Anonymous communication method, terminal device, and computer-readable storage medium

By generating a blockchain-based list of intermediate network nodes and information transmission timing, an anonymous communication path is constructed, solving the problem of existing technologies being unable to resist traffic analysis and achieving efficient anonymous communication.

CN115913654BActive Publication Date: 2026-03-31HANGZHOU QULIAN TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-27
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

Existing anonymous communication systems cannot effectively resist traffic analysis attacks, which can lead to the restoration of the communication path between the client and the server, thus compromising anonymity and confidentiality.

Method used

By generating a blockchain-based list of intermediate network nodes, a first and second link are constructed. By utilizing the information transmission timing and encryption mechanism of the intermediate network nodes, the client's identity information is hidden, increasing the difficulty of reconstructing the communication path.

Benefits of technology

It effectively hides the client's identity under traffic analysis attacks, improves communication anonymity, resists traffic analysis attacks, and ensures the confidentiality and anonymity of communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115913654B_ABST
    Figure CN115913654B_ABST
Patent Text Reader

Abstract

The application belongs to the field of communication, and particularly relates to an anonymous communication method, a terminal device and a computer readable storage medium. The method comprises the following steps: a first network node receives first anonymous information sent by a first client, and acquires a list of intermediate network nodes on a preset block chain; based on the list of intermediate network nodes, a first link is generated; based on the first link, the first anonymous information is sent to a server, and a second anonymous message fed back by the server through a second network node based on a second link is received. Under the attack of traffic analysis, the difficulty of restoring the entire path of the first link and the second link can be improved, the attack of traffic analysis can be resisted, and the anonymity of communication can be ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of communications, and in particular relates to an anonymous communication method, apparatus, terminal equipment, and storage medium. Background Technology

[0002] Currently, people desire communication systems that ensure communication quality while also guaranteeing message confidentiality and user anonymity. Confidentiality means that the content of a sent message cannot be known by others; therefore, only by ensuring confidentiality can personal privacy be protected. Anonymity means that the identities of the communicating parties cannot be obtained from outside sources; in most scenarios, users do not want to reveal who they are communicating with. Clearly, only by guaranteeing anonymity can a large number of relatively confidential online applications (apps) be supported. Therefore, people are now increasingly using anonymous communication systems.

[0003] Existing anonymous communication systems use the Onion routing protocol to encrypt message content and routing nodes layer by layer, ensuring that intermediate routing nodes cannot know which server the client is communicating with. However, under traffic analysis attacks, it is still possible to deduce which server the client is communicating with based on network-wide traffic analysis, making them unable to resist traffic analysis attacks. Summary of the Invention

[0004] This application provides an anonymous communication method, terminal device, and computer-readable storage medium that can resist traffic analysis attacks and ensure the confidentiality of privacy during communication.

[0005] In a first aspect, embodiments of this application provide an anonymous communication method applied to a first network node connected to a first client, the method comprising:

[0006] Receive the first anonymous information sent by the first client and obtain a list of intermediate network nodes on the preset blockchain;

[0007] Based on the list of intermediate network nodes, a first link is generated, which is used to indicate each of the intermediate network nodes and the information transmission timing corresponding to the intermediate network node when sending information.

[0008] The first anonymous information is sent to the server via the first link, and the second anonymous information is received from the server via the second network node via the second link; the second link is used to indicate the timing of information transmission for each intermediate network node when replying to the information.

[0009] The information transmission timing is used to indicate the time point at which the intermediate network node transmits anonymous information.

[0010] In one possible implementation of the first aspect, after generating the first link based on the list of intermediate network nodes, the method further includes:

[0011] Based on the list of intermediate network nodes, a first message packet corresponding to the first anonymous information is constructed. The first message packet includes a first message header and a first message body. The first message header includes the first link, and the first message body includes the first anonymous information; or...

[0012] After obtaining the list of intermediate network nodes on the preset blockchain, the method further includes:

[0013] Based on the list of intermediate network nodes, the first link and the second link are generated;

[0014] Accordingly, after generating the first link and the second link based on the list of intermediate network nodes, the method further includes:

[0015] Based on the list of intermediate network nodes, a second message packet corresponding to the first anonymous information is constructed. The second message packet includes a second message header and a second message body. The second message header includes the first link, and the second message body includes the first anonymous information and the second link.

[0016] In one possible implementation of the first aspect, constructing the first message packet corresponding to the first anonymous information based on the list of intermediate network nodes includes:

[0017] Based on the public keys of the intermediate network nodes included in the first link, the first anonymous information, the node addresses of the intermediate network nodes in the first link, and the information transmission timing are encrypted to obtain the first message packet; or,

[0018] The step of constructing the second message packet corresponding to the first anonymous information based on the list of intermediate network nodes includes:

[0019] Based on the public key of the intermediate network node included in the first link, the first anonymous information, the node address of the intermediate network node of the first link, the information transmission timing, and the second link are encrypted to obtain the second message packet.

[0020] In one possible implementation of the first aspect, sending the first anonymous information to the server based on the first link includes:

[0021] The first message packet or the second message packet is sent to the intermediate network node in the first link at a preset information sending time.

[0022] The first message packet or the second message packet is decrypted based on the private key of the intermediate network node in the first link;

[0023] Accordingly, during the decryption process, each of the intermediate network nodes decrypts the first message header or the second message header based on its private key to obtain the node address of the next intermediate network node and the information transmission timing for transmitting the sent message body to the next intermediate network node.

[0024] Based on the node address of the next intermediate network node and the timing of transmitting the message body to the next intermediate network node, the first message packet or the second message packet is transmitted to the next intermediate network node.

[0025] The first anonymous information is sent to the server by the second network node after the second network node decrypts the first message header or the second message header based on the private key to obtain the first anonymous information in the decrypted first message body or the second message body.

[0026] In one possible implementation of the first aspect, the method further includes:

[0027] Upon receiving the first anonymous message sent by the first client, the system also receives an anonymous message of a preset type sent by the second client.

[0028] Based on the first link, send the preset type of anonymous message to the server;

[0029] The preset type of anonymous message is used to instruct the server to discard the anonymous message based on the preset type when it receives the anonymous message.

[0030] In one possible implementation of the first aspect, the method further includes:

[0031] If the sum of the time points at which the intermediate network nodes of the first link transmit the first anonymous information is greater than a preset first threshold, then the first anonymous information is retransmitted to the second network node connected to the server based on the first link, and the second anonymous information fed back by the server through the second network node based on the second link is received.

[0032] Secondly, embodiments of this application provide an anonymous communication method applied to a second network node connected to a server, the method comprising:

[0033] Obtain the first anonymous information sent by the first client through the first network node based on the first link;

[0034] Send the first anonymous information to the server and receive the second anonymous information from the server.

[0035] The second anonymous information is fed back to the first client via the second link;

[0036] Wherein, the first link and the second link are generated based on a list of intermediate network nodes on a preset blockchain; the first link is used to indicate each of the intermediate network nodes and the corresponding information transmission timing when sending information; the second link is used to indicate each of the intermediate network nodes and the corresponding information transmission timing when replying to information; the information transmission timing is used to indicate the time point at which the intermediate network node transmits anonymous information.

[0037] In one possible implementation of the second aspect, before feeding back the second anonymous information to the first client based on the second link, the method further includes:

[0038] Obtain a list of intermediate network nodes on a preset blockchain, and generate the second link based on the list of intermediate network nodes; or,

[0039] Obtain the second link sent by the first client through the first network node based on the first link.

[0040] In one possible implementation of the second aspect, before feeding back the second anonymous information to the first client based on the second link, the method further includes:

[0041] Based on the second link, a third message packet corresponding to the second anonymous information is constructed, the third message packet including a third message header and a third message body;

[0042] Accordingly, based on the second link, a third message packet corresponding to the second anonymous information is constructed, including:

[0043] The node address and information transmission timing of the intermediate network node of the second link are encrypted based on the public key of the intermediate network node of the second link to obtain the third message header.

[0044] The third message body is encrypted using the public key of the first network node, and the third message body includes the second anonymous information;

[0045] Accordingly, the step of feeding back the second anonymous information to the first client based on the second link includes:

[0046] Send the third message packet to the intermediate network node of the second link;

[0047] The third message packet is decrypted based on the private key of the intermediate network node of the second link;

[0048] Accordingly, during the decryption process, each of the intermediate network nodes decrypts the third message header based on its private key to obtain the node address of the next intermediate network node and the information transmission timing for transmitting the third message packet to the next intermediate network node.

[0049] Based on the node address of the next intermediate network node and the timing of transmitting the third message packet to the next intermediate network node, the third message packet is transmitted to the next intermediate network node.

[0050] The process continues until the first network node decrypts the third message body using its private key, obtains the second anonymous information in the decrypted third message body, and then sends the second anonymous information to the client through the first network node.

[0051] Thirdly, embodiments of this application provide an anonymous communication device, the device comprising:

[0052] The receiving module is used to receive the first anonymous information sent by the first client and obtain a list of intermediate network nodes on the preset blockchain;

[0053] The generation module is used to generate a first link based on the list of intermediate network nodes. The first link is used to indicate each of the intermediate network nodes and the information transmission timing corresponding to the intermediate network node when sending information.

[0054] The sending module is used to send the first anonymous information to the server based on the first link, and to receive the second anonymous information fed back by the server through the second network node based on the second link; the second link is used to indicate each of the intermediate network nodes and the information transmission timing corresponding to the intermediate network node when replying to the information.

[0055] The information transmission timing is used to indicate the time point at which the intermediate network node transmits anonymous information.

[0056] Fourthly, embodiments of this application provide an anonymous communication device, the device comprising:

[0057] The acquisition module is used to acquire the first anonymous information sent by the first client through the first network node based on the first link;

[0058] The processing module is used to send the first anonymous information to the server and receive the second anonymous information fed back by the server.

[0059] The feedback module is used to send the second anonymous information back to the first client via the second link;

[0060] Wherein, the first link and the second link are generated based on a list of intermediate network nodes on a preset blockchain; the first link is used to indicate each of the intermediate network nodes and the corresponding information transmission timing when sending information; the second link is used to indicate each of the intermediate network nodes and the corresponding information transmission timing when replying to information; the information transmission timing is used to indicate the time point at which the intermediate network node transmits anonymous information.

[0061] Fifthly, embodiments of this application provide a terminal device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the anonymous communication method as described in either the first aspect or the second aspect.

[0062] In a sixth aspect, embodiments of this application provide a computer-readable storage medium storing a computer program, characterized in that the computer program, when executed by a processor, implements the anonymous communication method as described in either the first aspect or the second aspect.

[0063] The beneficial effects of this application embodiment compared with the prior art are as follows: In this application, a first anonymous message sent by a first client is received through a first network node, and a list of intermediate network nodes on a preset blockchain is obtained; a first link is generated based on the list of intermediate network nodes; the first anonymous message is sent to the server based on the first link, and the second anonymous message fed back by the server through a second network node based on the second link is received. That is, by setting the intermediate network nodes in the first and second links and the corresponding information transmission timing of the intermediate network nodes, the client's identity information can be hidden, and the difficulty of restoring the first and second links under traffic analysis attacks can be increased, thus resisting traffic analysis attacks and ensuring the anonymity of communication; it has strong ease of use and practicality. Attached Figure Description

[0064] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0065] Figure 1 This is a schematic diagram of an anonymous communication system provided in an embodiment of this application;

[0066] Figure 2a This is a schematic flowchart illustrating an anonymous communication method provided in an embodiment of this application;

[0067] Figure 2b This is an example diagram of a first link and a second link provided in an embodiment of this application;

[0068] Figure 2c This is an example diagram of a message packet provided in an embodiment of this application;

[0069] Figure 2d This is an example diagram of another message packet provided in an embodiment of this application;

[0070] Figure 3a This is a schematic flowchart illustrating a method for sending first anonymous information provided in an embodiment of this application;

[0071] Figure 3b This is an example diagram illustrating the decryption of a message packet according to an embodiment of this application;

[0072] Figure 3c This is another example diagram of decrypting message packets provided in the embodiments of this application;

[0073] Figure 4 This is a schematic flowchart illustrating another anonymous communication method provided in an embodiment of this application;

[0074] Figure 5 This is a schematic flowchart illustrating a method for providing feedback of second anonymous information according to an embodiment of this application;

[0075] Figure 6 This is an example diagram of the message packet used to reply to information provided in the embodiments of this application;

[0076] Figure 7 This is a schematic diagram of the structure of an anonymous communication device provided in an embodiment of this application;

[0077] Figure 8 This is a schematic diagram of another anonymous communication device provided in an embodiment of this application;

[0078] Figure 9 This is a schematic diagram of the structure of a terminal device provided in an embodiment of this application. Detailed Implementation

[0079] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application can also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods are omitted so as not to obscure the description of this application with unnecessary detail. In other instances, specific technical details in various embodiments can be referred to mutually, and specific systems not described in one embodiment can be referred to in other embodiments.

[0080] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.

[0081] It should also be understood that the term “and / or” as used in this application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.

[0082] References to "embodiments of this application" or "some embodiments" in this specification mean that one or more embodiments of this application include specific features, structures, or characteristics described in connection with that embodiment. Therefore, phrases such as "in other embodiments," "an embodiment of this application," and "other embodiments of this application" appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.

[0083] Furthermore, in the description of this application and the appended claims, the terms "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0084] Existing anonymous communication systems use the Onion routing protocol to encrypt message content and routing nodes layer by layer, preventing intermediate routing nodes from knowing which server the client is communicating with. However, under a full network traffic analysis attack, the system can deduce which server the client is communicating with based on the full network traffic analysis, reconstruct the communication path between the client and the server, and is therefore unable to resist traffic analysis attacks.

[0085] To address the aforementioned deficiencies, the inventive concept of this application is as follows:

[0086] This application can receive the first anonymous information sent by the first client through a first network node connected to the first client, and obtain a list of intermediate network nodes on a preset blockchain to generate a first link. The first link includes the information transmission timing, which is used to indicate the time point when the intermediate network node transmits anonymous information. This can hide the identity information of the first client. Under traffic analysis attacks, it increases the difficulty of restoring the first link and the second link, resists traffic analysis attacks, and ensures the anonymity of communication.

[0087] To illustrate the technical solution of this application, specific embodiments are described below.

[0088] Please refer to Figure 1 , Figure 1 This is a schematic diagram of an anonymous communication system provided in one embodiment of this application. For ease of explanation, only the parts relevant to this application are shown. The communication system is a blockchain-based distributed system, which includes, but is not limited to: a first client 10, a first network node 20, multiple intermediate network nodes 30, a second network node 40, a server 50, a second client 60, and a blockchain 70.

[0089] The first client 10, server 50, and second client 60 can be data communication devices based on blockchain 70 with data processing capabilities, such as terminal devices, servers, etc. Terminal devices include, but are not limited to, mobile phones, computers, smart voice interaction devices, smart home appliances, vehicle terminals, aircraft, etc.; servers can be independent physical servers, server clusters or distributed systems composed of multiple physical servers, or cloud servers providing cloud computing services, but are not limited thereto. Terminal devices and servers can be directly or indirectly connected via wired or wireless communication, and this application does not impose any restrictions on this connection.

[0090] The first network node 20, multiple intermediate network nodes 30, and the second network node 40 are peers and can be computing devices that access the network in any form, such as servers or terminal devices.

[0091] The first network node 20 is a proxy network node for the first client 10, used to forward information sent by the first client to the server 50 or to receive information fed back from the server 50 to the first client 10. The second network node 40 is a proxy network node for the server 50, used to receive information sent by the first client to the server 50 or to forward information fed back from the server 50 to the first client 10.

[0092] Multiple intermediate network nodes 30 can also be proxy network nodes for other clients or servers, used to forward information sent by other clients or servers, or to receive information fed back to other clients or servers.

[0093] Multiple intermediate network nodes (30 network nodes) form a peer-to-peer (P2P) network. The P2P protocol is an application layer protocol running on top of the Transmission Control Protocol (TCP). In a blockchain-based distributed system, any computing device, such as a server or terminal device, can join and become a network node. Network nodes include a hardware layer, a middleware layer, an operating system layer, and an application layer.

[0094] Upon startup, the first network node 20, multiple intermediate network nodes 30, and the second network node 40 register with blockchain 70. Blockchain 70 consists of a series of blocks sequentially generated in chronological order. Once a new block is added to blockchain 70, it is never removed. The blocks record the node address (Internet Protocol, IP), port, public key, and service information provided by each network node registered at startup within the distributed system based on blockchain 70.

[0095] Each block in Blockchain 70 includes the hash value of the interaction records stored in that block, as well as the hash value of the previous block. These blocks are linked together using their hash values ​​to form Blockchain 70. Additionally, blocks may include information such as a timestamp when they were generated. Essentially, Blockchain 70 is a decentralized database, a chain of data blocks linked using cryptographic methods. Each data block contains relevant information used to verify the validity of that information and to generate the next block.

[0096] In this embodiment of the application, when the first client 10 and the second client 60 send information to the server 50 through the first network node 20, the first network node 20 selects a first link, which includes multiple intermediate network nodes 30 and a second network node 40. Therefore, the second network node 40 can also be referred to as an intermediate network node between the first network node 20 and the server 50.

[0097] Both the first network node and the second network node can select the second link. The server 50 feeds back information to the first client 10 and the second client 60 through the second network node 40 based on the second link. The second link includes multiple intermediate network nodes 30 and the first network node 20. Therefore, the first network node 20 can also be called an intermediate network node between the second network node 40 and the first client 10.

[0098] In summary, when the first client sends anonymous information to the first server using the anonymity system of this application, it can forward the message through the proxy gateway node (first network node) of the first client. The first network node selects a first link, which includes multiple intermediate network nodes and the proxy gateway node (second network node) of the first server. The first network node or the second network node selects a second link. The server then uses the second network node to send information back to both the first and second clients based on the second link. During network-wide traffic analysis, even if the first and second links are reconstructed, the identity information of the first client and the first server cannot be determined, thus ensuring the anonymity of the communication. In other embodiments, it may include... Figure 1 The examples shown have more or fewer parts, or combine certain parts, or have different parts. Figure 1 This is merely an illustrative description and should not be construed as a specific limitation of this application. For example, it may also include memory, etc.

[0099] Please refer to Figure 2a , Figure 2a This is a schematic flowchart of an anonymous communication method provided in an embodiment of this application. Figure 2a The execution entity of the method in the middle can be Figure 1 The first network node in the network. For example... Figure 2a As shown, the method includes: S201 to S203.

[0100] S201. The first network node receives the first anonymous information sent by the first client and obtains a list of intermediate network nodes on the preset blockchain.

[0101] Specifically, the list of intermediate network nodes includes the node address, node port, node public key, and service information provided by each intermediate network node.

[0102] The node address IP refers to the network interconnection protocol. The first network node can interconnect with intermediate network nodes based on the IP of the intermediate network nodes.

[0103] A node port is not a computer hardware I / O port, but a software concept. In this embodiment, the network nodes communicate with each other using the TCP protocol. That is, after sending information, it is necessary to confirm whether the information has arrived. The node port corresponds to the port provided by the TCP protocol service, i.e., the TCP port.

[0104] In this embodiment, each network node obtains a key pair (i.e., a public key and a private key) through an encryption algorithm. Each network node registers its public key in the blockchain and stores its private key. The key pair obtained through the encryption algorithm is guaranteed to be unique worldwide. When using this key pair, if data is encrypted with one key, it must be decrypted with the other key. For example, if data is encrypted with the public key, it must be decrypted with the private key. In this embodiment, anonymous information is encrypted using the public key and decrypted using the private key. In this embodiment, the encryption algorithm includes symmetric encryption algorithms and asymmetric encryption algorithms, etc., and this embodiment does not limit the specific algorithms used.

[0105] In this embodiment of the application, the service information provided by the node includes the user's personal information, transaction records, etc.

[0106] The term "first" in the first client and first anonymous information in this application embodiment is used only to distinguish the client and anonymous information from those in other embodiments, and should not be construed as indicating or implying relative importance.

[0107] In this embodiment of the application, in order to hide the identity information of the first client, when the first client sends the first anonymous information to the server, it does not send it directly to the server through the first client, but forwards it through the first network node connected to the first client. The first network node selects the transmission path for sending the first anonymous message based on the list of intermediate network nodes on the preset blockchain. In this way, even if the transmission path constructed by the first network node is restored under the attack of full network traffic analysis, the identity information of the first client cannot be obtained, thus ensuring the anonymity of communication.

[0108] S202. The first network node generates the first link based on the list of intermediate network nodes.

[0109] In this embodiment, the first link includes at least one intermediate network node and the information transmission timing corresponding to the intermediate network node. The information transmission timing is used to indicate the time point when the intermediate network node transmits information. The first link refers to the path through which the first network node sends the first anonymous information to the server, and is used to indicate the first link of each intermediate network node and the information transmission timing corresponding to the intermediate network node when sending information.

[0110] In some embodiments, after the first network node obtains a list of intermediate network nodes on a preset blockchain, the method further includes:

[0111] Based on the list of intermediate network nodes, generate the first link and the second link.

[0112] The second link includes at least one intermediate network node and the information transmission timing corresponding to the intermediate network node, which is used to indicate the information transmission timing of each intermediate network node and the corresponding intermediate network node when replying to information.

[0113] For example, please refer to Figure 2b , Figure 2b This is an example diagram of a first link and a second link provided in an embodiment of this application.

[0114] The first link includes intermediate network nodes B, C, D, E, and a second network node F. When the first client sends the first anonymous information to the server, it first sends the first anonymous information to the first network node A at a preset information sending time (for example, any time between 0 and 60 seconds, such as a 5-second delay). A is used to forward the first anonymous information. Node A selects B, C, D, E, and F from the list of intermediate network nodes as the first link. After receiving the first anonymous information, node B sends the first anonymous information to C after a preset time b (the information transmission time corresponding to node B). After receiving the first anonymous information, node C sends the first anonymous information to D after a preset time c (the information transmission time corresponding to node C). After receiving the first anonymous information, node D sends the first anonymous information to E after a preset time d (the information transmission time corresponding to node D). After receiving the first anonymous information, node E sends the first anonymous information to F after a preset time e (the information transmission time corresponding to node E). After receiving the first anonymous information, node F sends the first anonymous information to the server after a preset time f (the information transmission time corresponding to node F).

[0115] In this embodiment, the second link refers to the path through which the server sends feedback to the first server that it has received the first anonymous information. The second link includes at least one intermediate network node and the information transmission timing corresponding to the intermediate network node. In this embodiment, the information that sends feedback to the first server that the first anonymous information has been received is referred to as the second anonymous information.

[0116] For example, the second link includes a second network node F, intermediate network nodes G, H, I, J, and a first network node A. Node A selects B, C, D, E, and F from the list of intermediate network nodes as the first link, and simultaneously selects F, G, H, I, J, and A as the second link.

[0117] When the server sends the second anonymous information to the first client, it first sends the second anonymous information to the second network node F at a preset information sending time (for example, any time between 0 and 60 seconds, such as a 5-second delay). F forwards the second anonymous information. After receiving the second anonymous information, node F sends the second anonymous information to G after a preset time f (the information transmission time corresponding to node F). After receiving the second anonymous information, node G sends the second anonymous information to H after a preset time g (the information transmission time corresponding to node G). After receiving the second anonymous information, node H sends the second anonymous information to I after a preset time h (the information transmission time corresponding to node H). After receiving the second anonymous information, node I sends the second anonymous information to J after a preset time i (the information transmission time corresponding to node I). After receiving the second anonymous information, node J sends the second anonymous information to the first network node A after a preset time j (the information transmission time corresponding to node J). After receiving the second anonymous information, the first network node A forwards the second anonymous information to the first client after a preset time a (the information transmission time corresponding to node A).

[0118] It should be noted that the first network node is at least one intermediate network node randomly selected from the list of intermediate network nodes as the first link or the second link. When randomly selecting an intermediate network node as the first link or the second link, since the first client sends the first anonymous information through the first network node, and the server sends the second anonymous information through the second network node, and this intermediate network node may also serve as an intermediate network node in the first or second link between other clients and servers, the existence of only one intermediate network node and setting a random delay time for its transmission can still improve the confidentiality of anonymous communication and ensure the anonymity of the communication mechanism because it is not easy to determine which client or server the transmission timing of this intermediate network node corresponds to.

[0119] When the first network node randomly selects multiple intermediate network nodes as the first or second link, such as five, it can ensure better anonymity in communication while also ensuring higher efficiency in information transmission.

[0120] In this embodiment, when the client's address is unknown to the server, both the first link and the second link can be generated by the first network node; when the server knows the client's address, the second link can also be generated by the second network node connected to the server. When both the first link and the second link are generated by the first network node, the preset delay time of each intermediate network node is determined by the first network node.

[0121] Accordingly, when the second link is generated by the second network node, the preset time of the delay of each intermediate network node in the second link is determined by the second network node.

[0122] In this embodiment, the information transmission timing corresponding to each intermediate network node is within a first numerical range, for example, the first numerical range is (0, 60) seconds. The information transmission timing corresponding to each intermediate network node may be the same or different, and this embodiment does not limit this.

[0123] In this embodiment of the application, after generating the first link based on the list of intermediate network nodes, the first message packet corresponding to the first anonymous information is constructed according to the list of intermediate network nodes.

[0124] Specifically, the first message packet includes a first message header and a first message body encrypted with the public key of an intermediate network node. The first message header may include a first link, and the first message body may include first anonymous information.

[0125] In this embodiment of the application, when constructing the first message packet corresponding to the first anonymous information, the first anonymous information, the node address of the second network node, and the information transmission timing corresponding to the second network node are repeatedly encrypted based on the public key of the second network node in the first link.

[0126] Specifically, the first network node can encrypt anonymous information twice, based on the public key of the second network node, the node address of the second network node, and the information transmission timing corresponding to the second network node.

[0127] In this embodiment, the double encryption using the public key of the second network node is to enable the second network node to determine that the first network node is sending the first anonymous information to the second network node acting as a proxy for the server. Specifically, when the second network node first decrypts the first message packet using its private key, it obtains the node address for transmitting information to the next network node. If the second network node finds that the node address for transmitting information to the next network node is still its own node address, then the second network node determines that the first message packet was sent to it, and decrypts the first message body in the first message packet based on its private key to obtain the first anonymous information.

[0128] For example, please refer to Figure 2c , Figure 2c This is an example diagram of an information packet provided in an embodiment of this application.

[0129] exist Figure 2cIn the first message packet, there are a first message header and a first message body. The first message header includes: the node addresses of nodes B, C, D, E, and F, encrypted using their respective public keys, and the information transmission times b, c, d, e, and f for nodes B, C, D, E, and F respectively. Specifically, F and f are encrypted twice using node F's public key.

[0130] The first message body includes the first anonymous message.

[0131] In this embodiment, the first network node generates the first link based on a list of intermediate network nodes, instead of the first client generating the first link based on a list of intermediate network nodes. Under attacks involving full network traffic analysis, the client's identity information can be hidden, ensuring the anonymity of communication.

[0132] In this embodiment of the application, after generating the first link and the second link based on the list of intermediate network nodes, the second message packet corresponding to the first anonymous information is constructed according to the list of intermediate network nodes.

[0133] Specifically, the second message packet includes a second message header and a second message body encrypted with the public key of the intermediate network node. The second message header includes a first link, and the second message body includes a first anonymous message and a second link.

[0134] For example, please refer to Figure 2d , Figure 2d This is an example diagram of another message packet provided in an embodiment of this application.

[0135] exist Figure 2d The second message packet includes a second message header and a second message body. The second message header includes:

[0136] The node addresses of nodes B, C, D, E, and F in the first link are encrypted using their respective public keys, along with the respective information transmission times b, c, d, e, and f for nodes B, C, D, E, and F. Specifically, F and f are encrypted twice using node F's public key.

[0137] The second message body includes: first anonymous information encrypted with the public keys of nodes F, G, H, I, J, and A in the second link; node addresses of nodes F, G, H, I, J, and A; and transmission times f, g, h, i, j, and a for nodes F, G, H, I, J, and A, respectively.

[0138] In this embodiment, the first network node generates the first link and the second link based on the list of intermediate network nodes, instead of the first client generating the first link and the second link based on the list of intermediate network nodes. Under attacks involving full network traffic analysis, the client's identity information can be hidden, ensuring the anonymity of communication.

[0139] S203, the first network node sends first anonymous information to the second network node connected to the server based on the first link, and receives second anonymous information fed back by the server through the second network node based on the second link.

[0140] Specifically, the first message packet or the second message packet sent to the second network node connected to the server based on the first link contains the first anonymous information (such as...). Figure 2c or Figure 2d (The message packet architecture shown) During the transmission process, the network nodes in the first link parse the first message packet or the second message packet, and decrypt it layer by layer using their respective private keys. The second network node can then obtain the first anonymous information and forward it to the server. Correspondingly, when the second message packet is being transmitted, after layer by layer decryption, the second network node can also obtain the first anonymous information and the second link, and can feed back the second anonymous information to the first network node based on the second link.

[0141] Please refer to Figure 3a , Figure 3a This is a schematic flowchart illustrating a method for sending first anonymous information provided in an embodiment of this application. Figure 3a The execution entity of the method in the middle can be Figure 1 The first network node in the network. For example... Figure 3a As shown, the method includes: S301 to S303.

[0142] S301, the first network node sends a first message packet or a second message packet to the intermediate network node in the first link at a preset information sending time.

[0143] Specifically, the specific settings for the preset information sending time have been described in the above embodiments and will not be repeated here.

[0144] This application embodiment uses message packets sent at preset information sending times to make it more difficult for attackers to analyze which network node is the sender when performing traffic analysis. This can resist traffic analysis attacks and ensure the anonymity of communication.

[0145] S302, the first network node decrypts the first message packet or the second message packet based on the private key of the intermediate network node in the first link; during the decryption process, each intermediate network node decrypts the first message header or the second message header based on its private key to obtain the node address of the next intermediate network node and the information transmission timing for transmitting the first message packet or the second message packet to the next intermediate network node.

[0146] Specifically, since the message body is encrypted using the public key of the intermediate network node in the first link, it can be decrypted using the private key of the intermediate network node in the first link.

[0147] During the decryption process, each intermediate network node in the first link decrypts the first message header based on its own private key to obtain the node address of the next intermediate network node and the information transmission timing for transmitting message packets to the next intermediate network node.

[0148] For example, please refer to Figure 3b , Figure 3b This is an example diagram illustrating the decryption of message packets provided in an embodiment of this application. Figure 3b The example used is the first message body including the first anonymous information.

[0149] Figure 3b N1 in the original text refers to the first message packet sent at the beginning.

[0150] Figure 3b In the first link, N2 is an intermediate network node B that decrypts the first message header using its private key to obtain the node address of intermediate network node C and the information transmission timing c for transmitting the message packet to intermediate network C. The decryption methods for other intermediate network nodes are the same as those described above, and will not be repeated here.

[0151] Figure 3b N3 in the text is the first message body after decryption.

[0152] For example, please refer to Figure 3c , Figure 3c This is another example diagram of decrypting message packets provided in the embodiments of this application. Figure 3c The second message body includes: first anonymous information encrypted with the public keys of nodes F, G, H, I, J, and A in the second link; node addresses of nodes F, G, H, I, J, and A; and transmission times f, g, h, i, j, and a of nodes F, G, H, I, J, and A, respectively, as illustrated by examples.

[0153] Figure 3c M1 in the packet is the second message packet sent at the beginning.

[0154] Figure 3c In this context, M2 represents intermediate network node B in the first link decrypting the first message header using its private key to obtain the node address of intermediate network node C and the information transmission timing c for transmitting the message packet to intermediate network C. The decryption methods for other intermediate network nodes are the same as described above and will not be repeated here.

[0155] Figure 3c M3 in the text is the decrypted second message body.

[0156] S303. The first network node transmits the first message packet or the second message packet to the next intermediate network node based on the node address of the next intermediate network node and the information transmission timing for transmitting the first message packet or the second message packet to the next intermediate network node; until the second network node decrypts the first message header or the second message header based on the private key to obtain the first anonymous information in the decrypted first message body or the second message body, and sends the first anonymous information to the server through the second network node.

[0157] For example, refer to Figure 3b In the first link, N3 is the last network node, which is the second network node F. The second network node F decrypts the first message header using its private key to obtain the decrypted first message body, which includes the first anonymous information. See also: Figure 3c In M3, the last network node in the first link is the second network node F. The second network node F decrypts the second message header based on F's private key to obtain the decrypted second message body, which includes the first anonymous information and the second link.

[0158] Specifically, when the first network node transmits the message packet to the second network node, the second network node decrypts it to obtain the first anonymous information, and then forwards the first anonymous information to the server.

[0159] In this embodiment, to increase the difficulty of reconstructing the paths of the first and second links under a full network traffic analysis attack, upon receiving the first anonymous information sent by the first client, an anonymous message of a preset type sent by the second client is also received. Based on the first link, an anonymous message of the preset type is sent to the server.

[0160] Among them, the preset type of anonymous message is used to instruct the server to discard the anonymous message based on the preset type when it receives it.

[0161] Specifically, the preset type of anonymous message is either obfuscated anonymous information or blank anonymous information. In this embodiment, to prevent network-wide traffic analysis from reconstructing the path of the first or second link, an idle second client sends obfuscated or blank anonymous information to the server via the first link selected by the first network node. The server automatically discards the obfuscated or blank anonymous information received. During network-wide traffic analysis, attackers cannot distinguish between real and obfuscated data, increasing the difficulty of reconstructing the first or second link path and ensuring the anonymity of communication.

[0162] In this embodiment of the application, in order to prevent the first anonymous information from being lost in the first link, when sending... Figure 2c When sending message packets, the anonymous communication method in this application embodiment further includes:

[0163] If the sum of the time points at which intermediate network nodes of the first link transmit the first anonymous information is greater than a preset first threshold, then the first anonymous information is retransmitted to the second network node connected to the server based on the first link, and the second anonymous information fed back by the server through the second network node based on the second link is received.

[0164] Specifically, when the message packet is transmitted in the first link, the first network node calculates the sum of the time points of the information transmitted by the intermediate network nodes in the first link. If the sum of the time points of the intermediate network nodes in the first link is greater than a preset first threshold, for example, if the sum of the time points of the information transmitted by the intermediate network nodes in the first link is greater than twice the preset sum of the time points of the information transmitted by the intermediate network nodes in the first link, then the first network node re-sends the message packet containing the first anonymous information to the second network node connected to the server based on the first link, and receives the second anonymous information fed back by the server through the second network node based on the second link.

[0165] Sending Figure 2d When sending message packets, the anonymous communication method in this application embodiment further includes:

[0166] If the sum of the time points at which intermediate network nodes of the first link and the second link transmit the first anonymous information is greater than a preset second threshold, then the first anonymous information is retransmitted to the second network node connected to the server based on the first link, and the second anonymous information fed back by the server through the second network node based on the second link is received.

[0167] Specifically, the first network node calculates the sum of the time points of information transmission between intermediate network nodes in the first and second links when the message packet is transmitted in the first and second links. If the sum of the time points of information transmission between intermediate network nodes in the first and second links is greater than a preset second threshold, for example, if the sum of the time points of information transmission between intermediate network nodes in the first and second links is greater than twice the preset sum of the time points of information transmission between intermediate network nodes, then the first anonymous information is resent to the second network node connected to the server based on the first link, and the second anonymous information fed back by the server through the second network node based on the second link is received.

[0168] In summary, the technical solution of this application is applied to a first network node connected to a first client. The first network node receives first anonymous information sent by the first client and obtains a list of intermediate network nodes on a preset blockchain. Based on the list of intermediate network nodes, a first link is generated. Based on the first link, the first anonymous information is sent to the server, and second anonymous information is received from the server through a second network node. That is, the first network node connected to the first client receives anonymous information sent by the first client and obtains a list of intermediate network nodes on a preset blockchain. Based on the list of intermediate network nodes, a first link is generated. The first link includes information transmission timing to indicate the time point when the intermediate network nodes transmit anonymous information. This can hide the client's identity information and increase the difficulty of restoring the first and second links under traffic analysis attacks, thus resisting traffic analysis attacks and ensuring the anonymity of communication.

[0169] Please refer to Figure 4 , Figure 4 This is a schematic flowchart illustrating another anonymous communication method provided in the embodiments of this application. Figure 4 The execution entity of the method in the middle can be Figure 1 The second network node in the network. For example... Figure 4 As shown, the method includes: S401 to S403.

[0170] S401, The second network node obtains the first anonymous information sent by the first client through the first network node based on the first link.

[0171] Specifically, the second network node decrypts the received message packet using its own private key to obtain the first anonymous information, which can be found in [reference needed]. Figure 3b N3 or Figure 3c M3 in the middle.

[0172] S402, the second network node sends the first anonymous information to the server and receives the second anonymous information from the server.

[0173] Specifically, the second network node is a proxy network node on the server side, used to forward information sent from the client to the server, or to forward information fed back from the server to the client.

[0174] S403, the second network node feeds back the second anonymous information to the first client based on the second link.

[0175] Specifically, the first link can be generated by the first network node based on a list of intermediate network nodes on a preset blockchain, and the second link can be generated by either the first network node or the second network node based on a list of intermediate network nodes on a preset blockchain. The first and second links each include at least one intermediate network node and the corresponding information transmission timing for that intermediate network node; the information transmission timing indicates the time point at which the intermediate network node transmits anonymous information.

[0176] The method by which the second network node generates the second link is the same as the method by which the first network node generates the first link, and will not be described again here.

[0177] In summary, the technical solution of this application is applied to a second network node connected to the server. The second network node obtains the first anonymous information sent by the first client through the first network node based on the first link, sends the first anonymous information to the server, and receives the second anonymous information fed back by the server. The second network node obtains a list of intermediate network nodes on a preset blockchain, and generates a second link based on the list of intermediate network nodes. It then feeds back the second anonymous information to the first client based on the second link. That is, when the server receives the first anonymous information sent by the first client, it can send the feedback second anonymous information to the second network node. The second network node is used to forward the second anonymous information. The second network node feeds back the second anonymous information to the first client based on the second link selected by the second network node. The information transmission timing is used to indicate the time point when the intermediate network node transmits the anonymous information. This can ensure that when the server and client communicate, it is impossible to know whether the client and the server are communicating. It can resist the traffic analysis of the entire network and ensure the privacy of the communication process between the client and the server.

[0178] Please refer to Figure 5 , Figure 5 This is a schematic flowchart illustrating another anonymous communication method provided in the embodiments of this application. Figure 5 The execution entity of the method in the middle can be Figure 1 The second network node in the network. For example... Figure 5 As shown, the method includes: S501 to S504.

[0179] S501, the second network node constructs a third message packet corresponding to the second anonymous information based on the second link.

[0180] Specifically, the third message packet may include a third message header and a third message body. The third message header may include the node address of the intermediate network node in the second link and the information transmission timing, which are encrypted based on the public key of the intermediate network node in the second link. The third message body may include second anonymous information. The third message body may also include the node address of the first network node and the information transmission timing, which are encrypted based on the first network node.

[0181] Accordingly, based on the second link, the third message packet corresponding to the second anonymous information can be constructed, which may include:

[0182] S502. The node address and information transmission timing of the intermediate network node of the second link are encrypted based on the public key of the intermediate network node of the second link to obtain the third message header; the third message body is encrypted based on the public key of the first network node, and the third message body may include second anonymous information.

[0183] For example, please refer to Figure 6 , Figure 6 This is an example diagram of a message packet provided in an embodiment of this application. The message packet may include a third message header and a third message body. The third message header includes the node addresses of nodes F, G, H, I, J, and A, encrypted using their respective public keys in the second link, and the respective transmission times f, g, h, i, j, and a for nodes F, G, H, I, J, and A. The third message body may include second anonymity information and the node address of node A, encrypted using the public key of a first network node, and the transmission time a of node A.

[0184] Accordingly, based on the second link, second anonymous information is fed back to the first client, including:

[0185] S503, the second network node decrypts the third message packet based on the private key of the intermediate network node of the second link; correspondingly, during the decryption process, each intermediate network node decrypts the third message header based on its private key to obtain the node address of the next intermediate network node and the information transmission timing for transmitting the third message packet to the next intermediate network node.

[0186] Specifically, the decryption process for the third message packet follows the same principle as S302, and will not be elaborated here.

[0187] S504, the second network node transmits the third message packet to the next intermediate network node based on the node address of the next intermediate network node and the information transmission timing for transmitting the third message packet to the next intermediate network node; until the first network node decrypts the third message body based on its private key, obtains the second anonymous information in the decrypted third message body, and sends the second anonymous information to the client through the first network node.

[0188] Specifically, when the second network node transmits the reply message body to the first network node, the first network node decrypts it to obtain the second anonymous information and forwards the second anonymous information to the first client. The implementation principle of S504 is the same as that of S303, and will not be repeated here.

[0189] In this embodiment, the second network node constructs a message packet corresponding to the second anonymous information based on the second link. The second network node sends the message packet to the intermediate network node in the second link. The second network node decrypts the message packet based on the private key of the intermediate network node in the second link, and the first network node can then obtain the decrypted second anonymous information. Moreover, if the second link is generated by the first network node, when the server returns the second anonymous information, it does not need to know the identity information of the first client, which is more privacy-friendly for the first client and ensures the anonymity of communication.

[0190] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0191] Please refer to Figure 7 , Figure 7 This is a schematic diagram of the structure of an anonymous communication device provided in an embodiment of this application. The device may include:

[0192] The receiving module 71 is used to receive the first anonymous information sent by the first client and obtain a list of intermediate network nodes on the preset blockchain;

[0193] The generation module 72 is used to generate a first link based on the list of intermediate network nodes. The first link is used to indicate each of the intermediate network nodes and the information transmission timing corresponding to the intermediate network node when sending information.

[0194] The sending module 73 is used to send the first anonymous information to the server based on the first link, and to receive the second anonymous information fed back by the server through the second network node based on the second link; the second link is used to indicate each of the intermediate network nodes and the information transmission timing corresponding to the intermediate network node when replying to the information.

[0195] The information transmission timing is used to indicate the time point at which the intermediate network node transmits anonymous information.

[0196] Please refer to Figure 8 , Figure 8 This is a schematic diagram of another anonymous communication device provided in an embodiment of this application. The device may include:

[0197] The acquisition module 81 is used to acquire the first anonymous information sent by the first client through the first network node based on the first link.

[0198] Processing module 82 is used to send the first anonymous information to the server and receive the second anonymous information fed back by the server.

[0199] Feedback module 83 is used to feed back the second anonymous information to the first client based on the second link;

[0200] Wherein, the first link and the second link are generated based on a list of intermediate network nodes on a preset blockchain; the first link is used to indicate each of the intermediate network nodes and the corresponding information transmission timing when sending information; the second link is used to indicate each of the intermediate network nodes and the corresponding information transmission timing when replying to information; the information transmission timing is used to indicate the time point at which the intermediate network node transmits anonymous information.

[0201] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application. The specific working process of the units and modules in the above system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0202] like Figure 9 As shown, this application embodiment also provides a terminal device 200, including a memory 21, a processor 22, and a computer program 23 stored in the memory 21 and executable on the processor 22. When the processor 22 executes the computer program 23, it implements the anonymous communication methods of the above embodiments.

[0203] The processor 22 can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor.

[0204] The memory 21 can be an internal storage unit of the terminal device 200. The memory 21 can also be an external storage device of the terminal device 200, such as a plug-in hard drive, SmartMedia Card (SMC), Secure Digital (SD) card, or Flash Card equipped on the terminal device 200. Furthermore, the memory 21 can include both internal and external storage units of the terminal device 200. The memory 21 is used to store computer programs and other programs and data required by the terminal device 200. The memory 21 can also be used to temporarily store data that has been output or will be output.

[0205] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the anonymous communication methods described in the above embodiments.

[0206] This application provides a computer program product that, when run on a mobile terminal, enables the mobile terminal to implement the anonymous communication methods described in the above embodiments.

[0207] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable storage medium can include at least: any entity or device capable of carrying computer program code to a photographing device / terminal device, a recording medium, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium. Examples include USB flash drives, portable hard drives, magnetic disks, or optical disks. In some jurisdictions, according to legislation and patent practice, computer-readable storage media cannot be electrical carrier signals or telecommunication signals.

[0208] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0209] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0210] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of the embodiments of this application, depending on actual needs.

[0211] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.

Claims

1. An anonymous communication method characterized by comprising: The method applied to a first network node connected with a first client comprises: receiving first anonymous information sent by the first client, and obtaining a list of intermediate network nodes on a preset blockchain; generating a first link based on the list of intermediate network nodes, the first link being used to indicate the intermediate network nodes and information transmission time of the intermediate network nodes when sending information; sending the first anonymous information to a server based on the first link, and receiving second anonymous information fed back by the server based on a second link through a second network node; the second link being used to indicate the intermediate network nodes and information transmission time of the intermediate network nodes when sending information; wherein the information transmission time is used to indicate a time point of transmitting anonymous information by the intermediate network nodes; the first network node, the intermediate network nodes and the second network node respectively register the public key in the respective key pair in the preset blockchain when starting, and reserve the private key in the respective key pair; after the first link is generated based on the list of intermediate network nodes, the method further comprises: constructing a first message packet corresponding to the first anonymous information according to the list of intermediate network nodes, the first message packet comprising a first message header and a first message body encrypted based on the public key of the intermediate network nodes, the first message header comprising the first link, and the first message body comprising the first anonymous information; or after the list of intermediate network nodes on the preset blockchain is obtained, the method further comprises: generating the first link and the second link based on the list of intermediate network nodes; correspondingly, after the first link and the second link are generated based on the list of intermediate network nodes, the method further comprises: constructing a second message packet corresponding to the first anonymous information according to the list of intermediate network nodes, the second message packet comprising a second message header and a second message body encrypted based on the public key of the intermediate network nodes, the second message header comprising the first link, and the second message body comprising the first anonymous information and the second link.

2. The anonymous communication method according to claim 1, characterized by, the constructing the first message packet corresponding to the first anonymous information according to the list of intermediate network nodes comprises: encrypting the first anonymous information, node address and information transmission time of the intermediate network nodes of the first link based on the public key of the intermediate network nodes included in the first link, to obtain the first message packet; or the constructing the second message packet corresponding to the first anonymous information according to the list of intermediate network nodes comprises: encrypting the first anonymous information, node address, information transmission time of the intermediate network nodes of the first link and the second link based on the public key of the intermediate network nodes included in the first link, to obtain the second message packet.

3. The anonymous communication method according to claim 2, characterized by, the sending the first anonymous information to the server based on the first link comprises: sending the first message packet or the second message packet to the intermediate network nodes in the first link at a preset information sending time point; decrypt the first message package or the second message package based on a private key of an intermediate network node in the first link; Correspondingly, in the decryption process, each intermediate network node decrypts the first message header or the second message header based on a private key to obtain a node address of a next intermediate network node and an information transmission time of transmitting the first message package or the second message package to the next intermediate network node; transmit the first message package or the second message package to the next intermediate network node based on the node address of the next intermediate network node and the information transmission time of transmitting the first message package or the second message package to the next intermediate network node; until the second network node decrypts the first message header or the second message header based on a private key to obtain the first anonymous information in the decrypted first message body or the second message body, the first anonymous information is sent to the server through the second network node.

4. The anonymous communication method according to any one of claims 1 to 3, characterized by, The method further comprises: Upon receiving the first anonymous information sent by the first client, receiving a preset type of anonymous message sent by a second client; Based on the first link, sending the preset type of anonymous message to the server; Wherein, the preset type of anonymous message is used to instruct the server to discard the anonymous message based on the preset type when receiving the anonymous message.

5. The anonymous communication method according to any one of claims 1 to 3, characterized by, The method further comprises: If the cumulative sum of the time points at which the intermediate network nodes of the first link transmit the first anonymous information is greater than a preset first threshold, the first anonymous information is re-sent to the second network node connected to the server based on the first link, and the second anonymous information fed back by the server based on the second link through the second network node is received.

6. An anonymous communication method characterized by comprising: Applied to a second network node connected to a server, the method comprises: Obtaining first anonymous information sent by a first client through a first network node based on a first link; Sending the first anonymous information to the server and receiving second anonymous information fed back by the server; Feedback the second anonymous information to the first client based on a second link; Wherein, the first link and the second link are generated based on a list of intermediate network nodes on a preset blockchain; the first link is used to indicate each intermediate network node and the corresponding information transmission time of the intermediate network node when sending information; the second link is used to indicate each intermediate network node and the corresponding information transmission time of the intermediate network node when replying information; the information transmission time is used to indicate the time point at which the intermediate network node transmits anonymous information; the first network node, the intermediate network node and the second network node register the public key in their respective key pairs in the preset blockchain when starting, and reserve the private key in their respective key pairs; Before the second anonymous information is fed back to the first client based on the second link, the method further comprises: obtaining the second link sent by the first network node based on the first link by the first client; the second link is generated by the first network node based on the list of intermediate network nodes.

7. The anonymous communication method according to claim 6, wherein Before the second anonymous information is fed back to the first client based on the second link, the method further comprises: based on the second link, constructing a third message package corresponding to the second anonymous information, the third message package comprising a third message header and a third message body; Accordingly, constructing a third message package corresponding to the second anonymous information according to the second link comprises: encrypting the node address and information transmission time of the intermediate network node of the second link based on the public key of the intermediate network node of the second link to obtain the third message header; encrypting the third message body based on the public key of the first network node, the third message body comprising the second anonymous information; Accordingly, the second anonymous information is fed back to the first client based on the second link, comprising: sending the third message package to the intermediate network node of the second link; decrypting the third message package based on the private key of the intermediate network node of the second link; Accordingly, in the decryption process, each intermediate network node decrypts the third message header based on the private key to obtain the node address of the next intermediate network node and the information transmission time of transmitting the third message package to the next intermediate network node; transmitting the third message package to the next intermediate network node based on the node address of the next intermediate network node and the information transmission time of transmitting the third message package to the next intermediate network node; until the third message body is decrypted by the first network node based on the private key to obtain the second anonymous information in the decrypted third message body, the second anonymous information is sent to the client by the first network node.

8. A terminal device, comprising: The computer program is executed by the processor to realize the anonymous communication method of any one of claims 1 to 5 or claims 6 to 7.

9. A computer-readable storage medium storing a computer program, the computer program comprising instructions that, when executed by a computer, cause the computer to perform the method of any one of claims 1 to 8. The computer program is executed by the processor to realize the anonymous communication method of any one of claims 1 to 5 or claims 6 to 7.

Citation Information

Patent Citations

  • Multi-stage routing message forwarding method in anonymous communication network

    CN111970243A

  • Anonymous connection method of broadband radio IP network

    CN1564508A