WO2022068239A1 - 数据处理方法、节点设备及存储介质 - Google Patents
数据处理方法、节点设备及存储介质 Download PDFInfo
- Publication number
- WO2022068239A1 WO2022068239A1 PCT/CN2021/097226 CN2021097226W WO2022068239A1 WO 2022068239 A1 WO2022068239 A1 WO 2022068239A1 CN 2021097226 W CN2021097226 W CN 2021097226W WO 2022068239 A1 WO2022068239 A1 WO 2022068239A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- key
- encrypted data
- order
- data
- preserving
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q40/00—Finance; Insurance; Tax strategies; Processing of corporate or income taxes
- G06Q40/04—Trading; Exchange, e.g. stocks, commodities, derivatives or currency exchange
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F16/00—Information retrieval; Database structures therefor; File system structures therefor
- G06F16/20—Information retrieval; Database structures therefor; File system structures therefor of structured data, e.g. relational data
- G06F16/27—Replication, distribution or synchronisation of data between databases or within a distributed database system; Distributed database system architectures therefor
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/602—Providing cryptographic facilities or services
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/64—Protecting data integrity, e.g. using checksums, certificates or signatures
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
- G06Q20/3829—Payment protocols; Details thereof insuring higher security of transaction involving key management
Definitions
- the present application relates to the field of blockchain technology, and in particular, to a data processing method, device, node device and storage medium.
- the signer will digitally sign the transaction data (such as medical data), and the verifier can verify the legitimacy of the transaction data according to the digital signature.
- a signer such as a doctor
- medical data such as patient diagnostic data
- a verifier such as a patient
- the public key of the signer the signed ciphertext of the medical data is verified, and the legality of the medical data is judged according to the verification result.
- the process of generating the digital signature is too simple, resulting in low security of the digital signature.
- the present application provides a data processing method, device, node device and storage medium, which can improve the security of digital signatures.
- the present application provides a data processing method, which is applied to a data providing node in a blockchain network, including:
- the data providing node determines the first key of each first sub-encrypted data in the first encrypted data and the second key of each second sub-encrypted data in the second encrypted data, wherein the first encrypted data is composed of at least one first sub-encrypted data.
- the encrypted data is composed according to the first order, a first sub-encrypted data corresponds to a first key, the second encrypted data is composed of at least one second sub-encrypted data according to the second order, and a second sub-encrypted data corresponds to a second key. key;
- the data providing node determines the private key according to each first key, the first order-preserving coefficient of each first key, each second key, and the second order-preserving coefficient of each second key, wherein each first key
- the first order-preserving coefficients of the first sub-encrypted data are different
- the second order-preserving coefficients of the second keys are different
- the first order-preserving coefficient and the second sub-key of the first sub-encrypted data in the same sorting position are different.
- the second order-preserving coefficient of the second key of the encrypted data is the same; the data providing node signs the first encrypted data and the second encrypted data according to the private key to generate a signature to be verified, and uploads the signature to be verified to the blockchain network
- the corresponding blockchain is used for the data verification node in the blockchain network to verify the first encrypted data and the second encrypted data.
- the present application provides a data processing device, which is applied to a data providing node in a blockchain network, including:
- a first determination module used for the data providing node to determine the first key of each first sub-encrypted data in the first encrypted data and the second key of each second sub-encrypted data in the second encrypted data, wherein the first encrypted data
- the data is composed of at least one first sub-encrypted data according to the first order, one first sub-encrypted data corresponds to a first key, the second encrypted data is composed of at least one second sub-encrypted data according to the second order, and a second sub-encrypted data is composed according to the second order.
- the encrypted data corresponds to a second key;
- the second determination module is used for the data providing node to determine the private key according to each first key, the first order-preserving coefficient of each first key, each second key, and the second order-preserving coefficient of each second key,
- the first order-preserving coefficient of each first key is different
- the second order-preserving coefficient of each second key is different
- the first sub-encrypted data in the same sorting position has a first order-preserving coefficient of the first key.
- the order-preserving coefficient is the same as the second order-preserving coefficient of the second key of the second sub-encrypted data;
- the signature uploading module is used for the data providing node to sign the first encrypted data and the second encrypted data according to the private key to generate a signature to be verified, and upload the signature to be verified to the blockchain corresponding to the blockchain network for block
- the data verification node in the chain network verifies the first encrypted data and the second encrypted data.
- the present application provides a data processing method, which is applied to a data verification node in a blockchain network, including:
- the data verification node obtains the first encrypted data, the second encrypted data and the signature to be verified from the blockchain corresponding to the blockchain network, wherein the first encrypted data is composed of at least one first sub-encrypted data according to the first order, and one The first sub-encrypted data corresponds to a first key, the second encrypted data is composed of at least one second sub-encrypted data according to the second order, one second sub-encrypted data corresponds to a second key, and the signature to be verified is determined by the blockchain.
- the data providing nodes in the network are uploaded to the blockchain;
- the data verification node determines the verification parameters, and determines the public key according to each first key, the first order-preserving coefficient of each first key, each second key, the second order-preserving coefficient of each second key, and the verification parameter , wherein the first order-preserving coefficient of each first key is different, the second order-preserving coefficient of each second key is different, and the first sub-encrypted data in the same sorting position has a different first key
- An order-preserving coefficient is the same as the second order-preserving coefficient of the second key of the second sub-encrypted data;
- the data verification node verifies the signature to be verified according to the public key
- the data verification node determines that the first encrypted data and the second encrypted data are the same.
- the present application provides a data processing device, which is applied to a data verification node in a blockchain network, including:
- the obtaining module is used for the data verification node to obtain the first encrypted data, the second encrypted data and the signature to be verified from the blockchain corresponding to the blockchain network, wherein the first encrypted data is obtained by at least one first sub-encrypted data according to the first encrypted data.
- a sequence is composed, a first sub-encrypted data corresponds to a first key, the second encrypted data is composed of at least one second sub-encrypted data according to the second order, and a second sub-encrypted data corresponds to a second key, to be verified
- the signature is uploaded to the blockchain by the data providing node in the blockchain network;
- the first determination module is used for the data verification node to determine the verification parameters, and according to each first key, the first order-preserving coefficient of each first key, each second key, and the second order-preserving coefficient of each second key coefficients and verification parameters to determine the public key, wherein the first order-preserving coefficients of each first key are different, the second order-preserving coefficients of each second key are different, and the first sub-encrypted data in the same sorting position
- the first order-preserving coefficient of the first key is the same as the second order-preserving coefficient of the second key of the second sub-encrypted data
- the signature verification module is used for the data verification node to verify the signature to be verified according to the public key
- the second determining module is configured to determine that the first encrypted data and the second encrypted data are the same if the to-be-verified signature verification passes, the data verification node determines.
- the present application provides a node device, comprising: a processor, a memory, and a network interface; the processor is connected to the memory and the network interface, wherein the network interface is used to provide a data communication function, and the memory is used to store a computer A program, the processor is used to invoke the computer program to perform the following methods:
- the private key is determined according to each first key, the first order-preserving coefficient of each first key, each second key, and the second order-preserving coefficient of each second key, wherein each first key is The first order-preserving coefficients of a key are different, the second order-preserving coefficients of the second keys are different, and the first order-preserving coefficients of the first keys of the first sub-encrypted data in the same sorting position are different.
- the coefficient is the same as the second order-preserving coefficient of the second key of the second sub-encrypted data;
- the first encrypted data and the second encrypted data are signed according to the private key to generate a signature to be verified, and the signature to be verified is uploaded to the blockchain corresponding to the blockchain network for the district to use.
- the data verification node in the blockchain network verifies the first encrypted data and the second encrypted data.
- the present application provides a node device, including: a processor, a memory, and a network interface; the processor is connected to the memory and the network interface, wherein the network interface is used to provide a data communication function, and the memory is used to store a computer A program, the processor is used to invoke the computer program to perform the following methods:
- the first encrypted data is composed of at least one first sub-encrypted data according to the first order, and a first encrypted data
- the second encrypted data is composed of at least one second sub-encrypted data according to the second order
- one second sub-encrypted data corresponds to a second key
- the signature to be verified is composed of The data providing nodes in the blockchain network are uploaded to the blockchain;
- the first order-preserving coefficient of the first key is the same as the second order-preserving coefficient of the second key of the second sub-encrypted data
- the present application provides a computer-readable storage medium, where the computer-readable storage medium stores a computer program, the computer program includes program instructions, and the program instructions, when executed by a processor, perform the following method:
- the private key is determined according to each first key, the first order-preserving coefficient of each first key, each second key, and the second order-preserving coefficient of each second key, wherein each first key is The first order-preserving coefficients of a key are different, the second order-preserving coefficients of the second keys are different, and the first order-preserving coefficients of the first keys of the first sub-encrypted data in the same sorting position are different.
- the coefficient is the same as the second order-preserving coefficient of the second key of the second sub-encrypted data;
- the first encrypted data and the second encrypted data are signed according to the private key to generate a signature to be verified, and the signature to be verified is uploaded to the blockchain corresponding to the blockchain network for the district to use.
- the data verification node in the blockchain network verifies the first encrypted data and the second encrypted data.
- the present application provides a computer-readable storage medium, where the computer-readable storage medium stores a computer program, the computer program includes program instructions, and the program instructions, when executed by a processor, perform the following method:
- the first encrypted data is composed of at least one first sub-encrypted data according to the first order, and a first encrypted data
- the second encrypted data is composed of at least one second sub-encrypted data according to the second order
- one second sub-encrypted data corresponds to a second key
- the signature to be verified is composed of The data providing nodes in the blockchain network are uploaded to the blockchain;
- the first order-preserving coefficient of the first key is the same as the second order-preserving coefficient of the second key of the second sub-encrypted data
- the present application improves the security of digital signatures (such as signatures to be verified).
- FIG. 1 is a schematic structural diagram of a network architecture provided by the application.
- FIG. 2 is a schematic diagram of an interaction scenario of a data processing method provided by the present application.
- FIG. 3 is a schematic flowchart of a data processing method provided by the present application.
- Fig. 4 is another schematic flow chart of the data processing method provided by the present application.
- FIG. 5 is a schematic structural diagram of a data processing device provided by the present application.
- FIG. 6 is a schematic structural diagram of a node device provided by the present application.
- FIG. 7 is another schematic structural diagram of the data processing device provided by the present application.
- FIG. 8 is another schematic structural diagram of a node device provided by the present application.
- FIG. 9 is a schematic structural diagram of a data processing system provided by the present application.
- the technical solutions of the present application may relate to the field of blockchain technology.
- the present application can be applied to scenarios such as financial technology such as verification of transaction information, or can be applied to scenarios such as digital medical treatment such as verification of electronic information files, so as to improve the security of digital signatures.
- the network architecture may include a blockchain node system for running the blockchain network and a cluster of user terminals.
- the blockchain corresponding to the blockchain network may be a blockchain associated with the business contract.
- the blockchain node system may refer to a system for data sharing between nodes.
- the blockchain node system may include multiple nodes.
- the blockchain node system may specifically include a node 100a, a node 100b, a node 100c, . . . , a node 100n.
- the user terminal cluster may include multiple user terminals, as shown in FIG. 1 , may specifically include user terminals 3000a, user terminals 3000b, user terminals 3000c, . . . , and user terminals 3000n.
- the blockchain node system when each node is working normally, it can obtain the data of the user terminal associated with the node, so as to maintain the shared data in the blockchain node system.
- a network connection can be established between each node in the blockchain node system, and data transmission is performed through the network connection.
- any node in the blockchain node system obtains the target verification data
- other nodes in the blockchain node system can obtain the target verification data according to the consensus algorithm, and use the target verification data as shared data
- the data in the blockchain node system is stored, so that the data stored on all nodes in the blockchain node system are consistent.
- the target verification data here may include the first encrypted data, the second encrypted data and the verification result, wherein the verification result may be that the first encrypted data and the second encrypted data are the same.
- each node in the blockchain node system can perform data interaction with each user terminal in the user terminal cluster. It can be understood that this application can select a node in the blockchain node system shown in Data validating nodes in this blockchain network. Wherein, this application may collectively refer to the nodes used to generate signatures to be verified in the blockchain network as data providing nodes, and this application may also collectively refer to the nodes used to verify signatures to be verified in the blockchain network as data verification nodes .
- the signature to be verified can be the information obtained after signing the first encrypted data and the second encrypted data, where the first encrypted data and the second encrypted data can be uploaded by both parties to the transaction stored on the blockchain for the same exchange encrypted data (such as encrypted data generated by combining multiple sub-encrypted data) or encrypted data corresponding to text.
- the present application may use the node 100a in the blockchain node system as the data providing node, and the present application may also use the node 100b in the blockchain node system as the data verification node. Both the data providing node and the data verification node can perform data interaction with each user terminal in the user terminal cluster.
- the encrypted data is uploaded to the user terminal of the blockchain and/or the user terminal that uploads the second encrypted data to the blockchain) outputs the same verification result of the first encrypted data and the second encrypted data.
- the node device in this application may be an entity terminal with a data processing function, and the entity terminal may be the node 100a or the node 100b as shown in FIG. 1 , or a user terminal, which is not limited herein.
- the application scenario of this application can be a commercial business scenario (such as a scenario where it is necessary to compare whether two encrypted amounts are equal).
- a bank lending scenario the user can make a loan at the bank, and the bank can verify the bank on the blockchain after lending. Whether the loan amount is the same as the user loan amount, that is, it is necessary to verify whether the bank loan encrypted amount and the user loan encrypted amount are the same.
- the application scenario of this application can also be a digital medical scenario, for example, performing zero-knowledge verification on an electronic information file, where the electronic information file may include but not limited to a patient's medical record, a doctor's diagnosis data for a patient, and prescribed drugs, etc. .
- the application scenarios in this application may also be other application scenarios, which are not specifically limited herein.
- FIG. 2 is a schematic diagram of an interaction scenario of the data processing method provided by the present application.
- the present application will involve the above data providing nodes and data verification nodes.
- the data providing node may be the above-mentioned node 100a in FIG. 1
- the data verification node may be the above-mentioned node 100b in FIG. 1 .
- the blockchain 1 can be the blockchain corresponding to the blockchain network in the above-mentioned FIG.
- the blockchain 1 can be a data providing node (eg, node 100a ) and a data verification node (eg, node 100b ) ), each node in the corresponding blockchain network shares an identical blockchain, and each node can obtain the information stored on the blockchain in blockchain 1.
- the block chain 1 may include block 10a, block 10b, block 10c, ..., block 10n, and the block 10a may be called the genesis block of the block chain 1. It can be understood that the blockchain 1 may be a blockchain storing the above-mentioned first encrypted data and second encrypted data.
- the node 100a can obtain the first encrypted data and the second encrypted data from the above-mentioned blockchain 1 . It can be understood that the node 100a can search for a block (such as a block) containing the first encrypted data in each block (such as block 10a, block 10b, block 10c, . . . , block 10n) in the blockchain 1 10a) and a block containing the second encrypted data (eg, block 10a), and respectively obtain the first encrypted data and the second encrypted data from the block 10a. It should be noted that the block containing the first encrypted data and the block containing the second encrypted data on the blockchain can be the same block or different blocks, which can be determined according to the actual application scenario, which is not made here. limited.
- the first encrypted data is composed of at least one first sub-encrypted data according to the first order
- one first sub-encrypted data corresponds to a first key
- the second encrypted data is composed of at least one second sub-encrypted data according to the second order.
- a second sub-encrypted data corresponds to a second key.
- the sub-encrypted data in the first encrypted data may be collectively referred to as the first sub-encrypted data
- the sub-encrypted data in the second encrypted data may also be collectively referred to as the second sub-encrypted data in the present application.
- the first order here may be the arrangement order in which at least one first sub-encrypted data is combined to form the first encrypted data
- the second order may be the arrangement order in which at least one second sub-encrypted data is combined into the second encrypted data.
- the keys corresponding to all the first sub-encrypted data may be collectively referred to as the first keys, and the present application may also collectively refer to the keys corresponding to all the second sub-encrypted data as the second keys.
- the node 100a may determine the first key of each first sub-encrypted data in the first encrypted data and the second key of each second sub-encrypted data in the second encrypted data.
- the node 100a can use the first key of each first sub-encrypted data, the first order-preserving coefficient of each first key, the second key of each second sub-encrypted data, and the first key of each second key
- the second order-preserving coefficient determines the private key, and signs the first encrypted data and the second encrypted data according to the private key to generate a signature to be verified.
- the coefficients of each first key may be collectively referred to as the first order-preserving coefficient, and the present application may also collectively refer to the coefficient of each second key as the second order-preserving coefficient.
- the node 100a can upload the signature to be verified to the blockchain 1, and the signature to be verified is stored on the blockchain 1 at this time.
- the signature to be verified here can be subsequently used by a data verification node (eg, node 100b) to verify the first encrypted data and the second encrypted data.
- the node 100b can obtain the first encrypted data, the second encrypted data and the signature to be verified from the blockchain 1 . It can be understood that the node 100b can search each block in the blockchain 1 for a block containing the first encrypted data (such as the above-mentioned block 10a), a block containing the second encrypted data (such as the above-mentioned block 10a), and The signature block containing the signature to be verified is obtained, and the first encrypted data, the second encrypted data and the signature to be verified are respectively obtained from the block 10a and the above-mentioned signature block.
- the block that stores the signature to be verified in the blockchain may be called the signature block.
- the node 100b can use the first keys, the first order-preserving coefficients of the first keys, the second keys, the second order-preserving coefficients of the second keys, and the verification parameters (the verification parameters here).
- the parameter may be a preset parameter) to determine the public key.
- the node 100b can verify the signature to be verified according to the public key. If the signature to be verified is verified, the node 100b determines that the first encrypted data and the second encrypted data are the same .
- the data providing node can be determined by each first key, the first order-preserving coefficient of each first key, each second key, and the second order-preserving coefficient of each second key
- the private key is used to generate signatures to be verified for the first encrypted data and the second encrypted data, thereby improving the security of digital signatures (eg, signatures to be verified).
- the signature to be verified here can be subsequently applied to the data verification node to verify whether the first encrypted data and the second encrypted data are the same.
- the data verification node can obtain the first encrypted data, the second encrypted data and the signature to be verified from the blockchain, and according to the above-mentioned first keys, the first order-preserving coefficients of the first keys, and the The second key, the second order-preserving coefficient of each second key, and the verification parameters determine the public key.
- the public key here can be used to verify the signature to be verified later, and further determine the first encrypted data and the second encrypted data according to the verification result. Whether the encrypted data is the same.
- the data verification node can verify the signature to be verified by using the public key, and if the signature to be verified passes the verification, it is determined that the first encrypted data and the second encrypted data are the same, the consistency of the encrypted data can be verified, and the verification efficiency is improved. And the verification accuracy is high.
- FIG. 3 is a schematic flowchart of the data processing method provided by the present application.
- the present application may take the node device as the data providing node (such as the node 100a in the above-mentioned FIG. 2 ) as an example, the method shown in FIG. 3 is applied to the data providing node in the blockchain network, and may include the following steps S101-S103 :
- Step S101 the data providing node determines the first key of each first sub-encrypted data in the first encrypted data and the second key of each second sub-encrypted data in the second encrypted data.
- the first encrypted data is composed of at least one first sub-encrypted data according to the first order
- one first sub-encrypted data corresponds to a first key
- the second encrypted data is composed of at least one second sub-encrypted data according to the second order.
- a second sub-encrypted data corresponds to a second key.
- each first key may be a key determined according to the first root key
- each second key may be a key determined according to the second root key, where the first root key and the second root key can both be preset or pre-stored root keys.
- the first keys may be independent of each other
- the second keys may also be independent of each other, which may be determined according to actual application scenarios, which are not limited here.
- the data providing node (such as the above-mentioned node 100a) can also obtain the first encrypted data and the second encrypted data from the blockchain.
- a block of encrypted data (such as the above-mentioned block 10a) and a block containing the above-mentioned second encrypted data (such as the block 10a), and the first encrypted data is obtained from the block containing the first encrypted data, and from the block containing the first encrypted data.
- the second encrypted data obtained in the block of the second encrypted data can be specifically determined according to the actual application scenario, which is not limited here.
- the node 100a can obtain the above hash value 1 and determine the root hash value 1 under the authentication path to which the hash value 1 belongs.
- the node 100a can obtain the first encrypted data from the block to which the root hash value 1 belongs (such as the above-mentioned block 10a); if the hash value corresponding to the second encrypted data is the hash value 2, the node 100a can obtain the above-mentioned hash value.
- the hash value is 2, and the root hash value 2 under the authentication path to which the hash value 2 belongs is determined.
- the node 100a can obtain the second encrypted value from the block (such as the above-mentioned block 10a) to which the root hash value 2 belongs.
- the authentication path to which the hash value (eg, hash value 1 or hash value 2) belongs may refer to a path for querying its corresponding root hash value (eg, root hash value 1 or root hash value 2) through the hash value.
- the data providing node can Hash value 2) determines the block containing encrypted data (either the first encrypted data or the second encrypted data).
- the block containing the first encrypted data and the block containing the second encrypted data on the blockchain can be the same block or different blocks, which can be determined according to the actual application scenario, which is not made here. limited.
- ECC elliptic curve cryptography
- M a M a0
- sub-encrypted data obtained by encrypting the sub-plaintext data such as M a0 , M a1 , ..., Man-1 .
- the elliptic curve encryption algorithm may include P224 curve, P256 curve (P256 curve may also be called secp256r1 curve), P384 curve and P512 curve.
- the data format of the above-mentioned first encrypted data can be the perdesen commitment format in cryptography, that is, the data format of each first sub-encrypted data can be the perdesen commitment format, and each first key can be called the perdesen commitment format.
- C ai can be a point represented by the uncompressed C ai on the elliptic curve, and C ai can be
- the (i+1)th first sub-encrypted data, i may be an integer greater than or equal to 0 and less than or equal to n-1.
- k ai can be the (i+th) 1
- the first key (ie blind factor) of the first sub-encrypted data, H can be a verification parameter, and H is used to represent the division on the above elliptic curve another point.
- the second encrypted data (such as C b ) is composed of at least one second sub-encrypted data (such as n second sub-encrypted data, namely C b0 , C b1 , . . . , C bn-1 ) according to the second order,
- n second sub-encrypted data such as C b0 , C b1 , . . . , C bn-1
- the second order here may be the order in which at least one second sub-encrypted data is combined into the second encrypted data.
- the first sorting is the same as the second sorting.
- the data format of the above-mentioned second encrypted data can be the perdesen commitment format in cryptography, that is, the data format of each second sub-encrypted data can be the perdesen commitment format, and each second key can be called each second key in the perdesen commitment format. Blind factor in sub-encrypted data.
- C bi may be the (i+1)th second sub-encrypted data.
- the data providing node may determine the first key of each first sub-encrypted data in the first encrypted data and each second sub-encrypted data in the second encrypted data. the second key.
- the first key of each first sub-encrypted data (ie, C a0 , C a1 , ..., Can -1 ) in the first encrypted data C a may be ka0 , ka1 , ..., kan-1
- k a0 may be the first key of the first first sub-encrypted data C a0
- k a1 may be the first key of the second first sub-encrypted data C a1
- k an-1 may be The first key of the n-th first sub-encrypted data Can-1 .
- the second key of each second sub-encrypted data (ie, C b0 , C b1 , ..., C bn-1 ) in the second encrypted data C b may be k b0 , k b1 , ..., k bn-1 , where k b0 can be the second key of the first second sub-encrypted data C b0 , k b1 can be the second key of the second second sub-encrypted data C b1 , ..., k bn-1 can be The second key for the n-th second sub-encrypted data C bn-1 .
- Step S102 the data providing node determines the private key according to each first key, the first order-preserving coefficient of each first key, each second key, and the second order-preserving coefficient of each second key.
- the first order-preserving coefficient of each first key is different
- the second order-preserving coefficient of each second key is different
- the first sub-encrypted data in the same sorting position has a first order-preserving coefficient of the first key.
- the order-preserving coefficient is the same as the second order-preserving coefficient of the second key of the second sub-encrypted data.
- the first order-preserving coefficient of the first key ka0 of the above-mentioned C a0 may be 1
- the first order-preserving coefficient of the first key ka1 of the above - mentioned C a1 may be 2, . . .
- the first order-preserving coefficient of the first key k an-1 may be n
- the second order-preserving coefficient of the second key k b0 of the above-mentioned C b0 may be the same as the first order-preserving coefficient of the above-mentioned k a0 , that is, the second
- the second order-preserving coefficient of the key k b0 may be 1
- the second order-preserving coefficient of the second key k b1 of the above-mentioned C b1 may be the same as the first order-preserving coefficient of the above-mentioned k a1 , that is, the second key k b1
- the second order-preserving coefficient of k an-1 may be 2, ..., the second order-preserving coefficient of the second key k bn-1 of the above C bn-1 may be the same as the first order-preserving coefficient of the above k an-1 , that is, the second The second order-preserving coefficient of the key kbn-1 may be n.
- the data providing node may determine the first order-preserving coefficient of each first key, and determine all the first keys according to each first key and the first order-preserving coefficient of each first key The first cumulative key of .
- the data providing node may determine the second order-preserving coefficient of each second key, and determine the second cumulative encryption of all second keys according to each second key and the second order-preserving coefficient of each second key key.
- the data providing node may determine the private key according to the first accumulated key and the second accumulated key.
- P can be the public key
- C a0 can be the first first sub-encrypted data
- C a1 can be the second first sub-encrypted data
- C an-1 can be the n-th first sub-encrypted data
- C b0 can be the first second sub-encrypted data
- C b1 can be the second second sub-encrypted data
- C bn-1 can be the n-th second sub-encrypted data
- 1, 2, ..., n may be the first order-preservation coefficient of each of the first keys, and also the second order-preservation coefficient of each of the second keys, that is, the first order-preservation coefficient of the first key of the first sub-encrypted data in the same sorting position
- the sequence coefficient is the same as the second sequence-preserving coefficient of the second key of the second sub-encrypted data.
- formula (5) is simplified according to the above formula (1)-formula (4). It should be noted that in the process of simplification, since the first sub-encrypted data and the second sub-encrypted data are based on the same The sub-encrypted data generated after the elliptic curve encryption algorithm (such as the above P256 curve) is encrypted, so and the same, at the same time and Under the same conditions, the private key can be obtained, so that the simplified formula (ie formula (6)) can be obtained.
- the formula (6) is as follows:
- P can be the above public key
- H can be a verification parameter.
- the first cumulative key and the second cumulative key are explained by the above formula (6), can be the first accumulated key, can be the second cumulative key, where i+1 is the first order-preserving coefficient of k ai , and i+1 is also the second order-preserving coefficient of k bi .
- Step S103 the data providing node signs the first encrypted data and the second encrypted data according to the private key to generate a signature to be verified, and uploads the signature to be verified to the blockchain corresponding to the blockchain network for use in the blockchain network
- the data verification node verifies the first encrypted data and the second encrypted data.
- the data providing node generates joint encrypted data according to the first encrypted data and the second encrypted data, and determines a first joint hash value of the joint encrypted data. Further, the data providing node signs the first joint hash value of the joint encrypted data according to the private key, and generates signatures to be verified for the first encrypted data and the second encrypted data.
- the encrypted data obtained by jointly processing the first encrypted data and the second encrypted data may be referred to as joint encrypted data, and the application may also refer to the hash value of the joint encrypted data as the first joint hash value.
- the data providing node may perform joint processing on the first encrypted data and the second encrypted data to obtain joint encrypted data.
- the first encrypted data C a
- the second encrypted data C b as an example for description.
- the joint encrypted data may also be joint encrypted data obtained according to other joint processing methods, which can be specifically determined according to the actual application scenario, which is not limited here.
- the data providing node may perform a hash operation on the joint encrypted data through a hash algorithm to obtain a first joint hash value of the joint encrypted data.
- the hash algorithm may be a secure hash algorithm (secure hash algorithm, SHA).
- the secure hash algorithm is a family of cryptographic hash functions and is a secure hash algorithm certified by the Federal Information Processing Standards (FIPS).
- the secure hash algorithm can calculate an algorithm of a fixed-length character string (also known as a message digest, for example, the first joint hash value) corresponding to a digital message.
- SHA can include SHA-1, SHA-224, SHA-256, SHA-384 and SHA-512.
- the data providing node can sign the first joint hash value through a digital signature algorithm to obtain the signature to be verified.
- the digital signature algorithm may include, but is not limited to: RSA (a signature algorithm), DSA (a signature algorithm), ECDSA (a signature algorithm), and the like.
- the data providing node may upload the signature to be verified to the blockchain corresponding to the blockchain network (such as the aforementioned blockchain 1). It can be understood that the data providing node can generate a signature block according to the signature to be verified, and upload the signature block to the blockchain. At this time, the signature to be verified is stored in the signature block of the blockchain.
- the signature to be verified here is subsequently used by the data verification node in the blockchain network to verify the first encrypted data and the second encrypted data (for example, to verify whether the first encrypted data and the second encrypted data are the same).
- the data providing node can determine the private key by using each first key, the first order-preserving coefficient of each first key, each second key, and the second order-preserving coefficient of each second key, and The first encrypted data and the second encrypted data are signed according to the private key to generate the signature to be verified, and the complexity of the private key is high, thereby improving the security of the digital signature (eg, the signature to be verified).
- FIG. 4 is another schematic flowchart of the data processing method provided by the present application.
- This application can take the node device as a data verification node (such as the node 100b in the above-mentioned FIG. 2 ) as an example, the method shown in FIG. 4 is applied to a data verification node in a blockchain network, and may include the following steps S201-S204 :
- Step S201 the data verification node obtains the first encrypted data, the second encrypted data and the signature to be verified from the blockchain corresponding to the blockchain network.
- the data verification node (such as the above node 100b) can respectively search for the block containing the first encrypted data (such as the above block 10a), the block containing the second encrypted data (such as the above block 10a) from all blocks in the blockchain. Above-mentioned block 10a) and the signature block containing the signature to be verified, and obtain the first encrypted data from the block containing the first encrypted data, obtain the second encrypted data from the block containing the second encrypted data, and from the block containing the second encrypted data. Obtain the signature to be verified from the signature block containing the signature to be verified.
- the node 100b can obtain the hash value 1 corresponding to the first encrypted data, and determine the root hash value 1 under the authentication path to which the hash value 1 belongs.
- the node 100b can obtain the hash value 2 corresponding to the second encrypted data, and determine the root hash value 2 under the authentication path to which the hash value 2 belongs.
- the second encrypted data is obtained from the block 10a to which the hash value 2 belongs; the node 100b can obtain the above-mentioned first joint hash value, and determine the root hash value 3 under the authentication path to which the first joint hash value belongs.
- the node 100b can obtain the signature to be verified from the signature block to which the root hash value 3 belongs.
- Step S202 the data verification node determines the verification parameters, and according to each first key, the first order-preserving coefficient of each first key, each second key, the second order-preserving coefficient of each second key, and the verification parameter Determine the public key.
- the data validation node determines validation parameters. After determining the verification parameters, the data verification node may determine the first order-preserving coefficient of each first key, and determine the first order-preserving coefficient of all the first keys according to each first key and the first order-preserving coefficient of each first key A cumulative key. At this time, the data verification node determines the second order-preserving coefficient of each second key, and determines the second cumulative key of all second keys according to each second key and the second order-preserving coefficient of each second key . Further, the data verification node determines the public key according to the first accumulated key, the second accumulated key and the verification parameter.
- the data verification node can calculate the public key according to the above formula (6). (ie the first cumulative key), (ie the second accumulated key) and H (ie the verification parameter) to calculate the public key (ie P).
- Step S203 the data verification node verifies the signature to be verified according to the public key.
- the data verification node generates joint encrypted data according to the first encrypted data and the second encrypted data, and determines a first joint hash value of the joint encrypted data.
- the data verification node verifies the signature to be verified according to the public key, and obtains the second joint hash value. If the second joint hash value is the same as the first joint hash value, the data verification node determines that the signature to be verified has passed the verification. If the second joint hash value is different from the first joint hash value, the data verification node determines that the signature verification to be verified fails.
- the hash value obtained by the data verification node after verifying the signature to be verified may be referred to as the second joint hash value.
- Step S204 if the signature to be verified passes the verification, the data verification node determines that the first encrypted data and the second encrypted data are the same.
- the data verification node can further determine that the plaintext data corresponding to the first encrypted data and the plaintext data corresponding to the second encrypted data are the same, and can verify the consistency of the encrypted data at this time. (that is, verifying whether the two encrypted data are the same, such as whether the first encrypted data and the second encrypted data are the same), the verification accuracy rate is high.
- the data verification node if the signature to be verified passes the verification, the data verification node generates a target block according to the first encrypted data, the second encrypted data and the verification result, and adds the target block to the blockchain, wherein, The verification result is that the first encrypted data and the second encrypted data are the same.
- the data verification node can package the first encrypted data, the second encrypted data and the verification result into a block to be verified, and send the block to be verified to the consensus node in the blockchain network consensus.
- the block to be verified may be a block that has not been reached by consensus nodes in the blockchain network.
- the data verification node can obtain the consensus confirmation information returned by the consensus node in the blockchain network.
- the consensus node can return a consensus confirmation to the data verification node at this time, the data verification node can obtain the consensus confirmation information returned by the consensus node in the blockchain network.
- one consensus node can correspond to one consensus confirmation message. Further, if the total number of consensus confirmation information counted by the data verification node is greater than the consensus threshold of the consensus node, the consensus is determined to be completed, and the block to be verified that has passed the verification is determined as the target block, and the target block is added. to the blockchain corresponding to the blockchain network (such as the above-mentioned blockchain 1).
- the consensus threshold of the consensus node is 0.8A. At this time, if the total number of consensus confirmation information B is greater than 0.8A , the consensus is confirmed.
- the data verification node determines that the first encrypted data and the second encrypted data are different, and outputs verification failure information.
- the verification failure information is used to indicate that the first encrypted data is different from the second encrypted data. It can be understood that the data verification node can output verification failure information to the data providing node.
- the data verification node may also output verification failure information to the user terminal, so that the user can perform subsequent processing on the first encrypted data and the second encrypted data according to the verification failure information.
- the first encrypted data and the second encrypted data are two encrypted loan amounts (such as encrypted loan amount a and encrypted loan amount b) of the bank and borrower (user a and bank staff b) for the same loan transaction, in the data
- the verification node verifies that the encrypted loan amount a and the encrypted loan amount b are different, it needs to output the verification failure to the user terminal where the user a is located (such as the user terminal 3000a above) and the user terminal where the bank staff b is located (such as the user terminal 3000b above). information, so that user a and bank staff b can follow up on the loan transaction.
- the data verification node can obtain the first encrypted data, the second encrypted data and the signature to be verified from the blockchain, and according to the above-mentioned first keys, the first order-preserving coefficients of the first keys, Each second key, the second order-preserving coefficient of each second key, and the verification parameters determine the public key, and the public key here can be used to verify the signature to be verified later, and further determine the first encrypted data and the first encrypted data according to the verification result. Whether the second encrypted data is the same. Further, the data verification node can verify the signature to be verified by using the public key, and if the signature to be verified passes the verification, it is determined that the first encrypted data and the second encrypted data are the same, the consistency of the encrypted data can be verified, and the verification efficiency is improved. And the verification accuracy is high.
- FIG. 5 is a schematic structural diagram of the data processing apparatus provided by the present application.
- the data processing apparatus may be a computer program (including program code) running in the node device, for example, the data processing apparatus is an application software; the data processing apparatus may be used to execute corresponding steps in the methods provided in this application.
- the data processing apparatus 1 can be applied to a data providing node in a blockchain network, and the data providing node can be the node 100 a in the embodiment corresponding to FIG. 2 above.
- the data processing apparatus 1 may include: a first determination module 10 , a second determination module 11 , and a signature uploading module 12 .
- the first determination module 10 is used for the data providing node to determine the first key of each first sub-encrypted data in the first encrypted data and the second key of each second sub-encrypted data in the second encrypted data, wherein the first The encrypted data is composed of at least one first sub-encrypted data according to the first order, one first sub-encrypted data corresponds to a first key, the second encrypted data is composed of at least one second sub-encrypted data according to the second order, and a second sub-encrypted data is composed according to the second order.
- the sub-encrypted data corresponds to a second key;
- the second determination module 11 is used for the data providing node to determine the private key according to each first key, the first order-preserving coefficient of each first key, each second key, and the second order-preserving coefficient of each second key , wherein the first order-preserving coefficient of each first key is different, the second order-preserving coefficient of each second key is different, and the first sub-encrypted data in the same sorting position has a different first key
- An order-preserving coefficient is the same as the second order-preserving coefficient of the second key of the second sub-encrypted data;
- the signature uploading module 12 is used for the data providing node to sign the first encrypted data and the second encrypted data according to the private key to generate a signature to be verified, and upload the signature to be verified to the blockchain corresponding to the blockchain network for the district.
- the data verification node in the blockchain network verifies the first encrypted data and the second encrypted data.
- the second determining module 11 includes: a first determining unit 111, configured for the data providing node to determine the first order-preserving coefficient of each first key, and according to each first key and each first key The first order-preserving coefficient of the key determines the first accumulated keys of all the first keys; the second determining unit 112 is used for the data providing node to determine the second order-preserving coefficient of each second key, and according to each second key The key and the second order-preserving coefficient of each second key determine the second cumulative keys of all the second keys; the third determination unit 113 is used for the data providing node to determine the second cumulative key according to the first cumulative key and the second cumulative key Determine the private key.
- the signature uploading module 12 includes: a fourth determining unit 121, configured for the data providing node to generate joint encrypted data according to the first encrypted data and the second encrypted data, and determine the first joint hash of the joint encrypted data value; the signature unit 122 is used for the data providing node to sign the first joint hash value according to the private key to obtain the signature to be verified.
- the specific implementation of the first determination module 10 , the second determination module 11 and the signature uploading module 12 can refer to the description of steps S101 to S103 in the embodiment corresponding to FIG. 3 , which will not be repeated here. In addition, the description of the beneficial effects of using the same method will not be repeated.
- FIG. 6 is a schematic structural diagram of a node device provided by the present application.
- the node device may include a processor, memory, and a network interface.
- the node device may further include a user interface.
- the node device 1000 may be the node 100a in the above-mentioned embodiment corresponding to FIG. 2 , and the node device 1000 may include: at least one processor 1001 , such as a CPU, at least one network interface 1004 , and user interface 1003 , memory 1005 , at least one communication bus 1002 .
- the communication bus 1002 is used to realize the connection and communication between these components.
- the user interface 1003 may include a display screen (Display) and a keyboard (Keyboard), and the network interface 1004 may optionally include a standard wired interface and a wireless interface (eg, a WI-FI interface).
- the memory 1005 may be high-speed RAM memory or non-volatile memory, such as at least one disk memory.
- the memory 1005 may optionally also be at least one storage device located remotely from the aforementioned processor 1001 .
- the memory 1005, which is a computer storage medium may include an operating system, a network communication module, a user interface module, and a device control application program.
- the network interface 1004 is mainly used for network communication with other nodes (such as data verification nodes) and user terminals in the blockchain network; and the user interface 1003 is mainly used to provide input for the user and the processor 1001 can be used to call the device control application program stored in the memory 1005 to realize:
- the data providing node determines the first key of each first sub-encrypted data in the first encrypted data and the second key of each second sub-encrypted data in the second encrypted data, wherein the first encrypted data is composed of at least one first sub-encrypted data.
- the encrypted data is composed according to the first order, a first sub-encrypted data corresponds to a first key, the second encrypted data is composed of at least one second sub-encrypted data according to the second order, and a second sub-encrypted data corresponds to a second key. key;
- the data providing node determines the private key according to each first key, the first order-preserving coefficient of each first key, each second key, and the second order-preserving coefficient of each second key, wherein each first key
- the first order-preserving coefficients of the first sub-encrypted data are different
- the second order-preserving coefficients of the second keys are different
- the first order-preserving coefficient and the second sub-key of the first sub-encrypted data in the same sorting position are different.
- the second order-preserving coefficients of the second key of the encrypted data are the same;
- the data providing node signs the first encrypted data and the second encrypted data according to the private key to generate a signature to be verified, and uploads the signature to be verified to the blockchain corresponding to the blockchain network for data verification in the blockchain network
- the node verifies the first encrypted data and the second encrypted data.
- the node device 1000 described in this application may execute the description of the data processing method in the foregoing embodiment corresponding to FIG. 3 , and may also execute the description of the data processing apparatus 1 in the foregoing embodiment corresponding to FIG. 5 , It is not repeated here. In addition, the description of the beneficial effects of using the same method will not be repeated.
- the present application also provides a computer-readable storage medium, and the computer-readable storage medium stores a computer program executed by the aforementioned data processing apparatus 1, and the computer program includes The program instruction, when the processor executes the program instruction, can execute the description of the data processing method in the above-mentioned embodiment corresponding to FIG. 3 , therefore, it will not be repeated here.
- the description of the beneficial effects of using the same method will not be repeated.
- program instructions may be deployed to execute on one computing device, or on multiple computing devices located at one site, or alternatively, on multiple computing devices distributed across multiple sites and interconnected by a communications network
- multiple computing devices distributed in multiple locations and interconnected by a communication network can form a blockchain system.
- FIG. 7 is another schematic structural diagram of the data processing apparatus provided by the present application.
- the data processing apparatus may be a computer program (including program code) running in the node device, for example, the data processing apparatus is an application software; the data processing apparatus may be used to execute corresponding steps in the methods provided in this application.
- the data processing apparatus 2 can be applied to a data verification node in a blockchain network, and the data verification node can be the node 100b in the embodiment corresponding to FIG. 2 above.
- the data processing apparatus 2 may include: an acquisition module 20 , a first determination module 21 , a signature verification module 22 , a second determination module 23 , an output module 24 and an addition module 25 .
- the obtaining module 20 is used for the data verification node to obtain the first encrypted data, the second encrypted data and the signature to be verified from the blockchain corresponding to the blockchain network, wherein the first encrypted data is composed of at least one first sub-encrypted data according to the The first order is composed, a first sub-encrypted data corresponds to a first key, the second encrypted data is composed of at least one second sub-encrypted data according to the second order, and a second sub-encrypted data corresponds to a second key.
- the verification signature is uploaded to the blockchain by the data providing node in the blockchain network;
- the first determination module 21 is used for the data verification node to determine the verification parameters, and according to each first key, the first order-preservation coefficient of each first key, each second key, and the second guarantee of each second key.
- the order coefficient and the verification parameter determine the public key, wherein the first order-preservation coefficient of each first key is different, the second order-preservation coefficient of each second key is different, and the first sub-encryption of the same sorting position
- the first order-preserving coefficient of the first key of the data is the same as the second order-preserving coefficient of the second key of the second sub-encrypted data;
- the signature verification module 22 is used for the data verification node to verify the signature to be verified according to the public key
- the second determination module 23 is configured to determine that the first encrypted data and the second encrypted data are the same if the signature to be verified passes the verification.
- the first determination module 21 includes: a first determination unit 211, which is used for the data verification node to determine the first order-preserving coefficient of each first key, and according to each first key and each first key The first order-preserving coefficient of the keys determines the first accumulated keys of all the first keys; the second determining unit 212 is used for the data verification node to determine the second order-preserving coefficient of each second key, and according to each second key The key and the second order-preserving coefficient of each second key determine the second cumulative key of all the second keys; the third determining unit 213 is used for the data verification node to determine the second cumulative key according to the first cumulative key and the second cumulative key. And the authentication parameter determines the public key.
- a first determination unit 211 which is used for the data verification node to determine the first order-preserving coefficient of each first key, and according to each first key and each first key The first order-preserving coefficient of the keys determines the first accumulated keys of all the first keys
- the second determining unit 212 is used for the data verification node to determine the second order
- the signature verification module 22 includes: a fourth determination unit 221, configured for the data verification node to generate joint encrypted data according to the first encrypted data and the second encrypted data, and to determine the first joint hash of the joint encrypted data value; the verification unit 222 is used for the data verification node to verify the signature to be verified according to the public key to obtain the second joint hash value; the fifth determination unit 223 is used for if the second joint hash value and the first joint hash value are If the hash values are the same, the data verification node determines that the signature to be verified has passed the verification; the sixth determination unit 224 is used for if the second joint hash value and the first joint hash value are different, the data verification node determines that the signature to be verified has not been verified. pass.
- a fourth determination unit 221 configured for the data verification node to generate joint encrypted data according to the first encrypted data and the second encrypted data, and to determine the first joint hash of the joint encrypted data value
- the verification unit 222 is used for the data verification node to verify the signature to be
- the data processing apparatus 2 further includes: an output module 24, configured to, if the signature verification to be verified fails, the data verification node determines that the first encrypted data and the second encrypted data are different, and outputs the verification failure information.
- the above data processing device 2 further includes: an adding module 25, configured to generate a target block according to the first encrypted data, the second encrypted data and the verification result if the signature to be verified passes the verification. , and add the target block to the blockchain, wherein the verification result is that the first encrypted data and the second encrypted data are the same.
- step S201 - step S201 in the embodiment corresponding to FIG. 4 above The description of S204 will not be repeated here. In addition, the description of the beneficial effects of using the same method will not be repeated.
- FIG. 8 is another schematic structural diagram of the node device provided by the present application.
- the node device may include a processor, memory, and a network interface.
- the node device may further include a user interface.
- the node device 2000 may be the node 200a in the above-mentioned embodiment corresponding to FIG. 2 , and the node device 2000 may include: at least one processor 2001 , such as a CPU, at least one network interface 2004 , and user interface 2003 , memory 2005 , at least one communication bus 2002 .
- the communication bus 2002 is used to realize the connection and communication between these components.
- the user interface 2003 may include a display screen (display) and a keyboard (keyboard), and the network interface 2004 may optionally include a standard wired interface and a wireless interface (eg, a WI-FI interface).
- the memory 2005 may be high-speed RAM memory or non-volatile memory, such as at least one disk memory.
- the memory 2005 may optionally also be at least one storage device located remotely from the aforementioned processor 2001 .
- the memory 2005 as a computer storage medium may include an operating system, a network communication module, a user interface module, and a device control application program.
- the network interface 2004 is mainly used for network communication with other nodes (such as data providing nodes) and user terminals in the blockchain network; and the user interface 2003 is mainly used to provide input for the user and the processor 2001 can be used to call the device control application program stored in the memory 2005 to realize:
- the data verification node obtains the first encrypted data, the second encrypted data and the signature to be verified from the blockchain corresponding to the blockchain network, wherein the first encrypted data is composed of at least one first sub-encrypted data according to the first order, and one The first sub-encrypted data corresponds to a first key, the second encrypted data is composed of at least one second sub-encrypted data according to the second order, one second sub-encrypted data corresponds to a second key, and the signature to be verified is determined by the blockchain.
- the data providing nodes in the network are uploaded to the blockchain;
- the data verification node determines the verification parameters, and determines the public key according to each first key, the first order-preserving coefficient of each first key, each second key, the second order-preserving coefficient of each second key, and the verification parameter , wherein the first order-preserving coefficient of each first key is different, the second order-preserving coefficient of each second key is different, and the first sub-encrypted data in the same sorting position has a different first key
- An order-preserving coefficient is the same as the second order-preserving coefficient of the second key of the second sub-encrypted data;
- the data verification node verifies the signature to be verified according to the public key
- the data verification node determines that the first encrypted data and the second encrypted data are the same.
- the node device 2000 described in this application may execute the description of the data processing method in the foregoing embodiment corresponding to FIG. 4 , and may also execute the description of the data processing apparatus 2 in the foregoing embodiment corresponding to FIG. 7 , It is not repeated here. In addition, the description of the beneficial effects of using the same method will not be repeated.
- the present application also provides a computer-readable storage medium, and the computer-readable storage medium stores a computer program executed by the aforementioned data processing device 2, and the computer program includes The program instruction, when the processor executes the program instruction, can execute the description of the data processing method in the foregoing embodiment corresponding to FIG. 4 , and therefore will not be repeated here.
- the description of the beneficial effects of using the same method will not be repeated.
- program instructions may be deployed to execute on one computing device, or on multiple computing devices located at one site, or alternatively, on multiple computing devices distributed across multiple sites and interconnected by a communications network
- multiple computing devices distributed in multiple locations and interconnected by a communication network can form a blockchain system.
- the storage medium involved in this application such as a computer-readable storage medium, may be non-volatile or volatile.
- FIG. 9 is a schematic structural diagram of the data processing system provided by the present application.
- the data processing system 3 may include a data processing device 1a and a data processing device 2a.
- the data processing apparatus 1a may be the data processing apparatus 1 in the embodiment corresponding to FIG. 5. It can be understood that the data processing apparatus 1a may be integrated into the node 100a in the embodiment corresponding to FIG. 2. Therefore, here No further description will be given.
- the data processing device 2a may be the data processing device 2 in the embodiment corresponding to FIG. 7. It is understood that the data processing device 2a may be integrated into the node 100b in the embodiment corresponding to FIG. 2. Therefore, here No further description will be given. In addition, the description of the beneficial effects of using the same method will not be repeated.
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Business, Economics & Management (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Accounting & Taxation (AREA)
- Computer Security & Cryptography (AREA)
- Finance (AREA)
- General Engineering & Computer Science (AREA)
- Health & Medical Sciences (AREA)
- Bioethics (AREA)
- Software Systems (AREA)
- Strategic Management (AREA)
- General Business, Economics & Management (AREA)
- Databases & Information Systems (AREA)
- Computer Hardware Design (AREA)
- General Health & Medical Sciences (AREA)
- Computing Systems (AREA)
- Development Economics (AREA)
- Economics (AREA)
- Marketing (AREA)
- Data Mining & Analysis (AREA)
- Technology Law (AREA)
- Storage Device Security (AREA)
Abstract
一种数据处理方法、节点设备及存储介质,其适用于零知识证明以及数字医疗,该方法应用于区块链网络中的数据提供节点,包括:数据提供节点确定第一加密数据中各第一子加密数据的第一密钥以及第二加密数据中各第二子加密数据的第二密钥(S101);数据提供节点根据各第一密钥、各第一密钥的第一保序系数、各第二密钥以及各第二密钥的第二保序系数确定私钥(S102);数据提供节点根据私钥对第一加密数据和第二加密数据进行签名以生成待验证签名,并将待验证签名上传至区块链网络对应的区块链以供区块链网络中的数据验证节点对第一加密数据和第二加密数据进行验证(S103)。可以提高数字签名的安全性。
Description
本申请要求于2020年9月29日提交中国专利局、申请号为202011048106.0,发明名称为“数据处理方法、装置、节点设备及存储介质”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
本申请涉及区块链技术领域,尤其涉及一种数据处理方法、装置、节点设备及存储介质。
目前,签名方会对交易数据(如医疗数据)进行数字签名,验证方则可以根据该数字签名验证交易数据的合法性。发明人意识到,通常来说,签名方(如医生)可以通过其私钥对医疗数据(如患者诊断数据)进行签名,从而得到医疗数据的签名密文,而验证方(如患者)则可以利用签名方的公钥,对医疗数据的签名密文进行验证,并根据验证结果判断医疗数据的合法性。然而在现有的数字签名的生成过程中,生成数字签名的过程过于简单,导致了数字签名的安全性较低。
发明内容
本申请提供一种数据处理方法、装置、节点设备及存储介质,可以提高数字签名的安全性。
第一方面,本申请提供了一种数据处理方法,该方法应用于区块链网络中的数据提供节点,包括:
数据提供节点确定第一加密数据中各第一子加密数据的第一密钥以及第二加密数据中各第二子加密数据的第二密钥,其中,第一加密数据由至少一个第一子加密数据按照第一排序组成,一个第一子加密数据对应一个第一密钥,第二加密数据由至少一个第二子加密数据按照第二排序组成,一个第二子加密数据对应一个第二密钥;
数据提供节点根据各第一密钥、各第一密钥的第一保序系数、各第二密钥以及各第二密钥的第二保序系数确定私钥,其中,各第一密钥的第一保序系数各不相同,各第二密钥的第二保序系数各不相同,且相同排序位置的第一子加密数据的第一密钥的第一保序系数和第二子加密数据的第二密钥的第二保序系数相同;数据提供节点根据私钥对第一加密数据和第二加密数据进行签名以生成待验证签名,并将待验证签名上传至区块链网络对应的区块链以供区块链网络中的数据验证节点对第一加密数据和第二加密数据进行验证。
第二方面,本申请提供了一种数据处理装置,该装置应用于区块链网络中的数据提供节点,包括:
第一确定模块,用于数据提供节点确定第一加密数据中各第一子加密数据的第一密钥以及第二加密数据中各第二子加密数据的第二密钥,其中,第一加密数据由至少一个第一子加密数据按照第一排序组成,一个第一子加密数据对应一个第一密钥,第二加密数据由至少一个第二子加密数据按照第二排序组成,一个第二子加密数据对应一个第二密钥;
第二确定模块,用于数据提供节点根据各第一密钥、各第一密钥的第一保序系数、各第二密钥以及各第二密钥的第二保序系数确定私钥,其中,各第一密钥的第一保序系数各不相同,各第二密钥的第二保序系数各不相同,且相同排序位置的第一子加密数据的第一密钥的第一保序系数和第二子加密数据的第二密钥的第二保序系数相同;
签名上传模块,用于数据提供节点根据私钥对第一加密数据和第二加密数据进行签名以生成待验证签名,并将待验证签名上传至区块链网络对应的区块链以供区块链网络中的数据验证节点对第一加密数据和第二加密数据进行验证。
第三方面,本申请提供了一种数据处理方法,该方法应用于区块链网络中的数据验证节点,包括:
数据验证节点从区块链网络对应的区块链中获取第一加密数据、第二加密数据以及待验证签名,其中,第一加密数据由至少一个第一子加密数据按照第一排序组成,一个第一子加密数据对应一个第一密钥,第二加密数据由至少一个第二子加密数据按照第二排序组成,一个第二子加密数据对应一个第二密钥,待验证签名由区块链网络中的数据提供节点上传至区块链;
数据验证节点确定验证参数,并根据各第一密钥、各第一密钥的第一保序系数、各第二密钥、各第二密钥的第二保序系数以及验证参数确定公钥,其中,各第一密钥的第一保序系数各不相同,各第二密钥的第二保序系数各不相同,且相同排序位置的第一子加密数据的第一密钥的第一保序系数和第二子加密数据的第二密钥的第二保序系数相同;
数据验证节点根据公钥对待验证签名进行验签;
若待验证签名验签通过,数据验证节点确定第一加密数据和第二加密数据相同。
第四方面,本申请提供了一种数据处理装置,该装置应用于区块链网络中的数据验证节点,包括:
获取模块,用于数据验证节点从区块链网络对应的区块链中获取第一加密数据、第二加密数据以及待验证签名,其中,第一加密数据由至少一个第一子加密数据按照第一排序组成,一个第一子加密数据对应一个第一密钥,第二加密数据由至少一个第二子加密数据按照第二排序组成,一个第二子加密数据对应一个第二密钥,待验证签名由区块链网络中的数据提供节点上传至区块链;
第一确定模块,用于数据验证节点确定验证参数,并根据各第一密钥、各第一密钥的第一保序系数、各第二密钥、各第二密钥的第二保序系数以及验证参数确定公钥,其中,各第一密钥的第一保序系数各不相同,各第二密钥的第二保序系数各不相同,且相同排序位置的第一子加密数据的第一密钥的第一保序系数和第二子加密数据的第二密钥的第二保序系数相同;
验签模块,用于数据验证节点根据公钥对待验证签名进行验签;
第二确定模块,用于若待验证签名验签通过,数据验证节点确定第一加密数据和第二加密数据相同。
第五方面,本申请提供了一种节点设备,包括:处理器、存储器、网络接口;该处理器与存储器、网络接口相连,其中,网络接口用于提供数据通信功能,该存储器用于存储计算机程序,该处理器用于调用该计算机程序,执行以下方法:
确定第一加密数据中各第一子加密数据的第一密钥以及第二加密数据中各第二子加密数据的第二密钥,其中,所述第一加密数据由至少一个第一子加密数据按照第一排序组成,一个第一子加密数据对应一个第一密钥,所述第二加密数据由至少一个第二子加密数据按照第二排序组成,一个第二子加密数据对应一个第二密钥;
根据各第一密钥、所述各第一密钥的第一保序系数、各第二密钥以及所述各第二密钥的第二保序系数确定私钥,其中,所述各第一密钥的第一保序系数各不相同,所述各第二密钥的第二保序系数各不相同,且相同排序位置的第一子加密数据的第一密钥的第一保序系数和第二子加密数据的第二密钥的第二保序系数相同;
根据所述私钥对所述第一加密数据和所述第二加密数据进行签名以生成待验证签名,并将所述待验证签名上传至区块链网络对应的区块链以供所述区块链网络中的数据验证节点对第一加密数据和第二加密数据进行验证。
第六方面,本申请提供了一种节点设备,包括:处理器、存储器、网络接口;该处理器与存储器、网络接口相连,其中,网络接口用于提供数据通信功能,该存储器用于存储计算机程序,该处理器用于调用该计算机程序,执行以下方法:
从区块链网络对应的区块链中获取第一加密数据、第二加密数据以及待验证签名,其 中,所述第一加密数据由至少一个第一子加密数据按照第一排序组成,一个第一子加密数据对应一个第一密钥,所述第二加密数据由至少一个第二子加密数据按照第二排序组成,一个第二子加密数据对应一个第二密钥,所述待验证签名由所述区块链网络中的数据提供节点上传至所述区块链;
确定验证参数,并根据各第一密钥、所述各第一密钥的第一保序系数、各第二密钥、所述各第二密钥的第二保序系数以及所述验证参数确定公钥,其中,所述各第一密钥的第一保序系数各不相同,所述各第二密钥的第二保序系数各不相同,且相同排序位置的第一子加密数据的第一密钥的第一保序系数和第二子加密数据的第二密钥的第二保序系数相同;
根据所述公钥对所述待验证签名进行验签;
若所述待验证签名验签通过,确定所述第一加密数据和所述第二加密数据相同。
第七方面,本申请提供了一种计算机可读存储介质,该计算机可读存储介质存储有计算机程序,该计算机程序包括程序指令,该程序指令当被处理器执行时,执行以下方法:
确定第一加密数据中各第一子加密数据的第一密钥以及第二加密数据中各第二子加密数据的第二密钥,其中,所述第一加密数据由至少一个第一子加密数据按照第一排序组成,一个第一子加密数据对应一个第一密钥,所述第二加密数据由至少一个第二子加密数据按照第二排序组成,一个第二子加密数据对应一个第二密钥;
根据各第一密钥、所述各第一密钥的第一保序系数、各第二密钥以及所述各第二密钥的第二保序系数确定私钥,其中,所述各第一密钥的第一保序系数各不相同,所述各第二密钥的第二保序系数各不相同,且相同排序位置的第一子加密数据的第一密钥的第一保序系数和第二子加密数据的第二密钥的第二保序系数相同;
根据所述私钥对所述第一加密数据和所述第二加密数据进行签名以生成待验证签名,并将所述待验证签名上传至区块链网络对应的区块链以供所述区块链网络中的数据验证节点对第一加密数据和第二加密数据进行验证。
第八方面,本申请提供了一种计算机可读存储介质,该计算机可读存储介质存储有计算机程序,该计算机程序包括程序指令,该程序指令当被处理器执行时,执行以下方法:
从区块链网络对应的区块链中获取第一加密数据、第二加密数据以及待验证签名,其中,所述第一加密数据由至少一个第一子加密数据按照第一排序组成,一个第一子加密数据对应一个第一密钥,所述第二加密数据由至少一个第二子加密数据按照第二排序组成,一个第二子加密数据对应一个第二密钥,所述待验证签名由所述区块链网络中的数据提供节点上传至所述区块链;
确定验证参数,并根据各第一密钥、所述各第一密钥的第一保序系数、各第二密钥、所述各第二密钥的第二保序系数以及所述验证参数确定公钥,其中,所述各第一密钥的第一保序系数各不相同,所述各第二密钥的第二保序系数各不相同,且相同排序位置的第一子加密数据的第一密钥的第一保序系数和第二子加密数据的第二密钥的第二保序系数相同;
根据所述公钥对所述待验证签名进行验签;
若所述待验证签名验签通过,确定所述第一加密数据和所述第二加密数据相同。
本申请提高了数字签名(如待验证签名)的安全性。
图1是本申请提供的网络架构的结构示意图;
图2是本申请提供的数据处理方法的交互场景示意图;
图3是本申请提供的数据处理方法的一流程示意图;
图4是本申请提供的数据处理方法的另一流程示意图;
图5是本申请提供的数据处理装置的一结构示意图;
图6是本申请提供的节点设备的一结构示意图;
图7是本申请提供的数据处理装置的另一结构示意图;
图8是本申请提供的节点设备的另一结构示意图;
图9是本申请提供的数据处理系统的结构示意图。
下面将结合本申请中的附图,对本申请中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本申请保护的范围。
本申请的技术方案可涉及区块链技术领域。可选的,本申请可应用于金融科技如对交易信息进行验证等场景中,又如可应用于数字医疗如对电子信息档案进行验证等场景中,以提升数字签名的安全性。
请参见图1,图1是本申请提供的网络架构的结构示意图。如图1所示,该网络架构可以包括用于运行区块链网络的区块链节点系统以及用户终端集群。其中,该区块链网络对应的区块链可以是与业务合约相关联的区块链。该区块链节点系统可以是指用于进行节点与节点之间数据共享的系统。该区块链节点系统可以包括多个节点。如图1所示,该区块链节点系统具体可以包括节点100a、节点100b、节点100c、…、节点100n。该用户终端集群可以包括多个用户终端,如图1所示,具体可以包括用户终端3000a、用户终端3000b、用户终端3000c、…、用户终端3000n。
其中,在该区块链节点系统中,每个节点在正常工作时,均可以获取与该节点相关联的用户终端的数据,以维护该区块链节点系统内的共享数据。为了保证该区块链节点系统内的信息互通,该区块链节点系统中的各个节点之间可以建立网络连接,并通过该网络连接进行数据传输。例如,当该区块链节点系统中的任一节点在获取目标验证数据时,区块链节点系统中的其它节点便可以根据共识算法获取该目标验证数据,并将该目标验证数据作为共享数据中的数据进行存储,使得该区块链节点系统中所有节点上存储的数据均一致。这里的目标验证数据可以包括第一加密数据、第二加密数据以及验证结果,其中,验证结果可以为第一加密数据和第二加密数据相同。
应当理解,区块链节点系统中的每个节点均可以与用户终端集群中的每个用户终端进行数据交互。可以理解的是,本申请可以在图1所示的区块链节点系统中选择一个节点作为该区块链网络中的数据提供节点,并在除该节点之外的其它节点中选择一个节点作为该区块链网络中的数据验证节点。其中,本申请可以将区块链网络中用于生成待验证签名的节点统称为数据提供节点,本申请还可以将区块链网络中用于对待验证签名进行验签的节点统称为数据验证节点。待验证签名可以为对第一加密数据和第二加密数据进行签名后所得到的信息,这里的第一加密数据和第二加密数据可以为区块链上所存储的交易双方针对同一交易所上传的加密数据(如由多个子加密数据组合所生成的加密数据)或者文本对应的加密数据。例如,本申请可以将区块链节点系统中的节点100a作为数据提供节点,本申请还可以将区块链节点系统中的节点100b作为数据验证节点。上述数据提供节点和数据验证节点均可以与用户终端集群中的每个用户终端进行数据交互,例如,数据验证节点在对待验证签名验签通过时,可以向目标用户终端(比如,将上述第一加密数据上传至区块链的用户终端和/或将上述第二加密数据上传至区块链的用户终端)输出第一加密数据和第二加密数据相同的验证结果。
可以理解的是,本申请中的节点设备可以为具有数据处理功能的实体终端,该实体终端可以为如图1所示的节点100a或者节点100b,也可以为用户终端,在此不做限定。
本申请的应用场景可以为商业业务场景(如需要比较两笔加密金额是否相等的场景),比如,在银行借贷场景中,用户可以在银行进行贷款,银行放贷后可以在区块链上验证银 行放贷金额和用户贷款金额是否一致,即需要验证银行放贷加密金额和用户贷款加密金额是否相同。本申请的应用场景也可以为数字医疗场景,比如,对电子信息档案进行零知识验证,这里的电子信息档案可以包含但不限于患者的病历,医生针对患者的诊断数据以及所开的药物等等。本申请中的应用场景还可以为其它应用场景,在此不作具体限定。
进一步地,为便于理解,请参见图2,图2是本申请提供的数据处理方法的交互场景示意图。本申请中会涉及上述数据提供节点和数据验证节点,比如,数据提供节点可以为上述图1中的节点100a,数据验证节点可以为上述图1中的节点100b。如图2所示,区块链1可以为上述图1中区块链网络所对应的区块链,且区块链1可以为数据提供节点(如节点100a)和数据验证节点(如节点100b)所对应的区块链网络中每个节点均共享的一条相同的区块链,每个节点均可以在区块链1中获取区块链上所存储的信息。其中,区块链1中可以包括区块10a、区块10b、区块10c、…、区块10n,该区块10a可以称之为区块链1的创世区块。可以理解,该区块链1可以为存储有上述第一加密数据和第二加密数据的区块链。
如图2所示,节点100a可以从上述区块链1中获取第一加密数据和第二加密数据。可以理解,节点100a可以在区块链1中的各个区块(如区块10a、区块10b、区块10c、…、区块10n)中查找包含第一加密数据的区块(如区块10a)和包含第二加密数据的区块(如区块10a),并从区块10a中分别获取第一加密数据和第二加密数据。需要说明的是,区块链上包含第一加密数据的区块和包含第二加密数据的区块可以为同一区块,也可以为不同区块,具体可根据实际应用场景确定,在此不作限定。其中,第一加密数据由至少一个第一子加密数据按照第一排序组成,一个第一子加密数据对应一个第一密钥,第二加密数据由至少一个第二子加密数据按照第二排序组成,一个第二子加密数据对应一个第二密钥。本申请可以将第一加密数据中的子加密数据统称为第一子加密数据,本申请还可以将第二加密数据中的子加密数据统称为第二子加密数据。这里的第一排序可以为至少一个第一子加密数据组合成为第一加密数据的排列顺序,第二排序可以为至少一个第二子加密数据组合成为第二加密数据的排列顺序。本申请可以将所有第一子加密数据对应的密钥统称为第一密钥,本申请还可以将所有第二子加密数据对应的密钥统称为第二密钥。进一步地,节点100a可以确定第一加密数据中各第一子加密数据的第一密钥以及第二加密数据中各第二子加密数据的第二密钥。此时,节点100a可以根据各第一子加密数据的第一密钥、各第一密钥的第一保序系数、各第二子加密数据的第二密钥以及各第二密钥的第二保序系数确定私钥,并根据私钥对第一加密数据和第二加密数据进行签名,生成待验证签名。本申请可以将各第一密钥的系数统称为第一保序系数,本申请还可以将各第二密钥的系数统称为第二保序系数。
进一步地,节点100a可以将待验证签名上传至区块链1,这时的区块链1上存储有待验证签名。这里的待验证签名后续可以用于数据验证节点(如节点100b)对第一加密数据和第二加密数据进行验证。
如图2所示,节点100b可以从区块链1上获取第一加密数据、第二加密数据和待验证签名。可以理解,节点100b可以在区块链1中的各个区块中查找包含第一加密数据的区块(如上述区块10a)、包含第二加密数据的区块(如上述区块10a)以及包含待验证签名的签名区块,并从区块10a和上述签名区块中分别获取第一加密数据、第二加密数据以及待验证签名。本申请可以将区块链中存储有待验证签名的区块称之为签名区块。这时,节点100b可以根据上述各第一密钥、各第一密钥的第一保序系数、各第二密钥、各第二密钥的第二保序系数以及验证参数(这里的验证参数可以为一个预置的参数)确定公钥,这时,节点100b可以根据公钥对待验证签名进行验签,若待验证签名验签通过,节点100b确定第一加密数据和第二加密数据相同。
由此可见,在本申请中,数据提供节点可以通过各第一密钥、各第一密钥的第一保序系数、各第二密钥以及各第二密钥的第二保序系数确定私钥,生成第一加密数据和第二加密数据的待验证签名,从而提高了数字签名(如待验证签名)的安全性。这里的待验证签名后续可以应用于数据验证节点验证第一加密数据和第二加密数据是否相同。此时,数据验证节点可以从区块链上获取第一加密数据、第二加密数据以及待验证签名,并根据上述各第一密钥、各第一密钥的第一保序系数、各第二密钥、各第二密钥的第二保序系数以及验证参数确定公钥,这里的公钥后续可以用于对待验证签名进行验签,进一步根据验签结果确定第一加密数据和第二加密数据是否相同。进一步地,数据验证节点可以通过公钥对待验证签名进行验签,若待验证签名验签通过,则确定第一加密数据和第二加密数据相同,可以验证加密数据的一致性,提高了验证效率且验证准确率高。
其中,节点设备对第一加密数据和第二加密数据进行数据处理的具体实现方式可以参见下述图3-图4所对应的实施例。
进一步地,请参见图3,图3是本申请提供的数据处理方法的一流程示意图。本申请可以以节点设备为数据提供节点(如上述图2中的节点100a)为例,如图3所示的方法应用于区块链网络中的数据提供节点,可以包括以下步骤S101-步骤S103:
步骤S101,数据提供节点确定第一加密数据中各第一子加密数据的第一密钥以及第二加密数据中各第二子加密数据的第二密钥。
其中,第一加密数据由至少一个第一子加密数据按照第一排序组成,一个第一子加密数据对应一个第一密钥,第二加密数据由至少一个第二子加密数据按照第二排序组成,一个第二子加密数据对应一个第二密钥。可以理解,各第一密钥均可以是根据第一根密钥所确定的密钥,各第二密钥均可以是根据第二根密钥所确定的密钥,这里的第一根密钥和第二根密钥均可以为预置或者预存储的根密钥。可选的,各第一密钥之间可以是相互独立的,各第二密钥之间也可以是相互独立的,具体可根据实际应用场景确定,在此不作限定。
可以理解,数据提供节点上存储有第一加密数据和第二加密数据时,无需从区块链上获取第一加密数据和第二加密数据。可选的,数据提供节点(如上述节点100a)还可以从区块链上获取第一加密数据和第二加密数据,具体地,数据提供节点可以从区块链的所有区块中查找包含第一加密数据的区块(如上述区块10a)以及包含上述第二加密数据的区块(如区块10a),并从包含第一加密数据的区块中获取第一加密数据,以及从包含上述第二加密数据的区块中获取第二加密数据,具体可根据实际应用场景确定,在此不作限定。例如,若第一加密数据对应的哈希值为哈希值1,则节点100a可以获取上述哈希值1,并确定哈希值1所属的认证路径下的根哈希值1,此时,节点100a可以从根哈希值1所属的区块(如上述区块10a)中获取第一加密数据;若第二加密数据对应的哈希值为哈希值2,则节点100a可以获取上述哈希值2,并确定哈希值2所属的认证路径下的根哈希值2,此时,节点100a可以从根哈希值2所属的区块(如上述区块10a)中获取第二加密数据。哈希值(如哈希值1或者哈希值2)所属的认证路径可以指通过哈希值查询其对应的根哈希值(如根哈希值1或者根哈希值2)的路径。可以理解,由于区块链(如上述区块链1)中的每个区块都具有唯一确定的根哈希值,因此数据提供节点可以根据根哈希值(如根哈希值1或者根哈希值2)确定包含加密数据(第一加密数据或者第二加密数据)的区块。需要说明的是,区块链上包含第一加密数据的区块和包含第二加密数据的区块可以为同一区块,也可以为不同区块,具体可根据实际应用场景确定,在此不作限定。
可以理解,第一加密数据(如C
a)可以由至少一个第一子加密数据(如n个第一子加密数据,即C
a0、C
a1、…、C
an-1)按照第一排序组成,即C
a=C
a0||C
a1||…||C
an-1,其中,n 可以为大于或者等于0的整数。这里的第一子加密数据可以为通过椭圆曲线加密算法(elliptic curve cryptography,ECC)对第一子加密数据对应的明文数据(如M
a=M
a0||M
a1||…||M
an-1)中的子明文数据(如M
a0、M
a1、…、M
an-1)进行加密后所得到的子加密数据。其中,椭圆曲线加密算法中可以包括P224曲线、P256曲线(P256曲线也可以称为secp256r1曲线)、P384曲线及P512曲线。上述第一加密数据的数据格式可以为密码学中的perdesen承诺(perdesen commitment)格式,即各第一子加密数据的数据格式可以为perdesen commitment格式,各第一密钥可以称为perdesen commitment格式下的各第一子加密数据中的盲因子。
以椭圆曲线加密算法为P256曲线(如椭圆曲线)为例,任一第一子加密数据的公式可以如下述公式(1)-公式(2)所示:
第(i+1)个第一子加密数据,i可以为大于或者等于0,且小于或者等于n-1的整数。
其中,
用于指示解压缩后的M
ai(即第一子加密数据对应的明文数据中的第(i+1)个子明文数据)在椭圆曲线上所表示的一个点,k
ai可以为第(i+1)个第一子加密数据的第一密钥(即盲因子),H可以为验证参数,且H用于表示上述椭圆曲线上除
之外的另一个点。
可以理解,第二加密数据(如C
b)由至少一个第二子加密数据(如n个第二子加密数据,即C
b0、C
b1、…、C
bn-1)按照第二排序组成,例如C
b=C
b0||C
b1||…||C
bn-1,这里的第二排序可以为至少一个第二子加密数据组合成为第二加密数据的排列顺序。需要说明的是,第一排序与第二排序相同。这里的第二子加密数据可以为通过椭圆曲线加密算法对第二子加密数据对应的明文数据(如M
b=M
b0||M
b1||…||M
bn-1)中的子明文数据(如M
b0、M
b1、…、M
bn-1)进行加密后所得到的子加密数据。上述第二加密数据的数据格式可以为密码学中的perdesen commitment格式,即各第二子加密数据的数据格式可以为perdesen commitment格式,各第二密钥可以称为perdesen commitment格式下的各第二子加密数据中的盲因子。
以椭圆曲线加密算法为P256曲线(如椭圆曲线)为例,任一第二子加密数据的公式可以如下述公式(3)-公式(4)所示:
进一步地,数据提供节点在获取到第一加密数据和第二加密数据之后,可以确定第一加密数据中各第一子加密数据的第一密钥以及第二加密数据中各第二子加密数据的第二密钥。例如,第一加密数据C
a中各第一子加密数据(即C
a0、C
a1、…、C
an-1)的第一密钥可以为k
a0、k
a1、…、k
an-1,其中,k
a0可以为第1个第一子加密数据C
a0的第一密钥,k
a1可以为第2个第一子加密数据C
a1的第一密钥,…,k
an-1可以为第n个第一子加密数据C
an-1的第一密钥。又例如,第二加密数据C
b中各第二子加密数据(即C
b0、C
b1、…、C
bn-1)的第二密钥可以为k
b0、k
b1、…、k
bn-1,其中,k
b0可以为第1个第二子加密数据C
b0的第二密钥,k
b1可以为第2个第二子加密数据C
b1的第二密钥,…,k
bn-1可以为第n个第二子加密数据C
bn-1的第二密钥。
步骤S102,数据提供节点根据各第一密钥、各第一密钥的第一保序系数、各第二密钥以及各第二密钥的第二保序系数确定私钥。
其中,各第一密钥的第一保序系数各不相同,各第二密钥的第二保序系数各不相同,且相同排序位置的第一子加密数据的第一密钥的第一保序系数和第二子加密数据的第二密钥的第二保序系数相同。例如,上述C
a0的第一密钥k
a0的第一保序系数可以为1,上述C
a1的第一密钥k
a1的第一保序系数可以为2,…,上述C
an-1的第一密钥k
an-1的第一保序系数可以为n,上述C
b0的第二密钥k
b0的第二保序系数可以与上述k
a0的第一保序系数相同,即第二密钥k
b0的第二保序系数可以为1,上述C
b1的第二密钥k
b1的第二保序系数可以与上述k
a1的第一保序系数相同,即第二密钥k
b1的第二保序系数可以为2,…,上述C
bn-1的第二密钥k
bn-1的第二保序系数可以与上述k
an-1的第一保序系数相同,即第二密钥k
bn-1的第二保序系数可以为n。
在一些可行的实施方式中,数据提供节点可以确定各第一密钥的第一保序系数,并根据各第一密钥和各第一密钥的第一保序系数确定所有第一密钥的第一累计密钥。这时,数 据提供节点可以确定各第二密钥的第二保序系数,并根据各第二密钥和各第二密钥的第二保序系数确定所有第二密钥的第二累计密钥。数据提供节点可以根据第一累计密钥和第二累计密钥确定私钥。
为方便描述,下面将以第一加密数据C
a和第二加密数据C
b为例对确定私钥的具体过程进行说明,上述私钥可以根据下述公式(5)-公式(6)确定,公式(5)如下所示:
P=1*(C
a0-C
b0)+2*(C
a1-C
b1)+…+n*(C
an-1-C
bn-1), (5)
其中,P可以为公钥,C
a0可以为第1个第一子加密数据,C
a1可以为第2个第一子加密数据,…,C
an-1可以为第n个第一子加密数据,C
b0可以为第1个第二子加密数据,C
b1可以为第2个第二子加密数据,…,C
bn-1可以为第n个第二子加密数据,1、2、…、n可以是上述各第一密钥的第一保序系数,同时也是上述各第二密钥的第二保序系数,即相同排序位置的第一子加密数据的第一密钥的第一保序系数和第二子加密数据的第二密钥的第二保序系数相同。
可以理解,根据上述公式(1)-公式(4)对公式(5)进行化简,需要说明的是,在化简的过程中,由于第一子加密数据和第二子加密数据是根据同一椭圆曲线加密算法(如上述P256曲线)进行加密后所生成的子加密数据,因此
与
相同,同时在
与
相同的情况下才可以得到私钥,从而可以得到化简后的公式(即公式(6)),公式(6)如下所示:
其中,P可以为上述公钥,
可以为私钥,H可以为验证参数。为方便描述,通过上述公式(6)对第一累计密钥和第二累计密钥进行解释说明,
可以为第一累计密钥,
可以为第二累计密钥,其中,i+1是k
ai的第一保序系数,同时i+1也是k
bi的第二保序系数。
步骤S103,数据提供节点根据私钥对第一加密数据和第二加密数据进行签名以生成待验证签名,并将待验证签名上传至区块链网络对应的区块链以供区块链网络中的数据验证节点对第一加密数据和第二加密数据进行验证。
在一些可行的实施方式中,数据提供节点根据第一加密数据和第二加密数据生成联合加密数据,并确定联合加密数据的第一联合哈希值。进一步地,数据提供节点根据私钥对联合加密数据的第一联合哈希值进行签名,生成第一加密数据和第二加密数据的待验证签名。本申请可以将对第一加密数据和第二加密数据进行联合处理后的加密数据称之为联合加密数据,本申请还可以将联合加密数据的哈希值称之为第一联合哈希值。
可以理解,数据提供节点可以对第一加密数据和第二加密数据进行联合处理,得到联合加密数据。为方便描述,下面将以第一加密数据为C
a,第二加密数据为C
b为例进行说明,数据提供节点可以对C
a=C
a0||C
a1||…||C
an-1和C
b=C
b0||C
b1||…||C
bn-1进行联合处理,这里所得 到的联合加密数据可以为C
ab=C
a0||C
a1||…||C
an-1||C
b0||C
b1||…||C
bn-1,联合加密数据也可以为C
ab=C
a0||C
b0||C
a1||C
b1||…||C
an-1||C
bn-1,联合加密数据也可以为根据其它联合处理方式得到的联合加密数据,具体可以根据实际应用场景确定,在此不做限定。这时,数据提供节点可以通过哈希算法对联合加密数据进行哈希运算,得到联合加密数据的第一联合哈希值。其中,哈希算法可以为安全散列算法(secure hash algorithm,SHA)。安全散列算法是一个密码散列函数家族,是联邦信息处理标准(federal information processing standards,FIPS)所认证的安全散列算法。其中,安全散列算法可以计算出一个数字消息所对应的长度固定的字符串(又称消息摘要,比如,第一联合哈希值)的算法。其中,SHA可以包括SHA-1、SHA-224、SHA-256、SHA-384以及SHA-512。进一步地,数据提供节点可以通过数字签名算法对第一联合哈希值进行签名,得到待验证签名。其中,该数字签名算法可以包括但不限于:RSA(一种签名算法)、DSA(一种签名算法)、ECDSA(一种签名算法),等等。进一步地,数据提供节点在生成待验证签名之后,可以将待验证签名上传至区块链网络对应的区块链(如上述区块链1)。可以理解,数据提供节点可以根据待验证签名生成签名区块,并将该签名区块上传至区块链,此时,区块链的签名区块中存储有待验证签名。这里的待验证签名后续用于区块链网络中的数据验证节点对第一加密数据和第二加密数据进行验证(如验证第一加密数据和第二加密数据是否相同)。
在本申请中,数据提供节点可以通过各第一密钥、各第一密钥的第一保序系数、各第二密钥以及各第二密钥的第二保序系数确定私钥,并根据该私钥对第一加密数据和第二加密数据进行签名以生成待验证签名,私钥的复杂度较高,从而提高了数字签名(如待验证签名)的安全性。
进一步地,请参见图4,图4是本申请提供的数据处理方法的另一流程示意图。本申请可以以节点设备为数据验证节点(如上述图2中的节点100b)为例,如图4所示的方法应用于区块链网络中的数据验证节点,可以包括以下步骤S201-步骤S204:
步骤S201,数据验证节点从区块链网络对应的区块链中获取第一加密数据、第二加密数据以及待验证签名。
可以理解,数据验证节点(如上述节点100b)可以从区块链的所有区块中分别查找包含第一加密数据的区块(如上述区块10a)、包含第二加密数据的区块(如上述区块10a)以及包含待验证签名的签名区块,并从包含第一加密数据的区块中获取第一加密数据,从包含第二加密数据的区块中获取第二加密数据,以及从包含待验证签名的签名区块中获取待验证签名。例如,节点100b可以获取第一加密数据对应的哈希值1,并确定哈希值1所属的认证路径下的根哈希值1,此时,节点100b可以从根哈希值1所属的区块10a中获取第一加密数据;节点100b可以获取第二加密数据对应的哈希值2,并确定哈希值2所属的认证路径下的根哈希值2,此时,节点100b可以从根哈希值2所属的区块10a中获取第二加密数据;节点100b可以获取上述第一联合哈希值,并确定第一联合哈希值所属的认证路径下的根哈希值3,此时,节点100b可以从根哈希值3所属的签名区块中获取待验证签名。
步骤S202,数据验证节点确定验证参数,并根据各第一密钥、各第一密钥的第一保序系数、各第二密钥、各第二密钥的第二保序系数以及验证参数确定公钥。
在一些可行的实施方式中,数据验证节点确定验证参数。在确定验证参数之后,数据验证节点可以确定各第一密钥的第一保序系数,并根据各第一密钥以及各第一密钥的第一保序系数确定所有第一密钥的第一累计密钥。此时,数据验证节点确定各第二密钥的第二保序系数,并根据各第二密钥以及各第二密钥的第二保序系数确定所有第二密钥的第二累计密钥。进一步地,数据验证节点根据第一累计密钥、第二累计密钥以及验证参数确定公 钥。
步骤S203,数据验证节点根据公钥对待验证签名进行验签。
在一些可行的实施方式中,数据验证节点根据第一加密数据和第二加密数据生成联合加密数据,并确定联合加密数据的第一联合哈希值。数据验证节点根据公钥对待验证签名进行验签,得到第二联合哈希值。若第二联合哈希值和第一联合哈希值相同,数据验证节点确定待验证签名验签通过。若第二联合哈希值和第一联合哈希值不同,数据验证节点确定待验证签名验签未通过。本申请可以将数据验证节点对待验证签名进行验签后所得到的哈希值称之为第二联合哈希值。
步骤S204,若待验证签名验签通过,数据验证节点确定第一加密数据和第二加密数据相同。
可以理解,数据验证节点在确定第一加密数据和第二加密数据相同之后,进而可以确定第一加密数据对应的明文数据和第二加密数据对应的明文数据相同,此时可以验证加密数据的一致性(即验证两个加密数据是否相同,如第一加密数据和第二加密数据是否相同),验证准确率高。
在一些可行的实施方式中,若待验证签名验签通过,数据验证节点根据第一加密数据、第二加密数据以及验证结果生成目标区块,并将目标区块添加至区块链,其中,验证结果为第一加密数据和第二加密数据相同。具体地,若验签通过,则数据验证节点可以将第一加密数据、第二加密数据以及验证结果打包成待验证区块,并将该待验证区块发送给区块链网络中的共识节点进行共识。其中,该待验证区块可以是没有通过区块链网络中的共识节点进行共识的区块。进一步地,数据验证节点可以获取该区块链网络中的共识节点所返回的共识确认信息。应当理解,数据验证节点将该待验证区块发送给区块链网络中的共识节点进行共识之后,若共识节点对该待验证区块验证通过,则该共识节点可以向数据验证节点返回共识确认信息,此时,数据验证节点可以获取到区块链网络中的共识节点所返回的共识确认信息。其中,一个共识节点可以对应一个共识确认信息。进一步地,若数据验证节点统计到的共识确认信息的总数量大于该共识节点的共识阈值,则确定完成共识,且将验证通过的待验证区块确定为目标区块,并将目标区块添加至该区块链网络对应的区块链(如上述区块链1)。比如,若共识节点的数量为A,数据验证节点统计到该共识确认信息的总数量为B,该共识节点的共识阈值为0.8A,此时,若是该共识确认信息的总数量B大于0.8A,则确认完成共识。
在一些可行的实施方式中,若待验证签名验签未通过,数据验证节点确定第一加密数据和第二加密数据不同,并输出验证失败信息。其中,验证失败信息用于指示第一加密数据与第二加密数据不同。可以理解,数据验证节点可以向数据提供节点输出验证失败信息。可选的,数据验证节点也可以向用户终端输出验证失败信息,以使用户根据验证失败信息对第一加密数据和第二加密数据进行后续处理。例如,若第一加密数据和第二加密数据为银行借贷双方(用户a和银行工作人员b)针对同一借贷交易的两个加密借贷金额(如加密借贷金额a何加密借贷金额b),在数据验证节点验证加密借贷金额a和加密借贷金额b不同时,需要向用户a所在的用户终端(如上述用户终端3000a)和银行工作人员b所在的用户终端(如上述用户终端3000b)分别输出验证失败信息,以使用户a和银行工作人员b针对该借贷交易进行后续处理。
在本申请中,数据验证节点可以从区块链上获取第一加密数据、第二加密数据以及待 验证签名,并根据上述各第一密钥、各第一密钥的第一保序系数、各第二密钥、各第二密钥的第二保序系数以及验证参数确定公钥,这里的公钥后续可以用于对待验证签名进行验签,进一步根据验签结果确定第一加密数据和第二加密数据是否相同。进一步地,数据验证节点可以通过公钥对待验证签名进行验签,若待验证签名验签通过,则确定第一加密数据和第二加密数据相同,可以验证加密数据的一致性,提高了验证效率且验证准确率高。
进一步地,请参见图5,图5是本申请提供的数据处理装置的一结构示意图。该数据处理装置可以是运行于节点设备中的一个计算机程序(包括程序代码),例如,该数据处理装置为一个应用软件;该数据处理装置可以用于执行本申请提供的方法中的相应步骤。如图5所示,该数据处理装置1可以应用于区块链网络中的数据提供节点,该数据提供节点可以为上述图2所对应实施例中的节点100a。该数据处理装置1可以包括:第一确定模块10、第二确定模块11、以及签名上传模块12。
第一确定模块10,用于数据提供节点确定第一加密数据中各第一子加密数据的第一密钥以及第二加密数据中各第二子加密数据的第二密钥,其中,第一加密数据由至少一个第一子加密数据按照第一排序组成,一个第一子加密数据对应一个第一密钥,第二加密数据由至少一个第二子加密数据按照第二排序组成,一个第二子加密数据对应一个第二密钥;
第二确定模块11,用于数据提供节点根据各第一密钥、各第一密钥的第一保序系数、各第二密钥以及各第二密钥的第二保序系数确定私钥,其中,各第一密钥的第一保序系数各不相同,各第二密钥的第二保序系数各不相同,且相同排序位置的第一子加密数据的第一密钥的第一保序系数和第二子加密数据的第二密钥的第二保序系数相同;
签名上传模块12,用于数据提供节点根据私钥对第一加密数据和第二加密数据进行签名以生成待验证签名,并将待验证签名上传至区块链网络对应的区块链以供区块链网络中的数据验证节点对第一加密数据和第二加密数据进行验证。
在一些可行的实施方式中,第二确定模块11包括:第一确定单元111,用于数据提供节点确定各第一密钥的第一保序系数,并根据各第一密钥和各第一密钥的第一保序系数确定所有第一密钥的第一累计密钥;第二确定单元112,用于数据提供节点确定各第二密钥的第二保序系数,并根据各第二密钥和各第二密钥的第二保序系数确定所有第二密钥的第二累计密钥;第三确定单元113,用于数据提供节点根据第一累计密钥和第二累计密钥确定私钥。
在一些可行的实施方式中,签名上传模块12包括:第四确定单元121,用于数据提供节点根据第一加密数据和第二加密数据生成联合加密数据,并确定联合加密数据的第一联合哈希值;签名单元122,用于数据提供节点根据私钥对第一联合哈希值进行签名,得到待验证签名。
其中,该第一确定模块10、第二确定模块11以及签名上传模块12的具体实现方式可以参见上述图3所对应实施例中对步骤S101-步骤S103的描述,这里将不再继续进行赘述。另外,对采用相同方法的有益效果描述,也不再进行赘述。
进一步地,请参见图6,图6是本申请提供的节点设备的一结构示意图。该节点设备可包括处理器、存储器以及网络接口。可选的,该节点设备还可包括用户接口。例如,如图6所示,该节点设备1000可以为上述图2对应实施例中的节点100a,该节点设备1000可以包括:至少一个处理器1001,例如CPU,至少一个网络接口1004,用户接口1003,存储器1005,至少一个通信总线1002。其中,通信总线1002用于实现这些组件之间的连接通信。其中,用户接口1003可以包括显示屏(Display)、键盘(Keyboard),网络接口1004可选地可以包括标准的有线接口、无线接口(如WI-FI接口)。存储器1005可以是高速RAM存储器,也可以是非不稳定的存储器(non-volatile memory),例如至少一个磁盘存储器。存储器1005可选地还可以是至少一个位于远离前述处理器1001的存储装置。如图 6所示,作为一种计算机存储介质的存储器1005中可以包括操作系统、网络通信模块、用户接口模块以及设备控制应用程序。
在图6所示的节点设备1000中,网络接口1004主要用于与区块链网络中的其它节点(如数据验证节点)以及用户终端进行网络通信;而用户接口1003主要用于为用户提供输入的接口;而处理器1001可以用于调用存储器1005中存储的设备控制应用程序,以实现:
数据提供节点确定第一加密数据中各第一子加密数据的第一密钥以及第二加密数据中各第二子加密数据的第二密钥,其中,第一加密数据由至少一个第一子加密数据按照第一排序组成,一个第一子加密数据对应一个第一密钥,第二加密数据由至少一个第二子加密数据按照第二排序组成,一个第二子加密数据对应一个第二密钥;
数据提供节点根据各第一密钥、各第一密钥的第一保序系数、各第二密钥以及各第二密钥的第二保序系数确定私钥,其中,各第一密钥的第一保序系数各不相同,各第二密钥的第二保序系数各不相同,且相同排序位置的第一子加密数据的第一密钥的第一保序系数和第二子加密数据的第二密钥的第二保序系数相同;
数据提供节点根据私钥对第一加密数据和第二加密数据进行签名以生成待验证签名,并将待验证签名上传至区块链网络对应的区块链以供区块链网络中的数据验证节点对第一加密数据和第二加密数据进行验证。
应当理解,本申请中所描述的节点设备1000可执行前文图3所对应实施例中对该数据处理方法的描述,也可执行前文图5所对应实施例中对该数据处理装置1的描述,在此不再赘述。另外,对采用相同方法的有益效果描述,也不再进行赘述。
此外,这里需要指出的是:本申请还提供了一种计算机可读存储介质,且该计算机可读存储介质中存储有前文提及的数据处理装置1所执行的计算机程序,且该计算机程序包括程序指令,当该处理器执行该程序指令时,能够执行前文图3所对应实施例中对该数据处理方法的描述,因此,这里将不再进行赘述。另外,对采用相同方法的有益效果描述,也不再进行赘述。对于本申请所涉及的计算机可读存储介质实施例中未披露的技术细节,请参照本申请方法实施例的描述。作为示例,程序指令可被部署为在一个计算设备上执行,或者在位于一个地点的多个计算设备上执行,又或者,在分布在多个地点且通过通信网络互连的多个计算设备上执行,分布在多个地点且通过通信网络互连的多个计算设备可以组成区块链系统。
进一步地,请参见图7,图7是本申请提供的数据处理装置的另一结构示意图。该数据处理装置可以是运行于节点设备中的一个计算机程序(包括程序代码),例如,该数据处理装置为一个应用软件;该数据处理装置可以用于执行本申请提供的方法中的相应步骤。如图7所示,该数据处理装置2可以应用于区块链网络中的数据验证节点,该数据验证节点可以为上述图2所对应实施例中的节点100b。该数据处理装置2可以包括:获取模块20、第一确定模块21、验签模块22、第二确定模块23、输出模块24以及添加模块25。
获取模块20,用于数据验证节点从区块链网络对应的区块链中获取第一加密数据、第二加密数据以及待验证签名,其中,第一加密数据由至少一个第一子加密数据按照第一排序组成,一个第一子加密数据对应一个第一密钥,第二加密数据由至少一个第二子加密数据按照第二排序组成,一个第二子加密数据对应一个第二密钥,待验证签名由区块链网络中的数据提供节点上传至区块链;
第一确定模块21,用于数据验证节点确定验证参数,并根据各第一密钥、各第一密钥的第一保序系数、各第二密钥、各第二密钥的第二保序系数以及验证参数确定公钥,其中,各第一密钥的第一保序系数各不相同,各第二密钥的第二保序系数各不相同,且相同排序位置的第一子加密数据的第一密钥的第一保序系数和第二子加密数据的第二密钥的第二保序系数相同;
验签模块22,用于数据验证节点根据公钥对待验证签名进行验签;
第二确定模块23,用于若待验证签名验签通过,数据验证节点确定第一加密数据和第二加密数据相同。
在一些可行的实施方式中,第一确定模块21包括:第一确定单元211,用于数据验证节点确定各第一密钥的第一保序系数,并根据各第一密钥以及各第一密钥的第一保序系数确定所有第一密钥的第一累计密钥;第二确定单元212,用于数据验证节点确定各第二密钥的第二保序系数,并根据各第二密钥以及各第二密钥的第二保序系数确定所有第二密钥的第二累计密钥;第三确定单元213,用于数据验证节点根据第一累计密钥、第二累计密钥以及验证参数确定公钥。
在一些可行的实施方式中,验签模块22包括:第四确定单元221,用于数据验证节点根据第一加密数据和第二加密数据生成联合加密数据,并确定联合加密数据的第一联合哈希值;验签单元222,用于数据验证节点根据公钥对待验证签名进行验签,得到第二联合哈希值;第五确定单元223,用于若第二联合哈希值和第一联合哈希值相同,数据验证节点确定待验证签名验签通过;第六确定单元224,用于若第二联合哈希值和第一联合哈希值不同,数据验证节点确定待验证签名验签未通过。
在一些可行的实施方式中,上述数据处理装置2还包括:输出模块24,用于若待验证签名验签未通过,数据验证节点确定第一加密数据和第二加密数据不同,并输出验证失败信息。
在一些可行的实施方式中,上述数据处理装置2还包括:添加模块25,用于若待验证签名验签通过,数据验证节点根据第一加密数据、第二加密数据以及验证结果生成目标区块,并将目标区块添加至区块链,其中,验证结果为第一加密数据和第二加密数据相同。
其中,该获取模块20、第一确定模块21、验签模块22、第二确定模块23、输出模块24以及添加模块25的具体实现方式可以参见上述图4所对应实施例中对步骤S201-步骤S204的描述,这里将不再继续进行赘述。另外,对采用相同方法的有益效果描述,也不再进行赘述。
进一步地,请参见图8,图8是本申请提供的节点设备的另一结构示意图。该节点设备可包括处理器、存储器以及网络接口。可选的,该节点设备还可包括用户接口。例如,如图8所示,该节点设备2000可以为上述图2对应实施例中的节点200a,该节点设备2000可以包括:至少一个处理器2001,例如CPU,至少一个网络接口2004,用户接口2003,存储器2005,至少一个通信总线2002。其中,通信总线2002用于实现这些组件之间的连接通信。其中,用户接口2003可以包括显示屏(display)、键盘(keyboard),网络接口2004可选地可以包括标准的有线接口、无线接口(如WI-FI接口)。存储器2005可以是高速RAM存储器,也可以是非不稳定的存储器(non-volatile memory),例如至少一个磁盘存储器。存储器2005可选地还可以是至少一个位于远离前述处理器2001的存储装置。如图8所示,作为一种计算机存储介质的存储器2005中可以包括操作系统、网络通信模块、用户接口模块以及设备控制应用程序。
在图8所示的节点设备2000中,网络接口2004主要用于与区块链网络中的其它节点(如数据提供节点)以及用户终端进行网络通信;而用户接口2003主要用于为用户提供输入的接口;而处理器2001可以用于调用存储器2005中存储的设备控制应用程序,以实现:
数据验证节点从区块链网络对应的区块链中获取第一加密数据、第二加密数据以及待验证签名,其中,第一加密数据由至少一个第一子加密数据按照第一排序组成,一个第一子加密数据对应一个第一密钥,第二加密数据由至少一个第二子加密数据按照第二排序组成,一个第二子加密数据对应一个第二密钥,待验证签名由区块链网络中的数据提供节点上传至区块链;
数据验证节点确定验证参数,并根据各第一密钥、各第一密钥的第一保序系数、各第二密钥、各第二密钥的第二保序系数以及验证参数确定公钥,其中,各第一密钥的第一保序系数各不相同,各第二密钥的第二保序系数各不相同,且相同排序位置的第一子加密数据的第一密钥的第一保序系数和第二子加密数据的第二密钥的第二保序系数相同;
数据验证节点根据公钥对待验证签名进行验签;
若待验证签名验签通过,数据验证节点确定第一加密数据和第二加密数据相同。
应当理解,本申请中所描述的节点设备2000可执行前文图4所对应实施例中对该数据处理方法的描述,也可执行前文图7所对应实施例中对该数据处理装置2的描述,在此不再赘述。另外,对采用相同方法的有益效果描述,也不再进行赘述。
此外,这里需要指出的是:本申请还提供了一种计算机可读存储介质,且该计算机可读存储介质中存储有前文提及的数据处理装置2所执行的计算机程序,且该计算机程序包括程序指令,当该处理器执行该程序指令时,能够执行前文图4所对应实施例中对该数据处理方法的描述,因此,这里将不再进行赘述。另外,对采用相同方法的有益效果描述,也不再进行赘述。对于本申请所涉及的计算机可读存储介质实施例中未披露的技术细节,请参照本申请方法实施例的描述。作为示例,程序指令可被部署为在一个计算设备上执行,或者在位于一个地点的多个计算设备上执行,又或者,在分布在多个地点且通过通信网络互连的多个计算设备上执行,分布在多个地点且通过通信网络互连的多个计算设备可以组成区块链系统。
可选的,本申请涉及的存储介质如计算机可读存储介质可以是非易失性的,也可以是易失性的。
进一步的,请参见图9,图9是本申请提供的数据处理系统的结构示意图。该数据处理系统3可以包含数据处理装置1a和数据处理装置2a。其中,数据处理装置1a可以为上述图5所对应实施例中的数据处理装置1,可以理解的是,该数据处理装置1a可以集成在上述图2所对应实施例中的节点100a,因此,这里将不再进行赘述。其中,数据处理装置2a可以为上述图7所对应实施例中的数据处理装置2,可以理解的是,该数据处理装置2a可以集成在上述图2所对应实施例中的节点100b,因此,这里将不再进行赘述。另外,对采用相同方法的有益效果描述,也不再进行赘述。对于本申请所涉及的数据处理系统实施例中未披露的技术细节,请参照本申请方法实施例的描述。
本领域普通技术人员可以意识到,结合本文中所公开的实施例描述的各示例的单元及算法步骤,能够以电子硬件、计算机软件或者二者的结合来实现,为了清楚地说明硬件和软件的可互换性,在上述说明中已经按照功能一般性地描述了各示例的组成及步骤。专业技术人员可以对每个特定的应用来使用不同方法来实现所描述的功能,但是这种实现不应认为超出本申请的范围。
以上所揭露的仅为本申请较佳实施例而已,当然不能以此来限定本申请之权利范围,因此依本申请权利要求所作的等同变化,仍属本申请所涵盖的范围。
Claims (20)
- 一种数据处理方法,其中,所述方法应用于区块链网络中的数据提供节点,包括:所述数据提供节点确定第一加密数据中各第一子加密数据的第一密钥以及第二加密数据中各第二子加密数据的第二密钥,其中,所述第一加密数据由至少一个第一子加密数据按照第一排序组成,一个第一子加密数据对应一个第一密钥,所述第二加密数据由至少一个第二子加密数据按照第二排序组成,一个第二子加密数据对应一个第二密钥;所述数据提供节点根据各第一密钥、所述各第一密钥的第一保序系数、各第二密钥以及所述各第二密钥的第二保序系数确定私钥,其中,所述各第一密钥的第一保序系数各不相同,所述各第二密钥的第二保序系数各不相同,且相同排序位置的第一子加密数据的第一密钥的第一保序系数和第二子加密数据的第二密钥的第二保序系数相同;所述数据提供节点根据所述私钥对所述第一加密数据和所述第二加密数据进行签名以生成待验证签名,并将所述待验证签名上传至所述区块链网络对应的区块链以供所述区块链网络中的数据验证节点对第一加密数据和第二加密数据进行验证。
- 根据权利要求1所述的方法,其中,所述数据提供节点根据各第一密钥、所述各第一密钥的第一保序系数、各第二密钥以及所述各第二密钥的第二保序系数确定私钥,包括:所述数据提供节点确定各第一密钥的第一保序系数,并根据所述各第一密钥和所述各第一密钥的第一保序系数确定所有第一密钥的第一累计密钥;所述数据提供节点确定各第二密钥的第二保序系数,并根据所述各第二密钥和所述各第二密钥的第二保序系数确定所有第二密钥的第二累计密钥;所述数据提供节点根据所述第一累计密钥和所述第二累计密钥确定私钥。
- 根据权利要求1所述的方法,其中,所述数据提供节点根据所述私钥对所述第一加密数据和所述第二加密数据进行签名以生成待验证签名,包括:所述数据提供节点根据所述第一加密数据和所述第二加密数据生成联合加密数据,并确定所述联合加密数据的第一联合哈希值;所述数据提供节点根据所述私钥对所述第一联合哈希值进行签名,生成所述第一加密数据和所述第二加密数据的待验证签名。
- 一种数据处理方法,其中,所述方法应用于区块链网络中的数据验证节点,包括:所述数据验证节点从所述区块链网络对应的区块链中获取第一加密数据、第二加密数据以及待验证签名,其中,所述第一加密数据由至少一个第一子加密数据按照第一排序组成,一个第一子加密数据对应一个第一密钥,所述第二加密数据由至少一个第二子加密数据按照第二排序组成,一个第二子加密数据对应一个第二密钥,所述待验证签名由所述区块链网络中的数据提供节点上传至所述区块链;所述数据验证节点确定验证参数,并根据各第一密钥、所述各第一密钥的第一保序系数、各第二密钥、所述各第二密钥的第二保序系数以及所述验证参数确定公钥,其中,所述各第一密钥的第一保序系数各不相同,所述各第二密钥的第二保序系数各不相同,且相同排序位置的第一子加密数据的第一密钥的第一保序系数和第二子加密数据的第二密钥的第二保序系数相同;所述数据验证节点根据所述公钥对所述待验证签名进行验签;若所述待验证签名验签通过,所述数据验证节点确定所述第一加密数据和所述第二加密数据相同。
- 根据权利要求4所述的方法,其中,所述数据验证节点根据各第一密钥、所述各第一密钥的第一保序系数、各第二密钥、所述各第二密钥的第二保序系数以及所述验证参数确定公钥,包括:所述数据验证节点确定各第一密钥的第一保序系数,并根据所述各第一密钥以及所述 各第一密钥的第一保序系数确定所有第一密钥的第一累计密钥;所述数据验证节点确定各第二密钥的第二保序系数,并根据所述各第二密钥以及所述各第二密钥的第二保序系数确定所有第二密钥的第二累计密钥;所述数据验证节点根据所述第一累计密钥、所述第二累计密钥以及所述验证参数确定公钥。
- 根据权利要求4所述的方法,其中,所述数据验证节点根据所述公钥对所述待验证签名进行验签,包括:所述数据验证节点根据所述第一加密数据和所述第二加密数据生成联合加密数据,并确定所述联合加密数据的第一联合哈希值;所述数据验证节点根据所述公钥对所述待验证签名进行验签,得到第二联合哈希值:若所述第二联合哈希值和所述第一联合哈希值相同,所述数据验证节点确定所述待验证签名验签通过;若所述第二联合哈希值和所述第一联合哈希值不同,所述数据验证节点确定所述待验证签名验签未通过。
- 根据权利要求4所述的方法,其中,所述方法还包括:若所述待验证签名验签未通过,所述数据验证节点确定所述第一加密数据和所述第二加密数据不同,并输出验证失败信息。
- 根据权利要求4所述的方法,其中,所述方法还包括:若所述待验证签名验签通过,所述数据验证节点根据所述第一加密数据、所述第二加密数据以及验证结果生成目标区块,并将所述目标区块添加至所述区块链,其中,所述验证结果为所述第一加密数据和所述第二加密数据相同。
- 一种节点设备,其中,包括:处理器、存储器以及网络接口;所述处理器与存储器、网络接口相连,其中,网络接口用于提供数据通信功能,所述存储器用于存储程序代码,所述处理器用于调用所述程序代码,以执行以下方法:确定第一加密数据中各第一子加密数据的第一密钥以及第二加密数据中各第二子加密数据的第二密钥,其中,所述第一加密数据由至少一个第一子加密数据按照第一排序组成,一个第一子加密数据对应一个第一密钥,所述第二加密数据由至少一个第二子加密数据按照第二排序组成,一个第二子加密数据对应一个第二密钥;根据各第一密钥、所述各第一密钥的第一保序系数、各第二密钥以及所述各第二密钥的第二保序系数确定私钥,其中,所述各第一密钥的第一保序系数各不相同,所述各第二密钥的第二保序系数各不相同,且相同排序位置的第一子加密数据的第一密钥的第一保序系数和第二子加密数据的第二密钥的第二保序系数相同;根据所述私钥对所述第一加密数据和所述第二加密数据进行签名以生成待验证签名,并将所述待验证签名上传至区块链网络对应的区块链以供所述区块链网络中的数据验证节点对第一加密数据和第二加密数据进行验证。
- 根据权利要求9所述的节点设备,其中,执行所述根据各第一密钥、所述各第一密钥的第一保序系数、各第二密钥以及所述各第二密钥的第二保序系数确定私钥,包括:确定各第一密钥的第一保序系数,并根据所述各第一密钥和所述各第一密钥的第一保序系数确定所有第一密钥的第一累计密钥;确定各第二密钥的第二保序系数,并根据所述各第二密钥和所述各第二密钥的第二保序系数确定所有第二密钥的第二累计密钥;根据所述第一累计密钥和所述第二累计密钥确定私钥。
- 根据权利要求9所述的节点设备,其中,执行所述根据所述私钥对所述第一加密数据和所述第二加密数据进行签名以生成待验证签名,包括:根据所述第一加密数据和所述第二加密数据生成联合加密数据,并确定所述联合加密数据的第一联合哈希值;根据所述私钥对所述第一联合哈希值进行签名,生成所述第一加密数据和所述第二加密数据的待验证签名。
- 一种节点设备,其中,包括:处理器、存储器以及网络接口;所述处理器与存储器、网络接口相连,其中,网络接口用于提供数据通信功能,所述存储器用于存储程序代码,所述处理器用于调用所述程序代码,以执行以下方法:从区块链网络对应的区块链中获取第一加密数据、第二加密数据以及待验证签名,其中,所述第一加密数据由至少一个第一子加密数据按照第一排序组成,一个第一子加密数据对应一个第一密钥,所述第二加密数据由至少一个第二子加密数据按照第二排序组成,一个第二子加密数据对应一个第二密钥,所述待验证签名由所述区块链网络中的数据提供节点上传至所述区块链;确定验证参数,并根据各第一密钥、所述各第一密钥的第一保序系数、各第二密钥、所述各第二密钥的第二保序系数以及所述验证参数确定公钥,其中,所述各第一密钥的第一保序系数各不相同,所述各第二密钥的第二保序系数各不相同,且相同排序位置的第一子加密数据的第一密钥的第一保序系数和第二子加密数据的第二密钥的第二保序系数相同;根据所述公钥对所述待验证签名进行验签;若所述待验证签名验签通过,确定所述第一加密数据和所述第二加密数据相同。
- 根据权利要求12所述的节点设备,其中,执行所述根据各第一密钥、所述各第一密钥的第一保序系数、各第二密钥、所述各第二密钥的第二保序系数以及所述验证参数确定公钥,包括:确定各第一密钥的第一保序系数,并根据所述各第一密钥以及所述各第一密钥的第一保序系数确定所有第一密钥的第一累计密钥;确定各第二密钥的第二保序系数,并根据所述各第二密钥以及所述各第二密钥的第二保序系数确定所有第二密钥的第二累计密钥;根据所述第一累计密钥、所述第二累计密钥以及所述验证参数确定公钥。
- 根据权利要求12所述的节点设备,其中,执行所述根据所述公钥对所述待验证签名进行验签,包括:根据所述第一加密数据和所述第二加密数据生成联合加密数据,并确定所述联合加密数据的第一联合哈希值;根据所述公钥对所述待验证签名进行验签,得到第二联合哈希值:若所述第二联合哈希值和所述第一联合哈希值相同,确定所述待验证签名验签通过;若所述第二联合哈希值和所述第一联合哈希值不同,确定所述待验证签名验签未通过。
- 一种计算机可读存储介质,其中,所述计算机可读存储介质存储有计算机程序,所述计算机程序包括程序指令,所述程序指令被处理器执行时,执行以下方法:确定第一加密数据中各第一子加密数据的第一密钥以及第二加密数据中各第二子加密数据的第二密钥,其中,所述第一加密数据由至少一个第一子加密数据按照第一排序组成,一个第一子加密数据对应一个第一密钥,所述第二加密数据由至少一个第二子加密数据按照第二排序组成,一个第二子加密数据对应一个第二密钥;根据各第一密钥、所述各第一密钥的第一保序系数、各第二密钥以及所述各第二密钥的第二保序系数确定私钥,其中,所述各第一密钥的第一保序系数各不相同,所述各第二密钥的第二保序系数各不相同,且相同排序位置的第一子加密数据的第一密钥的第一保序系数和第二子加密数据的第二密钥的第二保序系数相同;根据所述私钥对所述第一加密数据和所述第二加密数据进行签名以生成待验证签名, 并将所述待验证签名上传至区块链网络对应的区块链以供所述区块链网络中的数据验证节点对第一加密数据和第二加密数据进行验证。
- 根据权利要求15所述的计算机可读存储介质,其中,执行所述根据各第一密钥、所述各第一密钥的第一保序系数、各第二密钥以及所述各第二密钥的第二保序系数确定私钥,包括:确定各第一密钥的第一保序系数,并根据所述各第一密钥和所述各第一密钥的第一保序系数确定所有第一密钥的第一累计密钥;确定各第二密钥的第二保序系数,并根据所述各第二密钥和所述各第二密钥的第二保序系数确定所有第二密钥的第二累计密钥;根据所述第一累计密钥和所述第二累计密钥确定私钥。
- 根据权利要求15所述的计算机可读存储介质,其中,执行所述根据所述私钥对所述第一加密数据和所述第二加密数据进行签名以生成待验证签名,包括:根据所述第一加密数据和所述第二加密数据生成联合加密数据,并确定所述联合加密数据的第一联合哈希值;根据所述私钥对所述第一联合哈希值进行签名,生成所述第一加密数据和所述第二加密数据的待验证签名。
- 一种计算机可读存储介质,其中,所述计算机可读存储介质存储有计算机程序,所述计算机程序包括程序指令,所述程序指令被处理器执行时,执行以下方法:从区块链网络对应的区块链中获取第一加密数据、第二加密数据以及待验证签名,其中,所述第一加密数据由至少一个第一子加密数据按照第一排序组成,一个第一子加密数据对应一个第一密钥,所述第二加密数据由至少一个第二子加密数据按照第二排序组成,一个第二子加密数据对应一个第二密钥,所述待验证签名由所述区块链网络中的数据提供节点上传至所述区块链;确定验证参数,并根据各第一密钥、所述各第一密钥的第一保序系数、各第二密钥、所述各第二密钥的第二保序系数以及所述验证参数确定公钥,其中,所述各第一密钥的第一保序系数各不相同,所述各第二密钥的第二保序系数各不相同,且相同排序位置的第一子加密数据的第一密钥的第一保序系数和第二子加密数据的第二密钥的第二保序系数相同;根据所述公钥对所述待验证签名进行验签;若所述待验证签名验签通过,确定所述第一加密数据和所述第二加密数据相同。
- 根据权利要求18所述的计算机可读存储介质,其中,执行所述根据各第一密钥、所述各第一密钥的第一保序系数、各第二密钥、所述各第二密钥的第二保序系数以及所述验证参数确定公钥,包括:确定各第一密钥的第一保序系数,并根据所述各第一密钥以及所述各第一密钥的第一保序系数确定所有第一密钥的第一累计密钥;确定各第二密钥的第二保序系数,并根据所述各第二密钥以及所述各第二密钥的第二保序系数确定所有第二密钥的第二累计密钥;根据所述第一累计密钥、所述第二累计密钥以及所述验证参数确定公钥。
- 根据权利要求18所述的计算机可读存储介质,其中,执行所述根据所述公钥对所述待验证签名进行验签,包括:根据所述第一加密数据和所述第二加密数据生成联合加密数据,并确定所述联合加密数据的第一联合哈希值;根据所述公钥对所述待验证签名进行验签,得到第二联合哈希值:若所述第二联合哈希值和所述第一联合哈希值相同,确定所述待验证签名验签通过;若所述第二联合哈希值和所述第一联合哈希值不同,确定所述待验证签名验签未通过。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202011048106.0A CN112184441B (zh) | 2020-09-29 | 2020-09-29 | 数据处理方法、装置、节点设备及存储介质 |
| CN202011048106.0 | 2020-09-29 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2022068239A1 true WO2022068239A1 (zh) | 2022-04-07 |
Family
ID=73946421
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2021/097226 Ceased WO2022068239A1 (zh) | 2020-09-29 | 2021-05-31 | 数据处理方法、节点设备及存储介质 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN112184441B (zh) |
| WO (1) | WO2022068239A1 (zh) |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN112184441B (zh) * | 2020-09-29 | 2024-01-19 | 平安科技(深圳)有限公司 | 数据处理方法、装置、节点设备及存储介质 |
| CN112819467B (zh) * | 2021-02-23 | 2024-09-06 | 中国信息通信研究院 | 一种隐私交易方法、装置及系统 |
| CN113935070B (zh) * | 2021-12-16 | 2022-06-07 | 北京百度网讯科技有限公司 | 基于区块链的数据处理方法、装置、设备以及存储介质 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN110069939A (zh) * | 2019-03-12 | 2019-07-30 | 平安科技(深圳)有限公司 | 加密数据一致性校验方法、装置、计算机设备及存储介质 |
| CN110110163A (zh) * | 2018-01-18 | 2019-08-09 | Sap欧洲公司 | 安全子字符串搜索以过滤加密数据 |
| CN111062716A (zh) * | 2019-11-29 | 2020-04-24 | 支付宝(杭州)信息技术有限公司 | 生成区块链签名数据的方法及装置、区块链交易发起系统 |
| US10659233B1 (en) * | 2019-03-15 | 2020-05-19 | Alibaba Group Holding Limited | Authentication based on a recovered public key |
| CN112184441A (zh) * | 2020-09-29 | 2021-01-05 | 平安科技(深圳)有限公司 | 数据处理方法、装置、节点设备及存储介质 |
Family Cites Families (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11212081B2 (en) * | 2017-02-24 | 2021-12-28 | Nec Corporation | Method for signing a new block in a decentralized blockchain consensus network |
| CN110061845A (zh) * | 2019-03-14 | 2019-07-26 | 深圳壹账通智能科技有限公司 | 区块链数据加密方法、装置、计算机设备及存储介质 |
| US10951417B2 (en) * | 2019-07-12 | 2021-03-16 | Advanced New Technologies Co., Ltd. | Blockchain-based transaction verification |
| CN111447174A (zh) * | 2020-02-19 | 2020-07-24 | 江苏荣泽信息科技股份有限公司 | 一种基于区块链的数据加密方法 |
| CN111339569B (zh) * | 2020-02-26 | 2023-05-26 | 百度在线网络技术(北京)有限公司 | 区块链数据处理方法、装置、电子设备和介质 |
| CN111476617B (zh) * | 2020-04-03 | 2021-06-25 | 腾讯科技(深圳)有限公司 | 数据处理方法、装置、计算机设备及介质 |
| CN111490878B (zh) * | 2020-04-09 | 2021-07-27 | 腾讯科技(深圳)有限公司 | 密钥生成方法、装置、设备及介质 |
-
2020
- 2020-09-29 CN CN202011048106.0A patent/CN112184441B/zh active Active
-
2021
- 2021-05-31 WO PCT/CN2021/097226 patent/WO2022068239A1/zh not_active Ceased
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN110110163A (zh) * | 2018-01-18 | 2019-08-09 | Sap欧洲公司 | 安全子字符串搜索以过滤加密数据 |
| CN110069939A (zh) * | 2019-03-12 | 2019-07-30 | 平安科技(深圳)有限公司 | 加密数据一致性校验方法、装置、计算机设备及存储介质 |
| US10659233B1 (en) * | 2019-03-15 | 2020-05-19 | Alibaba Group Holding Limited | Authentication based on a recovered public key |
| CN111062716A (zh) * | 2019-11-29 | 2020-04-24 | 支付宝(杭州)信息技术有限公司 | 生成区块链签名数据的方法及装置、区块链交易发起系统 |
| CN112184441A (zh) * | 2020-09-29 | 2021-01-05 | 平安科技(深圳)有限公司 | 数据处理方法、装置、节点设备及存储介质 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN112184441A (zh) | 2021-01-05 |
| CN112184441B (zh) | 2024-01-19 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| JP6908700B2 (ja) | 情報保護のためのシステム及び方法 | |
| TWI831760B (zh) | 用以基於證明驗證認證鏈外資料之系統及方法 | |
| CN108418783B (zh) | 一种保护区块链智能合约隐私的方法、介质 | |
| US10892888B2 (en) | System and method for information protection | |
| US10938549B2 (en) | System and method for information protection | |
| US20200344068A1 (en) | Managing blockchain-based centralized ledger systems | |
| CN118104188A (zh) | 用于保护数字签名的方法和系统 | |
| JP2020502856A5 (zh) | ||
| AU2021370924A1 (en) | Certificate based security using post quantum cryptography | |
| CN110637441A (zh) | 应用于数据重复数据删除的加密密钥生成 | |
| US20200366499A1 (en) | Managing blockchain-based centralized ledger systems | |
| CN110263584B (zh) | 一种基于区块链的数据完整性审计方法和系统 | |
| JP2013539295A (ja) | メッセージ復元を伴うデジタル署名の認証された暗号化 | |
| WO2022068239A1 (zh) | 数据处理方法、节点设备及存储介质 | |
| CN112989436B (zh) | 一种基于区块链平台的多重签名方法 | |
| JP2024534237A (ja) | 共有暗号キーを生成すること | |
| TW202318833A (zh) | 臨界簽章方案 | |
| WO2022068240A1 (zh) | 数据处理方法、节点设备及存储介质 | |
| CN110827034B (zh) | 用于发起区块链交易的方法及装置 | |
| WO2022116175A1 (zh) | 数字签名的生成方法、装置和服务器 | |
| Stallings | Digital signature algorithms | |
| CN117837123A (zh) | 生成数字签名 | |
| CN117978376A (zh) | 一种数字身份标识符的生成及更新方法 | |
| JP2025526867A (ja) | 改良されたブロックチェーンシステム及び方法 | |
| CN117573684A (zh) | 一种支持动态数据更新和外包计算的存储时间证明方法 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 21873901 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 21873901 Country of ref document: EP Kind code of ref document: A1 |