Industrial internet encryption method and system based on block chain evidence storage
By embedding dynamic device fingerprints and multi-dimensional feature information in the encrypted data, and combining dual encryption and joint hashing mechanisms, a strong binding relationship between encrypted data and blockchain evidence storage is established, and the problem of decoupling of evidence storage information and actual encrypted data in the existing technology is solved, which significantly improves the anti-tampering and anti-counterfeiting capabilities of the data, ensuring the integrity, authenticity and high credibility of the data.
Patent Information
- Application Number
- CN202510532087.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-25
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2045-04-25
AI Technical Summary
In the prior art, there is a hidden danger of decoupling evidence information from actual encrypted data in the process of industrial Internet encryption based on blockchain evidence, which makes it difficult to detect and tamper with data in time during transmission, storage and use, especially when an attacker has mastered some evidence or on-chain data interfaces.
By embedding dynamic device fingerprints and multi-dimensional feature information in the encrypted data, combining dual encryption and joint hashing mechanisms, a strong binding relationship between encrypted data and blockchain evidence storage is established. Block weighting and two-way reconstruction verification strategies are adopted to enhance the system's sensitivity and detection capabilities to small tampering and local forgery.
It significantly improves data anti-tampering and anti-counterfeiting capabilities, ensures the integrity, authenticity and high credibility of data in the industrial Internet, solves the security risks of decoupling evidence from data, and enhances the multi-dimensional security verification capabilities in complex industrial scenarios.
Smart Images

Figure CN120200830A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical fields of information security and blockchain, and particularly relates to an industrial Internet encryption method and system based on blockchain evidence storage. Background Art
[0002] Industrial Internet encryption based on blockchain evidence storage refers to, in the industrial Internet environment, through the integration of blockchain technology, realizing the security guarantee and trusted evidence storage of industrial data during the encrypted transmission and storage processes; its core idea is that when various devices, systems, and platforms in the industrial Internet conduct data interaction, they first use encryption algorithms (such as symmetric or asymmetric encryption) to encrypt the data to ensure the confidentiality and integrity of the data during the transmission and storage processes; at the same time, important feature information of the data (such as hash value, timestamp, signature) is used as evidence storage information to be uploaded to the blockchain, and with the help of the immutable and traceable characteristics of the blockchain, realizing the trusted record and anti-counterfeiting evidence storage of industrial data behaviors; through this method, it is possible to effectively prevent security risks such as tampering, forgery, and repudiation of industrial data during the transmission, storage, and use processes, and improve the data security and credibility in the industrial Internet environment;
[0003] The prior art has the following deficiencies: In the prior art, during the industrial Internet encryption process based on blockchain evidence storage, there is generally a hidden danger of "decoupling of blockchain evidence storage information and actual encrypted data", that is, the evidence storage information cannot form a strong binding relationship with the real encrypted data; in practical applications, the evidence storage usually only records the hash value or digest of the encrypted data, but if the encrypted data is replaced or tampered with during the storage, transmission, or system integration process, even if the hash value of the tampered data is recalculated and uploaded to the blockchain, it is difficult for the system to detect data anomalies in a timely manner, especially when the attacker masters some evidence storage or data interfaces on the chain, it is easier to implement such attacks; this decoupling problem will directly threaten the integrity and credibility of industrial data, and may lead to the tampering of key control instructions, production process parameters, or device configurations without being discovered, thus triggering production failures, equipment damage, or even major safety accidents; for industrial Internet systems with high security requirements, this problem has a very serious impact;
[0004] The above information disclosed in the background art section is only used to enhance the understanding of the background of the present disclosure, and therefore it may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention
[0005] The object of the present invention is to provide an industrial Internet encryption method and system based on blockchain evidence storage. By embedding dynamic device fingerprints and multi-dimensional feature information in encrypted data and combining double encryption and joint hashing mechanisms, a strong binding relationship between encrypted data and blockchain evidence storage is established, significantly improving the data anti-tampering and anti-counterfeiting capabilities. The use of block weighting and two-way reconstruction verification strategies enhances the system's sensitivity and detection ability to minor tampering and local forgery, and can effectively guarantee the integrity, authenticity and high credibility of data in the industrial Internet in a complex industrial environment, solving the security risk of decoupling between evidence storage and data in the prior art, so as to solve the problems in the above-mentioned background technology.
[0006] To achieve the above object, the present invention provides the following technical solutions: An industrial Internet encryption method based on blockchain evidence storage, comprising the following steps:
[0007] When the industrial Internet system generates industrial data to be encrypted, identification information strongly bound to the content is synchronously generated for the industrial data. The identification information includes, but is not limited to, data fingerprint information, device fingerprint information, generation timestamp, and data usage environment information;
[0008] The industrial data is encrypted to obtain encrypted data; at the same time, the identification information is embedded in the metadata of the encrypted data, so that the identification information is bound to the encrypted data one by one.
[0009] The encrypted data and the embedded identification information are jointly hashed to generate a joint hash value;
[0010] The joint hash value is stored on the blockchain through the blockchain evidence storage module to form a blockchain evidence storage record, and the integrity, generation device, and time consistency of the stored evidence data are verified through a smart contract;
[0011] During data transmission and storage, consistency verification is performed through the joint hash value on the chain and the joint hash value recalculated from the encrypted data and its identification information received by the receiving side to ensure that the received data has not been tampered with;
[0012] Before data use, verify whether the identification information in the encrypted data is consistent with the identification information bound in the blockchain evidence storage record, confirm that the binding relationship between the encrypted data and the evidence storage is complete and valid, and block data decryption and use if they are inconsistent.
[0013] Preferably, the data fingerprint information in the identification information is generated by combining multiple features, including multi-dimensional feature hashes of data content, hardware unique identification numbers of data generation devices, operating system version information, and high-precision timestamps at the generation moment. The data fingerprint generated by multi-dimensional feature fusion can uniquely represent the industrial data itself and its generation environment, improving the binding accuracy between data and evidence storage and preventing misjudgment of homologous data due to environmental differences.
[0014] Preferably, during the encryption of the encrypted data, a dual encryption mechanism is adopted. The first layer is symmetric encryption to ensure the data transmission efficiency, and the second layer is asymmetric encryption to encrypt the metadata part embedded with identification information to ensure the security of the data fingerprint and metadata in an open environment. Even if the encrypted part of the main data is cracked, the attacker cannot obtain the complete identification information, thus ensuring the consistency and data integrity of the evidence preservation.
[0015] Preferably, before the generation of the combined hash value, the encrypted data and its identification information are preprocessed through a Merkle tree structure to form a Merkle root node containing the data block hash and the identification information hash, and the hash value of this root node is used as the input for the subsequent combined hash, further enhancing the immutability of the hash result and the high-strength consistency verification ability, and effectively resisting the attack behavior of the identification information being tampered with alone.
[0016] Preferably, the combined hash value adopts an improved weighted multi-level hash generation algorithm, and the specific steps are as follows:
[0017] The encrypted data is divided into n data blocks, and the block hash value calculation expressions are calculated respectively as follows:
[0018] H i =SHA256(D i )
[0019] , where D i is the data block, representing the i-th data block after the encrypted data is divided. The purpose of dividing the block is to improve the refinement degree of the hash and prevent the tamperer from only tampering with a small amount of data to escape verification. H i is the hash value of the i-th data block, that is, the i-th block D i after the original encrypted data is divided is hashed using the SHA256 algorithm for the i-th data block to generate a unique hash value for the block;
[0020] The blocks can be reasonably divided according to factors such as data structure, function classification, information sensitivity, or data generation time, etc., to improve the fineness and flexibility of the hash process;
[0021] The identification information is divided into m feature items, and the feature item hash value calculation expressions are calculated respectively as follows:
[0022] F j =SHA256(I j )
[0023] , where I j is the identification information feature item, F j is the feature item hash value. Each identification feature item is individually hashed using SHA256 to generate a fixed-length feature hash, Fj represents the hash value of the j-th identification information feature item, that is, the result of separately calculating the hash of the j-th identification information feature I related to the data, and SHA256 is the hash function; j
[0024] The feature items at least include data fingerprints, device unique identifiers, operating system environment information, timestamp information, and security policy identifiers to ensure the comprehensiveness and accuracy of the evidence storage information;
[0025] Weighted aggregation is performed on all block hash values to obtain an intermediate hash, and the calculation expression is as follows:
[0026]
[0027] , where w i is the weighting coefficient of the i-th data block, H M is the weighted aggregation value of the block hash, and n is the total number of data blocks
[0028] The weights are assigned according to the importance, sensitivity, and core degree of the data in the industrial control process, and satisfy ∑w i = 1;
[0029] Weighted aggregation is performed on all feature hash values to obtain an identification hash, and the calculation expression is as follows:
[0030]
[0031] , where v j is the weighting coefficient of the j-th identification information feature item, m is the total number of identification information feature items, F M is the weighted aggregation value of the feature hash, which is the weighted comprehensive hash result of all feature items and can represent the integrity characteristics of the environment and source information of the entire encrypted data;
[0032] The weights are determined according to the intensity of the role of each feature in integrity verification and security protection, and satisfy ∑v j = 1;
[0033] The intermediate hash and the identification hash are jointly aggregated to generate a final joint hash, and the calculation expression is as follows:
[0034] J H = SHA512(H M ||F M )
[0035] , where J H is the final joint hash value, which is the core hash for data to be stored on the chain, and fully expresses the content integrity and environment binding of industrial data. SHA512 is the hash function;
[0036] The combined hash has the dual attributes of data block integrity and identity information consistency;
[0037] The combined hash value and the weighting coefficient w of the data block i and the weighting coefficient v of the identity information feature item j are jointly used as the evidence data to be uploaded to the chain. During subsequent verification, the hash generation process is completely restored, fundamentally enhancing the binding strength and immutability between the blockchain evidence and the data.
[0038] Preferably, during the evidence uploading and verification stages, the smart contract automatically performs consistency checks, including cross-verifying the generation timestamp, device fingerprint, and operating environment in the encrypted data with the on-chain environment information in the blockchain network to ensure that the encrypted data is generated in a trusted generation environment. If there are abnormal timestamps, mismatched device fingerprints, or conflicting environment information, the evidence uploading and subsequent data usage processes are directly aborted to ensure the authenticity of the blockchain evidence information and the credibility of the data.
[0039] Preferably, the data receiving end completes the consistency check through a dual-verification mechanism. The first verification is the integrity verification based on the combined hash value, and the second verification is the comparison verification of the identity information in the blockchain evidence and the identity information extracted from the decrypted data. Only when both verifications pass, the data is allowed to enter the decryption and subsequent business processing processes, thus effectively preventing the occurrence of "false evidence and real tampering" attacks in the industrial Internet scenario.
[0040] Preferably, when the receiving party discovers inconsistent verification, an exception alarm and event uploading process are immediately triggered, automatically recording the abnormal data packet, abnormal device ID, data receiving time, and the detailed reasons for verification failure, and realizing automatic evidence collection and alarm through the smart contract to ensure that data security events can be traced and responded quickly and accurately.
[0041] Preferably, the decryption verification process adopts a two-way reconstruction verification mechanism, and the specific steps are as follows:
[0042] Extract the data block D of the encrypted data from the received data i ' and the extraction process of the identity information feature item embedded in the metadata adopts parsing and parsing integrity detection to ensure that the receiving side can correctly obtain all verification information;
[0043] Calculate the block hash and identity feature hash in the received data respectively, and the calculation expressions are as follows:
[0044]
[0045] , where D i ' is the i-th data block extracted by the receiving side from the received encrypted data, and H i' is the block hash value calculated for the i-th received data block, F j ' is the feature hash value calculated for the j-th received identification information feature item;
[0046] Denoising and format standardization are performed on the extraction process to eliminate the impact of data format differences in different environments on the consistency of the hash result;
[0047] Based on the received hash values, calculate the block weighted hash and the identification weighted hash. The calculation expressions are as follows:
[0048]
[0049] , where H M ' is the receiving-side block weighted hash value, F M ' is the receiving-side feature weighted hash value;
[0050] The weighting factors are exactly the same as those on the original encryption side to ensure the equivalence of the verification process;
[0051] Jointly calculate the joint hash on the receiving side. The calculation expression is as follows:
[0052] j H ' = SHA512(H M '|F M )
[0053] , where J H ' is the joint hash value calculated by the receiving side (the party receiving the data), and is compared one by one with the joint hash value J H stored on the blockchain. If the verification results are consistent, it is initially determined that the data is complete and consistent;
[0054] Further compare the identification information feature items extracted on the receiving side with the original identification information stored on the blockchain item by item and level by level to ensure that the data environment information, generation time, and key information of the device fingerprint are exactly the same;
[0055] If both the joint hash and the identification information are consistent, it is determined that the data passes the verification, and subsequent decryption and business processing are allowed;
[0056] If there is an inconsistency in the joint hash, immediately interrupt the decryption process and trigger the abnormal alarm and security event handling process to ensure sufficient response and handling capabilities in the face of active attacks or data tampering.
[0057] Preferably, an industrial Internet encryption system based on blockchain evidence storage includes an identification information generation module, an encryption and identification binding module, a joint hash generation module, a blockchain evidence storage and consistency verification module, a joint hash consistency verification module, and a decryption and identification integrity verification module:
[0058] An identification information generation module. When the industrial Internet system generates industrial data to be encrypted, identification information strongly bound to the content is synchronously generated for the industrial data. The identification information includes, but is not limited to, data fingerprint information, device fingerprint information, generation timestamps, and data usage environment information;
[0059] An encryption and identification binding module that encrypts the industrial data to obtain encrypted data; at the same time, embeds the identification information into the metadata of the encrypted data, so that the identification information is bound to the encrypted data one by one;
[0060] A combined hash generation module that performs combined hash processing on the encrypted data and its embedded identification information to generate a combined hash value;
[0061] A blockchain evidence storage and consistency verification module that stores the combined hash value on the blockchain through the blockchain evidence storage module to form a blockchain evidence storage record, and verifies the integrity of the evidence data, the generating device, and the time consistency through a smart contract;
[0062] A combined hash consistency verification module that, during data transmission and storage, performs consistency verification through the combined hash value on the chain and the combined hash value recalculated from the encrypted data and its identification information received on the receiving side to ensure that the received data has not been tampered with;
[0063] A decryption and identification integrity verification module that, before data usage, verifies whether the identification information in the encrypted data is consistent with the identification information bound in the blockchain evidence storage record, confirms that the binding relationship between the encrypted data and the evidence storage is complete and valid, and blocks data decryption and usage if they are inconsistent.
[0064] In the above technical solution, the technical effects and advantages provided by the present invention are as follows:
[0065] The present invention embeds dynamic device fingerprints and multi-dimensional data feature information in the encrypted data, establishing a strong binding relationship between the encrypted data and the blockchain evidence storage, and can effectively solve the problem that the evidence storage information is decoupled from the actual encrypted data in the prior art. By integrating the hardware characteristics, environment information, timestamps, and data characteristics of the device and completing the embedding during the encryption stage, the high consistency between the data and its generation environment is ensured. Even if an attacker obtains the encrypted data, they cannot complete a valid forged evidence storage without knowing or being unable to forge the device fingerprint and environmental characteristics, significantly improving the anti-counterfeiting ability of the evidence storage, avoiding the security risk that forged data can still pass the evidence storage verification, and enhancing the credibility and security of data in the industrial Internet environment.
[0066] The present invention introduces a dual encryption and combined hashing mechanism during the encryption and evidence storage processes, which can effectively improve the system's detection and protection capabilities against data tampering and forgery. By using symmetric encryption and asymmetric encryption for industrial data content and identification information respectively, and combining the Merkle tree structure with weighted aggregation to generate a combined hash, the evidence storage information has higher attack resistance and verifiability. The receiving end ensures the integrity, consistency, and credibility of the data and identification information throughout their life cycles through dual decryption and reconstruction verification. Compared with traditional solutions that only rely on a single hash or simple evidence storage, the present invention can more precisely capture fine-grained tampering behaviors, including complex attacks such as local field tampering, instruction replay, and device environment forgery, and safeguard the business security of industrial control systems.
[0067] The present invention effectively improves the sensitivity to partial data tampering and the ability for multi-dimensional security verification in complex industrial scenarios by designing a block weighting and two-way reconstruction verification mechanism. The block weighting mechanism allows for the assignment of different weights to fields of different importance in industrial data and identification information, and can provide higher security guarantees for key fields such as control instructions, device fingerprints, and process parameters. At the same time, the two-way reconstruction mechanism ensures that the receiving end and the blockchain evidence storage end can completely reproduce the encryption, evidence storage, and hashing calculation processes during the verification process, eliminating the forgery risk under one-way hash verification. Even if an attacker makes minor modifications to only some low-sensitivity fields, it can be detected in a timely manner through the combined hash difference, ensuring the integrity, authenticity, and high credibility of the data in the face of complex attacks and abnormal situations. BRIEF DESCRIPTION OF THE DRAWINGS
[0068] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required to be used in the embodiments. Obviously, the drawings described below are only some embodiments recorded in the present invention, and those of ordinary skill in the art can also obtain other drawings based on these drawings.
[0069] Figure 1 It is a flowchart of a method for encrypting an industrial Internet based on blockchain evidence storage according to the present invention.
[0070] Figure 2 It is a schematic diagram of the modules of an industrial Internet encryption system based on blockchain evidence storage according to the present invention.
[0071] Figure 3 It is a system mind map of an industrial Internet encryption system based on blockchain evidence storage according to the present invention.
[0072] Figure 4 It is a method mind map of a method for encrypting an industrial Internet based on blockchain evidence storage according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0073] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these example embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the concept of the example embodiments to those skilled in the art.
[0074] The present invention provides an industrial Internet encryption method based on blockchain evidence storage as Figure 1 shown, including the following steps:
[0075] When the industrial Internet system generates industrial data to be encrypted, identification information strongly bound to the content is synchronously generated for the industrial data. The identification information includes, but is not limited to, data fingerprint information, device fingerprint information, generation timestamp, and data usage environment information;
[0076] The data fingerprint information in the identification information is generated by combining multiple features, including multi-dimensional feature hashes of the data content, the hardware unique identification number of the data generation device, the operating system version information, and the high-precision timestamp at the generation moment. The data fingerprint generated through multi-dimensional feature fusion can uniquely represent the industrial data itself and its generation environment, improving the binding accuracy between the data and the evidence storage and preventing misjudgment of homologous data due to environmental differences.
[0077] The industrial data is encrypted to obtain encrypted data; at the same time, the identification information is embedded in the metadata of the encrypted data, so that the identification information is bound to the encrypted data one-to-one;
[0078] During the encryption process of the encrypted data, a dual encryption mechanism is adopted. The first layer is symmetric encryption to ensure data transmission efficiency, and the second layer is asymmetric encryption to encrypt the metadata part embedded with the identification information to ensure the security of the data fingerprint and metadata in an open environment. Even if the encrypted part of the main data is cracked, the attacker cannot obtain the complete identification information, thus ensuring the consistency of the evidence storage and data integrity.
[0079] The encrypted data and the embedded identification information are jointly hashed to generate a joint hash value;
[0080] Before the generation of the joint hash value, the encrypted data and its identification information are preprocessed through a Merkle tree structure to form a Merkle root node containing the data block hash and the identification information hash, and the root node hash value is used as the input for the subsequent joint hash, further improving the immutability of the hash result and the high-strength consistency verification ability, and effectively resisting the attack behavior of the identification information being tampered with alone.
[0081] The joint hash value is generated by an improved weighted multi-level hash generation algorithm, and the specific steps are as follows:
[0082] Divide the encrypted data into n data chunks, and calculate the chunk hash value. The calculation expressions are as follows:
[0083] H i = SHA256(D i )
[0084] , where D i is a data chunk, representing the i-th data chunk after the encrypted data is divided. The purpose of chunking is to improve the refinement of the hash and prevent tamperers from escaping verification by only tampering with a small amount of data. H i is the hash value of the i-th data chunk, that is, the i-th chunk D i after the original encrypted data is divided is hashed using the SHA256 algorithm to generate a unique hash value for the chunk;
[0085] The chunks can be reasonably divided according to factors such as data structure, function classification, information sensitivity, or data generation time to improve the fineness and flexibility of the hashing process;
[0086] Divide the identification information into m feature items, and calculate the feature item hash value. The calculation expressions are as follows:
[0087] F j = SHA256(I j )
[0088] , where I j is an identification information feature item, and F j is the feature item hash value. Each identification feature item is individually hashed using SHA256 to generate a feature hash of a fixed length. F j represents the hash value of the j-th identification information feature item, that is, the result of individually hashing the j-th identification information feature I j related to the data, and SHA256 is a hashing function;
[0089] The feature items at least include data fingerprints, device unique identifiers, operating system environment information, timestamp information, and security policy identifiers to ensure the comprehensiveness and accuracy of the evidence information;
[0090] Perform weighted aggregation on all chunk hash values to obtain an intermediate hash. The calculation expression is as follows:
[0091]
[0092] , where w i is the weighting coefficient of the i-th data chunk, H M is the weighted aggregation value of the chunk hash, and n is the total number of data chunks
[0093] Weights are assigned according to the importance, sensitivity, and core degree of the data in the industrial control process, and satisfy ∑w i = 1;
[0094] All feature hash values are weighted and aggregated to obtain an identification hash, and the calculation expression is as follows:
[0095]
[0096] , where v j is the weighting coefficient of the j-th identification information feature item, m is the total number of identification information feature items, and F M is the weighted aggregation value of the feature hash, which is the weighted comprehensive hash result of all feature items and can represent the integrity features of the environment and source information of the entire encrypted data;
[0097] Weights are determined according to the strength of the role of each feature in integrity verification and security protection, and satisfy ∑v j = 1;
[0098] The intermediate hash and the identification hash are jointly aggregated to generate a final joint hash, and the calculation expression is as follows:
[0099] J H = SHA512(H M ‖F M )
[0100] , where J H is the final joint hash value, which is used as the core hash for data on-chain storage and evidence, and fully expresses the content integrity and environment binding of industrial data. SHA512 is a hash function;
[0101] The joint hash has dual attributes of data block integrity and identification information consistency;
[0102] The joint hash value, the weighting coefficient w i of the data block, and the weighting coefficient v j of the identification information feature item are jointly used as the evidence data for on-chain storage. During subsequent verification, the hash generation process is fully restored, fundamentally enhancing the binding strength and immutability between the blockchain evidence and the data.
[0103] The joint hash value is stored on-chain through the blockchain evidence module to form a blockchain evidence record, and the integrity, generation device, and time consistency of the evidence data are verified through a smart contract;
[0104] During the process of depositing evidence on the blockchain and verification, the smart contract automatically performs consistency checks, including cross-verifying the generation timestamp, device fingerprint, and operating environment in the encrypted data with the on-chain environment information in the blockchain network to ensure that the encrypted data is generated in a trusted environment. If there are anomalies in the timestamp, mismatches in the device fingerprint, or contradictions in the environment information, the process of depositing evidence and subsequent data usage will be directly aborted to ensure the authenticity of the blockchain evidence information and the credibility of the data.
[0105] During the data transmission and storage process, consistency verification is carried out by comparing the on-chain combined hash value with the combined hash value recalculated from the encrypted data and its identification information received on the receiving side to ensure that the received data has not been tampered with.
[0106] The data receiving end completes the consistency check through a dual-verification mechanism. The first verification is the integrity verification based on the combined hash value, and the second verification is the comparison verification based on the identification information in the blockchain-based evidence and the identification information extracted from the decrypted data. Only when both verifications pass, the data is allowed to enter the decryption and subsequent business processing processes, thus effectively preventing the occurrence of "false evidence and true tampering" attacks in the industrial Internet scenario.
[0107] Before using the data, verify whether the identification information in the encrypted data is consistent with the identification information bound in the blockchain evidence record to confirm that the binding relationship between the encrypted data and the evidence is complete and valid. If they are inconsistent, block the data decryption and usage.
[0108] When the receiving party discovers an inconsistency in the verification, an exception alarm and event on-chain process are immediately triggered, automatically recording the abnormal data packet, abnormal device ID, data reception time, and the detailed reasons for the verification failure. Automatic evidence collection and alarm are achieved through the smart contract to ensure that data security incidents can be traced and responded to quickly and accurately.
[0109] The decryption verification process adopts a two-way reconstruction verification mechanism, and the specific steps are as follows:
[0110] Extract the data block D of the encrypted data from the received data i ' and the process of extracting the identification information feature items embedded in the metadata adopts parsing and parsing integrity detection to ensure that the receiving side can correctly obtain all verification information;
[0111] Calculate the block hash and identification feature hash in the received data respectively, and the calculation expressions are as follows:
[0112]
[0113] , where D i ' is the i-th data block extracted by the receiving side from the received encrypted data, and H i ' is the block hash value calculated for the i-th received data block, and Fj is the feature hash value calculated for the j-th received identification information feature item;
[0114] Denoising and format standardization are performed on the extraction process to eliminate the influence of data format differences in different environments on the consistency of the hash result;
[0115] Based on the received hash value, calculate the block weighted hash and the identification weighted hash. The calculation expressions are as follows:
[0116]
[0117] , where H M ' is the received-side block weighted hash value, and F M ' is the received-side feature weighted hash value;
[0118] The weighting factors are exactly the same as those on the original encryption side to ensure the equivalence of the verification process;
[0119] Jointly calculate the joint hash on the receiving side. The calculation expression is as follows:
[0120] J H ' = SHA512(H M '|F M )
[0121] , where J H ' is the joint hash value calculated on the receiving side (the party receiving the data), and it is compared one by one with the joint hash value J H stored on the blockchain. If the verification results are consistent, it is initially determined that the data is complete and consistent;
[0122] Further compare the identification information feature items extracted on the receiving side with the original identification information stored on the blockchain item by item and level by level to ensure that the data environment information, generation time, and key information of the device fingerprint are exactly the same;
[0123] If both the joint hash and the identification information are consistent, it is determined that the data passes the verification, and subsequent decryption and business processing are allowed;
[0124] If there is an inconsistency in the joint hash, the decryption process is immediately interrupted, and an exception alarm and a security event handling process are triggered to ensure sufficient response and handling capabilities in the face of active attacks or data tampering.
[0125] Embodiment 1: In this embodiment, in view of the characteristics of wide distribution of devices, complex environment, and diverse data flow in the industrial Internet environment, a deposit binding mechanism based on dynamic device fingerprints and multi-dimensional data features is designed. In the stage of generating encrypted data, the industrial Internet system first automatically collects the dynamic fingerprint information of the device. The dynamic fingerprint information not only includes the fixed physical information of the device, such as the hardware serial number, MAC address, motherboard serial number, firmware version of the device, but also further combines the operating system version, built-in security module version, network access environment (such as IP address, access gateway ID), current production environment code (such as production workshop number, production line ID), and high-precision timestamp and other dynamic parameters when the data is generated. These dynamic information can reflect the subtle changes of the device at different times and in different environments, effectively avoiding the problem that traditional static fingerprints are easily counterfeited.
[0126] After the fingerprint information is collected, the system extracts the content features of the industrial data to be encrypted according to the business type. The content feature extraction is not only based on the hash calculation of the whole data (such as SHA-256), but also can calculate the local hash in blocks for the key fields in the industrial data (such as control instructions, production parameters, process configurations) to obtain a more granular multi-dimensional feature hash set. Subsequently, the system forms identification information by combining the dynamic device fingerprint and the data feature hash set, and embeds the identification information into the metadata structure of the encrypted data. For example, the identification information is directly used as the extended header of the encrypted data, or embedded in the specific reserved fields in the encrypted data to form a one-to-one binding between the encrypted data and the identification information.
[0127] Then, the system adopts a joint hash mechanism to perform multi-layer hashing on the encrypted data content and the identification information respectively to generate a joint hash value. This joint hash value is stored on the chain through a dedicated blockchain network, and the smart contract in the blockchain network automatically verifies the hash structure, timestamp consistency, and the authenticity of the device ID to ensure that the deposit information is true and credible. The on-chain deposit record completely stores the joint hash value, device fingerprint summary, timestamp, and operation environment summary information.
[0128] In the data reception and subsequent use stage, the receiving device or system extracts the embedded identification information and data content in the received encrypted data, recalculates the joint hash value and compares it with the deposit value in the blockchain to ensure that the data has not been tampered with from generation to reception. At the same time, the receiving party can also judge whether the data comes from the expected trusted device and trusted environment based on the device fingerprint, timestamp, and environment information recorded in the blockchain deposit. If the verification fails, the system immediately blocks the data decryption and service invocation to prevent the forged or tampered data from being executed incorrectly.
[0129] Through this solution, the strong binding ability between encrypted data and blockchain evidence storage in the industrial Internet environment can be significantly enhanced, effectively solving the problem of decoupling between data and evidence storage in the existing technology, and ensuring the security of data in multiple dimensions such as integrity, authenticity, and environmental consistency. At the same time, due to the use of dynamic device fingerprints, even if an attacker successfully copies the static features of a certain device, it is impossible to forge the same dynamic fingerprint information at different times and in different environments, thus further enhancing the system's ability to resist forgery.
[0130] Embodiment 2: In view of the characteristics of high value, high sensitivity and high risk of data in the industrial Internet environment, this embodiment designs an anti-counterfeiting mechanism based on double encryption and joint hashing, focusing on solving risks such as man-in-the-middle attacks, evidence storage forgery, and data tampering that industrial data may face during transmission and storage. In the system design of this solution, the security levels of "data content" and "data fingerprint information" are clearly distinguished, and separate encryption and verification mechanisms are adopted for different types of information to establish a more stable encryption and evidence storage system.
[0131] During specific implementation, the industrial Internet system first collects the fingerprint information and data characteristics of the device and forms complete identification information. The identification information covers the unique identifier of the device (such as device ID, manufacturer code), the current operating environment information (such as network environment, production area ID), the data generation time, the system security policy version, and other contents. After generating the identification information, the system performs double encryption operations: the first encryption uses a symmetric encryption algorithm (such as AES) to encrypt the industrial data in full volume in a high-speed and efficient manner to ensure the encryption performance of the data during network transmission; the second encryption uses an asymmetric encryption algorithm (such as RSA or ECC) to encrypt the identification information and jointly encapsulate it with the data after the first encryption to form the final encrypted data packet.
[0132] During the data evidence storage process, the system extracts the jointly encapsulated encrypted data and identification information, and performs multi-level hashing operations on the data blocks and identification information blocks using the Merkle tree structure. By constructing a hierarchical Merkle tree, the fine-grained information of the data can be effectively recorded in the evidence storage, enhancing the tampering detection ability and preventing attackers from bypassing the overall hash verification by modifying local data. Finally, the system uses the Merkle root hash as the joint hash value and uploads it to the blockchain for evidence storage through the evidence storage module of the blockchain.
[0133] At the data receiving end, the receiving party system first parses the encrypted data packet, sequentially completes symmetric decryption to obtain the original data and asymmetric decryption to extract the identification information, and reconstructs the Merkle tree to calculate the root hash, and compares it with the joint hash value stored in the blockchain for consistency. If the verification passes, it means that the data has not been tampered with from generation, transmission, storage to reception. If the verification fails, the system immediately blocks the use of the data and alarms.
[0134] Through a dual encryption mechanism, this embodiment solves the security problem in the prior art that an attacker can cause the evidence storage to be valid but the data to be abnormal by forging or replacing encrypted data. At the same time, by using the hierarchical hashing mechanism of the Merkle tree, the fineness and security of the evidence storage are improved, ensuring a strong binding relationship between the data and the evidence storage.
[0135] Embodiment 3: When solving the problem of the decoupling of industrial Internet data and blockchain evidence storage, this embodiment innovatively adopts a block weighting and two-way reconstruction mechanism. The industrial data and its identification information are processed in blocks, and a combined hash is generated through weight control. At the data receiving end, two-way reconstruction verification is carried out, effectively improving the system's ability to guarantee data integrity, consistency, and environmental credibility.
[0136] Specifically, in the stage of generating encrypted data, the system first divides the industrial data to be encrypted according to the characteristics of the data content. For example, the control instruction area, configuration parameter area, and status monitoring data area are divided into different data blocks. At the same time, the collected identification information is also split into multiple items, including device fingerprints, timestamps, environmental information, security policy versions, etc., and independent feature hashes are generated respectively. The system assigns preset weights to each data block and feature hash, and the weights can be set based on the actual security requirements of industrial applications. For example, higher weights can be given to the control instruction area and device fingerprint items to enhance their influence in the combined hash.
[0137] Subsequently, the system performs weighted aggregation on the data block hash and the identification feature hash respectively to obtain the block weighted hash value and the feature weighted hash value, and then generates a combined hash value through a hash fusion function as the final evidence storage data to be uploaded to the chain. When storing evidence, the system synchronously uploads information such as the block division scheme, the weight parameters of each block and feature, the combined hash value, the device fingerprint summary, and the timestamp to the chain.
[0138] At the data receiving end, after receiving the encrypted data, the system first extracts the data blocks and identification features according to the same block and weight rules, calculates the block weighted hash and the feature weighted hash respectively, and reconstructs the combined hash value at the receiving end. The receiving end system then compares it with the one in the blockchain evidence storage. If the two are exactly the same, it means that the data has not been tampered with during the entire life cycle from generation to reception. At the same time, the receiving end also compares each item of the extracted identification information with the identification features in the evidence storage one by one to ensure that the identification information has not been forged or replaced. If the combined hash value does not match or the identification information is inconsistent, the system immediately aborts the decryption and business processes and automatically reports the anomaly.
[0139] Through the block weighting mechanism, the sensitivity of the system to partial tampering behavior is effectively improved. Even if the attacker only makes minor tampering to the low-weight blocks or identification information in the data, it will be detected due to the inconsistent combined hash value caused by weight aggregation. At the same time, the two-way reconstruction verification mechanism ensures the complete alignment of the data on the evidence chain and the received data during the verification process, eliminating the defect that common one-way evidence storage is easily forged, and significantly improving the security and credibility of industrial Internet encrypted evidence storage.
[0140] The present invention embeds dynamic device fingerprints and multi-dimensional data feature information in encrypted data, establishing a strong binding relationship between the encrypted data and blockchain evidence storage, and can effectively solve the problem of decoupling between the evidence storage information and the actual encrypted data in the prior art. By integrating the hardware features, environmental information, time stamps of the device with the data features and completing the embedding during the encryption stage, the high consistency between the data and its generation environment is ensured. Even if the attacker obtains the encrypted data, without knowing or being unable to forge the device fingerprint and environmental features, it is impossible to complete the effective evidence storage of forgery, significantly improving the anti-counterfeiting ability of the evidence storage, avoiding the security risk that the data can still pass the evidence storage verification after being forged, and enhancing the credibility and security of the data in the industrial Internet environment.
[0141] The present invention introduces a dual encryption and combined hash mechanism in the encryption and evidence storage processes, which can effectively improve the detection and protection capabilities of the system against data tampering and forgery. By using symmetric encryption and asymmetric encryption for the industrial data content and identification information respectively, and combining the Merkle tree structure with weighted aggregation to generate a combined hash, the evidence storage information has higher anti-attack ability and verifiability. The receiving end ensures the integrity, consistency and credibility of the data and identification information during the life cycle through dual decryption and reconstruction verification. Compared with the traditional scheme that only relies on a single hash or simple evidence storage, the present invention can capture fine-grained tampering behaviors more precisely, including complex attacks such as local field tampering, instruction replay, device environment forgery, etc., to ensure the business security of the industrial control system.
[0142] The present invention effectively improves the sensitivity to partial data tampering and the ability of multi-dimensional security verification in complex industrial scenarios by designing a block weighting and two-way reconstruction verification mechanism. The block weighting mechanism allows for the assignment of different weights to fields of different importance in industrial data and identification information, and can give higher security guarantees to key fields such as control instructions, device fingerprints, and process parameters. At the same time, the two-way reconstruction mechanism ensures that the receiving end and the blockchain evidence storage end can completely reproduce the encryption, evidence storage, and hash calculation processes during the verification process, eliminating the forgery risk under one-way hash verification. Even if the attacker only makes minor modifications to some low-sensitivity fields, it can be detected in time through the combined hash difference, ensuring that the system can still guarantee the integrity, authenticity and high credibility of the data in the face of complex attacks and abnormal situations.
[0143] The present invention provides an industrial Internet encryption system based on blockchain evidence storage as shown in Figure 2 Figure 1, including an identification information generation module, an encryption and identification binding module, a combined hash generation module, a blockchain evidence storage and consistency verification module, a combined hash consistency verification module, and a decryption and identification integrity verification module:
[0144] The identification information generation module: When the industrial Internet system generates industrial data to be encrypted, identification information strongly bound to the content is synchronously generated for the industrial data. The identification information includes, but is not limited to, data fingerprint information, device fingerprint information, generation timestamp, and data usage environment information;
[0145] The encryption and identification binding module: Encrypts the industrial data to obtain encrypted data; at the same time, embeds the identification information into the metadata of the encrypted data, so that the identification information is bound to the encrypted data one by one;
[0146] The combined hash generation module: Performs combined hash processing on the encrypted data and its embedded identification information to generate a combined hash value;
[0147] The blockchain evidence storage and consistency verification module: Uploads the combined hash value to the blockchain for evidence storage through the blockchain evidence storage module to form a blockchain evidence storage record, and verifies the integrity, generation device, and time consistency of the stored data through a smart contract;
[0148] The combined hash consistency verification module: During the data transmission and storage process, performs consistency verification through the combined hash value on the chain and the combined hash value recalculated from the encrypted data and its identification information received on the receiving side to ensure that the received data has not been tampered with;
[0149] The decryption and identification integrity verification module: Before using the data, verifies whether the identification information in the encrypted data is consistent with the identification information bound in the blockchain evidence storage record, confirms that the binding relationship between the encrypted data and the evidence storage is complete and valid, and blocks data decryption and use if they are inconsistent.
[0150] An industrial Internet encryption method based on blockchain evidence storage provided by an embodiment of the present invention is implemented through the above-mentioned industrial Internet encryption system based on blockchain evidence storage. The specific methods and processes of an industrial Internet encryption system based on blockchain evidence storage are detailed in the embodiments of the above-mentioned industrial Internet encryption method based on blockchain evidence storage, and will not be elaborated here.
[0151] As described above, it is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered within the protection scope of this application. Therefore, the protection scope of this application shall be subject to the protection scope of the claims described.
Claims
1. An industrial Internet encryption method based on blockchain evidence storage, characterized in that: The following steps are involved: When the industrial Internet system generates industrial data to be encrypted, it will simultaneously generate identification information that is strongly bound to the content for the industrial data; The industrial data is encrypted to obtain encrypted data; at the same time, the identification information is embedded in the metadata of the encrypted data so that the identification information and the encrypted data are bound one by one; Performing joint hashing on the encrypted data and the identification information embedded therein to generate a joint hash value; The joint hash value is stored on the blockchain through the blockchain evidence module to form a blockchain evidence record, and the integrity of the evidence data, the generation device, and the time consistency are verified through the smart contract; During data transmission and storage, consistency verification is performed between the on-chain joint hash value and the joint hash value recalculated from the encrypted data and its identification information received by the receiving side to ensure that the received data has not been tampered with; Before using the data, verify whether the identification information in the encrypted data is consistent with the identification information bound in the blockchain evidence record, and confirm that the binding relationship between the encrypted data and the evidence is complete and valid. If there is any inconsistency, block data decryption and use.
2. According to the industrial Internet encryption method based on blockchain evidence storage according to claim 1, it is characterized in that: The data fingerprint information in the identification information is generated by a combination of multiple features, including a multi-dimensional feature hash of the data content, the hardware unique identification number of the data generating device, the operating system version information, and a high-precision timestamp of the generation time. The data fingerprint generated by the fusion of multi-dimensional features can uniquely characterize the industrial data itself and its generation environment, improve the binding accuracy of data and evidence, and prevent misjudgment of homologous data due to environmental differences.
3. According to the industrial Internet encryption method based on blockchain evidence storage according to claim 2, it is characterized in that: During the encryption process of encrypted data, a double encryption mechanism is adopted. The first layer is symmetric encryption to ensure data transmission efficiency, and the second layer is asymmetric encryption to encrypt the metadata part of the embedded identification information, ensuring the security of data fingerprints and metadata in an open environment. Even if the encrypted part of the main data is cracked, the attacker cannot obtain the complete identification information, thereby ensuring the consistency of evidence and data integrity.
4. According to the industrial Internet encryption method based on blockchain evidence storage according to claim 3, it is characterized in that: Before the joint hash value is generated, the encrypted data and its identification information are preprocessed through the Merkle tree structure to form a Merkle tree root node that contains the data block hash and the identification information hash. The root node hash value is used as the input for subsequent joint hashes, further improving the immutability of the hash result and the high-intensity consistency verification capability, and effectively resisting attacks in which the identification information is tampered with alone.
5. According to the industrial Internet encryption method based on blockchain evidence storage according to claim 4, it is characterized in that: The joint hash value adopts an improved weighted multi-level hash generation algorithm. The specific steps are as follows: Divide the encrypted data into n data blocks and calculate the hash value of each block; Divide the identification information into m feature items, and calculate the hash values of the feature items respectively; The feature items shall at least include data fingerprint, device unique identifier, operating system environment information, timestamp information and security policy identifier to ensure the comprehensiveness and accuracy of the evidence information; Perform weighted aggregation on all block hash values to obtain the intermediate hash; Weights are assigned based on the importance, sensitivity, and coreness of the data in the industrial control process; Perform weighted aggregation on all feature hash values to obtain the identification hash; The weight is determined based on the strength of each feature in integrity verification and security protection; The intermediate hash and the identity hash are aggregated to generate the final joint hash; Joint hashing has the dual properties of data block integrity and identification information consistency; The joint hash value, the weighted coefficient of the data block, and the weighted coefficient of the identification information feature item are uploaded to the chain as evidence data, and the hash generation process is fully restored during subsequent verification.
6. The industrial Internet encryption method based on blockchain evidence storage according to claim 5 is characterized in that: During the evidence storage and verification stage, the smart contract automatically performs consistency checks, including cross-verification of the generation timestamp, device fingerprint, operating environment in the encrypted data and the on-chain environmental information in the blockchain network, to ensure that the encrypted data is generated in a trusted generation environment. If there is a timestamp anomaly, device fingerprint mismatch, or environmental information contradiction, the evidence storage and subsequent data usage process will be directly terminated to ensure the authenticity of the blockchain evidence information and the credibility of the data.
7. The industrial Internet encryption method based on blockchain evidence storage according to claim 6 is characterized in that: The data receiving end completes the consistency check through a double verification mechanism. The first verification is the integrity verification based on the joint hash value, and the second verification is the comparison verification based on the identification information of the blockchain memory certificate and the identification information extracted from the decrypted data. Only when both verifications are passed, the data is allowed to enter the decryption and subsequent business processing flow, thereby effectively preventing the occurrence of "fake evidence and real tampering" attacks in the industrial Internet scenario.
8. The industrial Internet encryption method based on blockchain evidence storage according to claim 7 is characterized in that: When the recipient finds verification inconsistencies, it immediately triggers an abnormal alarm and event chain process, automatically records abnormal data packets, abnormal device IDs, data reception time and detailed reasons for verification failures, and implements automatic evidence collection and alarms through smart contracts to ensure that data security incidents can be quickly and accurately traced and responded to.
9. The industrial Internet encryption method based on blockchain evidence storage according to claim 8 is characterized in that: The decryption verification process adopts a two-way reconstruction verification mechanism. The specific steps are as follows: Extract the encrypted data blocks and the identification information feature items embedded in the metadata from the received data. The extraction process uses parsing and parsing integrity detection to ensure that the receiving side can correctly obtain all the verification information. Calculate the block hash and identification feature hash in the received data respectively; De-noising and format standardization are performed on the extraction process to eliminate the impact of data format differences in different environments on the consistency of hash results; Based on the received hash value, calculate the block weighted hash and the identity weighted hash; The weighting factor remains completely consistent with the original encryption side to ensure the equivalence of the verification process; Jointly calculate the joint hash on the receiving side; The identification information feature items extracted by the receiving side are further compared with the original identification information stored in the blockchain item by item and level by level to ensure that the data environment information, generation time, and key information of the device fingerprint are completely consistent; If the joint hash and identification information are consistent, the data is determined to have passed the verification, and subsequent decryption and business processing are allowed; If there is any inconsistency in the joint hash, the decryption process will be interrupted immediately, triggering an abnormal alarm and security incident handling process.
10. An industrial Internet encryption system based on blockchain evidence storage, used to implement an industrial Internet encryption method based on blockchain evidence storage as described in any one of claims 1 to 9 above, characterized in that: It includes identification information generation module, encryption and identification binding module, joint hash generation module, blockchain evidence storage and consistency verification module, joint hash consistency verification module and decryption and identification integrity verification module: An identification information generation module: when the industrial Internet system generates industrial data to be encrypted, it will synchronously generate identification information that is strongly bound to the content for the industrial data. The identification information includes but is not limited to data fingerprint information, device fingerprint information, generation timestamp, and data usage environment information; The encryption and identification binding module encrypts the industrial data to obtain encrypted data; at the same time, the identification information is embedded in the metadata of the encrypted data, so that the identification information and the encrypted data are bound one by one; A joint hash generation module performs joint hash processing on the encrypted data and its embedded identification information to generate a joint hash value; The blockchain evidence storage and consistency verification module stores the joint hash value on the blockchain through the blockchain evidence storage module to form a blockchain evidence record, and verifies the integrity of the evidence data, the generation device, and the time consistency through the smart contract; The joint hash consistency verification module performs consistency verification on the joint hash value on the chain and the joint hash value recalculated from the encrypted data and its identification information received by the receiving side during the data transmission and storage process to ensure that the received data has not been tampered with; The decryption and identification integrity verification module verifies whether the identification information in the encrypted data is consistent with the identification information bound in the blockchain evidence record before the data is used, and confirms that the binding relationship between the encrypted data and the evidence is complete and valid. If there is any inconsistency, the data decryption and use will be blocked.
Citation Information
Patent Citations
Block chain-based anti-counterfeiting two-dimensional code generation and verification system and method
CN114595476A
Food detection data processing method based on block chain
CN118916369A
Industrial data asset management method and system based on block chain technology
CN119316199A
Intelligent integrated monitoring and analysis method based on multi-dimensional data fusion
CN119357999A
Breeding product tracing method and system based on block chain
CN119476716A
Cited By
Video stream dynamic fragment encryption and block chain evidence storage method
CN120416543A
Artificial intelligence model traceability and tamper-proofing method and system based on block chain enhancement
CN120512320A
Data processing method and system and electronic equipment
CN121309014A
Data storage evidence preservation processing method and system based on distributed storage technology
CN122348814A