Encryption Method and Device for Privacy Data, Processor, and Electronic Device

By adopting the threshold homomorphic encryption method of distributed keys in the blockchain system and using smart contracts to encrypt and decrypt private data, the problem of poor encryption effect in the existing homomorphic encryption technology in blockchain is solved, and data security and reliability are improved.

CN114978490BActive Publication Date: 2025-07-18INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210493613.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-05-07
Publication Date
2025-07-18
Estimated Expiration
2042-05-07

AI Technical Summary

Technical Problem

The existing homomorphic encryption technology is poor in the encryption of private data in blockchain and poses security risks, especially due to inconvenience and security risks caused by single-key encryption and non-computable ciphertexts.

Method used

The threshold homomorphic encryption method of distributed keys is adopted. By generating distributed keys, including public keys and partial private keys, in the blockchain system, and using smart contracts in the blockchain nodes for threshold homomorphic encryption and decryption, ensuring that only participants who exceed the threshold can decrypt the data.

Benefits of technology

It improves the encryption effect of private data in blockchain, reduces dependence on trusted homomorphic encryption key computing centers, reduces risks in key interaction, and ensures the security and reliability of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114978490B_ABST
    Figure CN114978490B_ABST
Patent Text Reader

Abstract

The present application discloses an encryption method and device for private data, a processor, and an electronic device, relating to the field of blockchain. The method is applied in a blockchain system, where the blockchain system includes at least one blockchain node, and at least one of the at least one blockchain node includes multiple smart contracts for processing private data, and includes: obtaining a target smart contract set from at least one blockchain node; generating a distributed key according to the multiple smart contracts in the target smart contract set; and performing threshold homomorphic encryption on the private data by using at least one smart contract in the target smart contract set in combination with the public key in the distributed key. Through the present application, the problem in the related art that the encryption effect of private data in the blockchain is poor due to the use of homomorphic encryption technology to encrypt the private data in the blockchain is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of blockchain, and in particular, to a method and device for encrypting private data, a processor, and an electronic device. Background Technique

[0002] In the current related technologies, combining blockchain with homomorphic encryption is one of the means to enable blockchain to support private transactions. Among them, homomorphic encryption technology is also an important one in privacy computing technologies. However, most of the existing homomorphic encryptions are single-key encryptions, that is, there is only one private key, and the ciphertexts encrypted by different public keys cannot be calculated with each other, which brings many inconveniences and security risks to the application of homomorphic encryption in privacy computing.

[0003] Moreover, the inconveniences brought by the application of homomorphic encryption in privacy computing are manifested in that before homomorphic encryption calculation, in order for each participating party in homomorphic encryption to obtain the same homomorphic encryption public key, each participating party in homomorphic encryption needs to interact with a trusted homomorphic encryption key calculation center to obtain the public and private keys of homomorphic encryption. And generally, this homomorphic encryption key calculation center is not any participating party in homomorphic calculation, but a trusted third party.

[0004] In addition, the security risks brought by the application of homomorphic encryption in privacy computing are manifested in that once a malicious participating party in the network intercepts the public and private keys of homomorphic encryption, it can easily decrypt or tamper with the homomorphic calculation result.

[0005] Aiming at the problem that the encryption effect of private data in the blockchain is not good when using homomorphic encryption technology in the related technologies, no effective solution has been proposed yet. Summary of the Invention

[0006] The main purpose of the present application is to provide a method and device for encrypting private data, a processor, and an electronic device, so as to solve the problem that the encryption effect of private data in the blockchain is not good when using homomorphic encryption technology in the related technologies.

[0007] To achieve the above object, according to one aspect of the present application, an encryption method for private data is provided. The method is applied in a blockchain system, and the blockchain system includes at least one blockchain node, and the at least one blockchain node includes at least a plurality of smart contracts for processing private data, including: obtaining a target smart contract set from the at least one blockchain node, where the target smart contract set includes a plurality of smart contracts for encrypting and decrypting private data in the blockchain system; generating a distributed key according to the plurality of smart contracts in the target smart contract set, where the distributed key at least includes: a public key for encrypting the private data and a partial private key for decrypting the private data; combining the public key in the distributed key, and using at least one smart contract in the target smart contract set to perform threshold homomorphic encryption on the private data, where the at least one smart contract is determined from the target smart contract set according to a verifiable random function in the blockchain system.

[0008] Further, after combining the public key in the distributed key and using at least one smart contract in the target smart contract set to perform threshold homomorphic encryption on the private data, the method further includes: obtaining a plurality of ciphertexts, where the plurality of ciphertexts are ciphertexts obtained by performing threshold homomorphic encryption on the private data; using a first smart contract to perform homomorphic calculation on the plurality of ciphertexts to obtain a calculation result, where the first smart contract is a smart contract determined according to the verifiable random function for calculating the private data; combining a target number of the partial private keys, and using the at least one smart contract to decrypt the calculation result to obtain a decryption result, where the target number is determined according to the threshold of the parties participating in the private data; and providing the decryption result to a requester who has been authorized to request access to the private data.

[0009] Further, after obtaining the target smart contract set from the at least one blockchain node and before generating a distributed key according to the plurality of smart contracts in the target smart contract set, the method further includes: obtaining the identity information of a plurality of private data providers in the blockchain system; determining the correspondence between the identity of each private data provider and each smart contract in the target smart contract set; and registering the correspondence in the blockchain system.

[0010] Further, after registering the corresponding relationship into the blockchain system, the method further includes: obtaining authorization information of the multiple privacy data providers, where the authorization information at least includes: identity information of the authorizer, identity information of the authorized party, smart contracts already registered by the authorizer in the blockchain system, and signature information of the authorizer; and recording the authorization information into the blockchain system.

[0011] Further, before generating a distributed key according to multiple smart contracts in the target smart contract set, the method further includes: determining whether the distributed key exists in the blockchain system; if the distributed key exists in the blockchain system, obtaining the distributed key; if the distributed key does not exist in the blockchain system, generating the distributed key according to multiple smart contracts in the target smart contract set.

[0012] Further, before determining whether the distributed key exists in the blockchain system, the method further includes: determining, according to the authorization information, whether the provider of the privacy data has authorized the requester to access the privacy data; if the provider of the privacy data has authorized the requester to access the privacy data, triggering a first request message, where the first request message is used to request to invoke at least one smart contract in the target smart contract set; in response to the first request message, invoking the at least one smart contract, and determining whether the distributed key exists in the blockchain system; if the provider of the privacy data has not authorized the requester to access the privacy data, triggering a first prompt message, where the first prompt message is used to prompt the requester that the privacy data cannot be accessed.

[0013] Further, before determining whether the provider of the privacy data has authorized the requester to access the privacy data according to the authorization information, the method further includes: obtaining target transaction parameters and a second smart contract, where the second smart contract is used to process data other than the privacy data in the blockchain system; determining, according to the target transaction parameters, a processing flow for the second smart contract to process data; determining whether the processing flow involves the privacy data; in the case where the processing flow involves the privacy data, triggering a second request message, where the second request message is used to request a cross-contract call operation, and the second request message at least includes: the identity information of the requester, the identity information of at least one provider of the privacy data, and a query condition for the privacy data; responding to the second request message, performing a cross-contract call operation, and determining whether the provider of the privacy data has authorized the requester to access the privacy data according to the authorization information; in the case where the processing flow does not involve the privacy data, triggering a second prompt message, where the second prompt message is used to prompt that the second smart contract does not involve the privacy data.

[0014] To achieve the above object, according to another aspect of the present application, there is provided an encryption device for privacy data. The device is applied in a blockchain system, and the blockchain system includes at least one blockchain node, and at least a plurality of smart contracts for processing privacy data are included in the at least one blockchain node, including: a first obtaining unit, configured to obtain a target smart contract set from the at least one blockchain node, where the target smart contract set includes a plurality of smart contracts for encrypting and decrypting privacy data in the blockchain system; a first generating unit, configured to generate a distributed key according to the plurality of smart contracts in the target smart contract set, where the distributed key at least includes: a public key for encrypting the privacy data and a partial private key for decrypting the privacy data; a first encrypting unit, configured to perform threshold homomorphic encryption on the privacy data by using at least one smart contract in the target smart contract set in combination with the public key in the distributed key, where the at least one smart contract is determined from the target smart contract set according to a verifiable random function in the blockchain system.

[0015] Further, the device further includes: a second obtaining unit, configured to obtain a plurality of ciphertexts after performing threshold homomorphic encryption on the privacy data by using at least one smart contract in the target smart contract set in combination with the public key in the distributed key, where the plurality of ciphertexts are ciphertexts obtained by performing threshold homomorphic encryption on the privacy data; a first computing unit, configured to perform homomorphic computation on the plurality of ciphertexts by using a first smart contract to obtain a computation result, where the first smart contract is a smart contract determined according to the verifiable random function and used for computing the privacy data; a first decryption unit, configured to decrypt the computation result by using the at least one smart contract in combination with a target number of the partial private keys to obtain a decryption result, where the target number is determined according to the threshold of the parties involved in the privacy data; and a first providing unit, configured to provide the decryption result to a requester authorized to request access to the privacy data.

[0016] Further, the device further includes: a third obtaining unit, configured to obtain the identity information of a plurality of privacy data providers in the blockchain system after obtaining the target smart contract set from the at least one blockchain node and before generating a distributed key according to a plurality of smart contracts in the target smart contract set; a first determining unit, configured to determine the correspondence between the identity of each privacy data provider and each smart contract in the target smart contract set; and a first registering unit, configured to register the correspondence in the blockchain system.

[0017] Further, the device further includes: a fourth obtaining unit, configured to obtain the authorization information of the plurality of privacy data providers after registering the correspondence in the blockchain system, where the authorization information at least includes: the identity information of the authorizer, the identity information of the authorizee, the smart contracts already registered by the authorizer in the blockchain system, and the signature information of the authorizer; and a first recording unit, configured to record the authorization information in the blockchain system.

[0018] Further, the device further includes: a first judging unit, configured to judge whether there is a distributed key in the blockchain system before generating a distributed key according to a plurality of smart contracts in the target smart contract set; a fifth obtaining unit, configured to obtain the distributed key if the distributed key exists in the blockchain system; and a second generating unit, configured to generate the distributed key according to a plurality of smart contracts in the target smart contract set if the distributed key does not exist in the blockchain system.

[0019] Further, the device further includes: a second determination unit, configured to determine whether the provider of the privacy data has authorized the requester to access the privacy data according to the authorization information before determining whether there is the distributed key in the blockchain system; a first trigger unit, configured to trigger a first request message when the provider of the privacy data has authorized the requester to access the privacy data, where the first request message is used to request to call at least one smart contract in the target smart contract set; a first response unit, configured to respond to the first request message, call the at least one smart contract, and determine whether there is the distributed key in the blockchain system; a second trigger unit, configured to trigger a first prompt message when the provider of the privacy data has not authorized the requester to access the privacy data, where the first prompt message is used to prompt that the requester cannot access the privacy data.

[0020] Further, the device further includes: a sixth acquisition unit, configured to acquire target transaction parameters and a second smart contract before determining whether the provider of the privacy data has authorized the requester to access the privacy data according to the authorization information, where the second smart contract is used to process data other than the privacy data in the blockchain system; a second determination unit, configured to determine a processing flow for the second smart contract to process data according to the target transaction parameters; a third determination unit, configured to determine whether the processing flow involves the privacy data; a third trigger unit, configured to trigger a second request message when the processing flow involves the privacy data, where the second request message is used to request a cross-contract call operation, and the second request message at least includes: the identity information of the requester, the identity information of at least one provider of the privacy data, and a query condition for the privacy data; a second response unit, configured to respond to the second request message, perform a cross-contract call operation, and determine whether the provider of the privacy data has authorized the requester to access the privacy data according to the authorization information; a fourth trigger unit, configured to trigger a second prompt message when the processing flow does not involve the privacy data, where the second prompt message is used to prompt that the second smart contract does not involve the privacy data.

[0021] To achieve the above object, according to another aspect of the present application, there is provided a processor, where the processor is used to run a program, and when the program runs, it executes the encryption method for privacy data described in any one of the above.

[0022] To achieve the above object, according to another aspect of the present application, there is provided an electronic device, which includes one or more processors and a memory for storing one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors implement the encryption method of the privacy data described in any one of the above.

[0023] By applying the present application in a blockchain system, the blockchain system includes at least one blockchain node, and at least one blockchain node includes at least a plurality of smart contracts for processing privacy data. The following steps are adopted: obtaining a target set of smart contracts from at least one blockchain node, where the target set of smart contracts includes a plurality of smart contracts for encrypting and decrypting privacy data in the blockchain system; generating a distributed key based on the plurality of smart contracts in the target set of smart contracts, where the distributed key at least includes: a public key for encrypting privacy data and a partial private key for decrypting privacy data; combining the public key in the distributed key, and using at least one smart contract in the target set of smart contracts to perform threshold homomorphic encryption on the privacy data, where the at least one smart contract is determined from the target set of smart contracts according to a verifiable random function in the blockchain system. This solves the problem in the related art that when using the homomorphic encryption technology to encrypt the privacy data in the blockchain, the encryption effect of the privacy data in the blockchain is not good. By generating a distributed key based on the plurality of smart contracts obtained from at least one blockchain node in the target set of smart contracts, and combining the public key in the distributed key, and using at least one smart contract in the target set of smart contracts, the privacy data in the blockchain system is thus subjected to threshold homomorphic encryption, thereby improving the encryption effect of the privacy data in the blockchain. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] The drawings constituting a part of the present application are used to provide a further understanding of the present application. The schematic embodiments and descriptions thereof of the present application are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:

[0025] Figure 1 is a schematic diagram of the network structure of a blockchain system supporting threshold homomorphic encryption of privacy data in an embodiment of the present application;

[0026] Figure 2 is a schematic diagram of a functional module for processing privacy data supporting threshold homomorphic encryption in an embodiment of the present application;

[0027] Figure 3 is a flowchart of an encryption method for privacy data provided according to an embodiment of the present application;

[0028] Figure 4It is a flowchart of the registration of the blockchain privacy data provider and the privacy data encryption and decryption smart contract set information in the embodiment of the present application;

[0029] Figure 5 It is a flowchart of the authorization information update of the blockchain privacy data provider in the embodiment of the present application;

[0030] Figure 6 It is a flowchart of the processing method for the blockchain general data processing smart contract to query privacy data in the embodiment of the present application;

[0031] Figure 7 It is a flowchart of an optional encryption method for privacy data provided according to the embodiment of the present application;

[0032] Figure 8 It is a schematic diagram of an encryption device for privacy data provided according to the embodiment of the present application;

[0033] Figure 9 It is a schematic diagram of an electronic device provided according to the embodiment of the present application. Detailed implementation manners

[0034] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other. The present application will be described in detail below with reference to the drawings and in combination with the embodiments.

[0035] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0036] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so as to describe the embodiments of the present application here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0037] It should be noted that the relevant information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties. For example, an interface is set between this system and the relevant user or organization. Before obtaining relevant information, it is necessary to send an acquisition request to the aforementioned user or organization through the interface, and obtain relevant information after receiving the consent information fed back by the aforementioned user or organization.

[0038] For the convenience of description, some nouns or terms involved in the embodiments of the present application are explained below:

[0039] Homomorphic encryption: a cryptographic technology based on the computational complexity theory of mathematical problems. In simple terms, "after data is homomorphically encrypted, the ciphertext can be directly operated, and the ciphertext result after the operation is decrypted is equivalent to the result of the same operation on the corresponding plaintext data." Its significance lies in the fundamental solution to the problem of privacy data confidentiality when entrusting data and its operations to a third party.

[0040] Threshold homomorphic encryption: supports multiple private keys, which are distributed to each participant holding private data. Each participant actually holds only a part of the complete private key. Each participant providing private data can independently calculate the homomorphic encryption result. Any entity can use the data of each participant for homomorphic calculation. If the calculated result needs to be decrypted, at least more than the threshold number of participants holding private keys are required to participate in the decryption.

[0041] Verifiable random function: In order to obtain a random number that can be verified by the entire network in a distributed system, a verifiable random function is generally used. It can be said to be a combination of hash function and asymmetric encryption. In order to prevent the message from being tampered with, a message verification code is generally added to the source of the message related to the calculation of the random number.

[0042] The present invention is described below in conjunction with preferred implementation steps. Figure 1 is a schematic diagram of the network structure of a blockchain system supporting threshold homomorphic encryption of private data in an embodiment of the present application, such as Figure 1As shown in the figure, a blockchain system that supports threshold homomorphic encryption of private data includes: blockchain node 11, general data processing smart contract 12, general data storage 13, private data processing smart contract 14, private data storage 15, and cross-contract call device 16. Among them, the general data processing smart contract 12, general data storage 13, private data processing smart contract 14, private data storage 15, and cross-contract call device 16 are all part of the blockchain node 11. Moreover, the general data processing smart contract 12 and the general data storage 13 are directly interconnected, the private data processing smart contract 14 and the private data storage 15 are directly interconnected, and there is no direct communication between the general data processing smart contract 12 and the private data storage 15, which can ensure that private data will not be illegally read.

[0043] Specifically, the blockchain node 11 refers to a software program with basic blockchain functions connected to the blockchain system. One blockchain node can occupy a single hardware server alone, or multiple blockchain nodes can share a single hardware server.

[0044] The general data processing smart contract 12 means that some smart contract business data of the blockchain users is publicly transparent, and such general data is open for query by all blockchain users.

[0045] The general data storage 13 refers to the data generated by the general data processing smart contract. When storing, it does not use the identity of the data owner for special privacy encryption processing and can be used for query by the general data processing smart contract.

[0046] The private data processing smart contract 14 means that some smart contract business data of the blockchain users is sensitive and private. Such private data is only open for query by the smart contract whose identity is the private data owner. To support private data services, in addition to the general data processing smart contract, the blockchain node also needs to introduce a series of smart contracts or functional modules related to private data processing that support threshold homomorphic encryption, such as the private node registration system smart contract, private data encryption and decryption smart contract, private data calculation smart contract, and distributed key generation module for threshold homomorphic encryption.

[0047] The private data storage 15 refers to the data generated by the private data processing smart contract. When storing, it uses the identity of the data owner for special privacy encryption processing and only supports query and use by the data owner and those authorized by the owner.

[0048] The cross - contract call device 16 means that the privacy data processing smart contract supports returning the processed data for use by other smart contracts. The premise for other smart contracts to use privacy data is authorization by the privacy data owner. The authorization processing flow is integrated in the cross - contract call device, including the privacy data owner identity and privacy data encryption - decryption smart contract relationship module, the privacy data owner authorization module, etc.

[0049] Figure 2 It is a schematic diagram of a functional module for privacy data processing that supports threshold homomorphic encryption in an embodiment of this application. As Figure 2 shown, in addition to the conventional blockchain functions, the blockchain system needs to newly introduce several important functional modules. That is, a functional module for privacy data processing that supports threshold homomorphic encryption includes: the privacy node registration system smart contract 21, the privacy data encryption - decryption smart contract 22, the privacy data calculation smart contract 23, the verifiable random function module 24, the privacy data owner identity and privacy data encryption - decryption smart contract relationship module 25, and the privacy data owner authorization module 26.

[0050] Specifically, the privacy node registration system smart contract 21 means that each privacy data provider uses the privacy node registration system smart contract to register the privacy data provider identity and the privacy data encryption - decryption smart contract set information to the blockchain. Then each privacy data owner corresponds to multiple privacy data encryption - decryption smart contracts. When subsequent privacy data calculations involving this privacy data provider are carried out, only one smart contract will be selected from the set of privacy data encryption - decryption smart contracts registered by this user to participate in the privacy calculation.

[0051] The privacy data encryption - decryption smart contract 22 means that the privacy data encryption - decryption smart contracts of each privacy data owner are interconnected, and through negotiation, a distributed key for threshold homomorphic encryption is generated for interaction. This key is used for subsequent independent threshold homomorphic encryption by each privacy data encryption - decryption smart contract or for decrypting the homomorphic encryption result through collaborative calculation.

[0052] The privacy data calculation smart contract 23 is a type of system smart contract that collects the ciphertexts of homomorphic encryption from each participant and completes homomorphic calculations.

[0053] The verifiable random function module 24 means that the blockchain system randomly selects any registered privacy data encryption - decryption smart contract and privacy data calculation smart contract of the privacy data owner, and only the selected smart contract participates in the threshold homomorphic encryption and decryption and homomorphic calculation of privacy data. Since privacy data queries in the blockchain are all managed by the cross - contract call device, this module is integrated in the cross - contract call device.

[0054] The privacy data owner identity and privacy data encryption / decryption smart contract relationship module 25 means that a privacy data owner can own multiple privacy data encryption / decryption smart contracts for processing different or the same privacy data encryption / decryption. When a smart contract specifies that it will use the data of a certain privacy data owner, the corresponding privacy data encryption / decryption smart contract will be found according to this record.

[0055] The privacy data owner authorization module 26 means that the privacy data encryption / decryption smart contract only supports the use by the privacy data owner and the people authorized by the owner. Therefore, the authorization whitelist information of each privacy data owner is recorded in the cross-contract call device, and the access of non-whitelist smart contracts to privacy data-related smart contracts will be rejected.

[0056] Figure 3 It is a flowchart of the encryption method for privacy data provided by an embodiment of the present application. As Figure 3 shown, the method includes the following steps:

[0057] Step S301, obtain a target smart contract set from at least one blockchain node, where the target smart contract set includes multiple smart contracts for encrypting and decrypting privacy data in the blockchain system.

[0058] In this embodiment, the smart contracts for encrypting and decrypting privacy data of all privacy data owners in the blockchain system can be obtained.

[0059] Step S302, generate a distributed key based on multiple smart contracts in the target smart contract set, where the distributed key at least includes: a public key for encrypting privacy data and a partial private key for decrypting privacy data.

[0060] For example, the privacy data encryption / decryption smart contracts of the privacy data owners are interconnected, and jointly calculate to generate a distributed key for threshold homomorphic encryption. That is, the privacy data encryption / decryption smart contracts of each privacy data owner are interconnected, and through negotiation, they complete the interaction to generate a distributed key for threshold homomorphic encryption. And this key is used for each subsequent privacy data encryption / decryption smart contract to independently complete threshold homomorphic encryption, or to complete the decryption of the homomorphic encryption result through collaborative calculation.

[0061] Step S303, combine the public key in the distributed key, and use at least one smart contract in the target smart contract set to perform threshold homomorphic encryption on the privacy data, where the at least one smart contract is determined from the target smart contract set according to the verifiable random function in the blockchain system.

[0062] For example, using the distributed key, each privacy data encryption / decryption smart contract independently completes the threshold homomorphic encryption of the privacy data in the blockchain system.

[0063] Through the above steps S301 to S303, a distributed key is generated based on multiple smart contracts in the target smart contract set obtained from at least one blockchain node, and combined with the public key in the distributed key, at least one smart contract in the target smart contract set is used to perform threshold homomorphic encryption on the private data in the blockchain system, thereby improving the encryption effect of the private data in the blockchain.

[0064] Optionally, in the encryption method for private data provided in an embodiment of the present application, after combining the public key in the distributed key and using at least one smart contract in the target smart contract set to perform threshold homomorphic encryption on the private data, the method also includes: obtaining multiple ciphertexts, wherein the multiple ciphertexts are ciphertexts obtained by performing threshold homomorphic encryption on the private data; using a first smart contract to perform homomorphic calculations on the multiple ciphertexts to obtain calculation results, wherein the first smart contract is a smart contract for calculating the private data determined based on a verifiable random function; combining a target number of partial private keys and using at least one smart contract to decrypt the calculation results to obtain a decrypted result, wherein the target number is determined based on a threshold of the participants in the private data; and providing the decrypted result to a requester who has been authorized to request access to the private data.

[0065] For example, after each privacy data encryption and decryption smart contract independently completes the threshold homomorphic encryption, the encryption result is sent to the privacy data calculation smart contract for further calculation, and then the encryption calculation result is returned to each privacy data encryption and decryption smart contract, and the threshold homomorphic decryption is completed through collaborative calculation, and the calculation result is returned in plain text to the general data processing smart contract. Specifically, after the privacy data encryption and decryption smart contract completes the threshold homomorphic encryption, the encryption result is returned to the cross-contract calling device; the cross-contract calling device forwards the encryption result to the privacy data calculation smart contract according to the verifiable random function; then the privacy data calculation smart contract performs homomorphic calculation based on the ciphertext, and the calculation result is returned to the cross-contract calling device; the cross-contract calling device initiates a joint decryption calculation request for the threshold homomorphic encryption result to the relevant privacy data encryption and decryption smart contract; the privacy data encryption and decryption smart contract executes the threshold homomorphic encryption protocol, jointly calculates and decrypts the threshold homomorphic encryption result, and returns the decryption result to the cross-contract calling device; the cross-contract calling device returns the decryption result of the homomorphic calculation; the general data processing smart contract continues the subsequent processing according to the returned result.

[0066] In summary, before using threshold homomorphic encryption in blockchain, during the distributed key calculation phase, the private key used for homomorphic encryption is split into multiple blockchain nodes, and each blockchain node only holds a part of the key. For the result of homomorphic encryption, only when more than t blockchain nodes participate in the decryption calculation can the plaintext data be finally restored. Therefore, using threshold homomorphic encryption can eliminate the need for a trusted homomorphic encryption key calculation center, reducing the operating cost of introducing a homomorphic encryption key calculation center. At the same time, using the threshold homomorphic encryption protocol, each participating party automatically calculates and deploys the encryption key at the end of the protocol, reducing the cost for developers to manage the key and facilitating the interaction of homomorphic encryption public keys. Additionally, using threshold homomorphic encryption ensures that even if some blockchain nodes are compromised and the key shards are lost, it will not cause the paralysis of the privacy calculation function of the entire system. On the other hand, it ensures that when the number of blockchain nodes participating in homomorphic decryption is insufficient, the homomorphic ciphertext cannot be restored to plaintext, guaranteeing the security of the data in the blockchain system after using threshold homomorphic encryption. Moreover, using threshold homomorphic encryption can eliminate the need for a trusted homomorphic encryption key calculation center, reducing the risk of key leakage to a certain extent during the process of interacting the homomorphic encryption key between the homomorphic encryption key calculation center and the blockchain nodes.

[0067] Optionally, in the encryption method for privacy data provided in the embodiments of the present application, after obtaining the target smart contract set from at least one blockchain node and before generating a distributed key based on the multiple smart contracts in the target smart contract set, the method further includes: obtaining the identity information of multiple privacy data providers in the blockchain system; determining the correspondence between the identity of each privacy data provider and each smart contract in the target smart contract set; and registering the correspondence in the blockchain system.

[0068] Figure 4 It is a flowchart of the registration of the blockchain privacy data provider and the privacy data encryption and decryption smart contract set information in the embodiments of the present application. As Figure 4 shown, the process of registering the blockchain privacy data provider and the privacy data encryption and decryption smart contract set information involves the privacy node registration system smart contract and the cross-contract call device. When a new privacy data provider A is added to the blockchain network and privacy data provider A newly enables several privacy data encryption and decryption smart contracts S1, S2, and S3, the processing steps are as follows:

[0069] Step S401: The blockchain privacy data provider starts the privacy data encryption and decryption smart contracts S1, S2, and S3, calls the privacy node registration system smart contract, generates the registration information of the privacy data provider identity A and the privacy data encryption and decryption smart contract set [S1, S2, S3], and sends the registration information to the cross-contract call device.

[0070] Step S402: The cross - contract call device records the correspondence between the identity of the privacy data provider and the privacy data encryption and decryption smart contract. After the processing is completed, the privacy data encryption and decryption smart contracts S1, S2, and S3 only allow the smart contracts related to the privacy data provider to call.

[0071] Through the above - mentioned solution, the correspondence between the blockchain privacy data provider and the privacy data encryption and decryption smart contract set information can be quickly and accurately registered in the blockchain system, laying a foundation for subsequent encryption of blockchain privacy data.

[0072] Optionally, in the privacy data encryption method provided in the embodiments of the present application, after registering the correspondence in the blockchain system, the method further includes: obtaining the authorization information of multiple privacy data providers, where the authorization information at least includes: the identity information of the authorizer, the identity information of the authorizee, the smart contracts already registered by the authorizer in the blockchain system, and the signature information of the authorizer; recording the authorization information in the blockchain system.

[0073] Figure 5 It is a flowchart of the update of the authorization information of the blockchain privacy data provider in the embodiments of the present application. As Figure 5 shown, the process of updating the authorization information of the blockchain privacy data provider involves the privacy node registration system smart contract and the cross - contract call device. The processing steps for the privacy data provider A in the blockchain network to open its privacy data encryption and decryption smart contract S1 to a certain caller B are as follows:

[0074] Step S501: The privacy data provider calls the privacy node registration system smart contract to generate the authorization information of the privacy data provider. The parameters include the identity information of the authorizer A, the identity information of the authorizee B, the registered privacy data encryption and decryption smart contract S1 of A, and the signature of A. The authorization information is sent to the cross - contract call device.

[0075] Step S502: The cross - contract call device records the authorization information. After the processing is completed, the privacy data encryption and decryption smart contract S1 of the privacy data provider A allows A and B to call.

[0076] Through the above - mentioned solution, the blockchain privacy data provider can quickly and accurately authorize the callers of the privacy data in the blockchain, avoiding the leakage of blockchain privacy data.

[0077] Optionally, in the encryption method of privacy data provided in the embodiments of the present application, before determining whether the provider of the privacy data has authorized the requester to access the privacy data based on the authorization information, the method further includes: obtaining target transaction parameters and a second smart contract, where the second smart contract is used to process data other than privacy data in the blockchain system; determining a processing flow for the second smart contract to process data based on the target transaction parameters; determining whether the processing flow involves privacy data; in the case where the processing flow involves privacy data, triggering a second request message, where the second request message is used to request a cross-contract call operation, and the second request message at least includes: the identity information of the requester, the identity information of at least one provider of the privacy data, and the query condition of the privacy data; in response to the second request message, performing a cross-contract call operation, and determining whether the provider of the privacy data has authorized the requester to access the privacy data based on the authorization information; in the case where the processing flow does not involve privacy data, triggering a second prompt message, where the second prompt message is used to prompt that the second smart contract does not involve privacy data.

[0078] Figure 6 is a flowchart of a method for querying privacy data by a general data processing smart contract in an embodiment of the present application. As Figure 6 shown, the process of the method for querying privacy data by the general data processing smart contract in the blockchain network involves a general data processing smart contract, a cross-contract call device, a privacy data encryption / decryption smart contract, and a privacy data calculation smart contract. The processing steps for the general data processing smart contract in the blockchain network to execute the query of blockchain privacy data include:

[0079] Step S601: The general data processing smart contract receives transaction parameters and executes a general data processing flow.

[0080] Step S602: The general data processing smart contract determines whether the processing flow involves other people's privacy data. If it does not involve other people's privacy data, it executes S603; if it involves other people's privacy data, it executes S604.

[0081] Step S603: The general data processing flow does not involve other people's privacy data, and the processing ends.

[0082] Step S604: The general data processing flow involves other people's privacy data. A cross-contract call is requested from the cross-contract call device, and the parameters include the identity information of the requester, the identity information of the privacy data owner, the data query condition, etc., where the identity information of the privacy data owner may be one or more.

[0083] Through the above solution, it is possible to quickly and accurately determine whether the processing flow of general data involves privacy data.

[0084] Optionally, in the encryption method of privacy data provided in the embodiments of the present application, before determining whether there is a distributed key in the blockchain system, the method further includes: judging whether the provider of the privacy data has authorized the requester to access the privacy data according to the authorization information; in the case that the provider of the privacy data has authorized the requester to access the privacy data, triggering a first request message, where the first request message is used to request to call at least one smart contract in the target smart contract set; in response to the first request message, calling at least one smart contract, and judging whether there is a distributed key in the blockchain system; in the case that the provider of the privacy data has not authorized the requester to access the privacy data, triggering a first prompt message, where the first prompt message is used to prompt the requester that the privacy data cannot be accessed.

[0085] As Figure 6 shown, the steps of the processing method for the blockchain general data processing smart contract to query privacy data further include:

[0086] Step S605: The cross-contract call device judges whether the owner of the privacy data has authorized the requester to access the privacy data. If not, execute S606; if so, execute S607.

[0087] Step S606: The owner of the privacy data has not authorized the requester to access the privacy data, and the cross-contract call device rejects the request and returns.

[0088] Step S607: The owner of the privacy data has authorized the requester to access the privacy data, and the cross-contract call device forwards the privacy data query request to the privacy data encryption and decryption smart contract according to the verifiable random function.

[0089] Through the above solution, it is possible to quickly and accurately judge whether the provider of the privacy data has authorized the requester to access the privacy data, thereby protecting the security of the blockchain privacy data.

[0090] Optionally, in the encryption method of privacy data provided in the embodiments of the present application, before generating a distributed key according to multiple smart contracts in the target smart contract set, the method further includes: judging whether there is a distributed key in the blockchain system; in the case that there is a distributed key in the blockchain system, obtaining the distributed key; in the case that there is no distributed key in the blockchain system, generating a distributed key according to multiple smart contracts in the target smart contract set.

[0091] As Figure 6 shown, the steps of the processing method for the blockchain general data processing smart contract to query privacy data further include:

[0092] Step S608: The privacy data encryption and decryption smart contract judges whether there is already a key pair for threshold homomorphic encryption locally. If so, execute S610; otherwise, execute S609.

[0093] Step S609: The private data encryption and decryption smart contract does not have a threshold homomorphic encryption key pair locally, and executes the threshold homomorphic encryption protocol. The private data encryption and decryption smart contract completes the joint calculation to generate the threshold homomorphic encryption distributed key.

[0094] Step S610: The private data encryption and decryption smart contract has a local threshold homomorphic encryption key pair, and the key is loaded before encryption is performed.

[0095] Step S611: The privacy data encryption and decryption smart contract completes threshold homomorphic encryption locally, and the encryption result is returned to the cross-contract calling device.

[0096] Step S612: The cross-contract calling device forwards the encryption result to the private data computing smart contract based on the verifiable random function.

[0097] Step S613: The privacy data calculation smart contract performs homomorphic calculation based on the ciphertext, and returns the calculation result to the cross-contract calling device.

[0098] Step S614: The cross-contract calling device initiates a joint decryption calculation request for the threshold homomorphic encryption result to the relevant privacy data encryption and decryption smart contract.

[0099] Step S615: The privacy data encryption and decryption smart contract executes the threshold homomorphic encryption protocol, jointly calculates the result of the decryption threshold homomorphic encryption, and returns the decryption result to the cross-contract calling device.

[0100] Step S616: The cross-contract calling device returns the decryption result of the homomorphic computing.

[0101] Step S617: The general data processing smart contract continues subsequent processing based on the returned result.

[0102] Through the above scheme, it is possible to quickly and accurately determine whether there is a distributed key in the blockchain system, thereby ensuring that there is a distributed key in the blockchain system, and paving the way for the subsequent threshold homomorphic encryption of blockchain privacy data.

[0103] Figure 7 is a flowchart of an optional privacy data encryption method provided according to an embodiment of the present application, such as Figure 7 As shown, optional encryption methods for private data include:

[0104] In the preparation stage, the privacy data provider starts the privacy data encryption and decryption smart contract, executes the registration process of the privacy data provider's identity and the privacy data encryption and decryption smart contract collection information, records the registration information to the blockchain, executes the privacy data provider's privacy data encryption and decryption smart contract authorization process, and records the authorization information to the blockchain.

[0105] In the external service stage, the general data processing smart contract initiates a query for private data. Each private data owner corresponds to multiple private data encryption and decryption smart contracts. The cross-contract call device combines a verifiable random function to randomly select one from the set of private data encryption and decryption smart contracts of the private data provider and the private data computing system smart contract to participate in private data computing. The private data encryption and decryption smart contracts of the private data owner are interconnected to jointly calculate and generate a distributed key for threshold homomorphic encryption and independently execute threshold homomorphic encryption. The encryption result is sent to the private data computing smart contract for further calculation. The encrypted calculation result is returned to each private data encryption and decryption smart contract, and collaborative calculation is performed to complete threshold homomorphic decryption, and the plaintext of the calculation result is returned to the general data processing smart contract.

[0106] In summary, the encryption method for private data provided in the embodiments of the present application is applied in a blockchain system. The blockchain system includes at least one blockchain node, and at least one blockchain node includes at least multiple smart contracts for processing private data. By obtaining a target smart contract set from at least one blockchain node, where the target smart contract set includes multiple smart contracts for encrypting and decrypting private data in the blockchain system; generating a distributed key according to the multiple smart contracts in the target smart contract set, where the distributed key at least includes: a public key for encrypting private data and a partial private key for decrypting private data; combining the public key in the distributed key, and using at least one smart contract in the target smart contract set to perform threshold homomorphic encryption on the private data, where the at least one smart contract is a smart contract determined from the target smart contract set according to the verifiable random function in the blockchain system, which solves the problem that in the related art, using the homomorphic encryption technology to encrypt the private data in the blockchain results in poor encryption effect of the private data in the blockchain. By generating a distributed key according to the multiple smart contracts in the target smart contract set obtained from at least one blockchain node and combining the public key in the distributed key, and using at least one smart contract in the target smart contract set, the threshold homomorphic encryption of the private data in the blockchain system is performed, thereby improving the encryption effect of the private data in the blockchain.

[0107] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0108] The embodiment of the present application also provides an encryption device for private data. It should be noted that the encryption device for private data in the embodiment of the present application can be used to execute the encryption method for private data provided by the embodiment of the present application. The following introduces the encryption device for private data provided by the embodiment of the present application.

[0109] Figure 8 It is a schematic diagram of the encryption device for private data according to the embodiment of the present application. This device is applied in a blockchain system, and the blockchain system includes at least one blockchain node. At least one blockchain node includes at least multiple smart contracts for processing private data, such as Figure 8 As shown, the device includes: a first acquisition unit 801, a first generation unit 802, and a first encryption unit 803.

[0110] Specifically, the first acquisition unit 801 is configured to acquire a target smart contract set from at least one blockchain node, where the target smart contract set includes multiple smart contracts for encrypting and decrypting private data in the blockchain system;

[0111] The first generation unit 802 is configured to generate a distributed key based on multiple smart contracts in the target smart contract set, where the distributed key at least includes: a public key for encrypting private data and a partial private key for decrypting private data;

[0112] The first encryption unit 803 is configured to perform threshold homomorphic encryption on the private data by using at least one smart contract in the target smart contract set in combination with the public key in the distributed key, where the at least one smart contract is determined from the target smart contract set according to the verifiable random function in the blockchain system.

[0113] In summary, the encryption device for private data provided in the embodiments of the present application obtains a target smart contract set from at least one blockchain node through a first acquisition unit 801, where the target smart contract set includes multiple smart contracts for encrypting and decrypting private data in the blockchain system; a first generation unit 802 generates a distributed key according to the multiple smart contracts in the target smart contract set, where the distributed key at least includes: a public key for encrypting private data and a partial private key for decrypting private data; a first encryption unit 803 combines the public key in the distributed key and uses at least one smart contract in the target smart contract set to perform threshold homomorphic encryption on the private data, where the at least one smart contract is a smart contract determined from the target smart contract set according to a verifiable random function in the blockchain system, which solves the problem in the related art that the encryption effect of private data in the blockchain is poor when using the homomorphic encryption technology to encrypt the private data in the blockchain. By generating a distributed key according to the multiple smart contracts in the target smart contract set obtained from at least one blockchain node and combining the public key in the distributed key, at least one smart contract in the target smart contract set is used to perform threshold homomorphic encryption on the private data in the blockchain system, thereby improving the encryption effect of the private data in the blockchain.

[0114] Optionally, in the encryption device for private data provided in the embodiments of the present application, the device further includes: a second acquisition unit, configured to obtain multiple ciphertexts after performing threshold homomorphic encryption on the private data by using at least one smart contract in the target smart contract set in combination with the public key in the distributed key, where the multiple ciphertexts are ciphertexts obtained by performing threshold homomorphic encryption on the private data; a first calculation unit, configured to perform homomorphic calculation on the multiple ciphertexts by using a first smart contract to obtain a calculation result, where the first smart contract is a smart contract determined according to a verifiable random function for calculating private data; a first decryption unit, configured to combine a target number of partial private keys and use at least one smart contract to decrypt the calculation result to obtain a decryption result, where the target number is determined according to the threshold of the participants of the private data; a first providing unit, configured to provide the decryption result to a requester who has been authorized to request access to the private data.

[0115] Optionally, in the encryption device for private data provided in the embodiments of the present application, the device further includes: a third acquisition unit, configured to obtain the identity information of multiple private data providers in the blockchain system after obtaining the target smart contract set from at least one blockchain node and before generating a distributed key according to the multiple smart contracts in the target smart contract set; a first determination unit, configured to determine the correspondence between the identity of each private data provider and each smart contract in the target smart contract set; a first registration unit, configured to register the correspondence in the blockchain system.

[0116] Optionally, in the encryption device for privacy data provided in the embodiments of the present application, the device further includes: a fourth acquisition unit, configured to acquire the authorization information of multiple privacy data providers after registering the corresponding relationship into the blockchain system, where the authorization information at least includes: the identity information of the authorizer, the identity information of the authorized party, the smart contract already registered by the authorizer in the blockchain system, and the signature information of the authorizer; a first recording unit, configured to record the authorization information into the blockchain system.

[0117] Optionally, in the encryption device for privacy data provided in the embodiments of the present application, the device further includes: a first determination unit, configured to determine whether there is a distributed key in the blockchain system before generating a distributed key according to multiple smart contracts in a target smart contract set; a fifth acquisition unit, configured to acquire the distributed key if there is a distributed key in the blockchain system; a second generation unit, configured to generate a distributed key according to multiple smart contracts in the target smart contract set if there is no distributed key in the blockchain system.

[0118] Optionally, in the encryption device for privacy data provided in the embodiments of the present application, the device further includes: a second determination unit, configured to determine whether the provider of privacy data has authorized the requester to access the privacy data according to the authorization information before determining whether there is a distributed key in the blockchain system; a first trigger unit, configured to trigger a first request message if the provider of privacy data has authorized the requester to access the privacy data, where the first request message is used to request to call at least one smart contract in the target smart contract set; a first response unit, configured to respond to the first request message, call at least one smart contract, and determine whether there is a distributed key in the blockchain system; a second trigger unit, configured to trigger a first prompt message if the provider of privacy data has not authorized the requester to access the privacy data, where the first prompt message is used to prompt the requester that the privacy data cannot be accessed.

[0119] Optionally, in the encryption device for privacy data provided in the embodiments of the present application, the device further includes: a sixth acquisition unit, configured to acquire a target transaction parameter and a second smart contract before determining whether the provider of the privacy data has authorized the requester to access the privacy data according to the authorization information, where the second smart contract is used to process data other than the privacy data in the blockchain system; a second determination unit, configured to determine a processing flow for the second smart contract to process data according to the target transaction parameter; a third judgment unit, configured to judge whether the processing flow involves privacy data; a third trigger unit, configured to trigger a second request message when the processing flow involves privacy data, where the second request message is used to request a cross-contract call operation, and the second request message at least includes: the identity information of the requester, the identity information of at least one provider of the privacy data, and a query condition for the privacy data; a second response unit, configured to respond to the second request message, perform a cross-contract call operation, and determine whether the provider of the privacy data has authorized the requester to access the privacy data according to the authorization information; a fourth trigger unit, configured to trigger a second prompt message when the processing flow does not involve privacy data, where the second prompt message is used to prompt that the second smart contract does not involve privacy data.

[0120] The encryption device for privacy data includes a processor and a memory. The above-mentioned first acquisition unit 801, first generation unit 802, first encryption unit 803, etc. are all stored in the memory as program units, and the corresponding functions are implemented by the processor executing the above program units stored in the memory.

[0121] The processor contains a kernel, and the kernel is used to retrieve the corresponding program unit from the memory. One or more kernels can be set, and the encryption effect of privacy data in the blockchain can be improved by adjusting the kernel parameters.

[0122] The memory may include non-permanent memory in a computer-readable medium, in the form of random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM), and the memory includes at least one memory chip.

[0123] An embodiment of the present invention provides a processor, and the processor is used to run a program, where the program executes the privacy data encryption method when running.

[0124] As Figure 9As shown in the figure, an embodiment of the present invention provides an electronic device. The device includes a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, the following steps are implemented: obtaining a target set of smart contracts from the at least one blockchain node, where the target set of smart contracts includes a plurality of smart contracts for encrypting and decrypting private data in the blockchain system; generating a distributed key based on the plurality of smart contracts in the target set of smart contracts, where the distributed key at least includes: a public key for encrypting the private data and a partial private key for decrypting the private data; combining the public key in the distributed key, and using at least one smart contract in the target set of smart contracts to perform threshold homomorphic encryption on the private data, where the at least one smart contract is determined from the target set of smart contracts according to a verifiable random function in the blockchain system.

[0125] When the processor executes the program, the following steps are further implemented: after combining the public key in the distributed key and using at least one smart contract in the target set of smart contracts to perform threshold homomorphic encryption on the private data, the method further includes: obtaining a plurality of ciphertexts, where the plurality of ciphertexts are ciphertexts obtained by performing threshold homomorphic encryption on the private data; performing homomorphic calculation on the plurality of ciphertexts using a first smart contract to obtain a calculation result, where the first smart contract is a smart contract determined according to the verifiable random function for calculating the private data; combining a target number of the partial private keys, and using the at least one smart contract to decrypt the calculation result to obtain a decryption result, where the target number is determined according to a threshold of a participant of the private data; providing the decryption result to a requester authorized to request access to the private data.

[0126] When the processor executes the program, the following steps are further implemented: after obtaining the target set of smart contracts from the at least one blockchain node and before generating a distributed key based on the plurality of smart contracts in the target set of smart contracts, the method further includes: obtaining identity information of a plurality of private data providers in the blockchain system; determining a correspondence between the identity of each private data provider and each smart contract in the target set of smart contracts; registering the correspondence in the blockchain system.

[0127] When the processor executes the program, the following steps are further implemented: after registering the correspondence in the blockchain system, the method further includes: obtaining authorization information of the plurality of private data providers, where the authorization information at least includes: identity information of an authorizing party, identity information of an authorized party, smart contracts registered by the authorizing party in the blockchain system, and signature information of the authorizing party; recording the authorization information in the blockchain system.

[0128] When the processor executes the program, the following steps are further implemented: Before generating a distributed key according to multiple smart contracts in the target smart contract set, the method further includes: determining whether the distributed key exists in the blockchain system; if the distributed key exists in the blockchain system, obtaining the distributed key; if the distributed key does not exist in the blockchain system, generating the distributed key according to multiple smart contracts in the target smart contract set.

[0129] When the processor executes the program, the following steps are further implemented: Before determining whether the distributed key exists in the blockchain system, the method further includes: determining whether the provider of the privacy data has authorized the requester to access the privacy data according to the authorization information; if the provider of the privacy data has authorized the requester to access the privacy data, triggering a first request message, where the first request message is used to request to call at least one smart contract in the target smart contract set; in response to the first request message, calling the at least one smart contract and determining whether the distributed key exists in the blockchain system; if the provider of the privacy data has not authorized the requester to access the privacy data, triggering a first prompt message, where the first prompt message is used to prompt the requester that the privacy data cannot be accessed.

[0130] When the processor executes the program, the following steps are further implemented: Before determining whether the provider of the privacy data has authorized the requester to access the privacy data according to the authorization information, the method further includes: obtaining target transaction parameters and a second smart contract, where the second smart contract is used to process data in the blockchain system other than the privacy data; determining a processing flow for the second smart contract to process data according to the target transaction parameters; determining whether the processing flow involves the privacy data; if the processing flow involves the privacy data, triggering a second request message, where the second request message is used to request a cross-contract call operation, and the second request message at least includes: the identity information of the requester, the identity information of at least one provider of the privacy data, and a query condition for the privacy data; in response to the second request message, performing a cross-contract call operation and determining whether the provider of the privacy data has authorized the requester to access the privacy data according to the authorization information; if the processing flow does not involve the privacy data, triggering a second prompt message, where the second prompt message is used to prompt that the second smart contract does not involve the privacy data. The device in this article can be a server, a PC, a PAD, a mobile phone, etc.

[0131] The present application also provides a computer program product which, when executed on a data processing device, is adapted to execute a program initialized with the following method steps: obtaining a target set of smart contracts from the at least one blockchain node, wherein the target set of smart contracts includes a plurality of smart contracts for encrypting and decrypting privacy data in the blockchain system; generating a distributed key according to the plurality of smart contracts in the target set of smart contracts, wherein the distributed key at least includes: a public key for encrypting the privacy data and a partial private key for decrypting the privacy data; and performing threshold homomorphic encryption on the privacy data by using at least one smart contract in the target set of smart contracts in combination with the public key in the distributed key, wherein the at least one smart contract is determined from the target set of smart contracts according to a verifiable random function in the blockchain system.

[0132] When executed on a data processing device, it is also adapted to execute a program initialized with the following method steps: after performing threshold homomorphic encryption on the privacy data by using at least one smart contract in the target set of smart contracts in combination with the public key in the distributed key, the method further includes: obtaining a plurality of ciphertexts, wherein the plurality of ciphertexts are ciphertexts obtained by performing threshold homomorphic encryption on the privacy data; performing homomorphic calculation on the plurality of ciphertexts by using a first smart contract to obtain a calculation result, wherein the first smart contract is a smart contract determined according to the verifiable random function and used for calculating the privacy data; decrypting the calculation result by using the at least one smart contract in combination with a target number of the partial private keys to obtain a decryption result, wherein the target number is determined according to a threshold of a party participating in the privacy data; and providing the decryption result to a requester authorized to request access to the privacy data.

[0133] When executed on a data processing device, it is also adapted to execute a program initialized with the following method steps: after obtaining the target set of smart contracts from the at least one blockchain node and before generating a distributed key according to the plurality of smart contracts in the target set of smart contracts, the method further includes: obtaining identity information of a plurality of privacy data providers in the blockchain system; determining a correspondence between the identity of each privacy data provider and each smart contract in the target set of smart contracts; and registering the correspondence in the blockchain system.

[0134] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: After registering the corresponding relationship into the blockchain system, the method further includes: obtaining authorization information of the multiple privacy data providers, where the authorization information at least includes: identity information of the authorizing party, identity information of the authorized party, smart contracts already registered by the authorizing party in the blockchain system, and signature information of the authorizing party; recording the authorization information into the blockchain system.

[0135] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: Before generating a distributed key based on multiple smart contracts in the target smart contract set, the method further includes: determining whether the distributed key exists in the blockchain system; if the distributed key exists in the blockchain system, obtaining the distributed key; if the distributed key does not exist in the blockchain system, generating the distributed key based on multiple smart contracts in the target smart contract set.

[0136] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: Before determining whether the distributed key exists in the blockchain system, the method further includes: determining, based on the authorization information, whether the provider of the privacy data has authorized the requester to access the privacy data; if the provider of the privacy data has authorized the requester to access the privacy data, triggering a first request message, where the first request message is used to request to invoke at least one smart contract in the target smart contract set; in response to the first request message, invoking the at least one smart contract and determining whether the distributed key exists in the blockchain system; if the provider of the privacy data has not authorized the requester to access the privacy data, triggering a first prompt message, where the first prompt message is used to prompt the requester that the privacy data cannot be accessed.

[0137] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: Before determining whether the provider of the privacy data has authorized the requester to access the privacy data according to the authorization information, the method further includes: obtaining target transaction parameters and a second smart contract, where the second smart contract is used to process data other than the privacy data in the blockchain system; determining a processing flow for the second smart contract to process data according to the target transaction parameters; determining whether the processing flow involves the privacy data; in the case where the processing flow involves the privacy data, triggering a second request message, where the second request message is used to request a cross-contract call operation, and the second request message at least includes: the identity information of the requester, the identity information of at least one provider of the privacy data, and a query condition for the privacy data; in response to the second request message, performing a cross-contract call operation, and determining whether the provider of the privacy data has authorized the requester to access the privacy data according to the authorization information; in the case where the processing flow does not involve the privacy data, triggering a second prompt message, where the second prompt message is used to prompt that the second smart contract does not involve the privacy data.

[0138] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0139] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for realizing the specified functions in one process Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0140] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to operate in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including an instruction means that implements the functions specified in one or more of the processes and / or blocks Figure 1 in one or more of the processes and / or blocks Figure 1 specified in one or more of the processes and / or blocks.

[0141] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one or more of the processes and / or blocks Figure 1 in one or more of the processes and / or blocks Figure 1 specified in one or more of the processes and / or blocks.

[0142] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0143] The memory may include non-permanent memory in the computer-readable medium, in the form of random access memory (RAM) and / or non-volatile memory such as read only memory (ROM) or flash memory. The memory is an example of a computer-readable medium.

[0144] Computer-readable media includes both permanent and non-permanent, removable and non-removable media implemented by any method or technology for storage of information such as computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read only memory (ROM), electrically erasable programmable read only memory (EEPROM), flash memory or other memory technologies, compact disc read only memory (CD-ROM), digital versatile discs (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory media such as modulated data signals and carrier waves.

[0145] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, commodity or device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the phrase "comprising an..." does not exclude the presence of additional identical elements in the process, method, commodity or device comprising the element.

[0146] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0147] The above are only the embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.

Claims

1. An encryption method for private data, characterized in that, The method is applied in a blockchain system, which includes at least one blockchain node. At least multiple smart contracts for processing private data are included in the at least one blockchain node, and it includes: Obtain a target set of smart contracts from the at least one blockchain node, where the target set of smart contracts includes multiple smart contracts for encrypting and decrypting private data in the blockchain system; Generate a distributed key according to the multiple smart contracts in the target set of smart contracts, where the distributed key at least includes: a public key for encrypting the private data and a partial private key for decrypting the private data; In combination with the public key in the distributed key, use at least one smart contract in the target set of smart contracts to perform threshold homomorphic encryption on the private data, where the at least one smart contract is determined from the target set of smart contracts according to a verifiable random function in the blockchain system; Wherein, after performing threshold homomorphic encryption on the private data by using at least one smart contract in the target set of smart contracts in combination with the public key in the distributed key, the method further includes: Obtain multiple ciphertexts, where the multiple ciphertexts are ciphertexts obtained by performing threshold homomorphic encryption on the private data; Perform homomorphic calculation on the multiple ciphertexts by using a first smart contract to obtain a calculation result, where the first smart contract is a smart contract determined according to the verifiable random function for calculating the private data; In combination with a target number of the partial private keys, use the at least one smart contract to decrypt the calculation result to obtain a decryption result, where the target number is determined according to the threshold of the parties involved in the private data; Provide the decryption result to a requester who has been authorized to request access to the private data; Wherein, the method further includes using a cross-contract call device to record the correspondence between the identity of the private data provider and the smart contracts for encrypting and decrypting the private data.

2. The method according to claim 1, wherein After obtaining the target set of smart contracts from the at least one blockchain node and before generating a distributed key according to the multiple smart contracts in the target set of smart contracts, the method further includes: Obtain the identity information of multiple private data providers in the blockchain system; Determine the correspondence between the identity of each private data provider and each smart contract in the target set of smart contracts; Register the correspondence in the blockchain system.

3. The method according to claim 2, wherein After registering the correspondence in the blockchain system, the method further includes: Obtain the authorization information of the multiple private data providers, where the authorization information at least includes: the identity information of the authorizing party, the identity information of the authorized party, the smart contracts already registered by the authorizing party in the blockchain system, and the signature information of the authorizing party; Record the authorization information in the blockchain system.

4. The method according to claim 3, wherein Before generating a distributed key according to the multiple smart contracts in the target set of smart contracts, the method further includes: Judge whether the distributed key exists in the blockchain system; When the distributed key exists in the blockchain system, obtain the distributed key; When the distributed key does not exist in the blockchain system, generate the distributed key according to multiple smart contracts in the target smart contract set.

5. The method according to claim 4, wherein Before determining whether the distributed key exists in the blockchain system, the method further includes: According to the authorization information, determine whether the provider of the privacy data has authorized the requester to access the privacy data; When the provider of the privacy data has authorized the requester to access the privacy data, trigger a first request message, where the first request message is used to request to call at least one smart contract in the target smart contract set; Respond to the first request message, call the at least one smart contract, and determine whether the distributed key exists in the blockchain system; When the provider of the privacy data has not authorized the requester to access the privacy data, trigger a first prompt message, where the first prompt message is used to prompt the requester that the privacy data cannot be accessed.

6. The method according to claim 5, characterized in that, Before determining whether the provider of the privacy data has authorized the requester to access the privacy data according to the authorization information, the method further includes: Obtain target transaction parameters and a second smart contract, where the second smart contract is used to process data in the blockchain system other than the privacy data; According to the target transaction parameters, determine the processing flow of the second smart contract for processing data; Determine whether the processing flow involves the privacy data; When the processing flow involves the privacy data, trigger a second request message, where the second request message is used to request a cross-contract call operation, and the second request message at least includes: the identity information of the requester, the identity information of at least one provider of the privacy data, and the query condition of the privacy data; Respond to the second request message, perform a cross-contract call operation, and determine whether the provider of the privacy data has authorized the requester to access the privacy data according to the authorization information; When the processing flow does not involve the privacy data, trigger a second prompt message, where the second prompt message is used to prompt that the second smart contract does not involve the privacy data.

7. An encryption device for private data, characterized in that, The device is applied in a blockchain system, and the blockchain system includes at least one blockchain node, and at least multiple smart contracts for processing privacy data are included in the at least one blockchain node, including: A first obtaining unit, configured to obtain a target smart contract set from the at least one blockchain node, where the target smart contract set includes multiple smart contracts for encrypting and decrypting privacy data in the blockchain system; A first generating unit, configured to generate a distributed key according to multiple smart contracts in the target smart contract set, where the distributed key at least includes: a public key for encrypting the privacy data and a partial private key for decrypting the privacy data; A first encryption unit, configured to perform threshold homomorphic encryption on the privacy data by combining the public key in the distributed key and using at least one smart contract in the target smart contract set, where the at least one smart contract is determined from the target smart contract set according to a verifiable random function in the blockchain system; Wherein, the device is further configured to obtain a plurality of ciphertexts, where the plurality of ciphertexts are ciphertexts obtained by performing threshold homomorphic encryption on the privacy data; perform homomorphic calculation on the plurality of ciphertexts by using a first smart contract to obtain a calculation result, where the first smart contract is a smart contract determined according to the verifiable random function and used for calculating the privacy data; combine a target number of the partial private keys, and use the at least one smart contract to decrypt the calculation result to obtain a decryption result, where the target number is determined according to the threshold of the parties involved in the privacy data; and provide the decryption result to a requester who has been authorized to request access to the privacy data; Wherein, the device is further configured to use a cross-contract call device to record the correspondence between the identity of the privacy data provider and the privacy data encryption and decryption smart contract.

8. A processor, characterized in that, The processor is configured to run a program, where when the program runs, it executes the encryption method for privacy data according to any one of claims 1 to 6.

9. An electronic device, characterized in that, Comprising one or more processors and a memory, the memory is configured to store one or more programs, where when the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the encryption method for privacy data according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Fully homomorphic encryption method for intelligent contract privacy protection

    CN110971390A

  • Smart contract privacy data processing system and method for block chain

    CN113051618A

  • Method and device for data encipher / deciphering

    CN1503503A