Data sharing method and device and electronic equipment

By registering and multi-chaining data owners, data requesters, smart contracts, and third-party cloud management entities, and combining this with dynamic path determination, the system addresses the shortcomings in security, efficiency, and flexibility of existing data sharing methods, thus achieving an efficient and secure data sharing process.

CN121792166APending Publication Date: 2026-04-03CHINA MOBILE INTERNET CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-23
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing data sharing methods are inadequate in terms of security, efficiency, and flexibility. They lack dynamic adjustment capabilities, and resource waste is particularly severe under high concurrency and network fluctuations. Cross-node data consistency management is difficult, and the smart contract authentication mechanism is not complex enough.

Method used

By registering data owners, data requesters, smart contracts, and third-party cloud management entities, and employing multi-chain encryption and dynamic path determination strategies, the security and reliability of the data sharing process are ensured, while improving its efficiency and flexibility.

Benefits of technology

It achieves the security and reliability of the data sharing process by combining accurate registration and verification with multi-chain encryption and dynamic transmission paths, while improving the efficiency and flexibility of data sharing and reducing potential risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121792166A_ABST
    Figure CN121792166A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a data sharing method and device and electronic equipment. The scheme comprises the following steps: registering participants; in response to the fact that all the participants complete registration, performing multi-chain encryption processing on the shared data provided by the data owner to obtain encrypted shared data; in response to a detected data acquisition request for target data sent by a data demander, verifying the entity; in response to the fact that the entities pass verification, obtaining target encrypted data according to the encrypted shared data; and determining a target transmission path, and sending the target encrypted data to a data demander through the target transmission path, so that the data demander performs reconstruction processing on the target encrypted data to obtain target data. According to the embodiment of the invention, on the basis of accurately registering and verifying participants, a safer multi-chain encryption processing mode and a dynamic transmission path determination mode are combined, so that the efficiency and the flexibility are improved, and the dynamic adjustment capability is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure generally relates to data processing techniques, and more particularly to a data sharing method, apparatus, and electronic device. Background Technology

[0002] With the rapid development of the Internet of Things (IoT), cloud computing, and big data technologies, data sharing has become increasingly prevalent and crucial in various fields. In particular, in areas such as smart offices, healthcare, and finance, which require the processing of large amounts of sensitive data, secure and efficient data sharing has become a top priority for research and application.

[0003] However, current data sharing methods often suffer from drawbacks such as low security, low efficiency, and poor flexibility. Therefore, how to achieve secure, efficient, and flexible data sharing has become a pressing issue that needs to be addressed. Summary of the Invention

[0004] This disclosure addresses some of the shortcomings mentioned in the background art by providing a data sharing method, apparatus, and electronic device.

[0005] In a first aspect, embodiments of this disclosure provide a data sharing method, comprising: registering a data owner, a data requester, a smart contract, and a third-party cloud management entity; in response to the completion of registration by the data owner, data requester, smart contract, and third-party cloud management entity, performing multi-chain encryption processing on the shared data provided by the data owner to obtain encrypted shared data; in response to detecting a data acquisition request for target data sent by a data requester, verifying the data owner, data requester, smart contract, and third-party cloud management entity, wherein the shared data includes the target data; in response to the verification by the data owner, data requester, smart contract, and third-party cloud management entity, obtaining the target encrypted data based on the encrypted shared data; determining a target transmission path based on a pre-set dynamic path determination strategy, and sending the target encrypted data to the data requester through the target transmission path, so that the data requester can obtain the target data by reconstructing the target encrypted data.

[0006] In a second aspect, embodiments of this disclosure provide a data sharing apparatus, comprising: a registration unit for registering a data owner, a data requester, a smart contract, and a third-party cloud management entity; an encryption processing unit for performing multi-chain encryption processing on shared data provided by the data owner in response to the completion of registration by the data owner, data requester, smart contract, and third-party cloud management entity, to obtain encrypted shared data; a verification unit for verifying the data owner, data requester, smart contract, and third-party cloud management entity in response to detecting a data acquisition request for target data sent by a data requester, wherein the shared data includes the target data; a data acquisition unit for acquiring the target encrypted data based on the encrypted shared data in response to the completion of verification by the data owner, data requester, smart contract, and third-party cloud management entity; and a data transmission unit for determining a target transmission path based on a pre-set dynamic path determination strategy, and sending the target encrypted data to the data requester through the target transmission path, so that the data requester can obtain the target data by reconstructing the target encrypted data.

[0007] In a third aspect, embodiments of this disclosure provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, it implements the method described in the first aspect.

[0008] In a fourth aspect, embodiments of this disclosure provide a processor-readable storage medium storing a computer program for causing a processor to perform the method described in the first aspect.

[0009] In a fifth aspect, embodiments of this disclosure provide a computer program product including a computer program that, when executed by a processor, implements the method described in the first aspect.

[0010] The embodiments provided in this disclosure have at least the following beneficial technical effects: According to an embodiment of this disclosure, a data sharing method involves registering a data owner, a data requester, a smart contract, and a third-party cloud management entity. Upon successful registration by all three entities, the shared data provided by the data owner undergoes more secure multi-chain encryption to obtain encrypted shared data. Further, upon detecting a data acquisition request for target data from a data requester, the data owner, data requester, smart contract, and third-party cloud management entity are verified. Once all three entities pass verification, the target encrypted data is obtained based on the encrypted shared data. This target encrypted data is then sent to the data requester via a dynamically determined target transmission path, allowing the data requester to reconstruct the target encrypted data and obtain the target data. Therefore, this embodiment of the present disclosure, based on accurate registration and verification of participants, combined with a more secure multi-chain encryption processing method and a dynamic transmission path determination method, ensures the security and reliability of the data sharing process. At the same time, it improves the efficiency and flexibility of the data sharing process, enabling the data sharing method to have dynamic adjustment capabilities, laying the foundation for improving communication security, optimizing service management, and reducing potential risks.

[0011] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0012] The accompanying drawings are provided to better understand this solution and do not constitute a limitation of this disclosure. Wherein: Figure 1 This is a flowchart illustrating a data sharing method. Figure 2 This is a diagram illustrating the participants in data sharing. Figure 3 This is a flowchart illustrating another data sharing method; Figure 4 This is a diagram illustrating the registration process between a third-party cloud management entity and a data user. Figure 5 This is a flowchart illustrating another data sharing method; Figure 6 This is a diagram illustrating the registration process between a third-party cloud management entity and a smart contract; Figure 7 This is a flowchart illustrating another data sharing method; Figure 8 This is a diagram illustrating the registration process between a third-party cloud management entity and the data owner; Figure 9 This is a flowchart illustrating another data sharing method; Figure 10 This is a flowchart illustrating another data sharing method; Figure 11 This is a schematic diagram of a data sharing device. Figure 12 It is a block diagram of an electronic device. Detailed Implementation

[0013] The present disclosure will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the present disclosure and not intended to limit it. Furthermore, it should be noted that, for ease of description, only the parts relevant to the present disclosure are shown in the drawings, not the entire structure.

[0014] It should be noted that in existing technologies, data sharing mainly relies on a combination of blockchain and cloud computing. Blockchain's distributed ledger and smart contract technologies ensure the transparency and immutability of data, while cloud resources enable efficient data storage and transmission.

[0015] However, existing data sharing solutions combining blockchain and cloud computing face the following core problems in practical applications: First, there is the issue of data storage and encryption efficiency. Existing technologies typically use fixed encryption methods for data storage and transmission, lacking flexible segmentation and encryption strategies. They cannot adjust storage and transmission schemes in real time based on data sensitivity, network conditions, resource utilization, etc., leading to serious resource waste in some cases, or low data transmission efficiency and even packet loss under high concurrency and network fluctuations.

[0016] Secondly, there are limitations in data storage path and node selection. Current data storage path selection is typically based on static configuration, lacking flexibility. When cloud or blockchain nodes experience excessive load or failure, the system struggles to quickly adjust data storage paths, leading to performance degradation. Furthermore, storage decisions between blockchain and cloud nodes are often based on simple sensitivity assessments, failing to fully consider dynamic factors such as network load and access frequency.

[0017] Furthermore, there is a lack of efficient cross-node data consistency management. In traditional blockchain data sharing solutions, although blockchain technology can guarantee the immutability of data on a single chain, ensuring data consistency and recoverability remains a challenge in cross-node or cross-chain storage scenarios. Existing solutions have low efficiency in cross-chain data synchronization and consistency verification, and are generally unable to meet the multi-node data synchronization needs in large-scale, distributed scenarios.

[0018] Furthermore, there is a lack of complexity in smart contract authentication mechanisms. While smart contracts are widely used in existing technologies to manage data access permissions, most smart contract authentication mechanisms are relatively simple, relying solely on user behavior records or predefined permission rules, lacking dynamic and intelligent authentication mechanisms. The user's real-time environment, historical operations, and abnormal behavior cannot be fully analyzed, leading to security vulnerabilities in data access control.

[0019] As can be seen from the above, existing data sharing methods need improvement in terms of security, efficiency, and flexibility. Furthermore, current data sharing methods often lack dynamic adjustment capabilities. Therefore, this disclosure proposes a data sharing method that, based on a more secure multi-chain encryption processing method and a dynamic transmission path determination method, can improve the efficiency and flexibility of the data sharing process while ensuring its security and reliability, and also enables the data sharing method to have dynamic adjustment capabilities.

[0020] Figure 1 This is a schematic diagram based on the first embodiment of this disclosure. (See diagram below.) Figure 1 As shown, a data sharing method proposed in this disclosure embodiment will be explained and described, specifically including the following steps: S101. Register data owners, data requesters, smart contracts, and third-party cloud management entities.

[0021] S102. In response to the completion of registration by the data owner, data requester, smart contract and third-party cloud management entity, the shared data provided by the data owner is subjected to multi-chain encryption to obtain the encrypted shared data.

[0022] S103. In response to detecting a data acquisition request for target data sent by a data requester, verify the data owner, data requester, smart contract, and third-party cloud management entity, wherein the shared data includes the target data.

[0023] S104. In response to the data owner, data requester, smart contract and third-party cloud management entity all being verified, obtain the target encrypted data based on the encrypted shared data.

[0024] S105. Based on a pre-defined dynamic path determination strategy, determine the target transmission path and send the target encrypted data to the data requester through the target transmission path, so that the data requester can obtain the target data by reconstructing the target encrypted data.

[0025] It should be noted that, as Figure 2 As shown in this disclosure, the data sharing process mainly involves the following four participants (entities): the data owner, the data requester, the smart contract, and the third-party cloud management entity. All participants are allowed to share the shared data provided by the data owner.

[0026] In this context, the data owner refers to the cloud provider responsible for software maintenance, and different types of data are provided by the data owner. It should be noted that in this disclosure, data sharing is initiated by the data owner. That is, in response to detecting that the data owner has triggered a data sharing operation, the system performs registration operations for the data owner, data requester, smart contract, and third-party cloud management entity.

[0027] Among them, data demanders can be users who need to share at least some of the shared data provided by the data owner.

[0028] Among them, smart contracts refer to the management components in data sharing.

[0029] Among them, a third-party cloud management entity refers to a cloud management entity that is processed externally, rather than a cloud management entity that is processed internally.

[0030] It should also be noted that this disclosure establishes a data sharing model built on a blockchain network framework in the cloud, based on data owners, data requesters, smart contracts, and third-party cloud management entities. This data sharing model achieves data sharing based on a blockchain-cloud transmission protocol. The blockchain network supports access control management, and data involved in the sharing process is forwarded between nodes within the blockchain network.

[0031] In this embodiment of the disclosure, after the data owner triggers the data sharing operation, the data owner, data requester, smart contract, and third-party cloud management entity are registered. In response to the completion of registration by the data owner, data requester, smart contract, and third-party cloud management entity, the shared data provided by the data owner undergoes multi-chain encryption processing to obtain encrypted shared data.

[0032] It should be noted that the shared data provided by the data owner is critical data in the data sharing process. After the data owner registers, multi-chain encryption can be applied to the shared data provided by the data owner. Multi-chain encryption refers to encryption methods applied across multiple links.

[0033] It should be noted that steps S101-S102 above can be considered as the preparatory stage of this public data sharing process. That is, after the registration of participants and the encryption of the shared data provided by the data owner are completed, the preparation is complete. Subsequently, steps S103-S104 can be executed based on the data acquisition request sent by the data requester.

[0034] It should be noted that a data requester may request at least a portion of the shared data provided by the shared data owner. In other words, a data request sent by a data requester for target data refers to a request for at least a portion of the shared data.

[0035] In this embodiment of the disclosure, after detecting a data acquisition request for target data sent by a data requester, the data owner, data requester, smart contract, and third-party cloud management entity are verified. After the data owner, data requester, smart contract, and third-party cloud management entity have all passed verification, the target encrypted data is obtained based on the encrypted shared data.

[0036] The target encrypted data is the encrypted form of the data requested by the data requester. After receiving the target encrypted data, the data requester can decode it to obtain the target data.

[0037] It should be noted that the transmission path of the target encrypted data is one of the main factors affecting data sharing efficiency. Selecting the optimal transmission path and optimizing the transmission path are important steps in the data sharing method proposed in this disclosure. In other words, the method for determining the target transmission path in this disclosure no longer relies on a fixed, pre-set transmission path, but rather dynamically determines the target transmission path at the current moment based on a pre-set dynamic path determination strategy.

[0038] In this embodiment of the disclosure, after obtaining the target encrypted data, the target transmission path can be dynamically determined from the candidate transmission paths based on a pre-set dynamic path determination strategy, and the target encrypted data can be sent to the data requester through the target transmission path, so that the data requester can obtain the target data by reconstructing the target encrypted data.

[0039] According to an embodiment of this disclosure, a data sharing method involves registering a data owner, a data requester, a smart contract, and a third-party cloud management entity. Upon successful registration by all three entities, the shared data provided by the data owner undergoes more secure multi-chain encryption to obtain encrypted shared data. Further, upon detecting a data acquisition request for target data from a data requester, the data owner, data requester, smart contract, and third-party cloud management entity are verified. Once all three entities pass verification, the target encrypted data is obtained based on the encrypted shared data. This target encrypted data is then sent to the data requester via a dynamically determined target transmission path, allowing the data requester to reconstruct the target encrypted data and obtain the target data. Therefore, this embodiment of the present disclosure, based on accurate registration and verification of participants, combined with a more secure multi-chain encryption processing method and a dynamic transmission path determination method, ensures the security and reliability of the data sharing process. At the same time, it improves the efficiency and flexibility of the data sharing process, enabling the data sharing method to have dynamic adjustment capabilities, laying the foundation for improving communication security, optimizing service management, and reducing potential risks.

[0040] The following examples illustrate in detail the processes of participant registration, encryption of shared data, participant verification, and optimization of transmission paths.

[0041] Regarding participant registration, in this embodiment of the disclosure, a target registration strategy can be obtained, and registration operations can be performed between the third-party cloud management entity and the corresponding other entities according to the target registration strategy. The other entities corresponding to the third-party cloud management entity include data owners, data requesters, and smart contracts.

[0042] In other words, in this disclosure, the registration of participants can be divided into three parts: registration between the third-party cloud management entity and the data requester, registration between the third-party cloud management entity and the data owner, and registration between the third-party cloud management entity and the smart contract.

[0043] Registration between third-party cloud management entities and data requesters is one possible implementation method, such as... Figure 3 As shown, the specific steps include: S301. Obtain the first identity identifier and first password of the data requester, and store the first identity identifier and first password through a third-party cloud management entity and blockchain.

[0044] S302. Obtain the first confirmation message and send the first confirmation message to the data requester through a third-party cloud management entity, wherein the first confirmation message is generated by the third-party cloud management entity based on the first identity identifier.

[0045] S303. Obtain the first feedback message and send the first feedback message to the third-party cloud management entity through the data requester, wherein the first feedback message is generated by the data requester based on the first confirmation message.

[0046] It should be noted that, in order to more clearly explain the registration process between third-party cloud management entities and data requesters, the following will combine... Figure 4 Please provide an explanation.

[0047] like Figure 4 As shown, obtain the first identity identifier of the data requester. C ID And through data demanders C ID Send to a third-party cloud management entity.

[0048] Furthermore, the third-party cloud management entity receives the first identity identifier. C ID After that, it can be based on the primary identity identifier. C ID Generate the first confirmation message B 1, and send the first confirmation message. B 1. Send to the data requester.

[0049] It should be noted that this disclosure does not limit the specific method by which the third-party cloud management entity generates the first confirmation message based on the first identity identifier, and can be set according to the actual situation.

[0050] For example, the first confirmation message B 1 can be generated using the following formula:

[0051] in, h () represents a pre-defined hash function; g and k This represents the random number used to initialize the blockchain data sharing model. This indicates that the third-party cloud management entity has received the first identity identifier. C ID The labeling results.

[0052] It should be noted that this disclosure can be based on verification elements. k and k Registration is conducted for third-party cloud management entities and data requesters. The verification formula is as follows:

[0053] like k = ~ k The verification process is then completed between the data requester and the third-party cloud management entity. This part will be described in detail later, and will not be repeated here.

[0054] Furthermore, the data requester receives the first confirmation message. B After 1, you can proceed based on the first confirmation message. B 1. Generate the first feedback message and the first feedback message The message is sent to a third-party cloud management entity, which then marks it as... Store it.

[0055] In this embodiment of the disclosure, when performing registration between a third-party cloud management entity and a data user, in addition to obtaining the data user's first identity identifier, the data user's first password can also be obtained. The first password is then sent to the blockchain sequentially by the data user and the third-party cloud management entity, so that the third-party cloud management entity and the blockchain can store the first identity identifier and the first password.

[0056] like Figure 4 As shown, the first password of the data requester can be obtained. C pwd The first password is obtained through data requesters. C pwd Send it to a third-party cloud management entity, which can then use the primary identity identifier. C ID And the first password C pwd Marked as and Storage is performed. Furthermore, a third-party cloud management entity can use the primary identity identifier... C ID And the first password C pwd Send it to the blockchain, and the blockchain will identify the first identity. C ID And the first password C pwd Marked as and Storage is performed. In this case, both the third-party cloud management entity and the blockchain store the data requester's primary identity identifier and primary password, which are respectively marked as... and ,as well as and .

[0057] Registration between third-party cloud management entities and smart contracts is one possible implementation method, such as... Figure 5 As shown, the specific steps include: S501. Obtain the second identity and second password of the third-party cloud management entity, and store the second identity and second password through the third-party cloud management entity, smart contract, miner and blockchain.

[0058] S502. Obtain the second confirmation message and send the second confirmation message to the third-party cloud management entity through a smart contract, wherein the second confirmation message is generated by the smart contract based on the second identity identifier.

[0059] S503. Obtain the second feedback message and send the second feedback message to the smart contract through a third-party cloud management entity, wherein the second feedback message is generated by the third-party cloud management entity based on the second confirmation message.

[0060] It should be noted that, in order to more clearly explain the registration process between the third-party cloud management entity and the smart contract, the following will combine... Figure 6 Please provide an explanation.

[0061] like Figure 6 As shown, obtain the second identity identifier of the third-party cloud management entity. D ID And through a third-party cloud management entity D ID Send to the smart contract.

[0062] Furthermore, the smart contract receives the second identity verification. D ID Then, based on the second identity identifier D ID Generate a second confirmation message B 2, and send the second confirmation message. B 2. Send to a third-party cloud management entity.

[0063] It should be noted that this disclosure does not limit the specific method by which smart contracts generate the second confirmation message based on the second identity identifier, and can be set according to the actual situation.

[0064] For example, the second confirmation message B 2 can be generated using the following formula:

[0065] in, h ( ) represents a pre-defined hash function; and This represents the random number used to initialize the blockchain data sharing model. This indicates that the smart contract accepts the received second identity identifier. D ID The labeling results.

[0066] It should be noted that this disclosure can be based on verification elements. and The registration of third-party cloud management entities and smart contracts is performed, with the verification formula as follows:

[0067] in, h ’ Represents a random number, if The verification process is completed between the third-party cloud management entity and the smart contract. This part will be described in detail later, and will not be repeated here.

[0068] Furthermore, the third-party cloud management entity receives the second confirmation message. B After step 2, you can proceed based on the second confirmation message. B 2. Generate a second feedback message and the second feedback message The message is sent to the smart contract, and the smart contract marks the message as... Store it.

[0069] In this embodiment of the disclosure, during the registration process between the third-party cloud management entity and the smart contract, in addition to obtaining the second identity identifier of the third-party cloud management entity, a second password of the third-party cloud management entity can also be obtained. The second password is then sequentially sent to the blockchain through the third-party cloud management entity, the smart contract, and the miner, enabling the smart contract, the miner, and the blockchain to store the second identity identifier and the second password. Here, the miner refers to a dedicated node that participates in verifying transactions and creating blocks.

[0070] like Figure 6 As shown, a second password for the third-party cloud management entity can be obtained. D pwd The second password is transmitted through a third-party cloud management entity. D pwd The information is sent to a smart contract for storage; the smart contract can then store the second identity. D ID Second password D pwd Marked as and Storage is performed. Furthermore, a second identity can be stored via smart contracts. D ID Second password D pwd Send it to the miner, who can then use the second identity identifier.D ID Second password D pwd Marked as and Storage is performed. Furthermore, a second identity can be obtained through miners. D ID Second password D pwd Sending it to the blockchain allows the blockchain to verify the second identity. D ID Second password D pwd Marked as and Storage is performed. In this case, the smart contract, miner, and blockchain all store a second identity and second password for the third-party cloud management entity, and are respectively marked as... and , and ,as well as and .

[0071] Registration between third-party cloud management entities and data owners is one possible implementation method, such as... Figure 7 As shown, the specific steps include: S701. Obtain the second identity and second password of the third-party cloud management entity, and store the second identity and second password through the third-party cloud management entity, smart contract, miner, data owner and blockchain.

[0072] S702. Obtain the third confirmation message and send the third confirmation message to the third-party cloud management entity through the data owner, wherein the third confirmation message is generated by the data owner based on the second identity identifier.

[0073] S703. Obtain the third feedback message and send the third feedback message to the data owner through the third-party cloud management entity. The third feedback message is generated by the third-party cloud management entity based on the third confirmation message.

[0074] It should be noted that, in order to more clearly explain the registration process between the third-party cloud management entity and the data owner, the following will combine... Figure 8 Please provide an explanation.

[0075] like Figure 8 As shown, obtain the second identity identifier of the third-party cloud management entity. D ID And through a third-party cloud management entity D ID Send to the data owner.

[0076] Furthermore, the data owner receives the second identity identifier. D ID Then, based on the second identity identifier D ID Generate a third confirmation message B 3, and send the third confirmation message B 3. Send to a third-party cloud management entity.

[0077] It should be noted that this disclosure does not limit the specific method by which the data owner generates the third confirmation message based on the second identity identifier, and can be set according to the actual situation.

[0078] For example, the third confirmation message B 3 can be generated using the following formula:

[0079] in, h ( ) represents a pre-defined hash function; i and j This represents the random number used to initialize the blockchain data sharing model. This indicates that the miner has received a second identity identifier. D ID The labeling results.

[0080] It should be noted that this disclosure can be based on verification elements. j and j Registration of third-party cloud management entities and data owners is required, with the following verification formula:

[0081] like j = ~ j In this case, the verification process is completed between the third-party cloud management entity and the data owner. This part will be described in detail later, and will not be repeated here.

[0082] Furthermore, the third-party cloud management entity receives a third confirmation message. B After step 3, you can proceed based on the third confirmation message. B 3. Generate a third feedback message And through a third-party cloud management entity, the third feedback message is sent. Send to the data owner.

[0083] In this embodiment of the disclosure, when performing the registration between the third-party cloud management entity and the smart contract, in addition to obtaining the second identity identifier of the third-party cloud management entity, the second password of the third-party cloud management entity can also be obtained. The second password is then sent to the blockchain in sequence through the third-party cloud management entity, the smart contract, the miner, and the data owner, so that the smart contract, the miner, the data owner, and the blockchain can store the second identity identifier and the second password.

[0084] like Figure 8 As shown, a second password for the third-party cloud management entity can be obtained. D pwd The second password is transmitted through a third-party cloud management entity. D pwd The information is sent to a smart contract for storage; the smart contract can then store the second identity. D ID Second password D pwd Marked as and Storage is performed. Furthermore, a second identity can be stored via smart contracts. D ID Second password D pwd Send it to the miner, who can then use the second identity identifier. D ID Second password D pwd Marked as and Storage is performed. Furthermore, a second identity can be obtained through miners. D ID Second password D pwd Send to the data owner, who can then use the second identity identifier. D ID Second password D pwd Marked as and Store it. Furthermore, a second identity can be established through the data owner. D ID Second password D pwd Sending it to the blockchain allows the blockchain to verify the second identity. D ID Second password D pwd Marked as and Storage is performed. In this case, the smart contract, miner, data owner, and blockchain all store a second identity and second password for the third-party cloud management entity, and are respectively marked as... and , and ,as well as and , and .

[0085] The above process ensures secure registration between the third-party cloud management entity and the data owner. Through hash and XOR operations, the security and integrity of the information are guaranteed even if the third-party cloud management entity's information is stored on the blockchain.

[0086] According to an embodiment of this disclosure, a data sharing method can obtain a target registration policy and, based on the target registration policy, execute registration operations between third-party cloud management entities and data owners, data requesters, and smart contracts. Therefore, this embodiment of the disclosure can accurately register participants, ensuring the security and integrity of information stored on the blockchain by data requesters and third-party cloud management entities, further improving the security and reliability of the data sharing process.

[0087] Regarding the encryption of shared data, it should be noted that in this embodiment, multi-chain encryption can be achieved by first segmenting the shared data and then encrypting it. Furthermore, to address factors such as the different sizes, sensitivity, network conditions, and resource utilization of the shared data, the data sharing method proposed in this embodiment can dynamically adjust the segmentation and encryption methods of the shared data according to the current environment.

[0088] In other words, in this embodiment of the disclosure, before encrypting the shared data, the shared data can be first segmented, and then the segmented shared data can be encrypted using multi-chain encryption.

[0089] As one possible implementation, such as Figure 9 As shown, the specific steps include: S901. The shared data provided by the data owner is segmented to obtain segmented data blocks, and all segmented data blocks are stored in the blockchain.

[0090] Optionally, a first data characteristic of the shared data and a first performance data of the current network can be obtained, and a target segmentation strategy can be obtained based on the first data characteristic and the first performance data. Further, the shared data can be segmented according to the target segmentation strategy.

[0091] Among them, the first data characteristic of the shared data can be indicators such as the total size and sensitivity of the shared data; the first performance data of the current network can be indicators such as network status and resource utilization; the target partitioning strategy includes the number of data blocks after the shared data is partitioned.

[0092] For example, after obtaining the first data characteristics and the first performance data, the number of shared data blocks after partitioning can be obtained based on the first data characteristics and the first performance data. n And based on the number of data blocks n The shared data is then segmented using the following formula:

[0093] in, n For the number of data blocks, S d The total size of the shared data, in bytes. β ( S sens The sensitivity factor of the shared data is the coefficient; the more sensitive the data, the more blocks it should be divided into.

[0094] in, Network status N stat and resource utilization rate R util The joint function will increase the number of blocks when the network condition is poor or the resource utilization is high, as expressed by the following formula:

[0095] in, B min To minimize the data block size and prevent excessively small partitions from impacting efficiency; γ The block size is dynamically adjusted using preset adjustment coefficients to ensure transmission and storage efficiency; φ ( S type ) is a data type correction function. Different types of data (such as text, images, etc.) have different segmentation requirements.

[0096] in, λ The preset time-related adjustment coefficient is adjusted based on the data processing time or storage time. ( T store The storage time factor represents the length of time the data is stored; the longer the storage time, the more blocks are required. opt Incremental optimization is selectively applied for special conditions, and adjustments are made dynamically based on network load or data type.

[0097] The data blocks are obtained and stored in the blockchain to facilitate data sharing in the future.

[0098] S902. For each segmented data block, obtain the hash value of the previous data block on other chains in the blockchain, and perform multi-chain cross-encryption processing on the corresponding segmented data block according to the hash value to obtain encrypted shared data composed of all encrypted data blocks.

[0099] For example, for each data block after splitting D 1, D 2,... D n It associates data blocks with each other on other chains in the blockchain using hash values ​​and performs multi-chain cross-encryption as follows:

[0100] in, C i For the first i The ciphertext of each data block; AES KAESi This indicates that it is based on the AES encryption algorithm and uses a symmetric key. K AESi Encrypt; ECC ki (D i ) This indicates that it is based on the elliptic curve cryptography algorithm and uses a private key. ki For data blocks D i Encrypt it.

[0101] Among them, H( D i [other] The hash value of the previous data block on other chains in the blockchain is used to implement cross-chain encryption and ensure data security; mod P Modular operations are used to ensure that the encryption result is within a reasonable range; ò opt To selectively optimize encryption increments.

[0102] The key generation strategy can be dynamically adjusted for different use cases. Optionally, the encryption key for data blocks can be determined based on a time window. T W Data block access frequency F a Network security level N sec Information such as key complexity is dynamically generated, and the key complexity is selectively optimized based on the usage scenario. In other words, symmetric keys... KAESi It can be combined with time windows T W Data block access frequency F a Network security level N sec and scene adjustment coefficient ψ secnario The following formula is used to determine it:

[0103] According to an embodiment of this disclosure, a data sharing method dynamically determines a target segmentation strategy for shared data based on data effects and network metrics in different scenarios, and segments the shared data according to the target segmentation strategy. Further, for the segmented data blocks, multi-chain cross-encryption processing is performed to obtain the encrypted shared data composed of all the encrypted data blocks. Therefore, this embodiment of the disclosure can segment shared data more flexibly and reliably based on a dynamic segmentation strategy, and associate it with the hash values ​​of data blocks on other chains in the blockchain, and perform cross-encryption according to a preset method. This ensures that even if one chain is compromised, the data remains unrecoverable, further improving the flexibility and reliability of the data sharing process, and further enhancing the dynamic adjustment capability of the data sharing process.

[0104] Furthermore, after multi-chain encryption of the shared data provided by the data owner to obtain the encrypted shared data, cross-storage can be achieved through smart contracts.

[0105] As one possible implementation, such as Figure 10 As shown, the specific steps include: S1001. For each encrypted data block, obtain a first evaluation result for at least two candidate storage regions, and determine the target storage region based on the first evaluation result, wherein the first evaluation result is calculated by the smart contract based on the second data characteristics of the encrypted data block and the second performance data of the current network.

[0106] The second data characteristic of the encrypted data block can be completely consistent with, partially consistent with, or completely inconsistent with the first data characteristic. For example, the second data characteristic can be an indicator such as total size or sensitivity, or it can be an indicator such as sensitivity or lifespan.

[0107] The second performance data of the current network can be completely consistent with, partially consistent with, or completely inconsistent with the first performance data. For example, the second performance data can be indicators such as access frequency, network status, and node load.

[0108] For example, the blockchain node storage value and cloud node storage value corresponding to a data block can be calculated using the following two sets of formulas based on indicators such as data block sensitivity, data block lifecycle, preset data block usage scenario adjustment coefficient, data block storage cost, and preset dynamic adjustment coefficient:

[0109] in, S blockchain ( D i () represents the value stored in the blockchain node corresponding to the data block; S sensi Sensitivity of data blocks; L ci For the lifecycle of a data block; α secnario Adjust the coefficients for the scene.

[0110]

[0111] in, S cloud ( D i This indicates the cloud node storage value corresponding to the data block; C cost For storage costs. β dynamic To dynamically adjust parameters.

[0112] Furthermore, if S blockchain ( D i > S cloud ( D i If the first evaluation result is to store the data block on the blockchain node, then the first evaluation result is to store the data block on the blockchain node; if S blockchain ( D i )< S cloud ( D i If the first assessment result is to store the data block in the cloud node, then the first assessment result is to store the data block in the cloud node. S blockchain ( D i )= S cloud ( D i If the first evaluation result is that it can be stored on any node in the blockchain node or cloud node, then the first evaluation result is that it can be stored on any node in the blockchain node or cloud node.

[0113] In this case, if the first evaluation result is to store the data block on a blockchain node, then the blockchain node can be identified as the target storage area; if the first evaluation result is to store the data block on a cloud node, then the cloud node can be identified as the target storage area; if the first evaluation result is that the data block can be stored on either a blockchain node or a cloud node, then either a blockchain node or a cloud node can be identified as the target storage area.

[0114] S1002. Obtain the second evaluation results for at least two candidate storage nodes in the target storage area. Based on the second evaluation results, determine the target storage node and store the encrypted data block to the corresponding target storage node. The second evaluation results are calculated by the smart contract based on the third performance data of the candidate storage nodes.

[0115] In this embodiment of the disclosure, after determining the target storage area based on the first evaluation result, the final storage location can be dynamically selected based on the information, for example, stored in a specific blockchain node or cloud node.

[0116] The third performance data for candidate storage nodes can include metrics such as the current load, available storage capacity, and consensus dynamics of the storage node.

[0117] For example, the specific storage node of the split data block can be determined using the following formula. P ( D i ):

[0118] in, L j The current load of the storage node; S capj Available storage capacity; △ T Lj This is due to network latency fluctuations; T avgj The average response time of the node; S secj The node's security level; C dynj For consensus dynamics; T histj The historical trust level of the node; R compj To calculate resource fluctuations; F partj Frequency of node participation; σ path Adjust the coefficients for dynamic path selection.

[0119] Furthermore, after storing the encrypted data blocks to the corresponding target storage nodes, a hash chain can be established between the nodes storing the data blocks through a dependency graph model.

[0120] As one possible implementation, for any target storage node, the corresponding adjacent storage nodes can be determined. Furthermore, the hash value of the encrypted data block stored by the target storage node can be obtained, and the hash value can be sent to the adjacent storage nodes for storage via a smart contract, where the hash value is generated by the smart contract.

[0121] For example, first, the set of nodes storing the data blocks can be determined. V i And the associated nodes in the node set (the data blocks stored in the associated nodes are adjacent in their split positions). Then, based on the node set... V i and node set V i The dependency graph model of data block storage nodes is constructed by connecting edges between associated nodes as follows. G dep ( V , E ):

[0122] in, E j Represents a set of nodes V i The set of edges connecting to associated nodes; ω hash The dynamic verification adjustment coefficients for the preset hash chain.

[0123] Furthermore, each storage node V i Upon receiving the data block D i Then, it can be based on the dependency graph model. G dep ( V , E Adjacent nodes in ) V adj Generate the hash value of the current data block. H(D i ) And send it to its neighboring nodes. Neighboring nodes V adj The hash value will be stored as a basis for verifying data consistency.

[0124] In addition, node set V iConnection edges between associated nodes E j It can record the hash value associations between nodes, ensuring that when the data of one node is corrupted, other nodes can verify and recover the data through dependencies.

[0125] After the data is stored, this scheme establishes a hash chain between the nodes storing the data blocks using a dependency graph model. This allows for the association of data hash values ​​across nodes, ensuring data consistency and immutability across all nodes.

[0126] According to an embodiment of this disclosure, a data sharing method dynamically determines target storage nodes based on the data characteristics of data blocks and network performance data, and stores encrypted data blocks to the corresponding target storage nodes. Therefore, this embodiment of the disclosure can more flexibly and reliably achieve cross-storage through smart contracts based on a dynamic target storage node determination method. After the data is stored, a hash chain can be established among the nodes storing the data blocks using a dependency graph model. This allows for the association of data hash values ​​between nodes, ensuring data consistency and immutability across nodes, further improving the security, flexibility, and reliability of the data sharing process, and enhancing the dynamic adjustment capability of the data sharing process.

[0127] In this embodiment of the disclosure, for the verification of participants, a target verification strategy can be obtained, and verification operations between the third-party cloud management entity and the corresponding other entities can be performed according to the target verification strategy. The other entities corresponding to the third-party cloud management entity include data owners, data requesters and smart contracts.

[0128] In this disclosure, the verification phase corresponds to the registration phase mentioned above. The verification of participants can also be divided into three parts: verification between the third-party cloud management entity and the data requester, verification between the third-party cloud management entity and the data owner, and verification between the third-party cloud management entity and the smart contract.

[0129] For example, in the authentication process between a third-party cloud management entity and a data requester, the data requester provides their identity identifier. C ID and user password C pwd Confirmation is required from the third-party cloud management entity, which has already... C ID and C pwd Marked as and It has been stored. In this case, if ,and Then the data requester will obtain a [data] from a third-party cloud management entity. OTP (One-time password), and store it as Furthermore, storage-based OTP Generate an authentication message for the user. F 1. Among them, OTP The generation method and F The representation of 1 is as follows:

[0130]

[0131] Furthermore, the authentication information will be stored in a third-party cloud management entity and verified in the following ways:

[0132] In this case, if F1 =~ F1 If so, it is assumed that the identity information of the data requester is verified through a third-party cloud management entity.

[0133] The above process ensures the verification of the data requester's identity and the secure transmission of information. This is achieved through hashing and... OTP Even if a third-party cloud management entity stores the data requester's information, the generation of this data ensures the security and integrity of the information. Clients can verify the validity of authentication requests by checking the timestamp.

[0134] For verification between the third-party cloud management entity and the smart contract, after completing the above verification, a timestamp can be calculated. A The authentication message is stored in the smart contract and represented as... The authentication message can be calculated using the following formula:

[0135] in, m ( D ID This indicates a mapping operation on the identity identifier of a third party; i It is a random number; A Represents a timestamp.

[0136] Furthermore, the smart contract checks the validity of the timestamp. If the timestamp is valid, a session is started; if invalid, the session is terminated. (Authentication message) F 2. Verification can be performed in the following ways:

[0137] Among them, when F 2=~ F At 2 o'clock, it indicates that the authentication of the third-party cloud management entity based on the smart contract is completed.

[0138] For authentication between a third-party cloud management entity and the data owner, an authentication message is created when authentication begins between the third party and the data owner. F 3, its expression is:

[0139] Furthermore, authentication messages F 3 is stored at the data owner's location, represented as The data owner checks the validity of the timestamp; if the timestamp is valid, the session continues; otherwise, the session is terminated. Furthermore, the validity of authentication information at the data owner's location is expressed as follows:

[0140] If the information has been verified F 3= ~F 3. Then the identity of the third-party cloud management entity as the data owner is verified.

[0141] Furthermore, in response to the fact that all participants have passed the verification, the target encrypted data is obtained based on the encrypted shared data, and the target transmission path is determined based on the pre-set dynamic path determination strategy. The target encrypted data is then sent to the data requester through the target transmission path.

[0142] Regarding the optimization of the transmission path, one possible approach is to determine the target transmission path based on the optimal path selection formula within a pre-defined dynamic path determination strategy. Once the target transmission path is selected, the encrypted data can be sent to the data requester via that path. The optimal path selection formula is as follows:

[0143] in, L path For path load; B w For bandwidth; B f This is due to bandwidth fluctuations; S path The security level of the path; T n Due to network latency; N t For transmission delay; ρ dynamic This is the preset multipath selection coefficient.

[0144] Furthermore, in this disclosure, path switching can be performed when necessary.

[0145] As one possible implementation, in response to detecting that the transmission path switching condition is met, an alternative transmission path is determined, and the target encrypted data is sent to the data requester through the alternative transmission path.

[0146] It should be noted that this disclosure does not limit the specific settings for transmission path switching conditions, which can be selected according to actual circumstances. For example, the transmission path switching conditions can be set when at least two of the following data points of the target transmission path—path load, bandwidth, bandwidth fluctuation, path security level, network latency, and transmission delay—have changed, resulting in performance degradation. In this case, the current target transmission path can no longer complete the efficient data transmission task, and a better alternative transmission path can be selected, and the target encrypted data can be sent to the data requester through the alternative transmission path.

[0147] It should also be noted that after receiving the target encrypted data, the data requester can reconstruct it to obtain the target data. The target encrypted data is in the form of encrypted data blocks, while the target data is the complete, reconstructed data.

[0148] For example, after receiving the target encrypted data, the data requester can, based on the random noise matrix and a preset data compensation factor, [the data can be processed / processed]. K comp The target encrypted data is reconstructed to obtain the complete data. D reconst (t) The target encrypted data can be reconstructed using the following formula:

[0149] in, D i (t- △ t) For the first node to be recovered i One data block; R t It is a random noise matrix.

[0150] According to an embodiment of this disclosure, a data sharing method can optimize the transmission path through a blockchain-cloud interaction channel, and send the target encrypted data to the data requester via an alternative transmission path based on the optimized target transmission path, thereby ensuring the security and efficiency of data block transmission. Furthermore, when the current target transmission path can no longer complete the efficient data transmission task, an alternative transmission path can be determined, and the target encrypted data can be sent to the data requester via the alternative transmission path, further improving the security, flexibility, and efficiency of the data sharing process, and further enhancing the dynamic adjustment capability of the data sharing process.

[0151] Corresponding to the data sharing method provided in the above embodiments, an embodiment of this disclosure also provides a data sharing device. Since the data sharing device provided in this disclosure corresponds to the data sharing method provided in the above embodiments, the implementation of a data sharing method is also applicable to the data sharing device provided in this embodiment, and will not be described in detail in this embodiment.

[0152] Figure 11 This is a schematic diagram of the structure of a data sharing device according to an embodiment of the present disclosure.

[0153] like Figure 11 As shown, the data sharing device 2000 includes: a registration unit 1110, an encryption processing unit 1120, a verification unit 1130, a data acquisition unit 1140, and a data transmission unit 1150.

[0154] The system comprises the following components: a registration unit 1110 for registering data owners, data requesters, smart contracts, and third-party cloud management entities; an encryption processing unit 1120 for performing multi-chain encryption on the shared data provided by the data owner in response to the registration of all data owners, data requesters, smart contracts, and third-party cloud management entities, resulting in encrypted shared data; a verification unit 1130 for verifying the data owner, data requester, smart contract, and third-party cloud management entity in response to a detected data acquisition request for target data sent by a data requester, wherein the shared data includes the target data; a data acquisition unit 1140 for acquiring the target encrypted data based on the encrypted shared data in response to the verification of all data owners, data requesters, smart contracts, and third-party cloud management entities; and a data transmission unit 1150 for determining the target transmission path based on a pre-set dynamic path determination strategy and sending the target encrypted data to the data requester through the target transmission path, so that the data requester can reconstruct the target encrypted data to obtain the target data.

[0155] According to one embodiment of this disclosure, the registration unit 1110 is further configured to: obtain a target registration strategy, and perform registration operations between a third-party cloud management entity and other corresponding entities according to the target registration strategy, wherein the other entities corresponding to the third-party cloud management entity include data owners, data requesters, and smart contracts.

[0156] According to one embodiment of this disclosure, the registration unit 1110 is further configured to: obtain a first identity identifier and a first password of a data requester, and store the first identity identifier and the first password through a third-party cloud management entity and a blockchain; obtain a first confirmation message, and send the first confirmation message to the data requester through the third-party cloud management entity, wherein the first confirmation message is generated by the third-party cloud management entity based on the first identity identifier; obtain a first feedback message, and send the first feedback message to the third-party cloud management entity through the data requester, wherein the first feedback message is generated by the data requester based on the first confirmation message.

[0157] According to one embodiment of this disclosure, the registration unit 1110 is further configured to: obtain a second identity identifier and a second password of a third-party cloud management entity, and store the second identity identifier and the second password through the third-party cloud management entity, a smart contract, a miner, and a blockchain; obtain a second confirmation message, and send the second confirmation message to the third-party cloud management entity through a smart contract, wherein the second confirmation message is generated by the smart contract based on the second identity identifier; obtain a second feedback message, and send the second feedback message to the smart contract through the third-party cloud management entity, wherein the second feedback message is generated by the third-party cloud management entity based on the second confirmation message.

[0158] According to one embodiment of this disclosure, the registration unit 1110 is further configured to: obtain a second identity identifier and a second password of a third-party cloud management entity, and store the second identity identifier and the second password through the third-party cloud management entity, a smart contract, a miner, a data owner, and a blockchain; obtain a third confirmation message, and send the third confirmation message to the third-party cloud management entity through the data owner, wherein the third confirmation message is generated by the data owner based on the second identity identifier; obtain a third feedback message, and send the third feedback message to the data owner through the third-party cloud management entity, wherein the third feedback message is generated by the third-party cloud management entity based on the third confirmation message.

[0159] According to one embodiment of this disclosure, the encryption processing unit 1120 is further configured to: segment the shared data provided by the data owner to obtain segmented data blocks, and store all segmented data blocks in the blockchain; for each segmented data block, obtain the hash value of the previous data block on other chains in the blockchain, and perform multi-chain cross-encryption processing on the corresponding segmented data block according to the hash value, to obtain encrypted shared data composed of all encrypted data blocks.

[0160] According to one embodiment of this disclosure, the encryption processing unit 1120 is further configured to: obtain a first data characteristic of the shared data and a first performance data of the current network, and obtain a target segmentation strategy based on the first data characteristic and the first performance data; and segment the shared data according to the target segmentation strategy.

[0161] According to one embodiment of this disclosure, the encryption processing unit 1120 is further configured to: for each encrypted data block, obtain a first evaluation result for at least two candidate storage regions, and determine a target storage region based on the first evaluation result, wherein the first evaluation result is calculated by a smart contract based on a second data characteristic of the encrypted data block and a second performance data of the current network; obtain a second evaluation result for at least two candidate storage nodes in the target storage region, determine a target storage node based on the second evaluation result, and store the encrypted data block to the corresponding target storage node, wherein the second evaluation result is calculated by a smart contract based on a third performance data of the candidate storage node.

[0162] According to one embodiment of this disclosure, the encryption processing unit 1120 is further configured to: determine the corresponding adjacent storage node for any target storage node; obtain the hash value of the encrypted data block stored in the target storage node, and send the hash value to the adjacent storage node for storage through a smart contract, wherein the hash value is generated by the smart contract.

[0163] According to one embodiment of this disclosure, the verification unit 1130 is further configured to: obtain a target verification strategy, and perform verification operations between the third-party cloud management entity and the corresponding other entities according to the target verification strategy, wherein the other entities corresponding to the third-party cloud management entity include data owners, data requesters and smart contracts.

[0164] According to one embodiment of this disclosure, the data transmission unit 1150 is further configured to: determine an alternative transmission path in response to detecting that the transmission path switching condition is met, and send the target encrypted data to the data requester through the alternative transmission path.

[0165] According to an embodiment of this disclosure, a data sharing device can register a data owner, a data requester, a smart contract, and a third-party cloud management entity. Upon successful registration by all three entities, the shared data provided by the data owner undergoes more secure multi-chain encryption to obtain encrypted shared data. Further, upon detecting a data acquisition request for target data sent by a data requester, the device verifies the data owner, data requester, smart contract, and third-party cloud management entity. Then, upon successful verification by all three entities, the device acquires the target encrypted data based on the encrypted shared data and sends the target encrypted data to the data requester via a dynamically determined target transmission path. This allows the data requester to reconstruct the target encrypted data and obtain the target data. Therefore, this embodiment of the present disclosure, based on accurate registration and verification of participants, combined with a more secure multi-chain encryption processing method and a dynamic transmission path determination method, ensures the security and reliability of the data sharing process. At the same time, it improves the efficiency and flexibility of the data sharing process, enabling the data sharing method to have dynamic adjustment capabilities, laying the foundation for improving communication security, optimizing service management, and reducing potential risks.

[0166] The method and apparatus are based on the same concept of the application. Since the methods and apparatus solve problems in similar ways, the implementation of the apparatus and methods can refer to each other, and the repeated parts will not be described again.

[0167] It should be noted that the division of units in the embodiments of this disclosure is illustrative and only represents one logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional units in the various embodiments of this disclosure can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated units described above can be implemented in hardware or as software functional units.

[0168] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this disclosure. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0169] According to embodiments of this disclosure, this disclosure also provides an electronic device 3000, such as... Figure 12 As shown, it includes a memory 400, a processor 500, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the aforementioned data sharing method.

[0170] According to embodiments of this disclosure, a processor-readable storage medium is also provided. This processor-readable storage medium stores a computer program that causes the processor to perform the aforementioned data sharing method.

[0171] The processor-readable storage medium can be any available medium or data storage device that the processor can access, including but not limited to magnetic memory (e.g., floppy disk, hard disk, magnetic tape, magneto-optical disk (MO)), optical memory (e.g., CD, DVD, BD, HVD), and semiconductor memory (e.g., ROM, EPROM, EEPROM, non-volatile memory (NAND FLASH), solid-state drive (SSD)).

[0172] According to embodiments of this disclosure, a computer program product is also provided. This computer program product includes a computer program that, when executed by a processor, performs the aforementioned data sharing method.

[0173] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this disclosure can be achieved, and this is not limited herein.

[0174] The specific embodiments described herein do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.

Claims

1. A data sharing method, characterized in that, include: Register data owners, data requesters, smart contracts, and third-party cloud management entities; In response to the completion of registration by the data owner, the data requester, the smart contract, and the third-party cloud management entity, the shared data provided by the data owner is subjected to multi-chain encryption to obtain encrypted shared data. In response to detecting a data acquisition request for target data sent by the data requester, the data owner, the data requester, the smart contract, and the third-party cloud management entity are verified, wherein the shared data includes the target data; In response to the data owner, the data requester, the smart contract, and the third-party cloud management entity all being verified, the target encrypted data is obtained based on the encrypted shared data; Based on a pre-defined dynamic path determination strategy, a target transmission path is determined, and the target encrypted data is sent to the data requester through the target transmission path, so that the data requester can obtain the target data by reconstructing the target encrypted data.

2. The method according to claim 1, characterized in that, The registration of data owners, data requesters, smart contracts, and third-party cloud management entities includes: Obtain the target registration strategy, and perform registration operations between the third-party cloud management entity and the corresponding other entities according to the target registration strategy. The other entities corresponding to the third-party cloud management entity include the data owner, the data requester, and the smart contract.

3. The method according to claim 2, characterized in that, The other entities corresponding to the third-party cloud management entity are the data requesters. The process of performing a registration operation between the third-party cloud management entity and the corresponding other entities includes: Obtain the first identity identifier and first password of the data requester, and store the first identity identifier and first password through the third-party cloud management entity and the blockchain; Obtain a first confirmation message and send the first confirmation message to the data requester through the third-party cloud management entity, wherein the first confirmation message is generated by the third-party cloud entity based on the first identity identifier; A first feedback message is obtained and sent to the third-party cloud management entity by the data requester, wherein the first feedback message is generated by the data requester based on the first confirmation message.

4. The method according to claim 2, characterized in that, The other entities corresponding to the third-party cloud management entity are the smart contracts. The execution of the registration operation between the third-party cloud management entity and the corresponding other entities includes: Obtain the second identity identifier and second password of the third-party cloud management entity, and store the second identity identifier and second password through the third-party cloud management entity, the smart contract, the miner and the blockchain; Obtain a second confirmation message and send the second confirmation message to the third-party cloud management entity through the smart contract, wherein the second confirmation message is generated by the smart contract based on the second identity identifier; A second feedback message is obtained and sent to the smart contract through the third-party cloud management entity, wherein the second feedback message is generated by the third-party cloud management entity based on the second confirmation message.

5. The method according to claim 2, characterized in that, The other entities corresponding to the third-party cloud management entity are the data owners. The process of performing a registration operation between the third-party cloud management entity and the corresponding other entities includes: Obtain the second identity identifier and second password of the third-party cloud management entity, and store the second identity identifier and second password through the third-party cloud management entity, the smart contract, the miner, the data owner, and the blockchain; Obtain a third confirmation message and send the third confirmation message to the third-party cloud management entity through the data owner, wherein the third confirmation message is generated by the data owner based on the second identity identifier; A third feedback message is obtained and sent to the data owner through the third-party cloud management entity, wherein the third feedback message is generated by the third-party cloud management entity based on the third confirmation message.

6. The method according to claim 1, characterized in that, The step of performing multi-chain encryption on the shared data provided by the data owner to obtain encrypted shared data includes: The shared data provided by the data owner is segmented to obtain segmented data blocks, and all the segmented data blocks are stored in the blockchain; For each of the segmented data blocks, the hash value of the previous data block on other chains in the blockchain is obtained, and multi-chain cross-encryption processing is performed on the corresponding segmented data block according to the hash value to obtain the encrypted shared data composed of all the encrypted data blocks.

7. The method according to claim 6, characterized in that, The process of segmenting the shared data provided by the data owner to obtain segmented data blocks includes: Obtain the first data characteristics of the shared data and the first performance data of the current network, and obtain the target segmentation strategy based on the first data characteristics and the first performance data; The shared data is segmented according to the target segmentation strategy.

8. The method according to claim 6, characterized in that, After performing multi-chain cross-encryption on the corresponding segmented data blocks according to the hash value to obtain the encrypted shared data composed of all the encrypted data blocks, the method further includes: For each encrypted data block, a first evaluation result is obtained for at least two candidate storage regions, and a target storage region is determined based on the first evaluation result, wherein the first evaluation result is calculated by the smart contract based on the second data characteristics of the encrypted data block and the second performance data of the current network; Obtain a second evaluation result for at least two candidate storage nodes in the target storage area, determine the target storage node based on the second evaluation result, and store the encrypted data block in the corresponding target storage node, wherein the second evaluation result is calculated by the smart contract based on the third performance data of the candidate storage nodes.

9. The method according to claim 8, characterized in that, After storing the encrypted data block to the corresponding target storage node, the method further includes: For any of the target storage nodes, determine the corresponding adjacent storage nodes; The hash value of the encrypted data block stored in the target storage node is obtained, and the hash value is sent to the adjacent storage node for storage through the smart contract, wherein the hash value is generated by the smart contract.

10. The method according to claim 1, characterized in that, The verification of the data owner, the data requester, the smart contract, and the third-party cloud management entity includes: Obtain the target verification strategy, and perform verification operations between the third-party cloud management entity and the corresponding other entities according to the target verification strategy. The other entities corresponding to the third-party cloud management entity include the data owner, the data requester, and the smart contract.

11. The method according to claim 1, characterized in that, The method further includes: In response to the detection that the transmission path switching conditions are met, an alternative transmission path is determined, and the target encrypted data is sent to the data requester through the alternative transmission path.

12. A data sharing device, characterized in that, include: The registration unit is used to register data owners, data requesters, smart contracts, and third-party cloud management entities. An encryption processing unit is used to perform multi-chain encryption processing on the shared data provided by the data owner in response to the completion of registration by the data owner, the data requester, the smart contract and the third-party cloud management entity, so as to obtain encrypted shared data. A verification unit is configured to verify the data owner, the data requester, the smart contract, and the third-party cloud management entity in response to detecting a data acquisition request for target data sent by the data requester, wherein the shared data includes the target data; The data acquisition unit is used to acquire target encrypted data based on the encrypted shared data, in response to the data owner, the data requester, the smart contract, and the third-party cloud management entity all passing verification. The data transmission unit is used to determine a target transmission path based on a pre-set dynamic path determination strategy, and send the target encrypted data to the data requester through the target transmission path, so that the data requester can obtain the target data by reconstructing the target encrypted data.

13. The apparatus according to claim 12, characterized in that, The registration unit is also used for: Obtain the target registration strategy, and perform registration operations between the third-party cloud management entity and the corresponding other entities according to the target registration strategy. The other entities corresponding to the third-party cloud management entity include the data owner, the data requester, and the smart contract.

14. The apparatus according to claim 13, characterized in that, The registration unit is also used for: Obtain the first identity identifier and first password of the data requester, and store the first identity identifier and first password through the third-party cloud management entity and the blockchain; Obtain a first confirmation message and send the first confirmation message to the data requester through the third-party cloud management entity, wherein the first confirmation message is generated by the third-party cloud entity based on the first identity identifier; A first feedback message is obtained and sent to the third-party cloud management entity by the data requester, wherein the first feedback message is generated by the data requester based on the first confirmation message.

15. The apparatus according to claim 13, characterized in that, The registration unit is also used for: Obtain the second identity identifier and second password of the third-party cloud management entity, and store the second identity identifier and second password through the third-party cloud management entity, the smart contract, the miner and the blockchain; Obtain a second confirmation message and send the second confirmation message to the third-party cloud management entity through the smart contract, wherein the second confirmation message is generated by the smart contract based on the second identity identifier; A second feedback message is obtained and sent to the smart contract through the third-party cloud management entity, wherein the second feedback message is generated by the third-party cloud management entity based on the second confirmation message.

16. The apparatus according to claim 13, characterized in that, The registration unit is also used for: Obtain the second identity identifier and second password of the third-party cloud management entity, and store the second identity identifier and second password through the third-party cloud management entity, the smart contract, the miner, the data owner, and the blockchain; Obtain a third confirmation message and send the third confirmation message to the third-party cloud management entity through the data owner, wherein the third confirmation message is generated by the data owner based on the second identity identifier; A third feedback message is obtained and sent to the data owner through the third-party cloud management entity, wherein the third feedback message is generated by the third-party cloud management entity based on the third confirmation message.

17. The apparatus according to claim 12, characterized in that, The encryption processing unit is further configured to: The shared data provided by the data owner is segmented to obtain segmented data blocks, and all the segmented data blocks are stored in the blockchain; For each of the segmented data blocks, the hash value of the previous data block on other chains in the blockchain is obtained, and multi-chain cross-encryption processing is performed on the corresponding segmented data block according to the hash value to obtain the encrypted shared data composed of all the encrypted data blocks.

18. The apparatus according to claim 17, characterized in that, The encryption processing unit is further configured to: Obtain the first data characteristics of the shared data and the first performance data of the current network, and obtain the target segmentation strategy based on the first data characteristics and the first performance data; The shared data is segmented according to the target segmentation strategy.

19. The apparatus according to claim 17, characterized in that, The encryption processing unit is further configured to: For each encrypted data block, a first evaluation result is obtained for at least two candidate storage regions, and a target storage region is determined based on the first evaluation result, wherein the first evaluation result is calculated by the smart contract based on the second data characteristics of the encrypted data block and the second performance data of the current network; Obtain a second evaluation result for at least two candidate storage nodes in the target storage area, determine the target storage node based on the second evaluation result, and store the encrypted data block in the corresponding target storage node, wherein the second evaluation result is calculated by the smart contract based on the third performance data of the candidate storage nodes.

20. The apparatus according to claim 19, characterized in that, The encryption processing unit is further configured to: For any of the target storage nodes, determine the corresponding adjacent storage nodes; The hash value of the encrypted data block stored in the target storage node is obtained, and the hash value is sent to the adjacent storage node for storage through the smart contract, wherein the hash value is generated by the smart contract.

21. The apparatus according to claim 12, characterized in that, The verification unit is further configured to: Obtain the target verification strategy, and perform verification operations between the third-party cloud management entity and the corresponding other entities according to the target verification strategy. The other entities corresponding to the third-party cloud management entity include the data owner, the data requester, and the smart contract.

22. The apparatus according to claim 12, characterized in that, The data transmission unit is further configured to: In response to the detection that the transmission path switching conditions are met, an alternative transmission path is determined, and the target encrypted data is sent to the data requester through the alternative transmission path.

23. An electronic device, characterized in that, include: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method as described in any one of claims 1-11.

24. A processor-readable storage medium having a computer program stored thereon, characterized in that, The computer program is used to cause the processor to perform the method as described in any one of claims 1-11.

25. A computer program product comprising a computer program that, when executed by a processor, implements the method as described in any one of claims 1-11.