A Fabric data privacy protection method based on trusted execution environment
By transferring the transaction simulation execution process of the endorsement node to a trusted execution environment and encrypting the data using symmetric keys, the problem of lack of supervision and cryptographic technology performance overhead of public chains is solved, and the entire process privacy protection of Fabric transaction data and high system availability is achieved.
Patent Information
- Application Number
- CN202211274486.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-18
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2042-10-18
AI Technical Summary
The lack of regulatory mechanisms for public chains leads to malicious nodes that may commit violations and evade responsibilities. The existing cryptography technology is expensive when used for data privacy protection, reducing the throughput and availability of blockchain systems.
By transferring the transaction simulation execution process of the endorsement node to a trusted execution environment, and encrypting the input and output data of the transaction using the symmetric key generated by the trusted execution environment, data privacy protection is achieved while ensuring the correct execution of the contract.
It realizes the privacy protection of input and output data during the transaction process and intermediate data during the contract execution process, ensures the privacy of the entire process of Fabric transaction data, and improves the availability and throughput of the system.
Smart Images

Figure CN115664749B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a protection method, and in particular to a data privacy protection method based on a trusted execution environment Fabric, which belongs to the technical field of blockchain smart contract privacy protection. Background Art
[0002] Blockchain can be divided into public chain, consortium chain and private chain according to the degree of openness. Among them, nodes in the public chain have the right to join and exit the blockchain network at any time, and there is no identity access mechanism. Because the public chain overemphasizes decentralization, there is no third-party regulatory agency in actual operation, so there is a lack of reasonable supervision. This allows malicious nodes to commit violations and evade due responsibilities. In addition, malicious nodes can also attack the blockchain system, and a successful attack will cause irreversible losses.
[17] . Therefore, public chains without regulatory functions are not suitable for current social development, and appropriate regulatory and auditing mechanisms should be added to effectively prevent or trace illegal activities in the system. Consortium chain refers to a blockchain system composed of multiple entities. The nodes on the chain have corresponding real organizations, which jointly maintain the healthy operation of the blockchain system. Unlike the public chain, the identity authentication mechanism of the consortium chain allows only authenticated users to join the network. In addition, the number of nodes on the consortium chain is limited, which can effectively control the size of the blockchain system and improve the credibility of the node identity. The main representatives are R3 Corda, Hyperledger Fabric, etc. Among them, Fabric, as a typical representative of consortium chain, has been widely used by enterprises. Therefore, studying the privacy protection scheme that balances privacy and regulation in Fabric is a direction with great significance and broad application prospects, which meets the actual needs of current social development.
[0003] In terms of data privacy protection in blockchain, cryptographic techniques are usually used to encrypt and protect private data, such as asymmetric encryption, zero-knowledge proof, homomorphic encryption, secure multi-party computing, etc. These technologies can complete the calculation of private data and the verification of calculation results without exposing private data. Because the private data is encrypted in plain text and uploaded to the blockchain through cryptography, observers cannot access the transaction content or obtain the plain text information of the transaction content. However, using cryptographic techniques to process private data usually brings a lot of performance overhead, thereby reducing the availability of the overall system. Large blockchain systems have certain requirements for transaction throughput. Excessive performance overhead may reduce the throughput of the system, thereby hindering the further development of blockchain systems (for example, zk-SNARK verification in Ethereum smart contracts requires more than 300 gas). In addition, some cryptographic techniques such as secure multi-party computing require frequent communication between multiple parties, and interaction on the blockchain system is a very expensive operation. This is because broadcasting information, contract status changes, block confirmation, etc. require a lot of on-chain interactions, resulting in secure multi-party computing methods usually causing large time overhead and gas consumption. Therefore, a new solution is urgently needed to solve the above technical problems. Summary of the invention
[0004] The present invention is aimed at the problems existing in the prior art, and provides a data privacy protection method based on a trusted execution environment. In this technical method, by transferring the transaction simulation execution process of the endorsement node to the trusted execution environment, and using the symmetric key generated by the trusted execution environment to encrypt the input and output data of the transaction, the privacy protection of the input and output data in the transaction process and the intermediate data in the contract execution process is achieved, and the correct execution of the contract can be guaranteed. This solution proposes to simulate the execution of smart contracts based on a trusted execution environment, which can ensure the privacy of the entire process of Fabric transaction data and the availability of the trusted execution environment, and solves the problems of transaction data privacy leakage caused by untrustworthy endorsement nodes and endorsement process interruption caused by poor availability of the trusted execution environment in previous solutions.
[0005] In order to achieve the above purpose, the technical solution of the present invention is as follows: a Fabric data privacy protection method based on a trusted execution environment (TEE), the method includes three nodes: user node, endorsement node and sorting service, a cluster: TEE cluster, a contract: TEE contract, and three steps: TEE key generation based on transaction information, transaction proposal simulation execution based on TEE, and node status synchronization. The details are as follows:
[0006] Three types of nodes:
[0007] 1) User node, client: can interact with the TEE contract to send the hash value of transaction data or obtain the transaction key; can initiate a transaction simulation execution request to the endorsement node, the request contains encrypted transaction information and the hash value of transaction data; can send transaction results and endorsement information to the sorting service node;
[0008] 2) Endorsement node, endorse_peer: sends transaction information to the TEE cluster and endorses the execution results of the TEE cluster;
[0009] 3) Ordering service: ordering_service: Verifies the endorsement of transaction results and broadcasts the verified transaction results.
[0010] A cluster:
[0011] TEE cluster, cluster_tee: A cluster containing at least 3 TEE nodes that can execute transactions in TEE;
[0012] A smart contract:
[0013] TEE contract, contract_tee: records the hash value of transactions that require privacy protection.
[0014] Three steps:
[0015] Step 1 TEE key generation based on transaction information: The user node client records the hash value hash_txData of the transaction data and the user public key publicKey through the TEE contract contract_tee. The TEE cluster cluster_tee selects an idle TEE node, generates the session key sessionKey_tee according to the hash value hash_txData of the transaction data at the TEE contract_tee, and encrypts the session key encryptedKey_tee using the user node publicKey. The user node client obtains the session key ciphertext encryptedKey_tee from the TEE contract contract_tee according to the hash value hash_txData of the transaction data. The TEEs in the TEE cluster cluster_tee use a symmetric key exchange algorithm to generate the conference key session_key for the secure transmission of the session key sessionKey_tee.
[0016] Step 2: Simulate the execution of transaction proposal based on TEE: After the user node client decrypts and obtains the session key sessionKey_tee, it uses the key to encrypt the transaction input data data_txInput. The endorsement node endorse_peer sends the transaction data that needs to be private and its corresponding contract bytecode bytecode_contract to the TEE cluster cluster_tee. The TEE cluster cluster_tee selects 3 idle TEE nodes to execute the transaction. The TEE node returns the execution result result and signature signature to the endorsement node endorse_peer. The endorsement node endorse_peer verifies the result returned by the TEE cluster cluster_tee and the identity of the TEE node. After the verification is passed, it endorses the calculation result result.
[0017] Step 3 Node status synchronization: The user node client verifies the endorsement result of the endorsement node endorse_peer, and sends the calculation result result after verification to the ordering service ordering_service. The ordering service ordering_service verifies the calculation result result, and broadcasts the transaction calculation result result after verification.
[0018] As an improvement of the present invention, Step 1 generates TEE key based on transaction information, and generates a symmetric key in TEE according to the user's transaction information, as follows:
[0019] Step 1.1: The user node client in the Fabric network generates the hash value of the transaction data hash_txData based on the transaction input data data_txInput. The client submits the hash value of the transaction data to the TEE contract contract_tee by calling the contract. The TEE contract needs to record the hash value of the transaction data hash_txData and its corresponding session key ciphertext encryptedKey_tee.
[0020] Step 1.2: After a block time time_block, the TEE cluster cluster_tee obtains the transaction information that needs privacy protection from the TEE contract contract_tee, and selects an idle TEE node tee_keyGeneration in the cluster to generate a session key sessionKey_tee for it. After completing the key generation, the TEE node tee_keyGeneration will broadcast the transaction-related session key sessionKey_tee in the cluster through local attestation to ensure that all TEE nodes have the conditions to execute the transaction. At the same time, the user node public key publicKey is used to encrypt the session key sessionKey_tee to obtain the session key ciphertext encryptedKey_tee, and the session key ciphertext encryptedKey_tee corresponding to the transaction is recorded in the TEE contract contract_tee by calling the contract.
[0021] Among them, the TEE cluster contains a leading TEE node tee_leader, which is responsible for interacting with other nodes or contracts outside the cluster, such as obtaining transaction information of the TEE contract contract_tee, etc. In order to ensure that the TEE nodes in the cluster are legal and available, all TEE nodes need to send their own public key public_key and information summary information_abstract to the leading TEE node tee_leader before joining the cluster. The leading TEE node tee_leader obtains the legitimacy certificate of the TEE node from the certification center (certificate_authority) through remote attestation to ensure the legitimacy of the TEE node, and at the same time determines whether the TEE node is available through the heartbeat keep_alive method. This method means that every 10 block times time_block, the TEE node needs to send survival information to the leading TEE node tee_leader to prove its availability. In addition, the TEE node will store relevant information about the execution of transactions, such as the hash value hash_txData of the transaction input data, and record the number of executions of the corresponding transaction to prevent attacks from obtaining private data through replay attack analysis.
[0022] Step 1.3: After 3 block times time_block, the user node client obtains the session key sessionKey_tee corresponding to the transaction from the TEE contract contract_tee.
[0023] As an improvement of the present invention, Step 2 simulates the execution of the transaction proposal based on TEE, and transfers the process of simulating the execution of the smart contract by the endorsement node in Fabric to the TEE node in the TEE cluster, as follows:
[0024] Step 2.1: The user node client uses the session key sessionKey_tee to encrypt the transaction input data data_txInput and the random number number_random to generate the transaction input data ciphertext encryptedData_txInput. The user node sends the transaction input data ciphertext encryptedData_txInput to the corresponding endorsement node endorse_peer according to the endorsement policy of the called smart contract.
[0025] Step 2.2: The endorsement node endorse_peer sends the transaction data that needs to be privacy protected and the corresponding contract bytecode bytecode_contract to the TEE cluster cluster_tee. The leading TEE node tee_leader has the state table table_teeState of each TEE node. Three idle TEE nodes are selected from them, and the transaction input data ciphertext encryptedData_txInput and the corresponding contract bytecode bytecode_contract are sent to these three TEE nodes. The TEE node uses the local session key sessionKey_tee to decrypt the transaction input data ciphertext encryptedData_txInput to obtain the transaction input data plaintext data_txInput, and then executes the contract bytecode bytecode_contract to obtain the transaction calculation result result. The TEE node performs a hash operation on the calculation result result to obtain the hash value hash_result of the calculation result, and then uses the session key sessionKey_tee to encrypt the calculation result result and the random number number_random to obtain the transaction output data ciphertext encryptedData_txOutput.
[0026] Among them, the data of the endorsement request initiated by the user node client to the endorsement node endorse_peer includes the status of the transaction input data. The endorsement node endorse_peer determines whether it is necessary to simulate the execution of the transaction locally based on the status of the transaction input data. In addition, the endorsement node endorse_peer here usually contains multiple endorsements. This is because when a single endorsement node is used, the endorsement process may fail due to a DOS attack. Therefore, the leading TEE node tee_leader will only start execution after receiving the calculation request from 1 / 2 of the number of endorsement nodes in the endorsement policy.
[0027] Step 2.3: The leading TEE node tee_leader returns the transaction calculation result result to the endorsement node endorse_peer that initiated the calculation request. The transaction calculation result result needs to satisfy the calculation results of at least two TEE nodes, otherwise the endorsement node endorse_peer considers the endorsement failed. The endorsement node endorses the verified calculation result result and returns the endorsement result endorsement to the user node client.
[0028] As an improvement of the present invention, Step 3 node status synchronization is as follows:
[0029] Step 3.1: The client node determines whether 1 / 2 of the endorsing nodes have completed the endorsement process based on the endorsement policy, and then verifies the data returned by different endorsing nodes.
[0030] Among them, the user node client decrypts the encrypted data output encryptedData_txOutput to obtain the calculation result result, performs a hash operation on it and compares it with the hash value hash_result of the calculation result, and determines whether the random number number_random changes. This step determines whether the smart contract is executed correctly;
[0031] Step 3.2: The ordering service ordering_service verifies the endorsement of the calculation result result to determine whether it satisfies the endorsement policy that 1 / 2 of the number of endorsement nodes complete the endorsement. After the verification is passed, the transaction calculation result result is broadcasted. After obtaining the transaction in the block, the node will write the transaction data into the local ledger.
[0032] Compared with the prior art, the present invention has the following advantages: 1) The technical solution protects the privacy and credibility of data during the interaction between the blockchain and the TEE environment. By using a symmetric key to encrypt the transaction privacy data to ensure the privacy of the data during the interaction, a smart contract is deployed on the blockchain to record the transaction data to ensure the credibility of the interaction data. Although Fabric's existing channel mechanism and private data collection mechanism provide a certain degree of data privacy protection, the transaction data is still visible to the endorsement node. Since the honesty of the endorsement node cannot be guaranteed, the simulated execution of the transaction directly on the endorsement node locally has the risk of data privacy leakage. Therefore, transferring the simulated execution process to the TEE under the chain can effectively solve this problem. 2) The technology ensures the availability of the endorsement node and the TEE node during the transaction endorsement process. Since the attacker can launch a DOS attack on the endorsement node or the TEE node, the relevant node is unavailable during the endorsement process, thereby blocking or interrupting the endorsement process. This method ensures the availability of the node during the transaction endorsement process through the redundancy of the endorsement node and the TEE node. 3) The technology ensures that the attacker cannot analyze and obtain the data inside the TEE. Since attackers can repeatedly execute a transaction through replay attacks to analyze the private data inside the TEE. This method records all transactions to ensure that transactions cannot be executed repeatedly, thereby protecting the security of private data inside the TEE. 4) This technology can provide privacy protection for smart contracts that have been deployed on the Fabric alliance chain. Other privacy protection methods for Fabric require initializing relevant keys for smart contracts at the beginning of smart contract construction, and storing key information in a sealed form outside the trusted execution environment. This form cannot solve the privacy protection needs of existing smart contracts. Secondly, the act of sealing and storing key information also increases the risk of privacy leakage. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 It is a schematic diagram of the overall framework of the present invention. DETAILED DESCRIPTION
[0034] In order to deepen the understanding of the present invention, the present embodiment is described in detail below with reference to the accompanying drawings.
[0035] Example 1: See Figure 1 , a Fabric data privacy protection method based on a trusted execution environment (TEE), the method includes three nodes: user nodes, endorsement nodes and sorting services, a cluster: TEE cluster, a contract: TEE contract, and three steps: TEE key generation based on transaction information, TEE-based transaction proposal simulation execution and node status synchronization, as follows:
[0036] Three types of nodes:
[0037] 1) User node, client: can interact with the TEE contract to send the hash value of transaction data or obtain the transaction key; can initiate a transaction simulation execution request to the endorsement node, the request contains encrypted transaction information and the hash value of transaction data; can send transaction results and endorsement information to the sorting service node;
[0038] 2) Endorsement node, endorse_peer: sends transaction information to the TEE cluster and endorses the execution results of the TEE cluster;
[0039] 3) Ordering service: ordering_service: Verifies the endorsement of transaction results and broadcasts the verified transaction results.
[0040] A cluster:
[0041] TEE cluster, cluster_tee: A cluster containing at least 3 TEE nodes that can execute transactions in TEE;
[0042] A smart contract:
[0043] TEE contract, contract_tee: records the hash value of transactions that require privacy protection.
[0044] Three steps:
[0045] Step 1 TEE key generation based on transaction information: The user node client records the hash value hash_txData of the transaction data and the user public key publicKey through the TEE contract contract_tee. The TEE cluster cluster_tee selects an idle TEE node, generates the session key sessionKey_tee according to the hash value hash_txData of the transaction data at the TEE contract_tee, and encrypts the session key encryptedKey_tee using the user node publicKey. The user node client obtains the session key ciphertext encryptedKey_tee from the TEE contract contract_tee according to the hash value hash_txData of the transaction data. The TEEs in the TEE cluster cluster_tee use a symmetric key exchange algorithm to generate the conference key session_key for the secure transmission of the session key sessionKey_tee.
[0046] Step 2: Simulate the execution of transaction proposal based on TEE: After the user node client decrypts and obtains the session key sessionKey_tee, it uses the key to encrypt the transaction input data data_txInput. The endorsement node endorse_peer sends the transaction data that needs to be private and its corresponding contract bytecode bytecode_contract to the TEE cluster cluster_tee. The TEE cluster cluster_tee selects 3 idle TEE nodes to execute the transaction. The TEE node returns the execution result result and signature signature to the endorsement node endorse_peer. The endorsement node endorse_peer verifies the result returned by the TEE cluster cluster_tee and the identity of the TEE node. After the verification is passed, it endorses the calculation result result.
[0047] Step 3 Node status synchronization: The user node client verifies the endorsement result of the endorsement node endorse_peer, and sends the calculation result result after verification to the ordering service ordering_service. The ordering service ordering_service verifies the calculation result result, and broadcasts the transaction calculation result result after verification.
[0048] Among them, Step 1 generates TEE keys based on transaction information, and generates a symmetric key in TEE according to the user's transaction information, as follows:
[0049] Step 1.1: The user node client in the Fabric network generates the hash value of the transaction data hash_txData based on the transaction input data data_txInput. The client submits the hash value of the transaction data to the TEE contract contract_tee by calling the contract. The TEE contract needs to record the hash value of the transaction data hash_txData and its corresponding session key ciphertext encryptedKey_tee.
[0050] Step 1.2: After a block time time_block, the TEE cluster cluster_tee obtains the transaction information that needs privacy protection from the TEE contract contract_tee, and selects an idle TEE node tee_keyGeneration in the cluster to generate a session key sessionKey_tee for it. After completing the key generation, the TEE node tee_keyGeneration will broadcast the transaction-related session key sessionKey_tee in the cluster through local attestation to ensure that all TEE nodes have the conditions to execute the transaction. At the same time, the user node public key publicKey is used to encrypt the session key sessionKey_tee to obtain the session key ciphertext encryptedKey_tee, and the session key ciphertext encryptedKey_tee corresponding to the transaction is recorded in the TEE contract contract_tee by calling the contract.
[0051] Among them, the TEE cluster contains a leading TEE node tee_leader, which is responsible for interacting with other nodes or contracts outside the cluster, such as obtaining transaction information of the TEE contract contract_tee, etc. In order to ensure that the TEE nodes in the cluster are legal and available, all TEE nodes need to send their own public key public_key and information summary information_abstract to the leading TEE node tee_leader before joining the cluster. The leading TEE node tee_leader obtains the legitimacy certificate of the TEE node from the certification center (certificate_authority) through remote attestation to ensure the legitimacy of the TEE node, and at the same time determines whether the TEE node is available through the heartbeat keep_alive method. This method means that every 10 block times time_block, the TEE node needs to send survival information to the leading TEE node tee_leader to prove its availability. In addition, the TEE node will store relevant information about the execution of transactions, such as the hash value hash_txData of the transaction input data, and record the number of executions of the corresponding transaction to prevent attacks from obtaining private data through replay attack analysis.
[0052] Step 1.3: After 3 block times time_block, the user node client obtains the session key sessionKey_tee corresponding to the transaction from the TEE contract contract_tee.
[0053] Among them, Step 2 simulates the execution of TEE's transaction proposal, transferring the process of simulating the execution of smart contracts by the endorsement node in Fabric to the TEE node in the TEE cluster, as follows:
[0054] Step 2.1: The user node client uses the session key sessionKey_tee to encrypt the transaction input data data_txInput and the random number number_random to generate the transaction input data ciphertext encryptedData_txInput. The user node sends the transaction input data ciphertext encryptedData_txInput to the corresponding endorsement node endorse_peer according to the endorsement policy of the called smart contract.
[0055] Step 2.2: The endorsement node endorse_peer sends the transaction data that needs to be privacy protected and the corresponding contract bytecode bytecode_contract to the TEE cluster cluster_tee. The leading TEE node tee_leader has the state table table_teeState of each TEE node. Three idle TEE nodes are selected from them, and the transaction input data ciphertext encryptedData_txInput and the corresponding contract bytecode bytecode_contract are sent to these three TEE nodes. The TEE node uses the local session key sessionKey_tee to decrypt the transaction input data ciphertext encryptedData_txInput to obtain the transaction input data plaintext data_txInput, and then executes the contract bytecode bytecode_contract to obtain the transaction calculation result result. The TEE node performs a hash operation on the calculation result result to obtain the hash value hash_result of the calculation result, and then uses the session key sessionKey_tee to encrypt the calculation result result and the random number number_random to obtain the transaction output data ciphertext encryptedData_txOutput.
[0056] Among them, the data of the endorsement request initiated by the user node client to the endorsement node endorse_peer includes the status of the transaction input data. The endorsement node endorse_peer determines whether it is necessary to simulate the execution of the transaction locally based on the status of the transaction input data. In addition, the endorsement node endorse_peer here usually contains multiple endorsements. This is because when a single endorsement node is used, the endorsement process may fail due to a DOS attack. Therefore, the leading TEE node tee_leader will only start execution after receiving the calculation request from 1 / 2 of the number of endorsement nodes in the endorsement policy.
[0057] Step 2.3: The leading TEE node tee_leader returns the transaction calculation result result to the endorsement node endorse_peer that initiated the calculation request. The transaction calculation result result needs to satisfy the calculation results of at least two TEE nodes, otherwise the endorsement node endorse_peer considers the endorsement failed. The endorsement node endorses the verified calculation result result and returns the endorsement result endorsement to the user node client.
[0058] Among them, Step 3 node status synchronization is as follows:
[0059] Step 3.1: The user node client determines whether 1 / 2 of the endorsing nodes have completed the endorsement process based on the endorsement policy, and then verifies the data returned by different endorsing nodes.
[0060] Among them, the user node client decrypts the encrypted data of the transaction output encryptedData_txOutput to obtain the calculation result result, performs a hash operation on it and compares it with the hash value of the calculation result hash_result, and determines whether the random number number_random changes. This step determines whether the smart contract is executed correctly.
[0061] Step 3.2: The ordering service ordering_service verifies the endorsement of the calculation result result to determine whether it satisfies the endorsement policy that 1 / 2 of the number of endorsement nodes complete the endorsement. After the verification is passed, the transaction calculation result result is broadcasted. After obtaining the transaction in the block, the node will write the transaction data into the local ledger.
[0062] Example 2: Reference Figure 1For the convenience of description, it is assumed that there is a simplified application example as follows: a Fabric data privacy protection method based on a trusted execution environment, the method includes three steps: TEE key generation based on transaction information, TEE-based transaction proposal simulation execution, and node status synchronization. The details are as follows:
[0063] TEE key generation based on transaction information:
[0064] The hash value of the transaction input data is: 157bbeed38aee8e24cb9b44422606e74
[0065] The session key generated by the TEE cluster cluster_tee for the transaction is:
[0066] cuY1Zd1eNKaQMSJmrOZU6MK8ScUAmIQiYqK8WtqIRJjiOyaMQHB3cZQfYaw32r37 TEE-based transaction proposal simulation execution:
[0067] The user node encrypts the transaction input data to obtain the ciphertext:
[0068] U2FsdGVkX1 / soOv+CKtHWUPXQ0f / bdST5NPKrKZxAtw=
[0069] Hash value of random number:
[0070] U2FsdGVkX1 / KN7hckx0go+VI4C4VL82g32ug0R2dr5c=
[0071] The smart contract code executed by the TEE node is:
[0072]
[0073] The ciphertext of the TEE node execution result is:
[0074] Fe6aOJxmmNrDf6T9vOyNhgJbJMbluvFGvisuVgOASG4=
[0075] The signature of the endorsing node is:
[0076] wiN8951GTcWs3tuHiJpsQHjpEcKNALQE7KzHvELLD4O7P0G0DDd00euOBH3YWFH44PBqb0hnTrVoY2VxsGsEMD p1vkKeJA+oamdtvINnu9X2gGxmSc+DKz8lLBVHOhJQEfrbjzla2qORDOXATeg0z9I / 7hcs4mL6hthArnNCzKI=
[0077] Node status synchronization:
[0078] The user node client verifies the signature of the endorsing node received, and also verifies the hash value of the random number. After the verification, the signature of the endorsing node and the transaction result are sent to the sorting service. After the sorting service passes the verification, it broadcasts it in the pipeline. Other user nodes client_other update the local status database according to the transaction results.
[0079] It should be noted that the above embodiments are not intended to limit the protection scope of the present invention, and equivalent changes or substitutions made on the basis of the above technical solutions all fall within the protection scope of the claims of the present invention.
Claims
1. A Fabric data privacy protection method based on a trusted execution environment, It is characterized in that The method comprises the following steps: The method includes three types of nodes: user nodes, endorsement nodes and sorting services, one cluster: TEE cluster, one contract: TEE contract, and three steps: TEE key generation based on transaction information, TEE-based transaction proposal simulation execution, and node status synchronization, as follows: Three types of nodes: 1) User node, client: can interact with the TEE contract to send the hash value of transaction data or obtain the transaction key; can initiate a transaction simulation execution request to the endorsement node, the request contains encrypted transaction information and the hash value of transaction data; can send transaction results and endorsement information to the sorting service node; 2) Endorsement node, endorse_peer: sends transaction information to the TEE cluster and endorses the execution results of the TEE cluster; 3) Ordering service: ordering_service: Verifies the endorsement of transaction results and broadcasts the verified transaction results; A cluster: TEE cluster, cluster_tee: A cluster containing at least 3 TEE nodes that can execute transactions in TEE; A smart contract: TEE contract, contract_tee: records the hash value of transactions that require privacy protection; Three steps: Step 1 TEE key generation based on transaction information: The user node client records the hash value hash_txData of the transaction data and the user public key publicKey through the TEE contract contract_tee. The TEE cluster cluster_tee selects an idle TEE node, generates the session key sessionKey_tee according to the hash value hash_txData of the transaction data at the TEE contract contract_tee, and encrypts the session key encryptedKey_tee using the user node public key publicKey. The user node client obtains the session key ciphertext encryptedKey_tee from the TEE contract contract_tee according to the hash value hash_txData of the transaction data; the TEEs in the TEE cluster cluster_tee use a symmetric key exchange algorithm to generate a conference key session_key for secure transmission of the session key sessionKey_tee; Step 2: Simulate the execution of transaction proposals based on TEE: After the user node client decrypts and obtains the session key sessionKey_tee, it uses the session key to encrypt the transaction input data data_txInput. The endorsement node endorse_peer sends the transaction data that needs to be privately protected and its corresponding contract bytecode bytecode_contract to the TEE cluster cluster_tee. The TEE cluster cluster_tee selects three idle TEE nodes to execute the transaction. The TEE node returns the execution result result and signature signature to the endorsement node endorse_peer. The endorsement node endorse_peer verifies the result returned by the TEE cluster cluster_tee and the identity of the TEE node. After the verification is passed, it endorses the calculation result result. Step 3 Node status synchronization: The user node client verifies the endorsement result of the endorsement node endorse_peer, and sends the calculation result result after verification to the ordering service ordering_service. The ordering service ordering_service verifies the calculation result result, and broadcasts the transaction calculation result result after verification.
2. According to the Fabric data privacy protection method based on the trusted execution environment according to claim 1, It is characterized in that Step 1: Generate TEE key based on transaction information. Generate a symmetric key in TEE based on the user's transaction information. The details are as follows: Step 1.1: The user node client in the Fabric network generates the hash value hash_txData of the transaction data based on the transaction input data data_txInput. The client submits the hash value of the transaction data to the TEE contract contract_tee by calling the contract. The TEE contract needs to record the hash value hash_txData of the transaction data and its corresponding session key ciphertext encryptedKey_tee; Step 1.2: After a block time time_block, the TEE cluster cluster_tee obtains the transaction information that needs privacy protection from the TEE contract contract_tee, selects an idle TEE node tee_keyGeneration in the cluster to generate a session key sessionKey_tee for it, and after completing the key generation, the TEE node tee_keyGeneration will broadcast the transaction-related session key sessionKey_tee in the cluster through local attestation to ensure that all TEE nodes have the conditions to execute the transaction. At the same time, the user node public key publicKey is used to encrypt the session key sessionKey_tee to obtain the session key ciphertext encryptedKey_tee, and the session key ciphertext encryptedKey_tee corresponding to the transaction is recorded in the TEE contract contract_tee by calling the contract; Among them, the TEE cluster contains a leading TEE node tee_leader, which is responsible for interacting with other nodes or contracts outside the cluster. Before joining the cluster, all TEE nodes need to send their own public key public_key and information summary information_abstract to the leading TEE node tee_leader. The leading TEE node tee_leader obtains the legitimacy certificate of the TEE node from the certification center (certificate_authority) through remote attestation to ensure the legitimacy of the TEE node. At the same time, it determines whether the TEE node is available through the heartbeat keep_alive method. This method means that every 10 block times time_block, the TEE node needs to send survival information to the leading TEE node tee_leader to prove its availability. In addition, the TEE node will store relevant information about the execution of transactions; Step 1.3: After 3 block times time_block, the user node client obtains the session key sessionKey_tee corresponding to the transaction from the TEE contract contract_tee.
3. According to the Fabric data privacy protection method based on the trusted execution environment according to claim 2, It is characterized in that Step 2 is based on the simulated execution of TEE transaction proposals, transferring the process of simulated execution of smart contracts by endorsement nodes in Fabric to the TEE nodes in the TEE cluster, as follows: Step 2.1: The user node client uses the session key sessionKey_tee to encrypt the transaction input data data_txInput and the random number number_random to generate the transaction input data ciphertext encryptedData_txInput. The user node sends the transaction input data ciphertext encryptedData_txInput to the corresponding endorsement node endorse_peer according to the endorsement policy of the called smart contract. Step 2.2: The endorsement node endorse_peer sends the transaction data that needs to be protected for privacy and the corresponding contract bytecode bytecode_contract to the TEE cluster cluster_tee. The leading TEE node tee_leader has the state table table_teeState of each TEE node. Three idle TEE nodes are selected from them, and the transaction input data ciphertext encryptedData_txInput and the corresponding contract bytecode bytecode_contract are sent to these three TEE nodes. The TEE node uses the local session key sessionKey_tee to decrypt the transaction input data ciphertext encryptedData_txInput to obtain the transaction input data plaintext data_txInput, and then executes the contract bytecode bytecode_contract to obtain the transaction calculation result result. The TEE node performs a hash operation on the calculation result result to obtain the hash value hash_result of the calculation result, and then uses the session key sessionKey_tee to encrypt the calculation result result and the random number number_random to obtain the transaction output data ciphertext encryptedData_txOutput. Among them, the data of the endorsement request initiated by the user node client to the endorsement node endorse_peer includes the status of the transaction input data. The endorsement node endorse_peer determines whether it is necessary to simulate the execution of the transaction locally based on the status of the transaction input data. Step 2.3: The leading TEE node tee_leader returns the transaction calculation result result to the endorsement node endorse_peer that initiated the calculation request. The transaction calculation result result needs to satisfy the calculation results of at least two TEE nodes. Otherwise, the endorsement node endorse_peer considers the endorsement failed. The endorsement node endorses the verified calculation result result and returns the endorsement result endorsement to the user node client.
4. According to the Fabric data privacy protection method based on the trusted execution environment according to claim 3, It is characterized in that Step 3 Node status synchronization, as follows: Step 3.1: The client node determines whether 1 / 2 of the endorsing nodes have completed the endorsement process based on the endorsement policy, and then verifies the data returned by different endorsing nodes. Among them, the user node client decrypts the encrypted data output encryptedData_txOutput of the transaction to obtain the calculation result result, performs a hash operation on it and compares it with the hash value hash_result of the calculation result, and determines whether the random number number_random changes. This step determines whether the smart contract is executed correctly. Step 3.2: The ordering service ordering_service verifies the endorsement of the calculation result result to determine whether it satisfies the endorsement policy that 1 / 2 of the number of endorsement nodes complete the endorsement. After the verification is passed, the transaction calculation result result is broadcasted. After obtaining the transaction in the block, the node will write the transaction data into the local ledger.
Citation Information
Patent Citations
Encrypted smart contract privacy protection method based on trusted execution environment
CN113726733A
Private data processing system, method and device, computer equipment and storage medium
CN115001719A