Data ownership transaction method and system based on block chain

By trading data ownership on the blockchain, combined with convergent encryption technology and elliptic curve cryptography technology, the problems of heavy data auditing, unreasonable deduplication and chaotic data maintenance in the existing data trading platforms have been solved, and data security, reduced fees and improved transaction efficiency have been achieved.

CN119995822APending Publication Date: 2025-05-13SUQIAN COLLEGE
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510047941.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-13
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing data ownership trading platforms have problems such as heavy data integrity audit verification, data deduplication does not comply with the on-demand pay-as-you-go model and user data isolation requirements, and may cause confusion during data maintenance and transactions.

Method used

Using a blockchain-based data ownership transaction method, by dividing the target file into file data blocks, using convergent encryption technology and elliptic curve cryptography technology to generate keys, tuples containing tags, keys and homomorphic verification tags are constructed, and uploaded to the blockchain for auditing and transactions.

Benefits of technology

It realizes data security, integrity and recovery, reduces users' outsourcing storage costs and audit calculation overhead, reduces communication overhead between users, and supports dynamic data operations and cloud data ownership transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995822A_ABST
    Figure CN119995822A_ABST
Patent Text Reader

Abstract

The invention discloses a block chain-based data ownership transaction method and system, and relates to the field of block chains. The method comprises the following steps: generating a secret key by utilizing a method of combining a convergence encryption technology and an elliptic curve cryptography technology, generating a label and a homomorphic verification label according to the secret key, and constructing a first tuple; uploading the first tuple to a CSP, creating a dynamic structure Merkel tree in the CSP, and constructing a second tuple according to the first tuple and the Merkel tree; after an auditing request is received, performing autonomous auditing based on the second tuple by using the block chain smart contract; and after the audit result is obtained, initiating a data query, data update or data transaction request to the CSP. By adopting the method, the existing on-demand payment mode is not violated, the storage cost and the storage pressure of the cloud are saved from the perspective of the user, single-user multi-file data de-duplication is realized, and block-level de-duplication is further realized. And meanwhile, the cloud server can realize user data isolation and data post-maintenance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of blockchain technology, and in particular to a data ownership transaction method and system based on blockchain. Background Art

[0002] In the era of big data, the amount of data is growing explosively. In order to effectively save local storage space, many users often choose to outsource the storage of large amounts of data. Cloud servers play a key role in this process, providing users with data storage services and charging corresponding fees based on factors such as the amount of stored data and service duration.

[0003] By utilizing the storage resources of cloud servers and combining them with blockchain technology, a secure and reliable data ownership trading platform can be built.

[0004] However, existing trading platforms still have the following problems:

[0005] 1. Data integrity audit verification is undertaken by users or third-party organizations, which is a heavy task and difficult to achieve in practice;

[0006] 2. The data deduplication solution is to deduplicate files across users, which does not conform to the actual pay-as-you-go model, and the deduplication between multiple files of a single user does not meet the user data isolation requirements;

[0007] 3. Data deduplication solutions require cloud servers to retain only one copy of data, which may cause confusion during data maintenance and transactions. Summary of the invention

[0008] Based on this, it is necessary to provide a data ownership transaction method and system based on blockchain to address the above technical issues, ensuring the security, integrity and recoverability of outsourced data, and minimizing the user's outsourcing storage costs and audit computing overhead. In addition, during data transactions, by updating data ownership on the cloud server side, the communication overhead between users is reduced.

[0009] In the first aspect, the present application provides a data ownership transaction method based on blockchain. The method comprises:

[0010] Divide the target file into several file data blocks, generate keys corresponding to the target file and each file data block by combining convergent encryption technology with elliptic curve cryptography technology, generate labels and homomorphic verification labels according to the keys, and construct a first tuple including the labels, keys and homomorphic verification labels;

[0011] Upload the first tuple to CSP, create a dynamic structure Merkle tree in CSP, build the second tuple based on the first tuple and the Merkle tree, upload the second tuple to the blockchain, and delete the local target file, retaining the local label and key;

[0012] After receiving the audit request, the blockchain smart contract is used to conduct an autonomous audit based on the second tuple, and the audit results are published to the blockchain;

[0013] After obtaining the audit results, initiate data query, data update or data transaction requests to the CSP.

[0014] In one embodiment, the generation of the key includes:

[0015] Select a point on the elliptic curve as a generator, where the order of the selected point is a prime number;

[0016] Generate the private key corresponding to the target file using the hash value of the target file, and generate the public key corresponding to the target file based on the private key corresponding to the target file;

[0017] Generate corresponding private keys and public keys for the public fragments and private fragments in the file data block respectively;

[0018] Among them, each file data block is divided into a public segment and a private segment according to the data type.

[0019] In one embodiment, the generation of the tag includes:

[0020] Generate a file tag using the public key corresponding to the target file;

[0021] The hash values ​​of the public segment and the private segment are used to generate the public segment label and the private segment label.

[0022] In one embodiment, constructing a first tuple including a tag, a key, and a homomorphic verification tag includes:

[0023] Divide each file data block into a series of ordered groups containing several data blocks, and calculate the homomorphic verification label corresponding to each ordered group;

[0024] Generate a first tuple including a file label, a public segment label, a private segment label, a homomorphic verification label corresponding to the public segment, a homomorphic verification label corresponding to the private segment, a homomorphic verification label corresponding to the ordered group, and a key.

[0025] In one embodiment, after uploading the first tuple to the CSP, the method further includes:

[0026] According to the tag corresponding to the target file, check whether there is a file with the same tag stored locally; if not, check the tag corresponding to the file data block to find the unique file data block tag;

[0027] Get the file data block set corresponding to the unique file data block tag, and use CSP to verify according to the homomorphic verification tag corresponding to the file data block set; if the verification is successful, store the file data block set in CSP and enable the blockchain smart contract.

[0028] In one embodiment, after receiving the audit request, using the blockchain smart contract to perform an autonomous audit based on the second tuple, and publishing the audit result to the blockchain includes:

[0029] The blockchain smart contract generates an audit challenge after receiving an audit request; the audit challenge includes the index and calculation parameters of several challenge data blocks generated by a pseudo-random number function, and the aggregated authentication generated according to the index and calculation parameters;

[0030] The CSP obtains the audit challenge, generates an integrity proof for the challenge data block, and publishes the integrity proof to the blockchain smart contract;

[0031] The blockchain smart contract verifies the validity of the integrity proof based on the integrity proof and aggregate authentication, obtains the audit results, and publishes the audit results to the blockchain.

[0032] In one embodiment, the data query request includes:

[0033] The local tag is sent to the CSP, which queries the key of the corresponding target file based on the tag, uses the local key to restore the file data block key, restores the file data block based on the file data block key, and obtains the target file based on the file data block.

[0034] In one embodiment, data updating includes:

[0035] After modifying the target file obtained through the data query request, recalculate the corresponding label, key and homomorphic verification label after the modification, and update the Merkle tree and the second tuple; use the blockchain to verify the root node of the Merkle tree, and complete the data modification when the verification passes;

[0036] After deleting the target file obtained through the data query request, recalculate the corresponding label and key after deletion, update the Merkle tree and the second tuple; use the blockchain to verify the root node of the Merkle tree, and complete the data deletion when the verification passes;

[0037] After inserting the target file obtained through the data query request, recalculate the corresponding label and key after insertion, update the Merkle tree and the second tuple; use the blockchain to verify the root node of the Merkle tree, and complete the data insertion when the verification passes.

[0038] In one embodiment, the data transaction includes:

[0039] The transferor sends a transfer request to the CSP. After verifying the transferor's identity, the CSP updates the ownership information, recalculates the homomorphic verification label corresponding to the transferred file data block, and updates the second tuple. The transferor sends the label corresponding to the transferred target file, the label corresponding to the transferred file data block, and the key to the transferee through the off-chain secure channel.

[0040] In the second aspect, the present application also discloses a data ownership transaction system based on blockchain, the system comprising:

[0041] A privacy processing module, used for dividing a target file into a number of file data blocks, generating keys corresponding to the target file and each file data block by combining convergent encryption technology with elliptic curve cryptography technology, generating a label and a homomorphic verification label according to the key, and constructing a first tuple including the label, the key and the homomorphic verification label;

[0042] A duplicate check module is used to upload the first tuple to the CSP, create a dynamic structure Merkle tree in the CSP, construct the second tuple according to the first tuple and the Merkle tree, upload the second tuple to the blockchain, and delete the local target file, retaining the local label and key;

[0043] An audit module, configured to, after receiving an audit request, perform an autonomous audit based on the second tuple using a blockchain smart contract, and publish the audit result to the blockchain;

[0044] The application module is used to initiate data query, data update or data transaction requests to the CSP after obtaining the audit results.

[0045] The above-mentioned blockchain-based data ownership transaction method and system not only provides a new homomorphic verification tag, but also proposes a comprehensive solution that supports user multi-copy storage, duplicate data deletion, data dynamic operation and cloud data ownership transaction, in order to meet the needs and challenges of users for cloud storage services in the era of big data. This solution not only supports user multi-copy storage, but also can perform integrity audits combining plaintext and ciphertext while ensuring data security, realizes user-facing duplicate data deletion, and also meets the different changes in user needs, supporting data dynamic operation and cloud data ownership transactions. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] Figure 1 This is an application environment diagram of a data ownership transaction method based on blockchain in one embodiment;

[0047] Figure 2 Schematic diagram of a process for data ownership transaction based on blockchain in one embodiment. DETAILED DESCRIPTION

[0048] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0049] In the existing outsourced storage method using cloud servers, facing a large amount of data from multiple users, some data may be lost or damaged when the cloud server stores the data. At this time, in order to protect its own interests, the cloud server may behave dishonestly and claim to the user that the data is still intact in the cloud server. After uploading the data to the cloud server for storage, the user will lose direct control over the outsourced data, and thus worry about whether the cloud server stores their data correctly and completely and whether the privacy of the data is leaked. To address this problem, many integrity audit schemes have been proposed, and users can verify the integrity of the data stored in the cloud server. However, most integrity design schemes either require users to bear the heavy audit verification, or have a trusted third-party organization act as an auditor, which is difficult to achieve in practical applications. Therefore, it is necessary to propose a lightweight security integrity audit scheme on the user side.

[0050] At the same time, in the process of data outsourcing, users usually do not keep data copies in order to reduce the pressure on local storage space. As a result, once the data on the cloud server is damaged or lost, users will face the dilemma of difficulty in restoring the original data. To avoid such problems, users can adopt a multi-copy storage strategy, that is, upload the same data file to multiple different cloud servers. In this way, even if the data on some cloud servers is damaged, users can still restore the original data through the data fully saved in other cloud servers. However, for cloud service providers, storing duplicate data will increase the burden. At present, the proposed outsourced deduplication scheme aims to save storage resources on the cloud server side. Its core is to delete duplicate data uploaded by different users. However, this design has defects: (1) Existing cloud storage services follow a pay as you go model, that is, cloud services charge users according to the size of data and storage time. In order to control costs, it is necessary to remove duplicate data. Existing deduplication schemes implement cross-user file deduplication, which does not conform to the actual pay as you go model because it repeatedly pays for the storage space of duplicate data blocks according to multiple users. In addition, deduplication between multiple files of a single user does not meet the user data isolation requirements. (2) If multiple users store the same data, the existing deduplication solution requires that only one copy be stored in the cloud. Subsequent maintenance of the data will cause difficulties because different users may process the same data differently. As user needs change, users need to modify, delete, and add data stored on the cloud server. In addition, different users may conduct buy and sell transactions to change data ownership, and this model of keeping only one copy will also cause confusion.

[0051] In response to the above problems, this application proposes a data ownership transaction method based on blockchain. Figure 1 As shown in FIG. 1 , it is a schematic diagram of the application environment of the method disclosed in this application, which includes three entities: users, CSPs (Cryptographic Service Providers) and blockchains. First, users check whether the data is duplicated with CSPs through blockchains, and then upload the unique data after deduplication to different CSPs respectively ( Figure 1 The data includes the plain text of public data and the encrypted ciphertext of private data. After verifying the user's identity, CSP uploads and stores transaction information to the blockchain. The user submits an audit request to the smart contract, the smart contract initiates an integrity audit challenge, CSP calculates the data integrity proof, the smart contract verifies, and records the audit results to the blockchain. If the user needs to perform dynamic data operations, he sends a request to the blockchain, and CSP updates the data. When data transactions are conducted between users ( Figure 1Taking users 1 and 2 as examples, the original data owner, i.e., user 1, needs to send an ownership transfer request to the blockchain. After receiving the request from the blockchain, the CSP updates the user's ownership and records it on the blockchain. The data purchaser, i.e., user 2, can use the key obtained through off-chain communication from user 1 to recover the data.

[0052] The data ownership trading method based on blockchain disclosed in this application, as Figure 2 shown, includes the following steps:

[0053] S1. System setup.

[0054] The user executes an initialization algorithm to initialize a storage system. First, two multiplicative cyclic groups G1 and G2 of order p are selected, and a bilinear mapping e: G1×G1→G2 is constructed. Next, a generator g and a random element r are selected from G1, and three hash functions H2: {0,1} * →G1 and Two pseudo-random functions Finally, the user publishes the public parameters {G1, G2, p, e, g, r, H1, H2} to the blockchain.

[0055] S2. Key generation.

[0056] The user divides the file to be uploaded into blocks F = F1‖F2, where F1 = m1‖…‖m k represents the publicly available fragments in the data, and F2 = m k+1 ‖…‖m n represents the non-public privacy fragments in the data.

[0057] The user generates a key using the Secp256k1 elliptic curve E. First, a point G on the elliptic curve is selected as the generator, where the order of G is a prime number n. The user generates a private key sk = H1(F) for the file using the hash value of the file, sk < n, and then generates a public key Q = skG. Similarly, the user generates private keys for the file data blocks. The private key for the publicly available fragments is k i = H1(m i ), and the public key Q i = k i G, where 1 ≤ i ≤ k. The private key for the privacy fragments is k j = H1(m j ), and the public key Q j = k j G, where 1 ≤ j ≤ n.

[0058] S3. Tag generation.

[0059] The user first generates a file tag t = gQ , and then use the hash values ​​of the public fragment and the private fragment to generate the data block label.

[0060] The public fragment data block tag is tm i =H1 ( m i ) , the privacy fragment data block label is tc j =H1 ( c j ) , where c j =Enc(Q j ,m j ). Next, generate homomorphic verification tags and divide the n data blocks into a series of ordered groups Tp containing N data blocks group , calculate the homomorphic verification label for each ordered group in

[0061] Finally, the user obtains the uploaded data S after privacy protection. i ,c j ], file label t, data block label T = {tm i ,tc j}, homomorphic verification label σ={σ group}, data key Key = Enc(sk,Q j ).

[0062] S4. Repeat the check.

[0063] The user selects a suitable CSP (taking CSP1 and CSP2 as examples) for data storage.

[0064] First, the user will repeat the check tuple, that is, the first tuple<t,T,σ,Key> The transaction is sent to CSP through the off-chain secret channel. CSP first checks whether there is a file with the same tag stored locally based on the file tag t. If the same file is already stored, the storage transaction is terminated. Otherwise, according to T i ∈T Check the data block labels and find the unique data block label set t u , and t u Return to user.

[0065] The user uploads a unique data block set S u , and upload the corresponding storage fee fee1 and audit fee fee2 to the blockchain smart contract according to the data block size. CSP receives the unique data block set S u After that, the ordered group homomorphic authentication tag is calculated Verify user uploaded σ N, if it passes the verification, CSP stores the dataset S u and tuples <t,T,t u ,σ,Key>, upload the deposit Fee=2fee1 to the blockchain smart contract. If the verification fails, the transaction is terminated.

[0066] After storing the data, CSP creates a dynamic structure Merkle Hash Tree (MHT). Each leaf node w stores the label of the ordered group. The remaining internal nodes and the root node are aggregated by their child nodes in pairs, and finally the root node w is obtained. r .

[0067] Finally, CSP uploads the second tuple <t,t u ,σ,U,CSP,w r >To the blockchain, the user deletes the local file and only keeps the tuple <t,t u ,sk> for subsequent access.

[0068] S5. Challenge generation.

[0069] After receiving the user audit request, the blockchain smart contract generates an audit challenge Chal = (z, r1, r2), where z, r1, r2 are all random numbers, z∈[1,N], Use a pseudo-random number function to generate the index u of z challenge data blocks i =f1(i,r1) and calculate the parameter v i =f2(i,r2), and generate group aggregation authentication Finally, the smart contract publishes the challenge Chal to the blockchain.

[0070] S6. Proof generation.

[0071] After CSP obtains the audit challenge Chal from the blockchain, it generates an integrity proof based on the queried data block. in, The challenged data block. Finally, CSP publishes the integrity proof Proof to the blockchain.

[0072] S7. Proof verification.

[0073] After the smart contract obtains the integrity proof from the blockchain, Verify the validity of the integrity proof. If the equation holds, it proves that the CSP saves complete data and passes the audit. Otherwise, it proves that the data has been damaged or lost. Finally, the smart contract will audit the results.<Proof,integral> or<Proof,non-integral> Published to the blockchain.

[0074] S8. Restore data.

[0075] The user will <t,t u >Send the request data to CSP, CSP will <t,t u >Query the corresponding data and key and return it to the user<S,Key> The user uses the locally stored file key sk to recover the data block key Q j = Dec(sk,Key), and then restore the encrypted data m j = Dec(Q j ,c j ), and finally get the original data file F=F1‖F2.

[0076] S9. Update data.

[0077] The user initiates a data update request to the CSP, including modifying data, deleting data, and adding data.

[0078] After the user restores the original file, if the data is modified, the modified file label t′=g is recalculated Q′ , where Q′=sk′G,sk′=H1(F′), and the publicly available fragment private key in the modified data block is k′ i =H1(m′ i ), public key Q′ i = k′ i G, where 1≤i≤k, and the private key of the private fragment is k j ′=H1(m j ′), public key Q j ′=k j 'G, where 1≤j≤n', n' is the number of modified data blocks, and the index set of the modified data blocks is I. Then calculate the publicly available fragment data block label in the modified data block as t' i =H1(m′ i ), the privacy fragment data block label is t j ′=H1(c j ′), where c j ′=Enc(Q j ′,m j ′). Then calculate the homomorphic verification label of the ordered group in t′ v ∈TP′ group Finally, the user will <t,t′,T′={tm′ i ,tc j ′},σ′={σ′ group},Key′=Enc(sk′,Q j′), I> and the modified data S′={m′ i ,c j ′} to CSP. CSP queries the corresponding file through the file tag t, verifies the homomorphic authentication tag and updates the data block, tag information and MHT. <t',t u ,σ′,U,CSP,w′ r >Upload to the blockchain. The blockchain is responsible for the root node w′ of MHT r Verification is performed, and passing the verification proves that the CSP has honestly completed the data update.

[0079] After the user restores the original file, if the data is deleted, the deleted file label t′=g is recalculated Q′ , where Q′=sk′G,sk′=H1(F′), the index set I of the deleted data block. Finally, the user will<t′,I> Send it to CSP. CSP queries the corresponding file through the file label t, deletes the data block and its label, and recalculates the root node w′ r , the updated tuple <t′,t′ u ,σ′,U,CSP,w′ r >Upload to the blockchain, which verifies the update.

[0080] The process of adding data is similar to uploading data and will not be introduced here.

[0081] S10. Change of ownership.

[0082] When user 1 wants to transfer the ownership of cloud data to user 2, user 1 sends an ownership transfer request to CSP. CSP verifies the user's identity, updates the data ownership information, and recalculates the homomorphic verification tag. The homomorphic verification tag of the ordered group Finally, CSP converts the tuple <t,t u ,σ2,U2,CSP> is uploaded to the blockchain.

[0083] User 1 sends the tuple through the off-chain secure channel <t,t u ,sk> is sent to user 2 for subsequent data access.

[0084] In summary, this application has the following three innovative features:

[0085] (1) This application combines convergent encryption technology (MLE) with elliptic curve cryptography (ECC) to design homomorphic verification tags to achieve single-user deduplication at the block level and file level, while supporting mixed auditing of plaintext and ciphertext, effectively protecting data privacy and saving user-side overhead compared to pure ciphertext auditing. This design is more in line with the pay-as-you-go cloud application model. Compared with existing cloud-based deduplication technology, this application deduplicates multiple files among a single user while meeting the needs of user data isolation. This is because retaining only one copy of the data cannot meet subsequent data maintenance and ownership transaction needs, nor can it require multiple users to pay repeatedly for the storage space of the same data block.

[0086] (2) This application combines blockchain technology and introduces smart contracts to design a spontaneous audit mechanism, thereby abandoning the traditional trusted third-party audit (TPA) and making it easier to apply in practice. Compared with the traditional audit method that relies on TPA, the introduction of smart contracts realizes spontaneous audits and publishes the parameters of the audit process on the blockchain, making it easier for users to trace historical audit records. Compared with the existing solution of migrating data to the blockchain, the audit method proposed in this application facilitates users to maintain data and conduct ownership transactions because the maintenance cost of storing data on the blockchain is relatively high.

[0087] (3) This application combines ECC signatures with improved MHT to achieve dynamic operations on user data and transactions of data ownership. While ensuring the isolation of user data, efficient deduplication and integrity auditing are achieved at the same time. By combining MLE technology and ECC technology, this application achieves block-level identification and verifiable homomorphic tags, and combines MHT with hashing ideas based on block content to achieve user maintenance of cloud data. Further, by designing original verifiable tags, data can be traded directly in the cloud, saving the user's previous download and upload costs, and achieving efficient conversion of data ownership.

[0088] Compared with the prior art, the positive effects of this application include:

[0089] (1) Providing data privacy protection

[0090] The present invention provides data privacy protection for outsourced data. The private data is encrypted and protected before uploading to the cloud server to prevent the private data from being leaked during the outsourcing and auditing process.

[0091] (2) Deduplication

[0092] From the user's perspective, the present invention realizes outsourced duplicate data deletion, saving the user's expenses in outsourced data storage.

[0093] (3) Realize autonomous audit

[0094] The present invention utilizes the smart contract of blockchain to realize autonomous auditing, removes the restriction of requiring a trusted third party, and reduces the computing overhead on the user side.

[0095] (4) Support data dynamics

[0096] The present invention combines MHT to realize dynamic data operation based on blockchain, supporting users to access, modify, delete, insert and other operations on data more flexibly.

[0097] (5) Realizing data ownership transactions

[0098] The present invention realizes data ownership transactions between different users, and only updates data ownership on the cloud server side, thereby reducing communication overhead between users.

[0099] (6) Reduce computing and communication overhead

[0100] The present invention effectively reduces the computation and communication overhead in the process of data auditing and updating by dividing the data blocks into zones.

[0101] (7) Security is provable

[0102] In the present invention, any unauthorized entity cannot challenge the cloud server, and a dishonest cloud server cannot pass the integrity verification by forgery or the like.

[0103] It should be understood that, although the steps in the flowcharts involved in the above embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps is not strictly limited in order, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.

[0104] Based on the same inventive concept, the embodiment of the present application also provides a blockchain-based data ownership transaction system for implementing the blockchain-based data ownership transaction method involved above. The implementation solution provided by the system to solve the problem is similar to the implementation solution recorded in the above method, so the specific limitations in one or more blockchain-based data ownership transaction system embodiments provided below can refer to the limitations of the blockchain-based data ownership transaction method above, and will not be repeated here.

[0105] In one embodiment, a data ownership transaction system based on blockchain is provided, including: a privacy processing module, which is used to divide a target file into a plurality of file data blocks, generate a key corresponding to the target file and each file data block by combining convergent encryption technology with elliptic curve cryptography technology, generate a label and a homomorphic verification label according to the key, and construct a first tuple including the label, the key and the homomorphic verification label;

[0106] A duplicate check module is used to upload the first tuple to the CSP, create a dynamic structure Merkle tree in the CSP, construct the second tuple according to the first tuple and the Merkle tree, upload the second tuple to the blockchain, and delete the local target file, retaining the local label and key;

[0107] An audit module, configured to, after receiving an audit request, perform an autonomous audit based on the second tuple using a blockchain smart contract, and publish the audit result to the blockchain;

[0108] The application module is used to initiate data query, data update or data transaction requests to the CSP after obtaining the audit results.

[0109] Each module in the above-mentioned blockchain-based data ownership transaction system can be implemented in whole or in part through software, hardware, or a combination thereof. Each of the above-mentioned modules can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in a computer device in the form of software, so that the processor can call and execute the operations corresponding to each of the above modules.

[0110] In one embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the steps in all the above method embodiments when executing the computer program.

[0111] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in all the above method embodiments are implemented.

[0112] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in all the above method embodiments when executed by a processor.

[0113] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards of relevant countries and regions.

[0114] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., but are not limited to this.

[0115] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0116] The above embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.

Claims

1. A data ownership transaction method based on blockchain, characterized in that: Methods include: Divide the target file into several file data blocks, generate keys corresponding to the target file and each file data block by combining convergent encryption technology with elliptic curve cryptography technology, generate labels and homomorphic verification labels according to the keys, and construct a first tuple including the labels, keys and homomorphic verification labels; Upload the first tuple to CSP, create a dynamic structure Merkle tree in CSP, build the second tuple based on the first tuple and the Merkle tree, upload the second tuple to the blockchain, and delete the local target file, retaining the local label and key; After receiving the audit request, the blockchain smart contract is used to conduct an autonomous audit based on the second tuple, and the audit results are published to the blockchain; After obtaining the audit results, initiate data query, data update or data transaction requests to the CSP.

2. The method according to claim 1, characterized in that The key generation includes: Select a point on the elliptic curve as a generator, where the order of the selected point is a prime number; Generate the private key corresponding to the target file using the hash value of the target file, and generate the public key corresponding to the target file based on the private key corresponding to the target file; Generate corresponding private keys and public keys for the public fragments and private fragments in the file data block respectively; Among them, each file data block is divided into a public segment and a private segment according to the data type.

3. The method according to claim 2, characterized in that The generation of labels includes: Generate a file tag using the public key corresponding to the target file; The hash values ​​of the public segment and the private segment are used to generate the public segment label and the private segment label.

4. The method according to claim 3, characterized in that Constructing the first tuple containing the tag, key, and homomorphic verification tag involves: Divide each file data block into a series of ordered groups containing several data blocks, and calculate the homomorphic verification label corresponding to each ordered group; Generate a first tuple including a file label, a public segment label, a private segment label, a homomorphic verification label corresponding to the public segment, a homomorphic verification label corresponding to the private segment, a homomorphic verification label corresponding to the ordered group, and a key.

5. The method according to claim 1, characterized in that After uploading the first tuple to the CSP, the method further includes: According to the tag corresponding to the target file, check whether there is a file with the same tag stored locally; if not, check the tag corresponding to the file data block to find the unique file data block tag; Get the file data block set corresponding to the unique file data block tag, and use CSP to verify according to the homomorphic verification tag corresponding to the file data block set; if the verification is successful, store the file data block set in CSP and enable the blockchain smart contract.

6. The method according to claim 1, characterized in that After receiving the audit request, the blockchain smart contract is used to conduct an autonomous audit based on the second tuple, and the audit results are published to the blockchain, including: The blockchain smart contract generates an audit challenge after receiving an audit request; the audit challenge includes the index and calculation parameters of several challenge data blocks generated by a pseudo-random number function, and the aggregated authentication generated according to the index and calculation parameters; The CSP obtains the audit challenge, generates a proof of integrity for the challenge data block, and publishes the proof of integrity to the blockchain smart contract; The blockchain smart contract verifies the validity of the integrity proof based on the integrity proof and aggregate authentication, obtains the audit results, and publishes the audit results to the blockchain.

7. The method according to claim 1, characterized in that Data query requests include: The local tag is sent to the CSP, which queries the key of the corresponding target file based on the tag, uses the local key to restore the file data block key, restores the file data block based on the file data block key, and obtains the target file based on the file data block.

8. The method according to claim 1, characterized in that Data updates include: After modifying the target file obtained through the data query request, recalculate the corresponding label, key and homomorphic verification label after the modification, and update the Merkle tree and the second tuple; use the blockchain to verify the root node of the Merkle tree, and complete the data modification when the verification passes; After deleting the target file obtained through the data query request, recalculate the corresponding label and key after deletion, update the Merkle tree and the second tuple; use the blockchain to verify the root node of the Merkle tree, and complete the data deletion when the verification passes; After inserting the target file obtained through the data query request, recalculate the corresponding label and key after insertion, update the Merkle tree and the second tuple; use the blockchain to verify the root node of the Merkle tree, and complete the data insertion when the verification passes.

9. The method according to claim 1, characterized in that Data transactions include: The transferor sends a transfer request to the CSP. After verifying the transferor's identity, the CSP updates the ownership information, recalculates the homomorphic verification label corresponding to the transferred file data block, and updates the second tuple. The transferor sends the label corresponding to the transferred target file, the label corresponding to the transferred file data block, and the key to the transferee through the off-chain secure channel.

10. A data ownership transaction system based on blockchain, characterized in that: The system includes: A privacy processing module, used for dividing a target file into a number of file data blocks, generating keys corresponding to the target file and each file data block by combining convergent encryption technology with elliptic curve cryptography technology, generating a label and a homomorphic verification label according to the key, and constructing a first tuple including the label, the key and the homomorphic verification label; A duplicate check module is used to upload the first tuple to the CSP, create a dynamic structure Merkle tree in the CSP, construct the second tuple according to the first tuple and the Merkle tree, upload the second tuple to the blockchain, and delete the local target file, retaining the local label and key; An audit module, configured to, after receiving an audit request, perform an autonomous audit based on the second tuple using a blockchain smart contract, and publish the audit result to the blockchain; The application module is used to initiate data query, data update or data transaction requests to the CSP after obtaining the audit results.