Data desensitization method and data desensitization device based on block chain
By configuring smart contracts on the blockchain for data desensitization processing, and using multi-node verification and blockchain encryption, the problem of low security and credibility of data desensitization processing in centralized systems is solved, achieving higher data processing transparency and security.
Patent Information
- Application Number
- CN202510331684.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-19
- Publication Date
- 2025-06-27
AI Technical Summary
In the prior art, data desensitization processing based on centralized systems has problems with low security and credibility.
The blockchain-based data desensitization method is adopted, and the blockchain ledger is configured through smart contracts, and the data on the chain is monitored and desensitized when the preset conditions are met. After that, multiple nodes verify the desensitization data, and after verification is passed, encryption and storage is carried out through the blockchain.
Through the combination of decentralized blockchain system and smart contracts, the risk of single point of failure of the centralized system is avoided, the transparency and credibility of data processing is improved, and the security of data is ensured through multi-node verification and blockchain encryption.
Smart Images

Figure CN120217439A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data communication technologies, and in particular, to a blockchain-based data desensitization method, a data desensitization device, a computer-readable storage medium, and a data privacy desensitization system. Background Art
[0002] With the acceleration of the pace of the information age, big data and artificial intelligence technologies have become increasingly mature, and their applications in fields such as commerce, healthcare, and finance have become increasingly widespread, promoting the collection, analysis, and sharing of data to become unprecedentedly efficient and common. However, the popularization of this data utilization is also accompanied by serious privacy and security challenges. The improper handling of personal information may not only lead to privacy leakage but also breed data abuse behaviors, infringe on personal rights and interests, and even affect social stability.
[0003] Regarding the privacy protection in the process of data collection, analysis, and sharing, data desensitization is usually used in the prior art to hide sensitive data. However, the data desensitization in the prior art usually adopts a centralized mode, and the centralized mode has the risk of single-point failure. Once the server is attacked, a large amount of sensitive data may be illegally obtained. In addition, the centralized system lacks transparency and it is difficult to ensure the consistency and fairness in the data processing process.
[0004] In summary, the data desensitization system in the prior art relies on a centralized structure and has problems of low security and credibility in the application process. Summary of the Invention
[0005] The main purpose of the present application is to provide a blockchain-based data desensitization method, a data desensitization device, a computer-readable storage medium, and a data privacy desensitization system, so as to at least solve the problem of low security and credibility of data desensitization processing based on a centralized system in the prior art.
[0006] To achieve the above object, according to one aspect of the present application, a blockchain-based data desensitization method is provided, including: configuring at least an intelligent contract according to a desensitization algorithm and configuring the intelligent contract in a blockchain ledger of a blockchain, where the desensitization algorithm includes at least one of data de-identification, data replacement, data noise addition, and data obfuscation; monitoring, by the intelligent contract, on-chain data of the blockchain, and when the on-chain data meets a preset contract condition of the intelligent contract, performing desensitization processing on the on-chain data through the intelligent contract to obtain desensitized data; performing data verification on the desensitized data by multiple nodes in the blockchain; and encrypting and storing the desensitized data through the blockchain in the case where the data verification is passed.
[0007] Optionally, after desensitizing the on-chain data through a smart contract to obtain desensitized data, the method further includes: when the desensitization process is completed, triggering a preset event through the event mechanism of the smart contract, where the preset event is used to record the ID of the desensitized data, the processing steps of the desensitization process, and the desensitization time; when the preset event is triggered, configuring the event parameters of the preset event, where the event parameters include the data visitor address, the accessed data ID, and the access time; broadcasting the preset event to the first preset node of the blockchain, where the first preset node is used to generate an audit log based on the preset event for the staff to monitor the desensitization process.
[0008] Optionally, data verification of the desensitized data is performed by multiple nodes in the blockchain, including: splitting the desensitized data into multiple first target data according to a target quantity through a smart contract, performing hash processing on each first target data to obtain second target data; uploading the second target data to the blockchain through the smart contract and initiating a transaction broadcast through the blockchain network, where the transaction broadcast is used to instruct the nodes in the blockchain to perform local data verification respectively based on the received second target data; in response to the feedback information sent by the nodes of the blockchain, when all the feedback information is verified to pass, obtaining the verification results of each node of the blockchain through the smart contract and performing complete data verification based on all the verification results to obtain a comprehensive verification score; when the comprehensive verification score is greater than the first threshold, performing integrity verification and security verification on the desensitized data through the smart contract, and when both the integrity verification and the security verification pass, determining that the data verification of the desensitized data passes.
[0009] Optionally, before splitting the desensitized data into multiple parts according to a target quantity through a smart contract, the method further includes: determining the sensitivity score of the desensitized data based on the original on-chain data of the desensitized data; determining the security level of the desensitized data according to the sensitivity score, and determining the target quantity corresponding to the desensitized data according to the security level.
[0010] Optionally, encrypting the desensitized data through the blockchain includes: encrypting the desensitized data with the private key of the data holder of the desensitized data and encrypting it with the common network key of the nodes participating in the verification to obtain target encrypted data; storing the public keys of the private key and the common network key in the blockchain.
[0011] Optionally, storing the desensitized data through the blockchain includes: storing the encrypted desensitized data in the blockchain ledger of the blockchain, where each node stores a part of the encrypted desensitized data.
[0012] Optionally, after encrypting and storing the desensitized data through the blockchain, the method further includes: in response to an access request initiated by a node, accessing the digital identity system of the blockchain through a smart contract to obtain the target digital identity corresponding to the node, where the digital identity system is used to store the digital identities of each node in the blockchain; determining the allowed browsing range of the node according to the target digital identity, and determining the current browsing range of the node according to the access request; determining the absolute value of the browsing deviation of the node according to the current browsing range and the allowed browsing range; allowing the node to access the desensitized data when the absolute value of the browsing deviation is less than or equal to a second threshold; allowing the node to access the desensitized data when the absolute value of the browsing deviation is greater than the second threshold and the current browsing range is less than the allowed browsing range; determining that the node has an illegal access behavior when the absolute value of the browsing deviation is greater than the second threshold and the current browsing range is greater than the allowed browsing range; obtaining the access frequency of the illegal access behavior of the node and the single browsing duration of each access within a preset period; determining the illegal access behavior as a non-misoperation when the single browsing duration is greater than a third threshold, and determining the illegal access behavior as a misoperation when the single browsing duration is less than or equal to the third threshold; when the ratio of the frequency of misoperations to the access frequency within the preset period is greater than a fourth threshold, sending a target warning message to the node, where the target warning message indicates that the node has a locking risk; calculating a locking score according to the frequency of misoperations, the access frequency, and the total browsing duration of misoperations within the preset period, and locking the permissions of the node when the locking score is greater than a fifth threshold.
[0013] According to another aspect of the present application, there is provided a blockchain-based data desensitization device, the device includes: a control unit, configured to configure a smart contract at least according to a desensitization algorithm and configure the smart contract in the blockchain ledger of the blockchain, where the desensitization algorithm includes at least one of data de-identification, data replacement, data noise addition, and data fuzzification; a first processing unit, configured to monitor the on-chain data of the blockchain through the smart contract, and perform desensitization processing on the on-chain data through the smart contract to obtain desensitized data when the on-chain data meets the preset contract conditions of the smart contract; a verification unit, configured to perform data verification on the desensitized data through multiple nodes in the blockchain; a storage unit, configured to encrypt and store the desensitized data through the blockchain when the data verification is passed.
[0014] According to still another aspect of the present application, there is provided a computer-readable storage medium, the computer-readable storage medium includes a stored program, where, when the program runs, it controls the device where the computer-readable storage medium is located to execute any one of the methods.
[0015] According to another aspect of the present application, there is provided a data privacy de - identification system, including: one or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs include methods for performing any one of them.
[0016] Applying the technical solution of the present application, in the above - mentioned blockchain - based data de - identification method, first, at least configure a smart contract according to a de - identification algorithm and configure the smart contract in the blockchain ledger of the blockchain. The de - identification algorithm includes at least one of data de - identification, data replacement, data noise addition, and data obfuscation; then, the smart contract monitors the on - chain data of the blockchain, and when the on - chain data meets the preset contract conditions of the smart contract, the smart contract performs de - identification processing on the on - chain data to obtain de - identified data; after that, multiple nodes in the blockchain perform data verification on the de - identified data; finally, when the data verification passes, the blockchain encrypts and stores the de - identified data. The present application performs de - identification on the data to be de - identified through a smart contract configured on a blockchain - based decentralized system, avoiding the problem that data leakage is easily caused by attacks on centralized systems for de - identification. And it verifies the quality of the de - identified data through multiple nodes, ensuring the transparency and credibility of data processing, and encrypts and stores the de - identified data through the blockchain, solving the problem of low security and credibility in data de - identification processing based on centralized systems in the prior art. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 The hardware structure block diagram of a mobile terminal showing a blockchain - based data de - identification method provided in an embodiment of the present application is shown;
[0018] Figure 2 The flow schematic diagram of a blockchain - based data de - identification method provided in an embodiment of the present application is shown;
[0019] Figure 3 The structure block diagram of a blockchain - based data de - identification device provided in an embodiment of the present application is shown.
[0020] Among them, the above - mentioned drawings include the following reference numerals:
[0021] 102, processor; 104, memory; 106, transmission device; 108, input / output device. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0022] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other. The present application will be described in detail below with reference to the drawings and in combination with the embodiments.
[0023] In order to enable those skilled in the art to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.
[0024] It should be noted that the terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances for the embodiments of this application described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0025] As introduced in the background art, the data desensitization system in the prior art relies on a centralized structure and has problems of low security and credibility in the application process. To solve the problems of low security and credibility of data desensitization processing based on a centralized system in the prior art, the embodiments of this application provide a blockchain-based data desensitization method, a data desensitization device, a computer-readable storage medium, and a data privacy desensitization system.
[0026] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention.
[0027] The method embodiments provided in the embodiments of this application can be executed on a mobile terminal, a computer terminal, or a similar computing device. Taking the operation on a mobile terminal as an example, Figure 1 is a hardware structure block diagram of a mobile terminal of a blockchain-based data desensitization method according to an embodiment of the present invention. As Figure 1 shown, the mobile terminal may include one or more ( Figure 1 only one is shown in Figure 1The structure shown is only illustrative and does not limit the structure of the above-mentioned mobile terminal. For example, the mobile terminal may further include more or fewer components than those shown in Figure 1 or have a different configuration from that shown in Figure 1 .
[0028] The memory 104 can be used to store computer programs. For example, software programs and modules of application software, such as the computer program corresponding to the blockchain-based data desensitization method in the embodiments of the present invention. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, implements the above method. The memory 104 may include a high-speed random access memory and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely set relative to the processor 102, and these remote memories can be connected to the mobile terminal through a network. Examples of the above network include but are not limited to the Internet, enterprise intranet, local area network, mobile communication network, and combinations thereof. The transmission device 106 is used to receive or send data via a network. Specific examples of the above network may include the wireless network provided by the communication provider of the mobile terminal. In one instance, the transmission device 106 includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one instance, the transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0029] In this embodiment, a blockchain-based data desensitization method running on a mobile terminal, a computer terminal, or a similar computing device is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0030] Figure 2 is a flowchart of the blockchain-based data desensitization method according to the embodiments of the present application. As Figure 2 shown, the method includes the following steps:
[0031] Step S201, configure at least an intelligent contract according to a desensitization algorithm and configure the intelligent contract in the blockchain ledger of the blockchain. The desensitization algorithm includes at least one of data de-identification, data replacement, data noise addition, and data obfuscation;
[0032] Specifically, according to specific desensitization algorithms (such as data de-identification, data replacement, data noise addition, and data obfuscation), an intelligent contract is written and configured. The intelligent contract is designed to monitor data transmission on the blockchain and automatically initiate the desensitization process when the data meets the preset contract conditions. For example, the intelligent contract can be set to perform desensitization processing only when the data attributes contain sensitive identifiers. The intelligent contract code is deployed on the blockchain ledger and becomes an immutable part of the blockchain network.
[0033] Step S202, monitor the on-chain data of the blockchain through the intelligent contract. When the on-chain data meets the preset contract conditions of the intelligent contract, desensitize the on-chain data through the intelligent contract to obtain desensitized data;
[0034] Specifically, the intelligent contract continuously monitors data transmission on the blockchain. Once new data is uploaded to the chain, the intelligent contract checks whether the data meets the preset contract conditions, such as data type, data source, etc. If the data contains sensitive information, the intelligent contract will automatically execute the desensitization algorithm to replace, mask, or obfuscate the sensitive data to protect privacy. This process not only improves data security but also ensures the compliance and availability of the data after processing.
[0035] Step S203, perform data verification on the desensitized data through multiple nodes in the blockchain;
[0036] Specifically, the desensitized data is not directly stored but sent to multiple nodes in the blockchain network for verification. Each node checks the desensitization status of the data according to the rules and standards defined in the intelligent contract to ensure that no deviation or error occurs during the data processing process and that the privacy of the data is fully protected. The node verification mechanism enhances the reliability and security of data verification, ensuring data quality and the transparency of the data processing process.
[0037] Step S204, encrypt and store the desensitized data through the blockchain in the case where the data verification passes.
[0038] Specifically, when the desensitized data passes the multi-node verification, the intelligent contract will use the key generated by the privacy key management system to encrypt the data. The encrypted data is stored on the blockchain ledger, leveraging the encryption characteristics and immutability of the blockchain to ensure the security and integrity of the data. At the same time, the decentralized nature of the blockchain means that the data is not concentrated in the hands of a single entity, reducing the risk of a centralized attack on the data.
[0039] It is understandable that this application utilizes the three core features of blockchain technology - decentralization, encryption security, and immutability - to provide a solid underlying architecture for data privacy desensitization. Through smart contracts, these features can be programmatically implemented. A smart contract is an automatically executable protocol that runs on a blockchain and can process data according to preset rules. The combination of smart contracts and blockchain enables the data desensitization process to be carried out in an automated manner, while ensuring the transparency and consistency of data processing, reducing human intervention, and lowering the risk of data leakage.
[0040] Through this embodiment, first, at least configure a smart contract according to a desensitization algorithm and configure the smart contract in the blockchain ledger of the blockchain. The desensitization algorithm includes at least one of data de-identification, data replacement, data adding noise, and data obfuscation; then, monitor the on-chain data of the blockchain through the smart contract. When the on-chain data meets the preset contract conditions of the smart contract, desensitize the on-chain data through the smart contract to obtain desensitized data; after that, verify the desensitized data through multiple nodes in the blockchain; finally, when the data verification is passed, encrypt and store the desensitized data through the blockchain. This application desensitizes the data to be desensitized based on the smart contract configured on the decentralized system of the blockchain, avoiding the data leakage caused by the easy attack of the centralized system for desensitization, verifying the quality of the desensitized data through multiple nodes, ensuring the transparency and credibility of data processing, and encrypting and storing the desensitized data through the blockchain, solving the problem of low security and credibility in the data desensitization process based on the centralized system in the prior art.
[0041] To facilitate the monitoring of the operation process of the desensitized data, in an optional implementation manner, after desensitizing the on-chain data through the smart contract to obtain desensitized data, the above method further includes:
[0042] Step S301, when the desensitization process is completed, trigger a preset event through the event mechanism of the smart contract. The preset event is used to record the ID of the desensitized data, the processing steps of the desensitization process, and the desensitization time;
[0043] Specifically, after the smart contract completes the data desensitization process, the event mechanism inside the contract is triggered to generate a preset event. This event includes the unique ID of the desensitized data, the executed desensitization processing steps (such as data de-identification, data adding noise, etc.), and the timestamp of the desensitization process. This information will be permanently recorded on the blockchain, providing an immutable desensitization processing history record.
[0044] Step S302, when the preset event is triggered, configure the event parameters of the preset event. The event parameters include the data visitor address, the accessed data ID, and the access time;
[0045] Specifically, when a preset event is triggered, the smart contract configures event parameters, including the blockchain address of the data visitor, the ID of the accessed data, and the access time. These parameters are designed to be automatically filled when the event is triggered, ensuring the timeliness and accuracy of the information.
[0046] Step S303: Broadcast the preset event to the first preset node of the blockchain. The first preset node is used to generate an audit log based on the preset event for the staff to monitor the desensitization process.
[0047] Specifically, the smart contract broadcasts this event to the first preset node in the blockchain network. This node is a dedicated node for data auditing and monitoring, or a group of nodes in the network. After receiving the event broadcast, the first preset node generates a detailed audit log based on the event parameters. The audit log not only records the detailed information of data access and desensitization processing, but also includes the triggering background and results of the event. The staff can access the audit log to monitor the data desensitization process in real time and conduct post-event audits to ensure that the data processing complies with privacy protection policies and compliance requirements.
[0048] It can be understood that as a self-executing program, the smart contract can automatically execute predefined rules and processes on the chain. The event mechanism of the smart contract allows events to be automatically triggered and recorded when specific changes occur in the contract state. These events can contain key information during the contract execution process, such as the executor, timestamp, execution result, etc. By combining the smart contract with the event mechanism, automated monitoring and logging of data desensitization processing can be achieved, thereby enhancing the transparency and audibility of the entire system.
[0049] Through the above embodiments, each step of the desensitization process is recorded through the smart contract event mechanism, improving the transparency of the data processing process, facilitating the staff to conduct real-time monitoring and post-event audits, and ensuring that the data processing complies with privacy protection policies and compliance requirements. Since the event parameters and audit logs are stored on the blockchain, they are immutable and highly secure, which provides additional protection for the security of data desensitization processing and reduces the risk of data being illegally tampered with or misused. The event mechanism of the smart contract automatically triggers and records desensitization processing information without manual intervention, accelerating the event response speed and improving the data processing efficiency. The detailed information in the audit log, including the address and access time of the data visitor, helps to trace the responsibility for data access and processing. Once a data breach or abnormal access occurs, the problem can be quickly located and measures can be taken.
[0050] To ensure the transparency of the desensitized data, in an alternative embodiment, the above step S203 includes:
[0051] Step S2031: Split the de-identified data into multiple first target data according to the target quantity through a smart contract, and perform hashing on each first target data to obtain second target data;
[0052] Specifically, when the smart contract receives the de-identified data, it first splits it into multiple first target data according to a preset target quantity. Perform hashing on each first target data to generate its corresponding second target data (hash value). This process ensures the uniqueness and irreversibility of the data block. Even if the data is split, its consistency can be confirmed through the hash value.
[0053] Step S2032: Upload the second target data to the blockchain through the smart contract and initiate a transaction broadcast through the blockchain network. The transaction broadcast is used to instruct the nodes in the blockchain to perform local data verification respectively according to the received second target data;
[0054] Specifically, the smart contract uploads the second target data to the blockchain and initiates a transaction broadcast, inviting the nodes in the network to participate in the verification of the local data. After the nodes in the blockchain receive the broadcast second target data, they check the accuracy and consistency of the data according to the verification rules in the smart contract. It can be understood that each node verifies one second target data.
[0055] Step S2033: In response to the feedback information sent by the nodes in the blockchain, when all the feedback information indicates verification passed, obtain the verification results of each node in the blockchain through the smart contract, and perform complete data verification according to all the verification results to obtain a comprehensive verification score;
[0056] Specifically, when all nodes complete the local data verification and feedback the verification results, the smart contract aggregates these results to perform complete data verification to ensure that the de-identified data as a whole has not been tampered with or lost. According to the verification results of all nodes, the smart contract calculates a comprehensive verification score, which reflects the overall accuracy and security of the data.
[0057] Step S2034: When the comprehensive verification score is greater than the first threshold, perform integrity verification and security verification on the de-identified data through the smart contract. When both the integrity verification and the security verification pass, determine that the data verification of the de-identified data has passed.
[0058] Specifically, when the comprehensive verification score exceeds the preset first threshold, the smart contract performs further data integrity verification and security verification, which includes checking whether the structure of the data is complete and whether the data encryption process meets the security standards. Only when both of these verifications pass, the smart contract will confirm that the data verification of the de-identified data has passed and allow encrypted storage.
[0059] It is understandable that the core advantages of blockchain technology lie in its distributed ledger and consensus mechanism, which enable multiple nodes in the network to jointly verify transactions and form a transparent and tamper-proof data processing environment. During the data verification process, smart contracts utilize these characteristics of the blockchain to broadcast the results of data segmentation, encryption, and hashing, allowing nodes in the network to participate in data verification. Local data verification ensures the accuracy and consistency of the data, while complete data verification further confirms the overall integrity and security of the data to ensure the quality and compliance of data desensitization processing.
[0060] Through the above embodiments, the combination of data segmentation and hashing processing with the immutability of the blockchain enhances the security of data during transmission and storage. Local data verification by multiple nodes ensures the transparency and consistency of data processing, avoiding the risks of data tampering and single-point failures that may occur in a centralized system. Complete data verification and the comprehensive verification scoring mechanism further verify the overall quality and compliance of the data, ensuring that sensitive information is fully protected during the data desensitization process while retaining the statistical value and structural integrity of transaction data.
[0061] In order to perform suitable segmentation on the desensitized data while ensuring efficiency, transparency, and consistency, in an alternative embodiment, before the desensitized data is segmented into the target number through a smart contract, the method further includes:
[0062] Step S401, determining the sensitivity score of the desensitized data based on the original on-chain data of the desensitized data;
[0063] Specifically, the smart contract first analyzes the attributes of the on-chain data, such as data type, data source, data content, etc., and calculates the sensitivity score of the desensitized data in combination with preset scoring rules. The scoring rules may include the detection of highly sensitive information such as names, ID numbers, phone numbers, etc., and the sensitivity assessment of other data fields.
[0064] Step S402, determining the security level of the desensitized data based on the sensitivity score, and determining the target number corresponding to the desensitized data according to the security level.
[0065] Specifically, according to the sensitivity score, the smart contract divides the data security level into different levels, such as low, medium, and high. Each security level corresponds to different data protection policies. The higher the security level of the data, the stricter the protection policy. After the security level is determined, the smart contract determines the target number of data segments according to the preset policy. For example, for highly sensitive data, the smart contract may divide it into more small pieces, with less data in each piece, to reduce the concentration of sensitive information. For low-sensitivity data, it may be divided into fewer but larger data blocks to improve the efficiency of data processing while protecting privacy.
[0066] It can be understood that this application introduces a sensitivity scoring mechanism as a prerequisite for data segmentation, aiming to dynamically adjust the data security processing strategy according to the sensitivity of the data. The sensitivity score is calculated by analyzing the attributes of the data and the potential privacy leakage risk. This score is used to determine the security level of the data. The higher the security level, the more sensitive the data, and the more stringent the protection measures are required. Determining the target number of data segments based on the security level, that is, the size and number of data blocks, can ensure that sensitive data is more carefully protected during data transmission and storage, reducing the risk of privacy leakage caused by overly large data blocks.
[0067] To ensure the security of data storage, in an optional implementation manner, the above step S204 includes:
[0068] Step S2041, encrypt the desensitized data with the private key of the data holder of the desensitized data and encrypt it with the common network key of the nodes participating in the verification to obtain the target encrypted data;
[0069] Specifically, after the data desensitization process is completed, the smart contract will initially encrypt the desensitized data with the private key of the data holder. Private key encryption ensures that only the data holder (the entity with the corresponding public key) can decrypt and access the original data, improving the security and privacy of the data. The data encrypted with the private key is then encrypted a second time with the common network key generated jointly by multiple nodes in the blockchain network. The use of the common network key increases the security level of the data. Even if the private key is leaked, the data is still protected by the common network key, and only the nodes in the network can decrypt the data, and these nodes need to comply with strict access control policies, further enhancing the security guarantee of the data.
[0070] Step S2042, store the public keys of the private key and the common network key in the blockchain.
[0071] Specifically, to ensure the decryptability of data, the public key of the data holder, together with the public key of the shared network key, is stored on the blockchain ledger. The storage of the public key is public, but the security of the encryption process depends on the strict protection of the private key, as well as the dynamic generation and management of the shared network key.
[0072] It can be understood that this application utilizes the concepts of public key encryption and shared network key to ensure the security and privacy of the de-identified data stored in the blockchain. Public key encryption is an asymmetric encryption technology where the data holder uses their own private key to encrypt the data, and the data can only be decrypted using the public key corresponding to that private key. The shared network key is a symmetric encryption technology jointly generated by the blockchain nodes participating in data verification and is used to perform secondary encryption on the already encrypted data, adding an extra layer of data security.
[0073] Through the above embodiments, with the dual protection mechanism of private key encryption and shared network key encryption, the privacy and security of data during storage and transmission are ensured, reducing the risk of data leakage. The public key is stored on the blockchain ledger, facilitating the access control module to restrict access to the target encrypted data based on user permissions and identities, ensuring that only authorized users can decrypt and access the data. Although the dual encryption increases the data security, due to the use of the shared network key, the data decryption process remains relatively efficient, avoiding processing delays caused by over-encryption.
[0074] To ensure the security of data storage, in an alternative embodiment, the above step S204 further includes:
[0075] Step S2043, storing the encrypted de-identified data in the blockchain ledger of the blockchain, where each node stores a partial data of the encrypted de-identified data.
[0076] Specifically, the encrypted de-identified data is split into multiple data segments, and these segments are respectively stored on multiple nodes of the blockchain network. Each node only stores a part of the entire dataset, rather than the whole, which increases the dispersion and security of the data. Even if some nodes are attacked or the data is leaked, the attacker cannot obtain the complete dataset, thus reducing the risk of data leakage.
[0077] It can be understood that to further enhance the privacy of the data, the data segments stored on each node may contain different information, or the data segments stored on different nodes may be encrypted differently. In this way, even if an attacker can access multiple nodes, it is difficult to recombine the scattered data segments into meaningful information, thereby increasing the difficulty of data privacy protection.
[0078] Furthermore, the data storage on the blockchain of this application follows a consensus mechanism. Only when the majority of nodes in the network verify and agree on the data fragments to be stored will the data be officially written into the blockchain ledger. This mechanism ensures the accuracy and consistency of the data, avoiding data tampering during transmission or storage.
[0079] Through the above embodiments, by storing the encrypted desensitized data distributively on multiple nodes in the network, the privacy protection of the data is significantly enhanced. Even if some data is leaked, the complete dataset cannot be reconstructed, thereby reducing the risk of data leakage. The combination of the distributed storage mechanism and the blockchain consensus algorithm improves the fault tolerance and security of the data, reducing the possibility of data tampering or loss. The data is segmented into multiple fragments, reducing the storage pressure on a single node and improving the efficiency of data storage.
[0080] To restrict users' access to desensitized data, in an optional embodiment, after encrypting and storing the desensitized data through the blockchain, the above method further includes:
[0081] Step S501, in response to an access request initiated by a node, access the digital identity system of the blockchain through a smart contract to obtain the target digital identity corresponding to the node. The digital identity system is used to store the digital identities of each node in the blockchain;
[0082] Specifically, when a node in the blockchain initiates an access request, the smart contract first responds and accesses the digital identity system to obtain the target digital identity of the requesting node. The digital identity system stores the permission information of the node, including the data range allowed to be browsed.
[0083] Step S502, determine the allowed browsing range of the node according to the target digital identity, and determine the current browsing range of the node according to the access request;
[0084] Step S503, determine the absolute value of the browsing deviation of the node according to the current browsing range and the allowed browsing range;
[0085] Specifically, according to the target digital identity, the smart contract determines the allowed browsing range of the node. At the same time, the smart contract analyzes the access request to determine the current browsing range of the node. The absolute value of the difference between the two is the absolute value of the browsing deviation.
[0086] Step S504, when the absolute value of the browsing deviation is less than or equal to the second threshold, allow the node to access the desensitized data;
[0087] Step S505, when the absolute value of the browsing deviation is greater than the second threshold and the current browsing range is less than the allowed browsing range, allow the node to access the desensitized data;
[0088] Step S506, when the absolute value of the browsing deviation is greater than the second threshold and the current browsing range is greater than the allowed browsing range, determine that there is an illegal access behavior for the node;
[0089] Step S507, obtain the access frequency of the illegal access behavior of the node within a preset period and the single browsing duration of each access;
[0090] Specifically, when the absolute value of the browsing deviation is greater than the second threshold, the smart contract further checks the relationship between the current browsing range and the allowed browsing range. If the current browsing range is greater than the allowed browsing range, the smart contract determines that there is an illegal access behavior for the node. The system will record this access behavior, including the frequency of illegal access and the single browsing duration of each access.
[0091] Step S508, when the single browsing duration is greater than the third threshold, determine the illegal access behavior as a non-misoperation; when the single browsing duration is less than or equal to the third threshold, determine the illegal access behavior as a misoperation;
[0092] Specifically, according to the comparison between the single browsing duration and the third threshold, the smart contract classifies the illegal access behavior as a misoperation or a non-misoperation. A misoperation usually refers to an act of inadvertently exceeding the allowed browsing range within a short period of time; a non-misoperation refers to a purposeful and long-term illegal access.
[0093] Step S509, when the ratio of the frequency of misoperations to the access frequency within a preset period is greater than the fourth threshold, send a target warning message to the node, and the target warning message indicates that the node has a locking risk;
[0094] The system determines whether the node has a locking risk according to the ratio of the frequency of misoperations to the total access frequency (the fourth threshold) within a preset period.
[0095] Step S510, calculate a locking score according to the frequency of misoperations, the access frequency, and the total browsing duration of misoperations within a preset period, and when the locking score is greater than the fifth threshold, lock the permissions of the node.
[0096] Specifically, if the locking score (calculated based on the frequency of misoperations, the total access frequency, and the total browsing duration of misoperations) is greater than the fifth threshold, the system will lock the permissions of the node to prevent further illegal access.
[0097] It can be understood that a dynamic and secure data access control mechanism is constructed by using the digital identity system and smart contracts in blockchain technology. The digital identity system stores the digital identity information of each node in the network, including the permission level, browsing scope, etc. of the node. The smart contract can dynamically determine whether the access to data by a node is legal and whether there is a risk of illegal access behavior according to the digital identity of the node. By introducing the absolute value of browsing deviation and multiple thresholds (the second to fifth thresholds), the system can intelligently evaluate the access behavior of nodes to ensure the compliance and security of data access.
[0098] Through the above embodiments, through the dynamic data access control mechanism, illegal access behaviors can be detected and classified in a timely manner, and corresponding measures can be taken to prevent further violations. At the same time, the permission locking mechanism provides additional protection for data security, reduces the risk of data leakage, and enhances the compliance and transparency of data management. The combination of the smart contract and the digital identity system realizes automated and intelligent data access management, improving the efficiency and security of data use.
[0099] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0100] The embodiment of the present application also provides a blockchain-based data desensitization device. It should be noted that the blockchain-based data desensitization device of the embodiment of the present application can be used to execute the blockchain-based data desensitization method provided by the embodiment of the present application. This device is used to implement the above embodiments and preferred implementation manners, and those that have been described will not be repeated. As used below, the term "module" can be a combination of software and / or hardware that can achieve a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.
[0101] The following introduces the blockchain-based data desensitization device provided by the embodiment of the present application.
[0102] Figure 3 is a structural block diagram of a blockchain-based data desensitization device according to an embodiment of the present application. As Figure 3 shown, the device includes:
[0103] A control unit 10, configured to configure a smart contract at least according to a desensitization algorithm and configure the smart contract in the blockchain ledger of the blockchain, where the desensitization algorithm includes at least one of data de-identification, data replacement, data noise addition, and data obfuscation;
[0104] Specifically, according to specific data anonymization algorithms (such as data de-identification, data replacement, data noise addition, and data obfuscation), smart contracts are written and configured. The smart contract is designed to monitor data transmission on the blockchain and automatically initiate the data anonymization process when the data meets the preset contract conditions. For example, the smart contract can be set to perform anonymization processing only when the data attributes contain sensitive identifiers. The smart contract code is deployed on the blockchain ledger and becomes an immutable part of the blockchain network.
[0105] The first processing unit 20 is used to monitor the on-chain data of the blockchain through the smart contract, and when the on-chain data meets the preset contract conditions of the smart contract, perform data anonymization processing on the on-chain data through the smart contract to obtain anonymized data;
[0106] Specifically, the smart contract continuously monitors data transmission on the blockchain. Once new data is uploaded to the chain, the smart contract checks whether the data meets the preset contract conditions, such as data type, data source, etc. If the data contains sensitive information, the smart contract will automatically execute the anonymization algorithm to replace, mask, or obfuscate the sensitive data to protect privacy. This process not only improves the security of the data but also ensures the compliance and availability of the data after processing.
[0107] The verification unit 30 is used to perform data verification on the anonymized data through multiple nodes in the blockchain;
[0108] Specifically, the anonymized data is not directly stored but sent to multiple nodes in the blockchain network for verification. Each node will check the anonymization status of the data according to the rules and standards defined in the smart contract to ensure that no deviation or error occurs during the data processing process and that the privacy of the data is fully protected. The node verification mechanism enhances the reliability and security of data verification and ensures the data quality and transparency of the data processing process.
[0109] The storage unit 40 is used to encrypt and store the anonymized data through the blockchain when the data verification is passed.
[0110] Specifically, when the anonymized data passes the multi-node verification, the smart contract will use the key generated by the privacy key management system to encrypt the data. The encrypted data is stored on the blockchain ledger, leveraging the encryption characteristics and immutability of the blockchain to ensure the security and integrity of the data. At the same time, the decentralized nature of the blockchain means that the data is not concentrated in the hands of a single entity, reducing the risk of a centralized attack on the data.
[0111] It is understandable that this application utilizes the three core features of blockchain technology - decentralization, encryption security, and immutability - to provide a solid underlying architecture for data privacy desensitization. Through smart contracts, these features can be programmatically implemented. A smart contract is an automatically executable protocol that runs on a blockchain and can process data according to preset rules. The combination of smart contracts and blockchain enables the data desensitization process to be carried out in an automated manner, while ensuring the transparency and consistency of data processing, reducing human intervention, and lowering the risk of data leakage.
[0112] Through this embodiment, the control unit configures at least a smart contract according to a desensitization algorithm and configures the smart contract in the blockchain ledger of the blockchain. The desensitization algorithm includes at least one of data de-identification, data replacement, data noise addition, and data obfuscation; the first processing unit monitors the on-chain data of the blockchain through the smart contract, and when the on-chain data meets the preset contract conditions of the smart contract, desensitizes the on-chain data through the smart contract to obtain desensitized data; the verification unit verifies the desensitized data through multiple nodes in the blockchain; the storage unit encrypts and stores the desensitized data through the blockchain when the data verification is passed. This application desensitizes the data to be desensitized based on the smart contract configured on the decentralized system of the blockchain, avoiding the data leakage caused by the easy attack of the centralized system for desensitization, verifying the quality of the desensitized data through multiple nodes, ensuring the transparency and credibility of data processing, and encrypting and storing the desensitized data through the blockchain, solving the problem of low security and credibility of data desensitization processing based on the centralized system in the prior art.
[0113] To facilitate the monitoring of the operation process of the desensitized data, in an optional implementation manner, the above device further includes:
[0114] The first monitoring unit is configured to, after desensitizing the on-chain data through the smart contract to obtain desensitized data, trigger a preset event through the event mechanism of the smart contract when the desensitization process is completed. The preset event is used to record the ID of the desensitized data, the processing steps of the desensitization process, and the desensitization time;
[0115] Specifically, after the smart contract completes the data desensitization process, the event mechanism inside the contract is triggered to generate a preset event, which includes the unique ID of the desensitized data, the executed desensitization processing steps (such as data de-identification, data noise addition, etc.), and the timestamp of the desensitization process. These information will be permanently recorded on the blockchain, providing an immutable desensitization processing history record.
[0116] The second processing unit is configured to configure the event parameters of the preset event when the preset event is triggered. The event parameters include the data visitor address, the accessed data ID, and the access time;
[0117] Specifically, when a preset event is triggered, the smart contract configures event parameters, including the blockchain address of the data visitor, the ID of the accessed data, and the access time. These parameters are designed to be automatically filled when the event is triggered, ensuring the timeliness and accuracy of the information.
[0118] A first sending unit is used to broadcast the preset event to a first preset node of the blockchain. The first preset node is used to generate an audit log based on the preset event for the staff to monitor the desensitization process.
[0119] Specifically, the smart contract broadcasts this event to the first preset node in the blockchain network. This node is a node dedicated to data auditing and monitoring, or a group of nodes in the network. After receiving the event broadcast, the first preset node generates a detailed audit log based on the event parameters. The audit log not only records the detailed information of data access and desensitization processing, but also includes the triggering background and results of the event. The staff can access the audit log to monitor the data desensitization process in real time and conduct post-event audits to ensure that the data processing complies with privacy protection policies and compliance requirements.
[0120] It can be understood that as a self-executing program, the smart contract can automatically execute predefined rules and processes on the chain. The event mechanism of the smart contract allows events to be automatically triggered and recorded when specific changes occur in the contract state. These events can contain key information during the contract execution process, such as the executor, timestamp, execution result, etc. By combining the smart contract with the event mechanism, automated monitoring and logging of data desensitization processing can be achieved, thereby enhancing the transparency and audibility of the entire system.
[0121] Through the above embodiments, each step of the desensitization process is recorded through the smart contract event mechanism, improving the transparency of the data processing process, facilitating the staff to conduct real-time monitoring and post-event audits, and ensuring that the data processing complies with privacy protection policies and compliance requirements. Since the event parameters and audit logs are stored on the blockchain, they have the characteristics of non-tamperability and high security, which provides additional guarantee for the security of data desensitization processing and reduces the risk of data being illegally tampered with or misused. The event mechanism of the smart contract automatically triggers and records desensitization processing information without manual intervention, accelerating the event response speed and improving the data processing efficiency. The detailed information in the audit log, including the address and access time of the data visitor, helps to trace the responsibility of data access and processing. Once a data leak or abnormal access occurs, the problem can be quickly located and measures can be taken.
[0122] To ensure the transparency of the desensitized data, in an alternative embodiment, the above verification unit includes:
[0123] The first processing module is used to divide the desensitized data into multiple first target data according to the target quantity through a smart contract, and perform hashing processing on each first target data to obtain second target data;
[0124] Specifically, when the smart contract receives the desensitized data, it first divides it into multiple first target data according to the preset target quantity. Perform hashing processing on each first target data to generate its corresponding second target data (hash value). This process ensures the uniqueness and irreversibility of the data block. Even if the data is divided, its consistency can be confirmed through the hash value.
[0125] The first sending module is used to upload the second target data to the blockchain through a smart contract and initiate a transaction broadcast through the blockchain network. The transaction broadcast is used to instruct the nodes in the blockchain to perform local data verification respectively according to the received second target data;
[0126] Specifically, the smart contract uploads the second target data to the blockchain and initiates a transaction broadcast, inviting the nodes in the network to participate in the verification of the local data. After receiving the broadcast second target data, the nodes of the blockchain check the accuracy and consistency of the data according to the verification rules in the smart contract. It can be understood that each node verifies a second target data.
[0127] The second processing module is used to, in response to the feedback information sent by the nodes of the blockchain, when all the feedback information is verified to pass, obtain the verification results of each node of the blockchain through the smart contract, and perform complete data verification according to all the verification results to obtain a comprehensive verification score;
[0128] Specifically, when all nodes complete the local data verification and feedback the verification results, the smart contract aggregates these results and performs complete data verification to ensure that the desensitized data as a whole has not been tampered with or lost. According to the verification results of all nodes, the smart contract calculates a comprehensive verification score, which reflects the overall accuracy and security of the data.
[0129] The third processing module is used to, when the comprehensive verification score is greater than the first threshold, perform integrity verification and security verification on the desensitized data through the smart contract. When both the integrity verification and the security verification pass, it is determined that the data verification of the desensitized data passes.
[0130] Specifically, when the comprehensive verification score exceeds the preset first threshold, the smart contract performs further data integrity verification and security verification, which includes checking whether the structure of the data is complete and whether the data encryption process meets the security standards. Only when both of these verifications pass, the smart contract will confirm that the data verification of the desensitized data has passed and allow encrypted storage.
[0131] It is understandable that the core advantages of blockchain technology lie in its distributed ledger and consensus mechanism, which enable multiple nodes in the network to jointly verify transactions and form a transparent and tamper-proof data processing environment. During the data verification process, smart contracts utilize these characteristics of the blockchain to broadcast the results of data segmentation, encryption, and hashing, allowing nodes in the network to participate in data verification. Local data verification ensures the accuracy and consistency of data, while complete data verification further confirms the overall integrity and security of the data to ensure the quality and compliance of data desensitization processing.
[0132] Through the above embodiments, the combination of data segmentation and hashing processing with the immutability of the blockchain enhances the security of data during transmission and storage. Local data verification by multiple nodes ensures the transparency and consistency of data processing, avoiding the risks of data tampering and single-point failures that may occur in a centralized system. Complete data verification and the comprehensive verification scoring mechanism further verify the overall quality and compliance of the data, ensuring that sensitive information is fully protected while retaining the statistical value and structural integrity of transaction data during the data desensitization process.
[0133] To perform suitable segmentation on the desensitized data while ensuring efficiency, transparency, and consistency, the above device further includes:
[0134] A first determination unit, which in an alternative embodiment, before segmenting the desensitized data into a target number through a smart contract, determines the sensitivity score of the desensitized data based on the original on-chain data of the desensitized data.
[0135] Specifically, the smart contract first analyzes the attributes of the on-chain data, such as data type, data source, data content, etc., and calculates the sensitivity score of the desensitized data in combination with preset scoring rules. The scoring rules may include the detection of highly sensitive information such as names, ID numbers, phone numbers, etc., and the sensitivity assessment of other data fields.
[0136] A second determination unit, which determines the security level of the desensitized data based on the sensitivity score and determines the target number corresponding to the desensitized data according to the security level.
[0137] Specifically, according to the sensitivity score, the smart contract divides the data security level into different levels, such as low, medium, and high. Each security level corresponds to different data protection policies, and the higher the security level of the data, the stricter the protection policy. After the security level is determined, the smart contract determines the target number of data segments according to the preset policy. For example, for highly sensitive data, the smart contract may divide it into more smaller pieces, with less data in each piece, to reduce the concentration of sensitive information. For low-sensitivity data, it may be divided into fewer but larger data blocks to improve the efficiency of data processing while protecting privacy.
[0138] It can be understood that this application introduces a sensitivity scoring mechanism as a prerequisite for data segmentation, aiming to dynamically adjust the data security processing strategy according to the sensitivity of the data. The sensitivity score is calculated by analyzing the attributes of the data and the potential privacy leakage risk, and this score is used to determine the security level of the data. The higher the security level, the more sensitive the data, and more stringent protection measures are required. Determining the target number of data segments based on the security level, that is, the size and number of data blocks, can ensure that sensitive data is more carefully protected during data transmission and storage, reducing the privacy leakage risk caused by overly large data blocks.
[0139] To ensure the security of data storage, in an optional implementation, the above storage unit includes:
[0140] A fourth processing module, configured to encrypt the desensitized data with the private key of the data holder of the desensitized data and encrypt it with the common network key of the nodes participating in the verification to obtain the target encrypted data;
[0141] Specifically, after the data desensitization process is completed, the smart contract will use the private key of the data holder to initially encrypt the desensitized data. Encryption with the private key ensures that only the data holder (the entity with the corresponding public key) can decrypt and access the original data, improving the security and privacy of the data. The data encrypted with the private key is then encrypted a second time using the common network key generated jointly by multiple nodes in the blockchain network. The use of the common network key increases the security level of the data. Even if the private key is leaked, the data is still protected by the common network key, and only the nodes in the network can decrypt the data, and these nodes need to comply with strict access control policies, further enhancing the security guarantee of the data.
[0142] A first storage module, configured to store the private key and the public key of the common network key in the blockchain.
[0143] Specifically, to ensure the decryptability of data, the public key of the data holder, together with the public key of the shared network key, is stored on the blockchain ledger. The storage of the public key is public, but the security of the encryption process depends on the strict protection of the private key, as well as the dynamic generation and management of the shared network key.
[0144] It can be understood that this application utilizes the concepts of public key encryption and shared network key to ensure the security and privacy of the de-identified data stored in the blockchain. Public key encryption is an asymmetric encryption technology where the data holder uses their private key to encrypt the data, and the data can only be decrypted using the corresponding public key. The shared network key is a symmetric encryption technology jointly generated by the blockchain nodes participating in data verification, which is used to perform secondary encryption on the already encrypted data, adding an extra layer of data security.
[0145] Through the above embodiments, with the dual protection mechanism of private key encryption and shared network key encryption, the privacy and security of data during storage and transmission are ensured, reducing the risk of data leakage. The public key is stored on the blockchain ledger, facilitating the access control module to restrict access to the target encrypted data based on user permissions and identities, ensuring that only authorized users can decrypt and access the data. Although the dual encryption increases the security of the data, due to the use of the shared network key, the data decryption process remains relatively efficient, avoiding processing delays caused by over-encryption.
[0146] To ensure the security of data storage, in an alternative embodiment, the above storage unit further includes:
[0147] A second storage module for storing the encrypted de-identified data in the blockchain ledger of the blockchain, where each node stores a partial data of the encrypted de-identified data.
[0148] Specifically, the encrypted de-identified data is split into multiple data segments, which are respectively stored on multiple nodes of the blockchain network. Each node only stores a part of the entire dataset, rather than the whole, which increases the dispersion and security of the data. Even if some nodes are attacked or the data is leaked, the attacker cannot obtain the complete dataset, thus reducing the risk of data leakage.
[0149] It can be understood that to further enhance the privacy of the data, the data segments stored on each node may contain different information, or the data segments stored on different nodes may be encrypted differently. In this way, even if an attacker can access multiple nodes, it is difficult to recombine the scattered data segments into meaningful information, thereby increasing the difficulty of data privacy protection.
[0150] Furthermore, the data storage on the blockchain of this application follows a consensus mechanism. Only when the majority of nodes in the network verify and agree on the data fragments to be stored will the data be officially written into the blockchain ledger. This mechanism ensures the accuracy and consistency of the data, preventing the data from being tampered with during transmission or storage.
[0151] Through the above embodiments, by distributing and storing the encrypted desensitized data on multiple nodes in the network, the privacy protection of the data is significantly enhanced. Even if some data is leaked, the complete dataset cannot be reconstructed, thereby reducing the risk of data leakage. The combination of the distributed storage mechanism and the blockchain consensus algorithm improves the fault tolerance and security of the data, reducing the possibility of data being tampered with or lost. The data is segmented into multiple fragments, reducing the storage pressure on a single node and improving the efficiency of data storage.
[0152] To restrict users' access to desensitized data, in an alternative embodiment, the above device further includes:
[0153] An access unit, configured to, after encrypting and storing the desensitized data through the blockchain, in response to an access request initiated by a node, access the digital identity system of the blockchain through a smart contract to obtain the target digital identity corresponding to the node, where the digital identity system is used to store the digital identities of each node in the blockchain;
[0154] Specifically, when a node in the blockchain initiates an access request, the smart contract first responds and accesses the digital identity system to obtain the target digital identity of the requesting node. The digital identity system stores the permission information of the node, including the data range allowed to be browsed.
[0155] A third determination unit, configured to determine the allowed browsing range of the node according to the target digital identity and determine the current browsing range of the node according to the access request;
[0156] A fourth determination unit, configured to determine the absolute value of the browsing deviation of the node according to the current browsing range and the allowed browsing range;
[0157] Specifically, according to the target digital identity, the smart contract determines the allowed browsing range of the node. At the same time, the smart contract analyzes the access request to determine the current browsing range of the node. The absolute value of the difference between the two is the absolute value of the browsing deviation.
[0158] A second monitoring unit, configured to allow the node to access the desensitized data when the absolute value of the browsing deviation is less than or equal to a second threshold;
[0159] A third monitoring unit, configured to allow the node to access the desensitized data when the absolute value of the browsing deviation is greater than the second threshold and the current browsing range is less than the allowed browsing range;
[0160] A fifth determination unit, configured to determine that there is an illegal access behavior of the node when the absolute value of the browsing deviation is greater than a second threshold and the current browsing range is greater than the allowed browsing range;
[0161] A fourth monitoring unit, configured to obtain the access frequency of the illegal access behavior of the node within a preset period and the single browsing duration of each access;
[0162] Specifically, when the absolute value of the browsing deviation is greater than the second threshold, the smart contract further checks the relationship between the current browsing range and the allowed browsing range. If the current browsing range is greater than the allowed browsing range, the smart contract determines that there is an illegal access behavior of the node. The system will record this access behavior, including the frequency of illegal access and the single browsing duration of each access.
[0163] A sixth determination unit, configured to determine the illegal access behavior as a non-misoperation when the single browsing duration is greater than a third threshold, and determine the illegal access behavior as a misoperation when the single browsing duration is less than or equal to the third threshold;
[0164] Specifically, according to the comparison between the single browsing duration and the third threshold, the smart contract classifies the illegal access behavior as a misoperation or a non-misoperation. A misoperation usually refers to an act of inadvertently exceeding the allowed browsing range within a short period of time; a non-misoperation refers to a purposeful and long-term illegal access.
[0165] A second sending unit, configured to send a target warning message to the node when the ratio of the frequency of misoperations to the access frequency within a preset period is greater than a fourth threshold, where the target warning message indicates that the node has a locking risk;
[0166] The system determines whether the node has a locking risk according to the ratio (the fourth threshold) of the frequency of misoperations to the total access frequency within a preset period.
[0167] A fifth monitoring unit, configured to calculate a locking score according to the frequency of misoperations, the access frequency, and the total browsing duration of misoperations within a preset period, and lock the permissions of the node when the locking score is greater than a fifth threshold.
[0168] Specifically, if the locking score (calculated based on the frequency of misoperations, the total access frequency, and the total browsing duration of misoperations) is greater than the fifth threshold, the system will lock the permissions of the node to prevent further illegal access.
[0169] It can be understood that by using the digital identity system and smart contracts in blockchain technology, a dynamic and secure data access control mechanism is constructed. The digital identity system stores the digital identity information of each node in the network, including the permission level, browsing scope, etc. of the node. The smart contract can dynamically determine whether the access of the node to the data is legal and whether there is a risk of illegal access behavior according to the digital identity of the node. By introducing the absolute value of the browsing deviation and multiple thresholds (the second to fifth thresholds), the system can intelligently evaluate the access behavior of the node to ensure the compliance and security of data access.
[0170] Through the above embodiments, through the dynamic data access control mechanism, illegal access behaviors can be detected and classified in a timely manner, and corresponding measures can be taken to prevent further violations. At the same time, the permission locking mechanism provides additional protection for data security, reduces the risk of data leakage, and enhances the compliance and transparency of data management. The combination of the smart contract and the digital identity system realizes automated and intelligent data access management, improving the efficiency and security of data use.
[0171] The above blockchain-based data desensitization device includes a processor and a memory. The above control unit, first processing unit, verification unit, storage unit, etc. are all stored in the memory as program units, and the processor executes the above program units stored in the memory to implement corresponding functions. The above modules are all located in the same processor; or, the above modules are respectively located in different processors in any combination form.
[0172] The processor contains a kernel, and the kernel retrieves the corresponding program units from the memory. One or more kernels can be set, and the security and transparency of data desensitization can be improved by adjusting the kernel parameters.
[0173] The memory may include non-permanent memory in a computer-readable medium, forms such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM), and the memory includes at least one storage chip.
[0174] An embodiment of the present invention provides a computer-readable storage medium. The above computer-readable storage medium includes a stored program, wherein when the above program runs, it controls the device where the above computer-readable storage medium is located to execute the above blockchain-based data desensitization method.
[0175] An embodiment of the present invention provides a processor. The above processor is used to run a program, wherein when the above program runs, it executes the above blockchain-based data desensitization method.
[0176] An embodiment of the present invention provides a data privacy desensitization system. The data privacy desensitization system includes a processor, a memory, and a program stored on the memory and executable on the processor. When the processor executes the program, it implements at least the steps of the above-mentioned blockchain-based data desensitization method.
[0177] This application also provides a computer program product, which is suitable for executing a program initialized with at least the steps of the above-mentioned blockchain-based data desensitization method when executed on a data processing device.
[0178] Obviously, those skilled in the art should understand that the above-mentioned modules or steps of the present invention can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed on a network composed of multiple computing devices. They can be implemented by program codes executable by the computing device. Thus, they can be stored in a storage device and executed by the computing device. And in some cases, the steps shown or described herein can be executed in a different order, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module to be implemented. In this way, the present invention is not limited to any specific combination of hardware and software.
[0179] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.
[0180] This application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one or more of the flows or multiple flows and / or blocks Figure 1 one or more of the blocks or multiple blocks.
[0181] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to operate in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including an instruction means that implements the function specified in one or more of the processes and / or blocks Figure 1 in one or more of the processes and / or blocks Figure 1 specified in the block or blocks.
[0182] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, thereby providing steps for implementing the function specified in one or more of the processes and / or blocks Figure 1 in one or more of the processes and / or blocks Figure 1 specified in the block or blocks.
[0183] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0184] The memory may include non-permanent memory in the computer-readable medium, random access memory (RAM) and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of a computer-readable medium.
[0185] Computer-readable media includes both permanent and non-permanent, removable and non-removable media implemented by any method or technology for storage of information such as computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile discs (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory media such as modulated data signals and carrier waves.
[0186] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, commodity or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, commodity or device comprising the element.
[0187] From the above description, it can be seen that the above embodiments of the present application achieve the following technical effects:
[0188] 1), The blockchain-based data desensitization method of the present application, first, configures a smart contract at least according to a desensitization algorithm and configures the smart contract in the blockchain ledger of the blockchain. The desensitization algorithm includes at least one of data de-identification, data replacement, data noise addition, and data obfuscation; then, the smart contract monitors the on-chain data of the blockchain, and when the on-chain data meets the preset contract conditions of the smart contract, the smart contract performs desensitization processing on the on-chain data to obtain desensitized data; after that, multiple nodes in the blockchain perform data verification on the desensitized data; finally, when the data verification passes, the blockchain encrypts and stores the desensitized data. The present application desensitizes the data to be desensitized through the smart contract configured on the decentralized system of the blockchain, avoiding the data leakage caused by the easy attack of the centralized system for desensitization, and verifying the quality of the desensitized data through multiple nodes to ensure the transparency and credibility of data processing, and encrypting and storing the desensitized data through the blockchain, solving the problem of low security and credibility of data desensitization processing based on the centralized system in the prior art.
[0189] 2) The data desensitization device based on blockchain of the present application, the control unit configures the smart contract at least according to the desensitization algorithm, and configures the smart contract in the blockchain ledger of the blockchain. The desensitization algorithm includes at least one of data de-identification, data replacement, data noise addition, and data obfuscation; the first processing unit listens to the on-chain data of the blockchain through the smart contract, and when the on-chain data meets the preset contract conditions of the smart contract, performs desensitization processing on the on-chain data through the smart contract to obtain desensitized data; the verification unit performs data verification on the desensitized data through multiple nodes in the blockchain; the storage unit encrypts and stores the desensitized data through the blockchain in the case that the data verification is passed. The present application performs desensitization on the data to be desensitized through the smart contract configured on the decentralized system based on blockchain, avoiding the data leakage caused by the easy attack of the centralized system for desensitization, verifying the quality of the desensitized data through multiple nodes, ensuring the transparency and credibility of data processing, and encrypting and storing the desensitized data through the blockchain, solving the problem of low security and credibility of data desensitization processing based on the centralized system in the prior art.
[0190] The foregoing are only the preferred embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.
Claims
1. A data desensitization method based on blockchain, characterized in that: include: At least configuring a smart contract according to a desensitization algorithm, and configuring the smart contract in a blockchain ledger of a blockchain, wherein the desensitization algorithm includes at least one of data de-identification, data replacement, data noise addition, and data obfuscation; Monitoring the on-chain data of the blockchain through the smart contract, and when the on-chain data meets the preset contract conditions of the smart contract, performing desensitization processing on the on-chain data through the smart contract to obtain desensitized data; Performing data verification on the desensitized data through multiple nodes in the blockchain; When the data verification is passed, the desensitized data is encrypted and stored through the blockchain.
2. The method according to claim 1, characterized in that After desensitizing the on-chain data through the smart contract to obtain desensitized data, the method further includes: When the desensitization process is completed, a preset event is triggered through the event mechanism of the smart contract, and the preset event is used to record the ID of the desensitized data, the processing steps of the desensitization process, and the desensitization time; When the preset event is triggered, configure event parameters of the preset event, the event parameters including data accessor address, access data ID and access time; The preset event is broadcast to a first preset node of the blockchain, and the first preset node is used to generate an audit log according to the preset event so that staff can monitor the desensitization process.
3. The method according to claim 1, characterized in that The desensitized data is verified through multiple nodes in the blockchain, including: The desensitized data is divided according to the target quantity through the smart contract to obtain a plurality of first target data, and each of the first target data is hashed to obtain second target data; Uploading the second target data to the blockchain through the smart contract and initiating a transaction broadcast through the blockchain network, wherein the transaction broadcast is used to instruct the nodes in the blockchain to perform local data verification according to the received second target data respectively; In response to the feedback information sent by the node of the blockchain, when all the feedback information is verified, obtaining the verification result of each node of the blockchain through the smart contract, and performing complete data verification according to all the verification results to obtain a comprehensive verification score; When the comprehensive verification score is greater than the first threshold, the smart contract is used to perform integrity verification and security verification on the desensitized data. When both the integrity verification and the security verification are passed, it is determined that the data verification of the desensitized data has passed.
4. The method according to claim 3, characterized in that Before dividing the desensitized data according to the target quantity through the smart contract, the method further includes: Determine a sensitivity score of the desensitized data based on the original on-chain data of the desensitized data; The security level of the desensitized data is determined according to the sensitivity score, and the target quantity corresponding to the desensitized data is determined according to the security level.
5. The method according to claim 1, characterized in that Encrypting the desensitized data through the blockchain includes: The desensitized data is encrypted by using the private key of the data holder of the desensitized data, and is encrypted by using the common network key of the nodes participating in the verification to obtain target encrypted data; The private key and the public key of the common network key are stored in the blockchain.
6. The method according to claim 1, characterized in that Storing the desensitized data through the blockchain includes: The encrypted desensitized data is stored in the blockchain account book of the blockchain, wherein each of the nodes stores part of the encrypted desensitized data.
7. The method according to claim 1, characterized in that After encrypting and storing the desensitized data through the blockchain, the method further includes: In response to an access request initiated by the node, access the digital identity system of the blockchain through the smart contract to obtain a target digital identity corresponding to the node, wherein the digital identity system is used to store the digital identity of each of the nodes in the blockchain; Determining the allowed browsing range of the node according to the target digital identity, and determining the current browsing range of the node according to the access request; Determining an absolute value of a browsing deviation of the node according to the current browsing range and the allowed browsing range; When the absolute value of the browsing deviation is less than or equal to a second threshold, allowing the node to access the desensitized data; When the absolute value of the browsing deviation is greater than the second threshold and the current browsing range is smaller than the allowed browsing range, allowing the node to access the desensitized data; When the browsing deviation absolute value is greater than the second threshold and the current browsing range is greater than the allowed browsing range, it is determined that illegal access behavior exists in the node; Obtain the access frequency of illegal access behaviors of the node within a preset period and the single browsing duration of each access; When the single browsing time is longer than a third threshold, the illegal access behavior is determined as a non-error operation; when the single browsing time is less than or equal to the third threshold, the illegal access behavior is determined as an error operation; When the ratio of the frequency of erroneous operations to the access frequency within the preset period is greater than a fourth threshold, issuing target warning information to the node, the target warning information indicating that the node is at risk of being locked; A locking score is calculated according to the frequency of the erroneous operation, the access frequency and the total browsing time of the erroneous operation within the preset period, and when the locking score is greater than a fifth threshold, the node is locked for permission.
8. A data desensitization device based on blockchain, characterized in that: The device comprises: A control unit, configured to configure a smart contract at least according to a desensitization algorithm, and configure the smart contract in a blockchain ledger of a blockchain, wherein the desensitization algorithm includes at least one of data de-identification, data replacement, data noise addition, and data obfuscation; A first processing unit is configured to monitor the on-chain data of the blockchain through the smart contract, and when the on-chain data meets the preset contract conditions of the smart contract, perform desensitization processing on the on-chain data through the smart contract to obtain desensitized data; A verification unit, used to verify the desensitized data through multiple nodes in the blockchain; A storage unit is used to encrypt and store the desensitized data through the blockchain when the data verification is passed.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored program, wherein when the program is executed, the device where the computer-readable storage medium is located is controlled to execute the method according to any one of claims 1 to 7.
10. A data privacy desensitization system, characterized in that: include: One or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and are configured to be executed by the one or more processors, and the one or more programs include methods for executing any one of claims 1 to 7.