A government affair data security exchange method and system based on privacy protection

By using partitioned encryption of government data and exchanging it through a secure blockchain channel, the problem of insufficient privacy protection during data exchange has been solved, ensuring data confidentiality, integrity, and traceability, reducing the risk of data leakage, and improving the security of data exchange.

CN120979842BActive Publication Date: 2026-02-24CHINA NAT INST OF STANDARDIZATION
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511498119.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-20
Publication Date
2026-02-24
Estimated Expiration
2045-10-20

AI Technical Summary

Technical Problem

Existing data exchange technologies lack methods for auditing the entire process of data privacy protection and secure exchange, leading to the risk of privacy leaks during data exchange. This is especially true in sensitive data scenarios where data must be decrypted before it can be used, making it impossible to ensure data integrity and confidentiality.

Method used

By preprocessing the government data to be exchanged to generate a partitioned dataset and encrypting it, an encrypted data packet is generated. The exchange request is stored and verified on the blockchain using blockchain rules, an exchange token is generated, and the encrypted data packet is exchanged and securely processed in the blockchain secure channel to generate an audit certificate, thus ultimately forming a secure exchange of government data.

Benefits of technology

It achieves hierarchical encryption and minimization of exchanged data, ensuring the confidentiality, integrity and traceability of data, reducing the risk of data leakage, and improving the security and privacy protection capabilities of data exchange.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979842B_ABST
    Figure CN120979842B_ABST
Patent Text Reader

Abstract

The application discloses a kind of based on government affair data security exchange method and system of privacy protection, it is related to data security technical field, including, the government affair data to be exchanged is preprocessed, generates partitioned data set and is encrypted, generates encrypted data packet;Encrypted data packet is exchanged and is prepared to process, generates exchange request, and through the exchange request of blockchain rule is stored in chain, generates exchange token;According to the validity and data integrity of exchange request according to exchange token, generates exchange authorization signal, and in the exchange of encrypted data packet in blockchain security channel, generates encrypted exchange record;According to encrypted exchange record, using receiver private key is safely operated to encrypted data packet, generates encrypted result data packet.The application effectively improves the security and privacy protection ability of data exchange, reduces the risk of data leakage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data security technology, and in particular to a method and system for secure exchange of government data based on privacy protection. Background Technology

[0002] With the continuous advancement of digitalization and informatization, cross-domain and cross-scenario data sharing and collaboration have gradually become an important direction for informatization development. In recent years, research and practice on data exchange have gradually emerged. Traditional data exchange methods typically rely on centralized data sharing platforms, using access control, data anonymization, and identity authentication to ensure the compliant use of data. This has, to some extent, promoted data standardization and circulation, and provided basic capabilities for multi-party data collaboration.

[0003] Current data exchange technologies still present challenges in protecting data privacy and ensuring secure auditing of the entire exchange process. Specifically, traditional data exchange models largely rely on a central node for request verification and data transmission. While this allows for recording and managing the exchange process, ensuring data integrity and confidentiality during exchange, and subsequently generating verifiable audit evidence, remains a critical issue in multi-party application scenarios. Existing technologies often lack methods for direct computation based on encrypted data, meaning data must be decrypted after exchange before use, potentially leading to privacy breaches in sensitive data scenarios. Summary of the Invention

[0004] In view of the aforementioned existing problems, the present invention is proposed.

[0005] Therefore, this invention provides a privacy-preserving method for secure exchange of government data to address the problem of insufficient data security and privacy protection.

[0006] To solve the above-mentioned technical problems, the present invention provides the following technical solution:

[0007] In a first aspect, the present invention provides a method for secure exchange of government data based on privacy protection, comprising:

[0008] The government data to be exchanged is preprocessed to generate a partitioned dataset and then encrypted to generate an encrypted data packet;

[0009] The encrypted data packets are prepared for exchange, an exchange request is generated, and the exchange request is stored on the blockchain according to the blockchain rules to generate an exchange token.

[0010] The validity and data integrity of the exchange request are verified based on the exchange token, an exchange authorization signal is generated, and encrypted data packets are exchanged in the blockchain secure channel to generate an encrypted exchange record.

[0011] Based on the encrypted exchange record, the encrypted data packet is subjected to secure operations using the recipient's private key to generate an encrypted result data packet.

[0012] The encrypted result data packets are verified and recorded, an audit certificate is generated and delivered to the recipient, and the audit certificate is decrypted and used in accordance with blockchain rules, thus forming a secure exchange of government data.

[0013] As a preferred embodiment of the privacy-preserving secure exchange method for government data described in this invention, the following steps are taken: The government data to be exchanged is preprocessed to generate a partitioned dataset, which is then encrypted to generate an encrypted data packet.

[0014] The government data to be exchanged is cleaned, standardized, and labeled with sensitivity to generate a partitioned dataset;

[0015] Based on the sensitivity level and exchange purpose of the partitioned dataset, an encryption policy table is generated, and the minimum exchange dataset is extracted from the partitioned dataset.

[0016] Homomorphic encryption is performed on the minimum exchange dataset according to the encryption policy table to generate the encrypted dataset. The data is then divided into blocks and hash values ​​are calculated layer by layer to construct a tree digest.

[0017] A digital signature is generated using the initiator's private key, and then bound to the tree digest, encryption policy table, and encrypted dataset to generate an encrypted data packet.

[0018] As a preferred embodiment of the privacy-protected government data security exchange method described in this invention, the blockchain rules are formed by arranging node participation and transaction order through the consensus method of the blockchain network based on the business needs, sensitivity levels and regulatory requirements of both parties, formulating data protection methods through encryption algorithms, and setting data exchange formats, verification processes and permissions through transaction verification logic and access control policies.

[0019] As a preferred embodiment of the privacy-preserving secure exchange method for government data described in this invention, the specific steps for generating the exchange token are as follows:

[0020] The encrypted data packets are structured and parsed to generate a prepared dataset;

[0021] The prepared dataset is organized, an exchange request template is constructed and a data digest is populated, the exchange request template is digitally signed and its integrity is hardened, and it is formatted according to blockchain rules to generate an exchange request;

[0022] The exchange request is submitted, and the exchange request is verified and stored on the blockchain according to the blockchain rules, generating an exchange token.

[0023] As a preferred embodiment of the privacy-protected government data security exchange method described in this invention, the blockchain security channel is an encrypted communication path constructed based on the consensus method between blockchain network nodes. The set of participating nodes is selected according to the business needs and data sensitivity levels of the exchanging parties, and an encrypted communication connection and access control policy between the participating nodes is established according to blockchain rules. The channel is formed after the protocol is deployed and the channel is verified.

[0024] As a preferred embodiment of the privacy-preserving secure exchange method for government data described in this invention, the specific steps for generating the encrypted exchange record are as follows:

[0025] Extract the digest, timestamp, and permission tag from the exchange token to generate verification reference data, and match and verify it with the exchange request content to generate verification context information;

[0026] Based on the verification context information, the exchange request and exchange token are digitally signed and multi-signature verified to generate a signature verification result. Combined with the comparison of the root node of the tree digest and the block hash consistency check, a data integrity result is generated.

[0027] Based on the data integrity results, the access conditions of the verification context information are compared and verified, and an exchange authorization signal is generated.

[0028] By using the exchange authorization signal, a session is established in the blockchain secure channel to transmit and verify encrypted data packets, and a summary receipt is generated to produce an encrypted exchange record.

[0029] As a preferred embodiment of the privacy-preserving secure exchange method for government data according to the present invention, the specific steps for generating the encrypted result data packet are as follows:

[0030] Extract session parameters, data digests, and encrypted packet location indexes from encrypted exchange records to generate secure computation context information;

[0031] Based on the secure operation context information, the data blocks are extracted from the encrypted data packets by position index, and the block hash is verified to generate a set of data blocks that have passed the verification.

[0032] Using the receiver's private key, homomorphic secure operations are performed on the set of verified data blocks, and combined with a dynamic randomization factor, intermediate processing data packets are generated.

[0033] The intermediate data packets are subjected to integrity verification and signature binding to generate encrypted result data packets.

[0034] As a preferred embodiment of the privacy-protected government data secure exchange method described in this invention, the specific steps for generating the audit certificate are as follows:

[0035] Extract signature information, data digest, and operation log from the encrypted result data packet to generate verification context information;

[0036] Based on the verification context information, the encrypted result data packet is subjected to integrity verification and signature verification to generate a verification result.

[0037] The verification results and data exchange records are integrated to construct an audit dataset. The audit dataset is then digitally signed and encrypted to generate an audit certificate.

[0038] As a preferred embodiment of the privacy-protected secure exchange method for government data described in this invention, the specific steps for forming a secure exchange of government data are as follows:

[0039] Extract encrypted information and signature verification results from audit evidence to generate delivery context information;

[0040] Based on the delivery context information, the audit certificate is delivered to the recipient, the delivery status is recorded, and a delivery record is generated;

[0041] Based on delivery records and blockchain rules, the audit certificate is decrypted to generate data usage information;

[0042] Based on data usage information, data access and processing are carried out in the recipient's environment to form a secure exchange of government data.

[0043] Secondly, the present invention provides a privacy-protected government data secure exchange system, comprising:

[0044] The data encryption module is used to preprocess the government data to be exchanged, generate a partitioned dataset and encrypt it to generate encrypted data packets;

[0045] The request generation module is used to prepare encrypted data packets for exchange, generate exchange requests, store the exchange requests on the blockchain according to blockchain rules, and generate exchange tokens.

[0046] The authorization verification module is used to verify the validity and data integrity of the exchange request based on the exchange token, generate an exchange authorization signal, and exchange encrypted data packets in the blockchain secure channel to generate an encrypted exchange record.

[0047] The data processing module is used to perform secure operations on encrypted data packets using the recipient's private key based on the encrypted exchange record, and generate encrypted result data packets.

[0048] The audit generation module is used to verify and record encrypted result data packets, generate audit certificates, and deliver them to the recipient. At the same time, the audit certificates are decrypted and used in accordance with blockchain rules, forming a secure exchange of government data.

[0049] The beneficial effects of this invention are as follows: by cleaning, standardizing, and sensitivity-labeling the data to be exchanged to generate a partitioned dataset, generating an encryption policy table based on the sensitivity level and exchange purpose, extracting the minimum exchange dataset and performing homomorphic encryption and constructing a tree digest, and using the initiator's private key to generate encrypted data packets, hierarchical encryption and minimization processing of the exchanged data are achieved. A verifiable tree digest is constructed and bound with a digital signature, ensuring the confidentiality, integrity, and traceability of the data, effectively improving the security and privacy protection capabilities of data exchange, and reducing the risk of data leakage. Attached Figure Description

[0050] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0051] Figure 1 This is a flowchart illustrating a privacy-preserving method for secure exchange of government data.

[0052] Figure 2 This is a schematic diagram of a privacy-protected government data security exchange system.

[0053] Figure 3 A flowchart for generating token exchange.

[0054] Figure 4 A flowchart for generating encrypted exchange records. Detailed Implementation

[0055] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0056] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.

[0057] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it a single or selective embodiment that is mutually exclusive with other embodiments.

[0058] Reference Figures 1-4 This is one embodiment of the present invention, which provides a method for secure exchange of government data based on privacy protection, including the following steps:

[0059] S1. Preprocess the government data to be exchanged, generate a partitioned dataset and encrypt it to generate an encrypted data packet.

[0060] S1.1 Clean, standardize, and label the government data to be exchanged to generate a partitioned dataset.

[0061] Specifically, the government data collected includes identity information, business information, financial information, time information, statistical information, and document data. The collected government data undergoes format standardization processing, including using duplicate value detection to eliminate redundant fields, using character encoding conversion to standardize data encoding formats, using mean imputation to fill missing values, and using Z-Score-based correction for outliers. The processed government data is then standardized, for example, unifying dates to "YYYY-MM-DD" format and numerical precision to two decimal places. Based on preset sensitivity rules, the standardized government data is labeled with sensitivity levels, including but not limited to data category, sensitivity level, and access permissions. For example, fields involving personal information are labeled "highly sensitive," and fields involving statistical information are labeled "moderately sensitive." The labeling results are then used to generate a partitioned dataset.

[0062] It should also be noted that the preset sensitivity rules are sensitivity level judgment standards set by using keyword matching methods based on data categories, usage scenarios and security requirements, and are used to classify and protect government data.

[0063] S1.2. Generate an encryption policy table based on the sensitivity level and exchange purpose of the partitioned dataset, and extract the minimum exchange dataset from the partitioned dataset.

[0064] Specifically, based on the sensitivity level and exchange purpose of the partitioned dataset, a rule-based matching method is used to compare and calculate the sensitivity level to generate an encryption policy table, which includes encryption algorithm type, encryption strength and key length, etc. Then, based on the encryption policy table, a set filtering method is used to extract the minimum exchange dataset for the exchange purpose from the partitioned dataset. For example, a subset of key data with a proportion not exceeding 10% is selected as the minimum exchange dataset.

[0065] It should also be noted that sensitivity level refers to the classification of data in a partitioned dataset according to the degree of confidentiality and risk. For example, a qualitative assessment method combined with a quantitative scoring method can be used to calculate the sensitivity score and divide the data into high-sensitivity, medium-sensitivity and low-sensitivity levels. Exchange purpose refers to the business objectives or functional requirements that the data exchange is required to achieve. For example, a rule matching method can be used to determine the data types and scope required for the exchange. Examples include different purposes such as statistical analysis, business collaboration or authorization verification, so as to provide a basis for the generation of the encryption policy table.

[0066] Among them, the rule-based matching method compares the input data with the rule conditions by pre-defining and storing a set of rules, identifies the data that meets the conditions, and triggers the corresponding processing; the qualitative evaluation method combined with the quantitative scoring method refers to first determining the evaluation indicators and standards through qualitative analysis, and then using quantitative scoring to numerically evaluate the indicators to obtain a comprehensive evaluation result.

[0067] S1.3. Homomorphically encrypt the minimum exchange dataset according to the encryption policy table to generate the encrypted dataset, and then divide the data into blocks and calculate the hash value layer by layer to construct a tree digest.

[0068] Specifically, the minimum swap dataset is homomorphically encrypted according to the encryption policy table to generate an encrypted dataset. The encrypted dataset is then divided into several blocks, and a hash value is calculated for each block using a hash function available in existing technology. The expression is as follows:

[0069] ;

[0070] in, Indicates the first The hash value of each block, This indicates the existing hash algorithm used, such as SHA-256. Indicates the first The encrypted data in blocks, The index indicating the block;

[0071] Based on the tree-structured digest construction method, the hash values ​​of adjacent blocks are combined pairwise, and a hash function is used to calculate the combined hash value. The expression is as follows:

[0072] ;

[0073] in, This represents the hash value of the parent node of the current node. This represents the hash value of the left child node. This represents the hash value of the right child node. Indicates the parent node, Indicates the left child node, Indicates the right child node;

[0074] Repeat the process until a single hash value is generated, which serves as the root hash value of the tree digest, thus forming the tree digest.

[0075] S1.4. Use the initiator's private key to generate a digital signature, bind the tree digest, encryption policy table and encrypted dataset to generate an encrypted data packet.

[0076] Specifically, the tree digest, encryption policy table, and encrypted dataset are integrated. The integrated data is hashed using the elliptic curve digital signature algorithm to obtain the digest information. The digest information is then signed using the initiator's private key to generate a digital signature. The digital signature, tree digest, encryption policy table, and encrypted dataset are then bound together according to a predetermined data structure to form an encrypted data packet.

[0077] It should also be noted that the predetermined data structure refers to the specific format and rules for organizing, storing and transmitting data in advance, ensuring that it can be correctly identified and parsed during the exchange process. For example, in this invention, the predetermined data structure includes a fixed arrangement order, field length, encoding method and relationship between fields of digital signature field, tree digest field, encryption policy table field and encrypted dataset field, ensuring the consistency and parsability of encrypted data packets during the generation, transmission and verification process.

[0078] The initiator's private key is a unique secret key used to encrypt and sign the data. It belongs to the private key part of the asymmetric encryption method and is used in pairs with the initiator's public key. The private key is held only by the initiator and is used to digitally sign the tree digest, encryption policy table and encrypted dataset to ensure the authenticity and integrity of the data source and to provide the recipient with a basis for verifying the validity of the data and preventing tampering.

[0079] It should be noted that by meticulously classifying, grading, encrypting, and binding summaries to government data at the source, the confidentiality, integrity, and traceability of government data before exchange are ensured, thereby reducing the risk of data leakage and providing reliable credentials for subsequent exchange verification. Through structured security processing at the source, end-to-end data protection and minimized exchange are achieved, enhancing the security and privacy protection capabilities of data exchange.

[0080] S2. Prepare encrypted data packets for exchange, generate an exchange request, store the exchange request on the blockchain according to blockchain rules, and generate an exchange token.

[0081] S2.1 Blockchain rules are formed based on the business needs, sensitivity levels, and regulatory requirements of both parties involved in the exchange. They arrange node participation and transaction order through the consensus method of the blockchain network, formulate data protection methods through encryption algorithms, and set data exchange formats, verification processes, and permissions through transaction verification logic and access control policies.

[0082] Specifically, based on the business needs, sensitivity levels, and regulatory requirements of both parties involved in the exchange, the set of participating nodes and transaction priorities are determined, forming a node participation table and a transaction sequence table. A Byzantine fault-tolerant consensus algorithm is used to verify the node participation table and transaction sequence table, generating a consensus result. A symmetric encryption algorithm is used according to the sensitivity level to generate a data protection scheme, and an encryption algorithm configuration table is formed. A transaction format definition is established based on the transaction verification logic, and the verification process is defined using existing digital signature methods. An access control table is generated based on access control policies to clarify the access permissions of participating nodes. The node participation table, transaction sequence table, data protection scheme, transaction format definition, verification process, and access control table are integrated to form blockchain rules.

[0083] It should also be noted that business requirements refer to the data exchange conditions and objectives determined by both parties based on the purpose of the exchange, data types, usage scenarios, and efficiency requirements, such as the requirements for the real-time performance, integrity, and reliability of data exchange.

[0084] The regulations and requirements refer to industry standards and security specifications related to data exchange, such as data privacy protection regulations, information security level requirements, or compliance standards; transaction verification logic refers to the verification rules and methods used to ensure the authenticity of exchange requests and the integrity of data, such as using digital signature verification, hash comparison, or multi-signature verification.

[0085] Access control policies are rules used to limit the access and operation permissions of data by the two parties and participating nodes in the exchange. These rules can be role-based or attribute-based to ensure that data is accessed and used only by authorized nodes in a prescribed manner during the exchange process.

[0086] S2.2 Perform structured parsing on the encrypted data packets to generate a prepared dataset.

[0087] Specifically, the encrypted data packets are parsed according to a preset data format, extracting tree-structured summaries, encryption policy tables, encrypted datasets, and related metadata. These are then classified and labeled according to a preset data structure, such as labeling the data summary as summary information, the encryption policy table as policy information, and the encrypted dataset as data content. The labeled encrypted data is then combined and integrated to form a prepared dataset.

[0088] It should also be noted that the preset data format refers to the data organization structure and encoding specifications determined in advance according to the exchange rules and security requirements before data exchange. It is used to uniformly parse and process the content of data packets, including data type definitions, field order, field length, encoding method and metadata identification, and specifies the position and format of summary information, encryption policy table and encrypted dataset in data packets, so as to ensure that encrypted data packets can be correctly extracted and reassembled according to a unified standard during parsing, and to ensure the consistency and verifiability of data exchange.

[0089] S2.3 Organize the prepared dataset, construct an exchange request template and fill in the data digest, digitally sign and strengthen the integrity of the exchange request template, and format it according to blockchain rules to generate an exchange request.

[0090] Specifically, a data preparation method is used to filter the data fields in the prepared dataset according to the preset priority of the exchange request. The filtering rules include field type, field importance, and field completeness. For example, timestamp fields and permission tag fields are prioritized. The filtered fields are then sorted in a preset order, such as chronological order or field priority order. An exchange request template is constructed according to a preset data format, and a data digest is generated from the prepared dataset using the SHA-256 algorithm. The data digest is then filled into the specified field positions of the exchange request template. The exchange request template with the data digest is signed using the RSA algorithm, and the generated signature information is attached to the exchange request template to complete the integrity hardening. According to blockchain rules, a formatting method is used to encode and structure the hardened exchange request template to generate an exchange request that meets the requirements of blockchain transactions.

[0091] It should also be noted that preset priority refers to the importance of data fields set in advance based on exchange requests or business needs, which is used to guide the determination of which fields should be retained first during the data filtering process. For example, timestamps, permission tags, and data source fields are set as high priority. Preset order refers to the data field arrangement rules set in advance based on exchange requests or business specifications, which is used to guide the data sorting process. For example, the data is arranged in chronological order or according to the importance of the fields to ensure the consistency and parsability of the data in subsequent processing.

[0092] S2.4 Submit the exchange request, verify the exchange request and store it on the blockchain according to the blockchain rules, and generate an exchange token.

[0093] Specifically, the transaction submission method is used to send the exchange request to the blockchain network. According to the blockchain rules, the Byzantine fault-tolerant algorithm is used to verify the signature, data format and integrity of the exchange request. After the verification is passed, the consensus algorithm is used to determine the transaction order and generate transaction records. The transaction records are written into the blockchain ledger using the blockchain storage method, and an exchange token containing a transaction summary, timestamp and permission tag is generated.

[0094] It should also be noted that a blockchain network refers to a distributed network composed of multiple nodes that jointly maintain a distributed ledger through peer-to-peer communication. Transaction data is verified, sorted, and stored according to proof-of-work, proof-of-stake, or Byzantine fault-tolerant algorithms, forming an immutable and traceable blockchain data structure. This supports data exchange, transaction record storage, and access control, ensuring security, consistency, and transparency in a distributed environment.

[0095] Consensus algorithms refer to methods in distributed networks where multiple nodes reach a consensus on the consistency of data states through predetermined rules.

[0096] S3. Verify the validity and data integrity of the exchange request based on the exchange token, generate an exchange authorization signal, and exchange encrypted data packets in the blockchain secure channel to generate an encrypted exchange record.

[0097] S3.1. A blockchain secure channel is an encrypted communication path built based on the consensus method between blockchain network nodes. It is formed by selecting a set of participating nodes by exchanging the business needs and data sensitivity levels of both parties, establishing encrypted communication connections and access control policies between participating nodes according to blockchain rules, and completing protocol deployment and channel verification.

[0098] Specifically, based on the business needs and sensitivity levels of both parties involved in the exchange, a node selection method is adopted. By comparing the business capability indicators and security level parameters of each candidate node, such as node response speed, storage capacity, encryption capability, and security level value, nodes that meet the preset business requirement thresholds and sensitivity level requirements are included in the participating node set. According to blockchain rules, a proof-of-stake algorithm is used to determine the transaction order and node participation method. Symmetric encryption is used to establish encrypted communication connections between participating nodes, and communication permissions are set according to access control policies. A protocol deployment method is used to deploy encrypted communication protocols between participating nodes, and a channel verification method is used to verify the integrity and security of the communication path until a secure blockchain channel that can be used for the secure exchange of government data is formed.

[0099] It should also be noted that the preset business requirement thresholds and sensitivity level requirements refer to a set of standard parameters pre-set during the exchange process to determine whether participating nodes meet the participation conditions, based on the business types and data security requirements of both parties. The business requirement thresholds include indicators such as node response time not exceeding 500 milliseconds, storage capacity not less than 1TB, and processing capacity not less than the example value of 1000 times / second. The sensitivity level requirements include, for example, data classification as high-sensitivity, medium-sensitivity, or low-sensitivity, and the corresponding nodes must have the corresponding encryption capability level and access control policy, thereby providing a quantifiable basis for node selection.

[0100] S3.2 Extract the digest, timestamp, and permission tag from the exchange token, generate verification reference data, and match and verify it with the exchange request content to generate verification context information.

[0101] Specifically, the process involves using data parsing methods (such as JSON parsing, XML parsing, or binary parsing) to read the exchange token content and extracting the digest value, timestamp value, and permission tag value according to a preset data format. A timestamp parsing method is used to convert the timestamp value into a standard time format, and a permission parsing method is used to decode the permission tag. A matching and verification method is employed to compare the extracted digest value with the exchange request content using a hash algorithm, verify the time consistency of the timestamp value with the exchange request time, and verify the permission tag value with the permission requirements of the exchange request. The comparison results are then integrated to generate verification reference data containing the verification status and matching results, and verification context information is constructed using the verification reference data and the matching results.

[0102] It should also be noted that the verification reference data refers to the set of comparative data required in the data integrity verification and signature verification process. It is used to assist in judging the authenticity and consistency of the target data. Specifically, it includes pre-registered original digest values, signature public key information, transaction timestamps, permission identifiers, and historical exchange records. By comparing the calculation results of the target data with the corresponding content in the verification reference data, the basis for verification and validation is formed, ensuring that the verification process is traceable and verifiable.

[0103] S3.3. Based on the verification context information, perform digital signature and multi-signature verification on the exchange request and exchange token, generate signature verification results, and combine the tree digest root node comparison and block hash consistency check to generate data integrity results.

[0104] Specifically, the public key is used to verify the signature values ​​of the exchange request and the exchange token to obtain a preliminary signature verification result. A multi-signature verification method is then used to verify all signatures sequentially according to the list of participating nodes, and the verification results are integrated to generate the final signature verification result. A hash calculation method is used to calculate and compare the root node value of the tree digest to confirm digest consistency. A block hash consistency check method is used to compare the hash values ​​of each block of the encrypted data packet block by block to verify block integrity. Finally, the signature verification result, the tree digest comparison result, and the block hash consistency check result are integrated to generate a data integrity result that includes both signature status and integrity status.

[0105] S3.4. Based on the data integrity results, compare and verify the access conditions of the verification context information, and generate an exchange authorization signal.

[0106] Specifically, the permission tags in the verification context information are compared item by item with the access control policy to verify whether the access conditions are met. A conditional verification method is used to compare the access conditions based on business requirements and sensitivity levels to confirm whether they meet the exchange authorization requirements. Logical judgment is then performed on the comparison results. Boolean logic operations are used to compare the original digest value, transaction timestamp, and permission identifier with the preset access conditions one by one, and a comprehensive judgment is made based on preset logical rules to determine whether the access conditions are met, generating an access condition verification result. Finally, combining the access condition verification result with the data integrity result, an exchange authorization signal containing the authorization status, verification timestamp, and permission tags is generated.

[0107] It should also be noted that preset access conditions refer to a set of conditions set in advance based on the business needs, data sensitivity levels, and security policies of both parties in the exchange, used to determine whether data access is allowed. These conditions typically include access permission rules, time constraints, data category restrictions, and user authentication requirements, serving as the basis for access control decisions.

[0108] S3.5. Using the exchange authorization signal, establish a session in the blockchain secure channel, transmit and verify encrypted data packets, generate summary receipts, and generate encrypted exchange records.

[0109] Specifically, the permission tags in the exchange authorization signals are compared with the access control policies of the blockchain secure channel. A rule matching method is used to determine whether the permission tags meet the access conditions in the access control policies. If they do, the nodes are included in the set of eligible participating nodes. An encrypted communication method is used to negotiate session keys and deploy encryption protocols among participating nodes to establish an encrypted session connection. The encrypted data packets are segmented according to a preset data format and transmitted through the blockchain secure channel. After each segment is transmitted, a hash comparison method is used to verify data integrity. The transmission status and verification results are summarized to generate an encrypted exchange record containing session identifiers, timestamps, and verification status.

[0110] It should be noted that a multi-layered verification system, combined with a blockchain encrypted channel, is constructed. This system executes identity verification, permission verification, data integrity verification, and signature verification layer by layer, forming an interconnected verification process. Encrypted transmission and recording are performed within the blockchain encrypted channel, ensuring collaborative security for verification and transmission, and guaranteeing the authenticity, integrity, and immutability of the data exchange process. The combination of multiple verifications and the blockchain encrypted channel achieves end-to-end security control of the exchange process, not only enhancing the security and credibility of data exchange but also providing a reliable basis for subsequent auditing and traceability.

[0111] S4. Based on the encrypted exchange record, use the recipient's private key to perform secure operations on the encrypted data packet to generate an encrypted result data packet.

[0112] S4.1 Extract session parameters, data digests, and encrypted packet location indexes from the encrypted exchange record to generate secure operation context information.

[0113] Specifically, the session identifier, timestamp, data digest, and encrypted packet location index are read sequentially from the encrypted exchange record. The location index is used to locate the storage location of the encrypted data packet, and the corresponding encrypted packet content is extracted. The session identifier, data digest, and encrypted packet location index are integrated according to a preset data format to generate secure operation context information.

[0114] S4.2. Based on the security operation context information, extract the block data from the encrypted data packet by position index, perform block hash verification, and generate a set of data blocks that have passed the verification.

[0115] Specifically, based on the encrypted packet location index contained in the secure operation context information, the corresponding block data is located and read one by one from the encrypted data packet. The SHA-256 algorithm is used to perform a hash operation on each block data to obtain the block hash value. The obtained block hash value is compared and verified with the corresponding hash value recorded in the secure operation context information. Block data that matches the verification is selected and integrated in a preset order to form a set of verified data blocks for subsequent secure operation processing.

[0116] It should also be noted that the preset order refers to the order in which data blocks are processed and arranged in advance based on exchange rules, data structure and business requirements before data exchange. This order is used to ensure the consistency and verifiability of the segmented data in subsequent processing, verification and reorganization. It includes the logical order, time order or identification order of the data blocks, such as arranging them from earliest to latest according to the data generation time or arranging them in ascending order according to the index number, so as to ensure that the segmented data is processed and integrated in accordance with a unified standard.

[0117] S4.3. Using the receiver's private key, perform homomorphic secure operations on the set of verified data blocks, and combine this with a dynamic randomization factor to generate intermediate processing data packets.

[0118] Specifically, using the recipient's private key, homomorphic encryption is used to sequentially perform homomorphic operations on each data block in the verified data block set. The Paillier homomorphic encryption method is used to input the data blocks into the homomorphic encryption operation in a preset order, calculate the encryption result, and combine it with a random number generation algorithm to generate a dynamic randomization factor. The dynamic randomization factor is then homomorphically added to each encryption result to generate an intermediate processing data packet.

[0119] It should also be noted that the recipient's private key refers to the private key used by the recipient in encrypted communication for decryption or participation in homomorphic encryption operations. It is confidential and held only by the recipient to ensure the confidentiality and verifiability of the data. The dynamic randomization factor refers to a random value generated in real time according to a random number generation algorithm during the homomorphic secure operation process. It is used to perform randomization operations with the encrypted data to enhance the security of the data processing process and prevent attackers from inferring the original information through data analysis.

[0120] S4.4 Perform integrity verification and signature binding on the intermediate processing data packets to generate encrypted result data packets.

[0121] Specifically, a hash verification method is used to generate hash values ​​for intermediate processing data packets according to the field order in a preset data format. A digital signature is generated using the recipient's private key based on the encryption algorithm. The digital signature is then bound to the intermediate processing data packet and the corresponding hash value to form signature binding information. The signature binding information is then combined and encapsulated with the intermediate processing data packet according to the preset data format to generate an encrypted result data packet.

[0122] S5. Verify and record the encrypted result data packet, generate an audit certificate, and deliver it to the recipient. At the same time, according to the blockchain rules, decrypt and use the audit certificate to form a secure exchange of government data.

[0123] S5.1 Extract signature information, data digest, and operation log from the encrypted result data packet to generate verification context information.

[0124] Specifically, the field parsing method is used to parse the encrypted result data packet in the order of fields according to the preset data format, extract the signature information, data digest and operation log, and integrate the extracted signature information, data digest and operation log according to the preset data structure to generate verification context information.

[0125] S5.2. Based on the verification context information, perform integrity verification and signature verification on the encrypted result data packet to generate the verification result.

[0126] Specifically, integrity verification and signature verification methods are used. Based on the verification context information, the signature information, data digest, and operation log extracted from the encrypted result data packet are subjected to hash operation and public key verification, respectively. The calculated hash value is compared with the data digest, and the signature information is verified using the signature verification method to generate a verification result.

[0127] S5.3 Integrate the verification results and data exchange records to construct an audit dataset, digitally sign and encrypt the audit dataset, and generate an audit certificate.

[0128] Specifically, an integration method is adopted, which summarizes the verification results and data exchange records according to a preset data format to construct an audit dataset. The audit dataset is then signed using the initiator's private key using a digital signature method, and finally encrypted using a symmetric encryption algorithm to generate an audit certificate.

[0129] It should also be noted that audit proof refers to an encrypted file or data structure formed by digitally signing and encrypting the audit dataset to prove the integrity, authenticity, and traceability of the data exchange process. It includes signature information, encrypted content, timestamps, and related metadata, and can be used for subsequent audit verification and compliance proof.

[0130] S5.4 Extract encrypted information and signature verification results from the audit proof to generate delivery context information.

[0131] Specifically, the audit proof is structured using a JSON parsing method. The encrypted information field and the signature verification result field are read according to a preset data format. The signature verification result field is then verified using a signature verification method to confirm the validity of the signature. Based on the verification result and the encrypted information, delivery context information is generated. The delivery context information includes the encrypted information, the signature verification status, and related metadata, such as example results where the signature verification status is "passed" or "failed".

[0132] S5.5. Based on the delivery context information, deliver the audit certificate to the recipient, record the delivery status, and generate a delivery record.

[0133] Specifically, the transmission path of the audit certificate is determined based on the delivery context information, the audit certificate is encapsulated according to a preset data format, and the encapsulated audit certificate is sent to the recipient using an encrypted communication method. The recipient confirms receipt and returns a receipt confirmation message. The transmission time of the audit certificate, the recipient's identifier, the delivery status, and the receipt confirmation message are recorded to generate a delivery record. The delivery record includes the delivery time, the recipient's identifier, the delivery status, and related metadata, such as an example result where the delivery status is "success" or "failure".

[0134] S5.6. Based on the delivery records and blockchain rules, decrypt the audit certificate to generate data usage information.

[0135] Specifically, the process involves obtaining audit proof and related encrypted information based on delivery records, determining the decryption algorithm and key source according to blockchain rules, decrypting the encrypted information in the audit proof using the recipient's private key, verifying the integrity of the decryption result and the validity of the signature, extracting the decrypted audit data and related metadata, recording the decryption time, decryptor identifier, and verification status, and forming data usage information. This data usage information includes the decrypted content, decryption time, and verification status, such as an example result where the verification status is "passed".

[0136] S5.7. Based on the data usage information, data access and processing are carried out in the receiving environment to form a secure exchange of government data.

[0137] Specifically, based on the preset data format in the data usage information, a JSON parsing method is used to parse out the summary information field used to identify the data content and the permission information field used to identify access permissions. The data identification fields are matched one by one with the data entries in the data catalog to generate a candidate data set. The candidate data set is then mapped to permissions according to the permission identification fields. Using an access control list method, user roles or identities are compared with the permission identification fields to filter out data entries that meet the permission conditions. The range of filtered data entries is combined with the corresponding permission levels to generate the accessible data range and access permission results. The data content indicated in the data usage information is read according to the access permissions. The indicated data content is structured, parsed, and processed according to the needs of government business. Processing results are generated according to the processing rules, and the data access time, visitor identifier, and processing log are recorded. The processing results are then integrated with the data usage information to form a secure exchange of government data, such as an example record with the visitor identifier "Department A".

[0138] It should also be noted that processing rules refer to a set of standardized rules for the orderly parsing, transformation, and manipulation of data content based on specific business needs and data access permissions. These rules include data format conversion rules, data filtering rules, data operation rules, and data output rules. For example, field mapping rules can be used for structured data to map the original fields to the target fields; keyword extraction rules can be used for unstructured data to obtain specified information, thereby ensuring that the data access and processing process meets the predetermined requirements and produces processing results that meet business needs.

[0139] Permission conditions refer to the requirement that the access permissions corresponding to a user's role or identity must be consistent with the access level, operation type, and data range recorded in the permission identifier field. The specific filtering process is as follows: based on the access control list method, the user's role or identity information is compared with the permission identifier field one by one to determine whether they match. For example, if the access level is "read and write", the operation type is "query", and the data range is "data within the department", only data entries that match completely are retained to form a data set that meets the permission conditions.

[0140] This embodiment also provides a privacy-preserving government data secure exchange system, including: a data encryption module for preprocessing the government data to be exchanged, generating a partitioned dataset and encrypting it to generate an encrypted data packet; a request generation module for preparing the encrypted data packet for exchange, generating an exchange request, and storing the exchange request on the blockchain according to blockchain rules to generate an exchange token; an authorization verification module for verifying the validity and data integrity of the exchange request based on the exchange token, generating an exchange authorization signal, and exchanging the encrypted data packet in a secure blockchain channel to generate an encrypted exchange record; a data processing module for performing secure operations on the encrypted data packet using the recipient's private key according to the encrypted exchange record to generate an encrypted result data packet; and an audit generation module for verifying and recording the encrypted result data packet, generating an audit certificate, and delivering it to the recipient. Simultaneously, the audit certificate is decrypted and used according to blockchain rules to form a secure government data exchange.

[0141] This embodiment also provides a computer device applicable to the privacy-preserving secure exchange method for government data, comprising: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the privacy-preserving secure exchange method for government data as proposed in the above embodiment.

[0142] The computer device can be a terminal, comprising a processor, memory, communication interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, carrier networks, NFC (Near Field Communication), or other technologies. The display screen can be an LCD screen or an e-ink screen. The input devices can be a touch layer covering the display screen, buttons, a trackball, or a touchpad on the computer device's casing, or an external keyboard, touchpad, or mouse.

[0143] This embodiment also provides a storage medium storing a computer program, which, when executed by a processor, implements the privacy-preserving method for secure exchange of government data as proposed in the above embodiments. The storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random Access Memory (SRAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read Only Memory (EPROM), Programmable Red-Only Memory (PROM), Read-Only Memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.

[0144] In summary, this invention achieves hierarchical encryption and minimization of exchanged data by: cleaning, standardizing, and sensitivity-labeling the data to be exchanged to generate a partitioned dataset; generating an encryption policy table based on sensitivity levels and exchange purposes; extracting the minimum exchange dataset and performing homomorphic encryption and constructing a tree digest; and using the initiator's private key to generate encrypted data packets. This ensures the confidentiality, integrity, and traceability of the data, effectively improving the security and privacy protection capabilities of data exchange and reducing the risk of data leakage.

[0145] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

Claims

1. A method for secure exchange of government data based on privacy protection, characterized in that: include, The government data to be exchanged is preprocessed to generate a partitioned dataset, which is then encrypted to generate an encrypted data packet. The specific steps are as follows. The government data to be exchanged is cleaned, standardized, and labeled with sensitivity to generate a partitioned dataset; Based on the sensitivity level and exchange purpose of the partitioned dataset, an encryption policy table is generated, and the minimum exchange dataset is extracted from the partitioned dataset. Homomorphic encryption is performed on the minimum exchange dataset according to the encryption policy table to generate the encrypted dataset. The data is then divided into blocks and hash values ​​are calculated layer by layer to construct a tree digest. A digital signature is generated using the initiator's private key, and then bound to the tree digest, encryption policy table, and encrypted dataset to generate an encrypted data packet. The encrypted data packets are prepared for exchange, an exchange request is generated, and the exchange request is stored on the blockchain according to the blockchain rules to generate an exchange token. The blockchain rules are based on the business needs, sensitivity levels, and regulatory requirements of both parties involved in the exchange. They arrange node participation and transaction order through the consensus method of the blockchain network, formulate data protection methods through encryption algorithms, and set data exchange formats, verification processes, and permissions through transaction verification logic and access control policies, thus forming blockchain rules. The validity and data integrity of the exchange request are verified based on the exchange token, an exchange authorization signal is generated, and encrypted data packets are exchanged in the blockchain secure channel to generate an encrypted exchange record. The blockchain secure channel is an encrypted communication path built based on the consensus method between blockchain network nodes. It selects a set of participating nodes by exchanging the business needs and data sensitivity levels of both parties, and establishes encrypted communication connections and access control policies between participating nodes according to blockchain rules. It is formed after the protocol is deployed and the channel is verified. Based on the encrypted exchange record, the encrypted data packet is subjected to secure operations using the recipient's private key to generate an encrypted result data packet. The encrypted result data packets are verified and recorded, an audit certificate is generated and delivered to the recipient, and the audit certificate is decrypted and used in accordance with blockchain rules, thus forming a secure exchange of government data.

2. The method for secure exchange of government data based on privacy protection as described in claim 1, characterized in that: The specific steps for generating the exchange token are as follows: The encrypted data packets are structured and parsed to generate a prepared dataset; The prepared dataset is organized, an exchange request template is constructed and a data digest is populated, the exchange request template is digitally signed and its integrity is hardened, and it is formatted according to blockchain rules to generate an exchange request; The exchange request is submitted, and the exchange request is verified and stored on the blockchain according to the blockchain rules, generating an exchange token.

3. The method for secure exchange of government data based on privacy protection as described in claim 1, characterized in that: The specific steps for generating the encrypted exchange record are as follows: Extract the digest, timestamp, and permission tag from the exchange token to generate verification reference data, and match and verify it with the exchange request content to generate verification context information; Based on the verification context information, the exchange request and exchange token are digitally signed and multi-signature verified to generate a signature verification result. Combined with the comparison of the root node of the tree digest and the block hash consistency check, a data integrity result is generated. Based on the data integrity results, the access conditions of the verification context information are compared and verified, and an exchange authorization signal is generated. By using the exchange authorization signal, a session is established in the blockchain secure channel to transmit and verify encrypted data packets, and a summary receipt is generated to produce an encrypted exchange record.

4. The method for secure exchange of government data based on privacy protection as described in claim 1, characterized in that: The specific steps for generating the encrypted result data packet are as follows: Extract session parameters, data digests, and encrypted packet location indexes from encrypted exchange records to generate secure computation context information; Based on the secure operation context information, the data blocks are extracted from the encrypted data packets by position index, and the block hash is verified to generate a set of data blocks that have passed the verification. Using the receiver's private key, homomorphic secure operations are performed on the set of verified data blocks, and combined with a dynamic randomization factor, intermediate processing data packets are generated. The intermediate data packets are subjected to integrity verification and signature binding to generate encrypted result data packets.

5. The method for secure exchange of government data based on privacy protection as described in claim 1, characterized in that: The specific steps for generating the audit certificate are as follows: Extract signature information, data digest, and operation log from the encrypted result data packet to generate verification context information; Based on the verification context information, the encrypted result data packet is subjected to integrity verification and signature verification to generate a verification result. The verification results and data exchange records are integrated to construct an audit dataset. The audit dataset is then digitally signed and encrypted to generate an audit certificate.

6. The method for secure exchange of government data based on privacy protection as described in claim 1, characterized in that: The specific steps for establishing secure exchange of government data are as follows: Extract encrypted information and signature verification results from audit evidence to generate delivery context information; Based on the delivery context information, the audit certificate is delivered to the recipient, the delivery status is recorded, and a delivery record is generated; Based on delivery records and blockchain rules, the audit certificate is decrypted to generate data usage information; Based on data usage information, data access and processing are carried out in the recipient's environment to form a secure exchange of government data.

7. A privacy-preserving government data secure exchange system, based on the privacy-preserving government data secure exchange method according to any one of claims 1 to 6, characterized in that: include, The data encryption module is used to preprocess the government data to be exchanged, generate a partitioned dataset and encrypt it to generate encrypted data packets; The request generation module is used to prepare encrypted data packets for exchange, generate exchange requests, store the exchange requests on the blockchain according to blockchain rules, and generate exchange tokens. The authorization verification module is used to verify the validity and data integrity of the exchange request based on the exchange token, generate an exchange authorization signal, and exchange encrypted data packets in the blockchain secure channel to generate an encrypted exchange record. The data processing module is used to perform secure operations on encrypted data packets using the recipient's private key based on the encrypted exchange record, and generate encrypted result data packets. The audit generation module is used to verify and record encrypted result data packets, generate audit certificates, and deliver them to the recipient. At the same time, the audit certificates are decrypted and used in accordance with blockchain rules, forming a secure exchange of government data.

Citation Information

Patent Citations

  • Index-based on-chain data query method and device

    CN113901131A

  • Data exchange method and device based on privacy computing platform and electronic equipment

    CN114510743A