Blockchain-based Data Encryption Method, Device and Storage Medium
By using multiple encryption algorithms to splice and encrypt data in the cross-border trade blockchain, the problem of different participants choosing encryption standards in cross-border trade is solved, and data privacy and security are achieved.
Patent Information
- Application Number
- CN202011111365.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-10-16
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2040-10-16
AI Technical Summary
In cross-border trade blockchain, how to maintain data privacy while allowing each participant to choose different encryption standards based on actual needs.
The user node pre-stores the first encryption algorithm and the second encryption algorithm, encrypts the cross-border trade data separately, generates the first and second encryption information, and then splices and broadcasts, and other nodes decrypt according to their own encryption standards.
It has been realized that in the process of cross-border trade, each participant can choose different encryption standards according to actual needs, while maintaining data privacy and improving data security.
Smart Images

Figure CN114386080B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of blockchain technology, and in particular, to a data encryption method, device, and storage medium based on blockchain. Background Art
[0002] With the rapid development of blockchain technology, more and more enterprises or users begin to use blockchain technology to conduct transactions or transmit information with other enterprises. Especially in the process of cross-border trade, it involves multiple parties related to cross-border trade. Due to the public and transparent characteristics of blockchain, and the information stored in the cross-border trade blockchain is the core cross-border trade data of each party, each party is not willing to disclose these privacy data in plain text. Therefore, each party needs to perform encryption processing on these privacy data to achieve data protection. In the actual application scenarios of cross-border trade, the encryption standards recognized by different countries, regions, and institutions are different. For example, some countries, regions, and institutions recognize the Chinese national encryption standard, while other countries, regions, and institutions recognize the international commercial cryptography encryption standard. Thus, each party needs to select different encryption standards according to actual needs, and then use the encryption algorithm that conforms to the selected encryption standard to encrypt these privacy data. Therefore, how to ensure that each party can select different encryption standards according to actual needs while maintaining the privacy of cross-border trade data is the core problem to be solved in the cross-border trade blockchain.
[0003] Regarding the technical problem in the existing technology described above, in the cross-border trade process based on blockchain, how to ensure that each party can select different encryption standards according to actual needs while maintaining the privacy of cross-border trade data, no effective solution has been proposed yet. Summary of the Invention
[0004] Embodiments of the present disclosure provide a data encryption method, device, and storage medium based on blockchain to at least solve the technical problem in the existing technology that in the cross-border trade process based on blockchain, how to ensure that each party can select different encryption standards according to actual needs while maintaining the privacy of cross-border trade data.
[0005] According to one aspect of the embodiments of the present disclosure, there is provided a blockchain-based data encryption method, which is applied to a blockchain system for cross-border trade. The user nodes of the blockchain system pre-store a first encryption algorithm and a second encryption algorithm, and the method includes: the user node receives cross-border trade data related to cross-border trade operations; the user node uses the first encryption algorithm and the second encryption algorithm to encrypt the cross-border trade data respectively, generating a first encrypted message and a second encrypted message; the user node splices the first encrypted message and the second encrypted message to obtain a spliced encrypted message after splicing; and the user node broadcasts the spliced encrypted message in the blockchain system.
[0006] According to another aspect of the embodiments of the present disclosure, there is also provided a storage medium, which stores a program. When the program runs, the method described in any one of the above is executed by a processor.
[0007] According to another aspect of the embodiments of the present disclosure, there is also provided a blockchain-based data encryption device, which is applied to a blockchain system for cross-border trade. The user nodes of the blockchain system pre-store a first encryption algorithm and a second encryption algorithm, and the device includes: a receiving module, configured to receive cross-border trade data related to cross-border trade operations; an encryption module, configured to use the first encryption algorithm and the second encryption algorithm to encrypt the cross-border trade data respectively, generating a first encrypted message and a second encrypted message; a splicing module, configured to splice the first encrypted message and the second encrypted message to obtain a spliced encrypted message after splicing; and a broadcasting module, configured to broadcast the spliced encrypted message in the blockchain system.
[0008] According to another aspect of the embodiments of the present disclosure, there is also provided a blockchain-based data encryption device, which is applied to a blockchain system for cross-border trade. The user nodes of the blockchain system pre-store a first encryption algorithm and a second encryption algorithm, and the device includes: a processor; and a memory, connected to the processor, configured to provide instructions for the processor to perform the following processing steps: receive cross-border trade data related to cross-border trade operations; use the first encryption algorithm and the second encryption algorithm to encrypt the cross-border trade data respectively, generating a first encrypted message and a second encrypted message; splice the first encrypted message and the second encrypted message to obtain a spliced encrypted message after splicing; and broadcast the spliced encrypted message in the blockchain system.
[0009] In the embodiments of the present disclosure, a user node first receives cross-border trade data related to cross-border trade operations, and then uses a first encryption algorithm and a second encryption algorithm to encrypt the cross-border trade data respectively, generating a first encrypted message and a second encrypted message. The first encryption algorithm and the second encryption algorithm are encryption algorithms that conform to different encryption standards respectively. Then, the first encrypted message and the second encrypted message are concatenated to obtain a concatenated encrypted message after concatenation. Finally, the concatenated encrypted message is broadcast in the blockchain system. Other user nodes in the blockchain system can obtain the concatenated encrypted message from the blockchain, and then, according to the encryption standards they adopt respectively, obtain from the concatenated encrypted message the encrypted message encrypted using the encryption algorithm that conforms to their respective adopted encryption standards, and decrypt the obtained encrypted message to obtain the corresponding cross-border trade data. Thus, in this way, in the process of cross-border trade based on the blockchain, all parties participating in the cross-border trade can, while maintaining the privacy of cross-border trade data, also select different encryption standards according to actual needs. Furthermore, it solves the technical problem in the prior art that in the process of cross-border trade based on the blockchain, how to ensure that all parties participating in the cross-border trade can select different encryption standards according to actual needs while maintaining the privacy of cross-border trade data. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] The drawings described herein are used to provide a further understanding of the present disclosure and form a part of this application. The illustrative embodiments of the present disclosure and their descriptions are used to explain the present disclosure and do not constitute an improper limitation of the present disclosure. In the drawings:
[0011] Figure 1 is a hardware structure block diagram of a computing device for implementing the method according to Embodiment 1 of the present disclosure;
[0012] Figure 2 is a schematic diagram of a blockchain system applied to cross-border trade according to Embodiment 1 of the present disclosure;
[0013] Figure 3 is a schematic flowchart of a data encryption method based on the blockchain according to the first aspect of Embodiment 1 of the present disclosure;
[0014] Figure 4 is a schematic diagram of some splicing algorithms among multiple sets of splicing algorithms according to the first aspect of Embodiment 1 of the present disclosure;
[0015] Figure 5 is a schematic diagram of a data encryption device based on the blockchain according to Embodiment 2 of the present disclosure; and
[0016] Figure 6 is a schematic diagram of a data encryption device based on the blockchain according to Embodiment 3 of the present disclosure. Detailed implementation manners
[0017] In order to enable those skilled in the art to better understand the technical solutions of the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all of the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present disclosure.
[0018] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present disclosure described herein can be implemented in an order different from those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily need to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0019] Embodiment 1
[0020] According to this embodiment, an embodiment of a data encryption method based on a blockchain is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that here.
[0021] The method embodiment provided in this embodiment can be executed on a mobile terminal, a computer terminal, a server or a similar computing device. Figure 1 A hardware structure block diagram of a computing device for implementing a data encryption method based on a blockchain is shown. As Figure 1 shown, the computing device may include one or more processors (the processor may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory for storing data, and a transmission device for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the I / O interface), a network interface, a power supply, and / or a camera. Those of ordinary skill in the art can understand, Figure 1The structure shown is only illustrative and does not limit the structure of the above electronic device. For example, the computing device may also include more or fewer components than those shown in Figure 1 or have a different configuration from that shown in Figure 1 .
[0022] It should be noted that one or more of the above processors and / or other data processing circuits may generally be referred to herein as "data processing circuits". The data processing circuit may be embodied in whole or in part as software, hardware, firmware, or any combination thereof. In addition, the data processing circuit may be a single independent processing module, or may be incorporated in whole or in part into any one of the other elements in the computing device. As involved in the embodiments of the present disclosure, the data processing circuit is a processor control (such as the selection of a variable resistance terminal path connected to an interface).
[0023] The memory can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the blockchain-based data encryption method in the embodiments of the present disclosure. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, realizes the blockchain-based data encryption method of the above application program. The memory may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some instances, the memory may further include a memory remotely located relative to the processor, and these remote memories may be connected to the computing device through a network. Examples of the above network include but are not limited to the Internet, intranet, local area network, mobile communication network, and combinations thereof.
[0024] The transmission device is used to receive or send data via a network. Specific examples of the above network may include a wireless network provided by a communication provider of the computing device. In one instance, the transmission device includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one instance, the transmission device may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0025] The display may be, for example, a touch-screen liquid crystal display (LCD), which enables the user to interact with the user interface of the computing device.
[0026] It should be noted here that in some alternative embodiments, the above Figure 1The computing device shown may include hardware components (including circuits), software components (including computer code stored on a computer-readable medium), or a combination of both hardware and software components. It should be noted that Figure 1 is only an example of a specific concrete instance and is intended to illustrate the types of components that may exist in the above computing device.
[0027] Figure 2 is a schematic diagram of the blockchain system 200 applied to cross-border trade according to the present embodiment. Referring to Figure 2 as shown, the system 200 includes: a blockchain, multiple computing devices, and multiple user nodes 202a - 202n. Among them, each participating party in cross-border trade respectively operates the corresponding user node in the cross-border trade blockchain. For example, the multiple user nodes 202a - 202n are respectively the financial service party node 202a, the supplier node 202b, the purchaser node 202c, the customs clearance party node 202d, the transportation party node 202e, the warehousing party node 202f, the overseas inspection party node 202g, the carrier node 202h, the import and export service party node 202i, the insurance service party node 202j, the regulatory party node 202k, the freight forwarder node 202l, and other nodes, etc. Among them, each user node 202a - 202n runs a blockchain, and the blockchain stores the cross-border trade data uploaded by each business role-related party. The multiple computing devices correspond to the computing devices of different participating parties and are associated with their respective user nodes. For example, it includes computing devices 100a, 100b, 100c, 100d.... etc. The user node 202a of the financial service party is associated with the computing device 100a, the user node 202b of the supplier is associated with the computing device 100b, the user node 202c of the purchaser is associated with the computing device 100c, and the user node 202d of the customs clearance party is associated with the computing device 100d. Each computing device can communicate with the corresponding user node. For example, the computing device 100a can be a computing device (such as a computer at a bank counter) of a financial service party (such as a bank), and there can be multiple computing devices of the bank. The user node 202a of the bank is, for example, the user node corresponding to the bank. The computing device 100a of the bank can communicate with the user node 202a corresponding to the bank, and thus the computing device 100a can perform blockchain-related operations through the user node 202a. Among them. The computing device and the user node are, for example but not limited to, relevant electronic devices such as servers, terminal devices, desktop computers, etc., and no specific limitation is made here. It should be noted that the multiple computing devices 100a - 100d and the multiple user nodes 202a - 202n in the system can all apply the above-mentioned hardware structure.
[0028] Under the above operating environment, according to the first aspect of this embodiment, a blockchain-based data encryption method is provided, which is applied to a blockchain system for cross-border trade. The user nodes of the blockchain system pre-store a first encryption algorithm and a second encryption algorithm. This method is implemented by Figure 2 any one of the multiple user nodes 202a to 202n shown in Figure 3 FIG. shows a schematic flow diagram of this method. Referring to Figure 3 as shown, this method includes:
[0029] S302: The user node receives cross-border trade data related to cross-border trade business;
[0030] S304: The user node uses the first encryption algorithm and the second encryption algorithm to encrypt the cross-border trade data respectively, generating a first encrypted message and a second encrypted message;
[0031] S306: The user node splices the first encrypted message and the second encrypted message to obtain a spliced encrypted message after splicing; and
[0032] S308: The user node broadcasts the spliced encrypted message in the blockchain system.
[0033] As described in the background art, in the process of cross-border trade, there are multiple parties involved in cross-border trade. Due to the public and transparent characteristics of the blockchain, and the information stored in the cross-border trade blockchain is the core cross-border trade data of each party, each party is not willing to disclose these privacy data in plain text. Therefore, each party needs to perform encryption processing on the privacy data to achieve data protection. In the actual application scenario of cross-border trade, the encryption standards recognized by different countries, regions, and institutions are different. For example, some countries, regions, and institutions recognize the Chinese national encryption standard, while other countries, regions, and institutions recognize the international commercial cryptography encryption standard. Therefore, each party needs to select different encryption standards according to actual needs, and then use the encryption algorithm that conforms to the selected encryption standard to encrypt these privacy data. Therefore, how to ensure that each party can select different encryption standards according to actual needs while maintaining the privacy of cross-border trade data is the core problem to be solved in the cross-border trade blockchain.
[0034] In view of the technical problems existing in the background art, in this embodiment, when a certain participant in cross-border trade (for example, the supplier) has a need to store cross-border trade data related to cross-border trade operations in the blockchain, it can communicate with the supplier node 202b (i.e., the user node) through the computing device 100b to achieve the docking between the supplier and the blockchain system 200, and send the cross-border trade data to the supplier node 202b through the computing device 100a. At this time, the supplier node 202b receives cross-border trade data related to cross-border trade operations from the computing device 100b. (Corresponding to Figure 3 step S302 in
[0035] Further, the supplier node 202b pre-stores a first encryption algorithm and a second encryption algorithm, where the first encryption algorithm can be, for example, an encryption algorithm that complies with the Chinese national encryption standard, and the second encryption algorithm can be, for example, an encryption algorithm that complies with the international commercial cryptography encryption standard. At this time, in order to maintain the privacy of the cross-border trade data, the supplier node 202b uses the first encryption algorithm and the second encryption algorithm to encrypt the cross-border trade data respectively, generating a first encrypted message and a second encrypted message. Then, the supplier node 202b splices the generated first encrypted message and the second encrypted message to obtain a spliced encrypted message. Finally, the supplier node 202b broadcasts the obtained spliced encrypted message in the blockchain system 200. After broadcasting the spliced encrypted message in the blockchain system 200, the blockchain system 200 performs an operation of writing the spliced encrypted message onto the blockchain, that is, writing the spliced encrypted message into the blockchain.
[0036] Thus, other user nodes in the blockchain system 200 can obtain the spliced encrypted information from the blockchain, and then, according to the encryption standards they adopt, obtain the corresponding encrypted information encrypted using the encryption algorithm that conforms to their adopted encryption standards from the spliced encrypted information, and decrypt the obtained encrypted information to obtain the corresponding cross-border trade data. For example but not limited to, the purchaser node 202c in the blockchain system 200 adopts the national encryption standard of China. Therefore, after the purchaser node 202c obtains the spliced encrypted information from the blockchain, it obtains the first encrypted information encrypted using the encryption algorithm that conforms to the national encryption standard of China (corresponding to the first encryption algorithm) from the spliced encrypted information, and then decrypts the first encrypted information using the decryption algorithm corresponding to the first encryption algorithm to obtain the cross-border trade data. Similarly, the customs clearance node 202d in the blockchain system 200 adopts the international commercial cryptography encryption standard. Therefore, after the customs clearance node 202d obtains the spliced encrypted information from the blockchain, it obtains the second encrypted information encrypted using the encryption algorithm that conforms to the international commercial cryptography encryption standard (corresponding to the second encryption algorithm) from the spliced encrypted information, and then decrypts the first encrypted information using the decryption algorithm corresponding to the second encryption algorithm to obtain the cross-border trade data. Thus, in this way, in the cross-border trade process based on the blockchain, each participant in the cross-border trade can, while maintaining the privacy of the cross-border trade data, also select different encryption standards according to actual needs. Furthermore, it solves the technical problem in the prior art that in the cross-border trade process based on the blockchain, how to ensure that each participant can select different encryption standards according to actual needs while maintaining the privacy of the cross-border trade data.
[0037] Optionally, the first encryption algorithm includes a first public key and a first private key, the second encryption algorithm includes a second public key and a second private key, and the operations of encrypting the cross-border trade data using the first encryption algorithm and the second encryption algorithm respectively to generate the first encrypted information and the second encrypted information include: encrypting the cross-border trade data using the first public key and the second public key respectively to generate the first encrypted information and the second encrypted information, so that the node having the first private key can decrypt the first encrypted information using the first private key, or the node having the second private key can decrypt the second encrypted information using the second private key.
[0038] Specifically, the first encryption algorithm can be, for example, an encryption algorithm that complies with the Chinese national encryption standard, and the second encryption algorithm can be, for example, an encryption algorithm that complies with the international commercial cryptography encryption standard. The first encryption algorithm includes a first public key and a first private key, and the second encryption algorithm includes a second public key and a second private key. When the supplier node 202b uses the first encryption algorithm and the second encryption algorithm to encrypt the cross-border trade data respectively to generate the first encrypted information and the second encrypted information, it uses the first public key to encrypt the cross-border trade data to generate the first encrypted information, and uses the second public key to encrypt the cross-border trade data to generate the second encrypted information. Since all user nodes in the blockchain system 200 have pre-stored the first encryption algorithm and the second encryption algorithm, other user nodes can obtain the encrypted information encrypted by the encryption algorithm that complies with the encryption standard according to the encryption standard they adopt, and then use the private key they own to decrypt the encrypted information to obtain the cross-border trade data. In this way, if other user nodes adopt the international commercial cryptography encryption standard, they can decrypt using the private key of the encryption algorithm that complies with the international commercial cryptography encryption standard; if other user nodes adopt the Chinese national encryption standard, they can decrypt using the private key of the encryption algorithm that complies with the Chinese national encryption standard.
[0039] Optionally, the operation of the user node to splice the first encrypted information and the second encrypted information includes: the user node accesses a specified data block of the blockchain set in the blockchain system; the user node obtains splicing algorithm identification information from the specified data block; and the user node splices the first encrypted information and the second encrypted information according to the splicing algorithm corresponding to the splicing algorithm identification information.
[0040] Specifically, in order to further improve the security of the cross-border trade data stored on the blockchain, in this embodiment, multiple sets of splicing algorithms can be configured, and after the number of blocks in the blockchain reaches a certain amount, the block-producing node that generates the block is given the power to switch the splicing algorithm. For example, but not limited to: The blockchain system 200 is pre-configured with splicing algorithm a, splicing algorithm b, splicing algorithm c, and splicing algorithm d. The blockchain system 200 pre-configures a predetermined number of nodes with block-producing qualifications, and at least one of the above splicing algorithms is stored on the nodes with block-producing qualifications. For example: The nodes with block-producing qualifications are the purchaser node 202c, the transporter node 202e, the carrier node 202h, and the supervisor node 202k. The purchaser node 202c stores the splicing algorithm identification information of splicing algorithm a, the transporter node 202e stores the splicing algorithm identification information of splicing algorithm b, the carrier node 202h stores the splicing algorithm identification information of splicing algorithm c, and the supervisor node 202k stores the splicing algorithm identification information of splicing algorithm d.
[0041] Further, when the number of blocks in the blockchain reaches 10,000 or an integer multiple of 10,000, the block-producing node responsible for producing the corresponding block can switch the splicing algorithm. For example, currently, the number of blocks in the blockchain is 9,999, and the purchaser node 202c generates the 10,000th block. And the splicing algorithm adopted by each user node before this block production is splicing algorithm c. Therefore, when the purchaser node 202c generates the 10,000th block, it is necessary to switch the splicing algorithm. For example, the purchaser node 202c can use splicing algorithm a corresponding to the splicing algorithm identification information stored by itself as the subsequent splicing algorithm. And store the splicing algorithm identification information corresponding to splicing algorithm a in the 10,000th block, so that other user nodes can obtain the splicing algorithm identification information from the 10,000th block later, and use the splicing algorithm corresponding to the splicing algorithm identification information to splice the encrypted information. In addition, when the number of blocks in the blockchain reaches 20,000, according to the above principle, the block-producing node responsible for generating the 20,000th block uses the splicing algorithm corresponding to the splicing algorithm identification information stored by the block-producing node of this block as the subsequent splicing algorithm. For example, the 20,000th block is generated by the supervisor node 202k, so the supervisor node 202k writes the stored splicing algorithm identification information (that is, the splicing algorithm identification information of splicing algorithm d) into the 20,000th block, thus realizing the switching of the splicing algorithm in the blockchain system.
[0042] In the above operating environment, when a user node (for example, the supplier node 202b) performs encryption and splices the first encrypted information and the second encrypted information, it first obtains the splicing algorithm identification information from the specified data block. Among them, assuming that the number of blocks in the blockchain is 15,000, the supplier node 202b needs to obtain the splicing algorithm identification information (that is, the splicing algorithm identification information of splicing algorithm a) from the 10,000th block (corresponding to the specified data block), and then splice the first encrypted information and the second encrypted information according to the splicing algorithm corresponding to the splicing algorithm identification information. When the supplier node 202b performs encryption again and splices the generated first encrypted information and the second encrypted information after the number of blocks is greater than 20,000 (for example, the number of blocks is 25,000), it will obtain the splicing algorithm identification information of splicing algorithm d from the 20,000th block, so as to perform splicing using splicing algorithm d.
[0043] Among them, referring to Figure 4 As described above, the first encrypted information can be, for example, a string information composed of A1 A2 A3 A4, and the second encrypted information can be, for example, a string information composed of B1 B2 B3 B4. In this embodiment, the specific splicing methods of some splicing algorithms (such as splicing algorithm a, splicing algorithm b, splicing algorithm c, and splicing algorithm d) in multiple sets of splicing algorithms are exemplarily shown. Referring to Figure 4As shown, the splicing method of splicing algorithm a can be to directly splice the second encrypted information after the first encrypted information. After splicing the first encrypted information and the second encrypted information using splicing algorithm a, the spliced information obtained is a string information composed of A1 A2 A3 A4 B1 B2 B3 B4.
[0044] Among them, the splicing method of splicing algorithm b can be to first take the first string in the first encrypted information (i.e., A1), then take the first string in the second encrypted information (i.e., B1), and then sequentially and alternately take each string in the first encrypted information and the second encrypted information according to the sorting order of the strings, and re-sort them according to the order in which each string is taken. Refer to Figure 4 As shown, after splicing the first encrypted information and the second encrypted information using splicing algorithm b, the spliced information obtained is a string information composed of A1 B1 A2 B2 A3 B3 A4 B4.
[0045] Among them, the splicing method of splicing algorithm c can be to first randomly sort each string in the first encrypted information using a random number, and also randomly sort each string in the second encrypted information using another random number. Then, directly splice the second encrypted information after random sorting to the second encrypted information after random sorting. Refer to Figure 4 As shown, after splicing the first encrypted information and the second encrypted information using splicing algorithm c, the spliced information obtained is a string information composed of A1 A3 A4 A2 B4 B2 B3 B1. In addition, during the process of storing the splicing algorithm identification information corresponding to splicing algorithm c into the specified data block, the above two random numbers used can be stored into the specified data block together, so that the user can restore the original first encrypted information and the second encrypted information respectively according to these two random numbers.
[0046] Among them, the splicing method of splicing algorithm d can be to first directly splice the second encrypted information after the first encrypted information to obtain an initial spliced information, and then use a random number to randomly sort all the strings included in this initial spliced information to generate a randomly sorted spliced information. Refer to Figure 4 As shown, after splicing the first encrypted information and the second encrypted information using splicing algorithm d, the spliced information obtained is a string information composed of A1 B4 B1 A3 A4 B2 B3 A2. In addition, during the process of storing the splicing algorithm identification information corresponding to splicing algorithm d into the specified data block, the random number used can be stored into the specified data block together, so that the user can restore the original first encrypted information and the second encrypted information respectively according to this random number.
[0047] Thus, in this way, only the nodes in the blockchain system 200 can know the specific splicing algorithm. Even if a hacker intercepts the encrypted information and the public key, without knowing the splicing algorithm used, it is still impossible to obtain the specific cross-border trade data, improving the security of the cross-border trade data on the chain. Moreover, after a certain number of blocks in the blockchain are reached, the splicing algorithm can be randomly switched, further enhancing the security of the cross-border trade data on the chain.
[0048] Optionally, the method further includes: the blockchain system determines the current block-producing node from multiple pre-set nodes with block-producing qualifications, and the current block-producing node writes the spliced encrypted information and the splicing algorithm identification information into the blockchain in the blockchain system.
[0049] Specifically, as described above, the blockchain system 200 pre-sets multiple nodes with block-producing qualifications, such as the purchaser node 202c, the transporter node 202e, the carrier node 202h, and the supervisor node 202k. After the supplier node 202b broadcasts the spliced encrypted information in the blockchain system 200, the blockchain system 200 needs to determine the current block-producing node from the nodes with block-producing qualifications, that is, to determine the current block-producing node (for example, the transporter node 202e) from the purchaser node 202c, the transporter node 202e, the carrier node 202h, and the supervisor node 202k. The transporter node 202e writes the spliced encrypted information and the splicing algorithm identification information into the newly generated block and broadcasts the newly generated block in the blockchain system. This enables other user nodes to obtain the spliced encrypted information and the splicing algorithm identification information from the corresponding block in the blockchain, and then perform a de-splicing operation on the spliced encrypted information according to the splicing algorithm corresponding to the splicing algorithm identification information, so as to obtain the corresponding encrypted information, and obtain the final cross-border trade data based on the encrypted information. In this way, the security of the cross-border trade data on the chain is further improved.
[0050] In addition, optionally, the splicing algorithms are not limited to the above-described splicing algorithms a to d. For example, other known splicing algorithms may also be included, such as those that can be abbreviated as splicing algorithms e to h. Thus, each block-producing node can be provided with, for example, splicing algorithm identification information of multiple splicing algorithms. For example, the purchaser node 202c stores the splicing algorithm identification information of splicing algorithms a and b, the transporter node 202e stores the splicing algorithm identification information of splicing algorithms c and d, the carrier node 202h stores the splicing algorithm identification information of splicing algorithms e and f, and the supervisor node 202k stores the splicing algorithm identification information of splicing algorithms g and h. Thus, when a certain block-producing node needs to generate an integer multiple of ten thousand blocks, for example, one splicing algorithm can be selected from the set of multiple splicing algorithm identification information according to a preset rule and written into the generated block. In this way, the possibility of the splicing algorithm being cracked is further reduced, enhancing the security of encryption.
[0051] Optionally, the method further includes generating a specified data block through the following operations: The blockchain system determines, according to a preset consensus mechanism, a block-producing node corresponding to the specified data block from among a plurality of pre-set nodes with block-producing qualifications, and generates the specified data block and the write operation of related data through the block-producing node.
[0052] Specifically, referring to the above, the specified data block on the blockchain is, for example, the 30,000th block on the blockchain. In this embodiment, the 30,000th block is generated through the following operations: First, the blockchain system 200 determines, according to a preset consensus mechanism, a block-producing node corresponding to the 30,000th block (such as the carrier node 202h) from among a plurality of pre-set nodes with block-producing qualifications, and then generates the 30,000th block and the write operation of related data through the carrier node 202h.
[0053] In a preferred embodiment, the carrier node 202h writes relevant data into a specified data block through the following operations: The carrier node 202h first determines the block number of the specified data block, that is, determines whether the block number of the specified data block is thirty thousand. Then, the carrier node 202h selects a candidate splicing algorithm identification information from a plurality of preset candidate splicing algorithm identification information as the splicing algorithm identification information according to the block number. Assume that the splicing algorithm e and the splicing algorithm f are pre-stored on the carrier node 202h, and the splicing algorithm identification information corresponding to the splicing algorithm e and the splicing algorithm f is stored. At this time, the carrier node 202h first determines the switched splicing algorithm (such as the splicing algorithm f), and then stores the splicing algorithm identification information corresponding to the splicing algorithm f into the specified data block (that is, the thirtieth thousandth block). In this way, other user nodes can subsequently obtain the splicing algorithm identification information from the specified data block and splice the encrypted information by using the splicing algorithm corresponding to the splicing algorithm identification information.
[0054] In addition, referring to Figure 1 As shown, according to the second aspect of this embodiment, a storage medium is provided. The storage medium includes a stored program, wherein, when the program runs, the method described in any one of the above is executed by a processor.
[0055] It should be noted that, for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present invention is not limited by the described action sequence, because according to the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present invention.
[0056] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions for causing a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in various embodiments of the present invention.
[0057] Embodiment 2
[0058] Figure 5Fig. 0 shows a blockchain data encryption device 500 according to this embodiment, which is applied to a blockchain system for cross-border trade. The user nodes of the blockchain system pre-store a first encryption algorithm and a second encryption algorithm. The device 500 corresponds to the method described in the first aspect of Embodiment 1. Refer to Figure 5 As shown, the device 500 includes: a receiving module 510, configured to receive cross-border trade data related to cross-border trade operations; an encryption module 520, configured to use the first encryption algorithm and the second encryption algorithm to encrypt the cross-border trade data respectively, generating a first encrypted message and a second encrypted message; a splicing module 530, configured to splice the first encrypted message and the second encrypted message to obtain a spliced encrypted message after splicing; and a broadcasting module 540, configured to broadcast the spliced encrypted message in the blockchain system.
[0059] Optionally, the first encryption algorithm includes a first public key and a first private key, and the second encryption algorithm includes a second public key and a second private key. The encryption module 520 includes: an encryption sub-module, configured to use the first public key and the second public key to encrypt the cross-border trade data respectively, generating a first encrypted message and a second encrypted message, such that a node having the first private key can use the first private key to decrypt the first encrypted message, or a node having the second private key can use the second private key to decrypt the second encrypted message.
[0060] Optionally, the splicing module 530 includes: an access sub-module, configured to access a specified data block of the blockchain set in the blockchain system; an obtaining sub-module, configured to obtain splicing algorithm identification information from the specified data block; and a splicing sub-module, configured to splice the first encrypted message and the second encrypted message according to the splicing algorithm corresponding to the splicing algorithm identification information.
[0061] Optionally, the device 500 further includes: a determination module, configured to determine a current block-producing node from a plurality of pre-set nodes eligible for block production, and the current block-producing node writes the spliced encrypted message and the splicing algorithm identification information into the blockchain in the blockchain system.
[0062] Optionally, the device 500 further includes a generation module, configured to generate a specified data block. The generation module includes a determination sub-module, configured to determine a block-producing node corresponding to the specified data block from a plurality of pre-set nodes eligible for block production according to a preset consensus mechanism, and generate the specified data block and the write operation of related data through the block-producing node.
[0063] Optionally, the device 500 further includes a writing module, configured to write relevant data into a specified data block by performing the following operations: determining the block number of the specified data block; selecting, according to the block number, one piece of candidate splicing algorithm identification information from a plurality of preset candidate splicing algorithm identification information as the splicing algorithm identification information; and writing the splicing algorithm identification information into the specified data block.
[0064] Thus, according to this embodiment, the device 500 first receives cross-border trade data related to cross-border trade operations, and then uses a first encryption algorithm and a second encryption algorithm to encrypt the cross-border trade data respectively, generating a first encrypted message and a second encrypted message. The first encryption algorithm and the second encryption algorithm are encryption algorithms that conform to different encryption standards respectively. Then, the first encrypted message and the second encrypted message are spliced to obtain a spliced encrypted message after splicing. Finally, the spliced encrypted message is broadcast in the blockchain system. Other user nodes in the blockchain system can obtain the spliced encrypted message from the blockchain, and then, according to the encryption standards they adopt, obtain the encrypted message encrypted by using the encryption algorithm that conforms to their respective adopted encryption standards from the spliced encrypted message, and decrypt the obtained encrypted message to obtain the corresponding cross-border trade data. Thus, in this way, in the process of cross-border trade based on blockchain, all parties participating in the cross-border trade can, while maintaining the privacy of cross-border trade data, also select different encryption standards according to actual needs. Furthermore, it solves the technical problem in the prior art that in the process of cross-border trade based on blockchain, how to ensure that all parties participating in the cross-border trade can select different encryption standards according to actual needs while maintaining the privacy of cross-border trade data.
[0065] Embodiment 3
[0066] Figure 6 Fig. shows a blockchain-based data encryption device 600 according to this embodiment, which is applied to a blockchain system for cross-border trade. The user nodes of the blockchain system pre-store a first encryption algorithm and a second encryption algorithm, and the device 600 corresponds to the method described in the first aspect of Embodiment 1. Refer to Figure 6 As shown, the device 600 includes: a processor 610; and a memory 620, connected to the processor 610, for providing instructions for the processor 610 to perform the following processing steps: receiving cross-border trade data related to cross-border trade operations; using a first encryption algorithm and a second encryption algorithm to encrypt the cross-border trade data respectively, generating a first encrypted message and a second encrypted message; splicing the first encrypted message and the second encrypted message to obtain a spliced encrypted message after splicing; and broadcasting the spliced encrypted message in the blockchain system.
[0067] Optionally, the first encryption algorithm includes a first public key and a first private key, the second encryption algorithm includes a second public key and a second private key, and the operations of encrypting cross-border trade data using the first encryption algorithm and the second encryption algorithm respectively to generate first encrypted information and second encrypted information include: encrypting the cross-border trade data using the first public key and the second public key respectively to generate the first encrypted information and the second encrypted information, so that a node having the first private key can decrypt the first encrypted information using the first private key, or a node having the second private key can decrypt the second encrypted information using the second private key.
[0068] Optionally, the operation of splicing the first encrypted information and the second encrypted information includes: accessing a specified data block of the blockchain set in the blockchain system; obtaining splicing algorithm identification information from the specified data block; and splicing the first encrypted information and the second encrypted information according to the splicing algorithm corresponding to the splicing algorithm identification information.
[0069] Optionally, the memory 620 is further configured to provide instructions for the processor 610 to process the following processing steps: determining a current block-producing node from a plurality of pre-set nodes eligible for block production, and writing the spliced encrypted information and the splicing algorithm identification information into the blockchain in the blockchain system by the current block-producing node.
[0070] Optionally, the memory 620 is further configured to provide instructions for the processor 610 to process the following processing steps: generating a specified data block through the following operations: determining a block-producing node corresponding to the specified data block from a plurality of pre-set nodes eligible for block production according to a preset consensus mechanism, and generating the specified data block and the write operation of related data by the block-producing node.
[0071] Optionally, the memory 620 is further configured to provide instructions for the processor 610 to process the following processing steps: writing related data into the specified data block through the following operations: determining the block number of the specified data block; selecting a candidate splicing algorithm identification information from a plurality of pre-set candidate splicing algorithm identification information according to the block number as the splicing algorithm identification information; and writing the splicing algorithm identification information into the specified data block.
[0072] Thus, according to this embodiment, the device 600 first receives cross-border trade data related to cross-border trade operations, and then uses a first encryption algorithm and a second encryption algorithm to encrypt the cross-border trade data respectively, generating a first encrypted message and a second encrypted message. The first encryption algorithm and the second encryption algorithm are encryption algorithms that conform to different encryption standards respectively. Then, the first encrypted message and the second encrypted message are concatenated to obtain a concatenated encrypted message after concatenation. Finally, the concatenated encrypted message is broadcast in the blockchain system. Other user nodes in the blockchain system can obtain the concatenated encrypted message from the blockchain, and then according to the encryption standards they adopt, obtain the corresponding encrypted message encrypted by using the encryption algorithm that conforms to their adopted encryption standards from the concatenated encrypted message, and decrypt the obtained encrypted message to obtain the corresponding cross-border trade data. Thus, in this way, in the process of cross-border trade based on blockchain, all parties involved in cross-border trade can, while maintaining the privacy of cross-border trade data, also select different encryption standards according to actual needs. Furthermore, it solves the technical problem in the prior art that in the process of cross-border trade based on blockchain, how to ensure that all parties involved can select different encryption standards according to actual needs while maintaining the privacy of cross-border trade data.
[0073] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.
[0074] In the above embodiments of the present invention, the descriptions of the respective embodiments have their own emphases. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0075] In several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of units or modules can be in an electrical or other form.
[0076] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0077] In addition, in each embodiment of the present invention, each functional unit may be integrated into one processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit. The above integrated unit may be implemented in the form of hardware or in the form of a software functional unit.
[0078] If the above integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it may be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, may be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present invention. The foregoing storage medium includes: various media such as USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs that can store program codes.
[0079] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A data encryption method based on blockchain, which is applied to a blockchain system for cross-border trade. The blockchain system includes a blockchain, multiple computing devices, and multiple user nodes. Each participant in the cross-border trade operates and maintains the corresponding user node. The multiple computing devices are the computing devices of different participants and are associated with their respective user nodes. Among them, the user nodes of the blockchain system pre-store a first encryption algorithm and a second encryption algorithm, and it is characterized in that, Including: The first user node of the blockchain system receives cross-border trade data related to cross-border trade operations. The first user node uses the first encryption algorithm and the second encryption algorithm to encrypt the cross-border trade data respectively, generating first encrypted information and second encrypted information. The first user node accesses a specified data block of the blockchain set in the blockchain system. The first user node obtains splicing algorithm identification information from the specified data block. The first user node splices the first encrypted information and the second encrypted information according to the splicing algorithm corresponding to the splicing algorithm identification information, obtaining spliced encrypted information after splicing. The first user node broadcasts the spliced encrypted information in the blockchain system, and writes the spliced encrypted information into a preset blockchain through the blockchain system. The second user node of the blockchain system obtains the spliced encrypted information from the blockchain, selects one of the first encrypted information and the second encrypted information as target encrypted information from the spliced encrypted information, and decrypts the target encrypted information to obtain corresponding cross-border trade data; wherein, the target encrypted information is encrypted information obtained by encrypting the cross-border trade data using an encryption algorithm that conforms to the encryption standard adopted by the second user node itself.
2. The method according to claim 1, wherein The first encryption algorithm includes a first public key and a first private key, the second encryption algorithm includes a second public key and a second private key, and the operations of using the first encryption algorithm and the second encryption algorithm to encrypt the cross-border trade data respectively, generating first encrypted information and second encrypted information, include: Using the first public key and the second public key to encrypt the cross-border trade data respectively, generating the first encrypted information and the second encrypted information, such that a node having the first private key can decrypt the first encrypted information using the first private key, or a node having the second private key can decrypt the second encrypted information using the second private key.
3. The method according to claim 1, wherein Also including: The blockchain system determines a current block-producing node from a plurality of pre-set nodes having block-producing qualifications, and the current block-producing node writes the spliced encrypted information and the splicing algorithm identification information into the blockchain in the blockchain system.
4. The method according to claim 1, wherein Also including generating the specified data block through the following operations: The blockchain system determines a block-producing node corresponding to the specified data block from a plurality of pre-set nodes having block-producing qualifications according to a preset consensus mechanism, and generates the specified data block and the write operation of related data through the block-producing node.
5. The method according to claim 4, wherein The block-producing node writes the related data into the specified data block through the following operations: The block-producing node determines the block number of the specified data block. The block-producing node selects a candidate splicing algorithm identification information from a plurality of pre-set candidate splicing algorithm identification information as the splicing algorithm identification information according to the block number; and The block-producing node writes the splicing algorithm identification information into the specified data block.
6. A storage medium, characterized in that, The storage medium includes a stored program, wherein the method according to any one of claims 1 to 5 is executed by a processor when the program runs.
7. A data encryption device based on blockchain, which is applied to a blockchain system for cross-border trade. The blockchain system includes a blockchain, multiple computing devices, and multiple user nodes. Each participating party in the cross-border trade operates and maintains a corresponding user node. The multiple computing devices are computing devices of different participating parties and are associated with their respective user nodes. Among them, the user nodes of the blockchain system pre-store a first encryption algorithm and a second encryption algorithm, and it is characterized in that, Comprising: a receiving module, configured to receive cross-border trade data related to cross-border trade operations; an encryption module, configured to respectively encrypt the cross-border trade data by using the first encryption algorithm and the second encryption algorithm to generate first encrypted information and second encrypted information; a splicing module, configured to access a specified data block of a blockchain disposed in the blockchain system; obtain splicing algorithm identification information from the specified data block; and splice the first encrypted information and the second encrypted information according to a splicing algorithm corresponding to the splicing algorithm identification information to obtain spliced and encrypted information after splicing; a broadcasting module, configured to broadcast the spliced and encrypted information in the blockchain system, and write the spliced and encrypted information into a preset blockchain through the blockchain system; a decryption module, configured to obtain the spliced and encrypted information from the blockchain, obtain one of the first encrypted information and the second encrypted information as target encrypted information from the spliced and encrypted information, and decrypt the target encrypted information to obtain corresponding cross-border trade data; wherein the target encrypted information is encrypted information obtained by encrypting the cross-border trade data by using an encryption algorithm that conforms to the encryption standard adopted by the user node itself.
8. The device according to claim 7, characterized in that, The first encryption algorithm includes a first public key and a first private key, the second encryption algorithm includes a second public key and a second private key, and the encryption module includes: an encryption sub-module, configured to respectively encrypt the cross-border trade data by using the first public key and the second public key to generate the first encrypted information and the second encrypted information, so that a node having the first private key can decrypt the first encrypted information by using the first private key, or a node having the second private key can decrypt the second encrypted information by using the second private key.
9. A data encryption device based on blockchain, which is applied to a blockchain system for cross-border trade. The blockchain system includes a blockchain, multiple computing devices, and multiple user nodes. Each participant in cross-border trade operates and maintains a corresponding user node. The multiple computing devices are the computing devices of different participants and are associated with their respective user nodes. Among them, the user nodes of the blockchain system pre-store a first encryption algorithm and a second encryption algorithm, and it is characterized in that, Comprising: a processor; and a memory, connected to the processor, configured to provide instructions for the processor to perform the following processing steps: receive cross-border trade data related to cross-border trade operations; respectively encrypt the cross-border trade data by using the first encryption algorithm and the second encryption algorithm to generate first encrypted information and second encrypted information; access a specified data block of a blockchain disposed in the blockchain system; obtain splicing algorithm identification information from the specified data block; and splice the first encrypted information and the second encrypted information according to a splicing algorithm corresponding to the splicing algorithm identification information to obtain spliced and encrypted information after splicing; broadcast the spliced and encrypted information in the blockchain system, and write the spliced and encrypted information into a preset blockchain through the blockchain system; Obtain the spliced encrypted information from the blockchain, obtain one of the first encrypted information and the second encrypted information from the spliced encrypted information as the target encrypted information, and decrypt the target encrypted information to obtain the corresponding cross-border trade data; wherein, the target encrypted information is the encrypted information obtained by encrypting the cross-border trade data using an encryption algorithm that conforms to the encryption standard adopted by the user node itself.
Citation Information
Patent Citations
Information encryption processing method, server, terminal, equipment and storage medium
CN111191255A
Data encryption method and device, data decryption method and device, equipment and storage medium
CN111199047A
Monitoring management method and system
CN111275274A