Cross-chain transaction method, device, equipment and storage medium

By generating and verifying the hash value and encrypted data of cross-chain transactions in the first cross-chain gateway, and using multi-signature information for verification, the problem that the relay chain system cannot verify the content of cross-chain transactions is solved, and the security and authenticity verification of cross-chain transactions is realized.

CN115549984BActive Publication Date: 2025-06-06HANGZHOU QULIAN TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211115217.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-14
Publication Date
2025-06-06
Estimated Expiration
2042-09-14

AI Technical Summary

Technical Problem

In the privacy transaction scenario, the relay chain system cannot verify the content of cross-chain transactions, resulting in malicious forgery or tampering and inability to intercept, reducing the security of cross-chain transactions.

Method used

By generating hash values, encrypted data and proof information in the first cross-chain gateway, and obtaining multi-signature information, a cross-chain transaction request carrying this information is sent to the relay chain system. After verifying that the multi-signature information and proof information are passed, the relay chain system sends encrypted data to the second cross-chain gateway to ensure the authenticity and integrity of the data.

Benefits of technology

The authenticity verification of encrypted cross-chain transactions by the relay chain system is realized, ensuring the security of cross-chain transactions in the privacy transaction scenario, and preventing malicious forgery and tampering.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115549984B_ABST
    Figure CN115549984B_ABST
Patent Text Reader

Abstract

The present application discloses a cross-chain transaction method, device, equipment and storage medium, which belongs to the field of computer technology. It includes: obtaining the target cross-chain transaction sent by the first application chain system; generating a first hash value, a first encrypted data and proof information according to the target cross-chain transaction; obtaining multi-signature information; sending a cross-chain transaction request to the relay chain system, the cross-chain transaction request carries multi-signature information, a first hash value, a first encrypted data and proof information, and the cross-chain transaction request is used to instruct the relay chain system to send the first encrypted data to the second cross-chain gateway when the multi-signature information and the proof information are verified. In this application, the relay chain system can verify the authenticity of the first encrypted data sent by the first cross-chain gateway to ensure that the original cross-chain transaction text corresponding to the first encrypted data is not maliciously generated or tampered with. It will only be sent to the second cross-chain gateway when the first encrypted data is authentic, ensuring the security of cross-chain transactions in privacy transaction scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a cross-chain transaction method, device, equipment and storage medium. Background Art

[0002] At present, blockchain technology is gradually maturing and its application is becoming more and more extensive. In the cross-chain transaction scenario of blockchain technology, transactions in one application chain system (i.e., cross-chain transactions) need to be executed in another application chain system. In this case, since the two application chain systems cannot communicate directly, the cross-chain transactions between the two application chain systems can be forwarded through the relay chain system. The relay chain system is the circulation center for cross-chain transactions of various application chain systems, and has the function of recording and routing cross-chain transactions.

[0003] However, in the privacy transaction scenario, the cross-chain transaction initiated by the application chain system often needs to be encrypted before it can be sent to the relay chain system, so that the relay chain system receives the encrypted cross-chain transaction. Therefore, the relay chain system in the privacy transaction scenario cannot know the content of the cross-chain transaction, and cannot verify the content of the cross-chain transaction, but only performs a simple forwarding operation. This will cause the cross-chain transaction to be maliciously forged or tampered with, and the relay chain system cannot verify and intercept it, reducing the security of the cross-chain transaction. Summary of the invention

[0004] This application provides a cross-chain transaction method, device, equipment and storage medium, which can enable the relay chain system to verify the authenticity of encrypted cross-chain transactions and ensure the security of cross-chain transactions in privacy transaction scenarios. The technical solution is as follows:

[0005] In a first aspect, a cross-chain transaction method is provided, which is applied to a first cross-chain gateway, where the first cross-chain gateway is a cross-chain gateway connected to a first application chain system, and the method includes:

[0006] Obtain the target cross-chain transaction sent by the first application chain system;

[0007] Generate a first hash value, first encrypted data, and proof information according to the target cross-chain transaction, wherein the first hash value is obtained by performing a hash operation on the target cross-chain transaction, the first encrypted data is obtained by encrypting the target cross-chain transaction, and the proof information is used to prove that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction;

[0008] Obtain multi-signature information, where the multi-signature information includes the signature of each of the multiple nodes in the first application chain system on the hash value of the target cross-chain transaction, and the multi-signature information is used to prove that the first hash value is obtained by processing the target cross-chain transaction from the first application chain system;

[0009] A cross-chain transaction request is sent to the relay chain system, wherein the cross-chain transaction request carries the multi-signature information, the first hash value, the first encrypted data and the proof information. The cross-chain transaction request is used to instruct the relay chain system to send the first encrypted data to the second cross-chain gateway when the multi-signature information and the proof information are verified. The second cross-chain gateway is a cross-chain gateway connected to the second application chain system.

[0010] In the present application, a first hash value, a first encrypted data and a proof information are generated according to the obtained target cross-chain transaction, and the proof information can prove that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction. And obtain multi-signature information, which can prove that the first hash value is obtained by processing the cross-chain transaction from the first application chain system. A cross-chain transaction request carrying the first hash value, the first encrypted data, the proof information and the multi-signature information is sent to the relay chain system. After receiving the cross-chain transaction request sent by the first cross-chain gateway, the relay chain system verifies the multi-signature information and the proof information carried in the cross-chain transaction request. If the multi-signature information and the proof information are verified, the relay chain system can determine that the first hash value carried in the cross-chain transaction request is obtained by processing the target cross-chain transaction from the first application chain, and determine that the first hash value and the first encrypted data carried in the cross-chain transaction request are obtained by processing the same cross-chain transaction, thereby determining that the first encrypted data is obtained by processing the target cross-chain transaction from the first application chain, that is, determining that the first encrypted data is authentic, so that the first encrypted data can be sent to the second cross-chain gateway. In an embodiment of the present application, the relay chain system can verify the authenticity of the first encrypted data sent by the first cross-chain gateway to ensure that the cross-chain transaction original text corresponding to the first encrypted data is not maliciously generated or tampered with. Only when the first encrypted data is authentic will the relay chain system send the first encrypted data to the second cross-chain gateway, thereby ensuring the security of cross-chain transactions in privacy transaction scenarios.

[0011] In a second aspect, a cross-chain transaction method is provided, which is applied to a relay chain system, and the method includes:

[0012] Receive a cross-chain transaction request sent by a first cross-chain gateway, the cross-chain transaction request carrying multi-signature information, a first hash value, first encrypted data, and proof information, the multi-signature information is used to prove that the first hash value is obtained by processing a cross-chain transaction from the first application chain system, the proof information is used to prove that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction, and the first cross-chain gateway is a cross-chain gateway connected to the first application chain system;

[0013] Verifying the multi-signature information and the certification information;

[0014] When both the multi-signature information and the proof information are verified, the first encrypted data is sent to the second cross-chain gateway, where the second cross-chain gateway is a cross-chain gateway connected to the second application chain system.

[0015] In the present application, after receiving the cross-chain transaction request sent by the first cross-chain gateway, the multi-signature information and proof information carried in the cross-chain transaction request are verified. If the multi-signature information and proof information are verified, the relay chain system can determine that the first hash value carried in the cross-chain transaction request is obtained by processing the target cross-chain transaction from the first application chain, and determine that the first hash value and the first encrypted data carried in the cross-chain transaction request are obtained by processing the same cross-chain transaction, thereby determining that the first encrypted data is obtained by processing the target cross-chain transaction from the first application chain, that is, determining that the first encrypted data is authentic, so that the first encrypted data can be sent to the second cross-chain gateway. In the embodiment of the present application, the relay chain system can verify the authenticity of the first encrypted data sent by the first cross-chain gateway to ensure that the cross-chain transaction original corresponding to the first encrypted data is not maliciously generated or tampered with. Only when the first encrypted data is authentic will the relay chain system send the first encrypted data to the second cross-chain gateway, thereby ensuring the security of cross-chain transactions in privacy transaction scenarios.

[0016] In a third aspect, a cross-chain transaction method is provided, the method comprising:

[0017] The first cross-chain gateway obtains the target cross-chain transaction sent by the first application chain system;

[0018] The first cross-chain gateway generates a first hash value, first encrypted data and proof information according to the target cross-chain transaction, wherein the first hash value is obtained by performing a hash operation on the target cross-chain transaction, the first encrypted data is obtained by encrypting the target cross-chain transaction, and the proof information is used to prove that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction;

[0019] The first cross-chain gateway obtains multi-signature information, where the multi-signature information includes a signature of each of the multiple nodes in the first application chain system on the hash value of the target cross-chain transaction, and the multi-signature information is used to prove that the first hash value is obtained by processing the target cross-chain transaction from the first application chain system;

[0020] The first cross-chain gateway sends a cross-chain transaction request to the relay chain system, where the cross-chain transaction request carries the multi-signature information, the first hash value, the first encrypted data, and the proof information;

[0021] After receiving the cross-chain transaction request sent by the first cross-chain gateway, the relay chain system verifies the multi-signature information and the proof information;

[0022] When both the multi-signature information and the proof information are verified, the relay chain system sends the first encrypted data to the second cross-chain gateway, where the second cross-chain gateway is a cross-chain gateway connected to the second application chain system.

[0023] In the present application, the first cross-chain gateway generates a first hash value, first encrypted data and proof information according to the acquired target cross-chain transaction, and the proof information can prove that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction. In addition, the first cross-chain gateway can obtain multi-signature information, which can prove that the first hash value is obtained by processing the cross-chain transaction from the first application chain system. The first cross-chain gateway can send a cross-chain transaction request carrying the first hash value, the first encrypted data, the proof information and the multi-signature information to the relay chain system. After receiving the cross-chain transaction request sent by the first cross-chain gateway, the relay chain system verifies the multi-signature information and the proof information carried in the cross-chain transaction request. When the multi-signature information and proof information are verified, the relay chain system can determine that the first hash value carried in the cross-chain transaction request is obtained by processing the target cross-chain transaction from the first application chain, and determine that the first hash value and the first encrypted data carried in the cross-chain transaction request are obtained by processing the same cross-chain transaction, thereby determining that the first encrypted data is obtained by processing the target cross-chain transaction from the first application chain, that is, determining that the first encrypted data is authentic, so that the first encrypted data can be sent to the second cross-chain gateway. In the embodiment of the present application, the relay chain system can verify the authenticity of the first encrypted data sent by the first cross-chain gateway to ensure that the cross-chain transaction original corresponding to the first encrypted data is not maliciously generated or tampered with. Only when the first encrypted data is authentic will the relay chain system send the first encrypted data to the second cross-chain gateway, thereby ensuring the security of cross-chain transactions in privacy transaction scenarios.

[0024] In a fourth aspect, a cross-chain transaction device is provided, which is applied to a first cross-chain gateway, where the first cross-chain gateway is a cross-chain gateway connected to a first application chain system, and the device includes:

[0025] A first acquisition module, used to acquire a target cross-chain transaction sent by the first application chain system;

[0026] A generation module, configured to generate a first hash value, first encrypted data, and proof information according to the target cross-chain transaction, wherein the first hash value is obtained by performing a hash operation on the target cross-chain transaction, the first encrypted data is obtained by encrypting the target cross-chain transaction, and the proof information is used to prove that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction;

[0027] A second acquisition module is used to obtain multi-signature information, where the multi-signature information includes a signature of each of the multiple nodes in the first application chain system on the hash value of the target cross-chain transaction, and the multi-signature information is used to prove that the first hash value is obtained by processing the target cross-chain transaction from the first application chain system;

[0028] The first sending module is used to send a cross-chain transaction request to the relay chain system, wherein the cross-chain transaction request carries the multi-signature information, the first hash value, the first encrypted data and the proof information. The cross-chain transaction request is used to instruct the relay chain system to send the first encrypted data to the second cross-chain gateway when the multi-signature information and the proof information are verified. The second cross-chain gateway is a cross-chain gateway connected to the second application chain system.

[0029] In a fifth aspect, a cross-chain transaction device is provided, which is applied to a relay chain system, and the device includes:

[0030] A first receiving module is configured to receive a cross-chain transaction request sent by a first cross-chain gateway, wherein the cross-chain transaction request carries multi-signature information, a first hash value, first encrypted data, and proof information, wherein the multi-signature information is used to prove that the first hash value is obtained by processing a cross-chain transaction from the first application chain system, and the proof information is used to prove that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction, and the first cross-chain gateway is a cross-chain gateway connected to the first application chain system;

[0031] A verification module, used to verify the multi-signature information and the certification information;

[0032] The sending module is used to send the first encrypted data to the second cross-chain gateway when the multi-signature information and the proof information are verified, and the second cross-chain gateway is a cross-chain gateway connected to the second application chain system.

[0033] In a sixth aspect, a cross-chain transaction system is provided, the system comprising a first cross-chain gateway, a relay chain system, and a second cross-chain gateway;

[0034] The first cross-chain gateway is used to obtain the target cross-chain transaction sent by the first application chain system;

[0035] The first cross-chain gateway is used to generate a first hash value, first encrypted data and proof information according to the target cross-chain transaction, wherein the first hash value is obtained by performing a hash operation on the target cross-chain transaction, the first encrypted data is obtained by encrypting the target cross-chain transaction, and the proof information is used to prove that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction;

[0036] The first cross-chain gateway is used to obtain multi-signature information, where the multi-signature information includes a signature of each of the multiple nodes in the first application chain system on the hash value of the target cross-chain transaction, and the multi-signature information is used to prove that the first hash value is obtained by processing the target cross-chain transaction from the first application chain system;

[0037] The first cross-chain gateway is used to send a cross-chain transaction request to the relay chain system, where the cross-chain transaction request carries the multi-signature information, the first hash value, the first encrypted data, and the proof information;

[0038] The relay chain system is used to receive the cross-chain transaction request sent by the first cross-chain gateway, and verify the multi-signature information and the proof information;

[0039] The relay chain system is used to send the first encrypted data to the second cross-chain gateway when the multi-signature information and the proof information are verified, and the second cross-chain gateway is a cross-chain gateway connected to the second application chain system.

[0040] In the seventh aspect, a computer device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the cross-chain transaction method provided in the first aspect.

[0041] In an eighth aspect, a computer device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the cross-chain transaction method provided in the second aspect.

[0042] In a ninth aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the cross-chain transaction method provided in the first aspect is implemented.

[0043] In the tenth aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the cross-chain transaction method provided in the second aspect is implemented.

[0044] In the eleventh aspect, a computer program product comprising instructions is provided, which, when executed on a computer, enables the computer to execute the steps of the cross-chain transaction method provided in the first aspect above.

[0045] In the twelfth aspect, a computer program product comprising instructions is provided, which, when executed on a computer, enables the computer to execute the steps of the cross-chain transaction method provided in the second aspect above.

[0046] It can be understood that the beneficial effects of the fourth, seventh, ninth and eleventh aspects can refer to the relevant description of the first aspect. The beneficial effects of the fifth, eighth, tenth and twelfth aspects can refer to the relevant description of the second aspect, and the beneficial effects of the sixth aspect can refer to the relevant description of the third aspect, which will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0048] Figure 1 It is a structural diagram of a blockchain system provided by an embodiment of the present application;

[0049] Figure 2 It is a structural diagram of a cross-chain transaction system provided in an embodiment of the present application;

[0050] Figure 3 This is a flow chart of a cross-chain transaction method provided by an embodiment of the present application;

[0051] Figure 4 It is a structural schematic diagram of a proof circuit provided in an embodiment of the present application;

[0052] Figure 5 It is a data structure diagram of a cross-chain transaction request provided in an embodiment of the present application;

[0053] Figure 6 This is a flow chart of another cross-chain transaction method provided by an embodiment of the present application;

[0054] Figure 7 This is a flow chart of another cross-chain transaction method provided in an embodiment of the present application;

[0055] Figure 8 It is a structural schematic diagram of a cross-chain transaction device provided in an embodiment of the present application;

[0056] Fig. 9 It is a structural schematic diagram of another cross-chain transaction device provided in an embodiment of the present application;

[0057] Fig.10 is a structural schematic diagram of a computer device provided in an embodiment of the present application;

[0058] Fig.11 It is a structural schematic diagram of another computer device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0059] In order to make the objectives, technical solutions and advantages of the present application clearer, the implementation methods of the present application will be further described in detail below with reference to the accompanying drawings.

[0060] It should be understood that the "multiple" mentioned in this application refers to two or more. In the description of this application, unless otherwise specified, " / " means or, for example, A / B can mean A or B; "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in order to facilitate the clear description of the technical solution of this application, the words "first" and "second" are used to distinguish between the same items or similar items with basically the same functions and effects. Those skilled in the art can understand that the words "first" and "second" do not limit the quantity and execution order, and the words "first" and "second" do not limit them to be different.

[0061] Before explaining the embodiments of the present application in detail, the application scenarios of the embodiments of the present application are first described.

[0062] The cross-chain transaction method provided in the embodiment of the present application can be applied to the cross-chain transaction scenario, that is, it can be applied to the scenario where a transaction in one application chain system (i.e., a cross-chain transaction) needs to be executed in another application chain system, and can be specifically applied to the cross-chain transaction scenario under the privacy transaction scenario.

[0063] In an embodiment of the present application, when an application chain system receives or generates a transaction, the cross-chain gateway connected to the application chain system obtains the cross-chain transaction, encrypts the cross-chain transaction and generates relevant information of the cross-chain transaction that can be verified by the relay chain system. After the relay chain system receives the encrypted cross-chain transaction and the cross-chain transaction related information, it verifies the cross-chain transaction related information to determine the authenticity of the encrypted cross-chain transaction, and if the encrypted cross-chain transaction is authentic, it sends the encrypted cross-chain transaction to another application chain system so that the other application chain system executes the decrypted cross-chain transaction. This ensures that the encrypted cross-chain transaction sent to another application chain system is authentic, and solves the problem that the cross-chain transaction is tampered with in the privacy transaction scenario and the relay chain system cannot verify and intercept it.

[0064] Before explaining the embodiments of the present application, the relevant contents of the blockchain are explained first.

[0065] Figure 1 It is a structural diagram of a blockchain system provided in an embodiment of the present application.

[0066] See also Figure 1 , the blockchain system 100 refers to a system for sharing data between nodes, and the blockchain system 100 may include multiple nodes 101. Each node 101 can receive input information when performing normal work, and maintain the shared data in the blockchain system 100 based on the received input information. In order to ensure the information intercommunication within the blockchain system 100, there can be an information connection between each node 101 in the blockchain system 100, and information can be transmitted between the nodes 101 through the information connection. For example, when any node 101 in the blockchain system 100 receives input information, other nodes 101 in the blockchain system 100 obtain the input information according to the consensus algorithm, and store the input information as data in the shared data, so that the data stored on all nodes 101 in the blockchain system 100 are consistent. Each node 101 in the blockchain system 100 stores the same blockchain.

[0067] The blockchain system 100 has computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, encryption algorithm, etc. The blockchain system 100 is a distributed shared account book and database, which has the characteristics of decentralization, non-tamperability, full traceability, traceability, collective maintenance, openness and transparency. These characteristics ensure the sharing, openness, authenticity, integrity, security and reliability of the blockchain.

[0068] Before explaining in detail the cross-chain transaction method provided in the embodiment of the present application, the terms involved in the embodiment of the present application are first explained.

[0069] Application chain system: The application chain system is a blockchain system that receives or generates cross-chain transactions, or a blockchain system that executes cross-chain transactions.

[0070] Relay chain system: The relay chain system is a blockchain system. The relay chain system can be connected to the application chain system to realize the verification of cross-chain transactions.

[0071] Cross-chain gateway: The cross-chain gateway is the adapter between the application chain system and the relay chain system. The cross-chain gateway can capture cross-chain events generated in the application chain system and submit relevant data of cross-chain transactions to the relay chain system; or, the cross-chain gateway can receive cross-chain transactions verified by the relay chain system and submit cross-chain transactions to the application chain system.

[0072] Cross-chain transaction: A cross-chain transaction is a transaction between two application chain systems, which can contain information such as the source application chain identifier and the destination application chain identifier.

[0073] The system architecture involved in the embodiments of the present application is described below.

[0074] Figure 2 is a schematic diagram of a cross-chain transaction system provided by an embodiment of the present application. Figure 2 The cross-chain transaction system includes: a first cross-chain gateway 201, a relay chain system 202, and a second cross-chain gateway 203.

[0075] The first cross-chain gateway 201 is a cross-chain gateway connected to the first application chain system 204. The first cross-chain gateway 201 is used to capture cross-chain events generated in the first application chain system 204 and submit relevant data of cross-chain transactions to the relay chain system 202.

[0076] The second cross-chain gateway 203 is a cross-chain gateway connected to the second application chain system 205. The second cross-chain gateway 203 is used to receive cross-chain transactions verified by the relay chain system 202 and submit cross-chain transactions to the second application chain system 205.

[0077] The relay chain system 202 is located between the first cross-chain gateway 201 and the second cross-chain gateway 203, and the relay chain system 202 is used to verify the relevant data of the cross-chain transaction submitted by the first cross-chain gateway 201. The relay chain system 202 can communicate with the first cross-chain gateway 201 through a wired network or a wireless network, and can also communicate with the second cross-chain gateway 203 through a wired network or a wireless network.

[0078] The first application chain system 204, the second application chain system 205 and the relay chain system 202 are all blockchain systems, and the blockchain system can be as described above. Figure 1 The blockchain system 100 described in the embodiment.

[0079] In the embodiment of the present application, there is a cross-chain transaction between the first application chain system 204 and the second application chain system 205. For the cross-chain transaction, the first application chain system 204 can be the source application chain system, and the second application chain system 205 can be the destination application chain system. That is, the cross-chain transaction can be a transaction initiated by a user of the first application chain system 204 and needs to be sent to the second application chain system 205.

[0080] The first cross-chain gateway 201, the relay chain system 202, and the second cross-chain gateway 203 may execute the following Figure 3 The cross-chain transaction method described in the embodiment is used to implement the cross-chain transaction between the first application chain system 204 and the second application chain system 205.

[0081] The cross-chain transaction method provided in the embodiment of the present application is explained in detail below.

[0082] Figure 3 This is a flow chart of a cross-chain transaction method provided by an embodiment of the present application. Figure 3 , the method comprises the following steps.

[0083] Step 301: The first cross-chain gateway obtains the target cross-chain transaction sent by the first application chain system.

[0084] The target cross-chain transaction is a transaction between the first application chain system and the second application chain system. For the target cross-chain transaction, the first application chain system is the source application chain system, and the second application chain system is the destination application chain system. That is, the target cross-chain transaction can be a transaction initiated by a user of the first application chain system and needs to be sent to the second application chain system.

[0085] The target cross-chain transaction is a cross-chain transaction originating from the first application chain system. For example, the target cross-chain transaction can be a transaction sent by the client and received by the first application chain system, or it can be a transaction generated by the first application chain system.

[0086] The target cross-chain transaction can include information such as the source application chain identifier and the destination application chain identifier.

[0087] The source application chain identifier is used to identify the source application chain system of the target cross-chain transaction. In the embodiment of the present application, the source application chain identifier is the identifier of the first application chain system. The destination application chain identifier is used to identify the destination application chain system of the target cross-chain transaction. In the embodiment of the present application, the destination application chain identifier is the identifier of the second application chain system. The identifier of the application chain system can be the MAC (Media Access Control) address, IP (Internet Protocol) address, etc. of the application chain system, and the embodiment of the present application does not make a unique limitation on this.

[0088] Specifically, the operation of step 301 may be: the first cross-chain gateway obtains a cross-chain event generated by the first application chain system, and the cross-chain event carries the target cross-chain transaction.

[0089] In some embodiments, the user device can call the cross-chain contract deployed on the first application chain system to initiate a target cross-chain transaction to the first application chain system. After receiving the target cross-chain transaction sent by the user device, the first application chain system throws a cross-chain event, which includes the target cross-chain transaction. The application chain plug-in polls or subscribes to the cross-chain event, and then sends the cross-chain event to the first cross-chain gateway, so that the first cross-chain gateway can obtain the target cross-chain transaction.

[0090] Optionally, the cross-chain event may also include a target hash value, which is the hash value of the target cross-chain transaction generated by the first application chain system, that is, the target hash value obtained by the first application chain system performing a hash operation on the target cross-chain transaction. In this way, the first cross-chain gateway can also obtain the hash value (i.e., the target hash value) of the target cross-chain transaction generated by the first application chain.

[0091] Step 302: The first cross-chain gateway generates a first hash value, first encrypted data, and proof information according to the target cross-chain transaction.

[0092] The first hash value is obtained by the first cross-chain gateway performing a hash operation on the target cross-chain transaction, and the first encrypted data is obtained by the first cross-chain gateway encrypting the target cross-chain transaction.

[0093] The proof information is generated by the first cross-chain gateway based on the first hash value and the first encrypted data, and the proof information is used to prove that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction.

[0094] Specifically, the operation of step 302 may be implemented in the following two possible ways.

[0095] In a first possible manner, the first cross-chain gateway inputs the target cross-chain transaction into a proof circuit, and the proof circuit outputs a first hash value, first encrypted data, and the proof information.

[0096] The proof circuit is used to generate the first hash value, the first encrypted data and the proof information. For example, the proof circuit may be a circom circuit, which is a zero-knowledge proof circuit written in a circom circuit programming language.

[0097] The proof circuit includes a hash circuit, a first encryption circuit, and a second encryption circuit. The input data of the hash circuit and the first encryption circuit are the input data of the proof circuit, one input data of the second encryption circuit is the output data of the hash circuit, the other input data of the second encryption circuit is the output data of the first encryption circuit, and the output data of the proof circuit is the output data of the hash circuit, the output data of the first encryption circuit, and the output data of the second encryption circuit.

[0098] In order to ensure that the data is not leaked, the input data of the proof circuit is a private input, that is, the input data of the hash circuit and the input data of the first encryption circuit are both private inputs. In the embodiment of the present application, the private input is a cross-chain transaction from the first application chain system (i.e., the target cross-chain transaction).

[0099] The hash circuit is used to perform a hash operation on the input data, the first encryption circuit is used to encrypt the input data, the second encryption circuit is used to generate output data based on the two input data, and the output data of the second encryption circuit is used to prove that the output data of the hash circuit and the output data of the first encryption circuit are obtained by processing the same input data.

[0100] In this way, when the input data of the proof circuit is the target cross-chain transaction, the hash circuit can perform a hash operation on the input target cross-chain transaction to obtain a first hash value, the first encryption circuit can encrypt the input target cross-chain transaction to obtain first encrypted data, and the second encryption circuit can generate proof information based on the input first hash value and the first encrypted data, and the proof information is used to prove that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction.

[0101] Among them, the operation of the first encryption circuit to encrypt the input data is similar to the operation of a certain encryption circuit in the related art to encrypt a certain input data, and the embodiment of the present application will not elaborate on this in detail.

[0102] The operation of the second encryption circuit generating output data based on two input data is similar to the operation of a certain encryption circuit generating one output data based on two input data in the related art, which is not elaborated in detail in the present embodiment. For example, the second encryption circuit can encrypt two input data to obtain output data.

[0103] It should be noted that the proof circuit has verifier information, and the second encryption circuit can generate output data according to the two input data and the verifier information of the proof circuit.

[0104] The verifier information is used to verify whether a certain data is generated by the certification circuit. For example, the verifier information may be the public key of the certification circuit.

[0105] After the second encryption circuit generates an output data according to the verifier information of the proof circuit, the verifier information of the proof circuit can be analyzed from the output data. In this case, if the verifier information of the proof circuit is analyzed from a certain data, it means that the data is the output data of the second encryption circuit, that is, the data is generated by the proof circuit, otherwise, it means that the data is not generated by the proof circuit. Therefore, the verifier information of the proof circuit can be used to verify whether a certain data is generated by the proof circuit.

[0106] In this case, before obtaining the target cross-chain transaction sent by the first application chain system, the first cross-chain gateway can also send the verifier information of the proof circuit to the relay chain system. In this way, the relay chain system can subsequently use the verifier information of the proof circuit to verify whether the proof information sent by the first cross-chain gateway is generated by the proof circuit.

[0107] Optionally, the first cross-chain gateway may register the verifier information of the proof circuit in the relay chain system in the form of registration information.

[0108] For example: The input data of the proof circuit is the target cross-chain transaction. Figure 4 The schematic diagram of the circuit is shown in Figure 1. Figure 4 , Figure 4 The proof circuit 401 includes a hash circuit 402, a first encryption circuit 403, and a second encryption circuit 404. The target cross-chain transaction is input into the proof circuit 401, that is, the target cross-chain transaction is input into the hash circuit 402 and the first encryption circuit 403 at the same time. The hash circuit 402 performs a hash operation on the target cross-chain transaction to obtain a first hash value. The first encryption circuit 403 encrypts the target cross-chain transaction to obtain first encrypted data. Afterwards, the first hash value and the first encrypted data are input into the second encryption circuit 404. The second encryption circuit 404 encrypts the first hash value, the first encrypted data, and the verifier information of the proof circuit 401 to obtain proof information. Afterwards, the proof circuit 401 outputs the first hash value output by the hash circuit 402, the first encrypted data output by the first encryption circuit 403, and the proof information output by the second encryption circuit 404, thereby obtaining the output data of the proof circuit 401.

[0109] In an embodiment of the present application, after the target cross-chain transaction is used as the privacy input of the proof circuit, the proof circuit outputs a first hash value, a first encrypted data and the proof information. In this way, the proof information can be subsequently verified by the verifier information of the proof circuit to prove whether the proof information is generated by the proof circuit. If the proof information is generated by the proof circuit, it can be determined that the proof information is generated by the second encryption circuit according to the first hash value output by the hash circuit and the first encrypted data output by the first encryption circuit. Since the hash circuit and the first encryption circuit in the proof circuit share the same input data, the proof information can prove that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction, thereby proving that the first encrypted data has a certain authenticity. In this way, it can be ensured that the first cross-chain gateway can generate relevant proof information that can prove the authenticity of the encrypted cross-chain transaction (i.e., the first encrypted data) without leaking the target cross-chain transaction.

[0110] In a second possible manner, the first cross-chain gateway performs a hash operation on the target cross-chain transaction in a trusted computing environment to obtain a first hash value, and encrypts the target cross-chain transaction to obtain first encrypted data; in the trusted computing environment, a hash operation is performed on the first hash value and the first encrypted data to obtain an information summary; in the trusted computing environment, the information summary is encrypting using a private key of the trusted computing environment to obtain a digital signature as the proof information.

[0111] A trusted computing environment means that the computing services provided by the system are trustworthy. It is an information security technology that combines computing and protection, ensuring that the computing behavior is consistent with expectations and that the entire process is detectable and monitorable. A trusted computing environment can be implemented through Intel SGX (Software Guard Extensions), Intel TXT (Trusted Execution Technology), ARM TrustZone technology, TPM (Trusted Platform Module), TCM (Trusted Cryptography Module) or other similar technologies. The security of a trusted computing environment can be built on hardware, such as the presence of keys that are fixed in hardware, and the presence of measurement mechanisms and remote authentication mechanisms. Through these mechanisms, a trusted computing environment can prove that certain programs are running in a secure environment and can sign the results.

[0112] The private key of the trusted computing environment can be a key solidified in hardware. The trusted computing environment can ensure the security of the operation process. Therefore, the digital signature for the first hash value and the first encrypted data obtained in the trusted computing environment according to the private key of the trusted computing environment can prove that the first hash value and the first encrypted data are obtained through a pre-set operation in the trusted computing environment. Since the first cross-chain gateway obtains the first hash value by performing a hash operation on the target cross-chain transaction in the trusted computing environment, and the first encrypted data by encrypting the target cross-chain transaction, the digital signature (i.e., the proof information) can prove that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction.

[0113] Step 303: The first cross-chain gateway obtains multi-signature information.

[0114] The multi-signature information includes the signature of the hash value of the target cross-chain transaction (i.e., the target hash value) of each node in the multiple nodes in the first application chain system. The multi-signature information is used to prove that the first hash value is obtained by processing the target cross-chain transaction from the first application chain system.

[0115] Since the multi-signature information includes the signature of each of the multiple nodes in the first application chain system on the target hash value, and the target hash value is the hash value of the target cross-chain transaction generated by the first application chain system, it is possible to verify whether the target hash value is the same as the first hash value based on the multi-signature information. If they are the same, it means that the first hash value is the hash value of the target cross-chain transaction from the first application chain system; if they are different, it means that the first hash value is not the hash value of the target cross-chain transaction from the first application chain system. In this way, the multi-signature information can be used to verify whether the first hash value is obtained by processing the cross-chain transaction from the first application chain system.

[0116] Specifically, the operation of step 303 can be implemented in the following two possible ways.

[0117] In the first possible way, if the cross-chain event generated by the first application chain system obtained by the first cross-chain gateway includes not only the target cross-chain transaction but also the target hash value, the first cross-chain gateway sends a request message to each of the multiple nodes of the first application chain system, and the request message carries the target hash value. The request message is used to request the node to sign the target hash value carried by the request message; the first cross-chain gateway receives the signature of the target hash value sent by each of the multiple nodes to obtain the multi-signature information.

[0118] The first cross-chain gateway sends the request message to each of the multiple nodes of the first application chain system. For any one of the multiple nodes of the first application chain system, after receiving the request message carrying the target hash value sent by the first cross-chain gateway, the node compares the target hash value carried in the request message with the hash value of the target cross-chain transaction stored in its own blockchain. If the target hash value is the same as the hash value of the target cross-chain transaction stored in its own blockchain, the target hash value is signed and returned to the first cross-chain gateway. In this way, the first cross-chain gateway can obtain the signature of each of the multiple nodes on the target hash value, and thus obtain the multi-signature information.

[0119] The operation of signing the target hash value by any one of the multiple nodes may be: the node encrypts the target hash value using its own private key to obtain the signature of the target hash value.

[0120] The second possible way is that if the cross-chain event generated by the first application chain system obtained by the first cross-chain gateway includes not only the target cross-chain transaction but also multi-signature information, the first cross-chain gateway directly obtains the multi-signature information in the cross-chain event.

[0121] In this case, the first application chain system performs a hash operation on the target cross-chain transaction, obtains the target hash value, and then obtains the signature of each node in the multiple nodes of the first application chain system on the target hash value to obtain the multi-signature information, and then generates a cross-chain event carrying the target cross-chain transaction and the multi-signature information. In this case, the first cross-chain gateway can directly obtain the multi-signature information from the cross-chain event, thereby saving the processing resources of the first cross-chain gateway, reducing the pressure on the first cross-chain gateway, and improving the processing performance of the first cross-chain gateway.

[0122] It is worth noting that before the first cross-chain gateway obtains the target cross-chain transaction sent by the first application chain system, the first cross-chain gateway can send the public key of each of the multiple nodes in the first application chain system to the relay chain system. In this way, the relay chain system can subsequently use the public key of each of the multiple nodes in the first application chain system to verify the multi-signature information sent by the first cross-chain gateway.

[0123] Optionally, the first cross-chain gateway can register the public key of each of the multiple nodes in the first application chain system in the relay chain system in the form of registration information.

[0124] Step 304: The first cross-chain gateway sends a cross-chain transaction request to the relay chain system, and the cross-chain transaction request carries the multi-signature information, the first hash value, the first encrypted data and the proof information.

[0125] The cross-chain transaction request is used to instruct the relay chain system to send the first encrypted data to the second cross-chain gateway when the multi-signature information and the proof information are verified. The second cross-chain gateway is a cross-chain gateway connected to the second application chain system.

[0126] In this case, the relay chain system can receive the cross-chain transaction request carrying the multi-signature information, the first hash value, the first encrypted data and the proof information, and then can verify the multi-signature information and the proof information carried in the cross-chain transaction request, wherein verifying the multi-signature information is to verify whether the first hash value carried in the cross-chain transaction request is obtained by processing the target cross-chain transaction from the first application chain system, wherein verifying the proof information is to verify whether the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction, and then by verifying the multi-signature information and the proof information, it can be realized to verify whether the first encrypted data is obtained by processing the target cross-chain transaction from the first application chain system, that is, to verify whether the first encrypted data is authentic. Thus, the relay chain system can determine whether the encrypted cross-chain transaction (that is, the first encrypted data) is authentic without knowing the original text of the cross-chain transaction (that is, the target cross-chain transaction). In this way, without leaking the transaction data, the relay chain system can verify the authenticity of the first encrypted data sent by the first cross-chain gateway, and then ensure that the first encrypted data sent to the second cross-chain gateway is authentic, thereby solving the problem that the cross-chain transaction is tampered with in the privacy transaction scenario and the relay chain system cannot verify and intercept it.

[0127] Optionally, the first cross-chain gateway may send the cross-chain transaction request to the relay chain system through a cross-chain protocol.

[0128] For example: Figure 5 The data structure diagram of the cross-chain transaction request. The first cross-chain gateway can send the following to the relay chain system: Figure 5 The cross-chain transaction request shown. Figure 5 The cross-chain transaction request shown in 501 includes a header 501, a payload (valid data) part 502 and a proof (proof data) part 503. The header 501 of the cross-chain transaction request includes the version of the cross-chain protocol, the payload part 502 includes the first encrypted data, and the proof part 503 includes the first hash value, the multi-signature information and the proof information.

[0129] Step 305: After receiving the cross-chain transaction request sent by the first cross-chain gateway, the relay chain system verifies the multi-signature information carried in the cross-chain transaction request, and verifies the proof information carried in the cross-chain transaction request.

[0130] When the relay chain system receives the cross-chain transaction request sent by the first cross-chain gateway, it will obtain the multi-signature information, the first hash value, the first encrypted data and the proof information, and can further verify the multi-signature information and the proof information.

[0131] In this case, the relay chain system verifies the multi-signature information, that is, verifies whether the first hash value is obtained by processing the target cross-chain transaction from the first application chain, and verifies the proof information, that is, verifies whether the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction. If the multi-signature information is verified, it means that the first hash value is obtained by processing the target cross-chain transaction from the first application chain. In this case, if the proof information is verified, it means that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction, which means that the first encrypted data is obtained by processing the target cross-chain transaction from the first application chain, that is, the first encrypted data is authentic. Therefore, in the embodiment of the present application, by verifying the multi-signature information and the proof information, it can be realized to verify whether the first encrypted data is obtained by processing the target cross-chain transaction from the first application chain, that is, to verify whether the first encrypted data is authentic.

[0132] Among them, the operation of the relay chain system to verify the multi-signature information can be: the relay chain system decrypts the multi-signature information according to the public key of each node in the multiple nodes in the first application chain system; if the target hash value is successfully decrypted from the multi-signature information, then if the target hash value is the same as the first hash value, it is determined that the multi-signature information verification is successful; if the decryption of the multi-signature information fails, or if the target hash value is successfully decrypted from the multi-signature information and the target hash value is different from the first hash value, it is determined that the multi-signature information verification has failed.

[0133] The first cross-chain gateway has registered the public key of each of the multiple nodes of the first application chain system in the relay chain system in advance, so the relay chain system can directly use the public key of each of the multiple nodes of the first application chain system registered in advance to decrypt the multi-signature information.

[0134] If the relay chain system successfully decrypts the target hash value from the multi-signature information, it means that the multi-signature information is obtained by signing the target hash value by each of the multiple nodes of the first application chain system, that is, the multi-signature information is obtained by signing the hash value of the target cross-chain transaction from the first application chain system. In this case, if the target hash value decrypted from the multi-signature information is the same as the first hash value, it means that the first hash value is the hash value of the target cross-chain transaction from the first application chain system, that is, the first hash value is obtained by processing the target cross-chain transaction from the first application chain system, and thus the multi-signature information verification is successful. If the target hash value decrypted from the multi-signature information is different from the first hash value, it means that the first hash value is not the hash value of the target cross-chain transaction from the first application chain system, that is, the first hash value is not obtained by processing the target cross-chain transaction from the first application chain system, and thus the multi-signature information verification fails.

[0135] If the decryption of the multi-signature information fails, it means that the multi-signature information is not obtained by signing the target hash value by each node in the multiple nodes of the first application chain system, and thus the multi-signature information verification fails. In this case, the first hash value cannot be further verified, and it can be directly determined that the first hash value is not obtained by processing the target cross-chain transaction from the first application chain system.

[0136] Among them, when the proof information is generated by the first possible method in the above step 302, the operation of verifying the proof information by the relay chain system can be implemented through the following steps (1) to (3).

[0137] (1) The relay chain system decrypts the proof information to obtain the second hash value, the second encrypted data and the target verifier information.

[0138] In this way, the relay chain system will obtain the first hash value, the first encrypted data, the second hash value, the second encrypted data and the target verifier information, and the relay chain system can further verify this information.

[0139] The operation of the relay chain system to decrypt the proof information is similar to the operation of a certain device to decrypt a certain information in the related art, and the embodiment of the present application will not elaborate on this. For example: the relay chain system can use a decryption algorithm to decrypt the proof information to obtain the second hash value, the second encrypted data and the target verifier information. The decryption algorithm can be a decryption algorithm corresponding to the encryption algorithm in the second encryption circuit in the proof circuit.

[0140] (2) The relay chain system determines that the verification of the proof information is successful when the target verifier information is the same as the verifier information of the proof circuit, the second hash value is the same as the first hash value, and the second encrypted data is the same as the first encrypted data.

[0141] If the first cross-chain gateway has registered the verifier information of the proof circuit in the relay chain system in advance, the relay chain system can directly use the pre-registered verifier information of the proof circuit to verify the target verifier information to determine whether the proof information is generated by the proof circuit.

[0142] In this case, if the target verifier information is the same as the verifier information of the proof circuit, it means that the proof information is encrypted according to the verifier information of the proof circuit, that is, it means that the proof information is generated by the proof circuit, and thus it means that the second hash value and the second encrypted data decrypted from the proof information are obtained by processing the same cross-chain transaction. In this case, if the second hash value is the same as the first hash value, and the second encrypted data is the same as the first encrypted data, it means that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction, so it can be determined that the proof information has been verified.

[0143] (3) The relay chain system determines that the verification of the proof information has failed when the target verifier information is different from the verifier information of the proof circuit, and / or the second hash value is different from the first hash value, and / or the second encrypted data is different from the first encrypted data.

[0144] In this case, if the target verifier information is different from the verifier information of the proof circuit, it means that the proof information is not encrypted according to the verifier information of the proof circuit, that is, it means that the proof information is not generated by the proof circuit, so it can be directly determined that the verification of the proof information has failed. If the target verifier information is the same as the verifier information of the proof circuit, but the second hash value is different from the first hash value, and / or the second encrypted data is different from the first encrypted data, it means that the first hash value and the first encrypted data are not obtained by processing the same cross-chain transaction, so it can be determined that the verification of the proof information has failed.

[0145] Among them, when the proof information is generated through the second possible method in the above step 302, the operation of the relay chain system to verify the proof information can be: in a trusted computing environment, using the public key of the trusted computing environment to decrypt the proof information to obtain a first information summary; in the trusted computing environment, performing a hash operation on the first hash value and the first encrypted data to obtain a second information summary; if the first information summary is the same as the second information summary, it is determined that the proof information verification is successful; if the first information summary is different from the second information summary, it is determined that the proof information verification has failed.

[0146] The relay chain system can obtain the public key of the trusted computing environment from the first cross-chain gateway or from a third-party certification authority.

[0147] In this case, if the first information digest is the same as the second information digest, it means that the first hash value and the first encrypted data carried in the cross-chain transaction request are obtained through a pre-set operation in a trusted computing environment, then it can be determined that the fact proved by the proof information is true, that is, it is determined that the first hash value and the first encrypted data are indeed obtained by processing the same cross-chain transaction, and then it is determined that the proof information verification is passed. If the first information digest is different from the second information digest, it means that the first hash value and the first encrypted data carried in the cross-chain transaction request are not obtained through a pre-set operation in a trusted computing environment, then it can be determined that the fact proved by the proof information is false, that is, it is determined that the first hash value and the first encrypted data are not obtained by processing the same cross-chain transaction, and then it is determined that the proof information verification fails.

[0148] Step 306: When both the multi-signature information and the proof information are verified, the relay chain system sends the first encrypted data to the second cross-chain gateway.

[0149] If both the multi-signature information and the proof information are verified, it means that the first encrypted data is obtained by processing the target cross-chain transaction from the first application chain system, that is, the first encrypted data is authentic, and the relay chain system can send the first encrypted data to the second cross-chain gateway. If at least one of the multi-signature information and the proof information fails to be verified, it means that the first encrypted data is not obtained by processing the target cross-chain transaction from the first application chain system, that is, the first encrypted data is not authentic. In this case, the relay chain system can intercept the first encrypted data, that is, not send the first encrypted data to the second cross-chain gateway.

[0150] In the embodiment of the present application, the relay chain system can verify the first encrypted data sent by the first cross-chain gateway to ensure that the cross-chain transaction original corresponding to the first encrypted data is not maliciously generated or tampered with, that is, to ensure the authenticity of the first encrypted data. Only when the first encrypted data is authentic will the relay chain system send the first encrypted data to the second cross-chain gateway, thereby ensuring the security of cross-chain transactions.

[0151] Furthermore, after receiving the first encrypted data verified by the relay chain system, the second cross-chain gateway can decrypt the first encrypted data to obtain the target cross-chain transaction. After that, the second cross-chain gateway can send the decrypted target cross-chain transaction to the second application chain system so that the second application chain system executes the target cross-chain transaction.

[0152] It is worth noting that during the entire cross-chain transaction process, the relay chain system will not obtain the original cross-chain transaction text (i.e., the target cross-chain transaction), and the relay chain system has always been unknown to the original cross-chain transaction text. In the embodiment of the present application, the relay chain system can still verify the authenticity of the encrypted cross-chain transaction (i.e., the first encrypted data) without knowing the original cross-chain transaction text. In this way, the verification of the encrypted cross-chain transaction is achieved without leaking the original cross-chain transaction text, that is, while ensuring the security of the transaction data, thereby solving the problem that the cross-chain transaction is tampered with in the privacy transaction scenario and the relay chain system cannot verify and intercept it, and ensuring the security of the cross-chain transaction.

[0153] In an embodiment of the present application, the first cross-chain gateway generates a first hash value, first encrypted data, and proof information according to the acquired target cross-chain transaction, and the proof information can prove that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction. In addition, the first cross-chain gateway can obtain multi-signature information, which can prove that the first hash value is obtained by processing a cross-chain transaction from the first application chain system. The first cross-chain gateway can send a cross-chain transaction request carrying the first hash value, the first encrypted data, the proof information, and the multi-signature information to the relay chain system. After receiving the cross-chain transaction request sent by the first cross-chain gateway, the relay chain system verifies the multi-signature information and the proof information carried in the cross-chain transaction request. When the multi-signature information and proof information are verified, the relay chain system can determine that the first hash value carried in the cross-chain transaction request is obtained by processing the target cross-chain transaction from the first application chain, and determine that the first hash value and the first encrypted data carried in the cross-chain transaction request are obtained by processing the same cross-chain transaction, thereby determining that the first encrypted data is obtained by processing the target cross-chain transaction from the first application chain, that is, determining that the first encrypted data is authentic, so that the first encrypted data can be sent to the second cross-chain gateway. In the embodiment of the present application, the relay chain system can verify the authenticity of the first encrypted data sent by the first cross-chain gateway to ensure that the cross-chain transaction original corresponding to the first encrypted data is not maliciously generated or tampered with. Only when the first encrypted data is authentic will the relay chain system send the first encrypted data to the second cross-chain gateway, thereby ensuring the security of cross-chain transactions in privacy transaction scenarios.

[0154] Figure 6 is a flow chart of a cross-chain transaction method provided in an embodiment of the present application. The method is applied to a first cross-chain gateway, which is a cross-chain gateway connected to a first application chain system. Figure 6 , the method comprises the following steps:

[0155] Step 601: Obtain the target cross-chain transaction sent by the first application chain system.

[0156] The relevant content of step 601 has been explained in the above step 301, and will not be repeated in this embodiment of the present application.

[0157] Step 602: Generate a first hash value, first encrypted data, and proof information according to the target cross-chain transaction, where the proof information is used to prove that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction.

[0158] The first hash value is obtained by performing a hash operation on the target cross-chain transaction, and the first encrypted data is obtained by encrypting the target cross-chain transaction.

[0159] The relevant content of step 602 has been explained in the above step 302, and will not be repeated in this embodiment of the present application.

[0160] Step 603: Obtain multi-signature information, which is used to prove that the first hash value is obtained by processing the target cross-chain transaction from the first application chain system.

[0161] The relevant content of step 603 has been explained in the above step 303, and will not be repeated in this embodiment of the present application.

[0162] Step 604: Send a cross-chain transaction request to the relay chain system, which carries the multi-signature information, the first hash value, the first encrypted data and the proof information. The cross-chain transaction request is used to instruct the relay chain system to send the first encrypted data to the second cross-chain gateway when the multi-signature information and the proof information are verified.

[0163] The second cross-chain gateway is a cross-chain gateway that is connected to the second application chain system.

[0164] The relevant content of step 604 has been explained in the above step 304, and will not be repeated in this embodiment of the present application.

[0165] In an embodiment of the present application, the first cross-chain gateway generates a first hash value, first encrypted data, and proof information according to the acquired target cross-chain transaction, and the proof information can prove that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction. In addition, the first cross-chain gateway can obtain multi-signature information, which can prove that the first hash value is obtained by processing a cross-chain transaction from the first application chain system. The first cross-chain gateway can send a cross-chain transaction request carrying the first hash value, the first encrypted data, the proof information, and the multi-signature information to the relay chain system. After receiving the cross-chain transaction request sent by the first cross-chain gateway, the relay chain system verifies the multi-signature information and the proof information carried in the cross-chain transaction request. When the multi-signature information and proof information are verified, the relay chain system can determine that the first hash value carried in the cross-chain transaction request is obtained by processing the target cross-chain transaction from the first application chain, and determine that the first hash value and the first encrypted data carried in the cross-chain transaction request are obtained by processing the same cross-chain transaction, thereby determining that the first encrypted data is obtained by processing the target cross-chain transaction from the first application chain, that is, determining that the first encrypted data is authentic, so that the first encrypted data can be sent to the second cross-chain gateway. In the embodiment of the present application, the relay chain system can verify the authenticity of the first encrypted data sent by the first cross-chain gateway to ensure that the cross-chain transaction original corresponding to the first encrypted data is not maliciously generated or tampered with. Only when the first encrypted data is authentic will the relay chain system send the first encrypted data to the second cross-chain gateway, thereby ensuring the security of cross-chain transactions in privacy transaction scenarios.

[0166] Figure 7 is a flow chart of a cross-chain transaction method provided in an embodiment of the present application. The method is applied to the relay chain system. Figure 7 , the method comprises the following steps:

[0167] Step 701: Receive a cross-chain transaction request sent by the first cross-chain gateway. The cross-chain transaction request carries multi-signature information, a first hash value, first encrypted data and proof information. The multi-signature information is used to prove that the first hash value is obtained by processing a cross-chain transaction from the first application chain system, and the proof information is used to prove that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction.

[0168] The relevant content of step 701 has been explained in the above step 305, and will not be repeated in this embodiment of the present application.

[0169] Step 702: Verify the multi-signature information and the certification information.

[0170] The relevant content of step 702 has been explained in the above step 305, and will not be repeated in this embodiment of the present application.

[0171] Step 703: When both the multi-signature information and the proof information are verified, the first encrypted data is sent to the second cross-chain gateway.

[0172] The second cross-chain gateway is a cross-chain gateway that is connected to the second application chain system.

[0173] The relevant content of step 703 has been explained in the above step 306, and will not be repeated in this embodiment of the present application.

[0174] In an embodiment of the present application, after receiving the cross-chain transaction request sent by the first cross-chain gateway, the relay chain system verifies the multi-signature information and proof information carried in the cross-chain transaction request. If the multi-signature information and proof information are verified, the relay chain system can determine that the first hash value carried in the cross-chain transaction request is obtained by processing the target cross-chain transaction from the first application chain, and determine that the first hash value and the first encrypted data carried in the cross-chain transaction request are obtained by processing the same cross-chain transaction, thereby determining that the first encrypted data is obtained by processing the target cross-chain transaction from the first application chain, that is, determining that the first encrypted data is authentic, so that the first encrypted data can be sent to the second cross-chain gateway. In an embodiment of the present application, the relay chain system can verify the authenticity of the first encrypted data sent by the first cross-chain gateway to ensure that the cross-chain transaction original corresponding to the first encrypted data is not maliciously generated or tampered with. Only when the first encrypted data is authentic will the relay chain system send the first encrypted data to the second cross-chain gateway, thereby ensuring the security of cross-chain transactions in privacy transaction scenarios.

[0175] Figure 8 is a schematic diagram of the structure of a cross-chain transaction device provided in an embodiment of the present application. The cross-chain transaction device can be implemented by software, hardware, or a combination of both to form part or all of a computer device, and the computer device can be as follows Fig.10 The computer device shown. The device is applied to the first cross-chain gateway, which is a cross-chain gateway connected to the first application chain. Figure 8 The device includes: a first acquisition module 801, a generation module 802, a second acquisition module 803, and a first sending module 804.

[0176] The first acquisition module 801 is used to acquire the target cross-chain transaction sent by the first application chain system;

[0177] A generation module 802 is used to generate a first hash value, first encrypted data and proof information according to a target cross-chain transaction, wherein the first hash value is obtained by performing a hash operation on the target cross-chain transaction, the first encrypted data is obtained by encrypting the target cross-chain transaction, and the proof information is used to prove that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction;

[0178] The second acquisition module 803 is used to obtain multi-signature information, which includes the signature of each node in the multiple nodes in the first application chain system on the hash value of the target cross-chain transaction. The multi-signature information is used to prove that the first hash value is obtained by processing the target cross-chain transaction from the first application chain system;

[0179] The first sending module 804 is used to send a cross-chain transaction request to the relay chain system. The cross-chain transaction request carries multi-signature information, a first hash value, first encrypted data and proof information. The cross-chain transaction request is used to instruct the relay chain system to send the first encrypted data to the second cross-chain gateway when the multi-signature information and the proof information are verified. The second cross-chain gateway is a cross-chain gateway connected to the second application chain system.

[0180] Optionally, the device further comprises:

[0181] The second sending module is used to send the public key of each of the multiple nodes to the relay chain system, and the public key of each of the multiple nodes is used to verify the multi-signature information.

[0182] Optionally, the generating module 802 is used for:

[0183] Input the target cross-chain transaction into the proof circuit, and the proof circuit outputs the first hash value, the first encrypted data and the proof information;

[0184] The proof circuit includes a hash circuit, a first encryption circuit, and a second encryption circuit. The input data of the hash circuit and the first encryption circuit are the input data of the proof circuit. One input data of the second encryption circuit is the output data of the hash circuit. Another input data of the second encryption circuit is the output data of the first encryption circuit. The output data of the proof circuit is the output data of the hash circuit, the output data of the first encryption circuit, and the output data of the proof circuit.

[0185] The hash circuit is used to perform a hash operation on the input data, the first encryption circuit is used to encrypt the input data, the second encryption circuit is used to generate output data based on the two input data, and the output data of the second encryption circuit is used to prove that the output data of the hash circuit and the output data of the first encryption circuit are obtained by processing the same input data.

[0186] Optionally, the device further comprises:

[0187] The third sending module is used to send verifier information to the relay chain system, and the verifier information is used to verify whether the proof information is generated by the proof circuit.

[0188] Optionally, the generating module 802 is used for:

[0189] In a trusted computing environment, performing a hash operation on the target cross-chain transaction to obtain a first hash value, and encrypting the target cross-chain transaction to obtain first encrypted data;

[0190] In a trusted computing environment, performing a hash operation on the first hash value and the first encrypted data to obtain an information summary;

[0191] In a trusted computing environment, the information summary is encrypted using the private key of the trusted computing environment to obtain a digital signature as proof information.

[0192] Optionally, the first acquisition module 801 is used to:

[0193] Obtain a cross-chain event generated by the first application chain system. The cross-chain event carries a target cross-chain transaction and a target hash value. The target hash value is the hash value of the target cross-chain transaction generated by the first application chain system.

[0194] Optionally, the second acquisition module 803 is used to:

[0195] Sending a request message to each of the multiple nodes, where the request message carries a target hash value, and the request message is used to request the node to sign the target hash value carried in the request message;

[0196] Receive the signature of the target hash value sent by each of the multiple nodes to obtain multi-signature information.

[0197] In an embodiment of the present application, a first hash value, a first encrypted data and a proof information are generated according to the acquired target cross-chain transaction, and the proof information can prove that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction. And multi-signature information is obtained, and the multi-signature information can prove that the first hash value is obtained by processing the cross-chain transaction from the first application chain system. A cross-chain transaction request carrying the first hash value, the first encrypted data, the proof information and the multi-signature information is sent to the relay chain system. After receiving the cross-chain transaction request sent by the first cross-chain gateway, the relay chain system verifies the multi-signature information and the proof information carried in the cross-chain transaction request. If the multi-signature information and the proof information are verified, the relay chain system can determine that the first hash value carried in the cross-chain transaction request is obtained by processing the target cross-chain transaction from the first application chain, and determine that the first hash value and the first encrypted data carried in the cross-chain transaction request are obtained by processing the same cross-chain transaction, thereby determining that the first encrypted data is obtained by processing the target cross-chain transaction from the first application chain, that is, determining that the first encrypted data is authentic, so that the first encrypted data can be sent to the second cross-chain gateway. In an embodiment of the present application, the relay chain system can verify the authenticity of the first encrypted data sent by the first cross-chain gateway to ensure that the cross-chain transaction original text corresponding to the first encrypted data is not maliciously generated or tampered with. Only when the first encrypted data is authentic will the relay chain system send the first encrypted data to the second cross-chain gateway, thereby ensuring the security of cross-chain transactions in privacy transaction scenarios.

[0198] Fig. 9 is a schematic diagram of the structure of a cross-chain transaction device provided in an embodiment of the present application. The cross-chain transaction device can be implemented by software, hardware, or a combination of both to form part or all of a computer device, and the computer device can be as follows Fig.11 The computer device shown. This device is used in the relay chain system. See Fig. 9 The device includes: a first receiving module 901, a verification module 902, and a sending module 903.

[0199] The first receiving module 901 is used to receive a cross-chain transaction request sent by the first cross-chain gateway. The cross-chain transaction request carries multi-signature information, a first hash value, first encrypted data and proof information. The multi-signature information is used to prove that the first hash value is obtained by processing a cross-chain transaction from the first application chain system. The proof information is used to prove that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction. The first cross-chain gateway is a cross-chain gateway connected to the first application chain system.

[0200] Verification module 902, used to verify the multi-signature information and the certification information;

[0201] The sending module 903 is used to send the first encrypted data to the second cross-chain gateway when the multi-signature information and the proof information are verified. The second cross-chain gateway is a cross-chain gateway connected to the second application chain system.

[0202] Optionally, the verification module 902 is used to:

[0203] Decrypt the multi-signature information according to the public key of each of the multiple nodes in the first application chain system;

[0204] If the target hash value is successfully decrypted from the multi-signature information, then if the target hash value is the same as the first hash value, the multi-signature information is determined to have been verified;

[0205] If the decryption of the multi-signature information fails, or if the target hash value is successfully decrypted from the multi-signature information and the target hash value is different from the first hash value, it is determined that the verification of the multi-signature information has failed.

[0206] Optionally, the device further comprises:

[0207] A second receiving module is used to receive the verifier information of the proof circuit sent by the first cross-chain gateway, where the verifier information of the proof circuit is used to verify whether the proof information is generated by the proof circuit;

[0208] The proof circuit includes a hash circuit, a first encryption circuit, and a second encryption circuit. The input data of the hash circuit and the first encryption circuit are the input data of the proof circuit. One input data of the second encryption circuit is the output data of the hash circuit. Another input data of the second encryption circuit is the output data of the first encryption circuit. The output data of the proof circuit is the output data of the hash circuit, the output data of the first encryption circuit, and the output data of the second encryption circuit.

[0209] The hash circuit is used to perform a hash operation on the input data, the first encryption circuit is used to encrypt the input data, the second encryption circuit is used to generate output data based on the two input data, and the output data of the second encryption circuit is used to prove that the output data of the hash circuit and the output data of the first encryption circuit are obtained by processing the same input data.

[0210] Optionally, the verification module 902 is further configured to:

[0211] Decrypting the certification information to obtain a second hash value, second encrypted data, and target verifier information;

[0212] If the target verifier information is the same as the verifier information of the certification circuit, the second hash value is the same as the first hash value, and the second encrypted data is the same as the first encrypted data, determining that the certification information is verified;

[0213] When the target verifier information is different from the verifier information of the certification circuit, and / or the second hash value is different from the first hash value, and / or the second encrypted data is different from the first encrypted data, it is determined that the certification information verification has failed.

[0214] Optionally, the verification module is also used to:

[0215] In the trusted computing environment, decrypt the certification information using the public key of the trusted computing environment to obtain a first information summary;

[0216] In a trusted computing environment, performing a hash operation on the first hash value and the first encrypted data to obtain a second information summary;

[0217] If the first information digest is the same as the second information digest, then it is determined that the certification information has been verified;

[0218] If the first information digest is different from the second information digest, it is determined that the certification information verification has failed.

[0219] In an embodiment of the present application, after receiving the cross-chain transaction request sent by the first cross-chain gateway, the multi-signature information and proof information carried in the cross-chain transaction request are verified. If the multi-signature information and proof information are verified, the relay chain system can determine that the first hash value carried in the cross-chain transaction request is obtained by processing the target cross-chain transaction from the first application chain, and determine that the first hash value and the first encrypted data carried in the cross-chain transaction request are obtained by processing the same cross-chain transaction, thereby determining that the first encrypted data is obtained by processing the target cross-chain transaction from the first application chain, that is, determining that the first encrypted data is authentic, so that the first encrypted data can be sent to the second cross-chain gateway. In an embodiment of the present application, the relay chain system can verify the authenticity of the first encrypted data sent by the first cross-chain gateway to ensure that the cross-chain transaction original corresponding to the first encrypted data is not maliciously generated or tampered with. Only when the first encrypted data is authentic will the relay chain system send the first encrypted data to the second cross-chain gateway, thereby ensuring the security of cross-chain transactions in privacy transaction scenarios.

[0220] It should be noted that: the cross-chain transaction device provided in the above embodiment only uses the division of the above-mentioned functional modules as an example when conducting cross-chain transactions. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.

[0221] The functional units and modules in the above embodiments may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit, and the above integrated units may be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the protection scope of the embodiments of the present application.

[0222] The cross-chain transaction device and the cross-chain transaction method provided in the above embodiments belong to the same concept. The specific working process of the units and modules in the above embodiments and the technical effects brought about can be found in the method embodiment part, which will not be repeated here.

[0223] Fig.10 This is a schematic diagram of the structure of a computer device provided in an embodiment of the present application. Fig.10 As shown, the computer device 10 includes: a processor 100, a memory 101, and a computer program 102 stored in the memory 101 and executable on the processor 100. When the processor 100 executes the computer program 102, the above Figure 6 Steps in the cross-chain transaction method in the embodiment.

[0224] The computer device 10 may be a gateway device. Those skilled in the art will appreciate that Fig.10 This is only an example of the computer device 10 and does not constitute a limitation on the computer device 10. The computer device 10 may include more or fewer components than shown in the figure, or a combination of certain components, or different components, such as input and output devices, network access devices, etc.

[0225] The processor 100 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.

[0226] In some embodiments, the memory 101 may be an internal storage unit of the computer device 10, such as a hard disk or memory of the computer device 10. In other embodiments, the memory 101 may also be an external storage device of the computer device 10, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the computer device 10. Further, the memory 101 may also include both an internal storage unit of the computer device 10 and an external storage device. The memory 101 is used to store an operating system, an application program, a boot loader, data, and other programs. The memory 101 may also be used to temporarily store data that has been output or is to be output.

[0227] Fig.11 This is a schematic diagram of the structure of a computer device provided in an embodiment of the present application. Fig.11 As shown, the computer device 11 includes: a processor 110, a memory 111, and a computer program 112 stored in the memory 111 and executable on the processor 110. When the processor 110 executes the computer program 112, the above Figure 7 Cross-chain transaction method in an embodiment.

[0228] The computer device 11 may be a server cluster with multiple servers, and the server cluster may be a blockchain system. Those skilled in the art will appreciate that Fig.11 This is only an example of the computer device 11 and does not constitute a limitation on the computer device 11. It may include more or fewer components than shown in the figure, or a combination of certain components, or different components, such as input and output devices, network access devices, etc.

[0229] The processor 110 may be a central processing unit, or may be other general-purpose processors, digital signal processors, application-specific integrated circuits, off-the-shelf programmable gate arrays or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.

[0230] In some embodiments, the memory 111 may be an internal storage unit of the computer device 11, such as a hard disk or memory of the computer device 11. In other embodiments, the memory 111 may also be an external storage device of the computer device 11, such as a plug-in hard disk, a smart memory card, a secure digital card, a flash memory card, etc. equipped on the computer device 11. Further, the memory 111 may also include both an internal storage unit of the computer device 11 and an external storage device. The memory 111 is used to store an operating system, an application program, a boot loader, data, and other programs. The memory 111 may also be used to temporarily store data that has been output or is to be output.

[0231] An embodiment of the present application also provides a computer device, which includes: at least one processor, a memory, and a computer program stored in the memory and executable on the at least one processor, and when the processor executes the computer program, the steps in any of the above-mentioned method embodiments are implemented.

[0232] An embodiment of the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments can be implemented.

[0233] An embodiment of the present application provides a computer program product, which, when executed on a computer, enables the computer to execute the steps in the above-mentioned method embodiments.

[0234] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the processes in the above method embodiments, which can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by the processor, the steps of the above method embodiments can be implemented. Among them, the computer program includes computer program code, which can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may at least include: any entity or device that can carry the computer program code to the camera / terminal device, recording medium, computer memory, ROM (Read-Only Memory), RAM (Random Access Memory), CD-ROM (Compact Disc Read-Only Memory), magnetic tape, floppy disk and optical data storage device. The computer-readable storage medium mentioned in the present application can be a non-volatile storage medium, in other words, it can be a non-transient storage medium.

[0235] It should be understood that all or part of the steps to implement the above embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. The computer instructions can be stored in the above-mentioned computer readable storage medium.

[0236] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0237] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0238] In the embodiments provided in the present application, it should be understood that the disclosed devices / computer equipment and methods can be implemented in other ways. For example, the device / computer equipment embodiments described above are only schematic, for example, the division of modules or units is only a logical function division, and there may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0239] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0240] The embodiments described above are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, a person skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.

Claims

1. A cross-chain transaction method, It is characterized in that Applied to a first cross-chain gateway, the first cross-chain gateway is a cross-chain gateway connected to a first application chain system, and the method includes: Obtain the target cross-chain transaction sent by the first application chain system; Generate a first hash value, first encrypted data, and proof information according to the target cross-chain transaction, wherein the first hash value is obtained by performing a hash operation on the target cross-chain transaction, the first encrypted data is obtained by encrypting the target cross-chain transaction, and the proof information is used to prove that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction; Obtain multi-signature information, where the multi-signature information includes the signature of each of the multiple nodes in the first application chain system on the hash value of the target cross-chain transaction, and the multi-signature information is used to prove that the first hash value is obtained by processing the target cross-chain transaction from the first application chain system; A cross-chain transaction request is sent to the relay chain system, wherein the cross-chain transaction request carries the multi-signature information, the first hash value, the first encrypted data and the proof information. The cross-chain transaction request is used to instruct the relay chain system to send the first encrypted data to the second cross-chain gateway when the multi-signature information and the proof information are verified. The second cross-chain gateway is a cross-chain gateway connected to the second application chain system.

2. The method according to claim 1, It is characterized in that Before obtaining the target cross-chain transaction sent by the first application chain system, the method further includes: The public key of each of the multiple nodes is sent to the relay chain system, and the public key of each of the multiple nodes is used to verify the multi-signature information.

3. The method according to claim 1 or 2, It is characterized in that The generating a first hash value, first encrypted data, and proof information according to the target cross-chain transaction includes: Input the target cross-chain transaction into a proof circuit, and the proof circuit outputs the first hash value, the first encrypted data, and the proof information; The proof circuit includes a hash circuit, a first encryption circuit, and a second encryption circuit; the input data of the hash circuit and the first encryption circuit are the input data of the proof circuit; one input data of the second encryption circuit is the output data of the hash circuit; another input data of the second encryption circuit is the output data of the first encryption circuit; and the output data of the proof circuit is the output data of the hash circuit, the output data of the first encryption circuit, and the output data of the second encryption circuit; The hash circuit is used to perform a hash operation on the input data, the first encryption circuit is used to encrypt the input data, the second encryption circuit is used to generate output data based on the two input data, and the output data of the second encryption circuit is used to prove that the output data of the hash circuit and the output data of the first encryption circuit are obtained by processing the same input data.

4. The method according to claim 3, It is characterized in that The second encryption circuit is used to generate output data based on two input data and verifier information of the certification circuit; Before obtaining the target cross-chain transaction sent by the first application chain system, the method further includes: The verifier information is sent to the relay chain system, where the verifier information is used to verify whether the proof information is generated by the proof circuit.

5. The method according to claim 1 or 2, It is characterized in that The generating a first hash value, first encrypted data, and proof information according to the target cross-chain transaction includes: In a trusted computing environment, performing a hash operation on the target cross-chain transaction to obtain the first hash value, and encrypting the target cross-chain transaction to obtain the first encrypted data; In the trusted computing environment, performing a hash operation on the first hash value and the first encrypted data to obtain an information summary; In the trusted computing environment, the information summary is encrypted using the private key of the trusted computing environment to obtain a digital signature as the certification information.

6. The method according to claim 1 or 2, It is characterized in that The obtaining of the target cross-chain transaction sent by the first application chain system includes: Obtain a cross-chain event generated by the first application chain system, wherein the cross-chain event carries the target cross-chain transaction and the target hash value, and the target hash value is the hash value of the target cross-chain transaction generated by the first application chain system; The obtaining of multi-signature information includes: Sending a request message to each of the multiple nodes, where the request message carries the target hash value, and the request message is used to request the node to sign the target hash value carried by the request message; Receive a signature for the target hash value sent by each of the multiple nodes to obtain the multi-signature information.

7. A cross-chain transaction method, It is characterized in that Applied to a relay chain system, the method includes: Receive a cross-chain transaction request sent by a first cross-chain gateway, the cross-chain transaction request carrying multi-signature information, a first hash value, first encrypted data, and proof information, the multi-signature information is used to prove that the first hash value is obtained by processing a cross-chain transaction from a first application chain system, the proof information is used to prove that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction, and the first cross-chain gateway is a cross-chain gateway connected to the first application chain system; Verify the multi-signature information and the certification information, wherein the multi-signature information includes a signature of each of the multiple nodes in the first application chain system on the hash value of the target cross-chain transaction; When both the multi-signature information and the proof information are verified, the first encrypted data is sent to the second cross-chain gateway, where the second cross-chain gateway is a cross-chain gateway connected to the second application chain system.

8. The method according to claim 7, It is characterized in that The verifying of the multi-signature information includes: Decrypting the multi-signature information according to the public key of each of the multiple nodes in the first application chain system; If the target hash value is successfully decrypted from the multi-signature information, then if the target hash value is the same as the first hash value, it is determined that the multi-signature information has been verified; If the decryption of the multi-signature information fails, or if the target hash value is successfully decrypted from the multi-signature information and the target hash value is different from the first hash value, it is determined that the verification of the multi-signature information has failed.

9. The method according to claim 7 or 8, It is characterized in that Before receiving the cross-chain transaction request sent by the first cross-chain gateway, the method further includes: Receiving verifier information of the proof circuit sent by the first cross-chain gateway, where the verifier information of the proof circuit is used to verify whether the proof information is generated by the proof circuit; The proof circuit includes a hash circuit, a first encryption circuit, and a second encryption circuit; the input data of the hash circuit and the first encryption circuit are the input data of the proof circuit; one input data of the second encryption circuit is the output data of the hash circuit; another input data of the second encryption circuit is the output data of the first encryption circuit; and the output data of the proof circuit is the output data of the hash circuit, the output data of the first encryption circuit, and the output data of the second encryption circuit; The hash circuit is used to perform a hash operation on the input data, the first encryption circuit is used to encrypt the input data, the second encryption circuit is used to generate output data based on the two input data, and the output data of the second encryption circuit is used to prove that the output data of the hash circuit and the output data of the first encryption circuit are obtained by processing the same input data.

10. The method according to claim 9, It is characterized in that The verifying of the certification information includes: Decrypting the certification information to obtain a second hash value, second encrypted data, and target verifier information; If the target verifier information is identical to the verifier information of the certification circuit, the second hash value is identical to the first hash value, and the second encrypted data is identical to the first encrypted data, determining that the certification information verification is passed; When the target verifier information is different from the verifier information of the certification circuit, and / or the second hash value is different from the first hash value, and / or the second encrypted data is different from the first encrypted data, it is determined that the certification information verification has failed.

11. The method according to claim 7 or 8, It is characterized in that The verifying of the certification information includes: In a trusted computing environment, decrypting the certification information using a public key of the trusted computing environment to obtain a first information summary; In the trusted computing environment, performing a hash operation on the first hash value and the first encrypted data to obtain a second information summary; If the first information digest is the same as the second information digest, it is determined that the certification information has been verified; If the first information digest is different from the second information digest, it is determined that the certification information verification has failed.

12. A cross-chain transaction method, It is characterized in that The method comprises: The first cross-chain gateway obtains the target cross-chain transaction sent by the first application chain system; The first cross-chain gateway generates a first hash value, first encrypted data and proof information according to the target cross-chain transaction, wherein the first hash value is obtained by performing a hash operation on the target cross-chain transaction, the first encrypted data is obtained by encrypting the target cross-chain transaction, and the proof information is used to prove that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction; The first cross-chain gateway obtains multi-signature information, where the multi-signature information includes a signature of each of the multiple nodes in the first application chain system on the hash value of the target cross-chain transaction, and the multi-signature information is used to prove that the first hash value is obtained by processing the target cross-chain transaction from the first application chain system; The first cross-chain gateway sends a cross-chain transaction request to the relay chain system, where the cross-chain transaction request carries the multi-signature information, the first hash value, the first encrypted data, and the proof information; After receiving the cross-chain transaction request sent by the first cross-chain gateway, the relay chain system verifies the multi-signature information and the proof information; When both the multi-signature information and the proof information are verified, the relay chain system sends the first encrypted data to the second cross-chain gateway, where the second cross-chain gateway is a cross-chain gateway connected to the second application chain system.

13. A cross-chain transaction device, It is characterized in that Applied to a first cross-chain gateway, the first cross-chain gateway is a cross-chain gateway connected to a first application chain system, and the device includes: A first acquisition module, used to acquire a target cross-chain transaction sent by the first application chain system; A generation module, configured to generate a first hash value, first encrypted data, and proof information according to the target cross-chain transaction, wherein the first hash value is obtained by performing a hash operation on the target cross-chain transaction, the first encrypted data is obtained by encrypting the target cross-chain transaction, and the proof information is used to prove that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction; A second acquisition module is used to obtain multi-signature information, wherein the multi-signature information includes a signature of each of the multiple nodes in the first application chain system on the hash value of the target cross-chain transaction, and the multi-signature information is used to prove that the first hash value is obtained by processing the target cross-chain transaction from the first application chain system; The first sending module is used to send a cross-chain transaction request to the relay chain system, wherein the cross-chain transaction request carries the multi-signature information, the first hash value, the first encrypted data and the proof information. The cross-chain transaction request is used to instruct the relay chain system to send the first encrypted data to the second cross-chain gateway when the multi-signature information and the proof information are verified. The second cross-chain gateway is a cross-chain gateway connected to the second application chain system.

14. A cross-chain transaction device, It is characterized in that Applied to a relay chain system, the device comprises: A first receiving module is used to receive a cross-chain transaction request sent by a first cross-chain gateway, wherein the cross-chain transaction request carries multi-signature information, a first hash value, first encrypted data, and proof information, wherein the multi-signature information is used to prove that the first hash value is obtained by processing a cross-chain transaction from a first application chain system, and the proof information is used to prove that the first hash value and the first encrypted data are obtained by processing the same cross-chain transaction, and the first cross-chain gateway is a cross-chain gateway connected to the first application chain system, and the multi-signature information includes a signature of each of the multiple nodes in the first application chain system on the hash value of the target cross-chain transaction; A verification module, used to verify the multi-signature information and the certification information; The sending module is used to send the first encrypted data to the second cross-chain gateway when the multi-signature information and the proof information are verified, and the second cross-chain gateway is a cross-chain gateway connected to the second application chain system.

15. A computer device, It is characterized in that The computer device comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program implements the method according to any one of claims 1 to 11 when executed by the processor.

16. A computer-readable storage medium, It is characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 11 is implemented.

Citation Information

Patent Citations

  • Cross-chain transaction method, system and device, equipment and storage medium

    CN112446785A

  • Cross-chain transaction verification method, relay chain node device and medium

    CN112532393A