Party building data secure storage and sharing method based on block chain technology
Through multi-layer system architecture design and encryption technology, combined with Corda nodes and IPFS decentralized storage, the security problems in party building data storage and transmission are solved, distributed storage and management of data are realized, and the security and management efficiency of data access are improved.
Patent Information
- Application Number
- CN202510430106.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-07-08
AI Technical Summary
The existing party building data storage methods have the risk of data leakage and tampering, and the security and reliability of data cannot be guaranteed.
The multi-layer system architecture is designed, combined with Corda nodes, IPFS decentralized storage and multi-layer blockchain model, data is encrypted through the Blowfish algorithm and CBC mode, and TLS encrypted transmission is adopted to build role-based access control and PKI identity authentication to ensure the security of data during storage and transmission.
It realizes distributed storage and management of party building data, prevents data leakage and tampering, and improves the security and management efficiency of data access.
Smart Images

Figure CN120281532A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data storage and sharing, and particularly relates to a method for secure storage and sharing of Party building data based on blockchain technology. Background Art
[0002] Party building work is a very important daily work for various grass-roots organizations, organs and other institutions in China. A large amount of Party building data that needs to be kept confidential and / or displayed is generated during the daily process of Party building work. With the development of informatization, the informatization demand for Party building work is increasing day by day. How to securely store and share Party building data has become an important issue.
[0003] Existing Party building data is mostly stored by replacing traditional paper files with centralized electronic files. The centralized electronic files only require a certain amount of storage space and there is no problem of unclear handwriting damage. The sharing of centralized electronic files is very convenient, but the existing data storage method of centralized electronic files has risks such as data leakage and tampering. As a decentralized and tamper-proof distributed ledger technology, blockchain technology provides a new solution for the secure storage and sharing of Party building data.
[0004] Therefore, there is a need for a technical means that can ensure the security and reliability of Party building data during storage and transmission. Summary of the Invention
[0005] The main object of the present invention is to provide a method for secure storage and sharing of Party building data based on blockchain technology, aiming to solve the problems that the Party building data stored and transmitted by existing technical means is prone to data leakage and tampering.
[0006] To achieve the above object, the present invention proposes a method for secure storage and sharing of Party building data based on blockchain technology, the method comprising the following steps:
[0007] Construct a multi-layer system architecture design, the multi-layer system architecture design including: deploying Corda nodes at each level of Party organizations to form a node layer; adopting IPFS for decentralized storage to form a storage layer; performing data sharing through a multi-layer blockchain model and smart contracts to form a sharing layer; and forming a user layer composed of participants of each level of Party organizations, the user layer managing, updating, viewing and sharing data;
[0008] Encrypt the Party building data in the storage layer by using the Blowfish algorithm and the CBC mode, and store the encrypted data in the decentralized IPFS system;
[0009] Define the status and flow of each visitor in the user layer, and implement role-based access control in combination with the CorDapp smart contract to ensure that only authorized users can access the data;
[0010] Build access rights that distinguish between the internal and external networks, and use the Public Key Infrastructure (PKI) to authenticate all nodes and users;
[0011] Use the Transport Layer Security (TLS) protocol to encrypt the transmission of Party building data in the sharing layer to ensure that the data is fully encrypted during transmission;
[0012] Among them, the storage layer includes a main chain and a sub-chain, and realizes the distributed storage and management of data through a multi-layer blockchain model of the main chain and the sub-chain. The main chain adopts the form of a consortium chain, and the sub-chain adopts the form of a private chain.
[0013] Further, the steps of defining the status and flow of each visitor in the user layer, and implementing role-based access control in combination with the CorDapp smart contract to ensure that only authorized users can access the data include:
[0014] Define the role management status of the visitors in the user layer, define the role names, read permissions, and write permissions of the visitors, and store the role and permission information of the visitor users;
[0015] Define the role management contract of the visitors in the user layer, allowing a specific role to be assigned to a user and / or revoking a specific role of a user to verify the transactions of role assignment and revocation;
[0016] Define the role management flow of the visitors in the user layer, define a main role assignment process corresponding to an access application, responsible for initiating and managing the entire role assignment process, and an auxiliary process of a corresponding role assignment process, responsible for corresponding assignment requests and signing transactions;
[0017] Define the data access contract of the visitors in the user layer, obtain the role of the user from the input state of the transaction and verify whether the user has read permissions. If the read permission attribute of the user is true, allow reading the data; verify whether the user has write permissions. If the write permission attribute of the user is true, allow writing the data;
[0018] Define the data access flow of the visitors in the user layer, which is used to process data reading and writing operations.
[0019] Further, the steps of defining the role management flow of the visitors in the user layer, defining a main role assignment process corresponding to an access application, responsible for initiating and managing the entire role assignment process, and an auxiliary process of a corresponding role assignment process, responsible for corresponding assignment requests and signing transactions, further include:
[0020] Define a process class and its companion object. Start a process through RPC calls. This process receives two parameters: the user to whom the role will be assigned and the role to be assigned. At the same time, define each step of the process's precision tracker through the companion object to track the execution progress of the process;
[0021] Define a progress tracker to update and display the current progress during the process execution
[0022] Implement the call method to execute the auxiliary process of the corresponding role assignment process.
[0023] Further, the steps of implementing the call method to execute the auxiliary process of the corresponding role assignment process further include:
[0024] Generate a transaction, generate a transaction containing the new role status, and formulate the output status and related commands of the transaction;
[0025] Verify the transaction, verify whether the transaction containing the new role status meets the contract conditions in the contract. If it meets, execute the next command. If it does not meet, withdraw the transaction containing the new role status;
[0026] Sign the transaction. The initiator of the process uses its own private key of the outflow layer initiator to sign the transaction containing the new role status;
[0027] Collect the other party's signature, start a session with the user, and collect the user's signature on the transaction;
[0028] Complete the transaction, send the completed transaction to the Notary for final signature, and record it in the ledger.
[0029] Further, the steps of defining the role management flow of the visitor in the user layer, corresponding to an access application, defining a main role assignment process responsible for initiating and managing the entire role assignment process, and an auxiliary process of the corresponding role assignment process responsible for corresponding assignment requests and signing transactions further include:
[0030] Respond to the role assignment process, define an anonymous SignTransactionFlow object and sign the transaction, and the SignTransactionFlow object performs additional checks in the checkTransaction method;
[0031] Wait for and accept the final transaction record.
[0032] Further, the steps of encrypting the Party building data in the storage layer using the Blowfish algorithm and CBC mode and storing the encrypted data in the decentralized IPFS system include:
[0033] Generate a Blowfish algorithm key and store the Blowfish algorithm key in a hardware security module;
[0034] Generate an 8-byte random initialization vector IV, and store the random initialization vector IV together with the Party building data;
[0035] Initialize the Blowfish encryption algorithm using the Blowfish algorithm key and the random initialization vector IV;
[0036] Divide the Party building data into blocks, with each block being 8 bytes in size;
[0037] Apply the initialized Blowfish algorithm and the CBC mode to each data block for encryption to generate ciphertext data;
[0038] Combine the ciphertext data and the random initialization vector IV to obtain an encrypted data packet;
[0039] Upload the encrypted data packet to the IPFS system and obtain the content identifier CID returned by IPFS.
[0040] Furthermore, the step of encrypting the transmission of Party building data in the sharing layer by using the Transport Layer Security protocol TLS to ensure complete encrypted transmission of data during transmission includes:
[0041] Configure TLS support on the server side, generate the private key and CSR of the server, submit the CSR to the Certificate Authority CA, after CA verifies the CSR, issue a TLS certificate, then install the private key, certificate and intermediate certificate of CA on the server, and configure the server software to use these certificates for TLS connections;
[0042] Manage and update the TLS certificate, regularly update and manage the TLS certificate and ensure the integrity of the certificate trust chain configured on the server;
[0043] Client configuration, import and trust the root certificate and intermediate certificate, and configure the client application or browser to use TLS to connect to the server;
[0044] Establish a TLS connection and perform data encrypted transmission. Establish a TLS connection between the client and the server, perform a handshake process, after negotiating the encryption protocol and session key, perform data transmission on the TLS connection.
[0045] Furthermore, the step of building access rights that distinguish between internal and external networks and authenticating the identities of all nodes and users by using the Public Key Infrastructure PKI includes:
[0046] Distinguish the access rights of the internal and external networks, use firewalls and router configurations to divide different network segments into internal and external networks, configure an access control list ACL on the firewall to control the access rights of the internal and external networks, implement a network isolation policy, and securely isolate the internal and external networks;
[0047] Deploy a public key infrastructure PKI, install and configure the CA, RA, certificate repository, and CRL;
[0048] Create and distribute digital certificates, generate a public and private key pair for each node and user, submit a certificate signing request CSR to the CA, and after the CA verifies the CSR, issue a digital certificate and send the issued digital certificate back to the node and user;
[0049] Implement an identity authentication mechanism, configure the client application and the server application, and perform two-way authentication through digital certificates.
[0050] The present invention also proposes a method for sharing Party building data based on blockchain technology. According to the method for securely storing Party building data based on blockchain technology described in any one of the above solutions, the method for sharing Party building data includes the following steps:
[0051] When a user accesses a node, the access node issues a data access request in the main chain and attaches a digital signature, which is generated by the private key of the access node. The smart contract on the main chain verifies the authenticity and integrity of the digital signature and the access request;
[0052] While verifying the role and permission information of the access node, perform a permission check through the smart contract to verify whether the role has the right to access the requested data. If the verification passes, the leading node permits the smart contract and records the permission result, triggering a further data access process. If the verification fails, revoke the role and the access request and record the revocation result;
[0053] After the leading node permits, the verification result, access request, and leading permission trigger the main data access smart contract. According to the ordinary node ID information in the access request, find the corresponding group node;
[0054] After the group node obtains the access request, trigger the sub-data access smart contract and send the access request to the ordinary node;
[0055] After the ordinary node agrees to the access, encrypt the data secret key and data Hash using the public key of the access node and share them in the sub-chain through the sub-data sharing smart contract;
[0056] After the shared content is returned to the group node, the group node triggers the main data sharing smart contract on the main chain and sends the shared content to the access node;
[0057] The access node decrypts through its own public key, obtains the data ciphertext through data hashing, and decrypts through the data key to obtain the access data.
[0058] The present invention provides a method for secure storage and sharing of Party building data based on blockchain technology. Through technical means such as multi-layer system architecture design and data encryption processing, combined with Corda nodes and IPFS decentralized storage and multi-layer blockchain models, the distributed storage and management of Party building data are realized. Secondly, through encryption processing during storage and transmission, the confidentiality and integrity of data are ensured, preventing data leakage or tampering, and enhancing the security of accessing Party building data. The present invention has significant beneficial effects on improving the security, reliability, and management efficiency of Party building data during storage, transmission, and sharing. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or in the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained according to the processes shown in these drawings.
[0060] Figure 1 It is a schematic flowchart of the first embodiment in the method for secure storage and sharing of Party building data based on blockchain technology;
[0061] Figure 2 It is a schematic flowchart of the storage layer encryption in the second embodiment of the method for secure storage and sharing of Party building data based on blockchain technology;
[0062] Figure 3 It is a schematic flowchart of the implementation of the call method in the third embodiment of the method for secure storage and sharing of Party building data based on blockchain technology. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0063] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0064] It should be noted that all directional indications (such as up, down, left, right, front, back...) in the embodiments of the present invention are only used to explain the relative positional relationship and movement conditions between components in a specific posture (as shown in the drawings). If the specific posture changes, the directional indications will also change accordingly.
[0065] In addition, the descriptions involving "first", "second", etc. in the present invention are for descriptive purposes only, and should not be construed as indicating or implying their relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one such feature. In addition, the technical solutions between various embodiments may be combined with each other, but it must be based on what can be achieved by those of ordinary skill in the art. When the combination of technical solutions results in contradictions or cannot be achieved, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection required by the present invention.
[0066] In the present invention, the definition of Role is an abstract concept used in the system to represent user permissions. Each role corresponds to a set of permissions, and these permissions define the operations that the role can perform and the data scope that can be accessed, so as to manage and control the permissions of users in the system. The definition of user is a participant in the system, and each user is associated with one or more roles. After passing the system authentication, the user can access the corresponding data and / or perform specific operations according to their role. Blockchain is a decentralized distributed ledger technology, and data is stored in the form of blocks, so that each block is connected into a chain through a cryptographic hash function, which has the beneficial effects of storing data distributedly on multiple nodes, avoiding single-point failures and being almost impossible to be tampered with, and all operations have records that can be audited and traced. The definition of the Multi-layer Blockchain Model is to adopt the structure of the main chain and sub-chains in system design, and realize the distributed storage and management of data through blockchains at different levels. Through the multi-layer architecture design, different data storage requirements are allocated to chains at different levels, improving the flexibility of the system and enhancing the security of data storage and management. The definition of Smart Contract is an automated program running on the blockchain, which can automatically execute the contract terms when specific conditions are met, reducing human intervention and reliance on third parties, and the execution records are publicly transparent and available for auditing at any time. In CordaNode, Corda is a distributed ledger platform, and CordaNode is a participating node in its network, responsible for storing and processing transaction data. CordaNode only shares data with necessary nodes, and the nodes communicate directly with each other, which can effectively protect data privacy and achieve efficient and low-latency transaction processing. The definition of IPFS (InterPlanetary File System) is a decentralized file storage system that stores and shares files through content addressing. The files are distributedly stored on multiple nodes and backed up by multiple nodes, and the files are accessed through content hash values, avoiding single-point failures of centralized storage, improving storage and retrieval efficiency, and enhancing the persistence and reliability of data. The definition of PKI (PublicKey Infrastructure) is a public key infrastructure used to manage public and private key pairs, and provides identity authentication and data encryption services through functions such as identity authentication, data encryption, and digital signature. The Certificate Authority (CA) is the core component of PKI, responsible for issuing and managing digital certificates. After verifying the identity of the applicant, it generates and issues digital certificates, manages the update and revocation of certificates, and can list the revoked certificates to ensure that these certificates are no longer trusted.The Registration Authority (RA) is an auxiliary component of PKI, responsible for processing certificate applications and verifying the identities of applicants. The Certificate Repository is a public or private storage system used to store and distribute issued digital certificates and Certificate Revocation Lists (CRLs). The Certificate Revocation List (CRL) is a list published by the CA that lists revoked and no longer trustworthy digital certificates. TLS (Transport Layer Security) is defined as a transport layer security protocol used to provide security guarantees in network communication, ensuring the confidentiality and integrity of data during transmission. It has the functions of encrypting the transmitted data, verifying the identities of both communication parties, and ensuring that the data has not been tampered with during transmission through a Message Authentication Code (MAC). The Blowfish algorithm is a symmetric key block cipher algorithm with the advantages of variable key length (32 - 448 bits), fast and secure algorithm. CBC (Cipher-block chaining) refers to a block encryption mode of cipher block chaining that uses an initialization vector (IV) to start the encryption process. The encryption of each block depends on the ciphertext of the previous block, enhancing security.
[0067] Based on Figures 1-3 As shown, a method for securely storing Party building data based on blockchain technology is disclosed in the present invention, specifically including the following steps:
[0068] S1. Build a multi-layer system architecture design, which includes: deploying Corda nodes at each level of the Party organization to form a node layer; using IPFS for decentralized storage to form a storage layer; sharing data through a multi-layer blockchain model and smart contracts to form a sharing layer; the user layer consists of participants from each level of the Party organization, and the user layer manages, updates, views, and shares data;
[0069] In this embodiment, the multi-layer system architecture design of the present invention includes four layers: a node layer, a storage layer, a sharing layer, and a user layer. Among them, in the node layer, Corda nodes are respectively deployed through various electronic devices in party organizations at all levels (such as central party organizations, provincial-level party organizations, municipal-level party organizations, etc.). Each node maintains a complete or partial blockchain ledger, and data exchange is carried out between each node through peer-to-peer communication. The storage layer is used to store encrypted Party building data to ensure the immutability and high availability of the data. The sharing layer is used to record all transaction information that occurs, provide proof for the process of sharing Party building data, and automatically execute identity authentication to ensure the secure sharing of data without the participation of a third party. The sharing layer includes a multi-layer blockchain model and smart contracts on the blockchain. The user layer is used to manage, update, view, and share data, and is composed of participants in party organizations at all levels.
[0070] In another embodiment, the multi-layer blockchain model includes a main chain and multiple sub-chains. The main chain adopts a consortium chain. The nodes on the main chain include access nodes and leadership nodes. The leadership nodes are responsible for managing the affairs on the main chain and recording the registration and authentication information of all sub-chains. After the access nodes are registered and authenticated through smart contracts, the leadership nodes conduct permission authentication on the access nodes, and after authentication, the access nodes are allowed to make links. The sub-chains adopt the form of private chains. The nodes on the sub-chains are used to deploy smart contracts and conduct registration and identity authentication. The nodes on the sub-chains also have the function of uploading the identity registration information to the main chain for storage.
[0071] It can be understood that the present invention can also include a front-end user interface for user login, Party building data query, and / or operation. Users access the front-end user interface through a browser or a mobile application, and can perform corresponding operations after identity authentication.
[0072] S2. Encrypt the Party building data in the storage layer using the Blowfish algorithm and the CBC mode, and store the encrypted data in the decentralized IPFS system;
[0073] S21. Generate a Blowfish algorithm key and store the Blowfish algorithm key in the hardware security module;
[0074] S22. Generate an 8-byte random initialization vector IV, and store the random initialization vector IV together with the Party building data;
[0075] S23. Initialize the Blowfish encryption algorithm using the Blowfish algorithm key and the random initialization vector IV;
[0076] S24. Divide the Party building data into blocks, and the size of each block is 8 bytes;
[0077] S25. Apply the initialized Blowfish algorithm and CBC mode to each data block for encryption to generate ciphertext data;
[0078] S26. Combine the ciphertext data and the random initialization vector IV to obtain an encrypted data packet;
[0079] S27. Upload the encrypted data packet to the IPFS system and obtain the content identifier CID returned by IPFS;
[0080] In the present invention, the Blowfish symmetric encryption algorithm is adopted to use a variable-length (32 bits to 448 bits) key. In this embodiment, a 128-bit key is selected for encryption. The system generates a unique encryption key for each user, and this encryption key is managed and distributed by the key management module of the system. The generation of the key can be achieved through a random number generator (RNG). When a user registers for the first time, the system will generate a symmetric encryption key for him / her and store it in a secure key library. The key library is protected by a high-strength encryption algorithm. The Party building data to be stored is divided into several 8-byte data blocks, and then encrypted through the CBC mode. The ciphertext of the previous data block is XORed with the current data block and then encrypted, which enhances the encryption strength and security. An initialization vector IV is generated for each data block. The IV is used for data recovery during the decryption process. The value of the IV is randomly generated during the encryption process and stored together with the ciphertext. The encrypted data format is expressed as: ciphertext data block 1 + IV1 + ciphertext data block 2 + IV2 +... + ciphertext data block N + IVN.
[0081] In another embodiment, when storing Party building data, IPFS generates a unique content hash value (CID) for each data block. After the data block is uploaded to the IPFS network, the system will record the CID of each data block and combine these CIDs into a Merkle tree. The root hash value (rootCID) of the Merkle tree is used as the unique identifier of the entire data file. When a user needs to access the data, first retrieve the CID of the corresponding data block through the root hash value of the Merkle tree. After retrieving the corresponding data block from the IPFS network through the CID, perform the integrity verification of the data block. Recalculate the hash value of the retrieved data block and compare it with the CID to ensure that the data block has not been tampered with. After retrieving all the data blocks, the system restores the original data through the decryption process. The decryption process uses the stored key and IV for comparison and decryption.
[0082] S3. Define the states and flows of each visitor in the user layer, and implement role-based access control in combination with the CorDapp smart contract to ensure that only authorized users can access the data;
[0083] S31. Define the role management status of visitors in the user layer, define the role names, read permissions, and write permissions of visitors, and store the role and permission information of visitor users;
[0084] S32. Define the role management contract of visitors in the user layer, allowing a specific role to be assigned to a user and / or a specific role of a user to be revoked, for verifying transactions of role assignment and revocation;
[0085] S33. Define the role management flow of visitors in the user layer, define a main role assignment process corresponding to an access application, responsible for initiating and managing the entire role assignment process, and an auxiliary process of a corresponding role assignment process, responsible for corresponding to the assignment request and signing the transaction;
[0086] S33a. In response to the role assignment process, define an anonymous SignTransactionFlow object and sign the transaction, and the SignTransactionFlow object performs additional checks in the checkTransaction method;
[0087] Specifically, the SignTransactionFlow object is a built-in process in Corda. In a multi-party collaborative transaction, the participating parties verify and sign the transaction. This process is usually used in the responder (i.e., non-initiator) of the transaction to ensure that the transaction complies with business rules and security requirements, and then the responder signs the transaction.
[0088] Specifically, in this embodiment, when the initiator initiates a transaction, the system defines a responder process ReadDataFlowResponder, which is called when receiving the initiation of ReadDataFlow. Then create an anonymous object that inherits from SignTransactionFlow. The constructor receives a FlowSession object, namely counterpartySession. counterpartySession is the session object with the initiator, representing the communication channel with the initiator, and overrides the checkTransaction method to implement additional check logic. Then use the subflow method to start the SignTransactionFlow sub-process and obtain the ID of the just-signed transaction. subflow blocks the current process until the sub-process is completed, and after the sub-process is completed, subflow returns the result of the sub-process.
[0089] S33b. Wait for and accept the final transaction record;
[0090] S34. Define the data access contract for the visitor in the user layer, obtain the user's role from the input state of the transaction, and verify whether the user has read permission. If the read permission attribute of the user is true, allow data reading; verify whether the user has write permission. If the write permission attribute of the user is true, allow data writing;
[0091] S35. Define the data access flow for the visitor in the user layer, which is used to process data reading and writing operations;
[0092] S36. Define the process class and its companion object, start an initiation process through RPC call. This process receives two parameters: the user to whom the role will be assigned and the role to be assigned. At the same time, define each step of the process's precision tracker through the companion object to track the execution progress of the process;
[0093] S37. Define the progress tracker to update and display the current progress during the process execution
[0094] S38. Implement the call method to execute the auxiliary process of the corresponding role assignment process
[0095] S38a. Generate a transaction, generate a transaction containing the new role state, and formulate the output state and related commands of the transaction;
[0096] S38b. Verify the transaction, verify whether the transaction containing the new role state meets the contract conditions in the contract. If it meets, execute the next command; if not, withdraw the transaction containing the new role state;
[0097] S38c. Sign the transaction, and the process initiator uses the private key of the out - flow layer initiator to sign the transaction containing the new role state;
[0098] S38d. Collect the other - party's signature, start a session with the user, and collect the user's signature on the transaction;
[0099] S38e. Complete the transaction, send the completed transaction to the Notary for final signature, and record it in the ledger;
[0100] Specifically, in this embodiment, the role definitions and permission relationships first define the roles and permissions for different channels, such as "Central Administrator", "Provincial Administrator", "Municipal Administrator", etc. When each user registers for the first time, a pair of public key and private key is generated. The public key is used for identity authentication, and the private key is used for data signing. When the user logs in, the system verifies their digital certificate to ensure the credibility of the user's identity. The system adopts a Role-Based Access Control (RBAC) mechanism and assigns different access permissions according to the different roles obtained by different users. It can be understood that the present invention can also include two-factor authentication. In addition to the digital certificate and key, the user also needs to provide a dynamic verification code for login verification. When the user requests to access a resource, the system checks the user's session token, verifies the validity and permissions of the session, and can also perform permission checks based on the user's role and the type of resource requested, and the permission check is based on a predefined role-permission mapping table.
[0101] In another embodiment, the roles can include administrators, ordinary users, auditors, etc. Among them, the administrator has the highest authority and can manage all data; ordinary users can only access data related to themselves; the auditor has the audit authority and can view audit logs and operation records.
[0102] S4. Build access permissions for differentiating internal and external networks, and use Public Key Infrastructure (PKI) to authenticate all nodes and users.
[0103] S41. Differentiate access permissions for internal and external networks. Use firewalls and router configurations to divide different network segments into internal and external networks. Configure an Access Control List (ACL) on the firewall to control access permissions for internal and external networks, implement a network isolation policy, and securely isolate the internal and external networks.
[0104] S42. Deploy Public Key Infrastructure (PKI), install and configure the CA, RA, certificate repository, and CRL.
[0105] S43. Create and distribute digital certificates. Generate a public key and private key pair for each node and user, submit a Certificate Signing Request (CSR) to the CA. After the CA verifies the CSR, it issues a digital certificate and sends the issued digital certificate back to the node and user.
[0106] S44. Implement an identity authentication mechanism, configure the client application and the server application, and perform two-way authentication through digital certificates.
[0107] In this embodiment, the internal network is used to store and process sensitive Party building data, and only authorized internal users and nodes can access it. The internal network usually includes database servers, application servers, internal user terminals, etc. The external network is used to provide external services, such as public information query, access to non-sensitive Party building data, etc. The external network nodes can be web servers, external user terminals, etc. When users and nodes log in to the system, they provide digital certificates and use private keys to sign random challenge messages. The system uses the public key of the CA to verify the digital certificates and uses the public key in the certificates to verify the signatures. After successful verification, the system generates a session token. The session token is used to represent the session conducted by the user or node and is used for subsequent access control. When the system performs resource access control, it will first verify the validity of the session token to ensure that the request comes from an authenticated user or node, and decides whether to allow the access request based on the role and access rights of the user or node. It can be understood that the access rights to Party building data in the internal network are more stringent, and only authorized users and nodes can access it.
[0108] S5. Use the Transport Layer Security (TLS) protocol to encrypt the transmission of Party building data in the sharing layer to ensure that the data is fully encrypted during transmission;
[0109] S51. Configure TLS support on the server side, generate the private key and CSR of the server, and submit the CSR to the Certificate Authority (CA). After the CA verifies the CSR, it issues a TLS certificate, and then installs the private key, certificate, and intermediate certificate of the CA on the server, and configures the server software to use these certificates for TLS connections;
[0110] S52. Manage and update the TLS certificate, regularly update and manage the TLS certificate and ensure the integrity of the certificate trust chain configured on the server;
[0111] S53. Client configuration, import and trust the root certificate and intermediate certificate, and configure the client application or browser to use TLS to connect to the server;
[0112] S54. Establish a TLS connection and perform data encrypted transmission. Establish a TLS connection between the client and the server, conduct a handshake process, negotiate the encryption protocol and session secret key, and then perform data transmission on the TLS connection;
[0113] Among them, the storage layer includes a main chain and sub-chains, and realizes the distributed storage and management of data through a multi-layer blockchain model of the main chain and sub-chains. The main chain adopts the form of a consortium chain, and the sub-chains adopt the form of private chains.
[0114] In this embodiment, the TLS protocol is used to encrypt data transmission to ensure the confidentiality and integrity of Party building data during the transmission process. The TLS protocol protects Party building data through an encrypted transmission channel, preventing Party building data from being eavesdropped on or tampered with during the transmission process, and ensuring the authenticity of both parties through an authentication mechanism.
[0115] The present invention also proposes a method for sharing Party building data based on blockchain technology. According to the method for securely storing Party building data based on blockchain technology in any one of the above solutions, the method for sharing Party building data includes the following steps:
[0116] S001. When a user accesses a node, the access node sends a data access request in the main chain and attaches a digital signature, which is generated by the private key of the access node. The smart contract on the main chain verifies the authenticity and integrity of the digital signature and the access request.
[0117] S002. While verifying the role and permission information of the access node, a permission check is also carried out through the smart contract to verify whether the role has the right to access the requested data. If the verification passes, the leading node permits the smart contract and records the permission result, triggering a further data access process. If the verification fails, the role and the access request are revoked and the revocation result is recorded.
[0118] S003. After the leading node permits, the verification result, the access request, and the leading permission trigger the main data access smart contract. According to the ordinary node ID information in the access request, the corresponding group node is found.
[0119] S004. After the group node obtains the access request, it triggers the sub-data access smart contract and sends the access request to the ordinary node.
[0120] S005. After the ordinary node agrees to the access, it encrypts the data secret key and the data Hash using the public key of the access node and shares them in the sub-chain through the sub-data sharing smart contract.
[0121] S006. After the shared content is returned to the group node, the group node triggers the main data sharing smart contract on the main chain and sends the shared content to the access node.
[0122] S007. The access node decrypts through its own public key, obtains the data ciphertext through the data Hash, and decrypts through the data secret key to obtain the accessed data.
[0123] Combining all the above technical solutions, a method for secure storage and sharing of Party building data based on blockchain technology provided by the present invention realizes the distributed storage and management of data through a multi-layer system architecture combined with Corda nodes, IPFS decentralized storage, and a multi-layer blockchain model, enhancing the scalability and reliability of the system. The Blowfish algorithm and CBC mode are used for data encryption processing to ensure the confidentiality and integrity of the data, preventing data leakage and tampering. Through the role-based access control mechanism, the access rights of users are finely managed to ensure that only authorized users can access the corresponding Party building data, improving the security of Party building data access. The PKI identity authentication mechanism ensures the credibility of the identities of all nodes and users in the system, effectively preventing unauthorized nodes and users from accessing the data. The present invention has significant advantages in terms of security, reliability, and management efficiency during the storage, sharing, and transmission of Party building data.
[0124] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention. Any equivalent structural transformation made under the inventive concept of the present invention by using the content of the specification and drawings of the present invention, or directly / indirectly applied to other related technical fields, is included in the patent protection scope of the present invention.
Claims
1. A method for securely storing Party building data based on blockchain technology, characterized in that, It includes the following steps: Construct a multi-layer system architecture design, which includes: deploying Corda nodes in Party organizations at all levels to form a node layer; adopting IPFS for decentralized storage to form a storage layer; sharing data through a multi-layer blockchain model and smart contracts to form a sharing layer; and forming a user layer composed of participants in Party organizations at all levels, where the user layer manages, updates, views, and shares data; Use the Blowfish algorithm and CBC mode to encrypt the Party building data in the storage layer, and store the encrypted data in the decentralized IPFS system; Define the status and flow of each visitor in the user layer, and implement role-based access control in combination with the CorDapp smart contract to ensure that only authorized users can access the data; Construct access permissions that distinguish between internal and external networks, and use the public key infrastructure PKI to authenticate all nodes and users; Use the transport layer security protocol TLS to encrypt the transmission of Party building data in the sharing layer to ensure that the data is encrypted and transmitted completely during the transmission process; Among them, the storage layer includes a main chain and a sub-chain. The distributed storage and management of data are realized through the multi-layer blockchain model of the main chain and the sub-chain. The main chain adopts the form of a consortium chain, and the sub-chain adopts the form of a private chain.
2. The method for secure storage of party building data based on blockchain technology as claimed in claim 1, characterized in that: The step of defining the status and flow of each visitor in the user layer, and implementing role-based access control in combination with the CorDapp smart contract to ensure that only authorized users can access the data includes: Define the role management status of visitors in the user layer, define the role name, read permission, and write permission of visitors, and store the role and permission information of visitor users; Define the role management contract of visitors in the user layer, allowing a specific role to be assigned to a user and / or revoking a specific role of a user to verify the transactions of role assignment and revocation; Define the role management flow of visitors in the user layer, define a main role assignment process corresponding to an access application, responsible for initiating and managing the entire role assignment process, and an auxiliary process of a corresponding role assignment process, responsible for corresponding assignment requests and signing transactions; Define the data access contract of visitors in the user layer, obtain the role of the user from the input state of the transaction and verify whether the user has read permission. If the read permission attribute of the user is true, allow reading the data; verify whether the user has write permission. If the write permission attribute of the user is true, allow writing the data; Define the data access flow of visitors in the user layer for processing data reading and writing operations.
3. The method for secure storage of party building data based on blockchain technology as claimed in claim 2 is characterized in that: The step of defining the role management flow of visitors in the user layer, defining a main role assignment process corresponding to an access application, responsible for initiating and managing the entire role assignment process, and an auxiliary process of a corresponding role assignment process, responsible for corresponding assignment requests and signing transactions, further includes: Define process classes and companion objects, and start an initiating process through RPC calls. This process receives two parameters: the user to whom the role will be assigned and the role to be assigned. At the same time, define each step of the process's precision tracker through the companion object to track the execution progress of the process; Define a progress tracker to update and display the current progress during the process execution Implement the call method to execute the auxiliary process of the corresponding role assignment process.
4. The method for secure storage of party building data based on blockchain technology as claimed in claim 3 is characterized in that: The steps of implementing the call method to execute the auxiliary process of the corresponding role assignment process further include: Generate a transaction, generate a transaction containing the new role status, and formulate the output status and related commands of the transaction; Verify the transaction, verify whether the transaction containing the new role status meets the contract conditions in the contract. If it meets, execute the next command; if not, withdraw the transaction containing the new role status; Sign the transaction. The initiator of the process uses its own private key of the outflow layer initiator to sign the transaction containing the new role status; Collect the other party's signature, start a session with the user, and collect the user's signature on the transaction; Complete the transaction, send the completed transaction to the notary Notary for final signature, and record it in the ledger.
5. The method for secure storage of party building data based on blockchain technology as claimed in claim 2, characterized in that: The role management flow of the visitor in the defined user layer corresponds to a main role assignment process defined for an access application, which is responsible for initiating and managing the entire role assignment process, and an auxiliary process of the corresponding role assignment process, which is responsible for the steps of corresponding assignment requests and signing transactions. It further includes: Respond to the role assignment process, define an anonymous SignTransactionFlow object and sign the transaction, and the SignTransactionFlow object performs additional checks in the checkTransaction method; Wait for and accept the final transaction record.
6. The method for secure storage of party building data based on blockchain technology as claimed in claim 1, characterized in that: The steps of encrypting the Party building data in the storage layer using the Blowfish algorithm and the CBC mode and storing the encrypted data in the decentralized IPFS system include: Generate a Blowfish algorithm secret key and store the Blowfish algorithm secret key in the hardware security module; Generate an 8-byte random initialization vector IV, and store the random initialization vector IV together with the Party building data; Initialize the Blowfish encryption algorithm using the Blowfish algorithm secret key and the random initialization vector IV; Divide the Party building data into blocks, with each block being 8 bytes in size; Apply the initialized Blowfish algorithm and the CBC mode to each data block for encryption to generate ciphertext data; Combine the ciphertext data and the random initialization vector IV to obtain an encrypted data packet; Upload the encrypted data packet to the IPFS system and obtain the content identifier CID returned by IPFS.
7. The method for securely storing Party building data based on blockchain technology according to claim 1, characterized in that, The steps of encrypting the transmission of Party building data in the shared layer using the Transport Layer Security protocol TLS to ensure complete encrypted transmission of the data during transmission include: Configure TLS support on the server side, generate the private key and CSR of the server, and submit the CSR to the Certificate Authority (CA). After the CA verifies the CSR, issue a TLS certificate, then install the server's private key, certificate, and the CA's intermediate certificate on the server, and configure the server software to use these certificates for TLS connections; Manage and update TLS certificates, regularly update and manage TLS certificates and ensure the integrity of the certificate trust chain configured on the server; Client configuration, import and trust the root certificate and intermediate certificate, and configure the client application or browser to use TLS to connect to the server; Establish a TLS connection and perform encrypted data transmission. Establish a TLS connection between the client and the server, perform the handshake process, negotiate the encryption protocol and session secret key, and then perform data transmission on the TLS connection.
8. The method for secure storage of party building data based on blockchain technology as claimed in claim 1, characterized in that: The step of constructing access rights that distinguish between internal and external networks and using the Public Key Infrastructure (PKI) to authenticate all nodes and users includes: Distinguish access rights between internal and external networks. Use firewalls and router configurations to divide different network segments into internal and external networks. Configure an Access Control List (ACL) on the firewall to control access rights between internal and external networks, implement a network isolation policy, and securely isolate the internal and external networks; Deploy the Public Key Infrastructure (PKI), install and configure the CA, RA, certificate repository, and CRL; Create and distribute digital certificates. Generate a public key and private key pair for each node and user, submit a Certificate Signing Request (CSR) to the CA, and after the CA verifies the CSR, issue a digital certificate and send the signed digital certificate back to the node and user; Implement an authentication mechanism, configure the client application and the server application to perform two-way authentication through digital certificates.
9. A method for sharing Party building data based on blockchain technology, characterized in that, According to the method for secure storage of Party building data based on blockchain technology described in any one of claims 1-8, the method for sharing Party building data includes the following steps: When a user accesses a node, the access node issues a data access request in the main chain and attaches a digital signature generated by the private key of the access node. The smart contract on the main chain verifies the authenticity and integrity of the digital signature and the access request; While verifying the role and permission information of the access node, perform a permission check through the smart contract to verify whether the role has the right to access the requested data. If the verification passes, the leading node permits the smart contract and records the permission result, triggering a further data access process. If the verification fails, revoke the role and the access request and record the revocation result; After the leading node permits, the verification result, access request, and leading node permission trigger the main data access smart contract. According to the ordinary node ID information in the access request, find the corresponding group node; After the group node obtains the access request, trigger the sub-data access smart contract and send the access request to the ordinary node; After the ordinary node agrees to the access, encrypt the data secret key and data Hash using the public key of the access node and share them in the sub-chain through the sub-data sharing smart contract; After the shared content is returned to the group node, the group node triggers the main data sharing smart contract on the main chain and sends the shared content to the access node; The access node decrypts using its own public key, obtains the data ciphertext through the data Hash, and decrypts using the data secret key to obtain the access data.