Data access control and auditing method in block chain environment

By judging the access permission node in the blockchain environment and encrypting and blocking the data packets and redundant storage of multiple copies, the problem of inefficient data audits is solved, and efficient data integrity and security guarantees are achieved.

CN120474770APending Publication Date: 2025-08-12KARAMAY OIL CITY DATA CO LTD +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510601052.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-12
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

In the blockchain environment, existing data audit methods are difficult to accurately judge the storage integrity of uploaded data packets of uplink nodes, resulting in inefficient data audits.

Method used

By judging the access licensed node based on the upload representation value of the uplink node, obtain the uploaded data packet of the access licensed node, and encrypt it and divide it into several data blocks. The random function PRF is used to generate a pseudo-random sequence for XOR operation to form multiple copies, analyze the cascading values to judge the integrity of the data packet, and calculate the data audited representation value to ensure that the data is stored intact on the chain.

Benefits of technology

It improves the accuracy and efficiency of data audits, realizes fine-grained access control, prevents unauthorized nodes from accessing sensitive data, guarantees the security and privacy of data, and promptly detects data tampering.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474770A_ABST
    Figure CN120474770A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data processing, in particular to a data access control and auditing method in a block chain environment. The method comprises the following steps: acquiring an upload data packet of an access permission node; the method comprises the following steps: encrypting an uploaded data packet to obtain encrypted data, dividing the encrypted data into a plurality of data blocks, generating different pseudo-random sequences for each data block based on a random function PRF, carrying out XOR operation on the pseudo-random sequences and the uploaded data packet to form C copies, analyzing the copies to obtain a cascade value of the uploaded data packet, and storing the cascade value of the uploaded data packet in a database; judging whether the uploaded data packet meets the auditing requirement or not based on the cascade value, and auditing the uploaded data packet meeting the auditing requirement: selecting a random number corresponding to a data block corresponding to the uploaded data packet, and calculating a data auditing representation value of the uploaded data packet based on the random number, whether the uploaded data packet is completely stored on the chain or not can be judged based on the data auditing characterization value, and the data auditing accuracy and auditing efficiency are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing technology, and in particular to a data access control and auditing method in a blockchain environment. Background Art

[0002] With the rise of blockchain technology, its decentralized, tamper-proof, and traceable features have provided new solutions for data storage, management, and sharing. However, in a blockchain environment, data access control and auditing face many challenges.

[0003] In blockchains, data storage and transmission are subject to various attacks, such as tampering and forgery. To ensure data integrity, uploaded data must be audited. However, existing auditing methods suffer from inefficiencies and insecurity in blockchain environments. Due to the massive and ever-growing volume of data in blockchains, traditional data auditing methods struggle to accurately assess the storage integrity of uploaded data packets from on-chain nodes, resulting in low data audit efficiency.

[0004] Therefore, data access control and auditing methods in the blockchain environment are urgently needed to solve the above problems. Summary of the Invention

[0005] The purpose of the present invention is to provide a data access control and auditing method in a blockchain environment: it aims to solve the technical problem that traditional data auditing methods in the existing technology are difficult to accurately judge the storage integrity of uploaded data packets of on-chain nodes, resulting in low data auditing efficiency.

[0006] The purpose of the present invention can be achieved through the following technical solutions:

[0007] Data access control and audit methods in blockchain environments include:

[0008] Determine whether the node on the chain is an access permission node based on the upload representation value of the node on the chain, and obtain the upload data packet of the access permission node;

[0009] The uploaded data packet is encrypted to obtain encrypted data, which is then divided into several data blocks. A different pseudo-random sequence is generated for each data block based on the random function PRF and XORed with the uploaded data packet to form C copies. The copies are analyzed to obtain the concatenation value of the uploaded data packet. Based on the concatenation value, it is determined whether the uploaded data packet meets the audit requirements.

[0010] Audit the uploaded data packets that meet the audit requirements: select the random number corresponding to the data block corresponding to the uploaded data packet, calculate the data audit representation value of the uploaded data packet based on the random number, and determine whether the uploaded data packet is stored completely on the chain based on the data audit representation value.

[0011] Furthermore, obtaining the upload representation value of the on-chain node includes the following process:

[0012] Obtain N data management values continuously generated by the on-chain node before the current time, construct a rectangular coordinate system with the data management value as the X-axis and the generation time of the data management value as the Y-axis, mark all data management values as points in the rectangular coordinate system, connect adjacent points in the rectangular coordinate system to generate a data management curve, count the number of maximum and minimum values of the data management curve, and calculate the ratio of the number of maximum values to the number of minimum values;

[0013] Draw perpendicular lines from both ends of the data management curve to the X-axis to obtain two start and end line segments. The data management curve, the two start and end line segments, and the X-axis form a closed figure. Calculate the total area of the closed figure.

[0014] Substitute the ratio and total area into the upload value calculation formula of the upper chain node: SC = (B×α-A×β) / (α+β), and calculate the upload value SC of the upper chain node, where A is the ratio, B is the total area of the closed figure, α is the ratio weight, and β is the total area weight, and their values are 0.6 and 0.4 respectively.

[0015] Furthermore, obtaining the data management value specifically includes the following process:

[0016] The period of time before the current time when the node is on-chain is recorded as a marking period. The marking period is divided into several sub-periods, and the data processing volume of the node on-chain in each sub-period is collected. The data processing volume is the sum of the amount of data uploaded to the blockchain and the amount of data downloaded from the blockchain by the node on-chain. A rectangular coordinate system is established with the number of sub-periods as the X-axis and the data processing volume as the Y-axis. A data processing volume curve is plotted by plotting points, and the number of rising segments, falling segments, and horizontal segments of all curves are obtained from the data processing volume curve. The sum of the number of rising segments and the number of horizontal segments is calculated and subtracted from the number of falling segments to obtain the data management coefficient of the marking period, and the data management coefficients of G marking periods are obtained in sequence. A data management coefficient threshold is set, and each data management coefficient is compared with the data management coefficient threshold. The marking period corresponding to the data management coefficient exceeding the data management coefficient threshold is recorded as the multiplication period, and the marking period corresponding to the data management coefficient not exceeding the data management coefficient threshold is recorded as the abnormal period. The number of marking periods BL and the number of abnormal periods YC are counted, and the ratio of BL to YC is recorded as the data management value.

[0017] Furthermore, judging whether the uplink node is an access-permitted node based on the upload representation value of the uplink node includes the following process:

[0018] Load the upload characterization value threshold, where the upload characterization value threshold is set by the blockchain system. Determine whether the upload characterization value of the on-chain node is greater than the upload characterization value threshold. If so, the on-chain node is determined to be an access-permitted node. If not, the on-chain node is determined to be an inaccessible node.

[0019] Furthermore, the uploaded data packet is encrypted to obtain encrypted data, and the encrypted data is divided into several data blocks. The specific process includes the following: setting the security parameter λ so that the large prime number q satisfies log2 q≤λ, selecting the multiplicative cyclic groups G1 and G2 of order q, and defining the bilinear map e: For any generator g in G1, select the first one-way hash function H(·): Maps a binary string of arbitrary length to a random number set domain In , select the second one-way hash function H1(·): Map a binary string of arbitrary length to a binary string of length n, and select the third one-way hash function H2(·): Maps a binary string of arbitrary length to a random number set domain In Any random number θ in is used as the private key for uploading data packets, and μ=g is calculated. θ is the public key of the uploaded data packet; the encrypted data is divided into m data blocks (d1, d2, ..., d m ).

[0020] Furthermore, a different pseudo-random sequence is generated for each data block based on a random function PRF and XORed with the uploaded data packet to form C copies. The specific process includes the following:

[0021] Determine the number of copies C:

[0022] All data blocks are grouped into a data block set. The k value is set based on the size and shape of the data block set. A data block is randomly selected as the initial centroid. When the number of initial centroids is less than k, set X i (i=1,2…m) is the data block set, y j (j=1,2…k) is the initial center of mass; based on the objective function Calculate the distance D(x) between each data block in the data block set and the existing initial centroid, and use the data block corresponding to the maximum value in D(x) as the next initial centroid; obtain k initial centroids in sequence, and cluster the data block set based on the k initial centroids to obtain C categories;

[0023] A secure random function PRF is selected, where the random function PRF is HMAC-SHA256. A key K is selected, which will be used in the PRF. Based on the key K, a unique pseudo-random sequence is generated for each data block and replica using different input data. All encrypted data blocks are combined to form C replicas.

[0024] Furthermore, analyzing the replica to obtain the cascade value of the uploaded data packet specifically includes the following process:

[0025] Construct a C-fork multi-replica hash tree with leaf nodes based on replicas: perform a hash operation on each data block to generate a corresponding hash value, combine the hash values of the data blocks in the same replica by concatenation or XOR, and perform a hash operation on the combined results again to generate a replica hash value. Use the hash value of each replica as a leaf node to construct a C-fork hash tree. In the C-fork hash tree, each node except the leaf node contains a combined hash of the hash values of C child nodes. Starting from the leaf node, calculate the hash value of the parent node layer by layer until the root node. The hash value of the root node is the root hash of the replica, and C root hash values are obtained in sequence. The root hash differences between all replicas are calculated in sequence and the absolute values are taken to obtain the cascade value.

[0026] Furthermore, judging whether the uploaded data packet meets the audit requirements based on the cascade value specifically includes the following process:

[0027] The cascade value threshold is loaded, where the cascade value threshold is set by the blockchain system. It is determined whether the cascade value exceeds the cascade value threshold. If so, it is determined that the uploaded data packet meets the audit requirements. If not, it is determined that the uploaded data packet does not meet the audit requirements.

[0028] Furthermore, the data audit characterization value of the uploaded data packet calculated based on the random number specifically includes the following process:

[0029] The index number corresponding to the uploaded data packet and the random number θ are combined into a challenge request CR. The uploaded data packet stored on the blockchain by the access permission node and the storage representation index corresponding to the uploaded data packet are queried based on the challenge request CR. The storage representation value is obtained by counting the storage time of the uploaded data packet uploaded to the blockchain, counting the total storage time of other uploaded data packets uploaded by the access permission node at the same time in the blockchain, calculating the ratio of the storage time to the total storage time, and recording the ratio as the storage representation index. The storage representation index and the random number θ are substituted into the data audit representation value calculation formula to calculate the data audit representation value LMS of the uploaded data packet. The calculation formula is as follows:

[0030] Among them, CC is the storage characterization index, H(d i ) represents the hash value obtained by performing a hash operation on the uploaded data packet.

[0031] Furthermore, judging whether the uploaded data package is stored completely on the chain based on the data audit representation value specifically includes the following process:

[0032] Load the data audit characterization value threshold, where the data audit characterization value threshold is set by the blockchain system. Determine whether the data audit characterization value exceeds the data audit characterization value threshold. If so, it is determined that the uploaded data packet is stored completely on the chain. If not, it is determined that the uploaded data packet is stored incompletely on the chain.

[0033] Compared with the existing solutions, the present invention achieves the following beneficial effects:

[0034] The present invention judges whether the up-chain node is an access permission node based on the upload characterization value of the up-chain node, and obtains the upload data packet of the access permission node; encrypts the uploaded data packet to obtain encrypted data, and divides the encrypted data into several data blocks, generates a different pseudo-random sequence for each data block based on a random function PRF, and performs an XOR operation with the uploaded data packet to form C copies, analyzes the copies to obtain a cascade value of the uploaded data packet, judges whether the uploaded data packet meets the audit requirements based on the cascade value, and audits the uploaded data packet that meets the audit requirements: selects a random number corresponding to the data block corresponding to the uploaded data packet, calculates the data audit characterization value of the uploaded data packet based on the random number, and can judge whether the uploaded data packet is stored completely on the chain based on the data audit characterization value, thereby improving the accuracy and efficiency of data auditing.

[0035] Access permission nodes are judged based on the uploaded representation value of the on-chain node, realizing fine-grained access control. The access control mechanism based on node characteristics can effectively prevent unauthorized nodes from accessing sensitive data, thus ensuring the security and privacy of the data.

[0036] By analyzing the copies to obtain the cascade value of the uploaded data packet, and judging whether the uploaded data packet meets the audit requirements based on the cascade value, the present invention can promptly detect any tampering of the data during transmission and storage, and ensure the integrity and authenticity of the data. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments described in the present invention. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.

[0038] Figure 1 This is a workflow diagram of a data access control and audit method in a first blockchain environment according to an embodiment of the present invention;

[0039] Figure 2 This is a workflow diagram of the data access control and audit method in the second blockchain environment of an embodiment of the present invention;

[0040] Figure 3 This is a workflow diagram of a data access control and auditing method in a third blockchain environment according to an embodiment of the present invention. DETAILED DESCRIPTION

[0041] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0042] In addition, the described features, structures or characteristics can be combined in any suitable manner in one or more example embodiments. In the following description, many specific details are provided to provide a full understanding of the example embodiments of the present disclosure. However, those skilled in the art will appreciate that the technical solutions of the present disclosure can be practiced while omitting one or more of the specific details, or other methods, components, steps, etc. can be adopted. In other cases, well-known structures, methods, implementations or operations are not shown or described in detail to avoid obscuring various aspects of the present disclosure.

[0043] This embodiment provides a data access control and audit method in a blockchain environment. Figure 1 This is a workflow diagram of the data access control and audit method in the first blockchain environment of the embodiment of the present invention. Figure 1 As shown, the method includes:

[0044] Step S101: determining whether the uplink node is an access-permitted node based on the upload representation value of the uplink node, and obtaining the upload data packet of the access-permitted node;

[0045] Step S102: The uploaded data packet is encrypted to obtain encrypted data, which is then divided into several data blocks. A different pseudo-random sequence is generated for each data block based on a random function (PRF), and the sequence is XORed with the uploaded data packet to form C copies. The copies are analyzed to obtain a concatenation value of the uploaded data packet. Based on the concatenation value, it is determined whether the uploaded data packet meets the audit requirements.

[0046] Step S103: Audit the uploaded data packets that meet the audit requirements: select the random number corresponding to the data block corresponding to the uploaded data packet, calculate the data audit representation value of the uploaded data packet based on the random number, and determine whether the uploaded data packet is stored completely on the chain based on the data audit representation value.

[0047] In summary, the present invention determines whether the up-chain node is an access permission node based on the upload characterization value of the up-chain node, and obtains the upload data packet of the access permission node; encrypts the uploaded data packet to obtain encrypted data, and divides the encrypted data into several data blocks, generates a different pseudo-random sequence for each data block based on the random function PRF and performs an XOR operation with the uploaded data packet to form C copies, analyzes the copies to obtain the cascade value of the uploaded data packet, determines whether the uploaded data packet meets the audit requirements based on the cascade value, and audits the uploaded data packet that meets the audit requirements: selects a random number corresponding to the data block corresponding to the uploaded data packet, calculates the data audit characterization value of the uploaded data packet based on the random number, and can determine whether the uploaded data packet is stored completely on the chain based on the data audit characterization value, thereby improving the accuracy and efficiency of data audits.

[0048] Access permission nodes are judged based on the uploaded representation value of the on-chain node, realizing fine-grained access control. The access control mechanism based on node characteristics can effectively prevent unauthorized nodes from accessing sensitive data, thus ensuring the security and privacy of the data.

[0049] The encrypted data is divided into several data blocks, and different pseudo-random sequences are generated based on the random function PRF. These are XORed with the uploaded data packet to form C copies. This multi-copy redundant storage mechanism greatly improves the data's tamper resistance. Even if some copies are destroyed, the original data can be restored from other copies.

[0050] By analyzing the copies to obtain the cascade value of the uploaded data packet, and judging whether the uploaded data packet meets the audit requirements based on the cascade value, the present invention can promptly detect any tampering of the data during transmission and storage, and ensure the integrity and authenticity of the data.

[0051] In some embodiments, Figure 2 This is a workflow diagram of the data access control and audit method under the second blockchain environment of the embodiment of the present invention. Figure 2 As shown in the figure, obtaining the upload representation value of the on-chain node specifically includes the following process:

[0052] Step S201: Obtain N data management values continuously generated by the on-chain node before the current time, construct a rectangular coordinate system with the data management value as the X-axis and the generation time of the data management value as the Y-axis, mark all data management values as points in the rectangular coordinate system, connect adjacent points in the rectangular coordinate system to generate a data management curve, count the number of maximum values and minimum values of the data management curve, and calculate the ratio of the number of maximum values to the number of minimum values;

[0053] Step S202: Draw perpendicular lines from both ends of the data management curve to the X-axis to obtain two start and end line segments. The data management curve, the two start and end line segments, and the X-axis form a closed figure, and the total area of the closed figure is calculated.

[0054] Step S203: Substitute the ratio and the total area into the upload value calculation formula of the upper chain node: SC = (B×α-A×β) / (α+β), and calculate the upload value SC of the upper chain node, where A is the ratio, B is the total area of the closed figure, α is the ratio weight, and β is the total area weight, and their values are 0.6 and 0.4 respectively.

[0055] In some embodiments, Figure 3 This is a workflow diagram of the data access control and audit method under the third blockchain environment of the embodiment of the present invention. Figure 3 As shown, obtaining data management values includes the following processes:

[0056] Step S301: The period before the current time when the node is on-chain is recorded as a marked period, and the marked period is divided into several sub-periods. The data processing volume of the node on-chain in each sub-period is collected, where the data processing volume is the sum of the amount of data uploaded to the blockchain and the amount of data downloaded from the blockchain by the node on-chain;

[0057] Step S302: A rectangular coordinate system is established with the number of sub-time periods as the X-axis and the data processing volume as the Y-axis. A data processing volume curve is plotted by plotting points. The number of rising segments, falling segments, and horizontal segments of all curves are then obtained from the data processing volume curve. The sum of the number of rising segments and the number of horizontal segments is calculated, and the number of falling segments is subtracted from the sum to obtain the data management coefficient for the marking period. The data management coefficients for the G marking periods are then obtained in sequence.

[0058] Step S303: Set a data management coefficient threshold, compare each data management coefficient with the data management coefficient threshold, record the marked period corresponding to the data management coefficient higher than the data management coefficient threshold as the multiplication period, and record the marked period corresponding to the data management coefficient not higher than the data management coefficient threshold as the abnormal period; count the number of marked periods BL and the number of abnormal periods YC, and record the ratio of BL to YC as the data management value.

[0059] In some embodiments, determining whether the uplink node is an access-permitted node based on the upload representation value of the uplink node includes the following process:

[0060] Load the upload characterization value threshold, where the upload characterization value threshold is set by the blockchain system. Determine whether the upload characterization value of the on-chain node is greater than the upload characterization value threshold. If so, the on-chain node is determined to be an access-permitted node. If not, the on-chain node is determined to be an inaccessible node.

[0061] In some embodiments, encrypting an uploaded data packet to obtain encrypted data and dividing the encrypted data into a plurality of data blocks specifically includes the following steps: setting a security parameter λ so that a large prime number q satisfies log2 q≤λ, selecting multiplicative cyclic groups G1 and G2 of order q, and defining a bilinear map e: For any generator g in G1, select the first one-way hash function H(·): Maps a binary string of arbitrary length to a random number set domain In , select the second one-way hash function H1(·): Map a binary string of arbitrary length to a binary string of length n, and select the third one-way hash function H2(·): Maps a binary string of arbitrary length to a random number set domain In Any random number θ in is used as the private key for uploading data packets, and μ=g is calculated. θ is the public key of the uploaded data packet; the encrypted data is divided into m data blocks (d1, d2, ..., d m ).

[0062] In some embodiments, generating a different pseudo-random sequence for each data block based on a random function PRF and performing an XOR operation on the uploaded data packet to form C copies specifically includes the following process:

[0063] Determine the number of copies C:

[0064] All data blocks are grouped into a data block set. The k value is set based on the size and shape of the data block set. A data block is randomly selected as the initial centroid. When the number of initial centroids is less than k, set X i (i=1,2…m) is the data block set, y j (j=1,2…k) is the initial center of mass; based on the objective function Calculate the distance D(x) between each data block in the data block set and the existing initial centroid, and use the data block corresponding to the maximum value in D(x) as the next initial centroid; obtain k initial centroids in sequence, and cluster the data block set based on the k initial centroids to obtain C categories;

[0065] A secure random function PRF is selected, where the random function PRF is HMAC-SHA256. A key K is selected, which will be used in the PRF. Based on the key K, a unique pseudo-random sequence is generated for each data block and replica using different input data. All encrypted data blocks are combined to form C replicas.

[0066] In some embodiments, analyzing the replica to obtain the concatenation value of the uploaded data packet specifically includes the following process:

[0067] Construct a C-fork multi-replica hash tree with leaf nodes based on replicas: perform a hash operation on each data block to generate a corresponding hash value, combine the hash values of the data blocks in the same replica by concatenation or XOR, and perform a hash operation on the combined results again to generate a replica hash value. Use the hash value of each replica as a leaf node to construct a C-fork hash tree. In the C-fork hash tree, each node except the leaf node contains a combined hash of the hash values of C child nodes. Starting from the leaf node, calculate the hash value of the parent node layer by layer until the root node. The hash value of the root node is the root hash of the replica, and C root hash values are obtained in sequence. The root hash differences between all replicas are calculated in sequence and the absolute values are taken to obtain the cascade value.

[0068] In some embodiments, determining whether an uploaded data packet meets audit requirements based on the cascade value specifically includes the following process:

[0069] The cascade value threshold is loaded, where the cascade value threshold is set by the blockchain system. It is determined whether the cascade value exceeds the cascade value threshold. If so, it is determined that the uploaded data packet meets the audit requirements. If not, it is determined that the uploaded data packet does not meet the audit requirements.

[0070] In some embodiments, calculating the data audit representation value of the uploaded data packet based on the random number specifically includes the following process:

[0071] The index number corresponding to the uploaded data packet and the random number θ are combined into a challenge request CR. The uploaded data packet stored on the blockchain by the access permission node and the storage representation index corresponding to the uploaded data packet are queried based on the challenge request CR. The storage representation value is obtained by counting the storage time of the uploaded data packet uploaded to the blockchain, counting the total storage time of other uploaded data packets uploaded by the access permission node at the same time in the blockchain, calculating the ratio of the storage time to the total storage time, and recording the ratio as the storage representation index. The storage representation index and the random number θ are substituted into the data audit representation value calculation formula to calculate the data audit representation value LMS of the uploaded data packet. The calculation formula is as follows:

[0072] Among them, CC is the storage characterization index, H(d i ) represents the hash value obtained by performing a hash operation on the uploaded data packet.

[0073] Furthermore, judging whether the uploaded data package is stored completely on the chain based on the data audit representation value specifically includes the following process:

[0074] Load the data audit characterization value threshold, where the data audit characterization value threshold is set by the blockchain system. Determine whether the data audit characterization value exceeds the data audit characterization value threshold. If so, it is determined that the uploaded data packet is stored completely on the chain. If not, it is determined that the uploaded data packet is stored incompletely on the chain.

[0075] The above embodiments can be implemented in whole or in part by software, hardware, firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0076] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0077] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0078] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is only for some logical functions. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0079] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0080] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. The data access control and audit method in the blockchain environment is characterized by: Methods include: Determine whether the node on the chain is an access permission node based on the upload representation value of the node on the chain, and obtain the upload data packet of the access permission node; The uploaded data packet is encrypted to obtain encrypted data, which is then divided into several data blocks. A different pseudo-random sequence is generated for each data block based on the random function PRF and XORed with the uploaded data packet to form C copies. The copies are analyzed to obtain the concatenation value of the uploaded data packet. Based on the concatenation value, it is determined whether the uploaded data packet meets the audit requirements. Audit the uploaded data packets that meet the audit requirements: select the random number corresponding to the data block corresponding to the uploaded data packet, calculate the data audit representation value of the uploaded data packet based on the random number, and determine whether the uploaded data packet is stored completely on the chain based on the data audit representation value.

2. The data access control and auditing method in a blockchain environment according to claim 1 is characterized in that: Obtaining the upload representation value of the on-chain node includes the following process: Obtain N data management values continuously generated by the on-chain node before the current time, construct a rectangular coordinate system with the data management value as the X-axis and the generation time of the data management value as the Y-axis, mark all data management values as points in the rectangular coordinate system, connect adjacent points in the rectangular coordinate system to generate a data management curve, count the number of maximum and minimum values of the data management curve, and calculate the ratio of the number of maximum values to the number of minimum values; Draw perpendicular lines from both ends of the data management curve to the X-axis to obtain two start and end line segments. The data management curve, the two start and end line segments, and the X-axis form a closed figure. Calculate the total area of the closed figure. Substitute the ratio and total area into the upload value calculation formula of the upper chain node: SC = (B×α-A×β) / (α+β), and calculate the upload value SC of the upper chain node, where A is the ratio, B is the total area of the closed figure, α is the ratio weight, and β is the total area weight, and their values are 0.6 and 0.4 respectively.

3. The data access control and auditing method under the blockchain environment according to claim 2 is characterized in that: Get data management value specific The following processes are included: The period of time before the current time when the node is on-chain is recorded as a marking period. The marking period is divided into several sub-periods, and the data processing volume of the node on-chain in each sub-period is collected. The data processing volume is the sum of the amount of data uploaded to the blockchain and the amount of data downloaded from the blockchain by the node on-chain. A rectangular coordinate system is established with the number of sub-periods as the X-axis and the data processing volume as the Y-axis. A data processing volume curve is plotted by plotting points, and the number of rising segments, falling segments, and horizontal segments of all curves are obtained from the data processing volume curve. The sum of the number of rising segments and the number of horizontal segments is calculated and subtracted from the number of falling segments to obtain the data management coefficient of the marking period, and the data management coefficients of G marking periods are obtained in sequence. A data management coefficient threshold is set, and each data management coefficient is compared with the data management coefficient threshold. The marking period corresponding to the data management coefficient exceeding the data management coefficient threshold is recorded as the multiplication period, and the marking period corresponding to the data management coefficient not exceeding the data management coefficient threshold is recorded as the abnormal period. The number of marking periods BL and the number of abnormal periods YC are counted, and the ratio of BL to YC is recorded as the data management value.

4. The data access control and auditing method in a blockchain environment according to claim 1 is characterized in that: Determine whether the node on the chain is an access permission node based on the uploaded representation value of the node The following processes are included: Load the upload characterization value threshold, where the upload characterization value threshold is set by the blockchain system. Determine whether the upload characterization value of the on-chain node is greater than the upload characterization value threshold. If so, the on-chain node is determined to be an access-permitted node. If not, the on-chain node is determined to be an inaccessible node.

5. The data access control and auditing method in a blockchain environment according to claim 1 is characterized in that: The uploaded data packet is encrypted to obtain encrypted data, and the encrypted data is divided into several data blocks. The specific process includes the following: Set the security parameter λ so that the large prime number q satisfies log2 q≤λ, select the multiplicative cyclic groups G1 and G2 of order q, and define the bilinear map For any generator g in G1, select the first one-way hash function Maps a binary string of arbitrary length to a random number set domain In the example, select the second one-way hash function Map a binary string of arbitrary length to a binary string of length n, and select the third one-way hash function H2(·): Maps a binary string of arbitrary length to a random number set domain In Any random number θ in is used as the private key for uploading data packets, and μ=g is calculated. θ is the public key of the uploaded data packet; the encrypted data is divided into m data blocks (d1, d2, ..., d m ).

6. The data access control and auditing method in a blockchain environment according to claim 5 is characterized in that: A different pseudo-random sequence is generated for each data block based on the random function PRF and is XORed with the uploaded data packet to form C copies. The specific process includes the following: Determine the number of copies C: All data blocks are grouped into a data block set. The k value is set based on the size and shape of the data block set. A data block is randomly selected as the initial centroid. When the number of initial centroids is less than k, set X i (i=1,2…m) is the data block set, y j (j=1,2…k) is the initial center of mass; based on the objective function Calculate the distance D(x) between each data block in the data block set and the existing initial centroid, and use the data block corresponding to the maximum value in D(x) as the next initial centroid; obtain k initial centroids in sequence, and cluster the data block set based on the k initial centroids to obtain C categories; A secure random function PRF is selected, where the random function PRF is HMAC-SHA256. A key K is selected, which will be used in the PRF. Based on the key K, a unique pseudo-random sequence is generated for each data block and replica using different input data. All encrypted data blocks are combined to form C replicas.

7. The data access control and auditing method in a blockchain environment according to claim 1 is characterized in that: Analyze the replica to get the specific cascade value of the uploaded data packet The following processes are included: Construct a C-fork multi-replica hash tree with leaf nodes based on replicas: perform a hash operation on each data block to generate a corresponding hash value, combine the hash values of the data blocks in the same replica by concatenation or XOR, and perform a hash operation on the combined results again to generate a replica hash value. Use the hash value of each replica as a leaf node to construct a C-fork hash tree. In the C-fork hash tree, each node except the leaf node contains a combined hash of the hash values of C child nodes. Starting from the leaf node, calculate the hash value of the parent node layer by layer until the root node. The hash value of the root node is the root hash of the replica, and C root hash values are obtained in sequence. The root hash differences between all replicas are calculated in sequence and the absolute values are taken to obtain the cascade value.

8. The data access control and auditing method under the blockchain environment according to claim 7 is characterized in that: Determine whether the uploaded data packet meets the audit requirements based on the cascade value The following processes are included: The cascade value threshold is loaded, where the cascade value threshold is set by the blockchain system. It is determined whether the cascade value exceeds the cascade value threshold. If so, it is determined that the uploaded data packet meets the audit requirements. If not, it is determined that the uploaded data packet does not meet the audit requirements.

9. The data access control and auditing method in a blockchain environment according to claim 1 is characterized in that: The specific process of calculating the data audit representation value of the uploaded data packet based on the random number is as follows: The index number corresponding to the uploaded data packet and the random number θ are combined into a challenge request CR. The uploaded data packet stored on the blockchain by the access permission node and the storage representation index corresponding to the uploaded data packet are queried based on the challenge request CR. The storage representation value is obtained by counting the storage time of the uploaded data packet uploaded to the blockchain, counting the total storage time of other uploaded data packets uploaded by the access permission node at the same time in the blockchain, calculating the ratio of the storage time to the total storage time, and recording the ratio as the storage representation index. The storage representation index and the random number θ are substituted into the data audit representation value calculation formula to calculate the data audit representation value LMS of the uploaded data packet. The calculation formula is as follows: Among them, CC is the storage characterization index, H(d i ) represents the hash value obtained by performing a hash operation on the uploaded data packet.

10. The data access control and auditing method in a blockchain environment according to claim 1 is characterized in that: Based on the data audit characterization value, it is judged whether the uploaded data package is stored completely on the chain. The following processes are included: Load the data audit characterization value threshold, where the data audit characterization value threshold is set by the blockchain system. Determine whether the data audit characterization value exceeds the data audit characterization value threshold. If so, it is determined that the uploaded data packet is stored completely on the chain. If not, it is determined that the uploaded data packet is stored incompletely on the chain.

Citation Information

Patent Citations

  • Certificateless cloud storage data integrity public auditing method

    CN113364600A

  • Cloud data auditing method and system for power network and power communication network

    CN116305306A

  • Dynamic cloud data integrity public auditing method based on chameleon hash

    CN117650879A

  • Cloud storage multi-copy data integrity auditing method based on block design

    CN118890225A