Movatterモバイル変換


[0]ホーム

URL:


CN109325331A - Big data collection and transaction system based on blockchain and trusted computing platform - Google Patents

Big data collection and transaction system based on blockchain and trusted computing platform
Download PDF

Info

Publication number
CN109325331A
CN109325331ACN201811069639.XACN201811069639ACN109325331ACN 109325331 ACN109325331 ACN 109325331ACN 201811069639 ACN201811069639 ACN 201811069639ACN 109325331 ACN109325331 ACN 109325331A
Authority
CN
China
Prior art keywords
data
block
chain
dcc
module
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201811069639.XA
Other languages
Chinese (zh)
Other versions
CN109325331B (en
Inventor
关振宇
刘建伟
赵莹
李大伟
秦煜瑶
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beihang University
Original Assignee
Beihang University
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beihang UniversityfiledCriticalBeihang University
Priority to CN201811069639.XApriorityCriticalpatent/CN109325331B/en
Publication of CN109325331ApublicationCriticalpatent/CN109325331A/en
Application grantedgrantedCritical
Publication of CN109325331BpublicationCriticalpatent/CN109325331B/en
Activelegal-statusCriticalCurrent
Anticipated expirationlegal-statusCritical

Links

Classifications

Landscapes

Abstract

Translated fromChinese

本发明公开了一种基于区块链和可信计算平台的大数据采集交易系统,包括:用户链上地址验证模块、数据采集模块、数据上传模块、数据可信性验证模块和数据酬劳支付模块。该系统通过融合大规模个人数据孤岛以解决数据源紧缺的问题,并通过对数据的采集、存储、打包、上传操作实施全方位的监督和保护,实现了数据的全链路可信,使用直接匿名证明的方法使得数据采集公司在认证用户链上公钥地址的有效性时保护了用户隐私;并且,基于区块链智能合约去中心化和自动化的特点,保证数据酬劳支付的公开透明,从而在一定程度上调和了个人隐私保护和大数据采集之间的矛盾,并确保了数据源的可信性,同时具有实用性,简单易实现。

The invention discloses a big data acquisition and transaction system based on a blockchain and a trusted computing platform, comprising: a user chain address verification module, a data acquisition module, a data upload module, a data credibility verification module and a data remuneration payment module . The system solves the problem of shortage of data sources by integrating large-scale personal data islands, and implements all-round supervision and protection of data collection, storage, packaging, and uploading operations, and realizes the full link of data. The anonymous proof method enables the data collection company to protect user privacy when verifying the validity of the public key address on the user chain; and, based on the decentralization and automation of blockchain smart contracts, ensures the openness and transparency of data remuneration payments, thereby To a certain extent, the contradiction between personal privacy protection and big data collection is reconciled, and the credibility of the data source is ensured. At the same time, it is practical and easy to implement.

Description

Transaction system is acquired based on the big data of block chain and credible calculating platform
Technical field
It is the present invention relates to cloud computing security technology area, in particular to a kind of big based on block chain and credible calculating platformData acquire transaction system.
Background technique
Recently as the fast development of multimedia technology, software technology and memory technology, the skills such as big data, machine learningArt has a deep effect on and changes social production life style, but reliable data source is that these technologies are implemented, operation, developedPremise.Popularizing for internet of things equipment provides resolving ideas for big data source problem in short supply, and extensive internet of things equipment can be adoptedThe personal locating and tracking record data of collection, individual health data, personal lifestyle habit and hobby data etc. are a variety of with economic analysisThe data of value, but how to guarantee fair credible and data set provider the privacy of data trade currently without mature solutionCertainly scheme.
Summary of the invention
The application is to be made based on inventor to the understanding of following problems and discovery:
Internet network application technology fast development is universal, and the development of Web2.0 leads to the network user and network number in additionIt grows at top speed according to amount, the characteristics of more stringent requirements are proposed for storage and processing ability of the user to data, cloud computing has catered to thisA little demands.The cloud computing service of centralization provides great convenience for user's storage, and user need not be concerned about complicated hardware againManagement.Although cloud computing has these attracting advantages, it also brings new security challenge and threat to data protection: firstFirst, since user physically has their data no longer, the encryption for being conventionally used to data protection cannot be directly used.ItsSecondary, although the equipment under cloud computing is more powerful than personal computing devices reliable, they still suffer from inside and outside numberIt is threatened according to integrality, the hackers for largely coveting cloud data ceaselessly excavate service provider Web using upper loophole, with expectationIt makes a breach, obtains valuable data.Finally, that have high priority data access right is not user oneself, but cloud computingService provider.Due to benefits program, cloud service supplier may have dishonest conduct to the data of user.Private clound has objectControllability, specificity and high security are managed, so being the choosing of current more and more people using private cloud storage individual privacy dataIt selects.
Data demand collected of the embodiment of the present invention copes with Internet of Things from the hardware physical equipment by certification, systemSensor device carries out authentication.Conventional authentication mode is normally based on Cryptography Principles, by key storage non-volatileIn memory, certification and protection secret information therein to physical entity are realized by modes such as digital signature, encryptions, howeverThis mode may suffer from the physical attacks such as Network Intrusion, half Network Intrusion, side-channel attack, be also easy to soft by virus etc.The attack of part;Application of traditional authentication mode in the case where resource is limited, computing capability is poor can also there is a problem of manyAnd obstacle.Different from conventional authentication mode, the present invention uses the hardware accreditation scheme energy based on physics unclonable functionEffectively solve the problems, such as above-mentioned key storage and authentication.(Physical Unclonable Function, physics is or not PUFFunction can be cloned) it is widely used in digital circuit, usually broadly it is divided into the PUF based on the storage and PUF based on delay.ItsPrinciple be using certain rule by physical entity in process for making caused by random sex differernce and physics inhomogeneitiesIt extracts, under the premise of entity inputs an excitation, a uncertain response is exported, using the response as the physicsThe unique identification of hardware entities.In the PUF scheme of digital circuit, (Challenge Response Pairs swashs corresponding CRPsEncourage response to) can excitation input after, pass through BIST (Built-in self-test, self testing circuit) generate.PUF technology withThe excellent properties such as uniqueness, unpredictability, nonclonability and anti-tamper property can solve authentication and management, knowledge producePower protection and generation of encryption keys.
The network safety preventions such as traditional firewall, intrusion detection and virus defense means all lay particular emphasis on protection serverInformation security, and relatively fragile terminal just increasingly becomes the Main Weak Links of information system security.For these systemsDemand for security and all kinds of attack means, trust computing are set about from Computer Architecture, establish a kind of letter from hardware securityAppoint transport system to guarantee the credible of terminal, people and program, people and machine and interpersonal trust are solved from sourceProblem." credible " that industrial circle is generally accepted refers to establishes believable calculating environment based on security chips, it is ensured that system is realBody it is anticipated that behavior execute, wherein the safety chip for being embedded in hardware platform is known as credible platform module (TrustedPlatform Module, TPM), platform is collectively referred to as credible calculating platform.Trusted Computing Group (TCG) also proposed credible meterCalculate the related specifications of platform.The function that credible calculating platform generally has has: establishing root of trust and determines trust anchor, constructs credibleChain makes to trust transmitting layer by layer, platform identity proves, completeness of platform proves the function of connecting with support trustable network.To prevent from dislikingMeaning user makes up a large amount of false datas and uploads transaction, and the present invention uses reliable computing technology to mention for the acquisition of data, storage, processingFor the credible of full link.
It 2008, is put forward for the first time by middle acute hearing (Satoshi Nakamoto) and the Standard Proof concept of bit coin, areaBlock chain (Blockchain) technology, as a kind of information technology most crucial in bit coin transaction system, because of its transaction systemWhat open, not depend on any trust authority decentralization, timestamp and digital signature was guaranteed can not tamper and conjunctionMethod transaction be stored in block chain it is permanent the features such as, solve the problems, such as dual consumption problem and Byzantium general, and realize oneCommon recognition network system of the kind without trust.Then more and more block chain projects are come into being, and ether mill (Ethereum) isWherein representative one, it is the complete information system of figure spirit and supports that customized intelligent contract, intelligent contract areOne section of executable code on block chain, when a triggering condition is met, open and clear intelligent contract can go central place to hold automaticallyRow.This favors ether mill by more and more developers.The present invention is based on the peaces that block chain technology completes critical dataEntirely, fair, the automatic payment with data reward is permanently stored.
Based on above-mentioned application demand and technical background, the embodiment of the present invention is that one kind is set for extensive personal Internet of thingsThe credible big data of standby network acquires transaction system.Private clound, PUF, trust computing, block chain are merged to the system innovationTechnology solves the problem of under the premise of guaranteeing data validity and justice of exchange while protecting data set provider privacy, rightFused data isolated island solves the problems, such as that data are in short supply and is of great significance.
The present invention is directed to solve at least some of the technical problems in related technologies.
For this purpose, it is an object of the invention to propose that a kind of acquired based on the big data of block chain and credible calculating platform is tradedSystem, the contradiction which has reconciled to a certain extent between personal privacy protection and big data acquisition, and ensure data sourceCredibility, and have the advantages that practical, simple easily to realize.
In order to achieve the above objectives, the embodiment of the present invention proposes a kind of big data based on block chain and credible calculating platformAcquire transaction system, comprising: address verifying module on user's chain is used for data Collection Co., Ltd DCC, trusted third party TTP and useCommunication interaction proves (Direct Anonymous Attestation, DAA) agreement to complete Direct Anonymous between family, and will be withDCC trade user white list is added in public key address on the block chain of credible privately owned cloud platform binding;Data acquisition module, for privateIntegrity measurement (the Integrity of capture program code page is executed while having cloud platform to be acquired operationMeasurement) to obtain the first platform status, and hardware fingerprint is obtained and uploaded by Internet of things node, and described in utilizationThe data deblocking of credible privately owned cloud platform safely generates data voucher (Data Credential) with encapsulation function, to obtainThe foundation of subsequent module verify data credibility;Data uploading module, for executing the integrity measurement of upload program code pageTo obtain the second platform status, and data block voucher (Data is generated after linking packing with the data voucher of any time periodBlock Credential), and shape of the public key address to trade on the block chain by being bound with the credible privately owned cloud platformFormula is uploaded to System Committee's chain;Data credibility authentication module, after announcing the data type for it is expected purchase in the DCC,The corresponding block number of user feedback and corresponding original data set are received, and the DCC is obtained under the assistance of the TTPBy legitimate device under trusted status the corresponding effective district block number of acquired data, and calculate the data block of the effective blockCredential verification value is uploaded to intelligent contract entrance;Data recompense payment module, for passing through the automatic traceability chain of the intelligent contractIt is compared the data block voucher of the effective block of upper record with the DCC validation value submitted, with according to compare atThe number of blocks of function is disclosed and is automatically recompensed to user's payment data.
The embodiment of the present invention is to acquire transaction system based on the big data of block chain and credible calculating platform, by dataAcquisition, storage, packing, upload operation implement comprehensive supervision and protection, and the full link for realizing data is credible, using directThe method of anonymous attestation makes DCC protect privacy of user in the validity of public key address on authenticating user's chain;Also, it is based onThe characteristics of intelligence contract decentralization of block chain and automation, guarantees the open and clear of data reward payment, thus in certain journeyThe contradiction reconciled on degree between personal privacy protection and big data acquisition, and ensure the credibility of data source, and have realIt is simple easily to realize with property.
In addition, according to the above embodiment of the present invention acquire transaction system based on the big data of block chain and credible calculating platformSystem can also have following additional technical characteristic:
Further, in one embodiment of the invention, address verifying module is further used on user's chain: rawAt anonymous credentials issuer TTP key;The anonymous credentials are issued to user terminal by TTP and zero-knowledge proof;By describedUser terminal calculates anonymity signature, to realize the DCC verifying user terminal anonymity signature correctness.
Further, in one embodiment of the invention, the data acquisition module is specifically used for: passing through what is embeddedTPM carries out integrity measurement to the capture program code page, generates PCR value and metrics logs, and integrity measurement guarantees dataAcquisition process operates in credible performing environment (Trusted Execution Environment, TEE), PCR value and measurement dayWill can be used for the credible operation of subsequent module verifying acquisition process;Any selection is concentrated from the challenge of registration by internet of things equipmentOne challenge, and responded by executing BIST, challenge-response is uploaded to data, to obtain the hardware fingerprint;Data deblocking and data encapsulation are executed by the TPM, so that data are mutually bound with credible platform module, while being tied up by PCRDue to a kind of platform status, it is subsequent that the application of the technology will lead to the operation for distorting, making up privately owned cloud platform storing data willThe failure of data credibility verifying;According to preset data Structure Calculation each period corresponding data voucher, include by inputSensor measurement data, timestamp, integrity measurement log, integrity measurement value, PUF challenge-response are to, previous time periodData voucher value exports the data voucher value for this period.
Further, in one embodiment of the invention, the data uploading module is specifically used for: by the TPMTo upload data to block chain private clound scripting program code page carry out integrity measurement, generate corresponding metrics logs andPCR value;Input the data voucher, timestamp, the measurement day that integrity measurement generation is carried out to upload program of any one periodWill and metric, and the data block voucher that the output valve obtained after link and hash operation is any time period is executed, andIn the TEE set up, script is uploaded by public key address on chain and sends the transaction comprising data block voucher, so that transaction is beatenIt is permanently recorded on alliance's chain of this system after wrapping chain.
Further, in one embodiment of the invention, the data credibility authentication module is specifically to be used for: passing throughThe type of internet of things equipment data needed for DCC is announced;The corresponding number of initial data is obtained according to the data requirements that the DCC is announcedIt is sent to DCC together according to the block number where block voucher, and by the block number and the initial data;The TTP'sThe number of effective block is obtained under assistance and calculates the data block credential verification value of effective block, and is uploaded to block platform chainCorresponding interface.
Further, in one embodiment of the invention, the data reward payment module is further used for the areaIntelligent contract on block chain obtains effective block according to the data block credential verification value of the DCC effective block inputted and compilesNumber, the data block evidence record value of effective block is simultaneously compared with validation value on the automatic traceability chain of contract, and according to verifyingSuccessful data block voucher number, the intelligence contract are not relied on by third party, automatically to the user payment numberAccording to reward.
The additional aspect of the present invention and advantage will be set forth in part in the description, and will partially become from the following descriptionObviously, or practice through the invention is recognized.
Detailed description of the invention
Above-mentioned and/or additional aspect and advantage of the invention will become from the following description of the accompanying drawings of embodimentsObviously and it is readily appreciated that, in which:
Fig. 1 is to acquire transaction system based on the big data of block chain and credible calculating platform according to one embodiment of the inventionThe structural schematic diagram of system;
Fig. 2 is to be handed over according to being acquired based on the big data of block chain and credible calculating platform for one specific embodiment of the present inventionThe structural schematic diagram of easy system;
Fig. 3 is the data structure schematic diagram according to the data voucher of one embodiment of the invention;
Fig. 4 is the data structure schematic diagram traded according to ether mill alliance's chain of one embodiment of the invention.
Specific embodiment
The embodiment of the present invention is described below in detail, examples of the embodiments are shown in the accompanying drawings, wherein from beginning to endSame or similar label indicates same or similar element or element with the same or similar functions.Below with reference to attachedThe embodiment of figure description is exemplary, it is intended to is used to explain the present invention, and is not considered as limiting the invention.
Before introducing based on the big data of block chain and credible calculating platform acquisition transaction system, first simply introduceThe Fundamentals of Mathematics of the embodiment of the present invention.
(1) bilinear mapIf p is a Big prime,WithIt is the cyclic group of two p ranks, gIt isA generation member,It is a bilinear map.If e meets with properties, we claimWithIt is Bilinear Groups:
1. bilinear characteristics: forThere is e (ua,ub)=e (u, v)ab=e (ub,va);
2. non-degeneracy:At least there is an element g in group, so that the e (g, g) after calculating isSome generation of groupMember, i.e. e (g, g) ≠ 1;
3. computability: there are effective algorithms, so that allThe value of e (u, v) can effectively be calculated.
(2) q-SDH assumes (q-Strong Diffie-HellmanAssumption, q-SDH):
It is the cyclic group that rank is prime number p.Q-SDH assumesMiddle establishment refers to more to all probabilityItem formula time algorithm A, probability:
It is insignificant.Whereinψ is from groupIt arrivesIsomorphism.ψ(g2)=g1
(3) signatures of Knowledge: the embodiment of the present invention has used this work of signatures of Knowledge when constructing Direct Anonymous proof schemeTool.It allows a side to prove that he knows a secret value in the case where not revealing any useful information.This tool is substantiallyIt is that the zero-knowledge proof of knowledge or minimum leakage prove.Such as:
Indicate " about integer α, the zero-knowledge proof of β, δ, and y=gαhβ,It sets up, simultaneously (u≤α≤V) ", y, g, h therein,It is groupAnd groupIn element.Meanwhile it can useThe heuristic signatures of Knowledge converted zero-knowledge proof to message m of Fiat-Shamir, can such as be denoted as SPK { (α): y=gα}(m)。
(4) impact resistant hash algorithm:
Impact resistant hash function used in the embodiment of the present invention has two fundamental characteristics: one-way and anti-collision;One-way, which refers to input from hash function, derives output, and cannot export from hash function and calculate input;Impact resistantProperty refers to that cannot find two different inputs simultaneously keeps its hash result identical.Hash algorithm in the present invention inputsIn plain text, it exports to be mapped to domainIn element.
The big number based on block chain and credible calculating platform proposed according to embodiments of the present invention is described with reference to the accompanying drawingsAccording to acquisition transaction system.
Fig. 1 is one embodiment of the invention based on the big data of block chain and credible calculating platform acquisition transaction systemStructural schematic diagram.
As shown in Figure 1, should include: user's chain based on the big data of block chain and credible calculating platform acquisition transaction system 10Upper address verifying module 100, data acquisition module 200, data uploading module 300, data credibility authentication module 400 and dataRecompense payment module 500.
Wherein, on user's chain address verifying module 100 for data Collection Co., Ltd DCC, trusted third party TTP and user itBetween communication interaction to complete Direct Anonymous identification protocol, and will add with public key address on the block chain of credible privately owned cloud platform bindingEnter DCC trade user white list.Data acquisition module 200 executes acquisition journey while being acquired operation for privately owned cloud platformThe integrity measurement of sequence code page obtains by Internet of things node and uploads hardware fingerprint to obtain the first platform status, andData voucher is safely generated with encapsulation function using the data deblocking of the credible privately owned cloud platform, is tested with obtaining subsequent moduleDemonstrate,prove the foundation of data credibility.Data uploading module 300 is used to execute the integrity measurement of upload program code page to obtain theTwo platform status, and with the data voucher of any time period link packing after generate data block voucher, and by with credible privateThe block chain public key address for having cloud platform to bind is uploaded to System Committee's chain in the form traded.Data credibility authentication module400 for receiving the corresponding block number of user feedback and corresponding initial data after the data type that DCC announces expectation purchaseSet, and DCC obtains under the assistance of TTP by legitimate device the corresponding effective block of the acquired data under trusted statusNumber, and the data block credential verification value of effective district block number is calculated, it is uploaded to intelligent contract entrance.Data recompense payment moduleThe 500 data block voucher for the effective block by recording on the automatic traceability chain of intelligent contract tests it with what DCC was submittedCard value is compared, to be disclosed according to the successful number of blocks of comparison and automatically be recompensed to user's payment data.The present invention is realThe system 10 of example is applied by merging extensive personal data isolated island to solve the problems, such as that data source is in short supply, it can be achieved that fair transparentData trade guarantees the privacy that data set provider can also be protected while the credibility of transaction data.
It is understood that system 10 through the embodiment of the present invention, on the one hand, data Collection Co., Ltd can realize to being purchasedThe verifying of data reliability, integrality;On the other hand, data set provider is while keeping anonymity, deserved data rewardLabor can be disclosed pellucidly automated payment.System proposed by the present invention includes following 3 network entities:
(1) data Collection Co., Ltd (Data Collection Company, DCC): it is desirable that buying personal Internet of things equipment noteRecord data simultaneously provide the enterprise institution of credible calculating platform equipment and trade network platform;
(2) user (User): possessing smart machine and authenticates credible calculating platform and has a mind to carry out of data tradePeople;
(3) trusted third party (Trusted Third Party, TTP): user's smart machine CRPs registration office, DAA associationIn view the issuer (Issuer) of anonymous credential and the operating status that credible calculating platform is submitted can be carried out assessment and safetyThe mechanism of audit.
Specifically, the present embodiments relate to it is a kind of based on PUF, trust computing, block chain technology credible big dataAcquire address verifying module 100 in transaction system 10, including user's chain, data acquisition module 200, data uploading module 300, numberPayment module 500 is recompensed according to Trusting eBusiness module 400 and data, system flow is as follows: 1, address validation mould on user's chainDirect Anonymous identification protocol is completed in block 100:DCC, TTP, user's Three Party Communication interaction, by the area with credible privately owned cloud platform bindingDCC trade user white list is added in public key address on block chain, while not revealing any and subscriber identity information;2, data acquisition moduleBlock 200: the integrity measurement for executing capture program code page obtains the first platform status, and Internet of things node is obtained and uploaded laterHardware fingerprint, both of the above are the foundations of subsequent module verify data credibility, later privately owned cloud platform using data deblocking withEncapsulation function is safely completed the generation of data voucher;3, data uploading module 300: the integrality of upload program code page is executedMeasurement generates data block voucher after being packaged with the data links such as data voucher to obtain the second platform status, by with it is legalThe block chain public key address of credible privately owned cloud platform binding is uploaded to System Committee's chain in the form traded, and reaches and permanently recordsPurpose;4, after data credibility authentication module 400:DCC announces the data type that expectation is bought, the corresponding block number of user feedbackWith corresponding original data set, it is corresponding that DCC obtains under the assistance of TTP by legitimate device the acquired data under trusted statusEffective district block number, calculate effective district block number data block credential verification value, be uploaded to intelligent contract entrance;5, data are recompensedPayment module 500: the data block voucher of the effective block recorded on the intelligent automatic traceability chain of contract submits it with DCCValidation value is compared, and discloses, according to successful number of blocks is compared automatically to the reward of user's payment data.
Main thought: use PUF technology to obtain device hardware fingerprint as hardware on personal Internet of things device node and set" pass " of standby admission authentication.The privately owned cloud platform for being embedded in credible platform module passes through the integrality degree of acquisition data code pageAmount, data decapsulation operation guarantee from having authenticated credibility of the Internet of things node equipment to data link privately owned cloud platform.NumberIt is provided with public key on the block chain of certification TPM binding in such a way that Direct Anonymous proves to data Collection Co., Ltd according to supplierLocation, while the anonymity of itself can also be kept, achieve the purpose that secret protection.Finally, under the support of trusted third party, numberIt can verify that the credibility of data set provider data presented according to Collection Co., Ltd, data reward is obtained by the intelligent contract on block chainTo fair and just payment.
Transaction system 10 is acquired to the big data based on block chain and credible calculating platform below in conjunction with specific embodimentIt is further elaborated.
Further, in one embodiment of the invention, address verifying module 100 is further used on user's chain: rawAt anonymous credentials issuer TTP key;Anonymous credentials are issued to user terminal by TTP and zero-knowledge proof;Pass through user terminal meterAnonymity signature is calculated, to realize that DCC verifies user terminal anonymity signature correctness.
It is understood that user uploads data block voucher cre_blockiThe channel of (i=1,2 ..., N) is blockChain, by held with user embed legal TPM privately owned cloud platform binding block chain on public key addressInitiation transaction,Transaction is completed by the mode that miner is packaged cochain permanent storage.It is added that DCC can address white list will be according on trade user chainDAA agreement is completed by user, DCC and TTP Three Party Communication interaction to realize.Wherein TTP takes on issuer, and task is to interior chimericThe privately owned cloud platform of method TPM issues anonymous credentials;Certifier is served as at user terminal, i.e. credible private clound computing platform end, and task isDAA signature is provided to verifier, being signed message is public key address on user's chain;DCC serves as verifier, and task is that verifying provesThe white list that can trade is added to decide whether to be signed address in the correctness of the signature of DAA provided by person.
The implementation of the module 100 is specifically divided into 4 steps and executes in order, successively are as follows:
Step 1:KeyGen: anonymous credentials issuer TTP key is generated;
Step 2:DAA-Join:TTP issues anonymous credentials to user terminal by zero-knowledge proof;
Step 3:DAA-Sign: user terminal calculates anonymity signature;
Step 4:DAA-Verify:DCC verifies user terminal anonymity signature correctness.
Specifically, step 1:KeyGen:TTP is selectedGroup'sOrder is p, length k, and there are bilinear maps:ψ(g2)=g1, selectionIt calculatesThe key pair of TTP are as follows: (pk, sk)=((p, g1,g2,g3,Y,g,h),r)。
Step 2:DAA-Join:
(1) the embedded TPM of private clound selects secret informationRandom numberSignature identifiersSSID (Solely Signature Identifier) calculates η=H1(SSID), it calculates Pedersen and promises to undertake C=gfht, sendTo TTP, then private clound credible platform module proof possesses secret knowledge f, t': random selectionIt calculatesIt is sent to TTP;TTP random selectionIt is sent to privately owned cloud platform;TPM calculates sf=rf+cf,st'=rt'+ ct' sends sfAnd st'To TTP;TTP verifying
(2) TTP is selectedCalculate A=(g1Cht′)1/(y+x), A, x and t " are sent to privately ownedCloud.
(3) private clound host stores A and x, sends t " to TPM.
(4) TPM calculates t=t'+t ", stores f, t, whether true verifies following equation:
Step 3:DAA-Sign:
(1) private clound host randomly selectsCalculate T1=(Ahw),T2=gwh-x, T1And T2It is to A and xIt promises to undertake, it was demonstrated that following two equatioies are set up:
e(T1,Y)/e(g1,g2)=e (h, Y)we(h,g2)wx+te(g,g2)f/e(T1,g2)x,
T2=gwh-x,T2-xgwxh-xx=1, T3f
(2) it proves that privately owned cloud platform possesses knowledge f, x, w and t, meets above equation.Calculate instrumental value δ1=wx, δ2=-xx.TPM is randomly selectedIt calculatesIt willIt is sent to private clound host.
Private clound host is chosenIt calculates:
Private clound Framework computing:
ch=H (η | | g | | h | | g1||g2||g3||gT||Y||T1||T2||T3||R1||R2||R3||R4);
Send chTo TPM.
TPM selectionCalculate c=H (H (ch||nt) | | m), the message m being signed herein be with it is legal canBelieve the public key address on the user blocks chain of privately owned cloud platform binding.
Private clound Framework computing sx=rx+c(-x),sw=rw+cw,TPM calculates sf=rf+cf,st=rt+c(-t)。
Private clound host output signature
Step 4:DAA-Verify:
(1) signature of public key address m on user blocks chain is givenAnd public affairsKey (p, g1,g2,gT, Y, g, h), DCC is calculated:
(2) whether true DCC verifies following equalities:
Setting up then can trade user public key address white list by m addition.
Further, in one embodiment of the invention, data acquisition module 200 is specifically used for: passing through embedded TPMIntegrity measurement is carried out to capture program code page, generates PCR value and metrics logs;By internet of things equipment from the challenge of registrationOne challenge of any selection is concentrated, and is responded by executing BIST, challenge-response is uploaded to data, to obtainHardware fingerprint;Data deblocking and data encapsulation are executed by TPM, so that data voucher and credible platform that the previous period is storedModule is mutually bound, while being bound to a kind of platform status by PCR value;It is corresponding according to preset data Structure Calculation each periodData voucher is chosen by input comprising sensor measurement data, timestamp, integrity measurement log, integrity measurement value, PUFWar-response exports the data voucher value of this period to the data voucher value of, previous time period.
It is understood that particular content is such as shown in Fig. 2, data acquisition module 200 divides carries out for 4 sequence of stepsUnder.
Step 1: capture program code page integrity measurement: when privately owned cloud platform acquisition data, embedded TPM can be to acquisitionCode page where program carries out integrity measurement, and generation is stored in platform configuration register (Platform ConfigurationRegister, PCR) internal PCR value and metrics logs.Integrity measurement guarantees that data acquisition process operates in credible execution ringIn border, PCR value and metrics logs can be used for the subsequent module verifying whether credible operation of acquisition process.
Step 2: internet of things equipment hardware fingerprint obtains: the internet of things equipment of user just registers it at TTP before factoryCRPs, every time when privately owned cloud platform acquisition internet of things equipment data, internet of things equipment concentrates selection one to choose from the challenge of registrationWar is responded by executing BIST, and challenge-response is uploaded to private clound to data, shows to upload data with thisEquipment is that have the equipment of corresponding hardware identity.
Step 3: data deblocking and encapsulation: after internet of things equipment data are uploaded to privately owned cloud platform, TPM executes data deblockingSecurely generating for data voucher is ensured with data encapsulation operation, and data encapsulation not only mutually ties up data with a credible platform moduleIt is fixed, it is bound to a kind of platform status simultaneously also by PCR, ensure that the credible of system running environment and data.The technology is answeredWith making the operation for distorting, making up privately owned cloud platform storing data lead to the failure of follow-up data Trusting eBusiness, to preventThe forgeries of internet of things equipment data.
Step 4: data voucher generates: calculating corresponding data voucher cre_ of each period according to the data structure of attached drawing 3datai(i=1,2 ..., N).Input includes sensor measurement data, timestamp, integrity measurement log, integrity measurementTo the data voucher value of, previous time period, algorithm is the form of nested hash, is exported as this period for value, PUF challenge-responseData voucher value.
Specifically, step 1: capture program code page integrity measurement: this step can be obtained credible privately owned cloud platform and holdThe safe condition that key code is run when row data acquisition operations guarantees subsequently through the data of Trusting eBusiness to be all credibleIt is collected in performing environment.
Integrity measurement is one of function of TPM, actually calculates it to by measure object using cryptographic Hash algorithmThe process of Hash Value.The input of hash operation is the code page acquired where data program in the present invention, and the Hash Value of output isThe integrity measurement value of the code page, TPM charge to metric in specified PCR, and the method charged to is: new PCR value=hashCryptographic algorithm (former PCR value | | metric).When executing integrity measurement operation platform should be recorded in metrics process information by platformIn event log, content includes: measurement person's information, by measurement person's information, former PCR value, metric, new PCR value, deadline.Before each private clound executes data acquisition operations, embedded TPM will execute an aforesaid operations, generate key procedure code pagePCR value and metrics logs, one of the input as data packaging operation.
Step 2: internet of things equipment hardware fingerprint obtains: the present invention is realized using the PUF (such as SRAM PUF) based on storageThe certificate scheme of internet of things equipment hardware identity.By causing SRAM internal symmetry using the variation during the manufacturingThe mismatch of cell parameters, after power-up, the bistable unit of SRAM node enter a unstable state, and unstableConstantly concussion returns to 0 or 1 stable state in state, is responded accordingly.Before internet of things equipment transmits data to private clound every time,A pair is chosen from the CRPs registered from TTP, internally self testing circuit input stimulus C, obtains the response R of PUF.It is each hardPart equipment all relies on the embedded PUF of the equipment and generates unique Identity Code progress authentication, Identity Code (PUFChallenge-response to) with data be uploaded to private clound, be follow-up data Trusting eBusiness preparatory condition.
Step 3: data deblocking and encapsulation: private clound is in the authentication information and sensor for receiving internet of things equipment transmissionAfter recording data, it is carried out to compression packing processing with the data collected before.To guarantee the data compression value generated beforeSafety, the present invention using data encapsulate and solve encapsulation technique.Data encapsulation and unsealing operation are by critical data and specificPlatform status (PCR value) and credible platform module are bound together, so that data are not only bound to a credible platform module, togetherWhen a kind of platform status is bound to by PCR.
For example, i-th of sub-period within the 1st period, generates HiIt will be first to the H that (i-1) period generatesi-1It carries outDeblocking, the specific step of unsealing operation are as follows:
(1) H that (i-1) a sub-period encapsulation generates is read from specified PCRi-1:
Hi-1||PCR_valuei-1| | TPM_Proof=Decrypt (key, sealedDatai-1);
(2) whether identical as the PCR_value decrypted TPM compares PCR value at that time;
(3) whether identical as the numerical value of storage inside TPM compares the TPM_Proof decrypted;
(4) if comparison is identical, H is exportedi-1
Wherein, TPM_Proof is TPM unique identification.With Hi-1With remaining related data as inputting, executes data and beatPackage operation generates the data voucher H of i-th of periodi, and to HiData encapsulation operation is executed, to guarantee i to (i+1) in the periodThe secure storage of data voucher, that is, perform the following operations:
sealedDatai=Encrypt (key, (Hi||PCR_valuei||TPM_Proof))。
Step 4: data voucher generates: calculating corresponding data voucher cre_ of each period according to the data structure of attached drawing 3datai(i=1,2 ..., N).Setting has n sub-period in each period.The H generated with i-th of sub-period of the 1st periodiFor:
Hi=h (mi||ti||PCR_logi||PCR_valuei||Ci||Ri||Hi-1) (i=1,2 ..., n),
I.e. by tiWhen moment is uploaded to the internet of things equipment data of privately owned cloud platform, real-time time stamp, capture program operationIntegrity measurement log and PCR value, the input stimulus of internet of things equipment PUF and output response and (i-1) a sub-period it is rawAt Hi-1Link, and carry out hash operation.Hi-1(wherein i=2,3 ..., n) must can just read after data unsealing operation, thisSample guarantees that the data voucher before i-th of sub-period is not tampered with.After n sub-period, the data voucher H of first period is generatedn(namely cre_data1)。
Further, in one embodiment of the invention, data uploading module 300 is specifically used for: by TPM to dataThe scripting program code page for being uploaded to block chain carries out integrity measurement, generates corresponding metrics logs and PCR value;Input is anyThe data voucher of one period timestamp, carries out the metrics logs and metric of integrity measurement generation to upload program, and holdsThe output valve obtained after row link and hash operation is the data block voucher of any one period, and in the TEE set up, onIt passes script and the transaction comprising data block voucher is sent by public key address on chain, so that transaction is for good and all remembered after being packaged cochainRecord is on alliance's chain of this system.
It is understood that as shown in Fig. 2, data uploading module 300, specifically includes:
Step 1: upload program code page integrity measurement: the TPM of private clound platform built-in is uploaded to block chain to dataScripting program code page carry out integrity measurement, generate corresponding metrics logs and PCR value, for it is subsequent can to upload procedureThe verifying of letter property.
Step 2: the generation and upload of data block voucher: data block voucher be finally be recorded on block chain withCard.Input the data voucher, timestamp, the metrics logs and degree that integrity measurement generation is carried out to upload program of certain time periodMagnitude executes the data block voucher that the output valve obtained after link and hash operation is this period.It is setting up laterIn TEE, uploads script and pass throughChain on public key address send include data block voucher transaction, transaction be packaged cochainIt is permanently recorded on alliance's chain of this system afterwards.
Specifically, step 1: upload program code page integrity measurement: assuming that user terminal upload altogether N number of data block withCard, the scripting program code page that the TPM of private clound platform built-in is uploaded to block chain to data carry out integrity measurement, generate and closeThe metrics logs PCR_log of script is uploaded in datajAnd PCR_valuej(j=1,2 ..., N), follow-up data credibility linkThe credibility of upload procedure can be determined according to both information.
Step 2: the generation and upload of data block voucher: data block voucher be finally be recorded on block chain withCard, data structure are as follows:
cre_blockj=h (tj||PCR_logj||PCR_valuej||cre_dataj) (j=1,2 ..., N),
cre_blockjFor by tjThe timestamp at moment, credible privately owned cloud platform have been executed to scripting program code page is uploadedThe cre_data that metrics logs, PCR value and j-th of the period generated after whole property metric operations generatesj(j=1,2 ..., N) chainIt connects and carries out the value generated after hash operation.Later in the TEE set up, uploads script and pass through public key address on chainSend comprising data block voucher transaction (as shown in figure 4) to trading pit wait miner be packaged.Miner completes proof of workThe block comprising the transaction is generated afterwards and is broadcasted, when there are enough blocks to link after this block, it is believed that dataTransaction certificate is permanently recorded on block chain.
It should be noted that (1) nonce represents block number in attached drawing 4;(2) publication trades, executes tune in ether millIt is required to consume certain expense with operations such as contract functions, with being counted as unit of gas.GasLimit is the permission of single situationMost gas total amounts, gasPrice be setting gas price, generally with GWei (1ETH=1000000000GWei) be unit;(3) Recipient is the collecting account of transaction, which belongs to the message call transaction in the transaction of ether millType, therefore the value is to initiate the user of recorded data zone block certificate transactions itself;(4) Value is transfer amounts, because of the invention instituteTransaction is only for progress data record, therefore being worth is 0;(5) v, r, s are that miner carries out parameter necessary to ECDSA signs;(6) data is data block voucher, and block, which is packaged after cochain, is just recorded permanently storage.
Further, in one embodiment of the invention, data credibility authentication module 400 is specifically to be used for: passing throughThe type of internet of things equipment data needed for DCC is announced;The corresponding data field of initial data is obtained according to the data requirements that DCC is announcedBlock number where block voucher, and block number and initial data are sent to DCC together;The block number retrospect obtained according to feedbackCorresponding transaction and data block voucher, and the number of effective block is obtained under the assistance of TTP, and then calculate effective blockData block credential verification value, and it is uploaded to the corresponding interface of system data reward payment module.
It is understood that as shown in Fig. 2, data credibility authentication module 400 specifically includes:
Step 1:DCC announces data requirements: the type of internet of things equipment data needed for DCC is announced, such as device type, dataMeaning type etc..
Step 2: user feedback block number simultaneously sends initial data: user finds out according to the data requirements that DCC is announced to be metIt is required that the corresponding data block voucher of initial data where block number, and block number and initial data are sent to togetherDCC。
Step 3: the data block credential verification value of effective block generates: the block number retrospect pair that DCC is obtained according to feedbackThe transaction answered and data block voucher, and the number of effective block is obtained under the assistance of TTP, wherein effective block refer to pairThe data block voucher answered is the internet of things equipment upload by there is certification hardware identity, and executes acquisition in TEE, storage, beatsObtained by packet, upload operation.DCC is numbered according to effective block, the uploaded initial data of user is calculated according to side of the present inventionMethod calculates the data block credential verification value of effective block, and in the data of block chain payment platform interface input effective blockBlock credential verification value.
Specifically, step 1:DCC announces data requirements: DCC is by establishing on block chain the provision content of intelligent contractTo announce the data type of expectation purchase.DCC issue intelligent contract public key address be it is disclosed, advertisement, official website can be passed throughThe mode of bulletin tells user, and the publisher public key address of the only intelligent contract of user's comparison is identical with the account address of announcementWhen, user can just execute subsequent such as feedback block number operation.
Step 2: user feedback block number simultaneously sends initial data: user finds out according to the data requirements that DCC is announced to be metIt is required that the corresponding data block voucher of initial data where block number (being assumed to be 1 ..., N), and by block number and originalData are sent to DCC together.Initial data includes:
(1) sensor measurement data: M={ m1,...,mn;...;m(N-1)n,...,mNn};
(2) timestamp: T1={ t1,...,tn;...;t(N-1)n,...,tNnAnd T2={ tA,...,tA+N};
(3) internet of things equipment PUF challenge-response collection:
C={ C1,...,Cn;...;C(N-1)n,...,CNnAnd R={ R1,...,Rn;...;R(N-1)n,...,RNn};
(4) capture program integrity measurement log:
LOG1={ PCR_log1,...,PCR_logn;...;PCR_log(N-1)n,...,PCR_logNn};
(5) capture program integrity measurement value:
PCR1={ PCR_value1,...,PCR_valuen;...;PCR_value(N-1)n,...,PCR_valueNn};
(6) voucher upload program integrity measurement log: LOG2={ PCR_logA,...,PCR_logA+N};
(7) voucher upload program integrity measurement value: PCR2={ PCR_valueA,...,PCR_valueA+N}。
Step 3: the data block credential verification value of effective block generates: DCC is traced according to the block number that user submits1 ..., data block voucher value recorded in block S.DCC is by the C in initial data, R, LOG1,PCR1,LOG2,PCR2HairGive TTP.TTP motivates C according to the PUF that receives, inquires registered corresponding response R value, if the response of registration and receivingThe Hamming distance of both responses is less than threshold epsilon, then the authentication of Internet of things node passes through.Capture program and voucher are uploadedThe integrity measurement value and metrics logs of program, TTP by analyze integrity measurement event log information judge PCR value whether comeFrom correct metrics process, the value of PCR is compared with the completeness of platform a reference value of registration later, if they are the same, is then shownThe privately owned cloud platform for sending data is in trusted status when executing relevant operation.If the above verifying passes through, TTP thinks thisThe corresponding data of block be it is believable, the number of these effective blocks is sent to DCC by TTP.DCC uploads data using user and pressesThe data block credential verification value of effective block is calculated according to the method for the invention, and is disclosed, permanently by intelligent contract-defined interfaceGround is recorded on block chain.
Further, in one embodiment of the invention, data reward payment module 500 is further used for according to blockChain intelligence contract obtains the data block credential verification value of effective block to the interface input value of DCC and effective block is numbered, and closesIt corresponding data block evidence record value and is compared on about automatic traceability chain, and according to the data block voucher being proved to be successfulNumber, intelligent contract are not relied on by third party, automatically to the reward of user's payment data.
It is understood that as shown in Fig. 2, intelligent contract on block chain is according to the data of the DCC effective block inputtedBlock credential verification value obtains effective block number, corresponding data block evidence record value and is compared on the automatic traceability chain of contractIt is right, it is identical, prove that the state of platform when user uploads data is believable and sensing data is not tampered, it is on the contrary then proveData invalid.According to the data block voucher number being proved to be successful, intelligent contract is not relied on, by third party automatically to user's branchPay data reward.
Specifically, the ether mill that data reward payment module 500 is located at credible big data acquisition transaction system is intelligently closedIt about holds, intelligent contract is issued by DCC, leaves user's interface different with the end DCC for respectively, and DCC and user call the operation of contractRealize that the call operation of all pairs of contracts finally can all enter transaction in the form of transaction by the web3 module that ether mill providesPond, the operation for being packaged cochain are disclosed, are permanently recorded on block chain.DCC, which is allowed to input in intelligent contract-defined interface, to be hadThe data block credential verification value of block and the public key address of corresponding user are imitated, contract traces the data of Correlation block record automaticallyBlock voucher pays corresponding data reward, contract payment from trend client public key address according to identical number of blocks is comparedOperation enters generation after trading pit waits packing, miner to complete proof of work with transaction form and goes forward side by side comprising the block of the transactionRow broadcast, when there is enough blocks to link after this block, it is believed that data trade voucher is permanently recorded in blockOn chain, so far payment is completed.
To sum up, the embodiment of the present invention provide a kind of combination PUF technology, reliable computing technology, block chain technology it is credible bigData acquire transaction system, can be used under the premise of guaranteeing data credibility and justice of exchange, extensive Internet of Things individual setsStandby data silo fusion and transaction, and personal identification privacy is protected not to be leaked, advantage and effect are:
1) embodiment of the present invention combines PUF technology, reliable computing technology, block chain technology, and PUF ensures acquired dataFrom the hardware device being certified;Credible platform module guarantees data acquisition, stores, the safety of upload operation;Block chain generatesAnti-tamper data block evidence record account book.This system assures that acquiring, storage, being packaged, the full link of upload is credible.
2) embodiment of the present invention proves to carry out secret protection to public key address on user's chain using Direct Anonymous, and DCC can onlyIt proves that carry out account on the chain of data trade with it embeds the privately owned cloud platform binding of legal TPM with one really, but cannot obtainTo about other any information outside privately owned cloud platform validity, to protect the privacy of user terminal.
3) centrality and automation feature are gone based on the intelligent contract function of block chain support, this system ensure that number rewardFair, transparent, automatic payment, solve the big worry of user.
What is proposed according to embodiments of the present invention acquires transaction system based on the big data of block chain and credible calculating platform, leads toCross the acquisition to data, storage, packing, upload operation implement comprehensive supervision and protection, the full link for realizing data canLetter, the method for using Direct Anonymous to prove make DCC protect user hidden in the validity of public key address on authenticating user's chainIt is private;Also, the characteristics of based on the intelligence contract decentralization of block chain and automating guarantees the open and clear of data reward payment,Thus the contradiction reconciled between personal privacy protection and big data acquisition to a certain extent, and ensure the credible of data sourceProperty, and there is practicability, simple easily realization.
In addition, term " first ", " second " are used for descriptive purposes only and cannot be understood as indicating or suggesting relative importanceOr implicitly indicate the quantity of indicated technical characteristic.Define " first " as a result, the feature of " second " can be expressed orImplicitly include at least one this feature.In the description of the present invention, the meaning of " plurality " is at least two, such as two, threeIt is a etc., unless otherwise specifically defined.
In the description of this specification, reference term " one embodiment ", " some embodiments ", " example ", " specifically showThe description of example " or " some examples " etc. means specific features, structure, material or spy described in conjunction with this embodiment or examplePoint is included at least one embodiment or example of the invention.In the present specification, schematic expression of the above terms are notIt must be directed to identical embodiment or example.Moreover, particular features, structures, materials, or characteristics described can be in officeIt can be combined in any suitable manner in one or more embodiment or examples.In addition, without conflicting with each other, the skill of this fieldArt personnel can tie the feature of different embodiments or examples described in this specification and different embodiments or examplesIt closes and combines.
Although the embodiments of the present invention has been shown and described above, it is to be understood that above-described embodiment is exampleProperty, it is not considered as limiting the invention, those skilled in the art within the scope of the invention can be to above-mentionedEmbodiment is changed, modifies, replacement and variant.

Claims (6)

Translated fromChinese
1.一种基于区块链和可信计算平台的大数据采集交易系统,其特征在于,包括:1. a big data acquisition transaction system based on block chain and trusted computing platform, is characterized in that, comprises:用户链上地址验证模块,用于数据采集公司DCC、可信第三方TTP和用户之间通信交互以完成直接匿名证明协议,并将与可信私有云平台绑定的区块链上公钥地址加入DCC交易用户白名单;The address verification module on the user chain is used for the communication and interaction between the data collection company DCC, the trusted third party TTP and the user to complete the direct anonymous proof protocol, and binds the public key address on the blockchain to the trusted private cloud platform Join the whitelist of DCC trading users;数据采集模块,用于私有云平台进行采集操作的同时执行采集程序代码页的完整性度量以获取第一平台状态,并通过物联网节点获取并上传硬件指纹,并利用所述可信私有云平台的数据解封与封装功能生成数据凭证,以得到后续模块验证数据可信性的依据;The data acquisition module is used for the private cloud platform to perform the acquisition operation while executing the integrity measurement of the acquisition program code page to acquire the first platform state, acquire and upload the hardware fingerprint through the IoT node, and use the trusted private cloud platform The data decapsulation and encapsulation functions of the MCU generate data vouchers, so as to obtain the basis for the subsequent modules to verify the reliability of the data;数据上传模块,用于执行上传程序代码页的完整性度量以获取第二平台状态,并与任一时间段的数据凭证链接打包后生成数据区块凭证,且通过与所述可信私有云平台绑定的区块链上公钥地址以交易的形式上传至系统联盟链;The data uploading module is used to execute the integrity measurement of the code page of the uploading program to obtain the state of the second platform, and link and package with the data certificate of any time period to generate the data block certificate, and through the connection with the trusted private cloud platform The public key address on the bound blockchain is uploaded to the system alliance chain in the form of a transaction;数据可信性验证模块,用于在所述DCC公布期望购买的数据类型后,接收用户反馈相应的区块号和对应的原始数据集合,并且所述DCC在所述TTP的协助下获得由合法设备在可信状态下所采集数据对应的有效区块号,并计算所述有效区块的数据区块凭证验证值,上传至智能合约入口;The data credibility verification module is used to receive the corresponding block number and the corresponding original data set fed back by the user after the DCC announces the data type expected to be purchased, and the DCC obtains a legal The valid block number corresponding to the data collected by the device in a trusted state, and calculate the data block certificate verification value of the valid block, and upload it to the smart contract entrance;数据酬劳支付模块,用于通过所述智能合约自动追溯链上记录的有效区块的数据区块凭证,将其与所述DCC提交的验证值进行比对,以根据比对成功的区块数目公开并自动地向用户支付数据酬劳。The data reward payment module is used to automatically trace the data block certificate of the valid block recorded on the chain through the smart contract, and compare it with the verification value submitted by the DCC, so as to calculate the number of successful blocks according to the comparison. Publicly and automatically pay users for their data.2.根据权利要求1所述的基于区块链和可信计算平台的大数据采集交易系统,其特征在于,所述用户链上地址验证模块进一步用于:2. The big data collection and transaction system based on block chain and trusted computing platform according to claim 1, is characterized in that, the address verification module on described user chain is further used for:生成匿名凭证颁发者TTP密钥;Generate an anonymous credential issuer TTP key;通过TTP和零知识证明颁发所述匿名凭证给用户端;Issue the anonymous credential to the client through TTP and zero-knowledge proof;通过所述用户端计算匿名签名,以实现所述DCC验证用户端匿名签名正确性。The anonymous signature is calculated by the user terminal, so that the DCC can verify the correctness of the anonymous signature of the user terminal.3.根据权利要求1所述的基于区块链和可信计算平台的大数据采集交易系统,其特征在于,所述数据采集模块具体用于:3. The big data collection and transaction system based on block chain and trusted computing platform according to claim 1, is characterized in that, described data collection module is specifically used for:通过私有云平台内嵌的TPM对所述采集程序代码页进行完整性度量,生成PCR值和度量日志;Perform integrity measurement on the code page of the collection program through the TPM embedded in the private cloud platform, and generate PCR values and measurement logs;通过物联网设备从注册的挑战集中任意选取一个挑战,并通过执行BIST得到响应,获取所述硬件指纹,挑战-响应对随数据一起上传;A challenge is arbitrarily selected from the registered challenge set by the IoT device, and a response is obtained by executing BIST, the hardware fingerprint is obtained, and the challenge-response pair is uploaded together with the data;通过所述TPM执行数据解封和数据封装,使得将前一时段所生成的数据凭证与可信平台模块相绑定,同时通过PCR值绑定于一种平台状态;Perform data decapsulation and data encapsulation through the TPM, so that the data credentials generated in the previous period are bound to the trusted platform module, and are bound to a platform state through the PCR value;根据预设数据结构计算每个时段对应的数据凭证,输入为包含传感器测量数据、时间戳、完整性度量日志、完整性度量值、PUF挑战-响应对、前一时间段的数据凭证值,输出为本时段的数据凭证值。Calculate the data credential corresponding to each time period according to the preset data structure. The input includes sensor measurement data, timestamp, integrity measurement log, integrity measurement value, PUF challenge-response pair, and the data credential value of the previous time period, and the output is The data voucher value for this period.4.根据权利要求1所述的基于区块链和可信计算平台的大数据采集交易系统,其特征在于,所述数据上传模块具体用于:4. The big data collection and transaction system based on block chain and trusted computing platform according to claim 1, is characterized in that, described data uploading module is specifically used for:通过所述TPM对上传数据至区块链的脚本程序代码页进行完整性度量,生成对应的度量日志和PCR值;Perform integrity measurement on the script program code page of the uploaded data to the blockchain through the TPM, and generate the corresponding measurement log and PCR value;输入任意一时间段的数据凭证、时间戳、对上传程序进行完整性度量生成的度量日志及度量值,并执行链接和杂凑操作后得到的输出值为所述任一时段的数据区块凭证,并在建立起的可信执行环境中,上传脚本通过链上公钥地址发送包含数据区块凭证的交易,使得交易打包上链后被永久地记录在本系统的联盟链上。Input the data certificate, time stamp, metric log and metric value generated by the integrity measurement of the uploading program in any period of time, and the output value obtained after performing the linking and hashing operations is the data block credential of any period of time, In the established trusted execution environment, the upload script sends the transaction containing the data block certificate through the public key address on the chain, so that the transaction is permanently recorded on the alliance chain of the system after being packaged and uploaded to the chain.5.根据权利要求1所述的基于区块链和可信计算平台的大数据采集交易系统,其特征在于,所述数据可信性验证模块具体用于:5. The big data collection and transaction system based on block chain and trusted computing platform according to claim 1, is characterized in that, described data credibility verification module is specifically used for:通过DCC公布所需物联网设备数据的类型;Publish the type of IoT device data required through DCC;根据所述DCC公布的数据需求,用户查询原始数据对应的数据区块凭证所在的区块号,并将所述区块号和所述原始数据一同发送至DCC;According to the data requirements published by the DCC, the user queries the block number where the data block certificate corresponding to the original data is located, and sends the block number and the original data to the DCC together;根据反馈得到的区块号追溯对应的交易及数据区块凭证,并在所述TTP的协助下得到有效区块的编号并计算有效区块的数据区块凭证验证值,并上传至智能合约入口。According to the block number obtained from the feedback, the corresponding transaction and data block certificate are traced back, and with the assistance of the TTP, the number of the valid block is obtained, the data block certificate verification value of the valid block is calculated, and then uploaded to the smart contract entrance .6.根据权利要求1所述的基于区块链和可信计算平台的大数据采集交易系统,其特征在于,所述数据酬劳支付模块进一步用于:所述区块链上的智能合约根据所述DCC输入的有效区块的数据区块凭证验证值得到有效区块编号,合约自动追溯链上有效区块的数据区块凭证记录值并和验证值进行比对,并根据验证成功的数据区块凭证个数,所述智能合约不受第三方依赖、自动地向所述用户支付所述数据酬劳。6. The big data collection and transaction system based on blockchain and trusted computing platform according to claim 1, wherein the data remuneration payment module is further used for: the smart contract on the blockchain is based on the The data block certificate verification value of the valid block input by the DCC gets the valid block number, and the contract automatically traces the data block certificate record value of the valid block on the chain and compares it with the verification value. The number of block vouchers, the smart contract is not dependent on a third party and automatically pays the user the data remuneration.
CN201811069639.XA2018-09-132018-09-13 Big data collection and transaction system based on blockchain and trusted computing platformActiveCN109325331B (en)

Priority Applications (1)

Application NumberPriority DateFiling DateTitle
CN201811069639.XACN109325331B (en)2018-09-132018-09-13 Big data collection and transaction system based on blockchain and trusted computing platform

Applications Claiming Priority (1)

Application NumberPriority DateFiling DateTitle
CN201811069639.XACN109325331B (en)2018-09-132018-09-13 Big data collection and transaction system based on blockchain and trusted computing platform

Publications (2)

Publication NumberPublication Date
CN109325331Atrue CN109325331A (en)2019-02-12
CN109325331B CN109325331B (en)2022-05-20

Family

ID=65265796

Family Applications (1)

Application NumberTitlePriority DateFiling Date
CN201811069639.XAActiveCN109325331B (en)2018-09-132018-09-13 Big data collection and transaction system based on blockchain and trusted computing platform

Country Status (1)

CountryLink
CN (1)CN109325331B (en)

Cited By (38)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN110059497A (en)*2019-02-192019-07-26阿里巴巴集团控股有限公司Method, node and the storage medium of secret protection are realized in block chain
CN110278193A (en)*2019-05-202019-09-24阿里巴巴集团控股有限公司It is marked and transaction, the receipt storage method of event type and node in conjunction with code
CN110309634A (en)*2019-04-042019-10-08深圳大通实业股份有限公司A kind of credible advertisement data management system based on block chain
CN110324422A (en)*2019-07-052019-10-11北京大学A kind of substantive approach and system of cloud application
CN110336663A (en)*2019-06-142019-10-15东南大学 A PUFs group-to-group authentication scheme based on blockchain technology
CN110347607A (en)*2019-07-162019-10-18北京首汽智行科技有限公司A kind of data cochain test method
CN110442631A (en)*2019-08-072019-11-12北京艾摩瑞策科技有限公司About the knowledge payment associated data processing method and its device on block chain
CN110809058A (en)*2019-11-132020-02-18北京物资学院Block chain traceability system and method based on feature code identification and verification technology
CN110875930A (en)*2019-11-212020-03-10山东超越数控电子股份有限公司Method, equipment and medium for monitoring trusted state
CN110912712A (en)*2019-12-182020-03-24东莞市大易产业链服务有限公司Service operation risk authentication method and system based on block chain
CN111177096A (en)*2019-12-112020-05-19招银云创(深圳)信息技术有限公司Log management method and device, computer equipment and storage medium
CN111274594A (en)*2020-01-202020-06-12上海市大数据中心Block chain-based secure big data privacy protection sharing method
CN111428249A (en)*2020-01-202020-07-17中国科学院信息工程研究所 An anonymous registration method and system for protecting user privacy based on blockchain
CN111783133A (en)*2020-06-022020-10-16广东科学技术职业学院 A network resource management method based on blockchain technology
CN111950021A (en)*2020-07-312020-11-17南京航空航天大学 A solution to the problem of privacy leakage in data gifting of smart contracts
CN112380574A (en)*2020-11-112021-02-19杭州甘道智能科技有限公司Data chaining method based on block chain and SE chip
CN112395511A (en)*2020-11-042021-02-23北京大学Rumor detection and evidence preservation system based on message propagation path in mobile application
FR3101991A1 (en)*2019-10-092021-04-16Pierre-Francois Casanova Object authentication and assurance system and method
CN112751807A (en)*2019-10-312021-05-04中国电信股份有限公司Secure communication method, apparatus, system and storage medium
CN113098693A (en)*2021-04-082021-07-09太原理工大学Memory verification method based on physical unclonable function algorithm
CN113159769A (en)*2021-04-212021-07-23中国人民解放军国防科技大学Block chain-based data circulation intelligent contract implementation method and system
CN113221089A (en)*2021-03-152021-08-06东北大学Privacy protection attribute authentication system and method based on verifiable statement
CN113256427A (en)*2021-06-282021-08-13北京航空航天大学Joint signature-based alliance block chain consensus method and system
CN113326527A (en)*2021-06-242021-08-31北京八分量信息科技有限公司Credible digital signature system and method based on block chain
CN113433918A (en)*2021-08-252021-09-24江苏荣泽信息科技股份有限公司Enterprise electronic standing book energy consumption data acquisition system based on block chain
CN113946877A (en)*2021-09-042022-01-18西安链融科技有限公司 Data security computing method, system, computer equipment, storage medium and terminal
CN114117553A (en)*2022-01-282022-03-01北京豪尔赛智慧城域科技有限公司Block chain-based control method and system for Internet of things terminal
CN114139123A (en)*2021-09-102022-03-04南方电网数字电网研究院有限公司Intelligent electric meter safety access method and system based on ECC accumulator
WO2022073212A1 (en)*2020-10-092022-04-14Alipay (Hangzhou) Information Technology Co., Ltd.Managing blockchain-based trustable transaction services
CN114679284A (en)*2020-12-242022-06-28中国移动通信有限公司研究院 Trusted remote attestation system and its storage, verification method and storage medium
US11443307B2 (en)2020-07-312022-09-13Alipay (Hangzhou) Information Technology Co., Ltd.Cross-border resource transfer authenticity verification method, device and electronic equipment
CN115189863A (en)*2022-09-132022-10-14图林科技(深圳)有限公司 An e-commerce transaction information management system based on blockchain network architecture
CN115622728A (en)*2022-08-052023-01-17贵州大学 An auditable alliance chain privacy protection scheme based on DLIN encryption
EP4018597A4 (en)*2019-08-222023-04-12Quantumciel Pte. Ltd.Device, system and method for providing information security
CN116192395A (en)*2021-11-292023-05-30西部数据技术公司Trusted system for distributed data storage
CN116976891A (en)*2023-07-212023-10-31杭州易景数通科技有限公司Financial data security management system, device and method thereof
CN117349897A (en)*2023-12-052024-01-05哈尔滨工业大学(深圳)(哈尔滨工业大学深圳科技创新研究院) A blockchain-based privacy protection method for carbon quota transactions
US11935048B2 (en)2020-10-092024-03-19Alipay (Hangzhou) Information Technology Co., Ltd.Managing blockchain-based trustable transaction services

Citations (7)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN103763315A (en)*2014-01-142014-04-30北京航空航天大学Credible data access control method applied to cloud storage of mobile devices
CN106407481A (en)*2016-11-302017-02-15福州微启迪物联科技有限公司Block chain architecture-based ecological environment monitoring system and implementation method thereof
CN107274184A (en)*2017-05-112017-10-20上海点融信息科技有限责任公司block chain data processing based on zero-knowledge proof
US20170352027A1 (en)*2016-06-072017-12-07Cornell UniversityAuthenticated data feed for blockchains
US20170359374A1 (en)*2016-06-112017-12-14Lntel CorporationBlockchain System with Nucleobase Sequencing as Proof of Work
CN107533501A (en)*2015-03-202018-01-02里维茨公司Use block chain automated validation appliance integrality
CN108270571A (en)*2017-12-082018-07-10西安电子科技大学Internet of Things identity authorization system and its method based on block chain

Patent Citations (7)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN103763315A (en)*2014-01-142014-04-30北京航空航天大学Credible data access control method applied to cloud storage of mobile devices
CN107533501A (en)*2015-03-202018-01-02里维茨公司Use block chain automated validation appliance integrality
US20170352027A1 (en)*2016-06-072017-12-07Cornell UniversityAuthenticated data feed for blockchains
US20170359374A1 (en)*2016-06-112017-12-14Lntel CorporationBlockchain System with Nucleobase Sequencing as Proof of Work
CN106407481A (en)*2016-11-302017-02-15福州微启迪物联科技有限公司Block chain architecture-based ecological environment monitoring system and implementation method thereof
CN107274184A (en)*2017-05-112017-10-20上海点融信息科技有限责任公司block chain data processing based on zero-knowledge proof
CN108270571A (en)*2017-12-082018-07-10西安电子科技大学Internet of Things identity authorization system and its method based on block chain

Non-Patent Citations (3)

* Cited by examiner, † Cited by third party
Title
XIAOLIAN CHEN 等: "A Blockchain Based Access Authentication Scheme of Energy Internet", 《2018 2ND IEEE CONFERENCE ON ENERGY INTERNET AND ENERGY SYSTEM INTEGRATION (EI2)》*
李大伟 等: "基于区块链的密钥更新和可信定位系统", 《密码学报》*
李彬 等: "非可信环境下基于区块链的多级DR投标安全管理及技术支撑", 《中国电机工程学报》*

Cited By (56)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN110059497A (en)*2019-02-192019-07-26阿里巴巴集团控股有限公司Method, node and the storage medium of secret protection are realized in block chain
CN110309634A (en)*2019-04-042019-10-08深圳大通实业股份有限公司A kind of credible advertisement data management system based on block chain
CN110278193A (en)*2019-05-202019-09-24阿里巴巴集团控股有限公司It is marked and transaction, the receipt storage method of event type and node in conjunction with code
CN110278193B (en)*2019-05-202021-06-01创新先进技术有限公司Receipt storage method and node combining code marking with transaction and event types
CN110336663A (en)*2019-06-142019-10-15东南大学 A PUFs group-to-group authentication scheme based on blockchain technology
CN110336663B (en)*2019-06-142021-11-30东南大学PUFs group-to-group authentication method based on block chain technology
CN110324422B (en)*2019-07-052020-08-28北京大学Cloud application verification method and system
CN110324422A (en)*2019-07-052019-10-11北京大学A kind of substantive approach and system of cloud application
CN110347607A (en)*2019-07-162019-10-18北京首汽智行科技有限公司A kind of data cochain test method
CN110442631A (en)*2019-08-072019-11-12北京艾摩瑞策科技有限公司About the knowledge payment associated data processing method and its device on block chain
US12238227B2 (en)2019-08-222025-02-25Quantumciel Pte. Ltd.Device, system and method for providing information security
EP4018597A4 (en)*2019-08-222023-04-12Quantumciel Pte. Ltd.Device, system and method for providing information security
FR3101991A1 (en)*2019-10-092021-04-16Pierre-Francois Casanova Object authentication and assurance system and method
CN112751807B (en)*2019-10-312023-02-03中国电信股份有限公司Secure communication method, device, system and storage medium
CN112751807A (en)*2019-10-312021-05-04中国电信股份有限公司Secure communication method, apparatus, system and storage medium
CN110809058A (en)*2019-11-132020-02-18北京物资学院Block chain traceability system and method based on feature code identification and verification technology
CN110875930A (en)*2019-11-212020-03-10山东超越数控电子股份有限公司Method, equipment and medium for monitoring trusted state
CN111177096A (en)*2019-12-112020-05-19招银云创(深圳)信息技术有限公司Log management method and device, computer equipment and storage medium
CN110912712A (en)*2019-12-182020-03-24东莞市大易产业链服务有限公司Service operation risk authentication method and system based on block chain
CN110912712B (en)*2019-12-182022-03-08东莞市大易产业链服务有限公司Service operation risk authentication method and system based on block chain
CN111274594A (en)*2020-01-202020-06-12上海市大数据中心Block chain-based secure big data privacy protection sharing method
CN111428249A (en)*2020-01-202020-07-17中国科学院信息工程研究所 An anonymous registration method and system for protecting user privacy based on blockchain
CN111428249B (en)*2020-01-202022-06-28中国科学院信息工程研究所 An anonymous registration method and system for protecting user privacy based on blockchain
CN111783133A (en)*2020-06-022020-10-16广东科学技术职业学院 A network resource management method based on blockchain technology
CN111950021A (en)*2020-07-312020-11-17南京航空航天大学 A solution to the problem of privacy leakage in data gifting of smart contracts
US11443307B2 (en)2020-07-312022-09-13Alipay (Hangzhou) Information Technology Co., Ltd.Cross-border resource transfer authenticity verification method, device and electronic equipment
WO2022073212A1 (en)*2020-10-092022-04-14Alipay (Hangzhou) Information Technology Co., Ltd.Managing blockchain-based trustable transaction services
US11935048B2 (en)2020-10-092024-03-19Alipay (Hangzhou) Information Technology Co., Ltd.Managing blockchain-based trustable transaction services
US11798050B2 (en)2020-10-092023-10-24Alipay (Hangzhou) Information Technology Co., Ltd.Managing blockchain-based trustable transaction services
CN112395511A (en)*2020-11-042021-02-23北京大学Rumor detection and evidence preservation system based on message propagation path in mobile application
CN112380574A (en)*2020-11-112021-02-19杭州甘道智能科技有限公司Data chaining method based on block chain and SE chip
CN114679284A (en)*2020-12-242022-06-28中国移动通信有限公司研究院 Trusted remote attestation system and its storage, verification method and storage medium
CN114679284B (en)*2020-12-242024-11-08中国移动通信有限公司研究院 Trusted remote attestation system and storage, verification method and storage medium thereof
CN113221089A (en)*2021-03-152021-08-06东北大学Privacy protection attribute authentication system and method based on verifiable statement
CN113221089B (en)*2021-03-152023-11-07东北大学Privacy protection attribute authentication system and method based on verifiable statement
CN113098693A (en)*2021-04-082021-07-09太原理工大学Memory verification method based on physical unclonable function algorithm
CN113098693B (en)*2021-04-082022-08-16太原理工大学Memory verification method based on physical unclonable function algorithm
CN113159769A (en)*2021-04-212021-07-23中国人民解放军国防科技大学Block chain-based data circulation intelligent contract implementation method and system
CN113159769B (en)*2021-04-212022-07-19中国人民解放军国防科技大学 A method and system for realizing smart contract of data circulation based on blockchain
CN113326527A (en)*2021-06-242021-08-31北京八分量信息科技有限公司Credible digital signature system and method based on block chain
CN113256427A (en)*2021-06-282021-08-13北京航空航天大学Joint signature-based alliance block chain consensus method and system
CN113256427B (en)*2021-06-282021-09-14北京航空航天大学Joint signature-based alliance block chain consensus method and system
CN113433918B (en)*2021-08-252021-11-16江苏荣泽信息科技股份有限公司Enterprise electronic standing book energy consumption data acquisition system based on block chain
CN113433918A (en)*2021-08-252021-09-24江苏荣泽信息科技股份有限公司Enterprise electronic standing book energy consumption data acquisition system based on block chain
CN113946877A (en)*2021-09-042022-01-18西安链融科技有限公司 Data security computing method, system, computer equipment, storage medium and terminal
CN114139123A (en)*2021-09-102022-03-04南方电网数字电网研究院有限公司Intelligent electric meter safety access method and system based on ECC accumulator
CN114139123B (en)*2021-09-102024-12-13南方电网数字电网集团有限公司 A smart meter security access method and system based on ECC accumulator
CN116192395A (en)*2021-11-292023-05-30西部数据技术公司Trusted system for distributed data storage
CN114117553A (en)*2022-01-282022-03-01北京豪尔赛智慧城域科技有限公司Block chain-based control method and system for Internet of things terminal
CN115622728A (en)*2022-08-052023-01-17贵州大学 An auditable alliance chain privacy protection scheme based on DLIN encryption
CN115622728B (en)*2022-08-052025-01-28贵州大学 An auditable alliance chain privacy protection scheme based on DLIN encryption
CN115189863A (en)*2022-09-132022-10-14图林科技(深圳)有限公司 An e-commerce transaction information management system based on blockchain network architecture
CN116976891B (en)*2023-07-212025-01-07杭州易景数通科技有限公司Financial data security management system, device and method thereof
CN116976891A (en)*2023-07-212023-10-31杭州易景数通科技有限公司Financial data security management system, device and method thereof
CN117349897B (en)*2023-12-052024-03-26哈尔滨工业大学(深圳)(哈尔滨工业大学深圳科技创新研究院) A blockchain-based privacy protection method for carbon quota transactions
CN117349897A (en)*2023-12-052024-01-05哈尔滨工业大学(深圳)(哈尔滨工业大学深圳科技创新研究院) A blockchain-based privacy protection method for carbon quota transactions

Also Published As

Publication numberPublication date
CN109325331B (en)2022-05-20

Similar Documents

PublicationPublication DateTitle
CN109325331A (en) Big data collection and transaction system based on blockchain and trusted computing platform
Vangala et al.Smart contract-based blockchain-envisioned authentication scheme for smart farming
US11842317B2 (en)Blockchain-based authentication and authorization
Zhang et al.Blockchain-assisted public-key encryption with keyword search against keyword guessing attacks for cloud storage
Bera et al.Designing blockchain-based access control protocol in IoT-enabled smart-grid system
Lu et al.Zebralancer: Private and anonymous crowdsourcing system atop open blockchain
Liu et al.Anonymous reputation system for IIoT-enabled retail marketing atop PoS blockchain
Cai et al.Towards private, robust, and verifiable crowdsensing systems via public blockchains
CN114499895A (en) A data trusted processing method and system integrating trusted computing and blockchain
CN108650077B (en) Blockchain-based information transmission method, terminal, device and readable storage medium
CN109617699A (en) A key generation method, blockchain network service platform and storage medium
Li et al.A decentralized and secure blockchain platform for open fair data trading
Kumar et al.Ultra-lightweight blockchain-enabled RFID authentication protocol for supply chain in the domain of 5G mobile edge computing
Cui et al.Secure data sharing for consortium blockchainenabled vehicular social networks
Jiang et al.SearchBC: A blockchain-based PEKS framework for IoT services
Prateek et al.Q-Secure-P²-SMA: Quantum-Secure Privacy-Preserving Smart Meter Authentication for Unbreakable Security in Smart Grid
Zhang et al.Blockchain-based decentralized supply chain system with secure information sharing
CN108777673A (en)One kind carrying out Bidirectional identity authentication method in block chain
CN114866289B (en)Privacy credit data security protection method based on alliance chain
Hossain et al.A blockchain-based approach with zk-snarks for secure email applications
Luo et al.A Cloud-Fog Enabled and Privacy-Preserving IoT Data Market Platform Based on Blockchain.
Yang et al.PrivCrowd: A Secure Blockchain‐Based Crowdsourcing Framework with Fine‐Grained Worker Selection
Liu et al.PSRAKA: Physically Secure and Robust Authenticated Key Agreement for VANETs
Wang et al.Crowdchain: A location preserve anonymous payment system based on permissioned blockchain
Li et al.A new revocable reputation evaluation system based on blockchain

Legal Events

DateCodeTitleDescription
PB01Publication
PB01Publication
SE01Entry into force of request for substantive examination
SE01Entry into force of request for substantive examination
GR01Patent grant
GR01Patent grant

[8]ページ先頭

©2009-2025 Movatter.jp