Information sending method, decryption data generation method, device, equipment and medium
The blockchain data is encrypted through the proxy re-encryption layer and a collection of proxy re-encryption key fragments is generated, which solves the problem of insecure key distribution and realizes the secure flow of data on the blockchain.
Patent Information
- Application Number
- CN202310266184.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-13
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2043-03-13
AI Technical Summary
During the blockchain data flow process, key distribution is unsafe and unreliable, resulting in an increase in the possibility of data leakage.
The encrypted data is encrypted through the proxy re-encryption layer, and a collection of proxy re-encryption key fragments are generated. The public key information is used for data encryption and decryption, avoiding the direct passing of the key to the real entrusted party, realizing the secure flow of data.
Ensure the security of data during the circulation process, avoid the problem of insecure key distribution, and ensure the secure data flow between the real entrusted party and the entrusted party.
Smart Images

Figure CN116436643B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present disclosure relate to the field of computer technology, and in particular to an information sending method, a decrypted data generating method, an apparatus, a device, and a medium. Background Art
[0002] Currently, the typical method for data transfer on blockchains is as follows: the client encrypts plaintext data using symmetric encryption to obtain encrypted data. The encrypted data and the corresponding key are distributed to the client, who then uses the corresponding key to decrypt the plaintext data.
[0003] However, the inventors have discovered that when using the above method to transfer data, the following technical problems often occur:
[0004] During the key distribution process, there are problems of insecurity and unreliability in key distribution, which may lead to the possibility of data leakage during the flow process.
[0005] The above information disclosed in this Background section is only for enhancement of understanding of the background of the inventive concept and therefore it may contain information that does not form the prior art that is already known in this country to a person of ordinary skill in the art. Summary of the Invention
[0006] The content of this disclosure is used to briefly introduce concepts that will be described in detail in the detailed description section below. The content of this disclosure is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.
[0007] Some embodiments of the present disclosure propose information sending methods, decryption data generation methods, devices, equipment and media to solve the technical problems mentioned in the above background technology section.
[0008] In the first aspect, some embodiments of the present disclosure provide an information sending method, which is applied to a delegating client, comprising: in response to determining that a node corresponding to the delegating node information in a node information network receives a data encryption request, encrypting the encrypted data through a proxy re-encryption layer corresponding to the above-mentioned delegating node information to obtain ciphertext-related data information, wherein each node information corresponding node in the above-mentioned node information network includes: a proxy re-encryption layer; determining the public key information corresponding to at least one delegate node information in the above-mentioned node information network and a target delegate node in the above-mentioned at least one delegate node information for at least one delegate client; generating a proxy re-encryption key fragment set for the above-mentioned at least one delegate node information based on the above-mentioned public key information; executing a subscription to a message confirmation event for the above-mentioned delegating node information and the above-mentioned at least one delegate node information; in response to determining that the above-mentioned message confirmation event is successfully executed, distributing the above-mentioned proxy re-encryption key fragment set to at least one delegate client corresponding to the above-mentioned at least one delegate node information, and sending the above-mentioned ciphertext-related data information to the target delegate client corresponding to the above-mentioned target delegate node.
[0009] Optionally, each node information corresponding node in the above-mentioned node information network also includes: an interface layer; and in the above-mentioned response to determining that the node corresponding to the delegator node information in the node information network receives a data encryption request, the encrypted data is encrypting the proxy re-encryption layer corresponding to the above-mentioned delegator node information to obtain ciphertext-related data information, the above-mentioned method also includes: calling the interface layer of the node corresponding to the above-mentioned delegator node information to generate public node parameters; synchronizing the above-mentioned public node parameters to at least one delegate node corresponding to the above-mentioned at least one delegate node information.
[0010] Optionally, the above-mentioned ciphertext-related data information includes: ciphertext data, key-encrypted data, ciphertext data location information, key-encrypted data location information, and ciphertext data identification; and the above-mentioned proxy re-encryption layer corresponding to the above-mentioned client node information encrypts the encrypted data to obtain the ciphertext-related data information, including: generating the above-mentioned ciphertext data, the above-mentioned key-encrypted data and the above-mentioned ciphertext data identification by calling the proxy re-encryption layer; storing the above-mentioned ciphertext data and the above-mentioned key-encrypted data in the node corresponding to the above-mentioned client node information, and determining the storage location of the above-mentioned ciphertext data and the storage location of the above-mentioned key-encrypted data as the ciphertext data location information and the key-encrypted data location information, respectively.
[0011] Optionally, the above method also includes: calling the decryption data interface of the interface layer corresponding to the above-mentioned client node information according to the above-mentioned ciphertext data identifier to retrieve the above-mentioned ciphertext data location information; calling the proxy re-encryption layer interface corresponding to the above-mentioned client node information according to the above-mentioned ciphertext data location information to decrypt the above-mentioned ciphertext data and obtain the decrypted data.
[0012] Optionally, the above-mentioned ciphertext-related data information includes: a re-encryption result integration threshold corresponding to the target delegate node information; and the above-mentioned generation of a set of proxy re-encryption key fragments for the above-mentioned at least one delegate node information based on the above-mentioned public key information, including: generating the above-mentioned proxy re-encryption key fragment set based on the above-mentioned public key information, the number of delegate node information included in the above-mentioned at least one delegate node information and the above-mentioned re-encryption result integration threshold.
[0013] Optionally, the method further includes: storing the key fragment set and the ciphertext data identifier.
[0014] Optionally, each node information corresponding node in the above node information network further includes: a cryptographic algorithm management layer, a proxy re-encryption implementation layer and an algorithm layer.
[0015] In a second aspect, some embodiments of the present disclosure provide an information sending device, which is applied to a delegating client, including: an encryption unit, which is configured to, in response to receiving a data encryption request at a node corresponding to the delegating node information in a determined node information network, encrypt the encrypted data through a proxy re-encryption layer corresponding to the above-mentioned delegating node information to obtain ciphertext-related data information, wherein each node information corresponding node in the above-mentioned node information network includes: a proxy re-encryption layer; a determination unit, which is configured to determine, for at least one delegated client, at least one delegated node information in the above-mentioned node information network and a target node in the above-mentioned at least one delegated node information Public key information corresponding to the delegate node; a first generating unit, configured to generate a set of proxy re-encryption key fragments for the above-mentioned at least one delegate node information based on the above-mentioned public key information; an executing unit, configured to execute subscription to message confirmation events for the above-mentioned delegator node information and the above-mentioned at least one delegate node information; a sending unit, configured to distribute the above-mentioned proxy re-encryption key fragment set to at least one delegate client corresponding to the above-mentioned at least one delegate node information in response to determining that the above-mentioned message confirmation event is executed successfully, and send the above-mentioned ciphertext-related data information to the target delegate client corresponding to the above-mentioned target delegate node.
[0016] Optionally, each node information corresponding node in the above-mentioned node information network also includes: an interface layer; and the device also includes: calling the interface layer of the node corresponding to the above-mentioned delegator node information to generate public node parameters; synchronizing the above-mentioned public node parameters to at least one delegate node corresponding to the above-mentioned at least one delegate node information.
[0017] Optionally, the above-mentioned ciphertext-related data information includes: ciphertext data, key-encrypted data, ciphertext data location information, key-encrypted data location information, and ciphertext data identification; and the encryption unit can be further configured to: generate the above-mentioned ciphertext data, the above-mentioned key-encrypted data and the above-mentioned ciphertext data identification by calling the proxy re-encryption layer; store the above-mentioned ciphertext data and the above-mentioned key-encrypted data in the node corresponding to the above-mentioned client node information, and determine the storage location of the above-mentioned ciphertext data and the storage location of the above-mentioned key-encrypted data as the ciphertext data location information and the key-encrypted data location information, respectively.
[0018] Optionally, the above-mentioned device also includes: according to the above-mentioned ciphertext data identifier, calling the decryption data interface of the interface layer corresponding to the above-mentioned client node information to retrieve the above-mentioned ciphertext data location information; according to the above-mentioned ciphertext data location information, calling the proxy re-encryption layer interface corresponding to the above-mentioned client node information to decrypt the above-mentioned ciphertext data and obtain the decrypted data.
[0019] Optionally, the above-mentioned ciphertext-related data information includes: the re-encryption result integration threshold corresponding to the above-mentioned target delegate node information; and the first generation unit can be configured to generate the above-mentioned proxy re-encryption key fragment set based on the above-mentioned public key information, the number of delegate node information included in the above-mentioned at least one delegate node information and the above-mentioned re-encryption result integration threshold.
[0020] Optionally, the apparatus further includes: storing the key fragment set and the ciphertext data identifier.
[0021] Optionally, each node information corresponding node in the above node information network further includes: a cryptographic algorithm management layer, a proxy re-encryption implementation layer and an algorithm layer.
[0022] On the third aspect, some embodiments of the present disclosure provide a decryption data generation method, which is applied to the target delegate client, including: receiving the proxy re-encryption key fragment and ciphertext-related data information sent by the delegate client as the target proxy re-encryption key fragment and target ciphertext-related data information, wherein the above-mentioned target ciphertext-related data information includes: a re-encryption result integration threshold; generating re-encryption result acquisition event information; publishing the above-mentioned re-encryption result acquisition event information on the node information network; in response to successful publishing, receiving the re-encryption result sent by the corresponding node for at least one remaining node information in the above-mentioned node information network, and obtaining a re-encryption result set; in response to the number of re-encryption results corresponding to the received re-encryption result set reaching the above-mentioned re-encryption result integration threshold, generating decrypted data according to the above-mentioned target proxy re-encryption key fragment, the above-mentioned target ciphertext-related data information and the above-mentioned re-encryption result set.
[0023] Optionally, the re-encryption result is generated through the following steps: for each remaining node information in the at least one remaining node information mentioned above, in response to receiving the above-mentioned re-encryption result acquisition event information, using the proxy re-encryption layer corresponding to the above-mentioned remaining node information, according to the key fragment encryption requirement information included in the above-mentioned re-encryption result acquisition event information, the corresponding proxy re-encryption key fragment is re-encrypted to obtain the re-encryption result.
[0024] Optionally, the above-mentioned target ciphertext-related data information includes: ciphertext data; and the above-mentioned generation of decrypted data based on the above-mentioned target proxy re-encryption key fragment, the above-mentioned target ciphertext-related data information and the above-mentioned re-encryption result set, including: generating reorganization key information based on the above-mentioned target proxy re-encryption key fragment and the above-mentioned re-encryption result set; decrypting the above-mentioned ciphertext data based on the above-mentioned reorganization key information to obtain the above-mentioned decrypted data.
[0025] In a fourth aspect, some embodiments of the present disclosure provide a decryption data generation device, which is applied to a target delegate client, comprising: a first receiving unit, configured to receive a proxy re-encryption key fragment and ciphertext-related data information sent by the delegate client as a target proxy re-encryption key fragment and target ciphertext-related data information, wherein the above-mentioned target ciphertext-related data information includes: a re-encryption result integration threshold; a second generating unit, configured to generate re-encryption result acquisition event information; a publishing unit, configured to publish the above-mentioned re-encryption result acquisition event information on a node information network; the second receiving unit, configured to, in response to a successful publication, receive a re-encryption result for a corresponding proxy re-encryption key fragment sent by at least one remaining node information corresponding node in the above-mentioned node information network, and obtain a re-encryption result set; a third generating unit, configured to generate decrypted data based on the above-mentioned target proxy re-encryption key fragment, the above-mentioned target ciphertext-related data information and the above-mentioned re-encryption result set, in response to the number of re-encryption results corresponding to the received re-encryption result set reaching the above-mentioned re-encryption result integration threshold.
[0026] Optionally, the re-encryption result is generated through the following steps: for each remaining node information in the at least one remaining node information mentioned above, in response to receiving the above-mentioned re-encryption result acquisition event information, using the proxy re-encryption layer corresponding to the above-mentioned remaining node information, according to the key fragment encryption requirement information included in the above-mentioned re-encryption result acquisition event information, the corresponding proxy re-encryption key fragment is re-encrypted to obtain the re-encryption result.
[0027] Optionally, the above-mentioned target ciphertext-related data information includes: ciphertext data; and the third generation unit can be configured to: generate reorganization key information based on the above-mentioned target proxy re-encryption key fragment and the above-mentioned re-encryption result set; decrypt the above-mentioned ciphertext data according to the above-mentioned reorganization key information to obtain the above-mentioned decrypted data.
[0028] In a fifth aspect, some embodiments of the present disclosure provide an electronic device comprising: one or more processors; a storage device on which one or more programs are stored, and when the one or more programs are executed by one or more processors, the one or more processors implement the method described in any one of the implementation methods in the first and third aspects.
[0029] In a sixth aspect, some embodiments of the present disclosure provide a computer-readable medium having a computer program stored thereon, wherein when the program is executed by a processor, the method described in any one of the implementation modes of the first and third aspects is implemented.
[0030] In a seventh aspect, some embodiments of the present disclosure provide a computer program product, including a computer program, which, when executed by a processor, implements the method described in any one of the implementation modes of the first and third aspects above.
[0031] The above-described various embodiments of the present disclosure have the following beneficial effects: secure data transmission can be achieved through the information transmission methods of some embodiments of the present disclosure. Specifically, the lack of data security is caused by the insecure and unreliable key distribution process, which leads to the possibility of data leakage during the transmission process. Based on this, the information transmission methods of some embodiments of the present disclosure first, in response to determining that a node corresponding to a delegator's node information in a node information network receives a data encryption request, encrypt the data to be encrypted using a proxy re-encryption layer corresponding to the delegator's node information to obtain ciphertext-related data information, wherein each node corresponding to the node information in the node information network includes a proxy re-encryption layer. Here, the proxy re-encryption layer corresponding to the delegator's node information achieves precise encryption of the data to be encrypted, and the obtained ciphertext-related data information is subsequently sent to a target delegate client to decrypt the ciphertext data. Next, public key information corresponding to at least one delegate node in the node information network and a target delegate node in the at least one delegate node information is determined for at least one delegate client. Here, the at least one delegatee node information determined includes a target delegatee node (i.e., the delegatee node corresponding to the target delegatee client). Here, the target delegatee node is the node corresponding to the actual delegatee. The at least one remaining delegatee after removing the actual delegatee from the at least one delegatee can be at least one proxy delegatee. Thus, through the participation of the proxy delegate, the direct transfer of keys between the delegator and the actual delegatee, which can lead to insecure key transfer, is avoided, effectively ensuring the secure transfer of encrypted data. Furthermore, the obtained public key information is used for subsequent data decryption at the target delegatee node. Then, based on the public key information, a proxy re-encryption key fragment set is generated for the at least one delegatee node information. Here, the proxy re-encryption key fragment set is generated using the public key information to facilitate subsequent data decryption by the node corresponding to the target delegatee node information. Furthermore, a subscription is executed for message confirmation events for the delegator node information and the at least one delegatee node information to facilitate message confirmation between the delegator node and at least one delegatee node. Finally, in response to determining that the above-mentioned message confirmation event is executed successfully, the above-mentioned proxy re-encryption key fragment set is distributed to at least one delegate client corresponding to the above-mentioned at least one delegate node information, and the above-mentioned ciphertext-related data information is sent to the target delegate client corresponding to the above-mentioned target delegate node, so as to be used by the subsequent target delegate client corresponding to the delegate node to generate decrypted data.In summary, the present disclosure not only achieves accurate encryption of the data to be encrypted through the proxy re-encryption layer, but also realizes the participation of the proxy delegated node by generating a set of proxy re-encryption key fragments, avoiding the possible problems of insecure and unreliable key distribution when the key is directly sent to the real delegate, thereby subsequently ensuring the secure flow of data between the real delegate and the delegator. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] The above and other features, advantages, and aspects of the various embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that components and elements are not necessarily drawn to scale.
[0033] Figure 1 is a schematic diagram of an application scenario of the information sending method according to some embodiments of the present disclosure;
[0034] Figure 2 is a flow chart of some embodiments of the information sending method according to the present disclosure;
[0035] Figure 3 is a schematic diagram of a node information network in some embodiments of the information sending method according to the present disclosure;
[0036] Figure 4 is a flowchart of other embodiments of the information sending method according to the present disclosure;
[0037] Figure 5 is a flow chart of some embodiments of a method for generating decrypted data according to the present disclosure;
[0038] Figure 6 is a schematic structural diagram of some embodiments of the information sending device according to the present disclosure;
[0039] Figure 7 is a schematic structural diagram of some embodiments of the decryption data generating device according to the present disclosure;
[0040] Figure 8 It is a structural diagram of an electronic device suitable for implementing some embodiments of the present disclosure. DETAILED DESCRIPTION
[0041] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as being limited to the embodiments described herein. On the contrary, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of protection of the present disclosure.
[0042] It should also be noted that, for ease of description, only the parts related to the invention are shown in the drawings. In the absence of conflict, the embodiments and features in the embodiments of the present disclosure may be combined with each other.
[0043] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.
[0044] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, they should be understood as "one or more".
[0045] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.
[0046] The present disclosure will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments.
[0047] Figure 1 It is a schematic diagram of an application scenario of the information sending method according to some embodiments of the present disclosure.
[0048] exist Figure 1In an application scenario, first, in response to determining that a node corresponding to delegator node information 103 in node information network 102 has received a data encryption request, delegator client 101 may encrypt data to be encrypted 105 using proxy re-encryption layer 104 corresponding to delegator node information 103 to obtain ciphertext-related data information 106. Each node corresponding to node information in node information network 102 includes a proxy re-encryption layer. Delegator client 101 may then determine public key information 108 corresponding to at least one delegatee client, at least one delegatee node information 107 in node information network 102, and a target delegatee node 1072 in the at least one delegatee node information 107. In this application scenario, the at least one delegatee client includes delegatee client 110, delegatee client 111, and delegatee client 112. The at least one delegatee node information 107 includes delegatee node information 1071, delegatee node information 1072, and delegatee node information 1073. Next, the delegating client 101 can generate a proxy re-encryption key fragment set 109 for the at least one delegatee node information 107 based on the public key information 108. In this application scenario, the proxy re-encryption key fragment set 109 includes: a proxy re-encryption key fragment 1091 corresponding to the delegatee node information 1071, a proxy re-encryption key fragment 1092 corresponding to the delegatee node information 1072, and a proxy re-encryption key fragment 1093 corresponding to the delegatee node information 1073. Furthermore, the delegating client 101 can subscribe to message confirmation events for the delegating node information 103 and the at least one delegatee node information 107. Finally, in response to determining that the message confirmation event has been successfully executed, the delegating client 101 can distribute the proxy re-encryption key fragment set 109 to the at least one delegatee client corresponding to the at least one delegatee node information 107, and send the ciphertext-related data information 106 to the target delegatee client 111 corresponding to the target delegatee node.
[0049] It should be noted that the client client 101 can be hardware or software. When the client client is hardware, it can be implemented as a distributed cluster consisting of multiple servers or terminal devices, or as a single server or a single terminal device. When the client client is software, it can be installed in the hardware devices listed above. It can be implemented as multiple software or software modules for providing distributed services, or as a single software or software module. No specific limitations are given here.
[0050] It should be understood that Figure 1The number of client terminals in FIG is only illustrative. Any number of client terminals may be provided according to implementation requirements.
[0051] Continue to refer Figure 2 , shows a process 200 of some embodiments of the information sending method according to the present disclosure. The information sending method, applied to the client of the client, includes the following steps:
[0052] Step 201: In response to receiving a data encryption request from a node corresponding to the client node information in the node information network, the node to be encrypted is encrypted through the proxy re-encryption layer corresponding to the client node information to obtain ciphertext-related data information.
[0053] In some embodiments, in response to determining that the node corresponding to the client node information in the node information network receives a data encryption request, the execution subject of the above information sending method (for example Figure 1 The client client 101 shown can encrypt the data to be encrypted using the proxy re-encryption layer corresponding to the client node information to obtain ciphertext-related data information. The node information network can be a network consisting of individual node information. The node information can be node identification information. The node can be a node on a blockchain. The node corresponding to the node information can communicate with the re-encryption server. The actual communication method between the two can include, but is not limited to, at least one of the following: Unix domain sockets, RPC (Remote Produce Call) protocol, and Hypertext Transfer Protocol (HTTP). Unix domain sockets are preferred as the communication method between the two. Each node information in the node information network has corresponding organization information. Each organization information has corresponding at least one node information. In practice, the organization information can be the identity of the organization in the blockchain. Organization information is shared between organizations in the node information network. In practice, sharing of organization information can be achieved through a built-in broadcast interface of the organization's corresponding node. The client node information can be node information of the client node. The client node can be the node corresponding to the client client in the blockchain. The client node may be a node on the corresponding blockchain of the node information network. The data encryption request may be a request to encrypt data. The proxy re-encryption layer may provide proxy re-encryption functionality to implement the proxy re-encryption operation. Furthermore, the proxy re-encryption layer shields the specific implementation of the proxy re-encryption operation. The data to be encrypted may be data to be encrypted. In other words, the data to be encrypted may be plaintext data to be circulated. The ciphertext-related data information may be data information related to the encrypted data. For example, the related data information may include the size of the encrypted data.
[0054] It should be noted that each node corresponding to the node information network has a pre-added proxy re-encryption module to implement the proxy re-encryption operation. The proxy re-encryption module includes: a proxy re-encryption layer.
[0055] See also Figure 3 , shows a node information network consisting of four organizations. The four organizations include: Organization 1, Organization 2, Organization 3, and Organization 4. The node corresponding to Organization 1 is Node 1. The node corresponding to Organization 2 is Node 2. The node corresponding to Organization 3 is Node 3. The node corresponding to Organization 4 is Node 4.
[0056] In some optional implementations of some embodiments, each node information corresponding to a node in the node information network further includes an interface layer. The interface layer resides in the proxy re-encryption module. The interface layer is configured to provide public parameter generation.
[0057] Optionally, before step 201, the steps further include:
[0058] The first step is to call the interface layer of the node corresponding to the above-mentioned client node information to generate public node parameters.
[0059] The above-mentioned common node parameters are the node parameters to be configured at each node before data flow.
[0060] The second step is to synchronize the above-mentioned public node parameters to at least one delegate node corresponding to the above-mentioned at least one delegate node information.
[0061] As an example, the above-mentioned execution entity can use the node's built-in blockchain components and blockchain event subscription capabilities to synchronize public node parameters in the node information network.
[0062] It should be noted that after receiving the public node parameters, the delegated node will send a receipt message to the delegating node in response to the configuration event for the public node parameters.
[0063] In some optional implementations of some embodiments, the ciphertext-related data information includes: ciphertext data, key-encrypted data, ciphertext data location information, key-encrypted data location information, and ciphertext data identifier. The ciphertext data may be data obtained by encrypting the data to be encrypted. The key-encrypted data may be data obtained by encrypting the key. The key may be a key used to encrypt the data to be encrypted. The ciphertext data location information may be storage location information of the ciphertext data. The key-encrypted data location information may be storage location information of the key-encrypted data. The ciphertext data identifier may be a unique identifier of the ciphertext data. For example, the ciphertext data identifier may be a universally unique identifier (UUID).
[0064] Optionally, encrypting the data to be encrypted by the proxy re-encryption layer corresponding to the client node information to obtain ciphertext-related data information may include the following steps:
[0065] In the first step, the execution entity may generate the ciphertext data, the key-encrypted data and the ciphertext data identifier by calling a proxy re-encryption layer.
[0066] In the second step, the execution entity may store the ciphertext data and the key-encrypted data at the node corresponding to the client node information, and determine the storage location of the ciphertext data and the storage location of the key-encrypted data as ciphertext data location information and key-encrypted data location information, respectively.
[0067] In some optional implementations of some embodiments, each node corresponding to the node information in the node information network further includes: a cryptographic algorithm management layer, a proxy re-encryption implementation layer, and an algorithm layer. The cryptographic algorithm management layer, proxy re-encryption implementation layer, and algorithm layer reside in a proxy re-encryption module. The cryptographic algorithm management layer can reuse the shared storage and database built within the node while accessing the proxy re-encryption layer. The proxy re-encryption implementation layer can be the proxy re-encryption implementation layer and can contain six submodules. These six submodules include: a decryption 1 module, a decryption 2 module, a re-encryption module, an encryption module, a key generation module, and a re-encryption key generation module. The decryption 1 module can be the decryption module used by the client. The decryption 2 module can be the decryption module used by the client. The re-encryption module determines its calling method based on the configuration values of the node's proxy re-encryption component. If the communication mode is configured as in-memory mode, re-encryption is performed using functions within the node process; otherwise, re-encryption is performed using inter-process communication. The algorithm layer can include the implementation algorithms for each module in the proxy re-encryption implementation layer.
[0068] Step 202: Determine at least one delegate node information in the node information network and public key information corresponding to a target delegate node in the at least one delegate node information for at least one delegate client.
[0069] In some embodiments, the execution entity may determine, for at least one delegatee client, at least one delegatee node information in the node information network and public key information corresponding to a target delegatee node in the at least one delegatee node information. The number of delegatee node information included in the at least one delegatee node information may be preset. The delegatee node information may be node information of a delegatee node. The public key information is used to subsequently decrypt an encrypted public key received by the target delegatee node. The encrypted public key is obtained by encrypting and aggregating a set of re-encryption results sent by at least one remaining delegatee node corresponding to the at least one delegatee node information. The at least one remaining delegatee node is at least one node in the at least one delegatee node excluding the target delegatee node. The re-encryption result may be a result obtained by proxy re-encrypting the received proxy re-encryption key fragment by the remaining delegatee nodes. The delegatee corresponding to the target delegatee node is the delegatee that actually requires the data to be encrypted. The remaining delegatee node information in the at least one delegatee node information may be proxy delegatee node information. Here, the node corresponding to the proxy delegate node information is used to re-encrypt the received proxy re-encryption key fragment. In addition, the node corresponding to the proxy delegate node information can also send the re-encrypted re-encryption result to the target delegate node.
[0070] Step 203: Generate a set of proxy re-encryption key fragments for the at least one delegated node information based on the public key information.
[0071] In some embodiments, the execution entity may generate a set of proxy re-encryption key fragments for the at least one delegatee node information based on the at least one public key information. The proxy re-encryption key fragments in the set of proxy re-encryption key fragments correspond one-to-one to the delegatee node information in the at least one delegatee node information. The proxy re-encryption key fragments may be key fragments obtained by re-encrypting and fragmenting the public key information.
[0072] As an example, the execution entity may call a re-encryption key generation interface in the interface layer of the delegating node to generate a set of proxy re-encryption key fragments for the at least one delegated node information based on the public key information.
[0073] In some optional implementations of some embodiments, the ciphertext-related data information includes a re-encryption result consolidation threshold corresponding to the target delegatee node information. The re-encryption result consolidation threshold may be a value that triggers encryption consolidation of the re-encryption result set. For example, the re-encryption result consolidation threshold may be 5. That is, in response to determining that the number of re-encryption results included in the re-encryption result set is greater than or equal to the re-encryption result consolidation threshold, encryption result consolidation is performed on the re-encryption result set to obtain reconstructed key information.
[0074] Optionally, generating a set of proxy re-encryption key fragments for the at least one delegated node information based on the public key information includes:
[0075] The execution entity may generate the proxy re-encryption key fragment set according to the public key information, the number of delegated node information included in the at least one delegated node information, and the re-encryption result integration threshold.
[0076] As an example, the execution entity may utilize key sharding technology to generate the proxy re-encryption key fragment set based on the public key information, the number of delegated node information included in the at least one delegated node information, and the re-encryption result integration threshold.
[0077] Step 204: Subscribe to message confirmation events for the above-mentioned delegating party node information and the above-mentioned at least one delegatee node information.
[0078] In some embodiments, the execution entity may subscribe to a message confirmation event for the information of the delegating node and the information of the at least one delegated node. The message confirmation event may be an event confirming that messages can flow between the delegating node and the at least one delegated node.
[0079] Step 205, in response to determining that the above-mentioned message confirmation event is executed successfully, the above-mentioned proxy re-encryption key fragment set is distributed to at least one delegate client corresponding to the above-mentioned at least one delegate node information, and the above-mentioned ciphertext-related data information is sent to the target delegate client corresponding to the above-mentioned target delegate node.
[0080] In some embodiments, in response to determining that the message confirmation event has been successfully executed, the execution entity may distribute the proxy re-encryption key fragment set to at least one delegatee client corresponding to the at least one delegatee node information, and send the ciphertext-related data information to the target delegatee client corresponding to the target delegatee node. The number of delegatee nodes included in the at least one delegatee node is equal to the number of proxy re-encryption key fragments included in the proxy re-encryption key fragment set. That is, each delegatee node receives one proxy re-encryption key fragment.
[0081] The above-described various embodiments of the present disclosure have the following beneficial effects: secure data transmission can be achieved through the information transmission methods of some embodiments of the present disclosure. Specifically, the lack of data security is caused by the insecure and unreliable key distribution process, which leads to the possibility of data leakage during the transmission process. Based on this, the information transmission methods of some embodiments of the present disclosure first, in response to determining that a node corresponding to a delegator's node information in a node information network receives a data encryption request, encrypt the data to be encrypted using a proxy re-encryption layer corresponding to the delegator's node information to obtain ciphertext-related data information, wherein each node corresponding to the node information in the node information network includes a proxy re-encryption layer. Here, the proxy re-encryption layer corresponding to the delegator's node information achieves precise encryption of the data to be encrypted, and the obtained ciphertext-related data information is subsequently sent to a target delegate client to decrypt the ciphertext data. Next, public key information corresponding to at least one delegate node in the node information network and a target delegate node in the at least one delegate node information is determined for at least one delegate client. Here, the at least one delegatee node information determined includes a target delegatee node (i.e., the delegatee node corresponding to the target delegatee client). Here, the target delegatee node is the node corresponding to the actual delegatee. The at least one remaining delegatee after removing the actual delegatee from the at least one delegatee can be at least one proxy delegatee. Thus, through the participation of the proxy delegate, the direct transfer of keys between the delegator and the actual delegatee, which can lead to insecure key transfer, is avoided, effectively ensuring the secure transfer of encrypted data. Furthermore, the obtained public key information is used for subsequent data decryption at the target delegatee node. Then, based on the public key information, a proxy re-encryption key fragment set is generated for the at least one delegatee node information. Here, the proxy re-encryption key fragment set is generated using the public key information to facilitate subsequent data decryption by the node corresponding to the target delegatee node information. Furthermore, a subscription is executed for message confirmation events for the delegator node information and the at least one delegatee node information to facilitate message confirmation between the delegator node and at least one delegatee node. Finally, in response to determining that the above-mentioned message confirmation event is executed successfully, the above-mentioned proxy re-encryption key fragment set is distributed to at least one delegate client corresponding to the above-mentioned at least one delegate node information, and the above-mentioned ciphertext-related data information is sent to the target delegate client corresponding to the above-mentioned target delegate node, so as to be used by the subsequent target delegate client corresponding to the delegate node to generate decrypted data.In summary, the present disclosure not only achieves accurate encryption of the data to be encrypted through the proxy re-encryption layer, but also realizes the participation of the proxy delegated node by generating a set of proxy re-encryption key fragments, avoiding the possible problems of insecure and unreliable key distribution when the key is directly sent to the real delegate, thereby subsequently ensuring the secure flow of data between the real delegate and the delegator.
[0082] Further references Figure 4 , shows a process 400 of another embodiment of the information sending method according to the present disclosure. The information sending method, applied to the client of the client, includes the following steps:
[0083] Step 401: In response to receiving a data encryption request from a node corresponding to the client node information in the node information network, the node to be encrypted is encrypted through the proxy re-encryption layer corresponding to the client node information to obtain ciphertext-related data information.
[0084] Step 402: Determine at least one delegate node information in the node information network and public key information corresponding to a target delegate node in the at least one delegate node information for at least one delegate client.
[0085] Step 403: Generate a set of proxy re-encryption key fragments for the at least one delegated node information based on the public key information.
[0086] Step 404: Subscribe to the message confirmation event for the above-mentioned delegating node information and the above-mentioned at least one delegated node information.
[0087] Step 405, in response to determining that the above-mentioned message confirmation event is executed successfully, the above-mentioned proxy re-encryption key fragment set is distributed to at least one delegate client corresponding to the above-mentioned at least one delegate node information, and the above-mentioned ciphertext-related data information is sent to the target delegate client corresponding to the above-mentioned target delegate node.
[0088] In some embodiments, the specific implementation of steps 401-405 and the technical effects thereof can be referred to in Figure 2 Steps 201-205 in the corresponding embodiment are not repeated here.
[0089] Step 406: Based on the ciphertext data identifier, call the decryption data interface of the interface layer corresponding to the client node information to retrieve the ciphertext data location information.
[0090] In some embodiments, the execution entity (e.g. Figure 1The client client 101 shown can call the decryption data interface of the interface layer corresponding to the client node information based on the ciphertext data identifier to retrieve the ciphertext data location information. The ciphertext data identifier can be an identifier of the ciphertext data. The ciphertext data can be encrypted data. The decryption data interface can be an interface for decrypting the ciphertext data. The interface layer can also be used to decrypt the decrypted data. The ciphertext data location information can be the storage location of the ciphertext data.
[0091] Step 407: Based on the ciphertext data location information, the proxy re-encryption layer corresponding to the client node information is called to decrypt the ciphertext data to obtain decrypted data.
[0092] In some embodiments, the execution entity can call the proxy re-encryption layer interface corresponding to the client node information based on the ciphertext data location information to decrypt the ciphertext data to obtain the decrypted data. Here, the proxy re-encryption layer can also perform the decryption operation of the ciphertext data.
[0093] from Figure 4 It can be seen that Figure 2 Compared with the description of some corresponding embodiments, Figure 4 In some embodiments, the information transmission method process 400 uses the ciphertext data identifier to call the decryption data interface to accurately retrieve the storage location of the ciphertext data. Based on this, the ciphertext data can be decrypted through the proxy re-encryption layer, so that the client can encrypt and decrypt the data independently.
[0094] Continue to refer Figure 5 , shows a process 500 of some embodiments of the decrypted data generation method according to the present disclosure. The decrypted data generation method, applied to the target delegate client, includes the following steps:
[0095] Step 501: Receive the proxy re-encryption key fragment and ciphertext-related data information sent by the client as the target proxy re-encryption key fragment and target ciphertext-related data information.
[0096] In some embodiments, the execution entity (e.g., the target delegate client) may receive the proxy re-encryption key fragment and ciphertext-related data information sent by the delegating client as the target proxy re-encryption key fragment and target ciphertext-related data information. The target ciphertext-related data information includes a re-encryption result integration threshold. For example, the re-encryption result integration threshold may be "5." The target delegate client may be the client corresponding to the actual delegate. The actual delegate may be the transferor of the data to be encrypted.
[0097] Step 502: Generate re-encryption result and obtain event information.
[0098] In some embodiments, the execution entity may generate re-encryption result acquisition event information, wherein the re-encryption result acquisition event information may be information about an event requesting a re-encryption result from at least one other node.
[0099] Step 503: Publish the above-mentioned re-encryption result acquisition event information on the node information network.
[0100] In some embodiments, the execution entity may publish the re-encryption result acquisition event information on the node information network.
[0101] Step 504 , in response to the successful publishing, receiving a re-encryption result for a corresponding proxy re-encryption key fragment sent by at least one node corresponding to the remaining node information in the node information network, and obtaining a re-encryption result set.
[0102] In some embodiments, in response to a successful publication, the execution entity may receive a re-encryption result for a corresponding proxy re-encryption key fragment, sent from a node corresponding to at least one remaining node information in the node information network, to obtain a re-encryption result set. The at least one remaining node information may be at least one piece of information from the at least one delegatee node information excluding the target delegatee node information. The at least one remaining node information may be at least one proxy delegatee node information. The re-encryption results in the re-encryption result set correspond one-to-one with the remaining node information in the at least one remaining node information.
[0103] In some optional implementations of some embodiments, the re-encryption result is generated by the following steps:
[0104] For each piece of remaining node information in the at least one piece of remaining node information, in response to receiving the re-encryption result acquisition event information, the proxy delegatee client corresponding to the remaining node information may utilize the proxy re-encryption layer corresponding to the remaining node information and, based on the key fragment encryption requirement information included in the re-encryption result acquisition event information, re-encrypt the corresponding proxy re-encryption key fragment to obtain a re-encryption result. The key fragment encryption requirement information may be information requesting encryption of the key fragment.
[0105] Step 505 , in response to the number of re-encryption results corresponding to the received re-encryption result set reaching the re-encryption result integration threshold, decrypted data is generated according to the target proxy re-encryption key fragment, the target ciphertext-related data information and the re-encryption result set.
[0106] In some embodiments, in response to the number of re-encryption results corresponding to the received re-encryption result set reaching the above-mentioned re-encryption result integration threshold, the above-mentioned execution entity can generate decrypted data based on the above-mentioned target proxy re-encryption key fragment, the above-mentioned target ciphertext-related data information and the above-mentioned re-encryption result set.
[0107] As an example, the execution entity can concatenate the re-encrypted result set to obtain a concatenated re-encrypted result. The concatenated re-encrypted result is then decrypted to obtain a key fragment. Next, a reconstructed key is generated based on the key fragment and the target proxy's re-encrypted key fragment. Finally, the reconstructed key is used to decrypt the ciphertext data in the target ciphertext-related data information to obtain decrypted data.
[0108] In some optional implementations of some embodiments, the above-mentioned target ciphertext-related data information includes: ciphertext data.
[0109] Optionally, generating the decrypted data according to the target proxy re-encryption key fragment, the target ciphertext-related data information, and the re-encryption result set may include the following steps:
[0110] The first step is to generate re-key information based on the target proxy re-encryption key fragment and the re-encryption result set.
[0111] The reconstructed key information may be key information generated for ciphertext data by the target proxy re-encryption key fragment and the decryption result set corresponding to the re-encryption result set.
[0112] As an example, the execution entity may first decrypt each re-encrypted result in the re-encrypted result set to obtain a decrypted result. Then, the execution entity may generate re-key information using a key re-reconstruction technique based on each decrypted result and the target proxy re-encryption key fragment.
[0113] As another example, the execution entity may first re-encrypt the target proxy re-encryption key fragment to obtain a target re-encryption result. The execution entity may then add the target re-encryption result to a re-encryption result set to obtain an added re-encryption result set. Finally, the re-encryption result set may be decrypted as a whole using a multi-layer decryption process to obtain the reconstructed key information.
[0114] The second step is to decrypt the ciphertext data according to the reconstructed key information to obtain the decrypted data.
[0115] The above-mentioned various embodiments of the present disclosure have the following beneficial effects: accurate decryption of ciphertext data can be achieved through the decryption data generation method of some embodiments of the present disclosure.
[0116] Further references Figure 6 As an implementation of the methods shown in the above figures, the present disclosure provides some embodiments of an information sending device. These device embodiments are similar to Figure 2 Corresponding to the method embodiments shown, the information sending device can be specifically applied to various electronic devices.
[0117] like Figure 6 As shown, an information sending device 600 includes: an encryption unit 601, a determination unit 602, a first generation unit 603, an execution unit 604, and a sending unit 605. The encryption unit 601 is configured to, in response to receiving a data encryption request from a node corresponding to the client node information in the node information network, encrypt the data to be encrypted through the proxy re-encryption layer corresponding to the client node information to obtain ciphertext-related data information, wherein each node corresponding to the node information in the node information network includes: a proxy re-encryption layer; the determination unit 602 is configured to determine the public key information corresponding to at least one client client, at least one client node information in the node information network, and a target client node in the at least one client node information; the first generation unit 603; and the execution unit 604. Element 603 is configured to generate a set of proxy re-encryption key fragments for the above-mentioned at least one delegate node information based on the above-mentioned public key information; the execution unit 604 is configured to execute the subscription of the message confirmation event for the above-mentioned delegator node information and the above-mentioned at least one delegate node information; the sending unit 605 is configured to distribute the above-mentioned proxy re-encryption key fragment set to at least one delegate client corresponding to the above-mentioned at least one delegate node information in response to determining that the above-mentioned message confirmation event is executed successfully, and send the above-mentioned ciphertext-related data information to the target delegate client corresponding to the above-mentioned target delegate node.
[0118] In some optional implementations of some embodiments, each node corresponding to the node information in the node information network further includes an interface layer; and the information sending device 600 further includes a first calling unit and a synchronization unit (not shown). The first calling unit may be configured to call the interface layer of the node corresponding to the delegating node information to generate public node parameters. The synchronization unit may be configured to synchronize the public node parameters to at least one delegated node corresponding to the at least one delegated node information.
[0119] In some optional implementations of some embodiments, the above-mentioned ciphertext-related data information includes: ciphertext data, key-encrypted data, ciphertext data location information, key-encrypted data location information, and ciphertext data identification; and the encryption unit 601 can be further configured to: generate the above-mentioned ciphertext data, the above-mentioned key-encrypted data and the above-mentioned ciphertext data identification by calling the proxy re-encryption layer; store the above-mentioned ciphertext data and the above-mentioned key-encrypted data in the node corresponding to the above-mentioned entrusting party node information, and determine the storage location of the above-mentioned ciphertext data and the storage location of the above-mentioned key-encrypted data as the ciphertext data location information and the key-encrypted data location information, respectively.
[0120] In some optional implementations of some embodiments, the information sending device 600 further includes: a second calling unit and a third calling unit (not shown). The second calling unit may be configured to: based on the ciphertext data identifier, call the decryption data interface of the interface layer corresponding to the client node information to retrieve the ciphertext data location information. The third calling unit may be configured to: based on the ciphertext data location information, call the proxy re-encryption layer corresponding to the client node information to decrypt the ciphertext data to obtain the decrypted data.
[0121] In some optional implementations of some embodiments, the above-mentioned ciphertext-related data information includes: the re-encryption result integration threshold corresponding to the above-mentioned target delegate node information; and the above-mentioned first generation unit 603 can be further configured to: generate the above-mentioned proxy re-encryption key fragment set based on the above-mentioned public key information, the number of delegate node information included in the above-mentioned at least one delegate node information and the above-mentioned re-encryption result integration threshold.
[0122] In some optional implementations of some embodiments, each node information corresponding node in the above-mentioned node information network further includes: a cryptographic algorithm management layer, a proxy re-encryption implementation layer and an algorithm layer.
[0123] It is understandable that the units described in the information sending device 600 are similar to those in the reference Figure 2 Therefore, the operations, features and beneficial effects described above for the method are also applicable to the information sending device 600 and the units included therein, and will not be described in detail here.
[0124] Further references Figure 7 As an implementation of the methods shown in the above figures, the present disclosure provides some embodiments of a decryption data generating device. These device embodiments are similar to Figure 5 Corresponding to the method embodiments shown, the decryption data generating device can be specifically applied to various electronic devices.
[0125] like Figure 7 As shown, a decrypted data generating device 700 includes: a first receiving unit 701, a second generating unit 702, a publishing unit 703, a second receiving unit 704 and a third generating unit 705. Among them, the first receiving unit 701 is configured to receive the proxy re-encryption key fragment and ciphertext-related data information sent by the entrusting client as the target proxy re-encryption key fragment and target ciphertext-related data information, wherein the above-mentioned target ciphertext-related data information includes: a re-encryption result integration threshold; the second generating unit 702 is configured to generate re-encryption result acquisition event information; the publishing unit 703 is configured to publish the above-mentioned re-encryption result acquisition event information in the node information network; the second receiving unit 704 is configured to receive the re-encryption result sent by the corresponding node for at least one remaining node information in the above-mentioned node information network in response to successful publishing, and obtain a re-encryption result set; the third generating unit 705 is configured to generate decrypted data according to the above-mentioned target proxy re-encryption key fragment, the above-mentioned target ciphertext-related data information and the above-mentioned re-encryption result set in response to the number of re-encryption results corresponding to the received re-encryption result set reaching the above-mentioned re-encryption result integration threshold.
[0126] In some optional implementations of some embodiments, the re-encryption result is generated through the following steps: for each remaining node information in the at least one remaining node information mentioned above, in response to receiving the above-mentioned re-encryption result acquisition event information, using the proxy re-encryption layer corresponding to the above-mentioned remaining node information, based on the key fragment encryption requirement information included in the above-mentioned re-encryption result acquisition event information, the corresponding proxy re-encryption key fragment is re-encrypted to obtain the re-encryption result.
[0127] In some optional implementations of some embodiments, the above-mentioned target ciphertext-related data information includes: ciphertext data; and the third generation unit 705 can be configured to: generate reorganization key information based on the above-mentioned target proxy re-encryption key fragment and the above-mentioned re-encryption result set; decrypt the above-mentioned ciphertext data based on the above-mentioned reorganization key information to obtain the above-mentioned decrypted data.
[0128] It is understood that the units described in the decrypted data generating device 700 are similar to those in the reference Figure 5 Therefore, the operations, features and beneficial effects described above for the method are also applicable to the decryption data generating device 500 and the units included therein, and will not be described in detail here.
[0129] Reference below Figure 8 , which shows a structural diagram of an electronic device 800 suitable for implementing some embodiments of the present disclosure. Figure 8The electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.
[0130] like Figure 8 As shown, the electronic device 800 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 801, which can perform various appropriate actions and processes according to a program stored in a read-only memory 802 or a program loaded from a storage device 808 into a random access memory 803. Various programs and data required for the operation of the electronic device 800 are also stored in the random access memory 803. The processing device 801, the read-only memory 802, and the random access memory 803 are connected to each other via a bus 804. An input / output interface 806 is also connected to the bus 804.
[0131] Typically, the following devices may be connected to the I / O interface 806: an input device 806 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 807 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 808 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 809. The communication device 809 may allow the electronic device 800 to communicate with other devices wirelessly or by wire to exchange data. Although Figure 8 The electronic device 800 is shown with various devices, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead. Figure 8 Each block shown in the figure may represent one device, or may represent multiple devices as needed.
[0132] In particular, according to some embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, some embodiments of the present disclosure include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In some such embodiments, the computer program can be downloaded and installed from a network via the communication device 809, or installed from the storage device 808, or installed from the read-only memory 802. When the computer program is executed by the processing device 801, the above-mentioned functions defined in the method of some embodiments of the present disclosure are performed.
[0133] It should be noted that in some embodiments of the present disclosure, the computer-readable medium mentioned above may be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In some embodiments of the present disclosure, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device, or device. In some embodiments of the present disclosure, the computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any suitable medium, including but not limited to wires, optical cables, RF (radio frequency), etc., or any suitable combination thereof.
[0134] In some embodiments, the client and server can communicate using any currently known or future developed network protocol, such as HTTP (HyperText Transfer Protocol), and can be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or future developed network.
[0135] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device. The computer-readable medium carries one or more programs. When the one or more programs are executed by the electronic device, the electronic device: in response to determining that a node corresponding to the delegator node information in the node information network receives a data encryption request, encrypts the encrypted data through a proxy re-encryption layer corresponding to the delegator node information to obtain ciphertext-related data information, wherein each node corresponding to the node in the node information network includes: a proxy re-encryption layer; determining the public key information corresponding to at least one delegate node information in the node information network and a target delegate node in the at least one delegate node information for at least one delegate client; generating a proxy re-encryption key fragment set for the at least one delegate node information based on the public key information; executing a subscription to a message confirmation event for the delegator node information and the at least one delegate node information; in response to determining that the message confirmation event is successfully executed, distributing the proxy re-encryption key fragment set to at least one delegate client corresponding to the at least one delegate node information, and sending the ciphertext-related data information to the target delegate client corresponding to the target delegate node.
[0136] Computer program code for performing the operations of some embodiments of the present disclosure may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0137] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0138] The units described in some embodiments of the present disclosure may be implemented in software or in hardware. The described units may also be provided in a processor. For example, they may be described as follows: a processor including an encryption unit, a determination unit, a first generation unit, an execution unit, and a sending unit. The names of these units do not, in some cases, constitute limitations on the units themselves. For example, the first generation unit may also be described as "a unit that generates a set of proxy re-encryption key fragments for the at least one delegated node information based on the at least one public key information."
[0139] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chip (SOCs), complex programmable logic devices (CPLDs), and the like.
[0140] Some embodiments of the present disclosure further provide a computer program product, including a computer program, which implements any of the above-mentioned information sending methods and decrypted data generating methods when executed by a processor.
[0141] The above description is only an illustration of some preferred embodiments of the present disclosure and the technical principles used. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present disclosure is not limited to the technical solutions formed by the specific combination of the above-mentioned technical features, but should also cover other technical solutions formed by any combination of the above-mentioned technical features or their equivalent features without departing from the above-mentioned inventive concept. For example, the above-mentioned features are replaced with (but not limited to) technical features with similar functions disclosed in the embodiments of the present disclosure.
Claims
1. A method for sending information, applied to a client of a client, comprising: In response to determining that a node corresponding to the client node information in the node information network receives a data encryption request, encrypting the data to be encrypted through the proxy re-encryption layer corresponding to the client node information to obtain ciphertext-related data information, wherein each node corresponding to the node information in the node information network includes: a proxy re-encryption layer; Determining, for at least one delegate client, at least one delegate node information in the node information network and public key information corresponding to a target delegate node in the at least one delegate node information; generating, based on the public key information, a set of proxy re-encryption key fragments for the at least one delegated node information; Execute subscription for message confirmation events of the delegating node information and the at least one delegatee node information; In response to determining that the message confirmation event is executed successfully, the proxy re-encryption key fragment set is distributed to at least one delegate client corresponding to the at least one delegate node information, and the ciphertext-related data information is sent to the target delegate client corresponding to the target delegate node.
2. The method according to claim 1, wherein Each node information corresponding node in the node information network further includes: an interface layer; and Before receiving the data encryption request in response to determining that the node corresponding to the client node information in the node information network receives the data encryption request, and encrypting the data to be encrypted by the proxy re-encryption layer corresponding to the client node information to obtain ciphertext-related data information, the method further includes: Calling the interface layer of the node corresponding to the client node information to generate public node parameters; The public node parameters are synchronized to at least one delegate node corresponding to the at least one delegate node information.
3. The method according to claim 1, wherein The ciphertext-related data information includes: ciphertext data, key-encrypted data, ciphertext data location information, key-encrypted data location information, and ciphertext data identifier; and The method of encrypting the data to be encrypted by the proxy re-encryption layer corresponding to the client node information to obtain ciphertext-related data information includes: Generate the ciphertext data, the key-encrypted data, and the ciphertext data identifier by calling a proxy re-encryption layer; The ciphertext data and the key-encrypted data are stored in a node corresponding to the client node information, and the storage location of the ciphertext data and the storage location of the key-encrypted data are respectively determined as ciphertext data location information and key-encrypted data location information.
4. The method according to claim 3, wherein: The method further comprises: According to the ciphertext data identifier, calling the decryption data interface of the interface layer corresponding to the client node information to retrieve the ciphertext data location information; According to the ciphertext data location information, the proxy re-encryption layer corresponding to the client node information is called to decrypt the ciphertext data to obtain the decrypted data.
5. The method according to claim 1, wherein The ciphertext-related data information includes: the re-encryption result integration threshold corresponding to the target delegate node information; and Generating a set of proxy re-encryption key fragments for the at least one delegated node information according to the public key information includes: The proxy re-encryption key fragment set is generated according to the public key information, the number of delegate node information included in the at least one delegate node information, and the re-encryption result integration threshold.
6. The method according to claim 1, wherein Each node information corresponding node in the node information network also includes: a cryptographic algorithm management layer, a proxy re-encryption implementation layer and an algorithm layer.
7. A method for generating decrypted data, applied to a target client, comprising: Receiving the proxy re-encryption key fragment and ciphertext-related data information sent by the client as the target proxy re-encryption key fragment and target ciphertext-related data information, wherein the target ciphertext-related data information includes: a re-encryption result integration threshold; Generate re-encryption results to obtain event information; Publishing the re-encryption result acquisition event information on the node information network; In response to the successful publishing, receiving a re-encryption result for a corresponding proxy re-encryption key fragment sent by at least one remaining node corresponding to the node information in the node information network, and obtaining a re-encryption result set; In response to the number of re-encryption results corresponding to the received re-encryption result set reaching the re-encryption result integration threshold, decrypted data is generated according to the target proxy re-encryption key fragment, the target ciphertext-related data information and the re-encryption result set.
8. The method according to claim 7, wherein: The re-encryption result is generated by the following steps: For each of the at least one remaining node information, in response to receiving the re-encryption result acquisition event information, the proxy re-encryption layer corresponding to the remaining node information is used to re-encrypt the corresponding proxy re-encryption key fragment according to the key fragment encryption requirement information included in the re-encryption result acquisition event information to obtain a re-encryption result.
9. The method according to claim 7, wherein: The target ciphertext-related data information includes: ciphertext data; and The generating of decrypted data according to the target proxy re-encryption key fragment, the target ciphertext-related data information and the re-encryption result set includes: generating re-key information according to the target proxy re-encryption key fragment and the re-encryption result set; The ciphertext data is decrypted according to the reorganization key information to obtain the decrypted data.
10. An information sending device, applied to a client of a client, comprising: an encryption unit configured to, in response to receiving a data encryption request from a node corresponding to the client node information in a determined node information network, encrypt the data to be encrypted by a proxy re-encryption layer corresponding to the client node information to obtain ciphertext-related data information, wherein each node corresponding to the node information in the node information network includes: a proxy re-encryption layer; a determining unit configured to determine, for at least one delegate client, at least one delegate node information in the node information network and public key information corresponding to a target delegate node in the at least one delegate node information; A first generating unit is configured to generate a set of proxy re-encryption key fragments for the at least one delegate node information according to the public key information; An execution unit, configured to execute subscription of a message confirmation event for the delegator node information and the at least one delegatee node information; The sending unit is configured to distribute the proxy re-encryption key fragment set to at least one delegate client corresponding to the at least one delegate node information in response to determining that the message confirmation event is executed successfully, and to send the ciphertext-related data information to the target delegate client corresponding to the target delegate node.
11. A decryption data generating device, applied to a target entrusted party client, comprising: The first receiving unit is configured to receive the proxy re-encryption key fragment and ciphertext-related data information sent by the client as the target proxy re-encryption key fragment and target ciphertext-related data information, wherein the target ciphertext-related data information includes: a re-encryption result integration threshold; a second generating unit, configured to generate re-encryption result acquisition event information; a publishing unit configured to publish the re-encryption result acquisition event information on a node information network; a second receiving unit configured to, in response to a successful publication, receive a re-encryption result for a corresponding proxy re-encryption key fragment sent by at least one remaining node information corresponding node in the node information network, and obtain a re-encryption result set; The third generation unit is configured to generate decrypted data based on the target proxy re-encryption key fragment, the target ciphertext-related data information and the re-encryption result set in response to the number of re-encryption results corresponding to the received re-encryption result set reaching the re-encryption result integration threshold.
12. An electronic device comprising: one or more processors; a storage device having one or more programs stored thereon, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 9.
13. A computer-readable medium having a computer program stored thereon, wherein: When the program is executed by a processor, the method according to any one of claims 1 to 9 is implemented.
14. A computer program product comprising a computer program, which, when executed by a processor, implements the method according to any one of claims 1 to 9.
Citation Information
Patent Citations
Key protection method based on block chain
CN111147241A
Verifiable outsourcing partial policy hidden attribute encryption method and system
CN115361126A