Sensitive data privacy protection method and system based on alliance chain

By combining IPFS and MySQL database on the alliance chain, medical data is classified, encrypted, stored, and access controlled, which solves the problems of privacy leakage and storage capacity limitation in medical data storage and realizes the secure storage and sharing of data.

CN120671175APending Publication Date: 2025-09-19SOUTHEAST UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510665637.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-22
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

In existing technologies, there is a risk of privacy leakage when storing medical data in a database, and the data storage capacity of the alliance chain is limited, making it difficult to effectively store and share massive medical data.

Method used

A sensitive data privacy protection method based on alliance chain is adopted. By formulating an authorized access user information table, using symmetric and asymmetric encryption algorithms to classify and encrypt data, combining IPFS and MySQL database for storage, and setting access control policies, secure storage at the file level and data level is achieved.

Benefits of technology

It realizes the secure storage and sharing of massive medical data, reduces the pressure of data storage, ensures the data's immutability and privacy protection, and improves the reliability and security of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120671175A_ABST
    Figure CN120671175A_ABST
Patent Text Reader

Abstract

The invention discloses a sensitive data privacy protection method and system based on an alliance chain, and the method comprises the steps: authorizing to access a user information table, classifying information, constructing a privacy protection model based on file-level authorized access, constructing a privacy protection model based on data-level authorized access, and setting an access control strategy. And a privacy protection mechanism is perfected. The problem of safe storage of sensitive information can be solved, safe storage of information at a file level and a data level is realized, pressure caused by data storage and high-frequency access of an alliance chain is well reduced by combining an on-chain and off-chain storage mode, the characteristics of safe storage, non-tampering and safe sharing of data are further realized, and the security of the data is improved. And the privacy of the user is effectively ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of secure storage and secure sharing of sensitive data, and mainly relates to a sensitive data privacy protection method and system based on alliance chain. Background Art

[0002] With the rapid development of medical information technology, healthcare has become an integral part of people's lives. The demand for information exchange and sharing between medical institutions is increasing, and medical information is considered a key data resource, playing a vital role in improving medical research and services. However, the sharing of medical data is becoming increasingly difficult due to practical factors such as incompatible data systems between hospitals or institutions, uncertainty in data sources and volumes, and the risk of privacy breaches during data sharing.

[0003] Medical data plays a crucial role in patient diagnosis and subsequent treatment. In the era of big data, to address the vulnerability of traditional paper medical records to loss or damage, medical data, such as prescription records and medical histories, is being stored electronically. A growing number of hospitals are using electronic data to record the entire treatment process, storing patient medical records in databases. This allows service systems to extract the required data from the database for doctors. However, storing medical data directly in databases can pose various privacy risks, such as theft, tampering, or deletion, and thus fail to provide a comprehensive picture of the patient's condition. If data is submitted to a third-party notarization company for storage, the credibility of the third party cannot be verified, potentially leading to the leakage of personal information and compromising the data's reliability and usability. Therefore, promoting the secure sharing of sensitive medical data while ensuring data security and privacy is a critical issue that needs to be addressed.

[0004] As a decentralized, tamper-proof distributed ledger, the consortium chain offers a new approach to addressing the challenges of secure sharing and privacy protection in traditional medical data. A consortium chain is a distributed database technology that records and verifies information in a decentralized and distributed manner. It consists of multiple nodes, each of which maintains a copy of all data, encrypted and authenticated using cryptographic techniques. The core of a consortium chain is the "block," which contains data and a timestamp. These blocks are linked together in a chain-like structure to form an immutable data structure. Its most prominent feature is tamper-resistance. While data in a consortium chain can be publicly viewed, once written to a block, it cannot be tampered with, ensuring the integrity of the data on the chain. Furthermore, data can be backed up, resulting in a high level of security. Another key feature is decentralization, eliminating the need for a trusted third party. Compared to traditional centralized databases, consortium chain technology offers greater reliability and effectively mitigates risks such as data breaches. Due to its tamper-resistance, decentralization, and data sharing, consortium chains ensure secure data transmission and access, avoiding the risks of single points of failure and information leaks. Therefore, adopting consortium chain as the infrastructure provides a better solution for storing and sharing sensitive data.

[0005] While consortium chains are suitable for addressing the aforementioned issues, their limited data storage capacity makes them suitable only for storing digital summaries of electronic data. Centrally storing electronic data files for evidence is prone to tampering and loss, making storing massive amounts of medical data within the limited transaction space of consortium chains challenging. Therefore, building a decentralized, tamper-resistant, and highly available data security storage model based on consortium chains holds profound practical significance. Summary of the Invention

[0006] The present invention addresses the deficiencies in the existing technology and provides a sensitive data privacy protection method and system based on a consortium chain. First, an authorized access user information table is formulated, a unique identifier is generated for the data authorized user, and a user attribute identification bit is set; the information to be securely stored is classified into file level and data level; a privacy protection model based on file-level authorized access is constructed to enable designated fixed users to access encrypted stored sensitive data files and dynamically added users to access encrypted stored sensitive data files; a privacy protection model based on data-level authorized access is then constructed, and finally an access control policy is set to restrict data access to users in the authorized information table, thereby improving the privacy protection mechanism of the invention. The present invention not only solves the problem of secure storage of sensitive information, but also realizes secure storage of information at the file level and data level. By combining the on-chain and off-chain storage modes, it greatly reduces the pressure brought by data storage and high-frequency access of the consortium chain, further realizing the secure storage, non-tamperability and secure sharing characteristics of data, and effectively guarantees the privacy of users.

[0007] To achieve the above objectives, the present invention adopts a technical solution: a sensitive data privacy protection method based on a consortium chain, comprising the following steps:

[0008] S1. Authorized access user information table: Create an authorized access user information table before data storage, generate a unique identifier for the data authorized user, and set the user attribute identification bit;

[0009] S2. Information classification: classifying the information to be stored, wherein the classification includes at least file level and data level;

[0010] S3. Build a privacy protection model based on file-level authorized access: This file-level authorized access privacy protection model uses consortium chain technology to encrypt sensitive data files using a symmetric encryption algorithm. Combined with the IPFS decentralized storage system, the encrypted files are stored in IPFS and the CID value is returned. The CID value and encryption key are encrypted using an asymmetric encryption algorithm. This model enables designated fixed users to access encrypted and stored sensitive data files and dynamically add users to access encrypted and stored sensitive data files.

[0011] S4. Build a privacy protection model based on data-level authorized access: The storage model uses a symmetric encryption algorithm to encrypt and store data in a MySQL database. The encryption algorithm is specifically layered encryption, using the AES algorithm to encrypt the data, and then using the RSA algorithm to encrypt the key obtained from the data encryption.

[0012] S5. Set access control: Set access control policy. The access control includes two parts: on-chain query and access design, which restricts data access to only users in the authorization information table.

[0013] As an improvement of the present invention, in step S1, in the authorized access user information table, a public-private key pair (pk, sk) is generated for each user using the RSA algorithm, where pk is public and used for encryption; sk is used for decryption;

[0014] The user attribute identification bit is specifically: 0 for the data owner and 1 for the data user.

[0015] As an improvement of the present invention, the working process of the privacy protection model based on file-level authorized access in step S2 includes at least the following steps:

[0016] S31. Dataset construction: The dataset includes but is not limited to images and xlsx files, with privacy information attached;

[0017] S32. File encryption: Get random encryption key K M And the initial vector IV, use the symmetric encryption algorithm AES to encrypt the image and table file M to be uploaded to obtain E KM (M);

[0018] S33, IPFS storage encrypted files: Connect Fabric with IPFS by calling go-ipfs-api, store the encrypted sensitive data files to be stored in the IPFS system, and return the storage address H M value;

[0019] S34, Encrypted storage design and on-chain storage information: Hyperledger Fabric stores the information of all designated access users on the chain, with Sender1 as the key value, the file name Filename, the ciphertext encrypted by each user's public key (Secid1, Secid2, Secid3), the timestamp of the generated block, and the generated block ID as the value;

[0020] S35. Data is stored in the database: The Fabric chain code is called through go-fabric-sdk to store the information in the ledger of each peer node and stored in the default Level DB database in the form of key-value;

[0021] S36. Dynamically add users to access sensitive data files: In this step, the information of each accessing user is stored on the chain, with the user ID as the key value, the file name, the ciphertext after the public key encrypts the CID, the timestamp of the generated block, and the generated block ID as the value value. The Fabric chain code is called through go-fabric-sdk to store the information in the LevelDB database of the Peer node ledger. Specifically:

[0022] Secidb=E pkB (IDA||IDB||H m ||E pk A (IDB||K M ||IV||time))

[0023] Secidb is the ciphertext stored by user B, E pkA (·) is the encryption process using A’s public key, H m The CID returned for the file stored in IPFS, K M is the encryption key, IV is the initial vector, and time is the timestamp of the stored file.

[0024] As another improvement of the present invention, the step S34 of encrypting the storage design and storing information on the chain specifically includes the following steps:

[0025] S341: Use the public key of data owner A to encrypt. The encrypted content is the ID of data user B, file encryption key, initial vector and the time when the file was stored. Specifically:

[0026] Secida=E pkA (IDB||K M ||IV||time)

[0027] Among them, Secida is the ciphertext encrypted by A, E pkA (·) is the encryption process using A’s public key, IDB is the ID of data user B, K M is the encryption key, IV is the initial vector, and time is the timestamp of the stored file;

[0028] S342: Use the public key of data user B to encrypt. The encrypted content is A's ID, B's ID, the CID returned by the file stored in IPFS, and the content encrypted by data owner A, that is,

[0029] Secid1=E pkB (IDA||IDB||H M ||Secida)

[0030] Among them, Secid1 is the ciphertext, EpkB (·) is the encryption process using B’s public key, IDA is A’s ID, H M It is the CID returned by the file stored in IPFS, and Secida is the ciphertext encrypted by A.

[0031] As another improvement of the present invention, the working process of the privacy protection model based on data-level authorized access in step S4 includes at least the following steps:

[0032] S41. Determine user information: Register on the registration server and formulate an authorized access user information table, and generate public keys PK for each user in the authorized user table. i and private key SK i , determine user attributes;

[0033] S42, randomly generate a key and an initial vector: Generate a random number through a random number generator as the initial key K m and initial vector IV;

[0034] S43. Encrypt sensitive data: Use the AES-128-CBC symmetric encryption algorithm to symmetrically encrypt the data ni in the message, obtain the ciphertext K_ni, and combine it with the Hyperledger Fabric transaction process;

[0035] S44, secure storage of ciphertext and key: upload the ciphertext K_mi obtained in step S43 to the table user created in the MySQL database to construct a keyword index for the data set;

[0036] S45. Secure storage of data: The ID of the authorized access user B is used as the key value, the table name user and the ciphertext Ms are used as the value value, and stored in the alliance chain distributed database in key-value format; the data storage node manages all shared data, integrates the index structure of all data, and updates the ledger.

[0037] As another improvement of the present invention, the user attributes in step S41 are specifically: 0 for the data owner and 1 for the data user.

[0038] As another improvement of the present invention, the table name, the authorized access user name B, the key and the vector are set to the string s, and the public key PK of the authorized user is used. i Encrypt the string s for storage, that is

[0039] Ms=E PKB (user||IDB||K m ||IV)

[0040] Among them, Ms is the ciphertext, user is the table name, IDB is the authorized access user name, Km is the key and IV is a vector.

[0041] As a further improvement of the present invention, in step S5, the on-chain query of the privacy protection model based on file-level authorized access is specifically as follows: first, access control is performed, and the on-chain information is queried according to the key value to determine whether the user ID exists in the key value, thereby returning the value stored in the LevelDB database; after the information is queried, it is decrypted using its own private key to obtain the file address CID value stored in IPFS;

[0042] The specific on-chain query for the privacy protection model based on data-level authorized access is as follows: On the Hyperledger Fabric chain, based on the authenticated identity, the ciphertext Ms stored in the Hyperledger Fabric database is queried, and the ciphertext Ms is obtained by using its own private key PK. i Decrypt the ciphertext Ms to get the string s, and then get the data stored in the specified table user in the MySQL database, the IDB of the authorized access user B, and the key K m and initial vector IV.

[0043] Compared with the prior art, the present invention has the following beneficial effects:

[0044] (1) The present invention further improves the secure storage mechanism for massive data by combining on-chain and off-chain methods for data storage. The present invention also combines access control and symmetric encryption algorithms to encrypt data, further protecting data security. By integrating with the Hyperledger Fabric transaction process, data encryption keys and ciphertext are stored separately, adding multiple layers of security to data storage, ensuring that authorized users can more securely access information and verify the integrity and authenticity of stored data.

[0045] (2) The sensitive data privacy protection method based on alliance chain technology proposed in the present invention can realize the secure storage and sharing of data in an efficient and lightweight manner. For the data file block authorization access scheme model based on the alliance chain, the data owner uses a symmetric encryption algorithm to encrypt the medical information, and then uploads the encrypted file to IPFS. The combination of IPFS and alliance chain enables data owners to process large amounts of electronic data through IPFS, reducing the storage pressure caused by placing the data itself on the chain and saving network bandwidth in the alliance chain. This model ensures the reliability of medical information through the transparency and tamper-proofness of the alliance chain ledger, combines IPFS to encrypt and store the original medical information, and sets up an access mechanism to achieve data privacy protection, thereby improving the security of the model.

[0046] (3) The file data authorization access solution model based on the alliance chain in the present invention is combined with the MySQL database to encrypt data at the data level, allowing data users to perform keyword indexing on the data. Furthermore, fine-grained and flexible access control is achieved through the access control mechanism of smart contracts and attribute encryption, preventing unauthorized users from accessing data and effectively protecting data privacy and user rights. Security analysis shows that the model achieves secure data storage, secure sharing, and privacy protection. The reliability of input data is guaranteed based on the openness, transparency, and tamper-proof characteristics of the data in the alliance chain. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Figure 1 This is a flowchart of the steps of the sensitive data privacy protection method based on the alliance chain of the present invention;

[0048] Figure 2 It is a structural diagram of a privacy protection model based on file-level authorized access in the method of the present invention;

[0049] Figure 3 This is a schematic diagram of encrypted table information according to Example 1 of the present invention;

[0050] Figure 4 This is a schematic diagram of the information returned after a file is stored in IPFS in Example 1 of the present invention;

[0051] Figure 5 It is a flow chart of the steps of designing encrypted storage in the method of the present invention for fixed user authorized access to file blocks;

[0052] Figure 6 This is a schematic diagram of the information specifically stored on the chain returned in Example 1 of the present invention;

[0053] Figure 7 It is a flow chart of the steps of access design in the method of the present invention for fixed user authorized access to a file block;

[0054] Figure 8 This is an architectural diagram of dynamic user authorization access to file blocks in Example 1 of the present invention;

[0055] Figure 9 It is a structural diagram of a privacy protection model based on data-level authorized access in the method of the present invention;

[0056] Figure 10 This is a flow chart of an encrypted storage design in data-level authorized access in Example 1 of the present invention;

[0057] Figure 11 This is a flow chart of data access design in data-level authorized access in Example 1 of the present invention;

[0058] Figure 12Schematic diagram of the interface for viewing on-chain storage information in the Hyperledger Explorer consortium chain browser in Example 1 of the present invention. DETAILED DESCRIPTION

[0059] The present invention will be further described below with reference to the accompanying drawings and specific embodiments. It should be understood that the following specific embodiments are only used to illustrate the present invention and are not used to limit the scope of the present invention.

[0060] Example 1

[0061] A sensitive data privacy protection method based on alliance chain, this embodiment is applied to the medical field, and the relevant data is medical sensitive data, such as Figure 1 As shown, the following steps are included:

[0062] Step S1: Before storing data, a table of authorized access user information is prepared, a unique identifier is generated for the data authorized user, and the user attribute identification bit is set.

[0063] The registration server specifies the identities of users who can access the data file. A unique identifier is generated for each user using a UUID. Only designated users can query the data file, etc. A public-private key pair (pk, sk) is generated for each user using the RSA algorithm. pk is public and used for encryption, while sk is used for decryption. Additionally, the user attribute flag is set to 0 for the data owner and 1 for the data user.

[0064] Step S2: The information to be securely stored is divided into file level and data level according to different requirements, so that corresponding models can be built subsequently.

[0065] Step S3: Build a privacy protection model based on file-level authorized access, propose two solutions: specifying fixed user access and dynamically adding users, and analyze and design them in detail. Encrypt the data for storage and achieve secure storage through the combination of on-chain and off-chain.

[0066] Figure 2 The paper presents a schematic diagram of the privacy protection model based on file-level authorized access. Symmetric encryption algorithms are used to encrypt medical data files. Combined with the IPFS decentralized storage system, the encrypted files are stored in IPFS and the CID value is returned. An asymmetric encryption algorithm is then used to encrypt the CID value and encryption key. Two schemes are designed: one for designated fixed users to access encrypted and stored sensitive data files, and one for dynamically adding users to access encrypted and stored sensitive data files. The specific steps include:

[0067] Step S31: Construct a dataset, primarily consisting of medical images and .XLSX files. Testing was performed using medical images from an open-source dataset. During the design phase, personal information from the medical information, such as name, gender, phone number, ID number, and email address, was constructed. Other medical indicators from the open-source dataset were then combined with this generated personal information to further enhance the accuracy of the solution.

[0068] Step S32: Obtain random encryption key K M And the initial vector IV, use the symmetric encryption algorithm AES to encrypt the image and table file M to be uploaded to obtain E KM (M). Figure 3 The following is a schematic diagram showing the effect of file encryption in this embodiment.

[0069] Step S33: Connect Fabric to IPFS by calling go-ipfs-api. Then store the encrypted sensitive data file to be stored in the IPFS system and return the storage address H M value. Figure 4 This shows the value returned after IPFS stores the encrypted file in this step.

[0070] Step S34: Encrypted storage design and on-chain storage information. Hyperledger Fabric stores all designated access user information on-chain: Sender1 is the key value, the file name Filename, the ciphertext encrypted by each user's public key (Secid1, Secid2, Secid3), the timestamp of the generated block, and the generated block ID as the value.

[0071] Figure 5 The process of designing encrypted storage in the fixed user authorization access of file blocks is demonstrated, and the information stored on the chain is explained in detail. Taking Secid1 as an example, the encrypted content of each Secid is introduced. First, the public key of the data owner A is used for encryption. The encrypted content is the ID of the data user B, the file encryption key, the initial vector and the time when the file was stored, that is,

[0072] Secida=E pkA (IDB||K M ||IV||time)

[0073] Among them, Secida is the ciphertext encrypted by A, Epk A (·) is the encryption process using A’s public key, IDB is the ID of data user B, K M is the encryption key, IV is the initial vector, and time is the timestamp of the stored file.

[0074] Then use the public key of data user B to encrypt, the encrypted content is A's ID, B's ID, the CID returned by the file stored in IPFS, and the content encrypted by data owner A, that is

[0075] Secid1=E pkB (IDA||IDB||H M ||Secida)

[0076] Among them, Secid1 is the ciphertext, E pkB (·) is the encryption process using B’s public key, H M It is the CID returned by the file stored in IPFS, and Secida is the ciphertext encrypted by A.

[0077] Figure 6 The figure shows a schematic diagram of information stored on the chain after encrypted storage in the authorized access of file blocks in this embodiment.

[0078] Step S35: Call the Fabric chain code through go-fabric-sdk to store the information on each Peer node ledger, that is, store it in the default Level DB database in the form of key-value.

[0079] Figure 7 The access design process in the fixed user authorization access of the file block is demonstrated, and the query process on the chain is described in detail. Taking user B as an example, the specific decryption steps after obtaining the information are introduced. User B uses his own private key to decrypt Secid1, and can obtain the hash value returned by the file stored in IPFS and the ciphertext Cid encrypted by the data owner A; then use A's private key to decrypt Cid to obtain IDB and encryption key K M , compare IDB with user B’s ID to prove the correctness of this transaction.

[0080] In order to solve some problems in the solution of designated user access, such as avoiding the inability to add new user information, which may cause inconvenience in business operations, and preventing the mistake of adding designated users at the beginning, which causes waste of memory and space. Figure 8 Demonstrates a solution for dynamically adding users to access sensitive data files.

[0081] Step S36: Dynamically add users to access sensitive data files.

[0082] Compared with fixed user access, the information stored on the chain is different, but the rest is the same. The information of each accessing user is stored on the chain separately, with the user ID as the key value, the file name, the ciphertext after the public key is encrypted with the ClD, the timestamp of the generated block, and the generated block ID as the value. Then, the Fabric chain code is called through the go-fabric-sdk to store the information in the LevelIDB database of the Peer node ledger, which can be expressed as:

[0083] Secidb=E pkB (IDA||IDB||H m ||E pkA (IDB||K M ||IV||time))

[0084] Secidb is the ciphertext stored by user B, Epk B (·) is the encryption process using B’s public key, E pkA (·) is the encryption process using A’s public key, H m The CID returned for the file stored in IPFS, K M is the encryption key, IV is the initial vector, and time is the timestamp of the stored file.

[0085] Step S4: To address the problem of low data-level processing performance in the file block authorization access scheme, a privacy protection model based on data-level authorization access is proposed.

[0086] By using a symmetric encryption algorithm to encrypt and store the data within the file and then storing it in a MySQL database, the data in the file can be better processed, enhancing data processing capabilities while improving the performance and security of the model. A layered encryption scheme is employed, using the AES algorithm to encrypt medical data and the RSA algorithm to encrypt the key derived from the data, thereby protecting the privacy of sensitive medical data. Figure 9 The following diagram shows the structure of the privacy protection model based on data-level authorized access. It specifically includes the following steps:

[0087] Step S41: Determine user information. First register on the registration server and create an authorized access user information table, use UUID to generate user ID for the data authorized user, and generate public keys PK for each user in the authorized user table. i and private key SK i , determine the user attributes (data owner is 0, data user is 1) and store them in the authorized user table.

[0088] Step S42: Randomly generate a key and an initial vector. Generate random numbers through a random number generator as the initial key Km and initial vector IV.

[0089] Step S43: Encrypting Sensitive Medical Data. To protect the privacy of sensitive medical data sources, this solution uses the AES-128-CBC symmetric encryption algorithm to symmetrically encrypt the data ni in the medical information, obtaining the ciphertext K_ni, and integrating it with the Hyperledger Fabric transaction process.

[0090] Step S44: Secure storage of ciphertext and key. The ciphertext K_mi obtained in step S43 is uploaded to the table user created in the MySQL database to construct a keyword index for the data set.

[0091] Figure 10 This shows the process of data storage design in data-level authorized access. All authorized access users perform this step. Here, user B is used as an example. Set the table name, authorized access user name B, key, and vector to string s, and encrypt string s using the authorized user's public key, that is,

[0092] Ms=E PKB (user||IDB|K m ||IV)

[0093] Among them, Ms is the ciphertext, user is the table name, IDB is the authorized access user name, K m is the key and IV is a vector.

[0094] Step S45: The ID of the authorized user B is used as the key value, the table name user and the ciphertext Ms are used as the value, and the data is stored in the alliance chain distributed database in a key-value format. The data storage node manages all shared data, integrates the index structure of all data, and updates the ledger.

[0095] Step S5: Set the access control policy so that only users in the authorization information table can access the medical data, thus improving the privacy protection mechanism of the invention.

[0096] For a privacy-preserving model based on file-level authorized access, information is queried on-chain. When querying sensitive medical data, access control is first performed. The query is performed on-chain based on the key value. The query determines whether the user's ID matches the key value, and then returns the value stored in the LevelDB database. After the information is retrieved, it is decrypted using the user's private key to obtain the file address CID value stored in IPFS.

[0097] Download and distribute the file. The decrypted CID value is used to retrieve the file from the InterPlanetary File System (IPFS). The file is then decrypted using the key obtained from the data owner A's private key and distributed to data accessors. Non-designated users are unable to query the file, further enhancing the security of this model for accessing sensitive data files.

[0098] For the privacy protection model based on data-level authorized access, query information on the chain. On the Hyperledger Fabric chain, according to the authenticated identity, query the ciphertext Ms stored in the Hyperledger Fabric database, and use its own private key PK i Decrypt the ciphertext Ms to get the string s, and then get the data stored in the specified table user in the MySQL database, the IDB of the authorized access user B, and the key K m and initial vector IV.

[0099] In the MySQL database, the data user initiates a request to access and enters a search term, that is, uses the patient's name to query the corresponding medical information; after retrieving the ciphertext information K_ni that meets the search conditions, the key K is obtained. m Decrypt the ciphertext to get the plaintext information.

[0100] User permissions are also set up in a hierarchical manner. Data owners can not only query data, but also modify the content in the MySQL data table, such as inserting new data, modifying data, and deleting data; while data users can only query data but cannot change it.

[0101] Figure 11 The data access design process in data-level authorization access is shown. On the Hyperledger Fabric chain, based on the authenticated identity, the ciphertext Ms stored in the Hyperledger Fabric database is queried, and the private key PK is used to authenticate the ciphertext Ms. i Decrypt the ciphertext Ms to get the string s, and then get the data stored in the specified table user in the MySQL database, the IDB of the authorized access user B, and the key K m And the initial vector IV. In the MySQL database, the data user initiates a request to access and enters the search term, that is, uses the patient's name to query the corresponding medical information; after retrieving the ciphertext information K_ni that meets the search conditions, the key K is obtained. m Decrypt the ciphertext to get the plaintext information.

[0102] Figure 12This section shows the interface for viewing on-chain information in the Hyperledger Explorer consortium chain browser. By tracking transaction information through the Hyperledger Explorer browser, you can more intuitively view the specific information stored on the chain and transaction details.

[0103] In summary, the present invention proposes a sensitive data security sharing and privacy protection model based on alliance chain technology from the two aspects of secure storage and secure sharing of data, and proposes a file block authorization access scheme and a file data authorization access scheme respectively. Combined with the Interstellar File System IPFS and the MySQL database, it realizes on-chain and off-chain combined storage, ensuring the secure storage of data. By combining encryption technology and smart contracts, the pressure on alliance chain data storage is effectively alleviated. The present invention uses AES to encrypt file data and RSA to encrypt keys at the same time, reducing the risk of privacy leakage during data sharing, and uses the alliance chain to store verification information to ensure the reliability of shared data, realizing the secure storage, non-tamperability and secure sharing characteristics of data, and effectively protecting the privacy of users.

[0104] It should be noted that the above content merely illustrates the technical idea of ​​the present invention and cannot be used to limit the scope of protection of the present invention. For ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications all fall within the scope of protection of the claims of the present invention.

Claims

1. A sensitive data privacy protection method based on alliance chain, characterized by , including the following steps: S1. Authorized access user information table: Create an authorized access user information table before data storage, generate a unique identifier for the data authorized user, and set the user attribute identification bit; S2. Information classification: classifying the information to be stored, wherein the classification includes at least file level and data level; S3. Build a privacy protection model based on file-level authorized access: This file-level authorized access privacy protection model uses consortium chain technology to encrypt sensitive data files using a symmetric encryption algorithm. Combined with the IPFS decentralized storage system, the encrypted files are stored in IPFS and the CID value is returned. The CID value and encryption key are encrypted using an asymmetric encryption algorithm. This model enables designated fixed users to access encrypted and stored sensitive data files and dynamically add users to access encrypted and stored sensitive data files. S4. Build a privacy protection model based on data-level authorized access: The storage model uses a symmetric encryption algorithm to encrypt and store data in a MySQL database. The encryption algorithm is specifically layered encryption, using the AES algorithm to encrypt the data, and then using the RSA algorithm to encrypt the key obtained from the data encryption. S5. Set access control: Set access control policy. The access control includes two parts: on-chain query and access design, which restricts data access to only users in the authorization information table.

2. The sensitive data privacy protection method based on the alliance chain according to claim 1, characterized in that: In the step S1, the user information table is authorized to be accessed, and a public-private key pair (pk, sk) is generated for each user using the RSA algorithm, where pk is public and used for encryption; sk is used for decryption; The user attribute identification bit is specifically: 0 for the data owner and 1 for the data user.

3. The sensitive data privacy protection method based on the alliance chain according to claim 1 is characterized in that: The working process of the privacy protection model based on file-level authorized access in step S2 includes at least the following steps: S31. Dataset construction: The dataset includes but is not limited to images and xlsx files, with privacy information attached; S32. File encryption: Get random encryption key K M and the initial vector I V , use the symmetric encryption algorithm AES to encrypt the image and table file M to be uploaded to obtain E KM (M); S33, IPFS storage encrypted files: Connect Fabric with IPFS by calling go-ipfs-api, store the encrypted sensitive data files to be stored in the IPFS system, and return the storage address H M value; S34, Encrypted storage design and on-chain storage information: Hyperledger Fabric stores the information of all designated access users on the chain, with Sender1 as the key value, the file name Filename, the ciphertext encrypted by each user's public key (Secid1, Secid2, Secid3), the timestamp of the generated block, and the generated block ID as the value; S35. Data is stored in the database: The Fabric chain code is called through go-fabric-sdk to store the information in the ledger of each peer node and stored in the default Level DB database in the form of key-value; S36. Dynamically add users to access sensitive data files: In this step, the information of each accessing user is stored on the chain, with the user ID as the key value, the file name, the ciphertext after the public key encrypts the CID, the timestamp of the generated block, and the generated block ID as the value value. The Fabric chain code is called through go-fabric-sdk to store the information in the Level DB database of the Peer node ledger. Specifically: Secidb=E pkB (IDA||IDB||H m ||E pkA (IDB||K M ||IV||time)) Secidb is the ciphertext stored by user B, E pkA (·) is the encryption process using A’s public key, H m The CID returned for the file stored in IPFS, K M is the encryption key, IV is the initial vector, and time is the timestamp of the stored file.

4. The sensitive data privacy protection method based on the alliance chain according to claim 3 is characterized by: The step S34 of encrypting the storage design and storing the information on the chain specifically includes the following steps: S341: Use the public key of data owner A to encrypt. The encrypted content is the ID of data user B, file encryption key, initial vector and the time when the file was stored. Specifically: Secida=E pkA (IDB||K M ||IV||time) Among them, Secida is the ciphertext encrypted by A, EpkA(·) is the encryption process using A’s public key, IDB is the ID of data user B, K M is the encryption key, IV is the initial vector, and time is the timestamp of the stored file; S342: Use the public key of data user B to encrypt. The encrypted content is A's ID, B's ID, the CID returned by the file stored in IPFS, and the content encrypted by data owner A, that is, Secid1=E pkB (IDA||IDB||H M ||Secida) Among them, Secid1 is the ciphertext, E pkB (·) is the encryption process using B’s public key, IDA is A’s ID, H M It is the CID returned by the file stored in IPFS, and Secida is the ciphertext encrypted by A.

5. The sensitive data privacy protection method based on the alliance chain according to claim 1 is characterized in that: The working process of the privacy protection model based on data-level authorized access in step S4 includes at least the following steps: S41. Determine user information: Register on the registration server and formulate an authorized access user information table, and generate public keys PK for each user in the authorized user table. i and private key SK i , determine user attributes; S42, randomly generate a key and an initial vector: Generate a random number through a random number generator as the initial key K m and initial vector IV; S43. Encrypt sensitive data: Use the AES-128-CBC symmetric encryption algorithm to symmetrically encrypt the data ni in the message, obtain the ciphertext K_ni, and combine it with the Hyperledger Fabric transaction process; S44, secure storage of ciphertext and key: upload the ciphertext K_mi obtained in step S43 to the table user created in the MySQL database to construct a keyword index for the data set; S45. Secure data storage: The ID of the authorized access user B is used as the key value, the table name user and the ciphertext Ms are used as the value, and stored in the alliance chain distributed database in a key-value format; Data storage nodes manage all shared data, integrate the index structure of all data, and update the ledger.

6. The sensitive data privacy protection method based on the alliance chain according to claim 5 is characterized by: The user attributes in step S41 are specifically: 0 for data owner and 1 for data user.

7. The sensitive data privacy protection method based on consortium chain according to claim 5, characterized in that: In step S45, the table name, the authorized access user name B, the key and the vector are set to the string s, and the public key PK of the authorized user is used. i Encrypt the string s for storage, that is Ms=E PKB (user||IDB||K m ||IV) Among them, Ms is the ciphertext, user is the table name, IDB is the authorized access user name, K m is the key and IV is a vector.

8. The sensitive data privacy protection method based on the alliance chain according to claim 1 is characterized in that: In step S5, the on-chain query for the privacy protection model based on file-level authorized access is specifically as follows: first, access control is performed, and the on-chain information is queried according to the key value to determine whether the user ID exists in the key value, thereby returning the value stored in the LevelDB database; after querying the information, each user uses their own private key to decrypt it, thereby obtaining the file address CID value stored in IPFS; The specific on-chain query for the privacy protection model based on data-level authorized access is as follows: On the Hyperledger Fabric chain, based on the authenticated identity, the ciphertext Ms stored in the Hyperledger Fabric database is queried, and the ciphertext Ms is obtained by using its own private key PK. i Decrypt the ciphertext Ms to get the string s, and then get the data stored in the specified table user in the MySQL database, the IDB of the authorized access user B, and the key K m and initial vector IV.

9. A sensitive data privacy protection system based on a consortium chain, comprising a computer program, characterized in that: When the computer program is executed by a processor, the steps of any one of the above methods are implemented.