Privacy protection method based on block chain and related equipment

By using temporary private keys and temporary public keys for signature and encryption in blockchain technology, the privacy leakage problem caused by the fixed user public keys and transaction addresses is solved, and high security protection of user privacy is achieved.

CN120012144APending Publication Date: 2025-05-16HISENSE GRP HLDG CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311532992.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-16
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

In blockchain technology, the user's public key and transaction address are fixed, and it is easy for attackers to infer the user's identity through clustering technology or transaction graph analysis, resulting in the threat of user privacy protection.

Method used

The blockchain-based privacy protection method is adopted to generate temporary private keys and temporary public keys through the sender's device, and use these temporary keys to sign and encrypt the target message to ensure that the user's true identity can only be obtained by the receiver, thereby avoiding the leakage of user identity privacy.

Benefits of technology

By generating temporary keys, we ensure that the address of each transaction is not linkable, avoiding the problem of user identity privacy leakage and improving the security of user privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012144A_ABST
    Figure CN120012144A_ABST
Patent Text Reader

Abstract

The invention provides a privacy protection method based on a block chain and related equipment. The method is used for improving the security of user privacy. Comprising the following steps: receiving a data request sent by a user, signing a target message obtained based on the data request by using a first temporary private key, determining a first digital signature, and encrypting the target message by using an initial public key of receiver equipment to determine a first encrypted message; wherein the first temporary private key is generated based on an initial private key of the sender device and a first random number; and determining the first temporary public key, the first encrypted message and the first digital signature as a target data request, and sending the target data request to the block chain, so that the receiver equipment successfully verifies the first digital signature based on the first temporary public key in the target data request obtained from the block chain. And responding to a data request obtained by decrypting the first encrypted message by using the initial private key of the receiver device, the first temporary public key being generated by using the initial private key of the sender device and the first random number.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] In recent years, the application of blockchain technology in government affairs, finance, supply chain and other fields has gradually deepened. Due to its distributed accounting, tamper-proof, open and transparent features, it greatly facilitates the supervision and traceability of business processes within each platform. In addition, blockchain has a certain degree of anonymity. For a user, the user does not need to publish his or her real identity on the blockchain. Just generate a pair of public and private keys, keep the private key yourself, publish the public key on the chain, and generate a transaction address from the public key. When there is business interaction with other users later, the transaction content on the chain includes the initiator's transaction address, message (generally encrypted with the recipient's public key), recipient's transaction address and other information.

[0003] However, for the same user, the public key of the user does not change, and the generated transaction address is also fixed. Therefore, attackers can use clustering technology or transaction graph analysis to establish the connection between addresses and addresses, addresses and transactions, and then obtain the transaction rules and transaction characteristics of the addresses to infer the user's identity, posing a threat to user privacy protection.

[0004] Taking data trading or public data authorization operation scenarios as an example, in addition to platform operators and regulators, on-chain users also include many social enterprises that assume different roles such as data providers, data users, and data processors. These enterprises may be cooperative or competitors. If curious enterprises analyze the transaction status of other users on the chain through the above-mentioned address association analysis method, and combine it with the user identity information collected through on-chain cooperation or other means, they can deduce which other users on the chain their customers have intersections with. They can even know what data competitors use, which users they have intersections with, and other commercial confidential information. Therefore, the problem of blockchain identity privacy leakage needs to be solved urgently. Summary of the invention

[0005] In an exemplary embodiment of the present disclosure, a privacy protection method based on blockchain is provided to avoid the problem of user identity privacy leakage and improve the security of user privacy.

[0006] The first aspect of the present disclosure provides a privacy protection method based on blockchain, which is applied to a sender device, and the method includes:

[0007] receiving a data request sent by a user, and obtaining a target message based on the data request;

[0008] Signing the target message using a first temporary private key to obtain the first digital signature, and encrypting the target message using an initial public key of a receiving device to obtain a first encrypted message; wherein the first temporary private key is generated based on the initial private key of the sending device and a first random number;

[0009] The first temporary public key, the first encrypted message and the first digital signature are determined as a target data request, and the target data request is sent to the blockchain, so that after the receiving device successfully verifies the first digital signature based on the first temporary public key in the target data request obtained from the blockchain, it responds to the data request obtained by decrypting the first encrypted message using the initial private key of the receiving device, wherein the first temporary public key is generated using the initial private key of the sending device and the first random number.

[0010] In this embodiment, the sending device signs the target message with its own initial private key and the first temporary private key generated by the first random number to anonymize the user's identity information, and encapsulates the user's real identity and the first temporary public key generated based on the initial private key of the sending device and the first random number in the ciphertext encrypted using the initial public key of the receiving device to ensure that the sender's real identity can only be obtained by the receiving device. Therefore, in the embodiment of the present application, the sender's own initial private key and the first temporary private key generated by the first random number are used to anonymize the user's real identity. The first temporary private key generated each time is different, so the user address is unlinkable, avoiding the problem of user identity privacy leakage, and improving the security of user privacy.

[0011] In one embodiment, the first temporary private key is obtained by the following formula:

[0012]

[0013] in, is the first temporary private key of the sending device i, D i is the identifier of the sending device i, is the initial private key of the sender device i, and x1 is the first random number;

[0014] The first temporary public key is obtained by the following formula:

[0015]

[0016] in, is the first temporary public key of the sending device i, G is the base of the elliptic curve, and p is the prime number of the elliptic curve.

[0017] In this embodiment, the first temporary private key and the first temporary public key of the sender device are respectively determined by a random number and the initial private key of the sender device. This ensures that the first temporary public key and the first temporary private key generated each time are different, ensures the unlinkability of the user's address, avoids the problem of user identity privacy leakage, and improves the security of user privacy.

[0018] In one embodiment, obtaining a target message based on the data request includes:

[0019] Signing the hash value of the data request using the initial private key of the sender device to obtain a second digital signature; determining the data request, the second digital signature, and the identifier of the sender device as the target message, wherein the hash value of the data request is obtained by encrypting the data request using a hash algorithm;

[0020] Among them, the identification of the sending device is used to instruct the receiving device to obtain the initial public key of the sending device corresponding to the identification of the sending device from the blockchain after decrypting the first encrypted message, and the second digital signature is used to instruct the receiving device to use the initial public key to verify the second digital signature.

[0021] In this embodiment, the data request is signed by using the initial private key of the sender device to obtain a second digital signature, and the data request, the second digital signature and the identifier of the sender device are determined as the target message. Therefore, in the embodiment of the present application, the target message includes the second digital signature obtained by signing the data request using the initial private key of the sender device, so that after the recipient decrypts the first encrypted message, the initial public key of the sender device corresponding to the identifier of the sender device is obtained from the blockchain to verify the second digital signature to ensure that the target message is sent by the target sender device corresponding to the identifier of the sender device. Therefore, the embodiment of the present application ensures that the transaction content sent under the cover of an anonymous identity can be correctly decrypted by the recipient and its true identity can be identified, while preventing attackers from sending malicious information or tampering.

[0022] In one embodiment, after obtaining the target message based on the data request, the method further includes:

[0023] Based on the regulatory category of the data request, obtaining a regulatory public key corresponding to the regulatory category from the blockchain; encrypting the target message using the regulatory public key to obtain a second encrypted message;

[0024] After determining the first temporary public key, the first encrypted message, and the first digital signature as the target data request, the method further includes:

[0025] adding an identification of the regulatory category and the second encrypted message to the target data request;

[0026] Among them, the identifier of the regulatory category is used to indicate the target regulatory device that needs to decrypt the second encrypted message, and the second encrypted message is used to instruct the target regulatory device to use the regulatory private key of the target regulatory device to decrypt the second encrypted message in the target data request to obtain the target message, and based on the identifier of the sender device in the target message, obtain the initial public key of the sender device corresponding to the identifier of the sender device from the blockchain, and use the initial public key to verify the second digital signature.

[0027] In this embodiment, based on the regulatory category of the data request, the regulatory public key corresponding to the regulatory category can be obtained from the blockchain; the target message can be encrypted using the regulatory public key to obtain a second encrypted message, and then the regulatory category identifier and the second encrypted message can be added to the target data request to ensure that after the target regulatory device decrypts the second target encrypted message, the initial public key of the sender device corresponding to the identifier of the sender device can be obtained from the blockchain based on the identifier of the sender device in the target message, and the second digital signature can be verified using the initial public key. This ensures that only the target regulatory device can obtain the true identity of the user, ensuring the security of the user's privacy.

[0028] A second aspect of the present disclosure provides a privacy protection method based on blockchain, which is applied to a receiving device, and the method includes:

[0029] Obtaining a target data request sent by a sending device on a blockchain, wherein the target data request includes a first temporary public key of the sending device, a first encrypted message, and a first digital signature, wherein the first encrypted message is encrypted using a first temporary private key of the sending device, and the first temporary private key is generated based on an initial private key of the sending device and a first random number; and the first temporary public key is obtained by the sending device based on its own initial private key and the first random number, and the first digital signature is generated by the sending device based on the first temporary private key of the sending device;

[0030] Decrypting the first encrypted message using the initial private key of the receiving device to obtain a target message;

[0031] If the first digital signature is successfully verified using the first temporary public key, the data request in the target message is responded to.

[0032] In the embodiment of the present application, the receiving device verifies the first digital signature generated by the sending device based on the first temporary private key of the sending device in the received target data request by using the first temporary public key generated based on the initial private key of the sending device and the first random number. If the verification is successful, the data request in the target message is responded to. Therefore, in the embodiment of the present application, the initial private key of the sending device itself and the first temporary public key generated by the first random number are used to verify the real identity of the user. The first temporary public key generated each time is different, so the unlinkability of the user address is guaranteed, the problem of user identity privacy leakage is avoided, and the security of user privacy is improved.

[0033] In one embodiment, before responding to the data request in the target message, the method further includes:

[0034] Obtaining an identifier of a sender device in the target message;

[0035] Based on the identifier of the sender device, obtaining from the blockchain an initial public key of the sender device corresponding to the identifier of the sender device;

[0036] Verifying the second digital signature in the target message using the initial public key of the sender device;

[0037] If the signature verification is successful, a step of responding to the data request in the target message is determined.

[0038] In the embodiment of the present application, based on the identifier of the sender device, the initial public key of the sender device corresponding to the identifier of the sender device is obtained from the blockchain, and then the initial public key of the sender device is used to verify the second digital signature in the target message. Thus, the security of the user's privacy is further guaranteed.

[0039] The third aspect of the present disclosure provides a privacy protection method based on blockchain, which is applied to a supervision device, and the method includes:

[0040] Obtaining a target data request sent by a sending device on a blockchain, wherein the target data request includes a first temporary public key and a first digital signature of the sending device, and the first digital signature is generated by the sending device based on a first temporary private key of the sending device, the first temporary private key is generated based on an initial private key of the sending device and a first random number, and the first temporary public key is obtained by the sending device based on its own initial private key and the generated first random number;

[0041] Decrypting the second encrypted message in the target data request using the supervision private key of the supervision device to obtain a target message;

[0042] If the first digital signature in the target data request is successfully verified using the first temporary public key of the sender device in the target data request, then based on the identifier of the sender device in the target message, obtaining from the blockchain an initial public key of the sender device corresponding to the identifier of the sender device;

[0043] The second digital signature in the target message is verified using the initial public key of the sender device.

[0044] In the embodiment of the present application, if the supervisory device successfully verifies the first digital signature in the target data request using the first temporary public key of the sender device in the target data request, then the supervisory private key of the supervisory device is used to decrypt the second encrypted message in the target data request to obtain the target message, and based on the identifier of the sender device in the target message, the initial public key of the sender device corresponding to the identifier of the sender device is obtained from the blockchain; the second digital signature in the target message is verified using the initial public key of the sender device. Thus, in the embodiment of the present application, the user's real identity is anonymized by using the initial private key of the sender device itself and the first temporary private key generated by the first random number, and the first temporary private key generated each time is different, and the first digital signature in the target data request is verified by the first temporary public key of the sender device of the supervisory device, which ensures the unlinkability of the user address, avoids the problem of user identity privacy leakage, and improves the security of user privacy.

[0045] A fourth aspect of the present disclosure provides a sender device, comprising a processor and a memory, wherein the processor and the memory are connected via a bus;

[0046] The memory stores a computer program, and the processor is configured to perform the following operations based on the computer program:

[0047] receiving a data request sent by a user, and obtaining a target message based on the data request;

[0048] Signing the target message using a first temporary private key to obtain the first digital signature, and encrypting the target message using an initial public key of a receiving device to obtain a first encrypted message; wherein the first temporary private key is generated based on the initial private key of the sending device and a first random number;

[0049] The first temporary public key, the first encrypted message and the first digital signature are determined as a target data request, and the target data request is sent to the blockchain, so that after the receiving device successfully verifies the first digital signature based on the first temporary public key in the target data request obtained from the blockchain, it responds to the data request obtained by decrypting the first encrypted message using the initial private key of the receiving device, wherein the first temporary public key is generated using the initial private key of the sending device and the first random number.

[0050] In one embodiment, the processor is further configured to:

[0051] The first temporary private key is obtained by the following formula:

[0052]

[0053] in, is the first temporary private key of the sending device i, D i is the identifier of the sending device i, is the initial private key of the sender device i, and x1 is the first random number;

[0054] The first temporary public key is obtained by the following formula:

[0055]

[0056] in, is the first temporary public key of the sending device i, G is the base of the elliptic curve, and p is the prime number of the elliptic curve.

[0057] In one embodiment, the processor executes the step of obtaining a target message based on the data request, and is specifically configured to:

[0058] Signing the hash value of the data request using the initial private key of the sender device to obtain a second digital signature; determining the data request, the second digital signature, and the identifier of the sender device as the target message, wherein the hash value of the data request is obtained by encrypting the data request using a hash algorithm;

[0059] Among them, the identification of the sending device is used to instruct the receiving device to obtain the initial public key of the sending device corresponding to the identification of the sending device from the blockchain after decrypting the first encrypted message, and the second digital signature is used to instruct the receiving device to use the initial public key to verify the second digital signature.

[0060] In one embodiment, the processor is further configured to:

[0061] After obtaining the target message based on the data request, obtaining a regulatory public key corresponding to the regulatory category from the blockchain based on the regulatory category of the data request; encrypting the target message using the regulatory public key to obtain a second encrypted message;

[0062] After determining the first temporary public key, the first encrypted message, and the first digital signature as the target data request, the method further includes:

[0063] adding an identification of the regulatory category and the second encrypted message to the target data request;

[0064] Among them, the identifier of the regulatory category is used to indicate the target regulatory device that needs to decrypt the second encrypted message, and the second encrypted message is used to instruct the target regulatory device to use the regulatory private key of the target regulatory device to decrypt the second encrypted message in the target data request to obtain the target message, and based on the identifier of the sender device in the target message, obtain the initial public key of the sender device corresponding to the identifier of the sender device from the blockchain, and use the initial public key to verify the second digital signature.

[0065] A fifth aspect of the present disclosure provides a receiving device, comprising a processor and a memory, wherein the processor and the memory are connected via a bus;

[0066] The memory stores a computer program, and the processor is configured to perform the following operations based on the computer program:

[0067] Obtaining a target data request sent by a sending device on a blockchain, wherein the target data request includes a first temporary public key of the sending device, a first encrypted message, and a first digital signature, wherein the first encrypted message is encrypted using a first temporary private key of the sending device, and the first temporary private key is generated based on an initial private key of the sending device and a first random number; and the first temporary public key is obtained by the sending device based on its own initial private key and the first random number, and the first digital signature is generated by the sending device based on the first temporary private key of the sending device;

[0068] Decrypting the first encrypted message using the initial private key of the receiving device to obtain a target message;

[0069] If the first digital signature is successfully verified using the first temporary public key, the data request in the target message is responded to.

[0070] In one embodiment, the processor is further configured to:

[0071] Before responding to the data request in the target message, obtaining an identifier of a sender device in the target message;

[0072] Based on the identifier of the sender device, obtaining from the blockchain an initial public key of the sender device corresponding to the identifier of the sender device;

[0073] Verifying the second digital signature in the target message using the initial public key of the sender device;

[0074] If the signature verification is successful, a step of responding to the data request in the target message is determined.

[0075] A sixth aspect of the present disclosure provides a supervision device, comprising a processor and a memory, wherein the processor and the memory are connected via a bus;

[0076] The memory stores a computer program, and the processor is configured to perform the following operations based on the computer program:

[0077] Obtaining a target data request sent by a sending device on a blockchain, wherein the target data request includes a first temporary public key and a first digital signature of the sending device, and the first digital signature is generated by the sending device based on a first temporary private key of the sending device, the first temporary private key is generated based on an initial private key of the sending device and a first random number, and the first temporary public key is obtained by the sending device based on its own initial private key and the generated first random number;

[0078] Decrypting the second encrypted message in the target data request using the supervision private key of the supervision device to obtain a target message;

[0079] If the first digital signature in the target data request is successfully verified using the first temporary public key of the sender device in the target data request, then based on the identifier of the sender device in the target message, obtaining from the blockchain an initial public key of the sender device corresponding to the identifier of the sender device;

[0080] The second digital signature in the target message is verified using the initial public key of the sender device.

[0081] According to a seventh aspect provided by an embodiment of the present disclosure, a computer storage medium is provided, wherein the computer storage medium stores a computer program, and the computer program is used to execute the method described in the first aspect and / or the second aspect and / or the third aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0082] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0083] Figure 1 A schematic diagram of an applicable scenario in an embodiment of the present disclosure;

[0084] Figure 2 A flowchart of a privacy protection method based on blockchain according to an embodiment of the present disclosure;

[0085] Figure 3 A schematic diagram of a process for determining a first digital signature for signature verification according to an embodiment of the present disclosure;

[0086] Figure 4 A schematic diagram of a process of verifying a second digital signature according to an embodiment of the present disclosure;

[0087] Figure 5 A schematic diagram of the levels of supervision devices according to an embodiment of the present disclosure;

[0088] Figure 6 The second flowchart of the privacy protection method based on blockchain according to an embodiment of the present disclosure;

[0089] Figure 7 This is one of the schematic diagrams of a privacy protection device based on blockchain according to an embodiment of the present disclosure;

[0090] Figure 8 This is a second schematic diagram of a privacy protection device based on blockchain according to an embodiment of the present disclosure;

[0091] Fig. 9 This is a third schematic diagram of a privacy protection device based on blockchain according to an embodiment of the present disclosure;

[0092] Fig.10 The figure is a schematic diagram of the structure of an electronic device according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0093] In order to make the purpose, technical solution and advantages of the embodiments of the present disclosure clearer, the technical solution in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present disclosure.

[0094] In the embodiments of the present disclosure, the term "and / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent three situations: A exists alone, A and B exist at the same time, and B exists alone. The character " / " generally indicates that the associated objects before and after are in an "or" relationship.

[0095] The application scenarios described in the embodiments of the present disclosure are intended to more clearly illustrate the technical solutions of the embodiments of the present disclosure, and do not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. It is known to those skilled in the art that with the emergence of new application scenarios, the technical solutions provided by the embodiments of the present disclosure are also applicable to similar technical problems. In the description of the present disclosure, unless otherwise specified, the meaning of "multiple" is two or more.

[0096] In the existing technology, for the same user, the public key of the user does not change, and the generated transaction address is also fixed. Therefore, attackers can use clustering technology or transaction graph analysis to establish the connection between addresses and addresses, addresses and transactions, and then obtain the transaction rules and transaction characteristics of the addresses. To infer the user's identity, it poses a threat to user privacy protection. Therefore, the problem of blockchain identity privacy leakage needs to be solved urgently.

[0097] Therefore, the present disclosure provides a privacy protection method based on blockchain, in which the sender device signs the target message with its own initial private key and the first temporary private key generated by the first random number to anonymize the user's identity information, and encapsulates the user's real identity and the first temporary public key generated based on the initial private key of the sender device and the first random number in the ciphertext encrypted with the initial public key of the receiver device to ensure that the sender's real identity can only be obtained by the receiver. Therefore, in the embodiment of the present application, the sender device's own initial private key and the first temporary private key generated by the first random number are used to anonymize the user's real identity. The first temporary private key generated each time is different, so the unlinkability of the user address is guaranteed, the problem of user identity privacy leakage is avoided, and the security of user privacy is improved. Below, the scheme of the present disclosure is described in detail in conjunction with the accompanying drawings.

[0098] like Figure 1 As shown, an application scenario of a privacy protection method based on blockchain, the application scenario includes a first device 110, a second device 120 and a third device 130.

[0099] In a possible application scenario, the first device 110 receives a data request sent by a user, and obtains a target message based on the data request; then the first device 110 signs the target message using the first temporary private key to obtain the first digital signature, and the first device 110 encrypts the target message using the initial public key of the receiving device to obtain a first encrypted message. And the first device 110 obtains the regulatory public key corresponding to the regulatory category from the blockchain based on the regulatory category of the data request; encrypts the target message using the regulatory public key to obtain a second encrypted message. Among them, the first temporary private key is generated based on the initial private key of the sender device and the first random number. The first temporary public key, the first encrypted message, the first digital signature, the identifier of the regulatory category and the second encrypted message are determined as the target data request, and the target data request is sent to the blockchain. The second device 120 obtains the target data request. If the second device 120 successfully verifies the first digital signature using the first temporary public key, the first encrypted message is decrypted using the initial private key of the receiving device to obtain the target message, and responds to the data request in the target message. And the third device 130 obtains the target data request. If the third device 130 successfully verifies the first digital signature in the target data request using the first temporary public key of the sender device in the target data request, the third device 130 uses the supervisory private key of the supervisory device to decrypt the second encrypted message in the target data request to obtain the target message; then the third device 130 obtains the initial public key of the sender device corresponding to the identifier of the sender device from the blockchain based on the identifier of the sender device in the target message; and verifies the second digital signature in the target message using the initial public key of the sender device.

[0100] in, Figure 1 The first device 110 can exchange information with the second device 120 and the third device 130 through a communication network, wherein the communication mode adopted by the communication network can be divided into a wireless communication mode or a wired communication mode.

[0101] Exemplarily, the first device 110 can access the network through cellular mobile communication technology to communicate with the second device 120 and the third device 130, wherein the cellular mobile communication technology, for example, includes the fifth generation mobile communication (5th Generation Mobile Networks, 5G) technology.

[0102] Optionally, the first device 110 may access the network via short-range wireless communication to communicate with the second device 120 and the third device 130 , wherein the short-range wireless communication may include, for example, Wireless Fidelity (Wi-Fi) technology.

[0103] Among them, the description in this application only details a single first device 110, a single second device 120, and a single third device 130, but those skilled in the art should understand that the illustrated first device 110, the second device 120, and the third device 130 are intended to represent the operations of the first device 110, the second device 120, and the third device 130 involved in the technical solution of this application. It does not imply a limitation on the number, type, or location of the first device 110, the second device 120, and the third device 130. It should be noted that if additional modules are added to the illustrated environment or individual modules are removed therefrom, the underlying concepts of the exemplary embodiments of this application will not be changed.

[0104] It should be noted that the blockchain-based privacy protection method proposed in this application is not only applicable to Figure 1 The application scenario shown is also applicable to any blockchain-based privacy protection device.

[0105] The following describes the privacy protection method based on blockchain in an exemplary embodiment of the present application in combination with the application scenarios described above and with reference to the accompanying drawings. It should be noted that the above application scenarios are only shown to facilitate understanding of the methods and principles of the present application, and the implementation methods of the present application are not limited in this regard.

[0106] like Figure 2 As shown, it is a flowchart of the privacy protection method based on blockchain disclosed in the present invention, which may include the following steps:

[0107] Step 201: The sending device receives a data request sent by a user, and obtains a target message based on the data request;

[0108] In one embodiment, step 201 can be specifically implemented as follows: using the initial private key of the sending device to sign the hash value of the data request to obtain a second digital signature; determining the data request, the second digital signature and the identifier of the sending device as the target message, wherein the hash value of the data request is obtained by encrypting the data request using a hash algorithm.

[0109] The use of a hash algorithm to encrypt data requests in the embodiment of the present application belongs to the prior art and will not be described in detail in the embodiment of the present application.

[0110] Step 202: The sender device signs the target message using the first temporary private key to obtain the first digital signature, and encrypts the target message using the initial public key of the receiver device to obtain a first encrypted message; wherein the first temporary private key is generated based on the initial private key of the sender device and a first random number; wherein the first temporary private key can be obtained by formula (1):

[0111]

[0112] in, is the first temporary private key of the sending device i, D i is the identifier of the sending device i, is the initial private key of the sending device i, and x1 is the first random number.

[0113] In one embodiment, the first encrypted message is obtained by:

[0114] The initial public key of the receiving device and the target message are input into an elliptic curve encryption algorithm to encrypt the target message to obtain the first encrypted message.

[0115] In one embodiment, the first digital signature is obtained by:

[0116] The first temporary private key and the hash value of the target message are input into a digital signature algorithm to obtain the first digital signature, wherein the hash value of the target message is obtained by encrypting the target message using the hash algorithm.

[0117] The elliptic curve encryption algorithm in the embodiment of the present application is an encryption method in the prior art, and the embodiment of the present application will not be described in detail here.

[0118] It should be noted that the signing method in the embodiment of the present application is to use a digital signature algorithm to sign the corresponding data, which can be RSA, ElGamal, Fiat-Shamir, Guillou-Quisquarter, Schnorr, Ong-Schnorr-Shamir, etc. However, the digital signature algorithm is not limited in the embodiment of the present application, and the digital signature algorithm in the embodiment of the present application can be set according to actual conditions.

[0119] Step 203: The sending device obtains a regulatory public key corresponding to the regulatory category from the blockchain based on the regulatory category of the data request; and encrypts the target message using the regulatory public key to obtain a second encrypted message;

[0120] In one embodiment, the supervisory public key is determined by:

[0121] By using the preset correspondence between the regulatory category and the regulatory public key, the regulatory public key corresponding to the regulatory category of the data request is determined, and the regulatory public key is obtained from the block.

[0122] It should be noted that: in the embodiment of the present application, the target message is encrypted using an elliptic curve encryption algorithm. Since the elliptic curve encryption algorithm is an encryption algorithm in the prior art, the embodiment of the present application will not be described in detail here.

[0123] Step 204: The sending device determines the first temporary public key, the first encrypted message, the identification of the regulatory category, the second encrypted message and the first digital signature as a target data request, and sends the target data request to the blockchain, wherein the first temporary public key is generated using the initial private key of the sending device and the first random number; the first temporary public key can be obtained by formula (2):

[0124]

[0125] in, is the first temporary public key of the sending device i, G is the base of the elliptic curve, and p is the prime number of the elliptic curve.

[0126] Step 205: The receiving device obtains the target data request sent by the sending device on the blockchain;

[0127] The target data request also includes the public key of the recipient device.

[0128] In one embodiment, before executing step 206, the recipient device determines that the public key of the recipient device in the target data request is the same as its own public key.

[0129] In one embodiment, if the recipient device determines that the public key of the recipient device in the target data request is different from its own public key, it does not respond to the target data request.

[0130] Step 206: The receiving device decrypts the first encrypted message using the initial private key of the receiving device to obtain a target message;

[0131] In one embodiment, step 206 may be specifically implemented as follows: inputting the initial private key of the receiving device and the first encrypted message into an elliptic curve decryption algorithm to obtain the target message.

[0132] The elliptic curve decryption algorithm in the embodiment of the present application is an algorithm in the prior art, and the embodiment of the present application will not be described in detail here.

[0133] Step 207: If the receiving device successfully verifies the first digital signature using the first temporary public key, it responds to the data request in the target message;

[0134] like Figure 3 As shown, a flow chart of determining a first digital signature for signature verification may include the following steps:

[0135] Step 301: Input the first digital signature and the first temporary public key into a digital signature algorithm to obtain a signature verification hash value of the target message;

[0136] Step 302: Encrypt the target message using a hash algorithm to obtain an actual hash value of the target message;

[0137] It should be noted that the embodiment of the present application does not limit the execution sequence of step 301 and step 302. Step 301 may be executed first, and then step 302. Step 302 may also be executed first, and then step 301. Step 301 and step 302 may also be executed simultaneously.

[0138] Step 303: Determine whether the signature verification hash value of the target message is the same as the actual hash value of the target message. If they are the same, execute step 304; if they are not the same, execute step 305;

[0139] Step 304: Determine whether the verification of the first digital signature is successful;

[0140] Step 305: Determine that verification of the first digital signature fails.

[0141] In one embodiment, if it is determined that the verification of the first digital signature fails, the process ends.

[0142] In order to further protect the user's privacy data, in one embodiment, before the receiving device responds to the data request in the target message, it is necessary to verify the second digital signature in the target message, such as Figure 4 FIG. 1 is a flow chart of verifying the second digital signature. The following steps may be included:

[0143] Step 401: Obtain the identifier of the sender device in the target message;

[0144] Step 402: Based on the identifier of the sender device, obtain from the blockchain an initial public key of the sender device corresponding to the identifier of the sender device;

[0145] Step 403: Verify the second digital signature in the target message using the initial public key of the sender device;

[0146] In one embodiment, the initial public key and the second digital signature are input into the digital signature algorithm for decryption to obtain the hash value of the data request; the data request in the target message is encrypted using a hash encryption algorithm to obtain an actual hash value of the data request; the actual hash value of the data request is compared with the hash value of the data request obtained after decryption; if the actual hash value of the data request is the same as the hash value of the data request obtained after decryption, it is determined that the second digital signature verification is successful; if the actual hash value of the data request is different from the hash value of the data request obtained after decryption, it is determined that the second digital signature verification has failed.

[0147] Step 404: If the signature verification succeeds, determine to execute the step of responding to the data request in the target message.

[0148] In one embodiment, if the signature verification fails, the process ends.

[0149] Step 208: The supervisory device obtains the target data request sent by the sender device on the blockchain;

[0150] In one embodiment, after executing step 208 and before executing step 209, the identifier of the regulatory category in the target data request is obtained, and if it is determined that the identifier of the regulatory category in the target data request is the same as the identifier of the regulatory device itself, step 209 is executed.

[0151] The supervision device in the embodiment of the present application includes multiple ones, and the supervision devices in the embodiment of the present application are hierarchical. Figure 5 As shown, the main regulator (i.e. Figure 5 The supervisory device with device number 0 in the chain will be classified and grouped according to the type of operation on the chain or the institution to which it belongs. The main supervisor can supervise all records, and the single supervisory agency ( Figure 5 The other supervisory devices except the supervisory device with device number 0 can supervise the needs of all records supervised by the current group and subordinate groups, and the dynamic increase or decrease of supervisory agencies will not affect the needs of on-chain supervision.

[0152] The main supervisor holds the root private key and generates the supervisory public-private key pair of the first-level supervisory device according to business needs. If the first-level supervisory device has other supervisory devices to manage different businesses, the supervisory public-private key pair of the subordinate supervisory device is generated based on the supervisory private key of the first-level supervisory device itself, and so on. In addition, each supervisory device has its own device number OrganID, the supervisory public-private key pair generated by the upper-level supervisory device, and the identification of the supervisory category it is responsible for.

[0153] The regulatory level is determined by regulatory category classification, such as Figure 5For two supervisory devices with OrganIDs 11 and 12, the levels of supervisory devices 11 and 12 are the same, but the identification of the supervisory categories of the two supervisory devices is different. For two supervisory devices in the same supervisory category level but with different identification of the supervisory category, the two supervisory devices belong to the same supervisory level.

[0154] In the same regulatory level, regulatory devices responsible for supervising the same regulatory category hold the same regulatory public-private key, and regulatory devices responsible for supervising different regulatory categories hold different regulatory public-private key pairs. Figure 5 In the first-level supervisor, the supervisory category corresponding to the supervisory device 11 is marked as A, and the supervisory category corresponding to the supervisory device 12 is marked as B. The categories supervised by the two are different, so the supervisory device 11 and the supervisory device 12 hold different supervisory public and private key pairs. Figure 5 In the secondary supervisor, the supervisory categories supervised by supervisory device 111 and supervisory device 112 are both identified as supervisory category A1, so supervisory device 111 and supervisory device 112 hold the same supervisory public and private keys. However, supervisory device 113 has different supervisory categories from supervisory device 111 and supervisory device 112, so supervisory device 113 holds different supervisory public and private keys from supervisory device 111 and supervisory device 112.

[0155] Next, the generation method of the public and private keys of each supervisory device is introduced. The supervisory public key of any supervisory device can be obtained by formula (3):

[0156]

[0157] Among them, P j is the supervisory public key of supervisory device j, T n is the identifier of the regulatory category n corresponding to the regulatory device j, S q is the private key of the supervisory device at the upper level of the supervisory device j, and x2 is the second random number.

[0158] The method for obtaining the first random number and the second random number in the embodiment of the present application is not limited in the embodiment of the present application, but the random number obtained each time in the embodiment of the present application is different from the value of the random number obtained previously.

[0159] The supervisory private key of any supervisory device can be obtained through formula (4):

[0160]

[0161] Among them, S j is the supervisory private key of supervisory device j.

[0162] It should be noted that the supervisory public and private keys of the main supervisor in the embodiment of the present application are pre-set.

[0163] Based on the above method, it is possible to dynamically increase or decrease the supervision equipment on the chain without affecting the supervision process before and after the increase or decrease. Specifically:

[0164] When adding a supervision device, if the supervision category number corresponding to the supervision device already has a corresponding supervision public and private key, there is no need to generate new public and private keys. The public and private keys of the supervision device corresponding to the supervision category number are allocated to the new supervision device.

[0165] When reducing the number of supervision devices, if there are other supervision devices with the same identification as the supervision category supervised by the supervision device, the other supervision devices can continue to track and supervise. If the subsequent supervision security is considered, for example, the supervision device that has been withdrawn cannot decrypt the records of the category range at a later time, the upper-level supervision device will regenerate the public and private keys corresponding to other supervision devices.

[0166] Step 209: The supervisory device decrypts the second encrypted message in the target data request using the supervisory private key of the supervisory device to obtain a target message;

[0167] In one embodiment, step 209 may be specifically implemented as follows: inputting the supervisory private key and the second encrypted message into an elliptic curve decryption algorithm for decryption to obtain the target message.

[0168] Step 210: If the supervisory device successfully verifies the first digital signature in the target data request using the first temporary public key of the sender device in the target data request, then based on the identifier of the sender device in the target message, the supervisory device obtains the initial public key of the sender device corresponding to the identifier of the sender device from the blockchain;

[0169] It should be noted that the method for verifying the first digital signature in step 210 is the same as the method for verifying the first digital signature in step 207. For details, see the method for verifying the first digital signature in step 207 described above. The embodiment of the present application does not elaborate on the method for verifying the first digital signature.

[0170] Step 211: The supervisory device verifies the second digital signature in the target message using the initial public key of the sender device.

[0171] In one embodiment, if the verification of the second digital signature is successful, a subsequent supervisory audit operation is performed; if the verification of the second digital signature fails, an alarm is issued so that the staff can trace the request.

[0172] The method of verifying the second digital signature in the embodiment of the present application is the same as the method of verifying the second digital signature in step 303, and the method of verifying the second digital signature is not repeated in this embodiment of the present application.

[0173] In order to further understand the privacy protection method based on blockchain in the present disclosure, the privacy protection method based on blockchain in the present disclosure is further introduced, such as Figure 6 As shown, it is a flowchart of the privacy protection method based on blockchain in the present disclosure, which may include the following steps:

[0174] Step 601: The sending device receives a data request sent by a user, and signs the hash value of the data request using the initial private key of the sending device to obtain a second digital signature;

[0175] Step 602: The sending device determines the data request, the second digital signature, and the identifier of the sending device as the target message;

[0176] Step 603: The sending device signs the target message using the first temporary private key to obtain the first digital signature;

[0177] Step 604: The sending device encrypts the target message using the initial public key of the receiving device to obtain a first encrypted message;

[0178] Step 605: The sending device obtains a regulatory public key corresponding to the regulatory category from the blockchain based on the regulatory category of the data request; and encrypts the target message using the regulatory public key to obtain a second encrypted message;

[0179] It should be noted that the execution sequence of step 603, step 604 and step 605 in the embodiment of the present application is not limited in the implementation of the present application.

[0180] Step 606: The sending device determines the first temporary public key, the first encrypted message, the first digital signature, the identifier of the regulatory category, and the second encrypted message as a target data request;

[0181] Step 607: The sending device sends the target data request to the blockchain;

[0182] Step 608: The receiving device obtains the target data request sent by the sending device on the blockchain;

[0183] Step 609: The receiving device decrypts the first encrypted message using the initial private key of the receiving device to obtain a target message;

[0184] Step 610: If the receiving device successfully verifies the first digital signature using the first temporary public key, the receiving device verifies the second digital signature in the target message based on the initial public key of the sending device, wherein the initial public key of the sending device is determined based on the identifier of the sending device in the target message;

[0185] Step 611: If the receiving device successfully verifies the second digital signature, it responds to the data request in the target message;

[0186] Step 612: The supervisory device obtains the target data request sent by the sender device on the blockchain;

[0187] It should be noted that the execution sequence of step 608 and step 612 is not limited in this embodiment of the present application.

[0188] Step 613: The supervisory device decrypts the second encrypted message in the target data request using the supervisory private key of the supervisory device to obtain a target message;

[0189] Step 614: If the supervisory device successfully verifies the first digital signature in the target data request using the first temporary public key of the sender device in the target data request, then based on the identifier of the sender device in the target message, the supervisory device obtains the initial public key of the sender device corresponding to the identifier of the sender device from the blockchain;

[0190] Step 615: The supervisory device verifies the second digital signature in the target message using the initial public key of the sender device.

[0191] Based on the same public concept, the privacy protection method based on blockchain described above can also be implemented by a privacy protection device based on blockchain. The effect of the privacy protection device based on blockchain is similar to that of the aforementioned method, and will not be repeated here.

[0192] Figure 7 The figure is a schematic diagram of the structure of a privacy protection device based on blockchain according to an embodiment of the present disclosure.

[0193] like Figure 7 As shown, the blockchain-based privacy protection device 700 of the present disclosure may include a target message determination module 710, a first encryption module 720 and a target data request sending module 730.

[0194] A target message determination module 710 is configured to receive a data request sent by a user and obtain a target message based on the data request;

[0195] A first encryption module 720, configured to sign the target message using a first temporary private key to obtain the first digital signature, and to encrypt the target message using an initial public key of a receiving device to obtain a first encrypted message; wherein the first temporary private key is generated based on the initial private key of the sending device and a first random number;

[0196] The target data request sending module 730 is used to determine the first temporary public key, the first encrypted message and the first digital signature as the target data request, and send the target data request to the blockchain, so that the receiving device can successfully verify the first digital signature based on the first temporary public key in the target data request obtained from the blockchain, and then respond to the data request obtained by decrypting the first encrypted message using the initial private key of the receiving device, wherein the first temporary public key is generated using the initial private key of the sending device and the first random number.

[0197] In one embodiment, the apparatus further comprises:

[0198] The first temporary private key determination module 740 is configured to obtain the first temporary private key by using the following formula:

[0199]

[0200] in, is the first temporary private key of the sending device i, D i is the identifier of the sending device i, is the initial private key of the sender device i, and x1 is the first random number;

[0201] The first temporary public key determination module 750 is configured to obtain the first temporary public key by using the following formula:

[0202]

[0203] in, is the first temporary public key of the sending device i, G is the base of the elliptic curve, and p is the prime number of the elliptic curve.

[0204] In one embodiment, the target message determination module 710 is specifically configured to:

[0205] Signing the hash value of the data request using the initial private key of the sender device to obtain a second digital signature; determining the data request, the second digital signature, and the identifier of the sender device as the target message, wherein the hash value of the data request is obtained by encrypting the data request using a hash algorithm;

[0206] Among them, the identification of the sending device is used to instruct the receiving device to obtain the initial public key of the sending device corresponding to the identification of the sending device from the blockchain after decrypting the first encrypted message, and the second digital signature is used to instruct the receiving device to use the initial public key to verify the second digital signature.

[0207] In one embodiment, the apparatus further comprises:

[0208] A second encryption module 750 is configured to obtain, based on the data request, a target message and, based on the regulatory category of the data request, obtain a regulatory public key corresponding to the regulatory category from the blockchain; and encrypt the target message using the regulatory public key to obtain a second encrypted message;

[0209] The target data request sending module 730 is specifically used for:

[0210] adding an identification of the regulatory category and the second encrypted message to the target data request;

[0211] Among them, the identifier of the regulatory category is used to indicate the target regulatory device for obtaining the target data request, and the second encrypted message is used to instruct the target regulatory device to use the regulatory private key of the target regulatory device to decrypt the second encrypted message in the target data request to obtain the target message, and based on the identifier of the sender device in the target message, obtain the initial public key of the sender device corresponding to the identifier of the sender device from the blockchain, and use the initial public key to verify the second digital signature.

[0212] Based on the same inventive concept, this application also provides a structural diagram of another privacy protection device based on blockchain. Figure 8 The figure is a schematic diagram of the structure of a privacy protection device based on blockchain according to an embodiment of the present disclosure.

[0213] like Figure 8 As shown, the blockchain-based privacy protection device 800 of the present disclosure may include a first target data request acquisition module 810, a first decryption module 820 and a first signature verification module 830.

[0214] A first target data request acquisition module 810 is used to acquire a target data request sent by a sending device on a blockchain, wherein the target data request includes a first temporary public key of the sending device, a first encrypted message, and a first digital signature, wherein the first encrypted message is encrypted using a first temporary private key of the sending device, and the first temporary private key is generated based on an initial private key of the sending device and a first random number; and the first temporary public key is obtained by the sending device based on its own initial private key and the first random number, and the first digital signature is generated by the sending device based on the first temporary private key of the sending device;

[0215] A first decryption module 820, configured to decrypt the first encrypted message using the initial private key of the receiving device to obtain a target message;

[0216] The first signature verification module 830 is configured to respond to a data request in the target message if the first digital signature is successfully verified using the first temporary public key.

[0217] In one embodiment, the apparatus further comprises:

[0218] A second signature verification module 840 is configured to obtain an identifier of a sender device in the target message before responding to the data request in the target message;

[0219] Based on the identifier of the sender device, obtaining from the blockchain an initial public key of the sender device corresponding to the identifier of the sender device;

[0220] Verifying the second digital signature in the target message using the initial public key of the sender device;

[0221] If the signature verification is successful, a step of responding to the data request in the target message is determined.

[0222] Based on the same inventive concept, this application also provides a structural diagram of another privacy protection device based on blockchain. Fig. 9 The figure is a schematic diagram of the structure of a privacy protection device based on blockchain according to an embodiment of the present disclosure.

[0223] like Fig. 9 As shown, the blockchain-based privacy protection device 900 of the present disclosure may include a second target data request acquisition module 910, a second decryption module 920, a third signature verification module 930 and a fourth signature verification module 940.

[0224] A second target data request acquisition module 910 is used to acquire a target data request sent by a sending device on a blockchain, wherein the target data request includes a first temporary public key and a first digital signature of the sending device, and the first digital signature is generated by the sending device based on a first temporary private key of the sending device, the first temporary private key is generated based on an initial private key of the sending device and a first random number, and the first temporary public key is obtained by the sending device based on its own initial private key and the generated first random number;

[0225] A second decryption module 920, configured to decrypt the second encrypted message in the target data request using the supervision private key of the supervision device to obtain a target message;

[0226] A third signature verification module 930 is configured to obtain, from the blockchain, an initial public key of the sender device corresponding to the identifier of the sender device based on the identifier of the sender device in the target message, if the first temporary public key of the sender device in the target data request is used to successfully verify the first digital signature in the target data request;

[0227] The fourth signature verification module 940 is used to verify the second digital signature in the target message using the initial public key of the sending device.

[0228] After introducing a privacy protection method and apparatus based on blockchain according to an exemplary embodiment of the present disclosure, next, an electronic device according to another exemplary embodiment of the present disclosure is introduced.

[0229] Those skilled in the art will appreciate that various aspects of the present disclosure may be implemented as systems, methods or program products. Therefore, various aspects of the present disclosure may be specifically implemented in the following forms, namely: complete hardware implementation, complete software implementation (including firmware, microcode, etc.), or a combination of hardware and software, which may be collectively referred to herein as "circuits", "modules" or "systems".

[0230] In some possible implementations, the electronic device according to the present disclosure may include at least one processor and at least one computer storage medium. The computer storage medium stores program code, and when the program code is executed by the processor, the processor executes the steps of the privacy protection method based on blockchain according to various exemplary embodiments of the present disclosure described above in this specification. For example, the processor may execute the following steps: Figure 2 Steps 201-211 shown in .

[0231] Refer to the following Fig.10 The electronic device 1000 according to this embodiment of the present disclosure is described. Fig.10 The electronic device 1000 shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.

[0232] like Fig.10 As shown, the electronic device 1000 is in the form of a general electronic device. The components of the electronic device 1000 may include but are not limited to: the at least one processor 1001, the at least one computer storage medium 1002, and a bus 1003 connecting different system components (including the computer storage medium 1002 and the processor 1001).

[0233] Bus 1003 represents one or more of several types of bus structures, including a computer storage media bus or computer storage media controller, a peripheral bus, a processor, or a local bus using any of a variety of bus architectures.

[0234] The computer storage medium 1002 may include readable media in the form of volatile computer storage media, such as random access computer storage media (RAM) 1021 and / or cache storage media 1022 , and may further include read-only computer storage media (ROM) 1023 .

[0235] The computer storage medium 1002 may also include a program / utility 1025 having a set (at least one) of program modules 1024, such program modules 1024 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.

[0236] The electronic device 1000 may also communicate with one or more external devices 1004 (e.g., keyboards, pointing devices, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 1000, and / or communicate with any device that enables the electronic device 1000 to communicate with one or more other electronic devices (e.g., routers, modems, etc.). Such communication may be performed via an input / output (I / O) interface 1005. Furthermore, the electronic device 1000 may also communicate with one or more networks (e.g., local area networks (LANs), wide area networks (WANs), and / or public networks, such as the Internet) via a network adapter 1006. As shown, the network adapter 1006 communicates with other modules for the electronic device 1000 via a bus 1003. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 1000, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0237] In some possible implementations, various aspects of a privacy protection method based on blockchain provided by the present disclosure may also be implemented in the form of a program product, which includes a program code. When the program product is run on a computer device, the program code is used to enable the computer device to execute the steps of the privacy protection method based on blockchain according to various exemplary embodiments of the present disclosure described above in this specification.

[0238] The program product may use any combination of one or more readable media. The readable medium may be a readable signal medium or a readable storage medium. The readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of readable storage media (a non-exhaustive list) include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access computer storage medium (RAM), a read-only computer storage medium (ROM), an erasable programmable read-only computer storage medium (EPROM or flash memory), an optical fiber, a portable compact disk read-only computer storage medium (CD-ROM), an optical computer storage medium, a magnetic computer storage medium, or any suitable combination of the above.

[0239] The program product based on blockchain privacy protection of the embodiment of the present disclosure can adopt a portable compact disk read-only computer storage medium (CD-ROM) and include program code, and can be run on an electronic device. However, the program product of the present disclosure is not limited to this. In this document, the readable storage medium can be any tangible medium containing or storing a program, which can be used by or in combination with an instruction execution system, device or device.

[0240] The readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, wherein the readable program code is carried. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The readable signal medium may also be any readable medium other than a readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0241] The program code embodied on the readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination of the foregoing.

[0242] Program code for performing the disclosed operations may be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java, C++, etc., and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user electronic device, partially on the user device, as a separate software package, partially on the user electronic device and partially on a remote electronic device, or entirely on a remote electronic device or server. In the case of a remote electronic device, the remote electronic device may be connected to the user electronic device via any type of network including a local area network (LAN) or a wide area network (WAN), or may be connected to an external electronic device (e.g., via the Internet using an Internet service provider).

[0243] It should be noted that although several modules of the device are mentioned in the above detailed description, this division is merely exemplary and not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more modules described above can be embodied in one module. Conversely, the features and functions of one module described above can be further divided into multiple modules to be embodied.

[0244] In addition, although the operations of the disclosed method are described in a specific order in the drawings, this does not require or imply that the operations must be performed in this specific order, or that all the operations shown must be performed to achieve the desired results. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step, and / or one step may be decomposed into multiple steps.

[0245] Those skilled in the art will appreciate that the embodiments of the present disclosure may be provided as methods, systems, or computer program products. Therefore, the present disclosure may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present disclosure may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk computer storage media, CD-ROM, optical computer storage media, etc.) containing computer-usable program codes.

[0246] The present disclosure is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the present disclosure. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0247] These computer program instructions may also be stored in a computer-readable computer storage medium that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable computer storage medium produce a manufactured product including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0248] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0249] Obviously, those skilled in the art can make various changes and modifications to the present disclosure without departing from the spirit and scope of the present disclosure. Thus, if these modifications and variations of the present disclosure fall within the scope of the claims of the present disclosure and their equivalents, the present disclosure is also intended to include these modifications and variations.

Claims

1. A privacy protection method based on blockchain, characterized in that: Applied in a sending device, the method includes: receiving a data request sent by a user, and obtaining a target message based on the data request; Signing the target message using a first temporary private key to obtain the first digital signature, and encrypting the target message using an initial public key of a receiving device to obtain a first encrypted message; wherein the first temporary private key is generated based on the initial private key of the sending device and a first random number; The first temporary public key, the first encrypted message and the first digital signature are determined as a target data request, and the target data request is sent to the blockchain, so that after the receiving device successfully verifies the first digital signature based on the first temporary public key in the target data request obtained from the blockchain, it responds to the data request obtained by decrypting the first encrypted message using the initial private key of the receiving device, wherein the first temporary public key is generated using the initial private key of the sending device and the first random number.

2. The method according to claim 1, characterized in that The first temporary private key is obtained by the following formula: in, is the first temporary private key of the sending device i, D i is the identifier of the sending device i, is the initial private key of the sender device i, and x1 is the first random number; The first temporary public key is obtained by the following formula: in, is the first temporary public key of the sending device i, G is the base of the elliptic curve, and p is the prime number of the elliptic curve.

3. The method according to claim 1, characterized in that The obtaining of a target message based on the data request includes: Signing the hash value of the data request using the initial private key of the sender device to obtain a second digital signature; determining the data request, the second digital signature, and the identifier of the sender device as the target message, wherein the hash value of the data request is obtained by encrypting the data request using a hash algorithm; Among them, the identification of the sending device is used to instruct the receiving device to obtain the initial public key of the sending device corresponding to the identification of the sending device from the blockchain after decrypting the first encrypted message, and the second digital signature is used to instruct the receiving device to use the initial public key to verify the second digital signature.

4. The method according to claim 3, characterized in that After obtaining the target message based on the data request, the method further includes: Based on the regulatory category of the data request, obtaining a regulatory public key corresponding to the regulatory category from the blockchain; encrypting the target message using the regulatory public key to obtain a second encrypted message; After determining the first temporary public key, the first encrypted message, and the first digital signature as the target data request, the method further includes: adding an identification of the regulatory category and the second encrypted message to the target data request; Among them, the identifier of the regulatory category is used to indicate the target regulatory device that needs to decrypt the second encrypted message, and the second encrypted message is used to instruct the target regulatory device to use the regulatory private key of the target regulatory device to decrypt the second encrypted message in the target data request to obtain the target message, and based on the identifier of the sender device in the target message, obtain the initial public key of the sender device corresponding to the identifier of the sender device from the blockchain, and use the initial public key to verify the second digital signature.

5. A privacy protection method based on blockchain, characterized in that: Applied in a receiving device, the method includes: Obtaining a target data request sent by a sending device on a blockchain, wherein the target data request includes a first temporary public key of the sending device, a first encrypted message, and a first digital signature, wherein the first encrypted message is encrypted using a first temporary private key of the sending device, and the first temporary private key is generated based on an initial private key of the sending device and a first random number; and the first temporary public key is obtained by the sending device based on its own initial private key and the first random number, and the first digital signature is generated by the sending device based on the first temporary private key of the sending device; Decrypting the first encrypted message using the initial private key of the receiving device to obtain a target message; If the first digital signature is successfully verified using the first temporary public key, the data request in the target message is responded to.

6. The method according to claim 5, characterized in that Before responding to the data request in the target message, the method further includes: Obtaining an identifier of a sender device in the target message; Based on the identifier of the sender device, obtaining from the blockchain an initial public key of the sender device corresponding to the identifier of the sender device; Verifying the second digital signature in the target message using the initial public key of the sender device; If the signature verification is successful, a step of responding to the data request in the target message is determined.

7. A privacy protection method based on blockchain, characterized in that: Applied to a monitoring device, the method comprises: Obtaining a target data request sent by a sending device on a blockchain, wherein the target data request includes a first temporary public key and a first digital signature of the sending device, and the first digital signature is generated by the sending device based on a first temporary private key of the sending device, the first temporary private key is generated based on an initial private key of the sending device and a first random number, and the first temporary public key is obtained by the sending device based on its own initial private key and the generated first random number; Decrypting the second encrypted message in the target data request using the supervision private key of the supervision device to obtain a target message; If the first digital signature in the target data request is successfully verified using the first temporary public key of the sender device in the target data request, then based on the identifier of the sender device in the target message, obtaining from the blockchain an initial public key of the sender device corresponding to the identifier of the sender device; The second digital signature in the target message is verified using the initial public key of the sender device.

8. A sending device, characterized in that: comprising a processor and a memory, wherein the processor and the memory are connected via a bus; The memory stores a computer program, and the processor is configured to perform the following operations based on the computer program: receiving a data request sent by a user, and obtaining a target message based on the data request; Signing the target message using a first temporary private key to obtain the first digital signature, and encrypting the target message using an initial public key of a receiving device to obtain a first encrypted message; wherein the first temporary private key is generated based on the initial private key of the sending device and a first random number; The first temporary public key, the first encrypted message and the first digital signature are determined as a target data request, and the target data request is sent to the blockchain, so that after the receiving device successfully verifies the first digital signature based on the first temporary public key in the target data request obtained from the blockchain, it responds to the data request obtained by decrypting the first encrypted message using the initial private key of the receiving device, wherein the first temporary public key is generated using the initial private key of the sending device and the first random number.

9. A receiving device, characterized in that: comprising a processor and a memory, wherein the processor and the memory are connected via a bus; The memory stores a computer program, and the processor is configured to perform the following operations based on the computer program: Obtaining a target data request sent by a sending device on a blockchain, wherein the target data request includes a first temporary public key of the sending device, a first encrypted message, and a first digital signature, wherein the first encrypted message is encrypted using a first temporary private key of the sending device, and the first temporary private key is generated based on an initial private key of the sending device and a first random number; and the first temporary public key is obtained by the sending device based on its own initial private key and the first random number, and the first digital signature is generated by the sending device based on the first temporary private key of the sending device; Decrypting the first encrypted message using the initial private key of the receiving device to obtain a target message; If the first digital signature is successfully verified using the first temporary public key, the data request in the target message is responded to.

10. A monitoring device, characterized in that: comprising a processor and a memory, wherein the processor and the memory are connected via a bus; The memory stores a computer program, and the processor is configured to perform the following operations based on the computer program: Obtaining a target data request sent by a sending device on a blockchain, wherein the target data request includes a first temporary public key and a first digital signature of the sending device, and the first digital signature is generated by the sending device based on a first temporary private key of the sending device, the first temporary private key is generated based on an initial private key of the sending device and a first random number, and the first temporary public key is obtained by the sending device based on its own initial private key and the generated first random number; Decrypting the second encrypted message in the target data request using the supervision private key of the supervision device to obtain a target message; If the first digital signature in the target data request is successfully verified using the first temporary public key of the sender device in the target data request, then based on the identifier of the sender device in the target message, obtaining from the blockchain an initial public key of the sender device corresponding to the identifier of the sender device; The second digital signature in the target message is verified using the initial public key of the sender device.