Ship shipping data secure storage and transmission method and system based on block chain

Through the classification storage and encryption processing of ship shipping data, the problem of insufficient security of ship shipping data in the prior art is solved, and high security in the data transmission and reading process is achieved.

CN120547191APending Publication Date: 2025-08-26长江水上交通监测与应急处置中心
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510395143.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-08-26

AI Technical Summary

Technical Problem

The prior art has weak effect in ensuring the security of ship shipping data and cannot meet the corresponding confidentiality requirements.

Method used

Ship shipping data is classified into core data and non-core data. The core data is stored in distributed storage nodes and encrypted and stored in blockchain blocks. The non-core data is directly stored in blockchain blocks and access control is performed through encryption algorithms and key management mechanisms.

Benefits of technology

It realizes the classified storage and encryption processing of ship shipping data, improves the security in data transmission and reading, and meets the confidentiality requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120547191A_ABST
    Figure CN120547191A_ABST
Patent Text Reader

Abstract

The invention discloses a block chain-based ship shipping data secure storage and transmission method and system, and the method comprises the steps: obtaining ship shipping data, cutting the ship shipping data into core data and non-core data, the core data comprises cargo information and crew data, and the non-core data comprises non-core data; the non-core data comprises a real-time navigation position and a ship state; storing the core data in a distributed storage node, encrypting the core data through an encryption algorithm, and after encryption is completed, storing a storage address of the core data and corresponding metadata in a block of a block chain, and storing the non-core data in the block of the block chain; when the user identity is successfully verified, the non-core data are allowed to be transmitted or read, and when the core data are transmitted or read, the user searches the distributed storage node for the core data according to the storage address and the metadata stored in the block, and final transmission or reading is completed through the secret key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of secure storage of ship shipping data, and more specifically, relates to a blockchain-based method and system for secure storage and transmission of ship shipping data. Background Art

[0002] Data storage via blockchain is decentralized, tamper-proof, and highly secure. Data is distributed across multiple nodes, avoiding single points of failure and ensuring system stability. Encryption technology is used to protect data and prevent unauthorized access, while consensus mechanisms guarantee data authenticity and consistency. Furthermore, blockchain's transparency and traceability make data more trustworthy.

[0003] Since shipping data is highly sensitive and private, it has become a widely accepted practice to store it on the blockchain. However, although blockchain is transparent and traceable, it is not very effective in protecting the security of shipping data and cannot meet the corresponding confidentiality requirements. Therefore, there is an urgent need for a technical solution that can improve the security of shipping data while combining blockchain technology. Summary of the Invention

[0004] To solve the above technical problems, the present invention proposes a blockchain-based method for secure storage and transmission of shipping data, comprising:

[0005] Acquire ship shipping data and segment the ship shipping data into core data and non-core data, wherein the core data includes cargo information and crew data, and the non-core data includes real-time navigation position and ship status;

[0006] The core data is stored in a distributed storage node and encrypted using an encryption algorithm. After encryption, the storage address of the core data and the corresponding metadata are stored in a block of the blockchain, and the non-core data is stored in a block of the blockchain;

[0007] When the user identity authentication is successful, the non-core data is allowed to be transmitted or read. When transmitting or reading the core data, the user searches for the core data in the distributed storage node according to the storage address and metadata stored in the block, and completes the final transmission or reading through the key.

[0008] Furthermore, it also includes: using end-to-end encryption to encrypt all data uploaded to the blockchain, and using a key distribution mechanism to distribute the keys to the corresponding users.

[0009] Furthermore, it also includes: dynamically adjusting the storage capacity of the block according to the amount of data generated by the ship, wherein when the amount of data generated by the ship exceeds a first data volume threshold, the storage capacity of the corresponding block is increased; when the amount of data generated by the ship is less than a second data volume threshold, the storage capacity of the corresponding block is reduced, thereby saving storage resources.

[0010] Furthermore, the method further includes: allocating different levels of access rights to different users, wherein the core data requires the highest access right.

[0011] Furthermore, the encryption algorithm is: elliptic curve encryption or hash algorithm.

[0012] Furthermore, the encryption algorithm is:

[0013] Generate an encrypted identifier for each piece of data in the core data, specifically:

[0014] EID i =HMAC SHA-256 (ID ship ||T||i||salt,K salt )

[0015] Among them, EID i is the encryption identifier of the i-th data, HMAC SHA-256 The hash value generated using SHA-256 and HMAC, ID ship is the ship identifier, T is the timestamp of data generation, salt is the salt value used to increase randomness, K salt The first salt value is dynamically generated;

[0016] Encrypted identifier EID of data according to item i i Encrypt each piece of data, specifically:

[0017]

[0018] Among them, C i is the encrypted data of the i-th data, E Enc For encryption operations, d i is the i-th data, K i is the increasing key sequence of the i-th data, K i-1 is the increasing key sequence of the i-1th data, H salt is the salt value generated after hashing the i-th data. It is an exclusive OR operation.

[0019] Furthermore, the salt value used to increase randomness is calculated as follows:

[0020] salt=HMACSHA-256 (ID ship ||T||R,K salt_base )

[0021] Among them, R is a random number used for encryption security, K salt_base As the base key.

[0022] Furthermore, the dynamically generated salt value K is calculated salt , specifically:

[0023] K salt =HMAC SHA-512 (salt||ID ship ,K salt_key )

[0024] Among them, K salt_key The key used to perform secondary encryption on the salt value salt;

[0025] Calculate the salt value H generated by hashing the i-th data salt , specifically:

[0026] H salt =HMAC SHA-512 (d i ||salt,K′ salt )

[0027] Among them, K′ salt The second salt value is dynamically generated.

[0028] Furthermore, the dynamically generated second salt value K′ is calculated salt , specifically:

[0029] K′ salt =KDF(ID ship ||T,Salt)

[0030] Among them, KDF is the key derivation function.

[0031] The present invention also proposes a blockchain-based ship shipping data security storage and transmission system, comprising:

[0032] a cutting module for acquiring ship shipping data and cutting the ship shipping data into core data and non-core data, wherein the core data includes cargo information and crew data, and the non-core data includes real-time navigation position and ship status;

[0033] A storage module, configured to store the core data in a distributed storage node and encrypt the core data using an encryption algorithm. After encryption, the storage address and corresponding metadata of the core data are stored in a block of the blockchain, and the non-core data are stored in a block of the blockchain.

[0034] The transmission module is used to allow the transmission or reading of the non-core data after the user identity authentication is successful. When transmitting or reading the core data, the user searches for the core data in the distributed storage node according to the storage address and metadata stored in the block, and completes the final transmission or reading through the key.

[0035] In general, the above technical solutions conceived by the present invention have the following beneficial effects compared with the prior art:

[0036] Through the above technical solution, the present invention can classify and store ship shipping data by category (core and non-core), and further encrypt the core data, thereby effectively solving the security problems that may be encountered during the transmission or reading of ship shipping data. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 is a flow chart of the method of embodiment 1 of the present invention;

[0038] Figure 2 This is a system structure diagram of Example 2 of the present invention. DETAILED DESCRIPTION

[0039] In order to better understand the above technical solution, the above technical solution will be described in detail below with reference to the accompanying drawings and specific implementation methods.

[0040] The method provided by the present invention can be implemented in the following terminal environment, wherein the terminal may include one or more of the following components: a processor, a storage medium, and a display screen. The storage medium stores at least one instruction, which is loaded and executed by the processor to implement the method described in the following embodiments.

[0041] A processor can include one or more processing cores. It connects various components within the terminal using various interfaces and circuits. It executes instructions, programs, code sets, or instruction sets stored in storage media, and accesses data stored in storage media to perform various terminal functions and process data.

[0042] The storage medium may include a random access memory (RAM) or a read-only memory (ROM). The storage medium may be used to store instructions, programs, codes, code sets, or instructions.

[0043] The display is used to show the user interface of each application.

[0044] In addition, those skilled in the art will appreciate that the structure of the terminal described above does not limit the terminal. The terminal may include more or fewer components, or a combination of certain components, or a different arrangement of components. For example, the terminal may also include a radio frequency circuit, an input unit, a sensor, an audio circuit, a power supply, and other components, which will not be described in detail here.

[0045] Example 1

[0046] like Figure 1 This embodiment proposes a blockchain-based method for secure storage and transmission of shipping data, including:

[0047] Step 101: Acquire ship shipping data and segment the ship shipping data into core data and non-core data. The core data includes cargo information and crew data, and the non-core data includes real-time navigation position and ship status.

[0048] Step 102: Store the core data in a distributed storage node and encrypt the core data using an encryption algorithm. After encryption, store the storage address of the core data and the corresponding metadata in a block of the blockchain, and store the non-core data in a block of the blockchain.

[0049] Specifically, the encryption algorithm is: elliptic curve encryption or hash algorithm.

[0050] Preferably, in order to achieve better encryption effect, this embodiment proposes a new encryption algorithm, specifically:

[0051] Generate an encrypted identifier for each piece of data in the core data, specifically:

[0052] EID i =HMAC SHA-256 (ID ship ||T||i||salt,K salt )

[0053] Among them, EID i is the encryption identifier of the i-th data, HMAC SHA-256 The hash value generated using SHA-256 and HMAC (key-based hash message authentication code), ID ship is the ship identifier, T is the timestamp of data generation, salt is the salt value used to increase randomness, K salt The first salt value is dynamically generated;

[0054] Encrypted identifier EID of data according to item i i Encrypt each piece of data, specifically:

[0055]

[0056] Among them, C i is the encrypted data of the i-th data, E Enc For encryption operations (symmetric encryption (such as AES) or asymmetric encryption (such as RSA), d i is the i-th data, K i is the increasing key sequence of the i-th data, K i-1 is the increasing key sequence of the i-1th data, H salt is the salt value generated after hashing the i-th data. It is an exclusive OR operation.

[0057] Specifically, the salt value used to increase randomness is calculated as follows:

[0058] salt=HMAC SHA-256 (ID ship ||T||R,K salt_base )

[0059] Among them, R is a random number used for encryption security, K salt_base As the base key.

[0060] Specifically, calculate the dynamically generated salt value K salt , specifically:

[0061] K salt =HMAC SHA-512 (salt||ID ship ,K salt_key )

[0062] Among them, K salt_key The key used to perform secondary encryption on the salt value salt;

[0063] Calculate the salt value H generated by hashing the i-th data salt , specifically:

[0064] H salt =HMAC SHA-512 (d i ||salt,K′ salt )

[0065] Among them, K′ salt The second salt value is dynamically generated.

[0066] Specifically, calculate the dynamically generated second salt value K′salt , specifically:

[0067] K′ salt =KDF(ID ship ||T,Salt)

[0068] Wherein, KDF is a key derivation function, which can be:

[0069] 1. PBKDF2 (Password-Based Key Derivation Function 2), a password-based key derivation function, is widely used for password storage and encryption key generation. It uses Hash-based Message Authentication Code (HMAC) for multiple iterative hash calculations, making brute-force cracking more difficult.

[0070] 2. scrypt: A key derivation function designed by Colin Percival in 2009, specifically designed for brute force attacks optimized for GPU / FPGA computing, and primarily used for cryptocurrencies.

[0071] Step 103: When the user identity verification is successful, the non-core data is allowed to be transmitted or read. When transmitting or reading the core data, the user searches for the core data in the distributed storage node according to the storage address and metadata stored in the block, and completes the final transmission or reading through the key.

[0072] Specifically, it also includes: using end-to-end encryption to encrypt all data uploaded to the blockchain, and using a key distribution mechanism to distribute the keys to the corresponding users.

[0073] Specifically, it also includes: dynamically adjusting the storage capacity of the block according to the amount of data generated by the ship, wherein when the amount of data generated by the ship exceeds a first data volume threshold, the storage capacity of the corresponding block is increased; when the amount of data generated by the ship is less than a second data volume threshold, the storage capacity of the corresponding block is reduced, thereby saving storage resources.

[0074] Specifically, it also includes: allocating different levels of access rights to different users, wherein the core data requires the highest access right.

[0075] Example 2

[0076] like Figure 2 As shown, this embodiment proposes a blockchain-based ship shipping data security storage and transmission system, including:

[0077] a cutting module for acquiring ship shipping data and cutting the ship shipping data into core data and non-core data, wherein the core data includes cargo information and crew data, and the non-core data includes real-time navigation position and ship status;

[0078] A storage module, configured to store the core data in a distributed storage node and encrypt the core data using an encryption algorithm. After encryption, the storage address and corresponding metadata of the core data are stored in a block of the blockchain, and the non-core data are stored in a block of the blockchain.

[0079] Specifically, the encryption algorithm is: elliptic curve encryption or hash algorithm.

[0080] Preferably, in order to achieve better encryption effect, this embodiment proposes a new encryption algorithm, specifically:

[0081] Generate an encrypted identifier for each piece of data in the core data, specifically:

[0082] EID i =HMAC SHA-256 (ID ship ||T||i||salt,K salt )

[0083] Among them, EID i is the encryption identifier of the i-th data, HMAC SHA-256 The hash value generated using SHA-256 and HMAC, ID ship is the ship identifier, T is the timestamp of data generation, salt is the salt value used to increase randomness, K salt The first salt value is dynamically generated;

[0084] Encrypted identifier EID of data according to item i i Encrypt each piece of data, specifically:

[0085]

[0086] Among them, C i is the encrypted data of the i-th data, E Enc For encryption operations, d i is the i-th data, K i is the increasing key sequence of the i-th data, K i-1 is the increasing key sequence of the i-1th data, H salt is the salt value generated after hashing the i-th data. It is an exclusive OR operation.

[0087] Specifically, the salt value used to increase randomness is calculated as follows:

[0088] salt=HMAC SHA-256 (ID ship ||T||R,K salt_base

[0089] Among them, R is a random number used for encryption security, K salt_base As the base key.

[0090] Specifically, calculate the dynamically generated salt value K salt , specifically:

[0091] K salt =HMAC SHA-512 (salt||ID ship ,K salt_key )

[0092] Among them, K salt_key The key used to perform secondary encryption on the salt value salt;

[0093] Calculate the salt value H generated by hashing the i-th data salt , specifically:

[0094] H salt =HMAC SHA-512 (d i ||salt,K′ salt )

[0095] Among them, K′ salt The second salt value is dynamically generated.

[0096] Specifically, calculate the dynamically generated second salt value K′ salt , specifically:

[0097] K′ salt =KDF(ID ship ||T,Salt)

[0098] Among them, KDF is the key derivation function.

[0099] The transmission module is used to allow the transmission or reading of the non-core data after the user identity authentication is successful. When transmitting or reading the core data, the user searches for the core data in the distributed storage node according to the storage address and metadata stored in the block, and completes the final transmission or reading through the key.

[0100] Specifically, it also includes: using end-to-end encryption to encrypt all data uploaded to the blockchain, and using a key distribution mechanism to distribute the keys to the corresponding users.

[0101] Specifically, it also includes: dynamically adjusting the storage capacity of the block according to the amount of data generated by the ship, wherein when the amount of data generated by the ship exceeds a first data volume threshold, the storage capacity of the corresponding block is increased; when the amount of data generated by the ship is less than a second data volume threshold, the storage capacity of the corresponding block is reduced, thereby saving storage resources.

[0102] Specifically, it also includes: allocating different levels of access rights to different users, wherein the core data requires the highest access right.

[0103] Example 3

[0104] An embodiment of the present invention also proposes a storage medium storing multiple instructions, which are used to implement the blockchain-based method for secure storage and transmission of ship shipping data.

[0105] Optionally, in this embodiment, the storage medium may be located in any computer terminal in a computer terminal group in a computer network, or in any mobile terminal in a mobile terminal group.

[0106] Optionally, in this embodiment, the storage medium is configured to store program codes for executing the following steps: Step 101, obtaining ship shipping data, and segmenting the ship shipping data into core data and non-core data, wherein the core data includes cargo information and crew data, and the non-core data includes real-time navigation position and ship status;

[0107] Step 102: Store the core data in a distributed storage node and encrypt the core data using an encryption algorithm. After encryption, store the storage address of the core data and the corresponding metadata in a block of the blockchain, and store the non-core data in a block of the blockchain.

[0108] Specifically, the encryption algorithm is: elliptic curve encryption or hash algorithm.

[0109] Preferably, in order to achieve better encryption effect, this embodiment proposes a new encryption algorithm, specifically:

[0110] Generate an encrypted identifier for each piece of data in the core data, specifically:

[0111] EID i =HMAC SHA-256 (ID ship ||T||i||salt,K salt )

[0112] Among them, EID i is the encryption identifier of the i-th data, HMACSHA-256 The hash value generated using SHA-256 and HMAC, ID ship is the ship identifier, T is the timestamp of data generation, salt is the salt value used to increase randomness, K salt The first salt value is dynamically generated;

[0113] Encrypted identifier EID of data according to item i i Encrypt each piece of data, specifically:

[0114]

[0115] Among them, C i is the encrypted data of the i-th data, E Enc For encryption operations, d i is the i-th data, K i is the increasing key sequence of the i-th data, K i-1 is the increasing key sequence of the i-1th data, H salt is the salt value generated after hashing the i-th data. It is an exclusive OR operation.

[0116] Specifically, the salt value used to increase randomness is calculated as follows:

[0117] salt=HMAC SHA-256 (ID ship ||T||R,K salt_base )

[0118] Among them, R is a random number used for encryption security, K salt_base As the base key.

[0119] Specifically, calculate the dynamically generated salt value K salt , specifically:

[0120] K salt =HMAC SHA-512 (salt||ID ship ,K salt_key )

[0121] Among them, K salt_key The key used to perform secondary encryption on the salt value salt;

[0122] Calculate the salt value H generated by hashing the i-th data salt , specifically:

[0123] H salt =HMAC SHA-512 (d i ||salt,K′ salt)

[0124] Among them, K′ salt The second salt value is dynamically generated.

[0125] Specifically, calculate the dynamically generated second salt value K′ salt , specifically:

[0126] K′ salt =KDF(ID ship ||T,Salt)

[0127] Among them, KDF is the key derivation function.

[0128] Step 103: When the user identity verification is successful, the non-core data is allowed to be transmitted or read. When transmitting or reading the core data, the user searches for the core data in the distributed storage node according to the storage address and metadata stored in the block, and completes the final transmission or reading through the key.

[0129] Specifically, it also includes: using end-to-end encryption to encrypt all data uploaded to the blockchain, and using a key distribution mechanism to distribute the keys to the corresponding users.

[0130] Specifically, it also includes: dynamically adjusting the storage capacity of the block according to the amount of data generated by the ship, wherein when the amount of data generated by the ship exceeds a first data volume threshold, the storage capacity of the corresponding block is increased; when the amount of data generated by the ship is less than a second data volume threshold, the storage capacity of the corresponding block is reduced, thereby saving storage resources.

[0131] Specifically, it also includes: allocating different levels of access rights to different users, wherein the core data requires the highest access right.

[0132] Example 4

[0133] An embodiment of the present invention also proposes an electronic device, comprising a processor and a storage medium connected to the processor, wherein the storage medium stores a plurality of instructions, which can be loaded and executed by the processor, so that the processor can execute the blockchain-based method for secure storage and transmission of ship shipping data.

[0134] Specifically, the electronic device of this embodiment may be a computer terminal, which may include: one or more processors, and a storage medium.

[0135] The storage medium can be used to store software programs and modules, such as the corresponding program instructions / modules for a blockchain-based method for secure storage and transmission of shipping data in an embodiment of the present invention. The processor executes the software programs and modules stored on the storage medium to perform various functional applications and data processing, thereby implementing the blockchain-based method for secure storage and transmission of shipping data. The storage medium can include high-speed random access memory (RAM) and non-volatile storage media, such as one or more magnetic storage systems, flash memory, or other non-volatile solid-state storage media. In some instances, the storage medium may further include storage media located remotely from the processor, which can be connected to the terminal via a network. Examples of such networks include, but are not limited to, the internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0136] The processor can call the information and application stored in the storage medium through the transmission system to perform the following steps: Step 101, obtain ship shipping data, and cut the ship shipping data into core data and non-core data, wherein the core data includes: cargo information, crew data, and the non-core data includes: real-time navigation position, ship status;

[0137] Step 102: Store the core data in a distributed storage node and encrypt the core data using an encryption algorithm. After encryption, store the storage address of the core data and the corresponding metadata in a block of the blockchain, and store the non-core data in a block of the blockchain.

[0138] Specifically, the encryption algorithm is: elliptic curve encryption or hash algorithm.

[0139] Preferably, in order to achieve better encryption effect, this embodiment proposes a new encryption algorithm, specifically:

[0140] Generate an encrypted identifier for each piece of data in the core data, specifically:

[0141] EID i =HMAC SHA-256 (ID ship ||T||i||salt,K salt )

[0142] Among them, EID i is the encryption identifier of the i-th data, HMAC SHA-256 The hash value generated using SHA-256 and HMAC, ID ship is the ship identifier, T is the timestamp of data generation, salt is the salt value used to increase randomness, K salt The first salt value is dynamically generated;

[0143] Encrypted identifier EID of data according to item i i Encrypt each piece of data, specifically:

[0144]

[0145] Among them, C i is the encrypted data of the i-th data, E Enc For encryption operations, d i is the i-th data, K i is the increasing key sequence of the i-th data, K i-1 is the increasing key sequence of the i-1th data, H salt is the salt value generated after hashing the i-th data. It is an exclusive OR operation.

[0146] Specifically, the salt value used to increase randomness is calculated as follows:

[0147] salt=HMAC SHA-256 (ID ship ||T||R,K salt_base )

[0148] Among them, R is a random number used for encryption security, K salt_base As the base key.

[0149] Specifically, calculate the dynamically generated salt value K salt , specifically:

[0150] K salt =HMAC SHA-512 (salt||ID ship ,K salt_key )

[0151] Among them, K salt_key The key used to perform secondary encryption on the salt value salt;

[0152] Calculate the salt value H generated by hashing the i-th data salt , specifically:

[0153] H salt =HMAC SHA-512 (d i ||salt,K′ salt )

[0154] Among them, K′ salt The second salt value is dynamically generated.

[0155] Specifically, calculate the dynamically generated second salt value K′salt , specifically:

[0156] K′ salt =KDF(ID ship ||T,Salt)

[0157] Among them, KDF is the key derivation function.

[0158] Step 103: When the user identity verification is successful, the non-core data is allowed to be transmitted or read. When transmitting or reading the core data, the user searches for the core data in the distributed storage node according to the storage address and metadata stored in the block, and completes the final transmission or reading through the key.

[0159] Specifically, it also includes: using end-to-end encryption to encrypt all data uploaded to the blockchain, and using a key distribution mechanism to distribute the keys to the corresponding users.

[0160] Specifically, it also includes: dynamically adjusting the storage capacity of the block according to the amount of data generated by the ship, wherein when the amount of data generated by the ship exceeds a first data volume threshold, the storage capacity of the corresponding block is increased; when the amount of data generated by the ship is less than a second data volume threshold, the storage capacity of the corresponding block is reduced, thereby saving storage resources.

[0161] Specifically, it also includes: allocating different levels of access rights to different users, wherein the core data requires the highest access right.

[0162] The serial numbers of the above embodiments of the present invention are for description only and do not represent the advantages or disadvantages of the embodiments.

[0163] In the above embodiments of the present invention, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0164] In the several embodiments provided by the present invention, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the system embodiments described above are merely illustrative. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, and can be electrical or other forms.

[0165] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0166] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0167] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, read-only storage medium (ROM, Read-Only Memory), random access storage medium (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk, etc. Various media that can store program codes.

[0168] Obviously, the above embodiments are merely examples for clarity of explanation and are not intended to limit the implementation methods. Those skilled in the art will readily appreciate that other variations or modifications based on the above descriptions are possible. It is not necessary and impossible to enumerate all implementation methods here. Obvious variations or modifications arising therefrom remain within the scope of protection of the present invention.

Claims

1. A method for secure storage and transmission of ship shipping data based on blockchain, characterized in that: include: Acquire ship shipping data and segment the ship shipping data into core data and non-core data, wherein the core data includes cargo information and crew data, and the non-core data includes real-time navigation position and ship status; The core data is stored in a distributed storage node and encrypted using an encryption algorithm. After encryption, the storage address of the core data and the corresponding metadata are stored in a block of the blockchain, and the non-core data is stored in a block of the blockchain; When the user identity authentication is successful, the non-core data is allowed to be transmitted or read. When transmitting or reading the core data, the user searches for the core data in the distributed storage node according to the storage address and metadata stored in the block, and completes the final transmission or reading through the key.

2. The method for secure storage and transmission of ship shipping data based on blockchain according to claim 1, characterized in that: Also includes: All data uploaded to the blockchain is encrypted using end-to-end encryption, and the key distribution mechanism is used to distribute the key to the corresponding users.

3. The method for secure storage and transmission of ship shipping data based on blockchain according to claim 1, characterized in that: Also includes: The storage capacity of the block is dynamically adjusted according to the amount of data generated by the ship. When the amount of data generated by the ship exceeds a first data volume threshold, the storage capacity of the corresponding block is increased. When the amount of data generated by the ship is less than a second data volume threshold, the storage capacity of the corresponding block is reduced, thereby saving storage resources.

4. The method for secure storage and transmission of ship shipping data based on blockchain according to claim 1, characterized in that: Also includes: Different levels of access rights are assigned to different users, wherein the core data requires the highest access rights.

5. The method for secure storage and transmission of ship shipping data based on blockchain according to claim 1, characterized in that: The encryption algorithm is: elliptic curve encryption or hash algorithm.

6. The method for secure storage and transmission of ship shipping data based on blockchain according to claim 1, characterized in that: The encryption algorithm is: Generate an encrypted identifier for each piece of data in the core data, specifically: EID i HMAC SHA-256 (ID ship ∥T∥i∥salt,K salt ) Among them, EID i is the encryption identifier of the i-th data, HMAC SHA-256 The hash value generated using SHA-256 and HMAC, ID ship is the ship identifier, T is the timestamp of data generation, salt is the salt value used to increase randomness, K salt The first salt value is dynamically generated; Encrypted identifier EID of data according to item i i Encrypt each piece of data, specifically: Among them, C i is the encrypted data of the i-th data, E Enc For encryption operations, d i is the i-th data, K i is the increasing key sequence of the i-th data, K i-1 is the increasing key sequence of the i-1th data, H salt is the salt value generated after hashing the i-th data. It is an exclusive OR operation.

7. A method for secure storage and transmission of ship shipping data based on blockchain as claimed in claim 6, characterized in that: Calculate the salt value used to increase randomness, specifically: salt=HMAC SHA-256 (ID ship ∥T∥R,K salt_base ) Among them, R is a random number used for encryption security, K salt_base As the base key.

8. The method for secure storage and transmission of ship shipping data based on blockchain according to claim 7, characterized in that: Calculate the dynamically generated salt value K salt , specifically: K salt =HMAC SHA-512 (salt∥ID ship ,K salt_key ) Among them, K salt_key The key used to perform secondary encryption on the salt value salt; Calculate the salt value H generated by hashing the i-th data salt , specifically: H salt =HMAC SHA-512 (d i ∥salt,K s ′ alt ) Among them, K′ salt The second salt value is dynamically generated.

9. The method for secure storage and transmission of ship shipping data based on blockchain according to claim 8, characterized in that: Calculate the dynamically generated second salt value K′ salt , specifically: K s ′ alt =KDF(ID ship ∥T,Salt) Among them, KDF is the key derivation function.

10. A blockchain-based ship shipping data security storage and transmission system, characterized by: include: a cutting module for acquiring ship shipping data and cutting the ship shipping data into core data and non-core data, wherein the core data includes cargo information and crew data, and the non-core data includes real-time navigation position and ship status; A storage module, configured to store the core data in a distributed storage node and encrypt the core data using an encryption algorithm. After encryption, the storage address and corresponding metadata of the core data are stored in a block of the blockchain, and the non-core data are stored in a block of the blockchain. The transmission module is used to allow the transmission or reading of the non-core data after the user identity authentication is successful. When transmitting or reading the core data, the user searches for the core data in the distributed storage node according to the storage address and metadata stored in the block, and completes the final transmission or reading through the key.