Data sharing method, sharing device, processor and system thereof
By adopting a hierarchical encryption method on blockchain nodes, sensitive business information is symmetrically encrypted and asymmetrically encrypted layer two encryption, and the conversion key is calculated and put on the chain through the public and private keys on the blockchain, the problem of low security in sharing sensitive business information in the blockchain in financial scenarios is solved, and the secure sharing of sensitive information is realized.
Patent Information
- Application Number
- CN202211732571.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-30
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2042-12-30
AI Technical Summary
In financial scenarios, sensitive business information is not very secure in blockchain.
By adopting a hierarchical encryption method on the blockchain nodes, sensitive business information is symmetrically encrypted and asymmetrically encrypted layer two encryption, ciphertext is generated, and the conversion key is calculated and on-chain through the public and private keys on the blockchain, ensuring that only authorized nodes can decrypt and obtain plaintext.
It realizes the secure sharing of sensitive business information among different nodes on the blockchain, ensuring that only the owner and demanding party of the business information can decrypt and read, and other organizations can only obtain ciphertext and cannot parse plaintext, thus improving the security of data sharing.
Smart Images

Figure CN116346318B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of blockchain, and specifically, to a data sharing method, a sharing device, a computer-readable storage medium, a processor, and a data sharing system. Background Art
[0002] In financial scenarios, there are some sensitive business data. Institutions that own these sensitive business data only disclose these sensitive business data to trusted institutions, and do not disclose these sensitive business data to untrusted institutions. In the blockchain system, these data can be shared across institutions, but there are certain security risks in sharing in plain text. The use of proxy re-encryption technology can achieve effective data sharing, but the full-chain monitoring of the entire data encryption and sharing process is insufficient.
[0003] Therefore, an effective solution is needed to improve the security of sharing sensitive business data in blockchain in financial scenarios. Summary of the invention
[0004] The main purpose of this application is to provide a data sharing method, a sharing device, a computer-readable storage medium, a processor, and a data sharing system to solve the problem in the prior art that sensitive business information in financial scenarios is not secure enough when shared in the blockchain.
[0005] According to one aspect of an embodiment of the present invention, a data sharing method is provided, which is applied to a node of a blockchain, and the data sharing method includes: a first node generates a symmetric key, and uses the symmetric key to symmetrically encrypt first business information to generate a first ciphertext, wherein the first business information is core business information, wherein the first node is the owner of the business information, the business information includes the first business information and the second business information, and the second business information is publicly available business information; the first node obtains a first public key through a blockchain, and uses the first public key to asymmetrically encrypt the symmetric key to generate a first key ciphertext; the first node obtains a second public key on the chain of the second node through the blockchain, and calculates a conversion key based on the first public key and the second public key, and at least chains the conversion key, so that a third node calculates a second key ciphertext according to the conversion key, the first public key, the second public key and the first key ciphertext, so that the second node decrypts the second key ciphertext according to the second public key to obtain the symmetric key, and then decrypts the first ciphertext according to the symmetric key to obtain the first business information, wherein the second node is the demander of the business information, and the third node is a proxy re-encryption node.
[0006] Optionally, the method further includes: receiving request information sent by the second node, where the request information is information requesting to obtain the first service information.
[0007] Optionally, at least putting the conversion key on a chain includes: putting the ID of the second node and the signature of the second node on the business information on a chain.
[0008] Optionally, the method further includes: generating an initial conversion key based on digital certificates of other nodes, wherein the other nodes are nodes on the blockchain, and the digital certificates are signatures of the public keys of the nodes by an issuing authority of the digital certificates.
[0009] Optionally, the method further includes: updating the public key and the private key according to a predetermined period, obtaining an updated public key and an updated private key, and obtaining an updated digital certificate; and chaining the updated digital certificate, the validity period of the updated digital certificate, and the digital signatures of the other nodes.
[0010] Optionally, the method further includes: updating the conversion key according to the updated digital certificate, the updated public key and the updated private key, generating an updated conversion key, and chaining the updated conversion key.
[0011] Optionally, the symmetric encryption may adopt at least one of the following algorithms: AES algorithm, SM4 algorithm, and the asymmetric encryption may adopt at least one of the following algorithms: RSA encryption algorithm, elliptic curve encryption algorithm, SM2 algorithm.
[0012] According to another aspect of an embodiment of the present invention, a data sharing device is also provided, the device comprising: a first encryption unit, used for a first node to generate a symmetric key, and use the symmetric key to symmetrically encrypt first business information to generate a first ciphertext, the first business information is core business information, wherein the first node is the owner of the business information, the business information includes the first business information and the second business information, and the second business information is publicly available business information; a second encryption unit, used for the first node to obtain a first public key through a blockchain, and use the first public key to asymmetrically encrypt the symmetric key to generate a first key ciphertext; a third encryption unit, used for the first node to obtain a second public key on the chain of the second node through the blockchain, and calculate a conversion key based on the first public key and the second public key, and at least chain the conversion key, so that the third node calculates the second key ciphertext according to the conversion key, the first public key, the second public key and the first key ciphertext, so that the second node decrypts the second key ciphertext according to the second public key to obtain the symmetric key, and then decrypts the first ciphertext by the symmetric key to obtain the first business information, wherein the second node is the demander of the business information, and the third node is a proxy re-encryption node.
[0013] According to another aspect of the embodiments of the present invention, a computer-readable storage medium is provided. The computer-readable storage medium includes a stored program, wherein the program executes any one of the methods.
[0014] According to yet another aspect of an embodiment of the present invention, a processor is provided. The processor is used to run a program, wherein any one of the methods is executed when the program is run.
[0015] According to another aspect of an embodiment of the present invention, a data sharing system is also provided, comprising: one or more processors, a memory and one or more programs, wherein the one or more programs are stored in the memory and are configured to be executed by one or more processors, and the one or more programs include a method for executing any one of the methods.
[0016] In the embodiment of the present invention, a hierarchical encryption method is adopted to encrypt the first business information and upload it to the chain, while the second business information is not encrypted and uploaded to the chain; the first business information is encrypted by a two-layer encryption method of symmetric encryption and asymmetric encryption, so that the data demander can only obtain the ciphertext but not the plaintext, thereby achieving the technical effect of securely sharing business information between different nodes, and further solving the technical problem of low security in sharing sensitive business information in blockchain in financial scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The drawings constituting part of the present application are used to provide a further understanding of the present application. The exemplary embodiments and descriptions of the present application are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0018] Figure 1 A schematic diagram showing a flow chart of an embodiment of a data sharing method according to the present application;
[0019] Figure 2 A schematic diagram of a blockchain data sharing process according to an embodiment of a data sharing method of the present application is shown;
[0020] Figure 3 A schematic diagram of a blockchain node according to an embodiment of a data sharing method of the present application is shown;
[0021] Figure 4 A schematic diagram of the overall data sharing process according to an embodiment of a data sharing method of the present application is shown;
[0022] Figure 5 A schematic diagram of a device according to an embodiment of a data sharing method of the present application is shown. DETAILED DESCRIPTION
[0023] It should be noted that, in the absence of conflict, the embodiments and features in the embodiments of the present application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0024] In order to enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of this application.
[0025] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present application described here. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0026] As mentioned in the background technology, sensitive business information in financial scenarios in the prior art cannot be shared securely and effectively in the blockchain. In order to solve the above problem, in a typical implementation of the present application, a data sharing method, a sharing device, a computer-readable storage medium, a processor, and a data sharing system are provided.
[0027] According to an embodiment of the present application, a data sharing method is provided.
[0028] Figure 1 is a flow chart of a data sharing method according to an embodiment of the present application. Figure 1 As shown, the method comprises the following steps:
[0029] Step S101, the first node generates a symmetric key, and uses the symmetric key to symmetrically encrypt first business information to generate a first ciphertext, wherein the first business information is core business information, wherein the first node is the owner of the business information, and the business information includes the first business information and the second business information, and the second business information is publicly available business information;
[0030] In the above method, the generated symmetric key can be a random symmetric key. The above method of using the symmetric key for symmetric encryption can quickly encrypt business information, with small amount of calculation and reduced waiting time. The above core information is some sensitive business data in financial scenarios. The institutions that own these sensitive business data only disclose these sensitive business data to trusted institutions, and do not disclose these sensitive business data to untrusted institutions.
[0031] Step S102: The first node obtains a first public key through the blockchain, and uses the first public key to asymmetrically encrypt the symmetric key to generate a first key ciphertext;
[0032] In the above method, blockchain is a technical system that is jointly maintained by multiple parties in a peer-to-peer network environment and realizes data consistent storage, tamper-proof, and non-repudiation through multiple technical means such as cryptographic technology, peer-to-peer network, consensus mechanism, and block chain data structure. In the blockchain system, cross-institutional sharing of the first business information can be achieved, but there are certain security risks in sharing in plain text. The use of proxy re-encryption technology can achieve effective data sharing, but the full chain monitoring of the entire data encryption and sharing process is insufficient. The above method of using a public key to asymmetrically encrypt the above first ciphertext further improves the security of business information sharing. The node corresponding to the above first public key is any node on the blockchain. The above blockchain system can be implemented using an existing alliance chain framework, such as Fisco BCOS, Hyperledger Fabric, Changan Chain, etc.
[0033] Step S103, the first node obtains the second public key on the chain of the second node through the above-mentioned blockchain, and calculates the conversion key based on the above-mentioned first public key and the above-mentioned second public key, and at least puts the above-mentioned conversion key on the chain, so that the third node calculates the second key ciphertext according to the above-mentioned conversion key, the above-mentioned first public key, the above-mentioned second public key and the above-mentioned first key ciphertext, so that the above-mentioned second node decrypts the above-mentioned second key ciphertext according to the above-mentioned second public key to obtain the above-mentioned symmetric key, and then decrypts the above-mentioned first ciphertext through the above-mentioned symmetric key to obtain the above-mentioned first business information, wherein the above-mentioned second node is the demander of the above-mentioned business information, and the above-mentioned third node is the proxy re-encryption node.
[0034] In the above method, the above-mentioned second public key is used to asymmetrically encrypt the above-mentioned first ciphertext, which further improves the security of business information sharing. The node corresponding to the above-mentioned second public key is any node on the blockchain. In the above method, since the second business information is publicly available business information, it mainly includes: data id, basic description information and time information and other general information, and this information does not need to be encrypted and directly uploaded to the chain, so that the node organization on the blockchain can quickly obtain these publicly available business information, which can improve efficiency. The above-mentioned second ciphertext can be uploaded to the chain in the form of an information tuple, for example: [second business information, first key, second key, first ciphertext, digital signature], or other forms can be used. The above method can make the data on the blockchain chain only decrypted and read by the two organizations of the business information owner and the demander, and other organizations can only obtain the ciphertext and cannot parse the plaintext, which further improves the security of data sharing.
[0035] In the embodiment of the present invention, a hierarchical encryption method is adopted to encrypt the first business information and upload it to the chain, while the second business information is not encrypted and uploaded to the chain; the first business information is encrypted by a two-layer encryption method of symmetric encryption and split-symmetric encryption, so that the data demander can only obtain the ciphertext but not the plaintext, thereby achieving the technical effect of securely sharing business information between different nodes, and further solving the technical problem of low security in sharing sensitive business information in blockchain in financial scenarios.
[0036] It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and that, although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0037] In order to further improve the security of sensitive data sharing in financial scenarios, in a specific embodiment of the present application, the method further includes: receiving request information sent by the second node, the request information being information requesting to obtain the first business information. In the method, the second node is a trusted institution with information demand authority or permission from the information owner. The second node can be other data demanders or regulators. In the method, a semi-trusted node on the blockchain can be used, or the node can be independently made into a proxy re-encryption node for proxy re-encryption. The method introduces proxy re-encryption technology to divide business data, and by collaborating with a local certificate issuing authority, it can achieve limited knowledge and authorized directional sharing of shared data among multiple institutions, and rely on the blockchain system to share encrypted business data and store and supervise all operation processes. The overall process of data sharing is as follows: Figure 2 As shown, the data owner, organization A, uploads the data confidentially to the chain, the regulator sends an information sharing request message, organization A receives the information sharing request message and uploads the authorization information to the chain, the proxy re-encryption node receives the authorization information, and converts the authorization information into conversion information through the proxy re-encryption algorithm, and the regulator obtains the conversion information for decryption.
[0038] In another specific embodiment of the present application, at least the above-mentioned conversion key is chained, including: the ID of the above-mentioned second node and the signature of the above-mentioned second node on the above-mentioned business information are chained. In the above method, in addition to chaining the conversion key, the ID of the second node and the signature of the above-mentioned second node on the above-mentioned business information can also be chained. The above method can further enhance the security of sensitive data sharing in financial scenarios.
[0039] In another specific embodiment of the present application, the above method further includes: generating an initial conversion key based on the digital certificates of other nodes, the above other nodes are nodes on the above blockchain, and the above digital certificates are signatures of the node's public key by the issuing agency of the above digital certificates. In the above method, system configuration is required before obtaining the initial conversion key, and each participating organization node on the blockchain generates an asymmetric key pair and obtains its own identity certificate from the issuing agency of the local certificate. Start the blockchain system, set the participating organization configuration, and receive the role certificates of each participant. Each organization connects to the blockchain system through a blockchain access program. Each organization generates multiple corresponding initial re-encryption keys based on the certificates of other organizations, and pushes the node id and initial re-encryption key to the chain, along with the signature of the organization itself. Blockchain nodes such as Figure 3 As shown in Figure 1, it includes information owners, information demanders, regulators, local certificate issuing agencies, regulators, proxy re-encryption nodes, etc. The overall flow chart is as follows: Figure 4As shown in the figure, first, in the system startup and preparation phase, the system is prepared and a digital certificate is generated to join the blockchain, and a re-encryption key is generated and uploaded to the chain. In the data information upload phase, data is hierarchically encrypted and stored on the chain. Finally, in the data sharing phase, an application is initiated, authorization is performed, and a proxy re-encryption algorithm is used to finally realize data ciphertext sharing.
[0040] In another specific embodiment of the present application, the above method further includes: updating the public key and private key according to a predetermined period, obtaining an updated public key and an updated private key, and obtaining an updated digital certificate; uploading the above updated digital certificate, the validity period of the above updated digital certificate, and the digital signatures of the above other nodes to the chain. In the above method, after every 1 month or other time period, the public and private keys are regenerated, and each organization on the blockchain obtains a new certificate from the local certificate issuing agency, pushes the organization ID, certificate validity period, and certificate information to the chain, and attaches the signature of the organization. Then, the original certificate expires, and each organization uses a new certificate to process business. By using the above method of regularly replacing organization certificates and keys, the security of encryption and decryption of trusted nodes can be improved.
[0041] In another specific embodiment of the present application, the above method further includes: updating the above conversion key according to the above updated digital certificate, the above updated public key and the above updated private key, generating an updated conversion key, and putting the above updated conversion key on the chain. In the above method, after every 1 month or other time period, each organization on the blockchain obtains a new certificate from the local certificate issuing agency, generates a second updated re-encryption key according to the new agency certificate, the updated public key and the updated private key, and pushes it to the proxy computing node. Through the above method of updating the re-encryption key, the potential risk of semi-trusted computing nodes, i.e., proxy re-encryption nodes, can be reduced.
[0042] In another specific embodiment of the present application, the above-mentioned symmetric encryption can adopt at least one of the following algorithms: AES algorithm, SM1 algorithm, and the above-mentioned asymmetric encryption algorithm can adopt at least one of the following algorithms: RSA encryption algorithm, elliptic curve encryption algorithm, SM2 algorithm. In the above method, the AES algorithm (Advanced Encryption Standard), also known as Rijndael encryption method, is a block encryption standard adopted by the US federal government. After a five-year selection process, the Advanced Encryption Standard was published by the National Institute of Standards and Technology (NIST) in FIPS PUB 197 on November 26, 2001, and became a valid standard on May 26, 2002. AES supports three key lengths, including: 128 bits, 192 bits, and 256 bits. The SM1 algorithm (SM1 cryptographic algorithm, Commercial Secret No. 1 algorithm), also known as the SCB2 algorithm, is a commercial cryptographic block standard symmetric algorithm compiled by the State Cryptography Administration. The algorithm is the SM1 block cipher algorithm approved by the National Cryptography Administration. The block length and key length are both 128 bits. The algorithm is not public and only exists in the chip in the form of an IP core. The RSA algorithm is an asymmetric encryption algorithm proposed by Ronald Rivest, Adi Shamir and Leonard Adleman in 1977. The security length of the key is at least 1024 bits. The elliptic curve encryption algorithm is an asymmetric encryption algorithm based on the mathematical theory of elliptic curves. The SM2 algorithm is a national commercial encryption algorithm. It is a cryptographic algorithm standard and its application specification recognized and announced by the National Cryptography Administration. Some of the cryptographic algorithms have become international standards. Symmetric encryption algorithms and asymmetric encryption algorithms are not limited to the above algorithms. Those skilled in the art can also choose other symmetric encryption algorithms or asymmetric encryption algorithms according to actual conditions.
[0043] The embodiment of the present application also provides a data sharing device. It should be noted that the data sharing device of the embodiment of the present application can be used to execute the data sharing method provided by the embodiment of the present application. The data sharing device provided by the embodiment of the present application is introduced below.
[0044] Figure 5 Schematic diagram of a data sharing device according to an embodiment of the present application. Figure 5 As shown, the device comprises:
[0045] The first encryption unit 10 is used for the first node to generate a symmetric key, and use the symmetric key to symmetrically encrypt the first business information to generate a first ciphertext, wherein the first business information is core business information, wherein the first node is the owner of the business information, and the business information includes the first business information and the second business information, and the second business information is publicly available business information;
[0046] In the above device, the generated symmetric key can be a random symmetric key. The above method of symmetric encryption using a symmetric key can quickly encrypt business information, with a small amount of calculation and reduced waiting time. The above core information is some sensitive business data in financial scenarios. The institutions that own these sensitive business data only disclose these sensitive business data to trusted institutions, and do not disclose these sensitive business data to untrusted institutions.
[0047] The second encryption unit 20 is used for the first node to obtain the first public key through the blockchain, and use the first public key to asymmetrically encrypt the symmetric key to generate a first key ciphertext;
[0048] In the above device, blockchain is a technical system that is jointly maintained by multiple parties in a peer-to-peer network environment and realizes data consistent storage, tamper-proof and non-repudiation through multiple technical means such as cryptographic technology, peer-to-peer network, consensus mechanism, block chain data structure, etc. In the blockchain system, cross-institutional sharing of the first business information can be achieved, but there are certain security risks in sharing in plain text. The use of proxy re-encryption technology can realize effective sharing of data, but the full chain monitoring of the entire data encryption and sharing process is insufficient. The above method of using a public key to asymmetrically encrypt the above first ciphertext further improves the security of business information sharing. The node corresponding to the above first public key is any node on the blockchain. The above blockchain system can be implemented using an existing alliance chain framework, such as Fisco BCOS, Hyperledger Fabric, Changan Chain, etc.
[0049] The third encryption unit 30 is used for the first node to obtain the second public key on the chain of the second node through the blockchain, and calculate the conversion key based on the first public key and the second public key, and at least chain the conversion key, so that the third node calculates the second key ciphertext according to the conversion key, the first public key, the second public key and the first key ciphertext, so that the second node decrypts the second key ciphertext according to the second public key to obtain the symmetric key, and then decrypts the first ciphertext through the symmetric key to obtain the first business information, wherein the second node is the demander of the business information, and the third node is the proxy re-encryption node.
[0050] In the above device, the above-mentioned second public key is used to asymmetrically encrypt the above-mentioned first ciphertext, which further improves the security of business information sharing. The node corresponding to the above-mentioned second public key is any node on the blockchain. In the above device, since the second business information is publicly available business information, it mainly includes: data id, basic description information and time information and other general information, and this information does not need to be encrypted and directly uploaded to the chain, so that the node organization on the blockchain can quickly obtain these publicly available business information, which can improve efficiency. The above-mentioned second ciphertext can be uploaded to the chain in the form of an information tuple, for example: [second business information, first key, second key, first ciphertext, digital signature], or other forms can be used. The above method can make the data on the blockchain chain only decrypted and read by the two organizations of the business information owner and the demander, and other organizations can only obtain the ciphertext and cannot parse the plaintext, which further improves the security of data sharing.
[0051] The above-mentioned device adopts a hierarchical encryption method to encrypt the first business information and upload it to the chain, and does not encrypt the second business information and upload it to the chain; it adopts a two-layer encryption method of symmetric encryption and split-symmetric encryption to encrypt the first business information, so as to achieve the purpose that the data demander can only obtain the ciphertext but not the plaintext, thereby realizing the technical effect of securely sharing business information between different nodes, and further solving the technical problem of low security in sharing sensitive business information in blockchain in financial scenarios.
[0052] In order to further improve the security of sensitive data sharing in financial scenarios, in a specific embodiment of the present application, the above-mentioned device also includes: a receiving unit, which is used to receive the request information sent by the above-mentioned second node, and the above-mentioned request information is information requesting to obtain the above-mentioned first business information. In the above-mentioned device, the second node is a trusted organization with information demand authority or permission from the information owner. The above-mentioned second node can be other data demanders or regulators. In the above-mentioned device, the semi-trusted node on the blockchain can be used, or the node can be independently made into a proxy re-encryption node for proxy re-encryption. The above-mentioned device divides the business data by introducing proxy re-encryption technology, and by collaborating with the local certificate issuing agency, it can achieve limited knowledge scope and authorized targeted sharing of shared data among multiple institutions, rely on the blockchain system to share encrypted business data and perform evidence supervision on all operation processes. The overall process of data sharing is as follows: Figure 2 As shown, the data owner, organization A, uploads the data confidentially to the chain, the regulator sends an information sharing request message, organization A receives the information sharing request message and uploads the authorization information to the chain, the proxy re-encryption node receives the authorization information, and converts the authorization information into conversion information through the proxy re-encryption algorithm, and the regulator obtains the conversion information for decryption.
[0053] In another specific embodiment of the present application, on the basis of including the above-mentioned first encryption unit, the second encryption unit and the third encryption unit, the above-mentioned third encryption unit is further refined, including: a processing module, which is used to chain the ID of the above-mentioned second node and the signature of the above-mentioned second node on the above-mentioned business information. In the above-mentioned device, in addition to chaining the conversion key, the ID of the second node and the signature of the above-mentioned second node on the above-mentioned business information can also be chained. The above-mentioned device can further enhance the security of sensitive data sharing in financial scenarios.
[0054] In another specific embodiment of the present application, on the basis of including the above-mentioned first encryption unit, the second encryption unit and the third encryption unit, it also includes: a generation unit, which is used to generate an initial conversion key based on the digital certificates of other nodes, the above-mentioned other nodes are nodes on the above-mentioned blockchain, and the above-mentioned digital certificates are signatures of the public keys of the nodes issued by the issuing agency of the above-mentioned digital certificates. In the above-mentioned device, system configuration is required before obtaining the initial conversion key. Each participating organization node on the blockchain generates an asymmetric key pair and obtains its own identity certificate from the issuing agency of the local certificate. Start the blockchain system, set the participating organization configuration, and receive the role certificates of each participant. Each organization connects to the blockchain system through a blockchain access program. Each organization generates multiple corresponding initial re-encryption keys based on the certificates of other organizations, and pushes the node id and the initial re-encryption key to the chain, along with the signature of the organization itself. Blockchain nodes such as Figure 3 As shown in Figure 1, it includes information owners, information demanders, regulators, local certificate issuing agencies, regulators, proxy re-encryption nodes, etc. The overall flow chart is as follows: Figure 4 As shown in the figure, first, in the system startup and preparation phase, the system is prepared and a digital certificate is generated to join the blockchain, and a re-encryption key is generated and uploaded to the chain. In the data information upload phase, data is hierarchically encrypted and stored on the chain. Finally, in the data sharing phase, an application is initiated, authorization is performed, and a proxy re-encryption algorithm is used to finally realize data ciphertext sharing.
[0055] In another specific embodiment of the present application, on the basis of including the above-mentioned first encryption unit, the second encryption unit and the third encryption unit, it also includes: a first update unit, which is used to update the public key and the private key according to a predetermined period, obtain an updated public key and an updated private key, and obtain an updated digital certificate; the above-mentioned updated digital certificate, the validity period of the above-mentioned updated digital certificate and the digital signatures of the above-mentioned other nodes are uploaded to the chain. In the above-mentioned device, the public and private keys are regenerated every 1 month or other time period, and each organization on the blockchain obtains a new certificate from the local certificate issuing authority, and pushes the organization ID, certificate validity period, and certificate information to the chain, with the signature of the organization attached. Then, the original certificate becomes invalid, and each organization uses a new certificate to process business. Through the above-mentioned method of regularly replacing organization certificates and keys, the security of encryption and decryption of trusted nodes can be improved.
[0056] In another specific embodiment of the present application, on the basis of including the above-mentioned first encryption unit, the second encryption unit and the third encryption unit, it also includes: a second update unit, which is used to update the above-mentioned conversion key according to the above-mentioned updated digital certificate, the above-mentioned updated public key and the above-mentioned updated private key, generate an updated conversion key, and put the above-mentioned updated conversion key on the chain. In the above-mentioned device, every 1 month or other time period, each organization on the blockchain obtains a new certificate from the local certificate issuing agency, generates a second updated re-encryption key according to the new agency certificate, the updated public key and the updated private key, and pushes it to the proxy computing node. Through the above-mentioned method of updating the re-encryption key, the potential risk of semi-trusted computing nodes, i.e., proxy re-encryption nodes, can be reduced.
[0057] In another specific embodiment of the present application, on the basis of the first encryption unit, the second encryption unit and the third encryption unit, the first encryption unit is refined, the symmetric encryption can adopt at least one of the following algorithms: AES algorithm, SM1 algorithm, and the asymmetric encryption algorithm can adopt at least one of the following algorithms: RSA encryption algorithm, elliptic curve encryption algorithm, SM2 algorithm. In the above device, the AES algorithm (Advanced Encryption Standard), also known as Rijndael encryption, is a block encryption standard adopted by the US federal government. After five years of selection process, the Advanced Encryption Standard was published by the National Institute of Standards and Technology (NIST) of the United States in FIPS PUB 197 on November 26, 2001, and became a valid standard on May 26, 2002. AES supports three lengths of keys, including: 128 bits, 192 bits, and 256 bits. The SM1 algorithm (SM1 cryptographic algorithm, Commercial Secret No. 1 algorithm), also known as the SCB2 algorithm, is a commercial cryptographic block standard symmetric algorithm compiled by the State Cryptography Administration. The algorithm is the SM1 block cipher algorithm approved by the National Cryptography Administration. The block length and key length are both 128 bits. The algorithm is not public and only exists in the chip in the form of an IP core. The RSA algorithm is an asymmetric encryption algorithm proposed by Ronald Rivest, Adi Shamir and Leonard Adleman in 1977. The security length of the key is at least 1024 bits. The elliptic curve encryption algorithm is an asymmetric encryption algorithm based on the mathematical theory of elliptic curves. The SM2 algorithm is a national commercial encryption algorithm. It is a cryptographic algorithm standard and its application specification recognized and announced by the National Cryptography Administration. Some of the cryptographic algorithms have become international standards. Symmetric encryption algorithms and asymmetric encryption algorithms are not limited to the above algorithms. Those skilled in the art can also choose other symmetric encryption algorithms or asymmetric encryption algorithms according to actual conditions.
[0058] The data sharing device includes a processor and a memory. The first encryption unit, the second encryption unit and the third encryption unit are stored in the memory as program units. The processor executes the program units stored in the memory to implement corresponding functions.
[0059] The processor contains a kernel, which calls the corresponding program unit from the memory. One or more kernels can be set, and data sharing can be achieved by adjusting kernel parameters.
[0060] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.
[0061] An embodiment of the present invention provides a storage medium on which a program is stored. When the program is executed by a processor, the above data method is implemented.
[0062] An embodiment of the present invention provides a processor, and the processor is used to run a program, wherein the data sharing method is executed when the program is running.
[0063] An embodiment of the present invention provides a device, the device including a processor, a memory, and a program stored in the memory and executable on the processor, and when the processor executes the program, at least the following steps are implemented:
[0064] Step S101, the first node generates a symmetric key, and uses the symmetric key to symmetrically encrypt first business information to generate a first ciphertext, wherein the first business information is core business information, wherein the first node is the owner of the business information, and the business information includes the first business information and the second business information, and the second business information is publicly available business information;
[0065] Step S102: The first node obtains a first public key through the blockchain, and uses the first public key to asymmetrically encrypt the symmetric key to generate a first key ciphertext;
[0066] Step S103, the first node obtains the second public key on the chain of the second node through the above-mentioned blockchain, and calculates the conversion key based on the above-mentioned first public key and the above-mentioned second public key, and at least puts the above-mentioned conversion key on the chain, so that the third node calculates the second key ciphertext according to the above-mentioned conversion key, the above-mentioned first public key, the above-mentioned second public key and the above-mentioned first key ciphertext, so that the above-mentioned second node decrypts the above-mentioned second key ciphertext according to the above-mentioned second public key to obtain the above-mentioned symmetric key, and then decrypts the above-mentioned first ciphertext through the above-mentioned symmetric key to obtain the above-mentioned first business information, wherein the above-mentioned second node is the demander of the above-mentioned business information, and the above-mentioned third node is the proxy re-encryption node.
[0067] The devices in this article can be servers, PCs, PADs, mobile phones, etc.
[0068] The present application also provides a computer program product, which, when executed on a data processing device, is suitable for executing a program for initializing at least the following method steps:
[0069] Step S101, the first node generates a symmetric key, and uses the symmetric key to symmetrically encrypt first business information to generate a first ciphertext, wherein the first business information is core business information, wherein the first node is the owner of the business information, and the business information includes the first business information and the second business information, and the second business information is publicly available business information;
[0070] Step S102: The first node obtains a first public key through the blockchain, and uses the first public key to asymmetrically encrypt the symmetric key to generate a first key ciphertext;
[0071] Step S103, the first node obtains the second public key on the chain of the second node through the above-mentioned blockchain, and calculates the conversion key based on the above-mentioned first public key and the above-mentioned second public key, and at least puts the above-mentioned conversion key on the chain, so that the third node calculates the second key ciphertext according to the above-mentioned conversion key, the above-mentioned first public key, the above-mentioned second public key and the above-mentioned first key ciphertext, so that the above-mentioned second node decrypts the above-mentioned second key ciphertext according to the above-mentioned second public key to obtain the above-mentioned symmetric key, and then decrypts the above-mentioned first ciphertext through the above-mentioned symmetric key to obtain the above-mentioned first business information, wherein the above-mentioned second node is the demander of the above-mentioned business information, and the above-mentioned third node is the proxy re-encryption node.
[0072] In the above embodiments of the present invention, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0073] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only schematic. For example, the division of the above-mentioned units can be a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0074] The units described above as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0075] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0076] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, a server or a network device, etc.) to perform all or part of the steps of the above-mentioned methods of each embodiment of the present invention. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk and other media that can store program codes.
[0077] From the above description, it can be seen that the above embodiments of the present application achieve the following technical effects:
[0078] 1) The data sharing method of the present application first generates a symmetric key, and uses the symmetric key to symmetrically encrypt the first business information to generate a first ciphertext. Secondly, obtain the first public key through the blockchain, and use the first public key to asymmetrically encrypt the symmetric key to generate the first key ciphertext. Then, obtain the second public key on the second node through the blockchain, and calculate the conversion key based on the first public key and the second public key, and at least chain the conversion key, so that the third node calculates the second key ciphertext according to the conversion key, the first public key, the second public key and the first key ciphertext, so that the second node decrypts the second key ciphertext according to the second public key to obtain the symmetric key, and then decrypts the first ciphertext by the symmetric key to obtain the first business information. This method adopts a hierarchical encryption method to encrypt the first business information and upload it to the chain, and does not encrypt the second business information and upload it to the chain; it adopts a two-layer encryption method of symmetric encryption and split-symmetric encryption to encrypt the first business information, so as to achieve the purpose that the data demander can only obtain the ciphertext but not the plaintext, thereby realizing the technical effect of securely sharing business information between different nodes, and further solving the technical problem of low security in sharing sensitive business information in the blockchain in financial scenarios.
[0079] 2) In the data sharing device of the present application, the first encryption unit is used for the first node to generate a symmetric key, and use the above symmetric key to symmetrically encrypt the first business information to generate a first ciphertext, wherein the above first business information is core business information, wherein the above first node is the owner of the business information, and the above business information includes the above first business information and the second business information, and the above second business information is publicly available business information; the second encryption unit is used for the first node to obtain the first public key through the blockchain, and use the above first public key to asymmetrically encrypt the above symmetric key to generate a first key ciphertext; the third encryption unit is used for the first node to obtain the second public key on the chain of the second node through the blockchain, and calculate the conversion key based on the above first public key and the above second public key, and at least chain the above conversion key, so that the third node calculates the second key ciphertext according to the above conversion key, the above first public key, the above second public key and the above first key ciphertext, so that the above second node decrypts the above second key ciphertext according to the above second public key to obtain the above symmetric key, and then decrypts the above first ciphertext by the above symmetric key to obtain the above first business information. The device adopts a hierarchical encryption method to encrypt the first business information and upload it to the chain, and does not encrypt the second business information and upload it to the chain; it adopts a two-layer encryption method of symmetric encryption and split-symmetric encryption to encrypt the first business information, so that the data demander can only obtain the ciphertext but not the plaintext, thereby achieving the technical effect of securely sharing business information between different nodes, and further solving the technical problem of low security in sharing sensitive business information in blockchain in financial scenarios.
[0080] The above are only preferred embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A data sharing method, characterized in that: Applied on a node of a blockchain, the data sharing method includes: The first node generates a symmetric key, and uses the symmetric key to symmetrically encrypt first business information to generate a first ciphertext, wherein the first business information is core business information, wherein the first node is the owner of the business information, and the business information includes the first business information and the second business information, and the second business information is publicly available business information; The first node obtains a first public key through the blockchain, and uses the first public key to asymmetrically encrypt the symmetric key to generate a first key ciphertext; The first node obtains the second public key on the chain of the second node through the blockchain, calculates the conversion key based on the first public key and the second public key, and at least puts the conversion key on the chain, so that the third node calculates the second key ciphertext according to the conversion key, the first public key, the second public key and the first key ciphertext, so that the second node decrypts the second key ciphertext according to the second public key to obtain the symmetric key, and then decrypts the first ciphertext by the symmetric key to obtain the first business information, wherein the second node is the demander of the business information, and the third node is the proxy re-encryption node.
2. The method according to claim 1, characterized in that The method further comprises: Receive request information sent by the second node, where the request information is information for requesting to obtain the first service information.
3. The method according to claim 1, characterized in that: At least uploading the conversion key to the chain includes: The ID of the second node and the signature of the second node on the business information are put on the chain.
4. The method according to claim 1, characterized in that: The method further comprises: An initial conversion key is generated based on the digital certificates of other nodes, where the other nodes are nodes on the blockchain, and the digital certificates are signatures of the public keys of the nodes by the issuing authority of the digital certificates.
5. The method according to claim 4, characterized in that The method further comprises: Update the public key and the private key according to the predetermined period, obtain the updated public key and the updated private key, and obtain the updated digital certificate; The updated digital certificate, the validity period of the updated digital certificate and the digital signatures of the other nodes are uploaded to the chain.
6. The method according to claim 5, characterized in that The method further comprises: The conversion key is updated according to the updated digital certificate, the updated public key and the updated private key, an updated conversion key is generated, and the updated conversion key is put on the chain.
7. The method according to claim 1, characterized in that The symmetric encryption may adopt at least one of the following algorithms: AES algorithm, SM4 algorithm, and the asymmetric encryption may adopt at least one of the following algorithms: RSA encryption algorithm, elliptic curve encryption algorithm, SM2 algorithm.
8. A data sharing device, characterized in that: The device comprises: A first encryption unit is configured to generate a symmetric key at the first node, and symmetrically encrypt first business information using the symmetric key to generate a first ciphertext, wherein the first business information is core business information, wherein the first node is the owner of the business information, and the business information includes the first business information and second business information, and the second business information is publicly available business information; A second encryption unit is used for the first node to obtain a first public key through the blockchain, and use the first public key to asymmetrically encrypt the symmetric key to generate a first key ciphertext; The third encryption unit is used for the first node to obtain the second public key on the chain of the second node through the blockchain, and calculate the conversion key based on the first public key and the second public key, and at least chain the conversion key, so that the third node calculates the second key ciphertext according to the conversion key, the first public key, the second public key and the first key ciphertext, so that the second node decrypts the second key ciphertext according to the second public key to obtain the symmetric key, and then decrypts the first ciphertext by the symmetric key to obtain the first business information, wherein the second node is the demander of the business information, and the third node is the proxy re-encryption node.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored program, wherein the program executes the method of any one of claims 1 to 7.
10. A processor, characterized in that: The processor is used to run a program, wherein the program executes the method according to any one of claims 1 to 7 when running.
11. A data sharing system, characterized in that: include: One or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and are configured to be executed by the one or more processors, and the one or more programs include methods for executing any one of claims 1 to 7.
Citation Information
Patent Citations
Credible gene detection and data sharing method based on blockchain and proxy re-encryption technologies
CN108063752A
Data sharing method, device, equipment and system and storage medium
CN111181906A