A Data Encryption Method and System Based on Guardians

By introducing a guardian mechanism in the traditional encryption scheme, using the receiver and guardian public keys for double encryption and decryption, the problem of traditional encryption scheme being vulnerable to man-in-the-middle attacks and lacking homomorphic update properties is solved, and higher data transmission security and adaptability are achieved.

CN116405295BActive Publication Date: 2025-05-30BEIHANG UNIV +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202310393874.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-13
Publication Date
2025-05-30
Estimated Expiration
2043-04-13

AI Technical Summary

Technical Problem

Traditional encryption solutions are prone to man-in-the-middle attacks and lack homomorphic update properties, making them difficult to adapt to the complexity of actual use scenarios.

Method used

The data encryption method based on the guardian is adopted, and the sender uses the receiver's public key and the guardian's public key to encrypt the message, generate a double-encrypted ciphertext, and ensure that the receiver can decrypt the message through the guardian's decryption request and the delivery of the decrypted message.

Benefits of technology

It improves the security of data transmission, effectively avoids man-in-the-middle attacks, and has the nature of homomorphic updates, which is suitable for the complexity of actual use scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116405295B_ABST
    Figure CN116405295B_ABST
Patent Text Reader

Abstract

The present invention discloses a data encryption method and system based on a guardian, which relates to the technical field of data security. The method includes: the sender encrypts a first message using the public key of the receiver and the public key of the guardian, and sends the generated first ciphertext to the receiver; after receiving the first ciphertext, the receiver sends a decryption request to the guardian; after receiving the decryption request, the guardian calculates a first decryption message using the private key of the guardian and sends the first decryption message to the receiver; after receiving the first decryption message, the receiver obtains the decrypted first message according to the first decryption message and the private key of the receiver. The present invention improves the security of data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and particularly to a data encryption method and system based on a guardian. Background Art

[0002] In traditional encryption scenarios, the message sender hands over the encrypted ciphertext to the message receiver for decryption, and many man-in-the-middle attacks may occur in the intermediate links, which is not conducive to the secure transmission of messages.

[0003] In addition, traditional encryption schemes generally encrypt messages individually, and have poor adaptability to actual usage scenarios. In the actual use of encryption systems, there are often scenarios where users interact multiple times to update encryption information. Therefore, it is particularly important to design an encryption system with the property of homomorphic update. Summary of the Invention

[0004] The purpose of the present invention is to provide a data encryption method and system based on a guardian, which improves the security of data transmission.

[0005] To achieve the above object, the present invention provides the following solutions:

[0006] A data encryption method based on a guardian, comprising:

[0007] The sender encrypts the first message using the receiver's public key and the guardian's public key, and sends the generated first ciphertext to the receiver;

[0008] After receiving the first ciphertext, the receiver sends a decryption request to the guardian;

[0009] After receiving the decryption request, the guardian calculates the first decryption message using the guardian's private key, and sends the first decryption message to the receiver;

[0010] After receiving the first decryption message, the receiver obtains the decrypted first message according to the first decryption message and the receiver's private key.

[0011] Optionally, the sender encrypts the first message using the receiver's public key and the guardian's public key, and sends the generated first ciphertext to the receiver, specifically including:

[0012] The sender uses the receiver's public key and the guardian's public key to generate the first ciphertext for the message by means of Paillier encryption and the ElGamal encryption algorithm, and sends the generated first ciphertext to the receiver; the first ciphertext includes a first sub-ciphertext and a second sub-ciphertext;

[0013] The first sub-ciphertext is expressed as: CN 1 = g M r N ys ;

[0014] The second sub-ciphertext is represented as: CN 2 = h s ;

[0015] wherein, CN 1 represents the first sub-ciphertext, CN 2 represents the second sub-ciphertext, M represents the first message, (N, g) represents the recipient's public key, g represents the first random integer, N is an integer, N = pq, p is the first randomly selected prime number, q is the second randomly selected prime number, h represents the second random integer, y represents the guardian's public key, r is the third random integer, and s is the fourth random integer.

[0016] Optionally, after receiving the decryption request, the guardian calculates the first decryption message using the guardian's private key and sends the first decryption message to the recipient, specifically including:

[0017] The guardian decrypts the second sub-ciphertext using the guardian's private key to obtain the first decryption message;

[0018] The first decryption message is represented as:

[0019] wherein, E represents the first decryption message, and x represents the guardian's private key.

[0020] Optionally, it further includes: when the sender encrypts multiple messages using the recipient's public key and the guardian's public key, multiplying the generated multiple ciphertexts to obtain a combined ciphertext of the multiple messages, and sending the combined ciphertext to the recipient.

[0021] The present invention also discloses a data encryption system based on a guardian, including:

[0022] The sender is used to encrypt the first message using the recipient's public key and the guardian's public key, and send the generated first ciphertext to the recipient;

[0023] The recipient is used to send a decryption request to the guardian after receiving the first ciphertext;

[0024] The guardian is used to calculate the first decryption message using the guardian's private key after receiving the decryption request, and send the first decryption message to the recipient;

[0025] The recipient is used to obtain the decrypted first message according to the first decryption message and the recipient's private key after receiving the first decryption message.

[0026] The present invention also discloses a data encryption method based on a guardian, including:

[0027] The sender encrypts the first message using the recipient's public key and the public key of the guardian committee, and sends the generated first ciphertext to the recipient; the public key of the guardian committee is the public key in the threshold key pair generated by multiple guardians in the guardian committee using distributed keys; each guardian in the guardian committee is a node in the blockchain system;

[0028] After receiving the first ciphertext, the recipient sends a decryption request to the guardian committee;

[0029] After receiving the decryption request, the guardian calculates the decryption share using the guardian's private key and sends the decryption share to the recipient;

[0030] After receiving more than the set threshold number of the decryption shares, the recipient reconstructs the first decryption message based on more than the set threshold number of the decryption shares, and obtains the decrypted first message based on the first decryption message and the recipient's private key.

[0031] Optionally, after receiving more than the set threshold number of the decryption shares, the recipient reconstructs the first decryption message based on more than the set threshold number of the decryption shares, and obtains the decrypted first message based on the first decryption message and the recipient's private key, which specifically includes:

[0032] The recipient reconstructs more than the set threshold number of the decryption shares through Lagrange interpolation to obtain the first decryption message.

[0033] The present invention also discloses a data encryption system based on guardians, including:

[0034] The sender is used to encrypt the first message using the recipient's public key and the public key of the guardian committee, and send the generated first ciphertext to the recipient; the public key of the guardian committee is the public key in the threshold key pair generated by multiple guardians in the guardian committee using distributed keys; each guardian in the guardian committee is a node in the blockchain system;

[0035] The recipient is used to send a decryption request to the guardian committee after receiving the first ciphertext;

[0036] The guardian is used to calculate the decryption share using the guardian's private key and send the decryption share to the recipient after receiving the decryption request;

[0037] The recipient is used to reconstruct the first decryption message based on more than the set threshold number of the decryption shares and obtain the decrypted first message based on the first decryption message and the recipient's private key after receiving more than the set threshold number of the decryption shares.

[0038] According to the specific embodiments provided by the present invention, the present invention discloses the following technical effects:

[0039] The present invention adds a guardian as a trusted bridge between the sender and the receiver, forming a dual public key encryption method, which can solve various problems such as the existing traditional encryption scheme being vulnerable to man-in-the-middle attacks, and improve the security of data transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required to be used in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0041] Figure 1 Schematic flow of a data encryption method based on a guardian provided by an embodiment of the present invention Figure 1 ;

[0042] Figure 2 Schematic flow of a data encryption method based on a guardian provided by an embodiment of the present invention Figure 2 ;

[0043] Figure 3 Schematic diagram of the specific process of a data encryption method based on a guardian provided by an embodiment of the present invention;

[0044] Figure 4 Schematic diagram of the interaction process between the sender, the receiver, and the guardian or the guardianship committee in a data encryption method based on a guardian provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0045] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0046] The purpose of the present invention is to provide a data encryption method and system based on a guardian, which improves the security of data transmission.

[0047] In order to make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the drawings and specific embodiments.

[0048] Embodiment 1

[0049] As Figure 1 , Figure 3 and Figure 4As shown, this embodiment discloses a data encryption method based on a guardian, and the method specifically includes the following steps.

[0050] Step 101: The sender encrypts the first message using the recipient's public key and the guardian's public key, and sends the generated first ciphertext to the recipient.

[0051] Step 102: After receiving the first ciphertext, the recipient sends a decryption request to the guardian.

[0052] Step 103: After receiving the decryption request, the guardian calculates the first decryption message using the guardian's private key and sends the first decryption message to the recipient.

[0053] Step 104: After receiving the first decryption message, the recipient obtains the decrypted first message according to the first decryption message and the recipient's private key.

[0054] Among them, before step 101, a data encryption method based on a guardian in this embodiment further includes a user initialization phase and a guardian initialization phase. The user initialization phase includes:

[0055] Initialize the system parameters, select the security parameter 1 k , randomly select two prime numbers p and q, and try to ensure that the lengths of p and q are close or equal as much as possible. Select the RSA integer N = pq, λ = lcm(p - 1, q - 1), where lcm represents the least common multiple of two parameters. Randomly select denotes the first integer group, and the value range of the first integer group is from 1 to N 2 -1.

[0056] Let the function z represents the input of L(z), select to satisfy μ = (L(g λ mod N 2 )) - 1 mod N exists. Here, let g = N + 1.

[0057] The recipient generates its own public and private keys, the recipient's public key (N, g), and the recipient's private key (λ, μ).

[0058] The user initialization phase, that is, the system initialization phase, mainly initializes the parameters of the Paillier encryption scheme. In the subsequent steps, Paillier encryption is used to encrypt and decrypt messages. Therefore, each user participating in encryption and decryption needs to generate its own public and private key pairs according to this rule.

[0059] The guardian initialization phase includes: For the guardian user, the guardian generates its own public-private key pair. First, the guardian randomly selects its own private key and calculates the guardian public key y = h x .

[0060] For a single guardian, the guardian initialization phase generates the public and private keys of the guardian, which is convenient for users to encrypt.

[0061] Among them, step 101 specifically includes:

[0062] The sender uses the recipient's public key (N, g) and the guardian's public key y to generate the first ciphertext CN = (CN 1 , CN 2 ) for the message by using the Paillier encryption method and the ElGamal encryption algorithm, and sends the generated first ciphertext to the recipient; the first ciphertext includes a first sub-ciphertext and a second sub-ciphertext.

[0063] The first sub-ciphertext is expressed as: CN 1 = g M r N y s ;

[0064] The second sub-ciphertext is expressed as: CN 2 = h s ;

[0065] Among them, CN 1 represents the first sub-ciphertext, CN 2 represents the second sub-ciphertext, M represents the first message, (N, g) represents the recipient's public key, g represents the first random integer, N is an integer, N = pq, p is the first randomly selected prime number, q is the second randomly selected prime number, h represents the second random integer, y represents the guardian's public key, r is the third random integer, and s is the fourth random integer.

[0066] Step 101 performs two encryption operations on the first message M. Step 101 uses the public keys of the recipient and the guardian to encrypt the message, generates the combined first ciphertext and sends it to the recipient. Here, the Paillier encryption method is used, and the ElGamal encryption algorithm is used to generate two sub-ciphertexts, and then the corresponding decryption operations are performed.

[0067] Steps 102 and 103 are the guardian decryption phase, which specifically includes: When the recipient receives the ciphertext from the sender and needs to decrypt, it first needs to seek the help of the guardian, sends the identity information waiting for verification and requests the guardian to decrypt the ciphertext. The guardian calculates its own decryption message E through its private key x and sends it to the recipient.

[0068] The recipient who receives the encrypted message can request a decryption operation from the guardian. The guardian verifies and determines whether the message can be decrypted. After passing the verification, the guardian uses the private key to calculate the decryption share for subsequent secret recovery.

[0069] Among them, step 103 specifically includes:

[0070] The guardian decrypts the second sub-ciphertext using the guardian's private key to obtain the first decryption message.

[0071] The first decryption message is expressed as:

[0072] Among them, E represents the first decryption message, and x represents the guardian's private key.

[0073] Step 104 is the message decryption phase. Step 104 specifically includes: After the recipient receives the guardian's first decryption message E, the recipient first calculates the ciphertext C encrypted by the recipient's public key.

[0074] C = CN 1 / E = g M r N ;

[0075] After the recipient obtains the ciphertext C, the recipient then uses the recipient's private key (λ, μ) to call the Paillier scheme for decryption to obtain the final first message M.

[0076]

[0077] A data encryption method based on a guardian in this embodiment further includes a secret update phase, which specifically includes: When the sender encrypts multiple messages using the recipient's public key and the guardian's public key, the sender multiplies the generated multiple ciphertexts to obtain a combined ciphertext of the multiple messages, and sends the combined ciphertext to the recipient.

[0078] When the sender encrypts two messages using the recipient's public key and the guardian's public key, for the first ciphertext CN of the first message M = (CN 1 , CN 2 ), where CN 1 = g M r N y s , CN 2 = h s .

[0079] For the new secret (second ciphertext) of the second message M' is CN' = (CN 1 ', CN 2 '), where CN 1 ' = g M' r' N ys' , CN 2 ' = h s' , r' and s' are newly randomly generated during the encryption process for the new secret.

[0080] Users can combine multiple secrets into a complete new ciphertext TCN through the self-update method.

[0081] TCN = (TCN 1 , TCN 2 );

[0082] TCN 1 = CN 1 * CN 1 ' = g (M+M') (r + r') N y (s+s') ;

[0083] TCN 2 = CN 2 * CN 2 ' = h (s+s') ;

[0084] Among them, TCN represents the combined ciphertext, TCN 1 represents the first sub-combined ciphertext, TCN 2 represents the second sub-combined ciphertext, CN 1 represents the first sub-ciphertext, CN 2 represents the second sub-ciphertext, M represents the first message, (N, g) represents the recipient's public key, g represents the first random integer, N is an integer, N = pq, p is the first randomly selected prime number, q is the second randomly selected prime number, h represents the second random integer, y represents the guardian's public key, r is the third random integer, s is the fourth random integer, M' represents the second message, CN 1 ' represents the third sub-ciphertext, CN 2 ' represents the fourth sub-ciphertext, r' is the fifth random integer, s' is the sixth random integer. Among them, r, s, r' and s' are positive integers randomly selected from , and the value range of the second integer group starts from 1 to Q - 1.

[0085] The technical feature that users combine multiple secrets into a complete new ciphertext through the self-update method has good homomorphic properties. The multiplication of ciphertexts is the addition of plaintext messages, and on the original basis, the update operation of secret messages can be conveniently realized, which is more in line with the actual usage scenario.

[0086] Example 2

[0087] To execute the method corresponding to the above-mentioned Embodiment 1 to achieve the corresponding functions and technical effects, this embodiment discloses a data encryption system based on a guardian. The system includes: a sender, a receiver, and a guardian.

[0088] The sender is used to encrypt the first message using the receiver's public key and the guardian's public key, and send the generated first ciphertext to the receiver.

[0089] The receiver is used to send a decryption request to the guardian after receiving the first ciphertext.

[0090] The guardian is used to calculate the first decryption message using the guardian's private key after receiving the decryption request, and send the first decryption message to the receiver.

[0091] The receiver is used to obtain the decrypted first message according to the first decryption message and the receiver's private key after receiving the first decryption message.

[0092] Embodiment 3

[0093] As Figure 2 、 Figure 3 and Figure 4 shown, this embodiment discloses a data encryption method based on a guardian. The method includes the following steps.

[0094] Step 201: The sender encrypts the first message using the receiver's public key and the public key of the guardian committee, and sends the generated first ciphertext to the receiver; the public key of the guardian committee is the public key in the threshold key pair generated by multiple guardians in the guardian committee using a distributed key generation method; each guardian in the guardian committee is a node in the blockchain system.

[0095] Among them, before step 201, there is also a threshold guardian initialization stage: the guardian committee has n members, denoted as P 1 , P 2 , …, P n . The committee members pre-run a Distributed Key Generation (DKG) scheme, and the threshold key pairs of each member The public and private key pairs of the group (guardian committee) Here x 1 , x 2 , …, x n satisfy the relevant properties of the t-threshold secret sharing polynomial, that is, more than t guardians can jointly use their shares to recover the private key x of the group 0 .

[0096] For the guardian committee, this threshold guardian initialization phase is used for the initialization process of the guardian committee members. The determined committee members need to generate the group's threshold public-private key pair and the threshold private key share of each node through a predefined method, which is used for subsequent decryption operations on encrypted content.

[0097] Among them, step 201 specifically includes: The sender needs to perform two encryption operations on the first message M. Randomly select r and s from and encrypt the message M using the recipient's public key (N, g) and the guardian committee's public key for encryption.

[0098] The sender needs to encrypt a certain first message. Use the public keys of the recipient and the committee to encrypt the message, generate a combined first ciphertext and send it to the recipient. Here, the Paillier encryption method is adopted, and the ElGamal encryption algorithm is used to generate two sub-ciphertexts, and then corresponding decryption operations are performed later.

[0099] Step 202: After receiving the first ciphertext, the recipient sends a decryption request to the guardian committee.

[0100] Step 203: After receiving the decryption request, the guardian calculates the decryption share using the guardian's private key and sends the decryption share to the recipient.

[0101] Among them, steps 202 and 203 are the guardian threshold decryption phase: When the recipient receives the first ciphertext from the sender and needs to decrypt it, it first needs to seek the help of the guardian committee and send the identity information waiting for verification to request the decryption operation of the ciphertext from the guardian committee. The i-th guardian P i calculates its own decryption share E i through its own private key share (guardian's private key) x i and sends it to the recipient.

[0102]

[0103] In the guardian threshold decryption phase, the recipient who receives the encrypted message can request the decryption operation from the members of the supervision committee. Each supervisor of the committee independently verifies and judges whether the message can be decrypted. After verification, the decryption share is calculated using its own private key share for subsequent secret recovery.

[0104] Step 204: After the recipient receives more than the set threshold number of the decryption shares, reconstruct the first decryption message according to more than the set threshold number of the decryption shares, and obtain the decrypted first message according to the first decryption message and the recipient's private key.

[0105] Among them, step 204 is the message decryption and reconstruction stage. The receiver reconstructs more than a set threshold number of the decryption shares through Lagrange interpolation to obtain the first decryption message E, which specifically includes:

[0106] The receiver collects the decryption shares E of the guardian committee members i , when the number of correct decryption shares E i exceeds the threshold value t + 1, the decryption message E is reconstructed by the method of Lagrange interpolation. Subsequently, the same operations as described in the previous embodiment 1 can be completed to obtain the first message M. Among them, the set U is the set of correct decryption shares, and LA i,0 is the Lagrange coefficient corresponding to the 0th secret location of the P i user.

[0107]

[0108] In the message decryption and reconstruction stage, due to the previous DKG process, the guardian committee members have formed a set of group public and private key pairs and their corresponding public and private key shares. The private key shares exceeding the threshold can be reconstructed into the group private key through Lagrange interpolation. Therefore, the verified decryption shares exceeding the threshold can be reconstructed into a group decryption message E together, and then the first message M can be successfully solved by using the steps of the previous scheme.

[0109] Compared with the prior art, the present invention designs a decentralized data guardian encryption and ciphertext update method. First, a dual public key encryption method is adopted. On the basis of the traditional encryption system, a guardian mechanism is added to provide an additional layer of protection, which can better help the encryption system avoid risks such as man-in-the-middle attacks and provide more secure message encryption protection.

[0110] In addition, the decentralized data guardian encryption and ciphertext update system can adopt a threshold mechanism. Threshold cryptography has a more complex security model and richer application characteristics than traditional public key cryptography. It can construct a more secure cipher scheme. Combining the decentralized nature of the blockchain to build a trusted third-party guardian committee can ensure that the cipher scheme has stronger application applicability.

[0111] In terms of application scenario adaptability, it is impossible to perform only a single encryption operation on messages in the actual scenario. When designing the encryption scheme for the decentralized data guardian encryption and ciphertext update system of the present invention, the consideration of homomorphism is added, and the scheme is designed to have an additive homomorphism property construction method. The user's multiplication operation on their own message ciphertext is equivalent to the addition operation on the plaintext of the message to be encrypted. This measure has a significant effect in the actual application scenario, enabling users to update their own encrypted content, avoiding the complex and cumbersome multiple encryption transmission processes, making the transmission and modification process of encrypted messages more flexible, facilitating users to update encrypted messages, and having higher adaptability in the actual usage scenario.

[0112] Embodiment 4

[0113] In order to execute the method corresponding to the above Embodiment 3 to achieve the corresponding functions and technical effects, this embodiment discloses a data encryption system based on guardians, which includes:

[0114] The sender is used to encrypt the first message using the public key of the receiver and the public key of the guardian committee, and send the generated first ciphertext to the receiver; the public key of the guardian committee is the public key in the threshold key pair generated by multiple guardians in the guardian committee using distributed keys; each guardian in the guardian committee is a node in the blockchain system.

[0115] The receiver is used to send a decryption request to the guardian committee after receiving the first ciphertext.

[0116] The guardian is used to calculate the decryption share using the guardian's private key after receiving the decryption request, and send the decryption share to the receiver.

[0117] The receiver is used to reconstruct the first decrypted message according to more than the set threshold number of the decryption shares after receiving more than the set threshold number of the decryption shares, and obtain the decrypted first message according to the first decrypted message and the receiver's private key.

[0118] In this specification, each embodiment is described in a progressive manner. The key point of each embodiment is the difference from other embodiments. The same or similar parts among the embodiments can be referred to each other. For the system disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method part.

[0119] In this text, specific examples are used to illustrate the principles and implementation manners of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. A data encryption method based on a guardian, characterized in that, it includes: The sender encrypts the first message using the recipient's public key and the guardian's public key, and sends the generated first ciphertext to the recipient; After receiving the first ciphertext, the recipient sends a decryption request to the guardian; After receiving the decryption request, the guardian calculates the first decryption message using the guardian's private key and sends the first decryption message to the recipient; After receiving the first decryption message, the recipient obtains the decrypted first message according to the first decryption message and the recipient's private key; The sender encrypts the first message using the recipient's public key and the guardian's public key, and sends the generated first ciphertext to the recipient, specifically including: The sender uses the recipient's public key and the guardian's public key to generate the first ciphertext for the message by using the Paillier encryption method and the ElGamal encryption algorithm, and sends the generated first ciphertext to the recipient; the first ciphertext includes a first sub-ciphertext and a second sub-ciphertext; The first sub-ciphertext is represented as: CN 1 = g M r N y s ; The second sub-ciphertext is represented as: CN 2 = h s ; Among them, CN 1 represents the first sub-ciphertext, CN 2 represents the second sub-ciphertext, M represents the first message, (N, g) represents the recipient's public key, g represents the first random integer, N is an integer, N = pq, p is the first randomly selected prime number, q is the second randomly selected prime number, h represents the second random integer, y represents the guardian's public key, r is the third random integer, and s is the fourth random integer; After receiving the decryption request, the guardian calculates the first decryption message using the guardian's private key and sends the first decryption message to the recipient, specifically including: The guardian decrypts the second sub-ciphertext using the guardian's private key to obtain the first decryption message; The first decrypted message is expressed as: wherein, E represents the first decryption message, and x represents the guardian's private key.

2. The data encryption method based on a guardian according to claim 1, characterized in that, it further includes: When the sender encrypts multiple messages using the recipient's public key and the guardian's public key, multiply the generated multiple ciphertexts to obtain a combined ciphertext of the multiple messages, and send the combined ciphertext to the recipient.

3. A data encryption system based on a guardian, characterized in that, it includes: The sender is used to encrypt the first message using the recipient's public key and the guardian's public key, and send the generated first ciphertext to the recipient; The recipient is used to send a decryption request to the guardian after receiving the first ciphertext; The guardian is used to calculate the first decryption message using the guardian's private key after receiving the decryption request, and send the first decryption message to the recipient; The recipient is used to obtain the decrypted first message according to the first decryption message and the recipient's private key after receiving the first decryption message; The sender encrypts the first message using the recipient's public key and the guardian's public key, and sends the generated first ciphertext to the recipient, specifically including: The sender uses the recipient's public key and the guardian's public key to generate the first ciphertext for the message by using the Paillier encryption method and the ElGamal encryption algorithm, and sends the generated first ciphertext to the recipient; the first ciphertext includes a first sub-ciphertext and a second sub-ciphertext; The first sub-ciphertext is expressed as: CN 1 = g M r N y s ; The second sub-ciphertext is represented as: CN 2 = h s ; Among them, CN 1 represents the first sub-ciphertext, CN 2 represents the second sub-ciphertext, M represents the first message, (N, g) represents the recipient's public key, g represents the first random integer, N is an integer, N = pq, p is the first randomly selected prime number, q is the second randomly selected prime number, h represents the second random integer, y represents the guardian's public key, r is the third random integer, and s is the fourth random integer; After receiving the decryption request, the guardian calculates the first decryption message using the guardian's private key and sends the first decryption message to the recipient, specifically including: The guardian decrypts the second sub-ciphertext using the guardian's private key to obtain the first decryption message; The first decryption message is expressed as: wherein, E represents the first decryption message, and x represents the guardian's private key.

4. A data encryption method based on a guardian, characterized in that, The data encryption method based on guardians applies the data encryption method based on guardians described in claim 1. The data encryption method based on guardians includes: The sender encrypts the first message using the recipient's public key and the public key of the guardian committee, and sends the generated first ciphertext to the recipient; the public key of the guardian committee is the public key in the threshold key pair generated by multiple guardians in the guardian committee using distributed keys; each guardian in the guardian committee is a node in the blockchain system; After receiving the first ciphertext, the recipient sends a decryption request to the guardian committee; After receiving the decryption request, the guardian calculates the decryption share using the guardian's private key and sends the decryption share to the recipient; After receiving more than the set threshold number of the decryption shares, the recipient reconstructs the first decryption message based on more than the set threshold number of the decryption shares, and obtains the decrypted first message based on the first decryption message and the recipient's private key.

5. The data encryption method based on guardians according to claim 4, wherein, after receiving more than the set threshold number of the decryption shares, the recipient reconstructs the first decryption message based on more than the set threshold number of the decryption shares, and obtains the decrypted first message based on the first decryption message and the recipient's private key, specifically including: The recipient reconstructs more than the set threshold number of the decryption shares through Lagrange interpolation to obtain the first decryption message.

6. A data encryption system based on guardians, wherein, the data encryption system based on guardians applies the data encryption method based on guardians described in claim 4. The data encryption system based on guardians includes: The sender is used to encrypt the first message using the recipient's public key and the public key of the guardian committee, and send the generated first ciphertext to the recipient; the public key of the guardian committee is the public key in the threshold key pair generated by multiple guardians in the guardian committee using distributed keys; each guardian in the guardian committee is a node in the blockchain system; The recipient is used to send a decryption request to the guardian committee after receiving the first ciphertext; The guardian is used to calculate the decryption share using the guardian's private key and send the decryption share to the recipient after receiving the decryption request; The recipient is used to reconstruct the first decryption message based on more than the set threshold number of the decryption shares, and obtain the decrypted first message based on the first decryption message and the recipient's private key after receiving more than the set threshold number of the decryption shares.