A Method and System for Key Sorting in a Blockchain

By using the digest algorithm to process the public key in the blockchain to obtain feature values, determine the order and assemble the second ciphertext sequence, the problem of slow searching for the second ciphertext is solved, and a more efficient ciphertext extraction process is achieved.

CN116015659BActive Publication Date: 2025-06-24ZHONGKE MEILUO
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211530561.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-30
Publication Date
2025-06-24
Estimated Expiration
2042-11-30

AI Technical Summary

Technical Problem

During the sharing of target ciphertexts, the use of preset splicing order needs to be synchronized to each download node, resulting in a slow search speed for the second ciphertext.

Method used

By using the digest algorithm to process the public key in the blockchain, the eigenvalues ​​are obtained, and the order order is determined according to the character distribution characteristics of the eigenvalues, the second ciphertext is sorted and assembled into a sequence, and the second ciphertext is extracted in the same order at the download node, avoiding the comparison process.

Benefits of technology

The search speed of the second ciphertext is improved, and the time consumption of the download node when extracting the second ciphertext is reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116015659B_ABST
    Figure CN116015659B_ABST
Patent Text Reader

Abstract

The present invention provides a method and system for key sorting in a blockchain. The method is applied to a sending node and includes: using a symmetric encryption algorithm with a feature field as a symmetric key to obtain a first ciphertext corresponding to a file to be shared; obtaining the feature field of the file to be shared, and respectively encrypting the feature field with the public keys of download nodes to obtain at least two second ciphertexts; for each public key of a download node, processing the public key using a digest algorithm to obtain a corresponding feature value; determining an order corresponding to the feature value according to the character distribution feature included in the feature value; sorting and assembling the respective second ciphertexts according to the order to obtain a second ciphertext sequence; assembling the first ciphertext and the second ciphertext sequence into a target ciphertext and sending the target ciphertext to the download node. By applying the present invention, the corresponding second ciphertext can be directly extracted, improving the search speed of the second ciphertext.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of file storage, and particularly to a method and system for key sorting in a blockchain. Background Art

[0002] When performing one-to-many sharing of a target ciphertext, in the one-plus-many decryption file sharing, receiving method and system solution applied by the applicant, a preset splicing order is used when splicing the second ciphertext.

[0003] However, the inventor found in actual applications that before using the preset splicing order, it is necessary to synchronize the splicing order to each download node. When querying the corresponding second ciphertext at the download node, it is necessary to perform piece-by-piece comparison according to the length of the second ciphertext, which consumes a lot of time and results in a slow search speed for the second ciphertext. Summary of the Invention

[0004] The technical problem to be solved by the present invention is how to provide a method and system for key sorting in a blockchain to improve the search speed of the second ciphertext.

[0005] The present invention solves the above technical problem by the following technical means:

[0006] The present invention provides a method for key sorting in a blockchain, which is applied to a sending node. The method includes:

[0007] Using a feature field as a symmetric key, obtaining a first ciphertext corresponding to a file to be shared by using a symmetric encryption algorithm; obtaining the feature field of the file to be shared, and respectively encrypting the feature field with the public keys of download nodes to obtain at least two second ciphertexts, where the number of download nodes is two or more;

[0008] For the public key of each download node, processing the public key by using a digest algorithm to obtain a corresponding feature value; determining the order corresponding to the feature value according to the character distribution feature included in the feature value, where the digest algorithm includes: a hash algorithm;

[0009] Sorting and assembling the second ciphertexts according to the order to obtain a second ciphertext sequence; assembling the first ciphertext and the second ciphertext sequence into a target ciphertext, and sending the target ciphertext to the download node. The download node is used to extract the corresponding second ciphertext according to the order corresponding to the feature value of the public key, and obtain the corresponding target ciphertext by using the second ciphertext.

[0010] Optionally, the obtaining the feature field of the file to be shared includes:

[0011] Splitting the file to be shared into two parts, and using the part with a smaller data volume as the feature field of the file to be shared;

[0012] Alternatively, the file to be shared is split into several file shards, file feature shards are extracted from the file shards, and the file feature shards are concatenated as feature fields, where the file feature shards include: key features in the file shard with the most modification times in the file, paragraphs in the file shard where the semantic feature concentration exceeds a first preset threshold, or using a random number or the hash value of the file to be shared as one or a combination of the summary pictures of the file to be shared;

[0013] Alternatively, a random number or the hash value of the file to be shared is used as the feature field of the file to be shared.

[0014] Optionally, when using the key features in the file shard with the most modification times in the file as the file feature shards, the determination process of the feature fields includes:

[0015] For each file shard, the historical cumulative modification times of the file shard within a preset time range before the current moment are counted, and the maximum historical cumulative modification times are obtained;

[0016] If the maximum historical cumulative modification times correspond to two or more file shards, the strings at the same positions of each file shard are exchanged pairwise, a set of file shards after the exchange strings is obtained, and a file shard is randomly selected from the set as the feature field.

[0017] Optionally, determining the order sequence corresponding to the eigenvalue according to the character distribution feature included in the eigenvalue includes:

[0018] All eigenvalues are combined pairwise to obtain eigenvalue combinations;

[0019] For each eigenvalue combination, the edit distance between the two eigenvalues included is calculated;

[0020] It is determined whether the edit distances between the eigenvalues included in all eigenvalue combinations are greater than or equal to a set distance;

[0021] If so, for each eigenvalue, each character in the eigenvalue is converted to the ASCII code in decimal, and then the sum of all ASCII codes in the eigenvalue is calculated as the sorting label of the eigenvalue;

[0022] Sorting is performed according to the sorting label to obtain a label sequence, and the order sequence of the sorting label in the label sequence is used as the order sequence of the second ciphertext at the end of the second ciphertext sequence.

[0023] Optionally, when the determination result in the step of determining whether the edit distances between the eigenvalues included in all eigenvalue combinations are greater than or equal to a set distance is negative, the method further includes:

[0024] According to a preset current sampling point, use a sliding window with a preset length to extract a current string from each eigenvalue; combine all the current strings in pairs to obtain string combinations;

[0025] For each string combination, calculate the edit distance between the two strings included; when the distances between the strings included in all string combinations are greater than or equal to the set distance, for each string, convert each character in the string to its ASCII code in decimal, and then take the sum of all the ASCII codes calculated in the string as the sorting label of the string;

[0026] Sort according to the sorting label to obtain a label sequence, and use the order of the sorting label in the label sequence as the order of the second ciphertext at the end of the second ciphertext sequence.

[0027] Optionally, when the edit distance is less than the set distance, the method further includes:

[0028] Replace the current sampling point, and return to the step of using a sliding window with a preset length to extract a current string from each eigenvalue until the edit distances between the two strings included in all string combinations are greater than or equal to the set distance;

[0029] Optionally, the step of taking the sum of all the ASCII codes calculated in the string as the sorting label of the string includes:

[0030] Take the sum of the sequence number corresponding to each character in the string and the ASCII code corresponding to the character as the sorting label of the string.

[0031] Optionally, the step of sorting and assembling each second ciphertext according to the order to obtain a second ciphertext sequence includes:

[0032] For each second ciphertext, use the corresponding sorting label as the starting point of the second ciphertext, fill in zeros between each second ciphertext, and splice each second ciphertext in sequence to obtain a second ciphertext sequence.

[0033] The present invention also provides a second method for sorting keys in a blockchain, which is applied to a download node, and the method includes:

[0034] Send a download request for a target ciphertext to the download node that executes any one of the above methods, and receive the target ciphertext returned by the download node;

[0035] Split the target ciphertext into a third ciphertext and a fourth ciphertext, and use its own private key to decrypt the third ciphertext to obtain the decrypted field;

[0036] Use the decrypted field as the symmetric key, and use the symmetric encryption algorithm to decrypt the fourth ciphertext to obtain the plaintext of the file to be shared.

[0037] The present invention also provides a key sorting system in a blockchain. The system includes: a sending node, a storage node, and a downloading node. Among them,

[0038] The sending node obtains the feature field of the file to be shared, and uses the feature field as the symmetric key to obtain the first ciphertext corresponding to the file to be shared by using the symmetric encryption algorithm;

[0039] Respectively use the public key of the downloading node to encrypt the feature field to obtain at least two second ciphertexts;

[0040] Assemble the first ciphertext and at least two second ciphertexts into a target ciphertext according to a preset assembly order, and share the target ciphertext and the hash value corresponding to the target ciphertext to each storage node. Among them, the storage node includes: a blockchain node;

[0041] The downloading node receives the hash value of the target ciphertext, searches for the storage node according to the hash value, and obtains the target ciphertext from the storage node;

[0042] Split the target ciphertext into a third ciphertext and a fourth ciphertext, and use its own private key to decrypt the third ciphertext to obtain the decrypted field;

[0043] Use the decrypted field as the symmetric key, and use the symmetric encryption algorithm to decrypt the fourth ciphertext to obtain the plaintext of the file to be shared.

[0044] The advantages of the present invention are as follows:

[0045] Through the present invention, the corresponding eigenvalue is obtained by processing the public key using the digest algorithm; according to the character distribution characteristics included in the eigenvalue, the corresponding order is determined; the second ciphertexts are sorted and assembled according to the order, and the downloading node also determines the corresponding order using the same order determination rule. When the downloading node extracts the second ciphertext, it can be directly extracted according to the order, without the process of comparison, thereby improving the extraction speed of the second ciphertext. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] Figure 1 It is a schematic flowchart of a key sorting method in a blockchain provided by an embodiment of the present invention;

[0047] Figure 2 It is a schematic structural diagram of a key sorting and downloading system provided by an embodiment of the present invention. Detailed implementation manners

[0048] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the embodiments of the present invention. Apparently, the described embodiments are only a part rather than all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0049] Embodiment 1

[0050] With the rapid development of decentralized and distributed network technologies, the IPFS (InterPlanetary File System) technology based on blockchain technology has emerged. Embodiment 1 of the present invention introduces a method for sharing files with one - to - multiple decryption based on blockchain technology. Figure 1 It is a schematic flowchart of a method for sorting keys in a blockchain provided for an embodiment of the present invention, as Figure 1 shown. The method includes:

[0051] S101: Obtain the characteristic fields of the file to be shared, and use the characteristic fields as symmetric keys to obtain the first ciphertext corresponding to the file to be shared by using a symmetric encryption algorithm; obtain the characteristic fields of the file to be shared, and encrypt the characteristic fields respectively with the public keys of the download nodes to obtain at least two second ciphertexts, where the number of the download nodes is two or more.

[0052] Specifically, the blockchain network contains a large number of network nodes. Each network node can act as a sending node, a download node, or a storage node. The name of each node is determined according to the role it plays in the specific technical solution of the embodiment of the present invention. Of course, each node can concurrently execute multiple specific technical solutions. That is to say, a node can act as one or more of the roles of a sending node, a download node, and a storage node at the same time. The embodiment of the present invention does not make specific limitations on the number of roles it undertakes. When network node A is used to process the user's data and send it to other network nodes for storage, the role of network node A is a sending node; when network node A is used to receive the processed user's data sent by network node B and store it on itself, the role of network node A is a storage node. Similarly, network node B can also switch between a storage node and a sending node. Embodiment 1 of the present invention only takes the role of network node A as an example for introduction.

[0053] When the network node A serves as the sending node 20, the user logs in to the network node A using the account password to obtain the operation permission. Then, the user uploads the file to be shared to the network node A. The user performs the file sharing operation on the network node A, implementing the embodiments of the present invention.

[0054] First, the characteristic fields of the file to be shared are extracted. There are two methods for obtaining the characteristic fields:

[0055] The first method for generating the characteristic fields is as follows: The network node A, as the sending node, can split the file to be shared. For example, it can be preset that the preset data volume size of the file shard as the characteristic field after splitting is 5 kb. A 5-kb segment is split from the file to be shared according to the 5-kb file length, and this 5-kb segment is used as the characteristic field of the file to be shared. In practical applications, a 5-kb field can also be split from the file header to the file tail in the order of file encoding; or a 5-kb field can be split from the file tail. Applying the embodiments of the present invention, using the preset data volume as the splitting basis for the characteristic field is more simple and efficient.

[0056] The second method for generating the characteristic fields is as follows: The file to be shared can also be split into several file shards, and then a file shard is randomly selected from the file shards as the characteristic field of the file to be shared.

[0057] The third method for generating the characteristic fields is as follows: The hash value of the file to be shared is used as the characteristic field. Further, random fields can be inserted at preset positions in the file to be shared, and the hash value of the file to be shared after inserting the random fields is used as the characteristic field. Correspondingly, the preset positions for inserting the random fields should be synchronized to the download node in advance so that the download node can restore the file to be shared. Applying the embodiments of the present invention, compared with using the hash value of the file to be shared as the characteristic field, it avoids unauthorized personnel using the hash value of the existing file to crack the database by brute force.

[0058] In practical applications, the file to be shared can be split according to the preset data volume to obtain several file shards, and the data volume included in each file shard is the preset data volume; the file to be shared can also be split according to the preset number to obtain the preset number of file shards. Applying the embodiments of the present invention, the extraction of the characteristic fields can be achieved only by adjusting the value of the preset number or the size of the preset data volume. Since the above parameters can be freely set by the user, the difficulty of cracking the encrypted file is increased, and high security is achieved with a relatively low computational workload and user participation.

[0059] Then, use the symmetric encryption algorithm in the national cipher to encrypt the file to be shared with the feature field as the symmetric key; or first split the file to be shared into several data shards, and then encrypt each data shard with the feature field as the symmetric key; or first split the part of the file to be shared other than the feature field into several data shards, and then encrypt each data shard with the feature field as the symmetric key to obtain several first ciphertexts. In the embodiments of the present invention, any one of the above encryption methods can be used to encrypt the file to be shared, and the encryption method can be configured by the user in the human-computer interaction interface at stage A of sending. Combining with the splitting method of file sharding, the number of encryption combinations of the file to be shared is increased, thereby improving the encryption security of the file to be shared.

[0060] Then, when the sending node needs to share the first ciphertext with 5 download nodes 30, the corresponding relationship between each download node and each public key is as follows: Download node 1 (public key A); Download node 2 (public key B); Download node 3 (public key C); Download node 4 (public key D); Download node 5 (public key E).

[0061] The sending node encrypts the feature field with the above 5 public keys respectively to obtain 5 second ciphertexts:

[0062] Public key A (feature field) = second ciphertext 1;

[0063] Public key B (feature field) = second ciphertext 2;

[0064] Public key C (feature field) = second ciphertext 3;

[0065] Public key D (feature field) = second ciphertext 4;

[0066] Public key E (feature field) = second ciphertext 5.

[0067] It should be emphasized that the download nodes referred to in the embodiments of the present invention refer to download nodes in the sense of patent law, rather than download nodes in the physical sense: for example, when login account 1 has the permission to receive the file to be shared, while login account 2 does not have the permission to receive the file to be shared. When physical node 1 logs in to account 1, physical node 1 constitutes download node 1; when this physical node 1 logs in to account 2, physical node 1 cannot be used as a download node. Or, when physical node 1 logs in to account 1 and physical node 3 logs in to account 1, it means that physical node 1 and physical node 3 respectively constitute a download node. In the embodiments of the present invention, the binding relationship between the login account and the physical node is not limited, that is, in the embodiments of the present invention, the sending node and the download node are both named in a logical sense, and the specific technical logic they execute is determined by the permissions of the accounts they specifically log in to.

[0068] S102: For the public key of each download node, process the public key using a digest algorithm to obtain the corresponding eigenvalue; determine the order corresponding to the eigenvalue according to the character distribution characteristics included in the eigenvalue, where the digest algorithm includes: a hashing algorithm.

[0069] Specifically, the hashing algorithm can be used to perform hashing on the public keys of download node 1 (public key A); download node 2 (public key B); download node 3 (public key C); download node 4 (public key D); download node 5 (public key E) to obtain the corresponding hash values: download node 1 (hash1); download node 2 (hash2); download node 3 (hash3); download node 4 (hash4); download node 5 (hash5).

[0070] Then, combine all 5 eigenvalues in pairs to obtain 10 eigenvalue combinations; for each eigenvalue combination, calculate the edit distance between the two eigenvalues included. The edit distance (Levenshtein distance) refers to the minimum number of edit operations required to convert one string into another between two strings. Permissible edit operations include replacing one character with another, inserting a character, and deleting a character.

[0071] Taking the combination of has1 - hash2 as an example, where,

[0072] hash1 = a5052edaf33d14285cf5d237b37deac2e15e37ad;

[0073] hash2 = 80a36018cc4c893abb41ed5f3ab105a95c12303b.

[0074] Judge whether the edit distance between has1 and hash2 is greater than or equal to the set value. If the judgment result is yes, judge the next eigenvalue combination until all eigenvalue combinations have been judged.

[0075] When the judgment results corresponding to all eigenvalue combinations are yes,

[0076] Calculate the ASCII code -1 of "a5052edaf33d14285cf5d237b37deac2e15e37ad" in decimal, and the ASCII code -2 of "80a36018cc4c893abb41ed5f3ab105a95c12303b" in decimal. Assume that ASCII code -1 = 246; ASCII code -2 = 765. Then use 246 as the sorting label of hash1, and use 765 as the sorting label of hash2. Sort the sorting labels in descending order to obtain a label sequence. For example, if 765 is greater than 246, 765 can be placed before 246. Similarly, you can also sort the sorting labels in descending order to obtain the corresponding label sequence. It can be understood that the embodiments of the present invention do not limit the specific sorting method of the sorting tags, and any sorting rules should be pre-synchronized to the download node; or solidified in the chip of the download node. The download node can synchronize the sorting rules with the upload node according to time. The embodiments of the present invention do not limit the synchronization update process.

[0077] When the judgment results corresponding to not all eigenvalue combinations are yes, that is, among all eigenvalue combinations, there is one or more eigenvalue combinations whose edit distance is less than the set value. In this case, in order to determine the order of the eigenvalues, the following steps are added.

[0078] Taking the current sampling point as the 4th character and the sliding window length as 10 as an example, the current string "52edaf33d1" of the 4th to 13th points is extracted from the eigenvalue hash1. Similarly, the current string "36018cc4c8" of the 4th to 13th points is extracted from the eigenvalue hash2. The same number of current strings as the eigenvalues ​​can be obtained, and then the strings are combined to obtain the corresponding number of current string combinations.

[0079] Then, it is determined whether the edit distance between two current strings in each current string combination is greater than or equal to the set distance. If so, taking the current string combination "52edaf33d1-36018cc4c8" corresponding to the feature value combination of has1-hash2 as an example, the sorting label corresponding to each current string is calculated. The specific calculation process is the same as the method of calculating the sorting labels of has1 and hash2, and the embodiment of the present invention will not be repeated here. Then sort the sorting labels in the order from small to large to obtain the corresponding label sequence.

[0080] Further, the following method can be used to calculate the sorting tag corresponding to the current string "52edaf33d1". That is, the ASCII code value of the first character "5" plus the serial number "1"; the ASCII code value of the second character "2" plus "2"; the ASCII code value of the third character "2" plus "3", and so on. Thus, the sorting tags corresponding to each current string can be obtained.

[0081] When the edit distance between two current strings in any current string combination is less than the set distance, according to the preset update rule, replace the current sampling point, and return the step of extracting the current string from each eigenvalue using a sliding window of preset length until the edit distance between the two strings included in all string combinations is greater than or equal to the set distance.

[0082] It can be understood that the update rule needs to be synchronized to each upload node and download node in advance.

[0083] S103: Sort and assemble each second ciphertext according to the order sequence to obtain a second ciphertext sequence; assemble the first ciphertext and the second ciphertext sequence into a target ciphertext, and send the target ciphertext to the download node. The download node is used to extract the corresponding second ciphertext according to the order sequence corresponding to the eigenvalue of the public key, and use the second ciphertext to obtain the corresponding target ciphertext.

[0084] According to the order sequence of the sorting tags in the tag sequence, sequentially splice and assemble the second ciphertexts corresponding to each sorting tag into a second ciphertext sequence.

[0085] First, splice the second ciphertexts in order to obtain a second ciphertext sequence: [Second Ciphertext 1][Second Ciphertext 2][Second Ciphertext 3][Second Ciphertext 4][Second Ciphertext 5]

[0086] Then, splice the first ciphertext behind the second ciphertext sequence to obtain the target ciphertext:

[0087] [Second Ciphertext 1][Second Ciphertext 2][Second Ciphertext 3][Second Ciphertext 4][Second Ciphertext 5][First Ciphertext].

[0088] Further, the sorting tag corresponding to the first second ciphertext, that is, the corresponding ASCII code, can also be used as the starting point for assembly. That is, use the ASCII code as the character position corresponding to the serial number, insert each character of the second ciphertext in sequence, and then, use the character position corresponding to the ASCII code of the next second ciphertext as the starting point, and insert each character of the second ciphertext in sequence.

[0089] For example, the second ciphertext 1 corresponds to the public key A. The eigenvalue of the public key A is hash1, and the ASCII code corresponding to hash1 - 1 = 246. Similarly, the second ciphertext 2 corresponds to the public key B, and the eigenvalue of the public key B is hash2, and the ASCII code corresponding to hash2 - 2 = 765.

[0090] Pre - generate an empty second ciphertext sequence. The length of the second ciphertext sequence can be 2 times, 3 times, or 4 times the total length of all second ciphertexts. Take the 246th character position of the empty second ciphertext sequence as the insertion position of the second ciphertext 1. When inserting the second ciphertext 1, the blank character positions after the insertion position can be overwritten with the second ciphertext 1. Similarly, the 765th character position can be taken as the insertion position of the second ciphertext 2.

[0091] The download node calculates its own serial number according to its own public key. In this way, direct extraction can save time compared with traversing and comparing one by one. At the same time, the joint update order generation strategy between the download node and the sending node can achieve the secure transmission of the target ciphertext. Compared with the splicing based on a fixed order, the embodiment of the present invention improves the security of the target ciphertext transmission.

[0092] In another specific implementation of this step, when assembling the second ciphertext, the identification information of each download node can also be added before the corresponding second ciphertext. For example, the hash value of the user ID number on the download node can be used as the identification information, or the facial feature information of the user can be used as the identification information. The obtained target ciphertext sequence is:

[0093]

Identification information 1

Second ciphertext 1

Identification information 2

Second ciphertext 2

Identification information 3

Second ciphertext 3

Identification information 4

Second ciphertext 4

Identification information 5

Second ciphertext 5

First ciphertext

[0094] The sending node 20 sends the target ciphertext to each storage node (11, 12, 13), and each storage node stores the target ciphertext.

[0095] Adding identification information before hashing, after the download node decrypts, if it cannot be decrypted normally, it will not see the identification information. In this way, it can directly let the decryption party know whether the correct decryption has been performed.

[0096] The following takes the download node 30 as an example in the embodiment of the present invention to illustrate the decryption process of the decrypted file: When the download node 30 needs to download the target ciphertext, it can download from one or more of the storage nodes 11, storage node 12, and storage node 13. The specific download method can be point-to-point download or BT download. The embodiment of the present invention does not limit the specific download method. After the download node 30 downloads the target ciphertext, it disassembles the target ciphertext to obtain the first ciphertext and the second ciphertext, then calculates the corresponding sequence order using the same method as the sending node 20, searches for the corresponding encrypted feature field from the second ciphertext according to the sequence order, decrypts the encrypted feature field using its own private key to obtain the decrypted feature field, and then decrypts the first ciphertext using the decrypted feature field to obtain the file to be shared.

[0097] When the file to be shared is fully encrypted, the computing power overhead is K. When the file needs to be shared with N download nodes, the corresponding computing power overhead is NK, and then the encrypted files are uploaded separately.

[0098] In Embodiment 1 of the present invention, only the feature field is extracted from the file to be shared. The feature field is generally shorter than the total length of the file to be shared. Therefore, the computing power overhead k for encrypting the feature field once is less than K; therefore, the computing power overhead for file sharing in the embodiment of the present invention is nk. Since nk is less than NK, the more download nodes there are, the more obvious the advantage of saving computing power overhead in the embodiment of the present invention.

[0099] In addition, in the prior art, N copies of ciphertexts of the file to be shared need to be stored; while in the embodiment of the present invention, only 1 copy of ciphertext and N - 1 copies of encrypted feature field ciphertexts need to be stored. Since the feature field is shorter, the embodiment of the present invention can also save cloud storage resources.

[0100] In the third implementation manner of this step, when the sending node shares the target ciphertext to the storage node, the hash value corresponding to the target ciphertext can also be sent for the storage node and the download node to verify the target ciphertext according to the hash value. For example, the second ciphertext 1,..., the second ciphertext 5, and the first ciphertext can be concatenated in sequence to obtain the second ciphertext. Then the first ciphertext and the second ciphertext are concatenated to obtain the target ciphertext, and then the target ciphertext and the corresponding backup are sent to the storage nodes in the blockchain network respectively. After each storage node receives the target ciphertext, the sending node broadcasts the target ciphertext and the corresponding hash value. Each verification node that receives the broadcast calculates the hash value of the target ciphertext to verify the hash value broadcast by the storage node. When the verification passes, the storage node generates a new block on the blockchain, and this block stores information such as the target ciphertext, the hash value of the target ciphertext, the sending node identification information, and the storage time.

[0101] There is a problem in the above embodiments of the present invention. If one or several storage nodes go offline, the target ciphertext cannot be downloaded, resulting in low reliability of the storage of the file to be shared.

[0102] Therefore, in this step, based on the first embodiment, the following method is used to split the first ciphertext into several ciphertext shards, such as ciphertext shard 1, ciphertext shard 2,..., ciphertext shard n.

[0103] Then, the second ciphertext is combined with each ciphertext shard respectively to obtain the following target ciphertexts:

[0104] Second ciphertext + Ciphertext shard 1;

[0105] Second ciphertext + Ciphertext shard 2;

[0106] Second ciphertext + Ciphertext shard 3;

[0107] And so on, to obtain Second ciphertext + Ciphertext shard n.

[0108] Then, each target ciphertext is sent to each storage node in the blockchain network respectively. Further, each target ciphertext can be backed up multiple times and stored in different storage nodes respectively to achieve redundant storage. In this way, each storage node stores a shard of the first ciphertext, which can improve the storage reliability of the file to be shared. Even if one or several storage nodes go offline, it will not affect the download of the target ciphertext; if there are more offline storage nodes, only some ciphertext shards will be affected, and the entire target ciphertext will not be affected. Therefore, the storage reliability of the file to be shared is greatly improved.

[0109] In the fourth specific embodiment of the embodiments of the present invention, the storage nodes in the blockchain file storage network can also be classified, and some nodes are selected as high-reliability nodes, or the verified nodes are used as high-reliability nodes; at the same time, some nodes are selected as large-capacity nodes; the second ciphertext is stored using high-reliability nodes, and the first ciphertext or the ciphertext shards of the first ciphertext are stored using large-capacity nodes. At the same time, when storing the target ciphertext, a mapping relationship between the second ciphertext and the ciphertext shards of the first ciphertext, or a mapping relationship between the second ciphertext and the first ciphertext is established, and the mapping relationship table is stored in the high-reliability nodes. Applying the embodiments of the present invention can avoid the occupation of the capacity in the large-capacity nodes by the second ciphertext, and at the same time ensure the storage reliability of the target ciphertext.

[0110] In addition, when the second ciphertext and the ciphertext shards are stored on different storage nodes respectively, the process of establishing the mapping relationship can be as follows: High-reliability node 1 is mapped to large-capacity node 1, high-reliability node 1 is mapped to large-capacity node 2,..., high-reliability node x is mapped to large-capacity node n - 1, high-reliability node x is mapped to large-capacity node n, where x is less than n. That is to say, one high-reliability node can be mapped to multiple large-capacity nodes, unbinding the binding relationship between the second ciphertext and the number of the first ciphertext shards, thereby avoiding the technical problems of ciphertext shards caused by storing the second ciphertext and the ciphertext shards in a 1:1 ratio, or low file storage reliability caused by the damage of the second ciphertext.

[0111] It can be understood that the mapping relationship table can be stored in the high-reliability node. Figure 2 The following is a schematic structural diagram of the key sorting and downloading system provided by the embodiment of the present invention. As Figure 2 shown, when a user downloads a target ciphertext through download node 30, the user inputs the hash value of the target ciphertext. Download node 30 finds out the high-reliability node storing the second ciphertext from the blockchain file storage network according to the hash value. Then, the high-reliability node queries the corresponding large-capacity node from the mapping relationship table according to the hash value, and sends an instruction to the large-capacity node. After receiving the instruction, the large-capacity node sends the first ciphertext or the ciphertext shards of the first ciphertext stored in itself to download node 30. Or the high-reliability node sends the address of the large-capacity node to download node 30. Download node 30 sends a download request to the large-capacity node. After receiving the download request, the large-capacity node responds to the request to support data download. After download node 30 downloads the target ciphertext, it slices the target ciphertext to obtain a third ciphertext and a fourth ciphertext. According to the preset order, the third ciphertext corresponding to download node 30 can be screened out from the third ciphertext sequence according to the identification information of download node 30. Then, use the private key of download node 30 to decrypt the third ciphertext to obtain the encrypted field. This decrypted field is the symmetric key for encrypting the file to be shared. Download node 30 then uses the symmetric key to decrypt the fourth ciphertext to obtain the file to be shared.

[0112] Applying Embodiment 1 of the present invention, the feature field is encrypted with the public key of different download nodes 30 to obtain the second ciphertext, and then the first ciphertext of the file to be shared and the second ciphertext are stored on the storage nodes. After different download nodes 30 obtain the target ciphertext, they can all use their own private keys to decrypt the second ciphertext in the target ciphertext, thereby obtaining the feature field for encrypting the first ciphertext, realizing the decryption of the file to be shared, that is, achieving the technical effect of one sending node encrypting and two or more download nodes 30 decrypting.

[0113] Embodiment 2

[0114] On the basis of Embodiment 1, Embodiment 2 of the present invention provides another method for generating a feature field:

[0115] For each file fragment, count the historical cumulative number of times the file fragment has been modified within a preset time range before the current moment, that is, the modification frequency of the file fragment. The higher the modification frequency, the higher the importance of the file fragment. Use an asymmetric encryption algorithm to encrypt important file fragments. On the one hand, it can improve the data security of important data fragments; on the other hand, since the file fragment is modified frequently, even if some other users have legally obtained the old version of the file to be shared before, because other users do not know the splitting rules of the file fragments, they can only try to split the file fragments one by one through methods similar to brute-force cracking; moreover, they can only obtain the file fragments of the old version of the file to be shared. That is to say, it is extremely difficult for other users to obtain the file fragments that serve as feature fields in the current version of the file to be shared. That is, even if the file fragments of the old version of the file to be shared are used, the first ciphertext cannot be decrypted through brute-force cracking. Therefore, the above embodiments of the present invention can reduce the probability that illegal users obtain file fragments through the brute-force cracking method of trying one by one, and further improve the security of the symmetric encryption method. Applying the above embodiments of the present invention realizes the technical effect of controlling the decryption permission of the download node according to the file version without leakage.

[0116] In practical applications, when counting the modification frequency or the historical cumulative number of times of modification of a file fragment, if there are two or more file fragments with the same modification frequency, the following steps can be executed:

[0117] The following takes the case where the modification frequencies of two file fragments are the same as an example for illustration. The modification frequencies of file fragment A and file fragment B are both 2 times per day.

[0118] The characters corresponding to file fragment A are: 110111010110111010101001.

[0119] The characters corresponding to file fragment B are: 101110000111010101011110.

[0120] Randomly select the string "011101" corresponding to the 3rd - 8th character positions in file fragment A and exchange it with the string "111000" corresponding to the same positions, that is, the 3rd - 8th character positions, in file fragment B.

[0121] Obtain the new file fragment A1: 111110000110111010101001;

[0122] And file fragment B1: 100111010111010101011110.

[0123] Then, one of the file shards A1 and file shard B1 can be randomly selected as the feature field. Applying the above embodiments of the present invention further increases the complexity of the feature field and ensures the security of the file to be shared.

[0124] In practical applications, when the modification frequencies of the file shards are the same, or the historical cumulative number of modifications is the same, and the number of file shards corresponding to the maximum value is three or more, strings can be freely exchanged between these three or more file shards to increase the degree of string confusion and improve security.

[0125] Furthermore, when the number of file shards with equal modification frequencies is greater than two, a simulated closed container can be set up. For each file shard, a virtual elastic ball placed inside the closed container is created, and a mass, an initial velocity, and an initial movement angle are randomly assigned to each elastic ball, so that the elastic balls move and collide inside the closed container. Each time an elastic ball collides, it loses its own velocity according to a preset ratio. Strings are randomly exchanged between the two file shards corresponding to the two colliding elastic balls. After a set time period, the elastic ball with the most collision times is statistically determined, and the file shard corresponding to this elastic ball is used as the feature field. Applying the above embodiments of the present invention not only solves the selection problem when the number of file shards with equal modification frequencies is greater than two, but also can obtain a feature field that cannot be obtained by brute - force cracking through the collision method, improving the security of the feature field.

[0126] In practical applications, the formula can also be used to calculate the data volume of the feature field,

[0127] where l is the data volume of the feature field; L is the data volume of the file to be shared; k is an integer greater than or equal to 2; n is the number of download nodes. Applying the above embodiments of the present invention can not only determine the data volume of the feature field, but also control the data volume of the feature field at a relatively low level, avoiding the problem of excessive total data volume of the second ciphertext generated when the feature field is shared by n download nodes. While improving the encryption speed, storage space is saved.

[0128] Furthermore, the key features of the file shards in the above embodiments, such as keyword distribution features, image features, etc., can be used to replace the file shards as the feature field.

[0129] On the other hand, for text, it is also possible to count the distribution positions of semantic features such as keywords and task features in each file fragment. For video files, the distribution positions of human features, environmental features, etc. in video frames can be counted; for audio files, the distribution positions of audio features can be counted. Then, sort the various semantic features in the file fragment in order to obtain a semantic feature sequence, identify the feature interval between two adjacent semantic features in the semantic feature sequence, and count the number of interval characters. Then, use the number of interval characters as the horizontal axis and the number of feature intervals under this number of interval characters as the vertical axis to create an interval distribution diagram. Calculate the full width at half maximum of the interval distribution diagram, and use the reciprocal of the full width at half maximum as the semantic feature concentration degree of this file fragment. Then, use the file fragment with a semantic feature concentration degree greater than the first preset threshold, such as greater than 0.3, or the key features and / or semantic features of the file fragment with a semantic feature concentration degree greater than the first preset threshold as the first summary. In the embodiment of the present invention, the full width at half maximum is used to measure the semantic feature concentration degree. Compared with using the kurtosis coefficient in the prior art, there is only addition and subtraction operations and no calculation process of high-order sample central moments, so the calculation amount is smaller and the operation efficiency is higher.

[0130] Then, use the feature field as the encryption key and use the national secret SM4 symmetric encryption algorithm to encrypt the file to be shared to obtain the first ciphertext. In practical applications, the SM4 symmetric encryption algorithm can also be used to encrypt the part of the file to be shared except the feature field to obtain the first ciphertext.

[0131] In another specific implementation manner of this step, different users are working on the same file at the same time. However, when a user realizes one-to-many decryption and does not want other users to have the opportunity to crack the first ciphertext of this file, the following method can be used to determine the feature field extracted from the file to be shared, and then symmetrically encrypt the remaining part of the file to be shared after extracting the department feature field to obtain the first ciphertext.

[0132] For example, use the formula hash(current timestamp + file to be shared + hash(private key + perturbation code)) to calculate the feature field for the file to be shared. In practical applications, the perturbation code can be a SMS verification code. Then, randomly insert the SMS verification code into the private key string or randomly replace the characters in the private key string with the SMS verification code to obtain a changed private key, which ensures the security of the private key. Further, use the hash algorithm to perform a one-way mapping on the changed private key to further ensure that the private key is not leaked. Since the private key of each sending node is the only information in the whole network, using the information based on the private key to encrypt the feature field can ensure the uniqueness of the feature field in the whole network. At the same time, to ensure the security of the private key, the embodiment of the present invention uses the above method to protect the private key. The embodiment of the present invention realizes the control of different authorization ranges for the same file while ensuring the security of the private key, and avoids the possibility that the first ciphertext is cracked by other users.

[0133] Applying the embodiments of the present invention, even for the same file, the characteristic fields processed by different sending nodes are still different. Therefore, different users can control the diffusion range of the file, avoid unnecessary troubles caused by the file being cracked by competitors, and improve the security of file storage.

[0134] Embodiment 3

[0135] Based on Embodiment 1, in the embodiments of the present invention, before step S101, the following steps are added: The sending node sends a storage request to each storage node in the storage network, and after receiving the storage request, each storage node returns response information including its own status characteristics. For each storage node, the sending node matches the self-status characteristics of the storage node with the storage requirements of the file to be shared pre-configured by the user, and shares the target ciphertext and the hash value corresponding to the target ciphertext to the storage nodes whose matching degree is higher than the third preset threshold.

[0136] Exemplarily, the splicing order and splicing position of each field in the storage requirement vector used to represent the storage requirements and storage conditions are pre-specified.

[0137] When the user uploads the file to be shared, different requirements for the upload, storage, and reception of the file to be shared are generally put forward. For example, some users require high reliability, and the user can select the corresponding reliability value in the reliability form entry on the upload interface of the file to be shared; some users require the file upload or download speed, and the corresponding response speed can be selected in the corresponding speed form entry on the upload interface of the file to be shared. At the same time, the sending node reads the data volume size and data type (such as text data, audio-visual data, or code data) of the file to be shared, and splices them into the storage requirement vector of the file to be shared by the user in sequence according to the fields in the form entries input by the user.

[0138] When the user uploads the file to be shared and / or when the user makes selections or inputs in each form entry on the upload interface, a storage request can be sent to each storage node in the storage network. When the storage node receives the storage request, it will return its own status characteristics, such as receiving time, device performance, remaining bandwidth, remaining capacity, continuous running time, mean time between failures, etc. to the sending node. For each storage node, the return node splices the status characteristics returned by each storage node into a storage condition vector in sequence.

[0139] Use the string fuzzy matching algorithm in the prior art to match the storage condition vector with the storage requirement vector, and use the storage node corresponding to the storage condition vector with a matching degree greater than the second preset threshold as the matching result; then execute step S101.

[0140] In the first further improved technical solution of Embodiment 3 of the present invention, in order to narrow the selection range of storage nodes to avoid information congestion caused by full-network replies, each storage node that receives broadcast information from a receiving node in the present invention embodiment can determine whether the storage request exceeds a set duration according to the moment when the storage request is received and the moment when the storage request is transmitted. If not, the storage node returns its own status characteristics to the sending node according to the storage request; if so, the storage request is discarded. Generally speaking, the size of the set duration is proportional to the number of storage nodes in the storage network and proportional to the structural complexity of the storage network.

[0141] For example, a formula can be used. First, determine the complexity value of the storage network topology structure, where O is the topology complexity value of the storage network; l is the number of edges between each node in the storage network; M is half of the number of storage nodes in the storage network; p is the number of storage node clusters in the storage network; T1 is the number of communication routes in the storage network whose historical communication route length is greater than the mode of the communication route length; T2 is the number of historical communication routes in the storage network. In practical applications, whether the communication delay is greater than the fourth preset threshold can be used as the basis for node clustering: that is, when the direct communication time between two nodes is less than the fourth preset threshold, these two nodes are divided into one cluster.

[0142] Then, different weights are respectively assigned to the number of storage nodes and the structural complexity of the storage node network at the current moment, and the formula is used to calculate the value of the set duration, where

[0143] t is the size of the set duration; t1 is the first preset duration; w1 is the weight corresponding to the number of storage nodes at the current moment in the storage network; m1 is the number of online storage nodes at the current moment in the storage network; m max is the historical maximum number of simultaneously online nodes in the storage network; t2 is the second preset duration; w2 is the complexity value corresponding to the topology complexity of the storage network.

[0144] Furthermore, the effective range of the value of the set duration can be set to 1 hour, 8 hours, 1 day, or 2 days. The receiving node broadcasts the calculated set duration to the entire network. After receiving the broadcast, each storage node in the storage network no longer calculates the set duration within the effective range. At the same time, the storage node counts the effective range. When the timing of the effective range ends, the storage node calculates according to the state of the storage network at the current moment, and then returns to execute the step of broadcasting the calculated set duration to the entire network. In actual applications, in order to obtain the number of online storage nodes in the storage network at the current moment, the storage node will send an inquiry request to the entire network, which will increase the network communication load. In order to reduce the impact on the storage network, the storage node can calculate the set duration when the overall network communication load is low. If at the end of the effective range, the information of the set duration sent by other storage nodes has not been received, or the overall network communication load is high and not suitable for calculating the set duration, the system default set duration can be used until the information of the set duration sent by other storage nodes is received, or the overall network communication load drops to an appropriate level. Of course, not all storage nodes will participate in the calculation of the set duration. Storage nodes can voluntarily participate in the calculation of the set duration. After the storage node completes the calculation, it will share the calculation parameters and results with other storage nodes that voluntarily participate in the calculation of the set duration for verification. After the verification is passed, it will be broadcast to all storage nodes in the storage network.

[0145] Example 4

[0146] The storage nodes in the storage network may be distributed in different countries or regions. In addition, some storage nodes may restrict the data content or data type stored in the storage nodes due to their own storage capacity considerations. Therefore, how to review the data stored in each storage node to comply with local regulations or storage node internal control requirements is a technical problem that needs to be solved urgently.

[0147] In order to solve the above problems, the following steps are added:

[0148] When the sending node sends the concatenation result of the ciphertext shards of the first ciphertext and the second ciphertext, or the target ciphertext, to the storage node 12, it also sends the file content digest corresponding to the first ciphertext and the file type information. After receiving the information sent by the sending node, the storage node 12 determines whether it can store the concatenation result of the decrypted ciphertext shards of the first ciphertext and the second ciphertext, or the target ciphertext, according to the file content digest and the file type information; if so, it stores the concatenation result of the ciphertext shards of the first ciphertext and the second ciphertext, or the target ciphertext, and returns a receipt message to the sending node; if not, it forwards the received information from the sending node to other storage nodes 13 so that the other storage nodes 13 execute the step of determining whether they can store the concatenation result of the decrypted ciphertext shards of the first ciphertext and the second ciphertext, or the target ciphertext, according to the file content digest and the file type information; and returns a receipt message to the sending node 20 when the other storage nodes 13 can store the concatenation result of the decrypted ciphertext shards of the first ciphertext and the second ciphertext, or the target ciphertext.

[0149] Applying the above embodiments of the present invention, the storage node 12 can screen the data sent by the sending node to make its data storage behavior comply with the requirements of local laws, regulations or customs, and forward the data sent by the sending node to other storage nodes 13 when it does not meet the local requirements, so that the storage network can be compliant while ensuring the reliability of storage.

[0150] Embodiment 5

[0151] Since several second ciphertexts respectively correspond to the public keys of different download nodes, however, during the download process, the storage node does not know which download node will send a download request to itself. Therefore, the storage node needs to store all the second ciphertexts and store the first ciphertext or the ciphertext shards of the first ciphertext. Embodiment 5 of the present invention takes the storage node A storing the target ciphertext as an example for introduction: the target ciphertext includes the second ciphertext 1, the second ciphertext 2, the second ciphertext 3 and the first ciphertext. Different second ciphertexts correspond to the public keys of different download nodes. If the second ciphertext 1, the second ciphertext 2, the second ciphertext 3 and the first ciphertext are concatenated in sequence to obtain the target ciphertext, and then the target ciphertext is stored in the storage node. When the download node downloads, it cannot determine the position of the second ciphertext corresponding to its own public key. Therefore, it is necessary to pre-specify the position of the second ciphertext corresponding to each public key, and then the download node obtains the second ciphertext from the corresponding position.

[0152] However, in the above method, the download node still needs to search for the position character by character, so the efficiency is low.

[0153] To solve the above problems, when the storage node receives a download request from the download node, it automatically adjusts the second ciphertext corresponding to the public key of the download node to the head of the target ciphertext. For example:

[0154] The concatenation order of the strings in the target ciphertext is the second ciphertext 1, the second ciphertext 2, the second ciphertext 3, and the first ciphertext.

[0155] The second ciphertext corresponding to the public key C of the download node 3 is the second ciphertext 3, which is at the end of all the second ciphertexts. The storage node automatically adjusts the arrangement order of the second ciphertexts, and places the second ciphertext corresponding to the download node at the front of all the second ciphertexts. In this way, the download node 3 can obtain the corresponding second ciphertext from the beginning, without searching for the second ciphertext character by character, improving the decryption efficiency of the download node and reducing the hardware performance requirements for the download node. At the same time, when the download node 3 shares the target ciphertext with the download node 2, the download node 2 can decrypt the file to be shared without downloading the second ciphertext from the storage node, thereby expanding the application scope of the network in the embodiments of the present invention.

[0156] Embodiment 6

[0157] Embodiment 6 of the present invention provides another method for sorting keys in a blockchain, which is applied to a storage node. The method includes:

[0158] Receiving the target ciphertext sent by the sending node that executes the method according to any one of Embodiments 1-5.

[0159] In a specific real-time manner of the embodiments of the present invention, the method further includes:

[0160] When going online each time, or periodically forwarding the file shards stored by itself to the backup node, and the backup node is used to receive and store the file shards;

[0161] When the storage node receives a shutdown instruction, forwarding the file shards stored by itself to the pre-determined target neighbor nodes, where the target neighbor nodes are storage nodes with a network delay less than a set time from the storage node.

[0162] In another specific real-time manner of the embodiments of the present invention, the method for determining the target neighbor nodes includes:

[0163] Combining the neighbor nodes of the storage node and the neighbor nodes of the neighbor nodes to form a neighbor node set, and determining the node with the most connected neighbor nodes in the neighbor node set as the target neighbor node.

[0164] Embodiment 7

[0165] Embodiment 7 of the present invention provides another method for sorting keys in a blockchain, which is applied to a download node. The method includes:

[0166] Send a download request for the target ciphertext to the download node that executes the method described in Embodiment 6, and receive the target ciphertext returned by the download node;

[0167] Split the target ciphertext into a third ciphertext and a fourth ciphertext, and use its own private key to decrypt the third ciphertext to obtain the decrypted field;

[0168] Use the decrypted field as a symmetric key, and use the symmetric encryption algorithm to decrypt the fourth ciphertext to obtain the plaintext of the file to be shared.

[0169] Embodiment 8

[0170] Embodiment 8 of the present invention provides a key sorting system in a blockchain. The system includes: a sending node that executes the method described in any one of Embodiments 1-5, a storage node that executes the method described in Embodiment 6, and a download node that executes the method described in Embodiment 7. Among them,

[0171] The sending node obtains the characteristic field of the file to be shared, and uses the characteristic field as a symmetric key to obtain the first ciphertext corresponding to the file to be shared by using the symmetric encryption algorithm;

[0172] Encrypt the characteristic field respectively by using the public key of the download node to obtain at least two second ciphertexts;

[0173] Assemble the first ciphertext and at least two second ciphertexts into a target ciphertext according to a preset assembly order, and share the target ciphertext and the hash value corresponding to the target ciphertext to each storage node. Among them, the storage node includes: a blockchain node;

[0174] The download node receives the hash value of the target ciphertext, searches for the storage node according to the hash value, and obtains the target ciphertext from the storage node;

[0175] Split the target ciphertext into a third ciphertext and a fourth ciphertext, and use its own private key to decrypt the third ciphertext to obtain the decrypted field;

[0176] Use the decrypted field as a symmetric key, and use the symmetric encryption algorithm to decrypt the fourth ciphertext to obtain the plaintext of the file to be shared.

[0177] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for sorting keys in a blockchain, characterized in that, Applied to a sending node, the method includes: Using the feature field as a symmetric key and applying a symmetric encryption algorithm to obtain a first ciphertext corresponding to the file to be shared; obtaining the feature field of the file to be shared, and respectively encrypting the feature field using the public keys of the download nodes to obtain at least two second ciphertexts, where the number of the download nodes is two or more; For each public key of the download nodes, using a digest algorithm to process the public key to obtain a corresponding feature value; determining the order corresponding to the feature value according to the character distribution feature included in the feature value, where the digest algorithm includes: a hash algorithm; Sorting and assembling the second ciphertexts according to the order to obtain a second ciphertext sequence; assembling the first ciphertext and the second ciphertext sequence into a target ciphertext and sending the target ciphertext to the download nodes, where the download nodes are used to extract the corresponding second ciphertext according to the order corresponding to the feature value of the public key, and use the second ciphertext to obtain the corresponding target ciphertext; The determining the order corresponding to the feature value according to the character distribution feature included in the feature value includes: Combining all the feature values in pairs to obtain feature value combinations; For each feature value combination, calculating the edit distance between the two feature values included; Determining whether the edit distance between the feature values included in all the feature value combinations is greater than or equal to a set distance; If so, for each feature value, converting each character in the feature value to the ASCII code in decimal, and then taking the sum of all the ASCII codes calculated in the feature value as the sorting label of the feature value; sorting according to the sorting label to obtain a label sequence, and taking the order of the sorting label in the label sequence as the order of the second ciphertext at the end of the second ciphertext sequence; If not, according to a preset current sampling point position, using a sliding window with a preset length to extract a current string from each feature value; combining all the current strings in pairs to obtain string combinations; for each string combination, calculating the edit distance between the two strings included; when the distance between the strings included in all the string combinations is greater than or equal to the set distance, for each string, converting each character in the string to the ASCII code in decimal, and then taking the sum of all the ASCII codes calculated in the string as the sorting label of the string; sorting according to the sorting label to obtain a label sequence, and taking the order of the sorting label in the label sequence as the order of the second ciphertext at the end of the second ciphertext sequence.

2. The method for sorting keys in a blockchain according to claim 1, characterized in that The obtaining the feature field of the file to be shared includes: Splitting the file to be shared into two parts, and taking the part with a smaller data volume as the feature field of the file to be shared; Alternatively, the file to be shared is split into several file shards, file feature shards are extracted from the file shards, and the file feature shards are concatenated as feature fields, where the file feature shards include: key features in the file shard with the most modification times in the file, paragraphs in the file shard with a semantic feature concentration exceeding a first preset threshold, or using a random number or the hash value of the file to be shared as one or a combination of the summary pictures of the file to be shared; Alternatively, a random number or the hash value of the file to be shared is used as the feature field of the file to be shared.

3. The method for sorting keys in a blockchain according to claim 2, wherein, When using the key features in the file shard with the most modification times in the file as the file feature shards, the determination process of the feature fields includes: For each file shard, the historical cumulative modification times of the file shard within a preset time range before the current moment are counted, and the maximum historical cumulative modification times are obtained; When the maximum historical cumulative modification times correspond to two or more file shards, the strings at the same positions of each file shard are pairwise exchanged to obtain a set of file shards after the exchange of strings, and a file shard is randomly selected from the set as the feature field.

4. A method for sorting keys in a blockchain according to claim 1, characterized in that, After calculating the edit distance between the two strings included in the calculation, when the distances between the strings included in all string combinations are not all greater than or equal to the set distance, the method further includes: Changing the current sampling point, and returning to the step of extracting the current string from each feature value using a sliding window of a preset length until the edit distance between the two strings included in all string combinations is greater than or equal to the set distance.

5. A method for sorting keys in a blockchain according to claim 1, characterized in that, The step of taking the sum of all ASCII codes in the string as the sorting label of the string includes: Taking the sum of the sequence numbers corresponding to each character in the string and the ASCII code corresponding to the character as the sorting label of the string.

6. The method for sorting keys in a blockchain according to claim 1, characterized in that, The step of sorting and assembling each second ciphertext according to the order to obtain a second ciphertext sequence includes: For each second ciphertext, using the corresponding sorting label as the starting point of the second ciphertext, padding zeros between each second ciphertext, and sequentially concatenating each second ciphertext to obtain a second ciphertext sequence.

7. A key sorting method in a blockchain, applied to a download node, characterized in that, The method includes: Sending a download request for the target ciphertext to the download node that executes the method according to any one of claims 4-6, and receiving the target ciphertext returned by the download node; Splitting the target ciphertext into a third ciphertext and a fourth ciphertext, and decrypting the third ciphertext using its own private key to obtain a decrypted field; Using the decrypted field as a symmetric key, and decrypting the fourth ciphertext using a symmetric encryption algorithm to obtain the plaintext of the file to be shared.

8. A key sorting system in a blockchain for performing the method according to any one of claims 1-6, characterized in that, The system includes: a sending node, a storage node, and a download node, where The sending node obtains the feature field of the file to be shared, and uses the feature field as a symmetric key to obtain a first ciphertext corresponding to the file to be shared using a symmetric encryption algorithm; Encrypting the feature field using the public key of the download node respectively to obtain at least two second ciphertexts; Assemble the first ciphertext into a target ciphertext with at least two second ciphertexts according to a preset assembly order, and share the target ciphertext and the hash value corresponding to the target ciphertext to each storage node, where the storage nodes include: blockchain nodes; The download node receives the hash value of the target ciphertext, searches for the storage node according to the hash value, and obtains the target ciphertext from the storage node; Split the target ciphertext into a third ciphertext and a fourth ciphertext, and decrypt the third ciphertext with its own private key to obtain the decrypted field; Use the decrypted field as a symmetric key, and decrypt the fourth ciphertext with a symmetric encryption algorithm to obtain the plaintext of the file to be shared.

Citation Information

Patent Citations

  • Security data deduplication and encryption method adopting similarity perception

    CN107659401A

  • Information processing method and information processing system

    US20180203808A1