Trusted data acquisition verification method based on block chain, oracle machine, TEE and VRF

By introducing oracle, TEE and VRF technologies into blockchain data processing solutions, the performance and stability problems of existing solutions under high data volume and high computing requirements are solved, and efficient and reliable data acquisition and verification are achieved.

CN120086288AActive Publication Date: 2025-06-03BEIJING QU CREATIVE TECH CO LTD

Patent Information

Application Number
CN202510558951.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-06-03
Estimated Expiration
2045-04-30

AI Technical Summary

Technical Problem

The existing blockchain-based data processing solution has high resource occupancy, low query efficiency, and heavy computing tasks for smart contracts, which can easily cause performance decline and stability problems.

Method used

The trusted data acquisition verification method based on blockchain, oracle, TEE and VRF is adopted, and the target field is constructed through smart contracts and the private key is signed, and private chain data is processed and synchronously stored; TEE is used for aggregation calculation, oracle is used to chain aggregate results, and random verification of the aggregation results is achieved through VRF.

Benefits of technology

It improves data processing efficiency and storage optimization, reduces resource occupancy and computing task burden, enhances system performance and stability, and realizes trustworthy data acquisition and verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120086288A_ABST
    Figure CN120086288A_ABST
Patent Text Reader

Abstract

The invention relates to the related technical field of block chains, in particular to a trusted data acquisition verification method based on a block chain, an oracle machine, a TEE and a VRF. The method comprises the steps of processing collected data according to a preset frequency, constructing a target field corresponding to the collected data based on a preset smart contract, and performing private key signature to obtain uplink data; the target field is used for representing the collected data; performing uplink operation on the uplink data; meanwhile, synchronizing the collected data to a preset database for persistent storage; obtaining credible collection data based on the block chain, and performing aggregation calculation on the collection data based on a pre-constructed credible execution environment to obtain an aggregation result; on the basis of a preset oracle machine, adopting a block chain technology to perform uplink on the aggregation result; and when the user requests the aggregation result, random verification is carried out on the aggregation result based on the oracle machine and the VRF so as to realize credible acquisition.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of blockchain, and specifically relates to a method for obtaining and verifying trusted data based on blockchain, oracle machine, TEE, and VRF. Background Art

[0002] In practical applications, metering terminals are responsible for collecting power consumption data and reporting the data at a certain frequency (such as once per second). Each aggregation operator has multiple aggregation control units, and each control unit has multiple metering terminals under its jurisdiction. Aggregators summarize the active power data of all metering points under the unit with the aggregation control unit as the unit. To ensure the security, credibility, and traceability of data, existing solutions are mostly based on blockchain technology. The metering terminals report the collected power consumption data to the blockchain, and then aggregate the metering terminal data on the blockchain, and then compare and verify it with the data aggregated by the aggregator.

[0003] Although the above solutions guarantee the security, credibility, and immutability of data to a certain extent, in actual engineering practices, a series of problems that need to be solved urgently have emerged: on the one hand, the number of metering terminals is huge, reaching the scale of tens of thousands, and the data is reported once per second, resulting in a daily data volume of up to more than a dozen G. This has caused the scale of the state data stored based on smart contracts to expand rapidly, the resource occupancy rate to remain high, and the query efficiency to be greatly reduced; on the other hand, the aggregation and calculation of metering terminal data are processed by smart contracts. Due to the huge amount of data, the calculation tasks of smart contracts are heavy, the execution speed is slow, and problems such as stack overflow are even likely to occur, resulting in a decline in the overall performance of the system and a serious impact on stability.

[0004] Under this background, there is an urgent need for a more efficient, reliable, and scalable solution to overcome the defects of the existing technology, meet the growing data processing and verification requirements, and provide strong support for the wide application of distributed energy and the trusted acquisition and verification of data in other fields. Summary of the Invention

[0005] In view of this, embodiments of this application are committed to providing a method for obtaining and verifying trusted data based on blockchain, oracle machine, TEE, and VRF.

[0006] This application provides a method for obtaining and verifying trusted data based on blockchain, oracle machine, TEE, and VRF, including: Processing the collected data according to a preset frequency, constructing a target field corresponding to the collected data based on a preset smart contract, and performing private key signature to obtain the data to be uploaded to the chain; the target field is used to represent the collected data; Performing an operation to upload the data to the chain; at the same time, synchronizing the collected data to a preset database for persistent storage; Obtain trusted acquisition data based on the blockchain, and perform aggregation calculation on the acquisition data based on a pre-constructed trusted execution environment to obtain an aggregation result; Based on a preset oracle, use blockchain technology to upload the aggregation result to the chain; When a user requests the aggregation result, perform random verification on the aggregation result based on the oracle and VRF to achieve trusted acquisition; Among them, the target fields include: terminal code, operating status, active power, acquisition timestamp.

[0007] In some embodiments, the preset frequency is once per second.

[0008] In some embodiments, perform an on-chain operation on the on-chain data; at the same time, synchronize the acquisition data to a preset database for persistent storage, including: Emit a data record event in the data upload interface of the smart contract, and the event definition is as follows: event Recorded(string t_id, string status, string p, string tm); Among them, string t_id represents the terminal code; string status represents the operating status; string p represents the active power; string tm represents the acquisition timestamp.

[0009] The off-chain data synchronization service integrates the blockchain SDK, listens for data record events, and then stores the corresponding acquisition data in the database for persistent storage according to the event content.

[0010] In some embodiments, the obtaining of trusted acquisition data based on the blockchain and performing aggregation calculation on the acquisition data based on a pre-constructed trusted execution environment to obtain an aggregation result includes: Obtain a certificate for TLS communication from the authentication service and configure it into the TEE executable program service; The external service integrates the SDK of the TEE, registers and logs in the calling user, and then calls the TEE calculation service to initiate an aggregation calculation task; The TEE service executes the aggregation calculation task to perform aggregation calculation on the acquisition data to obtain an aggregation result.

[0011] In some embodiments, when the user requests the aggregation result, performing random verification on the aggregation result based on the oracle and VRF to achieve trusted acquisition includes: Obtain the aggregation result and a random number from the off-chain data source; the random number is within a first preset interval: If the random number is within the second preset interval, verify the aggregation result based on the blockchain; where the second preset interval belongs to the first preset interval; If the verification result is inconsistent, notify the preset business system.

[0012] In some embodiments, it further includes: Set the first preset interval and the second preset interval to adjust the probability of verification.

[0013] This application provides a trusted data acquisition and verification device based on blockchain, oracle, TEE, and VRF, including: A construction module, configured to process the collected data at a preset frequency, construct a target field corresponding to the collected data based on a preset smart contract, and perform a private key signature to obtain the data to be uploaded; the target field is used to represent the collected data; An uploading module, configured to perform an uploading operation on the data to be uploaded; meanwhile, synchronize the collected data to a preset database for persistent storage; An aggregation module, configured to obtain trusted collected data based on the blockchain, perform an aggregation calculation on the collected data based on a pre-constructed trusted execution environment, and obtain an aggregation result; The uploading module is further configured to upload the aggregation result based on a preset oracle using blockchain technology; A verification module, configured to perform a random verification on the aggregation result based on the oracle and VRF when a user requests the aggregation result to achieve trusted acquisition; Wherein, the target field includes: terminal encoding, operating status, active power, and acquisition timestamp.

[0014] This application provides an electronic device, including: A processor, and a memory for storing the executable program of the processor; The processor is configured to implement the trusted data acquisition and verification method based on blockchain, oracle, TEE, and VRF as described above by running the program in the memory.

[0015] This application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is run by a processor, the processor is caused to execute the trusted data acquisition and verification method based on blockchain, oracle, TEE, and VRF as described above.

[0016] This application provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the trusted data acquisition and verification method based on blockchain, oracle, TEE, and VRF as described above.

[0017] A trusted data acquisition and verification method based on blockchain, oracle, TEE, and VRF provided by this application processes the collected data at a preset frequency, constructs target fields corresponding to the collected data based on a preset smart contract, and performs private key signing to obtain the data to be uploaded to the chain; the target fields are used to characterize the collected data; perform an operation to upload the data to be uploaded to the chain; at the same time, synchronize the collected data to a preset database for persistent storage; obtain trusted collected data based on the blockchain, and perform aggregation calculation on the collected data based on a pre-constructed trusted execution environment to obtain an aggregation result; based on a preset oracle, use blockchain technology to upload the aggregation result to the chain; when a user requests the aggregation result, perform random verification on the aggregation result based on the oracle and VRF to achieve trusted acquisition; wherein, the target fields include: terminal code, operating status, active power, and acquisition timestamp. With such settings, in the solution provided by this application, data is collected at a preset frequency, which can comprehensively capture dynamic information and reflect the real-time state. Constructing target fields based on a smart contract and performing private key signing clarifies the key information of the data, and the signature guarantees the authenticity and integrity of the data source and prevents tampering. The preset processing flow and target fields standardize and automate data processing, improve efficiency, reduce manual intervention and errors, ensure that data is generated and stored according to a unified specification, and facilitate subsequent analysis and sharing. The operation of uploading to the chain utilizes the blockchain distributed ledger, encrypted storage, and consensus mechanism to ensure the security and immutability of data storage, providing a technical guarantee for the credibility of the data. TEE provides an isolated environment to prevent external illegal access during the calculation of sensitive data, protecting data privacy and security. Performing aggregation calculation in TEE and utilizing its security and integrity protection mechanism ensure that the calculation process is executed as expected and the result is credible and reliable. The oracle serves as a bridge to credibly obtain and upload data such as the off-chain aggregation result, expanding the functions of the blockchain and realizing data interaction with the external world. Randomly verifying the aggregation result can timely detect data anomalies or errors, take measures to correct them, ensure the stable operation of the system, and enhance reliability. The solution design considers data processing efficiency, storage optimization, and reasonable allocation of computing resources, improves the system performance, enhances stability, and meets business requirements. Combining technologies such as blockchain, TEE, oracle, and VRF, innovating data processing and verification methods, expanding the scope of technology application, and providing a practical and reliable way for the trusted acquisition and verification of aggregated data of distributed devices in the power industry. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] By describing the embodiments of the present application in more detail with reference to the accompanying drawings, the above and other objects, features, and advantages of the present application will become more obvious. The accompanying drawings are used to provide a further understanding of the embodiments of the present application, and constitute a part of the specification. They are used together with the embodiments of the present application to explain the present application and do not constitute a limitation to the present application. In the accompanying drawings, the same reference numerals generally represent the same components or steps.

[0019] Figure 1 It is a schematic flow chart of a trusted data acquisition and verification method based on blockchain, oracle machine, TEE, and VRF provided by an embodiment of the present application.

[0020] Figure 2 It is a schematic structural diagram of a trusted data acquisition and verification device based on blockchain, oracle machine, TEE, and VRF provided by an embodiment of the present application.

[0021] Figure 3 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0022] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0023] With the transformation of the power system towards low-carbon in recent years and the development of distributed power generation and distributed energy storage technologies, the number of distributed energy sources represented by wind power, photovoltaics, electric vehicles, energy storage devices, and controllable loads has grown rapidly. Under the background of "dual carbon", promoting third parties such as new energy storage and source-load aggregators to provide power ancillary services and participate in the power ancillary service market as independent entities is a key focus in the operation of the new power system and new business forms. However, the physical nodes of large-scale distributed resources are scattered, information acquisition is difficult, and there are many stakeholders, and there are many technical challenges to be solved for their participation in the operation of the power system. In practical applications, electricity consumption data is collected and uploaded by metering terminals. Each aggregator operator has multiple aggregation control units, and each aggregation control unit contains multiple metering terminals. Each aggregator will aggregate the active power data of all metering points under each aggregation control unit in units of the aggregation control unit. In the existing solutions, in order to ensure the security, credibility, and traceability of data, based on blockchain technology, the metering terminals will report the collected electricity consumption data to the blockchain, and then aggregate the metering terminal data on the blockchain, and then compare and verify it with the aggregated data of the aggregator obtained. The above solution is a great breakthrough in solving the security, credibility, and immutability of data. However, in actual engineering practice, many problems have also been exposed. On the one hand, the number of metering terminals is huge, reaching a scale of more than ten thousand. The data is reported once per second, and the daily data volume can reach more than a dozen G, resulting in a huge scale of state data stored by smart contracts, high resource occupancy, and low query efficiency. On the other hand, the aggregation calculation of metering terminal data is processed by smart contracts. However, due to the large amount of data, the smart contract calculation tasks are heavy, the calculation execution is slow, and problems such as stack overflow are likely to occur, resulting in a decline in the overall performance of the system and poor stability. Based on this, the present invention proposes a new solution. The smart contract does not store the collected data of the metering terminals. The off-chain service synchronizes the data on the chain, and uses a trusted execution environment (TEE) to perform the aggregation calculation of the terminal data. The blockchain obtains the result of the aggregation calculation through an oracle, ensuring the credibility of the aggregation calculation process. In addition, based on the verifiable random function (VRF), random verification of the terminal data is realized to ensure the credibility of the terminal data. Based on this, a method for realizing trusted data acquisition and verification based on blockchain, oracle, TEE, and VRF is proposed.

[0024] After introducing the basic principle of the present application, various non-limiting embodiments of the present application will be specifically introduced below with reference to the accompanying drawings.

[0025] Figure 1 is a schematic flowchart of a method for trusted data acquisition and verification based on blockchain, oracle, TEE, and VRF provided by an embodiment of the present application. As Figure 1 shown, the method includes the following content.

[0026] Step S110: Process the collected data at a preset frequency, construct target fields corresponding to the collected data based on a preset smart contract, and perform private key signing to obtain the data to be uploaded to the chain. The target fields are used to represent the collected data. Specifically, the preset frequency is once per second.

[0027] Step S120: Perform an operation to upload the data to the chain. At the same time, synchronize the collected data to a preset database for persistent storage. Step S130: Obtain trusted collected data based on the blockchain, and perform aggregation calculation on the collected data based on a pre-constructed trusted execution environment to obtain an aggregation result. Step S140: Based on a preset oracle, use blockchain technology to upload the aggregation result to the chain. Step S150: When a user requests the aggregation result, perform random verification on the aggregation result based on the oracle and VRF to achieve trusted acquisition. Among them, the target fields include: terminal encoding, operating status, active power, and collection timestamp.

[0028] With such settings, by defining relevant smart contract events and contract structures, it is realized that the contract does not store the data collected by the metering terminal, and the off-chain service synchronizes the metering terminal data by listening to the contract events. The TEE is used to obtain the data required for aggregation calculation from different services to ensure the security and trustworthiness of the aggregation calculation process. The oracle is used to securely and trustworthily obtain off-chain data. At the same time, the oracle is used to obtain the VRF, and according to the set algorithms and schemes, random verification of the off-chain terminal data is realized to ensure the security and trustworthiness of the terminal data.

[0029] In some embodiments, the performing an operation to upload the data to the chain. At the same time, synchronizing the collected data to a preset database for persistent storage includes: Emit a data record event in the data upload interface of the smart contract. The event definition is as follows: event Recorded(string t_id, string status, string p, string tm); Among them, string t_id represents the terminal encoding; string status represents the operating status; string p represents the active power; string tm represents the collection timestamp.

[0030] The off-chain data synchronization service integrates the blockchain SDK, listens to the data record event, and then stores the corresponding collected data in the database for persistent storage according to the event content.

[0031] Specifically, event definition: define a data recording event in the smart contract to trigger when the data is uploaded to the chain. The event definition is as follows: event Recorded(string t_id, string status, string p, string tm); Among them, string t_id represents the terminal code, which is used to uniquely identify each terminal device; string status represents the operating status, which is used to indicate whether the terminal device is currently online or offline; string p represents active power, which is used to reflect the power consumption of the terminal device at a specific time point; string tm represents the collection timestamp, which is used to record the exact time of data collection.

[0032] When the terminal device collects and processes the data, it constructs the on-chain data structure, signs the data with the account private key, and then calls the upload interface of the smart contract through the blockchain SDK or RPC interface. The Recorded event is triggered in the interface, and the key information of the data (terminal code, operating status, active power, collection timestamp) is sent as event parameters.

[0033] Off-chain data synchronization service integrates blockchain SDK: The off-chain data synchronization service integrates blockchain SDK so that events on the blockchain can be monitored in real time.

[0034] Listening to data recording events: The off-chain data synchronization service listens to the Recorded events issued by the smart contract through the blockchain SDK. Once the event is detected, the content of the event is obtained, including terminal code, operating status, active power, collection timestamp and other information.

[0035] Persistent data storage: Based on the acquired event content, the off-chain data synchronization service stores the corresponding collected data in the preset database for persistent storage. In this way, the collected data is not only stored securely and reliably on the blockchain, but also efficiently managed and queried in the off-chain database.

[0036] Through the above method, the on-chain operation of on-chain data and the off-chain synchronous storage of collected data are realized, which not only utilizes the tamper-proof characteristics of blockchain to ensure the security and credibility of data, but also relies on the efficient query and management capabilities of the off-chain database to meet the storage and processing needs of large amounts of collected data, providing a solid data foundation for subsequent data aggregation calculations and verification operations.

[0037] In some embodiments, obtaining trusted acquisition data based on a blockchain, and performing aggregation calculation on the acquisition data based on a pre-constructed trusted execution environment, including: obtaining a certificate for TLS communication from an authentication service and configuring it into the TEE executable program service; an external service integrates the TEE SDK, registers and logs in the calling user, and then calls the TEE computing service to initiate an aggregation calculation task; the TEE service executes the aggregation calculation task to perform aggregation calculation on the acquisition data and obtain an aggregation result.

[0038] Specifically, obtaining a certificate from the authentication service: Before starting the aggregation calculation, the TEE trusted execution service needs to obtain a certificate for TLS (Transport Layer Security) communication from the authentication service. This certificate is used to establish a secure communication channel between the TEE service and the external service, ensuring the confidentiality and integrity of data during transmission.

[0039] Configuring the certificate into the TEE executable program service: Configure the obtained TLS communication certificate into the TEE executable program service, so that the TEE service can use this certificate for secure network communication, verify the identity of the other party when interacting with other services, and encrypt the transmitted data.

[0040] The external service integrates the TEE SDK: External services (such as oracle services, etc.) need to integrate the software development kit (SDK) of the TEE in order to be able to interact with the TEE environment. By integrating the TEE SDK, external services can call various functions provided by the TEE, such as data encryption, signature verification, remote attestation, etc.

[0041] Registering and logging in the calling user: Before calling the TEE computing service, the external service needs to register and log in the calling user. This usually involves sending the user's identity information and authentication credentials to the TEE service, and the TEE service authenticates the user to ensure that only authorized users can initiate the aggregation calculation task.

[0042] Calling the TEE computing service to initiate an aggregation calculation task: After registration and login, the external service can call the TEE computing service to initiate an aggregation calculation task. This usually includes the following sub-steps: Registering the method for executing data: Define the main business logic of the aggregation calculation task, including from which data sources to obtain data, how to perform aggregation calculation, etc., and register these methods into the TEE service.

[0043] Creating a task and binding data and methods: According to the specific aggregation calculation requirements, create a task instance and bind the relevant data and methods to this task, clarifying the input data and execution logic of the task.

[0044] Execute the created task: Send a task execution request to the TEE service. After receiving the request, the TEE service starts the aggregation calculation according to the predetermined method and data.

[0045] The TEE service receives and processes the task request: After receiving the aggregation calculation task request sent by the external service, the TEE service first parses the request to extract relevant information of the task, such as task ID, input data, execution method, etc. Then it verifies the identity of the calling user to ensure that the task request comes from a legitimate user.

[0046] Obtain data from relevant services: According to the definition of the task, the TEE service needs to obtain data from different services such as the metering terminal data synchronization service cluster and the mapping relationship service cluster between the metering terminal and the aggregation control unit. For example, obtain the mapping relationship data between the aggregation control unit and the terminal, and the second-level data of the corresponding metering terminal under the specified aggregation control unit within a specified time range, etc.

[0047] Execute the aggregation calculation program: The TEE service uses the obtained data to perform calculations according to the predetermined aggregation calculation method. During the calculation process, the TEE environment provides security and integrity protection to ensure that the calculation process is not interfered with externally and the privacy of the data is strictly protected. After the calculation is completed, the aggregation result is obtained, which contains information such as the identification, name, total active power, and corresponding timestamp of each aggregation control unit.

[0048] Through the above steps, using the blockchain to obtain trustworthy acquisition data and performing aggregation calculations in a trusted execution environment not only ensures the credibility and security of the data, but also realizes the efficiency and reliability of the aggregation calculation process, providing accurate data support for subsequent business processes.

[0049] In some embodiments, when the user requests the aggregation result, based on the oracle and VRF, randomly verify the aggregation result to achieve trustworthy acquisition, including: obtaining the aggregation result and a random number from an off-chain data source; the random number is in a first preset interval: if the random number is in a second preset interval, then verify the aggregation result based on the blockchain; where the second preset interval belongs to the first preset interval; if the verification result is inconsistent, notify the preset business system.

[0050] Specifically, it includes the following content: The user requests the aggregation result: When the user side needs to obtain the aggregation result for certain business operations, it will call the relevant interfaces of the user business smart contract. For example, in the power system, the user may need to obtain the active power aggregation result of multiple metering terminals within a certain time range for energy consumption analysis or cost accounting.

[0051] Obtaining the Aggregation Result and Random Number: The user business contract sends a request to the oracle smart contract to obtain the aggregation result and the random number generated by the VRF algorithm. After the oracle service receives the event of generating the random number, it generates the VRF random number through the algorithm library, returns it to the oracle smart contract, and finally passes it to the user business contract. At the same time, the oracle service also obtains the aggregation result of the off-chain data source.

[0052] Random Number Interval Setting: The system pre-sets two intervals, the first preset interval and the second preset interval, where the second preset interval belongs to the first preset interval. For example, the first preset interval can be [1, 100], and the second preset interval can be [1, 20]. The setting of these two intervals is to control the verification probability, so that only some requests will trigger the verification process, thereby reducing the system's verification cost and resource consumption while ensuring the credibility of the data.

[0053] Judging Whether the Random Number Is within the Second Preset Interval: Compare the generated random number with the range of the second preset interval. If the random number falls within the second preset interval, trigger the blockchain-based verification process; otherwise, do not perform verification and directly use the obtained aggregation result for subsequent business operations.

[0054] Obtaining the Aggregation Result to Be Verified: If the random number is within the second preset interval, it is necessary to obtain the aggregation calculation result from the oracle again to get the aggregation calculation result to be compared and verified. This step is to ensure the fairness and randomness of the verification and avoid human intervention or malicious manipulation of the data source during the verification process.

[0055] Comparing and Verifying the Aggregation Result: Compare the previously obtained aggregation result with the aggregation result to be verified. The comparison dimensions include whether the number of aggregation control units is the same, whether the aggregation control unit ids are the same, whether the active power p of each aggregation control unit is the same, etc. Through multi-dimensional comparison, the accuracy of the aggregation result can be comprehensively checked.

[0056] Processing the Verification Result: If any verification result is found to be inconsistent during the comparison, it is considered that the aggregation result is not credible. At this time, record the untrusted data in the contract and trigger a contract event to notify the preset business system. The business system can take corresponding measures according to the notification, such as re-obtaining data, suspending relevant business processes, conducting data audits, etc., to ensure the normal operation of the system and the credibility of the data.

[0057] Through the above steps, the oracle and VRF are used to realize the random verification of the aggregation result, which not only ensures the credible acquisition of data, but also takes into account the verification efficiency and resource utilization, providing a strong guarantee for the safe and stable operation of the system.

[0058] In some embodiments, the first preset interval and the second preset interval can be set to adjust the probability of verification.

[0059] The first preset interval and the second preset interval are two ranges, where the second preset interval belongs to the first preset interval. For example, the first preset interval can be [1, 100], and the second preset interval can be [1, 20]. This inclusion relationship determines the probability that a random number falls within the second preset interval, and thus determines the probability of triggering the verification process. The verification probability is equal to the length of the second preset interval divided by the length of the first preset interval. In the above example, the verification probability is 20 / 100 = 20%. By adjusting the ranges of these two intervals, the probability of verification can be flexibly controlled to adapt to different business requirements and system resource conditions.

[0060] In different business scenarios, the requirements for data accuracy and verification cost are different. For example, in high-risk, high-value transaction scenarios, to ensure high data credibility, the second preset interval can be set larger, such as [1, 50], to increase the verification probability; while in low-risk, large-scale data processing scenarios, the second preset interval can be set smaller, such as [1, 10], to reduce the verification probability and save system resources.

[0061] The following uses specific embodiments to illustrate the solution provided by this application: The solution provided by this application mainly includes the following steps: establishing a solution for data on-chain and off-chain synchronization based on smart contract events to achieve terminal data on-chain and data synchronization; establishing a solution model for secure and trusted execution of aggregation calculations based on TEE to achieve the security and trustworthiness of the aggregation calculation process; establishing a solution for trusted acquisition of terminal data and random verification of data based on an oracle and VRF to achieve the trusted acquisition and efficient verification of terminal data.

[0062] Specifically, establish a solution for data on-chain and off-chain synchronization based on smart contract events. It mainly includes the following steps: (1.1) Before data is on-chain, it is necessary to deploy a smart contract for terminal data on-chain to achieve the on-chain of terminal data. Each piece of data to be on-chain contains fields such as terminal encoding (t_id), operating status (status), active power (p), and acquisition timestamp (timestamp).

[0063] struct Terminal { string t_id; / / Terminal encoding string status; / / Operating status: offline, online string p; / / Active power string timestamp; / / Acquisition timestamp } (1.2)The terminal collects the actual energy consumption data generated, processes the data at a certain frequency (such as once per second), constructs the data structure for uploading to the chain, signs the data to be uploaded using the private key of the account, and then calls the data upload interface in the on-chain smart contract through the RPC interface or blockchain SDK to upload the data to the chain.

[0064] (1.3)The on-chain smart contract for terminal data does not store the actual terminal data. It emits a data record event in the data upload interface, and the event definition is as follows: event Recorded(string t_id, string status, string p, string tm); (1.4)The off-chain data synchronization service integrates the blockchain SDK, listens for the data record event, and then stores the data of the metering terminal in a persistent storage such as a database according to the event content.

[0065] Furthermore, a solution model for secure and trusted execution of aggregation computing based on TEE is established. TEE is an independent processing environment with computing and storage functions that can provide security and integrity protection. Its basic idea is: a separate isolated memory is allocated in the hardware for sensitive data, and all calculations of sensitive data are performed in this memory. And except for the authorized interfaces, other parts of the hardware cannot access the information in this isolated memory. In this way, privacy computing of sensitive data is realized. To achieve high availability, security and trust of data sources, the mapping relationship between metering terminal data and metering terminals and aggregation control units is deployed as an independent service and cluster deployment is carried out at the same time. The main steps include the following: (2.1)Cluster-deploy the metering terminal data synchronization service, the mapping relationship service between metering terminals and aggregation control units, and the aggregation computing execution program. The communication between these services and the oracle service and TEE later is TLS encrypted communication, and the legitimacy of the certificate is verified through the authentication service.

[0066] (2.2)Before the TEE trusted execution service starts, it is necessary to obtain the certificate for TLS communication from the authentication service and configure it into the TEE executable program service.

[0067] (2.3)External services such as oracles integrate the SDK of TEE, register and log in the calling users, and then call the TEE computing service to initiate an aggregation computing task.

[0068] It includes the following sub-steps, and TLS is used for communication: [1] Call the interface of the SDK to register the corresponding data, including the metering terminal, the relationship between the metering terminal and the aggregation control unit, and the access address corresponding to the aggregation calculation program service.

[0069] [2] Register the method for executing data, which includes the main operations of performing aggregation calculation, such as obtaining data from three data sources and executing the aggregation calculation program, etc.

[0070] [3] Create a task and bind the data and the method.

[0071] [4] Execute the created task.

[0072] (2.4) The TEE service receives the data, method, and task in step (2.3) and processes them. After receiving the request to execute the task, it verifies the user identity, starts to execute the task, and obtains the mapping relationship data between the aggregation control unit and the terminal from the mapping relationship service cluster of the metering terminal and the aggregation control unit. The mapping relationship data between the aggregation control unit and the terminal is as follows: struct MapAggAndTerminal { string aggUnitId; / / Aggregation control unit identifier string terminalId; / / Terminal identifier } (2.5) The TEE service, based on the time range passed in by the caller and the mapping relationship data between the aggregation control unit and the terminal obtained in step (2.4), obtains the second-level data of the corresponding metering terminals under the corresponding aggregation control unit within the required time range from the metering terminal synchronization service cluster. Obtain the aggregation calculation execution program from the aggregation calculation execution program service.

[0073] (2.6) The TEE service obtains the metering terminal data, the data of the relationship between the metering terminal and the aggregation control unit, and the aggregation calculation execution program from the above steps, and executes the aggregation calculation program according to the steps defined in the method, thereby obtaining the result of the aggregation calculation. The data elements of the aggregation calculation result are as follows: struct AggResultData { string aggUnitId; / / Aggregation control unit identifier string aggUnitName; / / Aggregation control unit name string p; / / Active power string timestamp; / / Timestamp } Among them, the active power p is the sum of the active powers of all metering terminals corresponding to this aggregation control unit at the corresponding timestamp.

[0074] The oracle service finally obtains the execution result of the aggregated calculation, and after obtaining the result, it can enter other business processes.

[0075] Furthermore, a solution for establishing trusted acquisition of terminal data and random verification of data based on an oracle and VRF is proposed. When the user side calls the user business contract (such as for data comparison services), it is necessary to obtain the aggregated result data. The oracle is used to obtain the off-chain aggregated result. At the same time, in order to efficiently verify the aggregated data result, a VRF-based algorithm is used to achieve random verification. The main steps include: (3.1) The user side calls the relevant interface of the user business smart contract, and this interface needs to obtain the aggregated result data.

[0076] (3.2) Call the oracle smart contract to obtain the random number generated by the VRF algorithm. Specifically, it includes: [1] The user contract sends a request to the oracle smart contract, passing in the random number seed; [2] After the oracle service receives the event of generating a random number, it generates a VRF random number through the algorithm library, returns it to the oracle smart contract, and finally returns it to the user business contract, so as to obtain the random number VRFNum of this request.

[0077] Among them, the blockchain is a deterministic and closed system environment. The smart contract must produce the same result no matter when and where it runs. Therefore, the smart contract cannot have network calls, otherwise the result will be uncertain. The smart contract cannot directly obtain the real-world data outside the chain, resulting in the disconnection between the blockchain and the real world. To connect the blockchain with the real world, it is necessary to introduce the oracle service. Through the oracle, the real-world data is input into the blockchain to provide connectivity between the smart contract and the external world.

[0078] Among them, the Verifiable Random Function (VRF) is a cryptographic scheme that maps an input to a verifiable pseudo-random output, and is widely used in the consensus algorithm of the blockchain and the scenario of generating random numbers by smart contracts. The prover holding the private key sk can calculate the hash, and the verifier holding the public key PK can verify the correctness of the hash. VRF has the following security features: Full uniqueness: Given a VRF private key and an input, there is one and only one VRF output random number that can be verified as valid; given a VRF private key sk and an input alpha, an attacker cannot generate different {beta1, pi1} and {beta2, pi2} such that both VRF_verify(PK, alpha, pi1) and VRF_verify(PK, alpha, pi2) are verified as valid. Full collision resistance: Even if an attacker breaks the VRF key sk, the attacker cannot find two different inputs alpha1 and alpha2 such that VRF_hash(sk, alpha1) == VRF_hash(sk, alpha2). Full pseudorandomness: Without holding the VRF proof pi, an attacker cannot distinguish a VRF random number from a normal random number. Where, alpha: VRF input; beta: VRF output; pi: VRF proof.

[0079] (3.3) Call the oracle smart contract to obtain the aggregated result data. Specifically, it includes: The user contract initiates a request to the oracle smart contract to obtain the aggregated result data. The oracle contract calls the oracle cluster service. At least two oracle nodes are deployed in this cluster, and different oracles are called each time according to a polling or other strategy.

[0080] The oracle cluster calls the TEE service cluster. After receiving the request for obtaining the aggregated result, the TEE service cluster performs secure and trusted aggregation calculations, returns the result obtained from the aggregation calculations to the oracle service, then to the oracle contract, and finally to the user business contract.

[0081] (3.4) Based on the VRFNum obtained in step (3.2), determine whether random verification of the aggregation calculation result is required. The random verification probability can be specified by the user when calling. If not specified, the default probability is 20%. The probability supported within the contract can be determined according to the actual business. For example, the random verification probability can support 0%, 20%, 40%, 60%, 80%, 100%.

[0082] (3.5) Process according to the value of isToVerify obtained in step (3.4). If the value is 1, similar to step (3), obtain the aggregation calculation result from the oracle again to get the aggregation calculation result to be compared and verified. If the value is 0, the following steps are no longer performed, but the subsequent business process of the user contract is executed.

[0083] (3.6) Compare and verify the aggregation calculation results obtained in step (3.3) and the aggregation calculation result data for trusted verification obtained in step (3.5). The dimensions for comparison include: Whether the number of aggregation control units is the same; Whether the aggregation control unit IDs are the same; Whether the active power p of each aggregation control unit is the same.

[0084] (3.7) If any of the verification results is inconsistent, the aggregation result is not credible. Record the untrusted data in the contract and trigger a contract event to notify the business system. If the data is consistent, execute the subsequent business processes of the user contract.

[0085] Since the present invention adopts the above technical solutions, it has the following advantages: The present invention proposes a novel method for realizing trusted data acquisition and verification based on blockchain, oracle, TEE, and VRF. A solution for data on-chain and off-chain synchronization based on smart contract events is implemented. The contract does not store terminal data, significantly reducing the size of the data stored in the contract and improving scalability. A solution model for secure and trusted execution of aggregation calculations based on TEE is established. Metering terminal data and the relationship data between metering terminals and aggregation control units are obtained from the metering terminal data synchronization service cluster and the relationship mapping cluster between metering terminals and aggregation control units respectively, improving the availability and reliability of data sources. Aggregation calculations are performed by TEE, realizing the security and trustworthiness of the aggregation calculation process. A solution for realizing trusted acquisition of terminal data and random verification of data based on oracle and VRF is established. The blockchain is connected to the external world through the oracle to credibly obtain external aggregation calculation result data. At the same time, the proposed solution for random verification of data based on VRF takes into account the requirements of data verification efficiency and data trustworthiness, realizing random and unpredictable verification of the required data, greatly reducing the possibility of off-chain data source fraud. The present invention can be applied not only to the field of trusted acquisition and verification of aggregated data of distributed devices in the power industry described above, but also to other similar fields for realizing trusted acquisition and verification of data.

[0086] The device embodiments of the present application can be used to execute the method embodiments of the present application. For details not disclosed in the device embodiments of the present application, please refer to the method embodiments of the present application.

[0087] Figure 2 Shown is a block diagram of a trusted data acquisition and verification device based on blockchain, oracle, TEE, and VRF provided by an embodiment of the present application. As Figure 2 shown, the device includes: A construction module 21 is configured to process the collected data at a preset frequency, construct target fields corresponding to the collected data based on a preset smart contract, and perform private key signing to obtain data to be uploaded to the blockchain; the target fields are used to characterize the collected data. An uploading module 22 is configured to perform an uploading operation on the data to be uploaded to the blockchain; meanwhile, synchronize the collected data to a preset database for persistent storage. An aggregation module 23 is configured to obtain trusted collected data based on the blockchain, and perform aggregation calculation on the collected data based on a pre-constructed trusted execution environment to obtain an aggregation result. The uploading module 22 is further configured to upload the aggregation result based on a preset oracle using blockchain technology. A verification module 24 is configured to perform random verification on the aggregation result based on the oracle and VRF when a user requests the aggregation result, so as to achieve trusted acquisition. Wherein, the target fields include: terminal code, operating status, active power, and collection timestamp.

[0088] Next, reference Figure 3 is made to describe the electronic device according to an embodiment of the present application. Figure 3 The block diagram of the electronic device according to an embodiment of the present application is illustrated.

[0089] As Figure 3 shown, the electronic device 300 includes one or more processors 310 and a memory 320.

[0090] The processor 310 may be a central processing unit (CPU) or other form of processing unit having data processing capabilities and / or instruction execution capabilities, and may control other components in the electronic device 300 to perform desired functions.

[0091] The memory 320 may include one or more computer program products, and the computer program products may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory, etc. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage media, and the processor 310 may run the program instructions to implement the trusted data acquisition and verification method based on blockchain, oracle, TEE, and VRF in various embodiments of the present application as described above and / or other desired functions. Various contents such as category correspondence relationships may also be stored in the computer-readable storage media.

[0092] In one example, the electronic device 300 may further include: an input device 330 and an output device 340, and these components are interconnected through a bus system and / or other forms of connection mechanisms (not shown).

[0093] In addition, the input device 330 may further include, for example, a keyboard, a mouse, an interface, and so on. The output device 340 can output various information to the outside, including analysis results and the like. The output device 340 may include, for example, a display, a speaker, a printer, and a communication network and its connected remote output devices, and so on.

[0094] Of course, for simplicity, Figure 3 only some of the components related to the present application in the electronic device are shown, and components such as a bus, an input / output interface, and so on are omitted. In addition, according to specific application scenarios, the electronic device may further include any other appropriate components.

[0095] In addition to the above methods and devices, an embodiment of the present application may also be a computer program product, which includes computer program instructions, and when the computer program instructions are run by a processor, the processor is caused to execute the steps in the trusted data acquisition and verification method based on blockchain, oracle, TEE, and VRF according to various embodiments of the present application described in the above "Exemplary Method" section of this specification.

[0096] The computer program product can be written in any combination of one or more programming languages for programming code to perform the operations of the embodiments of the present application. The programming languages include object-oriented programming languages such as Java, C++, etc., and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed completely on the user computing device, partially on the user device, executed as an independent software package, partially on the user computing device and partially on a remote computing device, or completely executed on a remote computing device or server.

[0097] In addition, an embodiment of the present application may also be a computer-readable storage medium, on which computer program instructions are stored, and when the computer program instructions are run by a processor, the processor is caused to execute the steps in the trusted data acquisition and verification method based on blockchain, oracle, TEE, and VRF according to various embodiments of the present application described in the above "Exemplary Method" section of this specification.

[0098] The computer-readable storage medium may adopt any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. The readable storage medium may include, for example, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0099] The foregoing description has been presented for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of the present application to the form disclosed herein. Although several example aspects and embodiments have been discussed above, those skilled in the art will recognize some of their variations, modifications, alterations, additions, and sub-combinations.

Claims

1. A trusted data acquisition and verification method based on blockchain, oracle, TEE and VRF, characterized in that: include: The collected data is processed at a preset frequency, a target field corresponding to the collected data is constructed based on a preset smart contract, and a private key signature is performed to obtain the on-chain data; the target field is used to represent the collected data; Perform chain operations on the chained data; at the same time, synchronize the collected data to a preset database for persistent storage; Obtain trusted collected data based on blockchain, and perform aggregate calculations on the collected data based on a pre-built trusted execution environment to obtain aggregated results; Based on a preset oracle, the aggregation result is uploaded to the chain using blockchain technology; When a user requests an aggregated result, the aggregated result is randomly verified based on the oracle and VRF to achieve trusted acquisition; The target fields include: terminal code, operating status, active power, and acquisition timestamp.

2. The trusted data acquisition and verification method based on blockchain, oracle, TEE and VRF according to claim 1 is characterized in that: The preset frequency is once per second.

3. The trusted data acquisition and verification method based on blockchain, oracle, TEE and VRF according to claim 2 is characterized in that: The uplinking operation is performed on the uplinked data; at the same time, the collected data is synchronized to a preset database for persistent storage, including: A data record event is issued in the data upload interface of the smart contract. The event definition is as follows: event Recorded(string t_id, string status, string p, string tm); Among them, string t_id indicates the terminal code; string status indicates the operating status; string p indicates the active power; string tm indicates the acquisition timestamp; The off-chain data synchronization service integrates the blockchain SDK, monitors data recording events, and then stores the corresponding collected data in the database for persistent storage based on the event content.

4. The trusted data acquisition and verification method based on blockchain, oracle, TEE and VRF according to claim 1 is characterized in that: The method of obtaining trusted collected data based on blockchain and performing aggregate calculation on the collected data based on a pre-built trusted execution environment to obtain an aggregate result includes: Get the certificate for TLS communication from the authentication service and configure it in the TEE executable service; The external service integrates the TEE SDK, registers and logs in the calling user, and then calls the TEE computing service to initiate the aggregate computing task; The TEE service executes the aggregation computing task to aggregate the collected data and obtain the aggregation results.

5. The trusted data acquisition and verification method based on blockchain, oracle, TEE and VRF according to claim 1 is characterized in that: When the user requests the aggregated result, the aggregated result is randomly verified based on the oracle and VRF to achieve trusted acquisition, including: Obtain the off-chain data source to obtain the aggregation result and the random number; the random number is in the first preset interval: If the random number is in a second preset interval, verifying the aggregation result based on the blockchain; wherein the second preset interval belongs to the first preset interval; If the verification result is inconsistent, the preset business system will be notified.

6. The trusted data acquisition and verification method based on blockchain, oracle, TEE and VRF according to claim 5 is characterized in that: Also includes: The first preset interval and the second preset interval are set to adjust the probability of performing verification.

7. A trusted data acquisition and verification device based on blockchain, oracle, TEE and VRF, characterized in that: include: A construction module is used to process the collected data according to a preset frequency, construct a target field corresponding to the collected data based on a preset smart contract, and perform a private key signature to obtain the on-chain data; the target field is used to represent the collected data; The uplink module is used to perform uplink operations on the uplink data; at the same time, synchronize the collected data to a preset database for persistent storage; The aggregation module is used to obtain trusted collected data based on the blockchain, and to perform aggregate calculations on the collected data based on the pre-built trusted execution environment to obtain aggregate results; The chain-up module is also used to chain the aggregation results based on a preset oracle using blockchain technology; The verification module is used to perform random verification of the aggregation results based on the oracle and VRF when the user requests the aggregation results to achieve trusted acquisition; The target fields include: terminal code, operating status, active power, and acquisition timestamp.

8. An electronic device, characterized in that: include: A processor, and a memory for storing a program executable by the processor; The processor is used to implement the trusted data acquisition and verification method based on blockchain, oracle, TEE and VRF as described in any one of claims 1 to 6 by running the program in the memory.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, which, when executed by a processor, enables the processor to execute a trusted data acquisition and verification method based on blockchain, oracle, TEE and VRF as described in any one of claims 1 to 6.

10. A computer program product, comprising a computer program, which, when executed by a processor, implements the trusted data acquisition and verification method based on blockchain, oracle, TEE and VRF as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Data processing method and device based on block chain, equipment and storage medium

    CN111930852A

  • Block chain customizable system

    CN113947485A

  • Decentralization Internet collaboration system and data interaction method based on block chain

    CN114493865A

  • Block chain trusted oracle machine decision support system based on access control rule

    CN116866045A

  • Data processing method and device based on block chain, equipment and medium

    CN118227703A

Cited By

  • Block chain technology-based review data information security tamper-proofing method

    CN121502830A