A data processing method and apparatus

By dynamically determining the encryption method and obtaining the encryption key through the blockchain system, the problem of data leakage caused by the theft of data encryption and decryption methods is solved, and higher data transmission security is achieved.

CN116743407BActive Publication Date: 2026-02-24CHINA MOBILE GROUP SHANDONG +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210207632.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-03-04
Publication Date
2026-02-24
Estimated Expiration
2042-03-04

AI Technical Summary

Technical Problem

In existing technologies, there is a problem of data leakage caused by third parties stealing data encryption and decryption methods.

Method used

The encryption method of electronic devices is determined by the blockchain system, and the encryption method is sent to the Certificate Authority (CA) to obtain the corresponding encryption key and decryption key. The encryption method is dynamically changed to improve the security of data transmission.

Benefits of technology

It improves the security of data transmission and prevents data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116743407B_ABST
    Figure CN116743407B_ABST
Patent Text Reader

Abstract

The data processing method and device provided in the embodiments of the present application comprise the following steps: a block link receives a first request message sent by a first electronic device; the first request message carries identification information of the first electronic device, information of data to be sent by the first electronic device, and identification information of a second electronic device; the encryption mode of the first electronic device is determined according to the first request message; the encryption mode of the first electronic device is sent to a certificate authority (CA), so that the CA determines the encryption key and the decryption key corresponding to the encryption mode according to the encryption mode of the first electronic device, and sends the encryption key to the first electronic device. In this way, the dynamic change of the encryption mode can be realized, and the security of data transmission is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data processing technology, and specifically to a data processing method and apparatus. Background Technology

[0002] In today's information-rich world, various industries have gradually realized data informatization. With the development of computer technology, more and more data processing tasks can be analyzed and processed by computers.

[0003] In existing technologies, data is encrypted during transmission to ensure security. The sender and receiver typically agree on an encryption / decryption method beforehand. The sender encrypts the data using this method and transmits it to the receiver, who then decrypts it using the agreed-upon method to retrieve the data. However, if this encryption / decryption method is discovered by a third party, they can also decrypt the data, leading to data leakage. Therefore, ensuring data security is a pressing issue that needs to be addressed. Summary of the Invention

[0004] In view of this, this application provides a data processing method and apparatus to help solve the problem of data leakage caused by the theft of encryption methods.

[0005] In a first aspect, embodiments of this application provide a data processing method applied to blockchain, the method comprising:

[0006] The blockchain receives a first request message sent by a first electronic device; the first request message carries the identification information of the first electronic device, the information of the data to be sent by the first electronic device, and the identification information of a second electronic device;

[0007] The encryption method of the first electronic device is determined based on the first request message;

[0008] The encryption method of the first electronic device is sent to the Certificate Authority (CA), so that the CA can determine the encryption key and decryption key corresponding to the encryption method and send the encryption key to the first electronic device.

[0009] Preferably, the blockchain includes a main chain and at least one processing slave chain; wherein, the main chain includes a management node and at least one main chain node; the at least one processing slave chain is connected to the at least one main chain node respectively, and each processing slave chain is connected to only one main chain node; each of the at least one processing slave chains contains at least one slave chain node;

[0010] The blockchain receives a first request message sent by the first electronic device, including:

[0011] The blockchain's management node receives the first request message sent by the first electronic device;

[0012] Determining the encryption method of the first electronic device based on the first request message includes:

[0013] The management node identifies the target main chain node from at least one main chain node;

[0014] The management node sends information about the data to be sent by the first electronic device to the target processing slave chain through the target main chain node, so that at least one slave chain node of the target processing slave chain can determine the encryption method of the first electronic device based on the information about the data to be sent by the first electronic device; the target processing slave chain is a processing slave chain connected to the target main chain node;

[0015] The management node receives the encryption method of at least one of the first electronic devices through the target main chain node;

[0016] The encryption method for sending the first electronic device to the Certificate Authority (CA) includes:

[0017] If at least one of the first electronic devices receives the same encryption method, then the encryption method of the first electronic device is sent to the CA.

[0018] Preferably, the blockchain includes a main chain and at least two processing slave chains; wherein the main chain includes a management node and at least two main chain nodes; and the at least two processing slave chains are respectively connected to the at least one main chain node.

[0019] The management node identifies the target main chain node among at least one main chain node, including:

[0020] The management node broadcasts a second request message to at least two main chain nodes and records the broadcast time; the second request message carries identification information of the second information that the management node needs to obtain;

[0021] For each of the at least two main chain nodes, receive the second information sent by the main chain node and the arrival time of the second information; the second information includes the total number of slave chain nodes in the processing slave chain connected to the main chain node and the computing power of each slave chain node;

[0022] The support level of the main chain node is determined based on the recorded broadcast time, the second message received from the main chain node, and the arrival time of the second message.

[0023] Among at least two main chain nodes, the main chain node with the highest support is identified as the target main chain node.

[0024] Preferably, determining the support level of the main chain node based on the recorded broadcast time, the received second information sent by the main chain node, and the arrival time of the corresponding second information includes:

[0025] The computing power of at least one slave node of the processing slave chain connected to the main chain node is determined based on the second information received from the main chain node, and the maximum value of the computing power of at least one slave node is determined as the computing power of the main chain node.

[0026] The support level of a main chain node is determined based on the recorded broadcast time, the arrival time of the second message sent by the main chain node, and the computing power of the main chain node.

[0027] Preferably, the management node broadcasts the second request message to at least two main chain nodes and records the broadcast time, including:

[0028] The management node broadcasts the identification information of the first electronic device to at least two main chain nodes;

[0029] Receive the first information sent by the at least two main chain nodes, and determine, based on the received first information, whether the ledger of each of the at least two main chain nodes records the identification information of the first electronic device;

[0030] If it is determined that the ledger of each of the at least two main chain nodes records the identification information of the first electronic device, a first random decimal number is generated and broadcast to the at least two main chain nodes so that each main chain node can determine whether to send its recorded security level of the first electronic device to the management node based on the received first random decimal number.

[0031] The system receives the security level of the first electronic device sent by at least two main chain nodes, and determines the first main chain node based on the received security level.

[0032] Broadcast a second request message to at least two main chain nodes and record the broadcast time; the second request message carries the identification information of the first main chain node and the identification information of the second information that the management node needs to obtain.

[0033] Preferably, determining the first main chain node based on the received security level includes:

[0034] Based on the received security level, determine whether the number of main chain nodes sending the security level exceeds half of the total number of main chain nodes;

[0035] If the number of main chain nodes sending security levels exceeds half the total number of main chain nodes, then determine whether the received security levels are all the same.

[0036] If it is determined that the security levels of all received nodes are the same, then the main chain node with the same security level as the sending node is designated as the first main chain node.

[0037] Preferably, the method further includes:

[0038] If it is determined that the identification information of the first electronic device is not recorded in the ledger of at least one main chain node, a response message of refusing to obtain the encryption method is returned to the first electronic device;

[0039] Receive the identification information of the first electronic device sent by the first electronic device;

[0040] Broadcast the identification information of the first electronic device to at least two main chain nodes;

[0041] Receive third information sent by at least two main chain nodes, and determine, based on the received third information, whether each of the at least two main chain nodes has recorded the identification information of the first electronic device;

[0042] If it is determined that the ledger of at least one main chain node does not record the identification information of the first electronic device, a security level acquisition request message is sent to the first electronic device.

[0043] The security level received from the first electronic device;

[0044] The security level of the first electronic device is broadcast to at least two main chain nodes so that each main chain node records the identification information and security level of the first electronic device in its own ledger.

[0045] Preferably, after sending the encryption method of the first electronic device to the Certificate Authority (CA), the method further includes:

[0046] Receive a third request message sent by a second electronic device; the third request message carries the identification information of the first electronic device and the identification information of the second electronic device;

[0047] According to the third request message, the encryption method of the first electronic device is sent to the second electronic device so that the second electronic device can obtain the decryption key from the CA according to the encryption method of the first electronic device, and then decrypt the received encrypted data to obtain the data.

[0048] Secondly, embodiments of this application provide a data processing method, including:

[0049] The first electronic device sends a first request message to the blockchain;

[0050] Receive the encryption key sent by the CA, and encrypt the data according to the encryption method of the first electronic device and the encryption key;

[0051] The encrypted data is sent to a second electronic device.

[0052] Thirdly, embodiments of this application provide an electronic device, including:

[0053] A processor and a memory, the memory storing a computer program that, when executed, causes the electronic device to perform the method described in either the first or second aspect above.

[0054] Using the scheme provided in this application embodiment, when a first electronic device sends data to a second electronic device, the blockchain first receives a first request message sent by the first electronic device. This first request message carries the identification information of the first electronic device, information about the data to be sent by the first electronic device, and the identification information of the second electronic device. Then, based on the first request message, the blockchain determines the encryption method of the first electronic device and sends this encryption method to a Certificate Authority (CA). The CA then determines the corresponding encryption and decryption keys based on the encryption method and sends the encryption keys to the first electronic device. In this way, when the first electronic device sends data to the second electronic device, the blockchain can determine the encryption method based on the information about the data to be sent. Since the data to be sent by the first electronic device may differ, the encryption method determined by the blockchain may be the same or different. After determining the encryption method of the first electronic device, the blockchain sends the encryption method to the CA, and the CA sends the corresponding encryption keys to the first electronic device. In other words, according to the method provided in this application embodiment, the encryption method used by the first electronic device to send data is dynamically changing, which improves the security of data transmission. Attached Figure Description

[0055] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0056] Figure 1 A flowchart illustrating a data processing method provided in an embodiment of this application;

[0057] Figure 2 A schematic diagram of a blockchain structure is provided as an embodiment of this application;

[0058] Figure 3 A flowchart illustrating another data processing method provided in an embodiment of this application;

[0059] Figure 4 A flowchart illustrating another data processing method provided in an embodiment of this application;

[0060] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0061] To better understand the technical solution of this application, the embodiments of this application will be described in detail below with reference to the accompanying drawings.

[0062] It should be understood that the described embodiments are merely some, not all, of the embodiments in this application. All other embodiments obtained by those skilled in the art based on the embodiments in this application without inventive effort are within the scope of protection of this application.

[0063] The terminology used in the embodiments of this application is for the purpose of describing particular embodiments only and is not intended to be limiting of this application. The singular forms “a,” “the,” and “the” used in the embodiments of this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise.

[0064] It should be understood that the term "and / or" used in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this article generally indicates that the preceding and following related objects have an "or" relationship.

[0065] Before providing a detailed description of the embodiments of this application, the terms used or possibly used in the embodiments of this application will first be explained.

[0066] Computing power (also known as hash rate) is a measure of the processing power of the Bitcoin network. It refers to the speed at which a computer (CPU) calculates the output of a hash function. The Bitcoin network requires intensive mathematical and cryptographic operations for security purposes.

[0067] Blockchain: In essence, it is a shared database in which the data or information stored has characteristics such as "unforgeable", "fully traceable", "transparent", and "collectively maintained".

[0068] A Certificate Authority (CA) is a trusted third-party entity that issues digital certificate authorities and manages public keys and certificates used to encrypt end-user data. The CA's responsibility is to ensure that companies or users receive valid, unique certificates for identity verification.

[0069] In related technologies, the data sender and receiver pre-agree on encryption and decryption methods. The sender encrypts the data according to the agreed encryption method and transmits the encrypted data to the receiver. The receiver then decrypts the data according to the agreed decryption method to obtain the data. However, if the agreed encryption and decryption methods are discovered by a third party, the third party may also decrypt the encrypted data, resulting in data leakage.

[0070] To address the aforementioned problems, this application provides a data processing method. In this method, when a first electronic device sends data to a second electronic device, the blockchain first receives a first request message from the first electronic device. This first request message carries the identification information of the first electronic device, information about the data to be sent by the first electronic device, and the identification information of the second electronic device. Then, based on the first request message, the blockchain determines the encryption method of the first electronic device and sends this encryption method to a Certificate Authority (CA). The CA then determines the corresponding encryption and decryption keys based on the encryption method and sends the encryption keys to the first electronic device. In this way, when the first electronic device sends data to the second electronic device, the blockchain can determine the encryption method based on the information about the data to be sent. Different data will result in different encryption methods determined by the blockchain. After determining the encryption method, the blockchain sends the encryption method to the CA, and the CA sends the corresponding encryption keys to the first electronic device. In other words, according to the method provided in this application, the encryption method used by the first electronic device to send data is dynamically changing, thus improving the security of data transmission. A detailed explanation follows.

[0071] Figure 1 A data processing method provided in this application embodiment. See also Figure 1 As shown, the data processing method provided in this application mainly includes the following steps:

[0072] Step S101: The blockchain receives the first request message sent by the first electronic device.

[0073] The first request message contains the identification information of the first electronic device, the information of the data to be sent by the first electronic device, and the identification information of the second electronic device.

[0074] Specifically, when the first electronic device sends data to the second electronic device, it first sends a first request message to the blockchain to obtain the encryption method. At this time, the blockchain receives the first request message sent by the first electronic device. The first request message carries the identification information of the first electronic device, the information of the data to be sent by the first electronic device, and the identification information of the second electronic device.

[0075] As one possible implementation, the blockchain includes a main chain and at least one processing slave chain; wherein the main chain includes a management node and at least one main chain node; at least one processing slave chain is connected to at least one main chain node respectively, and each processing slave chain is connected to only one main chain node; each of the at least one processing slave chain contains at least one slave chain node.

[0076] In this embodiment, the blockchain includes a main chain and at least one processing slave chain. The main chain includes a management node and at least one main chain node. The management node communicates with electronic devices and stores the total number of main chain nodes. The at least one processing slave chain is used to determine the encryption method. Each processing slave chain contains at least one slave chain node, and the number of slave chain nodes in each processing slave chain can be the same or different.

[0077] Furthermore, the blockchain receiving the first request message sent by the first electronic device includes:

[0078] The blockchain's management node receives the first request message sent by the first electronic device.

[0079] Specifically, the blockchain's management node is used to communicate with electronic devices. Therefore, when the first electronic device sends a first request message to the blockchain, the management node receives the first request message and processes it accordingly.

[0080] Step S102: Determine the encryption method of the first electronic device based on the first request message.

[0081] In this embodiment of the application, after the blockchain receives the first request message sent by the first electronic device, it can determine the encryption method of the first electronic device based on the first request message.

[0082] As one possible implementation, determining the encryption method of the first electronic device based on the first request message includes:

[0083] The management node identifies the target main chain node from at least one main chain node;

[0084] The management node sends information about the data to be sent by the first electronic device to the target processing slave chain through the target main chain node, so that at least one slave chain node of the target processing slave chain can determine the encryption method of the first electronic device based on the information about the data to be sent by the first electronic device; the target processing slave chain is a processing slave chain connected to the target main chain node;

[0085] The management node receives the encryption method of at least one first electronic device through the target main chain node.

[0086] Specifically, the management node can only interact with the main chain node and cannot directly send the data information of the first electronic device to the processing slave chain. Therefore, the management node needs to first determine the target main chain node. For example, all main chain nodes can be designated as the target main chain node, or at least one main chain node can be selected as the target main chain node. Then, the data information of the first electronic device is sent to the target main chain node, which forwards the data information to the target processing slave chain, i.e., the processing slave chain connected to the target main chain node. This allows at least one slave chain node of the target processing slave chain to determine the encryption method of the first electronic device based on the data information. The data information to be sent by the first electronic device can include the size of the data to be sent, the data security level, and the data transmission method. For example, the data transmission method can be public network transmission or private network transmission.

[0087] It should be noted that the data security level can be set by the user according to actual needs, and can be divided into 1-5 levels or 1-10 levels, as long as the higher the number, the higher the data security level. Furthermore, the data security level of the data to be transmitted by the first electronic device can be determined by the user after the data is generated, and this application does not impose any restrictions on this.

[0088] For example, a chain node can determine the encryption method of the first electronic device based on the data information of the first electronic device using the following formula (1):

[0089]

[0090] Where I is the encryption index, a is the size of the data to be sent, A is the value of the maximum data transmission unit, b is the value of the data security level, and c is the value corresponding to the data transmission method. If the data transmission method is public network transmission, then c = 0.1; if the data transmission method is private network transmission, then c = 1. Since at least one encryption method is stored in the chain node, and each encryption method has a corresponding selection range, the chain node can calculate the encryption index based on the data information received from the first electronic device, and then determine the encryption method corresponding to the selection range where the encryption index is located as the encryption method of the first electronic device. If the encryption index does not have a corresponding selection range, the encryption method with the largest upper limit of the selection range can be determined as the encryption method of the first electronic device, or an encryption method can be randomly selected from at least one encryption method. Of course, the encryption method of the first electronic device can also be determined by other methods, for example, this application does not limit this.

[0091] It should be noted that if at least two encryption methods are stored in the chain node, the selection intervals corresponding to each pair of encryption methods may or may not overlap. In other words, the selection intervals corresponding to each pair of encryption methods may or may not overlap, and this application does not impose any restrictions on this. For example, the selection interval q corresponding to encryption method 1 is 0≤q<4, and the selection interval p corresponding to encryption method 1 is 1≤p<4. In this case, the selection intervals corresponding to encryption method 1 and encryption method 2 overlap. When the encryption index is determined to be 5 from the chain node, there is no corresponding selection interval for encryption index 5. At this time, it can be determined that there are two encryption methods corresponding to the selection interval with the largest upper limit, namely encryption method 1 and encryption method 2. Among encryption method 1 and encryption method 2, the encryption method with the smallest lower limit of the selection interval is determined as the encryption method of the first electronic device, namely encryption method 1.

[0092] Then, after the target processing subchain determines the encryption method of the first electronic device, it sends the encryption method of the first electronic device to the management node through the target main chain node connected to it. Since the target processing subchain contains at least one subchain node, each of the at least one subchain node will determine an encryption method of the first electronic device. At this time, the management node receives at least one encryption method of the first electronic device.

[0093] As one possible implementation, the management node can identify at least one main chain node as the target main chain node. Then, for each target main chain node, the management node sends information about the data to be transmitted by the first electronic device to the target processing slave chain connected to it through that target main chain node. This allows at least one slave chain node of the target processing slave chain to determine the encryption method of the first electronic device based on the information about the data to be transmitted. After the at least one slave chain node of the target processing slave chain determines the encryption method of the first electronic device, it receives the encryption method of at least one first electronic device through the target main chain node.

[0094] As one possible implementation, the blockchain includes a main chain and at least two processing slave chains. The main chain includes a management node and at least two main chain nodes, and the at least two processing slave chains are each connected to at least one main chain node. A target main chain node can then be identified from among the at least two main chain nodes, and information about the data to be sent by the first electronic device can be sent to the processing slave chains connected to the target main chain node through this target main chain node, so that the processing slave chains connected to the target main chain node can determine the encryption method of the first electronic device. In this case, the management node identifies the target main chain node from among the at least one main chain node by:

[0095] The management node broadcasts a second request message to at least two main chain nodes and records the broadcast time; the second request message carries identification information of the second information that the management node needs to obtain.

[0096] For each of the at least two main chain nodes, receive the second information sent by the main chain node and the arrival time of the second information; the second information includes the total number of slave chain nodes in the processing slave chain connected to the main chain node and the computing power of each slave chain node;

[0097] The support level of the main chain node is determined based on the recorded broadcast time, the second message received from the main chain node, and the arrival time of the second message.

[0098] Among at least two main chain nodes, the main chain node with the highest support is identified as the target main chain node.

[0099] Specifically, the management node can determine a target main chain node from at least two main chain nodes. First, it broadcasts a second request message to at least two main chain nodes and records the broadcast time. For each of the at least two main chain nodes, it receives a second message sent by that main chain node along with its corresponding arrival time. The second message includes the total number of slave chain nodes corresponding to that main chain node and the computing power of each slave chain node. Then, based on the recorded broadcast time, the received second message sent by that main chain node, and its corresponding arrival time, it determines the support level of that main chain node. After determining the support levels of at least two main chain nodes, the main chain node with the highest support level is selected as the target main chain node.

[0100] Furthermore, determining the support level of the main chain node based on the recorded broadcast time, the received second information sent by the main chain node, and the arrival time corresponding to the second information includes:

[0101] The computing power of at least one slave node of the processing slave chain connected to the main chain node is determined based on the second information received from the main chain node, and the maximum value of the computing power of at least one slave node is determined as the computing power of the main chain node.

[0102] The support level of a main chain node is determined based on the recorded broadcast time, the arrival time of the second message sent by the main chain node, and the computing power of the main chain node.

[0103] In other words, after receiving the second information sent by the main chain node, the computing power of each slave chain node in the processing slave chain connected to the main chain node can be obtained based on the second information sent by the main chain node, and the maximum value of the computing power of each slave chain node is determined as the computing power of the main chain node. Among them, computing power can indicate the data processing capability of the main chain node, and the larger the computing power value, the stronger the data processing capability. After determining the computing power of the main chain node, the support of the main chain node can be determined based on the recorded broadcast time, the arrival time corresponding to the second information sent by the main chain node, and the computing power of the main chain node. For example, when determining the support of the main chain node, computing power and transmission time can be considered together. If the computing power of the main chain node is not zero, the support of the main chain node can be determined according to the following formula (2):

[0104]

[0105] Where i represents the i-th main chain node, i = 1, 2, ..., n, and n is a positive integer greater than zero; D i P represents the support of the i-th main chain node. i This represents the computing power of the i-th main chain node, n represents the number of nodes with at least two main chain nodes, T0 is the broadcast time of the record, and T... i ΔT is the sending time corresponding to receiving the second message sent by the i-th main chain node. i The difference between the sending time and the recorded broadcast time for receiving the second message sent by the i-th main chain node.

[0106] If the computing power of a main chain node is zero, then the support level of that main chain node is directly determined to be zero.

[0107] As one possible implementation, the management node broadcasts a second request message to at least two main chain nodes and records the broadcast time, including:

[0108] The management node broadcasts the identification information of the first electronic device to at least two main chain nodes;

[0109] Receive first information sent by at least two main chain nodes, and determine, based on the received first information, whether the ledger of each of the at least two main chain nodes records the identification information of the first electronic device;

[0110] If it is determined that the ledger of at least two main chain nodes contains the identification information of the first electronic device, a first random decimal number is generated and broadcast to at least two main chain nodes so that each main chain node can determine whether to send its recorded security level of the first electronic device to the management node based on the received first random decimal number.

[0111] The system receives the security level of the first electronic device sent by at least two main chain nodes, and determines the first main chain node based on the received security level.

[0112] Broadcast a second request message to at least two main chain nodes and record the broadcast time; the second request message carries the identification information of the first main chain node and the identification information of the second information that the management node needs to obtain.

[0113] Specifically, when multiple main chain nodes exist, identifying the target main chain node from among them is extremely labor-intensive. Therefore, a subset of main chain nodes can be selected, and the target main chain node can be identified only from this subset, saving data processing time. In this way, the management node can first broadcast the identification information of the first electronic device to at least two main chain nodes. After receiving the identification information, each of the at least two main chain nodes generates first information based on whether its ledger records the identification information of the first electronic device, and sends the first information to the management node. The management node receives the first information from the at least two main chain nodes and, based on the received first information, determines whether the ledger of each of the at least two main chain nodes records the identification information of the first electronic device. If the ledger of each of the at least two main chain nodes records the identification information of the first electronic device, it means that the ledger of each main chain node records the identification information and security level of the first electronic device. At this point, the management node can generate a first random decimal and broadcast the first random decimal to the at least two main chain nodes. This allows each main chain node, upon receiving a first random decimal number, to determine whether to send its recorded security level for the first electronic device to the management node. For example, a main chain node can generate a second random decimal number. If the second random decimal number is not greater than the first, it determines to send its recorded security level for the first electronic device to the management node; if the second random decimal number is less than the first, it determines not to send its recorded security level for the first electronic device to the management node. The management node receives the security levels of the first electronic device sent by at least two main chain nodes and determines the first main chain node based on the received security levels. For example, the main chain node that sent the security levels of the first electronic device can be determined as the first main chain node. After determining the first main chain node, a second request message can be broadcast to at least two main chain nodes, and the broadcast time can be recorded. The second request message carries the identification information of the first main chain node and the identification information of the second information that the management node needs to obtain. That is, after at least two main chain nodes receive the second request message, only the first main chain node needs to send the second information to the management node; other main chain nodes do not need to process the second request message. In this way, the management node only needs to determine the target main chain node from the first main chain node, saving data processing time.

[0114] Furthermore, based on the received security level, the first main chain node is determined to include:

[0115] Based on the received security level, determine whether the number of main chain nodes sending the security level exceeds half of the total number of main chain nodes;

[0116] If the number of main chain nodes sending security levels exceeds half the total number of main chain nodes, then determine whether the received security levels are all the same.

[0117] If it is determined that the security levels of all received nodes are the same, then the main chain node with the same security level as the sending node is designated as the first main chain node.

[0118] Specifically, if the number of primary main chain nodes is too small, the computing power of each primary main chain node may be very low. Therefore, the number of primary main chain nodes should be at least half of the total number of main chain nodes. Since each received security level corresponds to one primary chain node sending the security level, the number of primary chain nodes sending the security level can be determined based on the received security levels, and it can be determined whether the number of primary chain nodes sending the security level exceeds half of the total number of main chain nodes. If it is determined that the number of primary chain nodes sending the security level exceeds half of the total number of main chain nodes, it means that at least half of the main chain nodes have sent the security level of the first electronic device to the management node. Furthermore, since the security levels of the first electronic devices stored in each primary chain node may be different, after determining that the number of primary chain nodes sending the security level exceeds half of the total number of main chain nodes, it is necessary to determine whether the received security levels are all the same. If it is determined that the received security levels are all the same, then the primary chain node that sent the security level is determined to be the primary main chain node.

[0119] If it is determined that there are different security levels among the received security levels, the first main chain node can be selected from all the main chain nodes of the sending security levels in descending order of the received security levels. Of course, the first main chain node can also be determined in other ways, as long as the number of the first main chain nodes is at least half of the total number of main chain nodes. This application does not impose any restrictions on this.

[0120] If the number of main chain nodes sending security levels does not exceed half the total number of main chain nodes, the management node regenerates a first random decimal and broadcasts it to at least two main chain nodes. Each of the at least two main chain nodes also regenerates a second random decimal and compares the regenerated second random decimal with the regenerated first random decimal. If the regenerated second random decimal is not greater than the regenerated first random decimal, the main chain node sends the security level of the first electronic device it records to the management node. The management node receives the security levels of the first electronic devices sent by the at least two main chain nodes and determines whether the total number of main chain nodes currently sending security levels and the total number of main chain nodes sending security levels after deduplication exceeds half the total number of main chain nodes. If it exceeds half the total number of main chain nodes, then among the main chain nodes currently sending security levels and the main chain nodes sending security levels in the previous period, all unique main chain nodes are identified as second main chain nodes. The management node then compares whether the security levels sent by all the received second main chain nodes are the same. If the security levels sent by all the received second main chain nodes are the same, then the second main chain node is identified as the first main chain node.

[0121] Step S103: Send the encryption method of the first electronic device to the Certificate Authority (CA) so that the CA can determine the encryption key and decryption key corresponding to the encryption method and send the encryption key to the first electronic device.

[0122] Specifically, the blockchain only stores the encryption method, not the encryption key and decryption key corresponding to the encryption method. The Certificate Authority (CA) stores the encryption key and decryption key corresponding to each encryption method. Therefore, after the encryption method of the first electronic device is determined, the management node sends the encryption method of the first electronic device to the CA so that the CA can determine the encryption key and decryption key corresponding to the encryption method and send the encryption key to the first electronic device.

[0123] Furthermore, the encryption method for sending the first electronic device to the Certificate Authority (CA) includes:

[0124] If the encryption methods of at least one first electronic device received are all the same, then the encryption method of the first electronic device is sent to the CA.

[0125] In this embodiment, the management node receives at least one encryption method. Only when all received encryption methods of at least one first electronic device are the same will the encryption method of the first electronic device be sent to the CA. If at least one encryption method of the first electronic device is different, step S102 is repeated until it is determined that all received encryption methods of at least one first electronic device are the same, and then the encryption method of the first electronic device is sent to the CA.

[0126] It should be noted that a blockchain can include at least one storage slave chain, which is also connected to a main chain node and can be used to store the encryption method of the determined electronic device. In other words, once the management node determines the encryption method of the first electronic device, it can send the encryption method of the first electronic device to the storage slave chain for storage through the main chain node.

[0127] For example, such as Figure 2As shown, assume the blockchain comprises one main chain, one storage sub-chain, and two processing sub-chains. The main chain includes one management node and four main chain nodes: main chain node 1, main chain node 2, main chain node 3, and main chain node 4. The two processing sub-chains are processing sub-chain A and processing sub-chain B. Processing sub-chain A includes four sub-chain nodes: sub-chain node 1, sub-chain node 2, sub-chain node 3, and sub-chain node 4; processing sub-chain B includes three sub-chain nodes: sub-chain node 5, sub-chain node 6, and sub-chain node 7; and the storage sub-chain includes two sub-chain nodes: sub-chain node 8 and sub-chain node 9. The storage sub-chain is connected to main chain node 3, processing sub-chain A is connected to main chain node 2, and processing sub-chain B is connected to main chain node 1. Suppose a first electronic device needs to send data to a second electronic device. The data size is 1000kb, the data transmission method is public network transmission, and the data security level is 3. The first electronic device sends a first request message to the blockchain to obtain the encryption method. This first request message carries the identification information C of the first electronic device, the identification information D of the second electronic device, and the information of the data to be sent. The information of the data to be sent includes the data size being 1000kb, the data transmission method being public network transmission, and the data security level being 3. The blockchain management node receives the first request message and parses it to obtain the identification information C, D, and the data to be sent. The management node broadcasts the identification information C of the first electronic device to the main chain. Each of the four main chain nodes must determine whether its ledger records the identification information C of the first electronic device, generate first information based on the determined result, and send the first information to the first electronic device. Assuming that each of the four main chain nodes records the identification information C of the first electronic device, the management node can determine that each of the four main chain nodes records the identification information C of the first electronic device based on the first information received from the four main chain nodes. The management node generates a first random decimal of 0.5 and broadcasts the first random decimal to the main chain so that each main chain node can determine whether to send its recorded security level of the first electronic device to the management node based on the received first random decimal.Assuming that main chain node 1 generates a second random decimal of 0.4, main chain node 2 generates a second random decimal of 0.3, main chain node 3 generates a random decimal of 0.8, and main chain node 4 generates a random decimal of 0.5, it can be determined that the second random decimal generated by main chain nodes 1, 2, and 4 is no greater than the first random decimal of 0.5. Therefore, main chain nodes 1, 2, and 4 will all send the security level of the first electronic device recorded in their ledgers to the management node. The management node can receive three security levels. Since the number of security levels exceeds half the number of main chain nodes, the management node determines whether the three received security levels are the same. Assuming that the security level of the first electronic device recorded in the ledgers of main chain nodes 1, 2, and 4 is all level 3, the management node can determine that the three received security levels are the same, and thus, main chain nodes 1, 2, and 4 can be identified as the first main chain node. The management node broadcasts a second request message to the main chain, recording the broadcast time as 8:00:00. This second request message carries the identification information of the first main chain node and the identification information of the second piece of information the management node needs to obtain. The identification information of the first main chain node is the same as that of main chain node 1, main chain node 2, and main chain node 4; for example, it could be the names of the main chain nodes. After receiving the second request message, the four main chain nodes parse it to obtain the identification information of the first main chain node and the identification information of the second piece of information the management node needs.First, based on the second request message, main chain node 1 can determine that its identifier is present in the identifier information of the first main chain node. At this point, main chain node 1 needs to send the second information to the management node. This second information contains the number of slave nodes in processing slave chain B connected to main chain node 1 and the computing power of each slave node. Specifically, processing slave chain B contains four slave nodes, and the computing powers of slave nodes 1, 2, 3, and 4 in processing slave chain B are 3 KH / s, 7 KH / s, 4 KH / s, and 6 KH / s, respectively. Similarly, based on the second request message, main chain node 2 can determine that its identifier is present in the identifier information of the first main chain node. At this point, main chain node 2 needs to send the second information to the management node. In the second request message, the second information is the number of slave nodes in the processing slave chain A connected to the main chain node 2 and the computing power of each slave node. That is, the processing slave chain A contains 3 slave nodes, and the computing power of slave nodes 5, 6 and 7 in the processing slave chain A is 5KH / s, 7KH / s and 2KH / s respectively. The main chain node 3 can determine from the second request message that the identification information of the first main chain node does not contain the identification information of the main chain node 3. At this time, the main chain node 3 does not need to process the second request message. The main chain node 4 can determine from the second request message that the identification information of the first main chain node contains the identification information of the main chain node 4. At this time, the main chain node 4 needs to send the second information to the management node, where the second information is the slave node that is not connected to the main chain node 1. The management node receives the second information sent by the first main chain node and the arrival time of the second information. The arrival time of the second information sent by the main chain node 1 is 8:00:03, the arrival time of the second information sent by the main chain node 2 is 8:00:02, and the arrival time of the second information sent by the main chain node 4 is 8:00:01. Then, the support of each main chain node in the first main chain node is determined. First, the support of main chain node 1 is determined. According to the second information received from main chain node 1, that is, processing the secondary chain B contains 4 secondary chain nodes, and the computing power of secondary chain node 1, secondary chain node 2, secondary chain node 3, and secondary chain node 4 in processing secondary chain B are 3KH / s, 7KH / s, 4KH / s, and 6KH / s respectively, the maximum value of the computing power of the secondary chain node is determined to be the computing power of main chain node 1, that is, the computing power of main chain node 1 is 7KH / s; according to the recorded broadcast time 8:00:00, the arrival time corresponding to the second information sent by main chain node 1 8:00:03, and the computing power of main chain node 1 7KH / s, the support of main chain node 1 is calculated. According to the above formula (2), the support of main chain node 1 D1 is determined to be 2.08. Similarly, the management node can determine the support of main chain node 2 to be 2.25. For details, please refer to the process of determining the support of main chain node 1, which will not be repeated here. Since the computing power of main chain node 4 is zero, the support of main chain node 4 can be directly determined as zero.Based on the support level of the first main chain node, the management node determines the main chain node with the highest support level as the target main chain node, namely, main chain node 2. The management node can send the data information to be sent by the first electronic device to the processing slave chain A through main chain node 2. The data information to be sent by the first electronic device is 2kb in size, transmitted via public network, and has a data security level of 3. Slave chain nodes 5, 6, and 7 in processing slave chain A can determine the encryption method of the first electronic device based on the data information to be sent by the first electronic device. Taking slave chain node 5 as an example, the process of determining the encryption method of the first electronic device is as follows: Based on the data information to be sent by the first electronic device, it can be known that the data size is 1000Kb, the data security level is 3, and the data transmission method is public network. Assuming that the maximum data transmission unit is 1500Kb, the encryption index I can be determined to be 1.22 according to the above formula (1). Assume that the selection intervals corresponding to the encryption methods stored in chain node 5 do not overlap, that is, the selection interval for encryption method 1 is 0≤D<5, the selection interval for encryption method 2 is 5≤E<10, and the selection interval for encryption method 3 is 10≤F<15. Since the determined encryption index I is 1.22, the encryption method of the first electronic device can be determined to be encryption method 1. Slave nodes 6 and 7 can also determine the encryption method of the first electronic device based on the data information to be sent by the first electronic device. For details, refer to the process of slave node 5 determining the encryption method of the first electronic device, which will not be repeated here. Assume that the encryption method of the first electronic device determined by slave nodes 6 and 7 is encryption method 1. The management node receives the encryption methods of the first electronic device sent by slave nodes 5, 6, and 7 through the main chain node 2. The management node can determine that the encryption methods of the three first electronic devices received are the same, and sends the encryption method of the first electronic device, i.e., encryption method 1, to the Certificate Authority (CA). After confirming that the encryption methods of the three first electronic devices are all the same, the management node can store the encryption methods of the first electronic devices to the storage slave chain through the main chain node 3. For example, when storing, it can be stored in the storage slave chain in the form of "identification information of the first electronic device - encryption method - identification information of the second electronic device", so that the second electronic device can obtain the encryption method of the first electronic device from the blockchain according to the identification information of the first electronic device and the identification information of the second electronic device.

[0128] Figure 3 This is a flowchart illustrating another data processing method provided in an embodiment of this application. Figure 3 As shown, the method mainly includes the following steps:

[0129] Step S301: The blockchain receives the first request message sent by the first electronic device.

[0130] For details, please refer to step S101, which will not be repeated here.

[0131] Step S302: Determine the encryption method of the first electronic device based on the first request message.

[0132] For details, please refer to step S102, which will not be repeated here.

[0133] As one possible implementation, if it is determined that the identification information of the first electronic device is not recorded in the ledger of at least one main chain node, a response message of refusing to obtain the encryption method is returned to the first electronic device;

[0134] Receive the identification information of the first electronic device sent by the first electronic device;

[0135] Broadcast the identification information of the first electronic device to at least two main chain nodes;

[0136] Receive third information sent by at least two main chain nodes, and determine, based on the received third information, whether each of the at least two main chain nodes has recorded the identification information of the first electronic device;

[0137] If it is determined that the ledger of at least one main chain node does not record the identification information of the first electronic device, a security level acquisition request message is sent to the first electronic device.

[0138] The security level received from the first electronic device;

[0139] The security level of the first electronic device is broadcast to at least two main chain nodes so that each main chain node records the identification information and security level of the first electronic device in its own ledger.

[0140] Specifically, if it is determined that at least one main chain node's ledger does not record the identification information of the first electronic device, it indicates that at least one main chain node's ledger does not record the identification information and security level of the first electronic device, thus affecting the determination of the first main chain node. Therefore, if it is determined that at least one main chain node's ledger does not record the identification information of the first electronic device, the management node returns a response message to the first electronic device refusing to obtain the encryption method. After receiving the response message refusing to obtain the encryption method, the first electronic device needs to first store its identification information and security level in the blockchain, and then re-obtain the encryption method. Based on this, the first electronic device can resend its identification information to the management node. The management node receives the identification information sent by the first electronic device and broadcasts it to at least two main chain nodes. It also receives third information sent by at least two main chain nodes, where the third information is the result information generated by each main chain node based on whether its ledger records the identification information of the first electronic device. Based on the received third information, the management node can determine whether each of the at least two main chain nodes has recorded the identification information of the first electronic device. If it is determined that at least one main chain node's ledger does not record the identification information of the first electronic device, a security level retrieval request message is sent to the first electronic device. Upon receiving the security level retrieval request message, the first electronic device sends its security level to the management node. The management node receives the security level sent by the first electronic device and broadcasts it to at least two main chain nodes, so that each main chain node records the identification information and security level of the first electronic device in its own ledger. In this way, at least two main chain nodes' ledgers record the identification information and security level of the first electronic device, allowing the first electronic device to resend the first request message to the blockchain to obtain the encryption method.

[0141] It should be noted that, since the security level of the first electronic device may be low, but when it is used to process confidential data, its security level needs to be adjusted to a high level. Therefore, when the security level of the first electronic device is adjusted, the security level of the first electronic device recorded in the ledgers of all main chain nodes in the blockchain needs to be updated accordingly. In this case, the steps described above can be executed: receiving the identification information of the first electronic device sent by the first electronic device, and then broadcasting the security level of the first electronic device to at least two main chain nodes. This allows each main chain node to record the identification information and security level of the first electronic device in its own ledger. In this way, when the security level of the first electronic device is adjusted, the security level of the first electronic device recorded in the ledgers of all main chain nodes in the blockchain can be updated simultaneously.

[0142] Step S303: If the encryption methods of at least one first electronic device are all the same, then the encryption method of the first electronic device is sent to the CA.

[0143] For details, please refer to step S103, which will not be repeated here.

[0144] Step S304: Receive the third request message sent by the second electronic device.

[0145] The third request message contains the identification information of the first electronic device and the identification information of the second electronic device.

[0146] Specifically, after receiving the encrypted data sent by the first electronic device, the second electronic device can send a third request message to the management node to obtain the encryption method of the first electronic device.

[0147] Step S305: According to the third request message, the encryption method of the first electronic device is sent to the second electronic device so that the second electronic device can obtain the decryption key from the CA according to the encryption method of the first electronic device, and then decrypt the received encrypted data to obtain the data.

[0148] Specifically, the management node can obtain the identification information of the first electronic device and the second electronic device by parsing the third request message, and send the determined encryption method of the first electronic device to the second electronic device so that the second electronic device can obtain the decryption key from the CA according to the encryption method of the first electronic device, and then decrypt the received encrypted data according to the decryption key to obtain the data.

[0149] This application provides another data processing method, the method comprising:

[0150] The first electronic device sends a first request message to the blockchain;

[0151] Receive the encryption key sent by the CA, and encrypt the data according to the encryption method and encryption key of the first electronic device;

[0152] The encrypted data is sent to a second electronic device.

[0153] In this embodiment, before sending data to the second electronic device, the first electronic device needs to encrypt the data to be sent. At this time, the first electronic device sends a first request message to the blockchain to obtain the encryption method. The first request message carries the identification information of the first electronic device, the information of the data to be sent by the first electronic device, and the identification information of the second electronic device. After the blockchain determines the encryption method of the first electronic device, it sends the encryption method to the CA (Certified Access Controller). The CA determines the encryption key and decryption key corresponding to the encryption method of the first electronic device and sends the encryption key to the first electronic device. Then, the first electronic device receives the encryption key sent by the CA, encrypts the data according to the encryption method and encryption key, and then sends the encrypted data to the second electronic device.

[0154] Figure 4 This is a flowchart illustrating another data processing method provided in an embodiment of this application. Figure 4 As shown, the method includes:

[0155] Step S401: The first electronic device sends a first request message to the blockchain, and the blockchain receives the first request message sent by the first electronic device.

[0156] For details, please refer to step S101 above, which will not be repeated here.

[0157] Step S402: Determine the encryption method of the first electronic device based on the first request message.

[0158] For details, please refer to step S102 above, which will not be repeated here.

[0159] Step S403: Send the encryption method of the first electronic device to the Certificate Authority (CA), and the CA receives the encryption method of the first electronic device.

[0160] For details, please refer to step S103 above, which will not be repeated here.

[0161] Step S404: CA sends the encryption key corresponding to the encryption method of the first electronic device to the first electronic device, and the first electronic device receives the encryption key corresponding to the encryption method of the first electronic device.

[0162] Specifically, after receiving the encryption method of the first electronic device, the CA can first determine the encryption key corresponding to the encryption method of the first electronic device, and send the encryption key corresponding to the encryption method of the first electronic device to the first electronic device so that the first electronic device can encrypt the data according to the encryption key.

[0163] Step S405: The first electronic device encrypts the data according to its encryption method and encryption key, and sends the encrypted data to the second electronic device.

[0164] Step S406: The second electronic device sends a third request message to the blockchain, and the blockchain receives the third request message sent by the second electronic device.

[0165] Specifically, after receiving the encrypted data sent by the first electronic device, the second electronic device needs to decrypt the data. It can first obtain the encryption method corresponding to the first electronic device from the blockchain. Therefore, the second electronic device sends a third request message to the blockchain, which receives the message. This third request message carries the identification information of both the first and second electronic devices.

[0166] Step S407: The blockchain sends the encryption method of the first electronic device to the second electronic device according to the third request message, and the second electronic device receives the encryption method of the first electronic device.

[0167] For details, please refer to step S505 above, which will not be repeated here.

[0168] Step S408: The second electronic device sends a fourth request message to the CA.

[0169] The fourth request message contains information about the encryption method of the first electronic device.

[0170] Specifically, after the second electronic device receives the encryption method of the first electronic device, it can obtain the decryption key corresponding to the encryption method of the first electronic device from the CA. At this time, the second electronic device sends a fourth request message to the CA.

[0171] Step S409: CA sends the decryption key corresponding to the encryption method of the first electronic device to the second electronic device, and the second electronic device receives the decryption key corresponding to the encryption method of the first electronic device.

[0172] Step S410: The second electronic device decrypts the encrypted data according to the received decryption key to obtain the data.

[0173] In this way, when the first electronic device sends data to the second electronic device, it can obtain the encryption method from the blockchain based on the data to be sent, and then encrypt the data according to the encryption method determined by the first electronic device. In other words, the encryption method used by the first electronic device when encrypting data is different. Depending on the data to be sent, the encryption method determined by the blockchain may be the same or different, which can improve the security of data transmission and make the encryption method less likely to be leaked.

[0174] Corresponding to the above embodiments, this application also provides an electronic device. Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. The electronic device 500 may include a processor 501, a memory 502, and a communication unit 503. These components communicate through one or more buses. Those skilled in the art will understand that the structure of the server shown in the figure does not constitute a limitation on the embodiment of the present invention. It may be a bus topology or a star topology, and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0175] The communication unit 503 is used to establish a communication channel, enabling the electronic device to communicate with other devices. It can receive user data sent by other devices or send user data to other devices.

[0176] The processor 501 serves as the control center of the electronic device, connecting various parts of the device via interfaces and lines. It executes software programs and / or modules stored in the memory 502, and calls data stored in the memory to perform various functions and / or process data. The processor can be composed of integrated circuits (ICs), such as a single packaged IC or multiple packaged ICs with the same or different functions connected together. For example, the processor 501 may consist only of a central processing unit (CPU). In this embodiment, the CPU may have a single processing core or include multiple processing cores.

[0177] The memory 502 is used to store the execution instructions of the processor 501. The memory 502 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk or optical disk.

[0178] When the execution instructions in memory 502 are executed by processor 501, the electronic device 500 is able to perform operations. Figure 4 Some or all of the steps in the illustrated embodiments.

[0179] Those skilled in the art will clearly understand that the techniques in the embodiments of the present invention can be implemented using software plus necessary general-purpose hardware platforms. Based on this understanding, the technical solutions in the embodiments of the present invention, or the parts that contribute to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in various embodiments or certain parts of the embodiments of the present invention.

[0180] The same or similar parts between the various embodiments in this specification can be referred to mutually. In particular, the device embodiments and terminal embodiments are basically similar to the method embodiments, so the description is relatively simple, and the relevant parts can be referred to the description in the method embodiments.

Claims

1. A data processing method, characterized in that, Applied to blockchain, the method includes: The blockchain receives a first request message sent by a first electronic device; the first request message carries the identification information of the first electronic device, the information of the data to be sent by the first electronic device, and the identification information of a second electronic device; The encryption method of the first electronic device is determined based on the first request message; The encryption method of the first electronic device is sent to the Certificate Authority (CA), so that the CA can determine the encryption key and decryption key corresponding to the encryption method and send the encryption key to the first electronic device. The blockchain includes a main chain and at least one processing slave chain; wherein, the main chain includes a management node and at least one main chain node; the at least one processing slave chain is connected to the at least one main chain node respectively, and each processing slave chain is connected to only one main chain node; each of the at least one processing slave chains contains at least one slave chain node; The blockchain receives a first request message sent by the first electronic device, including: The blockchain's management node receives the first request message sent by the first electronic device; Determining the encryption method of the first electronic device based on the first request message includes: The management node identifies the target main chain node from at least one main chain node; The management node sends information about the data to be sent by the first electronic device to the target processing slave chain through the target main chain node, so that at least one slave chain node of the target processing slave chain can determine the encryption method of the first electronic device based on the information about the data to be sent by the first electronic device; the target processing slave chain is a processing slave chain connected to the target main chain node; The management node receives the encryption method of at least one of the first electronic devices through the target main chain node; The encryption method for sending the first electronic device to the Certificate Authority (CA) includes: If at least one of the first electronic devices receives the same encryption method, then the encryption method of the first electronic device is sent to the CA.

2. The method according to claim 1, characterized in that, The blockchain includes a main chain and at least two processing slave chains; wherein the main chain includes a management node and at least two main chain nodes; and the at least two processing slave chains are respectively connected to the at least one main chain node. The management node identifies the target main chain node among at least one main chain node, including: The management node broadcasts a second request message to at least two main chain nodes and records the broadcast time; the second request message carries identification information of the second information that the management node needs to obtain; For each of the at least two main chain nodes, receive the second information sent by the main chain node and the arrival time of the second information; the second information includes the total number of slave chain nodes in the processing slave chain connected to the main chain node and the computing power of each slave chain node; The support level of the main chain node is determined based on the recorded broadcast time, the second message received from the main chain node, and the arrival time of the second message. Among at least two main chain nodes, the main chain node with the highest support is identified as the target main chain node.

3. The method according to claim 2, characterized in that, The determination of the support level of the main chain node based on the recorded broadcast time, the received second information sent by the main chain node, and the arrival time of the second information includes: The computing power of at least one slave node of the processing slave chain connected to the main chain node is determined based on the second information received from the main chain node, and the maximum value of the computing power of at least one slave node is determined as the computing power of the main chain node. The support level of a main chain node is determined based on the recorded broadcast time, the arrival time of the second message sent by the main chain node, and the computing power of the main chain node.

4. The method according to claim 2, characterized in that, The management node broadcasts the second request message to at least two main chain nodes and records the broadcast time, including: The management node broadcasts the identification information of the first electronic device to at least two main chain nodes; Receive the first information sent by the at least two main chain nodes, and determine, based on the received first information, whether the ledger of each of the at least two main chain nodes records the identification information of the first electronic device; If it is determined that the ledger of each of the at least two main chain nodes records the identification information of the first electronic device, a first random decimal number is generated and broadcast to the at least two main chain nodes so that each main chain node can determine whether to send its recorded security level of the first electronic device to the management node based on the received first random decimal number. The system receives the security level of the first electronic device sent by at least two main chain nodes, and determines the first main chain node based on the received security level. Broadcast a second request message to at least two main chain nodes and record the broadcast time; the second request message carries the identification information of the first main chain node and the identification information of the second information that the management node needs to obtain.

5. The method according to claim 4, characterized in that, The process of determining the first main chain node based on the received security level includes: Based on the received security level, determine whether the number of main chain nodes sending the security level exceeds half of the total number of main chain nodes; If the number of main chain nodes sending security levels exceeds half the total number of main chain nodes, then determine whether the received security levels are all the same. If it is determined that the security levels of all received nodes are the same, then the main chain node with the same security level as the sending node is designated as the first main chain node.

6. The method according to claim 4, characterized in that, The method further includes: If it is determined that the identification information of the first electronic device is not recorded in the ledger of at least one main chain node, a response message of refusing to obtain the encryption method is returned to the first electronic device; Receive the identification information of the first electronic device sent by the first electronic device; Broadcast the identification information of the first electronic device to at least two main chain nodes; Receive third information sent by at least two main chain nodes, and determine, based on the received third information, whether each of the at least two main chain nodes has recorded the identification information of the first electronic device; If it is determined that the ledger of at least one main chain node does not record the identification information of the first electronic device, a security level acquisition request message is sent to the first electronic device. The security level received from the first electronic device; The security level of the first electronic device is broadcast to at least two main chain nodes so that each main chain node records the identification information and security level of the first electronic device in its own ledger.

7. The method according to claim 1, characterized in that, After sending the encryption method of the first electronic device to the Certificate Authority (CA), the method further includes: Receive a third request message sent by a second electronic device; the third request message carries the identification information of the first electronic device and the identification information of the second electronic device; According to the third request message, the encryption method of the first electronic device is sent to the second electronic device so that the second electronic device can obtain the decryption key from the CA according to the encryption method of the first electronic device, and then decrypt the received encrypted data to obtain the data.

8. A data processing method, characterized in that, include: A first electronic device sends a first request message to the blockchain, enabling the blockchain to determine the encryption method of the first electronic device based on the first request message, and send the encryption method of the first electronic device to a Certificate Authority (CA), so that the CA can determine the encryption key and decryption key corresponding to the encryption method based on the encryption method of the first electronic device; the first request message carries the identification information of the first electronic device, the information of the data to be sent by the first electronic device, and the identification information of a second electronic device; Receive the encryption key sent by the CA, and encrypt the data according to the encryption method of the first electronic device and the encryption key; The encrypted data is sent to a second electronic device; wherein the blockchain includes a main chain and at least one processing slave chain; the main chain includes a management node and at least one main chain node; the at least one processing slave chain is connected to the at least one main chain node, and each processing slave chain is connected to only one main chain node; each processing slave chain contains at least one slave chain node; the first electronic device sending a first request message to the blockchain includes: the first electronic device sending a first request message to the management node of the blockchain; The blockchain can determine the encryption method of the first electronic device based on the first request message, and send the encryption method of the first electronic device to the Certificate Authority (CA) by: the management node identifying a target main chain node among at least one main chain node; the management node sending information about the data to be sent by the first electronic device to a target processing slave chain through the target main chain node, so that at least one slave chain node of the target processing slave chain determines the encryption method of the first electronic device based on the information about the data to be sent by the first electronic device; the target processing slave chain is a processing slave chain connected to the target main chain node; The management node receives the encryption method of at least one of the first electronic devices through the target main chain node; If at least one of the first electronic devices receives the same encryption method, then the encryption method of the first electronic device is sent to the CA.

9. An electronic device, characterized in that, include: A processor and a memory, the memory storing a computer program that, when executed, causes the electronic device to perform the method of any one of claims 1-7.

Citation Information

Patent Citations

  • Blockchain encryption ledger based on secret sharing

    CN108809652A

  • Digital encryption method and system based on block chain technology

    CN112019561A