Data transmission control method and device applied to block chain network system

By using data transmission control methods in blockchain network systems to generate and manage re-encryption keys, the security risks existing in the intervention of third-party agent service providers in proxy re-encryption technology are solved, and the security of data transmission is improved.

CN120151114AActive Publication Date: 2025-06-13GUANGDONG PLANNING & DESIGNING INST OF TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510623759.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-15
Publication Date
2025-06-13
Estimated Expiration
2045-05-15

AI Technical Summary

Technical Problem

When using proxy re-encryption technology to encrypt and transmit data, there are security risks in the intervention of third-party proxy service providers, which can easily lead to private key leakage, thereby affecting the security of data transmission.

Method used

By introducing a data transmission control method in the blockchain network system, the receiving target data uploaded by the sender generates a first feedback value, and performs a re-encryption operation through the first ciphertext and re-encryption key uploaded by the preset blockchain smart contract to generate a second ciphertext. When a target data acquisition request from the receiver is received, the second cipher text is sent to the receiver to grant it permission to obtain the target data.

Benefits of technology

By generating and managing re-encryption keys, the intervention of third-party agents is reduced, the security of the data transmission process is improved, the security of the private key is ensured, and the risk of private key leakage is reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151114A_ABST
    Figure CN120151114A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of block chains, in particular to a data transmission control method and device applied to a block chain network system. The method comprises the following steps: receiving target data uploaded by a sender, generating a first feedback value according to the target data, and sending the first feedback value to the sender; receiving a first ciphertext and a re-encryption key uploaded by a sender through a preset block chain smart contract; performing re-encryption operation on the first ciphertext according to the re-encryption key to obtain a second ciphertext; and when a target data acquisition request of a receiver is received, sending the second ciphertext to the receiver so as to grant the receiver the permission of acquiring the target data. It can be seen that the secret key is managed through the block chain smart contract, intervention of a third-party agent service provider is not needed, the reliability of privacy protection is enhanced, and the security of the data transmission process is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of blockchain technology, and in particular, to a data transmission control method and device applied to a blockchain network system. Background Art

[0002] Currently, proxy re-encryption technology has been widely used in encrypted data transmission. Proxy re-encryption technology allows an authorized proxy party to convert the ciphertext of a sender into the ciphertext of another receiver without exposing the plaintext. This technology is very useful in data transmission, reducing the processes of decryption and re-encryption and improving communication efficiency.

[0003] However, it is found in practice that there are security risks in the process of using proxy re-encryption technology for encrypted data transmission. For example, the private key of the authorized party needs to be submitted to the authorizer to generate the re-encryption key, which easily leads to the leakage of the private key, thus causing security problems.

[0004] Therefore, how to improve the security of the data transmission process is a technical problem that needs to be solved urgently at present. Summary of the Invention

[0005] The present invention provides a data transmission control method and device applied to a blockchain network system, which can improve the security of the data transmission process.

[0006] To solve the above technical problem, in a first aspect of the present invention, a data transmission control method applied to a blockchain network system is disclosed. The method includes: Receiving target data uploaded by a sender, generating a first feedback value according to the target data, and sending the first feedback value to the sender; Receiving a first ciphertext and a re-encryption key uploaded by the sender through a preset blockchain smart contract; wherein, the first ciphertext is obtained by the sender encrypting the first feedback value, and the re-encryption key is obtained by the sender performing a preset key generation operation according to the public information of the receiver; Performing a re-encryption operation on the first ciphertext according to the re-encryption key to obtain a second ciphertext; When receiving a target data acquisition request from the receiver, sending the second ciphertext to the receiver to grant the receiver the permission to acquire the target data; wherein, the target data acquisition request of the receiver is a request instruction generated by the receiver to acquire the target data.

[0007] As an alternative implementation manner, in the first aspect of the present invention, before receiving the target data uploaded by the sender, generating a first feedback value according to the target data, and sending the first feedback value to the sender, the method further includes: Receiving user identification parameters uploaded by each network system user and uniquely corresponding to the user; wherein, all the network system users include the sender and the receiver; For each network system user, generating a user initial key corresponding to the network system user according to the user identification parameter uniquely corresponding to the network system user, and sending the user initial key to the network system user to trigger an operation for the network system user to generate a user formal key corresponding to the network system user based on the user initial key; the user formal key corresponding to the network system user at least includes a user formal public key; Wherein, the first ciphertext is specifically obtained by the sender encrypting the first feedback value through its corresponding user formal public key; The re-encryption key is specifically obtained by the sender performing a key generation operation according to the user formal public key corresponding to the receiver and the public identity identifier of the receiver.

[0008] As an alternative implementation manner, in the first aspect of the present invention, before receiving the target data uploaded by the sender, generating a first feedback value according to the target data, and sending the first feedback value to the sender, the method further includes: Initializing the blockchain network system to obtain system operation parameters; Wherein, the system operation parameters at least include a system private key, and the system private key is at least used to generate a user initial private key for each network system user; The initializing the blockchain network system to obtain system operation parameters at least includes: Generating a target elliptic curve according to a predetermined first prime number and a second prime number; Constructing a target additive group according to the target elliptic curve; wherein, the target additive group is an additive group formed by multiple points on the target elliptic curve as group elements, and the group elements in the target additive group are used for encryption and / or decryption operations; Screening the group elements in the target additive group according to a predetermined target order to obtain a target high-order subgroup; wherein, the element order of each group element in the target high-order subgroup is equal to the target order; Determine the target generator corresponding to the target high-order subgroup; wherein, the target generator includes group elements in a plurality of the target high-order subgroups, and the group elements in the target generator are used to obtain other group elements in the target high-order subgroup except the target generator through product operations; Generate a system private key according to the target generator and a preset multiplicative cyclic group.

[0009] As an alternative implementation manner, in the first aspect of the present invention, for each network system user, the user initial key corresponding to the network system user includes a user initial public key and a user initial private key; For each network system user, generating the user initial key corresponding to the network system user according to the user identification parameter uniquely corresponding to the network system user includes: For each network system user, determine an initial key parameter uniquely corresponding to the network system user according to the multiplicative cyclic group, perform a product operation on the initial key parameter and the target generator to obtain the user initial public key corresponding to the network system user, and generate a key according to the initial key parameter, the user identification parameter, and the system private key to obtain the user initial private key corresponding to the network system user; Wherein, the initial key parameter is a group element in the multiplicative cyclic group.

[0010] As an alternative implementation manner, in the first aspect of the present invention, for each network system user, the user formal key corresponding to the network system user further includes a user formal private key; After receiving the target data acquisition request of the receiving party and sending the second ciphertext to the receiving party to grant the receiving party the permission to acquire the target data, the method further includes: Receive a second feedback value uploaded by the receiving party obtained by decrypting the second ciphertext with the user formal private key of the receiving party, and determine whether the second feedback value matches the first feedback value. If so, send the target data corresponding to the first feedback value to the receiving party.

[0011] As an alternative implementation manner, in the first aspect of the present invention, after receiving the first ciphertext and the re-encryption key uploaded by the sender through a preset blockchain smart contract, the method further includes: When receiving the target data acquisition request of the sender, send the first ciphertext to the sender; wherein, the target data acquisition request of the sender is a request instruction generated by the sender to acquire the target data; Receive the third feedback value obtained by decrypting the first ciphertext with the official private key of the sender's user, and determine whether the third feedback value matches the first feedback value. If so, send the target data corresponding to the first feedback value to the sender.

[0012] As an optional implementation manner, in the first aspect of the present invention, the blockchain network system includes an IPFS cluster; The step of receiving the target data uploaded by the sender, generating a first feedback value according to the target data, and sending the first feedback value to the sender includes: Receive the target data uploaded by the sender and store the target data in the IPFS cluster; Call the IPFS cluster to generate a first feedback value according to the target data and send the first feedback value to the sender.

[0013] The second aspect of the present invention discloses a data transmission control device applied to a blockchain network system. The device includes: A first data transmission module, configured to receive the target data uploaded by the sender, generate a first feedback value according to the target data, and send the first feedback value to the sender; A second data transmission module, configured to receive the first ciphertext and the re-encryption key uploaded by the sender through a preset blockchain smart contract; wherein, the first ciphertext is obtained by the sender encrypting the first feedback value, and the re-encryption key is obtained by the sender performing a preset key generation operation according to the public information of the receiver; A data re-encryption module, configured to perform a re-encryption operation on the first ciphertext according to the re-encryption key to obtain a second ciphertext; A third data transmission module, configured to send the second ciphertext to the receiver when receiving the target data acquisition request of the receiver, so as to grant the receiver the permission to acquire the target data; wherein, the target data acquisition request of the receiver is a request instruction generated by the receiver to acquire the target data.

[0014] As an optional implementation manner, in the second aspect of the present invention, the device further includes: An identification parameter acquisition module, configured to receive the user identification parameters uniquely corresponding to each network system user uploaded by each network system user before the first data transmission module receives the target data uploaded by the sender, generates a first feedback value according to the target data, and sends the first feedback value to the sender; wherein, all the network system users include the sender and the receiver; An initial key generation module, which is used for each of the network system users to generate a user initial key corresponding to the network system user according to the user identification parameter uniquely corresponding to the network system user, and send the user initial key to the network system user to trigger the operation of the network system user to generate a user formal key corresponding to the network system user based on the user initial key; the user formal key corresponding to the network system user at least includes a user formal public key; Wherein, the first ciphertext is specifically obtained by the sender encrypting the first feedback value with its corresponding user formal public key; The re-encryption key is specifically obtained by the sender performing a key generation operation according to the user formal public key corresponding to the receiver and the public identity identifier of the receiver.

[0015] As an optional implementation manner, in the second aspect of the present invention, the device further includes: A system initialization module, which is used to initialize the blockchain network system to obtain system operation parameters before the first data transmission module receives the target data uploaded by the sender, generates a first feedback value according to the target data, and sends the first feedback value to the sender; Wherein, the system operation parameters at least include a system private key, and the system private key is at least used to generate a user initial private key for each of the network system users; The specific manner in which the system initialization module initializes the blockchain network system to obtain system operation parameters at least includes: Generating a target elliptic curve according to a pre-determined first prime number and a second prime number; Constructing a target additive group according to the target elliptic curve; wherein, the target additive group is an additive group composed of multiple points on the target elliptic curve, and the group elements in the target additive group are used for encryption and / or decryption operations; Screening the group elements in the target additive group according to a pre-determined target order to obtain a target high-order subgroup; wherein, the element order of each group element in the target high-order subgroup is equal to the target order; Determining a target generator corresponding to the target high-order subgroup; wherein, the target generator includes group elements in multiple target high-order subgroups, and the group elements in the target generator are used to obtain other group elements in the target high-order subgroup except the target generator through product operations; Generating a system private key according to the target generator and a preset multiplicative cyclic group.

[0016] As an alternative implementation, in the second aspect of the present invention, for each of the network system users, the user initial key corresponding to the network system user includes a user initial public key and a user initial private key; The specific manner in which the initial key generation module generates the user initial key corresponding to each network system user according to the user identification parameter uniquely corresponding to the network system user includes: For each of the network system users, determine the initial key parameter uniquely corresponding to the network system user according to the multiplicative cyclic group, perform a product operation on the initial key parameter and the target generator to obtain the user initial public key corresponding to the network system user, and perform key generation according to the initial key parameter, the user identification parameter, and the system private key to obtain the user initial private key corresponding to the network system user; Wherein, the initial key parameter is a group element in the multiplicative cyclic group.

[0017] As an alternative implementation, in the second aspect of the present invention, for each of the network system users, the user formal key corresponding to the network system user further includes a user formal private key; The device further includes: A first data matching module, configured to, when receiving the target data acquisition request of the receiving party, after the third data transmission module sends the second ciphertext to the receiving party to grant the receiving party the permission to acquire the target data, receive the second feedback value uploaded by the receiving party after decrypting the second ciphertext with the user formal private key of the receiving party, and determine whether the second feedback value matches the first feedback value. If so, send the target data corresponding to the first feedback value to the receiving party.

[0018] As an alternative implementation, in the second aspect of the present invention, the device further includes: A fourth data transmission module, configured to, after the second data transmission module receives the first ciphertext and the re-encryption key uploaded by the sender through a preset blockchain smart contract, when receiving the target data acquisition request of the sender, send the first ciphertext to the sender; wherein, the target data acquisition request of the sender is a request instruction generated by the sender to acquire the target data; A second data matching module, configured to receive the third feedback value uploaded by the sender after decrypting the first ciphertext with the user formal private key of the sender, and determine whether the third feedback value matches the first feedback value. If so, send the target data corresponding to the first feedback value to the sender.

[0019] As an optional implementation, in the second aspect of the present invention, the blockchain network system includes an IPFS cluster; The specific manner in which the first data transmission module receives the target data uploaded by the sender, generates a first feedback value according to the target data, and sends the first feedback value to the sender includes: Receive the target data uploaded by the sender, and store the target data in the IPFS cluster; The IPFS cluster is called to generate a first feedback value according to the target data, and the first feedback value is sent to the sender.

[0020] The third aspect of the present invention discloses another data transmission control device applied to a blockchain network system, the device comprising: A memory storing executable program code; a processor coupled to the memory; The processor calls the executable program code stored in the memory to execute the data transmission control method applied to the blockchain network system disclosed in the first aspect of the present invention.

[0021] The fourth aspect of the present invention discloses a computer storage medium, which stores computer instructions. When the computer instructions are called by a processor, they are used to execute the data transmission control method applied to the blockchain network system disclosed in the first aspect of the present invention.

[0022] Compared with the prior art, the present invention has the following beneficial effects: In the present invention, after receiving the target data uploaded by the sender, a first feedback value is first generated according to the target data, and then the first feedback value is fed back to the sender, thereby triggering the sender to encrypt the first feedback value to obtain the first ciphertext and generate a re-encryption key; after receiving the first ciphertext and re-encryption key uploaded by the sender through the blockchain smart contract, the first ciphertext is re-encrypted according to the re-encryption key to obtain the second ciphertext, and when the target data acquisition request of the receiver is received, the second ciphertext is sent to the receiver to grant the receiver the right to obtain the target data, and the receiver can obtain the corresponding target data through the second ciphertext. It can be seen that the present invention generates a re-encryption key through the sender, and the key is managed through the blockchain smart contract, without the intervention of a third-party agent service provider, which strengthens the reliability of privacy protection and improves the security of the data transmission process. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0024] Figure 1 It is a schematic flowchart of a data transmission control method applied to a blockchain network system disclosed in an embodiment of the present invention; Figure 2 It is a schematic structural diagram of a data transmission control device applied to a blockchain network system disclosed in an embodiment of the present invention; Figure 3 It is a schematic structural diagram of another data transmission control device applied to a blockchain network system disclosed in an embodiment of the present invention; Figure 4 It is a schematic structural diagram of yet another data transmission control device applied to a blockchain network system disclosed in an embodiment of the present invention; Figure 5 It is a schematic structural diagram of yet another data transmission control device applied to a blockchain network system disclosed in an embodiment of the present invention; Figure 6 It is a schematic structural diagram of yet another data transmission control device applied to a blockchain network system disclosed in an embodiment of the present invention; Figure 7 It is a schematic structural diagram of yet another data transmission control device applied to a blockchain network system disclosed in an embodiment of the present invention. Specific embodiments

[0025] To enable those skilled in the art to better understand the solutions of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0026] The terms "first", "second", etc. in the specification and claims of the present invention and the above accompanying drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, device, product, or terminal that includes a series of steps or units is not limited to the listed steps or units, but may optionally further include steps or units not listed, or may optionally further include other steps or units inherent to these processes, methods, products, or terminals.

[0027] Reference to "embodiment" in this document means that the specific features, structures, or characteristics described in connection with the embodiment may be included in at least one embodiment of the present invention. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein may be combined with other embodiments.

[0028] Currently, proxy re-encryption technology has been widely used in encrypting data transmission. Proxy re-encryption technology allows an authorized proxy party to convert the ciphertext of a sender into the ciphertext of another receiver without exposing the plaintext. This technology is very useful in data transmission, reducing the process of decryption and re-encryption and improving communication efficiency. However, it has been found in practice that there are security risks in the process of using proxy re-encryption technology for data encryption transmission. For example, the private key of the authorized party needs to be submitted to the authorizer to generate the re-encryption key, which is likely to lead to the leakage of the private key, thus causing security problems. Therefore, how to improve the security of the data transmission process is a technical problem that needs to be solved urgently.

[0029] To solve the above technical problems, the present invention discloses a data transmission control method and device applied to a blockchain network system, aiming to improve the security of the data transmission process. The following will be described in detail respectively.

[0030] To better understand the data transmission control method and device applied to the blockchain network system involved in the present invention, first, the blockchain network system applied in the present invention will be described. The blockchain network system applied in the present invention is a peer-to-peer network system established and stored with a large amount of transaction data through technologies such as cryptography and consensus mechanisms. It can be understood that each network system user of the blockchain network system applied in the present invention can be both a sender and a receiver. For a specific piece of data, the network system user uploading the specific data is the sender, and other network system users are potential receivers. And the network system user uploading the specific data is also a potential receiver of the data uploaded by other network system users.

[0031] Embodiment 1 Please refer to Figure 1 , Figure 1 which is a schematic flow diagram of a data transmission control method applied to a blockchain network system disclosed in an embodiment of the present invention. Among them, Figure 1The method shown can be applied to a data transmission control device, which can control the data transmission process of a blockchain network system. Further, the data transmission control device can be integrated into the blockchain network system or exist independently of the blockchain network system, which is not limited in the embodiments of the present invention. As Figure 1 shown, a data transmission control method applied to a blockchain network system disclosed in an embodiment of the present invention includes but is not limited to the following operations: 101. Receive the target data uploaded by the sender, generate a first feedback value according to the target data, and send the first feedback value to the sender.

[0032] In the embodiments of the present invention, the first feedback value is a parameter value that uniquely corresponds to the target data and characterizes the data characteristics of the target data. Further, the hash value of the target data can be calculated through a hash algorithm as the first feedback value of the target data.

[0033] 102. Receive the first ciphertext and the re-encryption key uploaded by the sender through a preset blockchain smart contract; wherein, the first ciphertext is obtained by the sender encrypting the first feedback value, and the re-encryption key is obtained by the sender performing a preset key generation operation according to the public information of the receiver.

[0034] It can be seen that in the embodiments of the present invention, after the sender receives the first feedback value corresponding to the target data it uploads, it encrypts the first feedback value and uploads it to the blockchain network system. At the same time, in order to facilitate the sharing of the target data, a re-encryption key is generated and uploaded to the blockchain network system. The data encryption and transmission operations are completed through the first feedback value, rather than directly encrypting the target data and performing multiple transmission operations, which can not only relieve the on-chain storage pressure of the blockchain network system, but also effectively reduce the possibility of data being tampered with during the transmission process and improve the security of the data transmission process.

[0035] 103. Perform a re-encryption operation on the first ciphertext according to the re-encryption key to obtain a second ciphertext.

[0036] In the embodiments of the present invention, the re-encryption key is obtained by the sender performing a preset key generation operation according to the public information of the receiver. Therefore, only the corresponding receiver can decrypt the re-encrypted second ciphertext, thereby improving the security of data transmission. It should be noted that the sender can generate a re-encryption key according to the public information of multiple receivers, so that the target data can be shared with multiple receivers.

[0037] 104. When receiving a target data acquisition request from the receiver, send the second ciphertext to the receiver to grant the receiver the permission to acquire the target data.

[0038] The target data acquisition request of the receiving party is a request instruction generated by the receiving party to obtain the target data.

[0039] It can be seen that in the embodiment of the present invention, after receiving the target data uploaded by the sender, the first feedback value is first generated according to the target data, and then the first feedback value is fed back to the sender, thereby triggering the sender to encrypt the first feedback value to obtain the first ciphertext and generate a re-encryption key; after receiving the first ciphertext and re-encryption key uploaded by the sender through the blockchain smart contract, the first ciphertext is re-encrypted according to the re-encryption key to obtain the second ciphertext, and when the target data acquisition request of the receiver is received, the second ciphertext is sent to the receiver to grant the receiver the right to obtain the target data, and the receiver can obtain the corresponding target data through the second ciphertext. The present invention generates a re-encryption key by the sender and trusts the key through the blockchain smart contract, without the intervention of a third-party agent service provider, thereby enhancing the reliability of privacy protection and improving the security of the data transmission process. The present invention optimizes the traditional third-party agent service provider, realizes the function of the third-party agent through the blockchain smart contract, and reduces the security risks brought by the traditional third-party agent service provider. In addition, data sharing and use through the data traceability and non-tamperability characteristics of blockchain technology can also improve the security, integrity and authenticity of data storage.

[0040] In an optional embodiment, before receiving the target data uploaded by the sender, generating a first feedback value according to the target data, and sending the first feedback value to the sender, the data transmission control method applied to the blockchain network system of the embodiment of the present invention may further include: Receiving a unique user identification parameter uploaded by each network system user; wherein all network system users include a sender and a receiver; For each network system user, a user initial key corresponding to the network system user is generated according to a user identification parameter uniquely corresponding to the network system user, and the user initial key is sent to the network system user to trigger the network system user to generate a user formal key corresponding to the network system user based on the user initial key; the user formal key corresponding to the network system user at least includes a user formal public key; The first ciphertext is specifically obtained by the sender encrypting the first feedback value using its corresponding user official public key; The re-encryption key is specifically obtained by the sender performing a key generation operation based on the recipient's corresponding user official public key and the recipient's public identity.

[0041] In the embodiments of the present invention, the user initial key is a key with only partial key data content, and the user formal key is a key with complete key data content. First, obtain the user identification parameters of all network system users, then generate user initial keys for all network system users according to the user identification parameters, and send the user initial keys to the corresponding network system users, so that the corresponding network system users generate user formal keys based on the user initial keys. The present invention introduces a certificate-free key mechanism. First, the blockchain network system generates user initial keys with only partial key content and sends them to the network system users. The network system users generate user formal keys with complete key content based on the received user initial keys. The keys are entrusted through the smart contract of the blockchain network system, improving the security of data transmission and data integrity.

[0042] In an optional embodiment, before receiving the target data uploaded by the sender, generating a first feedback value according to the target data, and sending the first feedback value to the sender, the data transmission control method applied to the blockchain network system in the embodiments of the present invention may further include: Initialize the blockchain network system to obtain system operation parameters.

[0043] Among them, the system operation parameters at least include a system private key, and the system private key is at least used to generate the user initial private key of each network system user.

[0044] The specific ways to initialize the blockchain network system to obtain system operation parameters at least include: Generate a target elliptic curve according to a predetermined first prime number and a second prime number; Construct a target additive group according to the target elliptic curve; wherein, the target additive group is an additive group composed of multiple points on the target elliptic curve as group elements, and the group elements in the target additive group are used for encryption and / or decryption operations; Screen the group elements in the target additive group according to a predetermined target order to obtain a target high-order subgroup; wherein, the element order of each group element in the target high-order subgroup is equal to the target order; Determine the target generator corresponding to the target high-order subgroup; wherein, the target generator includes group elements in multiple target high-order subgroups, and the group elements in the target generator are used to obtain other group elements in the target high-order subgroup except the target generator through product operations; Generate a system private key according to the target generator and a preset multiplicative cyclic group.

[0045] In the embodiments of the present invention, a system private key is constructed through the elliptic curve encryption algorithm. The elliptic curve encryption algorithm is an algorithm for encryption based on mathematical operations on an elliptic curve. It can perform encryption and decryption operations through points on the elliptic curve, and has high security and efficiency. The elliptic curve encryption algorithm is widely used in the field of cryptography, such as digital signatures, identity authentication, etc. It is considered an excellent encryption algorithm that can provide strong security protection with a relatively short key length. In the embodiments of the present invention, the blockchain network system is initialized to obtain system operation parameters, thereby constructing a system encryption foundation to ensure the confidentiality and data integrity of the data transmission process.

[0046] It should be noted that the system operation parameters may also include other data or function sets, such as a secure hash function.

[0047] In an optional embodiment, for each network system user, the user initial key corresponding to the network system user includes a user initial public key and a user initial private key.

[0048] For each network system user, generating the user initial key corresponding to the network system user according to the user identification parameter uniquely corresponding to the network system user may include: For each network system user, determining an initial key parameter uniquely corresponding to the network system user according to the multiplicative cyclic group, performing a product operation on the initial key parameter and the target generator to obtain the user initial public key corresponding to the network system user, and generating a key according to the initial key parameter, the user identification parameter, and the system private key to obtain the user initial private key corresponding to the network system user; Wherein, the initial key parameter is a group element in the multiplicative cyclic group.

[0049] In the embodiments of the present invention, the user initial key corresponding to each network system user is generated according to the initialized system operation parameters.

[0050] In an optional embodiment, for each network system user, the user official key corresponding to the network system user further includes a user official private key; When receiving the target data acquisition request of the receiver and sending the second ciphertext to the receiver to grant the receiver the permission to acquire the target data, the data transmission control method applied to the blockchain network system in the embodiments of the present invention may further include: Receiving the second feedback value uploaded by the receiver obtained by decrypting the second ciphertext with the user official private key of the receiver, and determining whether the second feedback value matches the first feedback value. If so, sending the target data corresponding to the first feedback value to the receiver.

[0051] In an embodiment of the present invention, the recipient decrypts the re-encrypted second ciphertext with the user's official private key and uploads it to the blockchain network system. The blockchain network system matches and judges the second feedback value and the first feedback value. When the matching is successful, the target data is sent to the recipient, thereby improving the security and confidentiality during the data transmission process and effectively reducing the situations of information leakage and unauthorized access.

[0052] In an optional embodiment, after receiving the first ciphertext and the re-encryption key uploaded by the sender through a preset blockchain smart contract, the data transmission control method applied to the blockchain network system in the embodiment of the present invention may further include: When receiving the target data acquisition request from the sender, sending the first ciphertext to the sender; wherein, the target data acquisition request of the sender is a request instruction generated by the sender to acquire the target data; Receiving the third feedback value obtained by decrypting the first ciphertext with the user's official private key of the sender uploaded by the sender, and judging whether the third feedback value matches the first feedback value. If so, sending the target data corresponding to the first feedback value to the sender.

[0053] In an embodiment of the present invention, when the sender needs to acquire the previously uploaded target data, it also decrypts the first ciphertext with the user's official private key of the sender to obtain the third feedback value and uploads it to the blockchain network system. The blockchain network system matches and judges the third feedback value and the first feedback value. When the matching is successful, the target data is sent to the sender, thereby maintaining the security and privacy of the data.

[0054] In an optional embodiment, the blockchain network system includes an IPFS cluster; Receiving the target data uploaded by the sender, generating a first feedback value according to the target data, and sending the first feedback value to the sender may include: Receiving the target data uploaded by the sender, and storing the target data in the IPFS cluster; calling the IPFS cluster to generate a first feedback value according to the target data, and sending the first feedback value to the sender.

[0055] In traditional proxy re-encryption technologies, in application scenarios with high computing power requirements, in order to ensure the algorithm operation efficiency, a central server needs to be introduced to uniformly manage the data. If the central server fails or is attacked and its control authority is seized, the entire system may be paralyzed, resulting in service interruption and data leakage and loss, etc.

[0056] In the embodiments of the present invention, the IPFS cluster constitutes a peer-to-peer distributed file system, accessing data through content addressing, improving availability and redundancy. The content caching mechanism reduces the dependence on the network and accelerates data acquisition. The IPFS cluster has the characteristic of decentralization. Blockchain technology can ensure the security, integrity, and authenticity of data after being stored on the chain, but the storage space on the chain is limited, and security precautions need to be taken against other nodes on the chain. Using the IPFS cluster can alleviate the shortage of storage space on the chain, and the IPFS cluster can quickly process data, improving the operating efficiency of the entire system.

[0057] It can be seen that in the embodiments of the present invention, by storing the encrypted data through the IPFS cluster, not only can the data be processed quickly, but also the security risks such as data tampering and server downtime in the traditional centralized storage mechanism can be effectively prevented.

[0058] In another optional embodiment, the specific manner of initializing the blockchain network system to obtain the system operation parameters includes: Determine the security coefficient k of the blockchain network system, select the first prime number p and the second prime number q of k bits in the preset prime number value range, and generate a target elliptic curve E defined on F q ; where F q is the finite field of the second prime number q; Construct a target additive group G according to the target elliptic curve E; Screen the group elements in the target additive group G with the second prime number q as the target order to obtain the target high-order subgroup G q ; Determine the target generator g corresponding to the target high-order subgroup G q ; where g ∈ G q ; Randomly select a system initial key from the preset multiplicative cyclic group Z * q and generate a system formal key according to the system initial key and the target generator g; the system formal key includes the system formal private key system sk and the system formal public key system pk ; Define the following seven collision-resistant secure hash functions (denoted as H 1 , H 2 , H 3 , H 4 , H 5 , H 6 , H 7 ): H 1 : G q ×Gq ×{0, 1} l1 →Z * q ; H 2 : G q ×{0, 1} l1 →Z * q ; H 3 : {0, 1} l2 →Z * q ; H 4 : Z * q →Z * q ; H 5 : Z * q →Z * q ; H 6 : Z * q ×Z * q →{0, 1} l2 ; H 7 : {0, 1} l1 →Z * q ; Among them, l1 is the length of the identity identification ID of the network system user, and l2 is the length of the plaintext space; Make the system operation parameters: {p, q, l1, l2, E, G, G q , g, system pk , H 1 , H 2 , H 3 , H 4 , H 5 , H 6 , H 7} be made public within the blockchain network system.

[0059] In another optional embodiment, denote a certain network system user as user i, and the corresponding user identification parameters include the public parameter T i and the public identity identification ID i , among which, T i = t i g, t i ∈Z * q, t i is the secret value of user i. The specific method for generating the initial user key of user i includes: According to the multiplicative cyclic group Z * q Determine the initial key parameter y uniquely corresponding to user i i ; where y i ∈Z * q ; Generate the initial public key Y of user i i : Y i = y i g; Generate the initial private key k of user i i : k i = y i + system sk H 1 (Y i , T i , ID i ) + H 2 (system sk T i , ID i ).

[0060] The operation for user i to generate the corresponding formal user key based on the initial user key includes: Determine the preset key verification parameter gh; Judge the size of k i gh and Y i + system pk H 1 (Y i , T i , ID i ) + H 2 (t i system pk , ID i ) g; If k i gh and Y i + system pk H 1 (Y i , T i , ID i ) + H 2 (ti system pk ,ID i ) If the values of g are equal, generate the user's official private key sk of user i i =(s i ,t i ) and the user's official public key pk i =(Y i ,T i ), where s i is the private key parameter of user i, and s i =k i -H 2 (t i system pk ,ID i ); If k i gh and Y i +system pk H 1 (Y i ,T i ,ID i )+H 2 (t i system pk ,ID i ) the values of g are not equal, return an invalid output result to the blockchain network system, so that the blockchain network system regenerates a new user initial key for user i.

[0061] It should be noted that the "i" in the superscript or subscript of the above parameters corresponds to user i. When user i uses other symbols for identification, the "i" in the superscript or subscript of the above parameters also changes accordingly but always corresponds to the corresponding user identification symbol. This will not be elaborated in the following embodiments of the present invention.

[0062] In another optional embodiment, the blockchain network system includes an IPFS cluster, and calculates the hash value of the target data through a hash algorithm as the first feedback value of the target data (denoted as Hash1). Denote the sender as user s, then the user's official private key of the sender is sk s , and the user's official public key of the sender is pk s .

[0063] The specific way for the sender to encrypt the first feedback value with its corresponding user's official public key includes: Let z = H 3(Hash1); Z = z g, calculate: S = z (s s + t s ) -1 ; U s = z (Y s + system pk H 1 (Y s , T s , ID s ) + T s ); α = H 4 (s s t s ); θ = H 5 (U s α); C 0 = H 6 (Z, θ) ⊕ Hash1; E(Hash1) = (Z, C 0 , S); Among them, E(Hash1) represents the first ciphertext, z, Z, S, U s , α, θ, C 0 are all intermediate encryption parameters, ⊕ is the exclusive - or operator, s s is the private - key parameter of user s.

[0064] Denote any recipient as user Rj, and j = 1, 2,..., n (there are n recipient users in total). The set of official public keys of all recipients is pk R ={pk R1 , pk R2 ,..., pk Rn}}, and the set of public identity identifiers of all recipients is ID R ={ID R1 , ID R2 ,…, ID Rn}

[0065] The specific method for the sender to perform the key - generation operation to obtain the re - encryption key according to the official public key of the recipient corresponding user and the public identity identifier of the recipient includes: Select a re - encryption parameter β in the multiplicative cyclic group Z * q and calculate: Uj =z (Y j +system pk H 1 (Y j ,T j ,ID j )+T j ); (x - U j )+β = x n +a n-1 x n-1 +... + a 1 x + a 0 ; δ=(s s +t s ) α β -1 ; Among them, β, U j , and δ are all re - encryption key parameters, x is a custom unknown, and {a0, a1,...., an - 1} is a custom parameter group; Generate the re - encryption key rk S→R =(rk 1 , rk 2 )=(δ, {a 0 , a 1 ,...., a n-1})。

[0066] The specific method of re - encrypting the first ciphertext according to the re - encryption key to obtain the second ciphertext includes: Calculate C 1 =rk 1 Z and let C 2 =rk 2 , then the second ciphertext is RE(E(Hash1))=(Z, C 0 , C 1 , C 2 , S), where C 1 , C 2 are re - encryption intermediate parameters.

[0067] The specific method for the recipient to decrypt the second ciphertext with the recipient's user formal private key to obtain the second feedback value includes: Use C 2 ={a 0 ,..., a n-1} to construct a polynomial: f(x)=x n +a n-1 xn-1 +...+a 1 x + a 0 ; Calculate U' j =(s j + t j ) Z; β' = f(U' j ); θ'' = H 5 (C 1 β'); Hash2 = (C 0 ⊕ H 6 (Z, θ'')); Wherein, Hash2 is the decryption feedback value of the recipient, and U' j , β', θ'' are all decryption parameters of the recipient, x is a custom unknown, and {a 0 , a 1 ,...., a n-1} is a custom parameter group; Verify whether Z = S (Y s + system pk H 1 (Y s , T s , ID s ) + T s ) holds. If it holds, then Hash2 is a valid decryption feedback value of the recipient, and Hash2 is marked as the second feedback value; if it does not hold, then a result of invalid parameters is returned to the blockchain network system.

[0068] The specific method for the sender to decrypt the first ciphertext with the sender's formal private key to obtain the third feedback value includes: Calculate: U' s =(s s + t s ) Z; θ' s = H 5 (U' s α); Hash3 = C 0 ⊕ H 6 (Z, θ' s ); Wherein, Hash3 is the decryption feedback value of the sender, and U' s , θ' sThey are all decryption parameters of the sender, and ⊕ is the exclusive OR operator; Verify Z = S (Y s +system pk H 1 (Y s ,T s ,ID s ) + T s ) holds. If it holds, then Hash3 is a valid decryption feedback value of the sender, and Hash3 is marked as the third feedback value; if it does not hold, then a result of invalid parameters is returned to the blockchain network system.

[0069] Embodiment 2 Please refer to Figure 2 , Figure 2 , which is a schematic structural diagram of a data transmission control device applied to a blockchain network system disclosed in an embodiment of the present invention. Among them, Figure 2 The device shown is used to implement the data transmission control method applied to the blockchain network system described in Embodiment 1. This data transmission control device can control the data transmission process of the blockchain network system. Further, this data transmission control device can be integrated in the blockchain network system or exist independently of the blockchain network system, which is not limited in the embodiments of the present invention. As Figure 2 shown, the data transmission control device applied to the blockchain network system disclosed in the embodiment of the present invention includes but is not limited to the following modules: The first data transmission module 201 is configured to receive the target data uploaded by the sender, generate a first feedback value according to the target data, and send the first feedback value to the sender; The second data transmission module 202 is configured to receive the first ciphertext and the re-encryption key uploaded by the sender through a preset blockchain smart contract; wherein, the first ciphertext is obtained by the sender encrypting the first feedback value, and the re-encryption key is obtained by the sender performing a preset key generation operation according to the public information of the receiver; The data re-encryption module 203 is configured to perform a re-encryption operation on the first ciphertext according to the re-encryption key to obtain a second ciphertext; The third data transmission module 204 is configured to send the second ciphertext to the receiver when receiving the target data acquisition request of the receiver, so as to grant the receiver the permission to acquire the target data; wherein, the target data acquisition request of the receiver is a request instruction generated by the receiver to acquire the target data.

[0070] It can be seen that in the embodiment of the present invention, after receiving the target data uploaded by the sender, the first feedback value is first generated according to the target data, and then the first feedback value is fed back to the sender, thereby triggering the sender to encrypt the first feedback value to obtain the first ciphertext and generate a re-encryption key; after receiving the first ciphertext and re-encryption key uploaded by the sender through the blockchain smart contract, the first ciphertext is re-encrypted according to the re-encryption key to obtain the second ciphertext, and when the target data acquisition request of the receiver is received, the second ciphertext is sent to the receiver to grant the receiver the right to obtain the target data, and the receiver can obtain the corresponding target data through the second ciphertext. The present invention generates a re-encryption key by the sender and trusts the key through the blockchain smart contract, without the intervention of a third-party agent service provider, thereby enhancing the reliability of privacy protection and improving the security of the data transmission process. The present invention optimizes the traditional third-party agent service provider, realizes the function of the third-party agent through the blockchain smart contract, and reduces the security risks brought by the traditional third-party agent service provider. In addition, data sharing and use through the data traceability and non-tamperability characteristics of blockchain technology can also improve the security, integrity and authenticity of data storage.

[0071] In an alternative embodiment, see Figure 3 , Figure 3 Schematic diagram of another data transmission control device applied to a blockchain network system disclosed in an embodiment of the present invention. Figure 3 As shown, a data transmission control device applied to a blockchain network system disclosed in an embodiment of the present invention may also include: The identification parameter acquisition module 205 is used to receive the target data uploaded by the sender in the first data transmission module 201, generate a first feedback value according to the target data, and receive a unique corresponding user identification parameter uploaded by each network system user before sending the first feedback value to the sender; wherein all network system users include the sender and the receiver; The initial key generation module 206 is used to generate, for each network system user, a user initial key corresponding to the network system user according to a user identification parameter uniquely corresponding to the network system user, and send the user initial key to the network system user to trigger the network system user to generate a user formal key corresponding to the network system user based on the user initial key; the user formal key corresponding to the network system user at least includes a user formal public key; The first ciphertext is specifically obtained by the sender encrypting the first feedback value using its corresponding user official public key; The re-encryption key is specifically obtained by the sender performing a key generation operation based on the recipient's corresponding user official public key and the recipient's public identity.

[0072] In the embodiments of the present invention, the user initial key is a key with only partial key data content, and the user formal key is a key with complete key data content. First, obtain the user identification parameters of all network system users, then generate user initial keys for all network system users according to the user identification parameters, and send the user initial keys to the corresponding network system users, so that the corresponding network system users generate user formal keys based on the user initial keys. The present invention introduces a certificate-free key mechanism. First, the blockchain network system generates user initial keys with only partial key content and sends them to the network system users. The network system users generate user formal keys with complete key content based on the received user initial keys. The keys are entrusted through the smart contract of the blockchain network system, improving the security of data transmission and data integrity.

[0073] In an alternative embodiment, please refer to Figure 4 , Figure 4 which is a schematic structural diagram of another data transmission control device applied to a blockchain network system disclosed in the embodiments of the present invention. As Figure 4 shown, a data transmission control device applied to a blockchain network system disclosed in the embodiments of the present invention may further include: A system initialization module 207, configured to initialize the blockchain network system to obtain system operation parameters before the first data transmission module 201 receives the target data uploaded by the sender, generates a first feedback value according to the target data, and sends the first feedback value to the sender; wherein the system operation parameters at least include a system private key, and the system private key is at least used to generate the user initial private key of each network system user; The specific manner in which the system initialization module 207 initializes the blockchain network system to obtain system operation parameters at least includes: Generating a target elliptic curve according to a predetermined first prime number and a second prime number; Constructing a target additive group according to the target elliptic curve; wherein, the target additive group is an additive group composed of multiple points on the target elliptic curve, and the group elements in the target additive group are used for encryption and / or decryption operations; Screening the group elements in the target additive group according to a predetermined target order to obtain a target high-order subgroup; wherein, the element order of each group element in the target high-order subgroup is equal to the target order; Determining a target generator corresponding to the target high-order subgroup; wherein, the target generator includes group elements in multiple target high-order subgroups, and the group elements in the target generator are used to obtain other group elements in the target high-order subgroup except the target generator through product operations; Generating a system private key according to the target generator and a preset multiplicative cyclic group.

[0074] In the embodiment of the present invention, the system private key is constructed by using the elliptic curve encryption algorithm. The elliptic curve encryption algorithm is an algorithm for encryption based on mathematical operations on an elliptic curve. It can perform encryption and decryption operations through points on the elliptic curve, and has high security and efficiency. The elliptic curve encryption algorithm is widely used in the field of cryptography, such as digital signatures, identity authentication, etc. It is considered an excellent encryption algorithm that can provide strong security protection with a relatively short key length.

[0075] It can be seen that in the embodiment of the present invention, by initializing the blockchain network system to obtain system operation parameters, the system encryption foundation is constructed to ensure the confidentiality and data integrity of the data transmission process.

[0076] In an optional embodiment, for each network system user, the user initial key corresponding to the network system user includes a user initial public key and a user initial private key; The specific manner in which the initial key generation module 206 generates the user initial key corresponding to each network system user according to the user identification parameter uniquely corresponding to the network system user includes: For each network system user, an initial key parameter uniquely corresponding to the network system user is determined according to the multiplicative cyclic group, the initial key parameter and the target generator are multiplied to obtain the user initial public key corresponding to the network system user, and a key is generated according to the initial key parameter, the user identification parameter and the system private key to obtain the user initial private key corresponding to the network system user; Wherein, the initial key parameter is a group element in the multiplicative cyclic group.

[0077] In the embodiment of the present invention, the user initial key corresponding to each network system user is generated according to the system operation parameters obtained by initialization.

[0078] In an optional embodiment, for each network system user, the user official key corresponding to the network system user further includes a user official private key; Please refer to Figure 5 , Figure 5 which is a schematic structural diagram of another data transmission control device applied to the blockchain network system disclosed in the embodiment of the present invention. As Figure 5 shown, a data transmission control device applied to the blockchain network system disclosed in the embodiment of the present invention may further include: The first data matching module 208 is configured to, when receiving a target data acquisition request from the recipient, after the third data transmission module 204 sends the second ciphertext to the recipient to grant the recipient the permission to acquire the target data, receive the second feedback value uploaded by the recipient, which is obtained by decrypting the second ciphertext with the official private key of the recipient's user, and determine whether the second feedback value matches the first feedback value. If so, the target data corresponding to the first feedback value is sent to the recipient.

[0079] In the embodiment of the present invention, the recipient decrypts the re-encrypted second ciphertext with the official private key of the user and uploads it to the blockchain network system. The blockchain network system judges the matching between the second feedback value and the first feedback value. When the matching is successful, the target data is sent to the recipient, thereby improving the security and confidentiality in the data transmission process and effectively reducing the situations of information leakage and unauthorized access.

[0080] In an alternative embodiment, please refer to Figure 6 , Figure 6 which is a schematic structural diagram of another data transmission control device applied to the blockchain network system disclosed in the embodiment of the present invention. As Figure 6 shown, a data transmission control device applied to the blockchain network system disclosed in the embodiment of the present invention may further include: The fourth data transmission module 209 is configured to, after the second data transmission module 202 receives the first ciphertext and the re-encryption key uploaded by the sender through a preset blockchain smart contract, when receiving a target data acquisition request from the sender, send the first ciphertext to the sender; wherein, the target data acquisition request of the sender is a request instruction generated by the sender to acquire the target data; The second data matching module 210 is configured to receive the third feedback value uploaded by the sender, which is obtained by decrypting the first ciphertext with the official private key of the sender's user, and determine whether the third feedback value matches the first feedback value. If so, the target data corresponding to the first feedback value is sent to the sender.

[0081] In the embodiment of the present invention, when the sender needs to acquire the previously uploaded target data, the sender also decrypts the first ciphertext with the official private key of the sender's user to obtain the third feedback value and uploads it to the blockchain network system. The blockchain network system judges the matching between the third feedback value and the first feedback value. When the matching is successful, the target data is sent to the sender, thereby maintaining the security and privacy of the data.

[0082] In an alternative embodiment, the blockchain network system includes an IPFS cluster; The specific manner in which the first data transmission module 201 receives the target data uploaded by the sender, generates the first feedback value according to the target data, and sends the first feedback value to the sender includes: Receive the target data uploaded by the sender and store the target data in the IPFS cluster; Call the IPFS cluster to generate a first feedback value based on the target data and send the first feedback value to the sender.

[0083] In traditional proxy re-encryption technology, in application scenarios with high computing power requirements, in order to ensure the operation efficiency of the algorithm, a central server needs to be introduced to uniformly manage data. If the central server fails or is attacked and its control authority is seized, the entire system may be paralyzed, resulting in service interruption, data leakage, loss, etc.

[0084] In the embodiments of the present invention, the IPFS cluster constitutes a peer-to-peer distributed file system, accessing data through content addressing, improving availability and redundancy. The content caching mechanism reduces the dependence on the network and accelerates data acquisition. The IPFS cluster has the characteristic of decentralization. Blockchain technology can ensure the security, integrity, and authenticity of data after being stored on the chain, but the storage space on the chain is limited, and security precautions need to be taken against other nodes on the chain. Using the IPFS cluster to alleviate the shortage of storage space on the chain, and the IPFS cluster can quickly process data, improving the operation efficiency of the entire system.

[0085] It can be seen that in the embodiments of the present invention, by storing the encrypted data in the IPFS cluster, not only can data be processed quickly, but also security risks such as data tampering and server downtime in traditional centralized storage mechanisms can be effectively prevented.

[0086] Embodiment Three Please refer to Figure 7 , Figure 7 which is a schematic structural diagram of another data transmission control device applied to the blockchain network system disclosed in the embodiments of the present invention. Among them, Figure 7 the device shown is used to implement the data transmission control method applied to the blockchain network system described in Embodiment One. This data transmission control device can control the data transmission process of the blockchain network system. Further, this data transmission control device can be integrated in the blockchain network system or exist independently of the blockchain network system, which is not limited in the embodiments of the present invention. As Figure 7 shown, the data transmission control device applied to the blockchain network system disclosed in the embodiments of the present invention includes but is not limited to: A memory 301 storing executable program code; A processor 302 coupled to the memory 301; The processor 302 calls the executable program code stored in the memory 301 to execute some or all of the steps in the data transmission control method applied to the blockchain network system described in Embodiment One of the present invention.

[0087] Example 4 An embodiment of the present invention discloses a computer storage medium. When the computer instructions stored in the computer storage medium are called by a processor, they are used to execute some or all of the steps in the data transmission control method applied to the blockchain network system described in Embodiment 1 of the present invention.

[0088] The device embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separated. The components shown as modules may or may not be physical modules. They may be located in one place or distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.

[0089] Through the above specific descriptions of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the above technical solution, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, including read-only memory (ROM), random access memory (RAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), one-time programmable read-only memory (OTPROM), electrically-erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc memories, magnetic disk memories, tape memories, or any other computer-readable medium capable of carrying or storing data.

[0090] Finally, it should be noted that the data transmission control method and device disclosed in the embodiments of the present invention are only the preferred embodiments of the present invention, which are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A data transmission control method applied to a blockchain network system, characterized in that: The method comprises: receiving target data uploaded by a sender, generating a first feedback value according to the target data, and sending the first feedback value to the sender; Receive a first ciphertext and a re-encryption key uploaded by the sender through a preset blockchain smart contract; wherein the first ciphertext is obtained by the sender encrypting the first feedback value, and the re-encryption key is obtained by the sender performing a preset key generation operation according to the public information of the receiver; Re-encrypt the first ciphertext according to the re-encryption key to obtain a second ciphertext; When the target data acquisition request of the recipient is received, the second ciphertext is sent to the recipient to grant the recipient the authority to obtain the target data; wherein the target data acquisition request of the recipient is a request instruction generated by the recipient to obtain the target data.

2. The data transmission control method applied to the blockchain network system according to claim 1 is characterized in that: Before receiving the target data uploaded by the sender, generating a first feedback value according to the target data, and sending the first feedback value to the sender, the method further includes: Receiving a unique user identification parameter uploaded by each network system user; wherein all the network system users include the sender and the receiver; For each of the network system users, an initial user key corresponding to the network system user is generated according to a user identification parameter uniquely corresponding to the network system user, and the initial user key is sent to the network system user to trigger the network system user to generate a formal user key corresponding to the network system user based on the initial user key; the formal user key corresponding to the network system user includes at least a formal user public key; The first ciphertext is specifically obtained by the sender encrypting the first feedback value using its corresponding user official public key; The re-encryption key is specifically obtained by the sender performing a key generation operation according to the user formal public key corresponding to the receiver and the public identity of the receiver.

3. The data transmission control method applied to the blockchain network system according to claim 2 is characterized in that: Before receiving the target data uploaded by the sender, generating a first feedback value according to the target data, and sending the first feedback value to the sender, the method further includes: Initializing the blockchain network system to obtain system operating parameters; Wherein, the system operation parameters at least include a system private key, and the system private key is at least used to generate an initial private key of each user of the network system; Initializing the blockchain network system to obtain system operating parameters at least includes: Generate a target elliptic curve according to a predetermined first prime number and a second prime number; Constructing a target additive group according to the target elliptic curve; wherein the target additive group is an additive group composed of a plurality of points on the target elliptic curve as group elements, and the group elements in the target additive group are used for performing encryption and / or decryption operations; The group elements in the target additive group are screened according to a predetermined target order to obtain a target high-order subgroup; wherein the element order of each group element in the target high-order subgroup is equal to the target order; Determine a target generator corresponding to the target high-order subgroup; wherein the target generator includes a plurality of group elements in the target high-order subgroup, and the group elements in the target generator are used to obtain other group elements in the target high-order subgroup except the target generator through a product operation; A key is generated according to the target generator and a preset multiplication cyclic group to obtain a system private key.

4. The data transmission control method applied to the blockchain network system according to claim 3 is characterized in that: For each of the network system users, the user initial key corresponding to the network system user includes a user initial public key and a user initial private key; For each of the network system users, generating a user initial key corresponding to the network system user according to a user identification parameter uniquely corresponding to the network system user includes: For each of the network system users, determining an initial key parameter uniquely corresponding to the network system user according to the multiplication cyclic group, performing a product operation on the initial key parameter and the target generator to obtain an initial user public key corresponding to the network system user, and performing key generation according to the initial key parameter, the user identification parameter and the system private key to obtain an initial user private key corresponding to the network system user; The initial key parameter is a group element in the multiplication cycle group.

5. The data transmission control method applied to the blockchain network system according to claim 2 is characterized in that: For each of the network system users, the user formal key corresponding to the network system user also includes the user formal private key; After the second ciphertext is sent to the recipient to grant the recipient a right to obtain the target data upon receiving the target data acquisition request from the recipient, the method further includes: Receive a second feedback value uploaded by the receiver obtained by decrypting the second ciphertext using the receiver's user formal private key, and determine whether the second feedback value matches the first feedback value; if so, send the target data corresponding to the first feedback value to the receiver.

6. The data transmission control method applied to the blockchain network system according to claim 5 is characterized in that: After receiving the first ciphertext and the re-encryption key uploaded by the sender through a preset blockchain smart contract, the method further includes: When receiving the target data acquisition request of the sender, sending the first ciphertext to the sender; wherein the target data acquisition request of the sender is a request instruction generated by the sender to obtain the target data; Receive a third feedback value uploaded by the sender obtained by decrypting the first ciphertext using the sender's user formal private key, and determine whether the third feedback value matches the first feedback value; if so, send the target data corresponding to the first feedback value to the sender.

7. The data transmission control method applied to a blockchain network system according to any one of claims 1 to 6, characterized in that: The blockchain network system includes an IPFS cluster; The receiving target data uploaded by the sender, generating a first feedback value according to the target data, and sending the first feedback value to the sender includes: Receive the target data uploaded by the sender, and store the target data in the IPFS cluster; The IPFS cluster is called to generate a first feedback value according to the target data, and the first feedback value is sent to the sender.

8. A data transmission control device applied to a blockchain network system, characterized in that: The device comprises: A first data transmission module, configured to receive target data uploaded by a sender, generate a first feedback value according to the target data, and send the first feedback value to the sender; A second data transmission module is used to receive the first ciphertext and the re-encryption key uploaded by the sender through a preset blockchain smart contract; wherein the first ciphertext is obtained by the sender encrypting the first feedback value, and the re-encryption key is obtained by the sender performing a preset key generation operation according to the public information of the receiver; a data re-encryption module, configured to perform a re-encryption operation on the first ciphertext according to the re-encryption key to obtain a second ciphertext; The third data transmission module is used to send the second ciphertext to the recipient when receiving the recipient's target data acquisition request, so as to grant the recipient the authority to obtain the target data; wherein the recipient's target data acquisition request is a request instruction generated by the recipient to obtain the target data.

9. A data transmission control device applied to a blockchain network system, characterized in that: The device comprises: A memory storing executable program code; a processor coupled to the memory; The processor calls the executable program code stored in the memory to execute the data transmission control method applied to the blockchain network system as described in any one of claims 1 to 7.

10. A computer storage medium, characterized in that: The computer storage medium stores computer instructions, which, when called by the processor, are used to execute the data transmission control method applied to the blockchain network system as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Private data access control method based on alliance chain smart contract

    CN115580431A

  • System and method for protecting, managing and monetizing creative works using blockchain

    US20220229883A1