Contract management method and related equipment based on blockchain and combined key
By combining participants on the blockchain and generating combination keys, encrypting and hash verification of the business data of the enterprise, the problem of data leakage on the blockchain is solved, and the security of data and the authenticity of the contract is realized.
Patent Information
- Application Number
- CN202210668866.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-14
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2042-06-14
AI Technical Summary
Current applications of blockchain, Internet of Things, AIoT and other technologies cannot effectively solve the data leakage problems that enterprises may encounter when uploading core commercial data to blockchain, resulting in corporate privacy and commercial data leakage.
A contract management method based on blockchain and combination key is proposed. By obtaining all participants on the blockchain, combining them in pairs, generating the corresponding public and private key pairs of combinations, and sending the combined private keys to the corresponding participants in each combination. Use the combined public key to encrypt the key information in the contract, generate the encrypted contract, and checksum storage through the contract hash.
Through the use of combined keys, the privacy of participants is protected, data leakage is avoided, data security is improved, and the authenticity and immutability of the contract content are ensured through the verification of the contract hash value.
Smart Images

Figure CN115085934B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of blockchain information security technology, and in particular to a contract management method and related equipment based on blockchain and combined keys. Background Art
[0002] In recent years, with the country vigorously developing inclusive finance and the development of digital technology, data assets have become one of the preferred factors for judging the issuance of credit to small and medium-sized enterprises. As a direct manifestation of inclusive finance, supply chain finance business has received the focus of financial institutions. Traditional supply chain finance is subject to information asymmetry, difficulty in multi-layer credit penetration, cumbersome offline operations, and difficulty in distinguishing the authenticity of trade. By utilizing the decentralized, tamper-proof, and traceable characteristics of blockchain, combined with technologies such as the Internet of Things and AIoT, the rigid trust capability can be enhanced, so that the credit of core enterprises can be reliably and reliably transferred synchronously on the blockchain, effectively activating the accounts receivable of enterprises, and realizing the credibility of the entire trade process, thereby solving the problem of difficult and expensive financing for small and medium-sized enterprises.
[0003] However, the current application of blockchain, IoT, AIoT and other technologies cannot solve all problems. In the implementation of business, whether it is the core enterprise or its upstream and downstream suppliers and distributors, uploading core business data to the blockchain will still lead to data leakage, resulting in corporate privacy and business data leakage. Summary of the invention
[0004] The purpose of the embodiments of the present application is to propose a contract management method and related equipment based on blockchain and combined keys, so as to solve the technical problem in the related technology that when uploading core business data to the blockchain, there is still the possibility of data leakage, resulting in the leakage of corporate privacy and business data.
[0005] In order to solve the above technical problems, the embodiment of the present application provides a contract management method based on blockchain and combined keys, which is applied to the contract end and adopts the following technical solutions:
[0006] Obtain all participants on the blockchain, combine the participants in pairs to obtain combination results, and generate public-private key pairs corresponding to each combination according to the combination results, wherein the public-private key pairs include a combined public key and a combined private key;
[0007] Sending the combined private key to the corresponding participants in each of the combinations;
[0008] Obtaining identification information of the participants in the combination, performing hash calculation on the identification information, and obtaining a combined hash value;
[0009] Mapping the combined hash value and the corresponding combined public key of the public-private key pair and storing them in the blockchain;
[0010] Using the combined public key, encrypt the key information in the contract corresponding to the participants in the combination to obtain an encrypted contract;
[0011] Performing hash calculation on the encrypted contract to obtain a contract hash value;
[0012] The encrypted contract and the contract hash value are uploaded to the blockchain.
[0013] Furthermore, the step of mapping the combined hash value and the combined public key of the corresponding public-private key pair and storing them in the blockchain includes:
[0014] Using the combined hash value as a key name and the combined public key as a key value;
[0015] The combined hash value and the corresponding combined public key are stored in the blockchain in the form of a key-value pair.
[0016] In order to solve the above technical problems, the embodiment of the present application provides a contract management method based on blockchain and combined keys, which is applied to the contract verification end and adopts the following technical solutions:
[0017] Send the contract acquisition request to the client corresponding to the target participant;
[0018] Receiving a partially decrypted contract and a corresponding target combined hash value sent by the client, wherein the partially decrypted contract is obtained by the client decrypting the target encrypted contract obtained based on the contract acquisition request;
[0019] Obtain the corresponding target combination public key according to the target combination hash value, and use the target combination public key to re-encrypt the partially decrypted contract to obtain the contract to be verified;
[0020] Performing hash calculation on the contract to be verified to obtain a hash value to be verified;
[0021] The hash value to be verified is verified to obtain a verification result.
[0022] Furthermore, the step of verifying the hash value to be verified and obtaining a verification result includes:
[0023] Get the target contract hash value corresponding to the target encrypted contract from the blockchain;
[0024] Compare the hash value to be verified with the target contract hash value to obtain a comparison result;
[0025] If the comparison results are consistent, the contract verification passes, otherwise, the contract verification fails.
[0026] In order to solve the above technical problems, the embodiment of the present application provides a contract management method based on blockchain and combined keys, which is applied to the client and adopts the following technical solution:
[0027] Receive a contract acquisition request sent by the contract verification end, and obtain the corresponding target encrypted contract from the blockchain according to the contract acquisition request;
[0028] Calling the combined private key of the target participant to decrypt the target encrypted contract to obtain a partially decrypted contract;
[0029] Obtaining a target combined hash value based on identification information of the parties in the partial decryption contract;
[0030] The partially decrypted contract and the target hash value are sent to the contract verification end.
[0031] In order to solve the above technical problems, the embodiment of the present application also provides a contract management device based on blockchain and combined key, which is applied to the contract end and adopts the following technical solution:
[0032] A combination module, used to obtain all participants on the blockchain, combine the participants in pairs to obtain combination results, and generate public-private key pairs corresponding to each combination according to the combination results, wherein the public-private key pairs include a combined public key and a combined private key;
[0033] A sending module, used for sending the combined private key to the corresponding participants in each of the combinations;
[0034] A first calculation module, used to obtain identification information of the participants in the combination, perform hash calculation on the identification information, and obtain a combined hash value;
[0035] A mapping module, used to map the combined hash value and the corresponding combined public key of the public-private key pair and store them in the blockchain;
[0036] An encryption module, used to encrypt key information in the contract corresponding to the participants in the combination using the combined public key to obtain an encrypted contract;
[0037] A second calculation module is used to perform hash calculation on the encrypted contract to obtain a contract hash value;
[0038] An uploading module is used to upload the encrypted contract and the contract hash value to the blockchain.
[0039] In order to solve the above technical problems, the embodiment of the present application also provides a contract management device based on blockchain and combined key, which is applied to the contract verification end and adopts the following technical solution:
[0040] A sending module, used to send the contract acquisition request to the client corresponding to the target participant;
[0041] A receiving module, configured to receive a partially decrypted contract and a corresponding target combined hash value sent by the client, wherein the partially decrypted contract is obtained by the client decrypting the target encrypted contract obtained based on the contract acquisition request;
[0042] An encryption module, used to obtain a corresponding target combination public key according to the target combination hash value, and re-encrypt a part of the decrypted contract using the target combination public key to obtain a contract to be verified;
[0043] A third calculation module is used to perform hash calculation on the contract to be verified to obtain a hash value to be verified;
[0044] The verification module is used to verify the hash value to be verified and obtain a verification result.
[0045] In order to solve the above technical problems, the embodiment of the present application also provides a contract management device based on blockchain and combined key, which is applied to the client and adopts the following technical solution:
[0046] An acquisition module, used to receive a contract acquisition request sent by the contract verification end, and obtain the corresponding target encrypted contract from the blockchain according to the contract acquisition request;
[0047] A decryption module, used to decrypt the target encrypted contract using the combined private key of the target participant to obtain a partially decrypted contract;
[0048] A fourth calculation module, used to obtain a target combined hash value according to the identification information of the parties in the partial decryption contract;
[0049] A sending module is used to send the partially decrypted contract and the target hash value to the contract verification end.
[0050] In order to solve the above technical problems, the embodiment of the present application further provides a computer device, which adopts the following technical solution:
[0051] The computer device includes a contract end, a contract verification end and a client end, wherein the contract end includes a first memory and a first processor, wherein the first memory stores computer-readable instructions, and the first processor implements the steps of the contract management method based on blockchain and combined keys when executing the computer-readable instructions; the contract verification end includes a second memory and a second processor, wherein the second memory stores computer-readable instructions, and the second processor implements the steps of the contract management method based on blockchain and combined keys when executing the computer-readable instructions; the client end includes a third memory and a third processor, wherein the third memory stores computer-readable instructions, and the third processor implements the steps of the contract management method based on blockchain and combined keys when executing the computer-readable instructions.
[0052] In order to solve the above technical problems, the embodiment of the present application further provides a computer-readable storage medium, which adopts the following technical solution:
[0053] The computer-readable storage medium stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the steps of the contract management method based on blockchain and combined keys as described above are implemented.
[0054] Compared with the prior art, the embodiments of the present application have the following beneficial effects:
[0055] The present application obtains all the participants on the blockchain, combines the participants in pairs, obtains the combination result, generates the public-private key pair corresponding to each combination according to the combination result, wherein the public-private key pair includes a combined public key and a combined private key, sends the combined private key to the corresponding participants in each combination, combines all the participants on the blockchain in pairs, and generates the public-private key corresponding to the combination, the participants store the private key related to themselves, and use it to decrypt the information related to themselves, so as to protect the privacy of the other party; obtains the identification information of the participants in the combination, performs hash calculation on the identification information, obtains the combined hash value, maps the combined hash value and the combined public key of the corresponding public-private key pair and stores them in the blockchain, and can obtain the combined public key through the combined hash value, avoids exposing too much information of the participants, and ensures information security; uses the combined public key to encrypt the key information in the contract corresponding to the participants in the combination, obtains the encrypted contract, and encrypts the key information, so as to improve the security of the data and avoid exposing commercial secrets; performs hash calculation on the encrypted contract, obtains the contract hash value, uploads the encrypted contract and the contract hash value to the blockchain, and verifies the contract through the contract hash value to ensure that the content of the contract is authentic and has not been tampered with. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] In order to more clearly illustrate the scheme in the present application, a brief introduction is given below to the drawings required for use in the description of the embodiments of the present application. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0057] Figure 1 is an exemplary system architecture diagram to which the present application may be applied;
[0058] Figure 2 is a flowchart of an embodiment of a contract management method based on blockchain and combined keys according to the present application;
[0059] Figure 3 It is a structural diagram of an embodiment of a contract management device based on blockchain and combined keys according to the present application;
[0060] Figure 4 is a structural diagram of a second embodiment of a contract management device based on blockchain and combined keys according to the present application;
[0061] Figure 5 is a structural diagram of a third embodiment of a contract management device based on blockchain and combined keys according to the present application;
[0062] Figure 6 It is a structural diagram of an embodiment of a computer device according to the present application. DETAILED DESCRIPTION
[0063] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by technicians in the technical field of the present application; the terms used in the specification of the application herein are only for the purpose of describing specific embodiments and are not intended to limit the present application; the terms "including" and "having" and any variations thereof in the specification and claims of the present application and the above-mentioned drawings are intended to cover non-exclusive inclusions. The terms "first", "second", etc. in the specification and claims of the present application or the above-mentioned drawings are used to distinguish different objects, not to describe a specific order.
[0064] Reference to "embodiments" herein means that a particular feature, structure, or characteristic described in conjunction with the embodiments may be included in at least one embodiment of the present application. The appearance of the phrase in various locations in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein may be combined with other embodiments.
[0065] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings.
[0066] This application provides a contract management method based on blockchain and combined keys, which can be applied to Figure 1 In the system architecture 100 shown, the system architecture 100 may include terminal devices 101, 102, 103, a network 104 and a server 105. The network 104 is used to provide a medium for communication links between the terminal devices 101, 102, 103 and the server 105. The network 104 may include various connection types, such as wired, wireless communication links or optical fiber cables, etc.
[0067] Users can use terminal devices 101, 102, 103 to interact with server 105 through network 104 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 101, 102, 103, such as web browser applications, shopping applications, search applications, instant messaging tools, email clients, social platform software, etc.
[0068] Terminal devices 101, 102, 103 can be various electronic devices with display screens and supporting web browsing, including but not limited to smart phones, tablet computers, e-book readers, MP3 players (Moving Picture Experts Group Audio Layer III), MP4 (Moving Picture Experts Group Audio Layer IV), laptop computers, desktop computers, etc.
[0069] The server 105 may be a server that provides various services, such as a background server that provides support for web pages displayed on the terminal devices 101 , 102 , and 103 .
[0070] It should be noted that the contract management method based on blockchain and combined keys provided in the embodiments of the present application is generally executed by a server / terminal device, and accordingly, the contract management device based on blockchain and combined keys is generally set in the server / terminal device.
[0071] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is only for illustration. Any number of terminal devices, networks and servers may be provided according to the implementation requirements.
[0072] Continue to refer Figure 2, showing a flowchart of an embodiment of a contract management method based on blockchain and combined keys according to the present application, comprising the following steps:
[0073] Step S201, obtain all participants on the blockchain, combine the participants in pairs, obtain combination results, and generate public-private key pairs corresponding to each combination according to the combination results, wherein the public-private key pairs include a combined public key and a combined private key.
[0074] In this embodiment, each participant joins the blockchain network, and the contract end calls the smart contract based on the participant information on the chain to generate a public-private key pair corresponding to the number of combinations based on the possibility of two-by-two combinations. Among them, the participants can be various enterprises, and the participant information includes the enterprise name, enterprise address, enterprise type, enterprise operation mode and business scope, etc.; the public-private key pair can be an asymmetric encrypted public-private key pair.
[0075] Among them, smart contracts are codes written on the blockchain. They are computer transaction protocols that do not require intermediaries, are self-verified, and automatically execute contract terms. When the terms in the contract are triggered, they can be automatically executed by the program. Smart contracts on the blockchain have the characteristics of decentralization, trustlessness, programmability, and non-tamperability. They can flexibly embed various data and assets to help achieve safe and efficient information exchange, value transfer, and asset management.
[0076] For example, assuming there are three participants A, B and C on the blockchain, and the possible pairwise combinations are AB, AC and BC, the smart contract is called to generate three pairs of public and private key pairs, corresponding to the combinations AB, AC and BC respectively. The public and private key pairs include a combined public key and a combined private key. The private key is stored locally on the client corresponding to the participant, and the public key is saved on the blockchain.
[0077] Step S202, sending the combined private key to the corresponding participants in each combination.
[0078] Each combination has a corresponding public-private key pair. The combined private key of the public-private key pair corresponding to a combination is sent to the corresponding clients of both parties in the combination and stored locally. In this way, each party only stores the combined private key related to it.
[0079] For example, the public-private key pair of AB is the first public key and the first private key, the public-private key pair of AC is the second public key and the second private key, and the public-private key pair of BC is the third public key and the third private key. The first private key is sent to participants A and B, the second private key is sent to participants A and C, and the third private key is sent to participants B and C. In this way, participant A only stores the private key related to participant A, that is, AB (the storage method of the first private key in participant A) and AC (the storage method of the second private key in participant A), and cannot obtain the private key of BC; similarly, participant B only stores the private key related to participant B, that is, BA (the storage method of the first private key in participant B) and BC (the storage method of the third private key in participant B), and cannot obtain the private key of AC; participant C only stores the private key related to participant C, that is, CA (the storage method of the second private key in participant C) and CB (the storage method of the third private key in participant C), and cannot obtain the private key of AB. This approach protects the privacy of the other party in the combination.
[0080] Step S203, obtaining identification information of the participants in the combination, performing hash calculation on the identification information, and obtaining a combined hash value.
[0081] In this embodiment, the identification information of both parties is obtained, the identification information of both parties is combined, and the combined identification information is hashed using a hash algorithm to obtain a combined hash value. The identification information can be used as a unique identification of the party, which can be a name or an organization code, which is not limited here.
[0082] Hash algorithms, also known as hash algorithms, hash algorithms or digital fingerprints, are algorithms that can compress messages of any length into a message of a fixed length. Commonly used hash algorithms include the MD series algorithms and the SHA series algorithms.
[0083] The mathematical expression of the hash algorithm is as follows:
[0084] h=Hash(m)
[0085] In the formula, h is the output value of fixed length; m is the input value of arbitrary length. After the binary code of any input value (Message) is calculated by the hash algorithm, a hash value of an n-bit string of 0s and 1s can be obtained. The value of n may be different in different hash algorithms, such as 128, 160, 192, 256, 384 or 512.
[0086] If the initial value entered is text, the text needs to be converted into a string before hashing. Specifically, the identification information is the name of the participant, and the regular matching algorithm is used to generate a letter array from the name of the participant, and the letter array is reassembled into a string as the input value of the hash algorithm; for example, assuming that the name of participant A is A and the name of participant B is B, the names of both parties are combined into a string "AB", and then "AB" is hashed to obtain a combined hash value.
[0087] Step S204, mapping the combined hash value and the combined public key of the corresponding public-private key pair and storing them in the blockchain.
[0088] In this embodiment, the combined hash value and the combined public key of the corresponding public-private key pair are mapped in the form of a key-value pair. Specifically, the combined hash value is used as the key name key, and the combined public key is used as the key value value. The combined hash value and the combined public key are stored on the blockchain in the form of a key-value pair (key: value), that is, the combined hash value and the combined public key on the blockchain are one-to-one corresponding. The saved state on the blockchain is Hash (a+b), that is, the combined public key of participant A and participant B.
[0089] Through mapping storage, the corresponding combined public key can be obtained more quickly according to the combined hash value.
[0090] Step S205, using the combined public key, encrypt the key information in the contract corresponding to the participating parties in the combination to obtain an encrypted contract.
[0091] In this embodiment, the key information of both parties involved in the contract is encrypted into ciphertext using the combined public key, and then the corresponding plaintext in the original contract is replaced, making the contract an encrypted contract in the form of a combination of normal text + ciphertext.
[0092] Among them, key information includes but is not limited to the names of the participants, contract contents, etc. This information is encrypted to avoid leaking the privacy of the participants and improve information security.
[0093] Step S206, perform hash calculation on the encrypted contract to obtain the contract hash value.
[0094] In this embodiment, a hash algorithm is used to perform hash calculation on the encrypted contract, and the hash algorithm is the same as described in step S203.
[0095] The contract hash value is used to verify the contract, which can ensure that the contract content is authentic and not tampered with.
[0096] Step S207, upload the encrypted contract and contract hash value to the blockchain.
[0097] In this embodiment, the encrypted contract is uploaded to the blockchain, and the decryption key is held only by the two parties involved in the contract, which can ensure that a third party other than the two parties cannot decrypt the contract, thereby ensuring the security of information.
[0098] It should be emphasized that in order to further ensure the privacy and security of the encrypted contract and the contract hash value, the above-mentioned encrypted contract and the contract hash value can also be stored in a node of a blockchain.
[0099] The blockchain referred to in this application is a new application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, encryption algorithm, etc. Blockchain is essentially a decentralized database, a string of data blocks generated by cryptographic methods. Each data block contains a batch of network transaction information, which is used to verify the validity of its information (anti-counterfeiting) and generate the next block. Blockchain can include the underlying blockchain platform, platform product service layer, and application service layer.
[0100] In this embodiment, the contract verification end needs to verify the contract, and then sends a contract acquisition request to the client corresponding to the target participant. The contract verification end can be a financial institution. The target participant receives the contract acquisition request through the client, wherein the contract acquisition request includes the participant information involved in the contract, the contract identification, etc. The corresponding target encrypted contract is pulled from the blockchain according to the contract identification in the contract acquisition request, and the target encrypted contract is decrypted by calling the target participant's local combined private key. It should be understood that only the information related to the target participant is decrypted, and what is obtained is a partially decrypted contract. The participant identification information in the partially decrypted contract is obtained, and the participant identification information is hashed to obtain the target combined hash value.
[0101] In this embodiment, decryption is performed at the client to further ensure the security of the information.
[0102] The client sends the partially decrypted contract and the target combined hash value to the contract verification end. The contract verification end receives the partially decrypted contract and can view the contract content.
[0103] In this embodiment, the combined hash value and the combined public key are stored correspondingly. The contract verification end can obtain the corresponding target combined public key from the blockchain according to the target combined hash value, and use the target combined public key to re-encrypt the partially decrypted contract to obtain the contract to be verified, and perform hash calculation on the contract to be verified to obtain the hash value to be verified, and verify the hash value to be verified to obtain the verification result, which includes whether the contract verification passed or failed.
[0104] This embodiment re-encrypts the decrypted contract and performs hash calculation, and performs verification based on the obtained hash value, which can improve verification efficiency and verification accuracy.
[0105] In this embodiment, the step of verifying the hash value to be verified and obtaining the verification result includes:
[0106] Get the target contract hash value corresponding to the target encrypted contract from the blockchain;
[0107] Compare the hash value to be verified with the target contract hash value to obtain a comparison result;
[0108] If the comparison results are consistent, the contract verification passes, otherwise, the contract verification fails.
[0109] In this embodiment, if the comparison results are consistent, the contract verification is passed, indicating that the contract is authentic and has not been tampered with. If they are inconsistent, it means that the contract is forged and tampered with, and the contract cannot be used as proof.
[0110] This application combines all participants on the blockchain in pairs and generates public and private keys corresponding to the combination. Participants store their own private keys to decrypt information related to themselves, thereby protecting the privacy of the other party; the combined hash value and the combined public key of the corresponding public-private key pair are mapped and stored in the blockchain, and the combined public key can be obtained through the combined hash value to avoid exposing too much information of the participants and ensure information security; encrypting key information can improve data security and avoid exposing commercial secrets; in addition, the contract is verified through the contract hash value to ensure that the contract content is authentic and has not been tampered with.
[0111] The present application can be used in many general or special computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, etc. The present application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application can also be practiced in distributed computing environments, in which tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
[0112] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through computer-readable instructions, and the computer-readable instructions can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, the aforementioned storage medium can be a non-volatile storage medium such as a disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).
[0113] It should be understood that, although the steps in the flowchart of the accompanying drawings are displayed in sequence as indicated by the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least a part of the steps in the flowchart of the accompanying drawings may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed in turn or alternately with other steps or at least a part of the sub-steps or stages of other steps.
[0114] Further references Figure 3 , as a response to the above Figure 2 The present application provides an embodiment of a contract management device based on blockchain and combined keys applied to a contract end, and the device embodiment is similar to Figure 2 Corresponding to the method embodiment shown, the device can be specifically applied to various electronic devices.
[0115] like Figure 3 As shown, the contract management device 300 based on blockchain and combined key described in this embodiment includes: a combination module 301, a sending module 302, a first calculation module 303, a mapping module 304, an encryption module 305, a second calculation module 306 and an upload module 307. Among them:
[0116] The combination module 301 is used to obtain all participants on the blockchain, combine the participants in pairs to obtain combination results, and generate public-private key pairs corresponding to each combination according to the combination results, wherein the public-private key pairs include a combined public key and a combined private key;
[0117] The sending module 302 is used to send the combined private key to the corresponding participants in each combination;
[0118] The first calculation module 303 is used to obtain the identification information of the participants in the combination, perform hash calculation on the identification information, and obtain a combined hash value;
[0119] The mapping module 304 is used to map the combined hash value and the corresponding combined public key of the public-private key pair and store them in the blockchain;
[0120] The encryption module 305 is used to encrypt the key information in the contract corresponding to the participants in the combination using the combined public key to obtain an encrypted contract;
[0121] The second calculation module 306 is used to perform hash calculation on the encrypted contract to obtain a contract hash value;
[0122] The upload module 307 is used to upload the encrypted contract and the contract hash value to the blockchain.
[0123] Based on the above-mentioned contract management device based on blockchain and combined keys, by combining all participants on the blockchain in pairs and generating public and private keys corresponding to the combination, the participants store the private keys related to themselves for decrypting information related to themselves, thereby protecting the privacy of the other party; the combined hash value and the combined public key of the corresponding public and private key pair are mapped and stored in the blockchain, and the combined public key can be obtained through the combined hash value to avoid exposing too much information of the participants and ensure information security; encrypting key information can improve data security and avoid exposing commercial secrets; in addition, the contract is verified through the contract hash value to ensure that the content of the contract is authentic and has not been tampered with.
[0124] In some optional implementations of this embodiment, the mapping module 304 is further used to: use the combined hash value as the key name and the combined public key as the key value; and store the combined hash value and the corresponding combined public key in the blockchain in the form of a key-value pair.
[0125] See also Figure 4 The present application provides another embodiment of a contract management device based on blockchain and combined keys applied to a contract verification end. The contract management device 400 based on blockchain and combined keys described in this embodiment includes: a sending module 401, a receiving module 402, an encryption module 403, a third calculation module 404 and a verification module 405. Among them:
[0126] The sending module 401 is used to send the contract acquisition request to the client corresponding to the target participant;
[0127] The receiving module 402 is used to receive the partially decrypted contract and the corresponding target combined hash value sent by the client, wherein the partially decrypted contract is obtained by the client decrypting the target encrypted contract obtained based on the contract acquisition request;
[0128] The encryption module 403 is used to obtain the corresponding target combination public key according to the target combination hash value, and use the target combination public key to re-encrypt the partially decrypted contract to obtain the contract to be verified;
[0129] The third calculation module 404 is used to perform hash calculation on the contract to be verified to obtain a hash value to be verified;
[0130] The verification module 405 is used to verify the hash value to be verified and obtain a verification result.
[0131] In this embodiment, the verification module 405 is further used to:
[0132] Get the target contract hash value corresponding to the target encrypted contract from the blockchain;
[0133] Compare the hash value to be verified with the target contract hash value to obtain a comparison result;
[0134] If the comparison results are consistent, the contract verification passes, otherwise, the contract verification fails.
[0135] This embodiment re-encrypts the decrypted contract and performs hash calculation, and performs verification based on the obtained hash value, which can improve verification efficiency and verification accuracy.
[0136] like Figure 5 As shown, the contract management device 500 based on blockchain and combined key described in this embodiment is applied to the client, including: an acquisition module 501, a decryption module 502, a fourth calculation module 503 and a sending module 504. Among them:
[0137] An acquisition module, used to receive a contract acquisition request sent by the contract verification end, and obtain the corresponding target encrypted contract from the blockchain according to the contract acquisition request;
[0138] A decryption module, used to decrypt the target encrypted contract using the combined private key of the target participant to obtain a partially decrypted contract;
[0139] A fourth calculation module, used to obtain a target combined hash value according to the identification information of the parties in the partial decryption contract;
[0140] A sending module is used to send the partially decrypted contract and the target hash value to the contract verification end.
[0141] In this embodiment, decryption is performed at the client to further ensure the security of the information.
[0142] To solve the above technical problems, the present application also provides a computer device. Figure 6 , Figure 6This is a basic structural block diagram of the computer device in this embodiment.
[0143] The computer device 6 includes a contract terminal 61, a contract verification terminal 62 and a client 63. The contract terminal 61 includes a first memory 611 and a first processor 612. The contract verification terminal 62 includes a second memory 621 and a second processor 622. The client 63 includes a third memory 631 and a third processor 632. The first memory 611, the first processor 612 and the first network interface 613 are interconnected through a system bus for communication. The second memory 621, the second processor 622 and the second network interface 623 are interconnected through a system bus for communication. The third memory 631, the third processor 632 and the third network interface 633 are interconnected through a system bus for communication. It should be noted that the figure only shows a computer device 6 having components 61-63, but it should be understood that it is not required to implement all the components shown, and more or fewer components may be implemented instead. Among them, technicians in this technical field can understand that the computer device here is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes but is not limited to microprocessors, application-specific integrated circuits (Application Specific Integrated Circuit, ASIC), programmable gate arrays (Field-Programmable Gate Array, FPGA), digital processors (Digital Signal Processor, DSP), embedded devices, etc.
[0144] The computer device may be a computing device such as a desktop computer, a notebook, a PDA, a cloud server, etc. The computer device may interact with a user through a keyboard, a mouse, a remote controller, a touch pad, or a voice control device.
[0145] The first memory 611, the second memory 621 and the third memory 631 all include at least one type of readable storage medium, and the readable storage medium includes flash memory, hard disk, multimedia card, card-type memory (for example, SD or DX memory, etc.), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the first memory 611, the second memory 621 and the third memory 631 can be an internal storage unit of the computer device 6, such as a hard disk or memory of the computer device 6. In other embodiments, the first memory 611, the second memory 621 and the third memory 631 can also be an external storage device of the computer device 6, such as a plug-in hard disk, a smart memory card (Smart Media Card, SMC), a secure digital (Secure Digital, SD) card, a flash card, etc. equipped on the computer device 6. Of course, the first memory 611, the second memory 621 and the third memory 631 may also include both the internal storage unit and the external storage device of the computer device 6. In this embodiment, the first memory 611, the second memory 621 and the third memory 631 are generally used to store the operating system and various application software installed on the computer device 6, such as computer-readable instructions of the contract management method based on blockchain and combined keys. In addition, the first memory 611, the second memory 621 and the third memory 631 can also be used to temporarily store various data that have been output or are to be output.
[0146] In some embodiments, the first processor 612, the second processor 622 and the third processor 632 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chips. The first processor 612, the second processor 622 and the third processor 632 are generally used to control the overall operation of the computer device 6. In this embodiment, the first processor 612, the second processor 622 and the third processor 632 are used to run the computer-readable instructions or process data stored in the corresponding first memory 611, the second memory 621 and the third memory 631, such as running the computer-readable instructions of the contract management method based on blockchain and combined keys.
[0147] The first network interface 613, the second network interface 623 and the third network interface 633 may include wireless network interfaces or wired network interfaces. The first network interface 613, the second network interface 623 and the third network interface 633 are generally used to establish a communication connection between the computer device 6 and other electronic devices.
[0148] This embodiment implements the steps of the contract management method based on blockchain and combined keys as in the above-mentioned embodiment when the processor executes computer-readable instructions stored in the memory. By combining all the participants on the blockchain in pairs and generating public and private keys corresponding to the combination, the participants store the private keys related to themselves for decrypting information related to themselves, thereby protecting the privacy of the other party; the combined hash value and the combined public key of the corresponding public and private key pair are mapped and stored in the blockchain, and the combined public key can be obtained through the combined hash value to avoid exposing too much information of the participants and ensure information security; encrypting key information can improve data security and avoid exposing commercial secrets; in addition, the contract is verified through the contract hash value to ensure that the content of the contract is authentic and has not been tampered with.
[0149] The present application also provides another implementation mode, namely, providing a computer-readable storage medium, wherein the computer-readable storage medium stores computer-readable instructions, and the computer-readable instructions can be executed by at least one processor so that the at least one processor executes the steps of the contract management method based on blockchain and combined keys as described above, by combining all participants on the blockchain in pairs and generating public and private keys corresponding to the combination, and the participants store the private keys related to themselves for decrypting information related to themselves, thereby protecting the privacy of the other party; the combined hash value and the combined public key of the corresponding public and private key pair are mapped and stored in the blockchain, and the combined public key can be obtained through the combined hash value, thereby avoiding exposing too much information of the participants and ensuring information security; encrypting key information can improve data security and avoid exposing commercial secrets; in addition, the contract is verified through the contract hash value to ensure that the content of the contract is authentic and has not been tampered with.
[0150] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, a magnetic disk, or an optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) to execute the methods described in each embodiment of the present application.
[0151] Obviously, the embodiments described above are only some embodiments of the present application, rather than all embodiments. The preferred embodiments of the present application are given in the accompanying drawings, but they do not limit the patent scope of the present application. The present application can be implemented in many different forms. On the contrary, the purpose of providing these embodiments is to make the understanding of the disclosure of the present application more thorough and comprehensive. Although the present application is described in detail with reference to the aforementioned embodiments, for those skilled in the art, it is still possible to modify the technical solutions recorded in the aforementioned specific implementation methods, or to perform equivalent replacement of some of the technical features therein. Any equivalent structure made using the contents of the specification and drawings of this application, directly or indirectly used in other related technical fields, is similarly within the scope of patent protection of this application.
Claims
1. A contract management method based on blockchain and combined keys, applied to the contract end, characterized in that: The steps include: Obtain all participants on the blockchain, combine the participants in pairs to obtain combination results, and generate public-private key pairs corresponding to each combination according to the combination results, wherein the public-private key pairs include a combined public key and a combined private key; Sending the combined private key to the corresponding participants in each of the combinations; Obtaining identification information of the participants in the combination, performing hash calculation on the identification information, and obtaining a combined hash value; Mapping the combined hash value and the corresponding combined public key of the public-private key pair and storing them in the blockchain; Using the combined public key, encrypt the key information in the contract corresponding to the participants in the combination to obtain an encrypted contract; Performing hash calculation on the encrypted contract to obtain a contract hash value; The encrypted contract and the contract hash value are uploaded to the blockchain.
2. The contract management method based on blockchain and combined keys according to claim 1 is characterized in that: The step of mapping the combined hash value and the corresponding combined public key of the public-private key pair and storing them in the blockchain comprises: Using the combined hash value as a key name and the combined public key as a key value; The combined hash value and the corresponding combined public key are stored in the blockchain in the form of a key-value pair.
3. A contract management method based on blockchain and combined keys, applied to the contract verification end, characterized in that: The steps include: Send the contract acquisition request to the client corresponding to the target participant; Receiving a partially decrypted contract and a corresponding target combined hash value sent by the client, wherein the partially decrypted contract is obtained by the client decrypting the target encrypted contract obtained based on the contract acquisition request; Obtaining a corresponding target combined public key according to the target combined hash value, and re-encrypting the partially decrypted contract using the target combined public key to obtain a contract to be verified, wherein the combined hash value and the combined public key are stored correspondingly, and the contract verification end can obtain the corresponding target combined public key from the blockchain according to the target combined hash value; Performing hash calculation on the contract to be verified to obtain a hash value to be verified; Verifying the hash value to be verified to obtain a verification result; The step of verifying the hash value to be verified and obtaining a verification result comprises: Get the target contract hash value corresponding to the target encrypted contract from the blockchain; Compare the hash value to be verified with the target contract hash value to obtain a comparison result; If the comparison results are consistent, the contract verification passes, otherwise, the contract verification fails.
4. A contract management method based on blockchain and combined keys, applied to a client, characterized in that: The steps include: Receive a contract acquisition request sent by the contract verification end, and obtain the corresponding target encrypted contract from the blockchain according to the contract acquisition request; Calling the combined private key of the target participant to decrypt the target encrypted contract to obtain a partially decrypted contract, wherein each participant joins the blockchain network, and the contract end calls the smart contract based on the participant information on the chain to generate a public-private key pair corresponding to the number of combinations based on the possibility of two-by-two combinations, and the public-private key pair includes a combined public key and a combined private key; Obtaining a target combined hash value based on identification information of the parties in the partial decryption contract; The partially decrypted contract and the target hash value are sent to the contract verification end.
5. A contract management device based on blockchain and combined key, applied to the contract end, characterized in that: include: A combination module, used to obtain all participants on the blockchain, combine the participants in pairs to obtain combination results, and generate public-private key pairs corresponding to each combination according to the combination results, wherein the public-private key pairs include a combined public key and a combined private key; A sending module, used for sending the combined private key to the corresponding participants in each of the combinations; A first calculation module, used to obtain identification information of the participants in the combination, perform hash calculation on the identification information, and obtain a combined hash value; A mapping module, used to map the combined hash value and the corresponding combined public key of the public-private key pair and store them in the blockchain; An encryption module, used to encrypt key information in the contract corresponding to the participants in the combination using the combined public key to obtain an encrypted contract; A second calculation module is used to perform hash calculation on the encrypted contract to obtain a contract hash value; An uploading module is used to upload the encrypted contract and the contract hash value to the blockchain.
6. A contract management device based on blockchain and combined key, applied to the contract verification end, characterized in that: include: A sending module, used to send the contract acquisition request to the client corresponding to the target participant; A receiving module, configured to receive a partially decrypted contract and a corresponding target combined hash value sent by the client, wherein the partially decrypted contract is obtained by the client decrypting the target encrypted contract obtained based on the contract acquisition request; An encryption module, used to obtain a corresponding target combination public key according to the target combination hash value, and use the target combination public key to re-encrypt the partially decrypted contract to obtain a contract to be verified, wherein the combination hash value and the combination public key are stored correspondingly, and the contract verification end can obtain the corresponding target combination public key from the blockchain according to the target combination hash value; A third calculation module is used to perform hash calculation on the contract to be verified to obtain a hash value to be verified; A verification module, used to verify the hash value to be verified and obtain a verification result; The verification module is further used for: Get the target contract hash value corresponding to the target encrypted contract from the blockchain; The hash value to be verified is compared with the target contract hash value to obtain a comparison result; if the comparison results are consistent, the contract verification passes, otherwise, the contract verification fails.
7. A contract management device based on blockchain and combined key, applied to a client, characterized in that: include: An acquisition module, used to receive a contract acquisition request sent by the contract verification end, and obtain the corresponding target encrypted contract from the blockchain according to the contract acquisition request; A decryption module is used to decrypt the target encrypted contract using the combined private key of the target participant to obtain a partially decrypted contract, wherein each participant joins the blockchain network, and the contract end calls the smart contract based on the participant information on the chain to generate a public-private key pair corresponding to the number of combinations based on the possibility of two-by-two combinations, and the public-private key pair includes a combined public key and a combined private key; A fourth calculation module, used to obtain a target combined hash value according to the identification information of the parties in the partial decryption contract; The sending module is used to send the partially decrypted contract and the target hash value to the contract verification end.
8. A computer device, comprising a contract end, a contract verification end and a client end, the contract end comprising a first memory and a first processor, the first memory storing computer-readable instructions, and the first processor implementing the steps of the contract management method based on blockchain and combined keys as described in any one of claims 1 to 2 when executing the computer-readable instructions; the contract verification end comprising a second memory and a second processor, the second memory storing computer-readable instructions, and the second processor implementing the steps of the contract management method based on blockchain and combined keys as described in claim 3 when executing the computer-readable instructions; the client end comprising a third memory and a third processor, the third memory storing computer-readable instructions, and the third processor implementing the steps of the contract management method based on blockchain and combined keys as described in claim 4 when executing the computer-readable instructions.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the steps of the contract management method based on blockchain and combined keys as described in any one of claims 1 to 4 are implemented.
Citation Information
Patent Citations
Electronic contract signing method and system, storage medium and computing equipment
CN114266681A
Method and system for storing and sharing electronic contract
CN114500069A