Data Circulation and Transaction Privacy Protection Method Based on Blockchain Technology

By adopting distributed key generation, fully homomorphic encryption, secure multi-party computing and Byzantine fault-tolerant verification mechanisms in the decentralized privacy protection data sharing and processing system of blockchain technology, data privacy protection problems in data circulation transactions are solved, and an efficient and flexible privacy protection solution is achieved.

CN119577825BActive Publication Date: 2025-06-20DIGITAL DALI CONSTRUCTION OPERATION CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411595987.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-11
Publication Date
2025-06-20
Estimated Expiration
2044-11-11

AI Technical Summary

Technical Problem

Existing blockchain technology is difficult to effectively protect data privacy in data circulation and transactions, and due to high computing costs and poor system flexibility, it is difficult to apply in the rapidly developing supply chain management field.

Method used

Decentralized privacy-based privacy protection data sharing and processing system is adopted, and through distributed key generation, fully homomorphic encryption, secure multi-party computing and Byzantine fault-tolerant verification mechanism, we ensure the end-to-end privacy of the data during processing and verify the correctness of the calculation results.

Benefits of technology

It realizes improving privacy guarantee performance in the process of rapid data circulation and transactions, reducing transaction costs and performance delays, and is suitable for the rapidly developing supply chain management field.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119577825B_ABST
    Figure CN119577825B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for ensuring data circulation transaction privacy based on blockchain technology, including: constructing a data circulation transaction system based on blockchain; in the consensus layer, a pair of public and private keys are collaboratively generated through a distributed key generation protocol, the private key is split into multiple shares, and distributed to the PPS manager using a verifiable key sharing mechanism; the publisher encrypts the data with the public key and publishes it to the network in a publish-subscribe mode through the PPS manager in the decentralized processing layer; the computing node directly performs calculations on the ciphertext using fully homomorphic encryption technology; after the calculation is completed, the Byzantine fault tolerance mechanism is adopted in the consensus layer to verify the calculation results of the calculation layer; when decryption is required, the PPS managers participating in the reconstruction collaborate to reconstruct the private key through a secure multi-party calculation protocol and a verifiable key sharing mechanism. The present invention can improve the privacy guarantee performance during the fast data circulation transaction process and avoid high transaction costs and performance delays.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data circulation, and more specifically, to a method for protecting the privacy of data circulation transactions based on blockchain technology. Background Art

[0002] In current data circulation transactions, the use of blockchain technology can improve the reliability and transparency of near-real-time insight data extraction processes. However, this has also raised great concerns about data privacy. Existing privacy protection methods usually rely on smart contracts to achieve automation and zero-knowledge proofs to protect privacy. However, in addition to being unable to flexibly adopt system changes while effectively protecting data confidentiality, these methods also introduce a large amount of computational costs and overheads, making them impractical in dynamic data trading environments.

[0003] For example, in the rapidly developing field of supply chain management, the integration of digital technologies has greatly improved data-driven decision-making and operational efficiency. However, this transformation has also exacerbated privacy risks, especially for data producers and consumers of sensitive information such as shared production capabilities and transaction details. Without sufficient safeguards, the exposure of this data can lead to economic losses, loss of competitive advantage, and regulatory violations.

[0004] Current privacy protection methods usually utilize blockchain and smart contracts, often relying on zero-knowledge proofs (ZKP) for privacy-protected data processing. However, these methods face significant limitations, such as the lack of flexibility of smart contracts in handling computational changes and low cost efficiency in fast-paced data sharing environments. Integrating ZKP into smart contracts brings a large amount of computational overhead, including long setup and proof generation times. In addition, ZKP-based systems rely on the trust of a single entity to generate and verify proofs without being tampered with. This centralization of trust poses potential vulnerabilities, as a compromised proof generator may render the entire process ineffective, thereby weakening privacy guarantees. Moreover, many of these solutions require restarting the entire setup when computational changes are needed, thus reducing system flexibility and increasing costs. These limitations are not practical for competitive supply chains that require rapid data processing. Summary of the Invention

[0005] The object of the present invention is to propose a method for protecting the privacy of data circulation transactions based on blockchain technology, which can improve the privacy guarantee performance during fast data circulation transactions and avoid generating high transaction costs and performance delays.

[0006] To achieve the above object, the present invention proposes a method for protecting the privacy of data circulation transactions based on blockchain technology, including:

[0007] Build a blockchain-based data circulation and trading system, where the data circulation and trading system includes: a consensus layer, a decentralized processing layer on the chain, and a computing layer outside the chain; the consensus layer includes validator nodes, the decentralized processing layer includes proxy middleware, and the computing layer includes distributed computers; the proxy middleware includes multiple PPS managers;

[0008] Execute the following data circulation processing flow based on the data circulation and trading system:

[0009] In the consensus layer, the system collaboratively generates a pair of public and private keys through a distributed key generation protocol, where the private key is split into multiple shares and distributed to PPS managers using a verifiable key sharing mechanism to ensure that no single entity can reconstruct the private key;

[0010] The data publisher encrypts the data using the generated public key, and the encrypted data is published to the network in the decentralized processing layer through PPS managers using a publish-subscribe model. The encrypted data only exists in encrypted form to ensure data security;

[0011] The encrypted data is sent to the computing layer and processed by randomly selected computing nodes. The computing nodes use fully homomorphic encryption technology to directly perform calculations on the ciphertext, and the calculation results are submitted to the consensus layer and recorded on the blockchain;

[0012] After the calculation is completed in the computing layer, the Byzantine fault tolerance mechanism is used in the consensus layer to verify the calculation results of the computing layer;

[0013] When decryption is required, the PPS managers participating in the reconstruction collaborate to reconstruct the private key through a secure multi-party computing protocol and a verifiable key sharing mechanism;

[0014] The decrypted result is distributed to subscribers in a secure manner to ensure that sensitive data is not exposed to unauthorized entities throughout the process.

[0015] Optionally, the validators in the consensus layer periodically perform a round of distributed key generation, and new public and private keys are generated in each round of consensus;

[0016] Distribute the public key to the data publisher;

[0017] Split the private key into multiple parts and distribute them among all PPS managers to ensure that no single PPS manager can reconstruct the private key alone.

[0018] Optionally, the data publisher encrypts its data using the public key and submits the hash value of the encrypted information to the consensus layer for consensus;

[0019] The consensus layer submits the encrypted data to the blockchain to ensure data integrity and consensus among validators;

[0020] Among them, the data publisher publishes the encrypted data as a message to the local PPS manager, and the message includes the encrypted data and the computing function to be executed on the encrypted data.

[0021] Optionally, after reaching a consensus, all validator nodes send new verification transactions to the interconnected PPS managers;

[0022] The PPS manager verifies the integrity and consistency of the data by comparing the hash value in the received message with the hash value recorded on the blockchain;

[0023] After the data verification is completed, the PPS manager randomly selects one or more computing nodes from the registered computing node pool to execute specific computing tasks, and assigns the encrypted data and the function to be executed as tasks to the selected computing nodes;

[0024] After receiving the task, the computing node directly performs the calculation on the encrypted data using homomorphic encryption technology.

[0025] Optionally, after the computing node completes the calculation, it returns the encrypted calculation result to the PPS manager;

[0026] The PPS manager submits the hash value of the calculation result received from the computing node to the consensus layer;

[0027] The validator nodes in the consensus layer compare the submitted hash values. For the same input data, when more than two-thirds of the validator nodes reach an agreement on the hash value of the calculation result, a consensus is reached;

[0028] The hash value that reaches a consensus is recorded on the blockchain, indicating that the calculation result has passed the verification.

[0029] Optionally, when the calculation result needs to be decrypted, the PPS manager uses their key shares to jointly reconstruct the private key through a secure multi-party computing protocol and a verifiable key sharing mechanism, and the reconstructed private key is used to decrypt the calculation result to ensure that only authorized entities can access the decrypted data.

[0030] Optionally, the communication between the data publisher, the PPS manager, and the subscriber is encrypted using the Transport Layer Security protocol.

[0031] Optionally, the Byzantine fault tolerance verification mechanism includes verifying the hash value of the calculation result on multiple validator nodes to ensure the consistency and accuracy of the calculation.

[0032] Optionally, it further includes:

[0033] The PPS manager records the hash values of all relevant transactions and calculation results on the blockchain to provide an immutable audit trail.

[0034] Optionally, it further includes:

[0035] The system continuously monitors the behavior of the PPS manager to ensure that any suspicious activities can be detected in a timely manner. The suspicious activities include calculation failures or tampered messages.

[0036] The beneficial effects of the present invention are as follows:

[0037] The method of the present invention first constructs a decentralized privacy - protected data sharing and data - circulation trading system based on blockchain technology. It can ensure zero - knowledge communication without the traditional zero - knowledge proof (ZKP). This system can extract insights from encrypted data while verifying the correctness of the processing process. The system integrates a consensus mechanism of distributed key generation (DKG), that is, a public key is generated and the corresponding private key is divided into multiple shares; in terms of key reconstruction and decryption, the present invention uses a combination of secure multi - party computation (SMPC) and verifiable secret sharing (VSS). Fully homomorphic encryption (FHE) is used to calculate encrypted data, and the Byzantine fault - tolerant (BFT) verification mechanism ensures the integrity of the calculation by verifying whether the hash values of multiple replicated calculation results are consistent. The data - circulation trading system designed by the present invention adopts a decentralized framework, which can ensure end - to - end privacy during the data processing process and uses the BFT mechanism to verify the correctness of the calculation, thus providing secure insights for data consumers. The present invention utilizes SMPC and adds secret sharing in the key generation and key reconstruction steps to ensure that no single entity can tamper with data integrity or access the process of the original data. Based on the method of the present invention, the data - circulation performance is highly competitive, especially in scenarios with medium message rates, while also maintaining strong privacy guarantees. Compared with the state - of - the - art methods, the method of the present invention can better protect privacy without incurring high transaction costs and performance delays like smart contracts and zero - knowledge - proof - based systems.

[0038] The system of the present invention has other characteristics and advantages, which will be obvious from the accompanying drawings incorporated herein and the subsequent detailed description, or will be described in detail in the accompanying drawings incorporated herein and the subsequent detailed description. These accompanying drawings and detailed description are jointly used to explain the specific principles of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] By describing the exemplary embodiments of the present invention in more detail in conjunction with the accompanying drawings, the above - mentioned and other objects, features, and advantages of the present invention will become more obvious. In the exemplary embodiments of the present invention, the same reference numerals generally represent the same components.

[0040] Figure 1 A schematic diagram of a blockchain - based data - circulation trading system in an embodiment of the present invention is shown.

[0041] Figure 2 Shows the step diagram of the data circulation processing flow in an embodiment of the present invention. Detailed implementation mode

[0042] In view of the problems existing in the prior art, the present invention proposes a privacy protection method for data circulation transactions based on blockchain technology, introduces a decentralized privacy protection data processing solution, and adopts a verification mechanism based on secure multi-party computation, fully homomorphic encryption, and Byzantine fault tolerance to ensure the privacy and correctness of data without incurring the high computational costs in existing systems; by decentralizing the data processing and verification processes, the limitations of previous methods are solved, providing a more scalable and efficient solution for privacy protection in fast-circulating data transactions.

[0043] The present invention will be described in more detail below with reference to the accompanying drawings. Although the preferred embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided to make the present invention more thorough and complete, and to fully convey the scope of the present invention to those skilled in the art.

[0044] Embodiment 1

[0045] This embodiment provides a privacy protection method for data circulation transactions based on blockchain technology, including:

[0046] S1: Construct a data circulation transaction system based on blockchain, as Figure 1 shown, the data circulation transaction system includes: a consensus layer, a decentralized processing layer on the chain, and a computing layer outside the chain; the consensus layer includes verifier nodes, the decentralized processing layer includes proxy middleware, and the computing layer includes distributed computers; the proxy middleware includes multiple PPS managers;

[0047] Specifically, in the consensus layer, consensus based on Byzantine Fault Tolerance (BFT) occurs on each incoming transaction. More than two-thirds of the validators must reach a consensus in order to record the transaction on the ledger. Validator nodes also collaborate in the periodic key generation in the consensus layer. They use the Distributed Key Generation (DKG) protocol to generate public / private key pairs, and each validator participates in generating the shared public / private key pair. This protocol typically involves each validator generating a random polynomial and broadcasting commitments to the coefficients of this polynomial to all other validators. To ensure the integrity of the DKG protocol and mitigate the impact of the node collusion threat model, if a validator disputes the evaluation result, it can periodically request the validator that discloses the evaluation result to provide a zero-knowledge proof (ZKP) of the correctness of the evaluation result. If the proof is invalid or no proof is provided, the validator's polynomial and its commitments will be regarded as problematic and may be excluded from the process. After the protocol execution, all validators hold the same public key and generate private key shares corresponding to the private key, so that no group of validator nodes less than the two-thirds threshold can know the complete private key.

[0048] The validators in the consensus layer are interconnected with the PPS (Publish-Process-Subscribe) manager in the decentralized processing layer and use the above-established protocol for secure communication. All communications between validator nodes, PPS managers, and registered computers are protected using the Transport Layer Security (TLS) protocol. TLS ensures the integrity, confidentiality, and authenticity of data by encrypting the exchanged information. The validators send new key shares and new verification transactions to the corresponding PPS managers through the secure communication channel between the two layers.

[0049] The PPS manager of the proxy middleware in the decentralized processing layer is the connection facilitator between the consensus protocol and the computing layer. The PPS manager connects to the consensus nodes through the libraries of the underlying blockchain platform and the Application Blockchain Interface (ABCI). Whenever a new transaction is ready to be processed, the PPS manager receives a ping. After each ping received by the PPS manager, it is triggered to confirm the existence of the record. This confirmation is completed by comparing the hash value in the received message payload with the set of consensus transaction key values stored on the chain. The functions of the PPS manager include selecting random computers and allocating tasks for the pre-computation process, as well as key partitioning and key reconstruction for the received computation results.

[0050] The computing layer is a registered and identifiable pool of computers. The computing layer is responsible for executing tasks on the encrypted data sharing provided by the PPS manager. The computing layer runs off-chain, and each PPS manager in the network outsources tasks to randomly selected computers in the computing layer. The computations in this layer are performed on encrypted shares without accessing the complete dataset, thus protecting data privacy at all times. Without knowing the actual original data, the computers use fully homomorphic encryption (FHE) technology to compute on ciphertexts. Incorporating FHE into the system framework and decentralizing data processing to multiple computing nodes can significantly enhance privacy and security, thereby not only reducing the processing of sensitive information but also enhancing the security of the framework. The key protocol of this layer is the same as that of the decentralization processing layer, including key sharing and homomorphic encryption.

[0051] S2: As Figure 2 shown, the following data circulation processing flow is performed based on the data circulation trading system:

[0052] S201: In the consensus layer, the system collaboratively generates a pair of public and private keys through a distributed key generation protocol. The private key is split into multiple shares and distributed to PPS managers using a verifiable secret sharing mechanism to ensure that no single entity can reconstruct the private key;

[0053] In this step, the verifiers in the consensus layer regularly perform a round of distributed key generation. Each round of consensus generates new public and private keys; the public key is distributed to data publishers; the private key is divided into multiple parts and distributed among all PPS managers to ensure that no single PPS manager can reconstruct the private key alone.

[0054] Specifically, the verifier nodes (consensus nodes) in the consensus layer regularly perform DKG, and key shares generate new public and private key shares for each round of consensus. The private key is divided into many parts and distributed among all PPS managers to ensure that no single PPS manager can reconstruct the key alone, while the public key is distributed to data publishers.

[0055] The system uses distributed key generation (DKG) technology to collaboratively generate a pair of public and private keys. To reduce the risks associated with centralized key generation, this step uses verifiable secret sharing (VSS) to split the private key into multiple parts and distribute them among relevant nodes to ensure that no single entity can reconstruct the private key. This design can ensure that no single entity can reconstruct the private key, thereby enhancing the security and decentralization of the system.

[0056] S202: The data publisher encrypts the data using the generated public key. The encrypted data is published to the network in a publish-subscribe mode by the PPS manager in the decentralization processing layer. The encrypted data exists only in encrypted form to ensure data security;

[0057] In this step, the data publisher uses the public key to encrypt its data and submits the hash value of the encrypted information to the consensus layer for consensus.

[0058] The consensus layer submits the encrypted data to the blockchain to ensure data integrity and consensus among verifiers. Among them, the data publisher publishes the encrypted data as a message to the local PPS manager, and the message contains the encrypted data and the computing function to be executed on the encrypted data.

[0059] Furthermore, after reaching a consensus, all verifier nodes send new verification transactions to the interconnected PPS managers.

[0060] The PPS manager verifies the integrity and consistency of the data by comparing the hash value in the received message with the hash value recorded on the blockchain.

[0061] Preferably, the communication between the data publisher, the PPS manager, and the subscriber is encrypted using the Transport Layer Security protocol.

[0062] Specifically, after the key is generated and distributed, the publisher uses the generated public key to encrypt the data. The encrypted data is published to the network through the "publish-subscribe" mode and remains secure on the network, accessible only in encrypted form. The communication between the publisher, the agent (PPS manager), and the subscriber (data consumer) is guaranteed through Transport Layer Security (TLS), thus ensuring the secure transmission of data. By enabling encrypted data to be processed and shared without revealing its content. This zero-knowledge publish-subscribe structure applies to all system communications, including the communication between the publisher and the PPS manager, the PPS manager and the distributed computers, and the PPS manager and the subscriber. The consistent use of the zero-knowledge publish-subscribe structure ensures that sensitive information is protected throughout its entire life cycle within the system.

[0063] S203: The encrypted data is sent to the computing layer and processed by randomly selected computing nodes. The computing nodes use fully homomorphic encryption technology to directly perform calculations on the ciphertext, and the calculation results are submitted to the consensus layer and recorded on the blockchain.

[0064] In this step, after the data verification is completed through step S202, the PPS manager randomly selects one or more computing nodes from the computing node pool registered in the computing layer to execute specific computing tasks, and assigns the encrypted data and the function to be executed as tasks to the selected computing nodes.

[0065] After receiving the task, the computing node directly performs calculations on the encrypted data using homomorphic encryption technology.

[0066] In addition, the PPS manager records the hashes of all relevant transactions and calculation results on the blockchain to provide an immutable audit trail.

[0067] Specifically, in the next stage, the decentralized processing layer facilitates decentralized data processing based on its functions. A privacy-preserving data processing function is integrated into the system, which can directly perform calculations on ciphertext using fully homomorphic encryption (FHE). In this way, data processing can be carried out without revealing the original data, ensuring that sensitive information remains encrypted throughout the calculation process. That is, after the data processing stage, the distributed computers in the calculation layer run calculation from ciphertext to ciphertext on the encrypted data and submit the calculation results to the consensus layer for recording in the ledger. Thus, even in complex calculation tasks, the confidentiality of the data can be guaranteed. Different from the system that uses zero-knowledge proof (ZKP) to prove the correctness of the calculation, this system achieves zero-knowledge communication by directly performing calculations on encrypted data. This method protects data privacy by ensuring that only encrypted data is processed during the process, thus always maintaining the confidentiality of the data.

[0068] S204: After the calculation is completed in the calculation layer, the Byzantine fault tolerance mechanism is adopted in the consensus layer to verify the calculation results of the calculation layer;

[0069] Among them, the Byzantine fault tolerance verification mechanism includes verifying the hash value of the calculation result on multiple verifier nodes to ensure the consistency and accuracy of the calculation.

[0070] In this step, after the calculation node completes the calculation, the encrypted calculation result is returned to the PPS manager; the PPS manager submits the hash value of the calculation result received from the calculation node to the consensus layer; the verifier nodes in the consensus layer reach a consensus by comparing the submitted hash values. For the same input data, when more than two-thirds of the verifier nodes agree on the hash value of the calculation result, a consensus is reached; the hash value that reaches the consensus is recorded on the blockchain, indicating that the calculation result has passed the verification.

[0071] Specifically, to verify the correctness of the calculation results at the computing layer, a Byzantine Fault Tolerance (BFT) verification process is adopted. Byzantine Fault Tolerance verification involves verifying the hash values of the calculation results on multiple nodes to ensure the consistency and accuracy of the calculations. This verification process is crucial for confirming the integrity of the results without compromising data privacy. Once the calculation results are verified, a group of PPS managers is randomly selected to jointly reconstruct the private key for decryption. This group of PPS managers is selected through a secure random selection mechanism integrated into the consensus protocol, ensuring that the selection process is unpredictable and no single entity can manipulate it. As long as more than two-thirds of the nodes in the consensus layer, processing layer, and computing layer are honest, the privacy and correctness of the calculations can be guaranteed. This threshold ensures the system's resilience to Byzantine faults, enabling it to remain robust even in an adversarial environment.

[0072] S205: When decryption is required, the PPS managers participating in the reconstruction collaborate to reconstruct the private key through a secure multi-party computation protocol and a verifiable key sharing mechanism;

[0073] In this step, when the calculation results need to be decrypted, the PPS managers use their key shares to jointly reconstruct the private key through a secure multi-party computation protocol and a verifiable key sharing mechanism. The reconstructed private key is used to decrypt the calculation results, ensuring that only authorized entities can access the decrypted data.

[0074] Specifically, the processed and verified encrypted results are prepared for decryption in the processing layer. When the calculation results need to be decrypted, the selected PPS managers use their key shares to collaboratively reconstruct the private key in a privacy-preserving manner, that is, using the Secure Multi-Party Computation (SMPC) protocol and Verifiable Secret Sharing (VSS) to securely reconstruct the private key required for decryption. The key reconstruction is carried out in a decentralized manner, ensuring that no single entity can access the private key alone, thus further strengthening the zero-knowledge feature of the system. By only allowing the necessary number of nodes to participate in this process, the system can maintain privacy and security.

[0075] S206: Distribute the decrypted results to subscribers in a secure manner, ensuring that sensitive data is not exposed to unauthorized entities throughout the process.

[0076] Specifically, after successful decryption, the decrypted results are shared with users and other stakeholders as needed. The decrypted results are transmitted in a secure manner, ensuring that sensitive data is processed and shared without exposing the original data to potential risks.

[0077] In addition, the system continuously monitors the behavior of the PPS managers to ensure that any suspicious activities can be detected in a timely manner. The suspicious activities include calculation failures or message tampering.

[0078] Based on the above, the present invention utilizes verifications based on SMPC, FHE, and BFT to ensure the privacy and correctness of data without incurring the high computational costs in existing systems. By decentralizing the data processing and verification processes, it addresses the limitations of previous methods and provides a more scalable and efficient solution for the privacy-preserving sharing of data in the data circulation and trading process.

[0079] The embodiments of the present invention have been described above. The above description is exemplary and not exhaustive, and is also not limited to the disclosed embodiments. Many modifications and variations are obvious to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments.

Claims

1. A data circulation transaction privacy protection method based on blockchain technology, characterized in that: include: Construct a data circulation transaction system based on blockchain, the data circulation transaction system includes: a consensus layer on the chain, a distributed processing layer and a computing layer outside the chain; the consensus layer includes a verifier node, the distributed processing layer includes an agent middleware, and the agent middleware includes multiple PPS managers; the computing layer includes distributed computers, the computing layer is a registered and identifiable computer pool, the computing layer is responsible for performing tasks on the encrypted data share provided by the PPS manager, the computing layer runs outside the chain, and each PPS manager in the network outsources tasks to a randomly selected computer in the computing layer; The following data circulation processing flow is executed based on the data circulation transaction system: At the consensus layer, the system collaboratively generates a pair of public and private keys through a distributed key generation protocol, where the private key is split into multiple shares and distributed to PPS managers using a verifiable key sharing mechanism to ensure that no single entity can reconstruct the private key; the verifier in the consensus layer regularly performs a round of distributed key generation, each round of consensus generates new public and private keys, distributes the public key to the data publisher, and divides the private key into multiple shares and distributes them among all PPS managers; The data publisher uses the generated public key to encrypt the data. The encrypted data is published to the network in the distributed processing layer through the PPS manager in a publish-subscribe mode. The encrypted data only exists in encrypted form to ensure data security. The encrypted data is sent to the computing layer and processed by randomly selected computing nodes. The computing nodes use fully homomorphic encryption technology to perform calculations directly on the ciphertext. The calculation results are submitted to the consensus layer and recorded on the blockchain. After the calculation is completed at the calculation layer, the Byzantine fault tolerance mechanism is used at the consensus layer to verify the calculation results of the calculation layer; the Byzantine fault tolerance mechanism includes verifying the hash value of the calculation result on multiple verifier nodes. For the same input data, when more than two-thirds of the verifier nodes agree on the hash value of the calculation result, a consensus is reached; When decryption is required, the PPS managers involved in the reconstruction collaborate to reconstruct the private key through a secure multi-party computing protocol and a verifiable key sharing mechanism; The decrypted results are distributed to subscribers in a secure manner, ensuring that sensitive data is not exposed to unauthorized entities during the entire process.

2. The method according to claim 1, characterized in that The data publisher uses the public key to encrypt its data and submits the hash value of the encrypted information to the consensus layer for consensus; The consensus layer submits encrypted data to the blockchain, ensuring data integrity and consensus among validators; The data publisher publishes the encrypted data as a message to the local PPS manager, where the message contains the encrypted data and a calculation function to be executed on the encrypted data.

3. The method according to claim 2, characterized in that After reaching consensus, all validator nodes send new verification transactions to the interconnected PPS managers; The PPS Manager verifies the integrity and consistency of the data by comparing the hash value in the received message with the hash value recorded on the blockchain; After data verification is completed, the PPS manager randomly selects one or more computing nodes from the registered computing node pool to perform a specific computing task, and assigns the encrypted data and the function to be executed as a task to the selected computing node; After receiving the task, the computing node uses homomorphic encryption technology to perform calculations directly on the encrypted data.

4. The method according to claim 3, characterized in that After the computing node completes the calculation, it returns the encrypted calculation result to the PPS manager; The PPS manager submits the hash value of the calculation result received from the computing node to the consensus layer; The validator nodes in the consensus layer compare the submitted hash values. For the same input data, when more than two-thirds of the validator nodes agree on the hash value of the calculation result, a consensus is reached. The consensus hash value is recorded on the blockchain, indicating that the calculation result has been verified.

5. The method according to claim 4, characterized in that When the calculation results need to be decrypted, the PPS managers use their key shares to jointly reconstruct the private key through a secure multi-party computing protocol and a verifiable key sharing mechanism. The reconstructed private key is used to decrypt the calculation results, ensuring that only authorized entities can access the decrypted data.

6. The method according to claim 1, characterized in that Communications between data publishers, PPS managers, and subscribers are encrypted using the Transport Layer Security protocol.

7. The method according to claim 1, characterized in that Also includes: The PPS Manager records all relevant transactions and hashes of calculation results on the blockchain to provide an immutable audit trail.

8. The method according to claim 1, characterized in that Also includes: The system continuously monitors the behavior of the PPS Manager to ensure that any suspicious activities, such as computation failures or message tampering, are detected promptly.

Citation Information

Patent Citations

  • Supply chain management method and management system based on block chain

    CN118113702A

  • Homomorphic encryption voting method and system based on securely reconfigurable secret sharing

    CN118353603A