A data sharing method, system and device based on a service chain
By adopting business chain-based data sharing method and broadcast encryption technology in the data sharing solution of blockchain digital identity, the problem of complex and high cost of encryption process during multi-user sharing is solved, and simplified encryption and efficient sharing of data is achieved.
Patent Information
- Application Number
- CN202211683159.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-27
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2042-12-27
AI Technical Summary
The existing blockchain digital identity-based data sharing solution requires multiple encryption processing and generation of multiple verified credentials when shared by multiple users, resulting in complex encryption processes and high cost.
The data sharing method based on the business chain is adopted, and the verified data credentials are encrypted using broadcast encryption technology to realize one-to-many secure sharing of blockchain credentials, and simplify the encryption process and credential management process.
Through broadcast encryption technology, one-to-many secure sharing of data is realized, simplifying the encryption process and credential management, and reducing consumption costs.
Smart Images

Figure CN115987526B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, particularly to the field of artificial intelligence technology, and more particularly to a data sharing method, system and device based on a service chain. Background Art
[0002] When data is exchanged between cross-institutional business systems, it is necessary for the institution to endorse the true source of the file, and at the same time, it is necessary to ensure the integrity of the data during the transmission process. Blockchain digital identity is to establish a new flat and easily expandable digital identity authentication model. Users construct a distributed identity authentication system that can be interconnected across architectures, and promote the sharing and secure transfer of data between users under the control of the identity owner. In related technologies, the data sharing scheme based on blockchain digital identity needs to generate verifiable credentials that are only visible to authorized users one by one according to the data sharing user range. When the data needs to be shared with multiple users at the same time, multiple encryption processes and multiple verifiable credentials need to be generated. The encryption process and credential management process are complex and consume high costs. Summary of the Invention
[0003] An object of the present invention is to provide a data sharing method based on a service chain, which realizes one-to-many secure sharing of blockchain credentials based on broadcast encryption technology, can simplify the encryption process and credential management process, and save consumption costs. Another object of the present invention is to provide a data sharing device based on a service chain. Another object of the present invention is to provide a computer-readable medium. Still another object of the present invention is to provide a computer device.
[0004] To achieve the above objectives, on the one hand, the present invention discloses a data sharing method based on a service chain, including:
[0005] In response to a shared data encapsulation request, perform credential encapsulation processing on the shared data to obtain a verifiable data credential;
[0006] Encrypt the verifiable data credential according to the shared user set of the current institution to obtain a ciphertext message;
[0007] Send the ciphertext message to a blockchain node on the service chain, so that the blockchain node sends a data acquisition message to the data receivers in the shared user set, for the data receivers to decrypt the ciphertext message through the service chain to obtain the shared data.
[0008] Preferably, it further includes:
[0009] Receive a data sharing request sent by a data receiver in the service chain, where the data sharing request includes requested data information;
[0010] Send a data sharing confirmation message to the data receiver;
[0011] Add the data recipient to the shared user set of the current organization.
[0012] Preferably, perform voucher encapsulation processing on the shared data to obtain a verifiable data voucher, including:
[0013] Generate a data voucher according to the shared data;
[0014] Sign the data voucher with the private key corresponding to the current identity to obtain a verifiable data voucher.
[0015] Preferably, encrypt the verifiable data voucher according to the shared user set of the current organization to obtain a ciphertext message, including:
[0016] Generate a master key pair according to the shared user set of the current organization through a broadcast encryption generation algorithm, where the master key pair includes a broadcast public key and a broadcast private key;
[0017] Generate a decryptable private key corresponding to the user identity through a key generation algorithm according to the user identity and the broadcast private key in the shared user set of the current organization;
[0018] Encrypt the verifiable data voucher according to the user identity and the broadcast public key in the shared user set of the current organization through an encryption algorithm to obtain a shared ciphertext and a broadcast encryption header;
[0019] Encrypt the decryptable private key corresponding to the user identity according to the public key corresponding to the user identity in the shared user set of the current organization to obtain an encrypted private key corresponding to the user identity;
[0020] Generate a user encryption identity set according to the user identity and the corresponding encrypted private key;
[0021] Generate a ciphertext message according to the user encryption identity set, the shared user set, the broadcast public key, the shared ciphertext, and the broadcast encryption header.
[0022] Preferably, before sending the ciphertext message to the blockchain node on the business chain, include:
[0023] Perform access verification according to the ciphertext message. If the access verification passes, continue to execute the step of sending the ciphertext message to the blockchain node on the business chain.
[0024] The present invention also discloses a data sharing system based on a business chain. The system includes: a business system, a digital identity node, a business chain, and a blockchain node on the business chain;
[0025] The business system is used to send a shared data encapsulation request to the digital identity node;
[0026] The digital identity node is used to perform credential encapsulation processing on shared data in response to a shared data encapsulation request, obtaining a verifiable data credential; encrypting the verifiable data credential according to the shared user set of the current institution to obtain a ciphertext message; and sending the ciphertext message to a blockchain node on the business chain;
[0027] The blockchain node is used to receive the ciphertext message sent by the digital identity node; sending a data acquisition message to the data recipient in the shared user set, so that the data recipient can decrypt the ciphertext message through the business chain to obtain the shared data.
[0028] The present invention also discloses a data sharing device based on a business chain, including:
[0029] A credential encapsulation unit, configured to perform credential encapsulation processing on shared data in response to a shared data encapsulation request, obtaining a verifiable data credential;
[0030] An encryption unit, configured to encrypt the verifiable data credential according to the shared user set of the current institution to obtain a ciphertext message;
[0031] An on-chain unit, configured to send the ciphertext message to a blockchain node on the business chain, so that the blockchain node sends a data acquisition message to the data recipient in the shared user set, so that the data recipient can decrypt the ciphertext message through the business chain to obtain the shared data.
[0032] The present invention also discloses a computer-readable medium, on which a computer program is stored, and when the program is executed by a processor, the above-mentioned method is implemented.
[0033] The present invention also discloses a computer device, including a memory and a processor, the memory is used to store information including program instructions, the processor is used to control the execution of the program instructions, and when the processor executes the program, the above-mentioned method is implemented.
[0034] The present invention also discloses a computer program product, including computer program / instructions, and when the computer program / instructions are executed by a processor, the above-mentioned method is implemented.
[0035] In response to a shared data encapsulation request, the present invention performs credential encapsulation processing on shared data, obtaining a verifiable data credential; encrypting the verifiable data credential according to the shared user set of the current institution to obtain a ciphertext message; sending the ciphertext message to a blockchain node on the business chain, so that the blockchain node sends a data acquisition message to the data recipient in the shared user set, so that the data recipient can decrypt the ciphertext message through the business chain to obtain the shared data. Based on broadcast encryption technology, one-to-many secure sharing of blockchain credentials is realized, which can simplify the encryption process and the credential management process and save consumption costs. Description of the Drawings
[0036] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0037] Figure 1 It is a schematic structural diagram of a data sharing system based on a service chain provided by an embodiment of the present invention;
[0038] Figure 2 It is a schematic structural diagram of a digital identity node provided by an embodiment of the present invention;
[0039] Figure 3 It is a schematic structural diagram of a blockchain node provided by an embodiment of the present invention;
[0040] Figure 4 It is a flowchart of a data sharing method based on a service chain provided by an embodiment of the present invention;
[0041] Figure 5 It is a flowchart of another data sharing method based on a service chain provided by an embodiment of the present invention;
[0042] Figure 6 It is a schematic structural diagram of a data sharing device based on a service chain provided by an embodiment of the present invention;
[0043] Figure 7 It is a schematic structural diagram of a computer device provided by an embodiment of the present invention. Detailed implementation manners
[0044] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0045] It should be noted that a data sharing method, system and device based on a service chain disclosed in this application can be used in the field of artificial intelligence technology, and can also be used in any field other than the field of artificial intelligence technology. The application fields of a data sharing method, system and device based on a service chain disclosed in this application are not limited.
[0046] To facilitate the understanding of the technical solution provided in this application, the relevant content of the technical solution of this application will be described below. A business chain is a blockchain alliance network established among business cooperation institutions according to business needs. Business rules are extracted as business smart contracts and deployed on the blockchain alliance network to endorse specific business data.
[0047] Digital identity is the digital identity identifier of an entity and the associated digital attribute declarations. Blockchain digital identity is a new type of distributed digital identity technology based on the idea of weak centralization of the blockchain. It is an identity recognition and authentication solution based on a distributed ledger that does not rely on a centralized authority or identity provider, and user attribute information privacy protection is carried out based on cryptography. The core components include, but are not limited to, digital identity identifier DID (distributed digital identity identifier with specific rules and a corresponding set of public and private key pairs, the public key is uploaded to the chain, and the private key is saved by the user himself) and verifiable credential (VC).
[0048] A credential refers to the attribute description that an entity needs to disclose. A verifiable credential is a tamper-proof credential signed and encrypted by the issuer, with the characteristics of cryptographic security and privacy protection. Verifiable credentials include, but are not limited to, the verifiable credential itself and the digital signature of the verifiable credential. Among them, the verifiable credential itself includes, but is not limited to, credential metadata and declarations.
[0049] Distributed Public Key Infrastructure (DPKI) associates public keys with entity identifiers and stores and retrieves public key information based on decentralized nodes.
[0050] A data fingerprint refers to the unique hash value, i.e., the hash value, generated by compressing the original data through hash function technology. Since different original data generate different hash values, it can be used as a basis for judging whether the original data has been modified.
[0051] Broadcast encryption is a cryptographic system for transmitting digital information to multiple users. It can select different subsets of the broadcast group user group for broadcast encryption, so as to securely and efficiently realize the confidential transmission of messages in a one-to-many manner.
[0052] Figure 1 It is a schematic structural diagram of a data sharing system based on a business chain provided for an embodiment of the present invention. As Figure 1 shown, there is at least one business system 100, at least one digital identity node 200, a business chain 300, and multiple blockchain nodes 310 on the business chain. Figure 1 Taking 2 business systems 100 and 2 digital identity nodes 200 as examples, in actual applications, there may be more business systems 100 and digital identity nodes, which are not limited here.
[0053] The business system 100 is a business system that requires cross-organization identity mutual recognition and data interconnection, and conducts corresponding service processes according to the two different roles of data provider and data receiver in the data sharing process. The data provider controls the scope of data sharing users, obtains the user identity ID on the business chain 300 according to the data sharing scope, generates the corresponding broadcast encryption key, encapsulates the shared data into a verifiable digital identity credential, and shares and stores it on the business chain 300 after broadcast encryption processing, and triggers the notification of the credential connection information to each data receiver as event information. The data provider subscribes to the verifiable digital credential update event notification on the business chain 300. After receiving the notification, it obtains the corresponding broadcast encryption processed credential from the business chain 300, decrypts it according to the broadcast encryption processing rules, and obtains the shared data. The verifiable credential summary and the credential usage process are consensus and endorsed on the blockchain node 310 of the business chain 300 to ensure the authenticity of the credential and the full process traceability of the credential circulation.
[0054] The digital identity node 200 is for each alliance organization on the business chain 300, and is a service node that provides cross-alliance organization identity mutual recognition and data sharing and interconnection in cooperation with the blockchain node 310, and belongs to different alliance organizations synchronously with the blockchain node 310. The digital identity node 200 provides services such as digital identity ID registration, digital identity credential issuance and verification, and credential broadcast encryption processing related to digital identity, and the service call is triggered by the business system 100. The internal structure of each digital identity node 200 is the same.
[0055] Figure 2 The structure diagram of a digital identity node provided by an embodiment of the present invention is as Figure 2 shown, the digital identity node 200 includes a system initialization module 210 and a digital identity core module 220.
[0056] The system initialization module 210 is used to initialize the digital identity information of the digital identity node 200 itself, including but not limited to registering the identity DID information, and the identity DID information represents the alliance organization to which the digital identity node 200 belongs; it is also used to register the identity DID information on the business chain 300, including but not limited to the alliance organization DID and the attributes corresponding to the alliance organization DID (for example: Alliance Organization A), the public key corresponding to the DID, and the node communication address corresponding to the DID (domain name: port). Among them, the private key information corresponding to the DID is saved by the business system 100 corresponding to the alliance organization.
[0057] The digital identity core module 220 is used to process core processing processes related to the data cross-institutional sharing process, such as identity, credential, broadcast encryption, and data sharing request interaction. The digital identity core module 220 includes an identity DID management sub-module 221, a credential management sub-module 222, a broadcast encryption control sub-module 223, and a peer-to-peer communication sub-module 224.
[0058] The identity DID management sub-module 221 is used to process blockchain digital identity DID registration for affiliated consortium institutions and users within the institution who have data sharing requirements, DID attribute updates (the update scope includes but is not limited to affiliated institution updates and key pair updates corresponding to the identity, etc.), DID cancellation and other services. For example: To register the blockchain digital identity for Bob, a user of Alliance A, it is necessary to send an identity registration request to the business chain 300, generate a unique digital identity DID for Bob within the alliance, and register on the chain the DID identifier, the public key corresponding to the DID, the person corresponding to the DID, that is, Bob, the affiliated institution and other attribute information. The private key corresponding to the DID is managed by Bob himself.
[0059] The credential management sub-module 222 is used to process the credential encapsulation of shared data for affiliated consortium institutions and users within the institution who have data sharing requirements, including but not limited to credential generation, on-chain encrypted custody of credentials, credential update, credential deletion, etc.
[0060] The broadcast encryption control sub-module 223 is a module that performs broadcast encryption processing on data sharing credentials, including but not limited to encrypting credentials as a data provider into encrypted credentials that can be decrypted by users within the sharing scope and performing credential decryption operations as a data recipient.
[0061] The peer-to-peer communication sub-module 224 is a module for data sharing request interaction between different consortium institutions. When the business system 100 of institution A needs to apply for data sharing from the business system 100 of institution B, the digital identity node 200 of institution A, as the data recipient, searches for the communication address of the digital identity node 200 of institution B, which is the data provider, on the business chain 300, and establishes a communication link to apply for data sharing. After being approved by the business system 100 of institution B, the digital identity DID of the applicant of institution A is added to the shared user set DIDGroup of this data of institution B.
[0062] The business chain 300 is a consortium chain formed according to the cross-institutional data sharing requirements of the business system 100 of external consortium institutions. It includes multiple blockchain nodes 310 on the chain, all of which are member nodes of the business and belong to different consortium institutions. Digital identity smart contracts for interacting with the digital identity ID management and credential management services of the digital identity node 200 are deployed on each member node. The digital identity node 200 also has a distributed deployment architecture and is deployed in each consortium institution. The business system 100 calls the corresponding digital identity management and credential management services through the digital identity node 200. The total number of blockchain nodes 310 in the business chain 300 is 3f + 1, where f represents the number of fault-tolerant nodes that can be supported, and the minimum value is 1. Both the request and the business request use the Practical Byzantine Fault Tolerance (PBFT) algorithm for consensus. A consensus request must receive at least 2f + 1 consistent confirmation messages from other verification nodes at each verification node in the business chain before the transaction can complete the consensus at the current stage. It should be noted that the consensus is successful only after the consensus in the three stages of the Byzantine fault tolerance algorithm is completed, and then the system data access control policy update request and the business request are executed, and the execution result can be used as legal data to generate a new block and persist it.
[0063] The blockchain node 310 is used to receive requests for digital identity ID registration, digital identity credential issuance and verification, and update requests for the broadcast encryption control policy initiated by the digital identity node 200. The internal structures of all verification nodes are the same. They perform permission verification on transactions and complete duplicate and parameter legality verification. After passing the verification, the transactions are broadcast to all other blockchain nodes 310. They receive the broadcast notifications of the blocks to be consensus from other blockchain nodes 310, generate new block data according to the data processed according to the logic in the contract after the consensus is passed, and trigger the relevant system processes after the contract is executed.
[0064] Figure 3 As shown in the structure schematic diagram of a blockchain node provided by an embodiment of the present invention, Figure 3 As shown, the blockchain node 310 includes a transaction routing and event notification module 311 and a smart contract consensus and execution module 312.
[0065] The transaction routing and event notification module 311 is used to receive requests for the digital identity DID and credential management services initiated by the digital identity node 200, perform access judgments such as client post-signature, smart contract ID, and parameters according to the transaction. If the judgment passes, the main control transaction enters the corresponding contract consensus routing; at the same time, it listens to the time notifications pushed by the smart contract consensus and execution module 312, and pushes messages according to the node ID according to the time notifications.
[0066] The intelligent contract consensus and execution module 312 is used to perform transaction verification, consensus processing, and persistence according to requests such as digital identity ID management, verifiable credential management, and broadcast encryption rule management initiated by the digital identity node 200. The intelligent contract consensus and execution module 312 includes a transaction verification sub-module 12a, a transaction consensus sub-module 12b, an event control sub-module 12c, and a persistence sub-module 12d.
[0067] The transaction verification sub-module 12a is a module that verifies business request parameters and performs transaction preprocessing. It is used to determine whether a transaction is a query type or an update type based on the method type in the transaction request parameters. If it is a query type transaction, it obtains the corresponding data from the persistence sub-module 12d; if it is an update type transaction, it encapsulates the transaction request and the pre-execution result of the transaction into a block, increments the block sequence number by 1, and broadcasts the block consensus message to all verification nodes in the business chain 300.
[0068] The transaction consensus sub-module 12b is the core module for completing the consensus of update type business transactions. It performs a three-stage consensus process on the transaction using the Byzantine consensus algorithm. The first stage is the pre-prepare consensus, the second stage is the prepare consensus, and the third stage is the commit consensus. The three stages are executed sequentially. When the current stage has received 2f + 1 consistent confirmation messages from other transaction consensus nodes, the consensus of the current stage is completed and enters the next stage. After the consensus of all three stages is completed, it represents that the business request is legal, and the data processed according to the business contract logic is written into the block for persistence.
[0069] The event control sub-module 12c is used to push messages to the digital identity nodes of the data receivers in the DIDGroup submitted by the digital identity node 200 of the data provider institution, so as to notify the digital identity nodes of the data receivers to perform shared data acquisition operations. The event control sub-module 12c supports setting the full notification or incremental notification mode according to the institution.
[0070] The persistence sub-module 12d performs final execution processing on the transactions passed by the consensus, and persistently updates the generated blocks and the world state data after execution. Record the latest data update set of the world state and all transaction log blocks that contribute to the update of the world state data. The persistently stored data includes the digital identity IDs and public key information of the consortium institutions participating in data sharing, the digital identity IDs and public key information of users under the institution, the verifiable digital credentials processed by broadcast encryption and their fingerprint information, the verifiable credential transfer and verification information, the broadcast encryption authorization scope information, etc.
[0071] In the embodiment of the present invention, the business system 100 of the data provider is used to send a shared data encapsulation request to its corresponding digital identity node.
[0072] The digital identity node 200 of the data provider is used to, in response to a shared data encapsulation request, perform voucher encapsulation processing on the shared data to obtain a verifiable data voucher; encrypt the verifiable data voucher according to the shared user set of the current institution to obtain a ciphertext message; and send the ciphertext message to the blockchain node 310 on the service chain 300.
[0073] The blockchain node 310 is used to receive the ciphertext message sent by the digital identity node 200 of the data provider; send a data acquisition message to the digital identity node 200 corresponding to the data recipient in the shared user set, so that the digital identity node 200 corresponding to the data recipient can decrypt the ciphertext message through the service chain 300 to obtain the shared data.
[0074] It should be noted that Figures 1 to 3 the structure shown is also applicable to execute Figure 4 or Figure 5 the method described above, which will not be repeated here.
[0075] Next, taking the data sharing device based on the service chain as the execution subject as an example, the implementation process of the data sharing method based on the service chain provided in the embodiments of the present invention will be described. It can be understood that the execution subject of the data sharing method based on the service chain provided in the embodiments of the present invention includes but is not limited to the data sharing device based on the service chain.
[0076] Figure 4 is a flowchart of a data sharing method based on the service chain provided in the embodiments of the present invention. As Figure 4 shown, the method includes:
[0077] Step 101, in response to a shared data encapsulation request, perform voucher encapsulation processing on the shared data to obtain a verifiable data voucher.
[0078] Step 102, encrypt the verifiable data voucher according to the shared user set of the current institution to obtain a ciphertext message.
[0079] Step 103, send the ciphertext message to the blockchain node on the service chain, so that the blockchain node sends a data acquisition message to the data recipient in the shared user set, so that the data recipient can decrypt the ciphertext message through the service chain to obtain the shared data.
[0080] It should be noted that in the technical solution of this application, the acquisition, storage, use, processing, etc. of data all comply with the relevant provisions of national laws and regulations. The user information in the embodiments of this application is obtained through legal and compliant channels, and the acquisition, storage, use, processing, etc. of user information have obtained the authorization and consent of the customers.
[0081] In the technical solution provided by the embodiment of the present invention, in response to a shared data encapsulation request, the shared data is subjected to voucher encapsulation processing to obtain a verifiable data voucher; according to the shared user set of the current institution, the verifiable data voucher is encrypted to obtain a ciphertext message; the ciphertext message is sent to a blockchain node on the business chain, so that the blockchain node sends a data acquisition message to the data recipient in the shared user set, for the data recipient to decrypt the ciphertext message through the business chain to obtain the shared data. Based on the broadcast encryption technology, the one-to-many secure sharing of blockchain vouchers can be realized, which can simplify the encryption process and voucher management process and save consumption costs.
[0082] Figure 5 It is a flowchart of another data sharing method based on a business chain provided by an embodiment of the present invention. As Figure 5 shown, the method includes:
[0083] Step 201, a data provider in the business chain receives a data sharing request sent by a data recipient in the business chain, and the data sharing request includes requested data information.
[0084] In the embodiment of the present invention, the data provider is a node corresponding to a certain consortium institution that provides data in the business chain, and the data recipient is a node corresponding to a certain consortium institution that receives data in the business chain. A communication link is established between the data provider and the data recipient, and they can communicate through the communication link.
[0085] In the embodiment of the present invention, each consortium institution stores a list of sharable data on the chain, including but not limited to data names and data digest description information. Other consortium institutions can retrieve the corresponding shared data in business. If the shared data they need is retrieved, they send a data sharing request to the digital identity node of the corresponding consortium institution through their own corresponding digital identity node. The data sharing request includes requested data information, and the requested data information includes but not limited to the data information that the user hopes to obtain and the digital identity DID information of the institution or user that needs to obtain the data. Among them, the node that sends the data sharing request is the data recipient of the shared data waiting to receive the data; the node that receives the data sharing request acts as the data provider.
[0086] Step 202, the data provider sends a data sharing confirmation message to the data recipient.
[0087] In the embodiment of the present invention, the data provider reviews the received requested data information. If the review passes, a data sharing confirmation message is sent to the data recipient.
[0088] Step 203, the data provider adds the data recipient to the shared user set of the current institution.
[0089] Specifically, the data provider adds the digital identity DID information of the corresponding institution or user of the data recipient to the shared user set (DIDGroup) of its own corresponding current institution. The institutions or users in the shared user set are all institutions or users that have passed the review and can perform data sharing.
[0090] It should be noted that when the sharing permission of a certain institution or user is revoked, the data provider will perform corresponding updates on the institutions or users in the shared user set, that is: delete the institutions or users whose sharing permissions have been revoked from the shared user set. Further, it is necessary to recalculate the broadcast encryption message header Hdr and the symmetric encryption key Mkey, update the shared ciphertext CM, and update the encrypted shared data message hosted on the chain. The decryptable private key sk of each user remains unchanged. Even if a user whose permission has been revoked after the permission change has the decryptable private key sk, they cannot decrypt to obtain the corresponding symmetric encryption key Mkey. Unrevoked users can still obtain the corresponding symmetric encryption key Mkey using the original decryptable private key sk.
[0091] Step 204: In response to the shared data encapsulation request, the data identity node of the data provider performs credential encapsulation processing on the shared data to obtain a verifiable data credential.
[0092] In an embodiment of the present invention, the business system sends a shared data encapsulation request to the data identity node acting as the data provider, requesting the data identity node to encapsulate the shared data.
[0093] In an embodiment of the present invention, step 204 specifically includes:
[0094] Step 2041: Generate a data credential according to the shared data.
[0095] In an embodiment of the present invention, the shared data is written into the credential to generate a data credential.
[0096] Step 2042: Sign the data credential with the private key corresponding to the current identity to obtain a verifiable data credential.
[0097] In an embodiment of the present invention, the data credential is signed with the private key corresponding to the institution or user identity DID of the data provider to obtain a verifiable data credential.
[0098] Step 205: The data identity node of the data provider encrypts the verifiable data credential according to the shared user set of the current institution to obtain a ciphertext message.
[0099] In an embodiment of the present invention, step 205 specifically includes:
[0100] Step 2051: Generate a master key pair according to the shared user set of the current institution through a broadcast encryption generation algorithm. The master key pair includes a broadcast public key and a broadcast private key.
[0101] In an embodiment of the present invention, the total number of users who need to share data in the shared user set (DIDGroup) is N. A security parameter λ is selected, and encryption calculation is performed through a broadcast encryption generation algorithm to generate a main key pair <PubKey, MainKey> for broadcast encryption, where PubKey is the broadcast public key and MainKey is the broadcast private key, completing the initialization of the broadcast encryption key.
[0102] Step 2052: Through a key generation algorithm, according to the user identities and the broadcast private key of the users in the shared user set of the current institution, generate a decryptable private key corresponding to the user identity.
[0103] In an embodiment of the present invention, the shared user set (DIDGroup) includes multiple shared users and the identity DID of each shared user. The DID of each shared user is subjected to hash transcoding and mapped to an algorithm input salt with a fixed length; the algorithm input salt and the broadcast private key are input into the key generation algorithm for calculation to obtain a decryptable private key corresponding to each user identity. That is:
[0104] sk i = KeyGen(MainKey, encode(did i ))
[0105] where sk i is the decryptable private key corresponding to user i, MainKey is the broadcast private key, encode(did i ) is the algorithm input salt of user i, and KenGen() is the key generation algorithm.
[0106] Step 2053: Through an encryption algorithm, according to the user identities and the broadcast public key of the users in the shared user set of the current institution, encrypt the verifiable data credential to obtain a shared ciphertext and a broadcast encryption message header.
[0107] In an embodiment of the present invention, through an encryption algorithm, an encryption calculation is performed on the shared user set and the broadcast public key to obtain a symmetric encryption key and a broadcast encryption message header; an encryption calculation is performed on the verifiable data credential to obtain a shared ciphertext. That is:
[0108] (Hdr, MKey) = Encrypt(DIDGroup, PubKey)
[0109] CM = Menc(M, MKey)
[0110] Among them, Encrypt() and Menc() are both encryption algorithms, DIDGroup is the set of shared users, PubKey is the broadcast public key, Hdr is the broadcast encryption message header, MKey is the symmetric encryption key, M is the verifiable data credential, and CM is the shared ciphertext.
[0111] Step 2054: Encrypt the decryptable private key corresponding to the user identity according to the public key corresponding to the user identity in the shared user set of the current institution, to obtain the encrypted private key corresponding to the user identity.
[0112] In the embodiment of the present invention, the decryptable private key corresponding to the user identity is encrypted by the public key corresponding to the user identity, to obtain the encrypted private key corresponding to the user identity. For example: the decryptable private key of user A is encrypted by the public key of user A, to obtain the encrypted private key corresponding to user A. That is:
[0113] msk i = skenc(sk i , pk i )
[0114] Among them, skenc() is the encryption algorithm, msk i is the encrypted private key corresponding to user i, sk i is the decryptable private key corresponding to user i, and pk i is the public key corresponding to user i.
[0115] Step 2055: Generate a user encrypted identity set according to the user identity and the corresponding encrypted private key.
[0116] Specifically, form a review combination of the user identity DID i and the corresponding encrypted private key msk i to obtain the user encrypted identity set, that is: DIDmskGroup = {(DID i , msk i ), (DID j , msk j )....(DID n , msk n )}, where DIDmskGroup is the user encrypted identity set, DID i is the user identity of user i, and msk i is the encrypted private key corresponding to user i.
[0117] Step 2056: Generate a ciphertext message according to the user encrypted identity set, the shared user set, the broadcast public key, the shared ciphertext, and the broadcast encryption message header.
[0118] Specifically, the shared user set DIDGroup, the broadcast public key PubKey, the shared ciphertext CM, and the broadcast encryption message header Hdr are encapsulated to obtain an encapsulated shared data message Message = {Hdr, CM, PubKey, DIDGroup}; the encapsulated shared data message is encrypted using the private key corresponding to the identity DID of the data provider to obtain an encrypted shared data message; the encrypted shared data message is combined with the user encrypted identity set to obtain a ciphertext message.
[0119] Furthermore, the ciphertext message is entrusted on the business chain and the corresponding hash value (hash), i.e., the data fingerprint, is extracted for deposit evidence.
[0120] Step 206: The data identity node of the data provider performs an admission check based on the ciphertext message. If the admission check passes, step 207 is executed; if the admission check fails, the process ends.
[0121] In the embodiment of the present invention, the admission check includes but is not limited to ciphertext message signature verification, parameter legality verification, and smart contract ID verification. If the admission check passes, it indicates that the transaction where the ciphertext message is located can enter the business chain for transaction verification and transaction consensus, and step 207 is continued; if the admission check fails, it indicates that the transaction where the ciphertext message is located cannot enter the business chain, and the process ends.
[0122] Step 207: The data identity node of the data provider sends the ciphertext message to the blockchain node on the business chain.
[0123] In the embodiment of the present invention, the blockchain node determines whether the transaction is a query type or an update type based on the method type in the request parameters of the transaction where the ciphertext message is located. If it is a query type transaction, the corresponding data is obtained and returned; if it is an update type transaction, the transaction and the pre-execution result of the transaction are encapsulated into a block, the block number is incremented by 1, and the block consensus message is broadcast to all verification nodes in the business chain; the transaction is processed through a three-stage consensus process according to the block formula message using the Byzantine formula algorithm. The three stages are executed sequentially. When the current stage has received 2f + 1 consistent confirmation messages from other transaction consensus nodes in the previous stage, the consensus of the current stage is completed and the next stage is entered, where f is the number of tolerable fault nodes, and the minimum value of f is 1.
[0124] It should be noted that when the consensus of the three stages is all completed, it represents that the transaction request is legal. After processing the business logic of the transaction according to the business contract, the processed data result is written into the block for persistence.
[0125] Further, persistently update the generated block and the world state data after execution. Record the latest data update set of the world state and all transaction log block records that contribute to the update of the world state data. The persistently stored data includes the digital identity IDs and public key information of the consortium institutions participating in data sharing, the digital identity IDs and public key information of the users under the institutions, the verifiable digital certificates processed by broadcast encryption and their fingerprint information, the verifiable certificate transfer and verification information, the broadcast encryption authorization scope information, etc.
[0126] Step 208: The blockchain node sends a data acquisition message to the data receivers in the shared user set.
[0127] In the embodiment of the present invention, the shared user set includes the identity DIDs of multiple authorized shared users, all of which are data receivers corresponding to the institutions that are the current data providers. The blockchain node sends a data acquisition message to the data identity nodes of the corresponding data receivers according to the identity DIDs of the shared users in the shared user set, so as to notify the data receivers that the current shared data has been updated, and the data receivers can perform shared data acquisition operations through the digital identity nodes.
[0128] It should be noted that full notification of data receivers can be performed according to institutions, or incremental notification can be performed according to the set incremental notification mode. The embodiment of the present invention does not limit this.
[0129] Step 209: The data receiver decrypts the ciphertext message through the business chain to obtain the shared data.
[0130] In the embodiment of the present invention, step 209 specifically includes:
[0131] Step 2091: The data receiver verifies the ciphertext message through the business chain according to its own identity DID. If the verification passes, execute step 2092; if the verification fails, the process ends.
[0132] In the embodiment of the present invention, the ciphertext message includes an encrypted shared data message and a user encryption identity set, and the ciphertext message has a corresponding hash value (hash).
[0133] In the embodiment of the present invention, through its own identity DID, query its own encrypted private key from the user encryption identity set DIDmskGroup on the chain. Obtain the hash of the ciphertext message on the business chain, and verify the ciphertext message based on the hash. If the verification passes, it indicates that the ciphertext message has not been tampered with, and continue to execute step 2092; if the verification fails, it indicates that the ciphertext message has been tampered with and the data is untrustworthy, and the process ends.
[0134] Step 2092: Obtain the public key information corresponding to the identity DID of the data provider through the business chain, and decrypt the encrypted shared data message with the public key information to obtain the encapsulated shared data message.
[0135] In the embodiment of the present invention, the decrypted encapsulated shared data message Message includes the shared user set DIDGroup, the broadcast public key PubKey, the shared ciphertext CM, and the broadcast encryption header Hdr, that is: Message = {Hdr, CM, PubKey, DIDGroup}.
[0136] Step 2093: Decrypt the encrypted private key of itself according to its own private key through the decryption algorithm to obtain the corresponding decryptable private key.
[0137] Specifically, decrypt the encrypted private key of itself through sk = skdec(msk, vk) to obtain the corresponding decryptable private key. Where sk is the decryptable private key, skdec() is the decryption algorithm, msk is the encrypted private key of the data receiver itself, and vk is its own private key.
[0138] Step 2094: Decrypt according to its own identity DID, the encapsulated shared data message, and the private key of the data provider through the decryption algorithm to obtain the verifiable data certificate.
[0139] Specifically, decrypt the broadcast public key, the shared user set, the identity DID of the data receiver itself, the decryptable private key, and the broadcast encryption header to obtain the symmetric encryption key, that is:
[0140] Mkey = decrypt(PubKey, DIDGroup, DID, sk, Hdr)
[0141] M = mdec(CM, Mkey)
[0142] Where decrypt() and mdec() are both decryption algorithms, DIDGroup is the shared user set, PubKey is the broadcast public key, Hdr is the broadcast encryption header, MKey is the symmetric encryption key, M is the verifiable data certificate, CM is the shared ciphertext, sk is the decryptable private key, and M is the verifiable data certificate.
[0143] Step 2095: Obtain the public key corresponding to the identity DID of the data provider through the business chain, and verify the signature of the verifiable data certificate with the obtained public key to obtain the shared data.
[0144] In the embodiment of the present invention, if the signature verification passes, it indicates that the verifiable data certificate has not been tampered with and the data is authentic, and the shared data is obtained through the data certificate; if the signature verification fails, it indicates that the verifiable data certificate has been tampered with and the process ends.
[0145] The data sharing method based on the business chain provided by the present invention can realize the accurate authorized flow of data. At the same time, based on the broadcast encryption algorithm, the same data certificate only needs to be encrypted once for multiple shared user groups, avoiding the need to generate a certificate for each user, making the issuance and maintenance of data flow certificates more convenient and easy to use. The present invention can control the scope of data shareable users by modifying the data access control policy user set, and can optimize the sharing control of verifiable digital certificates from one-to-one to one-to-many, while supporting the revocation of shared users, making data access permission control more flexible; using traditional broadcast encryption technology, symmetric encryption technology, and asymmetric encryption technology, the data is signed and encrypted during the data certificate sharing process, and the data recipient obtains the right to decrypt the data through the ownership of the DID private key, ensuring that the data sharing scope can be accurately controlled and the data security protection strength is high.
[0146] In the technical solution of the data sharing method based on the business chain provided by the embodiment of the present invention, in response to a shared data encapsulation request, the shared data is encapsulated with credentials to obtain a verifiable data credential; the verifiable data credential is encrypted according to the shared user set of the current organization to obtain a ciphertext message; the ciphertext message is sent to the blockchain node on the business chain, so that the blockchain node sends a data acquisition message to the data recipient in the shared user set, so that the data recipient can decrypt the ciphertext message through the business chain to obtain the shared data. Based on the broadcast encryption technology, one-to-many secure sharing of blockchain credentials is realized, which can simplify the encryption process and the credential management process and save consumption costs.
[0147] Figure 6 A schematic diagram of the structure of a data sharing device based on a service chain provided by an embodiment of the present invention, wherein the device is used to execute the data sharing method based on the service chain, such as Figure 6 As shown, the device includes: a credential packaging unit 11, an encryption unit 12 and a chain unit 13.
[0148] The credential encapsulation unit 11 is used to respond to a shared data encapsulation request, perform credential encapsulation processing on the shared data, and obtain a verifiable data credential.
[0149] The encryption unit 12 is used to encrypt the verifiable data credentials according to the shared user set of the current organization to obtain a ciphertext message.
[0150] The on-chain unit 13 is used to send the encrypted message to the blockchain node on the business chain, so that the blockchain node sends a data acquisition message to the data recipient in the shared user concentration, so that the data recipient can decrypt the encrypted message through the business chain to obtain the shared data.
[0151] In an embodiment of the present invention, the device further includes: a receiving unit 14, a sending unit 15, and an adding unit 16.
[0152] The receiving unit 14 is configured to receive a data sharing request sent by a data recipient in a service chain, and the data sharing request includes requested data information.
[0153] The sending unit 15 is configured to send a data sharing confirmation message to the data recipient.
[0154] The adding unit 16 is configured to add the data recipient to the shared user set of the current institution.
[0155] In an embodiment of the present invention, the voucher encapsulation unit 11 is specifically configured to generate a data voucher according to the shared data; sign the data voucher with the private key corresponding to the current identity to obtain a verifiable data voucher.
[0156] In an embodiment of the present invention, the encryption unit 12 is specifically configured to generate a master key pair according to the shared user set of the current institution through a broadcast encryption generation algorithm, where the master key pair includes a broadcast public key and a broadcast private key; generate a decryptable private key corresponding to the user identity according to the user identity and the broadcast private key in the shared user set of the current institution through a key generation algorithm; encrypt the verifiable data voucher according to the user identity and the broadcast public key in the shared user set of the current institution through an encryption algorithm to obtain a shared ciphertext and a broadcast encryption message header; encrypt the decryptable private key corresponding to the user identity according to the public key corresponding to the user identity in the shared user set of the current institution to obtain an encrypted private key corresponding to the user identity; generate a user encryption identity set according to the user identity and the corresponding encrypted private key; generate a ciphertext message according to the user encryption identity set, the shared user set, the broadcast public key, the shared ciphertext, and the broadcast encryption message header.
[0157] In an embodiment of the present invention, the device further includes: a verification unit 17.
[0158] The verification unit 17 is configured to perform admission verification according to the ciphertext message. If the admission verification passes, it triggers the on-chain unit 13 to continue executing the step of sending the ciphertext message to a blockchain node on the service chain.
[0159] In the solution of the embodiment of the present invention, in response to a shared data encapsulation request, perform voucher encapsulation processing on the shared data to obtain a verifiable data voucher; encrypt the verifiable data voucher according to the shared user set of the current institution to obtain a ciphertext message; send the ciphertext message to a blockchain node on the service chain, so that the blockchain node sends a data acquisition message to the data recipient in the shared user set, for the data recipient to decrypt the ciphertext message through the service chain to obtain the shared data. Based on the broadcast encryption technology, realize the one-to-many secure sharing of blockchain vouchers, which can simplify the encryption process and voucher management process and save consumption costs.
[0160] The systems, devices, modules or units illustrated in the above embodiments may be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer device. Specifically, the computer device may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.
[0161] An embodiment of the present invention provides a computer device, including a memory and a processor. The memory is used to store information including program instructions, and the processor is used to control the execution of the program instructions. When the program instructions are loaded and executed by the processor, the steps of the above embodiments of the data sharing method based on the service chain are implemented. For specific descriptions, reference may be made to the embodiments of the data sharing method based on the service chain above.
[0162] Reference is made below to Figure 7 , which shows a schematic structural diagram of a computer device 600 suitable for implementing the embodiments of the present application.
[0163] As Figure 7 shown, the computer device 600 includes a central processing unit (CPU) 601, which can perform various appropriate operations and processes according to the program stored in the read-only memory (ROM) 602 or the program loaded from the storage section 608 into the random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the computer device 600 are also stored. The CPU 601, ROM 602, and RAM 603 are connected to each other via a bus 604. The input / output (I / O) interface 605 is also connected to the bus 604.
[0164] The following components are connected to the I / O interface 605: an input section 606 including a keyboard, a mouse, etc.; an output section 607 including, for example, a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 608 including a hard disk, etc.; and a communication section 609 including a network interface card such as a LAN card, a modem, etc. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the I / O interface 605 as required. A removable medium 611, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 610 as required, so that the computer program read from it can be installed into the storage section 608 as required.
[0165] In particular, according to an embodiment of the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, an embodiment of the present invention includes a computer program product that includes a computer program tangibly embodied on a machine-readable medium, the computer program including program code for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 609, and / or installed from the removable medium 611.
[0166] Computer-readable media includes both permanent and non-permanent, removable and non-removable media implemented by any method or technology for storing information. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile discs (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices, or any other non-transitory medium that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory media such as modulated data signals and carrier waves.
[0167] For convenience of description, the above-described apparatus is described by function as various units. Of course, when implementing the present application, the functions of each unit can be implemented in one or more software and / or hardware.
[0168] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and combinations of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to produce a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices generate means for implementing the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0169] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to operate in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including an instruction device that implements the functions specified in one or more of the processes Figure 1 or steps and / or Figure 1 boxes specified in one or more of the boxes.
[0170] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, so that the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one or more of the processes Figure 1 or steps and / or Figure 1 boxes specified in one or more of the boxes.
[0171] It should also be noted that the term "comprising", "including" or any other variation thereof is intended to cover a non-exclusive inclusion, such that a process, method, article or apparatus comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or apparatus. Without further limitation, an element defined by the phrase "comprising a..." does not exclude the presence of additional identical elements in the process, method, article or apparatus comprising the element.
[0172] In the technical solution of this application, the acquisition, storage, use, processing, etc. of data all comply with the relevant provisions of national laws and regulations.
[0173] Those skilled in the art should understand that the embodiments of this application can be provided as a method, system or computer program product. Therefore, this application can take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware aspects. Moreover, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0174] This application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. This application can also be practiced in a distributed computing environment where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
[0175] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and for the relevant parts, reference can be made to the corresponding description in the method embodiment.
[0176] The above are only the embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
Claims
1. A data sharing method based on a business chain, characterized in that, the method includes: In response to a shared data encapsulation request, perform credential encapsulation processing on the shared data to obtain a verifiable data credential; Encrypt the verifiable data credential according to the set of shared users of the current institution to obtain a ciphertext message; Send the ciphertext message to a blockchain node on the business chain, so that the blockchain node sends a data acquisition message to the data receivers in the set of shared users, for the data receivers to decrypt the ciphertext message through the business chain to obtain the shared data; Wherein, the encrypting the verifiable data credential according to the set of shared users of the current institution to obtain a ciphertext message includes: Generate a master key pair according to the set of shared users of the current institution through a broadcast encryption generation algorithm, the master key pair includes a broadcast public key and a broadcast private key; Generate a decryptable private key corresponding to the user identity through a key generation algorithm according to the user identity of the users in the set of shared users of the current institution and the broadcast private key; Encrypt the verifiable data credential according to the user identity of the users in the set of shared users of the current institution and the broadcast public key through an encryption algorithm to obtain a shared ciphertext and a broadcast encryption header; Encrypt the decryptable private key corresponding to the user identity according to the public key corresponding to the user identity in the set of shared users of the current institution to obtain an encrypted private key corresponding to the user identity; Generate a set of user encrypted identities according to the user identity and the corresponding encrypted private key; Generate a ciphertext message according to the set of user encrypted identities, the set of shared users, the broadcast public key, the shared ciphertext and the broadcast encryption header.
2. The data sharing method based on a business chain according to claim 1, characterized in that, further includes: Receive a data sharing request sent by a data receiver in the business chain, the data sharing request includes requested data information; Send a data sharing confirmation message to the data receiver; Add the data receiver to the set of shared users of the current institution.
3. The data sharing method based on a business chain according to claim 1, characterized in that, the performing credential encapsulation processing on the shared data to obtain a verifiable data credential includes: Generate a data credential according to the shared data; Sign the data credential with the private key corresponding to the current identity to obtain a verifiable data credential.
4. The data sharing method based on a business chain according to claim 1, characterized in that, before sending the ciphertext message to a blockchain node on the business chain, includes: Perform admission verification according to the ciphertext message, if the admission verification passes, continue to execute the step of sending the ciphertext message to the blockchain node on the business chain.
5. A data sharing system based on a business chain, characterized in that, the system includes: a business system, a digital identity node, a business chain and a blockchain node on the business chain; the business system is used to send a shared data encapsulation request to the digital identity node; The digital identity node is used to respond to a shared data encapsulation request, perform credential encapsulation processing on the shared data to obtain a verifiable data credential; encrypt the verifiable data credential according to the shared user set of the current institution to obtain a ciphertext message; and send the ciphertext message to a blockchain node on the business chain. The blockchain node is used to receive the ciphertext message sent by the digital identity node; send a data acquisition message to a data recipient in the shared user set for the data recipient to decrypt the ciphertext message through the business chain to obtain the shared data. Wherein, the digital identity node is specifically used to generate a master key pair including a broadcast public key and a broadcast private key according to the shared user set of the current institution through a broadcast encryption generation algorithm; generate a decryptable private key corresponding to the user identity according to the user identity of the users in the shared user set of the current institution and the broadcast private key through a key generation algorithm; encrypt the verifiable data credential according to the user identity of the users in the shared user set of the current institution and the broadcast public key through an encryption algorithm to obtain a shared ciphertext and a broadcast encryption header; encrypt the decryptable private key corresponding to the user identity according to the public key corresponding to the user identity of the users in the shared user set of the current institution to obtain an encrypted private key corresponding to the user identity; generate a user encrypted identity set according to the user identity and the corresponding encrypted private key; and generate a ciphertext message according to the user encrypted identity set, the shared user set, the broadcast public key, the shared ciphertext and the broadcast encryption header.
6. A data sharing device based on a business chain Characterized in that The device includes: A credential encapsulation unit, configured to respond to a shared data encapsulation request, perform credential encapsulation processing on the shared data to obtain a verifiable data credential; An encryption unit, configured to encrypt the verifiable data credential according to the shared user set of the current institution to obtain a ciphertext message; An on-chain unit, configured to send the ciphertext message to a blockchain node on the business chain, so that the blockchain node sends a data acquisition message to a data recipient in the shared user set for the data recipient to decrypt the ciphertext message through the business chain to obtain the shared data; Wherein, the encryption unit is specifically used to generate a master key pair including a broadcast public key and a broadcast private key according to the shared user set of the current institution through a broadcast encryption generation algorithm; generate a decryptable private key corresponding to the user identity according to the user identity of the users in the shared user set of the current institution and the broadcast private key through a key generation algorithm; encrypt the verifiable data credential according to the user identity of the users in the shared user set of the current institution and the broadcast public key through an encryption algorithm to obtain a shared ciphertext and a broadcast encryption header; encrypt the decryptable private key corresponding to the user identity according to the public key corresponding to the user identity of the users in the shared user set of the current institution to obtain an encrypted private key corresponding to the user identity; generate a user encrypted identity set according to the user identity and the corresponding encrypted private key; and generate a ciphertext message according to the user encrypted identity set, the shared user set, the broadcast public key, the shared ciphertext and the broadcast encryption header.
7. A computer-readable medium having a computer program stored thereon, wherein, when the program is executed by a processor, it implements the data sharing method based on a service chain according to any one of claims 1 to 4.
8. A computer device comprising a memory and a processor, the memory being used for storing information including program instructions, and the processor being used for controlling the execution of the program instructions, wherein, when the program instructions are loaded and executed by the processor, they implement the data sharing method based on a service chain according to any one of claims 1 to 4.
9. A computer program product comprising a computer program / instructions, wherein, when the computer program / instructions are executed by a processor, they implement the data sharing method based on a service chain according to any one of claims 1 to 4.
Citation Information
Patent Citations
Private data sharing method based on smart contract
CN113468570A