Data processing system, data processing method
Through blockchain network and homomorphic encryption technology, data leakage problems during data interaction are solved, data transmission and processing are achieved, and data immutability and availability are ensured.
Patent Information
- Application Number
- CN202210812928.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-11
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2042-07-11
AI Technical Summary
During the data interaction process, the existing technology has the risk of data leakage, especially when relying on centralized third-party institutions, data security is difficult to guarantee.
The node set in the blockchain network is used to determine the target computing end through consensus, and the data is processed using homomorphic encryption technology to ensure that the data is transmitted and processed in the ciphertext state and avoid the leakage of the original data.
It reduces the risk of data leakage during data processing, ensures the security and immutability of data, while maintaining the availability and operability of data.
Smart Images

Figure CN115276946B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the technical field of data processing, and specifically, to a data processing system and a data processing method. Background Art
[0002] Data elements formed by big data come from both personal behaviors such as clothing, food, housing, transportation, medical care, and social interactions, and statistics and collections after services provided by platform companies, governments, and commercial institutions. Currently, aggregating multi-dimensional massive data and mining and utilizing the intrinsic value of data have become the research focus of many industrial institutions.
[0003] However, in related scenarios, data still faces risks during multi-party transmission, and data leakage is likely to occur. Summary of the Invention
[0004] The purpose of the present disclosure is to provide a data processing system and a data processing method to solve the above technical problems.
[0005] To achieve the above purpose, according to the first aspect of the embodiments of the present disclosure, a data processing system is provided, including a target data end, a plurality of computing ends, and a node set. The node set includes a plurality of blockchain nodes in a blockchain network. Among them,
[0006] The plurality of blockchain nodes in the node set are used to determine a target computing end from the plurality of computing ends through consensus;
[0007] The target data end is used to homomorphically encrypt the data to be processed to obtain first ciphertext data, and save the first ciphertext data to the blockchain in the blockchain network through the node set;
[0008] The target computing end is used to obtain the first ciphertext data, process the first ciphertext data to obtain a processing result, and save the processing result to the blockchain through the node set, so that the target data end can obtain the processing result.
[0009] Optionally, the target data end is used to generate a homomorphic key pair, save the homomorphic public key in the homomorphic key pair to the blockchain through the node set, and homomorphically encrypt the data to be processed with the homomorphic public key to obtain first ciphertext data;
[0010] The target computing end is used to obtain the first ciphertext data and the homomorphic public key in the blockchain, and process the first ciphertext data based on the homomorphic public key.
[0011] Optionally, the target data end is used to generate the homomorphic key pair in response to receiving a data processing request for the data to be processed.
[0012] Optionally, it includes multiple data terminals, and the target data terminal is any one of the multiple data terminals. The target data terminal is further configured to send the homomorphic private key in the homomorphic key pair to other data terminals among the multiple data terminals;
[0013] The target computing terminal is further configured to generate an encryption key pair, and save the encryption public key in the encryption key pair to the blockchain through the node set;
[0014] The target data terminal is further configured to obtain the encryption public key in the blockchain, encrypt the first ciphertext data based on the encryption public key, and save the encrypted second ciphertext data to the blockchain;
[0015] The target computing terminal is further configured to obtain the second ciphertext data in the blockchain, decrypt the second ciphertext data based on the encryption private key in the encryption key pair, and obtain the first ciphertext data.
[0016] Optionally, the target data terminal is further configured to encrypt the verification information based on the homomorphic private key, obtain encrypted verification information, save the encrypted verification information to the blockchain, and send the verification information and the homomorphic private key to other data terminals among the multiple data terminals;
[0017] Any of the data terminals is configured to obtain the encrypted verification information from the blockchain, and verify the correctness of the homomorphic private key through the encrypted verification information and the verification information when receiving the verification information and the homomorphic private key.
[0018] Optionally, the multiple data terminals are further configured to consensus-determine the processing rules for the data to be processed, and save the processing rules to the blockchain;
[0019] The target computing terminal is configured to obtain the processing rules in the blockchain, and process the first ciphertext data according to the processing rules and the homomorphic public key to obtain a processing result.
[0020] Optionally, the target computing terminal is further configured to encrypt the processing result through the encryption private key to obtain an encrypted processing result, and save the encrypted processing result to the blockchain through the node set;
[0021] Any of the data terminals is configured to obtain the encrypted processing result from the blockchain, decrypt the obtained encrypted processing result through the encryption public key to obtain the processing result, and decrypt the processing result through the homomorphic private key to obtain the plaintext of the processing result.
[0022] Optionally, multiple blockchain nodes in the node set are used to,
[0023] in response to receiving a data processing request from the target data end, consensus-determine a target computing end from the multiple computing ends through consensus; or,
[0024] at preset time intervals, consensus-determine a target computing end from the multiple computing ends through consensus.
[0025] Optionally, the node set includes multiple blockchain consensus nodes, and the multiple blockchain consensus nodes determine a target computing end from the multiple computing ends in the following manner:
[0026] Obtain the data processing history records of each computing end, where the data processing history records include data processing metrics;
[0027] Determine the target computing end from each computing end according to the data processing metrics.
[0028] According to a second aspect of the embodiments of the present disclosure, a data processing method is provided, which is applied to the data processing system described in any one of the first aspects above. The method includes:
[0029] Multiple blockchain nodes in the node set consensus-determine a target computing end from multiple computing ends through consensus;
[0030] The target data end homomorphically encrypts the data to be processed to obtain first ciphertext data;
[0031] The target data end saves the first ciphertext data to a blockchain in a blockchain network through the node set;
[0032] The target computing end obtains the first ciphertext data;
[0033] The target computing end processes the first ciphertext data to obtain a processing result;
[0034] The target computing end saves the processing result to the blockchain through the node set, so that the target data end can obtain the processing result.
[0035] Optionally, the method further includes:
[0036] The target data end generates a homomorphic key pair;
[0037] The target data end saves the homomorphic public key in the homomorphic key pair to the blockchain through the node set;
[0038] The target data terminal performs homomorphic encryption on the data to be processed to obtain first ciphertext data, including: the target data terminal performs homomorphic encryption on the data to be processed through the homomorphic public key to obtain first ciphertext data;
[0039] The target computing terminal processes the first ciphertext data to obtain a processing result, including:
[0040] The target computing terminal obtains the homomorphic public key in the blockchain and processes the first ciphertext data based on the homomorphic public key to obtain a processing result.
[0041] Optionally, the target data terminal generates a homomorphic key pair, including:
[0042] The target data terminal generates the homomorphic key pair in response to receiving a data processing request for the data to be processed.
[0043] Optionally, the data processing system includes multiple data terminals, the target data terminal is any one of the multiple data terminals, and the method further includes:
[0044] The target data terminal sends the homomorphic private key in the homomorphic key pair to other data terminals among the multiple data terminals;
[0045] The target computing terminal generates an encryption key pair and saves the encryption public key in the encryption key pair to the blockchain through the node set;
[0046] The target data terminal obtains the encryption public key in the blockchain, encrypts the first ciphertext data based on the encryption public key, and saves the second ciphertext data obtained by encryption to the blockchain;
[0047] The target computing terminal obtains the first ciphertext data, including:
[0048] The target computing terminal obtains the second ciphertext data in the blockchain, decrypts the second ciphertext data based on the encryption private key in the encryption key pair, and obtains the first ciphertext data.
[0049] Optionally, the target data terminal sending the homomorphic private key in the homomorphic key pair to other data terminals among the multiple data terminals includes:
[0050] The target data terminal encrypts the verification information based on the homomorphic private key to obtain encrypted verification information, saves the encrypted verification information to the blockchain, and sends the verification information and the homomorphic private key to other data terminals among the multiple data terminals;
[0051] The method further includes: any of the data terminals obtains the encrypted verification information from the blockchain, and when receiving the verification information and the homomorphic private key, verifies the correctness of the homomorphic private key through the encrypted verification information and the verification information.
[0052] Optionally, it further includes:
[0053] Multiple data terminals reach a consensus to determine the processing rule of the data to be processed, and save the processing rule to the blockchain;
[0054] The target computing terminal processes the first ciphertext data to obtain a processing result, including:
[0055] The target computing terminal obtains the processing rule in the blockchain, and processes the first ciphertext data according to the processing rule and the homomorphic public key to obtain a processing result.
[0056] Optionally, it further includes:
[0057] The target computing terminal encrypts the processing result through the encrypted private key to obtain an encrypted processing result, and saves the encrypted processing result to the blockchain through the node set;
[0058] Any of the data terminals obtains the encrypted processing result from the blockchain, decrypts the obtained encrypted processing result through the encrypted public key to obtain the processing result, and decrypts the processing result through the homomorphic private key to obtain the plaintext of the processing result.
[0059] Optionally, multiple blockchain nodes in the node set determine the target computing terminal through consensus from multiple computing terminals, including:
[0060] Multiple blockchain nodes in the node set respond to the data processing request of the target data terminal, and consensus to determine the target computing terminal from the multiple computing terminals; or,
[0061] Multiple blockchain nodes in the node set determine the target computing terminal through consensus from the multiple computing terminals according to a preset time period.
[0062] Optionally, the node set includes multiple blockchain consensus nodes, and multiple blockchain nodes in the node set determine the target computing terminal through consensus from multiple computing terminals, including:
[0063] Multiple blockchain nodes in the node set obtain the data processing history records of each computing terminal, and the data processing history records include data processing metrics;
[0064] A plurality of blockchain nodes in the node set determine the target computing end from each computing end according to the data processing metrics.
[0065] In the above technical solution, a plurality of blockchain nodes in the node set can determine the target computing end from multiple computing ends through a consensus method. In this way, the problem of centralization of the computing end can be avoided, and the risk of data leakage can be reduced. During data processing, the target data end can perform homomorphic encryption on the data to be processed to obtain the first ciphertext data, and save the first ciphertext data to the blockchain. In this way, the target computing end can obtain the first ciphertext data in the blockchain and process the data to be processed in the ciphertext state. After the processing is completed, the processing result can be uploaded to the blockchain for the target data end to obtain. That is to say, the first ciphertext data is a homomorphic ciphertext, and the target computing end also processes based on the homomorphic ciphertext without obtaining the original data. At the same time, the first ciphertext data and the processing result in the data processing process are transferred through the blockchain, and have the properties of being tamper-proof and traceable. Therefore, the above technical solution can reduce the risk of data leakage in the data processing process and ensure the security of the data.
[0066] Other features and advantages of the present disclosure will be described in detail in the subsequent specific implementation section. BRIEF DESCRIPTION OF THE DRAWINGS
[0067] The drawings are used to provide a further understanding of the present disclosure, and constitute a part of the specification. They are used together with the following specific implementation to explain the present disclosure, but do not constitute a limitation to the present disclosure. In the drawings:
[0068] Figure 1 is a block diagram of a data processing system shown in an exemplary embodiment of the present disclosure.
[0069] Figure 2 is a block diagram of a data processing system shown in an exemplary embodiment of the present disclosure.
[0070] Figure 3 is a block diagram of a data processing system shown in an exemplary embodiment of the present disclosure.
[0071] Figure 4 is a flowchart of a data processing method shown in an exemplary embodiment of the present disclosure.
[0072] Figure 5 is a flowchart of a data processing method shown in an exemplary embodiment of the present disclosure.
[0073] Figure 6 is a flowchart of a data processing method shown in an exemplary embodiment of the present disclosure.
[0074] Figure 7 It is a flowchart of a data processing method shown in an exemplary embodiment of the present disclosure. Detailed implementation manners
[0075] The following will describe in detail the specific implementation manners of the present disclosure with reference to the accompanying drawings. It should be understood that the specific implementation manners described herein are only used to illustrate and explain the present disclosure, and are not used to limit the present disclosure.
[0076] Before introducing the data processing system and data processing method of the present disclosure, the application scenarios of the present disclosure will be introduced first. Each embodiment provided by the present disclosure can be used in various data processing scenarios, such as calculating the average value of multi-party data, model training based on multi-party data, and so on.
[0077] In related scenarios, when multi-party data is exchanged, due to the lack of trust among all parties, a trusted third-party institution can be introduced. In this way, data can be exchanged among all parties through the trusted third-party institution. However, such a method still faces data security risks. For example, in some scenarios, the third-party institution acts as a data transfer party and has a high degree of centralization. When the third-party institution is attacked, phenomena such as data unable to flow and data leakage may occur. In some scenarios, the third-party institution may also have a high data viewing permission, so data leakage may occur.
[0078] Therefore, the present disclosure provides a data processing system, which includes a target data end, multiple computing ends, and a node set. The node set includes multiple blockchain nodes in a blockchain network. Among them, the target data end and the computing end can be nodes in the blockchain network or other devices capable of interacting with the blockchain network, and the present disclosure does not limit this.
[0079] Figure 1 It is a block diagram of a data processing system shown in an exemplary embodiment of the present disclosure. In Figure 1 the example of, the node set includes N nodes in the blockchain network, and the computing ends include computing end 1 to computing end M.
[0080] Among them, each blockchain node in the node set can be presented in the form of various computing devices. These computing devices can be servers, laptop computers, desktop computers, etc., or a combination thereof. In addition, the blockchain nodes in the node set can have different functions. For example, node 1 to node 4 can be nodes for consensus, such as endorsement nodes in a related blockchain network. Node 5 to node N can be accounting nodes for bookkeeping. Of course, based on the settings of the blockchain network, in some scenarios, the same blockchain node in the node set can also be used for consensus and bookkeeping, and the present disclosure does not limit this.
[0081] In the data processing system, multiple blockchain nodes in the node set are used to determine a target computing end from the multiple computing ends through consensus.
[0082] Here, in a possible implementation, multiple blockchain nodes in the node set are used to, in response to receiving a data processing request from the target data end, determine a target computing end from the multiple computing ends through consensus. That is to say, a target computing end for processing the data processing request can be determined when the data processing request from the target data end is received.
[0083] In a possible implementation, multiple blockchain nodes in the node set are used to, according to a preset time period, determine a target computing end from the multiple computing ends through consensus.
[0084] That is to say, the multiple blockchain nodes can determine the target computing end through consensus according to a preset time period (such as one hour, one day). In this way, when the target data end needs to perform data processing, it can query the current target computing end and then perform data processing through the target computing end.
[0085] In a possible implementation, the node set includes multiple blockchain consensus nodes, and the multiple blockchain consensus nodes determine a target computing end from the multiple computing ends in the following manner:
[0086] Obtain the data processing history records of each computing end, where the data processing history records include data processing metrics;
[0087] Determine the target computing end from each computing end according to the data processing metrics.
[0088] Exemplarily, after the data processing is completed, the target data end can upload the data processing record of the computing end used for this data processing to the blockchain. Here, the data processing record can include, for example, data processing quality parameters, data processing duration, data processing charging information, etc. Taking data processing as image recognition as an example, the data processing quality parameters can include the accuracy rate of image recognition, the success rate of image recognition, etc.
[0089] In this way, when determining the target computing end, each blockchain consensus node can obtain the data processing history records of each computing end from the blockchain. And determine the target computing end from each computing end according to the data processing metrics in the data processing history records. Exemplarily, referring to Figure 2 As shown in the block diagram of a data processing system, the blockchain consensus node can calculate the average value of the data processing times of computing end 1 to computing end M according to the obtained data processing history records, and take computing end 2 with the smallest average value as the target computing end.
[0090] In addition, it is worth noting that the steps for the blockchain node consensus to determine the target computing end described in the embodiments of the present disclosure can be used in combination with relevant consensus algorithms, such as the proof-of-work algorithm, the raft algorithm, and so on. Among them, the steps for determining the target computing end can be embedded into relevant consensus algorithms as algorithm modules. For example, in the raft algorithm, the master node can randomly select (or select in the manner of the above example) the target computing end and synchronize the target computing end to other slave nodes, thereby completing the consensus; in the proof-of-work algorithm, the node that obtains the bookkeeping right can select the target computing end and then synchronize it to other nodes, thereby completing the consensus.
[0091] Still referring to Figure 1 , the target data end is used to homomorphically encrypt the data to be processed to obtain the first ciphertext data, and save the first ciphertext data to the blockchain of the blockchain network through the node set.
[0092] The target computing end is used to obtain the first ciphertext data, process the first ciphertext data to obtain a processing result, and save the processing result to the blockchain through the node set, so that the target data end can obtain the processing result.
[0093] The following is an exemplary description of the processing flow of the first ciphertext data. In one possible implementation, the target data end is used to generate a homomorphic key pair, save the homomorphic public key in the homomorphic key pair to the blockchain through the node set, and homomorphically encrypt the data to be processed with the homomorphic public key to obtain the first ciphertext data.
[0094] Exemplarily, the target data end can pre-generate a homomorphic key pair, and the homomorphic key pair includes a homomorphic private key and a homomorphic public key. After generating the homomorphic key pair, the target data end can save the homomorphic public key to the blockchain so that the target computing end can obtain the homomorphic public key. In addition, the target data end can homomorphically encrypt the data to be processed with the homomorphic public key to obtain the first ciphertext data.
[0095] The target computing end is used to obtain the first ciphertext data and the homomorphic public key in the blockchain, and process the first ciphertext data based on the homomorphic public key.
[0096] It should be noted that the above homomorphic key pair can be used multiple times. In subsequent data processing flows, the target data end can still use the saved homomorphic key pair.
[0097] In some embodiments, the homomorphic key pair can also be one-time and used in one data processing flow.
[0098] For example, the target data end is used to generate the homomorphic key pair in response to receiving a data processing request for the data to be processed.
[0099] That is to say, when the target data end receives a data processing request, it can generate a homomorphic key pair for processing the data to be processed. In this way, when the data processing request is received next time, the target data end can regenerate a new homomorphic key pair. In this way, multiple data processing processes can use different homomorphic keys, thereby increasing the difficulty of data cracking and improving data security.
[0100] In the above technical solution, multiple blockchain nodes in the node set can determine the target computing end from multiple computing ends by consensus. In this way, the centralization problem of the computing end can be avoided and the risk of data leakage can be reduced. During data processing, the target data end can homomorphically encrypt the data to be processed to obtain the first ciphertext data, and save the first ciphertext data to the blockchain. In this way, the target computing end can obtain the first ciphertext data in the blockchain and process the data to be processed in the ciphertext state. After the processing is completed, the processing result can be uploaded to the blockchain for the target data end to obtain. In other words, the first ciphertext data is a homomorphic ciphertext, and the target computing end also processes based on the homomorphic ciphertext when processing, without obtaining the original data. At the same time, the first ciphertext data and the processing results in the data processing process are circulated through the blockchain, which has the properties of being tamper-proof and traceable. Therefore, the above technical solution can reduce the risk of data leakage in the data processing process and ensure the security of the data.
[0101] In some implementation scenarios, the data processing system may include multiple data terminals, and the target data terminal is any one of the multiple data terminals. Figure 3 is a block diagram of a data processing system shown in an exemplary embodiment of the present disclosure. Figure 3 The data processing system may include a data terminal 1, a data terminal 2 and a data terminal 3, wherein the data terminal 3 is a target data terminal.
[0102] The target data end is also used to send the homomorphic private key in the homomorphic key pair to other data ends among the multiple data ends.
[0103] For example, the target data end may be a data end that initiates the joint data processing request. Figure 3 For example, when data terminal 3 needs to jointly process data with data terminal 1 and data terminal 2, data terminal 3 can be used as the target data terminal and generate a homomorphic key pair. After generating the homomorphic key pair, the target data terminal can send the homomorphic private key in the homomorphic key pair to other data terminals.
[0104] The following provides an exemplary description of the distribution process of the homomorphic private key. In one possible implementation manner, the target data end is used to encrypt the verification information based on the homomorphic private key to obtain encrypted verification information, save the encrypted verification information to the blockchain, and send the verification information and the homomorphic private key to other data ends among the multiple data ends.
[0105] Here, the verification information (token) can be, for example, random content. The target data end can encrypt the verification information with the homomorphic private key to obtain encrypted verification information, and save the encrypted verification information to the blockchain. In addition, the target data end can distribute the homomorphic private key, for example, through off-chain communication. As an example, the target data end can distribute the homomorphic private key to other data ends in a P2P (Peer to Peer) manner.
[0106] In this way, any of the data ends is used to obtain the encrypted verification information from the blockchain, and when receiving the verification information and the homomorphic private key, verify the correctness of the homomorphic private key through the encrypted verification information and the verification information.
[0107] Continue with Figure 3 In the example, when Data End 1 and Data End 2 receive the verification information and the homomorphic private key, they can encrypt the verification information with the received homomorphic private key to obtain target verification information. In this way, Data End 1 and Data End 2 can compare the target verification information with the obtained encrypted verification information. When the target verification information is consistent with the encrypted verification information, it is determined that the homomorphic private key is correct; when the target verification information is inconsistent with the encrypted verification information, it is determined that the homomorphic private key is incorrect. In this way, it can be ensured that the homomorphic private key is correctly distributed.
[0108] It should be noted that since the homomorphic private keys of each data end are the same, the data ends can decrypt the data encrypted by other data ends with the homomorphic public key through the homomorphic private key. In this case, there may be a phenomenon of data leakage.
[0109] For this reason, the present disclosure also introduces a double-encryption mechanism. In this case, the target computing end is further used to generate an encryption key pair, and save the encryption public key in the encryption key pair to the blockchain through the node set;
[0110] The target data end is further used to obtain the encryption public key in the blockchain, encrypt the first ciphertext data based on the encryption public key, and save the encrypted second ciphertext data to the blockchain;
[0111] The target computing end is further configured to obtain second ciphertext data in the blockchain, and decrypt the second ciphertext data based on the encryption private key in the encryption key pair to obtain the first ciphertext data.
[0112] That is to say, the target data end can encrypt the data to be processed through the homomorphic public key to obtain the first ciphertext data, and encrypt the first ciphertext data through the encryption public key to obtain the second ciphertext data. In this way, since the encryption private key is held by the target computing end, the data end and the blockchain nodes in the node set cannot decrypt the second ciphertext data without the encryption private key. Therefore, even if the second ciphertext data is uploaded to the blockchain, the data end and the blockchain nodes in the node set cannot obtain the original text of the second ciphertext data. In addition, since the target computing end has the encryption private key, it can decrypt the second ciphertext data to obtain the first ciphertext data. However, since the target computing end lacks the homomorphic private key, the target computing end cannot obtain the original text of the second ciphertext data either.
[0113] With the above technical solution, other data ends, blockchain nodes in the node set, and the target computing end can only obtain data in some stages of the data processing process, and cannot obtain the original data of the target data end through any party. Moreover, the homomorphic ciphertext (the first encrypted data) is also operable. Therefore, the above technical solution hides the data plaintext while ensuring the availability and operability of the data, thus achieving the effect of data being available but invisible, which helps to ensure data security.
[0114] The following is an exemplary description of the processing method of the target computing end for the first ciphertext data. In a possible implementation manner, the multiple data ends are further configured to consensus-determine the processing rule of the data to be processed and save the processing rule to the blockchain.
[0115] The target computing end is configured to obtain the processing rule in the blockchain and process the first ciphertext data according to the processing rule and the homomorphic public key to obtain a processing result.
[0116] Take Figure 3 as an example. In some implementation scenarios, data end 1 has data to be processed A, data end 2 has data to be processed B, and data end 3 has data to be processed C. In this way, data ends 1 to 3 can agree on the processing rule of the data (for example, calculating the average value of data to be processed A, data to be processed B, and data to be processed C), and save the processing rule to the blockchain, or deploy the processing rule in the blockchain in the form of a smart contract.
[0117] In this case, the target computing end can obtain the processing rules in the blockchain, the first ciphertext data a of data end 1, the first ciphertext data b of data end 2, the first ciphertext data c of data end 3, and the homomorphic public key. In this way, the target computing end can process the first ciphertext data a, the first ciphertext data b, and the first ciphertext data c based on the homomorphic computing method to obtain a processing result. In addition, the target computing end can also upload the processing result to the blockchain so that data end 1, data end 2, and data end 3 can obtain the processing result.
[0118] In a possible implementation manner, the target computing end is further configured to encrypt the processing result with the encryption private key to obtain an encrypted processing result, and save the encrypted processing result to the blockchain through the node set;
[0119] Any of the data ends is configured to obtain the encrypted processing result from the blockchain, decrypt the obtained encrypted processing result with the encryption public key to obtain the processing result, and decrypt the processing result with the homomorphic private key to obtain the plaintext of the processing result.
[0120] Continuing with the above example regarding Figure 3 Data end 1, data end 2, and data end 3 can obtain the encrypted processing result from the blockchain and decrypt the obtained encrypted processing result with the encryption public key to obtain the processing result. In this way, data end 1, data end 2, and data end 3 can decrypt the processing result with the homomorphic private key to obtain the average value of the data to be processed A, the data to be processed B, and the data to be processed C.
[0121] With the above technical solution, multiple data ends can jointly perform data processing. During the data processing process, other data ends, blockchain nodes in the node set, and the target computing end can only obtain data at some stages, and it is impossible to obtain the original data of the target data end through any party. Moreover, the homomorphic ciphertext (the first encrypted data) is also operable. Therefore, the above technical solution hides the data plaintext while ensuring the availability and operability of the data, thereby achieving the effect of data being available but invisible, which helps to ensure data security.
[0122] Based on the same inventive concept, the present disclosure also provides a data processing method applied to the data processing system provided by the present disclosure. Figure 4 is a flowchart of a data processing method shown in an exemplary embodiment of the present disclosure. Referring to Figure 4 , the method includes:
[0123] In step S41, multiple blockchain nodes in the node set determine a target computing end through consensus from multiple computing ends.
[0124] In a possible implementation, multiple blockchain nodes in the node set may, in response to receiving a data processing request from the target data terminal, consensus-determine a target computing terminal from the multiple computing terminals through consensus. That is to say, in the case of receiving the data processing request from the target data terminal, a target computing terminal for processing the data processing request may be determined.
[0125] In a possible implementation, multiple blockchain nodes in the node set may, according to a preset time period, consensus-determine a target computing terminal from the multiple computing terminals through consensus.
[0126] That is to say, the multiple blockchain nodes may determine the target computing terminal in accordance with a preset time period through a consensus manner. In this way, when the target data terminal needs to perform data processing, it may query the current target computing terminal and then perform data processing through the target computing terminal.
[0127] In a possible implementation, the node set includes multiple blockchain consensus nodes. The multiple blockchain nodes in the node set determine a target computing terminal from multiple computing terminals through consensus (step S41), including:
[0128] The multiple blockchain nodes in the node set obtain the data processing history records of each computing terminal, and the data processing history records include data processing metrics;
[0129] The multiple blockchain nodes in the node set determine the target computing terminal from each computing terminal according to the data processing metrics.
[0130] Exemplarily, after the data processing is completed, the target data terminal may upload the data processing record of the computing terminal used for this data processing to the blockchain. Here, the data processing record may include, for example, data processing quality parameters, data processing duration, data processing charging information, and so on. Taking data processing as image recognition as an example, the data processing quality parameters may include the accuracy rate of image recognition, the success rate of image recognition, and so on.
[0131] In this way, when determining the target computing terminal, each blockchain consensus node may obtain the data processing history records of each computing terminal from the blockchain. And determine the target computing terminal from each computing terminal according to the data processing metrics in the data processing history records. Exemplarily, referring to Figure 2 the block diagram of a data processing system shown, the blockchain consensus node may calculate the average value of the data processing times of computing terminals 1 to M according to the obtained data processing history records, and use the computing terminal 2 with the smallest average value as the target computing terminal.
[0132] In step S42, the target data end homomorphically encrypts the data to be processed to obtain the first ciphertext data.
[0133] In step S43, the target data end saves the first ciphertext data to the blockchain in the blockchain network through the node set.
[0134] In step S44, the target computing end obtains the first ciphertext data.
[0135] In step S45, the target computing end processes the first ciphertext data to obtain a processing result.
[0136] In step S46, the target computing end saves the processing result to the blockchain through the node set so that the target data end can obtain the processing result.
[0137] In the above technical solution, multiple blockchain nodes in the node set can determine the target computing end from multiple computing ends through consensus. In this way, the problem of centralization of the computing end can be avoided and the risk of data leakage can be reduced. When processing data, the target data end can homomorphically encrypt the data to be processed to obtain the first ciphertext data and save the first ciphertext data to the blockchain. In this way, the target computing end can obtain the first ciphertext data in the blockchain and process the data to be processed in the ciphertext state. After the processing is completed, the processing result can be uploaded to the blockchain so that the target data end can obtain it. That is to say, the first ciphertext data is a homomorphic ciphertext, and the target computing end also processes it based on the homomorphic ciphertext without obtaining the original data. At the same time, the first ciphertext data and the processing result in the data processing process are transferred through the blockchain and have the properties of being tamper-proof and traceable. Therefore, the above technical solution can reduce the risk of data leakage in the data processing process and ensure the security of the data.
[0138] Figure 5 is a flowchart of a data processing method shown in an exemplary embodiment of the present disclosure, and the method is applied to the data processing system provided by the present disclosure. Refer to Figure 5 , the method includes:
[0139] In step S51, multiple blockchain nodes in the node set determine the target computing end from multiple computing ends through consensus.
[0140] In step S52, the target data end generates a homomorphic key pair.
[0141] In step S53, the target data end saves the homomorphic public key in the homomorphic key pair to the blockchain through the node set.
[0142] In step S54, the target data end homomorphically encrypts the data to be processed using the homomorphic public key, obtaining the first ciphertext data.
[0143] Exemplarily, the target data end can pre-generate a homomorphic key pair, which includes a homomorphic private key and a homomorphic public key. After generating the homomorphic key pair, the target data end can save the homomorphic public key to the blockchain for the target computing end to obtain the homomorphic public key. In addition, the target data end can homomorphically encrypt the data to be processed using the homomorphic public key, obtaining the first ciphertext data.
[0144] In step S55, the target data end saves the first ciphertext data to the blockchain in the blockchain network through the node set.
[0145] In step S56, the target computing end obtains the first ciphertext data.
[0146] In step S57, the target computing end obtains the homomorphic public key in the blockchain and processes the first ciphertext data based on the homomorphic public key, obtaining a processing result.
[0147] In step S58, the target computing end saves the processing result to the blockchain through the node set for the target data end to obtain the processing result.
[0148] It should be noted that the above homomorphic key pair can be used multiple times. In subsequent data processing flows, the target data end can still use the saved homomorphic key pair.
[0149] In some embodiments, the homomorphic key pair can also be one-time and used in one data processing flow. In this case, the target data end generates a homomorphic key pair (step S52), including:
[0150] The target data end generates the homomorphic key pair in response to receiving a data processing request for the data to be processed.
[0151] That is to say, the target data end can generate a homomorphic key pair for processing the data to be processed when receiving a data processing request. In this way, when receiving a data processing request next time, the target data end can regenerate a new homomorphic key pair. In this way, different homomorphic keys can be used in multiple data processing flows, thus increasing the difficulty of data cracking and achieving the effect of enhancing data security.
[0152] In a possible embodiment, the data processing system includes multiple data ends, and the target data end is any one of the multiple data ends. Refer to Figure 6The flowchart of a data processing method shown, the method is applied to the data processing system provided by the present disclosure, and the method includes:
[0153] In step S61, multiple blockchain nodes in the node set determine a target computing end from multiple computing ends through consensus.
[0154] In step S62, the target data end generates a homomorphic key pair.
[0155] In step S63, the target data end saves the homomorphic public key in the homomorphic key pair to the blockchain through the node set.
[0156] In step S64, the target data end sends the homomorphic private key in the homomorphic key pair to other data ends among the multiple data ends.
[0157] Exemplarily, the target data end can be the data end that initiates the joint data processing request. Continuing Figure 3 the example, when data end 3 needs to jointly process data with data end 1 and data end 2, data end 3 can be the target data end and generate a homomorphic key pair. After generating the homomorphic key pair, the target data end can send the homomorphic private key in the homomorphic key pair to other data ends.
[0158] The following is an exemplary description of the distribution process of the homomorphic private key. In a possible implementation manner, the target data end sending the homomorphic private key in the homomorphic key pair to other data ends among the multiple data ends includes:
[0159] The target data end encrypts based on the homomorphic private key pair verification information to obtain encrypted verification information, saves the encrypted verification information to the blockchain, and sends the verification information and the homomorphic private key to other data ends among the multiple data ends.
[0160] Here, the verification information (token) can be random content, for example. The target data end can encrypt the homomorphic private key pair verification information to obtain encrypted verification information and save the encrypted verification information to the blockchain. In addition, the target data end can distribute the homomorphic private key through off-chain communication. As an example, the target data end can distribute the homomorphic private key to other data ends through the P2P (Peer to Peer) method.
[0161] In this way, any data end obtains the encrypted verification information from the blockchain, and verifies the correctness of the homomorphic private key through the encrypted verification information and the verification information when receiving the verification information and the homomorphic private key.
[0162] Continuing Figure 3For example, when data terminal 1 and data terminal 2 receive the verification information and the homomorphic private key, they can encrypt the verification information with the received homomorphic private key to obtain the target verification information. In this way, data terminal 1 and data terminal 2 can compare the target verification information with the obtained encrypted verification information. When the target verification information is consistent with the encrypted verification information, it is determined that the homomorphic private key is correct. When the target verification information is inconsistent with the encrypted verification information, it is determined that the homomorphic private key is incorrect. In this way, it can be ensured that the homomorphic secret key is correctly distributed.
[0163] It should be noted that since the homomorphic private keys of each data terminal are the same, the data terminals can decrypt the data encrypted by other data terminals with the homomorphic public key through the homomorphic private key. In this case, the phenomenon of data leakage may occur.
[0164] Therefore, the present disclosure also introduces a double encryption mechanism. In step S65, the target computing terminal generates an encryption key pair, and saves the encryption public key in the encryption key pair to the blockchain through the node set.
[0165] In step S66, the target data terminal performs homomorphic encryption on the data to be processed with the homomorphic public key to obtain the first ciphertext data.
[0166] In step S67, the target data terminal obtains the encryption public key in the blockchain, and encrypts the first ciphertext data based on the encryption public key to obtain the second ciphertext data.
[0167] In step S68, the target data terminal saves the second ciphertext data to the blockchain in the blockchain network through the node set.
[0168] In step S69, the target computing terminal obtains the second ciphertext data in the blockchain, and decrypts the second ciphertext data based on the encryption private key in the encryption key pair to obtain the first ciphertext data.
[0169] That is to say, the target data terminal can encrypt the data to be processed with the homomorphic public key to obtain the first ciphertext data, and encrypt the first ciphertext data with the encryption public key to obtain the second ciphertext data. In this way, since the encryption private key is held by the target computing terminal, the data terminal and the blockchain nodes in the node set cannot decrypt the second ciphertext data without the encryption private key. Therefore, even if the second ciphertext data is uploaded to the blockchain, the data terminal and the blockchain nodes in the node set cannot obtain the original text of the second ciphertext data. In addition, since the target computing terminal has the encryption private key, it can decrypt the second ciphertext data to obtain the first ciphertext data. However, since the target computing terminal lacks the homomorphic private key, the target computing terminal cannot obtain the original text of the second ciphertext data either.
[0170] With the above technical solution, other data terminals, blockchain nodes in the node set, and the target computing terminal can only obtain data at some stages during the data processing process, and cannot obtain the original data of the target data terminal through any party. Moreover, the homomorphic ciphertext (the first encrypted data) is also operable. Therefore, the above technical solution hides the data plaintext while ensuring data availability and operability, thus achieving the effect of data being available but invisible, which helps to ensure data security.
[0171] In step S610, the target computing terminal obtains the homomorphic public key in the blockchain and processes the first ciphertext data based on the homomorphic public key to obtain a processing result.
[0172] In step S611, the target computing terminal saves the processing result to the blockchain through the node set so that the target data terminal can obtain the processing result.
[0173] The following gives an exemplary description of the processing method of the first ciphertext data by the target computing terminal. In one possible implementation, the method includes:
[0174] Multiple data terminals reach a consensus to determine the processing rules for the data to be processed and save the processing rules to the blockchain;
[0175] In this case, the processing of the first ciphertext data by the target computing terminal to obtain a processing result includes:
[0176] The target computing terminal obtains the processing rules in the blockchain and processes the first ciphertext data according to the processing rules and the homomorphic public key to obtain a processing result.
[0177] For Figure 3 example, in some implementation scenarios, data terminal 1 has data to be processed A, data terminal 2 has data to be processed B, and data terminal 3 has data to be processed C. In this way, data terminals 1 to 3 can agree on the processing rules for the data (for example, calculating the average of data to be processed A, data to be processed B, and data to be processed C) and save the processing rules in the blockchain, or deploy the processing rules in the blockchain in the form of a smart contract.
[0178] In this case, the target computing terminal can obtain the processing rules in the blockchain, the first ciphertext data a of data terminal 1, the first ciphertext data b of data terminal 2, the first ciphertext data c of data terminal 3, and the homomorphic public key. In this way, the target computing terminal can process the first ciphertext data a, the first ciphertext data b, and the first ciphertext data c based on the homomorphic calculation method to obtain a processing result. In addition, the target computing terminal can also upload the processing result to the blockchain so that data terminals 1, 2, and 3 can obtain the processing result.
[0179] In a possible implementation, the method further includes:
[0180] The target computing end encrypts the processing result with the encryption private key to obtain an encrypted processing result, and saves the encrypted processing result to the blockchain through the node set;
[0181] Any of the data ends obtains the encrypted processing result from the blockchain, decrypts the obtained encrypted processing result with the encryption public key to obtain the processing result, and decrypts the processing result with the homomorphic private key to obtain the plaintext of the processing result.
[0182] Continuing with the above example regarding Figure 3 Data end 1, data end 2, and data end 3 can obtain the encrypted processing result from the blockchain and decrypt the obtained encrypted processing result with the encryption public key to obtain the processing result. In this way, data end 1, data end 2, and data end 3 can decrypt the processing result with the homomorphic private key to obtain the average values of the data to be processed A, the data to be processed B, and the data to be processed C.
[0183] With the above technical solution, multiple data ends can jointly perform data processing. During the data processing process, other data ends, blockchain nodes in the node set, and the target computing end can only obtain data at some stages, and cannot obtain the original data of the target data end through any party. Moreover, the homomorphic ciphertext (the first encrypted data) is also operable. Therefore, the above technical solution hides the data plaintext while ensuring the availability and operability of the data, thus achieving the effect of data being available but invisible, which helps to ensure data security.
[0184] In addition, it is worth noting that for the above method embodiments, for the sake of simple description, they are expressed as a series of action combinations. However, those skilled in the art should know that the present disclosure is not limited by the described action sequence. For example, referring to Figure 7 the flowchart of a data processing method shown, in some possible implementations, the step of selecting the target computing end can be performed after the homomorphic private keys of each data end are distributed. The present disclosure does not limit this. In addition, for the implementation manners of each step in Figure 7 , please refer to the description in the above embodiments of the present disclosure. For the sake of brevity of the specification, the present disclosure does not elaborate on this.
[0185] In another exemplary embodiment, a computer program product is further provided. The computer program product includes a computer program that can be executed by a programmable device, and the computer program has a code part for executing the above data processing method when executed by the programmable device.
[0186] The preferred embodiments of the present disclosure have been described in detail above in conjunction with the accompanying drawings. However, the present disclosure is not limited to the specific details in the above embodiments. Within the scope of the technical concept of the present disclosure, various simple modifications can be made to the technical solutions of the present disclosure, and these simple modifications all fall within the protection scope of the present disclosure.
[0187] In addition, it should be noted that, in the case of no contradiction, the various specific technical features described in the above specific embodiments can be combined in any suitable manner. To avoid unnecessary repetition, the present disclosure will not separately describe various possible combination manners.
[0188] Furthermore, any combination can be made between various different embodiments of the present disclosure, as long as it does not violate the idea of the present disclosure, and it should also be regarded as the content disclosed by the present disclosure.
Claims
1. A data processing system, characterized in that, It includes a target data end, multiple computing ends, and a node set, where the node set includes multiple blockchain nodes in a blockchain network. Among them, multiple blockchain nodes in the node set are used to determine a target computing end from the multiple computing ends through consensus; the target data end is used to homomorphically encrypt the data to be processed to obtain first ciphertext data, and save the first ciphertext data to the blockchain in the blockchain network through the node set; the target computing end is used to obtain the first ciphertext data, process the first ciphertext data to obtain a processing result, and save the processing result to the blockchain through the node set so that the target data end can obtain the processing result; the target data end is used to generate a homomorphic key pair, save the homomorphic public key in the homomorphic key pair to the blockchain through the node set, and homomorphically encrypt the data to be processed with the homomorphic public key to obtain first ciphertext data; the target computing end is used to obtain the first ciphertext data and the homomorphic public key in the blockchain, and process the first ciphertext data based on the homomorphic public key; wherein, it includes multiple data ends, the target data end is any one of the multiple data ends, and the target data end is further used to send the homomorphic private key in the homomorphic key pair to other data ends among the multiple data ends; the target computing end is further used to generate an encryption key pair, and save the encryption public key in the encryption key pair to the blockchain through the node set; the target data end is further used to obtain the encryption public key in the blockchain, encrypt the first ciphertext data based on the encryption public key, and save the second ciphertext data obtained by encryption to the blockchain; the target computing end is further used to obtain the second ciphertext data in the blockchain, and decrypt the second ciphertext data based on the encryption private key in the encryption key pair to obtain the first ciphertext data.
2. The data processing system according to claim 1, wherein The target data end is used to generate the homomorphic key pair in response to receiving a data processing request for the data to be processed.
3. The data processing system according to claim 1, wherein The target data end is further used to encrypt the verification information based on the homomorphic private key to obtain encrypted verification information, save the encrypted verification information to the blockchain, and send the verification information and the homomorphic private key to other data ends among the multiple data ends; any of the data ends is used to obtain the encrypted verification information from the blockchain, and verify the correctness of the homomorphic private key through the encrypted verification information and the verification information when receiving the verification information and the homomorphic private key; 4. The data processing system according to claim 1, wherein the multiple data ends are further used to determine the processing rule of the data to be processed through consensus, and save the processing rule to the blockchain; the target computing end is used to obtain the processing rule in the blockchain, and process the first ciphertext data according to the processing rule and the homomorphic public key to obtain a processing result.
5. The data processing system according to claim 1, wherein The target computing end is further configured to encrypt the processing result with the encryption private key to obtain an encrypted processing result, and save the encrypted processing result to the blockchain through the node set; Any of the data ends is configured to obtain the encrypted processing result from the blockchain, decrypt the obtained encrypted processing result with the encryption public key to obtain the processing result, and decrypt the processing result with the homomorphic private key to obtain the plaintext of the processing result.
6. The data processing system according to claim 1 or 2, characterized in that The multiple blockchain nodes in the node set are configured to in response to receiving a data processing request from the target data end, consensus-determine a target computing end from the multiple computing ends through consensus; or, at a preset time period, consensus-determine a target computing end from the multiple computing ends through consensus.
7. The data processing system according to claim 1 or 2, characterized in that, The node set includes multiple blockchain consensus nodes, and the multiple blockchain consensus nodes determine a target computing end from the multiple computing ends in the following manner: Obtain the data processing history records of each computing end, where the data processing history records include data processing metrics; Determine the target computing end from each computing end according to the data processing metrics.
8. A data processing method, characterized in that, Applied to the data processing system according to any one of claims 1 to 7, the method includes: Multiple blockchain nodes in the node set consensus-determine a target computing end from multiple computing ends; The target data end performs homomorphic encryption on the data to be processed to obtain first ciphertext data; The target data end saves the first ciphertext data to the blockchain in the blockchain network through the node set; The target computing end obtains the first ciphertext data; The target computing end processes the first ciphertext data to obtain a processing result; The target computing end saves the processing result to the blockchain through the node set so that the target data end can obtain the processing result; The target data end performs homomorphic encryption on the data to be processed to obtain first ciphertext data, including: generating a homomorphic key pair, saving the homomorphic public key in the homomorphic key pair to the blockchain through the node set, and performing homomorphic encryption on the data to be processed with the homomorphic public key to obtain first ciphertext data; The target computing end processes the first ciphertext data, including: obtaining the first ciphertext data and the homomorphic public key in the blockchain, and processing the first ciphertext data based on the homomorphic public key; Among them, it includes multiple data ends, and the target data end is any one of the multiple data ends. The method further includes: The target data end sends the homomorphic private key in the homomorphic key pair to other data ends among the multiple data ends; The target computing end generates an encryption key pair, and saves the encryption public key in the encryption key pair to the blockchain through the node set; The target data end obtains the encryption public key in the blockchain, encrypts the first ciphertext data based on the encryption public key, and saves the second ciphertext data obtained by encryption to the blockchain; The target computing end obtains the second ciphertext data in the blockchain, and decrypts the second ciphertext data based on the encryption private key in the encryption key pair to obtain the first ciphertext data.
Citation Information
Patent Citations
Blockchain data protection method, device, system and computer readable storage medium
CN109690551A
Data privacy calculation method and system based on block chain
CN113726758A