A method and system for improving data security based on blockchain consensus
By setting up a data security front-end module and a middle platform module in the blockchain consensus architecture, the problem of lack of collaborative protection for data security in blockchain consensus is solved, and more efficient data security management and system stability are achieved.
Patent Information
- Application Number
- CN202511105666.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-08
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2045-08-08
AI Technical Summary
In existing blockchain consensus processes, data security relies on traditional security mechanisms, lacks collaborative protection, and has centralized or singular security management strategies. It does not consider the underlying importance of data security in the system and has not conducted in-depth layered research on simulated fault tolerance.
A data security front-end module and a middleware module are set up on the hierarchical consensus architecture. The data security front-end module performs cluster head security management and monitors middleware security, while the data security middleware module supervises the pooling process of the node cluster pool. A multi-pool fault-tolerant simulation security mechanism and a front-end security supervision mode are proposed.
It enhances data and system security in the blockchain consensus process, and improves data security and system stability through dynamic adjustments and regulatory strategies.
Smart Images

Figure CN120614210B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the field of new generation information technology, and particularly relates to a method and system for improving data security based on blockchain consensus. BACKGROUND
[0002] Blockchain technology plays an important role in promoting data transmission, data storage and data security. In a blockchain system, the consistency and security of data are verified by a majority of blocks, thereby realizing basic security protection of distributed data.
[0003] Blockchain is a distributed ledger technology, and its core is to build a decentralized and tamper-proof data recording system. In the traditional data storage mode, data is often stored centrally in a certain central server or institution, which has the risk of being tampered with, lost, etc. Blockchain stores data in a decentralized manner on a large number of nodes, and each node saves a complete copy of the ledger. When new data is generated, a block containing the data and previous data information is generated according to certain rules. The new block is connected to the previous block through an encryption algorithm, forming a chain that extends continuously. This structure makes it difficult to tamper with data once it is written into the blockchain, because it is almost impossible to modify the data on most nodes in the network at the same time, thereby ensuring the authenticity and integrity of the data, and providing a reliable data storage and verification method for financial transactions, supply chain management and many other fields.
[0004] Blockchain consensus is a mechanism for nodes in a blockchain network to reach an agreement. In a decentralized blockchain environment, there is no authority to determine whether the data is correct or not, so a consensus mechanism is needed to ensure that all nodes reach a consensus on the validity of the data on the blockchain. Common consensus mechanisms include Proof of Work (PoW), Proof of Stake (PoS), etc. The Proof of Work mechanism requires nodes to prove their work by solving complex mathematical problems. The first node to solve the problem has the right to add a new block and receive a reward. Although this method can effectively prevent malicious nodes from committing fraud, it consumes a large amount of computing resources and energy. The Proof of Stake mechanism selects block creators based on the number of tokens and time held by the nodes. It is more energy-efficient than Proof of Work, but also has its own limitations. The reasonable selection and design of the consensus mechanism are crucial for the stable operation of the blockchain network, the rapid confirmation of transactions and the security of the network. It enables the blockchain to achieve trust and collaborative work of the entire network without trusting individual nodes.
[0005] As blockchain technology continues to evolve and expand into new applications, the consensus mechanism is also constantly evolving and innovating. For example, some emerging blockchain projects attempt to combine the strengths of multiple consensus mechanisms or introduce new technical means to improve consensus efficiency and security. At the same time, the study of blockchain consensus mechanisms involves multiple disciplines such as game theory and cryptography, and requires comprehensive consideration of network performance, decentralization level, security, and other factors to meet the operational needs of blockchain networks in different application scenarios. In the future, as technology matures and application scenarios are further explored, blockchain consensus mechanisms are expected to provide stronger support for building more efficient, secure, and trustworthy distributed networks, driving the widespread application and innovative development of blockchain technology in more fields.
[0006] Data security refers to ensuring the confidentiality, integrity, and availability of data, preventing unauthorized access, tampering, disclosure, destruction, or loss, and other threats. In today's digital age, data has become one of the core assets of enterprises and organizations, whether it is personal privacy information, business secrets, or important government data, all face risks from network attacks, internal personnel operational errors, hardware failures, and other risks. The core of data security lies in taking a series of technical and management measures to build a solid protection system to resist these risks and protect the integrity and reliability of data. For example, by encrypting data using encryption technology, even if the data is illegally obtained, it is difficult for attackers to interpret the content, thus ensuring data confidentiality; at the same time, data backup and recovery mechanisms are used to ensure that data can be quickly recovered in the event of data loss or damage, ensuring data availability.
[0007] The implementation of data security needs to be considered and planned comprehensively from multiple levels. In terms of technology, in addition to the encryption technology and data backup and recovery mechanism mentioned above, access control technology is also needed. Through strict permission management, the access rights of different users to data are limited to ensure that only authorized users can access the corresponding data. Intrusion detection and defense system can monitor abnormal behavior in the network in real time, discover and prevent potential attacks in time, and protect data from external threats. Data desensitization technology can desensitize sensitive information during data sharing and use, reducing the risk of data leakage. In terms of management, it is essential to establish and improve data security management system, including formulating data classification and grading standards, classifying management according to the importance and sensitivity of data, reasonably allocating resources and taking appropriate security measures, clearly defining data security responsibilities, ensuring the effective implementation of data security measures, and carrying out data security training to improve employees' data security awareness and make them understand the importance of data security and how to avoid data security risks in daily work. Only by combining technology and management can a comprehensive data security protection system be formed to effectively protect data security.
[0008] Data security is a dynamic field that evolves with the advancement of information technology and the increasing complexity of network environments. For example, with the widespread application of emerging technologies such as cloud computing, big data, and artificial intelligence, the way data is stored and processed has changed dramatically, and the boundaries of data security have expanded. In the cloud computing environment, data is stored in the cloud. How to ensure the data security protection capability of cloud service providers and how to protect the isolation and security of user data in a multi-tenant environment have become new challenges. The vastness and complexity of big data make data management and protection more difficult, and the risk of data leakage increases. The development of artificial intelligence technology provides new protection means for data security, but it can also be maliciously used, such as using artificial intelligence to generate false data for attacks. Therefore, data security needs to adapt to new technical environments and threat situations, continuously update and optimize security strategies and technical means to cope with changing data security challenges and ensure the security and reliability of data in various application scenarios.
[0009] In the existing blockchain consensus process, data security often relies on traditional blockchain security mechanisms, lacks secure collaboration protection, and for security management strategies, a relatively centralized or single security policy management module is often used, ignoring the underlying importance of data security in the system, not considering the pre-processing of data security in the data formation stage, and focusing too much on centralized security management and security policies in distributed systems without further hierarchical research on fault tolerance simulation.
[0010] The application provides a method and system for improving data security based on blockchain consensus. SUMMARY
[0011] The application aims to provide a method and system for improving data security based on blockchain consensus, which is superior to the prior art.
[0012] To achieve the above-mentioned purpose, the technical scheme of the application is as follows:
[0013] A system for improving data security based on blockchain consensus, comprising:
[0014] A data security front-end module for setting a secure cluster head of an Internet of Things node cluster and configuring security exemption information of a distributed arrangement middleware; the data security front-end module also instructs a specific node group in a plurality of Internet of Things terminal nodes to form an Internet of Things terminal node cluster, aggregates cluster internal Internet of Things terminal collection information data messages based on a cluster head node configured by the system, and submits them to the distributed arrangement middleware for distributed processing;
[0015] A distributed arrangement middleware for connecting any two Internet of Things terminal node clusters and determining a distributed arrangement algorithm of each Internet of Things terminal node in the system based on non-actual geographic location information;
[0016] A data security middle platform module for performing pool remodeling of a multi-type node cluster pool in a fault-tolerant consensus process and determining parameter security of the pool process; a security verification and fault-tolerant consensus middleware for setting a dynamic fault-tolerance mechanism based on a fault-tolerance threshold of a distributed consensus, including a fault-tolerant node pool, a fault-tolerant backup node pool, and a fault-tolerant main error correction node cluster pool; wherein the fault-tolerant node pool includes a first type of fault-tolerant node; the fault-tolerant backup node pool includes a second type of fault-tolerant node; and the fault-tolerant main error correction node cluster pool includes a main error correction node cluster.
[0017] Preferably, the data security front-end module further comprises a data security clustering arrangement submodule, which is configured to perform vulnerability checking on a system clustering algorithm and dynamically adjust the complexity level of the system clustering algorithm based on the operation resources of the blockchain.
[0018] Preferably, the system further comprises a consensus termination state balancing module, which confirms that at least part of the correct nodes will form a specific consensus, establishes an intra-cluster termination parameter table and an inter-cluster termination parameter table; and the Internet of Things terminal node is configured to connect terminal Internet of Things equipment, collect equipment state information, and form Internet of Things terminal collection information data messages after associating with equipment IDs.
[0019] Preferably, the system executes efficient and low-delay distributed consensus based on a distributed arrangement algorithm determined by a distributed arrangement middleware, a dynamic fault tolerance mechanism, and the intra-cluster termination parameter table and the inter-cluster termination parameter table; the distributed arrangement middleware determines the distributed arrangement algorithm of each Internet of Things terminal node in the system based on the type proportion of the serial cluster Internet of Things terminal nodes and the system logical position information rather than the actual geographic position information of all Internet of Things terminal nodes in the cluster; and the distributed arrangement middleware ID is formed by sequentially connecting two hexadecimal cluster IDs of the serial cluster, with the cluster ID having a smaller value located at the low bit.
[0020] Preferably, the fault tolerance node pool comprises first type fault tolerance nodes, which are manually set as fault-free when a non-consensus error occurs in the consensus phase and are forced to perform information assignment to form a consensus according to the consensus node information; the fault tolerance backup node pool comprises second type fault tolerance nodes, which are manually set as fault-free when a non-consensus error occurs in the consensus phase and are put into the fault tolerance node pool from the fault tolerance backup node pool; the fault tolerance main error correction node cluster pool comprises a main error correction node cluster, which at least comprises one specific node of each node cluster, and is configured to force to cover a preset consensus value to all nodes in the cluster when a non-consensus error occurs in the consensus phase; and the fault tolerance threshold of the distributed consensus is a preset ratio of the fault tolerance nodes to the total number of nodes in the current consensus.
[0021] Preferably, the intra-cluster termination parameter table is configured to regulate intra-cluster termination parameters, i.e., to determine the inter-layer flow direction of consensus flooding sublayers and consensus information transmission parameters in the intra-cluster consensus, and to determine the maximum number of consensus nodes in the cluster; and the inter-cluster termination parameter table is configured to regulate inter-cluster termination parameters, i.e., to determine the inter-cluster information flow direction and consensus information transmission parameters in the inter-cluster consensus, and to determine the maximum number of consensus clusters in the inter-cluster consensus.
[0022] Preferably, the data security middle platform module connects each of the other submodules in the form of a system middle platform.
[0023] Preferably, each Internet of Things terminal node forms an Internet of Things terminal collection information data packet with its own Internet of Things terminal node ID and submits it to the cluster head node;
[0024] The cluster head node constructs an Internet of Things terminal collection information data packet summary table of the cluster based on the converged Internet of Things terminal collection information data packet, and the Internet of Things terminal collection information data packet summary table at least includes an Internet of Things terminal node ID and its corresponding Internet of Things terminal collection information data packet, a cluster ID;
[0025] The cluster ID is a hexadecimal identifier of the cluster to which the Internet of Things terminal node belongs, and the Internet of Things terminal node ID is a hexadecimal identifier of the Internet of Things terminal node.
[0026] Preferably, the data security mid-module calls system out-of-band resources for execution in the pooling remodeling process.
[0027] Preferably, the preset consensus value is a system preset consensus information, or
[0028] The preset consensus value is a system instruction identifier for notifying the system to execute consensus information clearing and restart consensus.
[0029] Preferably, the master error correction node in the master error correction node cluster is elected by each node cluster execution node, and at least a processing capacity suboptimal node is used as a master error correction node, and a processing capacity optimal node is not used as a master error correction node, so as to leave the processing capacity optimal node for cluster information aggregation processing.
[0030] At the same time, the application also provides a method for improving data security based on blockchain consensus applied to the above-mentioned system, which at least includes:
[0031] Step one: using a data security front-end module to set a secure cluster head of an Internet of Things node cluster and configure security exemption information of a distributed arrangement middleware; using the data security front-end module to instruct a specific node in a plurality of Internet of Things terminal nodes to form an Internet of Things terminal node cluster, based on a cluster head node configured by the system to converge Internet of Things terminal collection information data packets in the cluster, and submit them to the distributed arrangement middleware for distributed processing;
[0032] Step two: using the distributed arrangement middleware to connect any two Internet of Things terminal node clusters, and determining a distributed arrangement algorithm of each Internet of Things terminal node in the system based on non-actual geographic location information;
[0033] Step three: the data security middle platform module is used for performing pool remodeling on the multi-type node cluster pool in the fault-tolerant consensus process, determining the parameter security of the pool process; the security check and fault-tolerant consensus middleware are used, a dynamic fault-tolerant mechanism is set based on the fault-tolerant threshold of the distributed consensus, including a fault-tolerant node pool, a fault-tolerant backup node pool and a fault-tolerant main error correction node cluster pool;
[0034] The fault-tolerant node pool includes the first type of fault-tolerant node; the fault-tolerant backup node pool includes the second type of fault-tolerant node; and the fault-tolerant main error correction node cluster pool includes the main error correction node cluster.
[0035] Meanwhile, the application also provides a computer program product, which contains computer instructions, and when the computer instructions are executed by a processor, the corresponding functions of the system for improving data security based on blockchain consensus are performed.
[0036] The application provides a method and system for improving data security based on blockchain consensus, which sets a front and rear associated data security front-end module and a data security middle platform module on the basis of a hierarchical consensus architecture. On the one hand, the data security front-end module regulates the security of part of specific system functions, performs cluster head security management on the Internet of Things consensus node cluster, monitors the security status of multiple distributed arrangement middleware, and adjusts the security management strategy configuration in a timely manner. On the other hand, based on the data security middle platform module, the pool process of the multi-type node cluster pool is simulated and reconstructed, and the pool authority process vulnerability is captured, so as to cooperate with the security check and fault-tolerant consensus middleware, based on the consensus data consistency requirement, a better multi-pool fault-tolerant simulation security mechanism and front-end security supervision mode are proposed than the prior art, and the data and system security in the blockchain consensus process are improved. BRIEF DESCRIPTION OF DRAWINGS
[0037] Figure 1 is a basic example diagram of the system for improving data security based on blockchain consensus shown by the application;
[0038] Figure 2 is a basic example diagram of the data security front-end module in the system for improving data security based on blockchain consensus shown by the application;
[0039] Figure 3 is an example diagram of the distributed arrangement middleware in the system for improving data security based on blockchain consensus claimed by the application;
[0040] Figure 4 is one of the data security middle platform module embodiments in the system for improving data security based on blockchain consensus claimed by the application;
[0041] Figure 5 is one of the embodiments of the method for improving data security based on blockchain consensus claimed by the present application. DETAILED DESCRIPTION
[0042] The following specifically describes several embodiments and advantages of the method and system and method for improving data security based on blockchain consensus claimed by the present application, so as to help to make a more detailed review and decomposition of the present application.
[0043] In order to better understand the technical solutions of the present application, the embodiments of the present application are described in detail below in combination with the drawings.
[0044] It should be clear that the described embodiments are only part of the embodiments of the present application, not all the embodiments. All other embodiments obtained by those skilled in the art on the basis of the embodiments in the present application without creative labor belong to the scope of protection of the present application.
[0045] The terms used in the embodiments of the present application are only for the purpose of describing specific embodiments, and are not intended to limit the present application. The singular forms "a", "said" and "the" used in the embodiments of the present application and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise.
[0046] It should be understood that the term "and / or" used herein is only to describe the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B can mean that A exists alone, A and B exist together, and B exists alone. In addition, the character " / " in this paper generally represents that the front and rear associated objects are a "or" relationship.
[0047] It should be understood that although the terms first, second, etc. may be used in the embodiments of the present application to describe the methods and corresponding devices, these key words should not be limited to these terms. These terms are only used to distinguish the key words from each other. For example, without departing from the scope of the embodiments of the present application, the first type of fault-tolerant node can also be called the second type of fault-tolerant node, and the second type of fault-tolerant node can also be called the first type of fault-tolerant node.
[0048] Depending on the context, the word "if" as used herein can be interpreted as "when" or "upon" or "in response to determining" or "in response to detecting". Similarly, depending on the context, the phrase "if it is determined" or "if (a stated condition or event) is detected" can be interpreted as "when it is determined" or "in response to determining" or "when (a stated condition or event) is detected" or "in response to detecting (a stated condition or event)".
[0049] As the description of the drawings Figure 1 - the drawingsFigure 4 As a basic example of the system for improving data security based on blockchain consensus shown by the present application, as a stackable preferred embodiment, each node or module can be interconnected with other nodes or modules for data and instruction transmission, and of course, as another stackable preferred embodiment, some nodes may not have interconnection with some other nodes or may be allowed to close or open the interconnection with other nodes.
[0050] The method and system for improving data security based on blockchain consensus claimed by the present application, the system comprises:
[0051] A data security front-end module is used to set a secure cluster head of an Internet of Things node cluster and configure security exemption information of a distributed arrangement middleware; the data security front-end module also instructs specific nodes in a plurality of Internet of Things terminal nodes to form an Internet of Things terminal node cluster, gathers information data messages of Internet of Things terminal nodes in the cluster based on a cluster head node configured by the system, and submits the information data messages to the distributed arrangement middleware for distributed processing;
[0052] As a stackable preferred embodiment, the data security front-end module is used to set a secure cluster head of an Internet of Things node cluster and configure security exemption information of a distributed arrangement middleware, specifically, the data security front-end module performs permission configuration on specific nodes in unclustered nodes, selects nodes that meet a system preset security policy or are specified by a security administrator, and elects the nodes as a secure cluster head. As another stackable preferred embodiment, the system preset security policy is an external security configuration introduced in the system initialization stage, or a system preset security policy updated synchronously by the system update. At the same time, the data security front-end module determines that some of the distributed arrangement middlewares belong to fixedly configured distributed arrangement middlewares, that is, their system level positions, configuration information and permission information cannot be changed, and thus configures security exemption information of the distributed arrangement middlewares, which is exempted from any security policy change process set by a non-administrator.
[0053] A distributed arrangement middleware is connected in series with any two Internet of Things terminal node clusters, determines a distributed arrangement algorithm of each Internet of Things terminal node in the system based on non-actual geographic position information;
[0054] A data security middle platform module is used to perform pool remodeling on a plurality of node cluster pools in a fault-tolerant consensus process, and determine parameter security of the pool remodeling process.
[0055] As a stackable preferred embodiment, the data security middleware module is used to perform pool remodeling on the multi-type node cluster pool in the fault-tolerant consensus process, and determine the parameter security of the pool process, specifically: the data security middleware module forms a logical security platform of the system, tracks the pool process of each node cluster pool, when the monitoring finds that the pool process of a specific node cluster pool has an operation lower or higher than the system security permission level, performs a simulated re-run process of the pool process of the specific node cluster pool, confirms whether the corresponding permission code segment is permitted or has security risks by the system security administrator, if yes, determines that the pool process parameter security of the specific node cluster pool is FALSE, and re-executes the pool; if not, determines that the pool process parameter security of the specific node cluster pool is TRUE. As another stackable preferred embodiment, the operation lower or higher than the system security permission level is an operation or code whose code reference relationship or storage area call relationship exceeds the preset security level found in the code detection process.
[0056] The security verification and fault-tolerant consensus middleware sets a dynamic fault-tolerance mechanism based on the fault-tolerance threshold of the distributed consensus, including a fault-tolerant node pool, a fault-tolerant backup node pool, and a fault-tolerant main error correction node cluster pool; wherein the fault-tolerant node pool includes a first type of fault-tolerant node; the fault-tolerant backup node pool includes a second type of fault-tolerant node; and the fault-tolerant main error correction node cluster pool includes a main error correction node cluster.
[0057] As a stackable preferred embodiment, the data security pre-module further includes a data security clustering and placement sub-module, which is used to check the vulnerabilities of the system clustering algorithm, and dynamically adjust the complexity level of the system clustering algorithm based on the operation resources of the block chain.
[0058] As another stackable preferred embodiment, the system further includes a consensus termination state balancing module, which confirms that at least part of the correct nodes will form a specific consensus, establishes an intra-cluster termination parameter table and an inter-cluster termination parameter table; and the Internet of Things terminal node is used to connect terminal Internet of Things devices, collect device state information, and form Internet of Things terminal collection information data messages after associating with device IDs.
[0059] As another stackable preferred embodiment, the system performs efficient and low-delay distributed consensus based on the distributed arrangement algorithm determined by the distributed arrangement middleware, the dynamic fault-tolerance mechanism, and the intra-cluster termination parameter table and the inter-cluster termination parameter table.
[0060] As a preferred embodiment that can be superimposed, the distributed arrangement algorithm determined based on the distributed arrangement middleware, the dynamic fault-tolerant mechanism and the intra-cluster termination parameter table and the inter-cluster termination parameter table execute efficient and low-delay distributed consensus, specifically including: the distributed arrangement algorithm determined based on the distributed arrangement middleware determines the system hierarchical architecture; the dynamic fault-tolerant mechanism determines the node pool to which each node belongs, and through the consensus rule of the nodes in the corresponding node pool, when it belongs to the first type of fault-tolerant node, it is forced to execute information assignment to form consensus; when it belongs to the second type of fault-tolerant node, it is manually set to be fault-free and put into the fault-tolerant node pool from the fault-tolerant backup node pool; the fault-tolerant main error correction node cluster pool includes the main error correction node cluster, and when it belongs to the main error correction node cluster, it is forced to cover the preset consensus value to all nodes in the cluster, and at other times, it executes information update according to the conventional blockchain consensus algorithm. The nodes in the fault-tolerant node pool, the fault-tolerant backup node pool and the fault-tolerant main error correction node cluster pool are preset by the system according to the processing capacity or load capacity of the nodes. The consensus flooding inter-flow direction and consensus information transmission parameters of intra-cluster and inter-cluster are determined according to the intra-cluster termination parameter table and the inter-cluster termination parameter table, and efficient and low-delay distributed consensus is executed accordingly.
[0061] The distributed arrangement middleware determines the distributed arrangement algorithm of each Internet of Things terminal node in the system based on the proportion of the type of the Internet of Things terminal node in the serial cluster and the system logical position information of all Internet of Things terminal nodes in the cluster, rather than the actual geographic position information; the distributed arrangement middleware ID is formed in sequence with two hexadecimal cluster IDs of the serial cluster, and the cluster ID with a smaller value is located at the low bit.
[0062] As a stackable preferred embodiment, the distributed arrangement middleware connects any two Internet of Things terminal node clusters in series, determines the distributed arrangement algorithm of each Internet of Things terminal node in the system based on the proportion of the Internet of Things terminal node type of the series cluster and the system logical position information of all Internet of Things terminal nodes in the cluster rather than the actual geographic position information, specifically: preconfigure the Internet of Things terminal node type based on the high-efficiency low-delay distributed consensus application system of the Internet of Things environment, as another stackable preferred embodiment, the preconfigured Internet of Things terminal node type can include: type weight 1, non-image storage Internet of Things node with central control processing chip; type weight 2, communication non-image storage Internet of Things node without central control; type weight 3, image storage node, used to distinguish Internet of Things information processing and aggregation center node, communication relay or terminal, image video processing node, etc. As another stackable preferred embodiment, the distributed arrangement middleware can determine the system hierarchy of the cluster based on the number of weight products of the type weight 1-3 Internet of Things terminal nodes in the cluster and the weight multiplication, as another stackable preferred embodiment, based on the number of weight products of the type weight 1-3 Internet of Things terminal nodes in the cluster and the weight multiplication, determine the system hierarchy of the cluster, specifically including: for example, a specific cluster includes 3 type weight 1 nodes; 10 type weight 2 nodes; 2 type weight 3 nodes, then the number of weight products of the type weight 1-3 Internet of Things terminal nodes in the cluster is 1*3+2*10+3*2=29, after calculating the weight number sum of all Internet of Things terminal node clusters in the system, set it in order from high to low according to a specific sorting proportion (such as the first 1 / 3, the middle 1 / 3, the last 1 / 3, etc.) to set the distributed system level I / II / III, and set the node in the sub-level of the current distributed level based on the type weight of each node, and determine the system logical position combined with the cluster ID. For example, in a certain node cluster (ID 0xC51) of system level II, a certain Internet of Things terminal node of type weight 3, its system logical position is II-0xC51-3, that is, it is located in the 3rd sub-level of the 0xC51 cluster in the second logical layer of the system, each node determines the system logical position in order, thereby forming a complete distributed system node distribution.
[0063] As another stackable preferred embodiment, the fault-tolerant node pool includes first-type fault-tolerant nodes, which are manually set as fault-free when a non-consensus error occurs in the consensus phase and enforce information assignment to form consensus according to the consensus information of the nodes; the fault-tolerant backup node pool includes second-type fault-tolerant nodes, which are manually set as fault-free when a non-consensus error occurs in the consensus phase and are put into the fault-tolerant node pool from the fault-tolerant backup node pool; the fault-tolerant main error correction node cluster pool includes a main error correction node cluster, which includes at least one specific node of each node cluster, and is used to forcibly cover the preset consensus value to all nodes in the cluster when a non-consensus error occurs in the consensus phase; and the fault-tolerance threshold of the distributed consensus is a preset ratio of the number of fault-tolerant nodes to the total number of nodes in the consensus.
[0064] As another stackable preferred embodiment, the intra-cluster termination parameter table is used to regulate intra-cluster termination parameters, i.e., to determine the inter-layer flow direction of consensus flooding and consensus information transmission parameters in intra-cluster consensus, and to determine the maximum number of consensus nodes in the cluster; and the inter-cluster termination parameter table is used to regulate inter-cluster termination parameters, i.e., to determine the inter-cluster information flow direction and consensus information transmission parameters in inter-cluster consensus, and to determine the maximum number of consensus clusters in the cluster.
[0065] As another stackable preferred embodiment, the data security middleware module is connected to each of the other sub-modules in the form of a system middleware.
[0066] As another stackable preferred embodiment, each Internet of Things terminal node forms an Internet of Things terminal collection information data message with its own Internet of Things terminal node ID and submits it to the cluster head node.
[0067] The cluster head node constructs an Internet of Things terminal collection information data message summary table of the cluster based on the collected Internet of Things terminal collection information data messages, which at least includes the Internet of Things terminal node ID and its corresponding Internet of Things terminal collection information data message, and the cluster ID.
[0068] The cluster ID is a hexadecimal identifier of the cluster to which the Internet of Things terminal node belongs, and the Internet of Things terminal node ID is a hexadecimal identifier of the Internet of Things terminal node.
[0069] As another stackable preferred embodiment, the data security middleware module calls system out-of-band resources for execution during the pooling and remodeling process.
[0070] As another stackable preferred embodiment, the preset consensus value is a system preset consensus information, or,
[0071] The preset consensus value is a system instruction identifier, which is used to inform the system to execute consensus information clearing and restart consensus.
[0072] As another stackable preferred embodiment, the master error correction node in the master error correction node cluster is elected by each node cluster execution node, and at least the processing capacity suboptimal node is taken as the master error correction node, and the processing capacity optimal node is not taken as the master error correction node, so as to leave the processing capacity optimal node for cluster information aggregation processing.
[0073] At the same time, the application also proposes a method for improving data security based on blockchain consensus applied to the system as described above, as shown in the accompanying drawings Figure 5 The method at least includes:
[0074] S102: The security cluster head of the Internet of Things node cluster is set by using the data security front-end module, and the security exemption information of the distributed arrangement middleware is configured; a specific node in the plurality of Internet of Things terminal nodes is instructed by using the data security front-end module to form an Internet of Things terminal node cluster, the cluster head node is configured by the system, the information data message collected by the Internet of Things terminal in the cluster is aggregated, and is submitted to the distributed arrangement middleware for distributed processing;
[0075] S104: Any two Internet of Things terminal node clusters are connected in series by using the distributed arrangement middleware, and the distributed arrangement algorithm of each Internet of Things terminal node in the system is determined based on non-actual geographic location information;
[0076] S106: The data security middle module is used to execute pool remodeling on the plurality of node cluster pools in the fault-tolerant consensus process, to determine the parameter security of the pool process; the security check and fault-tolerant consensus middleware are used, based on the fault-tolerant threshold of the distributed consensus, to set a dynamic fault-tolerant mechanism, including a fault-tolerant node pool, a fault-tolerant backup node pool, and a fault-tolerant master error correction node cluster pool.
[0077] The fault-tolerant node pool includes a first type of fault-tolerant node; the fault-tolerant backup node pool includes a second type of fault-tolerant node; and the fault-tolerant master error correction node cluster pool includes a master error correction node cluster.
[0078] At the same time, the application also proposes a computer program product, which contains computer instructions, and the computer instructions execute the corresponding functions of the system for improving data security based on blockchain consensus as described above when running through a processor.
[0079] The application provides a method and system for improving data security based on blockchain consensus, which sets a front data security pre-module and a data security middle-module in association with each other on the basis of a hierarchical consensus architecture, regulates part of specific system functions for security by the data security pre-module, performs cluster head security management on the Internet of Things consensus node cluster, monitors the security status of multiple distributed middleware, and adjusts the security management strategy configuration in a timely manner; on the other hand, the data security middle-module supervises the pooling process of multiple node cluster pools, simulates and reconstructs the pooling of three different fault-tolerant consensus point cluster pools, and captures the pooling authority process vulnerability, so as to cooperate with the security check and fault-tolerant consensus middleware, based on the consensus data consistency requirement, a better multi-pool fault-tolerant simulation security mechanism and pre-security supervision mode than the prior art are proposed to improve the data and system security in the blockchain consensus process.
[0080] In all the above-mentioned embodiments, in order to realize the requirements of some special data transmission, read / write functions, the above-mentioned method operation process and its corresponding device can increase devices, modules, components, hardware, pin connections or memory, processor differences to expand functions.
[0081] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the above-mentioned method, device and unit can refer to the corresponding process in the foregoing method embodiment, which will not be repeated here.
[0082] In the several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the device embodiments described above are only schematic, for example, the division of the method steps is only a logical or functional division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interface, device or unit, and can be electrical, mechanical or other forms.
[0083] The units described as separate components of the method or device can or can not be logically or physically separated, and can not be physical units, that is, can be located in one place, or can be distributed on multiple network units. According to actual needs, part or all of the units can be selected to achieve the purpose of the embodiment scheme.
[0084] In addition, each method step in various embodiments of the present application and its implementation, functional units can be integrated in a processing unit, or each unit can be physically present alone, or two or more units can be integrated in one unit. The integrated unit described above can be realized in the form of hardware or in the form of hardware plus software functional units.
[0085] The above method and device can be realized in the form of integrated units of software functional units, and can be stored in a computer readable storage medium. The above software functional units stored in a storage medium include a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute part of the steps of the method described in various embodiments of the present application. The aforementioned storage medium includes a variety of storage media that can store program codes, such as a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), an NVRAM, a magnetic disk or an optical disk.
[0086] The above is only the preferred embodiment of the present application, and is not intended to limit the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.
[0087] It should be noted that: the above embodiments are only used to more clearly explain and describe the technical solutions of the present application, and are not intended to limit the present application; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A system for improving data security based on blockchain consensus, characterized in that: The system includes: The data security front-end module is used to set a security cluster head for IoT node clusters and configure security exemption information for the distributed arrangement middleware. The data security front-end module also instructs specific nodes among multiple IoT terminal nodes to form an IoT terminal node cluster. Based on the cluster head node configured by the system, it aggregates the data packets collected by the IoT terminals within the cluster and submits them to the distributed arrangement middleware for distributed processing. The data security front-end module also includes a data security clustering and placement submodule, which is used to perform vulnerability checks on the system's clustering algorithm and dynamically adjust the complexity level of the system's clustering algorithm based on the computing resources of the blockchain. Distributed arrangement middleware connects any two IoT terminal node clusters and determines the distributed arrangement algorithm for each IoT terminal node in the system based on non-real geographical location information; The data security platform module is used to perform pooling reshaping of multiple types of node cluster pools in the fault-tolerant consensus process and determine the parameter security of the pooling process. The security verification and fault-tolerant consensus middleware, based on the fault tolerance threshold of distributed consensus, sets a dynamic fault tolerance mechanism, including a fault-tolerant node pool, a fault-tolerant backup node pool, and a fault-tolerant master error-correcting node cluster pool. The fault-tolerant node pool includes a first type of fault-tolerant node. When a first type of fault-tolerant node encounters a consensus failure error during the consensus phase, it is manually set to fault-free status, and information assignment is forcibly performed based on the already agreed-upon node information to form consensus. The backup node pool includes a second type of fault-tolerant node. When a consensus failure occurs during the consensus phase, the second type of fault-tolerant node is manually set to fault-free and moved from the fault-tolerant backup node pool to the fault-tolerant node pool. The fault-tolerant primary error-correcting node cluster pool includes a primary error-correcting node cluster. The primary error-correcting node cluster includes at least one specific node from each node cluster. The primary error-correcting node cluster is used to force the overwrite of a preset consensus value to all nodes in its cluster when a consensus failure occurs during the consensus phase. The fault tolerance threshold of the distributed consensus is the ratio of the pre-set fault-tolerant nodes to the total number of nodes in this consensus.
2. The system for improving data security based on blockchain consensus as described in claim 1, characterized in that: The system also includes a consensus termination state balancing module, which confirms that at least some correct nodes will form a specific consensus and establishes intra-cluster termination parameter tables and inter-cluster termination parameter tables; the IoT terminal node is used to connect to terminal IoT devices, collect device status information, and form IoT terminal collected information data packets after associating with device IDs.
3. The system for improving data security based on blockchain consensus as described in claim 2, characterized in that: The intra-cluster termination parameter table is used to regulate intra-cluster termination parameters, that is, to determine the flow direction and consensus information transmission parameters between consensus flooding sublayers within the cluster, and to determine the maximum number of consensus nodes within the cluster; the inter-cluster termination parameter table is used to regulate inter-cluster termination parameters, that is, to determine the flow direction and consensus information transmission parameters between clusters, and to determine the maximum number of consensus clusters between clusters.
4. The system for improving data security based on blockchain consensus as described in claim 1, characterized in that: The data security platform module connects to other sub-modules in the form of a system platform.
5. The system for improving data security based on blockchain consensus as described in claim 1, characterized in that: During the pooling and refactoring process, the data security platform module calls out-of-band system resources for execution.
6. The system for improving data security based on blockchain consensus as described in claim 1, characterized in that: The primary error correction node in the primary error correction node cluster is elected by each node cluster, and at least the node with the second-best processing capability is selected as the primary error correction node, while the node with the best processing capability is not selected as the primary error correction node, so that the node with the best processing capability can be used for cluster information aggregation processing.
7. A method for improving data security based on blockchain consensus applied to the system described in any one of claims 1-5, characterized in that: The method includes at least: Step 1: Use the data security front-end module to set up a secure cluster head for the IoT node cluster and configure security exemption information for the distributed arrangement middleware; use the data security front-end module to instruct specific nodes among multiple IoT terminal nodes to form an IoT terminal node cluster, and based on the cluster head node configured by the system, aggregate the data packets collected by the IoT terminals within the cluster and submit them to the distributed arrangement middleware for distributed processing. The data security front-end module also includes a data security clustering and placement submodule, which is used to perform vulnerability checks on the system clustering algorithm and dynamically adjust the complexity level of the system clustering algorithm based on the computing resources of the blockchain. Step 2: Use distributed arrangement middleware to connect any two IoT terminal node clusters, and determine the distributed arrangement algorithm for each IoT terminal node in the system based on non-actual geographical location information; Step 3: Use the data security middleware module to perform pooling reshaping on the various node cluster pools in the fault-tolerant consensus process to determine the parameter security of the pooling process; use the security verification and fault-tolerant consensus middleware to set up a dynamic fault tolerance mechanism based on the fault tolerance threshold of distributed consensus, including fault-tolerant node pool, fault-tolerant backup node pool, and fault-tolerant master error correction node cluster pool. The fault-tolerant node pool includes a first type of fault-tolerant node. When a consensus failure occurs during the consensus phase, the first type of fault-tolerant node is manually set to fault-free and, based on the already agreed-upon node information, forces the assignment of information to form a consensus. The fault-tolerant backup node pool includes a second type of fault-tolerant node. When a consensus failure occurs during the consensus phase, the second type of fault-tolerant node is manually set to fault-free and moved from the fault-tolerant backup node pool to the fault-tolerant node pool. The fault-tolerant primary error-correcting node cluster pool includes a primary error-correcting node cluster. The primary error-correcting node cluster includes at least one specific node from each node cluster. The primary error-correcting node cluster is used to force the overlay of a preset consensus value onto all nodes in its cluster when a consensus failure occurs during the consensus phase. The fault tolerance threshold of the distributed consensus is the ratio of the pre-set fault-tolerant nodes to the total number of nodes in this consensus.
8. A computer program product, the computer program product comprising computer instructions, characterized in that: The computer instructions execute the corresponding system functions for improving data security based on blockchain consensus as described in any one of claims 1-6 when the processor runs.
Citation Information
Patent Citations
Block chain adaptive consensus method based on dynamic authorization and network environment perception
CN108616596A
Industrial Internet of Things fault-tolerant time synchronization method and system based on block chain
CN111865469A