Method, device and equipment for protecting privacy of smart contract of block chain
By adding privacy annotations and homomorphic encryption technology to blockchain smart contracts, the data of external private owners is protected, and the problem of smart contracts being executed without leaking private data is solved, and secure data transactions are achieved.
Patent Information
- Application Number
- CN202311665750.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-06
- Publication Date
- 2025-06-06
AI Technical Summary
In blockchain smart contracts, how to execute smart contracts without leaking private data, especially the issue of allowing operations on external values.
By adding privacy comments to smart contracts, parsing the privacy types in function statements, and using homomorphic encryption to encrypt the addition and subtraction expressions of external privateers, completing the contract conversion, and adding NIZK proof to the converted contract to verify equivalence.
It realizes secure data transactions between smart contract callers and external private owners, ensures the protection of private data and avoids privacy data leakage.
Smart Images

Figure CN120105441A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of blockchain technology, and in particular to a method, device and equipment for protecting the privacy of blockchain smart contracts. Background Art
[0002] In recent years, smart contracts have gained great popularity. They are programs deployed on top of blockchains that enable trusted execution without a trusted third party. In order to benefit from unmediated trusted execution, many real-world processes (e.g., trading or insurance) are being ported to smart contracts. When implementing applications in smart contracts, there is a great concern about data privacy: smart contract transactions are processed by blockchain nodes, which requires that the operations and data of the transaction are available to all nodes. This poses a privacy risk for applications that process sensitive data.
[0003] If the function statement called in the smart contract includes addition and subtraction expressions, and the addition and subtraction expressions include data belonging to external private owners, such operations are not allowed by the smart contract caller. How to ensure that the smart contract is executed without leaking private data and allow operations on external values requires a corresponding solution. Summary of the invention
[0004] The purpose of this application is to provide a method, device and equipment for privacy protection of blockchain smart contracts, which is used to solve the problem of how to ensure that smart contracts are executed without leaking private data and allow operations on external values in related technologies.
[0005] In a first aspect, an embodiment of the present application provides a method for protecting the privacy of a blockchain smart contract, the method comprising:
[0006] According to the privacy data annotation specification, privacy annotations are added to the data in the original smart contract to obtain a standard smart contract, where the privacy annotations are used to indicate the owner of the data;
[0007] Traversing the canonical smart contract, parsing the privacy type of expressions in function statements based on privacy annotations;
[0008] The function statement is converted into a contract based on the smart contract conversion rules. For the addition and subtraction expressions whose privacy type is external private, the public key of the external private owner is used to encrypt each operation item in the addition and subtraction expression using homomorphic encryption to complete the contract conversion of the function statement where the addition and subtraction expression is located;
[0009] Add a NIZK proof in the converted contract to verify that the converted function statement is equivalent to the original function statement;
[0010] After the traversal is completed, the converted contract is put on the chain to conduct transactions based on the converted contract.
[0011] In one or more possible embodiments, adding a privacy annotation to the private data in the original smart contract includes at least one of the following steps:
[0012] For variables that belong to private data, add a privacy identifier and the owner identifier of the variable after the data type of the variable in the original smart contract and before the variable;
[0013] For expression reclassification statements, add explicit comments that explicitly express the smart contract caller expression to another owner.
[0014] In one or more possible embodiments, the following privacy type determination rule is adopted to parse the privacy type of an expression in a function statement based on the privacy annotation:
[0015] If the owner of one operand of an expression in a function statement is public, and the owner of another operand is public, the privacy type of the expression is determined to be public;
[0016] If the owner of one operation item in the expression of the function statement is the smart contract caller, and the owner of the other operation item is public or the smart contract caller, the privacy type of the expression is determined to be self-owned;
[0017] If the owner of one operand in an expression in a function statement is external private, and the owner of another operand is the same external private or public, the privacy type of the expression is determined to be external private.
[0018] In one or more possible embodiments, the function statement includes a request statement and a variable assignment statement, and the privacy type of the expression in the function statement is parsed based on the privacy annotation, including:
[0019] For multiple expressions with recursive relationships in the function statement, the privacy type of each expression is recursively determined according to the recursive relationship of the expression operation, based on the privacy annotation and privacy type determination rules;
[0020] The function statements are converted to contracts based on the smart contract conversion rules, including:
[0021] For expressions with display comments in request statements, or expressions assigned in variable assignment statements, the expression of the top-level private owner in the expression is replaced with function parameters, where the owner of the private owner's expression is the smart contract caller or an external private owner;
[0022] Generate a constraint instruction for constructing a NIZK proof and add it to a constraint instruction set, wherein the constraint instruction is used to express an equivalence relationship between the plain text of the replaced expression and the function parameter;
[0023] Among them, when the privacy type of the expression of the function statement is public, the function parameter is equal to the plaintext of the replaced expression. When the privacy type of the expression of the function statement is external private or self-owned, the function parameter is equal to the ciphertext obtained by encrypting the plaintext of the private owner's expression using the public key of the external private owner or the public key of the smart contract caller.
[0024] In one or more possible embodiments, a NIZK proof is added to the converted contract to verify that the converted function statement is equivalent to the original function statement, including:
[0025] For the constraint instructions of the public function statement, it is equivalent to converting to use the decryption function T in the proof circuit plain Solve the plaintext of the replaced expression and prove the constraint that it is equal to the function argument;
[0026] For the constraint instructions of the self-owned function statement, it is equivalent to converting to use the decryption function T plain After solving the plain text of the replaced expression according to the decryption rules, the encrypted result is encrypted with the public key of the smart contract caller, which is equal to the proof constraint of the function parameter;
[0027] Convert the constraint instructions of the external private function statement into equivalent ones using the encryption function T α According to the encryption rules, each operation item in the plain text of the replaced expression is encrypted with the public key of the external private owner, and the proof constraint is equal to the function parameter;
[0028] Based on the proof constraints, a NIZK proof is added to verify that the converted function statement is equivalent to the original function statement.
[0029] In one or more possible embodiments, based on the proof constraint, a NIZK proof is added to verify that the converted function statement is equivalent to the original function statement, including:
[0030] For the initial parameters whose owner is an external private owner or the caller of the smart contract, the ciphertext value of the initial parameters encrypted with the public key of the external private owner or the public key of the caller of the smart contract, the public key of the external private owner, the public key of the caller of the smart contract, and the random number used for encryption are added to the proof function, and the private key of the caller of the smart contract is added to the proof function in a private manner;
[0031] According to the proof constraints of the public function statement, if the replaced expression contains the initial parameters of the smart contract caller, the initial parameter ciphertext value is obtained from the proof function, and the initial parameter ciphertext value is decrypted using the private key of the smart contract caller, and a proof statement is generated that the replaced expression is equal to the function parameter;
[0032] According to the proof constraints of the function statement owned by the user, if the replaced expression contains the initial parameters of the smart contract caller, the initial parameter ciphertext value is obtained from the proof function, the initial parameter ciphertext value is decrypted using the private key of the smart contract caller, and then the replaced expression is encrypt with the public key and random number of the smart contract caller, and the proof statement is equal to the function parameter;
[0033] According to the proof constraints of the external private function statement, if the expression contains the initial parameters of the smart contract caller, the initial parameter ciphertext value is obtained from the proof function, and the initial parameter ciphertext value is decrypted using the private key of the smart contract caller, and then substituted into the replaced expression. Then, the public key of the external private owner is used to encrypt each operation item using homomorphic encryption, and the proof statement is equal to the function parameter.
[0034] In one or more possible embodiments, the decryption rule includes:
[0035] For an expression of a constant, decrypt the expression into the constant;
[0036] For an expression of an address, decrypt the expression into the address;
[0037] For an expression that operates on two sub-expressions, the expression is decrypted into two sub-expressions using T plain Decrypt the two sub-expressions before operating;
[0038] If the expression is a display comment, and it indicates that the private type is the expression of the smart contract caller, the expression is decrypted as T plain Decrypt the expression of the smart contract caller;
[0039] If the expression has a privacy type of public and is an initial parameter ciphertext value, decrypt the initial parameter ciphertext value;
[0040] If the privacy type of the expression is self-owned or externally private and it is an initial parameter ciphertext value, the initial parameter ciphertext value is encrypted using the corresponding private key.
[0041] In one or more possible embodiments, the encryption rule includes:
[0042] If the operand in the expression is a constant, the constant is encrypted using the public key of the external private owner;
[0043] If the operand in the expression is an address, the address is encrypted using the public key of the external private owner;
[0044] If the operation item in the expression is a variable and the initial parameter ciphertext value of the external private owner, the initial parameter ciphertext value is directly used;
[0045] If the operand in the expression is a variable and is public, the variable is encrypted using the public key of the external private owner;
[0046] If the operation item in the expression is a variable including a sub-expression and the privacy type of the sub-expression is public, the sub-expression is encrypted using the public key of the external private owner;
[0047] If the operation item in the expression is addition or subtraction of two sub-expressions, and the privacy type of the operation item is public, the operation item is encrypted using the public key of the external owner. Otherwise, each sub-expression is encrypted using the public key of the external owner before addition or subtraction.
[0048] If the operation item in the expression includes a display comment, and it indicates that the expression of the private type of the smart contract caller is explicitly expressed to the external private owner, according to T plain Decrypt the expression of the smart contract caller and encrypt the decrypted expression using the public key of the owner.
[0049] In a second aspect, an embodiment of the present application provides a device for protecting the privacy of a blockchain smart contract, the device comprising:
[0050] A privacy annotation module is used to add privacy annotations to the data in the original smart contract according to the privacy data annotation specification to obtain a standard smart contract. The privacy annotation is used to indicate the owner of the data;
[0051] A privacy type parsing module, used to traverse the standard smart contract and parse the privacy type of expressions in function statements based on privacy annotations;
[0052] A contract conversion module is used to perform contract conversion on function statements based on smart contract conversion rules. For addition and subtraction expressions whose privacy type is external private, each operation item in the addition and subtraction expression is encrypted using the public key of the external private owner in a homomorphic encryption manner to complete the contract conversion of the function statement where the addition and subtraction expression is located;
[0053] A proof circuit building module, which is used to add NIZK proofs to the converted contract to verify that the converted function statements are equivalent to the original function statements;
[0054] The contract chain module is used to chain the converted contract after the traversal is completed, so as to conduct transactions based on the converted contract.
[0055] On the third aspect, another embodiment of the present application also provides a device for protecting the privacy of blockchain smart contracts, comprising at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute any method for protecting the privacy of blockchain smart contracts provided in the embodiments of the present application.
[0056] In a fourth aspect, another embodiment of the present application further provides a computer storage medium, wherein the computer storage medium stores a computer program, and the computer program is used to enable a computer to execute any method for protecting the privacy of blockchain smart contracts provided in an embodiment of the present application.
[0057] The method, device and apparatus for protecting the privacy of blockchain smart contracts provided in the embodiments of the present application have the following beneficial effects:
[0058] In the embodiment of the present application, the annotation of private data is realized through privacy annotation. Based on the standard smart contract with privacy annotation, the private data is encrypted using the public key of the private owner. For the addition and subtraction expressions whose owners are external private owners, the homomorphic encryption is adopted to ensure the privacy of external data. In order to prove that the converted statement is equivalent to the original statement, it is necessary to add a NIZK proof that the converted statement is equivalent to the original statement. In this way, secure data transactions can be realized between the smart contract caller and the external private owner without leaking the data of either the smart contract caller or the external private owner.
[0059] Other features and advantages of the present application will be described in the following description, and partly become apparent from the description, or be understood by practicing the present application. The purpose and other advantages of the present application can be realized and obtained by the structures specifically pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0060] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. Obviously, the drawings introduced below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0061] Figure 1 is a schematic diagram of an application environment according to an embodiment of the present application;
[0062] Figure 2 A flowchart of a method for protecting the privacy of a blockchain smart contract according to an embodiment of the present application;
[0063] Figure 3 A schematic diagram of a process for adding privacy annotations to a smart contract according to an embodiment of the present application;
[0064] Figure 4a This is a schematic diagram of an original smart contract according to an example of an embodiment of the present application;
[0065] Figure 4b This is a schematic diagram of a standard smart contract obtained after adding privacy annotations according to an example of an embodiment of the present application;
[0066] Figure 5 The expression tree structure diagram obtained after performing privacy type parsing on the expression corresponding to line 8 in FIG. 4 according to an embodiment of the present application;
[0067] Figure 6 The expression tree structure diagram obtained after performing privacy type parsing on the expression corresponding to line 9 in FIG. 4 according to an embodiment of the present application;
[0068] Figure 7 A schematic diagram of a process of performing contract conversion on a function statement based on a smart contract conversion rule according to an embodiment of the present application;
[0069] Figure 8 A schematic diagram of a smart contract conversion process and generation of a constraint instruction set according to an embodiment of the present application;
[0070] Fig. 9 A schematic diagram of a process of obtaining a proof constraint based on a constraint instruction according to an embodiment of the present application;
[0071] Fig.10 A schematic diagram of adding a proof statement according to an embodiment of the present application;
[0072] Fig.11 A schematic diagram of a flow chart for adding an input of a proof function in a NIZK proof according to an embodiment of the present application;
[0073] Fig.12 A schematic diagram of a process of obtaining a proof statement based on a public proof constraint according to an embodiment of the present disclosure;
[0074] Fig.13 A schematic diagram of a process of obtaining a proof statement based on a self-owned proof constraint according to an embodiment of the present application;
[0075] Fig.14 A schematic diagram of a process of obtaining a proof statement based on an external private proof constraint according to an embodiment of the present disclosure;
[0076] Fig.15 A schematic diagram of a NIZK proof statement according to an embodiment of the present disclosure;
[0077] Fig.16 A schematic diagram of a device structure for protecting the privacy of blockchain smart contracts according to an embodiment of the present disclosure;
[0078] Fig.17 The present invention is a schematic diagram of a device structure for protecting the privacy of blockchain smart contracts according to an embodiment of the present invention. DETAILED DESCRIPTION
[0079] To further illustrate the technical solution provided by the embodiment of the present application, this is described in detail below in conjunction with the accompanying drawings and specific implementation methods. Although the embodiment of the present application provides the method operation steps as shown in the following embodiments or drawings, more or fewer operation steps may be included in the method based on routine or no creative labor. In the steps where there is no necessary causal relationship logically, the execution order of these steps is not limited to the execution order provided by the embodiment of the present application. The method can be executed in the order of the method shown in the embodiment or drawings or in parallel during the actual processing process or when the control device is executed.
[0080] See also Figure 1 , is a schematic diagram of an application environment according to an embodiment of the present application. The application environment may include, for example, a blockchain node 10. A user may access a blockchain node by accessing a blockchain application. Each blockchain node stores the smart contract uploaded by the user and conducts transactions based on the smart contract.
[0081] In order to solve the problem in the related art of how to ensure that smart contracts are executed without leaking private data and allow operations on external values, an embodiment of the present application provides a method for protecting the privacy of blockchain smart contracts. The method for protecting the privacy of blockchain smart contracts in the embodiment of the present application is described in detail below with reference to the accompanying drawings.
[0082] like Figure 2 As shown, a flowchart of a method for protecting the privacy of blockchain smart contracts provided by an embodiment of the present application includes:
[0083] Step 201, according to the privacy data annotation specification, add privacy annotations to the data in the original smart contract to obtain a standard smart contract, wherein the privacy annotations are used to indicate the owner of the data;
[0084] The above privacy data annotation specification is used to track the ownership of data in smart contracts. Data with different ownerships correspond to different privacy types, and the owner of the data can be marked with the owner of the data. The above data owners include three types:
[0085] The owner of the data is identified as all, indicating that the data is public, and the corresponding privacy type is public;
[0086] If the owner of the data is me, it means that the data is only visible to the caller of the smart contract, and the corresponding privacy type is self-owned;
[0087] For the other owner identifiers of the data, it means that the owner of the data is an external private owner other than the smart contract caller, and is only seen by the external private owner. The corresponding privacy type is external private foreign.
[0088] In the embodiment of the present application, the data in the original smart contract is annotated by parsing the owner of the data in the original smart contract, wherein the data whose owner is all may not be annotated. In this embodiment, the data whose owner is the smart contract caller or external private owner is called private data.
[0089] As an optional implementation, Figure 3 As shown, privacy annotations are added to the privacy data in the original smart contract, such as Figure 3 As shown,
[0090] Step 301, parse the original smart contract. If a variable belonging to private data is parsed, execute step 302. If an expression reclassification statement is parsed, execute step 303.
[0091] In the function statement of the smart contract, the expression e of require(e) needs to be public. In addition, for the assignment statement id=e, the owners of both sides must be equal, or the expression e is public. It is allowed to implicitly make public values private, but it is not allowed to implicitly leak any private values.
[0092] Privacy annotations have two main purposes: prevent implicit information leakage; and guide compilation by declaring which expressions should be encrypted for which party.
[0093] In the function statement of the smart contract, in order to realize the normal transaction, the data whose owner is the caller of the smart contract needs to be displayed to another owner. This type of function statement is an expression reclassification statement.
[0094] Step 302: For variables belonging to private data, add a privacy identifier and the owner identifier of the variable after the data type of the variable in the original smart contract and before the variable, so as to obtain the corresponding privacy annotation;
[0095] In the embodiment of the present application, for variables belonging to private data, the privacy annotation obtained by annotating in the above manner is specifically a type declaration τ@α. The type declaration (τ@α) consists of a data type (τ) and an owner identifier (α), which is used to specify the owner of the private data and enforces the requirement that data of type τ can only be read by its owner α. The data type τ can be an integer or a Boolean value.
[0096] As Figure 4a is an example of the execution of the original smart contract, Figure 4b and is an example of the execution of the standardized smart contract obtained after adding privacy annotations. The code in the figure covers all relevant aspects of compilation, but does not implement any meaningful functions. For the variable a in the original smart contract, a declared as an integer type by unit@alice can only be owned by alice, b declared as an integer type by unit@bob can only be owned by bob, and x declared as an integer type by unit@me can only be owned by the smart contract caller.
[0097] Step 303: For the expression reclassification statement, add a display annotation that explicitly expresses the expression of the smart contract caller to another owner.
[0098] To prevent implicit information leakage, generally, a private expression owned by the smart contract caller cannot be directly assigned to a different owner. However, in some cases, it is necessary to explicitly express the expression of the smart contract call to another owner. Such function statements are expression reclassification statements, and the privacy data annotation specification adds a display annotation to such statements. Specifically, developers can use the display annotation reveal(e,α) to explicitly express the private expression e belonging to a smart contract caller to another owner α. As Figure 4a shown, the request statement in the original smart contract require(1 < x % 3) requires that x % 3 be public, but the owner of x is me. Therefore, this function statement is an expression reclassification statement and requires a display annotation to mark it as require(1 < reveal(x % 3, all)), indicating that the result of x % 3 is reclassified as all.
[0099] Step 202: Traverse the standardized smart contract and parse the privacy type of the expression in the function statement based on the privacy annotation.
[0100] For expressions with a recursive relationship in the function statement of the smart contract, the privacy type of each expression can be parsed according to the privacy type determination rule.
[0101] Since there is a recursive relationship in the expressions in the function statement, this application parses the privacy annotation in the standardized smart contract and assigns a privacy type to each expression. One expression can be used as an operand for the expression that recurses upward, and finally determines the privacy type of each expression. The embodiments of this application adopt the following privacy type determination rules to parse the privacy type of the expression in the function statement based on the privacy annotation:
[0102] 1) If the owner of one operation item in the expression in the function statement is public, and the owner of the other operation item is public, the privacy type of the expression is determined to be public. Specifically, it can be expressed by the following privacy type determination rule binop-all:
[0103]
[0104] In the molecule Indicates one of the operation items e 0 The owner of is all, Indicates another operation item e 1 The owner of is all, and the denominator Indicates that the privacy type of the result of two operation items is all.
[0105] For example, in Figure 4b In line 8, the two operation items of the less-than sign < are 1 and reveal(x%3, all). The owners of these two operation items are all. This operation is used to compare two public values, so the result is also public.
[0106] 2) If the owner of one operation item in the expression in the function statement is the smart contract caller, and the owner of the other operation item is public or the smart contract caller, the privacy type of the expression is determined to be self-owned; specifically, it can be expressed by the following privacy type determination rule binop-me:
[0107]
[0108] In the molecule Indicates one of the operation items e 0 The owner of is α 0 , Indicates another operation item e 1 The owner of is α 1 , Indicates that one of the owners is me, the other owner is me or all, and the denominator Γ├e 0 op e 1 ∶me means the result of the two operands is me. This is because the result depends on the private operand, so it should remain private.
[0109] For example, Figure 4b In the 10th line of , the owner of x is me and the owner of 1 is all, so the result of x+1 is me.
[0110] 3) If the owner of one operation item in the expression of the function statement is an external private owner, and the owner of the other operation item is the same external private owner or public, the privacy type of the expression is determined to be external private. Specifically, it can be expressed by the following privacy type determination rule binop-foreign:
[0111]
[0112] In the molecule Indicates one of the operation items e 0 The owner of is α 0 , Indicates another operation item e 1 The owner of is α 1 , α 1-i ∈{α i ,all} means that one of the owners belongs to neither me nor all, that is, an external private owner, and the other owner is the same external private owner or all. Indicates that the result of both operations is externally private. That is, if the owner of one of the operations is externally private, both operations must have the same owner, or one of the operations must be public.
[0113] For example, Figure 4b In line 9 of the expression b=(b+reveal(2*a, bob))+4, the owner of operation item a is me, and the owner of operation item b is bob, then the owner of the result of the operation is bob.
[0114] Step 203, performing contract conversion on the function statement based on the smart contract conversion rule, wherein for the addition and subtraction expressions whose privacy type is external private, each operation item in the addition and subtraction expression is encrypted by using the public key of the external private owner in a homomorphic encryption manner to complete the contract conversion of the function statement where the addition and subtraction expression is located;
[0115] For expressions with a privacy type of external private owner, the addition and subtraction expressions need to be encrypted and the data of the external private owner cannot be leaked. In the embodiment of the present application, the public key of the external private owner is used to encrypt each operation item in the addition and subtraction expressions using homomorphic encryption, thereby realizing the privacy protection of the external private owner's data and realizing normal transactions between the external private owner and the smart contract call.
[0116] Homomorphic encryption is a form of encryption that allows specific algebraic operations to be performed on ciphertext to produce a result that is still encrypted, and the result of decrypting it is the same as the result of the same operation on the plaintext.
[0117] When a smart contract caller calls a smart contract, if it involves an addition or subtraction expression whose privacy type is external private, it means that there is a transaction between the smart contract caller and the external private owner, that is, there is data transfer, that is, the addition or subtraction expression contains operation items whose owner is the smart contract caller. In order not to disclose the private data of the smart contract caller and the external private owner, the embodiment of the present application adopts a homomorphic encryption method and uses the public key of the external private owner to encrypt each operation item in the addition or subtraction expression, thereby ensuring the security of the transaction, and neither the data of the smart contract caller nor the data of the external private owner will be disclosed.
[0118] The smart contract conversion rules in the embodiment of the present application include: for private data in the function statement, the private data is encrypted using the public key of the owner of the private data, and the private data is changed into ciphertext form.
[0119] Step 204, adding a NIZK proof to the converted contract to verify that the converted function statement is equivalent to the original function statement;
[0120] The converted contract changes the plaintext in the original smart contract into ciphertext. In order to verify that the ciphertext in the converted contract is equivalent to the plaintext before the conversion after decryption, this application adds a NIZK proof to verify that the converted function statement is equivalent to the original function statement.
[0121] For addition and subtraction expressions with privacy type external private, the proof statement of the NIZK proof equivalent to the original function statement includes: obtaining the encrypted value of the initial parameters belonging to the smart contract caller and the encrypted value of the initial parameters of the external private owner in the addition and subtraction expressions from the converted contract; if the operation item in the addition and subtraction expression is the initial parameter of the smart contract caller, use the private key of the smart contract caller to decrypt the encrypted value of the initial parameters of the smart contract caller, and then encrypt it with the public key of the external private owner to obtain the homomorphically encrypted operation item; if the operation item of the addition and subtraction expression is the initial parameter of the external private owner, use the corresponding encrypted value of the initial parameter as the operation item participating in the homomorphic encryption; if the operation item in the addition and subtraction expression is public, encrypt it with the public key of the external private owner to obtain the homomorphically encrypted operation item; perform addition and subtraction operations on the homomorphically encrypted operation item according to the addition and subtraction expression, and the result obtained is the same as the result of the addition and subtraction expression after contract conversion.
[0122] The initial parameters of the function statement in the original smart contract. When the smart contract is converted, the initial parameters of the private owner are encrypted using the private owner's public key and added to the converted contract. Therefore, the encrypted value of the initial parameters can be obtained in the converted smart contract. In the embodiment of the present application, the private owner includes the smart contract caller and the external private owner.
[0123] Step 205, after the traversal is completed, the converted contract is uploaded to the chain to conduct transactions based on the converted contract.
[0124] In the embodiment of the present application, the canonical smart contract is first obtained from the original smart contract. Since the canonical smart contract adds privacy annotations to the data according to the privacy annotation specification, by traversing the canonical smart contract, when traversing to the private data with privacy annotations, the owner of the private data can be determined according to the annotation method of the privacy annotation, and the private data is encrypted using the public key of the private owner. For the addition and subtraction expressions whose owners are external private owners, the homomorphic encryption is adopted to ensure the privacy of the external data. In order to prove that the converted statement is equivalent to the original statement, it is necessary to add a NIZK proof that the converted statement is equivalent to the original statement. In this way, secure data transactions between the smart contract caller and the external private owner can be realized without leaking the data of either the smart contract caller or the external private owner.
[0125] The method for privacy protection of blockchain smart contracts in the embodiment of the present application adds privacy annotations to the data in the original smart contract according to the privacy data annotation specification. After obtaining the standardized smart contract, it mainly performs privacy type analysis, contract conversion, and proof circuit construction to obtain a protected smart contract on the chain. The specific implementation method is given below.
[0126] 1) Privacy type analysis
[0127] The embodiment of the present application determines the privacy type of an expression based on the above-mentioned privacy type determination rules, but the expressions in the smart contract usually have a recursive relationship. For multiple expressions in a recursive relationship in a function statement, the privacy type of each expression is recursively determined based on the privacy annotation and the privacy type determination rules according to the recursive relationship of the expression calculation. Through this recursive privacy type determination process, an expression tree structure can be constructed. In the expression tree structure, an operation involves two operation items, each operation item and the operation result are used as a node, and an operation result is used as an operation item for the upper level operation. The node belonging to the private owner at the top level is the root node of the expression tree structure.
[0128] like Figure 5 Shown is the pair Figure 4b The expression tree structure obtained after the privacy type parsing of the expression corresponding to line 8 in Figure 6 Shown is the pair Figure 4bThe expression tree structure obtained after the privacy type parsing of the expression corresponding to line 9 in the figure marks the privacy type of each node. By observing the expression tree structure, it can be found that if the expression tree contains a node with a privacy type of external private owner, the node must be at the top of the tree and contain the root node. This is because the expression of the external private owner cannot be displayed to me or all. The embodiment of the present application requires that the parameter e of the display annotation reveal must be self-owned. After parsing the expression tree structure, the nodes corresponding to e are divided into two sets, foreign and own, where:
[0129] foreign contains all owners Nodes;
[0130] own contains all nodes whose owners are α∈{me,all};
[0131] The subgraph guided by foreign is connected and contains the root node if it is not empty.
[0132] Conceptually, the expression tree is divided into an upper foreign part and a lower own part. For example, in Figure 6 In , own contains nodes *, 2, a, and 4. If the root is self-owned, there are no nodes for external owners, e.g. Figure 5 The expression tree rooted at Figure 5 The smart contract caller usually does not know the value of the foreign node. Therefore, it is necessary to prove that the circuit solves the data transmission of the foreign node through homomorphic encryption.
[0133] 2) Contract conversion
[0134] After completing the privacy type analysis of the contract, the input specification contract can be converted into an executable smart contract on the blockchain to encrypt the privacy data and collect the constraint instruction set used to build the proof circuit.
[0135] The embodiment of the present application parses the privacy type of expressions in function statements based on privacy annotations, including: for multiple expressions in a recursive relationship in the function statement, according to the recursive relationship of the expression calculation, based on the privacy annotations and privacy type determination rules, recursively determine the privacy type of each expression. The specific parsing process is described in the above implementation method and will not be described in detail here.
[0136] In the embodiment of the present application, the function statement includes a request statement require and a variable assignment statement id=e, such as Figure 7 As shown, the function statement is converted into a contract based on the smart contract conversion rules, including:
[0137] Step 701: For expressions with display comments in request statements or expressions assigned in variable assignment statements, replace the expression of the top-level private owner in the expression with function parameters, where the owner of the private owner expression is the smart contract caller or an external private owner;
[0138] The specific replacement method is that when the privacy type of the expression of the function statement is public, the function parameter is equal to the plaintext of the replaced expression. When the privacy type of the expression of the function statement is external private or self-owned, the function parameter is equal to the ciphertext obtained by encrypting the plaintext of the private owner's expression using the public key of the external private owner or the public key of the smart contract caller.
[0139] After recursively determining the privacy type of each expression, an expression tree structure is obtained. To prevent privacy data leakage, if the expression tree structure includes a private owner's node, the private owner expression belonging to the top level is determined. The private owner expression at the top level may be a tree node or a root node.
[0140] For a require statement require(e), it may contain sub-expressions of the form reveal(e′,all), where e′ is self-owned. Figure 4b In line 8 of , the node corresponding to reveal(x%3,all) is public, and the node corresponding to x%3 is self-owned. Therefore, in this embodiment, if there is an expression showing comments in the request statement, a top-down tree search (e.g., breadth-first search) is performed to find a tree node with the node of reveal(e′,all) expression as the root node and belonging to the top-level self-owned tree node, and the expression x%3 corresponding to the tree node is replaced by the function parameter arg, where arg is the plain text of the replaced expression x%3, represented by e1.
[0141] For the variable assignment statement id=e, if e is private to α (the owner is the smart contract caller or an external private owner), the function parameter arg is the ciphertext encrypted using the public key of the private owner of e.
[0142] For example, Figure 8 As shown, for Figure 4b In line 9 of the code, the expression tree structure is obtained by parsing the expression of the function statement in line 9. The expression of the top-level owner in the expression is the root node, so the function parameter arg is used to replace the entire expression tree structure b+reveal(2*a, bob)+4. arg is the ciphertext of the encrypted items of b+reveal(2*a, bob)+4 using the public key of the external owner, specifically represented by e2.
[0143] For example, Figure 8 As shown, for Figure 4b In line 10, the expression tree structure is obtained by parsing the expression of the function statement in line 10. The expression of the top-level private owner in the expression is the root node, that is, x+1. Therefore, the entire expression tree structure x+1 is replaced by the function parameter arg. arg is the ciphertext encrypted by the public key of the replaced smart contract caller to x+1, represented by e3.
[0144] Step 702: Generate constraint instructions for constructing a NIZK proof and add them to a constraint instruction set, wherein the constraint instructions are used to express the equivalence relationship between the plain text of the replaced expression and the function parameter.
[0145] For variable x and expression e whose owner is α, define constraint instruction x≡ α e, represents the plaintext value of e must be equivalent to the value of x. There are two cases of equivalence here: ① e is public, ②e is private, and That is, using the private owner's public key pk α After encrypting the plain text of e with the random number r, it is equal to x.
[0146] The equivalent relationship of the embodiments of the present application includes: if the expression of a function statement is public, the plaintext of the expression of the top-level private owner in the expression must be equivalent to the value of the function parameter; if the expression of the function statement is externally private or self-owned, the plaintext of the expression of the top-level private owner encrypted with the private owner's public key must be equivalent to the value of the function parameter.
[0147] like Figure 8 The following figure shows the contract obtained after the conversion of the standard smart contract. For the request statement require in line 8 of the contract before the conversion, x%3 is replaced by e1, the expression for assigning a value to b in line 9 of the contract before the conversion is replaced by e2, and the expression for assigning a value to a in line 10 of the contract before the conversion is replaced by e3. α e is added to the constraint instruction set C f In the specific Figure 8 As shown, Figure 4b The 8th row in the Figure 8 The constraint instruction with label (2) is Figure 4b The 9th row corresponds to Figure 8 The constraint instruction numbered (3) is: Figure 5 The 10th row in Figure 8 The constraint instruction numbered (4) in the figure.
[0148] When performing contract conversion, the embodiment of the present application also includes adding bin to self-owned or external private variables, function parameters, and proof circuits, indicating that these data appear in ciphertext form in the converted contract, such as bin x, bin e2, e3, and p are ciphertext in the converted contract, and p is the proof statement. In addition, the initial parameters of the smart contract caller in the function statement are added to the converted contract using the initial parameter ciphertext value encrypted with the public key of the smart contract caller. For example, by bin_a=a, the encrypted initial parameter value of the initial parameter a can be obtained, and by bin_b=b, the encrypted initial parameter value of the initial parameter b can be obtained.
[0149] 3) Prove circuit construction
[0150] like Fig. 9 As shown, the embodiment of the present application adds a NIZK proof in the converted contract to verify that the converted function statement is equivalent to the original function statement, including:
[0151] Step 901, determine the privacy type of the constraint instruction of the function statement, if it is public, execute step 902, if it is self-owned, execute step 903, if it is external private, execute step 904;
[0152] Step 902: for the constraint instructions of the public function statement, convert them into equivalent instructions using the decryption function T in the proof circuit. plain Solve the plaintext of the replaced expression and prove the constraint that it is equal to the function argument;
[0153] Step 903: For the constraint instruction of the self-owned function statement, convert it into an equivalent function using the decryption function T plain After solving the plain text of the replaced expression according to the decryption rules, the encrypted result is encrypted with the public key of the smart contract caller, which is equal to the proof constraint of the function parameter;
[0154] Step 904: convert the constraint instruction of the external private function statement into an equivalent function using the encryption function T α According to the encryption rules, each operation item in the plain text of the replaced expression is encrypted with the public key of the external private owner, and the proof constraint is equal to the function parameter;
[0155] Step 905: Based on the proof constraint, add a NIZK proof to verify that the converted function statement is equivalent to the original function statement.
[0156] The present embodiment defines a decryption function T plain and encryption function T α After obtaining the expression tree structure of the function statement in the manner of the above embodiment of the present application, T plain To process the nodes in own, for any e∈own, calculate Tplain The proof circuit result of (e) is (the plain text of e). α It is used to process nodes in foreign and nodes in own whose parent nodes are in foreign. For expression e, in the proof function, α (e) Evaluate and obtain the ciphertext In this embodiment of the application, the constraint instruction set C f Each constraint in x≡ α e equivalent to the conversion to prove the circuit φ f According to the different owners α, the constraint instructions are equivalently converted into proof constraints as follows.
[0157]
[0158] If α=all,T plain So that x holds the plaintext value of e. This ensures that the self-owned value is correctly displayed by reveal(e,all). If α=me, x should contain the public key pk of the caller of the smart contract. me and a random number r i Encrypted (Use T plain For non-empty expressions of foreign, in this case, x is owned by α≠me. The embodiment of the present application uses T α to ensure that x contains the correctly encrypted value.
[0159] For example, Fig.10 As shown, Figure 8 The constraint instruction numbered (2) performs the proof constraint transformation according to the first line above. Figure 8 The constraint instruction numbered (3) performs the proof constraint transformation according to the second line above. Figure 8 The constraint instruction numbered (4) is transformed according to the third line above, and the constraint instruction e1≡ all x%3, equivalent to using the decryption function T in the proof circuit plain Solve the plaintext of x%3, which is equal to the proof constraint of e1, that is, e1=T plain (x%3); According to the second line, the constraint instruction e2≡ bob (b+reveal(2*a,bob))+4, equivalent to the conversion using the encryption function T α According to the encryption rules, each operation item in the plaintext (b+reveal(2*a,bob))+4 is encrypted with the public key of the external private owner, and the proof constraint is equal to e2, that is, e2=T α((b+reveal(2*a,bob))+4); According to the third line, the constraint instruction e3≡ me (x+1), equivalently converted to using the decryption function T plain After solving the plaintext of x+1 according to the decryption rules, the result is encrypted using the public key of the smart contract caller, which is equal to the proof constraint of e3.
[0160] Based on the proof constraint, a NIZK proof is added to verify that the converted function statement is equivalent to the original function statement, which mainly includes adding the input of the proof function to the NIZK proof and obtaining the proof statement based on the proof constraint. The specific implementation method is as follows.
[0161] like Fig.11 As shown in Figure 1, the process of adding the input of the proof function in the NIZK proof includes:
[0162] Step 1101, for the initial parameters whose owner is an external private owner or a smart contract caller, the ciphertext value of the initial parameters encrypted by the public key of the external private owner or the public key of the smart contract caller, the public key of the external private owner, the public key of the smart contract caller, and the random number used for encryption are added to the proof function;
[0163] Step 1102, add the private key of the smart contract caller to the proof function in a private manner.
[0164] This application embodiment constructs a proof function φ f When obtaining the NIZK proof, first determine the proof function path φ f The input is determined by adding the function parameters, the public key of the smart contract caller, the public key of the external private owner, the initial parameter ciphertext value of the smart contract caller, and the initial parameter ciphertext value of the external private owner to the proof circuit φ according to the constraint instruction set. f For example, by constraining the instruction set, the function input is proved to be: e1, e2, e3, x old ,a old ,b old ,pk me ,pk bob , where x old ,a old ,b old are the ciphertext values of x, a, and b obtained from the converted contract, respectively, pk me is the public key of the smart contract caller, pk bob The input of the proof function also includes private input: the private key sk of the smart contract caller me and a list of random values r i .
[0165] To copy the old values of any overwritten fields at the beginning of the function. For example, in Figure 8 In , we first copy the old values of a and b in line 2. In line 7, we introduce a proof function that protects the proof statement.
[0166] like Fig.12 As shown, the process of obtaining a proof statement based on the proof constraint in the embodiment of the present application includes:
[0167] Step 1201, according to the proof constraint of the public function statement, if the replaced expression contains the initial parameters of the smart contract caller, obtain the initial parameter ciphertext value from the proof function;
[0168] For example, Fig.15 As shown, the constraint instruction labeled (5) is public, and x%3 contains the self-owned x, then the ciphertext value x of x is obtained from the proof function. old .
[0169] Step 1202, generate a proof statement that the initial parameter ciphertext value is decrypted using the private key of the smart contract caller, and the replaced expression is equal to the function parameter.
[0170] For example, the ciphertext value x of x is obtained old After that, generate the private key sk of the smart contract caller me Decrypted ciphertext value x old , substitute the replaced expression into the proof statement that it is equal to e1, that is, Fig.15 The proof statement marked with (8) e1=Dec(x old ,sk me )%3.
[0171] like Fig.13 As shown, the process of obtaining a proof statement based on the proof constraint in the embodiment of the present application includes:
[0172] Step 1301, according to the proof constraint of the function statement owned by the user, if the replaced expression contains the initial parameter of the smart contract caller, obtain the ciphertext value of the initial parameter from the proof function;
[0173] For example, Fig.15 As shown, the constraint instruction labeled (7) is self-owned, and x+1 contains self-owned x, then the ciphertext value x of x is obtained from the proof function old .
[0174] Step 1302, after decrypting the initial parameter ciphertext value using the private key of the smart contract caller, substitute the replaced expression, and then encrypt the replaced expression using the public key and random number of the smart contract caller to prove that it is equal to the function parameter.
[0175] For example, the ciphertext value x of x is obtained old After that, generate the private key sk of the smart contract caller me Decrypted ciphertext value x old , and then use the public key pk of the smart contract caller me and a random number r 0 The proof statement that the encryption of x+1 is equal to e3 is Fig.15 The proof statement with label number 10 is:
[0176] e3=Enc(Dec(x old ,sk me )+1,pk me , r 0 ).
[0177] like Fig.14 As shown, the process of obtaining a proof statement based on the proof constraint in the embodiment of the present application includes:
[0178] Step 1401, according to the proof constraint of the external private function statement, if the expression contains the initial parameters of the smart contract caller, obtain the initial parameter ciphertext value from the proof function;
[0179] For example, Fig.15 As shown, the constraint instruction labeled (6) is external private. The expression contains the initial parameter a of the smart contract caller, and the ciphertext value a of a is obtained from the proof function. old .
[0180] Step 1402, after decrypting the initial parameter ciphertext value using the private key of the smart contract caller, substituting it into the replaced expression, encrypting each operation item using the public key of the external private owner using homomorphic encryption, and proving that the statement is equal to the function parameter.
[0181] For example, the ciphertext value a of a is obtained old After that, generate the private key sk of the smart contract caller me Decrypted ciphertext value a old , substitute the addition and subtraction expressions, and use the public key pk of the external private owner bob Use homomorphic encryption to encrypt each operation item, and the proof statement equal to e2 is Fig.15 The proof statement numbered (9) is:
[0182]
[0183] Among them, b old The ciphertext value in the contract after converting the external private parameter b.
[0184] In the embodiments of this application, T plainIt is used to decrypt any self-owned variables that appear in e and recursively evaluate the expression. The rules for constants, addresses me (if me appears in a function statement, it represents the address, and if it is used to represent the owner, it identifies the smart contract caller) and binary operations are simple and clear. If the variable id is public, you can directly access id old Otherwise, due to T plain Applies only to nodes in own, so the value is self-owned, so use sk me Decrypt.
[0185] Specifically, the decryption rules include:
[0186] 3.1) For an expression of a constant, decrypt the expression into the constant, as follows:
[0187] T plain (c)==c
[0188] Here, c represents a constant.
[0189] 3.2) For the expression of the address, the expression is decrypted into the address, as follows:
[0190] T plain (me)==me
[0191] Among them, me represents the address, corresponding to line 7 in the standard smart contract.
[0192] 3.2) For an expression that operates on two sub-expressions, decrypt the expression into two sub-expressions using T plain The two sub-expressions are decrypted and then operated as follows:
[0193] T plain (e1 op e2)==T plain (e1)op T plain (e2)
[0194] Among them, e1 and e2 are two sub-expressions.
[0195] 3.3) If the expression is a display comment and represents an expression of private type as the smart contract caller, decrypt the expression into plain Decrypt the expression of the smart contract caller as follows:
[0196] T plain (reveal(e,α))==T plain (e)
[0197] For line 8 in the canonical smart contract, via T plainThe reveal expression can be ignored.
[0198] 3.4) If the privacy type of the expression is public and it is the initial parameter ciphertext value, decrypt the initial parameter ciphertext value; if the privacy type of the expression is self-owned or externally private and it is the initial parameter ciphertext value, use the corresponding private key to encrypt the initial parameter ciphertext value, as follows:
[0199]
[0200] For binary operations in addition and subtraction expressions, if the operation is common, use T plain Calculate its plaintext value and apply Enc again α Private addition and subtraction are computed homomorphically: in the application or Previously, parameters were passed through T α Recursively transform to obtain two ciphertexts encrypted for α.
[0201] T α Applies only to nodes in foreign and its direct children. Therefore, the expression reveal(e, α′) can be expressed by T only when α′=α. α We can apply T plain and Enc α Perform recursive calculations. Conceptually, the introduction of Enc α Provides a bridge between own and foreign.
[0202] T α The definition of is as follows: This function generates ciphertext for α. The constants and me are public, so their plaintext values are encrypted using the public key of α using the encryption function Enc α Here, r i Yes f A new private input for the external variable id, through T α (id)Convert to id old , which contains the ciphertext of α. If the id is public, then old Encryption is performed.
[0203] The encryption rules in this embodiment include:
[0204] 3.5) If the operand in the expression is a constant, the constant is encrypted using the public key of the external private owner, as follows:
[0205] T α (c) = Enc α (c);
[0206] Where c is a constant.
[0207] 3.6) If the operand in the expression is an address, the address is encrypted using the public key of the external private owner, as follows:
[0208] T α (me)=Enc α (me);
[0209] Among them, me is the address of the smart contract caller.
[0210] 3.7) If the operation item in the expression is a variable and the initial parameter ciphertext value of the external private owner, the initial parameter ciphertext value is directly used, otherwise the variable is encrypted using the public key of the external private owner; if the operation item in the expression is a variable and is public, the variable is encrypted using the public key of the external private owner, as follows:
[0211]
[0212] Among them, id represents a variable, and ⊥ is not processed.
[0213] 3.8) If the operation item in the expression is addition or subtraction of two sub-expressions, and the privacy type of the operation item is public, the operation item is encrypted using the public key of the external private owner. Otherwise, each sub-expression is encrypted using the public key of the external private owner before addition or subtraction, as follows;
[0214]
[0215] represents the addition after homomorphic encryption, Indicates subtraction after homomorphic encryption.
[0216] 3.9) If the operation item in the expression includes a display comment, and it indicates that the expression of the private type of the smart contract caller is explicitly expressed to the external private owner, according to T plain Decrypt the expression of the smart contract caller, and encrypt the decrypted expression using the public key of the private owner, as follows:
[0217]
[0218] Enc α (e):=Enc α (e,pk α ,r i )
[0219] By using the method for protecting the privacy of blockchain smart contracts provided in the embodiment of the present application, the homomorphic encryption scheme can effectively solve the problem that the owners of expressions e1 and e2 are In this case, calculations of e1+e2 and e1-e2 are allowed.
[0220] Based on the same inventive concept, the present application also provides a device 1600 for protecting the privacy of blockchain smart contracts, such as Fig.16 As shown, the device comprises:
[0221] The privacy annotation module 1601 is used to add privacy annotations to the data in the original smart contract according to the privacy data annotation specification to obtain a standard smart contract, wherein the privacy annotation is used to indicate the owner of the data;
[0222] A privacy type parsing module 1602, used to traverse the standard smart contract and parse the privacy type of expressions in function statements based on privacy annotations;
[0223] The contract conversion module 1603 is used to perform contract conversion on the function statement based on the smart contract conversion rule. For the addition and subtraction expressions whose privacy type is external private, each operation item in the addition and subtraction expression is encrypted by using the public key of the external private owner in a homomorphic encryption manner to complete the contract conversion of the function statement where the addition and subtraction expression is located;
[0224] A proof circuit construction module 1604 is used to add a NIZK proof in the converted contract to verify that the converted function statement is equivalent to the original function statement;
[0225] The contract chain module 1605 is used to chain the converted contract after the traversal is completed, so as to conduct transactions based on the converted contract.
[0226] In one or more possible embodiments, the privacy annotation module adds a privacy annotation to the privacy data in the original smart contract, including at least one of the following steps:
[0227] For variables that belong to private data, add a privacy identifier and the owner identifier of the variable after the data type of the variable in the original smart contract and before the variable;
[0228] For expression reclassification statements, add explicit comments that explicitly express the smart contract caller expression to another owner.
[0229] In one or more possible embodiments, the privacy type parsing module adopts the following privacy type determination rule to parse the privacy type of the expression in the function statement based on the privacy annotation:
[0230] If the owner of one operand of an expression in a function statement is public, and the owner of another operand is public, the privacy type of the expression is determined to be public;
[0231] If the owner of one operation item in the expression of the function statement is the smart contract caller, and the owner of the other operation item is public or the smart contract caller, the privacy type of the expression is determined to be self-owned;
[0232] If the owner of one operand in an expression in a function statement is external private, and the owner of another operand is the same external private or public, the privacy type of the expression is determined to be external private.
[0233] In one or more possible embodiments, the function statement includes a request statement and a variable assignment statement, and the privacy type parsing module parses the privacy type of the expression in the function statement based on the privacy annotation, including:
[0234] For multiple expressions with recursive relationships in the function statement, the privacy type of each expression is recursively determined according to the recursive relationship of the expression operation, based on the privacy annotation and privacy type determination rules;
[0235] The function statements are converted to contracts based on the smart contract conversion rules, including:
[0236] For expressions with display comments in request statements, or expressions assigned in variable assignment statements, the expression of the top-level private owner in the expression is replaced with function parameters, where the owner of the private owner's expression is the smart contract caller or an external private owner;
[0237] Generate a constraint instruction for constructing a NIZK proof and add it to a constraint instruction set, wherein the constraint instruction is used to express an equivalence relationship between the plain text of the replaced expression and the function parameter;
[0238] Among them, when the privacy type of the expression of the function statement is public, the function parameter is equal to the plaintext of the replaced expression. When the privacy type of the expression of the function statement is external private or self-owned, the function parameter is equal to the ciphertext obtained by encrypting the plaintext of the private owner's expression using the public key of the external private owner or the public key of the smart contract caller.
[0239] In one or more possible embodiments, a NIZK proof is added to the converted contract to verify that the converted function statement is equivalent to the original function statement, including:
[0240] For the constraint instructions of the public function statement, it is equivalent to converting to use the decryption function T in the proof circuit plain Solve the plaintext of the replaced expression and prove the constraint that it is equal to the function argument;
[0241] For the constraint instructions of the self-owned function statement, it is equivalent to converting to use the decryption function T plain After solving the plain text of the replaced expression according to the decryption rules, the encrypted result is encrypted with the public key of the smart contract caller, which is equal to the proof constraint of the function parameter;
[0242] Convert the constraint instructions of the external private function statement into equivalent ones using the encryption function Tα According to the encryption rules, each operation item in the plain text of the replaced expression is encrypted with the public key of the external private owner, and the proof constraint is equal to the function parameter;
[0243] Based on the proof constraints, a NIZK proof is added to verify that the converted function statement is equivalent to the original function statement.
[0244] In one or more possible embodiments, the proof circuit construction module adds a NIZK proof to verify that the converted function statement is equivalent to the original function statement based on the proof constraint, including:
[0245] For the initial parameters whose owner is an external private owner or the caller of the smart contract, the ciphertext value of the initial parameters encrypted with the public key of the external private owner or the public key of the caller of the smart contract, the public key of the external private owner, the public key of the caller of the smart contract, and the random number used for encryption are added to the proof function, and the private key of the caller of the smart contract is added to the proof function in a private manner;
[0246] According to the proof constraints of the public function statement, if the replaced expression contains the initial parameters of the smart contract caller, the initial parameter ciphertext value is obtained from the proof function, and the initial parameter ciphertext value is decrypted using the private key of the smart contract caller, and a proof statement is generated that the replaced expression is equal to the function parameter;
[0247] According to the proof constraints of the function statement owned by the user, if the replaced expression contains the initial parameters of the smart contract caller, the initial parameter ciphertext value is obtained from the proof function, the initial parameter ciphertext value is decrypted using the private key of the smart contract caller, and then the replaced expression is encrypt with the public key and random number of the smart contract caller, and the proof statement is equal to the function parameter;
[0248] According to the proof constraints of the external private function statement, if the expression contains the initial parameters of the smart contract caller, the initial parameter ciphertext value is obtained from the proof function, and the initial parameter ciphertext value is decrypted using the private key of the smart contract caller, and then substituted into the replaced expression. Then, the public key of the external private owner is used to encrypt each operation item using homomorphic encryption, and the proof statement is equal to the function parameter.
[0249] In one or more possible embodiments, the decryption rules include:
[0250] For an expression of a constant, decrypt the expression into the constant;
[0251] For an expression of an address, decrypt the expression into the address;
[0252] For an expression that operates on two sub-expressions, the expression is decrypted into two sub-expressions using Tplain Decrypt the two sub-expressions before operating;
[0253] If the expression is a display comment, and it indicates that the private type is the expression of the smart contract caller, the expression is decrypted as T plain Decrypt the expression of the smart contract caller;
[0254] If the expression has a privacy type of public and is an initial parameter ciphertext value, decrypt the initial parameter ciphertext value;
[0255] If the privacy type of the expression is self-owned or externally private and it is an initial parameter ciphertext value, the initial parameter ciphertext value is encrypted using the corresponding private key.
[0256] In one or more possible embodiments, the encryption rule includes:
[0257] If the operand in the expression is a constant, the constant is encrypted using the public key of the external private owner;
[0258] If the operand in the expression is an address, the address is encrypted using the public key of the external private owner;
[0259] If the operation item in the expression is a variable and the initial parameter ciphertext value of the external private owner, the initial parameter ciphertext value is directly used;
[0260] If the operand in the expression is a variable and is public, the variable is encrypted using the public key of the external private owner;
[0261] If the operation item in the expression is a variable including a sub-expression and the privacy type of the sub-expression is public, the sub-expression is encrypted using the public key of the external private owner;
[0262] If the operation item in the expression is addition or subtraction of two sub-expressions, and the privacy type of the operation item is public, the operation item is encrypted using the public key of the external owner. Otherwise, each sub-expression is encrypted using the public key of the external owner before addition or subtraction.
[0263] If the operation item in the expression includes a display comment, and it indicates that the expression of the private type of the smart contract caller is explicitly expressed to the external private owner, according to T plain Decrypt the expression of the smart contract caller and encrypt the decrypted expression using the public key of the owner.
[0264] After introducing the method for protecting the privacy of blockchain smart contracts according to an exemplary embodiment of the present application, next, an apparatus for protecting the privacy of blockchain smart contracts according to another exemplary embodiment of the present application is introduced.
[0265] In some possible implementations, the device for protecting the privacy of blockchain smart contracts according to the present application may include at least one processor and at least one memory. The memory stores program code, and when the program code is executed by the processor, the processor executes the steps in the method for protecting the privacy of blockchain smart contracts according to various exemplary implementations of the present application described above.
[0266] Refer to the following Fig.17 To describe the device 170 for protecting the privacy of blockchain smart contracts according to this embodiment of the present application. Fig.17 The device 170 shown for protecting the privacy of blockchain smart contracts is merely an example and should not bring any limitations to the functions and scope of use of the embodiments of the present application.
[0267] like Fig.17 As shown, the device 170 for protecting the privacy of blockchain smart contracts is presented in the form of a general electronic device. The components of the device 170 for protecting the privacy of blockchain smart contracts may include, but are not limited to: at least one processor 171, at least one memory 172, and a bus 173 connecting different system components (including the memory 172 and the processor 171).
[0268] Bus 173 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, a processor, or a local bus using any of a variety of bus architectures.
[0269] The memory 172 may include a readable medium in the form of a volatile memory, such as a random access memory (RAM) 1721 and / or a cache memory 1722 , and may further include a read-only memory (ROM) 1723 .
[0270] Memory 172 may also include a program / utility 1725 having a set (at least one) of program modules 1724, such program modules 1724 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.
[0271] The device 170 for protecting the privacy of blockchain smart contracts may also communicate with one or more external devices 174 (e.g., keyboards, pointing devices, etc.), and may also communicate with one or more devices that enable a user to interact with the device 170 for protecting the privacy of blockchain smart contracts, and / or communicate with any device that enables the device 170 for protecting the privacy of blockchain smart contracts to communicate with one or more other electronic devices (e.g., routers, modems, etc.). Such communication may be performed through an input / output (I / O) interface 175. In addition, the device 170 for protecting the privacy of blockchain smart contracts may also communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter 176. As shown, the network adapter 176 communicates with other modules of the device 170 for protecting the privacy of blockchain smart contracts through a bus 173. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the device 170 for protecting the privacy of blockchain smart contracts, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0272] In some possible implementations, various aspects of a method for protecting the privacy of blockchain smart contracts provided by the present application may also be implemented in the form of a program product, which includes a program code. When the program product is run on a computer device, the program code is used to enable the computer device to execute the steps of a method for protecting the privacy of blockchain smart contracts according to various exemplary embodiments of the present application described above in this specification.
[0273] The program product may employ any combination of one or more readable media. The readable medium may be a readable signal medium or a readable storage medium. The readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0274] The program product for privacy protection of blockchain smart contracts of the embodiments of the present application may adopt a portable compact disk read-only memory (CD-ROM) and include program code, and may be run on an electronic device. However, the program product of the present application is not limited thereto. In this document, a readable storage medium may be any tangible medium containing or storing a program, which may be used by or in combination with an instruction execution system, apparatus, or device.
[0275] The readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, wherein the readable program code is carried. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The readable signal medium may also be any readable medium other than a readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0276] The program code embodied on the readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination of the foregoing.
[0277] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.
Claims
1. A method for protecting the privacy of blockchain smart contracts. It is characterized in that The method comprises: According to the privacy data annotation specification, privacy annotations are added to the data in the original smart contract to obtain a standard smart contract, where the privacy annotations are used to indicate the owner of the data; Traversing the canonical smart contract, parsing the privacy type of expressions in function statements based on privacy annotations; The function statement is converted into a contract based on the smart contract conversion rules. For the addition and subtraction expressions whose privacy type is external private, the public key of the external private owner is used to encrypt each operation item in the addition and subtraction expression using homomorphic encryption to complete the contract conversion of the function statement where the addition and subtraction expression is located; Add a NIZK proof in the converted contract to verify that the converted function statement is equivalent to the original function statement; After the traversal is completed, the converted contract is put on the chain to conduct transactions based on the converted contract.
2. The method according to claim 1, It is characterized in that Adding privacy annotations to the private data in the original smart contract includes at least one of the following steps: For variables that belong to private data, add a privacy identifier and the owner identifier of the variable after the data type of the variable in the original smart contract and before the variable; For expression reclassification statements, add explicit comments that explicitly express the smart contract caller expression to another owner.
3. The method according to claim 1 or 2, It is characterized in that The privacy type of expressions in function statements is resolved based on privacy annotations using the following privacy type determination rules: If the owner of one operand of an expression in a function statement is public, and the owner of another operand is public, the privacy type of the expression is determined to be public; If the owner of one operation item in the expression of the function statement is the smart contract caller, and the owner of the other operation item is public or the smart contract caller, the privacy type of the expression is determined to be self-owned; If the owner of one operand in an expression in a function statement is external private, and the owner of another operand is the same external private or public, the privacy type of the expression is determined to be external private.
4. The method according to claim 3, It is characterized in that The function statement includes a request statement and a variable assignment statement. The privacy type of the expression in the function statement is parsed based on the privacy annotation, including: For multiple expressions with recursive relationships in the function statement, the privacy type of each expression is recursively determined according to the recursive relationship of the expression operation, based on the privacy annotation and privacy type determination rules; The function statements are converted to contracts based on the smart contract conversion rules, including: For expressions with display comments in request statements, or expressions assigned in variable assignment statements, the expression of the top-level private owner in the expression is replaced with function parameters, where the owner of the private owner's expression is the smart contract caller or an external private owner; Generate a constraint instruction for constructing a NIZK proof and add it to a constraint instruction set, wherein the constraint instruction is used to express an equivalence relationship between the plain text of the replaced expression and the function parameter; Among them, when the privacy type of the expression of the function statement is public, the function parameter is equal to the plaintext of the replaced expression. When the privacy type of the expression of the function statement is external private or self-owned, the function parameter is equal to the ciphertext obtained by encrypting the plaintext of the private owner's expression using the public key of the external private owner or the public key of the smart contract caller.
5. The method according to claim 4, It is characterized in that Add NIZK proofs in the converted contract to verify that the converted function statements are equivalent to the original function statements, including: For the constraint instructions of the public function statement, it is equivalent to converting to use the decryption function T in the proof circuit plain Solve the plaintext of the replaced expression and prove the constraint that it is equal to the function argument; For the constraint instructions of the self-owned function statement, it is equivalent to converting to use the decryption function T plain After solving the plain text of the replaced expression according to the decryption rules, the encrypted result is encrypted with the public key of the smart contract caller, which is equal to the proof constraint of the function parameter; Convert the constraint instructions of the external private function statement into equivalent ones using the encryption function T α According to the encryption rules, each operation item in the plain text of the replaced expression is encrypted with the public key of the external private owner, and the proof constraint is equal to the function parameter; Based on the proof constraints, a NIZK proof is added to verify that the converted function statement is equivalent to the original function statement.
6. The method according to claim 5, It is characterized in that Based on the proof constraints, a NIZK proof is added to verify that the converted function statement is equivalent to the original function statement, including: For the initial parameters whose owner is an external private owner or the caller of the smart contract, the ciphertext value of the initial parameters encrypted with the public key of the external private owner or the public key of the caller of the smart contract, the public key of the external private owner, the public key of the caller of the smart contract, and the random number used for encryption are added to the proof function, and the private key of the caller of the smart contract is added to the proof function in a private manner; According to the proof constraints of the public function statement, if the replaced expression contains the initial parameters of the smart contract caller, the initial parameter ciphertext value is obtained from the proof function, and the initial parameter ciphertext value is decrypted using the private key of the smart contract caller, and a proof statement is generated that the replaced expression is equal to the function parameter; According to the proof constraints of the function statement owned by the user, if the replaced expression contains the initial parameters of the smart contract caller, the initial parameter ciphertext value is obtained from the proof function, the initial parameter ciphertext value is decrypted using the private key of the smart contract caller, and then the replaced expression is encrypt with the public key and random number of the smart contract caller, and the proof statement is equal to the function parameter; According to the proof constraints of the external private function statement, if the expression contains the initial parameters of the smart contract caller, the initial parameter ciphertext value is obtained from the proof function, and the initial parameter ciphertext value is decrypted using the private key of the smart contract caller, and then substituted into the replaced expression. Then, the public key of the external private owner is used to encrypt each operation item using homomorphic encryption, and the proof statement is equal to the function parameter.
7. The method according to claim 5, It is characterized in that The decryption rules include: For an expression of a constant, decrypt the expression into the constant; For an expression of an address, decrypt the expression into the address; For an expression that operates on two sub-expressions, the expression is decrypted into two sub-expressions using T plain Decrypt the two sub-expressions before operating; If the expression is a display comment, and it indicates that the private type is the expression of the smart contract caller, the expression is decrypted as T plain Decrypt the expression of the smart contract caller; If the expression has a privacy type of public and is an initial parameter ciphertext value, decrypt the initial parameter ciphertext value; If the privacy type of the expression is self-owned or externally private and it is an initial parameter ciphertext value, the initial parameter ciphertext value is encrypted using the corresponding private key.
8. The method according to claim 5, It is characterized in that The encryption rules include: If the operand in the expression is a constant, the constant is encrypted using the public key of the external private owner; If the operand in the expression is an address, the address is encrypted using the public key of the external private owner; If the operation item in the expression is a variable and the initial parameter ciphertext value of the external private owner, the initial parameter ciphertext value is directly used; If the operand in the expression is a variable and is public, the variable is encrypted using the public key of the external private owner; If the operation item in the expression is a variable including a sub-expression and the privacy type of the sub-expression is public, the sub-expression is encrypted using the public key of the external private owner; If the operation item in the expression is addition or subtraction of two sub-expressions, and the privacy type of the operation item is public, the operation item is encrypted using the public key of the external owner. Otherwise, each sub-expression is encrypted using the public key of the external owner before addition or subtraction. If the operation item in the expression includes a display comment, and it indicates that the expression of the private type of the smart contract caller is explicitly expressed to the external private owner, according to T plain Decrypt the expression of the smart contract caller and encrypt the decrypted expression using the public key of the private owner.
9. A device for protecting the privacy of blockchain smart contracts. It is characterized in that The device comprises: A privacy annotation module is used to add privacy annotations to the data in the original smart contract according to the privacy data annotation specification to obtain a standard smart contract. The privacy annotation is used to indicate the owner of the data; A privacy type parsing module, used to traverse the standard smart contract and parse the privacy type of expressions in function statements based on privacy annotations; A contract conversion module is used to perform contract conversion on function statements based on smart contract conversion rules. For addition and subtraction expressions whose privacy type is external private, each operation item in the addition and subtraction expression is encrypted using the public key of the external private owner in a homomorphic encryption manner to complete the contract conversion of the function statement where the addition and subtraction expression is located; A proof circuit building module, which is used to add NIZK proofs to the converted contract to verify that the converted function statements are equivalent to the original function statements; The contract chain module is used to chain the converted contract after the traversal is completed, so as to conduct transactions based on the converted contract.
10. A device for protecting the privacy of blockchain smart contracts. It is characterized in that It comprises at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method as described in any one of claims 1-8.