Blockchain-based nationwide dialysis case registration data tamper-proofing method and system

CN121150904BActive Publication Date: 2026-08-07WEIGAO (SHANDONG) INFORMATION TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
WEIGAO (SHANDONG) INFORMATION TECHNOLOGY CO LTD
Filing Date
2025-09-29
Publication Date
2026-08-07

AI Technical Summary

Technical Problem

但是在应用到大规模的全国性登记系统中,面临效率低、验证成本高以及无法抵御未来量子计算攻击等问题

Benefits of technology

[0054]本发明提出一种安全且可验证的全国透析病例数据防篡改登记方法及系统。利用可验证随机函数生成公共参数,降低了主导节点单方面操纵计算过程的可能性;针对不同敏感度的数据,在关键计算环节运用了差异化的密码学协议,能够在保障核心数据抵御计算攻击的同时,维持整体计算的效率。通过对关键逻辑门的计算结果进行非交互式零知识证明验证,实现了对复杂计算过程的高效监督,能及时发现并阻止恶意计算,保证了结果的正确性。采用聚合签名对数据进行锚定,提供了不可篡改和可追溯保证,提升了大规模医疗数据协同登记的安全性和可信度。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121150904B_ABST
    Figure CN121150904B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of safety, and particularly relates to a nationwide dialysis case registration data tamper-proofing method and system based on a block chain. The data to be registered is divided into blocks, shared to a committee node subset through a verifiable secret sharing protocol, and initial data shares bound with data hashes are generated. A leading node aggregates commitments and generates a random vector as a public initialization parameter of a GMW protocol Boolean operation circuit. When the GMW circuit performs an AND gate calculation, an oblivious transfer protocol of a discrete logarithm or a lattice password base is switched according to input share sensitivity. For key logic gates with a fan-out value or input sources exceeding a preset threshold, the committee cooperatively generates and verifies a non-interactive zero-knowledge proof. The committee generates an aggregated signature and anchors storage with the data blocks, ensuring data tamper-proofing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of security technology, specifically a method and system for preventing tampering of national dialysis case registration data based on blockchain. Background Technology

[0002] Dialysis data is scattered across hundreds of independent medical institutions nationwide. Due to concerns about patient privacy, data security, and their own interests, these institutions are unwilling or unable to share data on a centralized platform, resulting in ineffective data integration and utilization. Dialysis cases contain a large amount of highly sensitive personal health information, and any form of data aggregation must adhere to the highest standards of patient privacy protection. However, for epidemiological research, treatment optimization, or public health decision-making, this data must be aggregated, analyzed, and verified. Traditional centralized database solutions struggle to address both issues simultaneously, as they are both targets of single points of failure and attacks, and cannot technically guarantee against data misuse by data managers. Distributed ledger technologies such as blockchain, with their tamper-proof and traceability features, can solve the security issues of dialysis case registration data. However, blockchain technology primarily addresses the storage security of data after it is uploaded to the chain. For the need for collaborative computation and privacy protection of multi-party data before it is uploaded, cryptographic techniques such as secure multi-party computation are required, allowing multiple parties to collaboratively complete data computation and verification without disclosing their original data. However, when applied to a large-scale nationwide registration system, it faces problems such as low efficiency, high verification costs, and inability to withstand future quantum computing attacks. Summary of the Invention

[0003] To address the aforementioned issues, this invention first proposes a blockchain-based method for preventing tampering with national dialysis case registration data, comprising the following steps:

[0004] The dialysis case data to be registered by each participating node is divided into data blocks; each participating node shares its data block with a subset of committee nodes elected based on historical behavior reputation scores through a verifiable secret sharing protocol, generating an initial data share bound to the hash value of the data block; a leading node in the subset of committee nodes takes the global commitment formed by aggregating the commitments of the initial data shares of each party as input, generates a random vector through a verifiable random function, and uses the random vector as a common initialization parameter of the GMW protocol Boolean operation circuit;

[0005] When performing the AND gate calculation of the GMW protocol Boolean operation circuit, the system switches between an unintentional transmission protocol based on the discrete logarithm problem and an unintentional transmission protocol based on lattice cryptography, according to the sensitivity index of the original data field corresponding to the input share.

[0006] During circuit calculation, critical logic gates whose fan-out value and / or number of input sources exceed a preset threshold are identified. The committee nodes collaboratively generate non-interactive zero-knowledge proofs for the calculation correctness of each critical logic gate. The critical logic gate is activated only after the proof is verified.

[0007] The committee node generates an aggregate signature based on the results of calculations of all gate circuits, and anchors the aggregate signature to the data block for storage.

[0008] Optionally, each participating node shares its data block with a subset of committee nodes elected based on historical behavior reputation scores via a verifiable secret sharing protocol, including:

[0009] Periodically based on the online duration of each node Historical mission success rate Data validation pass rate Using the weighted summation formula Calculate the historical behavior reputation score S for each node, where , , For preset weighting factors and ;

[0010] Nodes with scores S higher than a preset threshold are included in the candidate pool, and a specific number of nodes are randomly selected from the candidate pool to form the committee node subset.

[0011] Optionally, the process involves a dominant node from the subset of committee nodes taking a global commitment, aggregated from the initial data share commitments of all parties, as input, and generating a random vector using a verifiable random function, including:

[0012] Based on the current registration round number, a leading node is designated from a subset of committee nodes using a deterministic algorithm;

[0013] The dominant node takes the global commitment as input to a verifiable random function to generate a 256-bit random vector and a zero-knowledge proof.

[0014] The leading node broadcasts the random vector and the zero-knowledge proof to the other members of the committee. The other member nodes verify the validity of the proof. If the verification is successful, the 256-bit random vector is used as a common initialization parameter.

[0015] Optionally, when performing the AND gate calculation of the GMW protocol Boolean operation circuit, switching between an unintentional transmission protocol based on the discrete logarithm problem and an unintentional transmission protocol based on lattice ciphers, according to the sensitivity index of the original data field corresponding to the input share, includes:

[0016] The patient identification and contact information fields are defined as having a sensitivity index of level 5.

[0017] The fields for medical records and medication use history are defined as sensitivity index level 4;

[0018] Define the routine vital signs data field as a sensitivity index of 1 to 3;

[0019] When the sensitivity index of the original data field corresponding to the input share of the AND gate computation is level 4 to 5, an inadvertent transmission protocol based on lattice cryptography is adopted.

[0020] When the sensitivity index is between level 1 and level 3, an unintentional transmission protocol based on the discrete logarithm problem is adopted.

[0021] Optionally, the key logic gate that identifies the fan-out value and / or the number of input sources exceeding a preset threshold includes:

[0022] Before circuit calculation, static analysis is performed on the Boolean operation circuit. Logic gates with a fan-out value exceeding 32 and logic gates with more than 16 input sources are identified as critical logic gates.

[0023] Optionally, the committee nodes collaboratively generate non-interactive zero-knowledge proofs for the computational correctness of each critical logic gate, including:

[0024] For each identified critical logic gate, the input and output shares of the critical logic gate at each node of the committee are used as secret inputs, and the circuit definition of the critical logic gate is used as common inputs. They collaboratively execute the bulletproofs protocol to generate a non-interactive zero-knowledge proof that proves the correctness of the input-output relationship of the logic gate, and attach the generated proof to the output share of the critical logic gate.

[0025] Optionally, the generation of the aggregate signature by the committee node based on the results of calculations by all gate circuits includes:

[0026] Each node in the committee uses its BLS private key to sign the hash value calculated by concatenating the hash value of the data block with the result of the gate circuit calculation, thus generating a partial signature.

[0027] The leading node collects partial signatures generated by all committee member nodes and aggregates these partial signatures into a BLS aggregate signature with constant length.

[0028] This invention also proposes a blockchain-based national dialysis case registration data anti-tampering system, comprising:

[0029] The initialization module is used to divide the dialysis case data to be registered by each participating node into data blocks; each participating node shares its data block with a subset of committee nodes elected based on historical behavior reputation scores through a verifiable secret sharing protocol, generating an initial data share bound to the hash value of the data block; a leading node in the subset of committee nodes takes the global commitment formed by aggregating the commitments of the initial data shares of all parties as input, generates a random vector through a verifiable random function, and uses the random vector as a common initialization parameter of the GMW protocol Boolean operation circuit;

[0030] The switching module is used to switch between an unintentional transmission protocol based on the discrete logarithm problem and an unintentional transmission protocol based on lattice cryptography when performing the AND gate calculation of the Boolean operation circuit of the GMW protocol, according to the sensitivity index of the original data field corresponding to the input share.

[0031] The activation module is used to identify critical logic gates whose fan-out value and / or number of input sources exceed a preset threshold during circuit calculation. The committee nodes collaboratively generate non-interactive zero-knowledge proofs for the calculation correctness of each critical logic gate. The critical logic gate is activated only after the proof is verified.

[0032] The storage module is used to generate an aggregate signature by the committee node based on the results of calculations of all gate circuits, and to anchor the aggregate signature to the data block for storage.

[0033] Optionally, each participating node shares its data block with a subset of committee nodes elected based on historical behavior reputation scores via a verifiable secret sharing protocol, including:

[0034] Periodically based on the online duration of each node Historical mission success rate Data validation pass rate Using the weighted summation formula Calculate the historical behavior reputation score S for each node, where , , For preset weighting factors and ;

[0035] Nodes with scores S higher than a preset threshold are included in the candidate pool, and a specific number of nodes are randomly selected from the candidate pool to form the committee node subset.

[0036] Optionally, the process involves a dominant node from the subset of committee nodes taking a global commitment, aggregated from the initial data share commitments of all parties, as input, and generating a random vector using a verifiable random function, including:

[0037] Based on the current registration round number, a leading node is designated from a subset of committee nodes using a deterministic algorithm;

[0038] The dominant node takes the global commitment as input to a verifiable random function to generate a 256-bit random vector and a zero-knowledge proof.

[0039] The leading node broadcasts the random vector and the zero-knowledge proof to the other members of the committee. The other member nodes verify the validity of the proof. If the verification is successful, the 256-bit random vector is used as a common initialization parameter.

[0040] Optionally, when performing the AND gate calculation of the GMW protocol Boolean operation circuit, switching between an unintentional transmission protocol based on the discrete logarithm problem and an unintentional transmission protocol based on lattice ciphers, according to the sensitivity index of the original data field corresponding to the input share, includes:

[0041] The patient identification and contact information fields are defined as having a sensitivity index of level 5.

[0042] The fields for medical records and medication use history are defined as sensitivity index level 4;

[0043] Define the routine vital signs data field as a sensitivity index of 1 to 3;

[0044] When the sensitivity index of the original data field corresponding to the input share of the AND gate computation is level 4 to 5, an inadvertent transmission protocol based on lattice cryptography is adopted.

[0045] When the sensitivity index is between level 1 and level 3, an unintentional transmission protocol based on the discrete logarithm problem is adopted.

[0046] Optionally, the key logic gate that identifies the fan-out value and / or the number of input sources exceeding a preset threshold includes:

[0047] Before circuit calculation, static analysis is performed on the Boolean operation circuit. Logic gates with a fan-out value exceeding 32 and logic gates with more than 16 input sources are identified as critical logic gates.

[0048] Optionally, the committee nodes collaboratively generate non-interactive zero-knowledge proofs for the computational correctness of each critical logic gate, including:

[0049] For each identified critical logic gate, the input and output shares of the critical logic gate at each node of the committee are used as secret inputs, and the circuit definition of the critical logic gate is used as common inputs. They collaboratively execute the bulletproofs protocol to generate a non-interactive zero-knowledge proof that proves the correctness of the input-output relationship of the logic gate, and attach the generated proof to the output share of the critical logic gate.

[0050] Optionally, the generation of the aggregate signature by the committee node based on the results of calculations by all gate circuits includes:

[0051] Each node in the committee uses its BLS private key to sign the hash value calculated by concatenating the hash value of the data block with the result of the gate circuit calculation, thus generating a partial signature.

[0052] The leading node collects partial signatures generated by all committee member nodes and aggregates these partial signatures into a BLS aggregate signature with constant length.

[0053] Compared with the prior art, the present invention has the following beneficial effects:

[0054] This invention proposes a secure and verifiable method and system for tamper-proof registration of nationwide dialysis case data. By utilizing verifiable random functions to generate common parameters, the possibility of a dominant node unilaterally manipulating the computation process is reduced. Differentiated cryptographic protocols are employed at key computational stages for data of varying sensitivity, ensuring core data is protected against computational attacks while maintaining overall computational efficiency. Non-interactive zero-knowledge proof verification of the computation results of key logic gates enables efficient supervision of complex computation processes, promptly detecting and preventing malicious computations and guaranteeing the correctness of results. Aggregate signatures are used to anchor data, providing immutability and traceability guarantees, thus enhancing the security and credibility of large-scale collaborative registration of medical data. Attached Figure Description

[0055] Figure 1 This is a flowchart of Example 1;

[0056] Figure 2 This is a schematic diagram illustrating the switching protocol based on the sensitivity index.

[0057] Figure 3 A schematic diagram for generating aggregate signatures. Detailed Implementation

[0058] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this invention, and not all of them. Based on the embodiments of this invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this invention. It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this invention are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of related data must comply with relevant laws, regulations, and standards, and corresponding operation entry points are provided for users to choose to authorize or refuse.

[0059] Example 1

[0060] like Figure 1 As shown, a blockchain-based method for preventing tampering with national dialysis case registration data includes the following steps:

[0061] S1, the dialysis case data to be registered by each participating node is divided into data blocks; each participating node shares its data block with a subset of committee nodes elected based on historical behavior reputation scores through a verifiable secret sharing protocol, generating an initial data share bound to the hash value of the data block; a leading node in the subset of committee nodes takes the global commitment formed by aggregating the commitments of the initial data shares of each party as input, generates a random vector through a verifiable random function, and uses the random vector as a common initialization parameter of the GMW protocol Boolean operation circuit;

[0062] For example, a hospital node packages 100 newly added dialysis case records for the day into a data block and calculates its SHA256 hash value. All nodes in the network maintain a reputation score based on historical online time, task success rate, and honest computation records. Nodes with the highest reputation scores are selected as committee members. The hospital node, acting as the sharer, uses the Feldman verifiable secret sharing scheme, sharing each bit of the data block as a secret with all committee members. During the sharing process, the sharer's commitment to the sharing polynomial constructed for the secret is bound to the hash value of the data block, ensuring that the share corresponds to specific data content.

[0063] In one embodiment, each participating node shares its data block with a subset of committee nodes elected based on historical behavior reputation scores through a verifiable secret sharing protocol. Specifically, each participating node treats a data block to be registered as a secret S and constructs a polynomial, for example... The constant term is the secret S, which calculates a separate share for each node i in the committee, i.e. The share is secretly sent to the corresponding node. A public commitment to the entire polynomial P(x) is also broadcast, for example, through encryption or authentication. , , Equivalent. After receiving their share P(i), each node of the committee can use the public commitment to verify that the share they received does indeed conform to the definition of a polynomial, thereby confirming that the shares received by all members come from the same and correctly encoded secret S.

[0064] The node with the highest reputation score in the committee is designated as the leader node. All hospital nodes participating in data sharing broadcast their respective polynomial commitments to the committee when performing verifiable secret sharing. The leader node concatenates all received commitments into a long string and calculates its hash value as a global commitment. Using this global commitment as input, the leader node executes a VDF based on repeated square operations, outputting a result and a corresponding proof of correctness after a preset time delay. After all committee members verify the proof, the output of the VDF is used as a common seed to generate consistent Beaver triplet shares for AND gates in the GMW protocol. The GMW protocol Boolean operation circuit represents functions or operations in the GMW protocol as Boolean circuits, employing a series of basic logical operations, namely combinations of AND, OR, NOT, or XOR gates.

[0065] In one embodiment, each participating node shares its data block with a subset of committee nodes elected based on historical behavior reputation scores via a verifiable secret sharing protocol, including:

[0066] Periodically based on the online duration of each node Historical mission success rate Data validation pass rate Using the weighted summation formula Calculate the historical behavior reputation score S for each node, where , , For preset weighting factors and ;

[0067] Nodes with scores S higher than a preset threshold are included in the candidate pool, and a specific number of nodes are randomly selected from the candidate pool to form the committee node subset.

[0068] For example, online time is weighted at 0.5, historical task success rate at 0.3, and data verification pass rate at 0.2. A node with 300 hours of online time, a 98% task success rate, and a 95% data verification pass rate will have a final reputation score of 198.4. In contrast, a node with only 50 hours of online time and an 80% task success rate might only score 64. Only nodes with scores above a reputation threshold, such as 100, are eligible to be selected into the candidate pool, thus filtering out poorly performing or potentially malicious nodes. To prevent centralization risks and increase the difficulty of attacks, 10 nodes are randomly selected from the candidate pool of all high-scoring nodes, for example, a pool containing 50 qualified nodes, to form a committee to execute the current round of computation tasks. This random selection mechanism ensures both the reliability of the committee members and decentralization.

[0069] In one embodiment, the process of generating a random vector using a verifiable random function, with input from a dominant node in the subset of committee nodes, aggregating the initial data share commitments of each party, includes:

[0070] Based on the current registration round number, a leading node is designated from a subset of committee nodes using a deterministic algorithm;

[0071] The dominant node takes the global commitment as input to a verifiable random function to generate a 256-bit random vector and a zero-knowledge proof.

[0072] The leading node broadcasts the random vector and the zero-knowledge proof to the other members of the committee. The other member nodes verify the validity of the proof. If the verification is successful, the 256-bit random vector is used as a common initialization parameter.

[0073] The selection of the dominant node is open, transparent, and reproducible. For example, in a committee with 10 nodes, it can be agreed that in the 5th round of calculation, the dominant node is determined by taking the round number modulo the committee size, i.e., 5 modulo 10, which results in 5. Therefore, the node with index 5 becomes the dominant node, avoiding disputes or manipulation.

[0074] The leading node executes a verifiable random function, taking a 512-bit hash value that aggregates the data commitments of all participants as input. This hash value represents the global initial state for this round of computation. After the function operation, a 256-bit random vector is generated, along with a proof. The leading node broadcasts this vector and proof to the other nine committee members. The other members independently verify the proof using the leading node's public key and the global commitment, confirming that the random vector was indeed legally generated from the specified input and not arbitrarily fabricated by the leading node. After successful verification, all members reach a consensus and adopt the 256-bit vector as the unified random seed in subsequent encryption protocols. The global commitment can be generated using hashing or elliptic curve point addition. After obtaining the common initialization parameters, all committee members load these parameters before starting to compute the logic gates in the circuit. During AND gate computation, the specific bits of the common initialization parameters used are determined according to the order of the AND gates; for example, when computing the first AND gate in the circuit, bits 1 to 1k of the common parameters are used.

[0075] S2, when performing the AND gate calculation of the GMW protocol Boolean operation circuit, the system switches between the unintentional transmission protocol based on the discrete logarithm problem and the unintentional transmission protocol based on lattice cipher according to the sensitivity index of the original data field corresponding to the input share.

[0076] Each input segment processed by the Boolean operation circuit can be traced back to its original data field, such as the patient's ID number, age, or treatment plan. Sensitivity indices are pre-defined for different fields; the ID number has an index of 10, and the age has an index of 3. When the input segment for the AND gate computation originates from the ID number field, because its index is higher than the preset quantum security threshold of 5, a lattice cryptographic inadvertent transmission protocol based on the LWE problem is invoked to complete the computation. When the input segment originates from the age field, because its index is lower than the threshold, an IKNP inadvertent transmission protocol based on the elliptic curve discrete logarithm problem is invoked, such as... Figure 2 As shown, this is to achieve higher computational efficiency. Among them, the unintentional transmission protocol based on the discrete logarithm problem utilizes the discrete logarithm problem, while the unintentional transmission protocol based on lattice ciphers utilizes either lattice ciphers or the lattice problem. Both are unintentional transmission protocols, but their specific difficulty differs. In another embodiment, the protocol switches between different difficulty levels based on the sensitivity index; data with a high sensitivity index uses a high-difficulty unintentional transmission protocol, and vice versa.

[0077] In one embodiment, the switching between an unintentional transmission protocol based on the discrete logarithm problem and an unintentional transmission protocol based on lattice cryptography, according to the sensitivity index of the original data field corresponding to the input share, during the execution of the AND gate calculation of the GMW protocol Boolean operation circuit, includes:

[0078] The patient identification and contact information fields are defined as having a sensitivity index of level 5.

[0079] The fields for medical records and medication use history are defined as sensitivity index level 4;

[0080] Define the routine vital signs data field as a sensitivity index of 1 to 3;

[0081] When the sensitivity index of the original data field corresponding to the input share of the AND gate computation is level 4 to 5, an inadvertent transmission protocol based on lattice cryptography is adopted.

[0082] When the sensitivity index is between level 1 and level 3, an unintentional transmission protocol based on the discrete logarithm problem is adopted.

[0083] In a typical scenario of joint analysis of medical data, the data contains multiple fields with varying sensitivities. For example, a patient's ID number has the highest sensitivity level (Level 5), their medical records are Level 4, while routine vital signs such as blood pressure and heart rate are at a lower Level 2. When a secure multi-party computation executes an AND gate whose operand involves a secret share of the patient's ID number, it identifies the corresponding Level 5 sensitivity and invokes an inadvertent transmission protocol based on lattice cryptography to complete the AND gate computation. Although this protocol has a significant computational overhead—for example, requiring 80 milliseconds to complete one operation—it can withstand attacks from future quantum computers, providing long-term security for core privacy data. Conversely, when another AND gate computation processes a secret share of blood pressure data (Level 2 sensitivity), it switches to an inadvertent transmission protocol based on the discrete logarithm problem. This protocol is extremely fast, requiring only 5 milliseconds per operation, sufficient to meet current security requirements. Thus, while ensuring the absolute security of the most critical data, it significantly improves overall computational efficiency.

[0084] S3, during the circuit calculation process, key logic gates whose fan-out value and / or number of input sources exceed a preset threshold are identified. The committee nodes collaboratively generate non-interactive zero-knowledge proofs for the calculation correctness of each key logic gate. The key logic gate is activated only after the proof is verified.

[0085] During the circuit design phase, static analysis is performed on all logic gates. For example, an AND gate that aggregates risk level assessment results from multiple hospital nodes, with more than 10 input sources, is marked as a critical logic gate. When this gate is computed, the protocol pauses. All committee members use their respective input and output shares to collaboratively participate in a Groth16 zero-knowledge proof generation protocol, jointly generating a short proof that the input-output relationship of the AND gate is correct. The short proof is broadcast to all members, and each member independently verifies it. Only after successful verification is the output share of the gate used to continue the computation of subsequent circuits. If not activated, the computation result of the logic gate is considered invalid and will not be used in any subsequent operations.

[0086] In one embodiment, the key logic gate that identifies the fan-out value and / or the number of input sources exceeding a preset threshold includes:

[0087] Before circuit calculation, static analysis is performed on the Boolean operation circuit. Logic gates with a fan-out value exceeding 32 and logic gates with more than 16 input sources are identified as critical logic gates.

[0088] Before the computation task begins, the system loads and parses the logic diagram of the entire circuit. It does not perform actual calculations, but instead iterates through each logic gate, checking its connections.

[0089] For example, in the analysis process, an AND gate G1, whose calculation result is used as the input to 40 subsequent different logic gates, is considered a critical logic gate because its fan-out value of 40 exceeds the preset threshold of 32. An error in G1's calculation result will propagate widely, potentially causing serious deviations in the overall computation result. Similarly, another OR gate G2 aggregates the output signals from 20 different upstream logic gates. Because its number of input sources of 20 exceeds the preset threshold of 16, G2 is also marked as a critical logic gate. Such gates are typically key nodes in information aggregation, and their correctness directly affects the accuracy of an important intermediate state.

[0090] In one embodiment, the committee nodes collaboratively generate non-interactive zero-knowledge proofs for the computational correctness of each critical logic gate, including:

[0091] For each identified critical logic gate, the input and output shares of the critical logic gate at each node of the committee are used as secret inputs, and the circuit definition of the critical logic gate is used as common inputs. They collaboratively execute the bulletproofs protocol to generate a non-interactive zero-knowledge proof that proves the correctness of the input-output relationship of the logic gate, and attach the generated proof to the output share of the critical logic gate.

[0092] Taking the previously identified key AND gate G1 as an example, this gate has two inputs A and B, and one output C. Under the secure multi-party computation framework, each member of the committee, for example, 10 members, holds a secret share of the inputs Ai and Bi, as well as the calculated output share Ci.

[0093] To prove the correctness of G1's computation, the 10 committee members will collaboratively initiate a Bulletproofs generation process. During this process, the type of the logic gate (i.e., an AND gate) and its input-output relationship C equal to A and B are provided to the protocol as public information. Each member's respective shares Ai, Bi, and Ci serve as their secret inputs. Through multiple rounds of collaborative computation, a non-interactive zero-knowledge proof can be constructed, for example, using only 675 bytes of data, without revealing their shares to each other. This non-interactive zero-knowledge proof can verify to any third party that the set of output shares Ci held by all members is indeed obtained by correctly ANDing the sets of input shares Ai and Bi. The non-interactive zero-knowledge proof is attached to G1's output shares and flows with the data, providing a trust anchor for the most vulnerable link in the entire computation chain.

[0094] S4, the committee node generates an aggregate signature based on the results of calculations of all gate circuits, and anchors the aggregate signature to the data block for storage.

[0095] After the entire Boolean circuit calculation is completed, each committee member receives a share of the final result. They reconstruct the plaintext calculation result by broadcasting their respective shares and performing an XOR operation, such as a report containing statistical analysis indicators for all cases. Each committee member uses their respective BLS signing private key to sign the hash value of the report, generating their own partial signature. After collecting more than two-thirds of the valid partial signatures, any node can aggregate these partial signatures into a constant-size aggregate signature using BLS signing or hashing, such as... Figure 3 As shown, a transaction is created that includes the original data block hash, the plaintext calculation result, and the aggregate signature, and this transaction is submitted to the underlying blockchain for on-chain storage.

[0096] In one embodiment, the generation of the aggregate signature by the committee node based on the results of calculations by all gate circuits includes:

[0097] Each node in the committee uses its BLS private key to sign the hash value calculated by concatenating the hash value of the data block with the result of the gate circuit calculation, thus generating a partial signature.

[0098] The leading node collects partial signatures generated by all committee member nodes and aggregates these partial signatures into a BLS aggregate signature with constant length.

[0099] Once the entire Boolean circuit has finished executing, the final calculation result is obtained, such as a 32-bit integer representing the statistical result. First, obtain a SHA256 hash value for all original input data blocks, such as a string like ABCD. Then, concatenate this hash value with the calculated 32-bit integer result, and calculate another SHA256 hash for this concatenated new string to obtain the message to be signed.

[0100] Each member of the committee signs the hash value using their unique BLS private key, thus generating a partial signature. For example, node one generates partial signature S1, node two generates S2, and so on. These partial signatures are then sent to the master node. After collecting all 10 partial signatures, the master node executes the BLS aggregation algorithm to merge the 10 independent signatures into an aggregate signature. The final aggregate signature is not only small in size but also includes the mutual approval of all committee members, and anyone can verify the signature using the committee's aggregate public key.

[0101] Example 2

[0102] A blockchain-based national dialysis case registration data tamper-proof system includes:

[0103] The initialization module is used to divide the dialysis case data to be registered by each participating node into data blocks; each participating node shares its data block with a subset of committee nodes elected based on historical behavior reputation scores through a verifiable secret sharing protocol, generating an initial data share bound to the hash value of the data block; a leading node in the subset of committee nodes takes the global commitment formed by aggregating the commitments of the initial data shares of all parties as input, generates a random vector through a verifiable random function, and uses the random vector as a common initialization parameter of the GMW protocol Boolean operation circuit;

[0104] The switching module is used to switch between an unintentional transmission protocol based on the discrete logarithm problem and an unintentional transmission protocol based on lattice cryptography when performing the AND gate calculation of the Boolean operation circuit of the GMW protocol, according to the sensitivity index of the original data field corresponding to the input share.

[0105] The activation module is used to identify critical logic gates whose fan-out value and / or number of input sources exceed a preset threshold during circuit calculation. The committee nodes collaboratively generate non-interactive zero-knowledge proofs for the calculation correctness of each critical logic gate. The critical logic gate is activated only after the proof is verified.

[0106] The storage module is used to generate an aggregate signature by the committee node based on the results of calculations of all gate circuits, and to anchor the aggregate signature to the data block for storage.

[0107] In one embodiment, each participating node shares its data block with a subset of committee nodes elected based on historical behavior reputation scores via a verifiable secret sharing protocol, including:

[0108] Periodically based on the online duration of each node Historical mission success rate Data validation pass rate Using the weighted summation formula Calculate the historical behavior reputation score S for each node, where , , For preset weighting factors and ;

[0109] Nodes with scores S higher than a preset threshold are included in the candidate pool, and a specific number of nodes are randomly selected from the candidate pool to form the committee node subset.

[0110] In one embodiment, the process of generating a random vector using a verifiable random function, with input from a dominant node in the subset of committee nodes, aggregating the initial data share commitments of each party, includes:

[0111] Based on the current registration round number, a leading node is designated from a subset of committee nodes using a deterministic algorithm;

[0112] The dominant node takes the global commitment as input to a verifiable random function to generate a 256-bit random vector and a zero-knowledge proof.

[0113] The leading node broadcasts the random vector and the zero-knowledge proof to the other members of the committee. The other member nodes verify the validity of the proof. If the verification is successful, the 256-bit random vector is used as a common initialization parameter.

[0114] In one embodiment, the switching between an unintentional transmission protocol based on the discrete logarithm problem and an unintentional transmission protocol based on lattice cryptography, according to the sensitivity index of the original data field corresponding to the input share, during the execution of the AND gate calculation of the GMW protocol Boolean operation circuit, includes:

[0115] The patient identification and contact information fields are defined as having a sensitivity index of level 5.

[0116] The fields for medical records and medication use history are defined as sensitivity index level 4;

[0117] Define the routine vital signs data field as a sensitivity index of 1 to 3;

[0118] When the sensitivity index of the original data field corresponding to the input share of the AND gate computation is level 4 to 5, an inadvertent transmission protocol based on lattice cryptography is adopted.

[0119] When the sensitivity index is between level 1 and level 3, an unintentional transmission protocol based on the discrete logarithm problem is adopted.

[0120] In one embodiment, the key logic gate that identifies the fan-out value and / or the number of input sources exceeding a preset threshold includes:

[0121] Before circuit calculation, static analysis is performed on the Boolean operation circuit. Logic gates with a fan-out value exceeding 32 and logic gates with more than 16 input sources are identified as critical logic gates.

[0122] In one embodiment, the committee nodes collaboratively generate non-interactive zero-knowledge proofs for the computational correctness of each critical logic gate, including:

[0123] For each identified critical logic gate, the input and output shares of the critical logic gate at each node of the committee are used as secret inputs, and the circuit definition of the critical logic gate is used as common inputs. They collaboratively execute the bulletproofs protocol to generate a non-interactive zero-knowledge proof that proves the correctness of the input-output relationship of the logic gate, and attach the generated proof to the output share of the critical logic gate.

[0124] In one embodiment, the generation of the aggregate signature by the committee node based on the results of calculations by all gate circuits includes:

[0125] Each node in the committee uses its BLS private key to sign the hash value calculated by concatenating the hash value of the data block with the result of the gate circuit calculation, thus generating a partial signature.

[0126] The leading node collects partial signatures generated by all committee member nodes and aggregates these partial signatures into a BLS aggregate signature with constant length.

[0127] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, compact disc read-only memory (CD-ROM), optical storage, etc.) containing computer-usable program code.

[0128] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0129] The above description is merely an embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of the present invention should be included within the scope of the claims of the present invention.

Claims

1. A blockchain-based method for preventing tampering with national dialysis case registration data, characterized in that: Includes the following steps: The dialysis case data to be registered by each participating node is divided into data blocks; each participating node shares its data block with a subset of committee nodes elected based on historical behavior reputation scores through a verifiable secret sharing protocol, generating an initial data share bound to the hash value of the data block; a leading node in the subset of committee nodes takes the global commitment formed by aggregating the commitments of the initial data shares of each party as input, generates a random vector through a verifiable random function, and uses the random vector as a common initialization parameter of the GMW protocol Boolean operation circuit; When performing the AND gate calculation of the GMW protocol Boolean operation circuit, the system switches between an unintentional transmission protocol based on the discrete logarithm problem and an unintentional transmission protocol based on lattice cryptography, according to the sensitivity index of the original data field corresponding to the input share. During circuit calculation, critical logic gates whose fan-out value and / or number of input sources exceed a preset threshold are identified. The committee nodes collaboratively generate non-interactive zero-knowledge proofs for the calculation correctness of each critical logic gate. The critical logic gate is activated only after the proof is verified. The committee node generates an aggregate signature based on the calculation results of all gate circuits, and anchors the aggregate signature to the data block for storage; When performing the AND gate calculation of the GMW protocol Boolean operation circuit, the switching between the unintentional transmission protocol based on the discrete logarithm problem and the unintentional transmission protocol based on lattice ciphers is performed according to the sensitivity index of the original data field corresponding to the input share, including: The patient identification and contact information fields are defined as having a sensitivity index of level 5. The fields for medical records and medication use history are defined as sensitivity index level 4; Define the routine vital signs data field as a sensitivity index of 1 to 3; When the sensitivity index of the original data field corresponding to the input share of the AND gate computation is level 4 to 5, an inadvertent transmission protocol based on lattice cryptography is adopted. When the sensitivity index is between level 1 and level 3, an unintentional transmission protocol based on the discrete logarithm problem is adopted. The committee nodes collaboratively generate non-interactive zero-knowledge proofs for the computational correctness of each key logic gate, including: For each identified critical logic gate, the input and output shares of the critical logic gate at each node of the committee are used as secret inputs, and the circuit definition of the critical logic gate is used as common inputs. They collaboratively execute the bulletproofs protocol to generate a non-interactive zero-knowledge proof that proves the correctness of the input-output relationship of the logic gate, and attach the generated proof to the output share of the critical logic gate.

2. The method for preventing tampering of national dialysis case registration data based on blockchain according to claim 1, characterized in that, Each participating node shares its data block with a subset of committee nodes elected based on historical behavior reputation scores via a verifiable secret sharing protocol, including: Periodically based on the online duration of each node Historical mission success rate Data validation pass rate Using the weighted summation formula Calculate the historical behavior reputation score S for each node, where , , For preset weighting factors and ; Nodes with scores S higher than a preset threshold are included in the candidate pool, and a preset number of nodes are randomly selected from the candidate pool to form the committee node subset.

3. The method for preventing tampering of national dialysis case registration data based on blockchain according to claim 1, characterized in that, The process involves a dominant node from a subset of committee nodes taking a global commitment, aggregated from the initial data share commitments of all parties, as input, and generating a random vector using a verifiable random function, including: Based on the current registration round number, a leading node is designated from a subset of committee nodes using a deterministic algorithm; The dominant node takes the global commitment as input to a verifiable random function to generate a 256-bit random vector and a zero-knowledge proof. The leading node broadcasts the random vector and the zero-knowledge proof to the other members of the committee. The other member nodes verify the validity of the proof. If the verification is successful, the 256-bit random vector is used as a common initialization parameter.

4. The method for preventing tampering of national dialysis case registration data based on blockchain according to claim 1, characterized in that, The key logic gates that identify fan-out values ​​and / or the number of input sources exceeding a preset threshold include: Before circuit calculation, static analysis is performed on the Boolean operation circuit. Logic gates with a fan-out value exceeding 32 and logic gates with more than 16 input sources are identified as critical logic gates.

5. The method for preventing tampering of national dialysis case registration data based on blockchain according to claim 1, characterized in that, The generation of the aggregate signature by the committee node based on the calculation results of all gate circuits includes: Each node in the committee uses its BLS private key to sign the hash value calculated by concatenating the hash value of the data block with the result of the gate circuit calculation, thus generating a partial signature. The leading node collects partial signatures generated by all committee member nodes and aggregates these partial signatures into a BLS aggregate signature with constant length.

6. A blockchain-based national dialysis case registration data anti-tampering system, characterized in that, include: The initialization module is used to divide the dialysis case data to be registered by each participating node into data blocks; Each participating node shares its data block with a subset of committee nodes elected based on historical behavior reputation scores through a verifiable secret sharing protocol, generating an initial data share bound to the hash value of the data block; a leading node in the subset of committee nodes takes a global commitment aggregated from the commitments of the parties' initial data shares as input, generates a random vector through a verifiable random function, and uses the random vector as a common initialization parameter for the GMW protocol Boolean operation circuit; The switching module is used to switch between an unintentional transmission protocol based on the discrete logarithm problem and an unintentional transmission protocol based on lattice cryptography when performing the AND gate calculation of the Boolean operation circuit of the GMW protocol, according to the sensitivity index of the original data field corresponding to the input share. The activation module is used to identify critical logic gates whose fan-out value and / or number of input sources exceed a preset threshold during circuit calculation. The committee nodes collaboratively generate non-interactive zero-knowledge proofs for the calculation correctness of each critical logic gate. The critical logic gate is activated only after the proof is verified. The storage module is used to generate an aggregate signature by the committee node based on the results of calculations of all gate circuits, and to anchor the aggregate signature to the data block for storage; When performing the AND gate calculation of the GMW protocol Boolean operation circuit, the switching between the unintentional transmission protocol based on the discrete logarithm problem and the unintentional transmission protocol based on lattice ciphers is performed according to the sensitivity index of the original data field corresponding to the input share, including: The patient identification and contact information fields are defined as having a sensitivity index of level 5. The fields for medical records and medication use history are defined as sensitivity index level 4; Define the routine vital signs data field as a sensitivity index of 1 to 3; When the sensitivity index of the original data field corresponding to the input share of the AND gate computation is level 4 to 5, an inadvertent transmission protocol based on lattice cryptography is adopted. When the sensitivity index is between level 1 and level 3, an unintentional transmission protocol based on the discrete logarithm problem is adopted. The committee nodes collaboratively generate non-interactive zero-knowledge proofs for the computational correctness of each key logic gate, including: For each identified critical logic gate, the input and output shares of the critical logic gate at each node of the committee are used as secret inputs, and the circuit definition of the critical logic gate is used as common inputs. They collaboratively execute the bulletproofs protocol to generate a non-interactive zero-knowledge proof that proves the correctness of the input-output relationship of the logic gate, and attach the generated proof to the output share of the critical logic gate.

7. The blockchain-based national dialysis case registration data anti-tampering system according to claim 6, characterized in that, Each participating node shares its data block with a subset of committee nodes elected based on historical behavior reputation scores via a verifiable secret sharing protocol, including: Periodically based on the online duration of each node Historical mission success rate Data validation pass rate Using the weighted summation formula Calculate the historical behavior reputation score S for each node, where , , For preset weighting factors and ; Nodes with scores S higher than a preset threshold are included in the candidate pool, and a preset number of nodes are randomly selected from the candidate pool to form the committee node subset.

8. The blockchain-based national dialysis case registration data anti-tampering system according to claim 6, characterized in that, The process involves a dominant node from a subset of committee nodes taking a global commitment, aggregated from the initial data share commitments of all parties, as input, and generating a random vector using a verifiable random function, including: Based on the current registration round number, a leading node is designated from a subset of committee nodes using a deterministic algorithm; The dominant node takes the global commitment as input to a verifiable random function to generate a 256-bit random vector and a zero-knowledge proof. The leading node broadcasts the random vector and the zero-knowledge proof to the other members of the committee. The other member nodes verify the validity of the proof. If the verification is successful, the 256-bit random vector is used as a common initialization parameter.

Citation Information

Patent Citations

  • (2, 3) threshold SM2 signature method without trusted center

    CN116961899A

  • Block chain revision method based on weighted voting

    CN120017280A