Data processing method and device based on block chain, equipment and medium
By using dual encryption and permission access contracts in blockchain technology, the problem that file encryption keys are easily stolen in data transmission is solved, and high security of file transmission is achieved.
Patent Information
- Application Number
- CN202311614988.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-28
- Publication Date
- 2025-05-30
AI Technical Summary
During data transmission, the encryption key of the file is easily stolen by third parties, resulting in the risk of file data leakage and illegal dissemination.
The blockchain-based data processing method is adopted to obtain the file decryption key of the encrypted file, perform dual encryption processing, and store the encryption key in a trusted execution environment. At the same time, a permission access contract is created and deployed in the blockchain to verify the permissions of file access objects.
It effectively improves the security of file-related keys, reduces the security risks of file transfer, ensures high security of file decryption keys, and thus improves the security of the original file.
Smart Images

Figure CN120074843A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of blockchain technology, and in particular, to a data processing method, device, equipment, and medium based on blockchain. Background Art
[0002] Currently, when two communication parties perform data transmission (such as transmitting a certain file), they usually use an encryption key to encrypt the transmitted file, and then share and transmit the encrypted file.
[0003] However, the inventor found in practice that the encryption key for the file is directly stored in plaintext on the server, which means that the encryption key is extremely easy to be stolen by a third party. Then, once an illegal object steals the encryption key stored on the server, it will lead to the risk of data leakage and illegal dissemination of the file. It can be seen that in the data transmission service, the storage and use methods of the file encryption key have risks, and the security of file transmission is relatively low. Summary of the Invention
[0004] The embodiments of the present application provide a data processing method, device, equipment, and medium based on blockchain, which can improve the security of the file-related key, thereby improving the security of file transmission.
[0005] On the one hand, the embodiments of the present application provide a data processing method based on blockchain, including:
[0006] Obtain a file decryption key for an encrypted file; the encrypted file is obtained by encrypting an original file with a file encryption key; the file decryption key is used to decrypt and restore the encrypted file to obtain the original file;
[0007] Perform an encryption process on the file decryption key to obtain a first encryption key corresponding to the file decryption key;
[0008] Store the first encryption key in a first storage location;
[0009] Obtain a second storage location of the encrypted file and a file receiving object of the original file, create a permission access contract through the first storage location, the second storage location, and the file receiving object, and deploy the permission access contract to the blockchain; the permission access contract deployed to the blockchain is used to perform permission verification on the file access object of the original file, and after the permission verification is passed, send the first storage location, the second storage location, and the decryption method of the first encryption key to the file access object, and the file access object decrypts and obtains the original file through the decryption method of the first encryption key, the first storage location, and the second storage location.
[0010] On the one hand, the embodiments of the present application provide a data processing device based on blockchain, including:
[0011] A key acquisition module, configured to acquire a file decryption key for an encrypted file; the encrypted file is obtained by encrypting an original file with a file encryption key; the file decryption key is used to decrypt the encrypted file to restore the original file.
[0012] An encryption processing module, configured to perform an encryption process on the file decryption key to obtain a first encryption key corresponding to the file decryption key.
[0013] A key storage module, configured to store the first encryption key in a first storage location.
[0014] A contract creation module, configured to obtain a second storage location of the encrypted file and a file receiving object of the original file, create a permission access contract through the first storage location, the second storage location, and the file receiving object, and deploy the permission access contract to a blockchain; the permission access contract deployed to the blockchain is configured to perform a permission verification on a file access object of the original file, and after the permission verification is passed, send the decryption method of the first storage location, the second storage location, and the first encryption key to the file access object, and the file access object decrypts and obtains the original file through the decryption method of the first encryption key, the first storage location, and the second storage location.
[0015] Wherein, the encryption processing module includes:
[0016] A quantity statistics unit, configured to count the quantity of file receiving objects of the original file.
[0017] An encryption method determination unit, configured to determine an encryption method for encrypting the file decryption key based on the quantity of file receiving objects.
[0018] A decryption key encryption unit, configured to encrypt the file decryption key by using the encryption method to obtain an encrypted file decryption key, and use the encrypted file decryption key as the first encryption key.
[0019] Wherein, the encryption method determination unit includes:
[0020] A first encryption method determination subunit, configured to determine the encryption method as a public key encryption method if it is determined that the quantity of file receiving objects is a single one.
[0021] A second encryption method determination subunit, configured to determine the encryption method as an encryption method based on a key generation algorithm if it is determined that the quantity of file receiving objects is at least two.
[0022] Wherein, the encryption method is a public key encryption method.
[0023] The decryption key encryption unit includes:
[0024] A secret key encryption key determination subunit, configured to obtain the public key of the file receiving object based on the public key encryption method, and use the public key as the secret key encryption key of the file decryption key;
[0025] A first encryption subunit, configured to encrypt the file decryption key by using the secret key encryption key of the file decryption key to obtain the encrypted file decryption key.
[0026] Wherein, the encryption method is an encryption method based on a key generation algorithm;
[0027] The decryption key encryption unit includes:
[0028] A key generation algorithm determination subunit, configured to obtain the key generation algorithm jointly determined by at least two file receiving objects through an encryption method based on a key generation algorithm; the key generation algorithm includes a symmetric encryption algorithm or an asymmetric encryption algorithm;
[0029] A key pair generation subunit, configured to generate a key pair through the key generation algorithm; the key pair includes the secret key encryption key of the file decryption key and the secret key decryption key of the first encryption key;
[0030] A second encryption subunit, configured to encrypt the file decryption key by using the secret key encryption key included in the key pair to obtain the encrypted file decryption key.
[0031] Wherein, the first storage location refers to a trusted execution environment; the trusted execution environment includes a trusted program for key management, and the operating system of the trusted execution environment has isolation;
[0032] The key storage module includes:
[0033] A key storage unit, configured to store the first encryption key into the trusted execution environment.
[0034] Wherein, the contract creation module includes:
[0035] A storage location acquisition unit, configured to acquire the first storage location and the second storage location;
[0036] An address information statistics unit, configured to acquire the address information of the file receiving object of the original file, perform information statistics on the acquired address information, and obtain the address information list corresponding to the file receiving object;
[0037] An intelligent contract creation unit, configured to create an intelligent contract with permission management logic based on the first storage location, the second storage location, and the address information list;
[0038] An information addition unit, configured to add the first storage location, the second storage location, and the address information list to the intelligent contract;
[0039] A permission access contract determination unit for using the smart contract as a permission access contract.
[0040] Wherein, the device further includes:
[0041] A request receiving module for receiving a file access request of a file access object of the original file; the file access request is used to request to obtain the original file;
[0042] A contract calling module for calling the permission access contract based on the file access request;
[0043] A permission verification module for verifying the permission of the file access object through the permission access contract;
[0044] An information sending module for sending the first storage location, the second storage location, and the decryption method of the first encryption key to the file access object after the permission verification is passed.
[0045] Wherein, the permission verification module includes:
[0046] An address information acquisition unit for acquiring the address information of the file access object and using the address information as the address information to be verified;
[0047] An address information search unit for searching for the address information matching the address information to be verified in the address information list stored in the permission access contract to obtain an address information search result;
[0048] A first permission verification unit for determining that the permission verification of the file access object is passed if the address information search result indicates that there is address information matching the address information to be verified in the address information list.
[0049] Wherein, the permission verification module further includes:
[0050] A second permission verification unit for determining that the permission verification of the file access object fails if the address information search result indicates that there is no address information matching the address information to be verified in the address information list;
[0051] A denied access notice generation unit for generating a denied access notice and returning the denied access notice to the file access object.
[0052] Wherein, the decryption method of the first encryption key is determined by the number of file receiving objects;
[0053] When the number of file receiving objects is single, the key encryption key of the file decryption key is the public key of the file receiving object, the key decryption key of the first encryption key refers to the private key of the file receiving object, and the decryption method of the first encryption key refers to the method of decrypting using the private key of the file receiving object;
[0054] When the number of file receiving objects is at least two, the key encryption key of the file decryption key is the encryption key in the key pair generated based on the key generation algorithm; the key generation algorithm is jointly determined by multiple file receiving objects; the key decryption key of the first encryption key refers to the decryption key in the key pair generated based on the key generation algorithm, and the decryption method of the first encryption key refers to the method of decrypting using the decryption key in the key pair generated based on the key generation algorithm.
[0055] An embodiment of the present application provides a computer device on the one hand, including a memory and a processor. The memory is connected to the processor. The memory is used to store a computer program, and the processor is used to call the computer program so that the computer device executes the method provided in the above-mentioned aspect of the embodiment of the present application.
[0056] An embodiment of the present application provides a computer-readable storage medium on the one hand. A computer program is stored in the computer-readable storage medium. The computer program is suitable for being loaded and executed by a processor so that a computer device with a processor executes the method provided in the above-mentioned aspect of the embodiment of the present application.
[0057] According to one aspect of the present application, a computer program product or a computer program is provided. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions so that the computer device executes the method provided in the above-mentioned aspect.
[0058] In an embodiment of the present application, a computer device may obtain a file decryption key for an encrypted file; it should be understood that the encrypted file here is obtained by encrypting an original file with a file encryption key; the file decryption key here is used to decrypt the encrypted file to restore the original file; further, the computer device may encrypt the file decryption key to obtain a first encryption key corresponding to the file decryption key; further, the embodiment of the present application may store the first encryption key in a first storage location; thus, it can be seen that when the embodiment of the present application obtains the file decryption key for the encrypted file, it encrypts the file decryption key again. Such a double encryption mechanism can effectively protect the file decryption key and prevent an illegal entity from obtaining the file decryption key, thereby ensuring the security of the file decryption key at the source. In addition to encrypting the file decryption key, the present application also obtains a second storage location of the encrypted file and the file recipient of the original file, and creates a permission access contract through the first storage location, the second storage location, and the file recipient, and deploys the permission access contract on the blockchain; it can be understood that by deploying the permission access contract, the file recipient can be given the access permission to the original file, and the permission access contract can verify the permissions of any file access entity for the original file. Only the entity that passes the verification can obtain the decryption method after encryption of the above first storage location, second storage location, and file decryption key. This means that the high-strength permission verification mechanism of the permission access contract for file access entities can further protect the possibility of the file decryption key being illegally obtained. Thus, it can be seen that the present application can protect the file-related keys (such as the file decryption key) multiplicatively through the key encryption method and the creation of the permission access contract, improving its security. When the file-related keys (such as the file decryption key) have high security, the possibility of the original file being illegally decrypted and spread is very low, thereby improving the security of the original file. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0060] Figure 1 is a schematic diagram of a network architecture based on a blockchain provided by an embodiment of the present application;
[0061] Figure 2 is a schematic diagram of a data interaction scenario provided by an embodiment of the present application;
[0062] Figure 3 It is a schematic diagram of a data processing method based on blockchain provided by an embodiment of the present application;
[0063] Figure 4 It is a schematic diagram of encrypting a file decryption key to obtain a first encryption key provided by an embodiment of the present application;
[0064] Figure 5 It is a schematic diagram of another data processing method based on blockchain provided by an embodiment of the present application;
[0065] Figure 6 It is a schematic diagram of verifying the access permission of a file access object provided by an embodiment of the present application;
[0066] Figure 7 It is a schematic diagram of a file access object obtaining an original file provided by an embodiment of the present application;
[0067] Figure 8 It is a timing diagram of a data processing method based on blockchain provided by an embodiment of the present application;
[0068] Figure 9 Structural schematic diagram of a data processing device based on blockchain provided by an embodiment of the present application;
[0069] Figure 10 It is a structural schematic diagram of a computer device provided by an embodiment of the present application. Detailed implementation manners
[0070] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0071] Please refer to Figure 1 , Figure 1 It is a schematic diagram of a network architecture based on blockchain provided by an embodiment of the present application. As Figure 1 shown, the network architecture may include a terminal device cluster and a blockchain network, and the network architecture can be applied to a data processing system in a data sharing scenario. Among them, the data sharing scenario in the present application may refer to a scenario of sharing any type of data. For example, the data sharing scenario includes but is not limited to: file sharing scenario, string (composed of at least one character) sharing scenario, letter sharing scenario... In the writing of subsequent embodiments, the file sharing scenario will be used as an example for illustration.
[0072] AsFigure 1 As shown, the blockchain network here can be the blockchain network A11 as Figure 1 shown, and the terminal device cluster here can be the sender terminal device cluster A10 and the receiver terminal device cluster A12 as Figure 1 shown.
[0073] Among them, it can be understood that Figure 1 the sender terminal device cluster A10 as shown may include one or more terminal devices. The number of terminal devices in the sender terminal device cluster A10 will not be limited here. As Figure 1 shown, the terminal devices in the sender terminal device cluster A10 may include terminal device 10a, terminal device 10b,..., terminal device 10n, etc. Among them, the terminal devices in the sender terminal device cluster A10 (for example, terminal device 10a) may include: smart phones, tablet computers, laptop computers, palmtop computers, mobile internet devices (MIDs), wearable devices (such as smart watches, smart bracelets, etc.), intelligent voice interaction devices, smart home appliances (such as smart TVs, etc.), and in-vehicle devices and other electronic devices. A file sending client can run on any one of the terminal devices. The file sending client can be a tool responsible for processing the file to be shared, and can be used to encrypt the file to be shared, so as to obtain an encrypted file. Among them, for the convenience of understanding, the embodiments of the present application may collectively refer to the file to be shared as the original file, and refer to the encrypted file as the encrypted file.
[0074] It should be understood that the blockchain network A11 may include one or more blockchain nodes, and the number of blockchain nodes is not limited here. As Figure 1 shown, the blockchain network A11 may specifically include blockchain node 11a, blockchain node 11b, blockchain node 11c,..., blockchain node 11n. Among them, it can be understood that blockchain is a new application mode of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithm, mainly used to sort data in chronological order, encrypt it into a ledger, make it impossible to be tampered with and forged, and at the same time, data verification, storage, and update can be performed. Blockchain is essentially a decentralized database, and each node in the database maintains a blockchain (for example, Figure 1 the blockchain 10e as shown).
[0075] It can be understood that the method provided by the embodiments of the present application can be executed by a computer device, which includes but is not limited to a terminal or a server. The blockchain nodes 11a, 11b, 11c, ..., 11n in the embodiments of the present application can be computer devices (that is, the terminal or server in the present application can be used as a blockchain node). The above server can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. As Figure 1 shown, the blockchain nodes 11a, 11b, 11c, ..., 11n can be respectively network-connected to the blockchain network A11.
[0076] It should be understood that one or more smart contracts can be deployed on the blockchain of the above blockchain network (for example, the above blockchain network A11). In the embodiments of the present application, the smart contract deployed on the blockchain should have permission access logic. Then, for the smart contract deployed in the embodiments of the present application, it can be called a permission access contract. The permission access contract can be some contracts used to verify the access permissions of certain users. For example, a contract used to verify the file access permissions of file access objects in a file sharing scenario.
[0077] Furthermore, as Figure 1 shown, the terminal devices (for example, the terminal device 10a) in the sender terminal device cluster A10 can be network-connected to blockchain nodes such as the blockchain nodes 11a, 11b, 11c, and 11d to perform data interaction with the blockchain nodes in the blockchain network A11 when the terminal devices in the sender terminal device cluster A10 access the blockchain network A11. For example, when the terminal device (for example, the terminal device 10a) corresponding to a certain sender (for example, user A) runs a file sending client, the terminal device 10a can send an encrypted file to the blockchain network A11 through the file sending client. Then, the blockchain node (for example, the blockchain node 11a) in the blockchain network A11 can obtain the encrypted file and the decryption key of the encrypted file, further encrypt the decryption key, and store the encrypted file and the encrypted key in the smart contract (for example, the above permission access contract) deployed on the blockchain (for example, the above blockchain 10e). For ease of understanding, the sender (for example, user A) in the embodiments of the present application can be collectively referred to as a file sending object.
[0078] It can be understood that Figure 1 the receiving party's terminal device cluster A12 shown may include one or more terminal devices. The number of terminal devices in the receiving party's terminal device cluster A12 will not be limited here. For example Figure 1 as shown, the terminal devices in the receiving party's terminal device cluster A12 may include terminal device 12a, terminal device 12b,..., terminal device 12n, etc. Among them, the terminal devices in the receiving party's terminal device cluster A12 (for example, terminal device 12a) may include: smart phones, tablet computers, laptop computers, handheld computers, mobile internet devices (MID), wearable devices (such as smart watches, smart bracelets, etc.), intelligent voice interaction devices, smart home appliances (such as smart TVs, etc.), and in-vehicle devices and other electronic devices.
[0079] Furthermore, as Figure 1 shown, the terminal devices in the receiving party's terminal device cluster A12 (for example, terminal device 12a) can be network-connected to blockchain nodes such as blockchain node 11a, blockchain node 11b, blockchain node 11c, blockchain node 11d, etc., so that when the terminal devices in the receiving party's terminal device cluster A12 access the blockchain network A11, data interaction can be performed with the blockchain nodes in the blockchain network A11. For example, when the terminal device (for example, terminal device 12a) corresponding to a certain receiving party (for example, user B) runs a file receiving client, the terminal device 10a can send a file access request for the above encrypted file to the blockchain network A11 through the file receiving client. Furthermore, the blockchain node (for example, blockchain node 11a) in the blockchain network A11 can obtain the file access request of the above original file, and further call the above intelligent contract (for example, the above permission access contract) to verify the file access permission of the receiving party (for example, user B). Thus, after the permission verification passes, the storage location of the encrypted file and the storage location of the above encrypted decryption key are sent to the receiving party (for example, user B). Furthermore, the receiving party (for example, user B) obtains the above encrypted file and the above encrypted decryption key, and then decrypts the above encrypted decryption key, so as to decrypt the above encrypted file to obtain the original file. Among them, for the sake of easy understanding, the receiving party (for example, user B) in the embodiments of the present application may be collectively referred to as the file receiving object.
[0080] For the sake of easy understanding, furthermore, please refer to Figure 2 , Figure 2 which is a schematic diagram of a data interaction scenario provided by the embodiments of the present application. In Figure 2 it, specifically, the electronic bill sharing scenario will be used as an example for elaboration, that is, the file shared in the embodiments of the present application is an electronic bill. For exampleFigure 2 As shown, the user terminal 20a can be the terminal device 10a in the corresponding embodiment above, and the user 20b can be the user A in the corresponding embodiment above, that is, the file sending object. In addition, as Figure 1 shown, the blockchain node 21a can be any blockchain node in the blockchain network A11 in the corresponding embodiment above (such as the blockchain node 11a, blockchain node 11b, etc.), and the blockchain 20e can correspond to the blockchain 10e in the corresponding embodiment above. Figure 1 Among them, as Figure 2 shown, the user 20b can generate an encryption key Y1 through the corresponding user terminal 20a. Further, use this encryption key Y1 to encrypt the electronic bill TX1, so as to obtain the encrypted electronic bill TX1, that is, the electronic bill TX2. It should be understood that the electronic bill TX1 here can correspond to the original file in the corresponding embodiment above, and the electronic bill TX2 here can correspond to the encrypted file in the corresponding embodiment above. Further, the user 20b can send the electronic bill TX2 to the blockchain node 21a through the corresponding user terminal 20a. Figure 1 As shown, when the blockchain node 21a obtains the electronic bill TX2, it can obtain the decryption key Y2 for the electronic bill TX2. In order to prevent the decryption key Y2 saved in plaintext from being stolen by illegal objects, the embodiment of the present application will also encrypt the decryption key Y2. For example, the blockchain node 21a will encrypt the decryption key Y2, and then obtain the encryption key Y3 corresponding to the decryption key. To further ensure the security of the encryption key Y3, after obtaining the encryption key Y3, the blockchain node 21a will store the encryption key Y3 in the first storage location 201a. Here, the first storage location 201a can be a trusted execution environment, a smart contract (that is, the present application can use a trusted execution environment or a smart contract as the storage location of the encryption key Y3). It should be understood that such a double encryption mechanism can effectively ensure the storage security of relevant keys (for example, the decryption key Y2). Figure 1
[0081] Among them, as Figure 2 shown, the user 20b can generate an encryption key Y1 through the corresponding user terminal 20a. Further, use this encryption key Y1 to encrypt the electronic bill TX1, so as to obtain the encrypted electronic bill TX1, that is, the electronic bill TX2. It should be understood that the electronic bill TX1 here can correspond to the original file in the corresponding embodiment above, and the electronic bill TX2 here can correspond to the encrypted file in the corresponding embodiment above. Further, the user 20b can send the electronic bill TX2 to the blockchain node 21a through the corresponding user terminal 20a. Figure 2 As shown, when the blockchain node 21a obtains the electronic bill TX2, it can obtain the decryption key Y2 for the electronic bill TX2. In order to prevent the decryption key Y2 saved in plaintext from being stolen by illegal objects, the embodiment of the present application will also encrypt the decryption key Y2. For example, the blockchain node 21a will encrypt the decryption key Y2, and then obtain the encryption key Y3 corresponding to the decryption key. To further ensure the security of the encryption key Y3, after obtaining the encryption key Y3, the blockchain node 21a will store the encryption key Y3 in the first storage location 201a. Here, the first storage location 201a can be a trusted execution environment, a smart contract (that is, the present application can use a trusted execution environment or a smart contract as the storage location of the encryption key Y3). It should be understood that such a double encryption mechanism can effectively ensure the storage security of relevant keys (for example, the decryption key Y2). Figure 1 shown, the user 20b can generate an encryption key Y1 through the corresponding user terminal 20a. Further, use this encryption key Y1 to encrypt the electronic bill TX1, so as to obtain the encrypted electronic bill TX1, that is, the electronic bill TX2. It should be understood that the electronic bill TX1 here can correspond to the original file in the corresponding embodiment above, and the electronic bill TX2 here can correspond to the encrypted file in the corresponding embodiment above. Further, the user 20b can send the electronic bill TX2 to the blockchain node 21a through the corresponding user terminal 20a. Figure 1 shown, the user 20b can generate an encryption key Y1 through the corresponding user terminal 20a. Further, use this encryption key Y1 to encrypt the electronic bill TX1, so as to obtain the encrypted electronic bill TX1, that is, the electronic bill TX2. It should be understood that the electronic bill TX1 here can correspond to the original file in the corresponding embodiment above, and the electronic bill TX2 here can correspond to the encrypted file in the corresponding embodiment above. Further, the user 20b can send the electronic bill TX2 to the blockchain node 21a through the corresponding user terminal 20a. Figure 2 shown, the user 20b can generate an encryption key Y1 through the corresponding user terminal 20a. Further, use this encryption key Y1 to encrypt the electronic bill TX1, so as to obtain the encrypted electronic bill TX1, that is, the electronic bill TX2. It should be understood that the electronic bill TX1 here can correspond to the original file in the corresponding embodiment above, and the electronic bill TX2 here can correspond to the encrypted file in the corresponding embodiment above. Further, the user 20b can send the electronic bill TX2 to the blockchain node 21a through the corresponding user terminal 20a.
[0082] Among them, as Figure 2 shown, when the blockchain node 21a obtains the electronic bill TX2, it can obtain the decryption key Y2 for the electronic bill TX2. In order to prevent the decryption key Y2 saved in plaintext from being stolen by illegal objects, the embodiment of the present application will also encrypt the decryption key Y2. For example, the blockchain node 21a will encrypt the decryption key Y2, and then obtain the encryption key Y3 corresponding to the decryption key. To further ensure the security of the encryption key Y3, after obtaining the encryption key Y3, the blockchain node 21a will store the encryption key Y3 in the first storage location 201a. Here, the first storage location 201a can be a trusted execution environment, a smart contract (that is, the present application can use a trusted execution environment or a smart contract as the storage location of the encryption key Y3). It should be understood that such a double encryption mechanism can effectively ensure the storage security of relevant keys (for example, the decryption key Y2).
[0083] Among them, it should be understood that the blockchain node 21a will obtain the second storage location 201b of the electronic bill TX2 (i.e., the location where the electronic bill TX2 is stored) and the recipient of the electronic bill TX1, and then create a smart contract. It should be understood that the recipient of the electronic bill TX1 here can correspond to the file recipient in the corresponding embodiment above Figure 1 corresponding to the file recipient in the corresponding embodiment. In other words, after the blockchain node 21a obtains the second storage location 201b of the electronic bill TX2 and the recipient of the electronic bill TX1, it will create a smart contract through the first storage location 201a, the second storage location 201b, and the recipient. Among them, the smart contract in this embodiment of the present application is collectively referred to as a permission access contract, such as Figure 2 the permission access contract 200a shown. In addition, the blockchain node 21a deploys the permission access contract 200a in the blockchain 20e. Specifically, as Figure 2 shown, the permission access contract 200a is deployed in the blockchain 20e, where the first storage location 201a and the second storage location 201b are stored in the permission access contract 200a. Specifically, the encryption key Y3 is stored in the first storage location 201a, and the electronic bill TX2 is stored in the second storage location 201b.
[0084] It should be noted that the above Figure 2 corresponding embodiment is described by taking the electronic bill sharing scenario as an example. It should be understood that the files in this embodiment of the present application include but are not limited to electronic bills, and may also be electronic certificates, contract files, etc. The types of the above files will not be limited here.
[0085] The computer device in this embodiment of the present application (for example, the user terminal 20a shown above Figure 2 during the process of constructing the encrypted file (for example, the electronic bill TX2 shown above Figure 2 to be sent to the blockchain node 21a), if the encrypted file is a file associated with an electronic bill (for example, an electronic bill file), it may involve displaying a prompt interface or a pop-up window when it is necessary to obtain the business data of business objects such as users, enterprises, and institutions associated with the electronic bill (for example, the invoicing information, credit information, tax refund information, etc. of users, and the profit and loss, enterprise qualifications, etc. of enterprises). The prompt interface or the pop-up window is used to prompt the user that the business data of business objects such as users, enterprises, and institutions (for example, the invoicing information, credit information, tax refund information, etc. of users, and the profit and loss, enterprise qualifications, etc. of enterprises) is being collected. Only after obtaining the confirmation operation of the user on the prompt interface or the pop-up window, the relevant steps of data acquisition are started, otherwise it ends.
[0086] It can be understood that in the specific implementation manner of the present application, the file sender (for example, the aboveFigure 2 The user 20b) shown, during the process of constructing an encrypted file (for example, the electronic bill TX2 shown above), if the electronic bill TX2 is a file associated with the electronic bill, it may involve using business data of business objects such as users, enterprises, and institutions obtained (for example, the invoicing information, credit information, tax refund information, etc. of users, and the profit and loss, enterprise qualifications, etc. information of enterprises) as file parameters of the electronic bill TX2 to construct the electronic bill TX2. When the above embodiments of the present application are applied to specific products or technologies, the permission or consent of business objects such as users, enterprises, and institutions needs to be obtained, and the collection, use, and processing of relevant data need to comply with relevant laws, regulations, and standards in relevant regions and areas. Figure 2 During the process of constructing the encrypted file (such as the electronic bill TX2 shown above), if the electronic bill TX2 is a file associated with the electronic bill, it may involve using business data of business objects such as users, enterprises, and institutions obtained (such as the invoicing information, credit information, tax refund information, etc. of users, and the profit and loss, enterprise qualifications, etc. information of enterprises) as file parameters of the electronic bill TX2 to construct the electronic bill TX2. When the above embodiments of the present application are applied to specific products or technologies, the permission or consent of business objects such as users, enterprises, and institutions needs to be obtained, and the collection, use, and processing of relevant data need to comply with relevant laws, regulations, and standards in relevant regions and areas.
[0087] Among them, after the file sender encrypts the original file to obtain an encrypted file, the encrypted file is sent to the blockchain node. The specific process of the blockchain node obtaining the file decryption key for the encrypted file, performing secondary encryption, and the file access object obtaining the original file can be seen in Figures 3 to 8 the corresponding embodiments.
[0088] Furthermore, please refer to Figure 3 , Figure 3 which is a schematic diagram of a data processing method based on blockchain provided by an embodiment of the present application. As Figure 3 shown, the method can be executed by the blockchain node 11a in the corresponding embodiment above. The method can specifically include the following steps S101 - step S104. Figure 1 shown, the method can be executed by the blockchain node 11a in the corresponding embodiment above. The method can specifically include the following steps S101 - step S104.
[0089] Step S101, obtain the file decryption key for the encrypted file; the encrypted file is obtained by encrypting the original file with the file encryption key; the file decryption key is used to decrypt and restore the encrypted file to obtain the original file.
[0090] It should be understood that in the embodiments of the present application, the encrypted file (for example, the electronic bill TX2 in the corresponding embodiment above) can be the file sender (for example, user U1, and this user U1 can be the user 20b in the corresponding embodiment above), and the file encryption key (for example, the one shown above) is generated by the terminal device corresponding to the file sender (for example, the user terminal 20a in the corresponding embodiment above). Figure 2 It should be understood that in the embodiments of the present application, the encrypted file (for example, the electronic bill TX2 in the corresponding embodiment above) can be the file sender (for example, user U1, and this user U1 can be the user 20b in the corresponding embodiment above), and the file encryption key (for example, the one shown above) is generated by the terminal device corresponding to the file sender (for example, the user terminal 20a in the corresponding embodiment above). Figure 2 It should be understood that in the embodiments of the present application, the encrypted file (for example, the electronic bill TX2 in the corresponding embodiment above) can be the file sender (for example, user U1, and this user U1 can be the user 20b in the corresponding embodiment above), and the file encryption key (for example, the one shown above) is generated by the terminal device corresponding to the file sender (for example, the user terminal 20a in the corresponding embodiment above). Figure 2 It should be understood that in the embodiments of the present application, the encrypted file (for example, the electronic bill TX2 in the corresponding embodiment above) can be the file sender (for example, user U1, and this user U1 can be the user 20b in the corresponding embodiment above), and the file encryption key (for example, the one shown above) is generated by the terminal device corresponding to the file sender (for example, the user terminal 20a in the corresponding embodiment above). Figure 2It is obtained by encrypting the original file with the encryption key Y1) in the corresponding embodiment. Among them, the original file is a file sent by the file sender to the file recipient (the file recipient here can be specified by the file sender, that is, the file recipient needs to be known and agreed by the file sender).
[0091] Among them, the file decryption key refers to the key used to decrypt the encrypted file. For example: the above Figure 2 decryption key Y2 in the corresponding embodiment.
[0092] It should be understood that the file encryption key and the file decryption key are generated based on the encryption algorithm. It should be noted that the encryption algorithm here can include but is not limited to symmetric encryption algorithms and asymmetric encryption algorithms. For the convenience of understanding, the symmetric encryption algorithm and the asymmetric encryption algorithm will be introduced below:
[0093] Symmetric encryption algorithm: That is, an algorithm that uses the same key for encryption and decryption. In the symmetric encryption algorithm, the data sender (for example, the above file sender) processes the plaintext and the encryption key together through a special encryption algorithm to make it into a complex encrypted ciphertext and send it out. After the recipient (for example, the above file recipient) receives the ciphertext, if it wants to interpret the original text, it needs to use the key used for encryption and the inverse algorithm of the same algorithm to decrypt the ciphertext in order to restore it to readable plaintext. The symmetric encryption (also called private key encryption) algorithm is sometimes called the traditional cipher algorithm. The encryption key can be deduced from the decryption key, and at the same time, the decryption key can also be deduced from the encryption key. In most symmetric algorithms, the encryption key and the decryption key are the same. Among them, common symmetric encryption algorithms can include the DES TripleDES algorithm, the RC algorithm, the BlowFish algorithm, and so on. Here, the types of symmetric encryption algorithms will not be restricted.
[0094] Asymmetric encryption algorithm: An algorithm that uses different keys for encryption and decryption. In an asymmetric encryption algorithm, the keys are divided into two types: an encryption key and a decryption key. The data sender (e.g., the above-mentioned file sending object) uses the encryption key to encrypt the data, turning it into a complex encrypted ciphertext and sending it out. After the recipient (e.g., the above-mentioned file receiving object) receives the ciphertext, if it wants to interpret the original text, it needs to use the decryption key to decrypt the ciphertext to restore it to readable plaintext. In an asymmetric encryption algorithm, a pair of generated keys will include an encryption key and a decryption key, and the encryption key and the decryption key are usually two different keys (in some optional embodiments, the encryption key can be made public). The ciphertext encrypted by the encryption key must be decrypted using the decryption key paired with that encryption key. Among them, common asymmetric encryption algorithms can include the RSA algorithm, the DSA algorithm, etc. Here, the types of the asymmetric encryption algorithm will not be restricted.
[0095] Step S102, perform an encryption process on the file decryption key to obtain a first encryption key corresponding to the file decryption key.
[0096] Specifically, the blockchain node can count the number of file receiving objects of the original file; further, the blockchain node can determine an encryption method for encrypting the file decryption key based on the number of file receiving objects; further, the blockchain node can use the encryption method to encrypt the file decryption key to obtain the encrypted file decryption key, and use the encrypted file decryption key as the first encryption key.
[0097] Among them, the file receiving object of the original file can be any one of the Figure 1 terminal devices in the receiving party terminal device cluster A12 corresponding to the above-mentioned corresponding embodiment (e.g., the user corresponding to terminal device 12a).
[0098] Among them, when the blockchain node counts the number of file receiving objects of the original file, a quantity counting method can be used, and this quantity counting method can be used to obtain the number of file receiving objects.
[0099] Among them, when the blockchain node obtains the number of file receiving objects based on the quantity counting method, if the number of file receiving objects is single, the blockchain node can determine the encryption method as the public key encryption method.
[0100] Among them, the public key encryption method here can refer to the method of using the public key as the encryption key to encrypt the file decryption key. For ease of understanding, the public key and the private key will be introduced below:
[0101] Public key and private key: In asymmetric cryptography algorithms, two keys are required. One is the public key, and the other is the private key. The public key is used for encryption, and the private key is used for decryption. The ciphertext obtained by encrypting the plaintext with the public key can only be decrypted with the corresponding private key to obtain the original plaintext. The public key initially used for encryption cannot be used for decryption. The public key can be made public, while the private key cannot be made public. Once the private key is leaked, the public key and private key pair need to be updated, otherwise it will not be secure.
[0102] It should be understood that in the embodiments of the present application, the public key encryption method refers to that the blockchain node obtains the public key of the file receiving object, and then uses this public key as the key for encrypting the decryption key of the above file. For ease of understanding, in the embodiments of the present application, the key for encrypting the decryption key of the above file is collectively referred to as the key encryption key. Further, the blockchain node encrypts the file decryption key with the key encryption key to obtain the encrypted file decryption key. Among them, in the embodiments of the present application, the encrypted file decryption key is collectively referred to as the first encryption key. At this time, when decrypting the first encryption key, the decryption key required is the private key of the file receiving object.
[0103] Among them, it should be understood that when the blockchain node obtains the number of file receiving objects based on the quantity statistics method, if the number of file receiving objects is at least two, the blockchain node can determine the encryption method as the encryption method based on the key generation algorithm. It should be noted that the key generation algorithm here can refer to any algorithm with the function of generating keys. For example, the key generation algorithm can be the symmetric encryption algorithm and the asymmetric encryption algorithm described above.
[0104] Specifically, the blockchain node can obtain the key generation algorithm jointly determined by at least two file receiving objects through the encryption method based on the key generation algorithm. Among them, the key generation algorithm here includes the symmetric encryption algorithm or the asymmetric encryption algorithm. Further, the blockchain node can generate a key pair through the key generation algorithm. Among them, the key pair includes the key encryption key of the file decryption key and the key decryption key of the first encryption key. Further, the blockchain node can use the key encryption key of the file decryption key included in the key pair to encrypt the file decryption key to obtain the encrypted file decryption key. At this time, when decrypting the first encryption key, the decryption key required is the decryption key included in the key pair in the above key generation algorithm.
[0105] Among them, when the key generation algorithm adopted above is the symmetric encryption algorithm, the above key encryption key and key decryption key are the same. In addition, when the key generation algorithm adopted above is the asymmetric encryption algorithm, the above key encryption key and key decryption key are different.
[0106] Further, please refer to Figure 4 , Figure 4 which is a schematic diagram of encrypting a file decryption key to obtain a first encryption key provided by an embodiment of the present application. As Figure 4 shown, the blockchain node 40a may correspond to the blockchain node 20a in the corresponding embodiment above. In addition, Figure 2 it further includes a file receiving object terminal device cluster 400a. In the embodiment of the present application, assuming that the number of the above file receiving objects is three, as Figure 4 shown, the file receiving object terminal device cluster 400a includes terminal devices corresponding to three file receiving objects, namely the terminal device 41a corresponding to the user 42a, the terminal device 41b corresponding to the user 42b, and the terminal device 41c corresponding to the user 42c. Figure 4 Specifically, the blockchain node 40a first obtains the number of file receiving objects, and then determines the number of file receiving objects. Further, when the blockchain node 40a determines that the number of file receiving objects exceeds one, it will send a notification for determining the key generation algorithm to the file receiving objects. In other words, the blockchain node 40a will send a notification for the file receiving objects (such as
[0107] the users 42a, 42b, and 42c shown in Figure 4 ) to determine the key generation algorithm to each terminal device in the above file receiving object terminal device cluster 400a, so that the file receiving objects (such as Figure 4 the users 42a, 42b, and 42c shown in
[0108] ) return the jointly determined key generation algorithm to the blockchain node 40a, so as to encrypt the above file decryption key (such as the decryption key Y2). Figure 4 As Figure 4 shown, when the terminal device 41b and the terminal device 41c corresponding to the user 42c receive the notification sent by the blockchain node 40a, the file receiving objects (such as Figure 4 the users 42a, 42b, and 42c shown in
[0109] Further, the blockchain node 40a can receive the jointly determined key generation algorithm 4a sent by the file receiving object, and thus can generate a key pair through the key generation algorithm 4a. Among them, the key pair includes an encryption key for encrypting the above-mentioned file decryption key (for example, the decryption key Y2), and a decryption key for decrypting the above-mentioned first encryption key. For the sake of understanding, in the embodiments of the present application, the encryption key for encrypting the above-mentioned file decryption key (for example, the decryption key Y2) is collectively referred to as the key encryption key, and the decryption key for decrypting the above-mentioned first encryption key is collectively referred to as the key decryption key.
[0110] Among them, it should be understood that the key generation algorithm 4a can be the symmetric encryption algorithm or the asymmetric encryption algorithm described above. Specifically, the algorithm category of the key generation algorithm 4a is jointly determined by the above-mentioned file receiving objects.
[0111] Further, the blockchain node 40a can use the generated key encryption key to encrypt the above-mentioned file decryption key (for example, the decryption key Y2), so as to obtain the encrypted file decryption key, that is, the first encryption key.
[0112] Among them, in an optional implementation manner, when the number of file receiving objects is at least two, the above encryption method can also be a public key encryption method, and the blockchain node can use the public key of one of the multiple file receiving objects to encrypt the above-mentioned first encryption key. For example, the blockchain node 40a uses the Figure 4 corresponding public key of the user 42a to encrypt the first encryption key. At this time, when decrypting the first encryption key, the key required for decrypting the first encryption key is the above-mentioned Figure 4 corresponding private key of the user 42a.
[0113] Step S103, store the first encryption key in the first storage location.
[0114] Among them, to improve the security of the file decryption key, the present application can store the first encryption key used for encrypting the file decryption key in a location with higher security, which can be called the first storage location. Correspondingly, the key decryption key corresponding to the first encryption key will also be stored in the first storage location.
[0115] Among them, the first storage location can refer to a trusted execution environment; the trusted execution environment includes a trusted program for key management, and the operating system of the trusted execution environment has isolation;
[0116] It should be understood that a trusted execution environment (TEE) is an independent processing environment with computing and storage functions that can provide security and integrity protection. The basic idea is that in the hardware, a separate isolated memory is allocated for the target data, and all calculations of the target data are performed in this memory. Moreover, except through authorized interfaces, other parts of the hardware cannot access the information in this isolated memory. It should be understood that the target data here refers to the data that needs to be processed. Among them, the isolation of the operating system of the above-mentioned trusted execution environment means that the operating system of the trusted execution environment is isolated from the operating system of the untrusted execution environment. When executing a program that needs to be processed, it is executed in isolation. Therefore, the content stored in the trusted execution environment and the processing operations performed are not readable or tamperable by other devices.
[0117] In addition, in the embodiments of the present application, the trusted execution environment contains a trusted program for key management. When a file access object initiates a decryption request for the first encryption key stored in the trusted execution environment through a relevant interface, the trusted program in the trusted execution environment can use the above-mentioned key decryption key to decrypt the first encryption key to obtain the file decryption key. It should be understood that since the decryption operation in the trusted execution environment is isolated, others cannot know the keys stored in the trusted execution environment (for example, the first encryption key, the key decryption key), nor can they know the process of decrypting the first encryption key. In other words, the trusted execution environment only outputs the result after the trusted program finishes execution. For example, the trusted execution environment will output the file decryption key obtained after decrypting the first encryption key as described above.
[0118] Among them, the above-mentioned relevant interface can be an access interface, which can be used for the file access object to access the processing result of the trusted execution environment to send a decryption request, so as to obtain the decrypted first encryption key. Among them, the access method required by this access interface can be jointly determined by the above-mentioned file receiving objects. For example, the access method can be the voice information of each file receiving object, the fingerprint information of each file receiving object, and the facial information of each file receiving object. The above access method will not be limited here.
[0119] It is understandable that the trusted execution environment stores the information required for the above file receiving object to access (for example, the voice information of each file receiving object). This means that even if the permission verification contract determines that the permission access object passes the permission verification, if the file access object fails the verification of the above access method, the file access object cannot initiate a decryption request to the trusted execution environment, and thus the trusted execution environment cannot perform relevant decryption processing. It can be seen that the trusted execution environment can highly protect the security of the file decryption key from being leaked. Therefore, the security of the file decryption key can be further improved.
[0120] Step S104: Obtain the second storage location of the encrypted file and the file receiving object of the original file, create a permission access contract through the first storage location, the second storage location, and the file receiving object, and deploy the permission access contract to the blockchain; the permission access contract deployed to the blockchain is used to verify the permissions of the file access object of the original file, and after the permission verification passes, send the first storage location, the second storage location, and the decryption method of the first encryption key to the file access object, and the file access object decrypts and obtains the original file through the decryption method of the first encryption key, the first storage location, and the second storage location.
[0121] Specifically, the blockchain node can obtain the first storage location and the second storage location; in addition, the blockchain node can also obtain the address information of the file receiving object of the original file, and perform information statistics on the obtained address information to obtain the address information list corresponding to the file receiving object; further, the blockchain node can create an intelligent contract with permission management logic based on the first storage location, the second storage location, and the address information list; after creating the intelligent contract, the blockchain node can add the first storage location, the second storage location, and the address information list to the intelligent contract, and can use the intelligent contract as the permission access contract.
[0122] Among them, the first storage location is used to store the first encryption key, and as described in the above step S103, the first storage location is the trusted execution environment. It is understandable that the blockchain node obtains the first storage location, which can be that the blockchain node sends a location query request to the trusted execution environment, and then the blockchain node can obtain the location information of the trusted execution environment.
[0123] Among them, the second storage location is used to store the encrypted file. In the embodiments of the present application, the second storage location may include but is not limited to a cloud disk (such as a network disk for storing a large amount of data) or a distributed file storage system.
[0124] Among them, the cloud disk is a cloud storage and file sharing platform, and the system design of the cloud disk adopts a distributed architecture to cope with the large number of users and the huge storage requirements.
[0125] Among them, distributed file storage refers to a storage system that disperses files across multiple computer nodes. It extends a file system fixed at a certain location to any number of locations or multiple file systems, and numerous nodes form a file system network. Each node can be located in different places, and communication and data transmission between nodes are carried out through the network. It distributes a large amount of data across different nodes for storage, greatly reducing the risk of data loss. A common distributed file storage system is the InterPlanetary File System (IPFS).
[0126] It can be understood that, as described in the corresponding embodiments above Figure 2 After the user 20b (i.e., the file sending object) encrypts the electronic bill TX1 through the user terminal 20a to obtain the electronic bill TX2, subsequently, the electronic bill TX2 can be stored. That is, as described above, the user 20b (i.e., the file sending object) can store the electronic bill TX2 in the above cloud disk or distributed file storage system through the user terminal 20a. Among them, it should be understood that the choice of the storage location here is determined by the user 20b (i.e., the file sending object) himself. It should be understood that in the embodiments of the present application, the location for storing the encrypted file (for example, the electronic bill TX2) is referred to as the second storage location.
[0127] Among them, the address information list is used to store the address information of the file receiving object. The blockchain node can access the address information of each file receiving object, and then summarize all the address information to obtain the address information list.
[0128] Among them, in the embodiments of the present application, to further ensure the security of the first encryption key and the encrypted file, the created smart contract has a permission management logic. Among them, the permission management logic here can be written and deployed manually. Specifically, the permission management can be carried out by writing code, and the obtained address information list can be added to the code. In this way, the above code can store the address information of legitimate file receiving objects.
[0129] Among them, since the plaintext of the encrypted file is stored on the server, other illegal entities can attack the server so as to obtain the encrypted file stored on the server. In addition, for the first encryption key, if the first encryption key is stored in the server, then the illegal entity can attack the server and thus illegally obtain the first encryption key. Therefore, in the embodiments of the present application, the first storage location and the second storage location storing the encrypted file will be stored in the smart contract. Further, the above-written and deployed permission management logic includes a list of address information. In other words, the list of address information of the above file receiving entity is also stored in the smart contract. Among them, in the embodiments of the present application, the above smart contract is used as the permission access contract. The permission access contract is used to store the first storage location and the second storage location, and perform permission verification on the file access entity.
[0130] Further, the permission access contract stores the second storage location. The second storage location contains the encrypted file and may also include relevant information of the encrypted file, such as the file name of the encrypted file, the file type of the encrypted file, and the hash value of the encrypted file.
[0131] As can be seen, in the embodiments of the present application, when a blockchain node obtains a file decryption key for an encrypted file, it can obtain the number of file receiving objects, and based on the number of file receiving objects, determine an encryption method for encrypting the file decryption key. Furthermore, it can use this encryption method to encrypt the file encryption key, thereby obtaining an encrypted file decryption key, that is, a first encryption key. This means that in the embodiments of the present application, by encrypting the file decryption key again, such a dual encryption mechanism can effectively protect the file decryption key, prevent an illegal object from obtaining the file decryption key, and thus ensure the security of the file decryption key at the source. In addition, the blockchain node will store the first encryption key in a first storage location, where the first storage location is a trusted execution environment. The use of the first encryption key will only be executed in the trusted execution environment, and the first encryption key will never leave the trusted execution environment. Therefore, even if an illegal object obtains the first encryption key, the illegal object cannot decrypt the first encryption key in the trusted execution environment to obtain the file decryption key, which can further ensure the security of the first encryption key with high strength. Further, the blockchain node can obtain the second storage location of the encrypted file and the file receiving objects of the original file, and create a permission access contract through the first storage location, the second storage location, and the file receiving objects, so as to deploy the permission access contract on the blockchain. It can be understood that through the permission access contract, the above file access objects can be verified for permissions, and only the objects that pass the verification can obtain the decryption method after encryption of the above first storage location, second storage location, and file decryption key. This means that the high-strength permission verification mechanism of the permission access contract for file access objects can further protect against the possibility of the file decryption key being illegally obtained. As can be seen, through the key encryption method, storing the first encryption key in the trusted execution environment, and creating a permission access contract, the present application can protect the file decryption key multiply and improve its security. When the file decryption key has high security, the possibility of the original file being illegally decrypted and spread is very low, thereby improving the security of the original file.
[0132] Further, please refer to Figure 5 , Figure 5 which is a schematic diagram of another data processing method based on a blockchain provided by the embodiments of the present application. This method can be executed by a blockchain node, for example, any blockchain node deployed in the blockchain network A11. This method can at least include the following steps S201 to S212.
[0133] Step S201, obtain a file decryption key for an encrypted file.
[0134] Among them, the encrypted file is obtained by encrypting the original file with a file encryption key; the file decryption key is used to decrypt the encrypted file to restore the original file.
[0135] Step S202: Encrypt the file decryption key to obtain a first encryption key corresponding to the file decryption key.
[0136] Step S203: Store the first encryption key in a first storage location.
[0137] Step S204: Obtain a second storage location of the encrypted file and a file receiving object of the original file, create a permission access contract through the first storage location, the second storage location, and the file receiving object, and deploy the permission access contract on the blockchain.
[0138] Among them, for the specific implementation manners of steps S201 - S204, reference can be made to the descriptions of steps S101 - S104 in the corresponding embodiments above, and details will not be elaborated here. Figure 3 The descriptions of steps S101 - S104 in the corresponding embodiments above will not be repeated here.
[0139] Step S205: Receive a file access request from a file access object of the original file.
[0140] Among them, the file access request is used to request to obtain the original file.
[0141] It should be understood that the above file sending object is to send the original file to the file receiving object so that the file receiving object can receive the original file and complete the sharing operation of the original file. Therefore, after the above file sending object sends the encrypted file, according to the above description, the encrypted file is stored in the second storage location in the permission access contract deployed on the blockchain. In order to obtain the encrypted file, the file receiving object needs to send a file access request for the original file to the blockchain node. It should be understood that in the embodiments of the present application, the file receiving object that sends a file access request to the blockchain node to obtain the encrypted file is collectively referred to as the file access object.
[0142] Step S206: Invoke the permission access contract based on the file access request.
[0143] Among them, it can be understood that the permission access contract may include contract call parameters, and the contract call parameters are used to invoke the permission access contract.
[0144] Step S207: Obtain the address information of the file access object and use the address information as the address information to be verified.
[0145] Among them, the address information of the file access object here may be the address information carried by the file access object in the file access request.
[0146] Step S208, searching for address information matching the address information to be verified in the address information list stored in the permission access contract, and obtaining the address information search result.
[0147] The address information list here can be the above Figure 3 In step S104 of the corresponding embodiment, the blockchain node obtains the address information of the file receiving object of the original file, and performs information statistics on the obtained address information. It should be understood that the address information list contains the address information of all file access objects that are allowed to be accessed as stipulated by all permission access contracts. Therefore, when a file access object (for example, user U1) accesses an encrypted file stored in a permission access contract, the blockchain node can search and compare the address information carried in the file access request sent by the file access object (for example, user U1) based on the address information list, thereby determining the access rights of the file access object (for example, user U1).
[0148] Step S209: If the address information search result indicates that there is address information matching the address information to be verified in the address information list, it is determined that the file access object permission verification is successful.
[0149] Step S210, after the authority verification is passed, the first storage location, the second storage location, and the decryption method of the first encryption key are sent to the file access object.
[0150] For details, see Figure 6 , Figure 6 Schematic diagram of a method for verifying access rights of a file access object provided by an embodiment of the present application. Figure 6 As shown, user 61b can be the above-mentioned file access object, and user terminal 61a can be the terminal device corresponding to user 61b. In addition, blockchain node 60a can correspond to the above-mentioned Figure 2 The blockchain node 20a in the corresponding embodiment.
[0151] like Figure 6 As shown, user 61b sends a file access request through user terminal 61a, where Figure 6 As shown, the file access request includes address information x. Further, the blockchain node 60a receives the file access request including address information x, and then obtains the address information x from the file access request, thereby searching for the address information x in the address information list 600a stored in the permission access contract deployed on the blockchain.
[0152] Specifically, Figure 6As shown, it can be seen that the address information list 600a contains address information 101, address information 102, …, address information n. The blockchain node 60a traverses all the address information in the address information list 600a to obtain the search result. Further, as Figure 6 shown, the blockchain node 60a finds that the address information 102 matches the address of the address information x. In other words, the address information x and the address information 102 have the same address. This means that the blockchain node can determine that the user 61b is the object authorized by the permission access contract, and the user 61b has the permission to receive the encrypted file. That is to say, the permission verification of the user 61b passes. The method used in the above search process can be an access permission verification method, which is used to search for the address information that matches the file access object (for example, the user 61b) in the address information list, so as to determine the access permission of the file access object (for example, the user 61b).
[0153] Further, after the blockchain node 60a determines that the permission verification of the user 61b passes, the blockchain node 60a can send the first storage location, the second storage location, and the decryption method of the first encryption key in the permission verification contract deployed in the blockchain to the user 61b.
[0154] Step S211, if the address information search result indicates that there is no address information in the address information list that matches the address information to be verified, it is determined that the permission verification of the file access object fails.
[0155] Step S212, generate a deny access notice and return the deny access notice to the file access object.
[0156] Specifically, described with the above Figure 6 corresponding embodiment, the blockchain node 60a uses the permission verification method to traverse and search for the address information that matches the address information x in the address information list 600a. After the traversal ends, no address information that matches the address information x is found. This means that the above file receiving object does not include the user 61b. That is to say, the user 61b is not the object specified by the file sending object to share. At this time, the blockchain node 60a determines that the user 61b is not the object authorized by the permission access contract, and the user 61b has the permission to receive the encrypted file. That is to say, the permission verification of the user 61b fails.
[0157] Further, the blockchain node 60a generates a denial-of-access notice and returns the denial-of-access notice to the user 61b. The denial-of-access notice is used to inform the user 61b that they do not have access rights and to stop the access. This means that the blockchain node 60a does not send to the user 61b the first storage location, the second storage location, and the decryption method of the first encryption key in the permission verification contract deployed in the blockchain.
[0158] It can be seen that in the embodiments of the present application, when a blockchain node obtains a file decryption key for an encrypted file, it can obtain the number of file receiving objects, and based on the number of file receiving objects, determine an encryption method for encrypting the file decryption key. Furthermore, the file encryption key can be encrypted using this encryption method to obtain an encrypted file decryption key, that is, a first encryption key. This means that in the embodiments of the present application, by encrypting the file decryption key again, such a dual encryption mechanism can effectively protect the file decryption key, prevent illegal objects from obtaining the file decryption key, and thus ensure the security of the file decryption key at the source. In addition, the blockchain node will store the first encryption key in a first storage location, where the first storage location is a trusted execution environment. The use of the first encryption key will only be executed in the trusted execution environment, and the first encryption key will never leave the trusted execution environment. Therefore, even if an illegal object obtains the first encryption key, the illegal object cannot cause the trusted execution environment to decrypt the first encryption key to obtain the file decryption key, which can further ensure the security of the first encryption key with high strength. Further, the blockchain node can obtain the first storage location, a second storage location for the encrypted file, and the address information of the file receiving object for the original file, and perform information statistics on the obtained address information to obtain an address information list corresponding to the file receiving object. Furthermore, based on the first storage location, the second storage location, and the address information list, a permission access contract with a permission management logic is created, and the first storage location, the second storage location, and the address information list are added to the permission access contract. Further, the blockchain node obtains the address information of the file access object, searches for the address information in the address information list stored in the permission access contract, and when it determines that the address information that matches the address information is found, it can determine that the permission verification of the file access object has passed. Furthermore, the blockchain node can send the first storage location, the second storage location, and the decryption method of the first encryption key to the above-mentioned file access object. In addition, if the address information that matches the address information is not found, it can be determined that the permission verification of the file access object has not passed, and the blockchain node generates a denial of access notice and returns the denial of access notice to the file access object. This means that the high-strength permission verification mechanism of the permission access contract for the file access object can further protect the possibility of the file decryption key being illegally obtained. It can be seen that through the key encryption method, storing the first encryption key in the trusted execution environment, and creating a permission access contract, the present application can protect the file decryption key multiple times and improve its security. When the file decryption key has high security, the possibility of the original file being illegally decrypted and spread is very low, thereby improving the security of the original file.
[0159] Further, when it is determined that the permission verification of the file access object passes, the file access object decrypts and obtains the original file through the decryption method of the first encryption key, the first storage location, and the second storage location.
[0160] Among them, since the encryption method of the above-mentioned first encryption key is determined by the number of file receiving objects, the decryption method of the first encryption key here is correspondingly also determined by the number of file receiving objects. Therefore, for the file access object to decrypt and obtain the original file through the decryption method of the first encryption key, the first storage location, and the second storage location, the following two situations are included:
[0161] Situation 1, the number of the above-mentioned file receiving objects is single. At this time, the file access object is the same as the file receiving object. According to the above Figure 3 description of step S102 in the corresponding embodiment, the key encryption key for encrypting the file decryption key is the public key of the file receiving object, that is, the public key of the file access object. At this time, the blockchain node will access the file access object to obtain the private key of the file access object, and then decrypt the first encryption key through the private key of the file access object.
[0162] Situation 2, the number of the above-mentioned file receiving objects is at least two. At this time, the file access object is one of the multiple file receiving objects. According to the above Figure 3 description of step S102 in the corresponding embodiment, the key encryption key for encrypting the file decryption key is the encryption key in the key pair generated by the key generation algorithm jointly determined by the blockchain node through multiple file receiving objects. That is, at this time, the key for decrypting the first encryption key is the decryption key in the key pair generated by the key generation algorithm. And at this time, the decryption key is stored in the first storage location together with the first encryption key. This means that the blockchain node can directly obtain the decryption key in the key pair generated by the key generation algorithm, and then decrypt the first encryption key through the decryption key.
[0163] For the convenience of understanding, in the embodiments of the present application, the keys for decrypting the first encryption key in Situation 1 and Situation 2 are collectively referred to as key decryption keys.
[0164] Among them, it can be understood that the above process of decrypting the first encryption key is all executed in the first storage location, that is, the process of decrypting the first encryption key is all executed in the trusted execution environment. Specifically, the trusted execution environment will execute a trusted program for key management, decrypt the first encryption key based on the obtained key decryption key, so as to obtain the decrypted first encryption key, that is, the file decryption key, and then return the file decryption key to the file access object.
[0165] Specifically, please refer to Figure 7 , Figure 7 which is a schematic diagram of a file access object provided by an embodiment of the present application for obtaining an original file. As Figure 7 shown, the blockchain node 70a can be the blockchain node 20a in the corresponding embodiment above, the user 71b can be the user 61b in the corresponding embodiment of Figure 2 , that is, the file access object, and the user terminal 71a is the terminal device corresponding to the user 71b (i.e., the file access object), which can correspond to the user terminal 61a in the corresponding embodiment of Figure 6 above. Figure 6 After the permission verification of the user 61b by the blockchain node 60a in the corresponding embodiment above is passed, correspondingly, here the permission verification of the user 71b by the blockchain node 70a is passed. As
[0166] shown, the blockchain node 70a sends the first storage location, the second storage location, and the decryption method of the first encryption key to the user terminal 71a corresponding to the user 71b. Among them, the first storage location is the above-mentioned trusted execution environment, the first encryption key is stored in the trusted execution environment, and the encrypted file is stored in the second storage location. Figure 6 Furthermore, the user 71b receives the first storage location, the second storage location, and the decryption method of the first encryption key. At this time, the user 71b learns that the decryption method of the first encryption key is a method of decrypting based on a key decryption key, and it is executed by the first storage location, that is, executed by the trusted execution environment. At this time, the user 71b will send a decryption request to the blockchain node 70a through the user terminal 71a to obtain the file decryption key. From the above description, the processing of the file decryption key is executed by the trusted program in the trusted execution environment. When the user 71b sends a decryption request to the blockchain node 70a through the user terminal 71a, it is sent to the first storage location (i.e., the trusted execution environment) in the permission access contract deployed by the blockchain node 70a. At this time, the user 71b will access the relevant interface (such as the access interface) through the access method jointly determined by the above step S103 (for example, the facial information of the user 71b), so that the trusted execution environment determines that the user 71b is a user who can initiate the decryption process of the first encryption key. At this time, the trusted execution environment executes the relevant program. It should be understood that the trusted execution environment will execute the trusted program to decrypt the first encryption key into the file decryption key, as Figure 7 shown.
[0167] shown. Figure 7As shown, the steps include: blockchain node 70a obtains a key decryption key for decrypting the first encryption key. It should be understood that, as described above, the key decryption key will be different due to the number of file receiving objects. Here, it is assumed that the number of file receiving objects is single, that is, user 71b is the file receiving object. At this time, the blockchain obtains the private key of user 71b by accessing the user terminal 71a corresponding to user 71b. Further, the private key is used as a key decryption key, and the trusted program in the trusted execution environment uses the private key to decrypt the first encryption key, as shown in FIG. Figure 7 As shown, the file decryption key is obtained by decryption. Further, the trusted execution environment outputs the result of the decryption process, that is, the file decryption key.
[0168] Furthermore, the blockchain node 70a sends the file decryption key to the user terminal 71a corresponding to the user 71b. The user terminal 71a corresponding to the user 71b obtains the file decryption key sent by the blockchain node 70a, and decrypts the encrypted file in the second storage location obtained above based on the file decryption key. Specifically, Figure 7 As shown, user 71b uses the file decryption key to decrypt the first encryption key through user terminal 71a, thereby obtaining Figure 7 Original file shown.
[0169] For further information, see Figure 8 , Figure 8 is a timing diagram of a data processing method based on blockchain provided in an embodiment of the present application, such as Figure 8 As shown, the method can be Figure 1 Any terminal device in the sender terminal device cluster in the corresponding embodiment, any blockchain node in the blockchain network, and any terminal device in the sender terminal device cluster interact and execute. The method may specifically include the following steps S301-S314.
[0170] Step S301: The sending terminal encrypts the original file to obtain an encrypted file.
[0171] Step S302: The sending terminal sends the encrypted file to the blockchain node.
[0172] Step S303, the blockchain node obtains the file decryption key for the encrypted file.
[0173] Step S304: The receiving terminal determines a key generation algorithm.
[0174] Step S305: The receiving terminal sends the determined key generation algorithm to the blockchain node.
[0175] Step S306: The blockchain node encrypts the file decryption key to obtain a first encryption key corresponding to the file decryption key.
[0176] Step S307: The blockchain node stores the first encryption key in a first storage location.
[0177] Step S308: The blockchain node obtains a second storage location of the encrypted file and the file recipient of the original file, creates a permission access contract through the first storage location, the second storage location, and the file recipient, and deploys the permission access contract on the blockchain.
[0178] Among them, for the specific implementation manners of steps S301 - S308, reference can be made to the descriptions of steps S101 - S104 in the corresponding embodiments above, and details will not be elaborated here. Figure 3 The descriptions of steps S101 - S104 in the corresponding embodiments above will not be repeated here.
[0179] Step S309: The receiving terminal generates a file access request for the original file.
[0180] Step S310: The receiving terminal sends the file access request to the blockchain node.
[0181] Step S311: The blockchain node invokes the permission access contract based on the file access request to verify the permissions of the file access object.
[0182] Step S312: The blockchain node determines that the permission verification of the file access object passes.
[0183] Among them, for the specific implementation manners of steps S309 - S312, reference can be made to the descriptions of steps S205 - S209 in the corresponding embodiments above, and details will not be elaborated here. Figure 5 The descriptions of steps S205 - S209 in the corresponding embodiments above will not be repeated here.
[0184] Step S313: The blockchain node sends the first storage location, the second storage location, and the decryption method of the first encryption key to the receiving terminal.
[0185] Step S314: The sending terminal decrypts and obtains the original file through the decryption method of the first encryption key, the first storage location, and the second storage location.
[0186] Among them, for the specific implementation manners of steps S313 - S314, reference can be made to the descriptions in the corresponding embodiments above, and details will not be elaborated here. Figure 7 The descriptions in the corresponding embodiments above will not be repeated here.
[0187] It can be seen that in the embodiments of the present application, the file sending object can encrypt the original file through the sending terminal to obtain an encrypted file, and then send the encrypted file to the blockchain node. In this way, the blockchain node can obtain the above encrypted file and the file decryption key for the encrypted file. Further, the file receiving object will determine the key generation algorithm and send the determined key generation algorithm to the blockchain node through the receiving terminal. Then, the blockchain node generates a key pair based on the above key generation algorithm and encrypts the file decryption key to obtain the first encrypted key. This means that in the embodiments of the present application, by encrypting the file decryption key again, such a double encryption mechanism can effectively protect the file decryption key and prevent illegal objects from obtaining the file decryption key, thereby ensuring the security of the file decryption key at the root. In addition, the blockchain node stores the first encrypted key in the first storage location, where the first storage location is a trusted execution environment. The use of the first encrypted key will only be executed in the trusted execution environment, and the first encrypted key will never leave the trusted execution environment. Therefore, even if an illegal object obtains the first encrypted key, the illegal object cannot make the trusted execution environment decrypt the first encrypted key to obtain the file decryption key, which can further protect the security of the first encrypted key with high strength. Further, the blockchain node can create a permission access contract with permission management logic based on the first storage location, the second storage location, and the address information list, and add the first storage location, the second storage location, and the address information list to the permission access contract. It can be understood that through the permission access contract, the above file access object can be verified for permissions, and only the objects that pass the verification can obtain the above first storage location, the second storage location, and the decryption method after encryption of the file decryption key, so as to decrypt and obtain the original file. This means that the high-strength permission verification mechanism of the permission access contract for the file access object can further protect the possibility of the file decryption key being illegally obtained. It can be seen that through the key encryption method, storing the first encrypted key in the trusted execution environment, and creating the permission access contract, the present application can protect the file decryption key multiplicatively and improve its security. When the file decryption key has high security, the possibility of the original file being illegally decrypted and spread is very low, thereby improving the security of the original file.
[0188] Further, please refer to Figure 9 , Figure 9 which is a schematic structural diagram of a blockchain-based data processing device provided by an embodiment of the present application. As Figure 9As shown in the figure, the blockchain-based data processing device 1 can be applied to a blockchain node in a blockchain network. It should be understood that the blockchain-based data processing device 1 can be a computer program (including program code) running in a blockchain node (for example, the aforementioned blockchain node 11a). For example, the blockchain-based data processing device 1 can be an application software. It can be understood that the blockchain-based data processing device 1 can be used to execute the corresponding steps in the method provided in the embodiments of the present application. As Figure 9 shown in the figure, the blockchain-based data processing device 1 may include: a key acquisition module 11, an encryption processing module 12, a key storage module 13, and a contract creation module 14;
[0189] The key acquisition module 11 is used to acquire a file decryption key for an encrypted file; the encrypted file is obtained by encrypting an original file with a file encryption key; the file decryption key is used to decrypt the encrypted file to restore the original file;
[0190] The encryption processing module 12 is used to perform encryption processing on the file decryption key to obtain a first encryption key corresponding to the file decryption key;
[0191] The key storage module 13 is used to store the first encryption key in a first storage location;
[0192] The contract creation module 14 is used to obtain a second storage location of the encrypted file and a file receiving object of the original file, create a permission access contract through the first storage location, the second storage location, and the file receiving object, and deploy the permission access contract to the blockchain; the permission access contract deployed to the blockchain is used to perform permission verification on the file access object of the original file, and after the permission verification is passed, send the first storage location, the second storage location, and the decryption method of the first encryption key to the file access object, and the file access object decrypts and obtains the original file through the decryption method of the first encryption key, the first storage location, and the second storage location.
[0193] Among them, for the specific implementation manners of the key acquisition module 11, the encryption processing module 12, the key storage module 13, and the contract creation module 14, reference can be made to the descriptions of steps S101 - S104 in the corresponding embodiments above, and details will not be elaborated here. Figure 3 As described in the corresponding embodiments of steps S101 - S104 above, no further elaboration will be provided here.
[0194] Among them, the encryption processing module 12 includes:
[0195] A quantity statistics unit 121 is used to count the quantity of file receiving objects of the original file;
[0196] The encryption method determining unit 122 is used to determine the encryption method used to encrypt the file decryption key based on the number of file receiving objects;
[0197] The decryption key encryption unit 123 is used to encrypt the file decryption key in an encryption manner to obtain the encrypted file decryption key, and use the encrypted file decryption key as the first encryption key.
[0198] The specific implementation of the quantity counting unit 121, the encryption method determining unit 122 and the decryption key encryption unit 123 can be found in the above Figure 3 The description of step S102 in the corresponding embodiment will not be repeated here.
[0199] The encryption mode determination unit 122 includes:
[0200] The first encryption mode determination subunit 1221 is used to determine the encryption mode as a public key encryption mode if it is determined that the number of file receiving objects is a single one;
[0201] The second encryption mode determination subunit 1222 is configured to determine the encryption mode as an encryption mode based on a key generation algorithm if it is determined that the number of the file receiving objects is at least two.
[0202] The specific implementation of the first encryption mode determination subunit 1221 and the second encryption mode determination subunit 1222 can be referred to above. Figure 3 The description of step S102 in the corresponding embodiment will not be repeated here.
[0203] Among them, the encryption method is public key encryption;
[0204] The decryption key encryption unit 123 comprises:
[0205] The key encryption key determination subunit 1231 is used to obtain the public key of the file receiving object based on the public key encryption method, and use the public key as the key encryption key of the file decryption key;
[0206] The first encryption subunit 1232 is used to encrypt the file decryption key using the key encryption key of the file decryption key to obtain the encrypted file decryption key.
[0207] The specific implementation of the key encryption key determination subunit 1231 and the first encryption subunit 1232 can be found in the above Figure 3 The description of step S102 in the corresponding embodiment will not be repeated here.
[0208] The encryption method is an encryption method based on a key generation algorithm;
[0209] The decryption key encryption unit 123 includes:
[0210] The key generation algorithm determination subunit 1233 is configured to obtain, through an encryption method based on a key generation algorithm, the key generation algorithm jointly determined by at least two file receiving objects; the key generation algorithm includes a symmetric encryption algorithm or an asymmetric encryption algorithm;
[0211] The key pair generation subunit 1234 is configured to generate a key pair through the key generation algorithm; the key pair includes a key encryption key for the file decryption key and a key decryption key for the first encryption key;
[0212] The second encryption subunit 1235 is configured to encrypt the file decryption key by using the key encryption key for the file decryption key included in the key pair to obtain the encrypted file decryption key.
[0213] Among them, for the specific implementation manners of the key generation algorithm determination subunit 1233, the key pair generation subunit 1234, and the second encryption subunit 1235, reference may be made to the descriptions in the corresponding embodiments above, and details will not be elaborated here. Figure 4 Herein, the first storage location refers to a trusted execution environment; the trusted execution environment includes a trusted program for key management, and the operating system of the trusted execution environment has isolation properties;
[0214] The key storage module 13 includes:
[0215] The key storage unit 131 is configured to store the first encryption key into the trusted execution environment.
[0216] Among them, for the specific implementation manner of the key storage unit 131, reference may be made to the description of step S103 in the corresponding embodiment above, and details will not be elaborated here.
[0217] Among them, the contract creation module 14 includes: Figure 3 The storage location acquisition unit 141 is configured to acquire the first storage location and the second storage location;
[0218] The address information statistics unit 142 is configured to acquire the address information of the file receiving object of the original file, perform information statistics on the acquired address information, and obtain the address information list corresponding to the file receiving object;
[0219] The intelligent contract creation unit 143 is configured to create an intelligent contract with permission management logic based on the first storage location, the second storage location, and the address information list;
[0220]
[0221]
[0222]
[0222] An information adding unit 144 for adding the first storage location, the second storage location, and the address information list to the smart contract;
[0223] A permission access contract determination unit 145 for using the smart contract as a permission access contract.
[0224] Among them, for the specific implementation manners of the storage location acquisition unit 141, the address information statistics unit 142, the smart contract creation unit 143, the information adding unit 144, and the permission access contract determination unit 145, reference can be made to the above Figure 3 corresponding embodiments for step S104, and details will not be elaborated here.
[0225] Optionally, the apparatus 1 further includes: a request receiving module 15, a contract calling module 16, a permission verification module 17, and an information sending module 18;
[0226] The request receiving module 15 is configured to receive a file access request of a file access object of the original file; the file access request is used to request to obtain the original file;
[0227] The contract calling module 16 is configured to call the permission access contract based on the file access request;
[0228] The permission verification module 17 is configured to perform permission verification on the file access object through the permission access contract;
[0229] The information sending module 18 is configured to, after the permission verification is passed, send the first storage location, the second storage location, and the decryption method of the first encryption key to the file access object.
[0230] Among them, for the specific implementation manners of the request receiving module 15, the contract calling module 16, the permission verification module 17, and the information sending module 18, reference can be made to the above Figure 6 description of the specific process of verifying the access permission of user 61a in the corresponding embodiments, and details will not be elaborated here.
[0231] Among them, the permission verification module 17 includes:
[0232] An address information acquisition unit 171 for acquiring the address information of the file access object and using the address information as the address information to be verified;
[0233] An address information search unit 172 for searching for the address information matching the address information to be verified in the address information list stored in the permission access contract to obtain an address information search result;
[0234] The first permission verification unit 173 is configured to determine that the file access object permission verification is passed if the address information lookup result indicates that there is address information in the address information list that matches the address information to be verified.
[0235] Among them, for the specific implementation manners of the address information acquisition unit 171, the address information lookup unit 172, and the first permission verification unit 173, reference can be made to the description of the specific process of verifying the access permission of user 61a in the corresponding embodiment above, and details will not be elaborated here. Figure 6 For the specific process of verifying the access permission of user 61a in the corresponding embodiment above, details will not be elaborated here.
[0236] Optionally, the permission verification module 17 further includes:
[0237] The second permission verification unit 174 is configured to determine that the file access object permission verification fails if the address information lookup result indicates that there is no address information in the address information list that matches the address information to be verified;
[0238] The access rejection notice generation unit 175 is configured to generate an access rejection notice and return the access rejection notice to the file access object.
[0239] Among them, for the specific implementation manners of the second permission verification unit 174 and the access rejection notice generation unit 175, reference can be made to the description of the specific process of generating an access rejection notice for user 61a in the corresponding embodiment above, and details will not be elaborated here. Figure 6 For the specific process of generating an access rejection notice for user 61a in the corresponding embodiment above, details will not be elaborated here.
[0240] Among them, the decryption method of the first encryption key is determined by the number of file receiving objects;
[0241] When the number of file receiving objects is one, the key encryption key of the file decryption key is the public key of the file receiving object, the key decryption key of the first encryption key refers to the private key of the file receiving object, and the decryption method of the first encryption key refers to the method of decrypting using the private key of the file receiving object;
[0242] When the number of file receiving objects is at least two, the key encryption key of the file decryption key is the encryption key in the key pair generated based on the key generation algorithm; the key generation algorithm is jointly determined by multiple file receiving objects; the key decryption key of the first encryption key refers to the decryption key in the key pair generated based on the key generation algorithm, and the decryption method of the first encryption key refers to the method of decrypting using the decryption key in the key pair generated based on the key generation algorithm.
[0243] Further, please refer to Figure 10 , Figure 10 which is a schematic structural diagram of a computer device provided by an embodiment of the present application. As Figure 10As shown, the computer device 1000 can be a user terminal. For example, the terminal device 10a in the corresponding embodiment mentioned above, or it can also be a server. For example, the server 10d in the corresponding embodiment mentioned above. Here, no limitation will be imposed on it. For the sake of understanding, this application takes the computer device as a user terminal as an example. The computer device 1000 may include: a processor 1001, a network interface 1004, and a memory 1005. In addition, the computer device 1000 may further include: a user interface 1003, and at least one communication bus 1002. Among them, the communication bus 1002 is used to realize the connection and communication between these components. Among them, the user interface 1003 may further include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface). The memory 1005 can be a high-speed RAM memory, or a non-volatile memory, for example, at least one disk memory. The memory 1005 may optionally also be at least one storage device located far from the aforementioned processor 1001. As Figure 1 shown, in the memory 1005, which is a computer-readable storage medium, there may be included an operating system, a network communication module, a user interface module, and a device control application program. Figure 1 As shown, the computer device 1000 can be a user terminal. For example, the terminal device 10a in the corresponding embodiment mentioned above, or it can also be a server. For example, the server 10d in the corresponding embodiment mentioned above. Here, no limitation will be imposed on it. For the sake of understanding, this application takes the computer device as a user terminal as an example. The computer device 1000 may include: a processor 1001, a network interface 1004, and a memory 1005. In addition, the computer device 1000 may further include: a user interface 1003, and at least one communication bus 1002. Among them, the communication bus 1002 is used to realize the connection and communication between these components. Among them, the user interface 1003 may further include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface). The memory 1005 can be a high-speed RAM memory, or a non-volatile memory, for example, at least one disk memory. The memory 1005 may optionally also be at least one storage device located far from the aforementioned processor 1001. As Figure 10 shown, in the memory 1005, which is a computer-readable storage medium, there may be included an operating system, a network communication module, a user interface module, and a device control application program.
[0244] Among them, the network interface 1004 in the computer device 1000 can also provide network communication functions, and optionally the user interface 1003 may further include a display screen (Display) and a keyboard (Keyboard). In Figure 10 the computer device 1000 shown, the network interface 1004 can provide network communication functions; while the user interface 1003 is mainly used to provide an input interface for the user; and the processor 1001 can be used to call the device control application program stored in the memory 1005 to execute the description of the blockchain-based data processing method in the previous Figure 3 、 Figure 5 and Figure 8 corresponding embodiments, and can also execute the description of the blockchain-based data processing device 1 in the previous Figure 9 corresponding embodiments, which will not be elaborated here. In addition, the description of the beneficial effects of adopting the same method will not be elaborated either.
[0245] In addition, it should be pointed out here that: The embodiments of this application also provide a computer-readable storage medium, and the computer-readable storage medium stores the computer program executed by the aforementioned blockchain-based data processing device 1, and the computer program includes computer instructions. When the processor executes the computer instructions, it can execute the previous Figure 3 、 Figure 5 andFigure 8 The description of the data processing method for the blockchain in the corresponding embodiment will not be repeated here. In addition, the description of the beneficial effects of using the same method will not be repeated either. For the technical details not disclosed in the embodiment of the computer-readable storage medium involved in this application, please refer to the description of the method embodiment of this application. As an example, the computer instructions can be deployed to be executed on a computing device, or on multiple computing devices located at one place, or on multiple computing devices distributed at multiple places and interconnected through a communication network. The multiple computing devices distributed at multiple places and interconnected through a communication network can form a blockchain system.
[0246] In addition, it should be noted that: The embodiment of this application also provides a computer program product or a computer program. The computer program product or the computer program may include computer instructions, and the computer instructions can be stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor can execute the computer instructions, so that the computer device executes the Figure 3 , Figure 5 and Figure 8 description of the data processing method in the corresponding embodiments, so it will not be repeated here. In addition, the description of the beneficial effects of using the same method will not be repeated either. For the technical details not disclosed in the embodiment of the computer program product or the computer program involved in this application, please refer to the description of the method embodiment of this application.
[0247] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, some steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to this application.
[0248] The steps in the method embodiments of this application can be adjusted, combined, and deleted according to actual needs.
[0249] The modules in the device embodiments of this application can be combined, divided, and deleted according to actual needs.
[0250] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above various methods. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM), etc.
[0251] The above-disclosed are only the preferred embodiments of the present application. Of course, the scope of rights of the present application cannot be limited thereby. Therefore, equivalent changes made according to the claims of the present application still fall within the scope covered by the present application.
Claims
1. A data processing method based on blockchain, characterized in that, the method includes: Obtaining a file decryption key for an encrypted file; the encrypted file is obtained by encrypting an original file with a file encryption key; the file decryption key is used to decrypt and restore the encrypted file to obtain the original file; Performing an encryption process on the file decryption key to obtain a first encryption key corresponding to the file decryption key; Storing the first encryption key in a first storage location; Obtaining a second storage location of the encrypted file and a file receiving object of the original file, creating a permission access contract through the first storage location, the second storage location, and the file receiving object, and deploying the permission access contract on the blockchain; the permission access contract deployed on the blockchain is used to perform permission verification on a file access object of the original file, and after the permission verification is passed, send the first storage location, the second storage location, and the decryption method of the first encryption key to the file access object, and the file access object decrypts and obtains the original file through the decryption method of the first encryption key, the first storage location, and the second storage location.
2. The method according to claim 1, characterized in that, the performing an encryption process on the file decryption key to obtain a first encryption key corresponding to the file decryption key includes: Counting the number of file receiving objects of the original file; Based on the number of file receiving objects, determining an encryption method for encrypting the file decryption key; Using the encryption method to encrypt the file decryption key to obtain an encrypted file decryption key, and taking the encrypted file decryption key as the first encryption key.
3. The method according to claim 2, characterized in that, the based on the number of file receiving objects, determining an encryption method for encrypting the file decryption key includes: If it is determined that the number of file receiving objects is single, determining the encryption method as a public key encryption method; If it is determined that the number of file receiving objects is at least two, determining the encryption method as an encryption method based on a key generation algorithm.
4. The method according to claim 2, characterized in that, the encryption method is a public key encryption method; the using the encryption method to encrypt the file decryption key to obtain an encrypted file decryption key includes: Based on the public key encryption method, obtaining the public key of the file receiving object, and taking the public key as the key encryption key of the file decryption key; Using the key encryption key of the file decryption key to encrypt the file decryption key to obtain an encrypted file decryption key.
5. The method according to claim 2, characterized in that, the encryption method is an encryption method based on a key generation algorithm; the using the encryption method to encrypt the file decryption key to obtain an encrypted file decryption key includes: Obtain the key generation algorithm jointly determined by at least two file receiving objects through the encryption method based on the key generation algorithm; the key generation algorithm includes a symmetric encryption algorithm or an asymmetric encryption algorithm; Generate a key pair through the key generation algorithm; the key pair includes the key encryption key of the file decryption key and the key decryption key of the first encryption key; Use the key encryption key of the file decryption key included in the key pair to encrypt the file decryption key to obtain the encrypted file decryption key.
6. The method according to claim 1, wherein, The first storage location refers to a trusted execution environment; the trusted execution environment includes a trusted program for key management, and the operating system of the trusted execution environment has isolation; The storing the first encryption key in the first storage location includes: Storing the first encryption key in the trusted execution environment.
7. The method according to claim 1, wherein, The obtaining the second storage location of the encrypted file and the file receiving object of the original file, and creating a permission access contract through the first storage location, the second storage location and the file receiving object includes: Obtain the first storage location and the second storage location; Obtain the address information of the file receiving object of the original file, perform information statistics on the obtained address information to obtain the address information list corresponding to the file receiving object; Create an intelligent contract with permission management logic based on the first storage location, the second storage location and the address information list; Add the first storage location, the second storage location and the address information list to the intelligent contract; Use the intelligent contract as the permission access contract.
8. The method according to claim 1, wherein, After deploying the permission access contract to the blockchain, the method further includes: Receive a file access request from the file access object of the original file; the file access request is used to request to obtain the original file; Call the permission access contract based on the file access request; Perform permission verification on the file access object through the permission access contract; After the permission verification is passed, send the first storage location, the second storage location, and the decryption method of the first encryption key to the file access object.
9. The method according to claim 8, wherein, The performing permission verification on the file access object through the permission access contract includes: Obtain the address information of the file access object, and use the address information as the address information to be verified; In the address information list stored in the permission access contract, search for the address information that matches the address information to be verified to obtain an address information search result; If the address information search result indicates that there is address information in the address information list that matches the address information to be verified, it is determined that the permission verification of the file access object is passed.
10. The method according to claim 9, Characterized in that, After obtaining the address information lookup result, the method further includes: If the address information lookup result indicates that there is no address information in the address information list that matches the address information to be verified, it is determined that the file access object permission verification fails; Generate a denial of access notice and return the denial of access notice to the file access object.
11. The method according to claim 1, Characterized in that, The decryption method of the first encryption key is determined by the number of file receiving objects; When the number of file receiving objects is one, the key encryption key of the file decryption key is the public key of the file receiving object, the key decryption key of the first encryption key refers to the private key of the file receiving object, and the decryption method of the first encryption key refers to the method of decrypting with the private key of the file receiving object; When the number of file receiving objects is at least two, the key encryption key of the file decryption key is the encryption key in the key pair generated based on the key generation algorithm; the key generation algorithm is jointly determined by multiple file receiving objects; the key decryption key of the first encryption key refers to the decryption key in the key pair generated based on the key generation algorithm, and the decryption method of the first encryption key refers to the method of decrypting with the decryption key in the key pair generated by the key generation algorithm.
12. A blockchain-based data processing device, Characterized in that, The device includes: A key acquisition module for acquiring a file decryption key for an encrypted file; the encrypted file is obtained by encrypting an original file with a file encryption key; the file decryption key is used to decrypt the encrypted file to restore the original file; An encryption processing module for encrypting the file decryption key to obtain a first encryption key corresponding to the file decryption key; A key storage module for storing the first encryption key in a first storage location; A contract deployment module for obtaining a second storage location of the encrypted file and file receiving objects of the original file, creating a permission access contract through the first storage location, the second storage location, and the file receiving objects, and deploying the permission access contract to the blockchain; the permission access contract deployed to the blockchain is used to verify the permissions of the file access object of the original file, and after the permission verification is passed, send the first storage location, the second storage location, and the decryption method of the first encryption key to the file access object, and the file access object decrypts and obtains the original file through the decryption method of the first encryption key, the first storage location, and the second storage location.
13. A computer device, Characterized in that, It includes a memory and a processor; The memory is connected to the processor, the memory is used to store a computer program, and the processor is used to call the computer program so that the computer device executes the method according to any one of claims 1-11.
14. A computer-readable storage medium, characterized in that, a computer program is stored in the computer-readable storage medium, and the computer program is adapted to be loaded and executed by a processor, so that a computer device having the processor executes the method according to any one of claims 1-11.
15. A computer program product, characterized in that, it includes computer programs / instructions, and when the computer programs / instructions are executed by a processor, the method according to any one of claims 1-11 is implemented.