Dynamic fragmentation desensitization privacy protection method based on block chain

Through sensitivity-driven dynamic sharding algorithms and improved zero-knowledge proofs, combined with the double-chain storage architecture, the problems of high overhead and static desensitization strategies of traditional blockchain storage solutions are solved, efficient data protection and flexible access control are achieved, and the transaction throughput and data security of blockchain are improved.

CN120408654AInactive Publication Date: 2025-08-01JIANGSU SAIXIN MEDICAL TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510348199.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2025-08-01
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional blockchain storage solutions have high computing and storage overhead, static desensitization strategies lack flexibility, and zero-knowledge proof computing complexity, making it difficult to meet the storage and real-time verification requirements of large-scale sensitive data.

Method used

The sensitivity-driven dynamic sharding desensitization algorithm is adopted, combining data type, access frequency and privacy levels, and dynamically adjusts the sharding strategy, adopts format retention encryption, lightweight zero-knowledge proof and homomorphic encryption for data protection, uses the improved zero-knowledge proof protocol to optimize the computing complexity, and stores data through the double-chain storage architecture of the main chain and shard chain.

Benefits of technology

Reduces computing complexity and storage overhead, improves data availability and security, improves blockchain transaction throughput, and realizes flexible data access control and abnormal behavior monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120408654A_ABST
    Figure CN120408654A_ABST
Patent Text Reader

Abstract

The invention discloses a dynamic fragmentation desensitization privacy protection method based on a block chain. The method comprises the following steps: data sensitivity analysis; performing dynamic fragmentation processing; multi-level privacy protection is realized; a double-chain storage architecture; efficient privacy verification; and the access control and auditing module is used for monitoring and detecting the behavior of abnormally accessing the high-sensitivity data. According to the method, a sensitivity-driven dynamic fragmentation desensitization algorithm is adopted, data security and availability are considered, and fragmentation modes including full desensitization, partial desensitization and format reservation encryption are adaptively selected according to data types, access frequency and privacy level factors; according to the method, improved Bulletprofs zero knowledge is adopted for proving, the verification calculation complexity is reduced by 50% by reducing the number of times of Pedersen commitment generation, parallel calculation is supported, and the throughput is remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field at the intersection of information security and blockchain technology, and particularly to a dynamic sharding desensitization privacy protection method based on blockchain. Background Art

[0002] With the development of big data, artificial intelligence, and blockchain technology, data privacy protection has become an important research direction in the field of information security. Especially in high-sensitivity data storage and sharing scenarios such as medical, financial, and government affairs, traditional data encryption and access control mechanisms face the following challenges:

[0003] High overhead of traditional encryption storage

[0004] 1. Existing blockchain storage solutions (such as Hyperledger Fabric, Ethereum) usually use symmetric or asymmetric encryption (such as AES, RSA) for data protection, but such methods will lead to huge storage and computing overheads and are difficult to meet the storage requirements of large-scale sensitive data.

[0005] 2. Lack of flexibility in static desensitization strategies

[0006] Traditional data desensitization strategies (such as static data masking, hashing of some fields) are usually predefined fixed rules and cannot be dynamically adjusted according to factors such as data access frequency and sensitivity level, resulting in reduced data availability and difficulty in meeting the requirements of different privacy levels.

[0007] 3. High computational complexity of existing zero-knowledge proofs

[0008] Existing zero-knowledge proof (ZKP) schemes, such as zk-SNARKs and zk-STARKs, have relatively large computational overheads, which affect the real-time verification of private data. Especially when the data access frequency is high, the computational latency of traditional ZKP will affect the throughput of blockchain transactions.

[0009] Therefore, we propose a dynamic sharding desensitization privacy protection method based on blockchain to solve the above-mentioned problems. Summary of the Invention

[0010] The purpose of this part is to outline some aspects of the embodiments of the present invention and briefly introduce some preferred embodiments. Some simplifications or omissions may be made in this part, as well as in the abstract and title of the specification of this application, to avoid obscuring the purpose of this part, the abstract, and the title. However, such simplifications or omissions shall not be used to limit the scope of the present invention.

[0011] In view of the problems existing in the above-mentioned existing dynamic sharding desensitization privacy protection method based on blockchain, the present invention is proposed.

[0012] Therefore, the purpose of the present invention is to provide a dynamic sharding desensitization privacy protection method based on blockchain, which adopts a sensitivity-driven dynamic sharding desensitization algorithm, takes into account data security and availability, and adaptively selects sharding methods according to data type, access frequency, and privacy level factors: full desensitization, partial desensitization, and format-preserving encryption.

[0013] To solve the above technical problems, the present invention provides the following technical solution: a dynamic sharding desensitization privacy protection method based on blockchain, comprising the following steps:

[0014] Data sensitivity analysis: Use machine learning models to score the sensitivity of input data and automatically annotate sensitive fields based on the scoring results;

[0015] Dynamic sharding: Adaptively adjust sharding strategies based on sensitivity scores, including fully desensitized sharding, partially desensitized sharding, and format-preserving sharding.

[0016] Multi-level privacy protection: Format-preserving encryption, lightweight zero-knowledge proof, and homomorphic encryption are used for data protection for different types of data shards.

[0017] Dual-chain storage architecture: Data is stored through the main chain and shard chains, where the main chain stores data hashes, access policies, and verification parameters, and the shard chains store encrypted data shards;

[0018] Efficient privacy verification: Utilizes an improved zero-knowledge proof protocol to verify data consistency, reducing computational complexity and storage overhead.

[0019] Access control and auditing: used to monitor and detect abnormal access to highly sensitive data.

[0020] As a preferred solution of the blockchain-based dynamic sharding desensitization privacy protection method described in the present invention, the dynamic sharding process adopts an improved sensitivity-driven sharding algorithm, which dynamically adjusts data sharding based on data distribution characteristics, sensitivity level, and access frequency, including:

[0021] enter:

[0022] D: original dataset;

[0023] A={A1,A2,…,A n}: data field collection;

[0024] S(A i ): Data field A i The sensitivity score is 0-1;

[0025] F(A i ): Data field A i Frequency of visits;

[0026] T: Set sensitivity boundary threshold;

[0027] K: Set number of shards;

[0028] Output:

[0029] P = {P1, P2,..., P m}: Data shard set;

[0030] E(P i ): Encryption strategy for shard P i ;

[0031] Among them, sensitivity score calculation:

[0032] S(A i ) = α·R(A i ) + β·C(A i ) + γ·L(A i )

[0033] R(A i ): Data leakage risk; C(A i ): Data compliance requirements; L(A i ): Historical leakage records; α, β, γ: Weight parameters;

[0034] Among them, access frequency calculation:

[0035] F(A i ) (t) = λ·F(A i ) (t-1) + (1 - λ)·A t

[0036] F(A i ) (t) : Access frequency calculated in the t-th round; A t : Number of accesses within the current time window; λ ∈ [0, 1]: Decay factor, determining the weight of historical accesses;

[0037] Among them, the calculation of the number of shards adopts a dynamic sharding strategy driven by sensitivity + access frequency, calculating the optimal number of shards K(A i ):

[0038]

[0039] W s ,W f : Weight coefficients of sensitivity and access frequency; C: Control parameter, determining the shard granularity.

[0040] As a preferred solution of the blockchain-based dynamic sharding desensitization privacy protection method of the present invention, in which: in the sensitivity score calculation, a high range T of the sensitivity threshold is set h and a low range T m , to divide the sensitive levels of data fields:

[0041] Highly sensitive data, S(A i ) > T h : Use format-preserving encryption + shard key separated storage;

[0042] Medium-sensitive data, T m < S9A i ) ≤ T h : Use AES-128-GCM encryption or zero-knowledge proof protection;

[0043] Low-sensitive data, S(A i ) ≤ T m : Use partial desensitization or hash storage;

[0044] Among them, a threshold range F of the access frequency is set th , to divide the access frequency levels:

[0045] F(A i ) > F th : Use zero-knowledge proof protection.

[0046] As a preferred solution of the blockchain-based dynamic sharding desensitization privacy protection method of the present invention, in which: for highly sensitive data S*A i ) > T h , the number of shards should be increased to reduce the risk of a single storage node;

[0047] For high-access-frequency data F(A i ) > F th , the number of shards should be reduced to reduce query latency.

[0048] As a preferred solution of the blockchain-based dynamic sharding desensitization privacy protection method of the present invention, in which: according to the shard number K*A i ), the data is sharded and different storage strategies are adopted:

[0049]

[0050] Among them, the main chain: stores the data hash, access control policy, and verification parameters;

[0051] The shard chain: stores the encrypted data shards and performs decentralized storage through IPFS.

[0052] As a preferred solution of the blockchain-based dynamic sharding desensitization privacy protection method described in the present invention, wherein: the improved zero-knowledge proof protocol adopts an optimized variant of Bulletproofs, including:

[0053] 1) Use multiple Pedersen commitments:

[0054] C = vH + rG

[0055] Where: C is the commitment value; v is the data value to be protected; H, G are different base points; r is a random number;

[0056] To reduce the computational complexity, single-base-point merging optimization is introduced:

[0057] C′ = (v1 + v2 + … + v n )H + (r1 + r2 + … r n )G

[0058] Merge n Pedersen commitments into 1, reducing the computational overhead by 50%;

[0059] 2) Bulletproofs uses vector inner product calculation for constraint verification:

[0060]

[0061] Where a and b are vectors, and P is the verification target, using parallel computing and recursive compression:

[0062] Parallel computing: Utilize single instruction multiple data technology to calculate multiple vector inner products simultaneously;

[0063] Recursive compression: Split a long vector into smaller sub-vectors, and recursively calculate the inner product for each sub-vector;

[0064] The computational cost of each proof can be reduced by 40% - 50%;

[0065] 3) Use the double-base-point technology to optimize batch verification:

[0066] C i = v i H + r i G

[0067] C j = v j H′ + r j G′

[0068] Through refrigerator calculations with different base points H, H', multiple transactions are verified at once, avoiding the overhead of verifying one by one, and increasing the verification throughput by more than 2 times.

[0069] A blockchain-based dynamic sharding desensitization privacy protection system, comprising:

[0070] A data sensitivity analysis module, which uses a machine learning model to perform sensitivity scoring on the input data and automatically annotate sensitive fields based on the scoring results;

[0071] A dynamic sharding processing module, which adaptively adjusts the sharding strategy according to the sensitivity score, including full desensitization sharding, partial desensitization sharding, and format-preserving sharding;

[0072] A multi-level privacy protection module, which uses format-preserving encryption, lightweight zero-knowledge proof, and homomorphic encryption for data protection for different types of data shards respectively;

[0073] A double-chain storage module, which stores data through a main chain and a sharding chain, where the main chain stores data hashes, access policies, and verification parameters, and the sharding chain stores encrypted data shards;

[0074] An efficient privacy verification module, which uses an improved zero-knowledge proof protocol for data consistency verification to reduce computational complexity and storage overhead;

[0075] An access control and auditing module, which is used to monitor and detect behaviors of abnormally accessing highly sensitive data.

[0076] As a preferred solution of the blockchain-based dynamic sharding desensitization privacy protection system of the present invention, wherein: the access control and auditing module is used to monitor and detect behaviors of abnormally accessing highly sensitive data. When the same user frequently requests specific highly sensitive data within a short period of time, the system will trigger an on-chain warning mechanism and notify the regulatory department for auditing, specifically including:

[0077] Access log storage: Record all sensitive data requests accessed by users, including user ID, data category, access time, and IP address;

[0078] Threshold detection: Set an access frequency threshold, such as N times / minute, and trigger anomaly detection when the threshold is exceeded;

[0079] Anomaly warning: Once an abnormal access behavior is detected, the contract immediately generates a warning event, which is broadcast and stored on the chain;

[0080] Automatically notify the regulatory agency: Trigger an on-chain audit contract, send an alarm message to the relevant regulatory account, and request an audit of the access behavior.

[0081] The beneficial effects of the present invention: The present invention adopts a sensitivity-driven dynamic sharding desensitization algorithm, taking into account both data security and availability, and adaptively selects the sharding method according to factors such as data type, access frequency, and privacy level: full desensitization, partial desensitization, and format-preserving encryption;

[0082] Adopt improved Bulletproofs zero - knowledge proof. By reducing the number of Pedersen commitment generations, the verification computational complexity is reduced by 50%, parallel computing is supported, and the throughput is significantly improved.

[0083] Adopt a double - chain storage architecture to enhance storage security. Main chain: store data hashes, access policies, and verification parameters; Sharding chain: store encrypted data shards to improve access performance. Brief Description of the Drawings

[0084] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following - described drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings. Among them:

[0085] Figure 1 It is a schematic diagram of the overall process of the blockchain - based dynamic sharding desensitization privacy protection method of the present invention.

[0086] Figure 2 It is a logic diagram of the sensitivity - driven sharding algorithm of the blockchain - based dynamic sharding desensitization privacy protection method of the present invention.

[0087] Figure 3 It is a logic diagram of the improved zero - knowledge proof of the blockchain - based dynamic sharding desensitization privacy protection method of the present invention. Detailed Embodiments

[0088] To make the above - mentioned objects, features, and advantages of the present invention more obvious and understandable, the following will make a detailed description of the specific embodiments of the present invention in conjunction with the drawings of the specification.

[0089] Many specific details are set forth in the following description in order to fully understand the present invention. However, the present invention can also be implemented in other ways different from those described herein. Those skilled in the art can make similar extensions without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.

[0090] Secondly, the so - called "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that can be included in at least one implementation of the present invention. The "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor is it a separate or selectively exclusive embodiment from other embodiments.

[0091] Next, the present invention will be described in detail with reference to the schematic diagrams. When describing the embodiments of the present invention in detail, for the sake of convenience of explanation, the cross-sectional views showing the device structure will be enlarged locally not in accordance with the general scale, and the schematic diagrams are only examples and should not limit the scope of protection of the present invention herein. In addition, in actual production, three-dimensional spatial dimensions including length, width, and depth should be included.

[0092] Referring to Figures 1 - 3 , a blockchain-based dynamic sharding desensitization privacy protection method is provided, including the following steps:

[0093] Data sensitivity analysis: Using a machine learning model to perform sensitivity scoring on the input data and automatically annotating sensitive fields based on the scoring results;

[0094] Dynamic sharding processing: Adaptively adjusting the sharding strategy according to the sensitivity score, including fully desensitized sharding, partially desensitized sharding, and format-preserving sharding;

[0095] Multi-level privacy protection: For different types of data shards, format-preserving encryption, lightweight zero-knowledge proof, and homomorphic encryption are respectively used for data protection;

[0096] Double-chain storage architecture: Storing data through the main chain and the sharding chain, where the main chain stores data hashes, access policies, and verification parameters, and the sharding chain stores encrypted data shards;

[0097] Efficient privacy verification: Using an improved zero-knowledge proof protocol for data consistency verification to reduce computational complexity and storage overhead;

[0098] Access control and auditing: Used to monitor and detect behaviors of abnormally accessing highly sensitive data.

[0099] The data sensitivity analysis process belongs to the prior art and will not be elaborated here;

[0100] Among them, the dynamic sharding processing adopts an improved sensitivity-driven sharding algorithm, which dynamically adjusts data sharding in combination with data distribution characteristics, sensitivity levels, and access frequencies, including:

[0101] Input:

[0102] D: Original data set;

[0103] A = {A1, A2,..., A n}: Set of data fields;

[0104] S(A i ): Sensitivity score of data field A i , with a value range of 0 - 1;

[0105] F(A i ): Data field A iThe access frequency;

[0106] T: The set sensitivity threshold;

[0107] K: The set number of shards;

[0108] Output:

[0109] P = {P1, P2,..., P m}: The data shard set;

[0110] E(P i ): The encryption strategy for shard P i ;

[0111] Among them, the sensitivity score calculation:

[0112] S(A i ) = α · R(A i ) + β · C(A i ) + γ · L(A i )

[0113] R(A i ): The data leakage risk; C(A i ): The data compliance requirements; L(A i ): The historical leakage record; α, β, γ: The weight parameters;

[0114] Among them, the access frequency calculation:

[0115] F(A i ) (t) = λ · F(A i ) (t-1) + (1 - λ) · A t

[0116] F(A i ) (t) : The access frequency calculated in the t-th round; A t : The number of accesses within the current time window; λ ∈ [0, 1]: The decay factor, determining the weight of historical accesses;

[0117] Among them, the calculation of the number of shards adopts a dynamic sharding strategy driven by sensitivity + access frequency, calculating the optimal number of shards K(A i ):

[0118]

[0119] W s ,W f : The weight coefficients of sensitivity and access frequency; C: The control parameter, determining the sharding granularity.

[0120] Specifically, a high-range sensitivity threshold T is set in the sensitivity score calculation h and a low-range T m , to classify the sensitivity levels of data fields:

[0121] Highly sensitive data, S(A i ) > T h : Use format-preserving encryption + shard key separation storage;

[0122] Medium-sensitive data, T m < S(A i ) ≤ T h : Use AES-128-GCM encryption or zero-knowledge proof protection;

[0123] Low-sensitive data, S(A i ) ≤ T m : Use partial desensitization or hash storage;

[0124] Among them, a threshold range F for access frequency is set th , to classify the access frequency levels:

[0125] F(A i ) > F th : Use zero-knowledge proof protection;

[0126] Furthermore, for highly sensitive data S(A i ) > T h , the number of shards should be increased to reduce the risk of a single storage node;

[0127] For high-access-frequency data F(A i ) > F th , the number of shards should be reduced to reduce query latency;

[0128] According to the shard number K(A i ), the data is sharded and different storage strategies are adopted:

[0129]

[0130] Among them, the main chain: stores data hashes, access control policies, and verification parameters;

[0131] The shard chain: stores encrypted data shards and performs decentralized storage through IPFS.

[0132] Among them, an example of the data desensitization process (medical scenario)

[0133] 1. Input: Complete patient medical records (including name, ID number, diagnosis information).

[0134] 2. Automatically label sensitive fields through a sensitive analysis engine.

[0135] 3. Adopt dynamic sharding (K = 3):

[0136] Shard 1: Patient identity information, encrypted using format-preserving encryption;

[0137] Shard 2: Diagnostic data, encrypted using AES-128-GCM;

[0138] Shard 3: Treatment records, protected using lightweight ZKP;

[0139] 4. Store the shards in different consensus nodes;

[0140] 5. Generate a Uniform Resource Identifier (URI) and chain it for access control management.

[0141] A specific example is shown in Table 1 below:

[0142]

[0143] Among them, the improved zero-knowledge proof protocol adopts an optimized variant of Bulletproofs, including:

[0144] 1) Use multiple Pedersen commitments:

[0145] C = vH + rG

[0146] Where: C is the commitment value; v is the data value to be protected; H, G are different base points; r is a random number;

[0147] To reduce the computational load, single-base point merging optimization is introduced:

[0148] C′ = (v1 + v2 + … + v n )H + (r1 + r2 + … r n )G

[0149] Merge n Pedersen commitments into 1, reducing the computational overhead by 50%;

[0150] 2) Bulletproofs uses vector inner product calculation for constraint verification:

[0151]

[0152] Where a and b are vectors, and P is the verification target, adopting parallel computing and recursive compression:

[0153] Parallel computing: Utilize single instruction multiple data technology to calculate multiple vector inner products simultaneously;

[0154] Recursive compression: Split a long vector into smaller sub-vectors, and recursively calculate the inner product for each sub-vector;

[0155] The computational cost of each proof can be reduced by 40% - 50%;

[0156] 3) Optimize batch verification using the double-base point technology:

[0157] C i = v i H + r i G

[0158] C j = v j H'+ r j G'

[0159] Perform refrigerator calculations through different base points H, H', and verify multiple transactions at once, avoiding the overhead of verifying one by one, and increasing the verification throughput by more than 2 times.

[0160] Specific example:

[0161] Assume the medical record data of the patient is as shown in Table 2 below:

[0162]

[0163] The hospital generates Pedersen commitments for each medical record data field of the patient:

[0164] C 年龄 = v 年龄 H + r 年龄 G

[0165] C 诊断 = v 诊断 H + r 诊断 G

[0166] C 服药情况 = v 服药 H + r 服药 G

[0167] where: v 年龄 ,v 诊断 ,v 服药 is the numerical representation of the case data;

[0168] H, G are different base points used to ensure security; r is a random number used to protect data privacy;

[0169] Generate zero-knowledge proofs:

[0170] 1. Whether the patient's age > 50 years old (meets the insurance claim conditions).

[0171] 2. Whether the patient has diabetes (diabetes is within the insurance coverage).

[0172] Zero-knowledge proof 1: The patient's age > 50

[0173] The hospital generates a vector inner product constraint:

[0174] v 年龄 -50 > 0

[0175] Since Bulletproofs supports range proofs, we use optimized vector inner product calculation to quickly verify this constraint:

[0176] Prove(55 - 50 > 0)

[0177] Reduce the computational complexity through recursive compression of the vector inner product;

[0178] Adopt SIMD (Single Instruction Multiple Data) optimization to calculate multiple medical record data simultaneously and improve throughput; Zero - knowledge proof 2: Whether the patient has diabetes

[0179] Constraint:

[0180] v 诊断 = diabetes

[0181] Verification:

[0182] Prove(C 诊断 = diabetes)

[0183] Since Bulletproofs allows boolean condition verification, the hospital can prove that the patient indeed has diabetes without revealing information about other diseases;

[0184] Optimization points:

[0185] Pedersen commitment merging: Reduce computational overhead;

[0186] Dual - base batch verification: Verify multiple patient medical records at once to improve throughput;

[0187] Furthermore, verify the data:

[0188] 1. Case data commitment C 年龄 , C 诊断

[0189] 2. Zero - knowledge proof P 年龄 , P 诊断

[0190] Execute Bulletproofs batch verification:

[0191] Verify commitment consistency:

[0192] C′ = PH + r′G

[0193] Verify the age range:

[0194] 55 - 50 > 0

[0195] Verification diagnosis compliance range:

[0196] v 诊断 = diabetes

[0197] If the verification passes, confirm the information:

[0198] The patient's age is indeed > 50 years old; the patient's case indeed contains diabetes; the patient's case has not been tampered with;

[0199] However, external personnel cannot obtain the patient's specific age or case content, achieving privacy protection.

[0200] A blockchain - based dynamic sharding desensitization privacy protection system, including:

[0201] Data sensitivity analysis module, used to perform sensitivity scoring on input data using a machine learning model and automatically label sensitive fields based on the scoring results;

[0202] Dynamic sharding processing module, used to adaptively adjust the sharding strategy according to the sensitivity score, including full - desensitization sharding, partial - desensitization sharding, and format - preserving sharding;

[0203] Multi - level privacy protection module, used to perform data protection on different types of data shards using format - preserving encryption, lightweight zero - knowledge proof, and homomorphic encryption respectively;

[0204] Double - chain storage module, used to store data through the main chain and sharding chain, where the main chain stores data hashes, access policies, and verification parameters, and the sharding chain stores encrypted data shards;

[0205] Efficient privacy verification module, used to perform data consistency verification using an improved zero - knowledge proof protocol to reduce computational complexity and storage overhead;

[0206] Access control and auditing module, used to monitor and detect behaviors of accessing highly sensitive data abnormally.

[0207] Specifically, the access control and auditing module is used to monitor and detect behaviors of accessing highly sensitive data abnormally. When the same user frequently requests specific highly sensitive data within a short period of time, the system will trigger an on - chain warning mechanism and notify the regulatory department for auditing, specifically including:

[0208] Access log storage: Record all sensitive data requests accessed by users, including user ID, data category, access time, IP address;

[0209] Threshold detection: Set an access frequency threshold, such as N times / minute, and trigger anomaly detection when the threshold is exceeded;

[0210] Abnormal warning: Once an abnormal access behavior is detected, the contract immediately generates a warning event, broadcasts it on the chain and stores the evidence;

[0211] Automatically notify the regulatory agency: Trigger the on-chain audit contract, send an alarm message to the relevant regulatory account, and request an audit of the access behavior. This process belongs to the prior art.

[0212] Applicable scenarios: Medical data access supervision (protect patient privacy and prevent malicious queries).

[0213] The present invention also provides a computer device, applicable to a situation of a dynamic sharding desensitization privacy protection method based on blockchain, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement a dynamic sharding desensitization privacy protection method based on blockchain as proposed in the above invention.

[0214] The computer device can be a terminal. The computer device includes a processor, a memory, a communication interface, a display screen and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner. The wireless manner can be achieved through WIFI, a carrier network, NFC (Near Field Communication) or other technologies. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer covered on the display screen, or a button, a trackball or a touchpad set on the shell of the computer device, or an external keyboard, a touchpad or a mouse, etc.

[0215] The present invention also provides a storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the method for realizing dynamic sharding desensitization privacy protection based on blockchain as proposed in the above invention; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM for short), electrically erasable programmable read-only memory (EEPROM for short), erasable programmable read-only memory (EPROM for short), programmable read-only memory (PROM for short), read-only memory (ROM for short), magnetic memory, flash memory, a magnetic disk or an optical disc.

[0216] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.

Claims

1. A dynamic sharding desensitization privacy protection method based on blockchain, characterized in that, It includes the following steps: Data sensitivity analysis: Use a machine learning model to perform sensitivity scoring on the input data and automatically label sensitive fields based on the scoring results; Dynamic sharding processing: Adaptively adjust the sharding strategy according to the sensitivity score, including full desensitization sharding, partial desensitization sharding, and format-preserving sharding; Multi-level privacy protection: For different types of data shards, use format-preserving encryption, lightweight zero-knowledge proof, and homomorphic encryption for data protection respectively; Double-chain storage architecture: Store data through the main chain and the sharding chain, where the main chain stores data hashes, access policies, and verification parameters, and the sharding chain stores encrypted data shards; Efficient privacy verification: Use an improved zero-knowledge proof protocol for data consistency verification to reduce computational complexity and storage overhead; Access control and auditing: Used to monitor and detect behaviors of accessing highly sensitive data abnormally.

2. The dynamic sharding desensitization privacy protection method based on blockchain according to claim 1, characterized in that: The dynamic sharding processing adopts an improved sensitivity-driven sharding algorithm, which combines data distribution characteristics, sensitivity levels, and access frequencies to dynamically adjust data shards, including: Input: D: The original data set; A = {A1, A2, …, A n}: A set of data fields; S(A i ):Sensitivity score of data field A i , ranging from 0 to 1; F(A i ):The access frequency of data field A i ; T: The set sensitivity demarcation threshold; K: The set number of shards; Output: P = {P1, P2, …, P m}: A set of data shards; E(P i ): Encryption policy for shard P i ; Among them, the sensitivity score calculation: S(A i ) = α·R(A i ) + β·C(A i ) + γ·L(A i ) R(A i ): Data leakage risk; C(A i ): Data compliance requirements; L(A i ): Historical leakage records; α, β, γ: Weight parameters; Among them, the access frequency calculation: F(A i ) (t) = λ·F(A i ) (t-1) + (1 - λ)·A t F(A i ) (t) : The access frequency calculated in the t-th round; A t : The number of accesses within the current time window; λ ∈ [0, 1]: The decay factor, which determines the weight of historical accesses; Among them, the calculation of the number of shards adopts a dynamic sharding strategy driven by sensitivity + access frequency to calculate the optimal number of shards K(A i ): W s , W f : The weight coefficient of sensitivity and access frequency; C: The control parameter, which determines the sharding granularity.

3. The dynamic sharding desensitization privacy protection method based on blockchain according to claim 2, characterized in that: In the calculation of the sensitivity score, a high range T of the sensitivity threshold is set h and a low range T m , and the sensitive levels of the data fields are divided: Highly sensitive data, S(A i )>T h : Adopt format-preserving encryption + separate storage of shard keys; Sensitive data, T m <S(A i ) ≤ T h : Protected by AES-128-GCM encryption or zero-knowledge proof; Low-sensitivity data, S(A i ) ≤ T m : Use partial desensitization or hash storage; Among them, the access frequency threshold range F is set th , and the access frequency levels are divided: F(A i )>F th : Protected by zero-knowledge proof.

4. The method for dynamically sharding and desensitizing privacy protection based on blockchain according to claim 3, wherein: For highly sensitive data S(A i )>T h , the number of shards should be increased to reduce the risk of a single storage node; For high-access-frequency data F(A i )>F th , the number of shards should be reduced to lower the query latency.

5. The dynamic sharding desensitization privacy protection method based on blockchain according to claim 4, wherein: According to the shard number K(A i ), the data is sharded and different storage strategies are adopted: Among them, the main chain: Stores data hashes, access control policies, and verification parameters; The sharding chain: Stores encrypted data shards and performs decentralized storage through IPFS.

6. The method for dynamic sharding desensitization privacy protection based on blockchain according to claim 5, characterized in that: The improved zero-knowledge proof protocol adopts an optimized Bulletproofs variant, including: 1) Use multiple Pedersen commitments: C = vH + rG Where: C is the commitment value; v is the protected data value; H, G are different base points; r is a random number; To reduce the computational amount, single-base point merging optimization is introduced: C′ = (v1 + v2 + … + v n )H + (r1 + r2 + … r n )G Merge n Pedersen commitments into 1, reducing the computational overhead by 50%; 2) Bulletproofs uses vector inner product calculation for constraint verification: Among them, a and b are vectors, P is the verification target, and parallel computing and recursive compression are adopted: Parallel computing: Use single instruction multiple data technology to calculate multiple vector inner products simultaneously; Recursive compression: Split the long vector into smaller sub-vectors, and calculate the inner product of each sub-vector recursively; The computational cost of each proof can be reduced by 40% - 50%; 3) Use the double-base point technology to optimize batch verification: C i = v i H + r i G C j = v j H′ + r j G′ Perform refrigerator calculation through different base points H, H', and verify multiple transactions at one time, avoiding the overhead of verifying one by one, and increasing the verification throughput by more than 2 times.

7. A blockchain-based dynamic sharding desensitization privacy protection system, characterized in that: It includes: A data sensitivity analysis module, which is used to perform sensitivity scoring on the input data using a machine learning model and automatically label sensitive fields based on the scoring results; A dynamic sharding processing module, which is used to adaptively adjust the sharding strategy according to the sensitivity score, including full desensitization sharding, partial desensitization sharding, and format-preserving sharding; A multi-level privacy protection module, which is used to use format-preserving encryption, lightweight zero-knowledge proof, and homomorphic encryption for data protection for different types of data shards respectively; A double-chain storage module, which is used to store data through the main chain and the sharding chain, where the main chain stores data hashes, access policies, and verification parameters, and the sharding chain stores encrypted data shards; An efficient privacy verification module for verifying data consistency using an improved zero-knowledge proof protocol to reduce computational complexity and storage overhead; An access control and auditing module for monitoring and detecting behaviors of accessing highly sensitive data abnormally.

8. The blockchain-based dynamic sharding desensitization privacy protection system according to claim 7, wherein: The access control and auditing module is used to monitor and detect behaviors of accessing highly sensitive data abnormally. When the same user frequently requests specific highly sensitive data within a short period of time, the system will trigger an on-chain early warning mechanism and notify the regulatory department for auditing, specifically including: Access log storage: Recording all sensitive data requests accessed by users, including user ID, data category, access time, and IP address; Threshold detection: Setting an access frequency threshold, such as N times / minute, and triggering abnormal detection when the threshold is exceeded; Abnormal early warning: Once an abnormal access behavior is detected, the contract immediately generates an early warning event, broadcasts it on the chain and stores the evidence; Automatically notifying the regulatory agency: Triggering an on-chain audit contract and sending an alarm message to the relevant regulatory account to request an audit of the access behavior.

9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that: When the processor executes the computer program, it implements the steps of any one of claims 1 to 6 of a blockchain-based dynamic sharding desensitization privacy protection method.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, it implements the steps of any one of claims 1 to 6 of a blockchain-based dynamic sharding desensitization privacy protection method.

Citation Information

Cited By

  • Database management system with data stream security and real-time data protection

    CN120763216A