Transaction Processing Method, Device and System

By using input and output blinding factors to encrypt and hash signatures in blockchain transactions, the problem of insufficient transaction security in the existing technology is solved, and higher security is achieved.

CN114154989BActive Publication Date: 2025-07-25WEBANK (CHINA)
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111483903.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-07
Publication Date
2025-07-25
Estimated Expiration
2041-12-07

AI Technical Summary

Technical Problem

In the prior art, the encryption algorithm and verification algorithm of blockchain transaction data affect transaction security, and there are problems of security reduction caused by malicious attacks.

Method used

By encrypting the transaction data using input and output blinding factors, the input commitment and output commitment are generated, and their ratios are hashed and signed as verification information, and signed with the blinding factor difference value to generate transaction information to ensure that the blinding factor is used in the commitment and signature calculation process.

Benefits of technology

Improve the security of transactions and prevent malicious attacks from being able to pass signature verification after modifying the promises, enhancing the security of transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114154989B_ABST
    Figure CN114154989B_ABST
Patent Text Reader

Abstract

The present application provides a transaction processing method, device and system. The method includes: encrypting the input transaction data of the first user through a first input blinding factor to obtain a first input commitment, and encrypting the output transaction data of the first user through a first output blinding factor to obtain a first output commitment; determining the ratio of the first output blinding factor to the first input blinding factor as the first verification information; obtaining a first signature content by hashing the first verification information; signing the first signature content through the difference between the first output blinding factor and the first input blinding factor to obtain a first signature information; generating a first transaction information, the first transaction information includes: the first input commitment, the first output commitment, the first verification information, the first signature information and the first signature content. The embodiments of the present application can combine commitments and signatures, and both calculation processes of them need to use blinding factors, improving the transaction security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the technical field of fintech, and in particular, to a transaction processing method, device and system. Background Art

[0002] In the technical field of fintech, blockchain technology is a commonly used technology for storing transaction data in a chain structure, which can be called a blockchain. The transaction data on the blockchain usually needs to be encrypted and stored, and the transaction data can be used only after it is verified.

[0003] The encryption algorithm and verification algorithm of the above transaction data will affect the security of the transaction data, that is, the transaction security. Therefore, how to improve the transaction security in the encryption process and verification process is an urgent problem to be solved. Summary of the Invention

[0004] The present application provides a transaction processing method, device and system to improve transaction security.

[0005] In a first aspect, the present application provides a transaction processing method, the method includes:

[0006] The first electronic device encrypts the input transaction data of the first user through a first input blinding factor to obtain a first input commitment, and encrypts the output transaction data of the first user through a first output blinding factor to obtain a first output commitment;

[0007] The first electronic device determines the ratio of the first output blinding factor to the first input blinding factor as the first verification information;

[0008] The first electronic device calculates the hash of the first verification information to obtain a first signature content;

[0009] The first electronic device signs the first signature content through the difference between the first output blinding factor and the first input blinding factor to obtain a first signature information;

[0010] The first electronic device generates a first transaction information, the first transaction information includes: the first input commitment, the first output commitment, the first verification information, the first signature information and the first signature content.

[0011] Optionally, the first user is any user in the first user group, the first user group includes multiple users, and the method further includes:

[0012] The first electronic device receives first transaction information of a second user sent by at least one second electronic device. The first transaction information of the second user is generated by the second electronic device according to information of the second user. The manner in which the second electronic device generates the first transaction information of the second user is the same as the manner in which the first electronic device generates the first transaction information of the first user. The second user is a user other than the first user in the first user group;

[0013] The first electronic device aggregates the first transaction information of each user in the first user group to obtain first aggregated transaction information of the first user group. The first aggregated transaction information includes at least one of the following types of information: a first aggregated input commitment obtained by aggregating the first input commitments of each user, a first aggregated output commitment obtained by aggregating the first output commitments of each user, a first aggregated verification information obtained by aggregating the first verification information of each user, a first aggregated signature information obtained by aggregating the first signature information of each user, and a first aggregated signature content obtained by aggregating the first signature contents of each user.

[0014] Optionally, the first user is any user in the first user group, and the first user group includes multiple users. The method further includes:

[0015] The first electronic device sends the first transaction information to a third electronic device, so that the third electronic device aggregates the first transaction information of each user in the first user group to obtain first aggregated transaction information of the first user group. The first aggregated transaction information includes at least one of the following types of information: a first aggregated input commitment obtained by aggregating the first input commitments of each user, a first aggregated output commitment obtained by aggregating the first output commitments of each user, a first aggregated verification information obtained by aggregating the first verification information of each user, a first aggregated signature information obtained by aggregating the first signature information of each user, and a first aggregated signature content obtained by aggregating the first signature contents of each user.

[0016] Optionally, the first electronic device obtains a first signature content by hashing the first verification information, including:

[0017] The first electronic device obtains the first signature content by hashing the first verification information and the public keys of each user in the first user group.

[0018] Optionally, the public key of the first user is generated through the following steps:

[0019] The first electronic device randomly selects an initial private key of the first user from a preset integer finite field;

[0020] The first electronic device generates an initial public key of the first user according to the initial private key;

[0021] The first electronic device determines the private key of the first user according to the first target hash value and the initial private key, where the first target hash value is obtained by hashing the initial public key of the first user and the set of initial public keys of each user in the first user group;

[0022] The first electronic device generates the public key of the first user according to the private key of the first user.

[0023] In a second aspect, the present application provides a transaction processing method, including:

[0024] A fourth electronic device obtains first aggregated transaction information of a first user group, where the first aggregated transaction information includes: a first aggregated input commitment obtained by aggregating the first input commitments of each user in the first user group, a first aggregated output commitment obtained by aggregating the first output commitments of each user, a first aggregated verification information obtained by aggregating the first verification information of each user, a first aggregated signature information obtained by aggregating the first signature information of each user, and a first aggregated signature content obtained by aggregating the first signature content of each user;

[0025] The fourth electronic device performs a bilinear pairing on the first aggregated signature information and a generation subgroup of the first user group to obtain a first pairing result, and performs a bilinear pairing on the first aggregated signature content and the first aggregated verification information to obtain a second pairing result;

[0026] If the first pairing result is consistent with the second pairing result, and the ratio of the first aggregated output commitment to the first aggregated input commitment is consistent with the first aggregated verification information, the fourth electronic device determines that the first aggregated transaction information is successfully verified.

[0027] Optionally, after the fourth electronic device determines that the first aggregated transaction information is successfully verified, it further includes:

[0028] The fourth electronic device uses the sum of the first output blinding factors of each user in the first user group as a second input blinding factor;

[0029] When a third user conducts a transaction, the fourth electronic device encrypts the input transaction data of the third user through the second input blinding factor to obtain a second input commitment;

[0030] The fourth electronic device generates second transaction information of the third user, and the second transaction information includes the second input commitment.

[0031] Optionally, the third user is any user in the second user group, the second user group includes multiple users, and the second transaction information further includes a second output commitment. Before the fourth electronic device generates the second transaction information of the third user, the method further includes:

[0032] The fourth electronic device selects an initial blinding factor of the third user in a preset integer finite field;

[0033] The fourth electronic device calculates the hash of the initial blinding factor and the public key set of each user in the second user group to obtain a second target hash value;

[0034] The fourth electronic device determines a second output blinding factor of the third user according to the initial blinding factor and the second target hash value;

[0035] The fourth electronic device encrypts the output transaction data of the third user through the second output blinding factor to obtain the second output commitment.

[0036] Optionally, the method further includes:

[0037] The fourth electronic device determines real verification information according to the first output blinding factors of the users in the first user group and the first input blinding factors of the users in the first user group;

[0038] When the first pairing result is consistent with the second pairing result, and the ratio of the first aggregated output commitment to the first aggregated input commitment is consistent with the first aggregated verification information, the fourth electronic device determines that the first aggregated transaction information is successfully verified, including:

[0039] If the first pairing result is consistent with the second pairing result, and the ratio of the first aggregated output commitment to the first aggregated input commitment is consistent with the first aggregated verification information, and the real verification information is consistent with the first aggregated verification information, then the fourth electronic device determines that the first aggregated transaction information is successfully verified.

[0040] In a third aspect, the present application provides a first electronic device, including: at least one processor and a memory;

[0041] The memory stores computer execution instructions;

[0042] The at least one processor executes the computer execution instructions stored in the memory, so that the first electronic device implements the method in the foregoing first aspect.

[0043] In a fourth aspect, the present application provides a fourth electronic device, including: at least one processor and a memory;

[0044] The memory stores computer-executable instructions;

[0045] The at least one processor executes the computer-executable instructions stored in the memory, so that the fourth electronic device implements the method according to the second aspect as described above.

[0046] In a fifth aspect, the present application provides a transaction processing system, including the first electronic device according to the third aspect and the fourth electronic device according to the fourth aspect.

[0047] In a sixth aspect, the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When a processor executes the computer-executable instructions, a computing device is enabled to implement the method according to the first aspect or the second aspect as described above.

[0048] In a seventh aspect, the present application provides a computer program for implementing the method according to the first aspect or the second aspect as described above.

[0049] The transaction processing method, device and system provided by the present application, the method includes: encrypting the input transaction data of the first user through a first input blinding factor to obtain a first input commitment, and encrypting the output transaction data of the first user through a first output blinding factor to obtain a first output commitment; determining the ratio of the first output blinding factor to the first input blinding factor as the first verification information; hashing the first verification information to obtain a first signature content; signing the first signature content through the difference between the first output blinding factor and the first input blinding factor to obtain a first signature information; generating a first transaction information, the first transaction information includes: the first input commitment, the first output commitment, the first verification information, the first signature information and the first signature content. Embodiments of the present application can combine commitments and signatures, that is, both of their calculation processes need to use blinding factors. In this way, even if the blinding factors and commitments are modified to satisfy the commitment formula, they cannot satisfy the signature verification formula. Therefore, it can be ensured that the verification fails, avoiding the impact of malicious attacks on transactions and improving the security of transactions. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0051] Figure 1 is a schematic diagram of the relationship of multiple transactions provided by the prior art;

[0052] Figure 2 It is a schematic diagram of a transaction process based on commitment and aggregate signature provided by the prior art;

[0053] Figure 3 It is a schematic diagram of an aggregate transaction process provided by the prior art;

[0054] Figure 4 It is a specific step flowchart of a transaction processing method provided by an embodiment of the present application;

[0055] Figure 5 It is a specific step flowchart of another transaction processing method provided by an embodiment of the present application;

[0056] Figure 6 It is a structural block diagram of an electronic device provided by an embodiment of the present application. Specific Embodiments

[0057] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Apparently, the described embodiments are some, rather than all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without making creative efforts shall fall within the protection scope of the present application.

[0058] The embodiments of the present application can be applied to the transaction process of electronic currency. Each transaction has an input data and multiple output data. In the transaction process of electronic currency, the input data of each transaction is the output data of the previous transaction or the currency data rewarded by the system, and the output data of each transaction can be used as the input data of the next transaction. Here, both the input data and the output data can be the quantity of electronic currency.

[0059] In practical applications, the output data of a transaction can be stored in UTXO (unspent transaction outputs), and the input data is part or all of the output data of the previous transaction. Figure 1 It is a schematic diagram of the relationship of multiple transactions provided by the prior art.

[0060] Referring to Figure 1 As shown, the first transaction TX0 has an input data IPT00 and two output data OPT00 and OPT01. Among them, the input data IPT00 is 100 rewarded by the system, 40 in the output data OPT00 is used as the input data IPT10 of the next transaction TX1, and 50 in the output data OPT01 is used as the input data IPT20 of the next transaction TX2.

[0061] Referring toFigure 1 As shown, the next transaction TX1 of TX0 has an input data IPT10 and an output data OPT10. Among them, the input data IPT10 is 40 in the output data OPT00 of the previous transaction TX0, and 30 in the output data OPT10 is used as the input data IPT30 of the next transaction TX3.

[0062] Refer to Figure 1 As shown, the next transaction TX3 of TX1 has an input data IPT30 and an output data OPT30. Among them, the input data IPT30 is 30 in the output data OPT10 of the previous transaction TX1, and the output data OPT30 is not used by the next transaction for the time being.

[0063] Refer to Figure 1 As shown, the next transaction TX2 of TX0 has an input data IPT20 and two output data OPT20 and OPT21. Among them, the input data IPT20 is 50 in the output data OPT01 of the previous transaction TX1, 20 in the output data OPT20 is used as the input data TX4 of the next transaction TX4, and 20 in the output data OPT21 is used as the input data IPT50 of the next transaction TX5.

[0064] Refer to Figure 1 As shown, the next transaction TX4 of TX2 has an input data IPT40 and an output data OPT40. Among them, the input data IPT40 is 20 in the output data OPT20 of the previous transaction TX2, and 10 in the output data OPT40 is used as the input data IPT60 of the next transaction TX6.

[0065] Refer to Figure 1 As shown, the next transaction TX5 of TX2 has an input data IPT50 and an output data OPT50. Among them, the input data IPT50 is 20 in the output data OPT21 of the previous transaction TX2, and 10 in the output data OPT50 is used as the input data IPT61 of the next transaction TX6.

[0066] Refer to Figure 1 As shown, the next transaction TX6 of TX4 and TX5 has two input data IPT60 and IPT61 and an output data OPT60. Among them, the input data IPT60 is 10 in the output data OPT40 of the previous transaction TX4, the input data IPT61 is 10 in the output data OPT50 of the previous transaction TX5, and the output data OPT60 is not used by the next transaction for the time being.

[0067] As can be seen from the above process, the output data of each transaction can be used as the input data of the next transaction, that is, it is used by the next transaction. After the output data is used up, the output data of this transaction is no longer stored in the UTXO. If the output data is not used up, the output data of this transaction is stored in the UTXO.

[0068] To ensure the security of the above transaction process, the input data and output data can be encrypted through commitments. The data obtained by encrypting the input data can be called the input commitment, and the data obtained by encrypting the output data can be called the output commitment. The input commitment and output commitment of the previous transaction are sent to the recipient so that the recipient can use the output data of the previous transaction through the next transaction.

[0069] In the above commitment process, the transaction also needs to be signed. The transaction process based on commitments and aggregate signatures can involve two user groups: the sender user group and the recipient user group. The sender user group transfers funds to the recipient user group. The sender user group and the recipient user group are relative. For different transaction processes, the sender user group and the recipient user group can be different. For example, in the process of user group UG1 transferring funds to user group UG2, UG1 is the sender user group and UG2 is the recipient user group. Another example is that in the process of user group UG2 transferring funds to user group UG3, UG2 is the sender user group and UG3 is the recipient user group.

[0070] Among them, the user group can be obtained by dividing all users in any way. For example, user groups UG1, UG2, and UG3 can be obtained by dividing according to regions.

[0071] Figure 2 is a schematic diagram of a transaction process based on commitments and aggregate signatures provided by the prior art. Refer to Figure 2 As shown, the transaction process can include the following steps:

[0072] S1: The electronic device of each user in the sender user group generates an input commitment and an output commitment.

[0073] Specifically, the electronic device of the i-th user USR_i in the sender user group encrypts the input data IPT_i of USR_i through the randomly generated input blinding factor IK_i of USR_i to obtain the input commitment ICO_i of USR_i, and encrypts the output data OPT_i of USR_i through the randomly generated output blinding factor OK_i of USR_i to obtain the output commitment OCO_i of USR_i.

[0074] The encryption process here can use the following formula:

[0075] (1)

[0076] Among them, CO can be an input commitment or an output commitment, g and h are generators of a group with order q, k is an input blinding factor or an output blinding factor, and v is input data or output data.

[0077] It can be understood that when encrypting the input data IPT_i, by replacing IPT_i with v and IK_i with k, the CO can be calculated through the above formula (1). This CO is the input commitment of USR1_i, denoted as ICO_i. When encrypting the output data OPT_i, by replacing OPT_i with v and OK_i with k, the CO can be calculated through the above formula (1). This CO is the output commitment of USR_i, denoted as OCO_i.

[0078] S2: The electronic device of each user in the sender user group signs the empty string to obtain signature information.

[0079] Specifically, the signature information can be calculated through the following formula:

[0080] (2)

[0081] Among them, SGN_i is the signature information, Hash(m) is used to calculate the hash of the empty string m, and SK_i is the private key of the user.

[0082] After obtaining the above input commitment, output commitment, and signature information, the electronic devices of each user in the sender user group can send their input commitment, output commitment, and signature information to the untrusted aggregator, so that the untrusted aggregator can perform transaction aggregation on them to obtain aggregated transaction information.

[0083] Among them, the untrusted aggregator can be the electronic device of one of the target users in the sender user group, or can also be the electronic device of a third party. Among them, the target user can be any user in the sender user group.

[0084] When the untrusted aggregator is the electronic device of the target user, the electronic device of the target user can send the aggregated transaction information obtained by aggregation to the electronic device of the receiving user group or the electronic device of a third party to verify the aggregated transaction information. The above process of generating the input commitment and the output commitment can be referred to as the commitment phase, and there is also an opening phase afterwards. In the opening phase, the electronic device of each user in the sending user group needs to send the input blinding factor and the output blinding factor used for encryption to the electronic device of the target user, so that the target user's electronic device forwards the input blinding factor and the output blinding factor to the receiving user group or the electronic device of a third party. The receiving user group or the electronic device of a third party can perform commitment verification on the aggregated transaction information, and the generating subgroups g and h required for commitment verification are also publicly disclosed in advance by the sending user group.

[0085] When the untrusted aggregator is the electronic device of a third party, the electronic device of the third party can send the aggregated transaction information obtained by aggregation to the electronic device of the receiving user group, so that the electronic device of the receiving user group verifies the aggregated transaction information. The electronic device of the third party can also verify the aggregated transaction information obtained by aggregation. In the opening phase, the electronic device of each user in the sending user group needs to send the input blinding factor and the output blinding factor used for encryption to the electronic device of the third party, so that the third party's electronic device forwards the input blinding factor and the output blinding factor to the receiving user group or uses them for its own verification. The receiving user group or the electronic device of a third party can perform commitment verification on the aggregated transaction information, and the generating subgroups g and h required for commitment verification are also publicly disclosed in advance by the sending user group.

[0086] In the embodiments of the present application Figure 2 it is described by taking the example that the untrusted aggregator is the electronic device of the target user and the device for verifying the aggregated transaction information is the electronic device of the receiving user group.

[0087] S3: The electronic device of the target user aggregates the input commitments, output commitments and signature information of each user in the sending user group to obtain aggregated transaction information, and the aggregated transaction information includes: aggregated input commitment, aggregated output commitment and aggregated signature information.

[0088] Among them, the aggregated input commitment can be the product of the input commitments of each user in the sending user group, the aggregated output commitment can be the product of the output commitments of each user in the sending user group, and the aggregated signature information can be the product of the signature information of each user in the sending user group.

[0089] S4: The electronic device of the receiving user group performs commitment verification on the aggregated transaction information and signature verification on the aggregated signature information.

[0090] Among them, the electronic device of the receiving user group can be the electronic device of any user in the receiving user group. The electronic devices of all or part of the users in the receiving user group can perform the verification in S4 above.

[0091] In the commitment verification process, first, the input blinding factors of each user in the sender user group can be summed to obtain the total input blinding factor, and the output blinding factors of each user in the sender user group can be summed to obtain the total output blinding factor; then, the total input blinding factor is used to replace k in formula (1) to calculate a commitment, which can be called the verification input commitment, and the total output blinding factor is used to replace k in formula (1) to calculate another commitment, which can be called the verification output commitment; finally, if the verification input commitment is consistent with the aggregated input commitment, and the verification output commitment is consistent with the aggregated output commitment, it is determined that the commitment verification passes, otherwise, it is determined that the commitment verification fails.

[0092] In the signature verification process, the public keys PK_i of each user in the sender user group are multiplied to obtain the aggregated public key PK, and it is verified whether the following formula (3) holds. If formula (3) holds, it is determined that the signature verification passes, otherwise, it is determined that the signature verification fails.

[0093] (3)

[0094] Where Y is an empty string, e is the bilinear pairing algorithm, g is the aforementioned generator, and SGN is the aggregated signature information.

[0095] If the above commitment verification passes and the signature verification passes, then it represents successful verification, that is, the transfer transaction from the sender user group to the receiving user group is successful. Thus, the receiving user group can use the output data corresponding to this transfer transaction of the sender user group through its own transaction, which is the next transaction process, and this process is the same as Figure 2 the process shown, except that the sender user group and the receiving user group need to be adjusted.

[0096] It can be seen that the above aggregated transaction process requires the electronic devices of all users in the sender user group to send transaction information to the trustless aggregator. Figure 3 is a schematic diagram of the aggregated transaction process provided by the prior art, Figure 3 taking the aggregated transaction between the sender user group and the receiving user group as an example, Figure 3 the trustless aggregator in Figure 3As shown, the electronic devices of each user USR2_1 to USR2_m-1 in the sender user group send transaction information TX2_1 to TX2_m-1 to the trustless aggregator. The trustless aggregator aggregates the transaction information TX2_1 to TX2_m-1 and TX2_m to obtain the aggregated transaction information TX2. Then, the trustless aggregator sends TX2 to the receiver user group so that the electronic devices of the users USR3_1 to USR3_n in the receiver user group can use the total output data of the sender user group.

[0097] However, the above trustless aggregator may modify the sent transaction information. Since in the prior art, the commitment and the signature information are independent and there is no common parameter, it will result in modifying the commitment in the transaction information and then correspondingly modifying the blinding factor so that both the commitment verification and the signature verification are successful. In this case, a malicious attack can succeed by modifying the commitment, reducing the security of the transaction.

[0098] For example, first, the user group UG1 acts as the sender user group and conducts transactions with the receiver user group UG2 according to the above Figure 2 process. After the transaction between UG1 and UG2 is completed, UG2 acts as the sender user group and needs to conduct transactions with the receiver user group UG3 according to the above Figure 2 process.

[0099] Suppose the user group UG2 includes two users USR2_1 and USR2_2. Through the above Figure 2 method, after the electronic devices of the user group UG2 verify the aggregated transaction information of the user group UG1, the electronic devices of USR2_1 and USR2_2 need to generate new transactions to use the output data transferred from the user group UG1 to the user group UG2. When generating new transactions, the electronic devices of USR2_1 and USR2_2 respectively generate transaction information and uniformly send it to the electronic device of a user (such as USR2_1). If the electronic device of USR2_1 modifies the input commitment of USR2_1 to according to the input commitment sent by the electronic device of USR2_2, and, the electronic device of USR2_1 modifies the output commitment of USR2_1 to according to the output commitment of USR2_2, then, and then aggregates with the input commitment of USR2_2 to obtain the aggregated input commitment , aggregates with the output commitment Perform aggregation to obtain an aggregated output commitment ; Finally, the signature information of USR2_1 and the signature information of USR2_1 are aggregated to obtain aggregated signature information .

[0100] In this way, after sending the above aggregated input commitment, aggregated output commitment, aggregated signature information, input blinding factor IK_1, and output blinding factor OK_1 to the user group UG3, the user group UG3 verifies them.

[0101] When the electronic device of UG3 verifies the aggregated input commitment, first aggregate the input blinding factor IK_1 of the user group UG2 to obtain an aggregated input blinding factor, and then input the aggregated input blinding factor IK_1 and the total input data 10 into formula (1) to obtain a verified input commitment . It can be seen that the verified input commitment is the same as the aggregated input commitment, so the input commitment verification passes.

[0102] Similarly, when verifying the aggregated output commitment, first aggregate the output blinding factor OK_1 of the user group UG2 to obtain an aggregated output blinding factor, and then input the aggregated output blinding factor OK_1 and the total output data 10 into formula (1) to obtain a verified output commitment . It can be seen that the verified output commitment is the same as the aggregated output commitment, so the output commitment verification passes.

[0103] Finally, when verifying the aggregated signature information, since the signature information is not modified, the aggregated signature information still passes the verification.

[0104] Through the above verification process, the users in the user group UG3 can use the output data of USR2_2 without using the blinding factor of USR2_2. That is to say, the users in the user group UG3 can use its data even without being authorized by USR2_2, which reduces the security of the transaction.

[0105] To solve the above problem, the embodiments of the present application can combine the commitment and the signature, that is, make the blinding factor required in both calculation processes. In this way, even if the blinding factor and the commitment are modified to satisfy the commitment formula, they cannot satisfy the signature verification formula. Thus, it can be ensured that the verification fails, avoiding the impact of malicious attacks on the transaction and improving the security of the transaction.

[0106] Figure 4 is a specific step flowchart of a transaction processing method provided by the embodiments of the present application, which is applied to the first electronic device. Referring to Figure 4 shown, the method may include:

[0107] S101: The first electronic device encrypts the input transaction data of the first user with a first input blinding factor to obtain a first input commitment, and encrypts the output transaction data of the first user with a first output blinding factor to obtain a first output commitment.

[0108] Herein, the first user is any user in a first user group, and the first user group includes multiple users. The first user group in the embodiments of the present application may be a sender user group, and the first user is a sender user. In the embodiments of the present application, it is assumed that the first user is the i-th user USR_i in the first user group.

[0109] Specifically, for each transaction of the first user, a first input blinding factor for this transaction of the first user is randomly generated, so as to replace K in formula (1) with the first input blinding factor, replace v in formula (1) with the first input data of this transaction of the first user, and the CO calculated through formula (1) is the first input commitment of this transaction of the first user.

[0110] Similarly, for each transaction of the first user, a first output blinding factor for this transaction of the first user is randomly generated, so as to replace K in formula (1) with the first output blinding factor, replace v in formula (1) with the first output data of this transaction of the first user, and the CO calculated through formula (1) is the first output commitment of this transaction of the first user.

[0111] Certainly, if the same user has multiple transactions, then the above-mentioned first input commitments and first output commitments for multiple transactions will be correspondingly generated. Each transaction corresponds to a first input blinding factor, and each transaction corresponds to a first output blinding factor. In this way, a first input commitment set of the first user, a first output commitment set of the first user, a first input blinding factor set of the first user, and a first output blinding factor set of the first user will be obtained. Thus, the first input commitment of the first user can be the product of the first input commitments of multiple transactions in the first input commitment set of the first user, and the first output commitment of the first user can be the product of the first output commitments of multiple transactions in the first output commitment set of the first user.

[0112] S102: The first electronic device determines the ratio of the first output blinding factor to the first input blinding factor as the first verification information.

[0113] It should be noted that the first verification information here can be understood not only as the verification information for the input-output commitment, but also as the public key for the first signature information.

[0114] S103: The first electronic device calculates the hash of the first verification information to obtain the first signature content.

[0115] Among them, the hash algorithm is a commonly used algorithm in cryptography and will not be elaborated here.

[0116] Optionally, the first signature content can be obtained by hashing only the first verification information, or can be obtained by hashing the first verification information and the public keys of each user in the first user group.

[0117] S104: The first electronic device signs the first signature content through the difference between the first output blinding factor and the first input blinding factor to obtain the first signature information.

[0118] Specifically, for the first user USR_i, the first signature information of this first user can be calculated through the following formula:

[0119] (3)

[0120] Among them, SGN_i is the first signature information of USR_i, E_i is the first verification information of USR_i, PK is the public key set of the first user group composed of the public keys of each user in the first user group, is the first output blinding factor of the j-th transaction of USR_i, is the first input blinding factor of the j-th transaction of USR_i, and J_i is the number of transactions of USR_i.

[0121] In the above formula (3), is the first signature content M_i of USR_i. In the embodiments of the present application, when calculating the first signature content, the public key set PK can also not be used, that is, is used as the first signature content, that is, the first signature information of the first user is calculated through the following formula (4).

[0122] (4)

[0123] It can be seen that the first signature content in formula (3) is obtained by hashing the first verification information and the public keys of each user in the first user group, and the first signature content in formula (4) is obtained by hashing the first verification information. Thus, the verification of the first signature content of formula (3) requires the use of the public keys of all users in the first user group. Therefore, compared with formula (4), the reliability of formula (3) is better, which helps to further improve the security of transactions.

[0124] S105: The first electronic device generates the first transaction information, and the first transaction information includes: the first input commitment, the first output commitment, the first verification information, the first signature information, and the first signature content.

[0125] Specifically, the first transaction information TX_i = {ICO_i, OCO_i, E_i, SGN_i, M_i} can be generated based on the previously obtained first input commitment ICO_i, first output commitment OCO_i, first verification information E_i, first signature information SGN_i, and first signature content M_i.

[0126] It should be noted that since the foregoing first user is any user in the first user group, the above S101 to S105 can be used by the electronic devices of any user in the first user group to generate the first transaction information of its user. Based on this, the first transaction information of each user in the first user group can be aggregated to obtain the first aggregated transaction information of the first user group. This aggregation process is performed by a non-trusted aggregator, which can be the electronic device of the foregoing first user or the electronic device of a third party.

[0127] When the non-trusted aggregator is the foregoing first electronic device, in order to aggregate the first transaction information of each user in the first user group, the first electronic device also needs to receive the first transaction information of the second user sent by at least one second electronic device. The first transaction information of the second user is generated by the second electronic device according to the information of the second user. The method for the second electronic device to generate the first transaction information of the second user is the same as the method for the first electronic device to generate the first transaction information of the first user. The second user is a user other than the first user in the first user group.

[0128] After the first electronic device receives the above first transaction information sent by the second electronic device, the first electronic device can aggregate the first transaction information of each user in the first user group to obtain the first aggregated transaction information of the first user group. The first aggregated transaction information includes at least one of the following information: the first aggregated input commitment obtained by aggregating the first input commitments of each user, the first aggregated output commitment obtained by aggregating the first output commitments of each user, the first aggregated verification information obtained by aggregating the first verification information of each user, the first aggregated signature information obtained by aggregating the first signature information of each user, and the first aggregated signature content obtained by aggregating the first signature contents of each user.

[0129] When the untrusted aggregator is the electronic device of the aforementioned third party (subsequently referred to as the third electronic device), the first electronic device sends the first transaction information to the third electronic device, so that the third electronic device aggregates the first transaction information of each user in the first user group to obtain the first aggregated transaction information of the first user group. The first aggregated transaction information includes at least one of the following information: the first aggregated input commitment obtained by aggregating the first input commitments of each user, the first aggregated output commitment obtained by aggregating the first output commitments of each user, the first aggregated verification information obtained by aggregating the first verification information of each user, the first aggregated signature information obtained by aggregating the first signature information of each user, and the first aggregated signature content obtained by aggregating the first signature contents of each user.

[0130] Among them, the first aggregated input commitment is the product of the first input commitments of each user in the first user group, the first aggregated output commitment is the product of the first output commitments of each user in the first user group, the first aggregated verification information is the product of the first verification information of each user in the first user group, the first aggregated signature information is the product of the first signature information of each user in the first user group, and the first aggregated signature content is the product of the aggregation of the first signature contents of each user in the first user group.

[0131] This application can aggregate the first transaction information of each user in the first user group to obtain the first aggregated transaction information for verifying the first aggregated transaction information. This aggregation process can effectively reduce the number of verification times and thus reduce the verification complexity. In practical applications, before the first electronic device generates the first transaction information, the first electronic device needs to initialize the cryptographic environment, and this cryptographic environment initialization process is the same as the prior art. Specifically, it can include the following signature environment initialization, commitment environment initialization, and range proof environment initialization.

[0132] Specifically, it can include the following process:

[0133] First, the first electronic device selects an elliptic curve. G1, G2, and Gt are the public point sets on this curve, which is a finite group of order p, and Zp is the finite integer field of order p. g1 and g2 are the public points on the above curve, and are the values in G1 and G2 respectively, and are the generating elements of G1 and G2 respectively. g and h are the generating elements of the group G2.

[0134] Then, the first electronic device determines the bilinear mapping function e: G1 G2 -> Gt.

[0135] Then, the first electronic device determines the hash function Hash.

[0136] After the above initialization of the first electronic device, it is also necessary to generate a key pair. Specifically, each user participating in the transaction only needs to generate a key pair.

[0137] Specifically, first, the first electronic device randomly selects an integer in the above-mentioned preset integer finite field Zp as the initial private key KL_i to calculate the initial public key of the first user according to the initial private key ; then, the first electronic device sends its initial public key to the electronic devices of the remaining users in the first user group, so that each user in the first user group can obtain the initial public key set PL = {PL_1,..., PL_i,..., PL_m}; then, the first electronic device generates the private key of the first user according to the first target hash value and the initial private key , where is the first target hash value, that is, the first target hash value is obtained by the first electronic device by hashing the initial public key of the first user and the initial public key sets of the users in the first user group; finally, the first electronic device generates the public key of the first user according to the private key of the first user , and the public key set PK = {P_1,..., P_i,..., P_m}.

[0138] It can be seen that compared with the prior art that uses the initial private key and the initial public key in the above process as the finally used private key and public key, the embodiment of the present application regenerates the finally used private key according to the initial private key and the first target hash value. In this way, the randomness of the private key can be improved, the private key can be prevented from being cracked, which helps to improve the security of the private key, and further improves the security of the transaction.

[0139] Figure 4 The above method shown is the process of generating transaction information and aggregating transaction information. Correspondingly, Figure 5 is a specific step flowchart of another transaction processing method provided by the embodiment of the present application, which is applied to the fourth electronic device. Figure 5 The method shown is the verification process of the first aggregated transaction information. The fourth electronic device can be the aforementioned third electronic device, or the electronic devices where some or all of the users in the receiving user group are located. Referring to Figure 5 shown, the method may include:

[0140] S201: The fourth electronic device obtains the first aggregated transaction information of the first user group. The first aggregated transaction information includes: the first aggregated input commitment aggregated from the first input commitments of the users in the first user group, the first aggregated output commitment aggregated from the first output commitments of the users, the first aggregated verification information aggregated from the first verification information of the users, the first aggregated signature information aggregated from the first signature information of the users, and the first aggregated signature content aggregated from the first signature contents of the users.

[0141] It is understandable that the first aggregated transaction information here is sent by the aforementioned trustless aggregator.

[0142] S202: The fourth electronic device performs a bilinear pairing on the first aggregated signature information and the generating subgroup of the first user group to obtain a first pairing result, and performs a bilinear pairing on the first aggregated signature content and the first aggregated verification information to obtain a second pairing result.

[0143] Among them, the first pairing result is , and the second pairing result is , where e is the bilinear pairing algorithm. SGN is the first aggregated signature information, g2 is the generating subgroup of the first user group obtained during the aforementioned initialization, M is the first aggregated signature content, and E is the first aggregated verification information.

[0144] When , the fourth-generation electronic device determines that the first pairing result is consistent with the second pairing result. Otherwise, the fourth electronic device determines that the first pairing result and the second pairing result are inconsistent.

[0145] S203: If the first pairing result is consistent with the second pairing result, and the ratio of the first aggregated output commitment to the first aggregated input commitment is consistent with the first aggregated verification information, then the fourth electronic device determines that the verification of the first aggregated transaction information is successful.

[0146] According to the definition of the aforementioned first aggregated verification information, the first aggregated verification information , where E_i is the first verification information of USR_i.

[0147] Also, according to the definition of the first verification information E_i, it can be known that , so that the first aggregated verification information can be determined as , where OCO_i and ICO_i are the first output commitment and the first input commitment of USR_i respectively, and OCO and ICO are the first aggregated output commitment and the first aggregated input commitment respectively. That is to say, if the ratio of the first aggregated output commitment to the first aggregated input commitment is consistent with the first verification information, it means that the commitment and the verification information are corresponding, and thus the commitment verification is successful. Otherwise, the first aggregated output commitment and the first aggregated input commitment are not corresponding, and thus the commitment verification fails.

[0148] Optionally, the fourth electronic device according to the embodiments of the present application may further determine the true verification information according to the first output blinding factors of the users in the first user group and the first input blinding factors of the users in the first user group. Specifically, first, calculate the sum of the first output blinding factors of the users in the first user group, and then calculate the sum of the first input blinding factors of the users in the first user group; then, use the sum of the first output blinding factors as the exponent and g as the base to calculate the exponent result, which is called the first exponent result, and use the sum of the first input blinding factors as the exponent and g as the base to calculate the exponent result, which is called the second exponent result; finally, calculate the ratio of the second exponent result to the first exponent result as the true verification information.

[0149] Thus, the fourth electronic device may verify the first aggregated transaction information by combining the above true verification information, the above first pairing result, the second pairing result, the ratio of the first aggregated output commitment to the first aggregated input commitment, and the first aggregated verification information. Specifically, if the first pairing result is consistent with the second pairing result, and the ratio of the first aggregated output commitment to the first aggregated input commitment is consistent with the first aggregated verification information, and the true verification information is consistent with the first aggregated verification information, then the fourth electronic device determines that the verification of the first aggregated transaction information is successful.

[0150] Since the true verification information is determined according to the first output blinding factors of the users in the first user group and the first input blinding factors of the users in the first user group, whether the true verification information is consistent with the first aggregated verification information also represents whether the first aggregated verification information is determined according to the first output blinding factors of the users in the first user group and the first input blinding factors of the users in the first user group, thereby improving the accuracy of the first aggregated verification information and further improving the security of the transaction.

[0151] It can be understood that when the above verification process is executed by an electronic device of a third party, the electronic device of the third party may send the verification result to the electronic device of the users in the second user group so that the electronic device of the users in the second user group can use the output data of the first user group. When the above verification process is executed by the electronic device of the users in the second user group, the fourth electronic device is the electronic device of the users in the second user group, and the fourth electronic device can directly use the output data of the first user group. The second user group may be the receiving user group.

[0152] The process of the fourth electronic device using the output data of the first user group may include: First, the fourth electronic device takes the sum of the first output blinding factors of each user in the first user group as the second input blinding factor; Then, when the third user conducts a transaction, the fourth electronic device encrypts the input data of the third user through the second input blinding factor to obtain a second input commitment. The third user is a user in the second user group, that is, a user of the fourth electronic device; Finally, the fourth electronic device generates the second transaction information of the third user, and the second transaction information includes the second input commitment.

[0153] Specifically, replacing k in formula (1) with the second input blinding factor, replacing v in formula (1) with the input data of the third user, and substituting the generating elements g and h of the second user group and the order q into formula (1) can obtain the second input commitment.

[0154] Similarly, replacing k in formula (1) with the second output blinding factor, replacing v in formula (1) with the output data of the third user, and substituting the generating elements g and h of the second user group and the order q into formula (1) can obtain the second output commitment.

[0155] In the prior art, the second output blinding factor is randomly selected from a preset integer finite field. This can lead to the second output blinding factor being easily attacked, thereby reducing the security of the second output blinding factor and further reducing the transaction security.

[0156] To improve the transaction security, the fourth electronic device in the embodiment of the present application can perform secondary blinding to improve the security of the second output blinding factor, thereby improving the transaction security.

[0157] Specifically, first, the fourth electronic device can select the initial blinding factor of the third user in a preset integer finite field; Then, the fourth electronic device calculates the hash of the initial blinding factor and the public key set of each user in the second user group to obtain a second target hash value; Then, the fourth electronic device determines the second output blinding factor of the third user according to the initial blinding factor and the second target hash value; Finally, the fourth electronic device encrypts the output data of the third user through the second output blinding factor to obtain the second output commitment.

[0158] Of course, in addition to generating the second output commitment and the second input commitment, the fourth electronic device also needs to determine the ratio of the second output commitment and the second input commitment as the second verification information, and generate the second signature information and the second signature content. The second input commitment, the second output commitment, the second verification information, the second signature information, and the second signature content constitute the second transaction information. The second transaction information of each user in the second user group is aggregated to obtain the second aggregated transaction information and sent to a third party or the third user group.

[0159] It can be seen that the above process is a transaction process in which the second user group serves as the new sender user group and the third user group serves as the new receiver user group. The third user group needs to verify the second aggregated transaction information. In this way, the process loops until there are no more transactions among the user groups.

[0160] It can be understood that when any user group serves as the sender user group, the process of generating transaction information can refer to the process of generating the first transaction information in Figure 4 . When any user group serves as the receiver user group, the process of verifying the transaction information can refer to the verification process in the foregoing Figure 5 .

[0161] The above first electronic device and fourth electronic device can be collectively referred to as electronic devices, Figure 6 which is a structural block diagram of an electronic device provided in an embodiment of the present application. The electronic device 600 includes a memory 602 and a processor 601.

[0162] Among them, the memory 602 stores computer execution instructions. The processor 601 executes the computer execution instructions stored in the memory 602, so that the first electronic device implements the method in Figure 4 or enables the fourth electronic device to implement the method in Figure 5 .

[0163] In addition, the electronic device may further include a receiver 603 and a transmitter 604. The receiver 603 is used to receive information from other devices or equipment and forward it to the processor 601, and the transmitter 604 is used to send information to other devices or equipment.

[0164] An embodiment of the present application further provides a transaction processing system, including: a first electronic device and a fourth electronic device.

[0165] Among them, the first electronic device is used for:

[0166] encrypting the input transaction data of the first user through a first input blinding factor to obtain a first input commitment, and encrypting the output transaction data of the first user through a first output blinding factor to obtain a first output commitment; determining the ratio of the first output blinding factor to the first input blinding factor as the first verification information; obtaining a first signature content by hashing the first verification information; signing the first signature content through the difference between the first output blinding factor and the first input blinding factor to obtain a first signature information; generating a first transaction information, the first transaction information includes: the first input commitment, the first output commitment, the first verification information, the first signature information and the first signature content.

[0167] Optionally, the first user is any user in a first user group, the first user group includes multiple users, and the first electronic device is further configured to:

[0168] First, receive first transaction information of a second user sent by at least one second electronic device. The first transaction information of the second user is generated by the second electronic device according to information of the second user. The manner in which the second electronic device generates the first transaction information of the second user is the same as the manner in which the first electronic device generates the first transaction information of the first user. The second user is a user other than the first user in the first user group.

[0169] Then, aggregate the first transaction information of each user in the first user group to obtain first aggregated transaction information of the first user group. The first aggregated transaction information includes at least one of the following information: a first aggregated input commitment obtained by aggregating the first input commitments of each user, a first aggregated output commitment obtained by aggregating the first output commitments of each user, a first aggregated verification information obtained by aggregating the first verification information of each user, a first aggregated signature information obtained by aggregating the first signature information of each user, and a first aggregated signature content obtained by aggregating the first signature contents of each user.

[0170] Optionally, the first user is any user in a first user group, the first user group includes multiple users, and the first electronic device is further configured to:

[0171] Send the first transaction information to a third electronic device, so that the third electronic device aggregates the first transaction information of each user in the first user group to obtain first aggregated transaction information of the first user group. The first aggregated transaction information includes at least one of the following information: a first aggregated input commitment obtained by aggregating the first input commitments of each user, a first aggregated output commitment obtained by aggregating the first output commitments of each user, a first aggregated verification information obtained by aggregating the first verification information of each user, a first aggregated signature information obtained by aggregating the first signature information of each user, and a first aggregated signature content obtained by aggregating the first signature contents of each user.

[0172] Optionally, the first electronic device is further configured to:

[0173] Calculate a hash of the first verification information and the public keys of each user in the first user group to obtain the first signature content.

[0174] Optionally, the first electronic device is further configured to generate the public key of the first user through the following steps:

[0175] Randomly select the initial private key of the first user from a preset integer finite field; generate the initial public key of the first user according to the initial private key; determine the private key of the first user according to the first target hash value and the initial private key, where the first target hash value is obtained by hashing the initial public key of the first user and the set of initial public keys of each user in the first user group; generate the public key of the first user according to the private key of the first user.

[0176] The above-mentioned fourth electronic device is used for:

[0177] First, obtain the first aggregated transaction information of the first user group, where the first aggregated transaction information includes: the first aggregated input commitment obtained by aggregating the first input commitments of each user in the first user group, the first aggregated output commitment obtained by aggregating the first output commitments of each user, the first aggregated verification information obtained by aggregating the first verification information of each user, the first aggregated signature information obtained by aggregating the first signature information of each user, and the first aggregated signature content obtained by aggregating the first signature contents of each user.

[0178] Then, perform a bilinear pairing on the first aggregated signature information and the generation subgroup of the first user group to obtain a first pairing result, and perform a bilinear pairing on the first aggregated signature content and the first aggregated verification information to obtain a second pairing result.

[0179] Finally, if the first pairing result is consistent with the second pairing result, and the ratio of the first aggregated output commitment to the first aggregated input commitment is consistent with the first aggregated verification information, it is determined that the first aggregated transaction information is successfully verified.

[0180] Optionally, the above-mentioned fourth electronic device is further used for:

[0181] After determining that the first aggregated transaction information is successfully verified, use the sum of the first output blinding factors of each user in the first user group as the second input blinding factor; when the third user conducts a transaction, encrypt the input transaction data of the third user through the second input blinding factor to obtain a second input commitment; generate the second transaction information of the third user, where the second transaction information includes the second input commitment.

[0182] Optionally, the third user is any user in the second user group, the second user group includes multiple users, the second transaction information further includes a second output commitment, and the fourth electronic device is further used for:

[0183] Before generating the second transaction information of the third user, select the initial blinding factor of the third user in a preset integer finite field; calculate the hash of the initial blinding factor and the public key set of each user in the second user group to obtain a second target hash value; determine the second output blinding factor of the third user according to the initial blinding factor and the second target hash value; encrypt the output transaction data of the third user through the second output blinding factor to obtain the second output commitment.

[0184] Optionally, the above fourth electronic device is further configured to:

[0185] Determine the true verification information according to the first output blinding factors of the users in the first user group and the first input blinding factors of the users in the first user group; thus, if the first pairing result is consistent with the second pairing result, and the ratio of the first aggregated output commitment to the first aggregated input commitment is consistent with the first aggregated verification information, and the true verification information is consistent with the first aggregated verification information, it is determined that the verification of the first aggregated transaction information is successful.

[0186] The embodiment of the present application further provides a computer-readable storage medium, in which computer execution instructions are stored. When a processor executes the computer execution instructions, it enables a computing device to implement the foregoing Figure 4 or Figure 5 shown method.

[0187] The embodiment of the present application further provides a computer program, and the computer program is used to implement Figure 4 or Figure 5 shown method.

[0188] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, and are not intended to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A transaction processing method, characterized in that, The method includes: The first electronic device encrypts the input transaction data of the first user with a first input blinding factor to obtain a first input commitment, and encrypts the output transaction data of the first user with a first output blinding factor to obtain a first output commitment; The first electronic device determines the ratio of the first output blinding factor to the first input blinding factor as the first verification information; The first electronic device calculates the hash of the first verification information to obtain a first signature content; The first electronic device signs the first signature content with the difference between the first output blinding factor and the first input blinding factor to obtain a first signature information, and the specific calculation formula is as follows: Where SGN_i is the first signature information, E_i is the first verification information, PK is the public key set of the first user group composed of the public keys of each user in the first user group where the first user is located, Kout_i_j is the first output blinding factor of the j-th transaction of the first user, Kin_i_j is the first input blinding factor of the j-th transaction of the first user, and J_i is the number of transactions of the first user; The first electronic device generates first transaction information, and the first transaction information includes: the first input commitment, the first output commitment, the first verification information, the first signature information, and the first signature content; Among them, the first electronic device calculates the hash of the first verification information to obtain the first signature content, including: The first electronic device calculates the hash of the first verification information and the public keys of each user in the first user group to obtain the first signature content; Among them, the public key of the first user is generated through the following steps: The first electronic device randomly selects an initial private key of the first user from a preset integer finite field; The first electronic device generates an initial public key of the first user according to the initial private key; The first electronic device determines the private key of the first user according to a first target hash value and the initial private key, and the first target hash value is obtained by calculating the hash of the initial public key of the first user and the set of initial public keys of each user in the first user group; The first electronic device generates the public key of the first user according to the private key of the first user.

2. The method according to claim 1, characterized in that, The first user is any user in the first user group, and the first user group includes multiple users. The method further includes: The first electronic device receives the first transaction information of a second user sent by at least one second electronic device. The first transaction information of the second user is generated by the second electronic device according to the information of the second user. The manner in which the second electronic device generates the first transaction information of the second user is the same as the manner in which the first electronic device generates the first transaction information of the first user. The second user is a user other than the first user in the first user group; The first electronic device aggregates the first transaction information of each user in the first user group to obtain the first aggregated transaction information of the first user group. The first aggregated transaction information includes at least one of the following: the first aggregated input commitment obtained by aggregating the first input commitments of each user, the first aggregated output commitment obtained by aggregating the first output commitments of each user, the first aggregated verification information obtained by aggregating the first verification information of each user, the first aggregated signature information obtained by aggregating the first signature information of each user, and the first aggregated signature content obtained by aggregating the first signature contents of each user.

3. The method according to claim 1, wherein The first user is any user in the first user group, and the first user group includes multiple users. The method further includes: The first electronic device sends the first transaction information to a third electronic device, so that the third electronic device aggregates the first transaction information of each user in the first user group to obtain the first aggregated transaction information of the first user group. The first aggregated transaction information includes at least one of the following: the first aggregated input commitment obtained by aggregating the first input commitments of each user, the first aggregated output commitment obtained by aggregating the first output commitments of each user, the first aggregated verification information obtained by aggregating the first verification information of each user, the first aggregated signature information obtained by aggregating the first signature information of each user, and the first aggregated signature content obtained by aggregating the first signature contents of each user.

4. A transaction processing method, characterized in that, Including: A fourth electronic device obtains the first aggregated transaction information of the first user group. The first aggregated transaction information includes: the first aggregated input commitment obtained by aggregating the first input commitments of each user in the first user group, the first aggregated output commitment obtained by aggregating the first output commitments of each user, the first aggregated verification information obtained by aggregating the first verification information of each user, the first aggregated signature information obtained by aggregating the first signature information of each user, and the first aggregated signature content obtained by aggregating the first signature contents of each user. The first user group includes a first user. The first signature information of the first user is obtained by signing the first signature content with the difference between the first output blinding factor and the first input blinding factor. The specific calculation formula is as follows: Where SGN_i is the first signature information of the first user, E_i is the first verification information of the first user, PK is the public key set of the first user group composed of the public keys of each user in the first user group, Kout_i_j is the first output blinding factor of the j-th transaction of the first user, Kin_i_j is the first input blinding factor of the j-th transaction of the first user, and J_i is the number of transactions of the first user; The fourth electronic device performs a bilinear pairing on the first aggregated signature information and the generation subgroup of the first user group to obtain a first pairing result, and performs a bilinear pairing on the first aggregated signature content and the first aggregated verification information to obtain a second pairing result; If the first pairing result is consistent with the second pairing result, and the ratio of the first aggregated output commitment to the first aggregated input commitment is consistent with the first aggregated verification information, then the fourth electronic device determines that the verification of the first aggregated transaction information is successful.

5. The method according to claim 4, wherein After the fourth electronic device determines that the verification of the first aggregated transaction information is successful, the following steps are further included: The fourth electronic device uses the sum of the first output blinding factors of each user in the first user group as the second input blinding factor; When a third user conducts a transaction, the fourth electronic device encrypts the input transaction data of the third user through the second input blinding factor to obtain a second input commitment; The fourth electronic device generates second transaction information of the third user, and the second transaction information includes the second input commitment.

6. The method according to claim 5, wherein The third user is any user in the second user group, the second user group includes multiple users, and the second transaction information further includes a second output commitment. Before the fourth electronic device generates the second transaction information of the third user, the following steps are further included: The fourth electronic device selects an initial blinding factor of the third user in a preset integer finite field; The fourth electronic device calculates the hash of the initial blinding factor and the public key set of each user in the second user group to obtain a second target hash value; The fourth electronic device determines the second output blinding factor of the third user according to the initial blinding factor and the second target hash value; The fourth electronic device encrypts the output transaction data of the third user through the second output blinding factor to obtain the second output commitment.

7. The method according to any one of claims 4 to 6, characterized in that The method further includes: The fourth electronic device determines the true verification information according to the first output blinding factors of each user in the first user group and the first input blinding factors of each user in the first user group; The step that if the first pairing result is consistent with the second pairing result, and the ratio of the first aggregated output commitment to the first aggregated input commitment is consistent with the first aggregated verification information, then the fourth electronic device determines that the verification of the first aggregated transaction information is successful, includes: If the first pairing result is consistent with the second pairing result, and the ratio of the first aggregated output commitment to the first aggregated input commitment is consistent with the first aggregated verification information, and the true verification information is consistent with the first aggregated verification information, then the fourth electronic device determines that the verification of the first aggregated transaction information is successful.

8. A first electronic device, characterized in that, The electronic device includes: at least one processor and a memory; The memory stores computer execution instructions; The at least one processor executes the computer execution instructions stored in the memory, so that the first electronic device implements the method described in any one of claims 1 to 3.

9. A fourth electronic device, characterized in that, The electronic device includes: at least one processor and a memory; The memory stores computer execution instructions; The at least one processor executes the computer execution instructions stored in the memory, so that the fourth electronic device implements the method described in any one of claims 4 to 7.

10. A transaction processing system, characterized in that, Including the first electronic device described in claim 8 and the fourth electronic device described in claim 9.

11. A computer-readable storage medium, characterized in that, Computer-executable instructions are stored in the computer-readable storage medium, and when the processor executes the computer-executable instructions, the computing device is caused to implement the method described in any one of claims 1 to 3, or the method described in any one of claims 4 to 7.

Citation Information

Patent Citations

  • System and method for information protection

    US20200228317A1