Method, device, computer-readable storage medium and computing device for obtaining data based on blockchain
By encrypting the attributes of data in the blockchain, only users who comply with specific policies are allowed to decrypt, the problem of data reading control on the blockchain is solved and the security and privacy of the data are improved.
Patent Information
- Application Number
- CN202210722354.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-24
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2042-06-24
AI Technical Summary
After digitizing assets on blockchain, how to control participants to read data to ensure the security and privacy of data?
By encrypting attributes of the first data stored in the blockchain, encrypting using the main public key and preset strategy based on the management device, only users whose attribute tags are consistent with the preset strategy corresponding to the first data are allowed to decrypt and obtain the second data.
It realizes control over data reading in the blockchain, improves data security and privacy, and ensures the rights and interests of data owners.
Smart Images

Figure CN115118485B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this specification belong to the field of blockchain technology, and more particularly, to a method and device for obtaining data based on blockchain. Background Art
[0002] Blockchain is a new application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, encryption algorithm, etc. In the blockchain system, data blocks are combined into a chain data structure in a sequential manner according to time sequence, and a distributed ledger that cannot be tampered with or forged is guaranteed by cryptography. Due to the characteristics of blockchain such as decentralization, information cannot be tampered with, and autonomy, blockchain has also received more and more attention and application.
[0003] Blockchain is changing many industries. Compared with traditional data management systems, blockchain allows all parties to manage and share stored data without mutual trust. Because the data is backed up by each party, the stored data is not modified. However, some information that can be used as intangible assets, such as intellectual property (IP) and proprietary technology, may involve information security issues when displayed and traded on the blockchain after the assets are digitized on the blockchain. The data owner does not want his data to be fully open and transparent to other participants, and needs to filter and open it to the participants in a targeted manner. Therefore, how to control the reading of data in the blockchain by the participants has important practical significance and value. Summary of the invention
[0004] The embodiments of this specification describe a method and device for obtaining data based on a blockchain, wherein the first data stored in the blockchain is obtained by encrypting the attributes based on the master public key of a management device and a preset policy, and only the user device of a user whose attribute tag is consistent with the preset policy corresponding to the first data can successfully decrypt the first data to obtain the second data, thereby realizing the control of data reading in the blockchain and improving the security of the data in the blockchain.
[0005] According to the first aspect, a method for obtaining data based on a blockchain is provided, wherein the first data stored in the above-mentioned blockchain is obtained by attribute encryption based on the master public key of the management device and a preset policy, and the above-mentioned method includes: the user device uploads the user information to the blockchain; the above-mentioned management device obtains the above-mentioned user information from the above-mentioned blockchain, determines the attribute label of the user based on the above-mentioned user information, generates the above-mentioned user's sub-private key based on the above-mentioned attribute label, the master public key of the above-mentioned management device and the master private key of the above-mentioned management device, and uploads the above-mentioned sub-private key to the blockchain; the above-mentioned user device obtains the above-mentioned sub-private key and the above-mentioned first data from the above-mentioned blockchain, and the above-mentioned user device decrypts the above-mentioned first data using the above-mentioned sub-private key. When the above-mentioned attribute label meets the above-mentioned preset policy, the decryption is successful to obtain the second data.
[0006] According to the second aspect, a method for obtaining data based on blockchain is provided, which is applied to a blockchain node, wherein the first data stored in the above-mentioned blockchain is obtained by attribute encryption based on a master public key of a management device and a preset policy, and the above-mentioned method includes: receiving user information, and storing the above-mentioned user information in the blockchain; in response to a request sent by the management device, sending the above-mentioned user information to the above-mentioned management device; receiving a sub-private key from the above-mentioned management device, and storing the above-mentioned sub-private key in the blockchain, wherein the above-mentioned sub-private key is generated based on the above-mentioned user information, the master public key of the above-mentioned management device and the master private key of the above-mentioned management device; in response to the request sent by the above-mentioned user device, sending the above-mentioned sub-private key and the above-mentioned first data to the above-mentioned user device.
[0007] According to a third aspect, a device for acquiring data based on a blockchain is provided, which is arranged in a blockchain node, wherein the first data stored in the above-mentioned blockchain is obtained by attribute encryption based on a master public key of a management device and a preset policy, and the above-mentioned device includes: a receiving unit, configured to receive user information, and store the above-mentioned user information in the blockchain; a sending unit, configured to send the above-mentioned user information to the above-mentioned management device in response to a request sent by the management device; a storage unit, configured to receive a sub-private key from the above-mentioned management device, and store the above-mentioned sub-private key in the blockchain, wherein the above-mentioned sub-private key is generated based on the above-mentioned user information, the master public key of the above-mentioned management device and the master private key of the above-mentioned management device; a data sending unit, configured to send the above-mentioned sub-private key and the above-mentioned first data to the above-mentioned user device in response to a request sent by the above-mentioned user device.
[0008] According to a fourth aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed in a computer, the computer is caused to execute the method described in any implementation manner in the second aspect.
[0009] According to the fifth aspect, a computing device is provided, comprising a memory and a processor, wherein executable code is stored in the memory, and when the processor executes the executable code, the method described in any implementation manner in the second aspect is implemented.
[0010] According to the method and device for obtaining data based on blockchain provided by the embodiments of this specification, the first data stored in the blockchain is obtained by attribute encryption based on the master public key of the management device and the preset policy. The specific method includes: first, the user device uploads the user information to the blockchain. After that, the management device obtains the user information from the blockchain, and determines the attribute label of the user based on the user information, generates the user's sub-private key based on the attribute label, the master public key of the management device and the master private key of the management device, and uploads the user's sub-private key to the blockchain. Finally, the user device obtains the sub-private key and the first data from the blockchain, and the user device uses the sub-private key to decrypt the first data. In the case where the attribute label conforms to the preset policy, the decryption is successful and the second data is obtained. Therefore, only the user device of the user whose attribute label conforms to the preset policy corresponding to the first data can successfully decrypt the first data and obtain the second data, thereby realizing the control of data reading in the blockchain and improving the security of the data in the blockchain. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] In order to more clearly illustrate the technical solutions of the embodiments of this specification, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.
[0012] Figure 1 A diagram of a blockchain architecture in one embodiment is shown;
[0013] Figure 2 A schematic diagram showing an application scenario in which the embodiments of this specification can be applied;
[0014] Figure 3 A timing diagram showing an example of multiple participant devices interacting with a blockchain before reading data from the blockchain;
[0015] Figure 4 A schematic diagram of a preset strategy is shown;
[0016] Figure 5 A timing diagram of a method for obtaining data based on blockchain according to one embodiment is shown;
[0017] Figure 6 A schematic diagram showing an example of a user device applying for a new attribute tag from a management device;
[0018] Figure 7 A schematic block diagram of an apparatus for acquiring data based on blockchain according to an embodiment is shown. DETAILED DESCRIPTION
[0019] In order to enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the drawings in the embodiments of this specification. Obviously, the described embodiments are only part of the embodiments of this specification, not all of the embodiments. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of this specification.
[0020] Blockchain technology was originally designed by a person with the pseudonym "Satoshi Nakamoto" for Bitcoin (a digital currency) as a special distributed database technology. It is suitable for storing simple, sequential, and verifiable data within the system, and uses cryptography and consensus algorithms to ensure that the data cannot be tampered with or forged. To further explain blockchain technology, Figure 1 A diagram of a blockchain architecture in one embodiment is shown. Figure 1 In the blockchain architecture diagram shown, the blockchain 100 includes, for example, 6 nodes. The lines between the nodes schematically represent P2P (Peer to Peer) connections. These nodes can store the full amount of ledgers, that is, store the status of all blocks and all accounts. Among them, each node in the blockchain can generate the same state in the blockchain by executing the same transaction, and each node in the blockchain can store the same state database. It can be understood that Figure 1 Although it is shown that the blockchain includes 6 nodes, the embodiments of this specification are not limited to this, but may include other numbers of nodes. Specifically, the nodes included in the blockchain can meet the Byzantine Fault Tolerance (BFT) requirements. The Byzantine Fault Tolerance requirement can be understood as Byzantine nodes can exist inside the blockchain, but the blockchain does not reflect Byzantine behavior to the outside. In general, some Byzantine fault tolerance algorithms require the number of nodes to be greater than 3f+1, where f is the number of Byzantine nodes, such as the practical Byzantine fault tolerance algorithm PBFT (Practical Byzantine Fault Tolerance).
[0021] Transactions in the blockchain field can refer to task units that are executed and recorded in the blockchain. Transactions usually include a send field (From), a receive field (To), and a data field (Data). Among them, in the case where the transaction is a transfer transaction, the From field indicates the account address that initiates the transaction (i.e., initiates a transfer task to another account), the To field indicates the account address that receives the transaction (i.e., receives the transfer), and the Data field includes the transfer amount. In the case where the transaction calls a smart contract in the blockchain, the From field indicates the account address that initiates the transaction, the To field indicates the account address of the contract called by the exchange, and the Data field includes the function name in the calling contract, and the incoming parameters of the function, etc., which are used to obtain the code of the function from the blockchain and execute the code of the function when the transaction is executed.
[0022] The blockchain can provide the function of smart contracts. Smart contracts on the blockchain are contracts that can be triggered and executed by transactions on the blockchain system. Smart contracts can be defined in the form of code. Calling a smart contract in Ethereum is to initiate a transaction pointing to the smart contract address, so that each node in the Ethereum network runs the smart contract code in a distributed manner. It should be noted that in addition to being able to create smart contracts by users, smart contracts can also be set by the system in the genesis block. This type of contract is generally called a genesis contract. Generally, some blockchain data structures, parameters, properties and methods can be set in the genesis contract. In addition, accounts with system administrator privileges can create system-level contracts or modify system-level contracts (referred to as system contracts). Among them, the system contract can be used to add data structures of data for different businesses in the blockchain.
[0023] In the scenario of deploying a contract, for example, Bob sends a transaction containing information about creating a smart contract (i.e. deploying a contract) to Figure 1 In the blockchain shown, the data field of the transaction includes the code of the contract to be created (such as bytecode or machine code), and the to field of the transaction is empty to indicate that the transaction is used to deploy the contract. After the nodes reach an agreement through the consensus mechanism, the contract address "0x6f8ae93..." of the contract is determined, and each node adds a contract account corresponding to the contract address of the smart contract in the state database, allocates the state storage corresponding to the contract account, and saves the contract code in the state storage of the contract, so that the contract is successfully created.
[0024] In the scenario of calling a contract, for example, Bob sends a transaction for calling a smart contract to Figure 1In the blockchain shown, the from field of the transaction is the address of the account of the transaction initiator (i.e. Bob), the "0x6f8ae93..." in the to field represents the address of the smart contract being called, and the data field of the transaction includes the method and parameters for calling the smart contract. After the transaction is reached in the blockchain, each node in the blockchain can execute the transaction separately, thereby executing the contract separately, and updating the status database based on the execution of the contract.
[0025] As mentioned above, in some scenarios, the data owner of the data on the blockchain does not want their data to be fully open and transparent to other participants, and needs to open it to the participants after filtering.
[0026] To this end, the embodiments of this specification provide a method for obtaining data based on blockchain, thereby realizing the control of data reading in blockchain and improving the security of data in blockchain. As an example, Figure 2 FIG. 1 is a schematic diagram showing an application scenario in which the embodiments of this specification can be applied. Figure 2 As shown, in this application scenario, multiple blockchain 100 participant devices such as management device 201, data owner device 202, and user device 203 may be included. Among them, management device 201 may refer to a device used by a regulatory agency. Data owner device 202 may refer to a device used by the copyright holder of information such as intellectual property, proprietary technology, etc. Here, intellectual property may include copyright, patent, trademark, etc. User device 203 may refer to a device used by a user who wants to read data on the blockchain. Each participant device may be provided with an encryption system. For example, a CP-ABE (ciphertext policy attribute based encryption) encryption system may be provided. The ciphertext of CP-ABE corresponds to an access policy, and the key corresponds to an attribute set. The ciphertext can be decrypted only when the attributes in the attribute set can satisfy this access policy. The first data stored in the blockchain 100 may be obtained by the data owner device 202 through attribute encryption using the master public key of the management device 201 and the preset policy. The data owner device 202 uploads the obtained first data to the blockchain 100. The user device 203 can upload user information to the blockchain 100, and then the management device 201 can obtain the user information from the blockchain 100, and determine the attribute tag of the user based on the user information, generate the sub-private key of the user based on the attribute tag, the master public key and the master private key, and upload the user ID of the user in association with the sub-private key to the blockchain 100. In this way, the user device 203 can obtain the sub-private key and the first data from the blockchain 100, and try to decrypt the first data using the sub-private key. In the case where the attribute tag meets the preset policy, the decryption can be successful to obtain the second data.
[0027] Continue to see Figure 3 , Figure 3 A timing diagram showing an example of multiple participant devices interacting with the blockchain before reading data from the blockchain. Figure 3 In the example shown, the participant devices interacting with the blockchain 100 include a management device 201 and a data owner device 202, and each participant device may be provided with a CP-ABE encryption system.
[0028] The specific interaction process can be shown as follows:
[0029] S301, the management device 201 generates a master public key and a master private key. As an example, the management device 201 can generate the master public key and the master private key by calling the Setup function of the CP-ABE encryption system. As another example, the master public key and the master private key can also be generated by secure multi-party computing. The master private key is jointly maintained by multiple management devices 201, and when the master private key needs to be used, multiple management devices 201 participate in the calculation at the same time. The calculation process can be as follows: CPABE_Setup (msk, mpk), where mpk can represent the master public key and msk can represent the master private key.
[0030] S302, the management device 201 uploads the master public key to the blockchain 100. For example, the management device 201 can send a transaction to any blockchain node of the blockchain 100, and the transaction can call the data supervision contract C1 (hereinafter referred to as contract C1) in the blockchain to upload the master public key to the blockchain. Among them, the contract can be deployed to the blockchain by the management device 201 to supervise data, supervise data access, etc. After receiving the transaction, the above-mentioned blockchain node sends the transaction to other nodes in the blockchain, so that each node in the blockchain can execute the transaction. By executing the transaction, each node of the blockchain stores the master public key in the contract state of the contract.
[0031] S303, the data owner device 202 sends the account registration information to the blockchain 100.
[0032] S304, the data owner device 202 receives the on-chain account information returned by the blockchain 100. Specifically, the data owner device 202 can send a transaction to the blockchain 100, and the transaction can call the contract C1 to register externally owned accounts (EOA) with the blockchain. The node of the blockchain executes the transaction, generates on-chain account information, and returns the on-chain account information to the data owner device 202. The blockchain can store the generated account information of the data owner under the contract account. Among them, the account registration information can include business certification information, enterprise information, asymmetric encrypted public key accountPK, etc. Among them, the enterprise information can include the name of the enterprise, address, customer group, business scope of the enterprise, category and scale of goods or services provided, etc. Among them, the business certification information and enterprise information can also be used for KYC (Knowyour customer). The data owner can save the private key accountSK corresponding to the asymmetric encrypted public key accountPK for subsequent encrypted information transmission. For example, the information included in the account registration information can be spliced and then hashed to obtain the on-chain account ID. Specifically,
[0033] accountId=RegisterCopyrightOwner(accountInfo,accountPK)=HASH(accountInfo||accountPK).
[0034] Among them, accountInfo may include business certification information, enterprise information, etc.
[0035] S305, after completing the registration, the data owner device 202 can obtain the master public key from the blockchain 100.
[0036] Specifically, the data owner device 202 can query the master public key by sending a transaction (or request) to call contract C1 to any blockchain node. After receiving the transaction, the blockchain node obtains the master public key from the status of contract C1 according to the transaction and returns the master public key to the data owner device 202.
[0037] S306, the data owner device 202 generates first data based on the master public key, the information to be uploaded to the chain and the preset strategy.
[0038] Here, the information to be uploaded can include intellectual property rights, proprietary technology and other information. The data owner can set the encryption policy according to its own needs. The policy can specify the conditions under which the attribute tags can be met before decryption. As an example, the structure of the policy can be a tree structure. Figure 4 , Figure 4 A schematic diagram of a preset strategy is shown. The preset strategy set by the data owner device 202 is Figure 4 Taking the tree structure shown in FIG. 1 as an example, the first data encrypted by this strategy can only be decrypted by users who meet the condition of "high credit company" and at least two of the three conditions of "luxury goods", "cultural trend" and "clothing", otherwise the decryption fails. Here, the data owner device 202 can generate the first data by calling the Encrypt function of the CP-ABE encryption system, specifically:
[0039] The first data = CPABE_ENCRYPT (information to be uploaded, ploicy, mpk).
[0040] Thus, attribute encryption can be performed based on the master public key and the policy to obtain the first data.
[0041] In some implementations, the data owner device 202 may also generate a hash value of the information to be uploaded to the chain, and upload the hash value to the blockchain 100 in association with the first data.
[0042] S307, the data owner device 202 uploads the first data to the blockchain 100. Specifically, the data owner device 202 may send a transaction to the blockchain 100, and the transaction may call the contract C1 to upload the first data to the blockchain. The node of the blockchain executes the transaction and stores the first data in the contract state of the contract C1.
[0043] Optionally, in the above S307, the data owner device uploads the first data to the blockchain, which may specifically include:
[0044] First, the data owner device sends a first transaction to the blockchain, and the first transaction can call contract C1 to upload the first data to the blockchain.
[0045] Then, the node of the blockchain executes the first transaction and stores the first data in the contract state of contract C1. As an example, the first data can be stored in the data list of contract C1, which can be used to store data uploaded by the data owner's device. Through this implementation, the storage of the first data in contract C1 can be achieved.
[0046] In some optional implementations, the above method may further include the following contents:
[0047] 1) The management device receives the first data from the blockchain by sending a second transaction to call the contract C1 to the blockchain.
[0048] 2) The management device uses the master private key msk to decrypt the first data to obtain the second data, and checks whether the second data is legal. As an example, the management device can decrypt the first data by calling the DECRYPT function of the CP-ABE encryption system to obtain the second data. Specifically:
[0049] Second data=CPABE_DECRYPT(first data, msk).
[0050] After decrypting and obtaining the second data, the management device may perform various checks on the second data, for example, checking whether the second data contains any speech, inappropriate images, etc.
[0051] 3) If the management device checks the second data and determines that the check fails, the management device may send a third transaction to the blockchain to call contract C1, and record the first data as illegal data in the contract state of contract C1. As an example, the hash value of the first data may be recorded in an illegal data list preset in contract C1, and the illegal data list may contain hash values of multiple illegal data.
[0052] Optionally, the first transaction sent by the data owner device to the blockchain is also used to upload the first hash value of the second data to the blockchain. Specifically, the data owner device can upload the first hash value of the second data to the blockchain in association with the first data. In this way, the management device checks whether the second data is legal, which can be specifically performed as follows:
[0053] First, the management device may obtain a first hash value from the blockchain, and calculate a second hash value of the decrypted second data.
[0054] Then, determine whether the second hash value matches the first hash value. For example, it can be determined whether the second hash value is the same as the first hash value. If they are the same, it means that the second hash value matches the first hash value, and the second data obtained by decryption is legal; if they are not the same, it means that the second hash value does not match the first hash value, and the second data obtained by decryption is illegal. In practice, if the first hash value received by the management device from the blockchain is different from the second hash value of the second data decrypted by the management device, it means that the second data in the first data is at risk of being tampered with. Therefore, in order to ensure data security, the first data is determined to be illegal data. Through this implementation method, the management device can check the data through the hash value to ensure the security of the data.
[0055] pass Figure 3 The example shown can complete the registration of the data owner device 202 in the blockchain 100, as well as the steps of generating and uploading the first data, and provide support for subsequent user devices to read data from the blockchain 100.
[0056] Continue to see Figure 5 , Figure 5 FIG. 1 shows a sequence diagram of a method for obtaining data based on blockchain according to an embodiment. It is understood that the method can be jointly executed by the management device 201, the user device 203, the data owner device 202 and the blockchain 100, wherein the management device, the user device, the data owner device and the blockchain node can be executed by any device, device, platform or device cluster with computing and processing capabilities. Figure 5 As shown, the method for obtaining data based on blockchain may include the following steps:
[0057] S501, the user device uploads user information to the blockchain.
[0058] In this embodiment, the user device can upload user information to the blockchain, and the user information can be used for account registration. User information can include business certification information, enterprise information, asymmetric encrypted public key accountPK, etc. Among them, enterprise information can include enterprise name, address, customer group, business scope, category of goods or services provided, scale, etc. Afterwards, the user device can receive the on-chain account information returned by the blockchain. It can be understood that the registration process of the user device is similar to the registration process of the data owner's device, and will not be repeated here.
[0059] In some optional implementations, the user device uploading the user information to the blockchain may specifically include: the user device uploading the user information to the blockchain for user registration, or for updating the user information.
[0060] S502, the management device obtains user information from the blockchain. Specifically, the management device 201 can send a transaction to the blockchain 100, and the transaction can call the contract C1 to obtain the user information from the blockchain. The node of the blockchain executes the transaction and sends the user information to the management device.
[0061] S503, the management device determines the attribute tag of the user based on the user information, and generates a sub-private key of the user based on the attribute tag, the master public key of the management device and the master private key of the management device.
[0062] S504, the management device uploads the child private key to the blockchain. Specifically, the management device may send a transaction to the blockchain 100, and the transaction may call contract C1 to upload the child private key to the blockchain. The node of the blockchain executes the transaction and stores the child private key in the contract state of contract C1.
[0063] In this embodiment, the management device can monitor the registration events of the user device on the chain, obtain user information from the blockchain, and determine the attribute label of the user based on the user information. For example, the management device can extract the attribute label from the user information. Here, the attribute label can be the sum of a category of features, for example, the customer groups that the enterprise targets, including the elderly, young and middle-aged people, young children, students, etc.; the service categories provided by the enterprise, including services, catering, hotels, tourism, etc.; the scale of the enterprise, including small enterprises, medium-sized enterprises, large enterprises, etc.; the type of information that the enterprise hopes to read, taking the information as intellectual property information as an example, the information type can include national trends, luxury goods, etc. Afterwards, the management device can generate the user's sub-private key based on the attribute label, the master public key mpk and the master private key msk. For example, the management device can generate a user-exclusive sub-private key sk by calling the KeyGen function of the CP-ABE encryption system. Specifically,
[0064] sk=CPABE_KeyGen(attribute tag, msk, mpk).
[0065] After the management device generates the user-specific sub-private key sk, the user's user ID and the sub-private key can be associated and uploaded to the blockchain so that the user device can obtain the sub-private key from the blockchain. Here, the user ID can include the user's on-chain account ID.
[0066] In some optional implementations, uploading the sub-private key to the blockchain may also be performed as follows:
[0067] First, the management device encrypts the sub-private key based on the public key of the blockchain account corresponding to the user device to obtain an encryption result. As an example, the public key of the blockchain account corresponding to the user device can be used to adopt an encryption scheme, such as ECIES (ellipticcurve integrate encrypt scheme, integrated encryption scheme), to encrypt the sub-private key to obtain a first encryption result, and the user device can obtain the sub-private key by decrypting the first encryption result. As another example, the public key can also be used to encrypt the attribute tag and the sub-private key to obtain a second encryption result. Specifically,
[0068] The second encryption result = ECIES_ENCRYPT (public key corresponding to the user device, attribute tag, sk).
[0069] The user device can obtain the attribute tag and the sub-private key by decrypting the second encryption result.
[0070] Then, the management device uploads the encryption result to the blockchain in association with the user's user ID. In this way, the user device can obtain the corresponding encryption result from the blockchain according to the user ID, and decrypt the encryption result to obtain the sub-private key. Through this implementation method, the sub-private key can be encrypted and then uploaded to the blockchain, thereby realizing the protection of the sub-private key and improving the security of the sub-private key.
[0071] In actual use, based on the blockchain 100, the user device 203 can also apply for a new attribute tag from the management device 201 at any time. Figure 6 As shown, Figure 6 A schematic diagram showing an example in which a user device applies for a new attribute tag from a management device.
[0072] exist Figure 6 In the example shown, the process of the user device 203 applying for a new attribute tag from the management device 201 specifically includes the following steps:
[0073] S601, the user device 203 uploads updated user information to the blockchain. The updated user information may include business certification information, enterprise information, etc.
[0074] S602, the management device 201 obtains the updated user information from the blockchain. Specifically, the management device 201 can send a transaction to the blockchain 100, and the transaction can call the contract C1 to obtain the updated user information from the blockchain. The node of the blockchain executes the transaction and sends the updated user information to the management device.
[0075] S603, the management device 201 determines the updated attribute tag of the user based on the updated user information, and generates the updated sub-private key skNew based on the updated attribute tag, the master public key of the management device and the master private key of the management device. For example, the management device can generate the updated sub-private key skNew by calling the KeyGen function of the CP-ABE encryption system. Specifically,
[0076] skNew = CPABE_KeyGen (updated attribute label, msk, mpk).
[0077] S604, the management device uploads the updated attribute tag and the updated sub-private key skNew to the blockchain. Specifically, the management device can send a transaction to the blockchain 100, and the transaction can call the contract C1 to upload the updated attribute tag and the updated sub-private key skNew to the blockchain. The nodes of the blockchain execute the transaction and store the updated attribute tag and the updated sub-private key skNew in the contract state of the contract C1. In this way, the attribute tag corresponding to the user device is updated, so that the user device can obtain the updated attribute tag and the updated sub-private key skNew from the blockchain in the future.
[0078] S505, the user device obtains the sub-private key and the first data from the blockchain. Specifically, the user device may send a transaction to the blockchain 100, and the transaction may call the contract C1 to obtain the sub-private key and the first data from the blockchain. The node of the blockchain executes the transaction and sends the sub-private key and the first data to the user device.
[0079] S506: The user device decrypts the first data using the sub-private key. When the attribute tag conforms to the preset policy, the decryption is successful, and the second data is obtained.
[0080] In this embodiment, the user device can obtain the sub-private key and the first data from the blockchain, and try to use the sub-private key to decrypt the first data. When the attribute tag meets the preset policy, the decryption is successful and the second data is obtained. Here, the second data is the same as the information to be uploaded to the blockchain used when generating the first data. For example, the user device can try to decrypt the first data by calling the Decrypt function of the CP-ABE encryption system. Specifically,
[0081] Second data=CPABE_DECRYPT(first data, sk).
[0082] Through the Decrypt function, only when the user's attribute tag meets the policy of the first data can the decryption be successful to obtain the second data.
[0083] Continue with Figure 4 Taking the preset policy shown as an example, the first data encrypted by this policy can only be decrypted by users who meet the condition of "high credit company" and at least two of the three conditions of "luxury goods", "cultural trends" and "clothing", otherwise the decryption fails. For example, user A, the attribute tags assigned to it by the management device include "high credit company", "luxury goods", and "hotel", then user A cannot decrypt the first data. For another example, user B, the attribute tags assigned to it by the management device include "high credit company", "luxury goods", "clothing", and "national trend", then user B can decrypt the first data and obtain the second data.
[0084] Reviewing the above process, in the above embodiments of this specification, the data owner sets the encryption policy according to its own needs, and performs attribute encryption based on the policy to obtain the first data. During decryption, only the user device of the user whose attribute tag matches the preset policy corresponding to the first data can successfully decrypt the first data and obtain the second data, thereby realizing the control of data reading in the blockchain and improving the security of the data in the blockchain.
[0085] This specification also shows a method for obtaining data based on blockchain in one embodiment. The method can be applied to blockchain nodes. The blockchain nodes can be executed by any device, equipment, platform, or device cluster with computing and processing capabilities. The method for obtaining data based on blockchain can include the following steps:
[0086] Step 1: Receive user information and store it in the blockchain.
[0087] In this embodiment, the first data stored in the blockchain is obtained by attribute encryption based on the master public key of the management device and the preset policy. The blockchain node can receive user information sent by the user device and store the user information in the blockchain, and the user information can be used for account registration. User information can include business certification information, enterprise information, asymmetric encryption public key accountPK, etc. Among them, enterprise information can include enterprise name, address, customer group, enterprise business scope, category of goods or services provided, scale, etc.
[0088] In some optional implementations, before step 1, the method may further include the following:
[0089] First, the blockchain node can receive a first transaction sent by a data owner device, and the first transaction can call a contract to upload the first data to the blockchain.
[0090] Then, the blockchain node can execute the first transaction and store the first data in the contract state of the contract. Through this implementation, the storage of the first data in the contract can be achieved.
[0091] Optionally, the above method may further include the following contents:
[0092] 1) Receive a second transaction for calling a contract sent by a management device, wherein the second transaction is used to receive first data from a blockchain.
[0093] 2) Execute the second transaction and send the first data to the management device. Afterwards, the management device can use the master private key msk to decrypt the first data to obtain the second data and check whether the second data is legal. As an example, the management device can decrypt the first data by calling the DECRYPT function of the CP-ABE encryption system to obtain the second data. Specifically:
[0094] Second data=CPABE_DECRYPT(first data, msk).
[0095] After decrypting the second data, the management device can check whether the second data is legal. If it is determined that the check fails, the management device can send a third transaction that calls the contract to the blockchain.
[0096] 3) Receive and execute a third transaction sent by the management device, and record the first data as illegal data in the contract status of the contract, wherein the third transaction is sent by the management device when the second data fails to pass the check.
[0097] Step 2: In response to the request sent by the management device, the user information is sent to the management device.
[0098] In this embodiment, the management device can monitor the registration event of the user device on the chain. After monitoring the registration event of the user, the management device can send a request to the blockchain for obtaining the user information. In response to the request sent by the management device, the blockchain node can send the user information to the management device. After that, the management device can determine the attribute tag of the user based on the user information, and generate the user's sub-private key based on the attribute tag, the master public key of the management device and the master private key of the management device, and upload the user's user ID to the blockchain in association with the sub-private key.
[0099] Step 3: Receive the sub-private key from the management device and store the sub-private key in the blockchain.
[0100] In this embodiment, the blockchain node can receive the user's user identification and sub-private key from the management device, and store the user's user identification and sub-private key in association in the blockchain. The sub-private key is generated based on the user information, the master public key of the management device, and the master private key of the management device. For example, the management device can extract the attribute tag from the user information. Afterwards, the management device can generate the user's sub-private key based on the attribute tag, the master public key mpk, and the master private key msk. For example, the management device can generate a user-specific sub-private key sk by calling the KeyGen function of the CP-ABE encryption system. Specifically,
[0101] sk=CPABE_KeyGen(attribute tag, msk, mpk).
[0102] In some optional implementations, storing the sub-private key in the blockchain may be performed as follows: storing the user identifier of the user and the ciphertext of the sub-private key in association with each other in the blockchain, wherein the ciphertext of the sub-private key may be obtained by encrypting the sub-private key based on the public key of the blockchain account corresponding to the user device.
[0103] Step 4: In response to the request sent by the user device, the sub-private key and the first data are sent to the user device.
[0104] In this embodiment, the user device may send a request to the blockchain node for obtaining a sub-private key, and in response to the request sent by the user device, the blockchain node may send the sub-private key to the user device. The user device may also send a request to the blockchain node for obtaining first data, and in response to the request sent by the user device, the blockchain node may send the first data to the user device. Afterwards, the user device may use the sub-private key to decrypt the first data, and in the case where the attribute tag meets the preset policy, the decryption is successful, and the second data is obtained.
[0105] According to another embodiment, a device for obtaining data based on blockchain is provided. The device for obtaining data based on blockchain can be set in a blockchain node, wherein the blockchain node can be deployed in any device, platform or device cluster with computing and processing capabilities.
[0106] Figure 7 A schematic block diagram of a device for obtaining data based on blockchain according to an embodiment is shown. The first data stored in the blockchain is obtained by encrypting the attributes based on the master public key of the management device and a preset policy. Figure 7 As shown, the device 700 for obtaining data based on blockchain includes: a receiving unit 701, configured to receive user information and store the above user information in the blockchain; a sending unit 702, configured to send the above user information to the above management device in response to a request sent by the management device; a storage unit 703, configured to receive a sub-private key from the above management device, and store the above sub-private key in the blockchain, wherein the above sub-private key is generated based on the above user information, the master public key of the above management device and the master private key of the above management device; a data sending unit 704, configured to send the above sub-private key and the above first data to the above user device in response to a request sent by the above user device.
[0107] In some optional implementations of this embodiment, the storage unit 703 is further configured to: store the user identifier of the user and the ciphertext of the sub-private key in association in the blockchain, wherein the ciphertext of the sub-private key is obtained by encrypting the sub-private key based on the public key of the blockchain account corresponding to the user device.
[0108] In some optional implementations of this embodiment, the above-mentioned device 700 also includes: a first transaction receiving unit (not shown in the figure), configured to receive a first transaction sent by the above-mentioned data owner device, wherein the above-mentioned first transaction calls a contract to upload the above-mentioned first data to the above-mentioned blockchain; a first transaction execution unit (not shown in the figure), configured to execute the above-mentioned first transaction and store the above-mentioned first data in the contract state of the above-mentioned contract.
[0109] In some optional implementations of this embodiment, the above-mentioned device 700 also includes: a second transaction receiving unit (not shown in the figure), configured to receive a second transaction sent by the above-mentioned management device to call the above-mentioned contract, wherein the above-mentioned second transaction is used to receive the above-mentioned first data from the above-mentioned blockchain; a second transaction execution unit (not shown in the figure), configured to execute the above-mentioned second transaction and send the above-mentioned first data to the above-mentioned management device; a third transaction receiving unit (not shown in the figure), configured to receive and execute the third transaction sent by the above-mentioned management device, and record the above-mentioned first data as illegal data in the contract status of the above-mentioned contract, wherein the above-mentioned third transaction is sent by the above-mentioned management device when checking that the above-mentioned second data fails.
[0110] According to another embodiment, a computer-readable storage medium is also provided, on which a computer program is stored. When the above-mentioned computer program is executed in a computer, the computer executes a method for obtaining data based on blockchain, and the method can be applied to blockchain nodes.
[0111] According to an embodiment of another aspect, a computing device is also provided, including a memory and a processor, characterized in that an executable code is stored in the memory, and when the processor executes the executable code, a method for obtaining data based on blockchain is implemented, and the method can be applied to blockchain nodes. In the 1990s, improvements to a technology can be clearly distinguished as hardware improvements (for example, improvements to circuit structures such as diodes, transistors, switches, etc.) or software improvements (improvements to method flows). However, with the development of technology, many improvements to method flows today can be regarded as direct improvements to hardware circuit structures. Designers almost always obtain corresponding hardware circuit structures by programming improved method flows into hardware circuits. Therefore, it cannot be said that an improvement in a method flow cannot be implemented using a hardware entity module. For example, a programmable logic device (PLD) (such as a field programmable gate array (FPGA)) is such an integrated circuit whose logical function is determined by the user programming the device. Designers program by themselves to "integrate" a digital system on a PLD without having to ask chip manufacturers to design and make dedicated integrated circuit chips. Moreover, nowadays, instead of manually making integrated circuit chips, this kind of programming is mostly implemented with "logic compiler" software, which is similar to the software compiler used when developing and writing programs. The original code before compilation must also be written in a specific programming language, which is called hardware description language (HDL). There is not only one HDL, but many types, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog.Those skilled in the art should also be aware that it is easy to obtain a hardware circuit that implements the logical method flow by simply performing some logic programming on the method flow using the above-mentioned hardware description languages and programming it into an integrated circuit.
[0112] The controller can be implemented in any appropriate manner, for example, the controller can take the form of a microprocessor or processor and a computer-readable medium storing a computer-readable program code (such as software or firmware) that can be executed by the (micro)processor, a logic gate, a switch, an application-specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that in addition to implementing the controller in a purely computer-readable program code manner, the controller can be implemented in the form of a logic gate, a switch, an application-specific integrated circuit, a programmable logic controller, and an embedded microcontroller by logically programming the method steps. Therefore, this controller can be considered as a hardware component, and the devices included therein for implementing various functions can also be regarded as structures within the hardware component. Or even, the devices for implementing various functions can be regarded as both software modules for implementing the method and structures within the hardware component.
[0113] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a server system. Of course, the present application does not exclude that with the development of computer technology in the future, the computer that implements the functions of the above embodiments may be, for example, a personal computer, a laptop computer, a vehicle-mounted human-computer interaction device, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0114] Although one or more embodiments of the present specification provide method operation steps as described in the embodiments or flow charts, more or less operation steps may be included based on conventional or non-creative means. The order of steps listed in the embodiments is only one way of executing the order of many steps, and does not represent the only execution order. When the device or terminal product in practice is executed, it can be executed in sequence or in parallel according to the method shown in the embodiments or the drawings (for example, a parallel processor or a multi-threaded processing environment, or even a distributed data processing environment). The term "include", "include" or any other variant thereof is intended to cover non-exclusive inclusion, so that the process, method, product or equipment including a series of elements includes not only those elements, but also includes other elements that are not explicitly listed, or also includes elements inherent to such a process, method, product or equipment. In the absence of more restrictions, it is not excluded that there are other identical or equivalent elements in the process, method, product or equipment including the elements. For example, if the words first, second, etc. are used to represent the name, they do not represent any specific order.
[0115] For the convenience of description, the above devices are described in various modules according to their functions. Of course, when implementing one or more of the present specification, the functions of each module can be implemented in the same or more software and / or hardware, or the module implementing the same function can be implemented by a combination of multiple sub-modules or sub-units, etc. The device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0116] The present invention is described with reference to flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0117] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0118] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0119] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0120] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0121] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage, graphene storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0122] It should be understood by those skilled in the art that one or more embodiments of the present specification may be provided as a method, system or computer program product. Therefore, one or more embodiments of the present specification may take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Moreover, one or more embodiments of the present specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0123] One or more embodiments of this specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. One or more embodiments of this specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.
[0124] Each embodiment in this specification is described in a progressive manner, and the same and similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment. In the description of this specification, the description of the reference terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of this specification. In this specification, the schematic representation of the above terms does not necessarily target the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples without contradiction.
[0125] The above description is only an example of one or more embodiments of this specification and is not intended to limit one or more embodiments of this specification. For those skilled in the art, one or more embodiments of this specification may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this specification shall be included in the scope of the claims.
Claims
1. A method for obtaining data based on blockchain, the method comprising: The management device generates a master public key and a master private key, and uploads the master public key to the blockchain; After the data owner device obtains the master public key from the blockchain, it performs attribute encryption on the information to be uploaded to the blockchain based on the master public key and a preset strategy to generate first data, and uploads the first data to the blockchain so that it is stored in the contract state of the contract; The user device uploads user information to the blockchain, where the user information includes at least one of business certification information and enterprise information; The management device obtains the user information from the blockchain, determines the attribute tag of the user based on the user information, generates a sub-private key of the user based on the attribute tag, the master public key of the management device and the master private key of the management device, and uploads the sub-private key to the blockchain; The user device obtains the sub-private key and the first data from the blockchain, and the user device decrypts the first data using the sub-private key. When the attribute tag meets the preset policy, the decryption is successful, and the second data is obtained, and the second data is the same as the information to be uploaded to the blockchain; The management device receives the first data from the blockchain by sending a second transaction to the blockchain to call the contract; the management device decrypts the first data using the generated master private key to obtain the second data, and checks whether the second data is legal; if the check fails, a third transaction to call the contract is sent to the blockchain, and the first data is recorded as illegal data in the contract status of the contract.
2. The method according to claim 1, wherein: The uploading of the sub-private key to the blockchain includes: The management device encrypts the sub-private key based on the public key of the blockchain account corresponding to the user device to obtain an encryption result, and uploads the encryption result to the blockchain in association with the user identifier of the user, so that the user device can decrypt the sub-private key after obtaining the encryption result from the blockchain.
3. The method according to claim 1, wherein: The data owner device uploading the first data to the blockchain includes: The data owner device sends a first transaction to the blockchain, where the first transaction calls a contract to upload the first data to the blockchain; The node of the blockchain executes the first transaction and stores the first data in the contract state of the contract.
4. The method according to claim 3, wherein: The first transaction is also used to upload the first hash value of the second data to the blockchain, and the management device checks whether the second data is legal, specifically including: The management device obtains the first hash value from the blockchain and calculates a second hash value of the second data; A determination is made as to whether the second hash value matches the first hash value.
5. The method according to claim 1, wherein: The user device uploading user information to the blockchain includes: The user device uploads user information to the blockchain for user registration or for updating user information.
6. A method for obtaining data based on blockchain, applied to a blockchain node, the method comprising: Receiving a master public key uploaded by a management device, the management device also generates a master private key corresponding to the master public key; Send the master public key to the data owner device, receive the first data uploaded by it, and store the first data in the contract state of the contract; wherein the first data is generated by the data owner device by encrypting the attributes of the on-chain information based on the master public key and a preset strategy; Receiving user information, and storing the user information in a blockchain, wherein the user information includes at least one of business certification information and enterprise information; In response to a request sent by a management device, sending the user information to the management device; Receiving a child private key from the management device, and storing the child private key in a blockchain, wherein the child private key is generated based on an attribute tag, a master public key of the management device, and a master private key of the management device, and the attribute tag is determined based on the user information; In response to a request sent by a user device, the sub-private key and the first data are sent to the user device, and the user device decrypts the first data using the sub-private key. When the attribute tag meets the preset policy, the decryption is successful, and the second data is obtained, and the second data is the same as the information to be uploaded to the chain; receiving a second transaction sent by the management device for calling the contract, wherein the second transaction is used to receive the first data from the blockchain; executing the second transaction and sending the first data to the management device; Receive and execute a third transaction sent by the management device, and record the first data as illegal data in the contract status of the contract, wherein the third transaction is sent by the management device when checking that the second data does not pass.
7. The method according to claim 6, wherein: Storing the sub-private key in the blockchain includes: The user identification of the user and the ciphertext of the sub-private key are stored in association in the blockchain, wherein the ciphertext of the sub-private key is obtained by encrypting the sub-private key based on the public key of the blockchain account corresponding to the user device.
8. The method according to claim 6, wherein: Receiving the first data uploaded by the user, and storing the first data in the contract state of the contract, includes: Receiving a first transaction sent by a data owner device, wherein the first transaction calls a contract to upload the first data to the blockchain; Execute the first transaction and store the first data in the contract state of the contract.
9. A device for acquiring data based on blockchain, arranged in a blockchain node, comprising: A first receiving unit is configured to receive a master public key uploaded by a management device, wherein the management device also generates a master private key corresponding to the master public key; An interaction unit is configured to send the master public key to the data owner device, receive the first data uploaded by the data owner device, and store the first data in the contract state of the contract; wherein the first data is generated by the data owner device by encrypting the on-chain information based on the master public key and a preset strategy; A second receiving unit is configured to receive user information and store the user information in the blockchain, wherein the user information includes at least one of business certification information and enterprise information; a sending unit, configured to send the user information to the management device in response to a request sent by the management device; a storage unit configured to receive a sub-private key from the management device, and store the sub-private key in a blockchain, wherein the sub-private key is generated based on an attribute tag, a master public key of the management device, and a master private key of the management device, and the attribute tag is determined based on the user information; a data sending unit, configured to send the sub-private key and the first data to the user device in response to a request sent by the user device, wherein the user device decrypts the first data using the sub-private key, and when the attribute tag conforms to the preset policy, the decryption succeeds to obtain the second data; A second transaction receiving unit is configured to receive a second transaction sent by the management device to call the contract, wherein the second transaction is used to receive the first data from the blockchain; a second transaction execution unit, configured to execute the second transaction and send the first data to the management device; A third transaction receiving unit is configured to receive and execute a third transaction sent by the management device, and record the first data as illegal data in the contract status of the contract, wherein the third transaction is sent by the management device when checking that the second data fails.
10. The device according to claim 9, wherein: The storage unit is further configured as: The user identification of the user and the ciphertext of the sub-private key are stored in association in the blockchain, wherein the ciphertext of the sub-private key is obtained by encrypting the sub-private key based on the public key of the blockchain account corresponding to the user device.
11. The device according to claim 9, wherein: The interaction unit is specifically configured as follows: A first transaction receiving unit is configured to receive a first transaction sent by a data owner device, wherein the first transaction calls a contract to upload the first data to the blockchain; A first transaction execution unit is configured to execute the first transaction and store the first data in the contract state of the contract.
12. A computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to execute the method according to any one of claims 6 to 8.
13. A computing device comprising a memory and a processor, characterized in that: The memory stores executable codes, and when the processor executes the executable codes, the method according to any one of claims 6 to 8 is implemented.
Citation Information
Patent Citations
Block chain data sharing method and device, computer equipment and storage medium
CN111935080A
IP content library service processing method, device and equipment
CN114465790A