Data reading method and device, nonvolatile storage medium and computer equipment
By obtaining verifiable credentials and an encrypted index list from the blockchain evidence storage platform, combined with lightweight and homomorphic decryption algorithms, the security and privacy issues of data during cloud circulation are resolved, and the security and privacy protection of data reading are achieved.
Patent Information
- Application Number
- CN202510780371.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-11
- Publication Date
- 2025-09-05
AI Technical Summary
In the industrial Internet environment, existing technologies lack effective solutions to ensure the authenticity and integrity of data during cross-domain circulation and prevent data abuse and security risks.
By obtaining verifiable credentials, using the blockchain evidence storage platform to obtain the encrypted index list, and combining the lightweight ciphertext policy attribute decryption algorithm and the homomorphic decryption algorithm, secure reading of cloud platform data is achieved, ensuring the privacy and integrity of the data.
It achieves security and privacy protection during data reading, prevents data abuse, and enhances the credibility and compliance of data during cloud circulation.
Smart Images

Figure CN120602070A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of blockchain technology, and in particular to a data reading method, device, non-volatile storage medium, and computer equipment. Background Art
[0002] In the current Industrial Internet landscape, the integration of IoT devices and cloud platforms has brought unprecedented data-driven intelligence to the manufacturing industry, significantly improving production efficiency and reducing costs. However, the widespread adoption of this model has also exposed a series of challenges in data security and privacy protection. Ensuring the authenticity and integrity of data during cross-domain circulation is a major challenge. Once cloud data circulates across domains, the owner's control is significantly weakened, increasing the risk of data misuse. Once data leaves its native management domain, it becomes difficult to effectively monitor its status during transmission, storage, and access. Data tampering and misuse are common, affecting data credibility and misleading subsequent business decisions.
[0003] To address the above-mentioned problems, no effective solutions have been proposed so far. Summary of the Invention
[0004] Embodiments of the present invention provide a data reading method, apparatus, non-volatile storage medium, and computer device to at least address the technical issues of data abuse risks and data security risks in current cloud data circulation.
[0005] According to one aspect of an embodiment of the present invention, a data reading method is provided, including: obtaining a verifiable credential, wherein the verifiable credential is used to verify the read permission of the requesting end of the data reading; based on the verifiable credential, obtaining an encrypted index list from a blockchain evidence storage platform; decrypting the encrypted index list to obtain an index list; based on the index list, reading encrypted target data on a cloud platform; decrypting the encrypted target data to obtain target data.
[0006] Optionally, obtaining a verifiable credential includes: obtaining a decentralized identity identifier, wherein the decentralized identity identifier is an identity authentication identifier of the requesting end; sending a credential application request to a target end for data reading through any blockchain node on the blockchain, wherein the credential application request includes the decentralized identity identifier; and receiving a verifiable credential generated by the target end based on the credential application request.
[0007] Optionally, obtaining a decentralized identity identifier includes: sending a registration request to any blockchain node on the blockchain, wherein the registration request includes basic information and authentication information of the requesting end; and receiving the decentralized identity identifier of the requesting end generated by the blockchain node based on the registration request.
[0008] Optionally, the receiving blockchain node generates a public key of the requesting end based on the registration request and a partial private key of the requesting end; based on the public key and the partial private key, the complete private key of the requesting end is obtained, wherein the public key is used to encrypt the index list and the complete private key is used to decrypt the encrypted index list.
[0009] Optionally, based on the verifiable credential, an encrypted index list is obtained from the blockchain evidence storage platform, including: based on the verifiable credential, generating a verifiable expression of the requesting end, wherein the verifiable expression is part of the information in the verifiable credential that proves the identity of the requesting end; based on the verifiable expression, obtaining the encrypted index list from the blockchain evidence storage platform.
[0010] Optionally, decrypting the encrypted index list to obtain the index list includes: decrypting the encrypted index list based on a lightweight ciphertext policy attribute decryption algorithm to obtain the index list.
[0011] Optionally, decrypting the encrypted target data to obtain the target data includes: decrypting the encrypted target data based on a homomorphic decryption algorithm to obtain the target data.
[0012] According to another aspect of an embodiment of the present invention, a data reading method is also provided, including: receiving a data reading request sent by a data reading requesting end, wherein the data reading request includes a verifiable expression corresponding to the requesting end, and the verifiable expression is used to verify the reading permission of the requesting end; reviewing the data reading request to obtain a first review result; if the first review result is passed, uploading the target data to the cloud platform, wherein the target data is used for the requesting end to execute any one of the above-mentioned data reading methods to perform data reading.
[0013] Optionally, before receiving the data reading request sent by the data reading requesting end, it also includes: receiving a credential application request sent by the requesting end through any blockchain node on the blockchain, wherein the credential application request includes a decentralized identity identifier; based on the credential application request, searching in any blockchain node on the blockchain to obtain a retrieval result corresponding to the requesting end; based on the retrieval result, reviewing the credential application request to obtain a second review result; if the second review result is passed, generating a verifiable credential.
[0014] Optionally, uploading the target data to the cloud platform includes: encrypting the target data based on a homomorphic encryption algorithm to obtain encrypted target data; and uploading the encrypted target data to the cloud platform.
[0015] Optionally, an index list generated by the receiving cloud platform based on the encrypted target data is included, wherein the index list includes a hash value corresponding to the encrypted target data; based on the verifiable expression, the index list is encrypted by a lightweight ciphertext policy attribute encryption algorithm to obtain an encrypted index list; and the encrypted index list is uploaded to the blockchain evidence storage platform.
[0016] According to another aspect of an embodiment of the present invention, a data reading method is also provided, including: receiving a data reading request sent by a data reading requesting end, wherein the data reading request includes a verifiable expression corresponding to the requesting end; reviewing the data reading request to obtain a third review result; if the third review result is passed, allowing the requesting end to execute any one of the above-mentioned data reading methods to read the target data.
[0017] According to another aspect of an embodiment of the present invention, a data reading method is also provided, including: sending a decentralized identity identifier corresponding to a requesting end for data reading to the requesting end, wherein the requesting end executes any one of the above-mentioned data reading methods; receiving a credential application request sent by the requesting end and passing it to a target end for data reading, wherein the credential application request includes a decentralized identity identifier; receiving and saving a verifiable credential of the requesting end generated by the target end based on the credential application request; and sending the verifiable credential to the requesting end.
[0018] Optionally, the decentralized identity identifier corresponding to the requesting end of the data reading is sent to the requesting end, including: receiving a registration request sent by the requesting end, wherein the registration request includes basic information and authentication materials of the requesting end; based on the registration request, generating and saving the decentralized identity identifier of the requesting end, and sending the decentralized identity identifier to the requesting end.
[0019] Optionally, based on the elliptic curve cryptography certificateless key distribution algorithm, the public key of the requesting end is generated, where the public key is used to encrypt the index list; based on the registration request, the decentralized identity identifier and the public key, a decentralized identity document is constructed and saved, where the decentralized identity document is used to manage all public keys of the requesting end.
[0020] According to another aspect of an embodiment of the present invention, a non-volatile storage medium is provided. The non-volatile storage medium includes a stored program, wherein when the program is running, the device where the non-volatile storage medium is located is controlled to execute any one of the above-mentioned data reading methods.
[0021] According to yet another aspect of an embodiment of the present invention, a computer device is provided. The computer device includes a processor, and the processor is configured to run a program. When the program is run, any one of the above-mentioned data reading methods is executed.
[0022] According to yet another aspect of an embodiment of the present invention, a computer program product is provided, including a computer program, which implements any one of the above-mentioned data reading methods when executed by a processor.
[0023] In an embodiment of the present invention, a data reading method is adopted, by obtaining a verifiable credential, wherein the verifiable credential is used to verify the read permission of the requesting end of data reading; based on the verifiable credential, an encrypted index list is obtained from the blockchain evidence storage platform; the encrypted index list is decrypted to obtain an index list; based on the index list, encrypted target data is read on the cloud platform; the encrypted target data is decrypted to obtain the target data, thereby achieving the purpose of combining the hash list stored in the blockchain with the cloud storage to perform data encryption reading, thereby realizing the technical effect of enhancing the security and privacy protection of data reading, and further solving the technical problems of data abuse risks and data security risks in the current cloud data circulation. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0025] Figure 1 A hardware structure block diagram of a computer terminal for implementing a data reading method is shown;
[0026] Figure 2 is a flow chart of a data reading method according to an embodiment of the present invention;
[0027] Figure 3 is a flow chart of a data sharing phase provided according to an optional embodiment of the present invention;
[0028] Figure 4 is a flow chart of a credential application phase according to an optional embodiment of the present invention;
[0029] Figure 5 is a flow chart of a data uploading phase provided according to an optional embodiment of the present invention;
[0030] Figure 6 is a flowchart of a registration phase provided according to an optional embodiment of the present invention;
[0031] Figure 7 is a schematic diagram of a data access control system provided according to an optional embodiment of the present invention;
[0032] Figure 8 is a structural block diagram of a data reading device provided according to an optional embodiment of the present invention. DETAILED DESCRIPTION
[0033] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0034] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0035] According to an embodiment of the present invention, an embodiment of a data reading method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0036] The method embodiment provided in the first embodiment of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Figure 1 FIG1 shows a hardware structure block diagram of a computer terminal for implementing a data reading method. Figure 1 As shown, the computer terminal 10 may include one or more (illustrated as 102a, 102b, ..., 102n in the figure) processors (the processor may include but is not limited to a microprocessor MCU or a programmable logic device FPGA and other processing devices), a memory 104 for storing data. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply and / or a camera. It will be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the above electronic device. Figure 1More or fewer components than shown, or with Figure 1 Different configurations shown.
[0037] It should be noted that the one or more processors and / or other data processing circuits described above may generally be referred to herein as "data processing circuitry." The data processing circuitry may be embodied in whole or in part as software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuitry may be a single, independent processing module, or may be incorporated in whole or in part into any of the other components of the computer terminal 10. As described in the embodiments of the present application, the data processing circuitry serves as a processor control (e.g., selection of a variable resistor terminal path connected to an interface).
[0038] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the data reading method in the embodiment of the present invention. The processor executes the software programs and modules stored in the memory 104 to perform various functional applications and data processing, that is, to implement the data reading method of the application described above. The memory 104 may include a high-speed random access memory and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, the memory 104 may further include a memory remotely located relative to the processor, and these remote memories may be connected to the computer terminal 10 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0039] The display may be, for example, a touch screen liquid crystal display (LCD) that enables a user to interact with a user interface of the computer terminal 10 .
[0040] Figure 2 FIG. 1 is a flow chart of a data reading method according to an embodiment of the present invention. Figure 2 As shown, the method includes the following steps:
[0041] Step S201: obtaining a verifiable credential, wherein the verifiable credential is used to verify the read permission of the requesting end for data reading.
[0042] In this step, a verifiable credential (VC) is a new type of credential that allows an entity to share the attributes or certificates of its identity in a secure and controllable manner. The design principles of VC are decentralization, privacy protection, and user control. For example, when enterprise B (the requesting end of data reading) wants to obtain specific industrial data from enterprise A (the target end of data reading), enterprise B must first obtain a verifiable credential issued by enterprise A, which contains information about reading permissions. This VC not only indicates that enterprise B has been authorized by enterprise A, but also specifies in detail the specific permission details such as the type of data that enterprise B can access, access time, and access frequency. This process usually involves enterprise B issuing a data access request to enterprise A. Enterprise A decides whether to grant access rights based on established access policies and agreements, and binds the VC to the DID of the requesting end through DID (distributed identity) technology to ensure the uniqueness and immutability of the VC.
[0043] Step S202: Based on the verifiable credentials, obtain the encrypted index list from the blockchain evidence storage platform.
[0044] In this step, the requesting party can generate a VP (Verifiable Presentation) from the VC it holds. The VP contains the requesting party's DID identifier and some attribute information, as well as the necessary credentials to prove that it has data access rights. The requesting party uses the VP to initiate a request to the blockchain evidence storage platform, requesting access to an encrypted index list of specific data, that is, a list of encrypted files containing data hash values. After receiving the VP, the blockchain evidence storage platform will verify the identity of the requesting party (through the DID identifier) and whether it has permission to access the data specified in the request (based on the attributes in the VC). If the verification is successful, the blockchain evidence storage platform will provide the encrypted index list to the requesting party.
[0045] Step S203: decrypt the encrypted index list to obtain an index list.
[0046] In this step, the requesting end can decrypt the encrypted index list. After decryption, the requesting end can obtain the index list containing the hash value of the encrypted target data, which is used to locate the specific data file on the cloud platform.
[0047] Step S204: Read the encrypted target data on the cloud platform based on the index list.
[0048] In this step, the requesting end can send a data request to the cloud sharing platform, along with an index list consisting of hash values, to index a specific encrypted file and obtain the encrypted target data.
[0049] Step S205: decrypt the encrypted target data to obtain the target data.
[0050] In this step, the requesting end can use the key to decrypt the data previously read from the cloud platform, and finally obtain the target data in plain text. This data reading process ensures the privacy, integrity and authenticity of the data, and avoids security issues that may arise during data circulation in the cloud. For example, Figure 3 is a flow chart of a data sharing phase according to an optional embodiment of the present invention. Figure 3 As shown, first, Enterprise B generates a VP (Verification Proof), extracting some information from the VC and attaching a digital signature, and then submits an access request to the blockchain evidence storage platform. The request includes Enterprise B's DID identifier and a description of the target data (such as a file hash list or time range). The blockchain evidence storage platform verifies the legitimacy of the VP information and confirms Enterprise B's identity and permissions. It then provides Enterprise B with access to the encrypted data uploaded by Enterprise A (file hash list and decryption key). Enterprise B uses the CP-ABE algorithm to decrypt the obtained encrypted data, extracting the file hash list and decryption key. Finally, Enterprise B uses the file hash list to index the encrypted files on the cloud sharing platform and restores the data locally using a homomorphic decryption algorithm. Once the data is decrypted, Enterprise B can safely use the sensitive shared data, and the entire process is recorded on the blockchain evidence storage platform to ensure traceability and compliance.
[0051] Through the above steps, the purpose of combining the hash list stored in the blockchain with cloud storage for encrypted data reading is achieved, thereby achieving the technical effect of enhancing the security and privacy protection of data reading, and further solving the technical problems of data abuse risks and data security risks in the current cloud data circulation.
[0052] As an optional embodiment, obtaining a verifiable credential includes: obtaining a decentralized identity identifier, wherein the decentralized identity identifier is an identity authentication identifier of the requesting end; sending a credential application request to a target end for data reading through any blockchain node on the blockchain, wherein the credential application request includes the decentralized identity identifier; and receiving a verifiable credential generated by the target end based on the credential application request.
[0053] Optionally, to securely access data stored in the cloud, the requester must first register with a blockchain node to obtain a decentralized identity (DID). The blockchain node returns the generated DID and partial private key information (used for subsequent authentication and data decryption) to the requester via a secure communication mechanism. The requester must securely store this information, especially the private key, as it is used to construct identity credentials for subsequent data access and sharing.
[0054] The requesting end then sends a credential application request to the target end through a blockchain node. The blockchain node ensures that the request is securely and accurately transmitted to the destination without being intercepted or tampered with by unauthorized entities. For example, the requesting end, Enterprise B, constructs a credential application request that includes Enterprise B's DID identifier, the reason for the application, the scope of the requested permission (such as the specific type or timeliness of the data to be read), and a digital signature. Enterprise B sends the application request to the DID identifier of the target end, Enterprise A, through the DID blockchain infrastructure (blockchain node), ensuring that the request will not be tampered with during transmission.
[0055] Finally, the requesting party receives the VC issued by the target party through the blockchain node. This reception process ensures the secure transmission of the VC, preventing it from being intercepted or tampered with by a third party. After verifying the integrity and validity of the VC, the requesting party can use it as proof of eligibility for data access.
[0056] As an optional embodiment, obtaining a decentralized identity identifier includes: sending a registration request to any blockchain node on the blockchain, wherein the registration request includes basic information and authentication information of the requesting end; and receiving the decentralized identity identifier of the requesting end generated by the blockchain node based on the registration request.
[0057] Optionally, when a data reader requests access to data on a target end, it can first go through a registration process to prove its identity and access legitimacy. This registration process involves sending a registration request to a blockchain node that supports DID. The request contains basic information and authentication information about the requester. For example, requester Enterprise B sends a registration request to the DID blockchain infrastructure (i.e., a blockchain node) through a trusted network interface (such as the DID API). The request contains Enterprise B's basic information, such as company name, organization code, email address, etc., as well as Enterprise B's authentication information, such as a digital signature or authentication documents issued by a third-party trusted organization, to ensure the authenticity and legitimacy of the application.
[0058] DID leverages blockchain technology to implement a decentralized identity authentication mechanism, replacing the single point of failure risk inherent in traditional centralized authentication systems and enhancing the robustness and security of the system. DID leverages on-chain evidence storage and smart contracts to achieve trusted cross-domain identity verification. Incorporating zero-knowledge proof (ZKP) technology, DID ensures authentication reliability while minimizing the disclosure of sensitive information. Through the DID system, data providers and demanders no longer need to rely on third-party institutions during the collaborative process, thus avoiding the potential loss of trust transfer in traditional trust chains and significantly improving the credibility of identity authentication and privacy protection.
[0059] As an optional embodiment, the blockchain node receives the public key of the requesting end generated based on the registration request and the partial private key of the requesting end; based on the public key and the partial private key, the complete private key of the requesting end is obtained, wherein the public key is used to encrypt the index list and the complete private key is used to decrypt the encrypted index list.
[0060] Optionally, after receiving the registration request, the blockchain node can generate a public-private key pair for the requester using the certificateless elliptic curve-based CP-ABE (Ciphertext-Policy Attribute-Based Encryption) algorithm. This decentralized process means that key generation and management do not rely on any single central authority, reducing centralization risks. The public key is publicly available and stored on the blockchain, while only a partial private key is securely stored by the blockchain node or sent to the requester via a secure channel such as a hardware security module (HSM). After receiving the partial private key, the requester uses a specific key combination algorithm to calculate the full private key. The full private key is used to decrypt the encrypted index list and is a critical component of the data encryption process. This calculation ensures the security of the private key because the full private key is generated without a third-party node, eliminating the risk of key leakage. For example, the DID blockchain infrastructure sends the generated DID identifier and partial private key to Enterprise B via a secure channel (such as the TLS protocol). The partial private key information is delivered only via the HSM or multi-factor authentication to prevent key leakage. Enterprise B needs to complete its own public and private key calculations, securely store the private key locally or in a dedicated hardware device (such as an encryption module), and record the DID identifier for subsequent use.
[0061] Specifically, the process of generating public and private keys using the certificateless CP-ABE algorithm based on elliptic curves is as follows: the system can first be initialized to generate system public parameters (no master key escrow requester private key). Based on the preset security parameter λ, the elliptic curve parameters are selected, and the bilinear group is selected. The order is a prime number p, and the generator is So we can define a bilinear map Next, choose a hash function, such as Can be used to map the requester identity to a random number, It can be used to map attributes to group elements. Finally, the public parameters of the system are generated and the master key is randomly selected. Compute the system public key P pub =g s , get the public parameters:
[0062] Then, the requesting end can generate the key and obtain the public-private key pair without certificate, avoiding the KGC (Key Generation Center) hosting the private key. Based on the identity ID of the requesting end, the public key can be generated and a random secret value can be selected. Calculate the public key: Then use KGC to calculate d ID =H1(ID), generate partial private key: The requester can synthesize the complete private key by itself: SK ID =(x ID ,D ID ). Therefore, KGC only knows D ID , I don't know x ID , the complete private key cannot be recovered.
[0063] Next, you can use the generated public key to encrypt the index list. First, select a random number calculate: C1=g σ . Access strategy corresponding to the index list For each attribute j, generate: C j =H2(j) σ ,C j ′=e(P ID ,R j ) σ Finally, the encrypted index list is output.
[0064] Finally, when decrypting, it is necessary to generate the attribute private key based on the complete private key. The attribute set of the requesting end is S. For each attribute j∈S, a random number is selected. calculate: KGC is calculated for each attribute j∈S: in Finally, x ID With K j Combined to generate the final attribute private key: SK j =(x ID ·K j ,R j ,Q j ), you also need to ensure that SK j Can be refactored to Then you can use the attribute private key SK j Decrypt the ciphertext of the encrypted index list. First verify whether the attribute set S satisfies For the attribute j that satisfies the condition, reconstruct the secret value and calculate: Recovery via Lagrange interpolation Finally, the plaintext of the index list is calculated:
[0065] The public-private key pair is generated by the certificateless CP-ABE algorithm based on the elliptic curve. The private key is generated by x ID (optional) and D ID (generated by KGC), KGC cannot obtain the complete private key, enhancing security. Furthermore, without the need for certificates to bind public keys to identities, the legitimacy of public keys is directly verified through hash functions and elliptic curve operations, simplifying management. Key generation based on elliptic curve discrete logarithms not only reduces the computational overhead of key generation, but also, through integration with the bilinear Diffie-Hellman (BDH) assumption, prevents plaintext attacks and key leakage.
[0066] As an optional embodiment, based on the verifiable credential, an encrypted index list is obtained from the blockchain evidence storage platform, including: based on the verifiable credential, generating a verifiable expression of the requesting end, wherein the verifiable expression is part of the information in the verifiable credential that proves the identity of the requesting end; based on the verifiable expression, obtaining the encrypted index list from the blockchain evidence storage platform.
[0067] Optionally, before the requesting end wishes to access the target end's data stored on the cloud platform, it must first obtain an encrypted index list from the blockchain Muramasa platform. The requesting end does not need to fully disclose the VC. Instead, it generates a VP (partial VC information) to disclose only the information necessary for access control (such as specific permissions, validity period, etc.) to reduce the exposure of private information. For example, the DID blockchain infrastructure returns the VC hash value and associated information issued by target enterprise A to requesting enterprise B for verification of subsequent data access requests. Enterprise B must verify the integrity and legitimacy of the VC content and securely store its related information. Once the VP verification is passed, the blockchain evidence storage platform will allow the requesting end to read the encrypted index list of the encrypted data, typically a list of hash values of the encrypted data. This index information is stored on the blockchain evidence storage platform, separate from the actual data, to protect data privacy.
[0068] As an optional embodiment, decrypting the encrypted index list to obtain the index list includes: decrypting the encrypted index list based on a lightweight ciphertext policy attribute decryption algorithm to obtain the index list.
[0069] Optionally, the requester can use the lightweight CP-ABE algorithm to decrypt the encrypted index list obtained from the blockchain evidence storage platform. This list contains the hash value of the encrypted data and serves as the index for locating data on the cloud platform.
[0070] Ciphertext policy attribute encryption (CP-ABE) is a data encryption mechanism that supports fine-grained access control. Its core concept is to embed access permissions into ciphertext through encryption policies. Traditional CP-ABE has high computational complexity and is not suitable for resource-constrained industrial IoT environments. In this embodiment, a lightweight CP-ABE algorithm is proposed by optimizing elliptic curve operations and key distribution processes to reduce the computational overhead during encryption and decryption, enabling efficient operation on embedded devices and edge nodes. Furthermore, the algorithm supports dynamic attribute updates, ensuring that access policies can flexibly adapt to real-time needs in data sharing scenarios, further improving the management efficiency and security of industrial data.
[0071] As an optional embodiment, decrypting the encrypted target data to obtain the target data includes: decrypting the encrypted target data based on a homomorphic decryption algorithm to obtain the target data.
[0072] Optionally, after obtaining the encrypted target data, the requesting end uses a homomorphic decryption algorithm to perform specific operations, such as searching or computing, without first decrypting the data, thereby protecting data privacy.
[0073] Homomorphic decryption technology allows operations on data in a decrypted state, effectively preventing the risk of plaintext exposure during data sharing. By combining homomorphic encryption and decryption technology with blockchain evidence storage, data privacy protection and trusted auditing are unified: data is homomorphically encrypted before being uploaded to the cloud platform, and the blockchain is responsible for storing the data's hash value and access rights for the encryption key. The blockchain's immutability ensures the trustworthiness and traceability of the entire data sharing process, while homomorphic encryption and decryption provide the privacy protection technical support for data operations and analysis. This combination significantly improves data security, controllability, and compliance in the Industrial Internet environment.
[0074] According to an embodiment of the present invention, a data reading method is also provided, including: receiving a data reading request sent by a data reading requesting end, wherein the data reading request includes a verifiable expression corresponding to the requesting end, and the verifiable expression is used to verify the reading permission of the requesting end; reviewing the data reading request to obtain a first review result; if the first review result is passed, uploading the target data to the cloud platform, wherein the target data is used for the requesting end to execute any one of the above-mentioned data reading methods to perform data reading.
[0075] Optionally, after receiving the request from the requesting end, the target end can first verify the validity of the VP. If the target end's first review of the data read request is successful, it means that the requesting end has the legal authority to access the target data. At this point, the target end can upload the target data to the cloud platform in a homomorphically encrypted form, and simultaneously upload the data hash list, as well as the decryption key and access policy encrypted using the CP-ABE algorithm to the blockchain evidence storage platform. This upload process ensures that the privacy of the data will not be leaked during transmission, while also providing the necessary index and key information for subsequent access by the requesting end, maintaining the integrity and accessibility of the data.
[0076] As an optional embodiment, before receiving the data reading request sent by the data reading requesting end, it also includes: receiving a credential application request sent by the requesting end through any blockchain node on the blockchain, wherein the credential application request includes a decentralized identity identifier; based on the credential application request, searching in any blockchain node on the blockchain to obtain a retrieval result corresponding to the requesting end; based on the retrieval result, reviewing the credential application request to obtain a second review result; if the second review result is passed, generating a verifiable credential.
[0077] Optionally, after receiving the request from the requester, the target uses the requester's DID to search the blockchain node for the corresponding decentralized identity document. This process ensures that the requester's identity information is registered and verified on the blockchain, enhancing the trust and security of the entire process. Based on the DID document retrieved from the blockchain node, the target begins to review the requester's credential application request. This review may include checking whether the requester's attributes meet the data access policy, verifying the validity of their authentication materials, and confirming the reasonableness of the requested data access rights. If the requester's application passes the review, the target generates a VC containing the requester's DID, the granted permissions, and possible other metadata such as the validity period. The VC is then stored on the blockchain and returned to the requester as a credential for data access.
[0078] For example, Figure 4 : is a flow chart of a credential application stage according to an optional embodiment of the present invention. Figure 4 As shown in the figure, Company A verifies whether Company B's DID exists on the blockchain network and checks Company B's authentication information and scope of authority. If approved, Company A issues a VC containing Company B's DID, scope of authority, validity period, and other information, and stores the VC on the blockchain. The VC on the blockchain is recorded as a hash value to ensure that the content cannot be tampered with and protect privacy.
[0079] As an optional embodiment, uploading the target data to the cloud platform includes: encrypting the target data based on a homomorphic encryption algorithm to obtain encrypted target data; and uploading the encrypted target data to the cloud platform.
[0080] Optionally, the target end uses a homomorphic encryption algorithm to encrypt the target data before uploading it to the cloud platform. Homomorphic encryption is a special encryption technology that allows mathematical or logical operations to be performed on encrypted data, and the decrypted results are consistent with the results of the same operations performed on the original plaintext data. This means that even if the data is encrypted, operations such as data analysis, processing, or retrieval can be performed on the cloud platform without first decrypting the data. The target end then uploads the encrypted target data to the cloud platform. The uploaded encrypted target data is stored in the cloud environment, and some data processing operations can be performed without decryption.
[0081] As an optional embodiment, an index list generated by a cloud platform based on encrypted target data is received, wherein the index list includes a hash value corresponding to the encrypted target data; based on verifiable expression, the index list is encrypted using a lightweight ciphertext policy attribute encryption algorithm to obtain an encrypted index list; and the encrypted index list is uploaded to a blockchain evidence storage platform.
[0082] Optionally, after the target end homomorphically encrypts the target data and uploads it to the cloud platform, the cloud platform will generate a hash value for each uploaded encrypted target data. These hash values constitute the index list of the encrypted target data, which is used for subsequent data location and access control. As the unique digital fingerprint of the data, the hash value can efficiently represent the integrity of the data without storing or transmitting the data itself, which is especially important when processing large amounts of data. Based on the verifiable credentials (VC) of the requesting end, the target end uses the lightweight ciphertext policy attribute encryption (CP-ABE) algorithm to encrypt the index list to obtain an encrypted index list. The CP-ABE algorithm allows the target end to embed access policies when encrypting the index list. For example, only users with specific permissions and attributes can decrypt the index list and access the encrypted data. This encryption process not only protects the privacy of the index list, but also provides fine-grained control for data access, ensuring that data access complies with preset permission rules. The encrypted index list is uploaded to the blockchain notarization platform for storage. The blockchain notarization of this information enables data owners, visitors and other relevant parties to trace the data flow history and access records during subsequent data access and audit processes, further enhancing the transparency and controllability of the data sharing process.
[0083] For example, Figure 5 : is a flow chart of a data uploading stage according to an optional embodiment of the present invention. Figure 5As shown in the figure, Enterprise B initiates a data sharing request to Enterprise A through the DID blockchain infrastructure, attaching VC information to prove access eligibility. Enterprise A reviews the request, including verifying the validity of the VP, checking the scope of permissions, and the feasibility of data sharing. Enterprise A encrypts the target data using a homomorphic encryption algorithm to ensure data privacy during upload and storage. Enterprise A uploads the encrypted data file to the cloud-based sharing platform and obtains the unique hash value of the file storage as an index identifier. The cloud-based sharing platform returns the hash value list of the encrypted data file to Enterprise A for subsequent blockchain storage and access policy binding. Based on Enterprise B's VC information, Enterprise A uses the CP-ABE algorithm to generate an access control policy and encrypt the file hash list and decryption key. The encrypted result is uploaded to the blockchain storage platform along with Enterprise B's DID identifier, notifying Enterprise B that the storage is complete.
[0084] According to another aspect of an embodiment of the present invention, a data reading method is also provided, including: receiving a data reading request sent by a data reading requesting end, wherein the data reading request includes a verifiable expression corresponding to the requesting end; reviewing the data reading request to obtain a third review result; if the third review result is passed, allowing the requesting end to execute any one of the above-mentioned data reading methods to read the target data.
[0085] Optionally, upon receiving a data read request from the requesting party, the blockchain evidence storage platform will immediately initiate a review process to verify whether the requesting party has permission to read the target data. If the third review result indicates that the requesting party's data read request is legitimate, meaning that all verifications have passed and the permissions match, the blockchain evidence storage platform will allow the requesting party to execute the data read method to access the target data. In other words, the blockchain evidence storage platform will provide the necessary information or permissions, allowing the requesting party to obtain the encrypted index list and decryption key, thereby locating and decrypting the target data on the cloud platform.
[0086] According to another aspect of an embodiment of the present invention, a data reading method is also provided, including: sending a decentralized identity identifier corresponding to a requesting end for data reading to the requesting end, wherein the requesting end executes any one of the above-mentioned data reading methods; receiving a credential application request sent by the requesting end and passing it to a target end for data reading, wherein the credential application request includes a decentralized identity identifier; receiving and saving a verifiable credential of the requesting end generated by the target end based on the credential application request; and sending the verifiable credential to the requesting end.
[0087] Optionally, the blockchain node can send the generated decentralized identity identifier to the requesting end, and then the requesting end can use its DID to initiate a VC application to the target end for data reading. The request contains the DID identifier of the requesting end, which is used to indicate its identity and request permission to access specific data. After the target end receives the credential application request containing the DID, it can use the CP-ABE algorithm to generate a VC based on the attributes and access requirements of the requesting end, which contains the permission information for the requesting end to access the data. The target end then sends the generated VC to the DID blockchain node (such as the DID blockchain infrastructure). After receiving and verifying the VC sent by the target end, the DID blockchain node saves it on the blockchain to ensure the immutability and credibility of the VC. Subsequently, the DID blockchain node sends the VC to the requesting end, and the requesting end can use this VC as legal proof of data access.
[0088] As an optional embodiment, the decentralized identity identifier corresponding to the requesting end of data reading is sent to the requesting end, including: receiving a registration request sent by the requesting end, wherein the registration request includes basic information and authentication materials of the requesting end; based on the registration request, generating and saving the decentralized identity identifier of the requesting end, and sending the decentralized identity identifier to the requesting end.
[0089] Optionally, upon receiving the registration request from the requesting party, the blockchain node generates a unique and immutable decentralized identity identifier (DID), associates it with the requesting party's basic information and authentication materials, and stores it on the blockchain. As a decentralized identity, the DID ensures the trustworthiness of the requesting party's identity and is independent of any centralized authority. The generated DID is securely sent back to the requesting party by the blockchain node, who will use it as proof of identity for subsequent VC applications and data access.
[0090] As an optional embodiment, the public key of the requesting end is generated based on the elliptic curve cryptography certificateless key distribution algorithm, where the public key is used to encrypt the index list; based on the registration request, the decentralized identity identifier and the public key, a decentralized identity document is constructed and saved, where the decentralized identity document is used to manage all public keys of the requesting end.
[0091] Optionally, the requesting end initiates a registration request to the blockchain node, which uses the certificateless CP-ABE algorithm based on elliptic curves to generate a pair of public and private keys. The elliptic curve, with its efficient computational performance and small key length, ensures that key generation and management are secure and computationally lightweight even on edge devices. After generating the public key, the blockchain node constructs the requesting end's decentralized identity document (DID document) based on the basic information and authentication materials in the registration request, as well as the newly generated public key. The storage and distribution of this information is completely decentralized and does not rely on a single authentication or key management organization, thereby improving the security of the system and the reliability of its continued operation. The constructed DID document will be stored on the blockchain and become part of the requesting end's digital identity.
[0092] For example, Figure 6 : is a flowchart of a registration phase according to an optional embodiment of the present invention. Figure 6 As shown in the figure, after receiving the registration request, the DID blockchain infrastructure generates a public key and a partial private key pair for Enterprise B using a certificateless key distribution algorithm based on elliptic curve cryptography. This DID document is then constructed, containing Enterprise B's DID identifier, public key, service endpoint (such as the callback interface URL), and other relevant metadata. The DID document is stored on-chain, ensuring its global verifiability and immutability within the blockchain network.
[0093] The present invention proposes a data reading method. First, the DID blockchain infrastructure is used to implement certificateless key distribution, combined with zero-knowledge proof technology to ensure key security and user privacy, and solve the trust bottleneck of centralized key management. Secondly, a fine-grained access control strategy based on DID is designed, integrating the lightweight CP-ABE algorithm to achieve the combination of data encryption and permission management, and meet the flexible permission requirements of multi-role collaboration in the industrial Internet. Finally, a data sharing mechanism integrating homomorphic encryption and CP-ABE is constructed, and the hash value, access policy and key information of encrypted data are recorded through the blockchain evidence storage platform to ensure privacy protection, compliance and full traceability of data sharing. It is suitable for resource-constrained IoT devices, supports dynamic security policy adjustment, and ensures long-term data security.
[0094] It should be noted that for the aforementioned method embodiments, for simplicity of description, they are all expressed as a series of action combinations. However, those skilled in the art should be aware that the present invention is not limited by the order of the actions described, because according to the present invention, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present invention.
[0095] Through the description of the above embodiments, those skilled in the art can clearly understand that the data reading method according to the above embodiment can be implemented by means of software plus the necessary general hardware platform, of course, it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), including a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in each embodiment of the present invention.
[0096] As an optional embodiment, a data access control system is also provided. Figure 7 Schematic diagram of a data access control system according to an optional embodiment of the present invention. Figure 7 As shown, the above system may include:
[0097] The DID blockchain infrastructure is responsible for the certificateless key distribution process, generates and maintains DID documents, ensures the credibility of DID through blockchain evidence storage, and completes identity authentication and privacy information protection through smart contracts.
[0098] The cloud-based sharing platform is responsible for storing industrial data and supports data homomorphic encryption and lightweight CP-ABE encryption access strategies to ensure data security and controllable circulation.
[0099] The blockchain evidence storage platform is responsible for storing the index list of homomorphically encrypted data and the file decryption key.
[0100] Upstream and downstream enterprises use DID-based identity authentication to achieve data credibility verification and privacy protection during cross-enterprise collaboration, ensuring the efficiency and security of data circulation.
[0101] As an optional embodiment, a data reading device for implementing the above data reading method is also provided. Figure 8 is a structural block diagram of a data reading device provided according to an optional embodiment of the present invention, such as Figure 8 As shown, the device includes: a first acquisition module 81, a second acquisition module 82, a first decryption module 83, a reading module 84 and a second decryption module 85. The device is described below.
[0102] The first acquisition module 81 is used to acquire a verifiable credential, wherein the verifiable credential is used to verify the read permission of the requesting end for data reading.
[0103] The second acquisition module 82 is connected to the first acquisition module 81 and is used to obtain the encrypted index list from the blockchain evidence storage platform based on the verifiable certificate.
[0104] The first decryption module 83 is connected to the second acquisition module 82 and is used to decrypt the encrypted index list to obtain the index list.
[0105] The reading module 84 is connected to the first decryption module 83 and is used to read the encrypted target data on the cloud platform based on the index list.
[0106] The second decryption module 85 is connected to the reading module 84 and is used to decrypt the encrypted target data to obtain the target data.
[0107] It should be noted that the first acquisition module 81, the second acquisition module 82, the first decryption module 83, the reading module 84, and the second decryption module 85 described above correspond to steps S201 to S205 in the embodiment. The examples and application scenarios implemented by these modules and the corresponding steps are the same, but are not limited to the contents disclosed in the above embodiment. It should be noted that the above modules, as part of the device, can be run in the computer terminal 10 provided in the embodiment.
[0108] An embodiment of the present invention may provide a computer device. Optionally, in this embodiment, the computer device may be located in at least one of a plurality of network devices in a computer network. The computer device includes a memory and a processor.
[0109] Among them, the memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the data reading method and device in the embodiments of the present invention. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, realizing the above-mentioned data reading method. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include a memory remotely located relative to the processor, and these remote memories may be connected to the computer terminal via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0110] The processor can call the information and application stored in the memory through the transmission device to perform the following steps: obtain a verifiable credential, wherein the verifiable credential is used to verify the read permission of the requesting end for data reading; based on the verifiable credential, obtain an encrypted index list from the blockchain evidence storage platform; decrypt the encrypted index list to obtain an index list; based on the index list, read the encrypted target data on the cloud platform; decrypt the encrypted target data to obtain the target data.
[0111] Optionally, obtaining a verifiable credential includes: obtaining a decentralized identity identifier, wherein the decentralized identity identifier is an identity authentication identifier of the requesting end; sending a credential application request to a target end for data reading through any blockchain node on the blockchain, wherein the credential application request includes the decentralized identity identifier; and receiving a verifiable credential generated by the target end based on the credential application request.
[0112] Optionally, obtaining a decentralized identity identifier includes: sending a registration request to any blockchain node on the blockchain, wherein the registration request includes basic information and authentication information of the requesting end; and receiving the decentralized identity identifier of the requesting end generated by the blockchain node based on the registration request.
[0113] Optionally, the receiving blockchain node generates a public key of the requesting end based on the registration request and a partial private key of the requesting end; based on the public key and the partial private key, the complete private key of the requesting end is obtained, wherein the public key is used to encrypt the index list and the complete private key is used to decrypt the encrypted index list.
[0114] Optionally, the processor may also execute the following program code: based on the verifiable credential, obtaining an encrypted index list from the blockchain evidence storage platform, including: based on the verifiable credential, generating a verifiable expression of the requesting end, wherein the verifiable expression is part of the information in the verifiable credential that proves the identity of the requesting end; based on the verifiable expression, obtaining an encrypted index list from the blockchain evidence storage platform.
[0115] Optionally, the processor may further execute program code of the following steps: decrypting the encrypted index list to obtain the index list, including: decrypting the encrypted index list based on a lightweight ciphertext policy attribute decryption algorithm to obtain the index list.
[0116] Optionally, the processor may also execute the program code of the following steps: decrypting the encrypted target data to obtain the target data, including: decrypting the encrypted target data based on a homomorphic decryption algorithm to obtain the target data.
[0117] An embodiment of the present invention provides a data reading method. The method obtains a verifiable credential, wherein the verifiable credential is used to verify the read permission of a data reading requester; based on the verifiable credential, obtains an encrypted index list from a blockchain evidence storage platform; decrypts the encrypted index list to obtain an index list; based on the index list, reads encrypted target data on a cloud platform; and decrypts the encrypted target data to obtain the target data. This method achieves decentralized identity authentication and data encryption in the data reading process, thereby achieving the technical effect of enhancing the security and privacy protection of data reading, and further resolving the technical issues of data abuse risks and data security risks in current cloud-based data circulation.
[0118] A person skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the hardware related to the terminal device through a program, and the program can be stored in a non-volatile storage medium, which may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0119] The embodiment of the present invention further provides a non-volatile storage medium. Optionally, in this embodiment, the non-volatile storage medium can be used to store the program code executed by the data reading method provided in the embodiment.
[0120] Optionally, in this embodiment, the non-volatile storage medium may be located in any computer terminal in a computer terminal group in a computer network, or in any mobile terminal in a mobile terminal group.
[0121] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: obtaining a verifiable credential, wherein the verifiable credential is used to verify the read permission of the requesting end for data reading; based on the verifiable credential, obtaining an encrypted index list from the blockchain evidence storage platform; decrypting the encrypted index list to obtain an index list; based on the index list, reading encrypted target data on the cloud platform; decrypting the encrypted target data to obtain target data.
[0122] Optionally, obtaining a verifiable credential includes: obtaining a decentralized identity identifier, wherein the decentralized identity identifier is an identity authentication identifier of the requesting end; sending a credential application request to a target end for data reading through any blockchain node on the blockchain, wherein the credential application request includes the decentralized identity identifier; and receiving a verifiable credential generated by the target end based on the credential application request.
[0123] Optionally, obtaining a decentralized identity identifier includes: sending a registration request to any blockchain node on the blockchain, wherein the registration request includes basic information and authentication information of the requesting end; and receiving the decentralized identity identifier of the requesting end generated by the blockchain node based on the registration request.
[0124] Optionally, the receiving blockchain node generates a public key of the requesting end based on the registration request and a partial private key of the requesting end; based on the public key and the partial private key, the complete private key of the requesting end is obtained, wherein the public key is used to encrypt the index list and the complete private key is used to decrypt the encrypted index list.
[0125] Optionally, based on the verifiable credential, an encrypted index list is obtained from the blockchain evidence storage platform, including: based on the verifiable credential, generating a verifiable expression of the requesting end, wherein the verifiable expression is part of the information in the verifiable credential that proves the identity of the requesting end; based on the verifiable expression, obtaining the encrypted index list from the blockchain evidence storage platform.
[0126] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: decrypting the encrypted index list to obtain an index list, including: decrypting the encrypted index list based on a lightweight ciphertext policy attribute decryption algorithm to obtain an index list.
[0127] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: decrypting the encrypted target data to obtain target data, including: decrypting the encrypted target data based on a homomorphic decryption algorithm to obtain target data.
[0128] An embodiment of the present invention also provides a computer program product, including a computer program. Optionally, in this embodiment, when the computer program is executed by a processor, it can achieve: obtaining a verifiable credential, wherein the verifiable credential is used to verify the read permission of the requesting end for data reading; based on the verifiable credential, obtaining an encrypted index list from the blockchain evidence storage platform; decrypting the encrypted index list to obtain an index list; based on the index list, reading encrypted target data on the cloud platform; decrypting the encrypted target data to obtain target data.
[0129] The serial numbers of the above embodiments of the present invention are for description only and do not represent the advantages or disadvantages of the embodiments.
[0130] In the above embodiments of the present invention, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0131] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0132] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0133] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0134] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a non-volatile storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk, and other media that can store program code.
[0135] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.
Claims
1. A data reading method, characterized in that: include: Obtaining a verifiable credential, wherein the verifiable credential is used to verify the read permission of the requesting end for data reading; Based on the verifiable credentials, obtain an encrypted index list from the blockchain evidence storage platform; Decrypting the encrypted index list to obtain an index list; Based on the index list, reading the encrypted target data on the cloud platform; The encrypted target data is decrypted to obtain target data.
2. The method according to claim 1, characterized in that The obtaining of the verifiable credentials includes: Obtaining a decentralized identity identifier, wherein the decentralized identity identifier is the identity authentication identifier of the requesting end; Sending a credential application request to a target end for data reading through any blockchain node on the blockchain, wherein the credential application request includes the decentralized identity identifier; Receive the verifiable credential generated by the target end based on the credential application request.
3. The method according to claim 2, characterized in that The obtaining of a decentralized identity identifier includes: Sending a registration request to any blockchain node on the blockchain, wherein the registration request includes basic information and authentication information of the requesting end; Receive a decentralized identity identifier of the requesting end generated by the blockchain node based on the registration request.
4. The method according to claim 3, characterized in that Also includes: Receiving the public key of the requesting end and the partial private key of the requesting end generated by the blockchain node based on the registration request; Based on the public key and the partial private key, a complete private key of the requesting end is obtained, wherein the public key is used to encrypt the index list, and the complete private key is used to decrypt the encrypted index list.
5. The method according to claim 1, characterized in that The step of obtaining an encrypted index list from a blockchain evidence storage platform based on the verifiable credential includes: Based on the verifiable credential, generating a verifiable expression of the requesting end, wherein the verifiable expression is part of the information in the verifiable credential that proves the identity of the requesting end; Based on the verifiable expression, the encrypted index list is obtained from the blockchain evidence storage platform.
6. The method according to claim 1, characterized in that The decrypting the encrypted index list to obtain the index list includes: The encrypted index list is decrypted based on a lightweight ciphertext policy attribute decryption algorithm to obtain the index list.
7. The method according to claim 1, characterized in that Decrypting the encrypted target data to obtain the target data includes: Based on the homomorphic decryption algorithm, the encrypted target data is decrypted to obtain the target data.
8. A data reading method, characterized in that: include: Receiving a data read request sent by a data read requesting end, wherein the data read request includes a verifiable expression corresponding to the requesting end, and the verifiable expression is used to verify the read permission of the requesting end; Reviewing the data read request to obtain a first review result; If the first audit result is passed, the target data is uploaded to the cloud platform, wherein the target data is used for the requesting end to execute any one of the data reading methods in claims 1 to 7 to perform data reading.
9. The method according to claim 8, characterized in that Before receiving the data reading request sent by the data reading request end, the method further includes: Receiving a credential application request sent by the requesting end through any blockchain node on the blockchain, wherein the credential application request includes a decentralized identity identifier; Based on the credential application request, searching any blockchain node on the blockchain to obtain a search result corresponding to the requesting end; Based on the search result, review the credential application request to obtain a second review result; If the second audit result is passed, a verifiable credential is generated.
10. The method according to claim 8, characterized in that The uploading of target data to the cloud platform includes: Encrypting the target data based on a homomorphic encryption algorithm to obtain encrypted target data; The encrypted target data is uploaded to the cloud platform.
11. The method according to claim 10, characterized in that Also includes: Receiving an index list generated by the cloud platform based on the encrypted target data, wherein the index list includes a hash value corresponding to the encrypted target data; Based on the verifiable expression, encrypting the index list by a lightweight ciphertext policy attribute encryption algorithm to obtain an encrypted index list; Upload the encrypted index list to the blockchain evidence storage platform.
12. A data reading method, characterized in that: include: Receiving a data read request sent by a data read requesting end, wherein the data read request includes a verifiable expression corresponding to the requesting end; Reviewing the data read request to obtain a third review result; If the third audit result is passed, the requesting end is allowed to execute any one of the data reading methods in claims 1 to 7 to read the target data.
13. A data reading method, characterized in that: include: Sending a decentralized identity identifier corresponding to a requesting end for data reading to the requesting end, wherein the requesting end executes the data reading method according to any one of claims 1 to 7; receiving a credential application request sent by the requesting end and transmitting the request to a target end for data reading, wherein the credential application request includes the decentralized identity identifier; Receiving and storing the verifiable credential of the requesting end generated by the target end based on the credential application request; The verifiable credential is sent to the requesting end.
14. The method according to claim 13, characterized in that The step of sending a decentralized identity identifier corresponding to a requesting end for data reading to the requesting end includes: receiving a registration request sent by the requesting end, wherein the registration request includes basic information and authentication materials of the requesting end; Based on the registration request, a decentralized identity identifier of the requesting end is generated and saved, and the decentralized identity identifier is sent to the requesting end.
15. The method according to claim 14, characterized in that Also includes: Generate a public key of the requesting end based on an elliptic curve cryptographic certificateless key distribution algorithm, wherein the public key is used to encrypt the index list; Based on the registration request, the decentralized identity identifier and the public key, a decentralized identity document is constructed and saved, wherein the decentralized identity document is used to manage all public keys of the requesting end.
16. A non-volatile storage medium, characterized in that: The non-volatile storage medium includes a stored program, wherein when the program is executed, the device where the non-volatile storage medium is located is controlled to execute the data reading method according to any one of claims 1 to 7.
17. A computer device, characterized in that: include: memory and processor, The memory stores a computer program; The processor is configured to execute a computer program stored in the memory, and when the computer program is run, the processor is enabled to execute the data reading method according to any one of claims 1 to 7.
18. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the data reading method according to any one of claims 1 to 7 is implemented.
Citation Information
Cited By
Cross-domain authentication method and device and storage medium
CN121486110A