Data security management device and method based on block chain
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- 雷鑫
- Filing Date
- 2023-10-20
- Publication Date
- 2026-04-14
Smart Images

Figure CN121859348A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security management equipment technology, and specifically to a data security management device and method based on blockchain. Background Technology
[0002] Blockchain is a decentralized distributed ledger technology that links data together in blocks and uses cryptographic techniques to ensure the security and immutability of the data.
[0003] Blockchain-based data security management methods distribute control over data storage, transmission, and access to various nodes in the network. This ensures that the blockchain does not rely on a single central server but is maintained jointly by multiple nodes in the network. This makes the data less vulnerable to a single attack point, thus improving data security. At the same time, each data block contains the hash value of the previous block, forming a continuously linked data chain. Once data is written to the blockchain, tampering with the data would require modifying all subsequent blocks simultaneously, which is virtually impossible, thus guaranteeing the immutability of the data.
[0004] The security and distributed nature of current blockchain technology provides a robust framework for data management and exchange. Faced with the challenge of high computing and storage costs, hardware wallets have emerged as a powerful security solution, offering a more secure method for managing digital assets by combining cryptographic technology and security chips.
[0005] Existing data management devices, due to their inherent structure, remain connected to the internet even after blockchain nodes reject requests from unauthorized users. This presents a vulnerability in terms of privacy and security, especially for high-value data. Even if the device denies access, if no measures are taken to expel unauthorized users after the device connects to the network, the data will remain exposed.
[0006] To address these issues and improve the security and efficiency of data storage, this invention provides a blockchain-based data security management device and method to solve the aforementioned problems. Summary of the Invention
[0007] The technical problem that this invention aims to solve is that, due to its inherent structure, existing data management devices remain connected to the Internet even after a blockchain node rejects a request from an unauthorized user, thus keeping the data exposed.
[0008] To solve the aforementioned technical problem, the present invention adopts the following technical solution: providing a blockchain-based data security management device, including a housing, a security key module, a security chip, a storage module, a random number generator, and an interface; one end of the housing is provided with an interface, one end of the interface is equipped with a storage module, one end of the storage module is equipped with a security key module, one side of the security key module is equipped with a security chip, and the side wall of the housing is equipped with a random number generator.
[0009] When a user first launches the hardware wallet, the security key module initializes, generating a unique seed that forms the basis for generating all subsequent encryption keys. The hardware wallet has a built-in security chip with hardware encryption and decryption capabilities, protecting the private key from physical attacks or malware intrusion, and ensuring the private key never leaves the security chip. The storage module within the security chip stores the cryptocurrency's private key and seed, keeping this information internal and not directly exposed to the outside. To ensure key randomness, the device has an internal random number generator used to generate data such as the public key, private key, and encrypted address.
[0010] It also includes a spring-back mechanism and connector pins; the connector pins are installed inside the interface, and the device reduces the risk of unauthorized access through the two-way verification and encryption mechanism of the blockchain; the spring-back mechanism is set on both sides of the interface, and the spring-back mechanism is deformed by the thrust when the device is connected, thereby enabling the security chip to interact with the current user, and controlling the polarity of the magnetic pole through the controller to eject and lock the unauthorized device from the interface.
[0011] The rebound mechanism includes a base plate, a push block, an extension post, a compression spring, a limiting groove, a slide rod, and a magnetic attraction assembly. The base plate is fixedly connected to the inner wall of the interface, i.e., arranged vertically, and serves as the foundation for the insertion device. When the device is inserted, the rebound mechanism activates. One side of the base plate has a guide groove for fixing the direction of the push block. The push block is slidably connected within the guide groove. The guide groove primarily provides correct guidance for the push block during device insertion, ensuring it remains stable within the rebound track. One side of the push block is fixedly connected to a push block that is synchronized with it. The push block is fixedly connected to the extension post, which is inserted into the compression spring, thus engaging the push block within the spring. The extension post and the compression spring are coaxially positioned, compressing the spring to provide the spring force for the rebound mechanism to eject the device. A limiting groove is provided at the lower end of the push block, and one end of the slide rod is located within the limiting groove. The slide rod, through the magnetic pole conversion of the magnetic attraction assembly within the limiting groove, ejects unauthorized devices via the rebound mechanism.
[0012] The slide rod extends with hooks perpendicular to its ends. The slide rod is long and U-shaped at both ends due to the hooks. The hooks are the same length as the depth of the limiting groove. The hooks slide synchronously within the limiting groove when the push block moves, thus providing stability to the rebound mechanism when the device is inserted. At the same time, it provides resistance when the device is inserted. This resistance is secured by a slot within the limiting groove. When an unauthorized user is detected, the resistance of the compression spring can be used to eject the device, thereby ensuring privacy and security.
[0013] The push block has a rectangular cavity on one side that provides a sliding space for the slide rod of the rebound mechanism. The limiting groove is an annular closed groove and is opened on the upper wall of the rectangular cavity, thus engaging with the hook foot. The starting section of the annular closed groove is in the same direction as the sliding channel of the slide rod, so that the slide rod can slide along the same track when the equipment is connected. Then, through the setting of the height difference, the slide rod is guided to the next area, and through the annular structure, the trajectory of the slide rod is guided, so that the slide rod can achieve reset and engagement.
[0014] The limiting groove is provided with a gradient difference to guide the slide bar. With the interface not connected as the base state, and the area where the hook foot is located as area a, there are also four areas in the clockwise direction: area b, area c, area d, and area e. The height of area b, area c, area d, area a, and area e are arranged from high to low. Thus, the slide bar can be ejected by the elastic force of the compressed spring when the rebound mechanism receives an unauthorized user.
[0015] When the slide bar slides into zone a, the thrust provided by the external connection raises the height of the slide bar, allowing it to slide into zone b. Since zone b has the highest gradient difference, the slide bar then slides into zone c, which has a lower gradient, through the height difference. After passing through the notch, it is stably engaged in zone d. Then, under the action of the magnetic suction component, the slide bar is selectively slid into zone e. Since zone e and zone a are connected by a closed loop, when the magnetic suction component bends during the movement of the slide bar, the slide bar will be guided by the slope and restored to its original state by the rebound force of the compression spring. The whole process is the rebound process of the rebound mechanism.
[0016] The magnetic attraction assembly is rotatably connected to region d. The magnetic attraction assembly includes a magnetic pole plate, a hinge shaft, and a torque spring. One end of the magnetic pole plate is attached to the edge of region e, and the hinge shaft is installed at a position opposite to the edge of region e. Thus, the magnetic pole plate deflects when the magnetic pole changes, which can guide the slide rod to slide towards region e. The hinge shaft is equipped with a torque spring, which provides a rebound force when the magnetism of the magnetic pole plate disappears.
[0017] The magnetic force generated by the magnetic suction component after being energized can deflect the magnetic suction plate, thereby causing the hinge shaft to deflect and the torque spring inside the hinge shaft to rotate. Combined with the slope formed by the magnetic suction plate, the slide rod can slide into area e through the slope. When the device senses that the return mechanism process has ended, the magnetic suction plate is de-energized. At this time, the magnetic force disappears, and under the elastic force of the torque spring, the magnetic suction plate returns to a parallel state.
[0018] The connection points between areas b and c, and between areas c and d, are all provided with slits, which allows the slide bar of the rebound mechanism to be within the limiting groove. The main purpose is to facilitate the stability and smoothness of different areas during the sliding process and reduce the probability of jamming.
[0019] The interface is equipped with two spring-loaded mechanisms, which are evenly arranged on the inner wall of the interface. The interface is equipped with multiple connector pins, and half of the connector pins overlap vertically. This allows for independent connection points of the connectors and disperses the spring-loaded mechanisms, thus speeding up the emergency spring-loaded process of the device.
[0020] A blockchain-based data security management method includes the following steps:
[0021] S1: First, the device is initialized and authenticated. When the system starts, the IoT device will start its initialization process and use a public / private key authentication mechanism based on elliptic curve cryptography to verify its identity. It will also use the generated key pair to authenticate with the authentication server or blockchain network, while loading the contract address and ABI.
[0022] S2: After initialization, when the RFID tag detects the presence of an unauthorized user, the IoT device will work with the embedded system to control the magnetic pole current through the hardware interface, so that the magnetic pole plate is energized and the magnetic pole plate descends to form a slope.
[0023] S3: After the magnetic pole plate is energized, the IoT device interacts with the smart contract on the blockchain. The device generates a transaction and submits it to the blockchain network. The transaction contains details about unauthorized user events.
[0024] S4: Nodes in the blockchain network verify the transaction, including the integrity of the data and the validity of the digital signature. Once the verification is successful, the transaction will be recorded on an immutable distributed ledger.
[0025] S5: After handling an unauthorized event, the rebound mechanism ejects the device, and the IoT device terminates the current supply to the magnetic poles, thereby eliminating magnetism;
[0026] S6: To ensure consistency between the device status and blockchain data for each transaction, IoT devices need to periodically synchronize the latest data on the blockchain.
[0027] The beneficial effects of this invention are as follows:
[0028] 1. This invention incorporates a spring-back mechanism in a blockchain-based data security management device. By verifying data on the blockchain and providing authorization, the device is ejected after authorization failure via the spring-back mechanism, thereby reducing the number of connector pins connected.
[0029] 2. This invention has unique advantages in equipment authorization through intelligent design, giving the mechanism the ability to identify unauthorized equipment. When unauthorized equipment is inserted, magnetic conversion causes the slide bar to act within the limiting groove, thereby triggering the rebound mechanism to eject it, effectively preventing unauthorized equipment from interfering with and posing risks to the system.
[0030] 3. By setting a closed-loop limiting groove, this invention ensures that the slide bar moves along the same track during equipment connection, thus guaranteeing stability. The application of height difference and ring structure in the design allows the slide bar to be accurately guided when passing through different areas, providing a path for operations such as resetting and locking. Attached Figure Description
[0031] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the accompanying drawings used in the description of the specific embodiments or the prior art will be briefly introduced below.
[0032] Figure 1 This is a schematic diagram of the internal components provided in an embodiment of the present invention;
[0033] Figure 2 This is a schematic diagram of the position of the springback mechanism provided in an embodiment of the present invention;
[0034] Figure 3 This is a schematic diagram of the limiting groove provided in an embodiment of the present invention;
[0035] Figure 4 This is a schematic diagram of the inside of the limiting groove provided in an embodiment of the present invention;
[0036] Figure 5 This is a schematic diagram of the gradient difference of the limiting groove provided in an embodiment of the present invention;
[0037] Figure 6 A schematic diagram of the magnetic attraction component provided in an embodiment of the present invention;
[0038] Figure 7 A schematic diagram of a blockchain framework provided in an embodiment of the present invention;
[0039] Figure 8 This is a schematic diagram of certificate traceability provided in an embodiment of the present invention;
[0040] Figure 9 A flowchart of a blockchain data management method provided in an embodiment of the present invention.
[0041] In the diagram: 1. Housing; 2. Security key module; 3. Security chip; 4. Storage module; 5. Random number generator; 6. Interface; 7. Springback mechanism; 71. Base plate; 711. Guide groove; 72. Push block; 721. Rectangular cavity; 73. Extension column; 74. Compression spring; 75. Limiting groove; 751. Area a; 752. Area b; 753. Area c; 754. Area d; 755. Area e; 76. Slide rod; 761. Hook foot; 77. Magnetic suction assembly; 771. Magnetic pole plate; 772. Hinge shaft; 773. Torque spring; 774. Cutout; 78. Push block; 8. Connector pin. Detailed Implementation
[0042] The specific embodiments of the present invention will be further described below with reference to the accompanying drawings. It should be noted that these descriptions are for the purpose of aiding understanding the present invention and do not constitute a limitation thereof. Furthermore, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.
[0043] like Figure 1 As shown, a blockchain-based data security management device includes a housing 1, a security key module 2, a security chip 3, a storage module 4, a random number generator 5, an interface 6, a spring-loaded mechanism 7, and connector pins 8. One end of the housing 1 has an interface 6, and one end of the interface 6 houses the storage module 4. The storage module 4 has the security key module 2 installed at one end of the storage module 4. The security chip 3 is installed on one side of the security key module 2, and the random number generator 5 is installed on the side wall of the housing 1. The connector pins 8 are installed inside the interface 6. The device reduces the risk of unauthorized access through the two-way verification and encryption mechanism of the blockchain. The spring-loaded mechanism 7 is located on both sides of the interface 6. When a device is connected, the spring-loaded mechanism 7 deforms, causing the security chip 3 to interact with the current user. The controller controls the polarity of the magnetic poles to eject and lock unauthorized devices from the interface 6.
[0044] When a user first launches the hardware wallet, the security key module 2 initializes and generates a unique seed, which serves as the basis for generating all subsequent encryption keys. The hardware wallet has a built-in security chip 3, which includes hardware encryption and decryption functions to protect the private key from physical attacks or malware intrusion, and the private key never leaves the security chip 3. The storage module 4 within the security chip 3 is responsible for storing the cryptocurrency's private key and seed, and this information is stored internally and not directly exposed to the outside. To ensure the randomness of the keys, a random number generator 5 is set up inside the device to generate data such as public keys, private keys, and encrypted addresses.
[0045] During initialization, the device needs to connect to the network to communicate with blockchain nodes. Security initialization is then performed, generating a key pair, including a public key and a private key, for authentication and encrypted communication. The private key must be securely stored to prevent unauthorized access. The public key will be used for communication with the blockchain network. Subsequently, the generated key pair is used to authenticate with an authentication server or the blockchain network, ensuring that only authorized devices can communicate with the blockchain network and perform specific operations. The device needs to load smart contract information related to its functionality, including the contract address and ABI, which will be used for subsequent interactions with the smart contract.
[0046] like Figure 2 , Figure 3 , Figure 4 and Figure 5 As shown, the spring-back mechanism 7 includes a base plate 71, a pushing block 72, an extension post 73, a compression spring 74, a limiting groove 75, a sliding rod 76, and a magnetic suction assembly 77. The base plate 71 is fixedly connected to the inner wall of the interface 6, i.e., arranged vertically, and serves as the base for the insertion device. When the device is inserted, the spring-back mechanism 7 begins to function. One side of the base plate 71 is provided with a guide groove 711 that fixes the direction of the pushing block 72. The pushing block 72 is slidably connected within the guide groove 711. The main purpose of the guide groove 711 is to provide correct guidance for the pushing block 72 during device insertion, so that the pushing block 72 can be stably positioned during insertion. Inside the spring track, a push block 78, which is synchronous with the push block 72, is fixedly connected to one side of the push block 72. The push block 78 is fixedly connected to the extension column 73. The extension column 73 is inserted into the compression spring 74, thereby engaging the push block 78 within the compression spring 74. The extension column 73 and the compression spring 74 are placed coaxially, thereby the compression spring 74 provides the spring force for the rebound mechanism 7 to eject the device. A limit groove 75 is provided at the lower end of the push block 72. One end of the slide rod 76 is located within the limit groove 75. When an unauthorized device is inserted, the slide rod 76 is ejected by the rebound mechanism 7 through the magnetic pole conversion of the magnetic attraction component 77 within the limit groove 75.
[0047] The guide groove 711 on one side of the substrate 71 and the sliding connection mechanism of the push block 72 ensure that the device maintains the correct guidance during insertion, effectively avoiding insertion deviation, so that the push block 72 can always slide stably within the springback track. At the same time, the push block 72 is connected to the synchronously moving push block 78, further enhancing the control and stability of the push block 72.
[0048] In the implementation of the rebound mechanism, the extension post 73 inserts into the compression spring 74 to engage the push block 78 within the compression spring 74. The extension post 73 and the compression spring 74 are placed coaxially, allowing the compression spring 74 to provide just the right amount of spring force. This design ensures that after the device is inserted, the compression spring 74 generates sufficient rebound force to quickly and smoothly eject the device from the interface 6, ensuring safe and stable device insertion and removal operations.
[0049] The intelligent design of the spring-loaded mechanism 7 offers unique advantages in device authorization. The interaction between the limiting groove 75 at the lower end of the push block 72 and the magnetic attraction component 77 within the limiting groove 75 on the slide rod 76 enables the mechanism to identify unauthorized devices. When an unauthorized device is inserted, magnetic conversion causes the slide rod 76 to move through the limiting groove 75, triggering the spring-loaded mechanism 7 to eject it, effectively preventing interference and risks to the system from unauthorized devices.
[0050] The slide rod 76 has hook feet 761 extending from both ends, perpendicular to the slide rod 76. The slide rod 76 is long and the two ends are U-shaped due to the hook feet 761. The length of the hook feet 761 is the same as the depth of the limiting groove 75. The hook feet 761 slide synchronously in the limiting groove 75 when the pushing block 72 moves, thereby providing stability for the rebound mechanism 7 when the device is inserted. At the same time, it is necessary to provide resistance when the device is inserted. This resistance is locked by the slot in the limiting groove 75. When an unauthorized user is detected, the resistance of the compression spring 74 can be used to pop the device out, thereby ensuring the security of privacy.
[0051] The push block 72 has a rectangular cavity 721 on one side, which provides sliding space for the slide rod 76 of the rebound mechanism 7. The limiting groove 75 is an annular closed groove and is opened on the upper wall of the rectangular cavity 721, and then engages with the hook foot 761. The starting section of the annular closed groove is in the same direction as the sliding channel of the slide rod 76, so that the slide rod 76 can slide along the same track when the equipment is connected. Then, through the setting of the height difference, the slide rod 76 is guided to the next area, and through the annular structure, the trajectory of the slide rod 76 is guided, so that the slide rod 76 can be reset and engaged.
[0052] The U-shaped design of the slide bar 76 and the depth of the limiting groove 75 that matches the hook foot 761 enable the slide bar 76 to slide synchronously within the limiting groove 75 when the push block 72 moves, ensuring stability during the insertion process of the device and providing necessary resistance when inserting the device to prevent accidental or excessive movement during insertion; the slide bar 76 can be firmly locked in place by the locking mechanism within the limiting groove 75.
[0053] The interaction between the rectangular cavity 721 on one side of the push block 72 and the annular closed groove further enhances the performance of the rebound mechanism 7. The annular closed groove, acting as a limiting groove 75, is located on the upper wall of the rectangular cavity 721 and is tightly engaged with the hook foot 761. The design of the rectangular cavity 721 provides space for the sliding rod 76 to slide, while the starting section of the annular closed groove is aligned with the sliding channel of the sliding rod 76, ensuring that the sliding rod 76 moves along the same track during equipment connection, thus guaranteeing stability. The height difference and the application of the annular structure in the design allow the sliding rod 76 to be precisely guided when passing through different areas, providing a path for operations such as reset and engagement.
[0054] The limiting groove 75 is provided with a gradient difference to guide the slide bar 76. With the interface 6 not connected as the base state, and the area where the hook foot 761 is located is area a 751, there are also four areas in the clockwise direction: area b 752, area c 753, area d 754 and area e 755. The heights from high to low are area b 752, area c 753, area d 754, area a 751 and area e 755. Thus, the slide bar 76 can be ejected by the elastic force of the compression spring 74 when the rebound mechanism 7 receives an unauthorized user.
[0055] When the slide rod 76 slides into area a 751, the thrust provided by the external connection raises the height of the slide rod 76, causing it to slide into area b 752. Since the gradient difference in area b is the highest, the slide rod 76 then slides into area c 753, which has a lower gradient, through the height difference. After passing through the notch 774, it is stably engaged in area d 754. Then, under the action of the magnetic suction component 77, the slide rod 76 is selectively slid into area e 755. Since area e 755 and area a 751 are connected through a closed loop, when the magnetic suction component 77 bends during the movement of the slide rod 76, the slide rod 76 will be guided by the slope and restored to its original state by the rebound force of the compression spring 74. The whole process is the rebound process of the rebound mechanism 7.
[0056] By setting a gradient difference within the limiting groove 75, dividing it into different areas such as area a 751, area b 752, area c 753, area d 754, and area e 755, the height of the slide rod 76 can be adjusted step by step according to external conditions. Taking the unconnected state of interface 6 as the base state, the gradient difference between different areas allows the slide rod 76 to adjust its position appropriately at different stages. The movement mode of the slide rod 76 in different areas and the application of gradient differences enable the rebound mechanism 7 to intelligently react according to external conditions. The movement process of the slide rod 76 is from area a 751 to area b 752, then to area c 753, then through the cut 774 into area d 754, where it is stably engaged, and finally slides into area e 755 through the action of the magnetic suction component 77. There is a closed-loop connection between area e 755 and area a 751; during the movement, the slide rod 76 is affected by the elastic force of the compression spring 74, rebounding in an intelligent manner. When the magnetic attachment 77 bends as the slide bar 76 moves, the slide bar 76 will automatically return to its original state guided by the slope and the rebound force of the compression spring 74. This adaptive rebound mechanism plays a crucial role in ensuring that the device can be quickly ejected when not needed, thus maintaining privacy and data security, when an unauthorized user inserts the device.
[0057] like Figure 6 As shown, the magnetic attraction assembly 77 is rotatably connected to region d 754. The magnetic attraction assembly 77 includes a magnetic pole plate 771, a hinge shaft 772, and a torque spring 773. One end of the magnetic pole plate 771 is in contact with the edge of region e 755, and the hinge shaft 772 is installed at a position opposite to the edge of region e 755. Thus, the magnetic pole plate 771 deflects when the magnetic pole changes, which can guide the slide rod 76 to slide towards region e 755. The torque spring 773 is provided inside the hinge shaft 772, thereby providing the rebound force when the magnetism of the magnetic pole plate 771 disappears.
[0058] The magnetic force generated by the magnetic suction component 77 after being energized can deflect the magnetic suction plate, thereby causing the hinge shaft 772 to deflect and the torque spring 773 inside the hinge shaft 772 to rotate. Combined with the slope formed by the magnetic suction plate, the slide rod 76 can slide into area e 755 through the slope. When the device senses that the process of the rebound mechanism 7 has ended, the magnetic suction plate is de-energized. At this time, the magnetic force disappears, and under the elastic force of the torque spring 773, the magnetic suction plate returns to a parallel state.
[0059] The connection points between area b 752 and area c 753, and between area c 753 and area d 754 are all provided with slits 774, so that the slide rod 76 of the rebound mechanism 7 can be in the limiting groove 75. The main purpose is to facilitate the stability and smoothness of different areas during the sliding process and reduce the probability of jamming.
[0060] The magnetic attraction assembly 77 is rotatably connected to region d 754. The magnetic pole plate 771 is in contact with the edge of region e 755 and is mounted opposite to the edge of region e 755 via the hinge shaft 772. This allows the magnetic pole plate 771 to deflect when the magnetic pole changes, thereby guiding the slide rod 76 to slide into region e 755, achieving controllable motion guidance. Secondly, a torque spring 773 is provided inside the hinge shaft 772, which provides the necessary elastic force for the rebound when the magnetism of the magnetic pole plate 771 disappears. When energized, the magnetic attraction assembly 77 generates magnetism, causing the magnetic plate to deflect, which in turn causes the hinge shaft 772 to deflect and the internal torque spring 773 to rotate. Combined with the slope formed by the magnetic plate, the slide rod 76 can smoothly slide into region e 755 through the slope. When the return mechanism 7 finishes its cycle, the magnetic plate is de-energized, the magnetic force disappears, and under the elastic action of the torque spring 773, the magnetic plate returns to a parallel state, achieving motion switching. Cutouts 774 are provided at the connections between areas b 752 and c 753, and between c 753 and d 754. This provides support for the stability and smoothness of the slide rod 76 of the return mechanism 7 within the limiting groove 75. The design of the cutouts 774 effectively reduces the probability of jamming, thereby improving the reliability and stability of the entire system.
[0061] The interface 6 is provided with two spring-back mechanisms 7, which are evenly arranged on the inner wall of the interface 6. The interface 6 is provided with multiple connector pins 8, and half of the connector pins 8 overlap in the vertical direction. This allows for independent connection points of the connectors and disperses the spring-back mechanisms 7, thereby speeding up the emergency spring-back process of the device.
[0062] like Figure 8 As shown, to address the problem of unauthorized certificates being issued for man-in-the-middle attacks, an automated platform for reviewing unauthorized certificates, IKP, is proposed. This platform utilizes smart contracts and consensus mechanisms to achieve decentralization while maintaining original functionality, and employs digital currency to incentivize users to report illegitimate certificates. Furthermore, a blockchain-based, publicly auditable authentication system, Certchain, is proposed, eliminating the need for a central CA. It utilizes a reliability ranking consensus and the CertOper data structure to ensure certificate correctness and traceability. DCBF is used for efficient confirmation of certificate revocation, and a designed three-layer verification mechanism reduces the false positive rate to 0. The traceability of Certchain certificates is guaranteed by the chain structure of the blockchain.
[0063] like Figure 7 As shown, regarding decentralized access control of blockchain, based on the ABAC model, smart contracts are used to manage resource access strategies, and transaction-based access control strategies are used to achieve data resource access control in dynamic environments. Using attribute-based encryption as the access control model, an enterprise-level data sharing and access control framework is proposed to achieve fine-grained access control and data sharing within the enterprise.
[0064] like Figure 9 As shown, when a user wants to change an application's authorization for certain data, permission settings are configured, and the granted permissions and data pointers are recorded on the blockchain. When an application needs to access certain data, it issues a data access request and records it on the blockchain. The system checks the signature and the blockchain record to confirm whether the application has the corresponding data access permission. If the check passes, the operation is recorded on the blockchain, and the database returns the data to the application. Because the blockchain fully records the application's behavior, users can change data access permissions at any time within this system.
[0065] During operation, when a device is plugged in, the IoT device generates a key pair during initialization, including a public key and a private key. These keys are generated based on an elliptic curve cryptography algorithm. The device's public key is broadcast across the blockchain network, and an authentication request, including the device's public key and other identity information, is sent to the blockchain nodes. The blockchain nodes receive the request and extract the device's identity information from the public key. The blockchain nodes verify the digital signature using the known device public key to ensure that the request indeed comes from a legitimate device possessing the private key. Upon successful verification, the blockchain nodes confirm the device's identity and allow it to perform operations on the network.
[0066] Upon receiving the digital signature and plaintext data, the blockchain node uses its public key to decrypt the digital signature, obtaining a cryptographic hash value. The blockchain node then hashes the plaintext data to obtain a decrypted hash value. It compares the decrypted hash value with the hash value of the original data. If they match, the digital signature is valid. If authentication fails, the IoT device collaborates with the embedded system, controlling the magnetic pole current via hardware interface 6. This energizes the magnetic pole plate 771, triggering a magnetic phenomenon that causes the slider 76 to slide out of area d 754 and into area e 755. The slider is then ejected by the compression spring 74, thus stopping the interaction.
[0067] Even though the present invention has been described with reference to specific exemplary embodiments, many different alternatives and modifications will become apparent to those skilled in the art. It should also be noted that the circuit layout and identification / detection methods within the device of the present invention can be omitted, and can be interchanged or arranged in various ways, while the structure of the device still enables it to perform the functionality of the present invention.
Claims
1. A data security management device based on blockchain, comprising a housing (1), a security key module (2), a security chip (3), a storage module (4), a random number generator (5), and an interface (6); one end of the housing (1) is provided with an interface (6), one end of the interface (6) is equipped with a storage module (4), one end of the storage module (4) is equipped with a security key module (2), one side of the security key module (2) is equipped with a security chip (3), and the side wall of the housing (1) is equipped with a random number generator (5); characterized in that: It also includes a spring-back mechanism (7) and connector pins (8); the connector pins (8) are installed inside the interface (6), and the device reduces the risk of unauthorized access through the two-way verification and encryption mechanism of the blockchain; the spring-back mechanism (7) is set on both sides of the interface (6), and the spring-back mechanism (7) is deformed by the thrust when the device is connected, so that the security chip (3) interacts with the current user and controls the polarity of the magnetic pole through the controller to pop the unauthorized device out of the interface (6) and lock it.
2. The data security management device based on blockchain according to claim 1, characterized in that: The rebound mechanism (7) includes a base plate (71), a push block (72), an extension post (73), a compression spring (74), a limiting groove (75), a slide rod (76), and a magnetic suction assembly (77). The base plate (71) is fixedly connected to the inner wall of the interface (6). A guide groove (711) is provided on one side of the base plate (71) to fix the direction of the push block (72). The push block (72) is slidably connected in the guide groove (711). A push rod that moves synchronously with the push block (72) is fixedly connected to one side of the push block (72). The push block (78) is fixedly connected to the extension column (73). The extension column (73) is placed coaxially with the compression spring (74). The compression spring (74) provides the elastic force for the rebound mechanism (7) to eject the device. The lower end of the push block (72) is provided with a limit groove (75). One end of the slide rod (76) is located in the limit groove (75). When the slide rod (76) causes the unauthorized device to be inserted through the magnetic pole conversion of the magnetic attraction component (77) in the limit groove (75), it is ejected by the rebound mechanism (7).
3. The data security management device based on blockchain according to claim 2, characterized in that: The slide bar (76) extends into hook feet (761) perpendicular to the slide bar (76) at both ends. The hook feet (761) slide synchronously in the limiting groove (75) when the push block (72) moves. The hook feet (761) provide a way to stabilize the rebound mechanism (7) when the device is inserted.
4. A data security management device based on blockchain according to claim 2, characterized in that: The push block (72) has a rectangular cavity (721) on one side that provides sliding space for the slide rod (76) of the rebound mechanism (7). The limiting groove (75) is an annular closed groove and is opened on the upper wall of the rectangular cavity (721), and then engages with the hook foot (761).
5. A data security management device based on blockchain according to claim 2, characterized in that: The limiting groove (75) is provided with a gradient difference to guide the slide bar (76). With the interface (6) not connected as the base state, and the area where the hook foot (761) is located as area a (751), there are also four areas in the clockwise direction: area b (752), area c (753), area d (754) and area e (755). The heights from high to low are area b (752), area c (753), area d (754), area a (751), and area e (755). The slide bar (76) can be ejected by the elastic force of the compression spring (74) when the rebound mechanism (7) receives an unauthorized user.
6. A data security management device based on blockchain according to claim 5, characterized in that: The magnetic attraction assembly (77) is rotatably connected to region d (754). The magnetic attraction assembly (77) includes a magnetic pole plate (771), a hinge shaft (772), and a torque spring (773). One end of the magnetic pole plate (771) is in contact with the edge of region e (755), and the hinge shaft (772) is installed at a position opposite to the edge of region e (755). The magnetic pole plate (771) deflects when the magnetic pole changes, which can guide the slide rod (76) to slide towards region e (755). The hinge shaft (772) is provided with a torque spring (773), which provides the rebound force when the magnetism of the magnetic pole plate (771) disappears.
7. A data security management device based on blockchain according to claim 5, characterized in that: A notch (774) is provided at the connection between area b (752) and area c (753), and between area c (753) and area d (754). The notch (774) allows the slide rod (76) of the spring mechanism (7) to slide in the limiting groove (75) by means of the inclined slope.
8. A data security management device based on blockchain according to claim 1, characterized in that: The interface (6) is provided with two spring-back mechanisms (7) and they are evenly arranged on the inner wall of the interface (6). The spring-back mechanisms (7) spring back simultaneously from the top and bottom, so that the device can be quickly ejected during unauthorized processes. The interface (6) is provided with multiple connector pins (8).
9. A blockchain-based data security management method, wherein the method employs a blockchain-based data security management device as described in any one of claims 1 to 8, characterized in that: The blockchain-based data security management method includes the following steps: S1: First, the device is initialized and authenticated. When the system starts, the IoT device will start its initialization process and use a public / private key authentication mechanism based on elliptic curve cryptography to verify its identity. It will also use the generated key pair to authenticate with the authentication server or blockchain network, while loading the contract address and ABI. S2: After initialization, when the RFID tag detects the presence of an unauthorized user, the IoT device will work with the embedded system to control the magnetic pole current through the hardware interface (6), so that the magnetic pole plate (771) is energized and the magnetic pole plate (771) descends to form a slope; S3: After the magnetic pole plate (771) is powered on, the IoT device interacts with the smart contract on the blockchain, the device generates a transaction and submits it to the blockchain network, the transaction contains details about unauthorized user events; S4: Nodes in the blockchain network verify the transaction, including the integrity of the data and the validity of the digital signature. Once the verification is successful, the transaction will be recorded on an immutable distributed ledger. S5: After handling the unauthorized event, the spring mechanism (7) ejects the device, and the IoT device will terminate the current supply to the magnetic pole, thereby eliminating the magnetism; S6: To ensure consistency between the device status and blockchain data for each transaction, IoT devices need to periodically synchronize the latest data on the blockchain.