Distributed account book encryption method and system
By using white box encryption technology in the alliance chain to encrypt and decrypt the block data, the risk of leakage of alliance chain ledger data in public cloud storage is solved, and security is improved and costs are reduced.
Patent Information
- Application Number
- CN202411939475.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-26
- Publication Date
- 2025-05-23
AI Technical Summary
There is a risk of data leakage in the alliance chain ledger data in public cloud storage, which may result in data leakage due to network and system security vulnerabilities or improper personnel operations.
The white box encryption technology is used to encrypt and decrypt the block data of the alliance chain. By generating the encrypted white box and the decrypted white box, the block data is serialized, encrypted and decrypted, ensuring the security of the data during storage and transmission.
Through white box encryption technology, effective encryption and decryption of alliance chain ledger data is achieved, which reduces the risk of data leakage, improves the security of alliance chain, and reduces the need for hardware devices to store encryption keys, reducing costs and management complexity.
Smart Images

Figure CN120030563A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of encryption technology, and more specifically, to a distributed ledger encryption method and system. Background Art
[0002] A consortium chain is a blockchain with authorized access. Ledger data and status data are only legally accessible to authorized blockchain users. However, most of the distributed ledgers of consortium chains are stored on public cloud storage devices, which poses a risk of data leakage. Even if the ledger is stored on a disk of a physical server in a highly secure "intranet", data may be illegally stolen due to network and system security vulnerabilities, improper human operation, and other reasons, resulting in ledger data leakage. Summary of the invention
[0003] According to the present invention, a distributed ledger encryption method and system are provided to solve the technical problem of illegal theft of alliance chain ledger data, resulting in ledger data leakage.
[0004] According to a first aspect of the present invention, there is provided a distributed ledger encryption method, comprising:
[0005] Check whether the white box is initialized. If not, initialize the white box, generate encryption white box and decryption white box, encode the white box and write it into the file. If it is initialized, read the encryption white box and decryption white box from the file to the service.
[0006] Receive and parse the request command, and call the block storage module to query the block data;
[0007] When the request command is to write block data, the block data is serialized into a byte array, the encryption white box is called to encrypt the serialized block data to generate block ciphertext data, and the block ciphertext data is written into a file;
[0008] When the request command is to read out the block data, the block ciphertext storage location is found through the index and the block ciphertext data is read out, and the decryption white box is called to decrypt the block ciphertext data to obtain the block plaintext information.
[0009] Optionally, initializing the white box and generating the encryption white box and the decryption white box includes:
[0010] Generate a 16-byte SM4 key;
[0011] Generate an encryption white box, randomly insert 5N redundant rounds according to the SM4 key, generate round keys according to the standard SM4 cryptographic algorithm, construct an encryption white box according to the round key lookup table and save it in encoding;
[0012] Generate a decryption white box and SM4 key, randomly insert 5N redundant rounds, generate round keys according to the standard SM4 cryptographic algorithm, construct a decryption white box according to the round key lookup table and save it in encoding.
[0013] Optionally, receiving and parsing the request command, and calling the block storage module to query the block data, includes:
[0014] Receive request commands through the storage service GRPC interface module;
[0015] Parsing the request command to determine whether the request command is to write block data or read block data;
[0016] Call the block storage module to query block data by block number or transaction ID.
[0017] Optionally, when the request command is to write block data, the block data is serialized into a byte array, the serialized block data is encrypted based on the encryption white box to generate block ciphertext data, and the block ciphertext data is written into a file, including:
[0018] When the request command is to write block data, the block storage module calls the file storage module interface according to the block storage configuration. If file storage is configured, the file storage module interface is called; if DB storage is configured, the DB storage module interface is called;
[0019] Processing the block data through the file storage module and the DB storage module, and serializing the block data into a byte array;
[0020] Call the encryption white box to encrypt the serialized block data to generate block ciphertext data;
[0021] The file storage module writes the block ciphertext data into a file, and the DB storage module writes the block ciphertext data into a database. At the same time, the storage module records the storage location of the block ciphertext data through an index.
[0022] Optionally, when the request command is to read out the block data, the block ciphertext storage location is searched through the index and the block ciphertext data is read out, and the decryption white box is called to decrypt the block ciphertext data to obtain the block plaintext information, including:
[0023] When the request command is to read out block data, the block storage module calls the file storage module or the DB storage module according to the block storage configuration to find the block ciphertext storage location through the index and read out the block ciphertext data;
[0024] The file storage module or the DB storage module obtains the block plaintext information by calling the decryption white box to decrypt the block ciphertext data.
[0025] According to another aspect of the present invention, a distributed ledger encryption system is provided, comprising:
[0026] Initialize the white box module, which is used to detect whether the white box is initialized. If not, initialize the white box, generate encryption white box and decryption white box, and write the white box encoding into the file. If it is initialized, read the encryption white box and decryption white box from the file into the service.
[0027] Get request command module, used to receive and parse request commands, and call block storage module to query block data;
[0028] The block data writing module is used to write the block data. When the request command is to write the block data, the block data is serialized into a byte array, the encryption white box is called to encrypt the serialized block data to generate block ciphertext data, and the block ciphertext data is written into the file;
[0029] The block data reading module is used to find the block ciphertext storage location through the index and read the block ciphertext data when the request command is to read the block data, and call the decryption white box to decrypt the block ciphertext data to obtain the block plaintext information.
[0030] Optionally, initialize the white box module, including:
[0031] Generate SM4 key submodule, used to generate a 16-byte SM4 key;
[0032] Generate an encryption white box module, which is used to generate an encryption white box, randomly insert 5N redundant rounds according to the SM4 key, generate round keys according to the standard SM4 cryptographic algorithm, construct an encryption white box according to the round key lookup table and save it in encoding;
[0033] Generate a decryption white box module, which is used to generate a decryption white box, SM4 key, randomly insert 5N redundant rounds, generate round keys according to the standard SM4 cryptographic algorithm, construct a decryption white box according to the round key lookup table and save it in encoding.
[0034] Optionally, the acquisition request command module includes:
[0035] The request command receiving submodule is used to receive the request command through the storage service GRPC interface module;
[0036] A request command parsing submodule, used to parse the request command and determine whether the request command is to write block data or read block data;
[0037] The block data query submodule is used to call the block storage module to query block data according to the block number or transaction ID.
[0038] Optionally, write a block data module, including:
[0039] The calling interface submodule is used for calling the file storage module interface according to the block storage configuration when the request command is to write block data, if the configuration is file storage, the DB storage module interface is called if the configuration is DB storage;
[0040] The block data serialization submodule is used to process the block data through the file storage module and the DB storage module, and serialize the block data into a byte array;
[0041] The block ciphertext data generation submodule is used to call the encryption white box to encrypt the serialized block data to generate block ciphertext data;
[0042] The submodule for recording block ciphertext data is used for the file storage module to write the block ciphertext data into the file, and the DB storage module to write the block ciphertext data into the database. At the same time, the storage module records the storage location of the block ciphertext data through the index.
[0043] Optionally, the block data module is read, including:
[0044] The block ciphertext data reading submodule is used for, when the request command is to read the block data, the block storage module calls the file storage module or the DB storage module according to the block storage configuration to find the block ciphertext storage location through the index and read the block ciphertext data;
[0045] The submodule for obtaining block plaintext information is used by the file storage module or the DB storage module to obtain block plaintext information by calling the decryption white box to decrypt the block ciphertext data.
[0046] Therefore, the ledger encryption implemented by white box encryption technology does not require hardware devices to store encryption keys, which reduces costs and management complexity, while improving the security of the alliance chain, which helps promote the wider application of the alliance chain. It solves the problem of illegal theft of alliance chain ledger data leading to ledger leakage and protects the security of ledger data. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] A more complete understanding of exemplary embodiments of the present invention may be obtained by referring to the following drawings:
[0048] Figure 1 This is a schematic diagram of a process of a distributed ledger encryption method described in this embodiment;
[0049] Figure 2 This is a functional architecture diagram of a distributed ledger encryption method described in this embodiment;
[0050] Figure 3 This is a schematic diagram of a distributed ledger encryption method described in this embodiment;
[0051] Figure 4 A schematic diagram of the white box initialization generation process described in this embodiment;
[0052] Figure 5 This is a schematic diagram of a distributed ledger encryption system described in this embodiment. DETAILED DESCRIPTION
[0053] Now, exemplary embodiments of the present invention are described with reference to the accompanying drawings. However, the present invention can be implemented in many different forms and is not limited to the embodiments described herein. These embodiments are provided to disclose the present invention in detail and completely and to fully convey the scope of the present invention to those skilled in the art. The terms used in the exemplary embodiments shown in the accompanying drawings are not intended to limit the present invention. In the accompanying drawings, the same units / elements are marked with the same reference numerals.
[0054] Unless otherwise specified, the terms (including technical terms) used herein have the commonly understood meanings to those skilled in the art. In addition, it is understood that the terms defined in commonly used dictionaries should be understood to have the same meanings as those in the context of the relevant fields, and should not be understood as idealized or overly formal meanings.
[0055] According to a first aspect of the present invention, a distributed ledger encryption method 100 is provided, referring to Figure 1 As shown, the method 100 includes:
[0056] S101: Check whether the white box is initialized. If not, initialize the white box, generate an encryption white box and a decryption white box, encode the white boxes and write them into a file. If initialized, read the encryption white box and the decryption white box from the file and put them into the service.
[0057] S102: receiving and parsing the request command, and calling the block storage module to query the block data;
[0058] S103: When the request command is to write block data, the block data is serialized into a byte array, the encryption white box is called to encrypt the serialized block data to generate block ciphertext data, and the block ciphertext data is written into a file;
[0059] S104: When the request command is to read out the block data, the block ciphertext storage location is searched through the index and the block ciphertext data is read out, and the decryption white box is called to decrypt the block ciphertext data to obtain the block plaintext information.
[0060] Specifically, refer to Figure 2As shown, the present invention is mainly implemented based on the Sinochain autonomous and controllable blockchain platform, which includes five service modules, namely access service, consensus service, execution service, storage service, and P2P network service. The access service verifies the user's identity and authority, the consensus service packages transactions, executes blockchain consensus, generates blocks, the execution service executes transactions, the storage service stores blockchain ledger data, and the P2P network service broadcasts transactions and blocks, and synchronizes the ledger data of each blockchain node.
[0061] The storage service includes GRPC command interface module, block storage module, white box encryption module, file storage module, and DB storage module. The GRPC command interface module receives block query and write commands for services such as access and consensus. The block storage service provides block query and block write functions such as query by block number and query by transaction ID. The white box encryption module implements the software implementation module of the white box cryptographic algorithm and provides white box initialization, white box encryption, and white box decryption functions. The file storage module provides related functions for storing ledger data based on files. The DB storage module implements related functions for storing ledger data based on an embedded key-value database.
[0062] refer to Figure 3 As shown, the process of ciphertext storage of ledger data based on white box encryption is as follows:
[0063] 1. The storage service detects whether the white box is initialized. If it is not initialized, it means that the storage service is started for the first time. Initialization generates a white box, generates an encryption white box and a decryption white box, and writes the encoded white boxes into a file. If it is initialized, the encryption white box and the decryption white box are read from the file into the service.
[0064] 2. The storage service GRPC interface module receives the command and calls the block storage module;
[0065] 3. When writing a block, the block storage module calls the file storage module interface according to the block storage configuration. If file storage is configured, the file storage module interface is called. If DB storage is configured, the DB storage module interface is called.
[0066] 4. The file storage module and DB storage module process block data and serialize block information into byte arrays;
[0067] 5. The white box encryption module encrypts the serialized block data to generate block ciphertext data;
[0068] 6. The file storage module writes the block ciphertext data into the file, and the DB storage module writes the block ciphertext data into the database. At the same time, the storage module records the block ciphertext storage location through the index;
[0069] 7. When the block is read out, the block storage module calls the file storage module or the DB storage module according to the block storage configuration to find the block ciphertext storage location through the index and read out the block ciphertext data;
[0070] 8. The file storage module or DB storage module obtains the block plaintext information by calling the white box decryption module to decrypt the block ciphertext data.
[0071] The entire process of encryption and decryption of the ledger block data is implemented in the storage service inside the node, which is transparent to the blockchain users. The user submits the transaction, the transaction is executed inside the node, and the block is generated by reaching a consensus. The block encryption and writing into the ledger does not require user participation and is automatically implemented. When the user reads the block data in the ledger, the storage service inside the node automatically decrypts it and returns the block plaintext data to the user, thus realizing transparent ledger encryption and decryption for the user.
[0072] The white-box encryption module uses the domestic cryptographic algorithm SM4 to implement white-box encryption and decryption to ensure the security and compliance of the algorithm.
[0073] The SM4 algorithm is a block algorithm with a block length of 128 bits and a key length of 128 bits. Both the encryption algorithm and the key expansion algorithm use a 32-round nonlinear iterative structure. The decryption process has the same structure as the encryption process, except that the order of use of the round keys is reversed. The round keys of the decryption algorithm are the reverse order of the round keys of the encryption algorithm.
[0074] In the SM4 algorithm, the output of each round is determined by the results of the previous four rounds. Redundant rounds are invalid rounds, that is, whether or not a redundant round is added does not affect the output of the encryption algorithm. Therefore, the input of the entire redundant round is the output of the last four rounds. Therefore, in the SM4 algorithm, at least four rounds must be inserted at one time to achieve that the overall input is equal to the output of the last four rounds.
[0075] The white box used in the present invention inserts 5N redundant rounds into the 32 regular rounds of SM4, where N is greater than or equal to 1. According to the redundant round T function, the round key is generated by the standard SM4 cryptographic algorithm, and a lookup table is constructed according to the round key. The T function is an affine transformation, and the lookup table is the coded data obtained by encrypting the SM4 white box by generating the white box ciphertext.
[0076] The white box encryption and decryption keys used in the present invention are files encoded with all round keys including redundant rounds to protect the original SM4 key. At the same time, redundant rounds are added to confuse the operation process, making it more difficult to crack the SM4 key from the memory during a white box attack.
[0077] refer to Figure 4 As shown, the initialization generation process of the white box in the storage service is as follows:
[0078] 1. Generate a 16-byte SM4 key;
[0079] 2. Generate an encryption white box. According to the SM4 key, randomly insert 5N redundant rounds, generate round keys according to the standard SM4 cryptographic algorithm, construct an encryption white box according to the round key lookup table and save it in encoding;
[0080] 3. Generate a decryption white box and SM4 key, randomly insert 5N redundant rounds, generate round keys according to the standard SM4 cryptographic algorithm, construct a decryption white box according to the round key lookup table and save it in encoding.
[0082] Therefore, white-box encryption technology is applied to the protection of the ledger data of the alliance chain, and the ciphertext storage of the ledger data is realized. Through white-box encryption technology, there is no need for hardware devices to store encryption keys, which ensures security while reducing costs. The access to the ciphertext storage of ledger data is transparent to authorized users, and blockchain users do not need to perform encryption and decryption operations. The blockchain node automatically realizes the encryption writing and decryption reading of the ledger data. The white-box encryption algorithm of the SM4 domestic cryptographic algorithm is realized, which has higher security and compliance.
[0083] Optionally, initializing the white box and generating the encryption white box and the decryption white box includes:
[0084] Generate a 16-byte SM4 key;
[0085] Generate an encryption white box, randomly insert 5N redundant rounds according to the SM4 key, generate round keys according to the standard SM4 cryptographic algorithm, construct an encryption white box according to the round key lookup table and save it in encoding;
[0086] Generate a decryption white box and SM4 key, randomly insert 5N redundant rounds, generate round keys according to the standard SM4 cryptographic algorithm, construct a decryption white box according to the round key lookup table and save it in encoding.
[0087] Optionally, receiving and parsing the request command, and calling the block storage module to query the block data, includes:
[0088] Receive request commands through the storage service GRPC interface module;
[0089] Parsing the request command to determine whether the request command is to write block data or read block data;
[0090] Call the block storage module to query block data by block number or transaction ID.
[0091] Optionally, when the request command is to write block data, the block data is serialized into a byte array, the serialized block data is encrypted based on the encryption white box to generate block ciphertext data, and the block ciphertext data is written into a file, including:
[0092] When the request command is to write block data, the block storage module calls the file storage module interface according to the block storage configuration. If file storage is configured, the file storage module interface is called; if DB storage is configured, the DB storage module interface is called;
[0093] Processing the block data through the file storage module and the DB storage module, and serializing the block data into a byte array;
[0094] Call the encryption white box to encrypt the serialized block data to generate block ciphertext data;
[0095] The file storage module writes the block ciphertext data into a file, and the DB storage module writes the block ciphertext data into a database. At the same time, the storage module records the storage location of the block ciphertext data through an index.
[0096] Optionally, when the request command is to read out the block data, the block ciphertext storage location is searched through the index and the block ciphertext data is read out, and the decryption white box is called to decrypt the block ciphertext data to obtain the block plaintext information, including:
[0097] When the request command is to read out block data, the block storage module calls the file storage module or the DB storage module according to the block storage configuration to find the block ciphertext storage location through the index and read out the block ciphertext data;
[0098] The file storage module or the DB storage module obtains the block plaintext information by calling the decryption white box to decrypt the block ciphertext data.
[0099] Therefore, the ledger encryption implemented by white box encryption technology does not require hardware devices to store encryption keys, which reduces costs and management complexity, while improving the security of the alliance chain, which helps promote the wider application of the alliance chain. It solves the problem of illegal theft of alliance chain ledger data leading to ledger leakage and protects the security of ledger data.
[0100] According to another aspect of the present invention, a distributed ledger encryption system 500 is provided. Figure 5 As shown, the system 500 includes:
[0101] Initialization white box module 510, used to detect whether the white box is initialized, if not initialized, initialize the white box, generate encryption white box and decryption white box and write the white box encoding into the file, if initialized, read the encryption white box and decryption white box from the file into the service;
[0102] The request command acquisition module 520 is used to receive and parse the request command and call the block storage module to query the block data;
[0103] The block data writing module 530 is used to write, when the request command is to write block data, serialize the block data into a byte array, call the encryption white box to encrypt the serialized block data to generate block ciphertext data, and write the block ciphertext data into a file;
[0104] The block data reading module 540 is used to find the block ciphertext storage location through the index and read the block ciphertext data when the request command is to read the block data, and call the decryption white box to decrypt the block ciphertext data to obtain the block plaintext information.
[0105] Optionally, initialize the white box module, including:
[0106] Generate SM4 key submodule, used to generate a 16-byte SM4 key;
[0107] Generate an encryption white box module, which is used to generate an encryption white box, randomly insert 5N redundant rounds according to the SM4 key, generate round keys according to the standard SM4 cryptographic algorithm, construct an encryption white box according to the round key lookup table and save it in encoding;
[0108] Generate a decryption white box module, which is used to generate a decryption white box, SM4 key, randomly insert 5N redundant rounds, generate round keys according to the standard SM4 cryptographic algorithm, construct a decryption white box according to the round key lookup table and save it in encoding.
[0109] Optionally, the acquisition request command module includes:
[0110] The request command receiving submodule is used to receive the request command through the storage service GRPC interface module;
[0111] A request command parsing submodule, used to parse the request command and determine whether the request command is to write block data or read block data;
[0112] The block data query submodule is used to call the block storage module to query block data according to the block number or transaction ID.
[0113] Optionally, write a block data module, including:
[0114] The calling interface submodule is used for calling the file storage module interface according to the block storage configuration when the request command is to write block data, if the configuration is file storage, the DB storage module interface is called if the configuration is DB storage;
[0115] The block data serialization submodule is used to process the block data through the file storage module and the DB storage module, and serialize the block data into a byte array;
[0116] The block ciphertext data generation submodule is used to call the encryption white box to encrypt the serialized block data to generate block ciphertext data;
[0117] The submodule for recording block ciphertext data is used for the file storage module to write the block ciphertext data into the file, and the DB storage module to write the block ciphertext data into the database. At the same time, the storage module records the storage location of the block ciphertext data through the index.
[0118] Optionally, the block data module is read, including:
[0119] The block ciphertext data reading submodule is used for, when the request command is to read the block data, the block storage module calls the file storage module or the DB storage module according to the block storage configuration to find the block ciphertext storage location through the index and read the block ciphertext data;
[0120] The submodule for obtaining block plaintext information is used by the file storage module or the DB storage module to obtain block plaintext information by calling the decryption white box to decrypt the block ciphertext data.
[0121] A distributed ledger encryption system 500 of an embodiment of the present invention corresponds to a distributed ledger encryption method 100 of another embodiment of the present invention, and will not be described in detail herein.
[0122] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of complete hardware embodiments, complete software embodiments, or embodiments in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code. The scheme in the embodiments of the present application can be implemented in various computer languages, for example, object-oriented programming language Java and literal scripting language JavaScript, etc.
[0123] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0124] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0125] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0126] Although the preferred embodiments of the present application have been described, those skilled in the art may make other changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications falling within the scope of the present application.
[0127] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.
Claims
1. A distributed ledger encryption method, characterized in that: include: Check whether the white box is initialized. If not, initialize the white box, generate encryption white box and decryption white box, encode the white box and write it into the file. If it is initialized, read the encryption white box and decryption white box from the file to the service. Receive and parse the request command, and call the block storage module to query the block data; When the request command is to write block data, the block data is serialized into a byte array, the encryption white box is called to encrypt the serialized block data to generate block ciphertext data, and the block ciphertext data is written into a file; When the request command is to read out the block data, the block ciphertext storage location is found through the index and the block ciphertext data is read out, and the decryption white box is called to decrypt the block ciphertext data to obtain the block plaintext information.
2. The method according to claim 1, characterized in that Initialize the white box and generate encryption white box and decryption white box, including: Generate a 16-byte SM4 key; Generate an encryption white box, randomly insert 5N redundant rounds according to the SM4 key, generate round keys according to the standard SM4 cryptographic algorithm, construct an encryption white box according to the round key lookup table and save it in encoding; Generate a decryption white box and SM4 key, randomly insert 5N redundant rounds, generate round keys according to the standard SM4 cryptographic algorithm, construct a decryption white box according to the round key lookup table and save it in encoding.
3. The method according to claim 1, characterized in that Receive and parse the request command, call the block storage module to query the block data, including: Receive request commands through the storage service GRPC interface module; Parsing the request command to determine whether the request command is to write block data or read block data; Call the block storage module to query block data by block number or transaction ID.
4. The method according to claim 1, characterized in that When the request command is to write block data, the block data is serialized into a byte array, the serialized block data is encrypted based on the encryption white box to generate block ciphertext data, and the block ciphertext data is written into a file, including: When the request command is to write block data, the block storage module calls the file storage module interface according to the block storage configuration. If file storage is configured, the file storage module interface is called; if DB storage is configured, the DB storage module interface is called; Processing the block data through the file storage module and the DB storage module, and serializing the block data into a byte array; Call the encryption white box to encrypt the serialized block data to generate block ciphertext data; The file storage module writes the block ciphertext data into a file, and the DB storage module writes the block ciphertext data into a database. At the same time, the storage module records the storage location of the block ciphertext data through an index.
5. The method according to claim 1, characterized in that When the request command is to read out the block data, the block ciphertext storage location is searched through the index and the block ciphertext data is read out, and the decryption white box is called to decrypt the block ciphertext data to obtain the block plaintext information, including: When the request command is to read out block data, the block storage module calls the file storage module or the DB storage module according to the block storage configuration to find the block ciphertext storage location through the index and read out the block ciphertext data; The file storage module or the DB storage module obtains the block plaintext information by calling the decryption white box to decrypt the block ciphertext data.
6. A distributed ledger encryption system, characterized in that: include: Initialize the white box module, which is used to detect whether the white box is initialized. If not, initialize the white box, generate encryption white box and decryption white box, and write the white box encoding into the file. If it is initialized, read the encryption white box and decryption white box from the file into the service. Get request command module, used to receive and parse request commands, and call block storage module to query block data; The block data writing module is used to write the block data. When the request command is to write the block data, the block data is serialized into a byte array, the encryption white box is called to encrypt the serialized block data to generate block ciphertext data, and the block ciphertext data is written into the file; The block data reading module is used to find the block ciphertext storage location through the index and read the block ciphertext data when the request command is to read the block data, and call the decryption white box to decrypt the block ciphertext data to obtain the block plaintext information.
7. The system according to claim 6, characterized in that Initialize the white box module, including: Generate SM4 key submodule, used to generate a 16-byte SM4 key; Generate an encryption white box module, which is used to generate an encryption white box, randomly insert 5N redundant rounds according to the SM4 key, generate round keys according to the standard SM4 cryptographic algorithm, construct an encryption white box according to the round key lookup table and save it in encoding; Generate a decryption white box module, which is used to generate a decryption white box, SM4 key, randomly insert 5N redundant rounds, generate round keys according to the standard SM4 cryptographic algorithm, construct a decryption white box according to the round key lookup table and save it in encoding.
8. The system according to claim 6, characterized in that Get request command module, including: The request command receiving submodule is used to receive the request command through the storage service GRPC interface module; A request command parsing submodule, used to parse the request command and determine whether the request command is to write block data or read block data; The block data query submodule is used to call the block storage module to query block data according to the block number or transaction ID.
9. The system according to claim 6, characterized in that Write block data module, including: The calling interface submodule is used for calling the file storage module interface according to the block storage configuration when the request command is to write block data, if the configuration is file storage, the DB storage module interface is called if the configuration is DB storage; The block data serialization submodule is used to process the block data through the file storage module and the DB storage module, and serialize the block data into a byte array; The block ciphertext data generation submodule is used to call the encryption white box to encrypt the serialized block data to generate block ciphertext data; The submodule for recording block ciphertext data is used for the file storage module to write the block ciphertext data into the file, and the DB storage module to write the block ciphertext data into the database. At the same time, the storage module records the storage location of the block ciphertext data through the index.
10. The system according to claim 6, characterized in that Read block data module, including: The block ciphertext data reading submodule is used for, when the request command is to read the block data, the block storage module calls the file storage module or the DB storage module according to the block storage configuration to find the block ciphertext storage location through the index and read the block ciphertext data; The submodule for obtaining block plaintext information is used by the file storage module or the DB storage module to obtain block plaintext information by calling the decryption white box to decrypt the block ciphertext data.