Privacy protection cross-chain data sharing and verification tracing method and system based on multi-chain relay

By using proxy re-encryption technology and third-party distributed cloud storage in multi-chain relay scenarios, privacy protection and verification traceability of cross-chain data are achieved, solving the privacy protection problem in cross-chain data transmission and ensuring the security and reliability of data transmission.

CN115865336BActive Publication Date: 2026-04-17SOUTHEAST UNIV
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-25
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

In multi-chain relay scenarios, cross-chain data transmission lacks privacy protection. Data requesters and data owners worry about the leakage of identity and data privacy, which affects cross-chain business interactions and deployments.

Method used

By selecting proxy nodes in heterogeneous blockchains to form a relay chain, proxy re-encryption technology is used to encrypt cross-chain data, and the re-encrypted ciphertext is cached in a third-party distributed cloud storage, thereby achieving privacy protection and verification traceability of cross-chain data.

Benefits of technology

This ensures that only blockchain nodes participating in cross-chain data sharing can access the data content, protects cross-chain data privacy, improves data transmission performance, and verifies the integrity and validity of cross-chain data through a relay chain.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115865336B_ABST
    Figure CN115865336B_ABST
Patent Text Reader

Abstract

This invention discloses a privacy-preserving cross-chain data sharing and verification traceability method and system based on multi-chain relays. Through five steps—heterogeneous multi-chain relay initialization, cross-chain data proxy request, cross-chain data generation, cross-chain data retrieval, and cross-chain data verification traceability—it strengthens privacy protection for cross-chain data transmission in multi-chain relay scenarios. The method establishes a relay chain among multiple heterogeneous blockchains for cross-chain data sharing and achieves privacy protection for the shared data content. The designed cross-chain data sharing scheme based on proxy re-encryption ensures that only blockchain nodes participating in cross-chain data sharing can access the shared data content in a multi-chain relay chain architecture, and provides efficient data transmission based on outsourced storage. The verification traceability scheme allows users participating in cross-chain data sharing to verify and trace cross-chain information through the relay chain.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of blockchain cross-chain technology, and mainly relates to a privacy-preserving cross-chain data sharing, verification and traceability method and system based on multi-chain relay. Background Technology

[0002] Blockchain is a decentralized, distributed data ledger that allows participating nodes in a network to collectively own, manage, and monitor data based on cryptographic techniques. In a blockchain network, no single node can control the operation of the system, giving it immutability and traceability. Based on this characteristic, blockchain has built a new trust system, and through deep integration with industry applications, it has transformed the way value is transferred in many fields, including information technology, finance, and insurance.

[0003] Currently, various blockchain projects have emerged worldwide. Some of these are localized optimizations based on the Bitcoin / Ethereum blockchain code, some are functional improvements for specific application scenarios, and some have made significant innovations in improving blockchain performance. However, blockchain systems for digital currencies have not considered the Turing completeness, scalability, and security requirements of blockchain functional applications, and face specific issues such as capacity and forks.

[0004] In terms of scalability, cross-chain technology can increase the scalability of blockchains and fundamentally solve the "data silo" problem caused by difficulties in transactions between different public chains / sidechains. Currently, there are five main types of cross-chain technology: notary scheme, hash-locking, sidechain, relay, and distributed private key control. These five mainstream cross-chain technologies have solved the cross-chain interoperability problem to varying degrees, providing technical solutions for cross-chain operations.

[0005] Compared to other cross-chain technologies, relay solutions are more flexible and easily scalable. However, relay chains are based on blockchain technology, and the ledger data is publicly visible. Users participating in cross-chain transactions face the following issues: For data requesters, the main concern during cross-chain data sharing is the potential leakage of their identity and data privacy; for data owners, the lack of data privacy protection may discourage them from sharing their data, impacting the interaction and deployment of cross-chain services. In summary, the key issue is how to protect the identity and data privacy of participants during cross-chain transactions while ensuring data availability. Summary of the Invention

[0006] This invention addresses the lack of privacy protection in cross-chain data transmission within multi-chain relay scenarios in existing technologies. It provides a privacy-preserving cross-chain data sharing, verification, and traceability method and system based on multi-chain relays. First, each heterogeneous blockchain selects proxy nodes to form a relay chain and initializes it. New proxy nodes in newly joined chains join through registration. A data requester initiates a cross-chain data request to the relay chain through a proxy node, and the target blockchain responds to the request. The target blockchain's proxy node returns encrypted cross-chain data to the relay chain, which re-encrypts the data using a proxy and caches the re-encrypted ciphertext in a third-party distributed cloud storage, obtaining a cached ciphertext file hash. The relay chain sends the returned cached ciphertext file hash to the source blockchain through the proxy node. The node that initiated the cross-chain request accepts this file hash, retrieves the corresponding data content through the third-party distributed cloud storage, decrypts the re-encrypted data, and obtains the requested data content. Finally, the data requester verifies the validity and integrity of the received cross-chain data through the relay chain and obtains cross-chain data transmission traceability information. The method in this case establishes a relay chain between multiple heterogeneous blockchains to facilitate cross-chain data sharing and protects the privacy of the shared data content. The designed cross-chain data sharing scheme based on proxy re-encryption ensures that only blockchain nodes participating in cross-chain data sharing can access the shared data content under the multi-linked relay chain architecture, and provides efficient data transmission based on outsourced storage. The verification and traceability scheme involved allows users participating in cross-chain data sharing to verify and trace cross-chain information through the relay chain.

[0007] To achieve the above objectives, the technical solution adopted by this invention is: a privacy-preserving cross-chain data sharing and verification traceability method based on multi-chain relay, comprising the following steps:

[0008] Step S1, Heterogeneous Multi-Chain Relay Initialization: Each heterogeneous blockchain selects proxy nodes to form a relay chain and initializes it, where proxy nodes in newly connected chains join by registering;

[0009] Step S2, Cross-chain data proxy request: The data requester initiates a cross-chain data request to the relay chain through the proxy node, and the target blockchain responds to the data request;

[0010] Step S3, Cross-chain data generation: The encrypted cross-chain data returned by the target blockchain proxy node is sent to the relay chain. The relay chain uses the proxy to re-encrypt the data and caches the re-encrypted ciphertext in a third-party distributed cloud storage to obtain the hash of the cached ciphertext file.

[0011] Step S4, Cross-chain data retrieval: The relay chain sends the returned cached encrypted file hash to the source blockchain through the proxy node. The node that initiated the cross-chain request accepts the file hash, retrieves the corresponding data content through third-party distributed cloud storage, decrypts and re-encrypts the data to obtain the requested data content.

[0012] Step S5, Cross-chain Data Verification and Traceability: The data requester verifies the validity and integrity of the received cross-chain data through the relay chain and obtains cross-chain data transmission traceability information.

[0013] As an improvement of the present invention, the initialization of the heterogeneous multi-chain relay chain in step S1 specifically includes the following steps:

[0014] S11. Initialization of the Access Chain System: The source blockchain C A , the target blockchain C B and other relay link access chains select a certain number of proxy nodes to form the relay blockchain C R , and perform system initialization; the step further includes:

[0015] S111. Selecting k nodes in the network as proxy nodes according to predefined rules for the heterogeneous access chain C X , where k < n, n represents the maximum number of proxy nodes of the current heterogeneous access chain, and X represents the access chain identifier;

[0016] S112. The heterogeneous access chain C X invokes the access chain contract to execute registering the proxy nodes on the current chain, where represents the proxy node in the access chain C X , SC X represents the smart contract in the access chain X, represents the ordinary user node in the access chain X;

[0017] S113. The relay chain CA selects an l-bit prime number q, generates an elliptic curve group G of order q and a random generator P, and then selects a random value as the private key, and calculates the public key pk R = sk R P;

[0018] S114. The relay chain CA selects and defines four different hash functions

[0019] S115. The relay chain CA packs the above parameters into the public parameters pp = {G, q, P, pk R , H1, H2, H3, H4}, and calls the relay chain smart contract SC R .SetParam(pp) to publish the parameters, where SC R represents the smart contract in the relay chain C R ;

[0020] S12. Registration Authorization of Proxy Nodes: The relay chain authorizes the joined proxy nodes within the registration validity period.

[0021] As an improvement of the present invention, the agent node registration and authorization in step S12 includes the following steps:

[0022] S121, Proxy Node Generate a random value Calculate R α =αP, and will (id P ,R α ) is sent to the relay chain CA, where id P Is the proxy node in relay chain C R Identity identifiers within;

[0023] S122, The relay chain CA received (id) P ,R α After that, verify the proxy node. The identity is then used to generate a random value. Calculate R β =βP, thus generating proxy nodes. Cert Certificate P =R α +R β and return (sk) P Cert P ) to the proxy node, where sk P =H1(Cert) P ‖id P )+sk R ;

[0024] S123, Proxy Node Received (sk) P Cert P After that, the public key pk is calculated. P =H1(Cert) P ‖id P )α+sk P and verify If the verification passes, the key pair is accepted, and the relay chain smart contract is invoked to register the agent node information SC. R .Enroll(pk P Cert P ).

[0025] As an improvement of the present invention, the cross-chain data proxy request in step S2 includes the following steps:

[0026] S21. Access Chain Cross-Chain Data Request: Access Chain C A Nodes in Through proxy node Initiate a campaign against access chain CB The request for cross-chain data M in the process; the step further includes:

[0027] S211, Access Chain C A Nodes in Call the access chain smart contract Request access chain C B The cross-chain data M in the data, where reqid is the identifier of this cross-chain request, It is a node The public key;

[0028] S212, Access Chain C A proxy nodes in Calling the access chain smart contract {reqid,reqinfo} ←SC A .QueryReq() retrieves currently valid cross-chain requests and obtains cross-chain data request information. Subsequently, relay chain C is called. R Smart Contracts in SC R .ReqData(reqid,reqinfo,id A ) to the proxy node in the access chain Initiate a cross-chain data request M, where id A It is a proxy node In relay chain C R Identity identifiers within;

[0029] S22, Cross-chain data initialization: Relay chain C R Middle access chain C B proxy nodes Obtain cross-chain data request metadata and generate a re-encryption key.

[0030] As another improvement of the present invention, the cross-chain data initialization in step S22 further includes the following steps:

[0031] S221, Relay Chain C R Middle access chain C B proxy nodes Calling the relay chain smart contract meta←SC R .QueryReq() retrieves cross-chain data request metadata meta = {reqid, reqinfo, id} A},calculate And generate a re-encryption key based on the above information. Where id B It is a proxy node In relay chain C R Identity identifiers in It is a proxy node The private and public keys, It is a proxy node The public key;

[0032] S222, Agent Node Calling the relay chain smart contract SC R .UploadRk(reqid,id B ,rk B→A Upload the re-encryption key.

[0033] As another improvement of the present invention, the cross-chain data generation in step S3 specifically includes the following steps:

[0034] S31, Cross-chain data ciphertext generation; Access chain C B proxy nodes Generate the ciphertext of cross-chain data M and outsource its storage to a third-party distributed cloud storage (DCS); the steps further include:

[0035] S311, Proxy Node Call access chain C B Smart Contract M←SC B .QueryData() retrieves the requested cross-chain data M, and encrypts the cross-chain data M to obtain the ciphertext. And generate verification information h = H4(E‖id) B )and

[0036] S312, Agent Node Divide the ciphertext E into n data blocks of equal size E. i Where E1‖E2‖…‖E n →E, the above data is outsourced and stored in a third-party distributed cloud storage (DCS), resulting in the hash of the re-encrypted data block outsourced storage file {enc1,enc2,…,enc i}, and then interacts with the relay chain, calling the relay chain's smart contract. Write the hash and verification information to the encrypted cross-chain data file, where T is the re-encryption validity period;

[0037] S313, If the cross-chain data request node Subsequent initiatives targeting access chain C B The same request for data M is forwarded to relay chain C when the cross-chain request is forwarded. R After that, relay chain C R Middle access chain C B proxy nodes In cross-chain data sharing contract SC R Generate a new re-encryption key within the validity period. in It is a node The public key;

[0038] S314. After the re-encryption key is generated, the proxy node... No need to re-encrypt data, simply re-invoke the relay chain smart contract SC. R .UploadRk(reqid′,id B ,rk′ B→A Upload the new re-encryption key to proceed with subsequent data transmission, where reqid′ represents a new cross-chain data request;

[0039] S32, Cross-chain data re-encryption ciphertext generation: Relay chain C R proxy nodes in Download the encrypted cross-chain data from the third-party distributed cloud storage (DCS), re-encrypt it, and re-upload it to the DCS in the distributed cloud storage.

[0040] As another improvement of the present invention, the generation of cross-chain data re-encryption ciphertext in step S32 specifically includes the following steps:

[0041] S321, Relay Chain C R proxy nodes in Calling the relay chain contract {enc i ,T,rk B→A}←SC R .REnc(reqid,id X Download encrypted cross-chain data information, including the ID. X It is a proxy node In relay chain C R Identity identifiers within;

[0042] S322, Agent Node Verify the data re-encryption validity period T, and verify the cross-chain data file hash enc. i Download cross-chain data block E i Perform re-encryption to obtain re-encrypted data. The data is then re-outsourced to a third-party distributed cloud storage (DCS), resulting in a re-encrypted data block outsourced storage file hash (renc). i ;

[0043] S323, Agent Node Calling the relay chain smart contract {null,⊥}←SC R .UploadREnc(reqid,id X ,renc i Upload re-encrypted data E iThe contract outsources storage information and receives corresponding compensation. If the contract returns a value of ⊥, then all encrypted data blocks in the cross-chain request reqid have been reencrypted.

[0044] As another improvement of the present invention, the cross-chain data retrieval in step S4 specifically includes the following steps:

[0045] S41, Proxy Node Calling the contract The hash of the re-encrypted cross-chain data file is obtained as renc = renc1‖renc2‖…‖renc i and call access chain C A Smart Contracts Upload cross-chain data-related information;

[0046] S42, Cross-chain data request node Call the access chain smart contract Based on the hash renc of the re-encrypted cross-chain data file, a request is sent to DCS to download the re-encrypted data file E′={E1′,E1′,…,E i ′};

[0047] S43, Cross-chain data request node calculate Decryption And obtain the cross-chain data plaintext M = M1‖M2‖…‖M i ,in It is a node The private key.

[0048] As a further improvement of the present invention, the cross-chain data verification and traceability in step S5 specifically includes the following steps:

[0049] S51, Cross-chain data request node verify If the verification passes, the re-encrypted cross-chain data is valid;

[0050] S52, Node Calling the access chain smart contract SC A .TraceReq(reqid) initiates a process trace for cross-chain data request reqid;

[0051] S53, Access Chain C A proxy nodes in Call SC R `.Trace(reqid)` retrieves the ID of the proxy node participating in the cross-chain sharing process. X And return the relevant traceability information to the access chain C. A Nodes in

[0052] To achieve the above objectives, the technical solution adopted by the present invention is: a privacy-preserving cross-chain data sharing and verification traceability system based on multi-chain relay, which includes at least heterogeneous access chains, permissioned relay chains, cross-chain contracts and third-party distributed cloud storage;

[0053] The heterogeneous access chain selects proxy nodes to join the relay chain and participate in the cross-chain data sharing process:

[0054] The permissioned relay chain is composed of proxy nodes selected by each heterogeneous access chain, which realizes privacy protection for cross-chain data sharing;

[0055] The cross-chain contract exists in the relay chain and the access chain, assists in the request and forwarding of cross-chain data, and records the cross-chain process for subsequent verification and traceability.

[0056] The third-party distributed cloud storage interacts with the relay chain, outsources the storage of re-encrypted cross-chain data, and returns the storage file index for cross-chain data requesters to retrieve.

[0057] Compared with the prior art, the present invention has the following beneficial effects:

[0058] (1) In this invention, a relay chain is used to realize cross-chain data sharing. This solution supports the access of heterogeneous blockchains. Each blockchain is accessed through a proxy node. It does not rely on the verification and judgment of a trusted third party. The cross-chain process is recorded in the relay chain, which facilitates subsequent verification and traceability.

[0059] (2) In the cross-chain data sharing stage, this invention realizes cross-chain data encryption outsourcing storage and privacy protection cross-chain data index sharing based on proxy re-encryption, ensuring that only blockchain nodes participating in cross-chain data sharing can access the data sharing content, protecting the privacy of cross-chain data, and using distributed cloud storage to cache the cross-chain data body, which can effectively improve data transmission performance.

[0060] (3) Based on the characteristics of blockchain, this invention allows nodes participating in cross-chain data transmission to verify cross-chain data transmission information through the relay chain, thus ensuring the integrity and validity of cross-chain data. Attached Figure Description

[0061] Figure 1 This is a system framework diagram of the privacy-preserving cross-chain data sharing and verification traceability system based on multi-chain relay of the present invention.

[0062] Figure 2 This is a schematic diagram illustrating the impact of the number of users on system performance in the test examples of this invention;

[0063] Figure 3 This is a schematic diagram illustrating the impact of relay chain size on system performance in the test examples of this invention. Detailed Implementation

[0064] The present invention will be further illustrated below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the following specific embodiments are only used to illustrate the present invention and not to limit the scope of the present invention.

[0065] Embodiment 1

[0066] A privacy protection cross-chain data sharing and verification tracing system based on multi-chain relay, as Figure 1 shown, at least includes heterogeneous access chains, permission relay chains, cross-chain contracts and third-party distributed cloud storage. Among the access chains, the chains where the two nodes of the cross-chain request are located are the source blockchain and the target blockchain, and the chains where only the proxy nodes assisting the cross-chain data request are located are the relay chain access chains. Each access chain selects proxy nodes to join the relay chain and participates in the cross-chain data sharing process: The relay chain is composed of proxy nodes, authorizes and authenticates the accessed proxy nodes, realizes access control and privacy protection in the cross-chain data sharing process, and incentives the nodes participating in the data sharing process; The third-party distributed cloud storage interacts with the relay chain, outsources the storage of encrypted cross-chain data and returns the hash value of the stored file for the data requester to retrieve.

[0067] A privacy protection cross-chain data sharing and verification tracing method based on multi-chain relay specifically includes the following steps:

[0068] Step S1, heterogeneous multi-chain relay initialization:

[0069] 1.1. Initialization of the access chain system

[0070] Heterogeneous access chain C X Select k nodes in the network as proxy nodes according to predefined rules, where k < n, n represents the maximum number of proxy nodes in the current heterogeneous access chain, and X represents the access chain identifier; Subsequently, the heterogeneous access chain C X Invokes the access chain contract to execute Register proxy nodes on the current chain, where represents the proxy node in the access chain C X , SC X represents the smart contract in the access chain X, represents the ordinary user node in the access chain X; After the registration is completed, the relay chain CA selects an l-bit prime number q, generates an elliptic curve group G of order q and a random generator P, and then selects a random value as the private key, and calculates the public key pk R = sk R P; The relay chain CA selects and defines four different hash functions The relay chain CA packs the above parameters into the public parameters pp = {G, q, P, pk RThe function calls the relay chain smart contract SC, which in turn calls the H1, H2, H3, H4}. R .SetParam(pp) publishes parameters, where SC R Represents relay chain C R Smart contracts in the context of [the system / mechanism].

[0071] 1.2 Agent Node Registration and Authorization

[0072] proxy node Generate a random value Calculate R α =αP, and will (id P ,R α ) is sent to the relay chain CA, where id P Is the proxy node in relay chain C R Identity identifier in the relay chain; CA receives (id) P ,R α After that, verify the proxy node. The identity is then used to generate a random value. Calculate R β =βP, thus generating proxy nodes. Cert Certificate P =R α +R β and return (sk) P Cert P ) to the proxy node, where sk P =H1(Cert) P ‖id P )+sk R Proxy node Received (sk) P Cert P After that, the public key pk is calculated. P =H1(Cert) P ‖id P )α+sk P and verify If the verification passes, the key pair is accepted, and the relay chain smart contract is invoked to register the agent node information SC. R .Enroll(pk P Cert P ).

[0073] Step S2, cross-chain data proxy request:

[0074] 2.1 Access Chain Cross-Chain Data Request

[0075] Access Chain C A Nodes in Call the access chain smart contract Request access chain C B The cross-chain data M in the data, where reqid is the identifier of this cross-chain request, It is a node Public key; Access chain C A proxy nodes in Calling the access chain smart contract {reqid,reqinfo} ←SC A .QueryReq() retrieves currently valid cross-chain requests and obtains cross-chain data request information. Subsequently, relay chain C is called. R Smart Contracts in SC R .ReqData(reqid,reqinfo,id A ) to the proxy node in the access chain Initiate a cross-chain data request M, where id A It is a proxy node In relay chain C R Identity identifiers within.

[0076] 2.2 Cross-chain data initialization

[0077] Relay chain C R Middle access chain C B proxy nodes Calling the relay chain smart contract meta←SC R .QueryReq() retrieves cross-chain data request metadata meta = {reqid, reqinfo, id} A},calculate And generate a re-encryption key based on the above information. Where id B It is a proxy node In relay chain C R Identity identifiers in It is a proxy node The private and public keys, It is a proxy node Public key; proxy node Calling the relay chain smart contract SC R .UploadRk(reqid,id B ,rk B→A Upload the re-encryption key.

[0078] Step S3, Cross-chain data generation:

[0079] 3.1 Cross-chain data ciphertext generation

[0080] proxy node Call access chain C BSmart Contract M←SC B .QueryData() retrieves the requested cross-chain data M, and encrypts the cross-chain data M to obtain the ciphertext. And generate verification information h = H4(E‖id) B )and proxy node Divide the ciphertext E into n data blocks of equal size E. i Where E1‖E2‖…‖E n →E, the above data is outsourced and stored in a third-party distributed cloud storage (DCS), resulting in the hash of the re-encrypted data block outsourced storage file {enc1,enc2,…,enc i}, and then interacts with the relay chain, calling the relay chain's smart contract. Write the hash and verification information to the encrypted cross-chain data file, where T is the re-encryption validity period; if the cross-chain data request node... Subsequent initiatives targeting access chain C B The same request for data M is forwarded to relay chain C when the cross-chain request is forwarded. R After that, relay chain C R Middle access chain C B proxy nodes In cross-chain data sharing contract SC R Generate a new re-encryption key within the validity period. in It is a node The public key; after the re-encryption key is generated, the proxy node No need to re-encrypt data, simply re-invoke the relay chain smart contract SC. R .UploadRk(reqid′,id B ,rk′ B→A Uploading a new re-encryption key allows for subsequent data transmission, where reqid′ represents a new cross-chain data request.

[0081] 3.2 Cross-chain data re-encryption ciphertext generation

[0082] Relay chain C R proxy nodes in Calling the relay chain contract {enc i ,T,rk B→A}←SC R .REnc(reqid,id X Download encrypted cross-chain data information, including the ID. X It is a proxy node In relay chain C R Identity identifier in the network; proxy node Verify the data re-encryption validity period T, and verify the cross-chain data file hash enc.i Download cross-chain data block E i Perform re-encryption to obtain re-encrypted data. The data is then re-outsourced to a third-party distributed cloud storage (DCS), resulting in a re-encrypted data block outsourced storage file hash (renc). i Proxy node Calling the relay chain smart contract {null,⊥}←SC R .UploadREnc(reqid,id X ,renc i Upload re-encrypted data E i The contract outsources storage information and receives corresponding compensation. If the contract returns a value of ⊥, then all encrypted data blocks in the cross-chain request reqid have been reencrypted.

[0083] Step S4, cross-chain data retrieval:

[0084] proxy node Calling the contract The hash of the re-encrypted cross-chain data file is obtained as renc = renc1‖renc2‖…‖renc i and call access chain C A Smart Contracts Upload cross-chain data related information; cross-chain data request node Call the access chain smart contract Based on the hash renc of the re-encrypted cross-chain data file, a request is sent to DCS to download the re-encrypted data file E′={E1′,E1′,…,E i Cross-chain data request node calculate Decryption And obtain the cross-chain data plaintext M = M1‖M2‖…‖M i ,in It is a node The private key.

[0085] Step S5, Cross-chain data verification and traceability:

[0086] Cross-chain data request node verify If the verification passes, the re-encrypted cross-chain data is valid; node Calling the access chain smart contract SC A `.TraceReq(reqid)` initiates process tracing for cross-chain data request `reqid`; (This is used when accessing chain C.) A proxy nodes in Call SC R `.Trace(reqid)` retrieves the ID of the proxy node participating in the cross-chain sharing process.X And return the relevant traceability information to the access chain C. A Nodes in

[0087] Test case

[0088] To evaluate the safety performance of the present invention, this experimental example analyzes its three safety features.

[0089] The security analysis is as follows:

[0090] 1) Confidentiality: Cross-chain data is transmitted to the relay chain in encrypted form through proxy nodes. Based on the proxy re-encryption feature, if an attacker does not obtain the private key of the cross-chain data sender, they cannot recover the original information from the encrypted cross-chain data. After the cross-chain data is re-encrypted, since the re-encryption key is generated based on the private key of the data sender and the private key of the data receiver, the re-encrypted data can only be decrypted by the private key of the data requester. Therefore, throughout the entire process, only the data sender and receiver can decrypt the plaintext of the cross-chain data.

[0091] 2) Integrity: The integrity of cross-chain data can be achieved by the data sender and receiver verifying the certificate contained in the hash value of the cross-chain data;

[0092] 3) Availability: After the cross-chain data outsourcing storage ends, even if the relay chain fails and communication is impossible, the data requester can still retrieve the requested data from the third-party distributed cloud storage through the file hash. Moreover, the data requester can only obtain and decrypt the requested data and cannot obtain other cross-chain data.

[0093] The above characteristics can defend against the following attacks:

[0094] 1) Man-in-the-middle attack: A man-in-the-middle attack attacks a Certificate Authority (CA) by providing a forged public key to the user, thereby leading to the leakage of encrypted data. The method of this invention uses a multi-chain relay to implement the CA function. The public key related to the cross-chain data transmission process is stored in the common block in the relay chain. The data is distributed on the participating nodes and forms a chain structure with the preceding and following blocks, making it difficult for attackers to tamper with the blocks and issue fake keys. Therefore, the method of this invention can resist man-in-the-middle attacks.

[0095] 2) Data tampering: If there is no data integrity verification scheme, attackers can inject tampered data into the system to carry out attacks; This invention uses a blockchain-based multi-chain relay to allow nodes participating in cross-chain data transmission to publish hash values ​​related to specific data. Even if attackers can tamper with cross-chain data in third-party distributed cloud storage, they cannot change the hash value stored on the blockchain. This allows data requesters to verify whether the retrieved data has been tampered with.

[0096] 3) Replay attack: A replay attack deceives the system by sending a data packet that the target host has already received; this invention adds a timestamp to each step of cross-chain data transmission, which can effectively resist replay attacks.

[0097] To evaluate the performance of the method described in this invention, this test case deployed a Hyperledger Fabric test network locally and executed the cross-chain data sharing method involved in this scheme within the test network. In this test case, the test platform used channels in Hyperledger Fabric to simulate the source blockchain, target blockchain, and relay chain joining the chain, and selected a certain number of nodes as proxies to form the relay chain. The Hyperledger Fabric network ran on a 12-core Intel 12700KF processor, 32GB RAM, and Ubuntu 22.04 operating system, with the performance testing using the open-source tool Tape.

[0098] The performance evaluation of the test cases is as follows:

[0099] 1) The impact of the number of users on system performance: such as Figure 2 As shown, the number of nodes in the blockchain is set to 50. As the proportion (cross-chain service users) increases, the transaction throughput gradually increases to a maximum point and then slowly decreases. This is because when there are few cross-chain requests, the relay chain has not yet reached its performance limit. When the number of users requesting cross-chain services in the network increases, the transaction throughput will decrease. Compared with the original cross-chain transmission scheme, this aspect can maintain the same rate of change as the original scheme.

[0100] 2) The impact of relay chain size on system performance: such as Figure 3 As shown, in this embodiment, 15% of user requests in the blockchain network are for cross-chain services. When the proportion of relay nodes is high, the performance degradation can be ignored as the scale of blockchain nodes increases. When the proportion of relay nodes is low, the increase in the scale of blockchain nodes will cause the cross-chain performance to slowly decline after reaching a bottleneck. In the above situations, the method of the present invention can still maintain performance similar to the original solution.

[0101] As demonstrated by the test examples above, the method of this invention achieves cross-chain data sharing through a relay chain. It enables access control of cross-chain data sharing content between multiple heterogeneous blockchains and designs a proxy-based re-encryption cross-chain data sharing scheme. This ensures that, in a multi-linked relay chain architecture, only blockchain nodes participating in cross-chain data sharing can access the shared data content, and it provides data transmission based on outsourced storage. Furthermore, the verification and traceability mechanism allows users participating in cross-chain data sharing to verify and trace cross-chain information through the relay chain.

[0102] It should be noted that the above content merely illustrates the technical concept of the present invention and should not be construed as limiting the scope of protection of the present invention. For those skilled in the art, various improvements and modifications can be made without departing from the principle of the present invention, and all such improvements and modifications fall within the scope of protection of the claims of the present invention.

Claims

1. A privacy protection cross-chain data sharing and verification tracing method based on multi-chain relay, characterized in that, Includes the following steps: Step S1, Heterogeneous Multi-Chain Relay Initialization: Each heterogeneous blockchain selects proxy nodes to form a relay chain and initializes it, where proxy nodes in newly connected chains join by registering; Step S2, Cross-chain data proxy request: The data requester initiates a cross-chain data request to the relay chain through the proxy node, and the target blockchain responds to the data request; Step S3, Cross-chain data generation: The target blockchain proxy node returns encrypted cross-chain data to the relay chain. The relay chain uses the proxy to re-encrypt the data and caches the re-encrypted ciphertext in a third-party distributed cloud storage to obtain the hash of the cached ciphertext file. Step S4, Cross-chain data retrieval: The relay chain sends the returned cached encrypted file hash to the source blockchain through the proxy node. The node that initiated the cross-chain request accepts the file hash, retrieves the corresponding data content through third-party distributed cloud storage, decrypts and re-encrypts the data to obtain the requested data content. S41, Proxy Nodes in the Source Blockchain Calling the contract Obtain the hash of the re-encrypted cross-chain data file and call the access chain Smart Contracts Upload cross-chain data-related information; among which, The hash of the file to be used to encapsulate the encrypted data block is stored outside the file. , Cipher Verification information; Refers to the proxy node in the target blockchain The public key; Refers to proxy node In relay chain Identity identifiers within; Relay chain Smart contracts in; This refers to the identifier of this cross-chain request; Refers to the information query function in a smart contract; S42, Cross-chain data request node Call the access chain smart contract Based on the hash of the re-encrypted cross-chain data file Send a request to a third-party distributed cloud storage (DCS) to download the re-encrypted data file. ; S43, Cross-chain data request node calculate Decryption And obtain cross-chain data plaintext ,in It is a node The private key; H3 refers to the random number generator; H3 refers to the cross-validation hash function. Refers to a general index; Step S5, Cross-chain data verification and traceability: The data requester verifies the validity and integrity of the received cross-chain data through the relay chain and obtains cross-chain data transmission traceability information.

2. The privacy-preserving cross-chain data sharing and verification traceability method based on multi-chain relay as described in claim 1, characterized in that: The heterogeneous multi-chain relay chain initialization in step S1 specifically includes the following steps: S11. Access Chain System Initialization: Source Blockchain Target Blockchain A certain number of proxy nodes are selected from other relay links to form a relay chain. The system is then initialized; the steps further include: S111, Heterogeneous Access Chain Select from the network according to predefined rules Each node acts as a proxy node, among which , This indicates the maximum number of proxy nodes in the current heterogeneous access chain. Indicates the access chain identifier; S112, Heterogeneous Access Chain Call the access chain contract to execute Register agent nodes in the current chain, among which Indicates access chain proxy nodes in Indicates access chain Smart contracts in Indicates access chain Ordinary user nodes in; S113, Relay Chain Choose one prime number to generate a Elliptic curve group of order and random generator Then select a random value. Used as the private key, and used to calculate the public key. ;in, The multiplication group of a finite field; S114, Relay Chain Select and define four different hash functions , , , ; S115, relay chain Package the above parameters into common parameters. and call the relay chain smart contract. Release parameters, among which Represents a relay chain Smart contracts in; S12, Agent Node Registration and Authorization: Agent nodes authorized to join the relay chain during the registration validity period.

3. The privacy-preserving cross-chain data sharing and verification traceability method based on multi-chain relay as described in claim 2, characterized in that: The agent node registration and authorization in step S12 includes the following steps: S121, Proxy Node Generate a random value Calculations yielded and will Send to relay chain ,in It is the proxy node in the relay chain Identity identifiers within; S122, Relay Chain Received Then, verify the proxy node. The identity is then used to generate a random value. Calculations yielded This generates proxy nodes. Certificate and return For the proxy node, where ; S123, Proxy Node Received Then, the public key is calculated. and call the relay chain smart contract. Registration agent node information.

4. The privacy-preserving cross-chain data sharing and verification traceability method based on multi-chain relay as described in claim 1, characterized in that: The cross-chain data proxy request in step S2 includes the following steps: S21. Access Chain Cross-Chain Data Request: Access Chain Nodes in Through proxy node Initiate targeting the access chain Cross-chain data The request; the steps further include: S211, Access Chain Nodes in Call the access chain smart contract Request access chain Cross-chain data ,in This is the identifier for this cross-chain request. It is a node The public key; S212, Access Chain proxy nodes in Call the access chain smart contract Retrieve currently valid cross-chain requests and obtain cross-chain data request information. Then, the relay chain is invoked. Smart contracts in to the proxy node in the access chain Initiate cross-chain data The request, in which It is a proxy node In relay chain Identity identifiers in the system; S22, Cross-chain data initialization: Relay chain Middle access chain proxy nodes Obtain cross-chain data request metadata and generate a re-encryption key.

5. The privacy-preserving cross-chain data sharing and verification traceability method based on multi-chain relay as described in claim 4, characterized in that: The cross-chain data initialization in step S22 further includes the following steps: S221, Relay Chain Middle access chain proxy nodes Calling the relay chain smart contract Obtain cross-chain data request metadata ,calculate And generate a re-encryption key based on the above information. ,in It is a proxy node In relay chain Identity identifiers in , It is a proxy node The private and public keys, It is a proxy node The public key; Refers to the key-derived hash function; Refers to the cross-validation hash function; S222, Agent Node Calling the relay chain smart contract Upload the re-encryption key.

6. The privacy-preserving cross-chain data sharing and verification traceability method based on multi-chain relay according to claim 5, characterized in that: The cross-chain data generation in step S3 specifically includes the following steps: S31. Cross-chain data ciphertext generation; access chain proxy nodes Generate cross-chain data The encrypted text is then outsourced to a third-party distributed cloud storage. The steps further include: S311, Proxy Node Call access chain Smart Contracts Retrieve the requested cross-chain data Encrypted cross-chain data Obtain the ciphertext and generate verification information. and ;in, Refers to the cross-validation hash function; Refers to the commitment hash function; Refers to proxy node In relay chain Identity identifiers within; Calculated value ; This refers to the identifier of this cross-chain request; and Refers to proxy node The public and private keys; S312, Agent Node ciphertext Cut into Data blocks of the same size ,in The aforementioned data will be outsourced and stored in third-party distributed cloud storage. Obtain the hash of the re-encrypted data block's outsourced storage file. It then interacts with the relay chain, calling the relay chain's smart contract. Write the hash and verification information to the encrypted cross-chain data file, where This is the validity period of the re-encryption; S313, If the cross-chain data request node Subsequent initiatives targeting the access chain China Data The same request, when the cross-chain request is forwarded to the relay chain After that, relay chain Middle access chain proxy nodes In cross-chain data sharing contracts Generate a new re-encryption key within the validity period. ,in It is a node The public key; S314. After the re-encryption key is generated, the proxy node... No need to re-encrypt data, simply re-invoke the relay chain smart contract. Uploading a new re-encryption key will allow subsequent data transmission. This represents a new cross-chain data request; This refers to the newly generated re-encryption key; S32. Cross-chain data re-encryption ciphertext generation: relay chain proxy nodes in From third-party distributed cloud storage Download the encrypted cross-chain data, re-encrypt it, and re-upload it to the distributed cloud storage. middle.

7. The privacy-preserving cross-chain data sharing and verification traceability method based on multi-chain relay as described in claim 6, characterized in that: The specific steps for generating cross-chain data re-encryption ciphertext in step S32 include the following: S321, Relay Chain proxy nodes in Calling the relay chain contract Download encrypted cross-chain data information, including It is a proxy node In relay chain Identity identifiers within; Re-encryption key; S322, Agent Node Verify data re-encryption validity period And through encrypted cross-chain data file hashing Download cross-chain data blocks Perform re-encryption to obtain re-encrypted data. The data will then be re-outsourced and stored in a third-party distributed cloud storage system. Obtain the hash of the re-encrypted data block's outsourced storage file. ; S323, Proxy Node Calling the relay chain smart contract Upload re-encrypted data The outsourced storage information is obtained and corresponding compensation is received. If the contract return value is... Then cross-chain request All encrypted data blocks have been re-encrypted.

8. The privacy-preserving cross-chain data sharing and verification traceability method based on multi-chain relay according to claim 7, characterized in that: The cross-chain data verification and traceability in step S5 specifically includes the following steps: S51, Cross-chain data request node ,verify If the verification passes, the re-encrypted cross-chain data is valid; S52, Node Call the access chain smart contract Initiate cross-chain data requests Process tracing; S53, Access Chain proxy nodes in Call Obtain information about the proxy nodes participating in the cross-chain sharing process. And return the relevant traceability information to the access chain. Nodes in .

9. A privacy-preserving cross-chain data sharing and verification traceability system based on multi-chain relays, implementing the method as described in claim 1, characterized in that: It includes at least heterogeneous access chains, permissioned relay chains, cross-chain contracts, and third-party distributed cloud storage; The heterogeneous access chain selects proxy nodes to join the relay chain and participate in the cross-chain data sharing process: The permissioned relay chain is composed of proxy nodes selected by each heterogeneous access chain, which realizes privacy protection for cross-chain data sharing; The cross-chain contract exists in the relay chain and the access chain, assists in the request and forwarding of cross-chain data, and records the cross-chain process for subsequent verification and traceability. The third-party distributed cloud storage interacts with the relay chain, outsources the storage of re-encrypted cross-chain data, and returns the storage file index for cross-chain data requesters to retrieve.

Citation Information

Patent Citations

  • Supervisable cross-chain private data sharing method and device

    CN115242555A