Block chain-based electronic commerce transaction privacy protection method and device, and medium
By building a privacy protection transaction management system in e-commerce, using blockchain and IPFS distributed storage and encryption technology, the problem of difficult to balance node credibility, abuse of permissions and privacy protection and performance is solved, and efficient, secure and privacy-protected e-commerce transaction management is achieved.
Patent Information
- Application Number
- CN202510240386.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-03
- Publication Date
- 2025-06-17
AI Technical Summary
In e-commerce, although the distributed storage and decentralization of blockchain technology improve transaction security, it also threatens user anonymity, making it difficult to balance privacy protection and performance, and the problem of node credibility and abuse of permissions is difficult to solve.
Adopting blockchain-based e-commerce transaction privacy protection methods, a privacy protection transaction management system is built, including functional layer and protocol, through data encryption transmission protocol and node consensus protocol, transaction content encryption, identity and balance verification, order storage, transaction details decryption and dispute resolution.
It effectively reduces the impact of node credibility on transmission, enhances the privacy and security of transactions, reduces transaction fees and resource consumption, and realizes efficient, secure and privacy-protected e-commerce transaction management.
Smart Images

Figure CN120163583A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical fields of blockchain and information security, and particularly to a method, device, and medium for protecting the privacy of e-commerce transactions based on blockchain. Background Art
[0002] In today's rapidly developing e-commerce, privacy and security issues have become increasingly important. The personal information provided by users in online transactions may be maliciously obtained by unauthorized third parties, resulting in serious privacy leaks. Due to the lack of transparency and insufficient security measures on e-commerce platforms, the transaction data and user information stored on servers are extremely vulnerable to cyberattacks and unauthorized access, increasing the risk of data theft or leakage. In addition, fraudulent transactions by malicious users, such as false purchases or refund scams, further exacerbate the security issues of online transactions. These problems indicate that it is necessary to adopt more comprehensive security measures to protect users' personal information and transaction data.
[0003] Implementing blockchain technology in e-commerce applications can bring many benefits, especially in enhancing the security of online transactions. Blockchain is known for its distributed storage, immutability, and traceability, and is considered an ideal choice for storing and trading digital assets. By distributing data across numerous network nodes, it reduces the reliance on single points of failure. On the blockchain, user identity information is protected and can only be accessed with the user's consent, effectively preventing unauthorized data access. Once transaction data is recorded on the blockchain, it cannot be altered, and each transaction has an accurate timestamp, ensuring data integrity, reducing the risk of tampering, and facilitating data traceability. However, the inherent characteristics of distributed ledgers and decentralization may pose a threat to user anonymity, which has become the main limiting factor in the application of blockchain in e-commerce. Therefore, protecting user privacy is a key challenge when deploying blockchain technology in e-commerce transactions.
[0004] Existing information hiding technologies, such as ring signatures, stealth addresses, confidential transactions, and zero-knowledge proofs, can not only ensure the verifiability of transactions but also ensure the confidentiality of identity and transaction amount information. For example, Monero achieves a higher level of privacy protection through a combination of the CryptoNote protocol and M-LSAGs, although there are certain transaction volume limitations. Zerocash enables fully anonymous transactions through the zk-SNARKs protocol, while Zether provides a method for Ethereum users to conduct anonymous transactions through smart contracts and non-interactive zero-knowledge proof protocols. In addition, BlockMaze utilizes a dual balance model based on zk-SNARKs to protect user privacy.
[0005] However, while implementing these privacy protection mechanisms, the following problems still exist: Firstly, there is the issue of node credibility. Current research evaluates and incentivizes the reliability of nodes through reward and punishment mechanisms based on smart contracts (such as the trust chain and the TRM framework), or uses technologies such as zero-knowledge proof and Pedersen commitments to reduce the impact of node credibility on transmission accuracy. Designing and implementing smart contracts to evaluate node credibility and apply rewards and punishments requires complex programming and smart contract logic, thus increasing the development and maintenance costs. In addition, frequent execution of smart contracts incurs high transaction fees, and the lack of a consistent and interoperable standardized method poses challenges to designing fair smart contracts across different systems. Therefore, minimizing the impact of node credibility on transmission becomes a more effective and reliable solution. However, in some cases, achieving a higher level of privacy protection may require sacrificing certain performance. Therefore, finding an effective method to reduce the impact of node credibility on transmission accuracy has become an urgent problem to be solved. Summary of the Invention
[0006] The object of the present invention is to provide a blockchain-based privacy protection method, device, and medium for e-commerce transactions, which can solve the problems of node credibility, abuse of permissions, and the difficulty in balancing privacy protection and performance.
[0007] To achieve the above object, the present invention provides the following solutions:
[0008] A blockchain-based privacy protection method for e-commerce transactions, comprising:
[0009] Construct a privacy protection transaction management system; the privacy protection transaction management system includes a function layer and protocols; the function layer includes a user layer, a verification layer, an authorization layer, and a storage layer composed of a blockchain and IPFS; the protocols include a data encryption transmission protocol and a node consensus protocol;
[0010] Conduct transactions based on the privacy protection transaction management system; the process of the transaction specifically includes:
[0011] Encrypt the transaction content to generate order encrypted data;
[0012] Verify the identities of both parties to the transaction and the buyer's balance, upload them to the blockchain, and generate a verification result;
[0013] After the verification result passes, the buyer uploads the order encrypted data to IPFS and stores it in the blockchain;
[0014] Decrypt the shards of the order encrypted data in IPFS, and the seller obtains the complete transaction details;
[0015] Deliver goods and update status according to transaction details, and generate respective Pedersen commitments using the transaction details and upload them to the blockchain;
[0016] When a transaction dispute occurs, relevant third parties and the two trading parties respectively provide their Pedersen commitments, and the dispute resolution plan is determined based on the results of the three-party commitments.
[0017] Optionally, encrypt the transaction content to generate order encrypted data, specifically including:
[0018] A trusted institution generates ECC keys and distributes them to the two trading parties;
[0019] Let the buyer generate a shared key using its own private key and the seller's public key, and encrypt the order details according to the shared key to obtain the order encrypted data.
[0020] Optionally, verify the identities of the two trading parties and the buyer's balance, upload them to the blockchain and generate verification results, specifically including:
[0021] Let the buyer and the seller generate Schnorr signatures for identity verification, specifically expressed as:
[0022] R = g k , s = k + x·H(m, R)
[0023] g s = R·y H(m,R)
[0024] Among them, R represents the signature random number generated by the random number k, x represents the private key, y represents the public key, m represents the hidden information, g represents the group generator, s represents the signature value, and H represents the hash calculation of the information and the random number;
[0025] Let the buyer generate a Bulletproof to prove the validity of the balance;
[0026] Upload the identity verification and validity verification to the blockchain, and let the miners verify the signatures and balances, and record the verification results through the consensus algorithm.
[0027] Optionally, after the verification result passes, the buyer uploads the order encrypted data to IPFS and stores it in the blockchain, specifically including:
[0028] Let the miners initiate an authorization proposal based on the verification results, grant the buyer the permission to upload data after the verification result passes, and the buyer uploads the order encrypted data to IPFS and associates it with the transaction information contract stored in the blockchain.
[0029] Optionally, decrypt the sharded encrypted order data in IPFS, and the seller obtains the complete transaction details, specifically including:
[0030] Let the seller decrypt the sharded encrypted order data in IPFS with its own private key to obtain the complete transaction details.
[0031] Optionally, perform commodity delivery and status update according to the transaction details, and generate respective Pedersen commitments using the transaction details and upload them to the blockchain, specifically including:
[0032] After the seller ships the goods according to the transaction details, update the seller's status to "successful". After the buyer receives the goods, update the buyer's status to "successful", and let both parties to the transaction generate their respective Pedersen commitments using the transaction details and upload them to the blockchain.
[0033] The present invention also provides an electronic device, including a memory and a processor. The memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the blockchain-based e-commerce transaction privacy protection method described above.
[0034] The present invention also provides a computer-readable storage medium, characterized in that it stores a computer program, and when the computer program is executed by a processor, it implements the blockchain-based e-commerce transaction privacy protection method described above.
[0035] According to the specific embodiments provided by the present invention, the following technical effects are disclosed:
[0036] The present invention discloses a method, device and medium for privacy protection in e-commerce transactions based on blockchain. The method includes constructing a privacy protection transaction management system. The privacy protection transaction management system includes a function layer and protocols. The function layer includes a user layer, a verification layer, an authorization layer, and a storage layer composed of blockchain and IPFS. The protocols include a data encryption transmission protocol and a node consensus protocol. Transactions are carried out based on the privacy protection transaction management system. The process of the transaction specifically includes: encrypting the transaction content to generate order encrypted data; verifying the identities of both parties to the transaction and the buyer's balance, uploading them to the blockchain and generating a verification result; after the verification result passes, the buyer uploads the order encrypted data to IPFS and stores it in the blockchain; decrypting the shards of the order encrypted data in IPFS, and the seller obtains the complete transaction details; delivering the goods and updating the status according to the transaction details, and generating their respective Pedersen commitments using the transaction details and uploading them to the blockchain; when a transaction dispute occurs, relevant third parties and both parties to the transaction respectively provide their Pedersen commitments, and the dispute resolution plan is determined based on the results of the three-party commitments. The present invention solves the problem of privacy performance trade-off while strengthening the constraint on node behavior and establishing a reliable trust mechanism for e-commerce transactions. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required to be used in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0038] Figure 1 It is a schematic diagram of the system roles and functions in this embodiment;
[0039] Figure 2 It is a schematic diagram of the system architecture in this embodiment;
[0040] Figure 3 It is a schematic diagram of the transaction process in this embodiment;
[0041] Figure 4 It is a schematic diagram of the TPS results in different node numbers and transaction scenarios in this embodiment;
[0042] Figure 5 It is a schematic diagram of the comparison results of GAS consumption between this embodiment and the existing solution;
[0043] Figure 6 It is a schematic diagram of the comparison results of the time consumption between this embodiment and the existing solution;
[0044] Figure 7Schematic diagram of the comparison result of data size between this embodiment and the existing solution. Detailed implementation manner
[0045] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0046] The purpose of the present invention is to provide a method, device and medium for privacy protection of e-commerce transactions based on blockchain, which can solve the problems of node credibility, abuse of authority, and the difficulty in balancing privacy protection and performance.
[0047] To make the above objects, features and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below in conjunction with the accompanying drawings and specific implementation manners.
[0048] The present invention provides a method for privacy protection of e-commerce transactions based on blockchain, including:
[0049] Construct a privacy protection transaction management system; the privacy protection transaction management system includes a function layer and a protocol; the function layer includes a user layer, a verification layer, an authorization layer, and a storage layer composed of blockchain and IPFS; the protocol includes a data encryption transmission protocol and a node consensus protocol;
[0050] Conduct transactions based on the privacy protection transaction management system; the process of the transaction specifically includes:
[0051] Encrypt the transaction content to generate order encrypted data; verify the identities of both parties to the transaction and the buyer's balance, upload them to the blockchain and generate a verification result; after the verification result passes, the buyer uploads the order encrypted data to IPFS and stores it in the blockchain; decrypt the shards of the order encrypted data in IPFS, and the seller obtains the complete transaction details; deliver the goods and update the status according to the transaction details, and use the transaction details to generate their respective Pedersen commitments and upload them to the blockchain; when a transaction dispute occurs, relevant third parties and both parties to the transaction respectively provide their Pedersen commitments, and the dispute resolution plan is determined based on the results of the three-party commitments.
[0052] As a specific implementation manner, the privacy protection transaction management system is described in detail.
[0053] (I) System overview
[0054] The system realizes the security and reliability of e-commerce physical commodity transactions through the following core functions:
[0055] 1. Encryption and Privacy Protection: Encrypt transaction data through encryption algorithms such as ECC and AES to ensure data privacy.
[0056] 2. Distributed Access Control: Miners complete the verification of transaction legality through consensus algorithms and manage the access rights of transaction data.
[0057] 3. Data Verification and Traceability: Use the blockchain to record transaction metadata and permission management, and store transaction details and proofs through IPFS to ensure data immutability and traceability.
[0058] 4. Fair Transaction Mechanism: Ensure transaction fairness through key sharing, commitment mechanisms (such as Pedersen commitment), and dispute resolution solutions.
[0059] (II) Main Roles and Responsibilities of the System
[0060] 1. Buyer: Initiate a transaction request, complete identity authentication and balance proof, pay the transaction amount, and submit a receipt proof.
[0061] 2. Seller: Receive the transaction request, confirm the order, complete identity authentication, and submit a shipping proof.
[0062] 3. Trusted Institution: Responsible for key generation and distribution, and conduct transaction authorization management.
[0063] 4. Miner: Responsible for blockchain consensus, verifying transaction legality and completion status, and executing smart contracts.
[0064] 5. Blockchain and IPFS: The blockchain stores transaction metadata and permission management information; IPFS stores transaction details and proofs to ensure data integrity and privacy.
[0065] The interactions of the above roles in the e-commerce transaction scenario are as Figure 1 shown.
[0066] (III) System Architecture
[0067] As Figure 2 shown, the present invention mainly consists of 4 layers and 2 protocols.
[0068] 1. User Layer
[0069] 1) Function Description:
[0070] The user layer mainly includes two types of users: buyers and sellers.
[0071] a) The buyer is responsible for initiating a transaction request, submitting an order, completing identity authentication and balance proof, and paying the transaction amount;
[0072] b) The seller is responsible for receiving transaction requests, confirming orders, submitting identity authentication and proof of delivery, and updating the transaction status.
[0073] 2) Core functions:
[0074] The user layer interacts with the lower layer through the node consensus protocol to meet the user's transaction needs and ensure data security.
[0075] 2. Verification layer
[0076] 1) Function description:
[0077] The verification layer consists of multiple verification nodes, mainly responsible for user identity authentication, balance proof verification, and transaction legality verification. The verification process includes verifying identity through Schnorr signatures, verifying balances through Bulletproof, and confirming the legality of transactions through consensus algorithms.
[0078] 2) Core functions:
[0079] Through a distributed verification mechanism, ensure the authenticity and security of transactions, and prevent identity forgery and malicious operations.
[0080] 3. Authorization layer
[0081] 1) Function description:
[0082] The authorization layer consists of multiple authorization nodes, responsible for managing permissions and authorizing transaction requests based on verification results.
[0083] The authorization process includes initiating authorization proposals, consensus voting, and executing permission distribution to ensure that the data access permissions of both parties to the transaction meet the transaction requirements.
[0084] 2) Core functions:
[0085] Ensure the privacy of data and the security of authorization management during the transaction process, and prevent unauthorized data operations.
[0086] 4. Storage layer
[0087] 1) Function description:
[0088] The storage layer consists of a blockchain and IPFS, responsible for storing and managing transaction data:
[0089] a) Blockchain: Used to store transaction metadata, permission management information, and transaction status, ensuring data immutability and traceability.
[0090] b) IPFS: Used to store transaction details and proof data, providing efficient distributed storage functions to ensure data integrity and privacy.
[0091] 2) Core functions:
[0092] Provide reliable storage support for the system to achieve data transparency and efficient storage.
[0093] 5. Data Encryption Transmission Protocol
[0094] 1) Function description:
[0095] The system realizes secure data exchange between layers through the data encryption transmission protocol.
[0096] The encryption methods include AES key encryption, ECC encryption, and address obfuscation to ensure the privacy and security of data during transmission.
[0097] 2) Core role:
[0098] Prevent data leakage and tampering during transmission to ensure the security of user information and transaction data.
[0099] 6. Node Consensus Protocol
[0100] 1) Function description:
[0101] The verification nodes and authorization nodes work together through the node consensus protocol to ensure the legality and consistency of verification results and authorization proposals.
[0102] The protocol adopts a distributed consensus algorithm to ensure the security and robustness of the system.
[0103] 2) Core role:
[0104] Provide reliable technical support for the system's distributed verification and authorization mechanism to avoid single-point failures and malicious attacks.
[0105] (IV) Main Algorithms
[0106] 1. Privacy Protection Algorithm:
[0107] In the present invention, the privacy protection algorithm mainly encrypts the important information of users and transactions through encryption algorithms to ensure the concealment of data and prevent the leakage of user information. At the same time, zero-knowledge proof and Pedersen commitment algorithms are used to ensure the anonymity of user identities, limit the knowledge scope of third-party agents, and complete interactions with third parties with a small amount of information.
[0108] 1) Data Encryption:
[0109] Amount and order information: Achieved through encryption using the shared key shards generated by ECC and AES
[0110] 2) Information Hiding:
[0111] Identity Verification: Use the Schnorr protocol to generate a digital signature for the trading account to prove the legal identities of both trading parties.
[0112] Proof of Amount Range: Use Bulletproof range proof to prove that the balance of the account is sufficient to pay for the price of the goods.
[0113] Proof of Receipt and Shipment: Use Pedersen commitment to generate proof of receipt and shipment
[0114] 2. Blockchain Consensus Algorithm and Access Control
[0115] In the present invention, mainly deploy contracts through the nodes of the blockchain to store transaction data and proofs, and control the access rights of users. At the same time, utilize the decentralization and consensus mechanism of the nodes to avoid the harm of malicious nodes and thus be used for the verification of proofs.
[0116] 1) Smart Contract:
[0117] Store Data: Used to store the identity verification of users, balance proofs, transaction information, transaction funds, and user balances.
[0118] Permission Management: Set permissions to only allow legitimate and valid users to upload and download proofs and funds.
[0119] 2) Consensus Mechanism
[0120] In the present invention, the consensus mechanism is used to obtain the verification results of proofs by each node, thereby reducing the influence of malicious nodes on the verification results.
[0121] Based on the above system for transactions, the transaction process is as Figure 3 shown:
[0122] 1. Transaction Initiation and Key Generation
[0123] 1) The trusted institution generates ECC keys and distributes them to both the buyer and the seller.
[0124] 2) The buyer generates a shared key using its own private key and the seller's public key for encrypting order data.
[0125] SharedKey = PriυateKey.exchange(ECDH, PeerPublicKey)
[0126] Where, PrivateKey represents the ECC private key, and PeerPublicKey represents the public key of the other party.
[0127] 3) The buyer creates an order, fragments and encrypts the data, and then uploads the transaction information.
[0128] DriuedKey = HKDF(SHA256, SharedKey, info=encryption, length=32)
[0129] EncryptedChunk i = AES Encrypt (chunki, DeriuedKey)
[0130] 2. Authentication and Balance Proof
[0131] 1) The buyer and the seller generate Schnorr signatures for authentication.
[0132] R = g k , s = k + x · H(m, R)
[0133] g s = R · y H(m,R)
[0134] Among them, R represents the signature random number generated by the random number k, x represents the private key, y represents the public key, m represents the hidden information, g represents the group generator, s represents the signature value, and H represents the hash calculation of the information and the random number.
[0135] 2) The buyer generates a Bulletproof to prove the validity of the balance.
[0136] 3) The verification information is uploaded to the blockchain, and the miner verifies the signature and the balance proof, and records the verification result through the consensus algorithm.
[0137] 3. Authorization and Data Storage
[0138] 1) The miner initiates an authorization proposal based on the verification result, and grants the buyer the permission to upload data after passing.
[0139] 2) The buyer uploads the encrypted data shards to IPFS and stores the associated data in the transaction information contract in the blockchain.
[0140] 4. Data Decryption and Transaction Information Retrieval
[0141] 1) The seller decrypts the AES key with its own private key.
[0142] 2) The seller downloads and decrypts the data shards on IPFS to obtain the complete transaction details.
[0143] 5. Commodity Delivery and Status Update
[0144] 1) The seller ships the goods according to the transaction details and updates the status to "successful".
[0145] 2) The buyer confirms receipt of the goods and updates the status to "successful".
[0146] 3) The buyer and seller use the transaction details to generate their respective Pedersen commitments and upload them to the blockchain.
[0147] r = AES k (Timestamp)
[0148]
[0149] Where x order represents the order details, r represents a random number, and g and h represent public parameters.
[0150] 6. Dispute Resolution
[0151] In case of a transaction dispute, relevant third parties (such as banks or logistics companies) and the buyer and seller provide their respective Pedersen commitments, and the dispute resolution plan is determined based on the results of the three-party commitments.
[0152] Therefore, by combining blockchain technology, IPFS distributed storage, and various cryptographic methods, the present invention proposes an efficient, secure, and privacy-protected transaction management system (PBTMS). Compared with the prior art, it has the following remarkable advantages and effects:
[0153] 1. Security and Privacy Protection
[0154] By adopting technologies such as AES key encryption, address obfuscation, ECC signature, and blockchain storage, the security and privacy of data are ensured, effectively resisting passive / active attacks, data leakage, and forgery risks.
[0155] The system further enhances the authenticity verification ability of data and identity through the combination of Schnorr signature and Pedersen commitment.
[0156] 2. Reliable Identity Authentication
[0157] Based on Schnorr signature and distributed verification mechanism, the system can effectively prevent identity forgery and man-in-the-middle attacks (MITM), ensuring the legitimacy of user identity and data integrity during the transaction process.
[0158] 3. High Performance and Efficiency
[0159] 1) High throughput (TPS):
[0160] By using off-chain permission verification and off-chain storage technologies, the transaction processing capacity per second is effectively improved, and the concurrent processing performance of the system is significantly enhanced. For example Figure 4As shown, as the number of nodes increases, the download TPS reaches its peak (about 700 TPS) when the number of nodes is 40, while the upload TPS and authorization TPS tend to stabilize at around 300 TPS and 250 TPS respectively, demonstrating excellent scalability and efficient transaction processing capabilities.
[0161] 2) Low response time:
[0162] The system adopts a task parallel mechanism and combines ECC - AES slice encryption storage technology, significantly reducing the response time and providing a smoother interaction experience for users. As Figure 6 shown, compared with the existing solutions, this solution shortens the decryption and verification times by 79.2% and 52.6% respectively.
[0163] 4. Optimized resource utilization
[0164] 1) Optimized Gas consumption:
[0165] The system effectively reduces on - chain computing requirements and storage occupancy through off - chain computing and IPFS index storage, significantly reducing transaction fees and improving resource utilization efficiency. As Figure 5 shown, the present invention reduces the overall consumption by 55.4%, which is superior to the state - of - the - art solutions.
[0166] 2) Lightweight proofs:
[0167] Using Bulletproofs and Pedersen commitment technologies, it significantly reduces the size of the proof files, lowers storage and communication costs, and provides more efficient privacy protection for blockchain transactions. As Figure 7 shown, the present invention reduces the encrypted data from 6336 bytes to 3008 words, and the proof data from 4672 bytes to 1403 words, while maintaining the compactness of the amount data (18 bytes).
[0168] 5. Fair transaction guarantee
[0169] Through commitment verification and consensus mechanisms, the system can prevent problems such as false delivery and miner bias, ensuring fairness and credibility in the transaction process.
[0170] 6. High scalability and availability
[0171] 1) High scalability:
[0172] The system supports task separation, distributed storage, and multi - node collaboration mechanisms, and can flexibly handle transaction demands of different scales and adapt to complex and changeable business scenarios.
[0173] 2) High availability:
[0174] Utilize IPFS storage, a robust consensus mechanism, and a collaborative management method to effectively resist distributed denial-of-service attacks (DoS) and miner interruptions, ensuring the continuous and stable operation of the system.
[0175] Through the above innovative design, the present invention is superior to the prior art in terms of security, performance, resource optimization, fairness, and scalability. It can be widely applied to e-commerce, digital asset trading driven by blockchain technology, and other scenarios that require high security and privacy protection, providing comprehensive and reliable technical support for related fields.
[0176] Based on the above-described technical solutions, the following embodiments are provided.
[0177] Embodiment 1: E-commerce Transaction Process Based on the PBTMS Framework
[0178] This embodiment describes the whole process of completing a typical physical commodity transaction through the PBTMS framework:
[0179] 1. Transaction Initiation and Key Generation
[0180] 1) The trust institution is responsible for generating an ECC key pair, distributing the public key to the buyer and the seller, and securely storing the private key.
[0181] 2) The buyer uses its own private key and the seller's public key to generate a shared key for encrypting order data.
[0182] 3) After the buyer creates an order, the order data is fragmented and encrypted by AES to generate transaction information, and the transaction information is submitted to off-chain storage (such as IPFS).
[0183] 2. Identity Authentication and Balance Proof
[0184] 1) The buyer and the seller respectively generate Schnorr signatures to complete the verification of identity legality.
[0185] 2) The buyer generates a Bulletproof to prove the validity of the balance and uploads the balance proof and signature to the blockchain.
[0186] 3) The miner verifies the legality of the signature and the balance proof through the consensus algorithm, and writes the verification result into the blockchain after verification.
[0187] 3. Authorization and Data Storage
[0188] 1) After the verification passes, the miner initiates an on-chain authorization proposal and grants the buyer permission through the consensus mechanism.
[0189] 2) The buyer uploads the encrypted data fragments to IPFS and records the index addresses of the fragments in the transaction information contract on the blockchain to ensure the integrity and privacy of the data.
[0190] 4. Data Decryption and Transaction Completion
[0191] 1) The seller decrypts the AES key with their own private key, downloads the encrypted data fragments from IPFS and decrypts them to obtain the complete transaction details.
[0192] 2) The seller ships the goods according to the transaction details and updates the shipping status to the blockchain.
[0193] 3) After the buyer confirms receipt of the goods, the transaction status is updated. Meanwhile, both the buyer and the seller generate Pedersen commitments using the transaction details and upload them to the blockchain as proof of transaction completion.
[0194] 5. Dispute Resolution
[0195] In the event of a transaction dispute, the buyer, the seller, and relevant third parties (such as logistics companies) provide their respective Pedersen commitments. The blockchain determines the ownership of the dispute based on the verification results of the commitments and updates the final status.
[0196] Embodiment 2: Multi-Node High-Efficiency Collaboration Based on PBTMS
[0197] This embodiment demonstrates the operation performance of the present invention in high-concurrency and multi-node scenarios:
[0198] 1. On-chain and Off-chain Collaborative Processing
[0199] The system distributes complex computations (such as encryption, decryption, balance proof generation) and large data storage (such as transaction details) to be executed off-chain, thereby significantly reducing on-chain resource occupancy and improving the system throughput (TPS).
[0200] For example, in the case of multiple concurrent tasks, the computations and verifications are completed off-chain, and the IPFS indexing and storage mechanism is used to quickly locate the transaction data to ensure the high performance of the system.
[0201] 2. Task Parallelism and Scalability
[0202] 1) The system adopts a design of task separation and distributed storage to process different tasks in the transaction process (such as identity verification, data upload, transaction status update) in parallel.
[0203] 2) Through the multi-node collaboration mechanism, the number of nodes participating in verification can be dynamically expanded in high-load scenarios to improve the scalability of the system.
[0204] 3. Lightweight Proof and Low Gas Consumption
[0205] This system reduces the size of balance proofs and transaction vouchers through Bulletproofs technology, and effectively reduces Gas consumption by combining off-chain computing, enabling users to participate in transactions at a lower cost.
[0206] Example 3: Anti-attack and High Availability Verification
[0207] This example illustrates how the PBTMS framework resists potential attacks and maintains high availability:
[0208] 1. Anti-attack ability
[0209] 1) The system effectively resists data leakage, identity forgery, and man-in-the-middle attacks (MITM) through AES encryption, address obfuscation, and distributed verification.
[0210] 2) By combining blockchain and IPFS, the immutability of data is guaranteed to prevent passive and active attacks.
[0211] 2. High availability
[0212] 1) In the face of distributed denial-of-service attacks (DoS), the system ensures the availability of transaction data at all times through IPFS distributed storage and a robust consensus mechanism.
[0213] 2) The multi-node collaboration mechanism of the system enables other nodes to quickly take over tasks when a single node fails, maintaining the continuity of system operation.
[0214] (4) Analysis of Example Effects
[0215] 1. Efficiency:
[0216] In the simulation test, compared with traditional centralized e-commerce platforms, the transaction response time of the PBTMS system was reduced by 60%. Through off-chain computing and storage optimization, the Gas consumption was reduced by more than 50%.
[0217] 2. Security:
[0218] The system successfully withstood multiple simulated attacks of identity forgery and data leakage, verifying its security and reliability.
[0219] 3. Scalability:
[0220] In the high-concurrency test, the system demonstrated good scalability, supporting tens of thousands of concurrent transactions while maintaining low latency.
[0221] According to the above two examples, the technical solution has the following characteristics:
[0222] Privacy-Preserving Transaction Management Framework (PBTMS) Based on Blockchain and IPFS
[0223] 1. The blockchain is adopted to store transaction metadata and permission management information, combined with IPFS distributed storage of transaction details and proofs, ensuring the integrity, privacy, and immutability of data.
[0224] 2. The combined application of data encryption technologies (AES encryption, ECC signature, address obfuscation) and distributed storage is used to safeguard the security and privacy of transaction data.
[0225] (II) Distributed Verification and Identity Authentication Mechanism:
[0226] 1. The identity authentication method based on Schnorr signature effectively prevents identity forgery and man-in-the-middle attacks (MITM).
[0227] 2. The Pedersen commitment is used to verify the authenticity and fairness of transaction results.
[0228] 3. The distributed verification mechanism with multi-miner collaboration ensures the security and consistency of the verification process based on the consensus algorithm.
[0229] (III) Efficient Transaction Processing Mechanism with On-chain and Off-chain Collaboration:
[0230] 1. Encryption, decryption, and verification operations are completed through off-chain computing. Combined with IPFS index storage, it reduces on-chain resource occupancy and improves transaction processing efficiency.
[0231] 2. The task separation and parallel processing mechanism are adopted to achieve high throughput (TPS) and low response time.
[0232] (IV) Lightweight Proof and Gas Optimization:
[0233] 1. Combining Bulletproofs and Pedersen commitment technologies reduces the volume of transaction vouchers and balance proofs.
[0234] 2. Through off-chain computing and storage, it reduces on-chain Gas consumption and improves the economy of the system.
[0235] (V) Fair Transaction and Dispute Resolution Mechanism:
[0236] 1. Through commitment verification technology, it ensures the fairness of the transaction process and prevents problems such as false delivery and miner bias.
[0237] 2. In the scenario of dispute resolution, combining the Pedersen commitments provided by the buyer, seller, and relevant third parties, the transaction is traced and verified to ensure the fairness of dispute resolution.
[0238] (VI) High Scalability and System Availability:
[0239] 1. Support multi-node collaboration and task separation mechanisms to achieve the dynamic expansion of the system to adapt to high-concurrency and large-scale transaction scenarios.
[0240] 2. Resist distributed denial-of-service attacks (DoS) and miner interruptions, and ensure the high availability of the system through IPFS distributed storage and consensus mechanisms.
[0241] (VII) Transaction full life cycle management:
[0242] From transaction initiation, identity authentication, data storage, transaction completion to dispute resolution, it realizes the full-process management of e-commerce transactions, improving the reliability and practicality of the system.
[0243] (VIII) Innovative technology combination:
[0244] Organically combine blockchain technology, distributed storage (IPFS), cryptography (AES, ECC, Bulletproofs, Pedersen commitments), and parallel task processing to provide an efficient, secure, and privacy-protected e-commerce transaction management solution.
[0245] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same and similar parts between the various embodiments, reference can be made to each other.
[0246] Specific examples are used in this article to elaborate on the principles and implementation methods of the present invention. The descriptions of the above embodiments are only used to help understand the core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation methods and application scopes. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. A method for protecting privacy in e-commerce transactions based on blockchain, characterized in that: include: Construct a privacy-preserving transaction management system; the privacy-preserving transaction management system includes a functional layer and a protocol; the functional layer includes a user layer, a verification layer, an authorization layer, and a storage layer composed of blockchain and IPFS; the protocol includes a data encryption transmission protocol and a node consensus protocol; Conducting transactions based on the privacy protection transaction management system; The transaction process specifically includes: Encrypt transaction content and generate encrypted order data; Verify the identities of both parties to the transaction and the buyer’s balance, upload to the blockchain and generate verification results; After the verification result is passed, the buyer uploads the encrypted order data to IPFS and stores it on the blockchain; Decrypt the encrypted order data shards in IPFS, and the seller obtains complete transaction details; Deliver goods and update status based on transaction details, and use transaction details to generate respective Pedersen commitments and upload them to the blockchain; When a transaction dispute occurs, the relevant third party and the transaction parties will each provide their own Pedersen commitments, and the dispute resolution plan will be determined based on the results of the three-party commitments.
2. The method for protecting privacy in e-commerce transactions based on blockchain according to claim 1, characterized in that: The encryption of the transaction content to generate encrypted order data specifically includes: The ECC key is generated by the trusted institution and distributed to both parties of the transaction; The buyer generates a shared key using his own private key and the seller's public key, and encrypts the order details according to the shared key to obtain the encrypted order data.
3. The method for protecting privacy in e-commerce transactions based on blockchain according to claim 1, characterized in that: The identity of both parties to the transaction and the balance of the buyer are verified, the blockchain is uploaded and the verification results are generated, specifically including: The buyer and seller are asked to generate Schnorr signatures for identity verification, which is specifically expressed as: R=g k ,s=k+x·H(m,R) g s =R·y H(m,R) Among them, R represents the signature random number generated by the random number k, x represents the private key, y represents the public key, m represents the hidden information, g represents the generator of the group, s represents the signature value, and H represents the hash calculation of the information and the random number; Ask the buyer to generate a Bulletproof to prove the validity of the balance; The identity authentication and validity verification are uploaded to the blockchain, the signature and balance are verified by the miners, and the verification results are recorded through the consensus algorithm.
4. The method for protecting privacy in e-commerce transactions based on blockchain according to claim 1, characterized in that: After the verification result is passed, the buyer uploads the encrypted order data to IPFS and stores it in the blockchain, including: The miners initiate an authorization proposal based on the verification results. After the verification results are passed, the buyers are granted the permission to upload data. The buyers upload the encrypted order data to IPFS and associate it with the transaction information contract stored in the blockchain.
5. The method for protecting privacy in e-commerce transactions based on blockchain according to claim 1, characterized in that: The encrypted order data shards in IPFS are decrypted, and the seller obtains complete transaction details, including: The seller can use his own private key to decrypt the encrypted order data shards in IPFS to obtain complete transaction details.
6. The method for protecting privacy in e-commerce transactions based on blockchain according to claim 1, characterized in that: The goods are delivered and the status is updated according to the transaction details, and the transaction details are used to generate respective Pedersen commitments and upload them to the blockchain, including: When the seller ships the goods according to the transaction details, the seller's status is updated to "successful". When the buyer receives the goods, the buyer's status is updated to "successful". Both parties of the transaction use the transaction details to generate their own Pedersen commitments and upload them to the blockchain.
7. An electronic device, characterized in that: It includes a memory and a processor, the memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the blockchain-based e-commerce transaction privacy protection method according to any one of claims 1-6.
8. A computer-readable storage medium, characterized in that: It stores a computer program, which, when executed by a processor, implements the blockchain-based e-commerce transaction privacy protection method as described in any one of claims 1-6.
Citation Information
Patent Citations
Block chain-based data transaction model and privacy protection method
CN114900290A
Alliance chain privacy transaction method based on Pedersen commitment
CN115062334A
Data privacy transaction method based on zero knowledge proof
CN115760399A
Cited By
Block chain-based electricity-carbon transaction method and device
CN122023010A