Block chain-based distributed data sharing method, system and device and server
By receiving and storing encryption policies and data on the blockchain, verifying user permissions, and using authoritative organizations' signature lists and zero-knowledge proofs, data privacy and security issues in distributed data sharing on the blockchain are solved, and data security, efficient sharing and traceability of behavior are achieved.
Patent Information
- Application Number
- CN202411949975.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-26
- Publication Date
- 2025-05-23
AI Technical Summary
When implementing distributed data sharing on blockchain, we face data privacy and security issues. Sensitive information may be leaked during the sharing process. Smart contracts and cyber attacks may lead to data tampering or loss, and it is difficult to ensure that data privacy is not leaked, and responsibility tracing is difficult.
By receiving and storing encryption policies and encrypted data, verifying the user's permissions to read data, using the authoritative organization's attribute signature list and zero-knowledge proof to ensure that the data is only decrypted by authorized users, and recording all operations through blockchain proof storage, ensuring transparency and traceability of data sharing.
It effectively guarantees data privacy and security, realizes the traceability of behavior, ensures that distributed data sharing can be achieved safely and efficiently, and improves the standardization and controllability of data sharing.
Smart Images

Figure CN120030586A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of blockchain technology, and in particular to a distributed data sharing method, system, device and server based on blockchain. Background Art
[0002] In the blockchain field, the importance of data sharing is self-evident. It greatly promotes transparency, enhances trust and improves efficiency. The decentralized nature ensures that all parties can access and verify data equally, effectively reducing information asymmetry and further accelerating the transaction process. In key areas such as financial services and supply chain management, real-time sharing of data has become an important means to accelerate decision-making processes, optimize resource allocation and reduce costs.
[0003] However, there are also many risks in the process of implementing distributed data sharing on the blockchain. Among them, data privacy and security are key issues. Sensitive information may face the risk of leakage during the sharing process. Smart contracts and network attacks may cause data to be tampered with or lost. When multiple parties participate in data sharing, it is difficult to ensure that data privacy is not leaked. Once there is a problem with the data, it is difficult to quickly and accurately locate the source of the problem and conduct effective responsibility tracing.
[0004] In view of this, how to ensure data privacy and security, achieve behavior traceability, and ensure that distributed data can be shared safely and efficiently among users is an issue that needs to be urgently addressed. Summary of the invention
[0005] In view of this, the embodiments of the present application provide a distributed data sharing method, system, device and server based on blockchain, which can ensure data privacy and security, achieve behavior traceability, and ensure that distributed data sharing can be achieved safely and efficiently among users.
[0006] A first aspect of an embodiment of the present application provides a distributed data sharing method based on blockchain, which is applied to a blockchain platform. The method includes:
[0007] Receive and store the encryption strategy and encrypted data sent by the data encryption user, wherein the encryption strategy is constructed by the data encryption user based on the attributes in the attribute set on the blockchain platform, and the encryption strategy is used by the data encryption user to encrypt the original data to obtain the encrypted data;
[0008] Receive the data decryption application submitted by the data reader calling the smart contract, and verify whether the data reader meets the attribute requirements in the corresponding encryption policy based on the attribute signature list uploaded by the authority and the zero-knowledge proof in the data decryption application;
[0009] If the data reading user meets the attribute requirements in the corresponding encryption policy, a decryption application event is triggered and broadcast. The decryption application event is used to instruct the authority to generate an attribute key corresponding to the data decryption application and send the attribute key to the data reading user so that the data reading user can decrypt the encrypted data according to the attribute key.
[0010] In a possible implementation manner of the first aspect, before receiving and storing the encryption policy and encrypted data sent by the data encryption user, the method further includes:
[0011] Obtaining the attribute application submitted by the user by calling the smart contract, wherein the attribute application includes the attribute to be applied encrypted according to the public key of the authority;
[0012] Trigger and broadcast a user attribute application event, wherein the user attribute application event is used to instruct the authority to decrypt the attribute to be applied for based on the institution's private key and then approve it, and feedback the attribute application approval result;
[0013] Receive the attribute application approval result fed back by the authority based on the user attribute application event.
[0014] In a possible implementation manner of the first aspect, the user attribute application event includes an institution identifier specified by a user and a user address of the user; and the authoritative institution decrypts the attribute to be applied for based on an institution private key and then performs approval, including:
[0015] The authority corresponding to the organization identifier verifies whether the user address matches the user public key of the user;
[0016] If the user address matches the user public key of the user, the attribute application is approved;
[0017] Alternatively, if the user address matches the user public key of the user, verify whether the user is a user supported by the service;
[0018] If the user is a user supported by the service, the attribute application is approved.
[0019] In a possible implementation manner of the first aspect, the receiving the attribute application approval result fed back by the authority based on the user attribute application event includes:
[0020] If the attribute application is approved, receiving the attribute signature list uploaded by the authority, wherein the attribute signature list is obtained by signing the attributes of the attribute application approved by the authority;
[0021] If the attribute application is not approved, the result of the attribute application not being approved uploaded by the authoritative organization is received.
[0022] In a possible implementation manner of the first aspect, the method further includes:
[0023] Obtaining a registration application and an institution public key submitted by an authority, wherein the registration application is used to register attributes supported by the authority;
[0024] The registration application is reviewed, and if the review is passed, the attributes supported by the authoritative organization and their corresponding organization public keys are stored.
[0025] In a possible implementation of the first aspect, the decryption application event is also used to instruct the authority to obtain the user public key of the data reader from the blockchain platform before sending the attribute key to the data reader, encrypt the attribute key according to the user public key, and send the encrypted attribute key to the data reader.
[0026] In the embodiment of the present application, the encrypted data and the encryption strategy are stored on the chain, and the blockchain platform verifies the authority of the data reading user by combining the zero-knowledge proof in the data decryption application of the attribute signature list of the authority, allowing the data reading user to prove that he meets the attribute requirements without disclosing his specific privacy information, which not only protects the user's privacy, but also makes the verification process accurate. At the same time, with the help of the credibility of the authority and the authority of the attribute signature list, it can effectively prevent unauthorized users from obtaining data, avoid the chaos of authority management, and enable data sharing to be carried out strictly in accordance with the preset rules and permissions, thereby improving the standardization and controllability of data sharing. Moreover, the operations of each participating entity are recorded on the blockchain and cannot be tampered with, which establishes a transparent and traceable collaborative environment for all parties. Any participating entity can verify the fairness of data access control, thereby ensuring that distributed data sharing can be achieved safely and efficiently among users.
[0027] A second aspect of an embodiment of the present application provides a distributed data sharing device based on blockchain, which is applied to a blockchain platform, and the device includes:
[0028] An encryption application processing unit, used to receive and store an encryption strategy and encrypted data sent by a data encryption user, wherein the encryption strategy is constructed by the data encryption user based on the attributes in the attribute set on the blockchain platform, and the encryption strategy is used by the data encryption user to encrypt the original data to obtain the encrypted data;
[0029] A decryption application processing unit is used to receive a data decryption application submitted by a data reader calling a smart contract, and verify whether the data reader meets the attribute requirements in the corresponding encryption policy based on the attribute signature list uploaded by the authority and the zero-knowledge proof in the data decryption application;
[0030] A data sharing unit is used to trigger and broadcast a decryption application event if the data reading user meets the attribute requirements in the corresponding encryption policy. The decryption application event is used to instruct an authority to generate an attribute key corresponding to the data decryption application and send the attribute key to the data reading user so that the data reading user can decrypt the encrypted data according to the attribute key.
[0031] A third aspect of the embodiments of the present application provides a distributed data sharing system based on blockchain, the system comprising a data encryption user, a data reading user, an authority, and a blockchain platform, wherein:
[0032] The data encryption user is used to construct an encryption strategy based on the attributes in the attribute set on the blockchain platform, the encryption strategy is used to encrypt the original data to obtain encrypted data, and send the encryption strategy and the encrypted data to the blockchain platform;
[0033] The blockchain platform is used to receive and store the encryption strategy and the encrypted data sent by the data encryption user;
[0034] The data reading user is used to send a decryption application to the blockchain platform;
[0035] The blockchain platform is also used to receive a data decryption application submitted by a data reader calling a smart contract, and verify whether the data reader meets the attribute requirements in the corresponding encryption policy based on the attribute signature list uploaded by the authority and the zero-knowledge proof in the data decryption application; if the data reader meets the attribute requirements in the corresponding encryption policy, a decryption application event is triggered and broadcast;
[0036] The authority is used to monitor the decryption application event, and after monitoring the decryption application event, generates an attribute key corresponding to the data decryption application, and sends the attribute key to the data reading user;
[0037] The data reading user is also used to decrypt the encrypted data according to the attribute key.
[0038] A fourth aspect of the embodiments of the present application provides a server, including a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, the steps of the blockchain-based distributed data sharing method provided in the first aspect of the embodiments of the present application are implemented.
[0039] A fifth aspect of the embodiments of the present application provides a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the steps of the blockchain-based distributed data sharing method provided in the first aspect of the embodiments of the present application are implemented.
[0040] A sixth aspect of the embodiments of the present application provides a computer program product. When the computer program product runs on a server, the server is caused to execute the steps of the blockchain-based distributed data sharing method described in the first aspect of the embodiments of the present application.
[0041] It can be understood that the beneficial effects of the above second aspect to the sixth aspect can refer to the relevant descriptions in the above first aspect, and will not be elaborated here. Description of the Drawings
[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0043] Figure 1.1 It is a system architecture diagram of a blockchain-based distributed data sharing system provided by the embodiments of the present application;
[0044] Figure 1.2 It is another system architecture diagram of a blockchain-based distributed data sharing system provided by the embodiments of the present application;
[0045] Figure 2 It is an implementation flowchart of a blockchain-based distributed data sharing method provided by the embodiments of the present application;
[0046] Figure 3 It is a specific implementation flowchart of a blockchain platform processing an authority registration application in a blockchain-based distributed data sharing method provided by the embodiments of the present application;
[0047] Figure 4 It is a specific implementation flowchart of a blockchain platform processing a user attribute application in a blockchain-based distributed data sharing method provided by the embodiments of the present application;
[0048] Figure 4.1 It is a specific implementation flow chart of a blockchain platform receiving an attribute application approval result in a distributed data sharing method based on blockchain provided in an embodiment of the present application;
[0049] Figure 5 This is a schematic diagram of an application scenario of a distributed data sharing method based on blockchain provided in an embodiment of the present application;
[0050] Figure 6 This is a structural block diagram of a distributed data sharing device based on blockchain provided in an embodiment of the present application;
[0051] Figure 7 A schematic diagram of a server provided in an embodiment of the present application. DETAILED DESCRIPTION
[0052] In the following description, specific details such as specific system structures, technologies, etc. are provided for the purpose of illustration rather than limitation, so as to provide a thorough understanding of the embodiments of the present application. However, it should be clear to those skilled in the art that the present application may also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to prevent unnecessary details from obstructing the description of the present application.
[0053] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.
[0054] References to "one embodiment" or "some embodiments" etc. described in the specification of this application mean that one or more embodiments of the present application include specific features, structures or characteristics described in conjunction with the embodiment. Therefore, the statements "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear in different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.
[0055] It should be understood that each method embodiment of the present application provides a distributed data sharing method based on blockchain, which is applicable to various types of terminal devices or servers that need to perform distributed data sharing, including mobile phones, tablet computers, wearable devices, laptops, ultra-mobile personal computers (UMPC), desktop computers and other terminal devices. The embodiments of the present application do not impose any restrictions on the specific types of terminal devices and servers.
[0056] In order to illustrate the technical solution described in this application, a specific embodiment is provided below for illustration.
[0057] Figure 1.1 and Figure 1.2 A system architecture diagram of a distributed data sharing system based on blockchain provided in an embodiment of the present application is shown, which is described in detail as follows: For ease of explanation, only the parts related to the embodiment of the present application are shown.
[0058] Reference Figure 1.1 The distributed data sharing system based on blockchain includes a data encryption user 1, a blockchain platform 2, a data reading user 3 and an authority 4, wherein:
[0059] Data encryption user 1 is used to build an encryption strategy based on the attributes in the attribute set on the blockchain platform 2, and the encryption strategy is used to encrypt the original data to obtain encrypted data, and send the encryption strategy and the encrypted data to the blockchain platform 2.
[0060] The blockchain platform 2 is used to receive and store the encryption strategy and the encrypted data sent by the data encryption user 1.
[0061] Data reading user 3 is used to send a decryption request to the blockchain platform 2.
[0062] The blockchain platform 2 is also used to receive the data decryption application submitted by the data reader 3 calling the smart contract, and verify whether the data reader 3 meets the attribute requirements in the corresponding encryption policy based on the attribute signature list uploaded by the authority and the zero-knowledge proof in the data decryption application; if the data reader 3 meets the attribute requirements in the corresponding encryption policy, the decryption application event is triggered and broadcast.
[0063] The authority 4 is used to monitor the decryption application event. When the decryption application event is monitored, it generates an attribute key corresponding to the data decryption application and sends the attribute key to the data reading user 3;
[0064] The data reading user 3 is also used to decrypt the encrypted data according to the attribute key.
[0065] Data encryption user 1 and data reading user 3 refer to any entity that can interact with the blockchain, including individual users, organizations, servers, and mobile devices. Data encryption user 1 is the data owner. Data encryption user 1 can select any set of attributes published by an authority 4 on the blockchain platform 2 and encrypt the data using any Boolean formula. The above-mentioned mobile devices include but are not limited to mobile phones, notebooks, tablet computers and other terminal devices with communication capabilities.
[0066] Blockchain Platform 2 is a virtual network consisting of distributed nodes, which can be physical servers, personal computers or other devices.
[0067] Authority 4 refers to an organization or entity responsible for verifying, certifying or supervising certain operations, such as a regulatory body, certification body or an organization with specific authority.
[0068] like Figure 1.2 As shown, there may be more than one authority 4. The embodiment of the present application does not impose any restrictions on the number of data encryption users 1, data reading users 3 and authority 4.
[0069] As a possible implementation method of the present application, the authority 4 will generate its own key pair during the system initialization phase: an institution public key and an institution private key. The institution public key is used for identity authentication when the authority registers with the blockchain platform, and is also used to encrypt the attributes to be applied for when the user submits an attribute application. The institution private key is used by the authority 4 to generate the attribute key of the data reading user 3, and is also used to decrypt the user's attributes to be applied for. The authority 4 submits the registration application and the institution public key to the blockchain platform 2 to register the supported attributes, wherein the registration application carries the supported attributes. The institution public key is used by the blockchain platform 2 to verify the identity of the authority 4, to ensure that the institution is indeed what it claims to be, and can reliably manage and issue the corresponding attributes and certificates, which helps to establish a trust mechanism and prevent forgery and fraud. When the blockchain platform 2 passes the review of the authority 4, the attributes supported by the authority 4 and their corresponding institution public keys are stored.
[0070] The data decryption application submitted by the data reader 3 to the blockchain platform 2 includes the zero-knowledge proof of the data reader 3, which is pre-built locally by the data reader 3. The zero-knowledge proof is used by the data reader 3 to prove that he has the attributes issued by the authority and meets the encryption policy of the corresponding data, but there is no need to disclose the specific content of the attributes. The blockchain platform 2 automatically verifies whether the data reader 3 meets the attribute requirements in the corresponding encryption policy based on the zero-knowledge proof and the attribute signature list uploaded by the authority 4. If it does, the decryption application event is broadcast. When the authority 4 listens to the decryption application event broadcast by the blockchain platform 2, the authority 4 will generate an attribute key corresponding to the data decryption application of the data reader 3. The attribute key is used by the data reader 3 to decrypt the encrypted data. The attribute key is bound to the GID (Global Identifier) of the data reader 3. When the encryption policy involves multiple attribute keys, the data reader 3 needs to obtain multiple attribute keys that meet the encryption policy before decrypting the encrypted data.
[0071] In this embodiment, the authority 4 can be added dynamically, and the attributes it supports and the public key of the organization need to be stored on the chain. Any party may become an authority 4. If any party wants to become an authority 4, it needs to submit a registration application and the public key of the organization to the blockchain platform 2. After passing the review of the blockchain platform 2, the registration can be completed and the role of the authority 4 can be assumed.
[0072] In a possible implementation, the data encryption user 1 is also used to read the attribute set on the blockchain platform 2, which includes the supported attributes registered by the authority 4 on the blockchain platform 2. The data encryption user 1 builds an encryption strategy based on the attributes in the attribute set, and uses the encryption strategy to encrypt the original data it has to obtain encrypted data, so that the data is stored and transmitted in an encrypted form, which greatly enhances the confidentiality of the data during the sharing process. The data encryption user 1 is also used to send the encryption strategy and encrypted data to the blockchain platform 2, so that the data reading user 3 whose decryption authority has been verified by the blockchain platform 2 can directly obtain the encrypted data from the blockchain platform 2.
[0073] In other embodiments, the data encryption user 1 is also used to upload the hash value of the encrypted data to the blockchain platform 2, and store the encrypted data in other file systems, for example, based on the InterPlanetary FileSystem (IPFS) to store the encrypted data. The data reading user 3 whose decryption authority is verified by the blockchain platform 2 reads the hash value of the encrypted data from the blockchain platform 2, and obtains the corresponding encrypted data from other file systems based on the hash value.
[0074] As a possible implementation manner of the present application, the user submits an attribute application to the blockchain platform 2 by invoking a smart contract. This attribute application is used to apply to an authoritative institution for the attributes required by the user. The blockchain platform 2 triggers and broadcasts a user attribute application event, which includes the attribute application. The attribute application includes the attribute to be applied encrypted according to the institutional public key of the authoritative institution, and the blockchain platform 2 cannot know the attributes applied by the user. When the authoritative institution 4 monitors this user attribute application event, it approves the attribute application and feeds back the approval result to the blockchain platform 2. The blockchain platform 2 receives the attribute application approval result fed back by the authoritative institution 4 based on the user attribute application event. The user can be the data encryption user 1 or the data reading user 3. This embodiment does not limit the type of user submitting the attribute application. For the data reading user 3, only when the attribute application is approved can it possibly obtain the attribute key corresponding to the attribute to decrypt the corresponding encrypted data.
[0075] In the embodiment of the present application, the user submits the attribute to be applied encrypted with the institutional public key to the blockchain platform 2 to ensure its own privacy. The authoritative institution 4 enables the blockchain platform 2 to implement attribute-based access control by registering the public key and related attributes on the blockchain platform 2. Different users can access different levels of data according to the attributes and permissions they hold.
[0076] As a possible implementation manner of the present application, the user attribute application event includes the institutional identifier specified by the user and the user address of the user. The authoritative institution 4 corresponding to the institutional identifier is also used to verify whether the user address matches the user public key of the user. If the user address matches the user public key of the user, the attribute application is approved. If the user address does not match the user public key of the user, the attribute application is not approved.
[0077] As a possible implementation manner of the present application, the authoritative institution 4 corresponding to the institutional identifier is also used to verify whether the user address matches the user public key of the user. If the user address matches the user public key of the user, it verifies whether the user is a user supported by the service. If the user is a user supported by the service, the attribute application is approved.
[0078] As a possible implementation manner of the present application, the authoritative institution 4 is also used to sign the approved attributes to obtain an attribute signature list. It invokes a smart contract to upload the attribute signature list to the blockchain platform 2 for deposit. If the attribute application is not approved, the authoritative institution 4 feeds back the result of non-approval to the blockchain platform. The signature of the authoritative institution 4 on the attributes is unique. For the same attribute, the attribute signature values obtained after multiple signatures are different.
[0079] In this embodiment, after the user submits an attribute application to the blockchain platform 2, even if the authority 4 approves it, the authority 4 does not send the attribute key to the user. Instead, when the user (data reading user 3) submits a data decryption application to the blockchain platform 2, when the blockchain platform 2 verifies that the user meets the attribute requirements in the corresponding encryption policy, that is, the user does have the decryption authority, the authority 4 issues the attribute key to the user through a secure channel. After verifying the user's decryption authority on the chain, the authority 4 issues the corresponding attribute key to the user, which not only makes the behavior traceable, but also helps to ensure the security of data sharing, ensuring that distributed data sharing can be achieved safely and efficiently among users.
[0080] In a possible implementation, when there is more than one authority 4, the user carries an organization ID in the attribute application submitted to the blockchain platform 2 by calling a smart contract, which is used to indicate the authority 4 for approval, and the blockchain platform 2 triggers and broadcasts the user attribute application event. The authority 4 is also used to approve the user's attribute application when it monitors that the organization ID in the user attribute application event is its own ID, and feedback the approval result. In this embodiment, the user can select the authority 4 according to the needs, and the attribute application submitted by the user includes the organization ID and the attributes to be applied encrypted according to the authority's public key, so that the corresponding authority 4 can quickly approve the user's attribute application when it monitors the user attribute application event.
[0081] As a possible implementation method of the present application, when there is more than one authority 4, the data encryption user 1 can simultaneously construct a joint encryption strategy based on the attributes supported by different authority 4, for example, a joint encryption strategy can be constructed based on the first attribute supported by the first authority and the second attribute supported by the second authority, and then the joint encryption strategy is used to encrypt the original data. In this case, if the data reading user 3 wants to decrypt the encrypted data encrypted by the joint encryption strategy, it is necessary to apply to the first authority for the first attribute key corresponding to the first attribute and to the second authority for the second attribute key corresponding to the second attribute through the blockchain platform 2. The data reading user 3 can only effectively decrypt the above encrypted data after obtaining the first attribute key and the second attribute key.
[0082] In some implementations, after completing the attribute application, the data reader 3 actively establishes a connection with the authority 4, and the authority 4 sends the attribute key to the data reader 3 based on the connection.
[0083] In a possible implementation, the authority 4 is also used to obtain the user public key of the data reading user 3 from the blockchain platform 2, encrypt the attribute key according to the user public key, and send the encrypted attribute key to the data reading user 3.
[0084] In the embodiment of the present application, in a decentralized scenario involving multiple parties, the encrypted data and encryption strategy are stored on the chain, and the blockchain platform 2 uses the zero-knowledge proof in the data decryption application of the attribute signature list of the authority 4 to verify the authority of the data reading user 3, allowing the data reading user 3 to prove that it meets the attribute requirements without disclosing its own specific privacy information, which not only protects user privacy but also makes the verification process accurate. At the same time, with the help of the credibility of the authority 4 and the authority of the attribute signature list, it can effectively prevent unauthorized users from obtaining data, avoid the chaos of authority management, and enable data sharing to be carried out strictly in accordance with the preset rules and permissions, thereby improving the standardization and controllability of data sharing. Moreover, the operations of each participating entity are recorded on the blockchain and cannot be tampered with, which establishes a transparent and traceable collaborative environment for all parties. Any participating entity can verify the fairness of data access control, and greatly limits the rights of the authority 4, thereby ensuring that distributed data sharing can be achieved safely and efficiently among users.
[0085] Figure 2 The implementation process of the distributed data sharing method based on blockchain provided by the embodiment of the present application is shown. The execution end of the embodiment of the present application is a blockchain platform. The method flow may include the following steps S201 to S203. The specific implementation principle of each step is as follows:
[0086] Step S201: receiving and storing the encryption policy and encrypted data sent by the data encryption user.
[0087] The encryption strategy is constructed by the data encryption user based on the attributes in the attribute set on the blockchain platform, and the encryption strategy is used by the data encryption user to encrypt the original data to obtain the encrypted data.
[0088] In the embodiment of the present application, the data encryption user reads the attribute set from the blockchain platform, builds an encryption strategy based on the attributes in the attribute set, and encrypts the original data according to the encryption strategy to obtain encrypted data. As the owner of the original data, the data encryption user encrypts the original data to limit the scope of users who can share the original data. The data encryption user also submits the encryption strategy and encrypted data to the blockchain platform for evidence storage. The blockchain platform also receives and stores the encryption strategy sent by the data encryption user based on the data encryption application, so that the blockchain platform can conduct permission review on the data reading users who want to share the encrypted data.
[0089] In some possible implementations, before receiving and storing the encryption policy and encrypted data sent by the data encryption user, the blockchain platform verifies the legitimacy of the data encryption user's identity; if the data encryption user's identity is legitimate, the data encryption user is allowed to read the attribute set on the blockchain platform. In this embodiment, before the data encryption user performs operations on the chain, it is necessary to provide identity information to the blockchain platform for verification, and the data encryption user is authenticated by the blockchain platform to ensure the legitimacy of its encryption authority. The blockchain platform can verify the legitimacy of the data encryption user's identity based on the relevant identity authentication mechanism on the chain. When the identity legitimacy verification is passed, the blockchain platform marks the identity status of the data encryption user as legitimate, and allows the data encryption user to read the attribute set on the chain. Through identity legitimacy verification, it can be ensured that only legitimate users can perform data encryption operations, thereby reducing the risk of data leakage or abuse and ensuring data security.
[0090] As a possible implementation of this application, Figure 3 The following is a specific implementation process of the blockchain platform processing the registration application of the authoritative institution in the distributed data sharing method based on blockchain provided in the embodiment of the present application, which is described in detail as follows:
[0091] A1: Obtain a registration application and an institution public key submitted by an authority, wherein the registration application is used to register the attributes supported by the authority. The institution public key is a public key in a key pair generated locally by the authority.
[0092] Any party on the blockchain platform can apply to become an authority. The authority needs to generate its own key pair locally: the institution's public key and the institution's private key. The institution's public key is used for identity authentication when the authority registers with the blockchain platform, and is also used to encrypt the attributes to be applied for when the user submits an attribute application. The institution's private key is used by the authority to generate data to read the attribute key of user 3. Submit a registration application and the institution's public key to the blockchain platform. The registration application carries the supported attributes. The supported attributes are registered on the blockchain platform. The attributes can be registered in plain text or attribute hash. The blockchain platform verifies the identity of the authority based on the institution's public key. There can be multiple authorities on the blockchain platform, and different authorities support different attributes.
[0093] A2: Review the registration application. If the application passes the review, store the attributes supported by the authority and their corresponding public keys.
[0094] The blockchain platform reviews the registration application of the authority based on the institution’s public key to ensure that the institution is indeed what it claims to be and can reliably manage and issue the corresponding attributes and certificates.
[0095] Institutional public keys can be used by smart contracts to verify and process operations related to specific attributes, thereby enhancing the flexibility and functionality of the contract.
[0096] In this embodiment, the registration application of the authoritative agency is reviewed through the blockchain platform, and the registration application with attributes that can be supported by the valid authoritative agency is completed, effectively building a trusted data sharing and access control mechanism.
[0097] As a possible implementation of this application, Figure 4 A specific implementation process of the blockchain platform processing user attribute application in the distributed data sharing method based on blockchain provided in the embodiment of the present application is shown, and the details are as follows:
[0098] B1: Obtain the attribute application submitted by the user by calling the smart contract, wherein the attribute application includes the attribute to be applied encrypted according to the public key of the authority. The user is a data encryption user or a data reading user.
[0099] B2: triggering and broadcasting a user attribute application event, wherein the user attribute application event is used to instruct the authority to decrypt the attributes to be applied for based on the institution's private key, conduct approval, and feedback the approval result.
[0100] The user attribute application event includes the organization identifier specified by the user and the user address of the user. The authority corresponding to the organization identifier approves the attribute application, including: verifying whether the user address matches the user public key of the user; if the user address matches the user public key of the user, the attribute application is approved; or, if the user address matches the user public key of the user, verifying whether the user is a user supported by the service; if the user is a user supported by the service, the attribute application is approved.
[0101] B3: receiving the attribute application approval result fed back by the authority based on the user attribute application event.
[0102] After the authority monitors the user attribute application event related to itself, it uses its own institution's private key to decrypt the application attributes and then approves and verifies the user's identity. Once approved, the user's identity can be associated with the applied attributes, and the attribute signature list obtained after signing the approved attributes is uploaded to the blockchain platform for evidence storage. It is stored on the chain in the form of an attribute signature list, which effectively prevents malicious attackers from forging signatures. All parties to data sharing can confirm the legitimacy of the attributes by viewing the attribute signature list on the blockchain, trace the source of the attribute signature, achieve behavior traceability, and ensure that distributed data sharing can be achieved safely and efficiently among users.
[0103] As a possible implementation of this application, Figure 4.1 A specific implementation process of receiving the attribute application approval result fed back by the authority based on the user attribute application event in the distributed data sharing method based on blockchain provided in an embodiment of the present application is shown, and is described in detail as follows:
[0104] B31: If the attribute application is approved, receive the attribute signature list uploaded by the authority, which is obtained by signing the attribute of the attribute application approved by the authority. The signature of the attribute by the authority is unique. For the same attribute, the attribute signature value obtained after multiple signatures is different.
[0105] B32: If the attribute application is not approved, receiving the result of the attribute application not being approved uploaded by the authority.
[0106] In the embodiment of the present application, the authority signs the approved attributes to obtain the attribute signature list; calls the smart contract to upload the attribute signature list to the blockchain platform for evidence storage; if the attribute application is not approved, the authority will feedback the result of the approval failure to the blockchain platform. The signature of the authority represents the approval and authentication of the attribute. The randomness is introduced by the signature algorithm. Even for the same attribute, the value after multiple signatures is different, which makes the signature unique and unpredictable, which can effectively prevent malicious attackers from forging signatures and ensure that only legally authorized attributes can be recognized and used in the data sharing process.
[0107] Step S202: Receive a data decryption application submitted by a data reader calling a smart contract, and verify whether the data reader meets the attribute requirements in the corresponding encryption policy based on the attribute signature list uploaded by the authority and the zero-knowledge proof in the data decryption application.
[0108] In the embodiment of the present application, the data reading user pre-builds a zero-knowledge proof locally, submits a data decryption application including the zero-knowledge proof, and uses the zero-knowledge proof to prove to the blockchain platform that he has the attributes issued by the authority and meets the encryption policy of the corresponding data, but there is no need to disclose the specific content of the attributes, which not only protects the user's privacy, but also makes the verification process accurate. The blockchain platform automatically verifies whether the data reading user 3 meets the attribute requirements in the corresponding encryption policy based on the zero-knowledge proof and the attribute signature list uploaded by the authority. If satisfied, the data reading user has the data decryption authority; if not satisfied, the data reading user does not have the data decryption authority. With the help of the credibility of the authority and the authority of the attribute signature list, the blockchain platform can effectively prevent unauthorized users from obtaining data, which can improve the standardization and controllability of data sharing.
[0109] Step S203: If the data reading user meets the attribute requirements in the corresponding encryption policy, a decryption application event is triggered and broadcast. The decryption application event is used to instruct the authority to generate an attribute key corresponding to the data decryption application and send the attribute key to the data reading user so that the data reading user can decrypt the encrypted data according to the attribute key.
[0110] In this embodiment, the attribute key is not stored on the blockchain platform. When the blockchain platform verifies that the data reading user meets the attribute requirements in the corresponding encryption policy based on the attribute signature list uploaded by the authority and the zero-knowledge proof in the data decryption application, the decryption application event is triggered and broadcast. When the authority monitors the decryption application event related to itself, the corresponding attribute key is sent to the data reading user through a secure channel, so that the data reading user decrypts the encrypted data according to the attribute key. Among them, related to itself means that the attributes associated in the decryption application event are attributes supported by the authority itself.
[0111] As a possible implementation of the present application, the decryption application event is also used to instruct the authority to obtain the user public key of the data reader from the blockchain platform before sending the attribute key to the data reader, encrypt the attribute key according to the user public key, and send the encrypted attribute key to the data reader.
[0112] In a possible implementation, the data reader can establish a connection with the authority after submitting the attribute application and it is approved. When the authority monitors the decryption application event of the data reader, the generated attribute key is sent to the data reader based on the above connection. That is, the data reader establishes a connection with the authority in advance after successfully completing the attribute application.
[0113] In one possible implementation, after verifying that the attributes of the data reader satisfy the encryption policy, the blockchain platform feeds back the verification result to the data reader. The data reader establishes a connection with the corresponding authority based on the organization identifier carried in the verification result, and the authority sends the attribute key to the data reader based on the connection.
[0114] In the embodiment of the present application, the data reading user does not submit a decryption application directly to the authority, but submits a decryption application to the blockchain platform. The blockchain platform verifies the identity based on the attribute signature list and zero-knowledge proof and then broadcasts the decryption application event. This not only protects user privacy, but also makes the verification process accurate, which is conducive to ensuring data privacy and security of distributed data sharing. The distribution of attribute keys by the authority depends on the blockchain platform broadcasting the decryption application event, which can meet the traceability of behavior. Any participant can verify the fairness of data access control, and it also greatly limits the rights of the authority.
[0115] For example, take an application scenario as an example. Figure 5 As shown in the figure, authority A and authority B apply for registration to the blockchain platform, register the supported attributes, and upload the locally generated institution public key and the supported attributes to the blockchain, which are managed by the blockchain platform through smart contracts. The data encryption user reads the attributes on the blockchain platform, selects the attributes to build an encryption strategy, and uploads the encryption strategy and encrypted data to the blockchain platform for storage. The data encryption user can select the specified attributes according to the needs and limit the users who can participate in data sharing. For example, the data encryption user hopes to share medical data only with users with the "doctor" attribute issued by the medical organization and the "researcher" attribute issued by the clinical trial administrator. Before submitting a decryption application, the data reader needs to submit a user attribute application to the blockchain platform. The attribute application submitted by the data reader includes the organization identification of the designated authority A. The attributes to be applied in the user attribute application are encrypted using the institution public key of the designated authority A. The blockchain platform triggers and broadcasts the attribute application event based on the user attribute application. After the authority A monitors the attribute application event, it approves the user attribute application of the data user, feeds back the user attribute application approval result to the blockchain platform, and signs the approved attributes to obtain the attribute signature list on the chain for evidence. If the data reader's identity legitimacy is verified, the blockchain platform updates the attribute status of the data reader, and the attribute status includes the attributes obtained by the data reader. The data reader establishes a connection with the authority A and submits a decryption application to the blockchain platform. The blockchain platform verifies whether the data reader meets the attribute requirements in the corresponding encryption policy based on the attribute signature list submitted by the authority on the platform and the zero-knowledge proof in the user's attribute application. If satisfied, the decryption application event is triggered and broadcast. After the authority A monitors the decryption application event, it issues the attribute key to the data reader based on the connection established by the data reader. After the data reading user obtains the attribute key corresponding to the encryption policy, the attribute key is used to decrypt the encrypted data, thereby realizing distributed data sharing.
[0116] It can be seen that in the embodiment of the present application, the encrypted data and the encryption strategy are stored on the chain, and the blockchain platform verifies the authority of the data reading user by combining the zero-knowledge proof in the data decryption application of the attribute signature list of the authority, allowing the data reading user to prove that it meets the attribute requirements without disclosing its specific privacy information, which not only protects the user's privacy, but also makes the verification process accurate. At the same time, with the help of the credibility of the authority and the authority of the attribute signature list, it can effectively prevent unauthorized users from obtaining data, avoid the chaos of authority management, and enable data sharing to be carried out strictly in accordance with the preset rules and permissions, thereby improving the standardization and controllability of data sharing. Moreover, the operations of each participating entity are recorded on the blockchain and cannot be tampered with, which establishes a transparent and traceable collaborative environment for all parties. Any participating entity can verify the fairness of data access control, thereby ensuring that distributed data sharing can be achieved safely and efficiently among users.
[0117] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0118] Corresponding to the distributed data sharing method based on blockchain described in the above embodiment, Figure 6 A structural block diagram of a distributed data sharing device based on blockchain provided in an embodiment of the present application is shown. For ease of explanation, only the parts related to the embodiment of the present application are shown.
[0119] Reference Figure 6 The distributed data sharing device is applied to the blockchain platform. The distributed data sharing device includes: an encryption application processing unit 61, a decryption application processing unit 62, and a data sharing unit 63, wherein:
[0120] The encryption application processing unit 61 is used to receive and store the encryption strategy and encrypted data sent by the data encryption user, wherein the encryption strategy is constructed by the data encryption user based on the attributes in the attribute set on the blockchain platform, and the encryption strategy is used by the data encryption user to encrypt the original data to obtain the encrypted data;
[0121] The decryption application processing unit 62 is used to receive the data decryption application submitted by the data reading user calling the smart contract, and verify whether the data reading user meets the attribute requirements in the corresponding encryption policy based on the attribute signature list uploaded by the authority and the zero-knowledge proof in the data decryption application;
[0122] The data sharing unit 63 is used to trigger and broadcast a decryption application event if the data reading user meets the attribute requirements in the corresponding encryption policy. The decryption application event is used to instruct the authority to generate an attribute key corresponding to the data decryption application and send the attribute key to the data reading user so that the data reading user can decrypt the encrypted data according to the attribute key.
[0123] As a possible implementation of the present application, the encryption application processing unit 61 is further used for:
[0124] Based on the data encryption application, verify the legitimacy of the data encryption user identity;
[0125] If the identity of the data encryption user is legal, the data encryption user is allowed to read the attribute set on the blockchain platform.
[0126] As a possible implementation of the present application, the above-mentioned distributed data sharing device further includes:
[0127] The institution registration review unit is used to obtain the registration application and institution public key submitted by the authority, wherein the registration application is used to register the attributes supported by the authority; the registration application is reviewed, and if the review is passed, the attributes supported by the authority and the corresponding institution public key are stored.
[0128] As a possible implementation of the present application, the above-mentioned distributed data sharing device further includes:
[0129] An attribute application processing unit, used to obtain an attribute application submitted by a user by calling a smart contract, wherein the attribute application includes an attribute to be applied encrypted according to an institution public key of an authority;
[0130] Trigger and broadcast a user attribute application event, wherein the user attribute application event is used to instruct the authority to decrypt the attribute to be applied for based on the institution's private key and then approve it, and feedback the attribute application approval result;
[0131] Receive the attribute application approval result fed back by the authority based on the user attribute application event.
[0132] As a possible implementation of the present application, the user attribute application event includes an organization identifier specified by the user and a user address of the user; the authoritative organization decrypts the attributes to be applied for based on the organization private key and then approves the application, including:
[0133] The authority corresponding to the organization identifier verifies whether the user address matches the user public key of the user;
[0134] If the user address matches the user public key of the user, the attribute application is approved;
[0135] Alternatively, if the user address matches the user public key of the user, verify whether the user is a user supported by the service;
[0136] If the user is a user supported by the service, the attribute application is approved.
[0137] As a possible implementation manner of the present application, the receiving the attribute application approval result fed back by the authority based on the user attribute application event includes:
[0138] If the attribute application is approved, receiving the attribute signature list uploaded by the authority, wherein the attribute signature list is obtained by signing the attributes of the attribute application approved by the authority;
[0139] If the attribute application is not approved, the result of the attribute application not being approved uploaded by the authoritative organization is received.
[0140] As a possible implementation of the present application, the decryption application event is also used to instruct the authority to obtain the user public key of the data reader from the blockchain platform before sending the attribute key to the data reader, encrypt the attribute key according to the user public key, and send the encrypted attribute key to the data reader.
[0141] As can be seen from the above, in the embodiment of the present application, the encrypted data and the encryption strategy are stored on the chain, and the blockchain platform verifies the authority of the data reading user by combining the zero-knowledge proof in the data decryption application of the attribute signature list of the authority, allowing the data reading user to prove that it meets the attribute requirements without disclosing its specific privacy information, which not only protects the user's privacy, but also makes the verification process accurate. At the same time, with the help of the credibility of the authority and the authority of the attribute signature list, it can effectively prevent unauthorized users from obtaining data, avoid the chaos of authority management, and enable data sharing to be carried out strictly in accordance with the preset rules and permissions, thereby improving the standardization and controllability of data sharing. Moreover, the operations of each participating entity are recorded on the blockchain and cannot be tampered with, which establishes a transparent and traceable collaborative environment for all parties. Any participating entity can verify the fairness of data access control, thereby ensuring that distributed data sharing can be achieved safely and efficiently among users.
[0142] The present application also provides a computer-readable storage medium storing a computer program, wherein when the computer program is executed by a processor, Figures 2 to 5 The steps of any distributed data sharing method based on blockchain are represented.
[0143] The present application also provides a computer program product, which, when executed on a server, enables the server to execute the following Figures 2 to 5 The steps of any distributed data sharing method based on blockchain are represented.
[0144] The embodiment of the present application also provides a server, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, Figures 2 to 5 The steps of any distributed data sharing method based on blockchain are represented.
[0145] Figure 7 Schematic diagram of a server provided by an embodiment of the present application. Figure 7 As shown, the server 7 of this embodiment includes: a processor 70, a memory 71, and a computer program 72 stored in the memory 71 and executable on the processor 70. When the processor 70 executes the computer program 72, the steps in the above-mentioned embodiments of the distributed data sharing method based on blockchain are implemented, for example Figure 2 Alternatively, when the processor 70 executes the computer program 72, the functions of each module / unit in the above-mentioned device embodiments are realized, for example Figure 6 The functions of the units 61 to 63 are shown.
[0146] The computer program 72 may be divided into one or more modules / units, which are stored in the memory 71 and executed by the processor 70 to complete the present application. The one or more modules / units may be a series of computer program instruction segments capable of completing specific functions, which are used to describe the execution process of the computer program 72 in the server 7.
[0147] The processor 70 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc.
[0148] The memory 71 may be an internal storage unit of the server 7, such as a hard disk or memory of the server 7. The memory 71 may also be an external storage device of the server 7, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the server 7. Further, the memory 71 may also include both an internal storage unit of the server 7 and an external storage device. The memory 71 is used to store the computer program and other programs and data required by the server. The memory 71 may also be used to temporarily store data that has been output or is to be output.
[0149] The technicians in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In practical applications, the above-mentioned function allocation can be completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated in a processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, which will not be repeated here.
[0150] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0151] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0152] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0153] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the system embodiments described above are only schematic. For example, the division of the modules or units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0154] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0155] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0156] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the processes in the above-mentioned embodiment method, and can also be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and the computer program can implement the steps of the above-mentioned various method embodiments when executed by the processor. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, U disk, mobile hard disk, disk, optical disk, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electric carrier signal, telecommunication signal and software distribution medium. It should be noted that the content contained in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electric carrier signals and telecommunication signals.
[0157] The embodiments described above are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, a person skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.
Claims
1. A distributed data sharing method based on blockchain, characterized in that: Applied to a blockchain platform, the method comprises: Receive and store the encryption strategy and encrypted data sent by the data encryption user, wherein the encryption strategy is constructed by the data encryption user based on the attributes in the attribute set on the blockchain platform, and the encryption strategy is used by the data encryption user to encrypt the original data to obtain the encrypted data; Receive the data decryption application submitted by the data reader calling the smart contract, and verify whether the data reader meets the attribute requirements in the corresponding encryption policy based on the attribute signature list uploaded by the authority and the zero-knowledge proof in the data decryption application; If the data reading user meets the attribute requirements in the corresponding encryption policy, a decryption application event is triggered and broadcast. The decryption application event is used to instruct the authority to generate an attribute key corresponding to the data decryption application and send the attribute key to the data reading user so that the data reading user can decrypt the encrypted data according to the attribute key.
2. The method according to claim 1, characterized in that Before receiving and storing the encryption policy and encrypted data sent by the data encryption user, the method further includes: Obtaining the attribute application submitted by the user by calling the smart contract, wherein the attribute application includes the attribute to be applied encrypted according to the public key of the authority; Trigger and broadcast a user attribute application event, wherein the user attribute application event is used to instruct the authority to decrypt the attribute to be applied for based on the institution's private key and then approve it, and feedback the attribute application approval result; Receive the attribute application approval result fed back by the authority based on the user attribute application event.
3. The method according to claim 2, characterized in that The user attribute application event includes the organization identifier specified by the user and the user address of the user; the authoritative organization decrypts the attributes to be applied for based on the organization private key and then approves the application, including: The authority corresponding to the organization identifier verifies whether the user address matches the user public key of the user; If the user address matches the user public key of the user, the attribute application is approved; Alternatively, if the user address matches the user public key of the user, verify whether the user is a user supported by the service; If the user is a user supported by the service, the attribute application is approved.
4. The method according to claim 2, characterized in that The receiving of the attribute application approval result fed back by the authority based on the user attribute application event includes: If the attribute application is approved, receiving the attribute signature list uploaded by the authority, wherein the attribute signature list is obtained by signing the attributes of the attribute application approved by the authority; If the attribute application is not approved, the result of the attribute application not being approved uploaded by the authoritative organization is received.
5. The method according to claim 1, characterized in that The method further comprises: Obtaining a registration application and an institution public key submitted by an authority, wherein the registration application is used to register attributes supported by the authority; The registration application is reviewed, and if the review is passed, the attributes supported by the authoritative organization and their corresponding organization public keys are stored.
6. The method according to any one of claims 1 to 5, characterized in that: The decryption application event is also used to instruct the authority to obtain the user public key of the data reader from the blockchain platform before sending the attribute key to the data reader, encrypt the attribute key according to the user public key, and send the encrypted attribute key to the data reader.
7. A distributed data sharing system based on blockchain, characterized in that: The system includes data encryption users, data reading users, an authority, and a blockchain platform, wherein: The data encryption user is used to construct an encryption strategy based on the attributes in the attribute set on the blockchain platform, the encryption strategy is used to encrypt the original data to obtain encrypted data, and send the encryption strategy and the encrypted data to the blockchain platform; The blockchain platform is used to receive and store the encryption strategy and the encrypted data sent by the data encryption user; The data reading user is used to send a decryption application to the blockchain platform; The blockchain platform is also used to receive a data decryption application submitted by a data reader calling a smart contract, and verify whether the data reader meets the attribute requirements in the corresponding encryption policy based on the attribute signature list uploaded by the authority and the zero-knowledge proof in the data decryption application; if the data reader meets the attribute requirements in the corresponding encryption policy, a decryption application event is triggered and broadcast; The authority is used to monitor the decryption application event, and after monitoring the decryption application event, generates an attribute key corresponding to the data decryption application, and sends the attribute key to the data reading user; The data reading user is also used to decrypt the encrypted data according to the attribute key.
8. A distributed data sharing device based on blockchain, characterized in that: Applied to the blockchain platform, the device includes: An encryption application processing unit, used to receive and store an encryption strategy and encrypted data sent by a data encryption user, wherein the encryption strategy is constructed by the data encryption user based on the attributes in the attribute set on the blockchain platform, and the encryption strategy is used by the data encryption user to encrypt the original data to obtain the encrypted data; A decryption application processing unit is used to receive a data decryption application submitted by a data reader calling a smart contract, and verify whether the data reader meets the attribute requirements in the corresponding encryption policy based on the attribute signature list uploaded by the authority and the zero-knowledge proof in the data decryption application; A data sharing unit is used to trigger and broadcast a decryption application event if the data reading user meets the attribute requirements in the corresponding encryption policy. The decryption application event is used to instruct an authority to generate an attribute key corresponding to the data decryption application and send the attribute key to the data reading user so that the data reading user can decrypt the encrypted data according to the attribute key.
9. A server comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the steps of the distributed data sharing method based on blockchain as described in any one of claims 1 to 6 are implemented.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the distributed data sharing method based on blockchain as described in any one of claims 1 to 6 are implemented.