algorithm) and a symmetric encryption key (such as AES-256) are generated. To enhance security, Shamir's SecretSharing algorithm is used to split the private key into multiple shares, which are stored on different child chains. Each share is then encrypted using a threshold encryption scheme to ensure that the full private key can only be reconstructed when certain conditions (such as multi-party authorization) are met. The public key and the encrypted symmetric key are stored directly on the main chain and associated with the user's unique identifier. The entire storage process is implemented through smart contracts to ensure the atomicity and consistency of the operation. This distributed storage solution not only improves security, but also ensures that keys can be quickly accessed and used when needed.

[0046] Finally, based on the user type, the user authentication identity is generated through the cross-chain smart contract and issued to the user using the blockchain computing node to complete the registration process. Specifically, first, the appropriate smart contract template is selected according to the user type, which predefines the permissions and attribute structure of different types of users. A unique identity identifier is generated using a verifiable random function (VRF) to ensure its unpredictability. Then, data such as user information, public key, and permissions are encoded into the contract state. During the contract execution process, the zero-knowledge proof library is called to generate proof of user identity to enhance privacy protection. The generated authentication identity includes a token in JWT format, which contains encrypted user information, permission declaration, and expiration time. The token is signed with the private key of the blockchain network to ensure that it cannot be forged. Finally, the authentication identity is sent to the user through a secure channel, and the hash value of the authentication event is recorded on the main chain for subsequent auditing. The entire process is synchronously executed between the main chain and the relevant subchains through the cross-chain protocol to ensure data consistency.

[0047] In one embodiment, referring to Figure 3 ,The user information processing model adopts a deep neural network architecture and contains multiple functional modules, mainly composed of information feature extraction module, information integrity verification module, information credibility verification module, decision unit, gating unit, user type classification module and noise injection module. The information feature extraction module uses a convolutional neural network (CNN) structure to extract key features from the original user information. The input of the information feature extraction module is the original user information, and the output includes information field features and information anomaly association features. The information field features reflect the semantic features of each field of user information, and the information anomaly association features reflect the abnormal association patterns between fields. The specific layer structure is as follows: Input layer: receives the original user information, with the dimension of (batch_size, input_length, embedding_dim), where batch_size is the batch size, input_length is the input sequence length, and embedding_dim is the embedding dimension of each element.

[0048] The first convolutional layer: uses 64 3x1 convolution kernels, with a stride of 1 and padding of "same". The purpose of this layer is to capture local features. The convolution operation can be expressed as: output = conv(input, kernel) + bias, where conv represents the convolution operation, kernel is the convolution kernel, and bias is the bias term.

[0049] First activation layer: Use ReLU (Rectified Linear Unit) activation function, the formula is f(x) = max(0, x). This layer introduces nonlinearity and increases the expressiveness of the model.

[0050] The first maximum pooling layer: the pooling size is 2x1 and the stride is 2. The pooling operation can reduce the feature dimension and enhance the translation invariance of the model.

[0051] Second convolutional layer: Use 128 3x1 convolution kernels, and other settings are the same as the first convolutional layer. This layer can capture more advanced features.

[0052] The second activation layer: also uses the ReLU activation function.

[0053] Second max pooling layer: The settings are the same as the first pooling layer.

[0054] The third convolutional layer: uses 256 3x1 convolution kernels, and other settings remain unchanged. This layer can extract more abstract features.

[0055] The third activation layer: ReLU activation function.

[0056] Global average pooling layer: compresses the feature map into a one-dimensional vector, retaining the average value of each channel.

[0057] The first fully connected layer: The output dimension is 512, and the ReLU activation function is used. The function of this layer is to integrate the features extracted previously.

[0058] The second fully connected layer (shared feature layer): The output dimension is 256, and the ReLU activation function is used. The output of this layer will be used as the input of the subsequent modules, representing the information field features and the information anomaly association features respectively.

[0059] The information integrity verification module adopts a recurrent neural network (RNN) structure. This module uses a long short-term memory network (LSTM) structure. The information integrity verification module receives information field features as input, captures the temporal dependencies between information fields through a recurrent structure, and outputs the integrity probability of user information to verify the integrity of user information. The specific layer structure is as follows: Input layer: receives information field features, with dimensions of (batch_size, sequence_length, feature_dim).

[0060] The first LSTM layer: contains 128 hidden units and returns the complete sequence. The core formula of the LSTM unit is as follows: f_t=σ(W_f·[h_{t-1},x_t]+b_f) i_t=σ(W_i·[h_{t-1},x_t]+b_i) o_t=σ(W_o·[h_{t-1},x_t]+b_o) c_t=tanh(W_c·[h_{t-1},x_t]+b_c) c_t=f_t c_{t-1}+i_t c_t h_t=o_t tanh(c_t) Among them, f_t, i_t, o_t are the forget gate, input gate and output gate respectively, c_t is the cell state, h_t is the hidden state, σ is the sigmoid function, Represents element-wise multiplication.

[0061] The second LSTM layer: contains 64 hidden units and also returns the complete sequence. This layer can capture higher-level temporal dependencies.

[0062] Fully connected layer: The output dimension is 1, and the Sigmoid activation function is used. This layer compresses the output of the LSTM into a value between 0 and 1, indicating the completeness probability.

[0063] The information credibility verification module combines the attention mechanism and the graph neural network (GNN). This module combines the graph neural network (GNN) and the attention mechanism. The attention mechanism is used to weight the abnormal information correlation features and highlight the important features. The GNN is used to model the relationship diagram between information fields and analyze the internal correlation, so as to finally output the credibility score of the user information, which is used to evaluate the credibility of the user information. The specific layer structure is as follows: Graph construction layer: Build a graph structure based on the information anomaly correlation features. This step converts user information into a graph, where nodes represent information fields and edges represent the relationship between fields.

[0064] The first graph convolution layer: the output dimension is 128, and the ReLU activation function is used. The graph convolution operation can be expressed as: H^(l+1)=σ(D^(-1 / 2)AD^(-1 / 2)H^(l)W^(l)) Where A is the adjacency matrix, D is the degree matrix, H^(l) is the node feature of the lth layer, and W^(l) is the learnable weight matrix.

[0065] The second graph convolution layer: The output dimension is 64, and the ReLU activation function is used. This layer can capture higher-order relationships between nodes.

[0066] Global pooling layer: aggregates node features into graph-level features. Commonly used pooling methods include average pooling and maximum pooling.

[0067] Attention layer: Use a multi-head attention mechanism with 8 heads and a dimension of 32 for each head. The calculation formula for multi-head attention is: MultiHead(Q,K,V)=Concat(head_1,...,head_h)W^O Among them, head_i=Attention(QW_i^Q,KW_i^K,VW_i^V) Fully connected layer: The output dimension is 1, and the Sigmoid activation function is used. This layer compresses the output of the attention layer into a value between 0 and 1, indicating the credibility score.

[0068] A multi-head attention mechanism is also built between the information integrity verification module and the information credibility verification module to realize the information interaction between the information integrity verification module and the information credibility verification module. Its structure can be described as: Input: Feature representations from both modules.

[0069] Linear transformation: Convert the input into query (Q), key (K), and value (V).

[0070] Attention calculation: For each head, calculate the attention weight and weight the aggregate value vector.

[0071] Splice: Splice the output of all heads together.

[0072] Linear transformation: Map the concatenated result to the desired output dimension.

[0073] The decision unit is a multi-layer perceptron (MLP), which receives the completeness probability and credibility score as input and outputs the verification result of the user information. This unit is used to combine the completeness probability and credibility score to make the final verification decision. The specific layer structure is as follows: Input layer: receives completeness probability and credibility score, with dimension 2.

[0074] The first hidden layer: 32 neurons, using the ReLU activation function. The calculation of this layer can be expressed as: h_1=ReLU(W_1x+b_1), where x is the input vector, W_1 is the weight matrix, and b_1 is the bias vector.

[0075] Second hidden layer: 16 neurons, using ReLU activation function. The calculation method is similar to the first hidden layer.

[0076] Output layer: 1 neuron, using Sigmoid activation function. Output a value between 0 and 1, indicating the verification result.

[0077] The gate control unit is a simple threshold judgment module, which decides whether to activate the user type classification module according to the verification result of the decision unit. Its structure can be described as: Input: Receive the output value of the decision unit.

[0078] Threshold comparison: If the input value is greater than the preset threshold (such as 0.5), the output is 1 (activation signal), otherwise the output is 0.

[0079] Output: Binary value, 1 for activation and 0 for inactivation.

[0080] The user type classification module also uses the MLP structure. After receiving the activation signal, it combines the credibility score and information field features to classify and output the user type. The specific layer structure is as follows: Input layer: receives the credibility score and information field features, with a total dimension of 257 (1+256).

[0081] The first hidden layer has 128 neurons and uses the ReLU activation function.

[0082] The second hidden layer has 64 neurons and uses the ReLU activation function.

[0083] Output layer: n neurons (n ​​is the number of user types), using Softmax activation function. The calculation formula of Softmax function is: softmax(x_i)=exp(x_i) / Σ_jexp(x_j) This ensures that the output values ​​sum to 1 and can be interpreted as a probability distribution over user types.

[0084] The noise injection module is based on the Laplace mechanism. It adds random noise to the user type classification results according to the preset privacy budget ε to achieve differential privacy protection. This module implements differential privacy protection based on the Laplace mechanism. Its structure can be described as: Input: Receive user type classification results.

[0085] Noise generation: Generate random noise that follows the Laplace distribution Lap(0,1 / ε), where ε is the preset privacy budget. The probability density function of the Laplace distribution is: f(x|μ,b)=(1 / (2b)) exp(-|x-μ| / b) where μ is the location parameter (0 in this case) and b is the scale parameter (1 / ε in this case).

[0086] Noise Addition: Add the generated noise to the classification results.

[0087] Output: User type classification result with noise.

[0088] In summary, the data processing flow of the user information processing model is as follows: First, the original user information is input into the information feature extraction module, and the information field features and information anomaly association features are obtained through CNN processing. The information field features are simultaneously input into the information integrity verification module and the user type classification module, and the information anomaly association features are input into the information credibility verification module. The RNN structure of the information integrity verification module processes the information field features and outputs the integrity probability; the GNN structure of the information credibility verification module processes the information anomaly association features and outputs the credibility score. At the same time, the two verification modules interact with each other through the multi-head attention mechanism to enhance the feature representation capability. The integrity probability and credibility score are input into the decision unit, and the decision unit outputs the verification result. The verification result is judged by the gate control unit to decide whether to activate the user type classification module. If activated, the user type classification module combines the credibility score and information field features for classification and outputs the user type. Finally, the noise injection module adds random noise to the classification result to obtain the final user type output.

[0089] The model training adopts the federated learning method to protect user privacy. Specifically, multiple participants train the model on local data, only exchanging model parameters without sharing original data. The central server aggregates parameters to update the global model, and then distributes it to each participant for the next round of training. The training goal is to minimize the weighted sum of information integrity verification error, information credibility verification error and user type classification error. To improve the robustness of the model, adversarial training, data enhancement and other technologies can be used in the training process. When the model is inferred, the input data is first preprocessed, including data cleaning and standardization. Then it is processed through each module in turn, and finally the user type with differential privacy protection is output. During the whole process, the model can also output intermediate results such as integrity probability, credibility score, etc., to provide more basis for decision-making. The advantages of this model are: 1) multi-module collaborative processing, comprehensive verification of user information; 2) deep learning and graph structure are combined to improve feature extraction and relationship modeling capabilities; 3) differential privacy mechanism protects user privacy; 4) the federated learning method realizes distributed training without data leaving the local area.

[0090] In one embodiment, storing user keys in the main chain-subchain architecture includes the following steps: Use Shamir's secret sharing algorithm to split the user key into n key fragments; Encrypt each key fragment using a homomorphic encryption algorithm; According to the node status of the blockchain computing nodes, m blockchain computing nodes are selected as trusted computing nodes, 2≤m<n; Distribute and store the encrypted key fragments to each trusted computing node; A key reconstruction protocol based on threshold signature is created for all trusted computing nodes. The key reconstruction protocol constrains that at least t trusted computing nodes are required to collaborate in the user key reconstruction process, t≤m.

[0091] In this embodiment, the Shamir secret sharing algorithm is based on the polynomial interpolation principle. First, a large prime number p is selected as a finite field, and then a polynomial f(x) of degree t-1 is randomly generated, where f(0) is equal to the key to be divided. Next, n non-zero points x1, x2, ..., xn are selected, and the corresponding f(x1), f(x2), ..., f(xn) are calculated as n key fragments. For example, for a 128-bit key, p can be selected as a prime number greater than 2^128, the key is regarded as f(0), and a polynomial such as f(x)=k+a1x+a2x^2+...+at-1x^(t-1)modp is generated, where k is the original key and ai is a random coefficient. By calculating f(1), f(2), ..., f(n), n key fragments are obtained. This method ensures that the original key can only be reconstructed if at least t fragments are simultaneously possessed, which greatly enhances security. At the same time, since the size of each fragment is the same as the original key, storage efficiency is also guaranteed.

[0092] The purpose of using a homomorphic encryption algorithm to encrypt each key fragment is to protect the security of the key fragment while allowing specific computing operations to be performed on the encrypted data. Common homomorphic encryption algorithms include the Paillier encryption system or the BGV scheme. Taking the Paillier algorithm as an example, first generate two large prime numbers p and q, calculate n=pq and λ=lcm(p-1,q-1), and select a random integer g so that gcd(L(g^λmodn^2),n)=1, where L(x)=(x-1) / n. The public key is (n,g) and the private key is λ. The encryption process is c=g^m r^nmodn^2, where m is the key fragment and r is a random number. This encryption method allows addition operations to be performed without decryption, that is, E(m1) E(m2)=E(m1+m2). For each key fragment, a different random number r is used for encryption to further enhance security. Homomorphic encryption not only protects the confidentiality of the key fragment, but also provides a basis for subsequent secure calculations and key reconstruction.

[0093] Selecting m blockchain computing nodes as trusted computing nodes based on the node status of the blockchain computing nodes is a key step to ensure the security and efficiency of key management. The selection process considers multiple factors, including the computing power of the node, the quality of the network connection, the historical reputation, and the current load. Multi-attribute decision-making methods, such as the analytic hierarchy process (AHP) or TOPSIS, can be used to calculate a comprehensive score for each node. For example, define the scoring function S=w1C+w2N+w3R+w4L, where C, N, R, and L represent computing power, network quality, reputation, and load, respectively, and wi is the corresponding weight. Select the m nodes with the highest scores as trusted computing nodes. In order to dynamically adapt to network conditions, a regular re-evaluation mechanism can be set, such as evaluating and adjusting every certain number of blocks. Selecting 2≤m<n ensures the fault tolerance and decentralization of the system, which can resist partial node failures or attacks and avoid single-point control risks.

[0094] Distributing and storing the encrypted key fragments to each trusted computing node is the core step to achieve distributed key management. The distribution process uses a secure multi-party computing protocol to ensure that each node only obtains the specified encrypted fragments, and cannot access other fragments or derive the original key. The specific implementation can use a method that combines Shamir secret sharing with homomorphic encryption. First, each encrypted fragment is split again using the Shamir scheme to generate multiple sub-fragments. Then, these sub-fragments are sent to different trusted nodes through a secure channel (such as TLS / SSL). After each node receives the sub-fragment, it partially decrypts it using its own private key and stores the result in its secure storage area (such as a hardware security module HSM). To enhance availability, a redundant storage strategy can be implemented, that is, each fragment is stored as a backup on multiple nodes. At the same time, a version control mechanism is implemented to ensure that the fragment versions on all nodes are consistent. This distributed storage solution greatly improves the security and reliability of the system. Even if some nodes are compromised, attackers cannot obtain enough information to reconstruct the key.

[0095] Creating a threshold signature-based key reconstruction protocol for all trusted computing nodes is the last line of defense to ensure the safe use of keys. The protocol is based on the (t,m) threshold scheme and requires at least t nodes to participate in key reconstruction. The specific implementation can be combined with Shamir's threshold signature scheme and homomorphic encryption. First, a shared public key is generated, and each node holds a part of the private key. When the key needs to be reconstructed, a reconstruction request is initiated, including the purpose of the operation, a timestamp, and a random challenge. The nodes participating in the reconstruction sign the request with their own partial private keys and submit the partial decryption results of the encrypted fragments. After collecting at least t valid signatures and partial decryption results, the system reconstructs the original key through the Lagrange interpolation method. The whole process is carried out in a secure multi-party computing environment to ensure that the intermediate results are not leaked. At the same time, an audit log mechanism is implemented to record the detailed information of each reconstruction operation for subsequent tracking and analysis. This protocol not only ensures the security of key reconstruction, but also provides sufficient flexibility to cope with various usage scenarios.

[0096] In one embodiment, generating a user authentication identity of a user to be registered based on the user type and through a cross-chain smart contract includes the following steps: Execute cross-chain smart contracts based on user type and generate verifiable credentials for the user to be registered; Based on user information, the attribute description language that supports multi-dimensional access policy definition is used to generate user attributes of the user to be registered, and the CP-ABE encryption algorithm is used to complete the attribute encryption of user attributes; Combining the verifiable credentials and the encrypted user attributes into the user identity of the user to be registered; Adding a zero-knowledge range proof-based authentication protocol for user identities; The user key of the user to be registered is reconstructed from the main chain-subchain architecture, and the user identity is signed by the user key to obtain the user authentication identity of the user to be registered.

[0097] In this embodiment, it is a complex process to execute a cross-chain smart contract based on the user type and generate a verifiable credential for the user to be registered. First, the corresponding smart contract template in the cross-chain smart contract is selected according to the user type. The template predefines the permissions and attribute structure of different types of users. The contract execution environment spans the main chain and related sub-chains, and uses cross-chain communication protocols such as hash time lock contracts (HTLC) to ensure data consistency. During the contract execution process, a verifiable random function (VRF) is called to generate a unique credential identifier to ensure its unpredictability. The credential content includes information such as user type, permission level, and validity period, and is digitally signed using the on-chain public key infrastructure (PKI). Finally, the credential content and signature are combined into a verifiable credential in a standard format such as JSON Web Token (JWT). This credential not only contains user identity information, but also can verify its authenticity and integrity through cryptographic methods, greatly enhancing the security and credibility of identity management.

[0098] Based on user information, the user attributes of the user to be registered are generated using an attribute description language that supports multi-dimensional access policy definition, and the attribute encryption of the user attributes is completed using the CP-ABE encryption algorithm. This is a key step in protecting user privacy. First, the user attributes are defined using an attribute description language such as XACML, including multi-dimensional information such as identity characteristics, authority level, and organizational affiliation. For example, an attribute expression such as "role:engineer AND clearance:secret AND department:R&D" can be defined. Then, the CP-ABE (Ciphertext-Policy Attribute-BasedEncryption) algorithm is used for encryption. The working principle of CP-ABE is to embed the access policy into the ciphertext, and only users with the attribute set that meets the policy can decrypt it. The specific steps include: setting global parameters, generating master keys and public keys, generating user keys based on attributes, and finally encrypting attribute information using public keys and access policies. This method not only protects the privacy of user attributes, but also implements fine-grained access control to ensure that only authorized entities can access specific user attribute information.

[0099] Combining the verifiable credentials and the encrypted user attributes into the user identity of the user to be registered is the process of creating a complete and secure user identity. This step first serializes the verifiable credentials and encrypted user attributes generated in the first two steps, usually in a structured data format such as JSON or Protocol Buffers. Then, a cryptographic hash function (such as SHA-256) is used to calculate the combined hash value of these two parts of data as the unique identifier of the user identity. Next, a data structure containing this identifier, the verifiable credentials, and the encrypted attribute reference is constructed, which forms a complete identity representation of the user. To enhance security, timestamps and random challenge values ​​can be used to prevent replay attacks. Finally, this identity structure is serialized and signed using a digital signature algorithm (such as ECDSA) to ensure its integrity and non-repudiation. This combined approach not only ensures the verifiability of identity information, but also protects the privacy of sensitive attributes, while providing a flexible access control mechanism.

[0100] Adding an authentication protocol based on zero-knowledge range proofs to user identities is an important step to enhance privacy protection. This protocol allows users to prove that they have certain attributes or meet certain conditions without revealing the specific attribute values. The implementation process uses zero-knowledge proof systems such as zk-SNARKs or Bulletproofs. First, define a set of assertions, such as "age between 18-65 years old" or "credit score above 700". Then, use these assertions to build arithmetic circuits to convert user attributes into inputs to the circuit. The prover (user) uses his own private attribute information and the public circuit to generate a proof, and the verifier can verify this proof without knowing the specific attribute value. The specific implementation can use a protocol such as Groth16, including a setup phase, a proof generation phase, and a verification phase. This approach not only protects user privacy, but also greatly reduces the amount of sensitive information that needs to be transmitted and stored, while ensuring the reliability of identity authentication.

[0101] Reconstructing the user key of the user to be registered from the main chain-subchain architecture, and signing the user identity with the user key to obtain the user authentication identity of the user to be registered is the last step to complete the user registration. First, the key reconstruction protocol is triggered, requiring at least t trusted computing nodes to cooperate. Each participating node provides the key fragments and partial signatures it holds. The system uses a threshold signature scheme (such as Shamir's threshold scheme) to combine these parts and reconstruct the complete user key. The reconstruction process is carried out in a secure multi-party computing environment to ensure that the intermediate results are not leaked. Next, the reconstructed user key is used to digitally sign the previously generated user identity, usually using the elliptic curve digital signature algorithm (ECDSA). The signing process includes generating a random number k, calculating the point R = kG on the curve (G is the base point), and then calculating the signature value s = k^-1(H(m) +r privateKey) mod n, where H(m) is the message hash and r is the x-coordinate of point R. Finally, the signature (r, s) is combined with the user identity information to form a complete user authentication identity. This process not only ensures the authenticity and integrity of the user identity, but also establishes a binding relationship between the user and his key, providing a solid foundation for subsequent identity authentication and authorization.

[0102] In one embodiment, the method further comprises the steps of: Count the number of user authentication identities generated through cross-chain smart contracts; Whenever the generated quantity reaches the preset quantity threshold, the contract code of the cross-chain smart contract is parsed and semantically checked; Combine the analysis and inspection results of syntax analysis and semantic checking and update the cross-chain smart contract through preset adaptive update rules.

[0103] In this embodiment, counting the number of user authentication identities generated by cross-chain smart contracts is an important measure to monitor system performance and security. This process involves setting up a counter mechanism on the main chain and each sub-chain. Whenever a cross-chain smart contract is executed and a new user authentication identity is generated, the corresponding counter will increase. In order to ensure the accuracy and consistency of the count, a distributed counter technology, such as the HyperLogLog algorithm, is used, which can provide an approximate unique count while maintaining a small memory footprint. In a cross-chain environment, each sub-chain maintains its own local counter and regularly synchronizes the counting results to the main chain through a cross-chain communication protocol (such as a hash time lock contract HTLC). The smart contract on the main chain is responsible for aggregating the counting results of all sub-chains and calculating the total number of generation. In order to prevent the counter from being maliciously manipulated, a multi-signature mechanism is implemented, requiring multiple trusted nodes to jointly verify the count update operation. In addition, using the immutable characteristics of the blockchain, each count update is recorded as a transaction to ensure the auditability and transparency of the counting process. This statistical mechanism not only provides real-time monitoring of the system operation status, but also provides important data support for subsequent contract optimization and security analysis.

[0104] Whenever the number of generated contracts reaches the preset number threshold, parsing and semantic checking of the contract code of the cross-chain smart contract is a key step to ensure the security and performance of the contract. First, set a reasonable threshold, such as triggering a check every 10,000 user authentication identities. The checking process is divided into two main stages: parsing and semantic checking. Parsing uses a lexical analyzer and a syntax analyzer to convert the contract code into an abstract syntax tree (AST). This process checks whether the code complies with the syntax rules of the smart contract language (such as Solidity), including variable declarations, function definitions, control structures, etc. Semantic checking analyzes the logical correctness and security of the code in more depth. It includes type checking, control flow analysis, data flow analysis, etc. For example, check for common problems such as integer overflow, reentrancy attack vulnerabilities, and uninitialized storage pointers. In addition, gas consumption analysis is performed to evaluate the efficiency of contract execution. These checks are performed using static analysis tools such as Mythril or Slither, combined with a custom set of rules. The inspection results are generated in the form of a report, which contains a detailed description of the potential problems and a severity rating. This regular automated inspection mechanism can promptly detect and fix potential problems in the contract, greatly improving the security and reliability of the system.

[0105] Combining the analysis and inspection results of syntax analysis and semantic inspection and updating the cross-chain smart contract through preset adaptive update rules is the last step to optimize system performance and security. First, the inspection report is analyzed in depth, and the problems found are classified (such as security vulnerabilities, performance bottlenecks, logical errors, etc.) and sorted by severity. Then, the update strategy is determined according to the preset adaptive update rules. These rules may include: immediate repair of serious security vulnerabilities, optimization of performance issues in the next planned update, and recording and monitoring of minor issues. The update process adopts a smart contract upgrade mode, such as proxy mode or data separation mode, to ensure that the update does not interrupt existing services. In specific implementation, the updated contract is first deployed on the test network for comprehensive testing, including unit testing, integration testing, and stress testing. After passing the test, the multi-signature mechanism is used to trigger the contract update on the main network. During the update process, each step is recorded using event logs to ensure traceability. After the update is completed, the system automatically verifies the consistency of the state of the new contract and monitors it closely for a period of time. This adaptive update mechanism can not only fix problems in a timely manner, but also continuously optimize contract performance to ensure the long-term stable operation and security of the system.

[0106] In one embodiment, granting a target user data access rights or data upload rights in the main chain-subchain architecture according to the request type of the data interaction request, so that the target user can access the target data stored in the main chain-subchain architecture by using the data access rights, or the target user can upload the target data in the main chain-subchain architecture by using the data upload rights, includes the following steps: Determine whether the request type of the data interaction request is a data upload request or a data access request; If it is a data upload request, the target user is granted data upload permission in the main chain-subchain architecture, and the target data of the target user and the data access policy preset by the target user for the target data are obtained; If the target data is encrypted by the target user through the user key, the target data and data access policy are packaged and sent to the blockchain subchain, and the data upload process of the target data is completed through the blockchain computing node; If the target data is not encrypted, the target data and data access policy are packaged and sent to the blockchain main chain, and the data upload process of the target data is completed through the blockchain consensus node; If it is a data access request, the data access rights of the target user are determined and granted based on the user authentication identity of the target user; Combined with data access permissions and data access policies for stored data in the main chain-subchain architecture, the data storage location of the target data accessible to the target user is fed back to the target user.

[0107] In this embodiment, determining whether the request type of a data interaction request is a data upload request or a data access request is the first step in processing a user request. This process involves parsing and classifying the received request message. First, the request message usually adopts a standardized format, such as JSON or Protocol Buffers, and contains fields such as request type, user identifier, and timestamp. The system uses a message parser to extract these fields, paying special attention to the field indicating the request type. The judgment logic can be based on simple conditional statements, such as checking whether the request type field is equal to a predefined "UPLOAD" or "ACCESS" value. To improve processing efficiency, a hash table can be used to store the mapping between request types and processing functions to achieve rapid distribution with O(1) time complexity. In addition, the system will verify the integrity and validity of the request, including checking the digital signature and verifying the timestamp to prevent replay attacks. This judgment process lays the foundation for subsequent permission granting and data processing, ensuring that the request is correctly routed to the corresponding processing module.

[0108] In the case of data upload requests, granting the target user data upload permissions in the main chain-subchain architecture and obtaining the target data and its preset data access policy are key steps in the data upload process. First, the system verifies the user's identity and permissions, usually by checking the user's digital certificate or token. After verification, an authorization transaction is recorded on the main chain, indicating that the user has obtained upload permissions. This transaction contains information such as the user ID, authorization timestamp, and validity period. Next, the system receives the target data and data access policy uploaded by the user. The data may be transmitted in the form of files or data streams, using secure transmission protocols such as HTTPS or SFTP. The data access policy usually adopts the attribute-based access control (ABAC) model, which defines who can access the data under what conditions. For example, the policy may specify that "only members of the R&D department with a level greater than 3 can access during working hours." The system converts this policy into a machine-readable format, such as XACML, and temporarily stores it with the data, waiting for subsequent processing.

[0109] If the target data is encrypted by the user's key, the target data and data access policy are packaged and sent to the blockchain subchain, and the data upload process is completed through the blockchain computing node. This step involves a complex process of data encryption, transmission and storage. First, the system verifies the encryption status of the data, which may be confirmed by checking the encryption flag in the data header or trying to decrypt a small part of the data. After confirming the encryption, the system packages the encrypted data and access policy into a transaction. This transaction contains the hash value of the data, the storage location of the encrypted data (which may be the IPFS address), the hash value of the access policy, etc. Then, the system selects the appropriate subchain for upload, and the selection criteria may be based on the data type, the user's department, etc. After selection, the transaction is sent to the target subchain through a cross-chain communication protocol (such as the hash time lock contract HTLC). After receiving the transaction, the computing node on the subchain verifies its legitimacy and then packages the transaction into a block. This process may involve consensus mechanisms such as PoS or DPoS. Finally, the computing node updates the status and records the index information of the new data. This method not only ensures the privacy of the data (because the data is encrypted), but also takes advantage of the efficient processing capabilities of the subchain.

[0110] If the target data is not encrypted, the data and access policy are packaged and sent to the main chain, and the upload process is completed through the consensus node. This step processes plaintext data, so a higher level of security measures is required. First, the system performs an integrity check on the data and calculates its hash value. Then, the data, access policy, data hash value, and metadata (such as upload time, user ID, etc.) are packaged into a transaction. To protect privacy, zero-knowledge proof technology can be used to allow verification of certain attributes of data without exposing the actual content. Next, this transaction is broadcast to the main chain network. The consensus nodes on the main chain (such as using PoW or PoS mechanisms) verify the legitimacy of the transaction, including checking user permissions, verifying data integrity, etc. After the verification is passed, the nodes reach a consensus and package the transaction into a new block. Once the block is confirmed, the data is considered to be securely stored on the blockchain. Finally, the system updates the global state to record the location and access policy of the new data. Although this method may be slower in processing, it provides the highest level of security and immutability.

[0111] If it is a data access request, the data access rights are determined and granted based on the user authentication identity of the target user. This process first verifies the user's authentication identity, which usually involves checking the validity of a digital signature, token, or certificate. The system queries the user's identity information stored on the blockchain and verifies the identity attributes claimed by the user. The system then evaluates the user's access rights. This is usually based on a predefined access control policy, which may use role-based access control (RBAC) or a more complex attribute-based access control (ABAC) model. For example, the system may check the user's department, rank, project participation and other attributes, and match these with the data access policy. The permission evaluation process may involve complex logical operations, such as "(rank>3AND department='R&D')OR(project='A'AND time is within working hours)". The evaluation result determines the operations that the user can perform, such as read-only, edit, or delete. The system then generates an access token containing the scope and validity period of the authorization. This token is signed with the system's private key to ensure that it cannot be forged. Finally, the system records this authorization operation on the blockchain to ensure auditability.

[0112] Combined with the data access rights and the access policy of the stored data, the user is fed back the accessible target data storage location. This step involves data retrieval and location resolution. First, the system queries the eligible data index based on the user's access rights. This may involve distributed searches on the main chain and multiple subchains. For each matching data record, the system checks whether its access policy matches the user's permissions. This process may use smart contracts to execute complex policy evaluation logic. Qualified data items are added to the result list. For each data item, the system resolves its storage location. This may be a direct storage location on the blockchain (such as a reference to a specific block and transaction), or a reference to an external storage system (such as an IPFS hash). The system may also generate a temporary access URL or token to allow users to directly access the data within a limited time. Finally, the system returns this location information to the user in a structured format (such as JSON), along with metadata for each data item (such as title, upload time, file size, etc.). This approach not only ensures the security of data access, but also provides a flexible data retrieval mechanism.

[0113] The present invention also discloses a blockchain-based data interaction security and privacy protection system, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that when the processor executes the computer program, the blockchain-based data interaction security and privacy protection method described in any one of the above embodiments is implemented.

[0114] Among them, the processor can adopt a central processing unit (CPU). Of course, according to actual usage, other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. can also be adopted. The general-purpose processor can adopt a microprocessor or any conventional processor, etc., and this application does not impose any restrictions on this.

[0115] Among them, the memory can be an internal storage unit of a computer device, such as a hard disk or memory of a computer device, or an external storage device of a computer device, such as a plug-in hard disk, a smart memory card (SMC), a secure digital card (SD) or a flash memory card (FC) equipped on the computer device, and the memory can also be a combination of an internal storage unit and an external storage device of a computer device. The memory is used to store computer programs and other programs and data required by the computer device. The memory can also be used to temporarily store data that has been output or is to be output, and this application does not impose any restrictions on this.

[0116] The present invention also discloses a computer-readable storage medium, on which instructions are stored. When the instructions are executed by a processor, the processor is configured to execute the blockchain-based data interaction security and privacy protection method described in any one of the above embodiments.

[0117] Among them, the computer program can be stored in a machine-readable medium, the computer program includes computer program code, the computer program code can be in the form of source code, object code, executable file or certain middleware, etc. The machine-readable medium includes any entity or device that can carry the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal and software distribution medium, etc. It should be noted that the machine-readable medium includes but is not limited to the above-mentioned components.

[0118] Among them, through this computer-readable storage medium, the blockchain-based data interaction security and privacy protection method in the above embodiment is stored in a computer-readable storage medium, and is loaded and executed on a processor to facilitate the storage and application of the above method.

[0119] A person skilled in the art should understand that the discussion of any of the above embodiments is merely illustrative and is not intended to imply that the scope of protection of the present application is limited to these examples. In line with the concept of the present application, the technical features in the above embodiments or different embodiments may be combined, the steps may be implemented in any order, and there are many other variations of different aspects of one or more embodiments of the present application as above, which are not provided in detail for the sake of simplicity.

[0120] One or more embodiments of the present application are intended to cover all such substitutions, modifications and variations that fall within the broad scope of the present application. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of one or more embodiments of the present application should be included in the protection scope of the present application.

Claims

1. A data interaction security and privacy protection method based on blockchain, characterized in that: Applied to a data interaction management system, the data interaction management system includes a cloud server, a two-layer trusted execution environment hardware and a user-end server, the user-end server and the two-layer trusted execution environment hardware are both connected to the cloud server through a secure communication channel created based on an end-to-end encryption mechanism, and the method includes the following steps: Deploy multiple blockchain consensus nodes in the cloud server, and build a blockchain main chain in the cloud server based on all the blockchain consensus nodes; Deploy multiple blockchain computing nodes for processing different business types in the two-layer trusted execution environment hardware, and build multiple blockchain sub-chains in the two-layer trusted execution environment hardware based on all the blockchain computing nodes and according to the business types; Based on the cross-chain communication protocol and through the secure communication channel, a communication connection is established between all the blockchain sub-chains and the blockchain main chain to form a main chain-sub-chain architecture, and a cross-chain smart contract is deployed in the main chain-sub-chain architecture; Receive a data interaction request from a target user through the user-side server, and verify the user authentication identity contained in the data interaction request, wherein the user authentication identity is authenticated and issued by the blockchain computing node; If the verification is successful, the target user is granted data access rights or data upload rights in the main chain-subchain architecture according to the request type of the data interaction request, so that the target user can use the data access rights to access the target data stored in the main chain-subchain architecture, or use the data upload rights to upload the target data in the main chain-subchain architecture; Generate a data fingerprint of the target data during the data interaction process, generate a data operation log of the target data in combination with the data fingerprint and the data interaction request, and organize the data operation log into a log Merkle tree structure; A hierarchical storage architecture based on a directed acyclic graph is used to store all the target data and the log Merkle tree structure in a hierarchical manner in the main chain-subchain architecture.

2. The data interaction security and privacy protection method based on blockchain according to claim 1 is characterized in that: Before receiving the data interaction request sent by the target user through the user-side server, the method further includes the following steps: Deploy a neural network-based user information processing model in the dual-layer trusted execution environment hardware, wherein the user information processing model includes an information feature extraction module, an information integrity verification module, an information credibility verification module, a user type classification module, and a noise injection module; Obtaining, from the user client server, a user registration request sent by the user to be registered to the main chain-sub-chain architecture; Extracting user information from the user registration request, inputting the user information into the user information processing model for information verification, and outputting the user type of the user to be registered according to the user information that passes the information verification through the user information processing model; Randomly generate a user key of the user to be registered, and store the user key in the main chain-subchain architecture; Based on the user type, the user authentication identity of the user to be registered is generated through the cross-chain smart contract, and the user authentication identity is issued to the user to be registered using the blockchain computing node to complete the user registration of the user to be registered in the main chain-sub-chain architecture.

3. The data interaction security and privacy protection method based on blockchain according to claim 2 is characterized in that: The information feature extraction module is used to extract information field features and information anomaly association features from the user information. The last shared feature layer of the information feature extraction module is connected to the information integrity verification module, the information credibility verification module and the user type classification module respectively. The information integrity verification module is used to output the integrity probability of the user information according to the information field features. The information credibility verification module is used to output the credibility score of the user information according to the information anomaly association features. The user information processing model also includes a decision unit and a gating unit. The output layer of the information integrity verification module is connected to the decision unit, and the output layer of the information credibility verification module is respectively connected to the decision unit and the user type classification module. The output layer of the decision unit is connected to the gating unit, and the output layer of the gating unit is connected to the user type classification module. The decision unit is used to output the verification result of the user information in combination with the integrity probability and the credibility score. The gating unit is used to determine whether to output a module activation signal to the user type classification module according to the verification result. After receiving the module activation signal, the user type classification module is used to identify and output the user type corresponding to the user information in combination with the credibility score and the information field feature. The output layer of the user type classification module is connected to the noise injection module. The noise injection module is used to inject noise into the output result of the user type classification module based on the Laplace mechanism and according to a preset privacy budget. The information integrity verification module and the information credibility verification module exchange information through a multi-head attention mechanism.

4. The data interaction security and privacy protection method based on blockchain according to claim 2 is characterized in that: The storing of the user key in the main chain-subchain architecture comprises the following steps: Using Shamir's secret sharing algorithm to split the user key into n key fragments; Encrypting each of the key fragments using a homomorphic encryption algorithm; Select m blockchain computing nodes as trusted computing nodes according to the node status of the blockchain computing nodes, 2≤m<n; Distribute and store the encrypted key fragments to each of the trusted computing nodes; A threshold signature-based key reconstruction protocol is created for all the trusted computing nodes, wherein the key reconstruction protocol constrains that at least t trusted computing nodes are required to collaborate in the user key reconstruction process, where t≤m.

5. The data interaction security and privacy protection method based on blockchain according to claim 4 is characterized in that: The step of generating the user authentication identity of the user to be registered based on the user type and through the cross-chain smart contract comprises the following steps: Execute the cross-chain smart contract based on the user type to generate a verifiable credential for the user to be registered; Based on the user information, the user attributes of the user to be registered are generated by using an attribute description language that supports multi-dimensional access policy definition, and the attribute encryption of the user attributes is completed by using a CP-ABE encryption algorithm; Combining the verifiable credential and the encrypted user attribute into the user identity of the user to be registered; Adding a zero-knowledge range proof based authentication protocol for said user identity; The user key of the user to be registered is reconstructed from the main chain-subchain architecture, and the user identity is signed by the user key to obtain the user authentication identity of the user to be registered.

6. The data interaction security and privacy protection method based on blockchain according to claim 5 is characterized in that: The method further comprises the steps of: Counting the number of user authentication identities generated by the cross-chain smart contract; Whenever the generated quantity reaches a preset quantity threshold, the contract code of the cross-chain smart contract is parsed and semantically checked; The cross-chain smart contract is updated by combining the analysis and inspection results of the syntax analysis and the semantic inspection and by using preset adaptive update rules.

7. The data interaction security and privacy protection method based on blockchain according to claim 4 is characterized in that: Granting the target user data access authority or data upload authority in the main chain-subchain architecture according to the request type of the data interaction request, so that the target user can use the data access authority to access the target data stored in the main chain-subchain architecture, or use the data upload authority to upload the target data in the main chain-subchain architecture, comprises the following steps: Determining whether the request type of the data interaction request is a data upload request or a data access request; If it is the data upload request, grant the target user the data upload permission in the main chain-subchain architecture, and obtain the target data of the target user and the data access policy preset by the target user for the target data; If the target data is encrypted by the target user through the user key, the target data and the data access policy are packaged and sent to the blockchain subchain, and the data upload process of the target data is completed through the blockchain computing node; If the target data is not encrypted, the target data and the data access policy are packaged and sent to the blockchain main chain, and the data upload process of the target data is completed through the blockchain consensus node; If it is the data access request, determining and granting the data access right of the target user based on the user authentication identity of the target user; In combination with the data access permission and the data access policy of the stored data in the main chain-subchain architecture, the data storage location of the target data accessible to the target user is fed back to the target user.

8. The data interaction security and privacy protection method based on blockchain according to claim 1 is characterized in that: The dual-layer trusted execution environment hardware includes a hardware security module and a trusted execution environment hardware.

9. A data interaction security and privacy protection system based on blockchain, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the blockchain-based data interaction security and privacy protection method is implemented as described in any one of claims 1 to 8.

10. A computer-readable storage medium having instructions stored thereon, characterized in that: When the instruction is executed by a processor, the processor is configured to execute the blockchain-based data interaction security and privacy protection method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Private data protection and authorization framework based on double-layer chain

    CN115118435A

  • Block chain-based secure and trusted interactive computing system and device for cloud side end

    CN115297117A

  • Industrial data privacy protection method and system combining block chain and identifier analysis

    CN118586034A

  • A system and method to provide a privacy-preserving hardware secure enclave environment for generating blockchain verifiable transactions at scale

    WO2024236572A1

Cited By

  • Financial data privacy protection system based on block chain security multi-party computing

    CN120658399A

  • Adversarial sample generation method for improving adversarial robustness for code model

    CN120763944A

  • An adversarial sample generation method for improving adversarial robustness for a code model

    CN120763944B

  • Safe and credible interaction method for photovoltaic data

    CN120811799A

  • A secure and trusted interaction method of photovoltaic data

    CN120811799B