Data transaction privacy protection method based on block chain

By adopting blockchain-based data transaction privacy protection methods in IoT data transactions, combining zero-knowledge proof and proxy re-encryption technology, the problem of data privacy protection in IoT data transactions is solved, the transparency and traceability of data transactions are achieved, and transaction efficiency is improved.

CN120030592APending Publication Date: 2025-05-23QILU UNIVERSITY OF TECHNOLOGY (SHANDONG ACADEMY OF SCIENCES)

Patent Information

Application Number
CN202510099239.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-22
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

How to ensure data privacy and ensure the traceability and transparency of data transactions in IoT data transactions is a technical problem that needs to be solved urgently.

Method used

A blockchain-based data transaction privacy protection method is adopted, through the steps of system initialization, data release, data transaction, authentication authorization and transaction payment, combined with zero-knowledge proof and proxy re-encryption technology, we ensure the privacy and security of data during the transaction process, and at the same time, the transparency and traceability of data transactions are achieved through smart contracts and blockchain technology.

Benefits of technology

It realizes the protection of data privacy in IoT data transactions, ensures transparency and traceability of data transactions, reduces the risk of human intervention, improves transaction efficiency, and is suitable for industries that attach great importance to data privacy and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030592A_ABST
    Figure CN120030592A_ABST
Patent Text Reader

Abstract

The invention discloses a data transaction privacy protection method based on a block chain, belongs to the technical field of data sharing, and aims to solve the technical problem of how to ensure data privacy and ensure traceability and transparency of data transaction in Internet of Things data transaction. Comprising the steps that a data buyer performs data validity verification based on a zero-knowledge proof submitted to a block chain by a data seller, after verification is passed, the data seller generates a re-encryption key based on a private key of the data seller and a public key of the data buyer and uploads the re-encryption key to a proxy node, the proxy node re-encrypts a related ciphertext based on the re-encryption key, and the data seller sends the re-encrypted ciphertext to the data seller; the obtained re-encrypted ciphertext is uploaded to the IPFS, a content identifier returned by the IPFS is written into the block chain, and the block chain writes the content identifier corresponding to the re-encrypted ciphertext into the smart contract; and after the data buyer pays, the re-encrypted ciphertext is obtained from the IPFS based on the content identifier returned by the block chain, and the re-encrypted ciphertext is decrypted based on the private key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data sharing technology, and in particular to a data transaction privacy protection method based on blockchain. Background Art

[0002] With the proliferation of IoT devices, the amount of data generated is increasing, making data trading and sharing a critical issue. However, much of the data generated in the IoT often involves user privacy and sensitive information, such as personal health data, location information, and financial data. Therefore, achieving secure and efficient IoT data trading without leaking sensitive data has become a pressing technical challenge.

[0003] Blockchain, a decentralized distributed ledger technology, boasts immutability, transparency, and traceability, and has been widely used in data security and transaction fields. However, blockchain itself presents challenges in data transparency and privacy protection when processing sensitive data. Existing IoT data transaction mechanisms often fail to fully consider data privacy and security, necessitating the introduction of encryption technologies and privacy protection mechanisms.

[0004] How to ensure data privacy and the traceability and transparency of data transactions in IoT data transactions is a technical problem that needs to be solved. Summary of the Invention

[0005] The technical task of the present invention is to address the above shortcomings and provide a data transaction privacy protection method based on blockchain to solve the technical problems of how to ensure data privacy in IoT data transactions and ensure the traceability and transparency of data transactions.

[0006] The present invention provides a data transaction privacy protection method based on blockchain, which is applied to data buyers, data sellers, IPFS, and blockchains deployed with Fabric networks, wherein smart contracts are deployed in the blockchain. The method comprises the following steps:

[0007] System initialization: The data seller and data buyer register their identities on the blockchain based on their generated key pairs, receive the identity authentication certificates returned by the blockchain, and make their public keys public;

[0008] Data publishing: The data seller encrypts the original data based on its private key, uploads the generated ciphertext to IPFS, and obtains the content identifier returned by IPFS. The data seller then uploads the data description, content identifier, data price, and transaction conditions corresponding to the original data as metadata to the blockchain, where the content identifier serves as the data storage location identifier.

[0009] Data transaction: The data buyer queries and selects the target data through the blockchain and initiates a data transaction request to the blockchain. The data transaction request includes the public key of the data buyer's key pair, the content identifier of the target data, and the payment method. The blockchain stores the data transaction request through a smart contract and forwards the data transaction request to the corresponding data seller;

[0010] Authentication and authorization: The data buyer verifies the validity of the data based on the zero-knowledge proof submitted by the data seller to the blockchain. After the verification is passed, the data seller generates a re-encryption key based on its private key and the data buyer's public key, and uploads its re-encryption key to the proxy node. The proxy node re-encrypts the relevant ciphertext based on the re-encryption key, uploads the obtained re-encrypted ciphertext to IPFS, and writes the content identifier returned by IPFS to the blockchain. The blockchain writes the content identifier corresponding to the re-encrypted ciphertext into the smart contract;

[0011] Transaction payment: After the data buyer pays, the re-encrypted ciphertext is obtained from IPFS based on the content identifier returned by the blockchain, and the re-encrypted ciphertext is decrypted based on its private key to obtain the original data, and the transaction payment process is recorded in the blockchain.

[0012] Preferably, both the data seller and the data buyer generate their key pairs through elliptic curve encryption algorithm or bilinear pairing.

[0013] Preferably, the data seller preprocesses the original data, performs denoising, format conversion, and compression operations on the data preprocessing to obtain the preprocessed original data, and encrypts the preprocessed original data based on its private key to generate ciphertext;

[0014] Correspondingly, the data buyer decrypts the re-encrypted ciphertext based on its private key to obtain the preprocessed original data.

[0015] Preferably, the data seller generates a zero-knowledge proof based on the data attributes of its original data and uploads the zero-knowledge proof to the blockchain. The blockchain verifies the validity of the original data through the zero-knowledge proof. If the verification passes, the transaction continues. If the verification fails, the transaction is terminated and the data buyer is notified.

[0016] Among them, data attributes include the generation time of the original data and the specific conditions that the data meets.

[0017] Preferably, the smart contract includes a data transaction contract, a re-encryption contract, and an access control list;

[0018] The blockchain manages the process of data transaction requests, authentication authorization, and transaction payments through data transaction contracts;

[0019] The blockchain coordinates each proxy node to re-encrypt the relevant ciphertext based on the re-encryption key through the re-encryption contract;

[0020] The blockchain controls the access rights of data buyers and sellers to the blockchain through an access control list, and adds data buyers and sellers registered through identities to the access control list.

[0021] Preferably, after the data buyer makes payment based on the provisions of the smart contract, the blockchain returns the content identifier of the target data corresponding to the re-encrypted ciphertext to the data buyer;

[0022] Among them, the payment methods for data buyers include payment through blockchain tokens or payment according to the payment methods specified in the smart contract.

[0023] Preferably, when the transaction payment process is recorded in the blockchain, the recorded transaction information includes the content identifier of the target data corresponding to the re-encrypted ciphertext, the identity authentication certificate of the data buyer, the identity authentication certificate of the data seller, the payment amount and payment time of the data buyer, and the authorization information of the re-encryption key;

[0024] Among them, the authorization information of the re-encryption key includes key generation information, key usage rights, key lifecycle management information, operation log audit information and revocation and freezing mechanism information. The key generation information includes the generation timestamp of the re-encryption key. The key usage rights include the user of the re-encryption key, the authorization scope and the re-encryption operation of the specific data applied. The key usage rights are managed through the access control list in the smart contract. The key lifecycle includes the validity period of the re-encryption key and the update and revocation mechanism information. The operation log audit information is used to record the corresponding logs generated by encryption operations, key authorization, and revocation events based on the re-encryption key. The revocation and freezing mechanism information is used to ensure that when there is a security problem with the key, the authorization of the key can be revoked or frozen in time.

[0025] The data transaction privacy protection method based on blockchain of the present invention has the following advantages:

[0026] 1. Privacy protection: Through technologies such as zero-knowledge proof and proxy re-encryption, we ensure that sensitive data is not leaked or accessed during the transaction process;

[0027] 2. Data transaction transparency: All data transaction records are stored on the blockchain, ensuring that the data transaction process is transparent, traceable, and tamper-proof;

[0028] 3. Automatic execution of smart contracts: Automatically execute transactions through smart contracts, reducing the risk of human intervention and improving transaction efficiency;

[0029] 4. Token incentive mechanism: Incentivize data providers through tokens to ensure enthusiasm for data transactions and promote data circulation;

[0030] 5. Data security and compliance: Applicable to industries that attach great importance to data privacy and security, ensuring the compliance and security of data transactions. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments or descriptions of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0032] The present invention will be further described below with reference to the accompanying drawings.

[0033] Figure 1 This is a flowchart of a data transaction privacy protection method based on blockchain in Example 1. DETAILED DESCRIPTION

[0034] The present invention will be further described below with reference to the accompanying drawings and specific embodiments so that those skilled in the art can better understand the present invention and implement it. However, the embodiments given are not intended to limit the present invention. Unless there is a conflict, the embodiments of the present invention and the technical features in the embodiments may be combined with each other.

[0035] The embodiment of the present invention provides a data transaction privacy protection method based on blockchain, which is used to solve the technical problem of how to ensure data privacy and ensure the traceability and transparency of data transactions in Internet of Things data transactions.

[0036] Example:

[0037] The present invention provides a data transaction privacy protection method based on blockchain, which is applied to data buyers, data sellers, IPFS, proxy nodes and blockchains deployed with Fabric networks. Smart contracts are deployed in the blockchain. The method includes five steps: system initialization, data release, data transaction, authentication and authorization, and transaction payment.

[0038] Step S100 System initialization: The data seller and data buyer register their identities with the blockchain based on the key pairs they generate, receive the identity authentication certificates returned by the blockchain, and make their public keys public.

[0039] As a specific implementation of system initialization, the data seller generates its key pair through the elliptic curve cryptography (ECC) or bilinear pairing, and registers it to the identity management module of the blockchain based on the key pair, and obtains the identity authentication certificate (X.509 certificate) returned by the blockchain. Among them, the data seller's key pair includes the public key PK s and private key SK s .

[0040] Similarly, the data buyer generates its key pair through the elliptic curve cryptography (ECC) or bilinear pairing, and registers the key pair to the identity management module of the blockchain to obtain the identity authentication certificate returned by the blockchain. The key pair of the data buyer includes the public key PK b and private key SK b .

[0041] In this embodiment, the data buyer and the data seller both make the public key of their key pair public and save their private key locally.

[0042] Step S200 Data Release: The data seller encrypts the original data based on its private key, uploads the generated ciphertext to IPFS, obtains the content identifier returned by IPFS, and uploads the data description, content identifier, data price and transaction conditions corresponding to the original data as metadata to the blockchain, where the content identifier serves as the data storage location identifier.

[0043] The data description includes data type, time range and purpose.

[0044] As a specific implementation of data release, the data seller preprocesses its original data, performs denoising, format conversion and compression operations through data preprocessing, obtains the preprocessed original data, and uses its private key SK s Encrypt the preprocessed original data Data to generate ciphertext C s , C s =Encrypt(SK s ,Data), the data seller uploads the ciphertext to IPFS, the ciphertext is stored in the IPFS distributed network, and IPFS returns the unique CID of the data as the identifier of the data storage location.

[0045] Step S300: Data transaction: The data buyer queries and filters the target data through the blockchain, and initiates a data transaction request to the blockchain. The data transaction request includes the public key in the data buyer's key pair, the content identifier of the target data, and the payment method. The blockchain stores the data transaction request through a smart contract and forwards the data transaction request to the corresponding data seller.

[0046] As a specific implementation of data transaction, the data buyer browses the data directory on the blockchain, finds the required data, selects the target data according to the data description and initiates a data transaction request on the blockchain. The content of the data transaction request includes the public key PK in the data buyer's key pair. b , content identifier of target data and payment method, etc. The blockchain stores data transaction requests through smart contracts and forwards the data transaction requests to the corresponding data seller.

[0047] Step S400 Authentication and Authorization: The data buyer verifies the validity of the data based on the zero-knowledge proof submitted by the data seller to the blockchain. After the verification is passed, the data seller generates a re-encryption key based on its private key and the data buyer's public key, and uploads its re-encryption key to the proxy node. The proxy node re-encrypts the relevant ciphertext based on the re-encryption key, uploads the obtained re-encrypted ciphertext to IPFS, and writes the content identifier returned by IPFS into the blockchain. The blockchain writes the content identifier corresponding to the re-encrypted ciphertext into the smart contract.

[0048] As a specific implementation of authentication and authorization, the data seller generates a zero-knowledge proof based on the data attributes of its original data and uploads the zero-knowledge proof to the blockchain. The data buyer verifies the validity of the original data through the zero-knowledge proof. If the verification passes, the transaction continues. If the verification fails, the transaction terminates. The data attributes include the generation time of the original data and the specific conditions that the data meets.

[0049] If the transaction continues, the data seller will send the data based on its private key SK according to the data transaction request. s and the data buyer's public key PK b Generate re-encryption key PK s-b , and the re-encryption key PK s-b Submit to the proxy node, the proxy node receives the re-encryption key PK s-b After that, perform proxy re-encryption operation: based on the re-encryption key PK s-b Ciphertext C for data sellers s Re-encrypt to generate ciphertext C that can be decrypted by the data buyer b , C b =PRE PKs-b (C s ), and stores the re-encrypted ciphertext in IPFS, submits the new content identifier returned by IPFS to the blockchain, and the blockchain updates the transaction status and writes the new content identifier into the smart contract.

[0050] Step S500: Transaction payment: After the data buyer pays, the re-encrypted ciphertext is obtained from IPFS based on the content identifier returned by the blockchain, and the re-encrypted ciphertext is decrypted based on its private key to obtain the original data, and the transaction payment process is recorded in the blockchain.

[0051] The smart contract in this embodiment includes a data transaction contract, a re-encryption contract, and an access control list. The blockchain manages the data transaction request, authentication and authorization, and payment processes through the data transaction contract. The blockchain coordinates the re-encryption contract to coordinate the re-encryption of relevant ciphertexts by proxy nodes using the re-encryption key. The blockchain controls the access rights of data buyers and sellers through the access control list, adding data buyers and sellers who have registered their identities to the access control list.

[0052] After the data buyer makes payment based on the provisions of the smart contract, the blockchain returns the content identifier of the target data corresponding to the re-encrypted ciphertext to the data buyer. The data buyer obtains the re-encrypted ciphertext C from IPFS based on the returned content identifier. b , and re-encrypt the ciphertext C based on its own private key b Decryption to obtain the pre-processed original data Data, Data = Dec SKb (C b The data buyer’s payment methods include payment via blockchain tokens or payment methods specified in the smart contract.

[0053] When executing a transaction payment in this embodiment, when recording the transaction payment process in the blockchain, the recorded transaction information includes the content identifier of the target data corresponding to the re-encrypted ciphertext, the identity authentication certificate of the data buyer, the identity authentication certificate of the data seller, the payment amount and payment time of the data buyer, and the authorization information of the re-encryption key.

[0054] In this embodiment, each re-encryption key is accompanied by a generation timestamp and is generated using elliptic curve cryptography or bilinear pairings. The key generation process requires proxy node identity authentication. Re-encryption key authorization information includes key generation information, key usage permissions, key lifecycle management information, operation log audit information, and revocation and freezing mechanism information. Key generation information includes the re-encryption key generation timestamp. Key usage permissions include the re-encryption key user, authorization scope, and the re-encryption operation of the specific data applied. Key usage permissions are managed through access control lists in smart contracts. The key lifecycle includes the re-encryption key's validity period and update and revocation mechanism information, ensuring that the key remains valid within its validity period and supporting timely revocation and update of the key. Operation log audit information is used to record the corresponding logs generated by encryption operations, key authorization, and revocation events based on the re-encryption key. Each re-encryption operation and key authorization and revocation event will generate a corresponding log and record it on the blockchain, ensuring the traceability and compliance of all operations. The revocation and freezing mechanism information is used to ensure that the authorization of the key can be revoked or frozen in a timely manner when a key security issue occurs.

[0055] The method of this embodiment is based on the Fabric consortium blockchain and integrates zero-knowledge proof (ZKP) and proxy re-encryption (PRE) technology to build an efficient and secure transaction model framework. Zero-knowledge proof is combined with proxy re-encryption technology to achieve a higher level of privacy protection and security. The data seller verifies the authenticity and legitimacy of the data by generating a zero-knowledge proof, and at the same time uses proxy re-encryption technology to encrypt the data and control access rights. In this way, the buyer obtains access rights through the proxy re-encryption key while obtaining the encrypted data without directly exposing the data content. Zero-knowledge proof ensures the legitimacy of the data, while proxy re-encryption ensures the privacy of the data during transmission. The data owner can dynamically authorize the encrypted data uploaded to the IPFS distributed storage network, and re-encrypt the ciphertext through the proxy node, so that the authorized user can decrypt and access it without revealing the data owner's private key. In addition, the present invention fully combines the capabilities of edge computing, offloading computationally intensive tasks (such as zero-knowledge proof generation and verification, ciphertext re-encryption) to the edge server, greatly improving the efficiency and adaptability of the system. At the same time, the data transaction process is managed through Fabric smart contracts to ensure the transparency and non-tamperability of each step of the operation.

[0056] The method of this embodiment is not only applicable to IoT data transactions but can also be extended to areas with high privacy and security requirements, such as smart cities, the Industrial Internet of Things (IIoT), and healthcare data sharing. Experimental results demonstrate that this method achieves high efficiency, flexibility, and scalability in data transactions while ensuring privacy and security, providing a secure and reliable solution for IoT data transactions.

[0057] Zero-knowledge proof: Data sellers use zero-knowledge proof to prove to data buyers that they own real and valid data without having to disclose the data content, thereby ensuring the authenticity and privacy of the data.

[0058] Zero-Knowledge Proof (ZKP) is a cryptographic technique that allows a prover to prove to a verifier that a statement is correct without revealing any additional information about the statement. In data transactions, ZKP can be used to prove that a transacting party possesses legitimate data or meets certain conditions, without revealing the specific content of the data. This technology ensures data privacy, which is particularly important in decentralized transactions, avoiding the risk of data leakage or misuse during the transaction process.

[0059] In this embodiment, zero-knowledge proofs are used to verify the authenticity of data without exposing the data itself. For example, a data seller can generate a zero-knowledge proof to prove that the data they are selling meets certain conditions, such as the data range or format (for example, the value of a temperature sensor is within a specified range). During the transaction, the data buyer verifies the legitimacy of the data by verifying this zero-knowledge proof without directly viewing the data itself. This process is implemented using zero-knowledge proofs generated by the go-snark library, which can efficiently generate and verify proofs, ensuring the security and privacy of the verification process.

[0060] In data transactions, generating a zero-knowledge proof involves two main steps: first, the data seller generates a cryptographic proof based on their data, proving that their data meets specific conditions; second, the data buyer verifies the proof to confirm the data's accuracy. In this embodiment, the go-snark library is used to generate proofs that conform to zk-SNARKs (Succinct Non-Interactive Zero-Knowledge Proofs). This proof format is efficient and compact, making it suitable for blockchain and distributed storage environments. During the verification process, the buyer only needs to check the validity of the proof without obtaining any actual data, thus ensuring data privacy.

[0061] Proxy re-encryption: Proxy re-encryption technology enables the secure transfer of data keys between data sellers and buyers. Data files uploaded by data sellers after encryption can be re-encrypted by the proxy, allowing buyers to decrypt and use them securely without having direct access to the original key.

[0062] Proxy re-encryption (PRE) is an encryption method that uses a proxy (i.e., an encryption agent) to convert the encryption key of the encrypted data, allowing the data to be accessed by different authorized parties while still in an encrypted state. During data storage and exchange, proxy re-encryption effectively protects data privacy, preventing direct exposure of sensitive information while allowing specific authorized parties to decrypt and access the data.

[0063] In this embodiment, transaction data is encrypted and stored in IPFS, ensuring data confidentiality during storage. To ensure secure data transmission between multiple transaction parties while still protecting data privacy, proxy re-encryption technology is employed. Specifically, the data owner (data provider) encrypts the data and uploads it to IPFS, generating an encrypted ciphertext. When the data buyer needs to access the data, the data provider uses proxy re-encryption technology to generate a new key, allowing the buyer to decrypt and access the data without obtaining the original encryption key. This process is performed by a trusted proxy re-encryption service, which enables secure data sharing between authorized parties through key conversion. Re-encryption technology provides strong data privacy protection. Throughout the data transaction process, the two parties do not need to directly exchange encryption keys. The proxy only allows authorized parties to access the data through the key conversion service. This approach ensures minimal data exposure, ensuring that only legally authorized parties can decrypt the data, significantly improving data security and privacy protection. Furthermore, proxy re-encryption prevents tampering or leakage of the data itself during storage, enhancing the trustworthiness of the system.

[0064] Compared to traditional data exchange methods, this invention uses proxy re-encryption technology to ensure data privacy while reducing reliance on centralized services. The introduction of proxy re-encryption ensures that data remains encrypted during transactions, allowing only authorized parties to decrypt and use the data. This offers significant security advantages in multi-party data transactions.

[0065] The method of this embodiment has the following advantages:

[0066] 1. Data access control and smart contracts:

[0067] (1) The blockchain platform automatically executes the data transaction process through smart contracts, and the data access control mechanism is embedded in the contract. Data providers can specify the access rights of the data, control who can access the data and the conditions for access;

[0068] (2) Smart contracts automatically execute the payment and data delivery process according to preset rules, ensuring that both parties complete the transaction in accordance with the terms of the contract;

[0069] (3) Access control is implemented through encryption keys and permission management mechanisms to ensure that only authorized users can access sensitive data. Different levels of data decryption or data access scope restrictions are provided for different access rights.

[0070] 2. Data transaction transparency and traceability:

[0071] (1) Data transaction records are permanently stored in the blockchain to ensure the transparency and traceability of the transaction process. All transaction history, identity information of data providers and users, transaction amounts, timestamps, and other information are recorded on the blockchain to ensure the legitimacy and transparency of data transactions.

[0072] (2) Users can check the transaction records they participated in at any time to ensure the credibility of the transaction.

[0073] The method of this embodiment can be applied to smart home data transactions. The data generated by home smart devices (such as temperature and humidity, air quality, security monitoring data, etc.) is uploaded to the platform in an encrypted manner. Data users (such as smart home service providers) can purchase this data for further analysis and service optimization; data providers set access rights based on the privacy requirements of the data to protect the privacy and security of family members.

[0074] The method of this embodiment can be used for the blockchain data transaction system of the Internet of Things. The valuable data generated by the Internet of Things is saved in the blockchain, and the transmission and transaction of the data are recorded. All transaction information is auditable and tamper-proof. The data is owned by both users and buyers. By deploying the blockchain network on edge layer devices, the shortcomings of the limited computing power of IoT devices are compensated, and an off-chain storage method is adopted for IoT big data. This article aims to propose a data transaction framework that combines blockchain technology to collect data from the user's IoT device end to the edge node layer and finally to the data demand end. In general, the following three goals are achieved:

[0075] 1. Data authenticity verification goal: Through zero-knowledge proof technology, data sellers can prove the authenticity and validity of their data to data buyers without revealing the data content. This solves the problem of buyers having difficulty trusting data quality in traditional data transactions.

[0076] 2. Data privacy protection goal: Use proxy re-encryption technology to ensure that data is not exposed to unauthorized third parties during the transaction process:

[0077] (1) The data seller encrypts the data and stores it, and the data buyer uses the agent's re-encrypted key to decrypt it;

[0078] (2) It avoids the risk of direct key sharing and ensures the privacy and security of transaction data;

[0079] 3. Data security objectives: Fabric blockchain technology provides the following:

[0080] (1) The hash value of the data is stored on the blockchain, ensuring the integrity of the data and its irreversibility;

[0081] (2) Each step of the data transaction process is driven by smart contracts, avoiding human intervention and improving security and transparency.

[0082] The method of this embodiment achieves the goals of authenticity verification, privacy protection, security assurance, and decentralization throughout the entire data transaction process. It also improves transaction efficiency through efficient storage and automated transaction processes, providing a reliable and efficient solution for IoT data transactions. To explain the different functions of this IoT-oriented blockchain data transaction system, the corresponding description of each entity is as follows:

[0083] IoT devices: Data producers typically use sensors to collect environmental data. These sensors monitor real-time environmental conditions (including temperature, humidity, light, air pressure, GPS location, and other factors) as well as device status (such as operating status and energy consumption). These devices also possess basic edge computing capabilities, enabling them to perform processing operations such as denoising, filtering, compression, or encryption on raw data to reduce redundant information and improve data transmission efficiency. They also utilize encryption algorithms (such as AES or ECC) to protect data privacy, and digital signatures to ensure data authenticity and integrity. Given the specific scale and level of detail (i.e., volume and granularity) of data generated by IoT (IIoT) devices, these data are uploaded to off-chain decentralized storage. This storage method not only ensures efficient data access but also effectively mitigates blockchain bloat. Notably, metadata such as device IDs, data capture timestamps, and hash values of the corresponding data are stored on-chain. This on-chain record ensures data integrity and source authenticity, enabling potential transaction participants to verify the authenticity of the data they access.

[0084] Data sellers: In the data trading world, data sellers are entities that sell data to other organizations or individuals, playing a key role in data circulation. Data sellers are diverse and can be the original data owners, such as business data generated by corporate operations or exclusive experimental data collected by scientific research institutions. They can also be professional data collectors who use methods such as web crawlers and sensor networks to collect data and, after cleaning and integrating it, form commercially valuable datasets. They also include entities that deeply process and organize data and obtain sales authorization in accordance with regulations. They use data mining and other technologies to uncover the deep value of data and then bring it to market. Data sellers often also serve as equipment owners or administrators, responsible for controlling the entire data transaction process. They also possess basic edge computing capabilities, enabling them to apply filtering algorithms for noise reduction, data compression algorithms for redundancy reduction, and encryption algorithms (such as AES and ECC) at the source to ensure data accuracy, transmission efficiency, and privacy. As far as the Internet of Things is concerned, device owners can sell valuable data generated by the devices (such as operating status, energy consumption, environmental parameters, etc.) to demanders, negotiate pricing based on value, obtain profit rewards through transactions, realize data asset monetization, and promote the rational flow of data and market prosperity.

[0085] Data buyers: Data buyers play a crucial role in data transactions. They are individuals, organizations, and other entities that purchase data to meet specific needs or achieve specific goals. The data purchased by these entities has a wide range of applications, including but not limited to market research, data analysis, advertising targeting, personalized recommendations, and decision support.

[0086] There are two main ways for data buyers to obtain data. One is to screen the data already published on the blockchain and select the data that meets their own needs; the other is to publish their own data demand information to the blockchain and obtain the required data through the transaction process.

[0087] In the Internet of Things (IIoT) data market, data users, often referred to as buyers, actively seek specific datasets for various purposes, such as conducting research, conducting industry analysis, and forecasting trends. Their participation fosters a vibrant and competitive auction environment, effectively enhancing the value of data.

[0088] Specifically, during the auction, the winning bidder receives a unique hash value from the data owner. This hash value allows the winning bidder to access and download the corresponding dataset from the decentralized InterPlanetary File System (IPFS) server. After analyzing the data, users can rate it based on metrics such as quality, relevance, and accuracy. This feedback mechanism not only ensures transparency in the data transaction process but also incentivizes data owners to maintain high data quality standards. It can be said that it is the continued demand from data users for accurate, timely, and targeted Industrial Internet of Things (IIoT) datasets that continues to drive the development of the entire data market.

[0089] Blockchain: Hyperledger Fabric is used as the underlying blockchain technology throughout the system architecture. Its nodes are deployed on edge service nodes, acting as the key intermediary between data transaction parties. Hyperledger Fabric, with its decentralized network architecture, creates an ideal operating environment for data transactions, freeing them from the limitations of traditional centralized models and enabling them to operate smoothly within a distributed network.

[0090] Crucially, Hyperledger Fabric provides a highly secure transaction environment. Within this environment, all data involved is encrypted and verified using advanced cryptographic techniques to ensure confidentiality, integrity, and verifiability. It utilizes a variety of cryptographic techniques, such as hashing algorithms and digital signatures, to strictly safeguard data security during transmission, storage, and transactions, allowing all parties involved in a transaction to interact with confidence.

[0091] For IoT data, both the digitization and blockchain process and the subsequent data transaction process are implemented through the smart contracts carefully designed and deployed on the Hyperledger Fabric blockchain in this embodiment. These smart contracts act like pre-defined rule engines, strictly executing related operations according to established logic, precisely controlling every step and ensuring the orderliness and standardization of the entire data interaction process. This enables the efficient flow and transaction of IoT data within the secure and decentralized framework built by Fabric.

[0092] Distributed off-chain storage: With the widespread adoption of IoT devices, the amount of data generated is growing exponentially, making the storage and management of this data crucial. Distributed storage, with its many advantages, offers a viable storage solution to this challenge. Its scalability and high availability make it a viable solution to the growing demand for data and ensures stable data access in a variety of complex scenarios.

[0093] Among numerous distributed storage solutions, choosing the InterPlanetary File System (IPFS) as an off-chain data storage method offers numerous benefits. On the one hand, it significantly enhances data security. Through its unique encryption mechanism and distributed data storage architecture, data faces fewer security threats during storage. On the other hand, IPFS improves data reliability. Leveraging its distributed node network, even if some nodes fail, data remains intact and accessible, significantly reducing the risk of data loss or inaccessibility due to single points of failure. Furthermore, the use of IPFS can effectively reduce storage costs. Compared to traditional storage methods, it utilizes idle network resources for data storage, avoiding the high hardware investment and maintenance costs required for large-scale centralized storage.

[0094] Crucially, IPFS, as an off-chain storage method, can build a more robust infrastructure for blockchain-based data transaction systems. It complements blockchain technology, ensuring the security and efficiency of data transactions while further expanding the carrying capacity and stability of the entire system, allowing data transactions to proceed smoothly in a more reliable environment.

[0095] The above is a detailed introduction to the blockchain-based data transaction privacy protection method provided by the present invention. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only intended to help understand the method of the present invention and its core ideas. At the same time, for those skilled in the art, according to the ideas of the present invention, there may be changes in the specific implementation methods and application scopes. In summary, the content of this specification should not be understood as limiting the present invention.

Claims

1. A data transaction privacy protection method based on blockchain, characterized in that: Applied to data buyers, data sellers, IPFS, proxy nodes, and blockchains deployed with Fabric networks, where smart contracts are deployed, the method comprises the following steps: System initialization: The data seller and the data buyer register their identities with the blockchain based on the key pairs they generate, receive the identity authentication certificates returned by the blockchain, and make their public keys public; Data publishing: The data seller encrypts the original data based on its private key, uploads the generated ciphertext to IPFS, obtains the content identifier returned by IPFS, and uploads the data description, content identifier, data price and transaction conditions corresponding to the original data to the blockchain as metadata, where the content identifier serves as the data storage location identifier; Data transaction: The data buyer queries and selects the target data through the blockchain, and initiates a data transaction request to the blockchain. The data transaction request includes the public key in the data buyer's key pair, the content identifier of the target data, and the payment method. The blockchain stores the data transaction request through a smart contract and forwards the data transaction request to the corresponding data seller; Authentication and authorization: The data buyer verifies the validity of the data based on the zero-knowledge proof submitted by the data seller to the blockchain. After the verification is passed, the data seller generates a re-encryption key based on its private key and the data buyer's public key, and uploads its re-encryption key to the proxy node. The proxy node re-encrypts the relevant ciphertext based on the re-encryption key, uploads the obtained re-encrypted ciphertext to IPFS, and writes the content identifier returned by IPFS into the blockchain. The blockchain writes the content identifier corresponding to the re-encrypted ciphertext into the smart contract; Transaction payment: After the data buyer pays, the re-encrypted ciphertext is obtained from IPFS based on the content identifier returned by the blockchain, and the re-encrypted ciphertext is decrypted based on its private key to obtain the original data, and the transaction payment process is recorded in the blockchain.

2. The data transaction privacy protection method based on blockchain according to claim 1 is characterized in that: Both the data seller and the data buyer generate their key pairs through elliptic curve encryption algorithm or bilinear pairing.

3. The data transaction privacy protection method based on blockchain according to claim 1 is characterized in that: The data seller preprocesses the original data, performs denoising, format conversion and compression operations through data preprocessing to obtain the preprocessed original data, and encrypts the preprocessed original data based on its private key to generate ciphertext; Correspondingly, the data buyer decrypts the re-encrypted ciphertext based on its private key to obtain the pre-processed original data.

4. The data transaction privacy protection method based on blockchain according to claim 1 is characterized in that: The data seller generates a zero-knowledge proof based on the data attributes of its original data and uploads the zero-knowledge proof to the blockchain. The blockchain verifies the validity of the original data through the zero-knowledge proof. If the verification passes, the transaction continues. If the verification fails, the transaction is terminated and the data buyer is notified. Among them, data attributes include the generation time of the original data and the specific conditions that the data meets.

5. The data transaction privacy protection method based on blockchain according to claim 1 is characterized in that: The smart contract includes a data transaction contract, a re-encryption contract, and an access control list; Blockchain manages the process of data transaction requests, authentication authorization, and transaction payment through data transaction contracts; The blockchain coordinates each proxy node to re-encrypt the relevant ciphertext based on the re-encryption key through the re-encryption contract; The blockchain controls the access rights of data buyers and data sellers to the blockchain through the access control list, and adds the data buyers and data sellers registered through identities to the access control list.

6. The data transaction privacy protection method based on blockchain according to claim 1 is characterized in that: After the data buyer makes payment based on the provisions of the smart contract, the blockchain returns the content identifier of the re-encrypted ciphertext corresponding to the target data to the data buyer; Among them, the payment methods for data buyers include payment through blockchain tokens or payment according to the payment methods specified in the smart contract.

7. The data transaction privacy protection method based on blockchain according to claim 1 is characterized in that: When the transaction payment process is recorded in the blockchain, the recorded transaction information includes the content identifier of the target data corresponding to the re-encrypted ciphertext, the identity authentication certificate of the data buyer, the identity authentication certificate of the data seller, the payment amount and payment time of the data buyer, and the authorization information of the re-encryption key; Among them, the authorization information of the re-encryption key includes key generation information, key usage rights, key life cycle management information, operation log audit information and revocation and freezing mechanism information. The key generation information includes the generation timestamp of the re-encryption key. The key usage rights include the user of the re-encryption key, the authorization scope and the re-encryption operation of the specific data applied. The key usage rights are managed through the access control list in the smart contract. The key life cycle includes the validity period of the re-encryption key and the update and revocation mechanism information. The operation log audit information is used to record the corresponding logs generated by encryption operations, key authorization and revocation events based on the re-encryption key. The revocation and freezing mechanism information is used to ensure that when there is a security problem with the key, the authorization of the key can be revoked or frozen in time.

Citation Information

Patent Citations

  • Private data storage and access control method and system based on block chain

    CN112989415A

  • Block chain-based data transaction model and privacy protection method

    CN114900290A

  • Block chain data proxy re-encryption model based on IPFS

    CN115348054A

  • Data privacy transaction method based on zero knowledge proof

    CN115760399A

  • Supply chain product traceability system and method based on proxy re-encryption

    CN116827573A

Cited By

  • Data transaction system

    CN121010379A

  • A data transaction system

    CN121010379B

  • Implementation method capable of verifying data asset transaction of Internet of Things equipment

    CN121530542A

  • An implementation method for verifying data asset transaction of internet of things device

    CN121530542B