Data security in a peer-to-peer network
A data protection implementation solution includes utilizing a peer-to-peer network and incorporating an auditing method to record and/or track transactions related to a customer's data. A private peer-to-peer network such as inter planetary file system (IPFS) is used to achieve secured and fast data accessibility while also managing data modifications. An auditing method such as blockchain is used to record activity related to data within the IPFS network. The IPFS network may include a plurality of nodes, among which data is distributed. Devices are registered with the network, and public keys, private keys, and node identifiers are used to authenticate users and secure the data. By incorporating blockchain with the IPFS network, file commit transactions are validated and a clear ledger regarding time of modification and count of file edits is provided.
1. A computer-implemented method, comprising:
receiving, by a processing device, a file to be uploaded to a private peer-to-peer network comprising an inter planetary file system, the private peer-to-peer network comprising a plurality of nodes including a sending user device providing the file to be uploaded, wherein the file to be uploaded is encrypted with a public key of a receiving user device;
generating, by the processing device, a hash value for the file encrypted with the public key of the receiving user device, the hash value beginning with a predetermined identifier indicating that the file belongs to the private peer-to-peer network;
storing, by the processing device, the hash value of the file in a distributed hash table in a subset of the plurality of nodes, wherein the distributed hash table comprises a Merkle directed acyclic graph, wherein a change to the hash file, which corresponds to a change to the file, is stored as a new block in the Merkle directed acyclic graph;
creating, by the processing device, a blockchain representation of the file, the blockchain representation including at least the hash value of the file, a previous hash value of the file, an authentication nonce, and a time stamp to provide an audit trail for validation of changes to the file, wherein the authentication nonce comprises a random or pseudo-random number provided as part of an authentication to ensure that prior communications cannot be used in a replay attack;
in response to a request from the receiving user device and upon verification of the receiving user device, providing, by the processing device, the file to the receiving user device, wherein the verification is based upon a public key exchange between the sending user device and the receiving user device and a determination that a hash of the public key of the receiving user device matches a corresponding node identifier for the receiving device, and wherein the file is provided by identifying, via the distributed hash table rather than the blockchain representation of the file, a nearest node of the plurality of nodes that contains the hash value;
in response to the providing, receiving, by the processing device and from the receiving user device, a modified version of the file;
in response to receiving the modified version of the file, generating, by the processing device, a new hash value for the modified version of the file, the new hash value assigned by the inter planetary file system;
appending, by the processing device, the new hash value to the blockchain representation of the file; and
updating, by the processing device, the distributed hash table with the new hash value for the modified version of the file, wherein the new hash value is stored as the new block in the distributed hash table comprising the Merkle directed acyclic graph.
2. The computer-implemented method of claim 1 , further comprising:
storing, by the processing device, the new hash value in the distributed hash table in a second subset of the plurality of nodes.
3. A system, comprising:
at least one data processor; and
at least one memory storing instructions which, when executed by the at least one data processor, result in operations comprising:
receiving, by a processing device, a file to be uploaded to a private peer-to-peer network comprising an inter planetary file system, the private peer-to-peer network comprising a plurality of nodes including a sending user device providing the file to be uploaded, wherein the file to be uploaded is encrypted with a public key of a receiving user device;
generating, by the processing device, a hash value for the file encrypted with the public key of the receiving user device, the hash value beginning with a predetermined identifier indicating that the file belongs to the private peer-to-peer network;
storing, by the processing device, the hash value of the file in a distributed hash table in a subset of the plurality of nodes, wherein the distributed hash table comprises a Merkle directed acyclic graph, wherein a change to the hash file, which corresponds to a change to the file, is stored as a new block in the Merkle directed acyclic graph;
creating, by the processing device, a blockchain representation of the file, the blockchain representation including at least the hash value of the file, a previous hash value of the file, an authentication nonce, and a time stamp to provide an audit trail for validation of changes to the file, wherein the authentication nonce comprises a random or pseudo-random number provided as part of an authentication to ensure that prior communications cannot be used in a replay attack;
in response to a request from the receiving user device and upon verification of the receiving user device, providing, by the processing device, the file to the receiving user device, wherein the verification is based upon a public key exchange between the sending user device and the receiving user device and a determination that a hash of the public key of the receiving user device matches a corresponding node identifier for the receiving device, and wherein the file is provided by identifying, via the distributed hash table rather than the blockchain representation of the file, a nearest node of the plurality of nodes that contains the hash value;
in response to the providing, receiving, by the processing device and from the receiving user device, a modified version of the file;
in response to receiving the modified version of the file, generating, by the processing device, a new hash value for the modified version of the file, the new hash value assigned by the inter planetary file system;
appending, by the processing device, the new hash value to the blockchain representation of the file; and
updating, by the processing device, the distributed hash table with the new hash value for the modified version of the file, wherein the new hash value is stored as the new block in the distributed hash table comprising the Merkle directed acyclic graph.
4. The system of claim 3 , wherein the at least one memory storing instructions which, when executed by the at least one data processor, result in further operations comprising:
storing the new hash value in the distributed hash table in a second subset of the plurality of nodes.
5. A non-transitory computer-readable storage medium including program code, which when executed by at least one data processor, causes operations comprising:
receiving, by a processing device, a file to be uploaded to a private peer-to-peer network comprising an inter planetary file system, the private peer-to-peer network comprising a plurality of nodes including a sending user device providing the file to be uploaded, wherein the file to be uploaded is encrypted with a public key of a receiving user device;
generating, by the processing device, a hash value for the file encrypted with the public key of the receiving user device, the hash value beginning with a predetermined identifier indicating that the file belongs to the private peer-to-peer network;
storing, by the processing device, the hash value of the file in a distributed hash table in a subset of the plurality of nodes, wherein the distributed hash table comprises a Merkle directed acyclic graph, wherein a change to the hash file, which corresponds to a change to the file, is stored as a new block in the Merkle directed acyclic graph;
creating, by the processing device, a blockchain representation of the file, the blockchain representation including at least the hash value of the file, a previous hash value of the file, an authentication nonce, and a time stamp to provide an audit trail for validation of changes to the file, wherein the authentication nonce comprises a random or pseudo-random number provided as part of an authentication to ensure that prior communications cannot be used in a replay attack;
in response to a request from the receiving user device and upon verification of the receiving user device, providing, by the processing device, the file to the receiving user device, wherein the verification is based upon a public key exchange between the sending user device and the receiving user device and a determination that a hash of the public key of the receiving user device matches a corresponding node identifier for the receiving device, and wherein the file is provided by identifying, via the distributed hash table rather than the blockchain representation of the file, a nearest node of the plurality of nodes that contains the hash value;
in response to the providing, receiving, by the processing device and from the receiving user device, a modified version of the file;
in response to receiving the modified version of the file, generating, by the processing device, a new hash value for the modified version of the file, the new hash value assigned by the inter planetary file system;
appending, by the processing device, the new hash value to the blockchain representation of the file; and
updating, by the processing device, the distributed hash table with the new hash value for the modified version of the file, wherein the new hash value is stored as the new block in the distributed hash table comprising the Merkle directed acyclic graph.
6. The non-transitory computer-readable storage medium of claim 5 , causing operations further comprising:
storing the new hash value in the distributed hash table in a second subset of the plurality of nodes.