Data security protection method and system under support of block chain

By using technical means such as data migration contracts, Sharding technology, HSM modules and QUIC protocols during the blockchain data migration process, the problem that traditional technologies are difficult to ensure the security of blockchain data migration is solved, and efficient and secure cross-blockchain data migration and storage are achieved.

CN120217416APending Publication Date: 2025-06-27LINGSHU TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510354244.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-25
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

During the blockchain data migration process, traditional encryption methods and transmission protocols are difficult to ensure the security and integrity of data between different blockchains, resulting in an increase in the risk of data leakage or loss, which cannot meet the needs of large-scale data security migration.

Method used

By determining the first and second blockchains based on the data migration contract, using Sharding technology to fragment the data, generating keys with the help of the HSM module for encryption, building a protective migration channel through the QUIC protocol, and establishing an exchange mark and key derivation mechanism during data exchange, setting the validity time of the key.

Benefits of technology

It realizes security and integrity in the cross-blockchain data migration process, improves data migration efficiency, and makes data interactions between blockchains more secure and reliable.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217416A_ABST
    Figure CN120217416A_ABST
Patent Text Reader

Abstract

The invention discloses a data security protection method and system under the support of a block chain, and relates to the technical field of data security and privacy protection, and the method comprises the steps: determining a first block chain and a second block chain based on a data migration contract; outputting the fragmented migration data packet; obtaining a fragmented encrypted data packet; and decoding and storing according to the decryption sub-key. The cross-block-chain data migration method and device solve the technical problem that in the prior art, in the cross-block-chain data migration process, the safety, integrity and migration efficiency of the data are insufficient, and the technical effect of safe migration and reliable storage of the cross-block-chain data is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security and privacy protection, and particularly to the technical field of data security protection methods and systems supported by blockchain. Background Art

[0002] In the scenario of blockchain data migration, data security is of crucial importance. Currently, security protection technologies in the data migration process are widely applied. Traditional data migration security protection mostly relies on simple encryption and conventional transmission protocols. These methods can play a certain role when the data volume is small and the network environment is stable.

[0003] However, with the development of blockchain technology, the scale and complexity of data migration have been continuously increasing, and many problems have emerged in traditional technologies. When migrating data across blockchains, traditional encryption methods are difficult to ensure the security of data transmission between different chains, and conventional transmission protocols are also unable to cope with complex network environments, resulting in data being easily leaked or lost, and unable to meet the requirements of large-scale blockchain data security migration and strict protection of data integrity and confidentiality. Summary of the Invention

[0004] This application solves the technical problems of insufficient security, integrity, and migration efficiency of data in the prior art during cross-blockchain data migration. This application determines the first and second blockchains based on a data migration contract, uses the Sharding technology to fragment and cut the migration storage data in the first blockchain, generates keys to encrypt the data with the help of the HSM module, constructs a protected migration channel to migrate the data through the QUIC protocol, finally decodes and stores it in the second blockchain, establishes an exchange tag during data exchange and uses it for key derivation, and also sets the key validity period, thereby ensuring the security and integrity during cross-blockchain data migration, improving the data migration efficiency, and making the data interaction between blockchains more secure and reliable.

[0005] In view of the above technical problems, this application proposes a technical solution for a data security protection method and system supported by blockchain.

[0006] In a first aspect, this application provides a data security protection method supported by blockchain, wherein the method includes:

[0007] Determine a first blockchain and a second blockchain based on a data migration contract, where the first blockchain is the blockchain from which data is migrated out in the data migration contract, and the second blockchain is the blockchain into which data is migrated in the data migration contract.

[0008] Obtain the migration storage data in the first blockchain, and perform fragmentation cutting on the migration storage data using the Sharding technology to output fragmented migration data packets.

[0009] Generate an encryption sub - key and a decryption sub - key through the HSM module. The fragmented migration data packet is subjected to fragmented encryption processing through the encryption sub - key to obtain a fragmented encrypted data packet.

[0010] Construct a protected migration channel between the first blockchain and the second blockchain through the QUIC protocol. Migrate the fragmented encrypted data packet into the second blockchain according to the protected migration channel, and perform decoding and storage according to the decryption sub - key.

[0011] In a second aspect, the present application provides a data security protection system supported by a blockchain. Wherein, the system includes:

[0012] A blockchain determination module, which determines a first blockchain and a second blockchain based on a data migration contract. The first blockchain is the blockchain from which data is migrated in the data migration contract, and the second blockchain is the blockchain into which data is migrated in the data migration contract.

[0013] A data packet output module, which is used to obtain the migration - stored data in the first blockchain, perform fragmented cutting processing on the migration - stored data using the Sharding technology, and output a fragmented migration data packet.

[0014] A data packet encryption module, which is used to generate an encryption sub - key and a decryption sub - key through the HSM module. The fragmented migration data packet is subjected to fragmented encryption processing through the encryption sub - key to obtain a fragmented encrypted data packet.

[0015] A data packet migration module, which is used to construct a protected migration channel between the first blockchain and the second blockchain through the QUIC protocol. Migrate the fragmented encrypted data packet into the second blockchain according to the protected migration channel, and perform decoding and storage according to the decryption sub - key.

[0016] The present application proposes one or more technical solutions, having at least the following technical effects:

[0017] This application determines the first blockchain and the second blockchain based on a data migration contract, clarifying the objects of data migration out and migration in. Then, it obtains the migration storage data in the first blockchain, and uses the Sharding technology to perform fragmentation cutting processing on it in the way of dividing according to data types and setting a fixed cutting size, and outputs fragmented migration data packets. Then, through the HSM module, a first initial key is generated by using a random number generator, and combined with multiple field encodings, encrypted sub-keys and decryption sub-keys are derived through the HKDF algorithm. The fragmented migration data packets are encrypted using the encrypted sub-keys to obtain fragmented encrypted data packets. After that, a protected migration channel between the first blockchain and the second blockchain is constructed through the QUIC protocol, and the fragmented encrypted data packets are migrated to the second blockchain and decoded and stored using the decryption sub-keys. During this process, if the number of migration storage blocks in the first blockchain is greater than or equal to 2, an inter-block exchange mark will also be established for data exchange and key derivation, and the key cycle management module of the HSM module will set the key validity duration, achieving the technical effect of secure migration and reliable storage of cross-blockchain data.

[0018] The above content outlines this application's method and system for solving data security protection under the support of blockchain. This application will describe the steps of the technical solution in detail in the following specific embodiments to facilitate those skilled in the art to understand this application clearly and completely. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for description in the embodiments. Obviously, the following described drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0020] Figure 1 It is a schematic flowchart of the data security protection method under the support of blockchain provided by the embodiments of this application.

[0021] Figure 2 It is a schematic structural diagram of the data security protection system under the support of blockchain provided by the embodiments of this application.

[0022] Description of the reference numerals: Blockchain determination module 1, data packet output module 2, data packet encryption module 3, data packet migration module 4. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0023] In this application, the first and second blockchains are determined based on a data migration contract. The migration storage data of the first blockchain is obtained and fragmented using the Sharding technology to obtain fragmented migration data packets. The HSM module is used to generate encryption and decryption sub-keys, and the data packets are encrypted to obtain fragmented encrypted data packets. A secure migration channel is constructed through the QUIC protocol to migrate them to the second blockchain and decode and store them. If the number of migrated storage blocks is ≥2, an exchange flag is established for data exchange and key derivation, and at the same time, the HSM module manages the key duration. The fragmented encrypted data packets are stored in the second blockchain and the data is recombined, achieving the technical effect of secure migration and reliable storage of cross-blockchain data.

[0024] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.

[0025] It should be noted that any variations of the terms "including" and "having" are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or server that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or modules that are not clearly listed or are inherent to these processes, methods, products, or devices.

[0026] Embodiment 1, as Figure 1 shown, a data security protection method supported by a blockchain, wherein the method includes:

[0027] Step A100: Determine a first blockchain and a second blockchain based on a data migration contract. The first blockchain is the blockchain from which data is migrated in the data migration contract, and the second blockchain is the blockchain to which data is migrated in the data migration contract.

[0028] In the embodiments of the present application, the data migration contract is a key element in the data security protection method supported by the blockchain, which is used to determine the first blockchain from which data is migrated and the second blockchain to which data is migrated, and clarify the source and destination of data migration.

[0029] Specifically, firstly, the core parameters of the outgoing chain (first blockchain) and the incoming chain (second blockchain) are specified in the data migration contract, including chain ID, consensus algorithm, block structure, etc. Then, based on the contract content, the two chains are tested for ETH (referring to the blockchain platform's support for the Ethereum protocol) and EVM (referring to whether the target blockchain supports EVM bytecode execution) compatibility. Finally, the contracts are deployed on both chains, and the specific steps are described in detail in A110-A120.

[0030] Through the above steps, the contract can record the relevant information of the two chains in detail to ensure the accuracy of the data migration direction.

[0031] Step A200: Obtain the migration storage data in the first blockchain, use Sharding technology to fragment the migration storage data, and output fragmented migration data packets.

[0032] In the embodiment of the present application, the migration storage data refers to the target data that needs to be migrated out of the first blockchain and migrated to the second blockchain. Sharding technology is a technology that divides the migration storage data into multiple independent fragments through a sharding strategy. The fragmented migration data packet is an independent data fragment generated after the Sharding technology is cut.

[0033] Optionally, it is necessary to first accurately identify multiple data storage blocks of the first blockchain, and then locate the migration storage blocks according to the relevant characteristics of the migration storage data, and then determine the number of migration storage blocks to determine whether the next step of storage data extraction and migration is to be carried out. The specific steps are described in detail in A240-A260. After obtaining the migration storage data, the Sharding technology is used to divide the migration storage data in detail according to the data type. For different categories of data, corresponding multiple fixed cutting sizes are set respectively. Finally, the migration storage data is fragmented and cut strictly according to these set fixed cutting sizes, so as to output the fragmented migration data packet. The specific steps are described in detail in A210-A230.

[0034] By fragmenting the original overall data, it has higher security and flexibility in the subsequent encryption, transmission and storage processes, can effectively reduce the risk of data loss or tampering, and is easier to manage and process.

[0035] Step A300: Generate an encryption subkey and a decryption subkey through the HSM module, and perform fragmented encryption processing on the fragmented migration data packet through the encryption subkey to obtain a fragmented encrypted data packet.

[0036] In the embodiments of the present application, the HSM (Hardware Security Module) module is a hardware device used to ensure the secure generation, storage, management, and data encryption operations of keys. The fragmented encrypted data packet is a data unit generated by further encrypting the fragmented migration data packet and obtained after specific encryption processing.

[0037] In an embodiment of the present application, first, the HSM module is used to generate an encryption sub-key and a decryption sub-key. The specific steps are described in detail in A310 - A320. Then, dynamic key binding is performed. When the migration data is distributed in multiple blocks, the HSM module will incorporate the exchange markers between blocks (such as block codes) into the key derivation process, making the key dynamically associated with the data distribution to prevent the key from being reused. Next, through the built-in key cycle management module, the valid duration of the key is automatically set (such as 24 hours), and the expired key is marked as invalid to avoid the security risks brought by using the same key for a long time. The specific steps are described in detail in A341. Finally, the fragmented encrypted data packet is generated. The fragmented migration data packet after being cut by the Sharding technology is encrypted using the corresponding encryption sub-keys generated by the HSM module respectively. Each shard data is encrypted independently to form a unique fragmented encrypted data packet. For example, after the migration data is cut into 100 shards, the HSM module will generate 100 pairs of exclusive keys to encrypt each shard respectively. This "one data one key" strategy ensures that when a single shard is leaked, the attacker cannot decrypt the other shard data and cannot reverse-engineer the original data structure from the key, fundamentally guaranteeing the confidentiality of data migration.

[0038] By encrypting the fragmented migration data packet, it provides a strong guarantee for the data security in the process of blockchain data migration.

[0039] Step A400: Construct a protected migration channel between the first blockchain and the second blockchain through the QUIC protocol, migrate the fragmented encrypted data packet to the second blockchain according to the protected migration channel, and decode and store it according to the decryption sub-key.

[0040] In the embodiments of the present application, the QUIC (Quick UDP Internet Connections) protocol is a low-latency, high-reliability transport protocol based on UDP (User Datagram Protocol, a connectionless transport layer protocol), which is used to construct a protected migration channel between the first blockchain and the second blockchain. The protected migration channel is a secure data transmission link constructed based on the QUIC protocol.

[0041] Specifically, when constructing a protected migration channel based on the QUIC protocol, it involves multiple specific steps:

[0042] Initial connection request: The first blockchain, as the data migration source, sends a connection request message based on the QUIC protocol to the second blockchain (data migration destination). This message contains information about the first blockchain, such as the supported protocol version, initial encryption parameter settings, etc. Since the QUIC protocol is based on UDP, it does not need to perform a complex three-way handshake like TCP (Transmission Control Protocol, a connection-oriented and reliable transport layer protocol), reducing the latency of connection establishment.

[0043] Encryption handshake negotiation: After receiving the connection request, the second blockchain responds with a message containing its own information, and both parties enter an encryption handshake mechanism process similar to TLS (Transport Layer Security protocol, used to provide confidentiality and data integrity protection between two communicating applications). They exchange encrypted handshake messages, which contain random numbers generated by each party. Using these random numbers and the pre-shared key material (if any) between the two parties, through a specific key negotiation algorithm (such as a variant of the Diffie-Hellman key exchange, Diffie-Hellman is an encryption algorithm mainly used to securely exchange keys between two parties over an insecure communication channel without having to share keys in advance), both parties generate random numbers respectively, and at the same time determine the public parameters required for the Diffie-Hellman algorithm, such as large prime number p and base number g. Based on the generated random numbers and public parameters, both parties calculate their own public keys respectively. Both parties exchange their public keys A and B over the network. After receiving the other party's public key, they calculate the shared key using their own random number and the other party's public key, and then negotiate the encryption key for subsequent data transmission. During this process, both parties also verify each other's identities, for example, through digital certificates, etc., to ensure that the communicating parties are legitimate blockchain nodes rather than middleman attackers.

[0044] Determine the encryption suite: According to the negotiation result, both parties determine the specific encryption suite, including the encryption algorithm used (such as AES-256, etc.), hash algorithm (such as SHA-256, etc.), and message authentication code algorithm, etc. These algorithms will be used to ensure the confidentiality, integrity, and authenticity of data transmission.

[0045] Use AES-256 to encrypt the data. Using the encryption sub-key generated by the HSM module, take the fragmented migration data packet as the input data and perform encryption processing according to the rules of the AES-256 algorithm. The AES-256 algorithm will divide the data into blocks of a fixed length, and then use the encryption sub-key to perform encryption operations on each data block to generate a fragmented encrypted data packet in ciphertext form to prevent the data from being stolen during network transmission.

[0046] Calculate the hash value of the data using SHA-256. Take the fragmented migration data packet as the input of the SHA-256 algorithm. The algorithm will pad the content of the data packet so that its length is 448 modulo 512. The padded data will be split into multiple 512-bit blocks, and each block will be processed independently. Then, a hash value with a fixed length (256 bits, consisting of 8 32-bit numbers respectively) will be generated. This hash value will be transmitted to the second blockchain together with the fragmented encrypted data packet. After the second blockchain receives the data, calculate the hash value of the received fragmented encrypted data packet again using the SHA-256 algorithm and compare it with the received original hash value. If the two are the same, it indicates that the data has not been tampered with during the transmission process, which is used to verify the integrity of the data.

[0047] Use the message authentication code algorithm to ensure the authenticity of the data source. In the first blockchain, take the fragmented migration data packet and the shared key as the input of the message authentication code algorithm. The algorithm will generate a message authentication code. This message authentication code is transmitted to the second blockchain through the protected migration channel together with the fragmented encrypted data packet. After the second blockchain receives the data, use the same shared key and the received fragmented encrypted data packet to calculate a new message authentication code through the same message authentication code algorithm and compare it with the received original message authentication code. If the two are the same, it can be confirmed that the data indeed comes from the legitimate first blockchain rather than forged or tampered data.

[0048] Multiplexing preparation: After completing the encryption handshake and encryption suite determination, both parties will prepare for the multiplexing function. This includes negotiating the identifiers of each data stream, flow control parameters, etc. Each fragmented encrypted data packet will be assigned to a different data stream for transmission, which can achieve concurrent transmission and improve the overall transmission efficiency. For example, mark different types or batches of fragmented encrypted data packets as different data streams and transmit them simultaneously on the same connection, avoiding waiting and blocking between data packets.

[0049] Channel establishment completed: When all the above steps are successfully completed, the protected migration channel based on the QUIC protocol between the first blockchain and the second blockchain is constructed. At this time, the channel has the ability to encrypt and transmit data, verify the identities of both parties, ensure data integrity, and efficiently and concurrently transmit fragmented encrypted data packets, and can start the data migration operation.

[0050] Next, use the constructed protected migration channel to migrate the fragmented encrypted data packets. These fragmented encrypted data packets will be sent to the channel in an orderly manner. After the fragmented encrypted data packets are successfully transmitted to the second blockchain, they enter the decoding and storage stage, and the specific steps are detailed in A410 - A420.

[0051] By constructing a protection migration channel based on the QUIC protocol to migrate fragmented encrypted data packets, the technical effect of secure and efficient migration and storage of data between different blockchains is achieved.

[0052] Further, step A200 in the method provided by the embodiments of the present application includes:

[0053] A210: Divide the migration storage data according to the data type, and output multiple types of migration storage data.

[0054] A220: Set multiple fixed cutting sizes corresponding to the multiple types of migration storage data.

[0055] A230: Fragment and cut the migration storage data according to the multiple fixed cutting sizes, and output fragmented migration data packets.

[0056] In the embodiments of the present application, multiple types of migration storage data refer to different types of data obtained by dividing the migration storage data in the first blockchain according to the data type. Fragmented migration data packets are data packets output after fragmenting and cutting multiple types of migration storage data according to the set fixed cutting sizes using the Sharding technology.

[0057] Specifically, first, with the help of data parsing technology, identify the structures and content characteristics of different types of data. There are various types of data, such as transaction data, user information data, smart contract code data, etc. The blockchain itself will record some meta-information about the data, such as the creator of the data, the creation time, the application scenario to which it belongs, etc. These metadata can be used to assist in judging the type of data. By identifying and distinguishing the characteristics of these data, the migration storage data is divided into different categories to obtain multiple types of migration storage data.

[0058] Next, set the corresponding fixed cutting size for each type of migration storage data. This requires comprehensively considering factors such as the nature of the data, the efficiency of network transmission, and the convenience of storage. For example, for transaction data, since its data volume is usually large and it has high requirements for real-time performance, it is set to be cut into one segment every 500KB to improve the transmission efficiency; for user information data, because its data volume is relatively small and it contains sensitive information, for the convenience of management and protection, it is set to be cut into one segment every 200KB; for smart contract code data, considering the integrity and security of its code structure, it is set to be cut into one segment every 800KB.

[0059] Finally, according to a set of multiple fixed cutting sizes, starting from the starting position of the data, cutting is carried out sequentially according to the fixed byte length. For data with a specific data structure, such as smart contract code data, it will be cut according to its code logical structure, function modules, etc. For example, cutting is carried out in units of functions, and a complete smart contract code is divided into multiple segments according to different function functions. This can ensure that the data in each fragmented migration data packet is relatively independent and complete logically, without damaging the functional structure of the code, and is helpful for subsequent reorganization and use on the second blockchain. During the cutting process, a fixed-length cutting algorithm and a cutting technology based on the data structure are used to ensure the integrity and accuracy of the data. Each data segment is accurately cut according to the set size to form fragmented migration data packets.

[0060] The fragmented migration data packets obtained through the above steps have higher flexibility and security compared to the uncut overall data during subsequent encryption, transmission, and storage processes.

[0061] Furthermore, step A200 in the method provided by the embodiments of the present application includes:

[0062] A240: Identify multiple data storage blocks of the first blockchain.

[0063] A250: Locate the migration storage blocks of the multiple data storage blocks according to the migration storage data, and determine whether the number of blocks of the migration storage blocks is greater than or equal to 2.

[0064] A260: If the number of blocks of the migration storage blocks is less than 2, extract the migration storage data from the migration storage blocks.

[0065] In the embodiments of the present application, the data storage block is the basic unit for storing data in the first blockchain. The migration storage block is the block related to data migration located in multiple data storage blocks of the first blockchain according to the migration storage data.

[0066] Optionally, first, use the indexing mechanism of the blockchain node and related blockchain browser tools to identify multiple data storage blocks of the first blockchain. The blockchain browser can display various information on the blockchain, and through it, the basic information and location of the data storage blocks can be obtained.

[0067] Then, according to the characteristic information of the migration storage data, such as the hash value, timestamp, or specific identification field of the data, locate the migration storage blocks in the identified multiple data storage blocks. These characteristic information are like the "identity cards" of the data, helping the system quickly find the blocks where the target data is located.

[0068] Then, judge the number of migrated storage blocks located. The specific steps are described in detail in A251 - A252. If the number of blocks in the migrated storage block is less than 2, this means that the data is relatively concentrated. At this time, directly extract the migrated storage data from the migrated storage block. The extraction process can utilize the standard data reading interface provided by the blockchain and extract the data accurately according to the data storage format and rules to ensure the integrity and accuracy of the data.

[0069] Further, step A250 in the method provided by the embodiment of the present application includes:

[0070] A251: If the number of blocks in the migrated storage block is greater than or equal to 2, establish an exchange mark between every two migrated storage blocks in the migrated storage block.

[0071] A252: Exchange the data in the migrated storage block according to the exchange mark, output the migrated storage block with updated data, and extract the migrated storage data according to the migrated storage block with updated data.

[0072] In the embodiment of the present application, the exchange mark is an identifier established between every two migrated storage blocks in the migrated storage block when the number of blocks in the migrated storage block is greater than or equal to 2, and its essence is the block codes of the two exchanged blocks.

[0073] Specifically, first, establish an exchange mark between every two migrated storage blocks in the migrated storage block. By constructing a data structure (such as a mapping table), first clarify that each migrated storage block has a unique identifier, such as a hash value or a block number. Then create an empty mapping table, and its structure can be in the form of key - value pairs. For every two migrated storage blocks, use the identifier of one block as the key and the identifier of the other block as the corresponding value, and add them to the mapping table in turn. For example, there are migrated storage blocks A, B, and C. Add the identifier of A as the key and the identifier of B as the value to the mapping table; then add the identifier of B as the key and the identifier of C as the value, and so on until all the corresponding relationships between every two migrated storage blocks are covered. In this way, a mapping table recording the corresponding relationships of data exchange between different blocks is constructed, and the identifiers of every two migrated storage blocks are associated to form an exchange mark. This exchange mark is like a "navigation map" for data exchange, recording the corresponding relationships of data exchange between different blocks.

[0074] Next, the data in the migrated storage blocks is exchanged according to the established exchange tags. Guided by the exchange tags, the corresponding data fragments are read from each migrated storage block, and then these data fragments are exchanged into the target migrated storage block according to the corresponding relationship of the tags. During the data exchange process, a hash algorithm is used to ensure the accuracy and integrity of the data. Before data transmission, the SHA-256 algorithm is used to calculate the hash value of the data in the migrated storage block, obtaining a hash string of a fixed length. After the data is transmitted to the target migrated storage block, the SHA-256 algorithm is used again to calculate the hash value of the received data. By comparing these two hash values, if they are exactly the same, it indicates that the data has not been tampered with during the transmission process, ensuring the integrity of the data.

[0075] After the data exchange operation, the migrated storage blocks with updated data are output. The data distribution in these updated migrated storage blocks has changed. Through this exchange operation, the original storage order of the data can be disrupted, increasing the security and complexity of the data and reducing the risk of the data being illegally obtained and tampered with.

[0076] Finally, the migrated storage data is extracted from the migrated storage blocks with updated data. Using the data reading interface of the blockchain, according to the established data format and storage rules, the required migrated storage data is accurately extracted from the updated migrated storage blocks.

[0077] By constructing exchange tags to exchange the data and obtaining the required migrated storage data, the needs of subsequent data processing and migration are met, providing a reliable data foundation for the entire blockchain data security protection process.

[0078] Furthermore, step A300 in the method provided by the embodiment of the present application includes:

[0079] A310: The HSM module includes a random number generator, and a first initial key is generated according to the random number generator.

[0080] A320: The random number generator generates a plurality of field encodings, and the first initial key and the plurality of field encodings are derived through the HKDF algorithm, outputting an encryption sub-key for fragmentation encryption and a decryption sub-key corresponding to the encryption sub-key.

[0081] In the embodiment of the present application, the first initial key is the basic seed for the entire key derivation process. The HKDF algorithm is a key derivation function based on HMAC (Hash Message Authentication Code), which is an algorithm for deriving one or more keys from an initial key material.

[0082] Specifically, as a hardware device dedicated to secure key management and encryption operations, the random number generator in the HSM module is the starting point of the whole process, and it can generate high-quality random numbers. The first initial key is generated according to the random number generator, and this initial key is the basis for the derivation of subsequent encryption sub-keys and decryption sub-keys.

[0083] The generated field encoding contains key information such as data type identifier (marking the migration data type), shard size parameter (corresponding to the fixed cut size set by the Sharding technology), block encoding (the unique identifier of the migration storage block, i.e., the hash value), and random salt value (an unpredictable random number generated by the HSM module). The random number generator of the HSM module generates the field encoding in the following ways:

[0084] True Random Number Generation (TRNG): Utilize hardware physical phenomena (such as voltage fluctuations, thermal noise) to generate unpredictable random numbers, which serve as the basis for the data type identifier and random salt value.

[0085] Pseudo-Random Number Generation (PRNG): Based on the seed generated by TRNG, expand it through an algorithm to generate a shard size parameter and block encoding of sufficient length (such as generating a pseudo-random sequence using the AES-CTR mode. AES-CTR is the Advanced Encryption Standard Counter mode, which is a working mode of the AES encryption algorithm).

[0086] After obtaining the field encoding, execute the HKDF algorithm, which is mainly divided into two stages: the extraction stage and the expansion stage.

[0087] Extraction stage: Use the HMAC function in combination with the salt value to process the first initial key to generate a pseudo-random key (PRK). The HMAC function is a message authentication code algorithm based on a hash function. It can mix the salt value and the first initial key and generate a fixed-length PRK through a hash operation. This PRK contains the key information of the initial key, and due to the addition of the salt value, different salt values will generate different PRKs.

[0088] Expansion stage: Use the HMAC function in combination with the PRK and multiple field encodings to generate encryption sub-keys and decryption sub-keys of the required length. In this stage, the HKDF algorithm will call the HMAC function multiple times according to the required key length, taking the PRK and multiple field encodings as inputs, and gradually generate encryption sub-keys and decryption sub-keys.

[0089] Through the processing of the HKDF algorithm, the encryption sub-keys and decryption sub-keys for fragmented encryption are finally output. The encryption sub-keys are used for encrypting data fragments, converting the data into ciphertext form to protect the confidentiality of the data. The decryption sub-keys are used to decrypt the encrypted data fragments when needed, restoring the ciphertext to the original data.

[0090] Further, step A330 in the method provided by the embodiments of the present application includes:

[0091] A331: Store the exchange tags between every two migration storage blocks in the migration storage blocks, where the exchange tags are the block codes of the two exchanged blocks.

[0092] A332: Input the exchange tags into the HSM module, and derive the first initial key and the exchange tags through the HKDF algorithm to output an encryption sub-key for fragmented encryption and a decryption sub-key corresponding to the encryption sub-key.

[0093] Specifically, first, store the exchange tags. When the number of migration storage blocks is greater than or equal to 2, exchange tags between every two migration storage blocks will be established, which are the block codes of the two exchanged blocks. These tags contain key information for data exchange and need to be properly stored in a dedicated database or a distributed storage system.

[0094] Next, input the exchange tags into the HSM module. The HSM has a dedicated security mechanism to protect keys and perform encryption operations, which can prevent external illegal access and attacks and provide the necessary input for subsequent key derivation.

[0095] Then, use the HKDF algorithm for key derivation. HKDF is a key derivation function based on HMAC, which takes the first initial key and the exchange tags as inputs. The first initial key is generated by the random number generator of the HSM module, which has high randomness and security. The HKDF algorithm is divided into two stages: extraction and expansion, and the specific steps are described in detail in A320.

[0096] Finally, output the encryption sub-key and the decryption sub-key. After being processed by the HKDF algorithm, an encryption sub-key for fragmented encryption and a corresponding decryption sub-key are obtained. The two are in one-to-one correspondence, and only the correct decryption sub-key can decrypt the corresponding encrypted data.

[0097] By combining the hardware security of the HSM module, the pertinence of the exchange tags, and the HKDF algorithm, reliable guarantee is provided for data security in blockchain data migration.

[0098] Further, step A340 in the method provided by the embodiments of the present application includes:

[0099] A341: The HSM module further includes a key cycle management module, and the key cycle management module is used to set the effective duration of the encryption sub-key and the decryption sub-key, and mark the keys that are not within the effective duration as invalid.

[0100] In the embodiments of the present application, the key cycle management module is an important part of the HSM module, mainly responsible for managing the entire life cycle of encryption sub-keys and decryption sub-keys to ensure the security, effectiveness, and compliance of the keys.

[0101] In one embodiment, first, the effective duration is determined. The key cycle management module sets the key effective period according to the security policy and business requirements. For example, the encryption key for highly sensitive data is set with a 24-hour validity period, and the general data key is set with a 7-day validity period. The security policy needs to comprehensively consider factors such as data type, attack risk, and compliance requirements, while the business requirements are combined with the data usage frequency and update cycle.

[0102] Then, the generation time is recorded. When the key is generated, the module records the generation timestamp accurate to milliseconds in the hardware security environment and stores the timestamp bound to the key ID in the secure database. For example, when generating the encryption key with ID K123, the "2025-03-17T10:00:00Z" is synchronously recorded as the start time.

[0103] Next, the key status is monitored in real time. The module scans all keys at a second-level frequency and calculates the remaining validity period by subtracting the generation time from the current time. For example, at 2025-03-18T09:59:59Z, it is detected that the K123 key has 1 second remaining until expiration, triggering the warning mechanism.

[0104] Finally, the expired key is marked. When the key exceeds the effective duration, the module immediately executes: modifying the key status to "EXPIRED" (EXPIRED is the status identifier set by the key cycle management module for marking the expired key); generating an expiration certificate and storing it on the chain for evidence; automatically triggering the key update process; blocking all encryption / decryption requests using the key.

[0105] Through this mechanism, the key life cycle is strictly controlled within the security boundary, and the key update process is synchronized with the data migration operation to ensure that the business continuity is not affected.

[0106] Furthermore, step A100 in the method provided by the embodiments of the present application includes:

[0107] A110: Determine the first blockchain and the second blockchain based on the data migration contract, where the data migration contract includes performing ETH and EVM compatibility detection on the first blockchain and the second blockchain.

[0108] A120: After the compatibility detection of ETH and EVM passes, perform contract deployment on the first blockchain and contract deployment on the second blockchain according to the content of the data migration contract.

[0109] Optionally, the data migration contract first contains compatibility detection parameters: including the ETH version requirements of the target chain (such as >= 2.0), the EVM version specification (such as support for the London hard fork), the gas fee standard (the gas fee is a charging unit used in blockchain networks such as Ethereum to measure the computing resources required to execute smart contracts or transactions), etc.; deployment configuration: defining the contract addresses, call interfaces, data format mapping rules, etc. of the first blockchain (source chain) and the second blockchain (target chain).

[0110] Then, perform ETH and EVM compatibility detection, including on-chain queries: send standard JSON-RPC (a lightweight remote procedure call protocol based on JSON) requests such as eth_chainId (used to obtain the network ID of the Ethereum blockchain) and eth_getBlockByNumber (a request to obtain the corresponding block information according to the block number) to the first chain and the second chain through the RPC (Remote Procedure Call) interface, and obtain information such as the ETH version number and EVM status (such as whether EIP-1559, that is, Ethereum Improvement Proposal No. 1559, is activated) of the current chain.

[0111] Compliance verification: Check whether the ETH version of the second chain meets the contract requirements (such as whether it supports pre-compiled contracts). Verify whether the EVM implementation of the second chain is compatible with the target contract bytecode (such as whether the gas consumption during the execution of the test transaction is within the allowable range).

[0112] Result feedback: If the detection fails, terminate the migration process and generate a report containing specific incompatibility items; if it passes, generate a compatibility certification hash value as a credential for subsequent contract deployment.

[0113] Next, perform the deployment of the first blockchain contract. According to the deployment configuration in the data migration contract, automatically generate a deployment script that conforms to the syntax of the first chain. For example, use the Truffle framework (a development framework for the Ethereum blockchain) to compile a Solidity (the main programming language for Ethereum smart contracts) contract into bytecode and generate a deployment transaction. Then sign the deployment transaction through the HSM module to ensure the security of the private key. The signature value generated inside the HSM is transmitted to the node client through an encrypted channel. Then send the deployment transaction to the first chain node, and the node includes the transaction in the block after verifying the transaction format. Confirm the success of the deployment by listening to the event log (such as the ContractDeployed event, that is, an event defined by the developer).

[0114] Finally, deploy the second blockchain contract, and adjust the contract parameters according to the characteristics of the second chain for cross-chain adaptation. For example, if the second chain is the Binance Smart Chain, the gas price unit needs to be converted from Gwei to Gigawei (a unit used to measure the quantity of Ether in the Ethereum network, and Gigawei actually refers to 10 to the 9th power of wei). Then perform mirror deployment, using the same deployment process as the first chain but pointing to the node address of the second chain. After deployment, verify whether the contract code hashes on the two chains are the same through a cross-chain oracle. Next, establish a cross-chain monitoring mechanism to ensure that the contract states (such as stored variables, event logs) on the two chains are synchronized in real time.

[0115] Through the automated detection and deployment process, the average time-consuming of cross-chain migration is shortened, and the failure rate caused by compatibility problems is reduced.

[0116] Furthermore, step A400 in the method provided by the embodiment of the present application includes:

[0117] A410: The second blockchain stores the received fragmented encrypted data packets according to the decryption sub-key, and reorganizes the stored fragmented encrypted data packets to obtain reorganized migration data.

[0118] A420: Store the reorganized migration data in the second blockchain.

[0119] In the embodiment of the present application, the reorganized migration data refers to a complete data set formed by decrypting fragmented encrypted data packets with a decryption sub-key and recombining the scattered fragment data in the original logical order during the blockchain data migration process.

[0120] In one embodiment, after the second blockchain receives the fragmented encrypted data packets transmitted from the protected migration channel, it stores them according to the decryption sub-key. During the storage process, the second blockchain organizes and manages these fragmented encrypted data packets according to certain rules, embeds metadata (shard ID, order, type) through sharding indexes and stores them distributively; associates the decryption sub-key ID and key aging management; stores the hash value and verifies the integrity through cross-node consensus; separates the hot and cold data for storage and compresses and optimizes them; sets a full-scale fragment threshold (such as 90%) or a time window to trigger reorganization for subsequent reorganization operations.

[0121] After the second blockchain finishes storing the fragmented encrypted data packets, it decrypts these data packets using the decryption sub-keys. The decryption process is the reverse operation of the encryption process, and the encrypted data is restored to the original fragmented data through the decryption sub-keys. Then, according to the rules and tags during data fragmentation, these fragmented data are recombined. For example, each fragmented data may contain its position information in the original data, and the second blockchain will splice the fragmented data in the correct order based on this information to finally obtain the recombined migration data.

[0122] The migration data obtained after recombination has been restored to the complete form of the original data. At this time, the second blockchain will store the recombined migration data in its own storage system. The storage method can be selected according to the specific architecture and requirements of the second blockchain. For example, it can be stored in a distributed ledger to ensure the immutability and traceability of the data. In this way, the data has been successfully migrated from the first blockchain to the second blockchain, and the security and integrity of the data are guaranteed during the migration process.

[0123] Through the above steps, the fragmented encrypted data packets are migrated to the second blockchain using the protected migration channel, then decoded and recombined using the decryption sub-keys, and finally the recombined migration data is securely stored in the second blockchain, realizing the secure migration of data between blockchains.

[0124] In summary, the data security protection method provided by the embodiments of the present application has the following technical effects:

[0125] In this application, a data migration link is constructed between the first blockchain and the second blockchain, the data is cut using the Sharding technology, encrypted by the HSM module, transmitted through the QUIC protocol, etc., to obtain fragmented encrypted data packets, and stored and recombined in the second blockchain. Through the ETH and EVM compatibility detection, contract deployment, combined with mechanisms such as key cycle management and exchange tags, decoding storage is performed based on the decryption sub-keys and dynamically adjusted to ensure the secure migration of data, achieving the technical effects of secure migration and reliable storage of cross-blockchain data.

[0126] Embodiment 2, a data security protection system supported by a blockchain, as Figure 2 shown, the system includes:

[0127] A blockchain determination module 1, which determines the first blockchain and the second blockchain based on a data migration contract. The first blockchain is the blockchain from which data is migrated in the data migration contract, and the second blockchain is the blockchain into which data is migrated in the data migration contract.

[0128] Data packet output module 2, which is used to obtain the migrated storage data in the first blockchain, perform fragmentation cutting on the migrated storage data using Sharding technology, and output fragmented migration data packets.

[0129] Data packet encryption module 3, which is used to generate an encryption sub-key and a decryption sub-key through the HSM module, and perform fragmentation encryption on the fragmented migration data packet through the encryption sub-key to obtain a fragmented encrypted data packet.

[0130] Data packet migration module 4, which is used to build a protected migration channel between the first blockchain and the second blockchain through the QUIC protocol, migrate the fragmented encrypted data packet to the second blockchain according to the protected migration channel, and perform decoding and storage according to the decryption sub-key.

[0131] Furthermore, the data packet output module 2 is used to perform the following steps:

[0132] Divide the migrated storage data according to the data type, and output multiple types of migrated storage data.

[0133] Set multiple fixed cutting sizes corresponding to the multiple types of migrated storage data.

[0134] Perform fragmentation cutting on the migrated storage data according to the multiple fixed cutting sizes, and output fragmented migration data packets.

[0135] Furthermore, the data packet output module 2 is used to perform the following steps:

[0136] Identify multiple data storage blocks of the first blockchain.

[0137] Locate the migrated storage blocks of the multiple data storage blocks according to the migrated storage data, and determine whether the number of blocks of the migrated storage blocks is greater than or equal to 2.

[0138] If the number of blocks of the migrated storage block is less than 2, extract the migrated storage data from the migrated storage block.

[0139] Furthermore, the data packet output module 2 is used to perform the following steps:

[0140] If the number of blocks of the migrated storage block is greater than or equal to 2, establish an exchange mark between every two migrated storage blocks in the migrated storage block.

[0141] Exchange the data in the migrated storage block according to the exchange mark, output the migrated storage block with updated data, and extract the migrated storage data according to the migrated storage block with updated data.

[0142] Further, the data packet encryption module 3 is used to perform the following steps:

[0143] The HSM module includes a random number generator, and a first initial key is generated according to the random number generator.

[0144] The random number generator generates a plurality of field codes, and the first initial key and the plurality of field codes are derived through the HKDF algorithm to output an encryption sub-key for fragmented encryption and a decryption sub-key corresponding to the encryption sub-key.

[0145] Further, the data packet encryption module 3 is used to perform the following steps:

[0146] Store the swap marks between every two migration storage blocks in the migration storage block, where the swap marks are the block codes of the two swapped blocks.

[0147] Input the swap marks into the HSM module, and the first initial key and the swap marks are derived through the HKDF algorithm to output an encryption sub-key for fragmented encryption and a decryption sub-key corresponding to the encryption sub-key.

[0148] Further, the data packet encryption module 3 is used to perform the following steps:

[0149] The HSM module further includes a key cycle management module, and the key cycle management module is used to set the valid duration of the encryption sub-key and the decryption sub-key, and mark the keys that are not within the valid duration as invalid.

[0150] Further, the blockchain determination module 1 is used to perform the following steps:

[0151] Determine a first blockchain and a second blockchain based on a data migration contract, where the data migration contract includes ETH and EVM compatibility detection for the first blockchain and the second blockchain.

[0152] After the compatibility detection of ETH and EVM passes, contract deployment is performed on the first blockchain and contract deployment is performed on the second blockchain according to the content of the data migration contract.

[0153] Further, the data packet migration module 4 is used to perform the following steps:

[0154] The second blockchain stores the received fragmented encrypted data packets according to the decryption sub-key and reorganizes the stored fragmented encrypted data packets to obtain reorganized migration data.

[0155] Store the recombinant migration data in the second blockchain.

[0156] The data security protection system supported by the blockchain provided by the embodiments of the present invention can execute the data security protection method supported by the blockchain provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.

[0157] Although the present application makes various references to certain modules in the system according to the embodiments of the present application, however, any number of different modules can be used and run on the user terminal and / or the server. The included individual units and modules are only divided according to the functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of mutual distinction and do not limit the protection scope of the present invention.

[0158] The above specific embodiments do not constitute a limitation on the protection scope of the present application. Those skilled in the art should understand that various modifications, combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of the present application shall be included within the protection scope of the present application. In some cases, the actions or steps recorded in the present application can be executed in a different order from that in the embodiments and still achieve the desired results. Additionally, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

Claims

1. A data security protection method supported by blockchain, characterized in that: The method comprises: Determine a first blockchain and a second blockchain based on the data migration contract, wherein the first blockchain is a blockchain from which data is migrated in the data migration contract, and the second blockchain is a blockchain from which data is migrated in the data migration contract; Obtain the migration storage data in the first blockchain, use Sharding technology to perform fragmentation processing on the migration storage data, and output fragmented migration data packets; Generate an encryption subkey and a decryption subkey through the HSM module, and perform fragmentation encryption processing on the fragmented migration data packet through the encryption subkey to obtain a fragmented encrypted data packet; A protection migration channel between the first blockchain and the second blockchain is constructed through the QUIC protocol, the fragmented encrypted data packet is migrated to the second blockchain according to the protection migration channel, and is decoded and stored according to the decryption subkey.

2. The method according to claim 1, characterized in that The migration storage data is fragmented and cut using Sharding technology to output fragmented migration data packets, the method comprising: Dividing the migration storage data according to data types, and outputting multiple types of migration storage data; Setting a plurality of fixed cutting sizes corresponding to the plurality of types of migration storage data; The migration storage data is fragmented according to the multiple fixed cutting sizes, and fragmented migration data packets are output.

3. The method according to claim 1, characterized in that Obtaining the migration storage data in the first blockchain, the method comprising: Identifying a plurality of data storage blocks of the first blockchain; Locating a migration storage block of the plurality of data storage blocks according to the migration storage data, and determining whether the number of blocks of the migration storage block is greater than or equal to 2; If the number of blocks of the migration storage block is less than 2, the migration storage data is extracted from the migration storage block.

4. The method according to claim 3, characterized in that Determining whether the number of blocks of the migration storage block is greater than or equal to 2, the method further includes: If the number of blocks in the migration storage block is greater than or equal to 2, establishing a swap mark between every two migration storage blocks in the migration storage block; The data in the migration storage block is exchanged according to the exchange mark, the migration storage block after the data is updated is output, and the migration storage data is extracted according to the migration storage block after the data is updated.

5. The method according to claim 4, characterized in that Generate encryption subkey and decryption subkey through HSM module, the method includes: The HSM module includes a random number generator, and generates a first initial key according to the random number generator; The random number generator generates multiple field codes, derives the first initial key and the multiple field codes through the HKDF algorithm, and outputs an encryption subkey for fragmented encryption and a decryption subkey corresponding to the encryption subkey.

6. The method according to claim 5, characterized in that Generate an encryption subkey and a decryption subkey by using the HSM module, and the method further includes: storing a swap mark between every two migration storage blocks in the migration storage blocks, wherein the swap mark is a block code of two swapped blocks; The exchange tag is input into the HSM module, the first initial key and the exchange tag are derived by the HKDF algorithm, and an encryption subkey for fragmented encryption and a decryption subkey corresponding to the encryption subkey are output.

7. The method according to claim 5, characterized in that The HSM module further includes a key period management module, which is used to set the valid duration of the encryption subkey and the decryption subkey, and to mark the keys that are not within the valid duration as invalid.

8. The method according to claim 1, characterized in that Also includes: Determine a first blockchain and a second blockchain based on a data migration contract, wherein the data migration contract includes performing ETH and EVM compatibility detection on the first blockchain and the second blockchain; When the compatibility test of ETH and EVM is passed, the contract is deployed on the first blockchain according to the content of the data migration contract, and the contract is deployed on the second blockchain.

9. The method according to claim 1, characterized in that Migrating the fragmented encrypted data packet to the second blockchain according to the protection migration channel, and decoding and storing the data packet according to the decryption subkey, the method comprising: The second blockchain stores the received fragmented encrypted data packets according to the decryption subkey, and reassembles the stored fragmented encrypted data packets to obtain reassembled migration data; The reorganized migration data is stored in the second blockchain.

10. The data security protection system supported by blockchain is characterized by: For implementing the data security protection method supported by blockchain according to any one of claims 1 to 9, the system comprises: A blockchain determination module, wherein the blockchain determination module determines a first blockchain and a second blockchain based on a data migration contract, wherein the first blockchain is a blockchain from which data is migrated in the data migration contract, and the second blockchain is a blockchain from which data is migrated in the data migration contract; A data packet output module, the data packet output module is used to obtain the migration storage data in the first blockchain, use Sharding technology to fragment the migration storage data, and output fragmented migration data packets; A data packet encryption module, the data packet encryption module is used to generate an encryption subkey and a decryption subkey through an HSM module, and the fragmented migration data packet is fragmented and encrypted by using the encryption subkey to obtain a fragmented encrypted data packet; A data packet migration module, wherein the data packet migration module is used to construct a protection migration channel between the first blockchain and the second blockchain through the QUIC protocol, migrate the fragmented encrypted data packet to the second blockchain according to the protection migration channel, and decode and store it according to the decryption subkey.