A fine-grained and configurable universal identity privacy protection system for blockchain

By pre-deploying the blockchain in the service layer of the blockchain and using smart contracts and functional algorithms, the problem that existing identity privacy protection systems are difficult to adapt to when the operating mode of the information system is changed, and general configuration and efficient privacy protection are achieved under different blockchain operating modes.

CN115333790BActive Publication Date: 2025-05-06HANGZHOU INNOVATION RES INST OF BEIJING UNIV OF AERONAUTICS & ASTRONAUTICS
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210858416.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-21
Publication Date
2025-05-06
Estimated Expiration
2042-07-21

AI Technical Summary

Technical Problem

The existing identity privacy protection system is difficult to adapt to when the operating mode of the information system changes, especially if it is not compatible with information systems with semi-trust and no trust modes, resulting in poor portability and universality.

Method used

A fine-grained configurable universal identity privacy protection system for blockchain is designed. By pre-deploying the blockchain in the service layer, and using smart contracts and multiple functional algorithms, fine-grained control and privacy protection of user attribute information is achieved.

Benefits of technology

The system can maintain the stability of the underlying architecture under different blockchain operating modes, realize general configuration, meet business needs under different operating modes, and improve the portability and universality of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115333790B_ABST
    Figure CN115333790B_ABST
Patent Text Reader

Abstract

The present invention relates to a fine-grained configurable universal identity privacy protection system for blockchain, the system comprising: an application layer, used for receiving user attribute information input by a user corresponding to any node in the blockchain and part of the user attribute information selected by the user in the user attribute information; the blockchain is pre-deployed in a service layer; the blockchain is a public chain corresponding to a distribution mode without a trust center, or a consortium chain corresponding to a semi-trust center distribution mode, or a private chain corresponding to a trust center; the service layer, used for executing a smart contract pre-deployed on the blockchain according to the user attribute information and part of the user attribute information input by the user, so that when the node in the blockchain interacts with other nodes on the blockchain, the part of the user attribute information selected by the user on the node in the user attribute information is hidden; and a basic layer, used for pre-storing a plurality of functional algorithms.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of user privacy protection in blockchain, and in particular to a fine-grained configurable universal identity privacy protection system for blockchain. Background Art

[0002] Personal privacy is a basic personal right and an important part of national network security. With the advent of the big data era, a large number of personal privacy leaks have been exposed in countries around the world, and people are troubled by the problems caused by privacy leaks. Therefore, personal identity privacy protection is an indispensable part of modern digital information systems.

[0003] The existing identity privacy protection system can meet the needs of most application scenarios under the current information system operation mode. The information system operation mode is the internal structure of the information system and the connection between its parts. Traditional information systems usually carry the computing services required by users in a trust center mode. With the continuous development of new generation information technologies such as blockchain and secure multi-party computing, modern information systems have derived a variety of operation modes, including no trust center mode and semi-trust center mode.

[0004] However, when the operation mode of the information system changes, the existing identity privacy protection system's underlying framework is difficult to change, and its portability and versatility are poor, and it cannot be applied to information systems in semi-trust and untrusted modes. There is a lack of a universal and configurable identity privacy protection system. Summary of the invention

[0005] 1. Technical issues to be resolved

[0006] In view of the above-mentioned shortcomings and deficiencies of the prior art, the present invention provides a fine-grained, configurable universal identity privacy protection system for blockchain, which solves the problem that when the operating mode of the information system changes, the underlying framework of the existing identity privacy protection system is difficult to change, and the portability and versatility are poor, and the technical problem that it is not applicable to information systems in semi-trusted and untrusted modes.

[0007] (II) Technical solution

[0008] In order to achieve the above object, the main technical solutions adopted by the present invention include:

[0009] The embodiment of the present invention provides a fine-grained and configurable universal identity privacy protection system for blockchain, including:

[0010] The application layer is used to receive user attribute information input by a user corresponding to any node in the blockchain and part of the user attribute information selected by the user from the user attribute information;

[0011] The blockchain is pre-deployed in the service layer; the blockchain is a public chain corresponding to the no-trust center distribution mode, a consortium chain corresponding to the semi-trust center distribution mode, or a private chain corresponding to the trust center;

[0012] A service layer, for executing a pre-deployed smart contract on the blockchain according to the user attribute information input by the user and part of the user attribute information selected by the user in the user attribute information, so that any node in the blockchain hides part of the user attribute information selected by the user in the user attribute information when the node in the blockchain interacts with other nodes in the blockchain;

[0013] Among them, the smart contract pre-deployed on the blockchain is a sub-algorithm in the identity privacy protection algorithm for certificate anonymization to hide some user attribute information;

[0014] The basic layer is used to store multiple functional algorithms in advance;

[0015] Among them, the smart contract pre-deployed on the blockchain completes the execution of the smart contract by calling the functional algorithm in the basic layer.

[0016] Preferably,

[0017] The application layer includes multiple clients;

[0018] Each client corresponds to each node in the blockchain one by one;

[0019] Each of the client terminals is used to receive the user attribute information input by the user and part of the user attribute information selected by the user in the user attribute information, and transmit the user attribute information and the part of the user attribute information to the service layer.

[0020] Preferably,

[0021] Among them, smart contracts deployed on public chains, consortium chains, or private chains include:

[0022] The first smart contract is composed of the certificate application algorithm in the certificate anonymization identity privacy protection algorithm, the second smart contract is composed of the initial certificate application algorithm in the certificate anonymization identity privacy protection algorithm, the third smart contract is composed of the anonymous certificate generation algorithm in the certificate anonymization identity privacy protection algorithm, the fourth smart contract is composed of the anonymous certificate verification algorithm in the certificate anonymization identity privacy protection algorithm, and the fifth smart contract is composed of the user tracking algorithm in the certificate anonymization identity privacy protection algorithm.

[0023] Preferably,

[0024] The first smart contract is used to enable any node on the public chain, alliance chain or private chain to generate its own DID document according to the user attribute information, and any node generates a certificate request after uploading the DID document to the blockchain;

[0025] The second smart contract is used to enable a pre-specified authoritative node on the blockchain to sign the certificate request to generate a verifiable certificate VC;

[0026] The third smart contract is used for any node to perform anonymization on the obtained verifiable credential VC and DID document according to the partial user attribute information to generate an anonymous certificate and an anonymous public key;

[0027] The fourth smart contract is used to enable a node pre-designated on the blockchain for verification to perform verification using the anonymous public key and the anonymous certificate, thereby obtaining a verification result;

[0028] The fifth smart contract is used to enable the authoritative node to obtain the original identity of the user according to the anonymous public key and the anonymous certificate, and to track the user according to the original identity to obtain the tracking result.

[0029] Preferably,

[0030] The service layer is used to execute a smart contract pre-deployed in a distributed mode without a trust center, a smart contract deployed in a semi-trust center mode, or a smart contract deployed in a trust center mode on the blockchain according to the user attribute information input by the user and part of the user attribute information selected by the user in the user attribute information, specifically including:

[0031] The service layer sequentially executes the first smart contract and the second smart contract deployed on the public chain, private chain or alliance chain according to the user attribute information to obtain a verifiable credential VC and a DID document;

[0032] The service layer executes the third smart contract, the fourth smart contract, and the fifth smart contract deployed on the public chain, the private chain, or the alliance chain in sequence according to the verifiable certificate VC and the DID document and the partial user attribute information.

[0033] Preferably,

[0034] The pre-set authoritative nodes on the alliance chain are: the distributed identity management agency DPKI composed of multiple pre-designated nodes on the alliance chain.

[0035] Preferably,

[0036] The pre-set authoritative nodes on the public chain are: nodes pre-designated on the public chain.

[0037] Preferably,

[0038] The pre-set authoritative nodes on the private chain are: nodes pre-specified on the private chain.

[0039] Preferably,

[0040] The functional algorithms in the basic layer include: asymmetric encryption algorithm, homomorphic encryption algorithm, proxy re-encryption algorithm, group signature algorithm, ring signature algorithm, blind signature algorithm, multi-signature algorithm, threshold signature algorithm, zk-SNARKs algorithm, zk-STARKs algorithm and BulletProofs algorithm, oblivious transfer algorithm, secret sharing algorithm, and threshold homomorphic encryption algorithm.

[0041] Preferably,

[0042] The basic layer also includes: an encryption algorithm storage module, a digital signature storage module, a zero-knowledge proof storage module, and a secure multi-party computing storage module;

[0043] The encryption algorithm storage module is used to store asymmetric encryption algorithms, homomorphic encryption algorithms, and proxy re-encryption algorithms;

[0044] The digital signature storage module includes a module for storing group signature algorithms, ring signature algorithms, blind signature algorithms, multi-signature algorithms, and threshold signature algorithms;

[0045] Zero-knowledge proof storage module, used to store zk-SNARKs algorithm, zk-STARKs algorithm and BulletProofs algorithm;

[0046] Secure multi-party computing storage module, used to store oblivious transmission algorithm, secret sharing algorithm, and threshold homomorphic encryption algorithm.

[0047] (III) Beneficial effects

[0048] The beneficial effects of the present invention are as follows: the present invention is a fine-grained configurable universal identity privacy protection system for blockchain, since the blockchain is pre-deployed in the service layer; the blockchain is a public chain corresponding to the distribution mode without a trust center or a consortium chain corresponding to the distribution mode with a semi-trust center or a private chain corresponding to a trust center. Compared with the prior art, the present invention is a fine-grained configurable universal identity privacy protection system for blockchain that can be compatible with blockchains in different operating modes. When it faces different operating modes, it does not need to change the underlying architecture, and can achieve universal configuration to meet business needs under different operating modes. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] Figure 1 This is a schematic diagram of the structure of a fine-grained, configurable, universal identity privacy protection system for blockchain of the present invention;

[0050] Figure 2 This is a schematic diagram of the structure of a fine-grained, configurable, universal identity privacy protection system for blockchain in an embodiment of the present invention;

[0051] Figure 3 This is a diagram for implementing a smart contract in a blockchain in an embodiment of the present invention. DETAILED DESCRIPTION

[0052] In order to better explain the present invention and facilitate understanding, the present invention is described in detail below through specific implementation modes in conjunction with the accompanying drawings.

[0053] In order to better understand the above technical solution, exemplary embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present invention are shown in the accompanying drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments described herein. On the contrary, these embodiments are provided to enable a clearer and more thorough understanding of the present invention and to fully convey the scope of the present invention to those skilled in the art.

[0054] See also Figure 1 ,This embodiment provides a fine-grained configurable universal identity privacy protection system for blockchain, including: an application layer, a service layer, and a basic layer.

[0055] The application layer is used to receive user attribute information input by a user corresponding to any node in the blockchain and part of the user attribute information selected by the user from the user attribute information.

[0056] Specifically, the application layer includes multiple clients.

[0057] Each client corresponds to each node in the blockchain.

[0058] Each of the client terminals is used to receive the user attribute information input by the user and part of the user attribute information selected by the user in the user attribute information, and transmit the user attribute information and the part of the user attribute information to the service layer.

[0059] The blockchain is pre-deployed in the service layer; the blockchain is a public chain corresponding to a distribution mode without a trust center, or a consortium chain corresponding to a semi-trust center distribution mode, or a private chain corresponding to a trust center.

[0060] For details, see Figure 2The service layer in this embodiment is used to execute the smart contract pre-deployed on the blockchain according to the user attribute information input by the user and the part of the user attribute information selected by the user in the user attribute information, so that any node in the blockchain hides the part of the user attribute information selected by the user in the user attribute information on any node when the node in the blockchain interacts with other nodes on the blockchain.

[0061] Among them, the smart contract pre-deployed on the blockchain is a sub-algorithm in the identity privacy protection algorithm for certificate anonymization to hide some user attribute information.

[0062] Among them, smart contracts deployed on public chains, consortium chains, or private chains include:

[0063] The first smart contract is composed of the certificate application algorithm in the certificate anonymization identity privacy protection algorithm, the second smart contract is composed of the initial certificate application algorithm in the certificate anonymization identity privacy protection algorithm, the third smart contract is composed of the anonymous certificate generation algorithm in the certificate anonymization identity privacy protection algorithm, the fourth smart contract is composed of the anonymous certificate verification algorithm in the certificate anonymization identity privacy protection algorithm, and the fifth smart contract is composed of the user tracking algorithm in the certificate anonymization identity privacy protection algorithm.

[0064] The base layer is used to pre-store multiple functional algorithms.

[0065] Among them, the smart contract pre-deployed on the blockchain completes the execution of the smart contract by calling the functional algorithm in the basic layer.

[0066] See also Figure 3 In the actual application of this embodiment, the first smart contract is used to enable any node on the public chain, alliance chain or private chain to generate its own DID document based on user attribute information, and after uploading the DID document to the blockchain, any node generates a certificate request.

[0067] The second smart contract is used to enable a pre-designated authoritative node on the blockchain to sign the certificate request to generate a verifiable certificate VC.

[0068] The third smart contract is used for any node to perform anonymization on the obtained verifiable credential VC and DID document based on the partial user attribute information to generate an anonymous certificate and an anonymous public key.

[0069] The fourth smart contract is used to enable a node pre-designated on the blockchain for verification to perform verification through the anonymous public key and the anonymous certificate to obtain a verification result.

[0070] The fifth smart contract is used to enable the authoritative node to obtain the original identity of the user according to the anonymous public key and the anonymous certificate, and to track the user according to the original identity to obtain the tracking result.

[0071] Specifically, the pre-set authoritative node on the alliance chain is: a distributed identity management agency DPKI composed of multiple pre-designated nodes on the alliance chain.

[0072] The pre-set authoritative nodes on the public chain are: nodes pre-designated on the public chain.

[0073] The pre-set authoritative nodes on the private chain are: nodes pre-specified on the private chain.

[0074] For example, if the blockchain deployed at the service layer is a public chain, it is initialized first:

[0075] The authority node generates the key pair and public parameters of the authority node;

[0076] Any node generates a key pair and tracking parameter Z of any node, and the service layer sends the user public key and tracking parameter to the authoritative node. The authoritative node manages a list list, Z∈list.

[0077] The first smart contract is used to enable any node on the public chain to generate its own DID document according to user attribute information, and after uploading the DID document to the blockchain, any node generates a certificate request. Specifically, any node generates its own DID document, and inputs the key pair of any node and the public key of the authoritative node to generate a certificate request.

[0078] In this embodiment, the first smart contract generates a certificate request by running the CQst algorithm.

[0079] The second smart contract is used to enable a pre-designated authoritative node on the blockchain to sign the certificate request to generate a verifiable certificate VC; specifically, the authoritative node inputs its own key pair, the certificate request, and the user's DID document, and outputs the verifiable certificate VC.

[0080] The second smart contract in this embodiment implements the output of verifiable certificate VC by running the CertGen algorithm.

[0081] The third smart contract is used for any node to anonymously process the obtained verifiable credential VC and DID document according to the partial user attribute information, and generate an anonymous certificate and an anonymous public key. Specifically, any node generates an anonymous certificate and an anonymous public key for the obtained verifiable credential VC and DID document.

[0082] The third smart contract in this embodiment generates an anonymous certificate and an anonymous public key by running the anonymous certificate RanSig algorithm.

[0083] The fourth smart contract is used to enable a node pre-designated on the blockchain for verification to perform verification through the anonymous public key and the anonymous certificate to obtain a verification result.

[0084] Specifically, the pre-designated node for verification completes the verification of the identity of any node through an anonymous public key. The pre-designated node for verification inputs the anonymous certificate of any node and the authoritative node public key to verify whether the anonymous certificate is valid.

[0085] The fourth smart contract in this embodiment verifies whether the anonymous certificate is valid by running the VerSig algorithm.

[0086] The fifth smart contract is used to enable the authoritative node to obtain the original identity of the user according to the anonymous public key and the anonymous certificate, and to track according to the original identity of the user to obtain a tracking result. Specifically, the authoritative node inputs the anonymous certificate, the tracking parameter list of the authoritative node, and outputs the registered public key and tracking parameter Z of the user corresponding to the anonymous certificate, thereby tracking the real identity of any node.

[0087] The fifth smart contract in this embodiment is to track the true identity of any node by running the Trac algorithm.

[0088] In the practical application of this embodiment, the service layer is used to execute the smart contract pre-deployed in a distributed mode without a trust center or a smart contract deployed in a semi-trust center mode or a smart contract deployed in a trust center mode on the blockchain according to the user attribute information input by the user and part of the user attribute information selected by the user in the user attribute information, specifically including:

[0089] The service layer executes the first smart contract and the second smart contract deployed on the public chain, private chain or alliance chain in sequence according to the user attribute information to obtain the verifiable certificate VC and DID document.

[0090] The service layer executes the third smart contract, the fourth smart contract, and the fifth smart contract deployed on the public chain, the private chain, or the alliance chain in sequence according to the verifiable certificate VC and the DID document and the partial user attribute information.

[0091] In the actual application of this embodiment, the functional algorithms in the basic layer include: asymmetric encryption algorithm, homomorphic encryption algorithm, proxy re-encryption algorithm, group signature algorithm, ring signature algorithm, blind signature algorithm, multi-signature algorithm, threshold signature algorithm, zk-SNARKs algorithm, zk-STARKs algorithm and BulletProofs algorithm, oblivious transfer algorithm, secret sharing algorithm, threshold homomorphic encryption algorithm.

[0092] In the actual application of this embodiment, the basic layer also includes: an encryption algorithm storage module, a digital signature storage module, a zero-knowledge proof storage module, and a secure multi-party computing storage module.

[0093] The encryption algorithm storage module is used to store asymmetric encryption algorithms, homomorphic encryption algorithms, and proxy re-encryption algorithms.

[0094] The digital signature storage module includes a module for storing group signature algorithms, ring signature algorithms, blind signature algorithms, multi-signature algorithms, and threshold signature algorithms.

[0095] Zero-knowledge proof storage module, used to store zk-SNARKs algorithm, zk-STARKs algorithm and BulletProofs algorithm.

[0096] Secure multi-party computing storage module, used to store oblivious transmission algorithm, secret sharing algorithm, and threshold homomorphic encryption algorithm.

[0097] A fine-grained configurable universal identity privacy protection system for blockchain in this embodiment, since the blockchain is pre-deployed in the service layer; the blockchain is a public chain corresponding to the distribution mode without a trust center, or a consortium chain corresponding to the semi-trust center distribution mode, or a private chain corresponding to a trust center. Compared with the prior art, a fine-grained configurable universal identity privacy protection system for blockchain in this embodiment can be compatible with blockchains in different operating modes. When it faces different operating modes, it does not need to change the underlying architecture, and can achieve universal configuration to meet business needs under different operating modes.

[0098] It should be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0099] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems) and computer program products according to embodiments of the present invention. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions.

[0100] It should be noted that in the claims, any reference numerals placed between brackets shall not be construed as limiting the claims. The word "comprising" does not exclude the presence of components or steps not listed in the claims. The word "a" or "an" preceding a component does not exclude the presence of a plurality of such components. The invention may be implemented by means of hardware comprising several different components and by means of a suitably programmed computer. In the claims enumerating several means, several of these means may be embodied by the same hardware. The use of the words first, second, third, etc., is for convenience of expression only and does not indicate any order. These words may be understood as part of the component name.

[0101] In addition, it should be noted that, in the description of this specification, the description of the terms "one embodiment", "some embodiments", "embodiment", "example", "specific example" or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, unless they are contradictory.

[0102] Although the preferred embodiments of the present invention have been described, those skilled in the art may make other changes and modifications to these embodiments after knowing the basic creative concept. Therefore, the claims should be interpreted as including the preferred embodiments and all changes and modifications falling within the scope of the present invention.

[0103] Obviously, those skilled in the art can make various modifications and variations to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention should also include these modifications and variations.

Claims

1. A fine-grained and configurable universal identity privacy protection system for blockchain, characterized in that: include: The application layer is used to receive user attribute information input by a user corresponding to any node in the blockchain and part of the user attribute information selected by the user from the user attribute information; The blockchain is pre-deployed in the service layer; the blockchain is a public chain corresponding to the no-trust center distribution mode, a consortium chain corresponding to the semi-trust center distribution mode, or a private chain corresponding to the trust center; A service layer, for executing a pre-deployed smart contract on the blockchain according to the user attribute information input by the user and part of the user attribute information selected by the user in the user attribute information, so that any node in the blockchain hides part of the user attribute information selected by the user in the user attribute information when the node in the blockchain interacts with other nodes in the blockchain; Among them, the smart contract pre-deployed on the blockchain is a sub-algorithm in the identity privacy protection algorithm for certificate anonymization to hide some user attribute information; The basic layer is used to store multiple functional algorithms in advance; The smart contract pre-deployed on the blockchain implements the execution of the smart contract by calling the functional algorithm in the base layer; The application layer includes multiple clients; Each client corresponds to each node in the blockchain one by one; Each of the client terminals is used to receive the user attribute information input by the user and part of the user attribute information selected by the user in the user attribute information, and transmit the user attribute information and the part of the user attribute information to the service layer; Among them, smart contracts deployed on public chains, consortium chains, or private chains include: The first smart contract is composed of the certificate application algorithm in the certificate anonymization identity privacy protection algorithm, the second smart contract is composed of the initial certificate application algorithm in the certificate anonymization identity privacy protection algorithm, the third smart contract is composed of the anonymous certificate generation algorithm in the certificate anonymization identity privacy protection algorithm, the fourth smart contract is composed of the anonymous certificate verification algorithm in the certificate anonymization identity privacy protection algorithm, and the fifth smart contract is composed of the user tracking algorithm in the certificate anonymization identity privacy protection algorithm.

2. The system according to claim 1, characterized in that The first smart contract is used to enable any node on the public chain, alliance chain or private chain to generate its own DID document according to the user attribute information, and any node generates a certificate request after uploading the DID document to the blockchain; The second smart contract is used to enable a pre-specified authoritative node on the blockchain to sign the certificate request to generate a verifiable certificate VC; The third smart contract is used for any node to perform anonymization on the obtained verifiable credential VC and DID document according to the partial user attribute information to generate an anonymous certificate and an anonymous public key; The fourth smart contract is used to enable a node pre-designated on the blockchain for verification to perform verification using the anonymous public key and the anonymous certificate, thereby obtaining a verification result; The fifth smart contract is used to enable the authoritative node to obtain the original identity of the user according to the anonymous public key and the anonymous certificate, and to track the user according to the original identity to obtain the tracking result.

3. The system according to claim 2, characterized in that The service layer is used to execute a smart contract pre-deployed in a distributed mode without a trust center, a smart contract deployed in a semi-trust center mode, or a smart contract deployed in a trust center mode on the blockchain according to the user attribute information input by the user and part of the user attribute information selected by the user in the user attribute information, specifically including: The service layer sequentially executes the first smart contract and the second smart contract deployed on the public chain, private chain or alliance chain according to the user attribute information to obtain a verifiable credential VC and a DID document; The service layer executes the third smart contract, the fourth smart contract, and the fifth smart contract deployed on the public chain, the private chain, or the alliance chain in sequence according to the verifiable certificate VC and the DID document and the partial user attribute information.

4. The system according to claim 3, characterized in that The pre-set authoritative nodes on the alliance chain are: the distributed identity management agency DPKI composed of multiple pre-designated nodes on the alliance chain.

5. The system according to claim 4, characterized in that The pre-set authoritative nodes on the public chain are: nodes pre-designated on the public chain.

6. The system according to claim 5, characterized in that The pre-set authoritative nodes on the private chain are: nodes pre-specified on the private chain.

7. The system according to claim 6, characterized in that The functional algorithms in the base layer include: Asymmetric encryption algorithm, homomorphic encryption algorithm, proxy re-encryption algorithm, group signature algorithm, ring signature algorithm, blind signature algorithm, multi-signature algorithm, threshold signature algorithm, zk-SNARKs algorithm, zk-STARKs algorithm and BulletProofs algorithm, oblivious transfer algorithm, secret sharing algorithm, threshold homomorphic encryption algorithm.

8. The system according to claim 7, characterized in that The basic layer also includes: an encryption algorithm storage module, a digital signature storage module, a zero-knowledge proof storage module, and a secure multi-party computing storage module; The encryption algorithm storage module is used to store asymmetric encryption algorithms, homomorphic encryption algorithms, and proxy re-encryption algorithms; The digital signature storage module includes a module for storing group signature algorithms, ring signature algorithms, blind signature algorithms, multi-signature algorithms, and threshold signature algorithms; Zero-knowledge proof storage module, used to store zk-SNARKs algorithm, zk-STARKs algorithm and BulletProofs algorithm; Secure multi-party computing storage module, used to store oblivious transmission algorithm, secret sharing algorithm, and threshold homomorphic encryption algorithm.

Citation Information

Patent Citations

  • Blockchain system capable of simultaneously supporting public blockchain, consortium blockchain and private blockchain and application method

    CN107733855A