Blockchain-based data security protection method for biological sample database
By employing protective encryption and distributed storage for the biological sample database, combined with blockchain and biometric verification, the issues of data authenticity and access permission forgery are resolved, thus achieving data security and validity.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- 华域生物科技(天津)有限公司
- Filing Date
- 2025-08-26
- Publication Date
- 2026-06-16
AI Technical Summary
Existing data security protection technologies cannot effectively ensure the authenticity of data, and access permission verification methods are simple and easily forged, leading to data leaks or tampering that cannot be recovered.
The biological sample data in the biological sample database is protected by encryption, generating protected data and storing it in a distributed manner. Combined with blockchain technology, user-specific biological data is generated through biometrics, and the data is restored after verifying the user's identity.
It improves the security and effectiveness of data security protection, ensures the uniqueness and complexity of access permissions, prevents data tampering, and enables effective data recovery.
Smart Images

Figure CN121167753B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security protection technology, specifically a data security protection method for a blockchain-based biological sample database. Background Technology
[0002] Data security protection technology refers to the use of technical and management measures to protect the confidentiality, integrity, availability, and compliance of digital data associated with biological samples during storage, transmission, and use, preventing unauthorized access, tampering, disclosure, or damage, while meeting bioethical and legal requirements.
[0003] Existing data security technologies typically employ encrypted storage to protect data. However, they lack the ability to effectively verify and restore secure data when it is maliciously tampered with. They only prevent others from stealing the specific content, failing to guarantee the authenticity of the secure data. Furthermore, existing data security technologies often only add usernames to an authorized user list when granting access. This method is weak in analyzing user permissions, making it easy for others to forge permissions through backend vulnerabilities. Moreover, existing data security technologies are ineffective in performing security checks. In the process of protection, fixed algorithms are usually used to calculate ciphertext, which lacks variability. For example, in the patent application with publication number CN115801432A, a "Cloud Data Center High-Efficiency Protection Security Service Management System and Design Method" is disclosed. This solution protects cloud data by registering cloud access permissions for users and using simple permission management. The security of the protection is weak. Existing data security protection technologies still cannot ensure the authenticity of the protected data. At the same time, the methods used to verify access permissions are too simple, making it easy for others to forge permissions through backend vulnerabilities, resulting in data leakage or tampering that cannot be restored. Summary of the Invention
[0004] This invention aims to at least partially address one of the technical problems in the prior art. It involves protective encryption of biological sample data in a biological sample database, converting the biological sample data into protective data, and then analyzing verification data of the protective data. This verification data is used to verify the integrity of the protective data. Storage units in a blockchain storage platform are assigned storage numbers, and the protective data and verification data are then distributed and stored based on the blockchain. During distributed storage, storage modifications are made to the protective data and verification data based on the storage numbers. Next, the biometrics of users with access permissions are obtained and converted into feature data. Based on the feature data, user-specific biometric data is generated. Finally, when a user accesses the biological sample database, the user's biometric data is verified. If the verification is successful, the protective data is verified using the verification data. If the protective data is normal, it is restored to biological sample data. This addresses the shortcomings of existing data security protection technologies, which cannot guarantee the authenticity of secure data and use overly simplistic methods for verifying access permissions, making it easy for others to forge permissions through backend vulnerabilities, leading to data leakage or tampering that cannot be restored.
[0005] To achieve the above objectives, this application provides a blockchain-based method for data security protection of biological sample databases, comprising the following steps:
[0006] Protective encryption is applied to biological sample data in the biological sample database, converting the biological sample data into protective data.
[0007] Analyze the verification data of the protective data, which is used to verify the integrity of the protective data;
[0008] Distributed storage of protective and verification data based on blockchain;
[0009] Generate biometric data for users with access permissions based on biometric features;
[0010] When a user accesses the biological sample database, the user's biological data is verified. If the verification is successful, the protective data is then verified using the verification data. If the protective data is normal, the protective data is restored to the biological sample data.
[0011] Furthermore, the biological sample data in the biological sample database is subjected to protective encryption processing. Specifically, the biological sample data in the biological sample database is input into the encryption model, and the biological sample data is protected by a symmetric encryption algorithm. The encryption model then outputs the protected data.
[0012] Further, the verification data for the protective data is analyzed. This verification data, used to verify the integrity of the protective data, includes the following sub-steps:
[0013] Obtain the protected data in decimal format and name it Decimal Security Data;
[0014] Number the digits in the decimal secure data, labeling them as Num from left to right. n , where n is a non-zero natural number and n is the index of Num;
[0015] Starting with n=1, obtain Num n and Num n+1 From Num n and Num n+1 A number is randomly selected and labeled as HN. n+1 Calculate Num n ×Num n+1 The calculation result is labeled as HN. n Repeat the analysis with n+2 until Num is reached. n or Num n+1 Until it no longer exists;
[0016] Arrange HN in ascending order of n. n Combine the data to obtain validation data.
[0017] Furthermore, the distributed storage of protective and verification data based on blockchain includes the following sub-steps:
[0018] Assign storage numbers to storage units in the blockchain storage platform;
[0019] Based on blockchain, protective data and verification data are stored in a distributed manner, and storage-based modifications are made to protective data and verification data based on storage numbers during distributed storage.
[0020] Furthermore, assigning storage numbers to storage units in the blockchain storage platform includes the following sub-steps:
[0021] Ensure that the number of storage units is a single digit. If the number of storage units exceeds a single digit, group the storage units to obtain a first number of storage groups. Treat each storage group as a storage unit. The first number is a single digit.
[0022] The memory cells are numbered using the symbol S. i Let S be a sequence of numbers, where i is a positive integer and i is the index of S. i This is the storage number.
[0023] Furthermore, based on blockchain, protective data and verification data are stored in a distributed manner, and storage-based modifications to protective data and verification data are made based on storage numbers during distributed storage, including the following sub-steps:
[0024] Distributed storage is used for protective data and verification data, and the protective data or verification data that needs to be stored is named as the data to be stored;
[0025] Randomly assign the data to be stored to any S. i , obtain S i The sequence number i is marked as I. Find the number in the data to be stored that is the same as I and name it the modified calibration number.
[0026] Mark the digits before and after the modified digit as F- and F+ respectively. Decrease F- by 1. If the decreased F- is negative, increase it by 10. Increase F+ by 1. If the increased F+ is a tens digit, decrease it by 10.
[0027] The modified F- and F+ values corresponding to all the calibration numbers will be named "storeable data" and stored in the corresponding S. i middle.
[0028] Furthermore, generating biometric data for users with access rights based on biometrics includes the following sub-steps:
[0029] Obtain the biometrics of users with access permissions and convert the biometrics into feature data;
[0030] Generate user-specific biological data based on feature data.
[0031] Furthermore, obtaining the biometrics of users with access rights and converting these biometrics into feature data includes the following sub-steps:
[0032] Obtain the biometric features of users with access permissions, wherein the biometric features are fingerprint features, and the fingerprint features include feature point orientation, feature point curvature, and feature point position;
[0033] Biometric features are combined according to the format of "feature point direction, feature point curvature, feature point position" to obtain feature data.
[0034] Furthermore, generating user-specific biological data based on feature data includes the following sub-steps:
[0035] The feature data is converted into a decimal format encoding, which is named feature encoding;
[0036] The number of bits in the statistical feature code is denoted as R. Calculate R / 3 and denot the integer bits of the result as Q.
[0037] Extract the first Q digits from the feature code and label them as T1. Extract the first Q digits from the remaining feature code and label them as T2. Label the remaining feature code as T3.
[0038] Based on the three coordinate points (1,T1), (2,T2), and (3,T3), a polynomial discrete regression analysis is performed to obtain the characteristic regression function, which is in the format Y = a × X. 2 +b×X+c, where Y is T1, T2 and T3, and X is 1, 2 and 3, and a, b and c are constant terms of the feature regression function;
[0039] Calculate a+b+c and name the result "biological data".
[0040] Furthermore, when a user accesses the biosample database, the user's biodata is verified. After successful verification, the protective data is verified against the verification data. If the protective data is normal, the protective data is restored to the biosample data, including the following sub-steps:
[0041] When a user accesses the biological sample database, the user's biological characteristics are verified. If the biological data obtained from the biological characteristic analysis has the necessary access permissions, the user is allowed to access the biological sample data.
[0042] Obtain the protective data and verification data corresponding to the biological sample data that the user needs to access, and name them "Data to be Accessed" and "Parameters to be Verified" respectively. Number the numbers in the data to be accessed and label them as F from left to right. h The numbers in the parameters to be verified are numbered and labeled as D from left to right. g , where h and g are both positive integers, and h is the index of F and g is the index of D;
[0043] Starting with h=1 and g=2, determine D g Is it equal to F? h or F h+1 If yes, then perform the verification check; if no, then increment g by 1 and check D again. g Is it equal to F? h or F h+1 If yes, then perform the verification judgment; otherwise, output a verification data corruption signal.
[0044] If a verification check is performed, then h+2 and g+2 will be executed repeatedly in the loop. g Is it equal to F? h or F h+1 The judgment and processing process continues until F does not exist. h or F h+1 until;
[0045] The verification judgment specifically involves judging F. h ×F h+1 Is it equal to D? g-1 Or D g-2 With D g-1 If the two-digit number is correct, output a protective data normal signal; otherwise, output a protective data abnormal signal.
[0046] If the output of the protective data is normal, the protective data is decrypted. If the output of the protective data is abnormal, the protective data is restored by verifying the data before decryption.
[0047] The beneficial effects of this invention are as follows: This invention performs protective encryption on biological sample data in a biological sample database, converting the biological sample data into protective data. Then, it analyzes the verification data of the protective data, which is used to verify the integrity of the protective data. Storage units in the blockchain storage platform are assigned storage numbers, and the protective data and verification data are then distributed and stored based on the blockchain. Furthermore, during distributed storage, storage modifications are made to the protective data and verification data based on the storage numbers. The advantage lies in the fact that after encrypting the biological sample data, the verification data of the protective data is calculated synchronously. This verification data not only verifies whether the protective data has been tampered with but also restores the tampered protective data. Moreover, during storage, the protective data is modified according to different storage units, adding a certain degree of variability to the protective data and improving the security and effectiveness of data security protection.
[0048] This invention acquires the biometrics of users with access permissions and converts them into feature data. Based on this feature data, it generates user-specific biometric data. Finally, when a user accesses the biometric database, the biometric data is verified. If the verification is successful, the protective data is verified against the protective data. If the protective data is valid, it is restored to biometric data. The advantage is that by combining the user's biometrics with the setting of user access permissions, access permissions cannot be forged. Only access permissions obtained through legitimate channels can access biometric data, further improving the security and effectiveness of data security protection. Attached Figure Description
[0049] Figure 1 This is a flowchart of the steps of the method of the present invention;
[0050] Figure 2 This is a flowchart illustrating the complete steps of data security protection for biological sample databases according to the method of the present invention.
[0051] Figure 3This is a schematic diagram of the structure of an electronic device according to the method of the present invention. Detailed Implementation
[0052] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0053] Example 1, please refer to Figure 1 As shown, this application provides a blockchain-based method for data security protection of biological sample databases, including the following steps:
[0054] Please see Figure 2 As shown, step S1 involves performing protective encryption on the biological sample data in the biological sample database, converting the biological sample data into protective data. Specifically, this involves inputting the biological sample data from the biological sample database into an encryption model, performing protective encryption on the biological sample data using a symmetric encryption algorithm, and outputting protective data from the encryption model.
[0055] In practice, the encryption model employs existing symmetric encryption algorithms. This embodiment focuses on analyzing the verification data of the protective data. Simultaneously, during storage, both the protective and verification data are modified to introduce variability. Biometric features are then incorporated into the access permission settings for analysis, ensuring the uniqueness and complexity of the access permission settings. The data encryption method can utilize any existing symmetric encryption algorithm, which will not be specifically described in this embodiment. Figure 2 It presents a flowchart illustrating the entire process of data security protection for biological sample databases.
[0056] Step S2 involves analyzing the verification data of the protective data, which is used to verify the integrity of the protective data. Step S2 includes the following sub-steps:
[0057] Step S201: Obtain the protective data in decimal format and name it Decimal Security Data;
[0058] Step S202: Number the digits in the decimal security data, labeling them as Num from left to right. n , where n is a non-zero natural number and n is the index of Num;
[0059] Step S203, starting with n=1, obtain Num n and Numn+1 From Num n and Num n+1 A number is randomly selected and labeled as HN. n+1 Calculate Num n ×Num n+1 The calculation result is labeled as HN. n Repeat the analysis with n+2 until Num is reached. n or Num n+1 Until it no longer exists;
[0060] Step S204: Arrange HN in ascending order of n. n Combine the data to obtain validation data;
[0061] In specific implementation, it is assumed that the protective data obtained in this embodiment is "U2Fs" (excluding quotation marks). The protective data listed in this embodiment has a small number of digits, only to facilitate observation of the number of digits and the relationship between different digits during the example process. In actual applications, the length of the protective data varies depending on the length of the biological sample data. The decimal security data is obtained by referring to the ASCII encoding table, and the decimal security data is "855070115", which is numbered as Num. n For a given set of conditions, 1 ≤ n ≤ 9, taking n = 1 as an example, Num1 is 8 and Num2 is 5. When performing random sampling, the same sampling rule is usually used for the same protected data, that is, for each value of n, Num1 is sampled. n As HN n Or, for each value of n, extract Num n+1 As HN n For the protective data listed in this embodiment, Num is selected for extraction. n As HN n HN2 is 8, and HN is calculated. n If the value is 40, then n+2, so n=3. Then analyze Num3 and Num4, and so on, until we get HN1 to HN8. When n=9, there is no Num... 10 Therefore, simply set Num9 to HN9, and the final verification data is 4080507115.
[0062] Step S3 involves distributed storage of protective and verification data based on blockchain technology. Step S3 includes the following sub-steps:
[0063] Step S301: Assign storage numbers to storage units in the blockchain storage platform;
[0064] Step S301 includes the following sub-steps:
[0065] Step S301.1: Ensure that the number of storage units is a single digit. If the number of storage units exceeds a single digit, group the storage units to obtain a first number of storage groups. Treat each storage group as a storage unit. The first number is a single digit.
[0066] Step S301.2: Number the storage cells using the symbol S. i Let S be a sequence of numbers, where i is a positive integer and i is the index of S. i That is, the storage number;
[0067] In this specific implementation, the blockchain storage platform in this embodiment has a total of 14 storage units. Therefore, the storage units are randomly grouped into 9 storage groups, which are then regarded as 9 storage units and numbered as S. i 1≤i≤9, the storage units are limited to 9 because the analysis needs to be combined with the single digits in the subsequent analysis;
[0068] Step S302: Based on the blockchain, protective data and verification data are distributed and stored in a distributed manner, and during distributed storage, protective data and verification data are modified in a storage manner based on the storage number;
[0069] Step S302 includes the following sub-steps:
[0070] Step S302.1: Distribute the protective data and verification data, and name the protective data or verification data that needs to be stored as the data to be stored.
[0071] Step S302.2: Randomly allocate the data to be stored to any S i , obtain S i The sequence number i is marked as I. Find the number in the data to be stored that is the same as I and name it the modified calibration number.
[0072] Step S302.3: Mark the digits before and after the modified digit as F- and F+ respectively. Decrease F- by 1. If the decreased F- is negative, increase it by 10. Increase F+ by 1. If the increased F+ is a tens digit, decrease it by 10.
[0073] Step S302.4: The modified F- and F+ values corresponding to all the driving calibration numbers are named as storable data and stored in the corresponding S. i middle;
[0074] In specific implementation, taking the protective data "855070115" in this embodiment as an example, assuming that "855070115" is allocated to S1 for storage, then I=1. The 1 in "855070115" is marked as calibration data. There are two calibration data. The F- and F+ of the first 1 are 0 and 1 respectively, and the F- and F+ of the second 1 are 1 and 5 respectively. Analyze in the order from front to back. First, subtract one from the F- of the first 1. The result is -1, which is a negative number. Then, increase it by 10 to get 9. After adding one to F+, it becomes 2. At this time, the data to be stored "855070115" is changed to "855079125". Since the second calibration data has been changed to 2, no more data calibration is needed. Therefore, the final storable data is "855079125". Similarly, the verification data "4080507115" is allocated and stored.
[0075] Step S4: Generate biometric data for users with access rights based on biometric features; Step S4 includes the following sub-steps:
[0076] Step S401: Obtain the biometrics of users with access rights and convert the biometrics into feature data;
[0077] Step S401 includes the following sub-steps:
[0078] Step S401.1: Obtain the biometrics of the user with access rights. The biometrics are fingerprint features, which include the feature point orientation, feature point curvature, and feature point position.
[0079] Step S401.2: Combine the biometric features according to the format of "feature point direction, feature point curvature, feature point position" to obtain feature data;
[0080] In practice, when granting access permissions to users, a dedicated access management device is used to collect the user's biometric features. The device then analyzes these features and outputs biometric data to confirm whether the user has the necessary access permissions. This process is not simply adding permissions or adding the user to a whitelist; rather, it involves converting the biometric features into biometric data using a specific method before verification. This prevents others from directly forging access permissions or biometric data through vulnerabilities. For example, a user's biometric features are as follows: feature point direction θ = 45°, feature point curvature k = 0.02, feature point position [120, 85]{r: 35.3, φ: 315°}. The combined feature data is "θ = 45°, k = 0.02, [120, 85]{r: 35.3, φ: 315°}", excluding the quotation marks.
[0081] Step S402: Generate user-specific biological data based on feature data;
[0082] Step S402 includes the following sub-steps:
[0083] Step S402.1: Convert the feature data into a decimal format code and name it the feature code;
[0084] Step S402.2: Calculate the number of bits in the statistical feature code, label it as R, calculate R / 3, and label the integer bits of the calculation result as Q;
[0085] Step S402.3: Extract the first Q digits of the feature code and label them as T1; extract the first Q digits of the remaining feature code and label them as T2; label the remaining feature code as T3.
[0086] Step S402.4: Based on the three coordinate points (1, T1), (2, T2), and (3, T3), perform a multinomial discrete regression analysis to obtain the characteristic regression function. The format of the characteristic regression function is Y = a × X. 2 +b×X+c, where Y is T1, T2 and T3, and X is 1, 2 and 3, and a, b and c are constant terms of the feature regression function;
[0087] Step S402.5: Calculate a+b+c and name the calculation result as biological data;
[0088] In specific implementation, referring to the ASCII encoding table, the feature code is obtained as "95261525317665292107614846485065292914950486529256539312311465306515346516529296665306514953176125". R is 98, and R / 3 ≈ 32.667. Removing the integer part, Q is 32. The first 32 bits of the feature code are then used to obtain T1 as "95261525317665292107614846485065". The last 32 bits of T1 are then used to obtain T2 as "2929149504865292565". The remaining digits after "3931231146530" represent T3, which is "6515346516529296665306514953176125". To ensure the feature regression function doesn't deviate too much, the number of digits in T1, T2, and T3 needs to be standardized to 32 digits. Since T3 has 34 digits, the last two digits are discarded, resulting in "65153465165292966653065149531761". This ensures that T1, T2, and T3 have the same number of digits, preventing excessively large differences in the feature regression function. The final fitted feature regression function is Y = 5.091600019282614e+31×X. 2 -2.1871803084749072e+32×X+2.6306355597232973e+32, where e+31 and e+32 represent 1×10 31 and 1×10 32 The final biometric data obtained is 9.526152531766515e+31. At this point, the biometric data obtained is only the data of a certain feature point in the user's fingerprint features. Analyze the biometric data of all feature points in the user's fingerprint features and form a set, named the biometric set. At this point, others cannot directly obtain access rights, and cannot forge the biometric set through vulnerabilities, because the biometric set needs to be specially processed, rather than simply recording the fingerprint.
[0089] Step S5: When a user accesses the biological sample database, the user's biological data is verified. After successful verification, the protective data is verified using the verification data. If the protective data is normal, the protective data is restored to the biological sample data. Step S5 includes the following sub-steps:
[0090] Step S501: When a user accesses the biological sample database, the user's biological characteristics are verified. If the biological data obtained from the biological characteristic analysis has access rights, the user is allowed to access the biological sample data.
[0091] In practice, when a user accesses the biological sample database, the user's biological characteristics are obtained and analyzed to obtain biological data. Then, it is verified whether all of the user's biological data are within the same set of biological characteristics. If so, the user is allowed to access the biological sample data.
[0092] Step S502: Obtain the protective data and verification data corresponding to the biological sample data that the user needs to access, and name them "data to be accessed" and "parameters to be verified" respectively. Number the numbers in the data to be accessed and label them as F from left to right. h The numbers in the parameters to be verified are numbered and labeled as D from left to right. g , where h and g are both positive integers, and h is the index of F and g is the index of D;
[0093] Step S503, starting with h=1 and g=2, determine D g Is it equal to F? h or F h+1 If yes, then perform the verification check; if no, then increment g by 1 and check D again. g Is it equal to F? h or F h+1 If yes, then perform the verification judgment; otherwise, output a verification data corruption signal.
[0094] In specific implementation, when obtaining the data to be accessed and the parameters to be verified, the data to be accessed and the parameters to be verified are first restored based on the storage unit. For example, if the data to be accessed is 855079125 and its storage unit is 1, then based on the reverse execution derivation of step S302, the actual data to be accessed can be obtained as 855070115. Similarly, the parameter to be verified is obtained as 4080507115, and the number is F. h and D g Where 1≤h≤9, 1≤g≤10, taking h=1 and g=2 as examples, F1 is 8, F2 is 4, D2 is 0, and D g Not equal to F h or F h+1 We increment g by 1, and D3 becomes 8. At this point, D3 = F1, and we perform a verification judgment.
[0095] Step S504: If verification is to be performed, then h+2 and g+2 are executed repeatedly in step D. g Is it equal to F? h or F h+1 The judgment and processing process continues until F does not exist. h or F h+1 until;
[0096] Step S505, the verification judgment specifically involves judging F. h×F h+1 Is it equal to D? g-1 Or D g-2 With D g-1 If the two-digit number is correct, output a protective data normal signal; otherwise, output a protective data abnormal signal.
[0097] Step S506: If the output of the protective data is normal, the protective data is decrypted; if the output of the protective data is abnormal, the protective data is restored by verifying the data and then decrypted.
[0098] In specific implementation, verification judgments need to be performed on F1, F2, D1, D2, and D3. At the same time, h and g are both increased by 2, and step S503 is executed again. When performing the verification judgment, F1×F2=40, and g=3. D1 and D2 together form the number 40, which is equal to F1×F2. Therefore, a normal protective data signal is output. If no verification data corruption signal is output and the normal protective data signal is output in all verification judgments, the protective data is decrypted. If an abnormal protective data signal is output, the protective data is restored through the verification data and then decrypted. Restoring the protective data through the verification data is the reverse derivation of step S2, which will not be described in detail in this embodiment.
[0099] Example 2, please refer to Figure 3 As shown, Figure 3 A schematic diagram of an electronic device is provided, which may include a processor, a communication interface, a memory, and a communication bus. The processor, communication interface, and memory communicate with each other via the communication bus. The memory stores computer-readable instructions, and the processor can invoke these instructions. When the processor executes a computer-readable instruction, it performs steps such as those in a blockchain-based biosample database data security protection method to achieve the following functions: converting biosample data into protective data; analyzing verification data of the protective data; distributing the protective data and verification data based on blockchain; generating biosample data for users with access rights based on biometrics; verifying the user's biosample data; and, upon successful verification, verifying the protective data using the verification data. If the protective data is valid, it is restored to biosample data.
[0100] Furthermore, the logical instructions in the aforementioned memory can be implemented as software functional units and sold or used as independent products, and can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0101] Example 3: This application also provides a computer program product, which includes a computer program stored on a computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the blockchain-based biosample database data security protection method provided by the above methods. This method includes: converting biosample data into protective data; analyzing verification data of the protective data; distributing the protective data and verification data based on blockchain; generating biosample data for users with access rights based on biometrics; verifying the user's biosample data; after successful verification, verifying the protective data using the verification data; and if the protective data is normal, restoring the protective data to biosample data.
[0102] Example 4: This application also provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it performs the steps of the above-mentioned blockchain-based biological sample database data security protection method to achieve the following functions: converting biological sample data into protective data; analyzing verification data of the protective data; distributing the protective data and verification data based on blockchain; generating biological data for users with access rights based on biometrics; verifying the user's biological data, and after successful verification, verifying the protective data using the verification data; if the protective data is normal, restoring the protective data to biological sample data.
[0103] Based on the above description of the embodiments, the embodiments of the present invention can be provided as methods, systems, or computer program products. Based on this understanding, the technical solutions described above, or the parts that contribute to the prior art, can be embodied in the form of software products. These computer software products can be stored in computer-readable storage media, such as ROM / RAM, magnetic disks, optical disks, etc., and include several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or certain parts of the embodiments.
[0104] In the embodiments provided in this application, it should be understood that the disclosed system or method can be implemented in other ways. The embodiments described above are merely illustrative. For example, the division of modules or units is only a logical functional division, and there may be other division methods in actual implementation. Furthermore, multiple modules or units may be combined or integrated into another system, or some features may be ignored or not executed. Additionally, the coupling or direct coupling or communication connection shown or discussed may be through some communication interfaces. The indirect coupling or communication connection between systems, modules, and units may be electrical, mechanical, or other forms.
[0105] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.
Claims
1. A data security protection method for a blockchain-based biological sample database, characterized in that, Includes the following steps: Protective encryption is applied to biological sample data in the biological sample database, converting the biological sample data into protective data. Analyze the verification data of the protective data, which is used to verify the integrity of the protective data; Distributed storage of protective and verification data based on blockchain; Generate biometric data for users with access permissions based on biometrics, obtain the biometrics of users with access permissions and convert the biometrics into feature data, and generate user-specific biometric data based on the feature data; When a user accesses the biological sample database, the user's biological data is verified. If the verification is successful, the protective data is verified using the verification data. If the protective data is normal, the protective data is restored to the biological sample data. The analysis of verification data for protective data, used to verify the integrity of the protective data, includes the following sub-steps: obtaining protective data in decimal format and naming it "Decimal Secure Data"; numbering the digits in the decimal secure data and labeling them as Num from left to right. n Where n is a non-zero natural number and n is the index of Num; starting with n=1, obtain Num n and Num n+1 From Num n and Num n+1 A number is randomly selected and labeled as HN. n+1 Calculate Num n ×Num n+1 The calculation result is labeled as HN. n Repeat the analysis with n+2 until Num is reached. n or Num n+1 Until it no longer exists; sort HN in ascending order of n. n Combine the data to obtain validation data; Generating user-specific biological data based on feature data includes the following sub-steps: converting the feature data into a decimal format code, named the feature code; counting the number of digits in the feature code, labeled R; calculating R / 3, and labeling the integer part of the result as Q; extracting the first Q digits from the feature code, labeled T1; extracting the first Q digits from the remaining feature code, labeled T2; and labeling the remaining feature code as T3; performing multinomial discrete regression analysis based on the three coordinate points (1,T1), (2,T2), and (3,T3) to obtain the feature regression function, the format of which is Y=a×X. 2 +b×X+c, where Y is T1, T2 and T3, and X is 1, 2 and 3, and a, b and c are constant terms of the feature regression function; calculate a+b+c, and name the calculation result as biological data.
2. The data security protection method for blockchain-based biological sample databases according to claim 1, characterized in that, Protective encryption is applied to biological sample data in a biological sample database. Specifically, the biological sample data is input into an encryption model, protected encryption is performed on the biological sample data using a symmetric encryption algorithm, and the encryption model outputs protected data.
3. The data security protection method for blockchain-based biological sample databases according to claim 2, characterized in that, Distributed storage of secure and verification data based on blockchain includes the following sub-steps: Assign storage numbers to storage units in the blockchain storage platform; Based on blockchain, protective data and verification data are stored in a distributed manner, and storage-based modifications are made to protective data and verification data based on storage numbers during distributed storage.
4. The data security protection method for blockchain-based biological sample databases according to claim 3, characterized in that, Assigning storage numbers to storage units in a blockchain storage platform includes the following sub-steps: Ensure that the number of storage units is a single digit. If the number of storage units exceeds a single digit, group the storage units to obtain a first number of storage groups. Treat each storage group as a storage unit. The first number is a single digit. The memory cells are numbered using the symbol S. i Let S be a sequence of numbers, where i is a positive integer and i is the index of S. i This is the storage number.
5. The data security protection method for blockchain-based biological sample databases according to claim 4, characterized in that, Based on blockchain, protective and verification data are stored in a distributed manner. During distributed storage, modifications to the protective and verification data based on storage numbers include the following sub-steps: Distributed storage is used for protective data and verification data, and the protective data or verification data that needs to be stored is named as the data to be stored; Randomly assign the data to be stored to any S. i , obtain S i The sequence number i is marked as I. Find the number in the data to be stored that is the same as I and name it the modified calibration number. Mark the digits before and after the modified digit as F- and F+ respectively. Decrease F- by 1. If the decreased F- is negative, increase it by 10. Increase F+ by 1. If the increased F+ is a tens digit, decrease it by 10. The modified F- and F+ values corresponding to all the calibration numbers will be named "storeable data" and stored in the corresponding S. i middle.
6. The data security protection method for a blockchain-based biological sample database according to claim 5, characterized in that, Obtaining the biometrics of users with access permissions and converting these biometrics into feature data includes the following sub-steps: Obtain the biometric features of users with access permissions, wherein the biometric features are fingerprint features, and the fingerprint features include feature point orientation, feature point curvature, and feature point position; Biometric features are combined according to the format of "feature point direction, feature point curvature, feature point position" to obtain feature data.
7. The data security protection method for blockchain-based biological sample databases according to claim 6, characterized in that, When a user accesses the biosample database, the user's biodata is verified. After successful verification, the protective data is verified against the verification data. If the protective data is normal, the protective data is restored to the biosample data, including the following sub-steps: When a user accesses the biological sample database, the user's biological characteristics are verified. If the biological data obtained from the biological characteristic analysis has the necessary access permissions, the user is allowed to access the biological sample data. Obtain the protective data and verification data corresponding to the biological sample data that the user needs to access, and name them "Data to be Accessed" and "Parameters to be Verified" respectively. Number the numbers in the data to be accessed and label them as F from left to right. h The numbers in the parameters to be verified are numbered and labeled as D from left to right. g , where h and g are both positive integers, and h is the index of F and g is the index of D; Starting with h=1 and g=2, determine D g Is it equal to F? h or F h+1 If yes, then perform the verification check; if no, then increment g by 1 and check D again. g Is it equal to F? h or F h+1 If yes, then perform the verification judgment; otherwise, output a verification data corruption signal. If a verification check is performed, then h+2 and g+2 will be executed repeatedly in the loop. g Is it equal to F? h or F h+1 The judgment and processing process continues until F does not exist. h or F h+1 until; The verification judgment specifically involves judging F. h ×F h+1 Is it equal to D? g-1 Or D g-2 With D g-1 If the two-digit number is correct, output a protective data normal signal; otherwise, output a protective data abnormal signal. If the output of the protective data is normal, the protective data is decrypted. If the output of the protective data is abnormal, the protective data is restored by verifying the data before decryption.
Citation Information
Patent Citations
Cloud data center efficient protection safety service management system and design method
CN115801432A
Block chain integration system for recording biological characteristics
CN115765970A
Security encryption method and system for digital collections
CN119885243A