A blockchain-based data transaction method
By performing multi-layer encryption on transaction data and secondary encryption on blockchain nodes, combined with smart contract verification and dynamic adjustment of consensus weights, the problems of data leakage and tampering in data transactions are solved, and efficient and secure data access and transaction processes are achieved.
Patent Information
- Application Number
- CN202510579476.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2045-05-07
AI Technical Summary
Existing technologies are insufficient to effectively prevent data leakage and tampering in high-density data transactions and complex network environments. They lack flexibility and automation capabilities, resulting in delays and inefficiencies in data access and verification processes, which increases security risks during transactions.
By performing multi-layer encryption on the original transaction data and combining it with secondary encryption of blockchain nodes, smart contracts are used to automatically verify access permissions, monitor the real-time transaction volume and node activity status of the blockchain network, dynamically adjust the consensus weight of nodes, generate encrypted data identifiers, access permission values and consensus type identification results, and generate audit log identifiers to ensure data integrity and security.
It significantly improves data security and tamper resistance, optimizes the flexibility and efficiency of data access, enhances network stability and response speed, and improves the security, efficiency, and reliability of data transactions.
Smart Images

Figure CN120090886B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data transaction, and particularly to a data transaction method based on a blockchain. BACKGROUND
[0002] The technical field of data transaction includes various technologies related to information transmission, data storage, data management, and data transaction security. In the field of data transaction, the core content focuses on how to effectively process, transmit, and protect data exchanged between different systems. This field is constantly evolving, covering from basic data encoding and transmission protocols to complex data security and privacy protection technologies. The development of data transaction technology supports various business and financial applications, ensuring the secure transmission and accurate delivery of data in Internet or network environments.
[0003] Among them, the data transaction method refers to the process of using distributed ledger technology to handle and record data transactions. The technical subject involved mainly includes methods for creating, verifying, and storing transactions in a blockchain network. Through the consensus mechanism among multiple nodes in the network, the security and tamper resistance of transactions are ensured, and encryption technology is used to protect data from unauthorized access. Based on the blockchain data transaction method, various data transaction needs are handled through the application of distributed processing and encryption technology, in order to maintain the trust between the two parties of the transaction and the integrity of the data.
[0004] The main deficiencies of existing technologies in the field of data transaction include limitations in data security and processing efficiency. Despite involving various information transmission and data management technologies, existing technologies are difficult to effectively prevent data leakage and tampering in high-density data transactions and complex network environments. Existing technologies lack sufficient flexibility and automated processing capabilities when handling large-scale real-time data transactions, resulting in delays and inefficiencies in data access and verification processes. Technical limitations not only affect the accurate delivery of data, but also increase the security risks in the transaction process. In the case of failing to update and verify data permission settings in a timely manner, unauthorized access or data misuse occurs, which damages the interests of data owners and the overall security of the network. SUMMARY
[0005] In order to solve the limitations of data security and processing efficiency in the prior art, although various information transmission and data management technologies are involved, in the high-density data transaction and complex network environment, the prior art is difficult to effectively prevent data leakage and tampering. The prior art lacks sufficient flexibility and automated processing capability when processing large-scale real-time data transactions, resulting in delays and inefficiencies in data access and verification processes. Technical limitations not only affect the accurate delivery of data, but also increase the security risks in the transaction process. In the case of failing to update and verify the data authority settings in time, unauthorized access or data abuse occurs, which damages the interests of the data owner and the overall security of the network. The present application provides a data transaction method based on blockchain. The technical solution is as follows:
[0006] In one aspect, a data transaction method based on blockchain is provided, the method comprising:
[0007] S1: obtaining original consumption transaction data, performing multi-layer encryption on the data, generating a primary encryption ciphertext in the first layer of encryption, inputting the primary encryption ciphertext into a blockchain node for secondary encryption, calculating a hash value of the multi-layer encryption ciphertext, and generating an encrypted data identifier;
[0008] S2: calling the smart contract corresponding to the encrypted data identifier, extracting the access permission conditions defined in the smart contract, detecting the public key address of the consumer and the transaction request type, matching the public key address with the address list in the permission condition, if the matching is successful, automatically verifying, referring to the consumer behavior to dynamically calculate the credit score, if the score exceeds the preset threshold, assigning an access permission instruction, generating an access permission value;
[0009]
[0009] S3: calling the transaction level classification corresponding to the access permission value, monitoring the real-time transaction volume and node activity status of the blockchain network, identifying the network load state, evaluating the relevance of the network load state and the transaction level classification, and generating a consensus type identification result;
[0010] S4: through the consensus type identification result, extracting the data request frequency and verification response speed of the blockchain node, analyzing the node behavior deviation state, if the deviation state exceeds the preset threshold, adjusting the consensus weight value of the node, and generating a node security score.
[0011] As a further scheme of the present application, the encrypted data identifier includes an encrypted ciphertext hash, a data storage location identifier, and an encryption level marker, the access permission value includes a permission matching state, a dynamic credit level, and a permission instruction code, the consensus type identification result includes a load state level, a transaction urgency classification, and a consensus mechanism type, and the node security score includes a behavior deviation coefficient, a weight adjustment proportion, and a security evaluation label.
[0012] As a further scheme of the present application, the step of obtaining the encrypted data identifier is specifically:
[0013] S101: Obtain the original consumption transaction data, extract the account information, transaction time and transaction amount, call the symmetric key, and perform encryption operation on the transaction character after field splicing, to generate a sequential encryption ciphertext structure;
[0014] S102: Call the sequential encryption ciphertext structure, write into the target blockchain node, index the input ciphertext according to the key index value built-in the node, combine the node timestamp and the ciphertext serial number, disperse and rearrange the field structure, and perform re-encryption calculation to generate a node hybrid encryption field;
[0015] S103: Perform hash generation operation based on the field combination structure extracted from the node hybrid encryption field, store and combine the hash signature value and the original data, and obtain the encrypted data identifier.
[0016] As a further scheme of the present application, the step of obtaining the access permission value is specifically:
[0017] S201: Call the smart contract corresponding to the encrypted data identifier, extract the access permission condition field defined in the smart contract structure, which includes the address list of access, the corresponding transaction type and the permission threshold, and perform field positioning and indexing based on the hash value bound in the identifier structure to generate a contract permission condition parameter set;
[0018] S202: According to the address list field in the contract permission condition parameter set, compare the public key address data provided by the consumer with the node address in the address list, compare whether there is a completely matched item with the same bit sequence, and obtain the public key address matching state according to the matching success flag bit identification verification state;
[0019] S203: Call the transaction type field in the public key address matching state, compare the real-time transaction request type data, extract the credit evaluation benchmark field corresponding to the matched item, combine the consumer transaction frequency, account credit score and transaction request in unit time, and generate the access permission value.
[0020] As a further scheme of the present application, the formula for comparing whether there is a completely matched item with the same bit sequence is as follows:
[0021] ;
[0022] Wherein, represents the matching degree of the public key address, represents the number of address bytes to be compared, represents the byte in the address list, The first bit byte, representing the first bit byte weight value, representing and the absolute value of the byte difference value.
[0023] As a further scheme of the present application, the consensus type identification result obtaining step is specifically:
[0024] S301: Call the transaction level classification field corresponding to the access permission value, extract the level category number and the corresponding processing priority value defined in the field, combine the real-time blockchain network data, monitor the total number of transaction broadcasts and the number of active nodes within the time window, and perform time synchronization and cumulative statistical processing on the two types of data to generate network operation state parameters;
[0025] S302: Based on the transaction broadcast quantity and node active quantity in the network operation state parameter, construct the transaction density value and node response ratio value within a unit time, compare and judge with the set blockchain load identification benchmark value, identify the load state interval identifier, and generate the network load state level;
[0026] S303: Cross-match the transaction level number associated with the network load state level and the access permission value, numerically compare the processing priority value defined in the level number with the resource allocation weight corresponding to the load state, calculate the resource allocation characteristic value, select the consensus identifier corresponding to the processing path, and generate the consensus type identification result.
[0027] As a further scheme of the present application, the formula for calculating the resource allocation characteristic value is as follows:
[0028] ;
[0029] Among them, representing the resource allocation characteristic value, representing the adjustment factor, representing the resource allocation weight dynamic balance coefficient, representing the processing priority value, representing the resource allocation weight corresponding to the load state, representing the load difference value, representing the priority correction coefficient.
[0030] As a further scheme of the present application, the node security score obtaining step is specifically:
[0031] S401: adopt the consensus type identification result, call the transaction data request record and the block verification response information of the blockchain node, combine the timestamp information and the operation frequency data of each node, calculate the average data request frequency and the response time of the node in the specified time period respectively, and generate a node behavior frequency parameter group;
[0032] S402: according to the node behavior frequency parameter group, combine the execution deviation time of multiple operation instructions of the node in the near period, extract the corresponding node execution delay and response abnormal amplitude, and compare the node delay and response abnormal amplitude with the set offset state threshold respectively, filter the node set exceeding the threshold range and mark the node number, and generate a node offset measurement result;
[0033] S403: call the node number corresponding to the consensus type classification information in the node offset measurement result, combine the network transaction activity value and the consensus participation frequency, adjust the consensus weight parameter of the node, and obtain the node security score.
[0034] As a further scheme of the application, the method further comprises a step S5:
[0035] S5: call the node security score, extract the block identifier and time marker corresponding to the transaction, combine the block identifier, time marker and permission change record into a log structure, perform hash calculation on the log structure using a chain hash process, bind the root hash identifier and the transaction metadata after the hash calculation, and write them into a tamper-proof storage layer to generate an audit log identifier;
[0036] The audit log identifier comprises a block height code, a timestamp sequence and a root hash digest.
[0037] As a further scheme of the application, the step of obtaining the audit log identifier is specifically:
[0038] S501: call the node security score, extract the transaction number field associated, and read the block identifier and time marker data bound under the corresponding transaction number item, combine the permission change type, target address and adjustment timestamp field, sequentially splice the three types of structures to obtain a block permission identification result;
[0039] S502: based on the field content in the block permission identification result, generate a local hash value for each log item in ascending order of time marker using a chain hash process, perform an aggregate hash operation on the local hash value to construct a hash tree structure, extract the root node hash field of the hash tree, and generate a permission adjustment record;
[0040] S503: Call the transaction metadata bound with the permission adjustment record and the transaction number, combine them into a bound structure after index alignment, and write the bound structure into the tamper-proof storage layer to generate an audit log identifier.
[0041] The technical scheme provided by the embodiment of the application brings at least the following beneficial effects:
[0042] By performing multi-layer encryption on the original transaction data and combining the encryption process with the secondary encryption of the blockchain node, the security and tamper resistance of the data are significantly improved. The hash value of the encrypted ciphertext is stored after being bound with the ciphertext, further ensuring the integrity and traceability of the data. Through the automatic verification of the smart contract and the dynamic allocation of access permissions, the flexibility and efficiency of data access are optimized. At the same time, according to the matching of the public key address and the permission conditions, and the dynamic calculation of the consumer credit score, the personalized and secure data access management is strengthened. By monitoring the real-time transaction volume and node activity status of the blockchain network, and dynamically adjusting the consensus weight of the node according to the correlation between network load and transaction level, the stability and response speed of the network are improved, the overall data processing capacity is improved, and the security, efficiency and reliability of the data in the transaction process are enhanced. BRIEF DESCRIPTION OF DRAWINGS
[0043] Figure 1 The workflow of the present application is shown in the figure. DETAILED DESCRIPTION
[0044] The technical scheme in the present application will be described below in conjunction with the drawings.
[0045] In the embodiments of the present application, the words such as "example", "for example" are used to represent as an example, illustration or description. Any embodiment or design scheme described as "example" in the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the word "example" is intended to present the concept in a specific way. In addition, in the embodiments of the present application, the meaning expressed by "and / or" can be both, or can be one of the two.
[0046] In order to make the technical problems, technical schemes and advantages of the present application clearer, the following will be described in detail in conjunction with the drawings and specific embodiments.
[0047] Please refer to Figure 1 The embodiment of the present application provides a data transaction method based on a blockchain. The processing flow of the method can include the following steps:
[0048] S1: Obtain original consumption transaction data, perform multi-layer encryption on the data, generate primary encrypted ciphertext in the first layer of encryption, input the primary encrypted ciphertext into a blockchain node for secondary encryption, obtain multi-layer encrypted ciphertext, calculate the hash value of the multi-layer encrypted ciphertext, store the hash value after binding with the encrypted ciphertext, and generate an encrypted data identifier;
[0049] S2: Call the smart contract corresponding to the encrypted data identifier, extract the access permission conditions defined in the smart contract, detect the public key address of the consumer and the transaction request type, match the public key address with the address list in the permission conditions, if the matching is successful, automatically verify, calculate the credit score according to the consumer behavior, if the score exceeds the preset threshold, assign an access permission instruction, and generate an access permission value;
[0050] S3: Call the transaction level classification corresponding to the access permission value, monitor the real-time transaction volume and node active state of the blockchain network, identify the network load state, evaluate the relevance of the network load state and the transaction level classification, and generate a consensus type identification result;
[0051] S4: Through the consensus type identification result, extract the data request frequency and verification response speed of the blockchain node, analyze the node behavior deviation state, if the deviation state exceeds the preset threshold, adjust the consensus weight value of the node, and generate a node security score;
[0052] S5: Call the node security score, extract the block identifier and time marker of the corresponding transaction, combine the block identifier, time marker, and permission change record into a log structure, perform hash calculation on the log structure using a chain hash process, bind the root hash identifier and transaction metadata, and write them into a tamper-proof storage layer to generate an audit log identifier;
[0053] The encrypted data identifier includes encrypted ciphertext hash, data storage location identifier, and encryption level marker, the access permission value includes permission matching state, dynamic credit level, and permission instruction code, the consensus type identification result includes load state level, transaction emergency classification, and consensus mechanism type, the node security score includes behavior deviation coefficient, weight adjustment proportion, and security evaluation label, and the audit log identifier includes block height code, timestamp sequence, and root hash digest.
[0054] The obtaining step of the encrypted data identifier is specifically:
[0055] S101: Obtain original consumption transaction data, extract account information, transaction time, and transaction amount, call a symmetric key, and perform encryption operation on the transaction characters after field splicing to generate a sequential encrypted ciphertext structure;
[0056] When obtaining original consumption transaction data from a financial transaction or mobile payment platform, the transaction records in the current day or a specified time period are obtained by calling a data synchronization interface, and the records contain account information (such as user ID or bank card number), transaction time (a timestamp accurate to seconds), and transaction amount (in RMB yuan). After data cleaning, the original fields are sequentially extracted into three key fields, namely the account field, the time field, and the amount field. Then, according to the predefined splicing rule, the three fields are combined into a single string in the form of "account_time_amount" for subsequent encryption. For example, a certain user's transaction account is "AC987654", the transaction time is "20250418120233", and the amount is "1000.00". The splicing result is "AC987654-20250418120233-1000.00". The pre-set symmetric key is called to perform AES encryption operation. The field order is not changed during the encryption process, and only the key and initialization vector are used as input to perform the encryption process. The encrypted content generates a piece of ciphertext, which is converted into a structured string through Base64 encoding, and a complete structure is formed together with the ciphertext serial number and key number. This structure records the original splicing method of the encrypted field, the key number used, the ciphertext content, and the corresponding data ID, etc. meta information, which is convenient for subsequent verification and processing. The output is a sequentially encrypted ciphertext structure.
[0057] S102: Call the sequentially encrypted ciphertext structure and write it to the target blockchain node. In the blockchain node, index the input ciphertext according to the node's built-in key index value, combine the node timestamp and the ciphertext serial number, disperse and rearrange the field structure, and perform re-encryption calculation to generate a node hybrid encrypted field.
[0058] When the sequential encryption ciphertext structure is written into the target blockchain node, the running state of the current blockchain node and the built-in key index are confirmed through the node identification interface, the corresponding key is found from the key index table in the node according to the key number field in the sequential ciphertext structure, the index table records the number, encryption rule and applicable time range of each group of keys, the ciphertext field is imported into the node encryption module after the finding is successful, the node encryption module rearranges the field order of the original ciphertext structure according to the configuration rule, for example, rearranging “account-time-amount” to “amount-account-time”, the field rearrangement is completed through field displacement or exchange combination, and the rearranged structure is re-encrypted using the encryption key independently maintained by the current node, the encryption key is different from the key used in the previous sequential encryption, a new encrypted content is formed, and then a unique index is generated by combining the current node write timestamp and the original ciphertext sequence number, the “node write time+ciphertext sequence number” is set to form a unique key value, the encrypted field structure and the node identification number are written into the data block of the blockchain node synchronously, and the field position information is marked for subsequent field restoration operation, and the generation process of the node mixed encryption field is completed, and the node mixed encryption field is generated.
[0059] S103: After the field combination structure is extracted based on the node mixed encryption field, a hash generation operation is performed, the hash signature value and the original data are stored and combined, and an encrypted data identifier is obtained;
[0060] The field structure is decomposed, the timestamp, key index, ciphertext content and sequence number contained therein are extracted as structure units in turn, and are combined and reconstructed according to a preset field analysis format to generate a field combination structure. Each group of structure units will be used as input content for subsequent hash operation, and hash generation processing is performed. In the specific process, the combination structure is subjected to digest operation in turn, and if the first field combination is “March 5, 2025, 14:20, key index 003, ciphertext fragment A, sequence number 5”, the corresponding hash signature value such as “hash value A1” is generated after hash processing, the signature value is bound to the original field combination to form a record item, all field combinations are processed in turn, and the hash signature results are generated and saved one by one to construct the mapping structure of the field and the signature, and a data storage structure is established, each combination structure and its hash signature value is classified and managed, the generated record items are combined to form a data set and stored in the node database, so that the field structure is traceable and verifiable, each record takes the generated hash value as a unique identifier, a specific encrypted data identifier is quickly located through an index structure, and the encrypted field has independent identifiability and supports subsequent quick query and verification, and an encrypted data identifier is obtained.
[0061] The access permission value obtaining step specifically includes:
[0062] S201: Call the smart contract corresponding to the encrypted data identifier, extract the access permission condition field defined in the smart contract structure, the field content includes the address list of access, the corresponding transaction type and the permission threshold, and based on the hash value bound in the identifier structure, the contract permission condition parameter set is generated by field positioning and indexing;
[0063] When calling the smart contract bound by the encrypted data identifier, the contract mapping retrieval is performed through the hash value in the input encrypted data identifier. The process looks up the smart contract address bound with the hash value in the contract registry. After the contract address is detected, the contract reading process is entered. The permission condition field in the contract structure definition is read, which includes three types of key information: access address list, transaction type field and permission threshold setting. The access address list is a number of preset white list addresses, represented by 16 hexadecimal public keys, such as "0xAB34...F1"; the transaction type field specifies the transaction behavior type number allowed to be executed by the address, such as "TRX01" for query type and "TRX02" for transfer type; the permission threshold field sets the access allowed score of each transaction, such as setting the score upper limit to 60 points, 80 points and 90 points. After extracting each field from the contract structure, the field content is positioned and matched using the initial hash identifier value to determine the offset position in the structure to ensure the integrity and correct order of reading. Each field is combined into a parameter structure, which records each address and the corresponding transaction type and its permission threshold setting, used in the subsequent access authorization process, to generate a contract permission condition parameter set.
[0064] S202: According to the address list field in the contract permission condition parameter set, compare the public key address data provided by the consumer with the node address in the address list to determine whether there is a completely matched item with the same bit sequence, and obtain the public key address matching state according to the matching success flag bit identification verification state;
[0065] The formula for comparing whether there is a completely matched item with the same bit sequence is as follows:
[0066] ;
[0067] Wherein, represents the matching degree of the public key address, represents the number of bytes to be compared, represents the th byte in the address list, represents the th byte in the public key address data provided by the consumer, represents the weight value of the th byte, represents the absolute value of the byte difference between and ;
[0068] Parameter meaning and formula calculation derivation process:
[0069] And : Obtained by comparing the byte values in the address list and the public key address data provided by the consumer;
[0070] : Set according to the importance of bytes in the address, the first few bytes of the address have high weight;
[0071] : Obtained by calculating the total number of address bytes;
[0072] Set the number of address bytes to be compared , that is, each address consists of 4 bytes;
[0073] Bytes in the address list:
[0074] ;
[0075] Bytes in the public key address data provided by the consumer:
[0076] ;
[0077] Byte weight: ;
[0078] Calculate the absolute value of the difference value of each byte:
[0079] ;
[0080] ;
[0081] ;
[0082] ;
[0083] Calculate the sum of the weighted difference values:
[0084] ;
[0085] Calculate the square root of the weight value:
[0086] ;
[0087] Calculate the sum of the square roots of the weight values:
[0088] ;
[0089] ;
[0090] Substitute the above results into the formula:
[0091] ;
[0092] The results show the degree of address matching, the smaller the value, the more matched the address, the larger the value, the greater the difference between the addresses.
[0093] S203: Call the transaction type field in the public key address matching state, compare the real-time transaction request type data, extract the credit evaluation benchmark field corresponding to the matched item, and generate access permission value combined with consumer transaction frequency, account credit score and transaction request in unit time;
[0094] The transaction type field corresponding to the address is automatically extracted and compared with the transaction type declared in the real-time transaction request. If the transaction type in the real-time request is "TRX02", the subset containing "TRX02" transaction permission is selected from the matched addresses. For each matched item, the credit evaluation benchmark field bound to it is read. This field structure contains three dimensions: transaction frequency, account credit score, and request number per unit time. The daily average transaction frequency of this consumer in the last 30 days is read from the transaction database. If the average daily transfer number is 15, the account credit score is generated according to the platform credit evaluation model, ranging from 0 to 100, and the current score is 85. The request per unit time is the number of transaction attempts in the current hour, which is 3 times in this round. According to the benchmark value set in the contract, for example, the credit requirement is not less than 80 points, the frequency requirement is less than 20 times per day, and the request per unit time is limited to 5 times. Compare these three indicators with the contract benchmark value one by one, and build a three-item combined scoring logic according to the rules. For example, the comprehensive access permission value is generated by weighting the scoring weight mechanism. If the credit score weight is set to 50%, the frequency is 30%, and the request number per unit time is 20%, the access permission value is calculated to be 88 points. This value will be used as the core parameter to determine whether to authorize or not in the subsequent decision-making process, and the access permission value is generated.
[0095] The steps of obtaining the consensus type identification result are as follows:
[0096] S301: Call the transaction level classification field corresponding to the access permission value, extract the level category number and corresponding processing priority value defined in the field, and combine the real-time blockchain network data to monitor the total number of transaction broadcasts and the number of active nodes in the time window. Process the two types of data for time synchronization and cumulative statistics to generate network operation status parameters.
[0097] After calling the access permission value, it is mapped to the predefined transaction level classification field, which generally contains a level category number (such as LV1, LV2, LV3) and a processing priority value (such as P1 = low, P2 = medium, P3 = high) bound to the level. According to the value range of the access permission value, set the access permission value between 80 to 100 to map to LV3, corresponding to P3 priority. After matching, further combine the current blockchain network state data to extract the number of broadcast transactions in the current time window from the global broadcast node. In the last 10 seconds, 3760 transactions were broadcasted, and through the node activity monitoring mechanism, the number of nodes that sent or received broadcast information in the time window was recorded, such as 85. Two types of data are synchronized through a unified timestamp mechanism, that is, to ensure that transaction data and node data are in the same time segment to ensure the accuracy of statistical analysis results. Perform cumulative statistics on these two types of data, including transaction count accumulation and active node total statistics, record the current transaction activity and node participation, provide data basis for subsequent load condition judgment, and generate network running state parameters.
[0098] S302: Based on the number of transaction broadcasts and the number of active nodes in the network running state parameters, construct the transaction density value and node response ratio value per unit time, compare with the set blockchain load identification reference value, identify the load state interval identifier, and generate the network load state level;
[0099] After obtaining the network running state parameters, the number of transaction broadcasts and the number of active nodes are converted into indicators available in the analysis model, that is, the transaction density value and node response ratio value per unit time. The transaction density value refers to the number of transactions broadcast per second, which is set to 3760 / 10 seconds, resulting in 376 / second. The node response ratio value refers to the ratio of active nodes to total nodes. If there are 100 nodes in the global network, the ratio is 85%. Set several load identification reference values, such as density exceeding 300 / second and response ratio exceeding 80% defined as "medium-high load" state. Set multiple intervals such as "low load", "medium load", "high load" to identify the current network state. Match the density value and response ratio value calculated at present with the reference interval, set the current transaction density to 376 / second and the response ratio to 85%, which falls into the "high load" interval. The judgment process uses a conditional judgment mechanism, and the judgment order is set to evaluate the transaction density first, and then consider the response ratio. The level name can be "LOAD_H" representing high load. Decide whether to enable high priority processing path or switch to backup consensus mechanism to relieve network pressure, and generate network load state level.
[0100] S303: Cross-match the transaction level number associated with the network load state level and access permission value, perform numerical comparison between the processing priority value defined in the level number and the resource allocation weight corresponding to the load state, calculate the resource allocation feature value, select the consensus identifier corresponding to the processing path, and generate the consensus type identification result;
[0101] The formula for calculating the resource allocation feature value is as follows:
[0102]
[0103] represents the resource allocation feature value, represents the adjustment factor, represents the dynamic balance coefficient of resource allocation weight, represents the processing priority value, represents the resource allocation weight corresponding to the load state, represents the load difference value, represents the priority correction coefficient;
[0104] Parameter meaning and formula calculation derivation process:
[0105] Adjustment factor According to the matching relationship between transaction level number and load state, the value range is 0.1 to 0.9, and it is linearly adjusted with load fluctuation rate, this time , corresponding to load fluctuation rate 10%;
[0106] Dynamic balance coefficient According to the balance demand of resource allocation weight and load, the value range is 0.2 to 0.8, and it is dynamically adjusted with resource allocation deviation index, this time , corresponding to deviation index 15;
[0107] Processing priority value Mapping to a numerical value through transaction level number, number 1 to 10 correspond to to , this time taking transaction level number 8, mapping to ;
[0108] Resource allocation weight Quantified through load state level conversion table, low, medium and high load states correspond to , , , the current load state is medium, so ;
[0109] Current load difference value Obtained through real-time monitoring equipment, the calculation formula is:
[0110] ;
[0111] wherein, the current load value , the load threshold value , calculated ;
[0112] priority correction coefficient According to the standard deviation adjustment of the processing priority value, the standard deviation interval 0.1 to 0.5 corresponds to to , the current standard deviation is 0.3, and the value is taken ;
[0113] Example calculation process: substitute parameters , , , , , , the formula is expanded as
[0114] ;
[0115] The results show that the resource allocation characteristic value tends to 1, reflecting that the current processing priority and the resource allocation weight matching degree are high, and the negative influence of the load difference on the allocation result is partially offset by the correction coefficient. The resource allocation characteristic value is directly related to the resource allocation characteristic parameter calculation, the numerical result is input into the consensus type identification information, and the consensus type identification result is generated through threshold determination.
[0116] The steps of obtaining the node security score are specifically:
[0117] S401: Use the consensus type identification result to call the transaction data request record and block verification response information of the blockchain node, combine the timestamp information and operation frequency data of each node, respectively calculate the average data request frequency and response time of the node within a specified time period, and generate a node behavior frequency parameter group;
[0118] In the consensus behavior analysis stage, through the identified consensus mechanism type (such as PBFT, DPoS, etc.), the transaction data request record and block verification response information of each node in the blockchain node management are called, the complete behavior log of each node in the specified time period is read, which can be defined as the past 60 seconds or 10 consensus rounds, the transaction request sending time and verification response time are obtained through the timestamp field recorded in the log, and the average data request frequency and average response time setting of the node are calculated combined with the operation frequency data (such as the request sending frequency is 120 times and the response record number is 110 times). If node A initiates 120 requests in the past 60 seconds, the average request frequency is 2 times per second; the response time is obtained by accumulating the time difference from each request sending to receiving the confirmation and then dividing by the response number to obtain the mean value. In this process, the timestamp information of each node needs to be synchronized to avoid time offset interference caused by node clock drift, and each node will generate a set of behavior parameter data including “average request frequency” and “average response delay”. This data is used for subsequent analysis of the behavior stability and response ability of the node under the current consensus mechanism, and a node behavior frequency parameter group is generated.
[0119] S402: According to the node behavior frequency parameter group, the execution deviation time of the node in the near cycle is combined, the corresponding node execution delay and response abnormal amplitude are extracted, and the node delay and response abnormal amplitude are respectively compared with the set offset state threshold value. The node set exceeding the threshold value range is screened and the node number is marked, and the node offset measurement result is generated.
[0120] Further analyze its actual operation performance in the specified period, especially focus on the deviation of operation instruction execution, obtain the execution delay of each instruction by calling the difference between the actual execution time of each instruction and the scheduled preset execution time; the preset response should be completed within 10 milliseconds, but node B spends 22 milliseconds in some execution, so the delay is 12 milliseconds. Organize the operation delay, calculate the delay mean and maximum value for each node to form the delay performance index, and analyze the response abnormal amplitude, which refers to the delay fluctuation degree in continuous requests. If the node response time exists a large amplitude jump, set from 8 milliseconds to 50 milliseconds, record its maximum abnormal amplitude as 42 milliseconds. The delay and abnormal amplitude are compared with the set offset state threshold value, such as setting the offset delay threshold value as 10 milliseconds and the abnormal amplitude threshold value as 20 milliseconds. The nodes exceeding any threshold value are screened. In the comparison process, the interval matching mechanism is used, and each node is marked as “normal” or “abnormal”, and its unique node number is recorded for subsequent consensus weight adjustment and node risk scoring, and the node offset measurement result is formed.
[0121] S403: Call the node number corresponding to the consensus type classification information in the node offset measurement result, adjust the consensus weight parameter of the node by combining the network transaction activity value and the consensus participation frequency, and obtain the node security score;
[0122] The consensus type classification information corresponding to each node number is called, and the consensus weight parameter of the node is corrected by combining the transaction activity index in the current network and the participation frequency of the node under the consensus mechanism. The transaction activity value is determined by the number of broadcast transactions per unit time, and the number of transactions in the last 10 seconds is set to 4000, which is defined as a high activity level. The consensus participation frequency is the number of block verification times participated by the node in the past one or more rounds of consensus. For example, if node C participates in 4 rounds in the past 5 rounds, its frequency is 80%. The node offset state is compared with the data, and for the nodes with delay anomaly or serious response offset, even if their consensus participation frequency is high, their consensus weight will be appropriately adjusted. On the contrary, if the node response is stable and the frequency is moderate, the weight parameter will be maintained or slightly adjusted. The adjustment range is controlled by the configured weight correction strategy. The score value quantifies the behavior stability and response reliability of the node under the current network and consensus mechanism, which can be used as the basis for subsequent consensus voting, task allocation and abnormal exclusion. The node security score is generated.
[0123] The obtaining step of the audit log identifier is specifically:
[0124] S501: Call the node security score, extract the associated transaction number field, and read the block identifier and time marker data bound under the corresponding transaction number item. Combine the permission change type, target address and adjustment timestamp field to sequentially splice the three types of structures to obtain the block permission identification result;
[0125] The transaction interaction information of the node is obtained through the interface, the corresponding transaction numbers of the node in the transaction index table are queried through the unique identification of the node, if the numbers are transaction 001, transaction 002, transaction 003, etc., the number records the node behavior data, the transaction numbers are processed one by one, the block number and block time marker information corresponding to each transaction number are extracted from the transaction detail table, if transaction 001 belongs to block A001, the time is March 1, 2025, 10:15, it is formatted as "block A001 | March 1, 2025, 10:15", transaction 002, transaction 003, etc. are continuously processed, then the permission change records related to the transaction are queried, the permission change type field (such as permission addition, permission revocation), the target address field (such as user address A1B2C3) and the adjustment time field (such as March 1, 2025, 10:16) matched with each transaction number are extracted from the permission management table, then the data is spliced in the order of "block number | block time | permission change type | target address | adjustment time", if "block A001 | March 1, 2025, 10:15 | permission addition | address A1B2C3 | March 1, 2025, 10:16", the splicing structure maintains the uniformity of the field order and the integrity of the content, the same extraction and splicing are repeated for the transaction numbers, which are used for subsequent structure processing and security behavior analysis, and the block permission recognition result is obtained.
[0126] S502: Based on the field content in the block permission recognition result, a local hash value is generated for each log entry in the time marker increasing order by using a chain hash flow, an aggregate hash operation is performed on the local hash value to construct a hash tree structure, a root node hash field of the hash tree is extracted, and a permission adjustment record is generated;
[0127] According to the adjustment timestamp field contained in each record, the sorting is in ascending order, which ensures that the processing order conforms to the time logic. During the sorting process, the adjustment time field values of all records need to be compared, and each permission change data is arranged in order from the earliest time, such as 10:15, 10:20, 10:25, etc. on March 1, 2025. After sorting, each record is numbered in sequence, and the local hash value of each record is generated by processing each record in sequence, that is, the overall structure data obtained by splicing the block number, original time, permission change type, target address and adjustment time is taken as input, and the chain hash processing method is used to form the encrypted digest of each log. This process can use a programming language to implement static hash processing logic, take the splicing result as an input string, generate a digest through a hash function, and generate a hash digest aabb1122 for a certain splicing structure. Continue to combine the local hash results in order, form a new hash input, and perform hash processing again to build a higher-level hash node. Each two combinations form a node, and continue to combine to form higher-level nodes to build a hash tree structure. In this tree structure, the root node is the permission change record digest value, representing the consistency of all permission adjustments. The generated root node hash value can be stored as a unique identifier of the permission adjustment record in the main record chain for future permission verification or backtracking operations, and the permission adjustment record is generated.
[0128] S503: Call the transaction metadata bound to the permission adjustment record and the transaction number, combine them into a binding structure after indexing alignment, and write the binding structure into the tamper-proof storage layer to generate an audit log identifier;
[0129] Immediately call the transaction metadata of the record under the transaction number corresponding to it, which includes transaction type, requester identity, public key address, original request parameter and other fields, to form a set of static information describing the transaction background and attributes. Through the index mapping mechanism, the permission log hash and the transaction number are one-to-one bound and aligned to ensure that each permission log corresponds to a specific transaction behavior. After alignment, a binding structure is built, which includes transaction number, permission adjustment record, block identifier, permission operation details and original metadata content. After building, call the write interface of the tamper-proof storage layer, set to use distributed files or special audit blockchain nodes, write the structure as an unchangeable data unit into the chain storage area, generate a unique data identifier number, set "LOG20250418140001", and record the timestamp and node number of the write operation to ensure the integrity and traceability of the log. Return the log identifier as an audit reference number for external or subsequent verification process calls, and generate an audit log identifier.
[0130] The above merely illustrates the specific embodiments of the present application, but the protection scope of the present application is not limited thereto, any person skilled in the art can easily think of the changes or replacements within the technical range disclosed by the present application, which should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A data transaction method based on blockchain, characterized in that, Includes the following steps: S1: Obtain the original consumer transaction data, perform multi-layer encryption on the data, the first layer of encryption generates primary encrypted ciphertext, the primary encrypted ciphertext is input into the blockchain node for secondary encryption, calculate the hash value of the multi-layer encrypted ciphertext, and generate encrypted data identifier; S2: Call the smart contract corresponding to the encrypted data identifier, extract the access permission conditions defined in the smart contract, detect the consumer's public key address and transaction request type, match the public key address with the address list in the access permission conditions, if the match is successful, perform automatic verification, dynamically calculate the credit score based on the consumer's behavior, if the score exceeds the preset threshold, assign an access permission instruction and generate an access permission value. S3: Call the transaction level classification corresponding to the access permission value, monitor the real-time transaction volume and node activity status of the blockchain network, evaluate the correlation between network load status and transaction level classification, and generate consensus type identification results; S4: Based on the consensus type identification results, extract the data request frequency and verification response speed of the blockchain node, analyze the deviation state of the node behavior, and if the deviation state exceeds the preset threshold, adjust the consensus weight value of the node and generate a node security score. S5: Call the node security score, extract the block identifier and time stamp of the corresponding transaction, combine the block identifier, time stamp and permission change record into a log structure, perform hash calculation on the log structure using a chain hash process, bind the root hash identifier with the transaction metadata and write it into the immutable storage layer to generate an audit log identifier; The audit log identifier includes block height encoding, timestamp sequence, and root hash digest; The specific steps for obtaining the audit log identifier are as follows: S501: Call the node security score, extract the associated transaction number field, and read the block identifier and timestamp data bound under the corresponding transaction number item. Combine the permission change type, target address and adjustment timestamp fields, and concatenate the three types of structures in sequence to obtain the block permission identification result. S502: Based on the field content in the block permission identification result, a chain hash process is used to generate a local hash value for each log entry in ascending order of time stamp. An aggregate hash operation is performed on the local hash value to construct a hash tree structure. The root node hash field of the hash tree is extracted to generate a permission adjustment record. S503: Call the transaction metadata that is bound to the permission adjustment record and the transaction number, index and align the two and combine them into a binding structure, write the binding structure to the immutable storage layer, and generate an audit log identifier.
2. The data transaction method based on blockchain according to claim 1, characterized in that, The encrypted data identifier includes encrypted ciphertext hash, data storage location identifier, and encryption level marker; the access permission value includes permission matching status, dynamic credit level, and permission instruction code; the consensus type identification result includes load status level, transaction emergency classification, and consensus mechanism type; and the node security score includes behavior deviation coefficient, weight adjustment ratio, and security assessment label.
3. The blockchain-based data transaction method according to claim 1, characterized in that, The specific steps for obtaining the encrypted data identifier are as follows: S101: Obtain the original consumer transaction data, extract account information, transaction time and transaction amount, call the symmetric key, encrypt the transaction characters after concatenating the fields, and generate a sequential encrypted ciphertext structure; S102: Call the sequential encrypted ciphertext structure and write it into the target blockchain node. In the blockchain node, the input ciphertext is indexed according to the key index value built into the node. Combined with the node timestamp and the ciphertext sequence number, the field structure is broken down and rearranged, and re-encryption calculation is performed to generate the node's hybrid encrypted field. S103: After extracting the field combination structure based on the node's hybrid encryption field, perform a hash generation operation, store and combine the hash signature value with the original data, and obtain the encrypted data identifier.
4. The blockchain-based data transaction method according to claim 3, characterized in that, The specific steps for obtaining the access permission value are as follows: S201: Call the smart contract corresponding to the encrypted data identifier, extract the access permission condition field defined in the smart contract structure. The field content includes the list of accessed addresses, the corresponding transaction type and permission threshold. Based on the hash value bound in the identifier structure, the field is located and indexed to generate a set of contract permission condition parameters. S202: Based on the address list field in the contract permission condition parameter set, compare the public key address data provided by the consumer with the node address in the address list, compare whether there is a complete match with the same position, and mark the verification status according to the matching success flag, and obtain the public key address matching status. S203: Call the transaction type field in the public key address matching status, compare it with the real-time transaction request type data, extract the credit assessment benchmark field corresponding to the successfully matched item, and generate the access permission value by combining the consumer transaction frequency, account credit score and transaction requests per unit time.
5. The blockchain-based data transaction method according to claim 4, characterized in that, The formula for comparing whether there is a perfect match with the same position is as follows: ; in, This represents the degree of matching between public key addresses. This represents the number of address bytes to be compared. The first in the address list Bit byte The first public key address data provided on behalf of the consumer Bit byte Representing the The weight value of the bit byte. express and The absolute value of the byte difference between them.
6. The blockchain-based data transaction method according to claim 4, characterized in that, The specific steps for obtaining the consensus type identification result are as follows: S301: Call the transaction level classification field corresponding to the access permission value, extract the level category number and corresponding processing priority value defined in the field, combine real-time blockchain network data, monitor the total number of transaction broadcasts and the number of active nodes within the time window, perform time synchronization and cumulative statistical processing on the two types of data, and generate network operation status parameters. S302: Based on the number of transaction broadcasts and the number of active nodes in the network operation status parameters, construct the transaction density value and node response ratio per unit time, compare and judge with the set blockchain load identification benchmark value, identify the load status interval identifier, and generate the network load status level. S303: Call the transaction level number associated with the network load status level and access permission value for cross-matching, compare the processing priority value defined in the level number with the resource allocation weight corresponding to the load status, calculate the resource allocation feature value, select the consensus identifier corresponding to the processing path, and generate a consensus type identification result.
7. The blockchain-based data transaction method according to claim 6, characterized in that, The formula for calculating the resource allocation characteristic value is as follows: ; in, Represents the characteristic value of resource allocation. Represents the adjustment factor. Represents the dynamic balance coefficient of resource allocation weights. This represents the processing priority value. This represents the resource allocation weight corresponding to the load status. Represents the load difference. This represents the priority adjustment coefficient.
8. The blockchain-based data transaction method according to claim 6, characterized in that, The specific steps for obtaining the node security score are as follows: S401: Using the consensus type identification result, call the transaction data request record and block verification response information of the blockchain node, and combine the timestamp information and operation frequency data of each node to calculate the average data request frequency and response time of the node in the specified time period, and generate a node behavior frequency parameter group. S402: Based on the node behavior frequency parameter group, combined with the execution deviation time of multiple operation instructions of the node in the recent cycle, extract the corresponding node execution delay and response abnormality amplitude, and compare the node delay and response abnormality amplitude with the set offset state threshold, filter the set of nodes that exceed the threshold range and mark the node number, and generate the node offset measurement result. S403: Call the consensus type classification information corresponding to the node number in the node offset measurement result, and adjust the consensus weight parameter of the node in combination with the network transaction activity value and consensus participation frequency to obtain the node security score.
Citation Information
Patent Citations
Consensus efficiency control system for blockchain network consensus accelerator
CN112260905A
Transaction method and system for realizing block chain user identity authentication based on smart contract
CN113240426A
System and method for controlling transaction data access
US20210294915A1