Block chain-based big data storage and access control method and system, and medium

Through the data sharding and distributed storage and dynamic verification methods of blockchain technology, the problem of insufficient data security risks and access control in the cultural big data system is solved, and secure storage and intelligent access control are realized.

CN120455098APending Publication Date: 2025-08-08BEIJING GUOXIN NETWORK TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510633998.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-16
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

The national cultural big data system has problems of data security risks and insufficient access control during storage and transmission, especially in the multi-institutional collaboration scenario.

Method used

Data sharding and distributed storage, dynamic verification and access control methods are adopted to realize secure storage and intelligent access control of big data through blockchain technology, including data sharding processing, distributed storage, smart contract verification and real-time monitoring of access behavior.

Benefits of technology

It improves the security and flexibility of big data, ensuring secure storage and dynamic permission management of data in multi-institutional collaboration scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455098A_ABST
    Figure CN120455098A_ABST
Patent Text Reader

Abstract

The invention provides a block chain-based big data storage and access control method and system and a medium. The method comprises the steps of obtaining predetermined big data, performing data fragmentation processing, generating predetermined data blocks, performing distributed storage on the predetermined data blocks, obtaining user identity information according to data access demand information, performing verification through an intelligent contract, triggering data access permission and generating a data access permission response if the user identity information passes the verification, and sending the data access permission response to the user. And finally, monitoring the data access permission response in real time, recording access behavior data, judging a user access behavior according to the access behavior data, and performing access control according to the user access behavior. Through data fragmentation, distributed storage, dynamic verification and access control, secure storage and intelligent access control of the predetermined big data are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of predetermined big data storage and access control technology, and in particular to a blockchain-based big data storage and access control method, system, and medium. Background Art

[0002] With the construction and development of the national cultural big data system, massive amounts of cultural data need to be stored and managed securely and efficiently. Currently, the construction of the national cultural big data system faces the following technical problems: data security risks. Cultural resource data, such as cultural heritage specimen libraries and gene libraries, are susceptible to tampering or leakage during storage and transmission, and traditional centralized storage has a single point failure risk. Access control is insufficient. Existing authority management relies on a centralized system, making it difficult to dynamically adapt to multi-institutional collaboration scenarios, and the efficiency of authority changes is low. Among existing technologies, although blockchain technology has been mentioned for data storage, it has not been deeply integrated into the storage architecture and access control mechanism of the cultural big data system. In particular, there is a lack of systematic solutions in the collaborative scenarios of multi-level cultural data service centers.

[0003] In response to the above problems, effective technical solutions are urgently needed. Summary of the Invention

[0004] The purpose of this application is to provide a big data storage and access control method, system and medium based on blockchain, which can realize the secure storage and intelligent access control of predetermined big data through data sharding and distributed storage, dynamic verification and access control.

[0005] This application also provides a big data storage and access control method based on blockchain, including the following steps:

[0006] Obtain predetermined big data, perform data sharding processing, and generate predetermined data blocks;

[0007] Distributed storage of the predetermined data blocks;

[0008] Obtain user identity information based on data access requirements and verify it through smart contracts. If verified, data access permission is triggered and a data access permission response is generated.

[0009] The data access permission response is monitored in real time and access behavior data is recorded, user access behavior is determined based on the access behavior data, and access control is performed based on the user access behavior.

[0010] Optionally, in the blockchain-based big data storage and access control method described in the present application, obtaining predetermined big data and performing data sharding processing to generate predetermined data blocks includes:

[0011] Obtain predetermined big data and extract data security attribute information and data metadata;

[0012] The data security attribute information includes top secret, confidential or secret;

[0013] The data metadata includes the data DCI code and data ownership information;

[0014] The predetermined big data is subjected to data slicing processing according to the data security attribute information to generate top secret predetermined data blocks, confidential predetermined data blocks and secret predetermined data blocks.

[0015] Optionally, in the blockchain-based big data storage and access control method described in this application, the distributed storage of the predetermined data blocks includes:

[0016] Processing the top secret predetermined data block, the confidential predetermined data block, and the secret predetermined data block respectively through a hash algorithm to obtain corresponding hash values, including a first hash value, a second hash value, and a third hash value;

[0017] Storing the data DCI code, data ownership information, and corresponding hash value in the blockchain;

[0018] Get the encryption key;

[0019] Encrypting the top secret predetermined data block, the confidential predetermined data block, and the secret predetermined data block respectively according to the encryption key to obtain a top secret predetermined encrypted data block, a confidential predetermined encrypted data block, and a secret predetermined encrypted data block;

[0020] The top secret predetermined encrypted data block, the confidential predetermined encrypted data block and the secret predetermined encrypted data block are stored in a distributed storage center in combination with corresponding preset access authority information.

[0021] Optionally, in the blockchain-based big data storage and access control method described in this application, obtaining user identity information based on data access requirement information and verifying it through a smart contract, triggering data access permission if passed, and generating a data access permission response, includes:

[0022] Obtain data access requirement information and user identity information;

[0023] The user identity information includes user identity identification information and user authority level information;

[0024] The blockchain node performs access verification through a smart contract based on the user identity information and user authority level information;

[0025] If the verification is successful, data access permission is triggered, and the predetermined big data is transmitted to the user end for display;

[0026] If the verification fails, data access is denied and an early warning response is output.

[0027] Optionally, the blockchain-based big data storage and access control method described in this application further includes:

[0028] The smart contracts include global contracts, regional contracts and local contracts;

[0029] Obtain permission change information, including user identity change information, data ownership change information, or access permission change information;

[0030] The access control method is dynamically adjusted through the smart contract according to the permission change information.

[0031] Optionally, in the blockchain-based big data storage and access control method described in this application, real-time monitoring of the data access permission response and recording of access behavior data, determining user access behavior based on the access behavior data, and performing access control based on the user access behavior include:

[0032] Monitor user access behavior in real time and record access behavior data, including access time, access data DCI code, and access operation feature data;

[0033] Inputting the access time, access data DCI code and access operation characteristic data into a preset access credibility prediction model for processing to obtain access risk parameters;

[0034] Comparing the access risk parameter with a preset access risk control threshold;

[0035] If the value is less than or equal to the preset access risk control threshold, the user's access behavior is considered normal and the access behavior data is recorded in the blockchain;

[0036] If it is greater than the preset access risk control threshold, the user access behavior is judged to be abnormal and data access is suspended.

[0037] In a second aspect, this application provides a big data storage and access control system based on blockchain, which includes:

[0038] A distributed data storage module, including a blockchain storage unit and a distributed storage center unit, for distributed storage and data retrieval of predetermined big data;

[0039] The data access control module includes an authentication unit, an access processing unit, and an access control unit, which are used to verify user access rights and control access behavior;

[0040] The data security and transmission module includes a data transmission unit, a data encryption unit, and a data decryption unit, and is used to encrypt, decrypt, and transmit predetermined large data;

[0041] Smart contract storage module, used to store smart contracts.

[0042] Optionally, in the blockchain-based big data storage and access control system described in the present application, the system further includes: a memory and a processor, wherein the memory includes a program of the blockchain-based big data storage and access control method, and when the program of the blockchain-based big data storage and access control method is executed by the processor, the following steps are implemented:

[0043] Obtain predetermined big data, perform data sharding processing, and generate predetermined data blocks;

[0044] Distributed storage of the predetermined data blocks;

[0045] Obtain user identity information based on data access requirements and verify it through smart contracts. If verified, data access permission is triggered and a data access permission response is generated.

[0046] The data access permission response is monitored in real time and access behavior data is recorded, user access behavior is determined based on the access behavior data, and access control is performed based on the user access behavior.

[0047] Optionally, in the blockchain-based big data storage and access control system described in the present application, obtaining predetermined big data and performing data sharding processing to generate predetermined data blocks includes:

[0048] Obtain predetermined big data and extract data security attribute information and data metadata;

[0049] The data security attribute information includes top secret, confidential or secret;

[0050] The data metadata includes the data DCI code and data ownership information;

[0051] The predetermined big data is subjected to data slicing processing according to the data security attribute information to generate top secret predetermined data blocks, confidential predetermined data blocks and secret predetermined data blocks.

[0052] In a third aspect, the present application also provides a computer-readable storage medium, which stores a blockchain-based big data storage and access control method program. When the blockchain-based big data storage and access control method program is executed by a processor, the steps of the blockchain-based big data storage and access control method as described in any one of the above items are implemented.

[0053] From the above, it can be seen that the blockchain-based big data storage and access control method, system and medium provided in this application realize the secure storage and intelligent access control of predetermined big data through data sharding and distributed storage, dynamic verification and access control.

[0054] Other features and advantages of the present application will be described in the following description, and in part will become apparent from the description, or understood by practicing the embodiments of the present application. The objectives and other advantages of the present application can be achieved and obtained through the structures particularly pointed out in the written description and the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.

[0056] Figure 1 A flowchart of a blockchain-based big data storage and access control method provided in an embodiment of the present application;

[0057] Figure 2 A flowchart of generating a predetermined data block for the blockchain-based big data storage and access control method provided in an embodiment of the present application;

[0058] Figure 3 A flowchart of generating a data access permission response for the blockchain-based big data storage and access control method provided in an embodiment of the present application;

[0059] Figure 4 A system diagram of a blockchain-based big data storage and access control system provided in an embodiment of the present application. DETAILED DESCRIPTION

[0060] The technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. The components of the embodiments of the present application generally described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the application for protection, but merely represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work fall within the scope of protection of the present application.

[0061] It should be noted that similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings. At the same time, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and should not be understood as indicating or implying relative importance.

[0062] Please refer to Figure 1 , Figure 1 This is a flowchart of a blockchain-based big data storage and access control method in some embodiments of the present application. The blockchain-based big data storage and access control method is used in terminal devices, such as computers and mobile terminals. The blockchain-based big data storage and access control method includes the following steps:

[0063] S11, obtaining predetermined big data, and performing data sharding processing to generate predetermined data blocks;

[0064] S12, performing distributed storage on the predetermined data blocks;

[0065] S13. Obtain user identity information based on data access request information and verify it through a smart contract. If it passes, data access permission is triggered and a data access permission response is generated;

[0066] S14. Monitor the data access permission response in real time and record access behavior data, determine the user access behavior based on the access behavior data, and perform access control based on the user access behavior.

[0067] It should be noted that in order to improve the storage security and access flexibility of scheduled big data, the scheduled big data collected from multiple data sources will be cleaned and structured, pre-processed, and then sharded according to the data confidentiality level, and distributed stored. Among them, scheduled big data refers to cultural big data; when users have access needs, user permissions are dynamically verified through preset contracts, and access control methods are adjusted accordingly, thereby achieving improved data security and enhanced access control flexibility based on blockchain.

[0068] Please refer to Figure 2 , Figure 2 This is a flowchart of a method for storing and accessing big data based on blockchain in some embodiments of the present application, wherein the method of generating predetermined data blocks includes: obtaining predetermined big data, performing data sharding processing, and generating predetermined data blocks;

[0069] S21. Obtain predetermined big data and extract data security attribute information and data metadata;

[0070] S22, the data security attribute information includes top secret, confidential or secret;

[0071] S23, the data metadata includes a data DCI code and data ownership information;

[0072] S24. Slice the predetermined big data according to the data security attribute information to generate top secret predetermined data blocks, confidential predetermined data blocks, and secret predetermined data blocks.

[0073] It should be noted that in order to realize distributed data storage and improve data access flexibility and security, the data security attribute information including top secret, confidential or secret is first extracted, including data metadata information of data DCI code and data ownership information, wherein the data DCI code is the data unique identifier, and the data ownership information includes the data owner, data access rights and / or data copyright status; then the predetermined big data is segmented according to the data security attribute information to improve the data basis for distributed storage.

[0074] According to an embodiment of the present invention, the distributed storage of the predetermined data blocks includes:

[0075] Processing the top secret predetermined data block, the confidential predetermined data block, and the secret predetermined data block respectively through a hash algorithm to obtain corresponding hash values, including a first hash value, a second hash value, and a third hash value;

[0076] Storing the data DCI code, data ownership information, and corresponding hash value in the blockchain;

[0077] Get the encryption key;

[0078] Encrypting the top secret predetermined data block, the confidential predetermined data block, and the secret predetermined data block respectively according to the encryption key to obtain a top secret predetermined encrypted data block, a confidential predetermined encrypted data block, and a secret predetermined encrypted data block;

[0079] The top secret predetermined encrypted data block, the confidential predetermined encrypted data block and the secret predetermined encrypted data block are stored in a distributed storage center in combination with corresponding preset access authority information.

[0080] It should be noted that in order to improve the security of the reserved big data, a hybrid storage mode is constructed, that is, the data source information, namely the data DCI code and data ownership information and the corresponding hash value are stored on the blockchain, and the actual content data is encrypted, namely the top secret reserved encrypted data block, the confidential reserved encrypted data block and the secret reserved encrypted data block are stored in the distributed storage center, which improves security while ensuring data access efficiency. Among them, the first hash value corresponds to the top secret reserved data block, the second hash value corresponds to the confidential reserved data block, and the third hash value corresponds to the secret reserved data block.

[0081] Please refer to Figure 3 , Figure 3 This is a flowchart of generating a data access permission response for a blockchain-based big data storage and access control method in some embodiments of the present application. According to embodiments of the present invention, obtaining user identity information based on data access requirement information and verifying it through a smart contract triggers data access permission if it passes, generating a data access permission response, including:

[0082] S31. Obtain data access requirement information and user identity information;

[0083] S32, the user identity information includes user identity identification information and user authority level information;

[0084] S33. The blockchain node performs access verification through a smart contract based on the user identity information and user authority level information;

[0085] S34. If the verification is successful, data access permission is triggered, and the predetermined big data is transmitted to the user terminal for display;

[0086] S35. If the verification fails, data access is denied and an early warning response is output.

[0087] It should be noted that users (such as cultural institutions and / or cultural and creative enterprises, etc.) perform identity authentication and registration through a preset big data platform to obtain a unique identity, that is, user identity information, and assign different user authority level information according to different identity identifiers. When a user initiates a data access request, the access request is transmitted to the distributed storage center blockchain node and authenticated through a preset contract. If passed, data access is allowed, and the stored predetermined big data is decrypted and sent to the user end for display. Otherwise, access is denied and an early warning response is output to avoid illegal access and improve data security.

[0088] According to an embodiment of the present invention, the further embodiment includes:

[0089] The smart contracts include global contracts, regional contracts and local contracts;

[0090] Obtain permission change information, including user identity change information, data ownership change information, or access permission change information;

[0091] The access control method is dynamically adjusted through the smart contract according to the permission change information.

[0092] It should be noted that since user identity information and scheduled data access rights change dynamically, in order to improve the accuracy of access control and build a dynamic access control mechanism, this embodiment designs a multi-layer smart contract system, that is, the global contract corresponds to the national center, which is used to manage cross-regional scheduled data, the regional contract corresponds to the regional center, which is used for scheduled data management and permission allocation within the region, and the local contract corresponds to the provincial center, which is used for permission allocation and data management of local users. Before performing identity and permission verification, the permission change information is first obtained. If there is a change, the access control method is adjusted according to the changed information. If there is no change, no adjustment is required.

[0093] According to an embodiment of the present invention, the real-time monitoring of the data access permission response and recording of access behavior data, determining user access behavior based on the access behavior data, and performing access control based on the user access behavior include:

[0094] Monitor user access behavior in real time and record access behavior data, including access time, access data DCI code, and access operation feature data;

[0095] Inputting the access time, access data DCI code and access operation characteristic data into a preset access credibility prediction model for processing to obtain access risk parameters;

[0096] Comparing the access risk parameter with a preset access risk control threshold;

[0097] If the value is less than or equal to the preset access risk control threshold, the user's access behavior is considered normal and the access behavior data is recorded in the blockchain;

[0098] If it is greater than the preset access risk control threshold, the user access behavior is judged to be abnormal and data access is suspended.

[0099] It should be noted that after the user is allowed to access, in order to ensure the legality of the user's access behavior, the access behavior is monitored in real time, and the access behavior data including access time, access data DCI code and access operation characteristic data are recorded, wherein the access operation characteristic data includes downloading, copying and / or modification, which is processed by a preset access credibility prediction model to obtain access risk parameters, and finally, whether the user access behavior is normal is determined by threshold comparison. If it is abnormal, data access is suspended, wherein the preset access credibility prediction model is obtained by training by obtaining the access time, access data DCI code and access operation characteristic data and corresponding access risk parameters of a large number of historical samples.

[0100] It is worth mentioning that according to an embodiment of the present invention, the present invention further includes:

[0101] Get access verification violation information;

[0102] Query the preset priority of the smart contract based on access verification conflict information;

[0103] The access verification pass status is determined according to the preset priority.

[0104] It should be noted that due to the design of a multi-layer smart contract system, when there is a conflict in the access rights assigned by different contracts, for example, the local contract allows a user to access data, while the regional contract prohibits access, the preset priority of the smart contract will be queried. If the regional contract priority is higher than the local contract, the user will be prohibited from accessing the data.

[0105] It is worth mentioning that according to an embodiment of the present invention, the present invention further includes:

[0106] Get user attribute code;

[0107] Calculate the user attribute code using a preset hash algorithm to obtain an identity commitment value;

[0108] generating an identity certificate through a preset protocol according to the identity commitment value;

[0109] A matching verification is performed through a smart contract based on the identity proof. If successful, a temporary data access token is issued;

[0110] The blockchain node performs matching verification based on the temporary data access token and the preset encryption method. If successful, the encrypted predetermined data will be decrypted and sent to the user end for display.

[0111] It should be noted that during the identity authentication process, zero-knowledge proof technology is used for privacy protection to prevent user identity leakage. The user identity attributes of the verification process are performed in a confidential form to achieve decentralized authentication. First, the user is encoded according to the user attributes including the affiliated institution, the affiliated region, the identity role and the identity authority information, such as "Museum_EAST_001:east_china:researcher:2", and an identity commitment value is generated through hash calculation, such as Commitment = SHA256("Museum_EAST_001:east_china:researcher:2")→0x3a7d... Then, this embodiment uses the zk-SNARKs protocol to generate identity proof, and then verifies whether the identity proof satisfies the smart contract. If it does, a temporary data access token is issued. Finally, the blockchain node storing the data performs a matching verification of the encryption method. If it passes, the decryption key is returned and the predetermined big data to be accessed is decrypted. If any link fails the verification, data access is denied.

[0112] Please refer to Figure 4 , Figure 4This is a system diagram of a blockchain-based big data storage and access control system in some embodiments of the present application.

[0113] In a second aspect, the present invention further discloses a big data storage and access control system 4 based on blockchain, which includes:

[0114] Distributed data storage module 41, including blockchain storage unit 411 and distributed storage center unit 412, for distributed storage and data retrieval of predetermined big data;

[0115] The data access control module 42 includes an identity authentication unit 421, an access processing unit 422, and an access control unit 423, and is used to verify the user's access rights and control access behavior;

[0116] The data security and transmission module 43 includes a data transmission unit 431, a data encryption unit 432, and a data decryption unit 333, and is used to encrypt, decrypt, and transmit predetermined large data;

[0117] The smart contract storage module 44 is used to store smart contracts.

[0118] According to an embodiment of the present invention, the blockchain-based big data storage and access control system further includes a memory and a processor, wherein the memory includes a blockchain-based big data storage and access control method program, and when the blockchain-based big data storage and access control method program is executed by the processor, the following steps are implemented:

[0119] Obtain predetermined big data, perform data sharding processing, and generate predetermined data blocks;

[0120] Distributed storage of the predetermined data blocks;

[0121] Obtain user identity information based on data access requirements and verify it through smart contracts. If verified, data access permission is triggered and a data access permission response is generated.

[0122] The data access permission response is monitored in real time and access behavior data is recorded, user access behavior is determined based on the access behavior data, and access control is performed based on the user access behavior.

[0123] It should be noted that in order to improve the storage security and access flexibility of scheduled big data, the scheduled big data collected from multiple data sources will be cleaned and structured, pre-processed, and then sharded according to the data confidentiality level, and distributed stored. Among them, scheduled big data refers to cultural big data; when users have access needs, user permissions are dynamically verified through preset contracts, and access control methods are adjusted accordingly, thereby achieving improved data security and enhanced access control flexibility based on blockchain.

[0124] According to an embodiment of the present invention, obtaining predetermined big data and performing data slicing processing to generate predetermined data blocks includes:

[0125] Obtain predetermined big data and extract data security attribute information and data metadata;

[0126] The data security attribute information includes top secret, confidential or secret;

[0127] The data metadata includes the data DCI code and data ownership information;

[0128] The predetermined big data is subjected to data slicing processing according to the data security attribute information to generate top secret predetermined data blocks, confidential predetermined data blocks and secret predetermined data blocks.

[0129] It should be noted that in order to realize distributed data storage and improve data access flexibility and security, the data security attribute information including top secret, confidential or secret is first extracted, including data metadata information of data DCI code and data ownership information, wherein the data DCI code is the data unique identifier, and the data ownership information includes the data owner, data access rights and / or data copyright status; then the predetermined big data is segmented according to the data security attribute information to improve the data basis for distributed storage.

[0130] According to an embodiment of the present invention, the distributed storage of the predetermined data blocks includes:

[0131] Processing the top secret predetermined data block, the confidential predetermined data block, and the secret predetermined data block respectively through a hash algorithm to obtain corresponding hash values, including a first hash value, a second hash value, and a third hash value;

[0132] Storing the data DCI code, data ownership information, and corresponding hash value in the blockchain;

[0133] Get the encryption key;

[0134] Encrypting the top secret predetermined data block, the confidential predetermined data block, and the secret predetermined data block respectively according to the encryption key to obtain a top secret predetermined encrypted data block, a confidential predetermined encrypted data block, and a secret predetermined encrypted data block;

[0135] The top secret predetermined encrypted data block, the confidential predetermined encrypted data block and the secret predetermined encrypted data block are stored in a distributed storage center in combination with corresponding preset access authority information.

[0136] It should be noted that in order to improve the security of the reserved big data, a hybrid storage mode is constructed, that is, the data source information, namely the data DCI code and data ownership information and the corresponding hash value are stored on the blockchain, and the actual content data is encrypted, namely the top secret reserved encrypted data block, the confidential reserved encrypted data block and the secret reserved encrypted data block are stored in the distributed storage center, which improves security while ensuring data access efficiency. Among them, the first hash value corresponds to the top secret reserved data block, the second hash value corresponds to the confidential reserved data block, and the third hash value corresponds to the secret reserved data block.

[0137] According to an embodiment of the present invention, the user identity information is obtained based on the data access requirement information, and is verified through a smart contract. If the verification is successful, data access permission is triggered, and a data access permission response is generated, including:

[0138] Obtain data access requirement information and user identity information;

[0139] The user identity information includes user identity identification information and user authority level information;

[0140] The blockchain node performs access verification through a smart contract based on the user identity information and user authority level information;

[0141] If the verification is successful, data access permission is triggered, and the predetermined big data is transmitted to the user end for display;

[0142] If the verification fails, data access is denied and an early warning response is output.

[0143] It should be noted that users (such as cultural institutions and / or cultural and creative enterprises, etc.) perform identity authentication and registration through a preset big data platform to obtain a unique identity, that is, user identity information, and assign different user authority level information according to different identity identifiers. When a user initiates a data access request, the access request is transmitted to the distributed storage center blockchain node and authenticated through a preset contract. If passed, data access is allowed, and the stored predetermined big data is decrypted and sent to the user end for display. Otherwise, access is denied and an early warning response is output to avoid illegal access and improve data security.

[0144] According to an embodiment of the present invention, the further embodiment includes:

[0145] The smart contracts include global contracts, regional contracts and local contracts;

[0146] Obtain permission change information, including user identity change information, data ownership change information, or access permission change information;

[0147] The access control method is dynamically adjusted through the smart contract according to the permission change information.

[0148] It should be noted that since user identity information and scheduled data access rights change dynamically, in order to improve the accuracy of access control and build a dynamic access control mechanism, this embodiment designs a multi-layer smart contract system, that is, the global contract corresponds to the national center, which is used to manage cross-regional scheduled data, the regional contract corresponds to the regional center, which is used for scheduled data management and permission allocation within the region, and the local contract corresponds to the provincial center, which is used for permission allocation and data management of local users. Before performing identity and permission verification, the permission change information is first obtained. If there is a change, the access control method is adjusted according to the changed information. If there is no change, no adjustment is required.

[0149] According to an embodiment of the present invention, the real-time monitoring of the data access permission response and recording of access behavior data, determining user access behavior based on the access behavior data, and performing access control based on the user access behavior include:

[0150] Monitor user access behavior in real time and record access behavior data, including access time, access data DCI code, and access operation feature data;

[0151] Inputting the access time, access data DCI code and access operation characteristic data into a preset access credibility prediction model for processing to obtain access risk parameters;

[0152] Comparing the access risk parameter with a preset access risk control threshold;

[0153] If the value is less than or equal to the preset access risk control threshold, the user's access behavior is considered normal and the access behavior data is recorded in the blockchain;

[0154] If it is greater than the preset access risk control threshold, the user access behavior is judged to be abnormal and data access is suspended.

[0155] It should be noted that after the user is allowed to access, in order to ensure the legality of the user's access behavior, the access behavior is monitored in real time, and the access behavior data including access time, access data DCI code and access operation characteristic data are recorded, wherein the access operation characteristic data includes downloading, copying and / or modification, which is processed by a preset access credibility prediction model to obtain access risk parameters, and finally, whether the user access behavior is normal is determined by threshold comparison. If it is abnormal, data access is suspended, wherein the preset access credibility prediction model is obtained by training by obtaining the access time, access data DCI code and access operation characteristic data and corresponding access risk parameters of a large number of historical samples.

[0156] It is worth mentioning that according to an embodiment of the present invention, the present invention further includes:

[0157] Get access verification violation information;

[0158] Query the preset priority of the smart contract based on access verification conflict information;

[0159] The access verification pass status is determined according to the preset priority.

[0160] It should be noted that due to the design of a multi-layer smart contract system, when there is a conflict in the access rights assigned by different contracts, for example, the local contract allows a user to access data, while the regional contract prohibits access, the preset priority of the smart contract will be queried. If the regional contract priority is higher than the local contract, the user will be prohibited from accessing the data.

[0161] It is worth mentioning that according to an embodiment of the present invention, the present invention further includes:

[0162] Get user attribute code;

[0163] Calculate the user attribute code using a preset hash algorithm to obtain an identity commitment value;

[0164] generating an identity certificate through a preset protocol according to the identity commitment value;

[0165] A matching verification is performed through a smart contract based on the identity proof. If successful, a temporary data access token is issued;

[0166] The blockchain node performs matching verification based on the temporary data access token and the preset encryption method. If successful, the encrypted predetermined data will be decrypted and sent to the user end for display.

[0167] It should be noted that during the identity authentication process, zero-knowledge proof technology is used for privacy protection to prevent user identity leakage. The user identity attributes of the verification process are performed in a confidential form to achieve decentralized authentication. First, the user is encoded according to the user attributes including the affiliated institution, the affiliated region, the identity role and the identity authority information, such as "Museum_EAST_001:east_china:researcher:2", and an identity commitment value is generated through hash calculation, such as Commitment = SHA256("Museum_EAST_001:east_china:researcher:2")→0x3a7d... Then, this embodiment uses the zk-SNARKs protocol to generate identity proof, and then verifies whether the identity proof satisfies the smart contract. If it does, a temporary data access token is issued. Finally, the blockchain node storing the data performs a matching verification of the encryption method. If it passes, the decryption key is returned and the predetermined big data to be accessed is decrypted. If any link fails the verification, data access is denied.

[0168] A third aspect of the present invention provides a readable storage medium, which stores a blockchain-based big data storage and access control method program. When the blockchain-based big data storage and access control method program is executed by a processor, the steps of the blockchain-based big data storage and access control method as described in any one of the above items are implemented.

[0169] The blockchain-based big data storage and access control method, system and medium disclosed in the present invention realize the secure storage and intelligent access control of predetermined big data through data sharding and distributed storage, dynamic verification and access control.

[0170] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as: multiple units or components can be combined, or can be integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be electrical, mechanical or other forms.

[0171] The units described above as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units; they may be located in one place or distributed across multiple network units; some or all of the units may be selected according to actual needs to achieve the purpose of the scheme of this embodiment.

[0172] In addition, all functional units in the embodiments of the present invention may be integrated into one processing unit, or each unit may be separately used as a unit, or two or more units may be integrated into one unit; the above-mentioned integrated units may be implemented in the form of hardware or in the form of hardware plus software functional units.

[0173] Those skilled in the art will understand that all or part of the steps of the above-mentioned method embodiment can be completed by hardware related to program instructions, and the aforementioned program can be stored in a readable storage medium. When the program is executed, it executes the steps of the above-mentioned method embodiment; and the aforementioned storage medium includes: mobile storage devices, read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, etc. Various media that can store program codes.

[0174] Alternatively, if the above-mentioned integrated unit of the present invention is implemented in the form of a software functional module and sold or used as an independent product, it can also be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiment of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the methods described in each embodiment of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROM, RAM, magnetic disks or optical disks.

Claims

1. A big data storage and access control method based on blockchain, characterized in that: The following steps are involved: Obtain predetermined big data, perform data sharding processing, and generate predetermined data blocks; Distributed storage of the predetermined data blocks; Obtain user identity information based on data access requirements and verify it through smart contracts. If verified, data access permission is triggered and a data access permission response is generated. The data access permission response is monitored in real time and access behavior data is recorded, user access behavior is determined based on the access behavior data, and access control is performed based on the user access behavior.

2. The big data storage and access control method based on blockchain according to claim 1 is characterized in that: The obtaining of predetermined big data and performing data slicing processing to generate predetermined data blocks includes: Obtain predetermined big data and extract data security attribute information and data metadata; The data security attribute information includes top secret, confidential or secret; The data metadata includes the data DCI code and data ownership information; The predetermined big data is subjected to data slicing processing according to the data security attribute information to generate top secret predetermined data blocks, confidential predetermined data blocks and secret predetermined data blocks.

3. The big data storage and access control method based on blockchain according to claim 2 is characterized in that: The distributed storage of the predetermined data blocks includes: Processing the top secret predetermined data block, the confidential predetermined data block, and the secret predetermined data block respectively through a hash algorithm to obtain corresponding hash values, including a first hash value, a second hash value, and a third hash value; Storing the data DCI code, data ownership information, and corresponding hash value in the blockchain; Get the encryption key; Encrypting the top secret predetermined data block, the confidential predetermined data block, and the secret predetermined data block respectively according to the encryption key to obtain a top secret predetermined encrypted data block, a confidential predetermined encrypted data block, and a secret predetermined encrypted data block; The top secret predetermined encrypted data block, the confidential predetermined encrypted data block and the secret predetermined encrypted data block are stored in a distributed storage center in combination with corresponding preset access authority information.

4. The big data storage and access control method based on blockchain according to claim 3 is characterized in that: The user identity information is obtained based on the data access requirement information and verified through the smart contract. If it passes, the data access permission is triggered and a data access permission response is generated, including: Obtain data access requirement information and user identity information; The user identity information includes user identity identification information and user authority level information; The blockchain node performs access verification through a smart contract based on the user identity information and user authority level information; If the verification is successful, data access permission is triggered, and the predetermined big data is transmitted to the user end for display; If the verification fails, data access is denied and an early warning response is output.

5. The big data storage and access control method based on blockchain according to claim 4 is characterized in that: Also includes: The smart contracts include global contracts, regional contracts and local contracts; Obtain permission change information, including user identity change information, data ownership change information, or access permission change information; The access control method is dynamically adjusted through the smart contract according to the permission change information.

6. The big data storage and access control method based on blockchain according to claim 5 is characterized in that: The real-time monitoring of the data access permission response and recording of access behavior data, determining user access behavior based on the access behavior data, and performing access control based on the user access behavior include: Monitor user access behavior in real time and record access behavior data, including access time, access data DCI code, and access operation feature data; Inputting the access time, access data DCI code and access operation characteristic data into a preset access credibility prediction model for processing to obtain access risk parameters; Comparing the access risk parameter with a preset access risk control threshold; If the value is less than or equal to the preset access risk control threshold, the user's access behavior is considered normal and the access behavior data is recorded in the blockchain; If it is greater than the preset access risk control threshold, the user access behavior is judged to be abnormal and data access is suspended.

7. Blockchain-based big data storage and access control system, characterized by: The system includes: A distributed data storage module, including a blockchain storage unit and a distributed storage center unit, for distributed storage and data retrieval of predetermined big data; The data access control module includes an authentication unit, an access processing unit, and an access control unit, which are used to verify user access rights and control access behavior; The data security and transmission module includes a data transmission unit, a data encryption unit, and a data decryption unit, and is used to encrypt, decrypt, and transmit predetermined large data; Smart contract storage module, used to store smart contracts.

8. A big data storage and access control system based on blockchain, characterized by: The system also includes a memory and a processor. The memory includes a program of a big data storage and access control method based on blockchain. When the program of the big data storage and access control method based on blockchain is executed by the processor, the following steps are implemented: Obtain predetermined big data, perform data sharding processing, and generate predetermined data blocks; Distributed storage of the predetermined data blocks; Obtain user identity information based on data access requirements and verify it through smart contracts. If verified, data access permission is triggered and a data access permission response is generated. The data access permission response is monitored in real time and access behavior data is recorded, user access behavior is determined based on the access behavior data, and access control is performed based on the user access behavior.

9. The big data storage and access control system based on blockchain according to claim 8, characterized in that: The obtaining of predetermined big data and performing data slicing processing to generate predetermined data blocks includes: Obtain predetermined big data and extract data security attribute information and data metadata; The data security attribute information includes top secret, confidential or secret; The data metadata includes the data DCI code and data ownership information; The predetermined big data is subjected to data slicing processing according to the data security attribute information to generate top secret predetermined data blocks, confidential predetermined data blocks and secret predetermined data blocks.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a big data storage and access control method program based on blockchain. When the big data storage and access control method program based on blockchain is executed by a processor, the steps of the big data storage and access control method based on blockchain as described in any one of claims 1 to 6 are implemented.