Private computing data access control method and system based on block chain
By introducing blockchain technology and smart contracts in privacy computing, the existing privacy computing data access control methods have solved the problems of poor flexibility, low security, low efficiency and poor experience, and efficient and secure data access control and refined management have been achieved.
Patent Information
- Application Number
- CN202510366585.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-06-17
AI Technical Summary
The existing privacy computing data access control methods have problems such as poor flexibility, low security, low efficiency and poor experience, and cannot effectively prevent illegal users from pretending and improving data access control efficiency.
The blockchain-based privacy computing data access control method is adopted, and the mobile terminal is generated and registered through trusted institutions, and the access permission levels are divided and the product classification model, access permission classification model and keyword extraction model are built. The encrypted data is linked and over-linked using the blockchain network, and signature verification and permission classification are automatically performed through smart contracts.
It enhances the security and efficiency of data access control, realizes refined management of different user roles, improves the historical traceability and immutability of data, reduces manual intervention, improves user experience, and ensures secure data interaction and transactions between the data provider and the data demander.
Smart Images

Figure CN120162827A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of privacy computing, and particularly relates to a privacy computing data access control method and system based on blockchain. Background Art
[0002] With the development of big data and artificial intelligence technologies, privacy computing has been widely applied in fields such as healthcare, finance, and government affairs. Privacy computing allows data to be calculated while encrypted or transformed, thereby protecting data privacy. However, how to effectively control data access without revealing the data content has become an urgent problem to be solved.
[0003] Existing privacy computing data access control methods have the following defects: 1) In the prior art, by setting user permissions for logged-in users, the permission management is not flexible and cannot defend against illegal user impersonation, resulting in low data security; 2) In the prior art, the efficiency of data access control is low, affecting the user experience. Summary of the Invention
[0004] In order to solve the problems of poor flexibility, low security, low efficiency, and poor experience existing in the prior art, the purpose of the present invention is to provide a privacy computing data access control method and system based on blockchain.
[0005] The technical solution adopted by the present invention is as follows: A privacy computing data access control method based on blockchain, comprising the following steps: Based on a trusted institution, generate keys and perform identity registration for all mobile terminals to obtain the public-private key pairs and signature information of each mobile terminal, return the private keys in the public-private key pairs and the signature information to the corresponding mobile terminals, and send the public keys in the public-private key pairs to the restricted database of the privacy computing center; Based on the privacy computing center, divide the access permission levels of mobile terminals, the preset product classification types of product data, and set the corresponding allowed access product classification ranges for each access permission level, and construct a product classification model, an access permission classification model, and a keyword extraction model; Based on the first mobile terminal as the data provider, collect real-time product data, encrypt and sign the real-time product data according to the first private key and the first signature information in the first public-private key pair of the first mobile terminal to obtain the encrypted real-time product data and the first signature data, and upload them to the privacy computing center; Based on the privacy computing center, perform signature verification on the first signature data. If the signature verification passes, then according to the encrypted real-time product data, use the preset product classification model to perform product classification, obtain the real-time product classification type, and proceed to the next step. Otherwise, abort the data access and wait for the next mobile terminal to access; Based on the privacy computing center, collect the first access behavior data of the first mobile terminal to the privacy computing center. According to the first access behavior data, use the preset access permission classification model to perform access permission classification and obtain the first access permission level; If the first access permission level has data storage permission and the real-time product classification type belongs to the first allowed access product classification range of the first access permission level, then based on the real-time product classification type, on the blockchain network of the privacy computing center, link and chain the encrypted real-time product data and wait for the next mobile terminal to access. Otherwise, abort the data access and wait for the next mobile terminal to access; Based on the second mobile terminal as the data requester, collect real-time demand data. According to the second private key and the second signature information in the second public-private key pair of the second mobile terminal, encrypt and sign the real-time demand data to obtain the encrypted real-time demand data and the second signature data, and upload them to the privacy computing center; Based on the privacy computing center, perform signature verification on the second signature data. If the signature verification passes, then decrypt the encrypted real-time demand data according to the second public key to obtain the decrypted real-time demand data and proceed to the next step. Otherwise, abort the data access and wait for the next mobile terminal to access; Based on the privacy computing center, according to the decrypted real-time demand data, use the preset keyword extraction model to perform keyword extraction to obtain the real-time demand product classification type, collect the second access behavior data of the second mobile terminal to the privacy computing center, and according to the second access behavior data, use the preset access permission classification model to perform access permission classification to obtain the second access permission level; If the second access permission level has data trading permission and the real-time demand product classification type belongs to the second allowed access product classification range of the second access permission level, then retrieve the corresponding encrypted target product data in the blockchain network according to the decrypted real-time demand data and the real-time demand product classification type, and proceed to the next step. Otherwise, abort the data access and wait for the next mobile terminal to access; Based on the privacy computing center, according to the target data provider of the encrypted target product data, extract the third public key of the third mobile terminal as the target data provider in the restricted database. According to the third public key, decrypt the encrypted target product data to obtain the decrypted target product data; Based on the privacy computing center, privacy computing is performed according to the decrypted required data and the decrypted target product data to generate transaction data. Based on the real-time required product classification type, the transaction data is linked and uploaded to the blockchain network.
[0006] Furthermore, the access permission levels include the high-level access permission level, the medium-level access permission level, and the low-level access permission level. The high-level access permission level includes the data storage permission and the data transaction permission, and the allowed access product classification range of the high-level access permission level includes all classified and unclassified preset product classification types. The medium-level access permission level includes either the data storage permission or the data transaction permission, and the allowed access product classification range of the medium-level access permission level includes all unclassified preset product classification types. The low-level access permission level does not include the data storage permission and the data transaction permission, and the allowed access product classification range of the low-level access permission level does not include any preset product classification type.
[0007] Furthermore, based on the privacy computing center, the access permission levels of the mobile terminals, the preset product classification types of the product data, and the corresponding allowed access product classification ranges are set for each access permission level, and a product classification model, an access permission classification model, and a keyword extraction model are constructed, including the following steps: Based on the privacy computing center, the access permission levels of the mobile terminals are divided into the high-level access permission level, the medium-level access permission level, and the low-level access permission level, and several different preset product classification types are divided. Collect several encrypted historical product data, set the corresponding preset product classification type labels for each encrypted historical product data to obtain several product classification samples, and use the deep learning algorithm to construct a product classification model according to the several product classification samples. Collect several historical access behavior data, set the corresponding access permission level labels for each historical access behavior data to obtain several access permission classification samples, and use the deep learning algorithm to construct an access permission classification model according to the several access permission classification samples. Collect several historical required data, perform named entity annotation for each historical required data according to the preset product classification type to obtain several keyword extraction samples, and use the natural language processing algorithm to construct a keyword extraction model according to the several keyword extraction samples.
[0008] Furthermore, the product classification model is constructed based on the RF-BiSLTM algorithm.
[0009] Furthermore, the access permission classification model is constructed based on the N-GAN-MLP algorithm.
[0010] Furthermore, the keyword extraction model is constructed based on the BERT-BILSTM-Attention-CRF algorithm.
[0011] Furthermore, the blockchain network of the privacy computing center includes a call interface, a smart contract, an IPFS system, and a blockchain composed of a distributed connection of several nodes.
[0012] Furthermore, according to the real-time product classification type, based on the blockchain network of the privacy computing center, the PBFT consensus algorithm is used to link and chain the encrypted real-time product data.
[0013] Furthermore, according to the real-time demand product classification type, based on the blockchain network, the PBFT consensus algorithm is used to link and chain the transaction data.
[0014] A blockchain-based privacy computing data access control system for implementing a privacy computing data access control method. The privacy computing data access control system includes a privacy computing center, a trusted institution, and several mobile terminals. The privacy computing center and the trusted institution are both communicatively connected to several mobile terminals respectively, and the privacy computing center is communicatively connected to the trusted institution.
[0015] The beneficial effects of the present invention are as follows: The present invention discloses a blockchain-based privacy computing data access control method and system, which combines blockchain technology with privacy computing to enhance the security of data access control through the immutability and decentralization characteristics of the blockchain. At the same time, privacy computing is used to protect the data content, realizing effective access control on the premise of ensuring data privacy; by generating keys and registering identities for mobile terminals, the uniqueness of each terminal and the security of data are ensured, and public-private key pairs and signature information are used to encrypt and sign data, ensuring the confidentiality and integrity of data during transmission; the access permission levels of mobile terminals are divided, and the corresponding allowed access product classification ranges are set, realizing refined management of different user roles. By constructing a product classification model, an access permission classification model, and a keyword extraction model, intelligent permission allocation, access control, and data query are realized, improving the practicality; by using the blockchain network to link and chain the encrypted real-time product data, the historical traceability and immutability of data are ensured; privacy computing is performed in the blockchain network, avoiding the direct exposure of data content, and at the same time ensuring the correctness and credibility of the calculation results; using smart contracts to automatically execute processes such as signature verification, permission classification, and data decryption reduces manual intervention, improves the automation and efficiency of the system, and improves the user experience; realizes secure data interaction and transactions between data providers and data demanders, and ensures the transparency and fairness of transactions through the blockchain network.
[0016] Other beneficial effects of the present invention will be further described in the specific implementation manners. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 is a flowchart of the blockchain-based privacy computing data access control method in the present invention Figure 1 .
[0018] Figure 2 is a flowchart of the blockchain-based privacy computing data access control method in the present invention Figure 2 .
[0019] Figure 3 is a structural block diagram of the blockchain-based privacy computing data access control system in the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0020] The present invention will be further explained below in conjunction with the accompanying drawings and specific embodiments.
[0021] Embodiment 1: As Figure 1 and Figure 2 jointly show, this embodiment provides a blockchain-based privacy computing data access control method, including the following steps: S1: Based on a trusted institution, key generation and identity registration are performed on all mobile terminals to obtain a public-private key pair and signature information for each mobile terminal. The private key in the public-private key pair and the signature information are returned to the corresponding mobile terminal, and the public key in the public-private key pair is sent to the restricted database of the privacy computing center, including the following steps: S1-1: Based on a trusted institution, key initialization is performed to obtain public parameters, a master key, and an initial key;
[0022] In the formula, are public parameters; is the master key; is the initial key; is the integer domain random number of; are all target hash functions; are all cyclic groups random numbers of the generators of; is the random number bilinear mapping of; S1-2: Collect the first attribute information and the entity ID of the mobile terminal, and based on the first attribute information, public parameters, master key, and initial key, use an asymmetric encryption algorithm to generate a key for the mobile terminal to obtain the corresponding first public-private key pair;
[0023] Wherein, is the first private key of the mobile terminal ; is a random number in the integer domain ; is the first private key parameter of the mobile terminal ; is the public parameter of the target hash hash function; is the mobile terminal indication quantity; is the master key; is the initial key; is the mobile terminal of the first public key; is a random number of the generator of the cyclic group ; is the mobile terminal of the first attribute information; S1-3: According to the first public-private key pair and the corresponding entity ID, use the digital identity authentication method to perform identity registration to obtain the signature information of the corresponding mobile terminal; The formula is:
[0024] Wherein, is a random number; is the registration parameter of the mobile terminal ; is the registration ID of the mobile terminal ; and the corresponding constitute the signature information ; is the target hash hash function; is the entity ID of the mobile terminal ; is the prime order; is the prime field base point; S1-4: Return the private key in the public-private key pair and the signature information to the corresponding mobile terminal, and send the public key in the public-private key pair to the restricted database of the privacy computing center; The restricted database is used to store the public key. Only when the access permission level meets the requirements can the required public key be extracted from the restricted database, avoiding the abuse of the public key and ensuring the security of the data; S2: Based on the privacy computing center, divide the access privilege levels of mobile terminals, the preset product classification types of product data, and set the corresponding allowed access product classification ranges for each access privilege level, and construct a product classification model, an access privilege classification model, and a keyword extraction model, including the following steps: S2-1: Based on the privacy computing center, divide the access privilege levels of mobile terminals into high-level access privilege levels, medium-level access privilege levels, and low-level access privilege levels, and divide several different preset product classification types; The access privilege levels include high-level access privilege levels, medium-level access privilege levels, and low-level access privilege levels; The high-level access privilege level includes data storage permission and data trading permission, and the allowed access product classification range of the high-level access privilege level includes all classified and unclassified preset product classification types; The medium-level access privilege level includes data storage permission or data trading permission, and the allowed access product classification range of the medium-level access privilege level includes all unclassified preset product classification types; The low-level access privilege level does not include data storage permission and data trading permission, and the allowed access product classification range of the low-level access privilege level does not include any preset product classification type; S2-2: Collect several encrypted historical product data, set the corresponding preset product classification type labels for each encrypted historical product data to obtain several product classification samples, and use a deep learning algorithm based on the several product classification samples to construct a product classification model; The product classification model is constructed based on the Random Forest (RF)-Bidirectional Long Short-Term Memory (BiLSTM) algorithm, and the product classification model includes a key feature extraction module constructed based on the RF algorithm and a product classification module constructed based on the BiSLTM algorithm; The RF module screens the key features of the input product data through the internal Classification And Regression Tree (CART), extracts the key features related to product classification. The BiLSTM network is also a deep learning network structure, and the BiLSTM network has a powerful memory function, which can predict the features of newly input product data. By mining the deep relationship between data features and product classification labels, the rapid, efficient, and accurate prediction of product classification labels is realized; S2-3: Collect a number of historical access behavior data, set corresponding access permission level labels for each historical access behavior data to obtain a number of access permission classification samples, and use a deep learning algorithm to construct an access permission classification model based on the number of access permission classification samples; The access permission classification model is constructed based on the N - Generative Adversarial Network (GAN) - Multilayer Perceptron (MLP) algorithm, and the access permission classification model includes N attention dimension feature extraction modules constructed based on the GAN algorithm and an access permission classification module constructed based on the MLP algorithm, where N is the total number of attention dimensions; The attention dimensions include the access legality dimension, the access frequency dimension, and the management cost dimension, etc.; By paying attention to the above dimensions, the characteristic information of access legality, access frequency, and management cost can be identified, and an appropriate access permission type can be assigned to each mobile terminal; The GAN network includes a generator and a discriminator. The generator is responsible for generating access behavior data features from the latent space, and the discriminator is responsible for judging the authenticity of the access behavior data features. The identification of the access behavior data is added to the discriminator so that it not only judges the authenticity of the access behavior data but also judges whether it conforms to the access behavior data features. By extracting the features of the access behavior data from different dimensions, multi - angle analysis is realized, improving the comprehensiveness of access permission classification. The MLP network fuses the multi - angle access behavior data features, improving the representation ability of the access behavior data features for data information and the accuracy of access permission classification; S2-4: Collect a number of historical requirement data, perform named entity annotation for each historical requirement data according to the preset product classification type to obtain a number of keyword extraction samples, and use a natural language processing algorithm to construct a keyword extraction model based on the number of keyword extraction samples; The keyword extraction model is constructed based on the Bidirectional Encoder Representation from Transformers (BERT)-BILSTM-Attention-Conditional Random Field (CRF) algorithm. The keyword extraction model includes an embedding module constructed based on the BERT algorithm, a semantic feature extraction module constructed based on the BILSTM algorithm, an attention weight acquisition module established based on the Attention mechanism, and a named entity recognition module constructed based on the CRF algorithm. After passing through the semantic feature extraction module based on the sequence model, the contract structured data can be converted from a character sequence into a dense vector representation. This vector has a low dimension and can well represent the semantic information and sequence information of the text. The Attention module provides attention weights for the features of interest, improving the accuracy of the model. The embedding module converts the requirement data into a sequence of word vectors. The BILSTM network of the semantic feature extraction module traverses the input sequence of word vectors bidirectionally, obtaining the bidirectional hidden layer representation of the data. Finally, a comprehensive feature representation of the requirement data, that is, the semantic feature, is constructed based on the bidirectional hidden layer vectors. The Attention module provides attention weights for the features of interest, improving the accuracy of the model. The CRF module can effectively capture the long-distance dependencies in the sequence data and achieve named entity recognition. S3: Based on the first mobile terminal as the data provider, collect real-time product data, encrypt and sign the real-time product data according to the first private key and the first signature information in the first public-private key pair of the first mobile terminal, obtain the encrypted real-time product data and the first signature data, and upload them to the privacy computing center. The formula is:
[0025] In the formula, is the encrypted real-time product data; is the asymmetric encryption function; is the real-time product data; is the first mobile terminal 's first private key;
[0026] In the formula, is a random number; is the prime order; is the prime field base point; is the target hash hash function; is the first signature information in the first mobile terminal Registration parameters; Is the first signature information In the first mobile terminal Registration ID; Is the first mobile terminal Entity ID; The first signature data composed of is ; The first mobile terminal First signature parameters; S4: Based on the privacy computing center, perform signature verification on the first signature data. If the signature verification passes, use the preset product classification model according to the encrypted real-time product data to perform product classification, obtain the real-time product classification type, and enter the next step. Otherwise, abort the data access and wait for the next mobile terminal to access; The formula is:
[0027] In the formula, Is the first signature parameter of the first mobile terminal ; Is the first mobile terminal First public key; If the left side is equal to the right side, the signature verification passes; Among them, according to the encrypted real-time product data, using the preset product classification model to perform product classification, obtaining the real-time product classification type includes the following steps: A-1: According to the encrypted real-time product data, use the key feature extraction module of the product classification model to perform key feature extraction, obtaining several real-time key features, including the following steps: A-1-1: Use the trained RF structure in the product classification model to extract the feature contribution degrees of several real-time alternative features in the encrypted real-time product data; The formula is:
[0028] In the formula, Is the Feature contribution degree of the real-time alternative feature; Is the Feature contribution degree of the real-time alternative feature in the th tree of the random forest; Is the CART tree indicator; Is the real-time alternative feature indicator; Is the total number of CARTs;
[0029] In the formula, The CART tree node of the random forest m , node and node r 's Gini index; is the CART tree node m in the category 's proportion; is the total number of categories; m , , r is the node indicator; is the category indicator; A-1-2: Normalize the feature contribution degrees of several real-time alternative features to obtain the corresponding several normalized feature contribution degrees; The formula is:
[0030] In the formula, is the normalized feature contribution degree; J is the total number of real-time alternative features; A-1-3: Generate the feature selection standard values of several real-time alternative features according to the normalized feature contribution degrees; The formula is:
[0031] In the formula, is the feature selection standard value of the real-time alternative feature; is the normalized feature contribution degree of the real-time alternative feature; is the alternative feature indicator; A-1-4: Sort the real-time alternative features in descending order according to the feature selection standard values, and select the first M real-time alternative features as real-time key features to obtain M real-time key features, where M is the total number of real-time key features; A-2: Use the product classification module to classify the products according to the M real-time key features to obtain the real-time product classification type; S5: Based on the privacy computing center, collect the first access behavior data of the first mobile terminal to the privacy computing center, and use the preset access permission classification model to classify the access permission according to the first access behavior data to obtain the first access permission level, including the following steps: S5-1: Collect the first access behavior data of the first mobile terminal to the privacy computing center; S5-2: Use the N attention dimension feature extraction modules of the access permission classification model to extract the N attention dimension features of the first access behavior data; S5-3: Feature fusion is performed on the N feature characteristics of the attention dimensions to obtain the fused feature of the attention dimensions. Based on the fused feature of the attention dimensions, access permission classification is carried out to obtain the first access permission level; S6: If the first access permission level has data storage permission, that is, it belongs to the high-level access permission level or the medium-level access permission level, and the real-time product classification type belongs to the first allowed access product classification range of the first access permission level, then based on the real-time product classification type, on the blockchain network of the privacy computing center, the encrypted real-time product data is linked to the chain and waits for the next mobile terminal to access. Otherwise, data access is aborted and waits for the next mobile terminal to access; The blockchain network of the privacy computing center includes a call interface, a smart contract, an InterPlanetary File System (IPFS), and a blockchain composed of a distributed connection of several nodes; In this embodiment, based on the real-time product classification type, on the blockchain network of the privacy computing center, using the Practical Byzantine Fault Tolerance (PBFT) consensus algorithm, the encrypted real-time product data is linked to the chain, including the following steps: B-1: According to the hierarchical mechanism, all nodes in the blockchain are divided into a classification consensus layer, a consensus confirmation layer, and a supervision layer; B-2: Using the Affinity-Propagation (AP) clustering algorithm, with the product classification type as the clustering target, all nodes in the classification consensus layer are clustered to obtain several consensus node groups corresponding to the preset product classification types, including the following steps: B-2-1: Collect the feature data of the nodes in the blockchain network, including the performance indicators of the nodes (such as processing capacity, storage capacity, network bandwidth), location data, and historical behaviors (such as processing product classification records, transaction volumes, consensus participation degrees, supervision records, etc.); B-2-3: Introduce a reward and punishment mechanism, obtain the reputation values of the nodes in the blockchain network, and sort the nodes in descending order according to the reputation values, and set bias parameters for the first nodes; The bias parameter represents the tendency of a data point to be selected as a clustering center and has an important impact on which class representatives will be the final clustering centers. When the bias parameter value is larger, it means that the data point is more likely to be the final clustering center, weakening the influence of the AP clustering algorithm on the initial nodes; The formula of the reward and punishment mechanism is:
[0032] In the formula, is the number of times a node participates in data security verification; e is the natural constant; the reward value formula is based on a Sigmoid function, which is a special form of the Logistic function and is a commonly used s type of activation function in neural networks; the output range of the function's value range is from 0 to 1, which can normalize the output variables. When a node participates in consensus, the reward value obtained by the node will experience a period of slow growth; as the number of verification times increases, the final reward value obtained by the node will gradually tend to be constant. The Sigmoid function maps the reward value obtained by the node within a certain range, which can prevent the reward value obtained by the node from being too large to produce a "super node";
[0033] In the formula, is the number of times of data security verification failure; is the penalty trigger times threshold; when the node fails in data security verification multiple times, the system will automatically determine that the node is a Byzantine node and does not allow it to participate in the consensus process, quickly removing malicious master nodes in the network, avoiding the influence of malicious master nodes on the reliability and security of the system, and effectively ensuring the honesty of consensus nodes; The formula for the reputation value is:
[0034] In the formula, is the current reputation value of each node; is the node indicator; is the initial reputation value of each node; is the weight of the reward mechanism; is the single - time reward value of the node; is the weight of the penalty mechanism; is the single - time penalty value of the node; the reputation value of the node will be updated after each consensus cycle; B - 2 - 3: Based on the bias parameter value of the node, using the AP clustering algorithm with the functional characteristics of the node as the clustering object for initialization, to obtain initial clustering centers, is the total number of clustering centers; B - 2 - 4: Obtain the initial attractiveness information and initial belonging information of the node for each initial clustering center; The formula for the attractiveness information is:
[0035] In the formula, is the number of iterations t when it is k +1, node iThe degree of the clustering center, i.e., the node k The attractiveness information of the node i ; is the number of iterations t When the node i Select the node j As its suitability as a clustering center; is the number of iterations t When the node j Is suitable as the node i The degree of the clustering center; Is the node k As the node i The similarity of the clustering center; i , j And k Are all node indicators; The formula for the membership information is:
[0036] In the formula, Is the number of iterations t +1 When the node k The overall suitability as a clustering center; Is the number of iterations t +1 When the node k Is suitable as other clustering centers except the node i Degree; Is the number of iterations t +1 When the node i Select the node k As its clustering center, that is, the node k To the node i Membership information; B-2-5: Introduce an iterative attenuation coefficient, update the attractiveness information and membership information of all nodes, and update the Initial clustering centers to obtain Updated clustering centers; The formula is:
[0037]
[0038] In the formula, , Are the number of iterations t +1 When the node k To the node i Updated attractiveness information and updated membership information; Is the iterative attenuation coefficient; is the number of iterations t and t when it is +1, the node k for the node i attraction information; is the number of iterations t and t when it is +1, the node k for the node i attribution information; The judgment formula for the clustering center is:
[0039] In the formula, i and k are both node indicators; if , then the node i is the node k clustering center; if , then the node k is the node i clustering center; B-2-6: Obtain the similarity between each node and several updated clustering centers, group all nodes, and obtain several corresponding initial consensus node groups; B-2-7: If the number of iterations exceeds the iteration threshold or the clustering center does not change, output the final several consensus node groups; B-2-8: Set a preset product classification type for each clustering center, and spread the preset product classification type to the corresponding consensus node group to obtain several consensus node groups corresponding to the preset product classification types; B-3: Conduct leadership elections for each consensus node group to obtain several leader nodes, and construct a leader node group based on the several leader nodes; In this embodiment, using the clustering center corresponding to each consensus node group as the leader node avoids leadership elections and improves the consensus efficiency; B-4: Store the encrypted real-time product data in the IPFS system to obtain the real-time data hash value and real-time storage address of the encrypted real-time product data; B-5: Based on the call interface, execute the smart contract to generate a real-time data storage request, package the real-time data hash value and real-time storage address into the first real-time data block, and send the real-time data storage request and the first real-time data block to the blockchain; B-6: Based on the blockchain, send the real-time data storage request and the first real-time data block to the first target consensus node group consistent with the real-time product classification type, and use the first leader node that receives the real-time data storage request and the first real-time data block as the first master node; B-7: Based on the first target consensus node group and the leader node group, use the PBFT consensus algorithm to conduct a consensus on the real-time data storage request once. If the consensus is successful once, proceed to the next step; otherwise, abort the data access and wait for the next mobile terminal to access, including the following steps: B-7-1: According to the first primary node and the corresponding first target consensus node group, use the PBFT consensus algorithm to conduct an in-group consensus on the real-time data storage request once. If the in-group consensus is successful once, proceed to the next step; otherwise, abort the data access and wait for the next mobile terminal to access; B-7-2: Based on the leader node group, use the PBFT consensus algorithm to conduct an inter-group consensus on the real-time data storage request once. If the inter-group consensus is successful once, proceed to the next step; otherwise, abort the data access and wait for the next mobile terminal to access; B-8: Send the real-time data storage request to the consensus confirmation layer, use the PBFT consensus algorithm to conduct a second consensus on the real-time data storage request. If the second consensus is successful, use the first primary node to link and chain the first real-time data block and wait for the next mobile terminal to access; otherwise, abort the data access and wait for the next mobile terminal to access; S7: Based on the second mobile terminal as the data requester, collect real-time demand data, encrypt and sign the real-time demand data according to the second private key and the second signature information in the second public-private key pair of the second mobile terminal to obtain the encrypted real-time demand data and the second signature data, and upload them to the privacy computing center; The formula is:
[0040] In the formula, is the encrypted real-time demand data; is the asymmetric encryption function; is the real-time demand data; is the second mobile terminal 's second private key;
[0041] In the formula, is a random number; is the prime order; is the prime field base point; is the target hash function; is the second signature information in the second mobile terminal 's registration parameters; is the second signature information in the second mobile terminal 's registration ID; is the second mobile terminal The entity ID; the second signature data formed is ; The second mobile terminal The second signature parameter of; S8: Based on the privacy computing center, perform signature verification on the second signature data. If the signature verification passes, decrypt the encrypted real-time demand data according to the second public key to obtain the decrypted real-time demand data, and proceed to the next step. Otherwise, abort the data access and wait for the next mobile terminal to access; The formula is:
[0042] In the formula, Is the second signature parameter of the second mobile terminal The second signature parameter of; Is the second public key of the second mobile terminal If the left side of the equation is equal to the right side, the signature verification passes;
[0043] In the formula, Is the encrypted real-time demand data; Is the asymmetric encryption function; Is the decrypted real-time demand data; Is the second public key of the second mobile terminal ; S9: Based on the privacy computing center, according to the decrypted real-time demand data, use the preset keyword extraction model to perform keyword extraction to obtain the real-time demand product classification type, collect the second access behavior data of the second mobile terminal to the privacy computing center, and according to the second access behavior data, use the preset access permission classification model to perform access permission classification to obtain the second access permission level; S10: If the second access permission level has the data trading permission and the real-time demand product classification type belongs to the second allowed access product classification range of the second access permission level, then retrieve the corresponding encrypted target product data in the blockchain network according to the decrypted real-time demand data and the real-time demand product classification type, and proceed to the next step. Otherwise, abort the data access and wait for the next mobile terminal to access; S11: Based on the privacy computing center, according to the target data provider of the encrypted target product data, extract the third public key of the third mobile terminal as the target data provider in the restricted database, and decrypt the encrypted target product data according to the third public key to obtain the decrypted target product data;
[0044] In the formula, is the decrypted target product data; is the asymmetric decryption function; is the encrypted target product data; is the third public key of the third mobile terminal; S12: Based on the privacy computing center, according to the decrypted demand data and the decrypted target product data, perform privacy computing to generate transaction data, and based on the real-time demand product classification type, use the PBFT consensus algorithm on the blockchain network to link and chain the transaction data, including the following steps: S12-1: Based on the privacy computing center, based on the call interface, execute the smart contract to generate a real-time data transaction request, send the real-time data transaction request to the second target consensus node group consistent with the real-time demand product classification type, and use the second leading node that receives the real-time data transaction request as the second primary node; S12-2: Based on the second target consensus node group and the leading node group, use the PBFT consensus algorithm to perform a primary consensus on the real-time data transaction request. If the primary consensus is successful, proceed to the next step; otherwise, abort the data access and wait for the next mobile terminal to access; S12-3: Send the real-time data transaction request to the consensus confirmation layer, use the PBFT consensus algorithm to perform a secondary consensus on the real-time data transaction request. If the secondary consensus is successful, perform privacy computing based on the decrypted demand data and the decrypted target product data using the second primary node to generate transaction data, and proceed to the next step; otherwise, abort the data access and wait for the next mobile terminal to access; S12-4: Based on the call interface, execute the smart contract to generate a real-time transaction storage request, package the transaction data into the second real-time data block, and use the PBFT consensus algorithm to perform a primary consensus on the real-time transaction storage request based on the second target consensus node group and the leading node group. If the primary consensus is successful, proceed to the next step; otherwise, abort the data access and wait for the next mobile terminal to access; S12-5: Send the real-time transaction storage request to the consensus confirmation layer, use the PBFT consensus algorithm to perform a secondary consensus on the real-time transaction storage request. If the secondary consensus is successful, use the second primary node to link and chain the second real-time data block and wait for the next mobile terminal to access; otherwise, abort the data access and wait for the next mobile terminal to access.
[0045] Embodiment 2: Such as Figure 3As shown in the figure, this embodiment provides a blockchain-based privacy computing data access control system for implementing a privacy computing data access control method. The privacy computing data access control system includes a privacy computing center, a trusted institution, and a number of mobile terminals. The privacy computing center and the trusted institution are respectively communicatively connected to the number of mobile terminals, and the privacy computing center is communicatively connected to the trusted institution; The trusted institution is used to generate keys and register identities for all mobile terminals, obtain the public-private key pairs and signature information of each mobile terminal, return the private keys in the public-private key pairs and the signature information to the corresponding mobile terminals, and send the public keys in the public-private key pairs to the restricted database of the privacy computing center; The first mobile terminal, as the data provider, collects real-time product data, encrypts and signs the real-time product data according to the first private key and the first signature information in the first public-private key pair of the first mobile terminal, obtains the encrypted real-time product data and the first signature data, and uploads them to the privacy computing center; The second mobile terminal, as the data requester, collects real-time demand data, encrypts and signs the real-time demand data according to the second private key and the second signature information in the second public-private key pair of the second mobile terminal, obtains the encrypted real-time demand data and the second signature data, and uploads them to the privacy computing center; A privacy computing center is used to divide the access permission levels of mobile terminals, preset product classification types of product data, and set corresponding allowed access product classification ranges for each access permission level, and construct a product classification model, an access permission classification model, and a keyword extraction model; verify the signature of the first signature data, and classify the encrypted real-time product data using the preset product classification model to obtain the real-time product classification type; collect the first access behavior data of the first mobile terminal to the privacy computing center, and classify the access permission according to the first access behavior data using the preset access permission classification model to obtain the first access permission level; based on the blockchain network of the privacy computing center, link and chain the encrypted real-time product data according to the real-time product classification type; verify the signature of the second signature data, and decrypt the encrypted real-time demand data to obtain the decrypted real-time demand data; extract keywords according to the decrypted real-time demand data using the preset keyword extraction model to obtain the real-time demand product classification type, collect the second access behavior data of the second mobile terminal to the privacy computing center, and classify the access permission according to the second access behavior data using the preset access permission classification model to obtain the second access permission level; retrieve the corresponding encrypted target product data in the blockchain network according to the decrypted real-time demand data and the real-time demand product classification type; extract the third public key of the third mobile terminal as the target data provider in the restricted database according to the target data provider of the encrypted target product data, and decrypt the encrypted target product data according to the third public key to obtain the decrypted target product data; perform privacy computing according to the decrypted demand data and the decrypted target product data to generate transaction data, and link and chain the transaction data based on the blockchain network according to the real-time demand product classification type.
[0046] The present invention discloses a privacy computing data access control method and system based on blockchain, which combines blockchain technology with privacy computing to enhance the security of data access control through the immutability and decentralization characteristics of blockchain. At the same time, privacy computing is used to protect data content, realizing effective access control on the premise of ensuring data privacy. By generating keys and registering identities for mobile terminals, the uniqueness of each terminal and the security of data are ensured. Public-private key pairs and signature information are used to encrypt and sign data, ensuring the confidentiality and integrity of data during transmission. The access permission levels of mobile terminals are divided, and the corresponding allowed access product classification ranges are set, realizing refined management of different user roles. By constructing a product classification model, an access permission classification model, and a keyword extraction model, intelligent permission allocation, access control, and data query are realized, improving practicability. The encrypted real-time product data is linked and uploaded to the blockchain network, ensuring the historical traceability and immutability of data. Privacy computing is carried out in the blockchain network, avoiding the direct exposure of data content while ensuring the correctness and credibility of calculation results. Smart contracts are used to automatically execute processes such as signature verification, permission classification, and data decryption, reducing manual intervention, improving the automation and efficiency of the system, and enhancing the user experience. Secure data interaction and transactions between data providers and data requesters are realized, and the transparency and fairness of transactions are ensured through the blockchain network.
[0047] The present invention is not limited to the above optional embodiments, and any person can obtain other various forms of products under the inspiration of the present invention. The above specific embodiments should not be construed as limiting the protection scope of the present invention, and the protection scope of the present invention should be defined by the claims, and the specification can be used to interpret the claims.
Claims
1. A privacy computing data access control method based on blockchain, characterized by: The steps include: Based on the trusted institution, all mobile terminals are key-generated and identity-registered, and the public-private key pair and signature information of each mobile terminal are obtained. The private key and signature information in the public-private key pair are returned to the corresponding mobile terminal, and the public key in the public-private key pair is sent to the restricted database of the privacy computing center. Based on the privacy computing center, the access rights level of mobile terminals, the preset product classification types of product data, and the corresponding allowed product classification range for each access rights level are divided, and a product classification model, an access rights classification model, and a keyword extraction model are constructed; Based on the first mobile terminal as the data provider, real-time product data is collected, and the real-time product data is encrypted and signed according to the first private key and the first signature information in the first public-private key pair of the first mobile terminal, to obtain the encrypted real-time product data and the first signature data, and upload them to the privacy computing center; Based on the privacy computing center, the first signature data is signature verified. If the signature verification is passed, the product classification is performed according to the encrypted real-time product data using a preset product classification model to obtain the real-time product classification type and proceed to the next step. Otherwise, data access is terminated and waits for the next mobile terminal to access. Based on the privacy computing center, first access behavior data of the first mobile terminal to the privacy computing center is collected, and according to the first access behavior data, a preset access permission classification model is used to classify the access permission to obtain a first access permission level; If the first access permission level has data storage permission, and the real-time product classification type belongs to the first allowed access product classification range of the first access permission level, then based on the real-time product classification type, based on the blockchain network of the privacy computing center, the encrypted real-time product data is linked to the chain and waits for the next mobile terminal to access it; otherwise, data access is terminated and waits for the next mobile terminal to access it; Based on the second mobile terminal as the data demander, real-time demand data is collected, and the real-time demand data is encrypted and signed according to the second private key and the second signature information in the second public-private key pair of the second mobile terminal, to obtain the encrypted real-time demand data and the second signature data, and upload them to the privacy computing center; Based on the privacy computing center, the second signature data is signature verified. If the signature verification is passed, the encrypted real-time demand data is decrypted according to the second public key to obtain the decrypted real-time demand data and proceed to the next step. Otherwise, data access is terminated and the next mobile terminal is waited for access. Based on the privacy computing center, according to the decrypted real-time demand data, a preset keyword extraction model is used to extract keywords to obtain the real-time demand product classification type, and the second access behavior data of the second mobile terminal to the privacy computing center is collected. According to the second access behavior data, a preset access permission classification model is used to classify the access permission to obtain the second access permission level; If the second access permission level has data transaction permission, and the real-time demand product classification type belongs to the second allowed access product classification range of the second access permission level, then according to the decrypted real-time demand data and the real-time demand product classification type, the corresponding encrypted target product data is retrieved in the blockchain network, and the next step is entered; otherwise, the data access is terminated, and the next mobile terminal access is waited for; Based on the privacy computing center, according to the target data provider of the encrypted target product data, extract the third public key of the third mobile terminal as the target data provider in the restricted database, decrypt the encrypted target product data according to the third public key, and obtain the decrypted target product data; Based on the privacy computing center, privacy computing is performed according to the decrypted demand data and the decrypted target product data to generate transaction data. According to the real-time demand product classification type, the transaction data is linked to the chain based on the blockchain network.
2. According to claim 1, a privacy computing data access control method based on blockchain is characterized in that: The access permission levels include a senior access permission level, an intermediate access permission level, and a primary access permission level; The advanced access rights level includes data storage rights and data transaction rights, and the product classification range allowed to be accessed by the advanced access rights level includes all confidential and non-confidential preset product classification types; The intermediate access right level includes data storage right or data transaction right, and the product classification range allowed to be accessed by the intermediate access right level includes all non-confidential preset product classification types; The primary access permission level does not include data storage permission and data transaction permission, and the scope of product categories allowed to be accessed by the primary access permission level does not include any preset product category type.
3. According to a blockchain-based privacy computing data access control method according to claim 2, it is characterized by: Based on the privacy computing center, the access rights level of mobile terminals, the preset product classification types of product data, and the corresponding allowed product classification range for each access rights level are divided, and a product classification model, an access rights classification model, and a keyword extraction model are constructed, including the following steps: Based on the privacy computing center, the access rights of mobile terminals are divided into advanced access rights, intermediate access rights and primary access rights, and are divided into several different preset product classification types; Collect a number of encrypted historical product data, set a corresponding preset product classification type label for each encrypted historical product data, obtain a number of product classification samples, and build a product classification model based on the number of product classification samples using a deep learning algorithm; Collect a number of historical access behavior data, set a corresponding access permission level label for each historical access behavior data, obtain a number of access permission classification samples, and build an access permission classification model based on the number of access permission classification samples using a deep learning algorithm; Collect some historical demand data, perform named entity annotation for each historical demand data according to the preset product classification type, obtain some keyword extraction samples, and build a keyword extraction model based on some keyword extraction samples using natural language processing algorithm.
4. According to claim 3, a privacy computing data access control method based on blockchain is characterized in that: The product classification model is constructed based on the RF-BiSLTM algorithm.
5. According to a blockchain-based privacy computing data access control method according to claim 3, it is characterized in that: The access rights classification model is constructed based on the N-GAN-MLP algorithm.
6. According to a blockchain-based privacy computing data access control method according to claim 3, it is characterized in that: The keyword extraction model is built based on the BERT-BILSTM-Attention-CRF algorithm.
7. According to a blockchain-based privacy computing data access control method according to claim 1, it is characterized by: The blockchain network of the privacy computing center includes a calling interface, a smart contract, an IPFS system, and a blockchain composed of distributed connections of several nodes.
8. According to claim 7, a privacy computing data access control method based on blockchain is characterized in that: According to the real-time product classification type, the blockchain network based on the Privacy Computing Center uses the PBFT consensus algorithm to link the encrypted real-time product data to the chain.
9. A privacy computing data access control method based on blockchain according to claim 8, characterized in that: According to the real-time demand product classification type, based on the blockchain network, the PBFT consensus algorithm is used to link the transaction data to the chain.
10. A privacy computing data access control system based on blockchain, used to implement the privacy computing data access control method as described in any one of claims 1 to 9, characterized in that: The privacy computing data access control system includes a privacy computing center, a trusted institution and several mobile terminals. The privacy computing center and the trusted institution are respectively connected to the several mobile terminals in communication, and the privacy computing center is connected to the trusted institution in communication.
Citation Information
Patent Citations
Data acquisition method and device based on blockchain, computer equipment and storage medium
CN111885153A
Block chain digital asset security management method and system
CN119090431A
Data encryption storage method and system of integrated system
CN119182527A
Private data management method and system
CN119378010A
Multi-private-domain visitor portrait sharing and privacy protection routing method based on federal learning
CN119383014A