Transaction processing method and device, computer equipment and computer readable storage medium

Through the encryption and decryption of the smart contract key and the object attribute private key authentication, the problem of low security of blockchain transaction information is solved, and efficient and secure processing of transaction information is achieved.

CN120181852APending Publication Date: 2025-06-20TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311763875.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-19
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

In traditional blockchain transaction processing, public ledgers lead to low security of transaction information and easy leakage of sensitive information.

Method used

By encrypting and decrypting the key of the smart contract, receiving the transaction encryption access request initiated by the initiator, using public key encryption and private key decryption, generating the object attribute private key for authentication, and decrypting the transaction information according to the authorized object attribute set.

Benefits of technology

It improves the security of transaction information, ensures that only authorized users can access and decrypt transaction information, and enhances the security and legality of transaction processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120181852A_ABST
    Figure CN120181852A_ABST
Patent Text Reader

Abstract

The invention relates to a transaction processing method and device, computer equipment and a computer readable storage medium, and is applied to the technical field of block chains. The method comprises the following steps: receiving a transaction encryption access request initiated by a request initiator for a smart contract, wherein the transaction encryption access request is encrypted by adopting a public key in a key pair of the smart contract; a private key in the key pair is adopted to decrypt the transaction encryption access request, a transaction identifier and an object attribute private key are obtained, and the object attribute private key is generated based on the private key and the object attribute of the request initiator; based on the smart contract, determining an encrypted ciphertext corresponding to the transaction identifier, the encrypted ciphertext being obtained by encrypting transaction information corresponding to the transaction identifier based on the public key and the object attribute in the authorized object attribute set; and decrypting the encrypted ciphertext based on the object attribute private key, and when the decryption is successful, representing that the identity verification is passed, and obtaining transaction information corresponding to the transaction identifier. By adopting the method, the security of the transaction information can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and particularly to a transaction processing method, apparatus, computer device, storage medium, and computer program product. Background Art

[0002] With the development of computer technology, blockchain technology has emerged. A blockchain is a data structure composed of several blocks connected by hash values in sequence. Smart contracts can be deployed on the blockchain. A smart contract is a contract written in the form of code and can be automatically executed on the blockchain. Smart contracts have a wide range of application scenarios in many fields, such as transaction processing, Internet of Things, supply chain management, and identity authentication.

[0003] In the transaction processing scenario, smart contracts can be used for transaction verification and execution. However, due to the characteristics of traditional public ledgers, all transactions are public and transparent, which exposes the sensitive information of both trading parties and results in low security of transaction information on the blockchain. Summary of the Invention

[0004] Based on this, it is necessary to provide a transaction processing method, apparatus, computer device, computer-readable storage medium, and computer program product that can improve transaction security for the above technical problems.

[0005] In a first aspect, the present application provides a transaction processing method. The method includes:

[0006] Receiving a transaction encryption access request for a smart contract initiated by a request initiator, where the transaction encryption access request is encrypted using the public key in the key pair of the smart contract;

[0007] Decrypting the transaction encryption access request using the private key in the key pair to obtain a transaction identifier and an object attribute private key, where the object attribute private key is generated based on the private key and the object attributes of the request initiator;

[0008] Based on the smart contract, determining an encrypted ciphertext corresponding to the transaction identifier, where the encrypted ciphertext is obtained by encrypting the transaction information corresponding to the transaction identifier using the public key and the object attributes in the authorized object attribute set;

[0009] Decrypting the encrypted ciphertext using the object attribute private key. When the decryption is successful, it indicates that the identity verification is passed, and the transaction information corresponding to the transaction identifier is obtained.

[0010] In a second aspect, the present application further provides a transaction processing apparatus. The apparatus includes:

[0011] A receiving module, configured to receive a transaction encryption access request for a smart contract initiated by a request initiator, where the transaction encryption access request is encrypted using the public key in the key pair of the smart contract;

[0012] A request decryption module, configured to decrypt the transaction encryption access request using the private key in the key pair to obtain a transaction identifier and an object attribute private key, where the object attribute private key is generated based on the private key and the object attribute of the request initiator;

[0013] A determination module, configured to determine, based on the smart contract, the encrypted ciphertext corresponding to the transaction identifier, where the encrypted ciphertext is obtained by encrypting the transaction information corresponding to the transaction identifier using the public key and the object attributes in the authorized object attribute set;

[0014] A ciphertext decryption module, configured to decrypt the encrypted ciphertext based on the object attribute private key. When the decryption is successful, it indicates that the authentication is passed, and the transaction information corresponding to the transaction identifier is obtained.

[0015] In one embodiment, the request decryption module is further configured to decrypt the transaction encryption access request using the private key in the key pair to obtain a transaction identifier, an object attribute private key, and the request time of the transaction identifier;

[0016] The ciphertext decryption module is further configured to determine the reception time of receiving the transaction encryption access request, and determine the preset valid duration of the encrypted ciphertext corresponding to the transaction identifier; when the request time is within the preset valid duration and the reception time is within the preset valid duration, decrypt the encrypted ciphertext based on the object attribute private key.

[0017] In one embodiment, the apparatus further includes a key generation module; the key generation module is configured to obtain the object attributes of multiple users respectively, and verify the object attributes of the multiple users respectively; when the verification is passed, generate a key pair for the smart contract based on the object attributes of the multiple users respectively.

[0018] In one embodiment, the ciphertext decryption module is further configured to decrypt the encrypted ciphertext based on the object attribute private key. When the decryption is successful, obtain the authorized user set corresponding to the transaction identifier; when the request initiator belongs to the authorized users in the authorized user set, it indicates that the authentication is passed, and the transaction information corresponding to the transaction identifier is obtained.

[0019] In one embodiment, the ciphertext decryption module is further configured to determine the current ciphertext state of the encrypted ciphertext, where the ciphertext state includes a valid state and an update state; when the ciphertext state indicates that the encrypted ciphertext is in the valid state, decrypt the encrypted ciphertext based on the object attribute private key.

[0020] In one embodiment, the ciphertext decryption module is further configured to, when the ciphertext state indicates that the encrypted ciphertext is in the update state, determine the backup ciphertext corresponding to the encrypted ciphertext; decrypt the backup ciphertext based on the object attribute private key.

[0021] In one embodiment, the apparatus further includes a ciphertext update module; the ciphertext update module is configured to determine the preset valid duration of the encrypted ciphertext and determine the elapsed effective duration of the encrypted ciphertext;

[0022] When the elapsed effective duration reaches the preset valid duration, generate a backup ciphertext of the encrypted ciphertext; adjust the current ciphertext state of the encrypted ciphertext from the valid state to the update state.

[0023] In one embodiment, the ciphertext update module is configured to determine the preset valid duration and the elapsed effective duration of the encrypted ciphertext corresponding to the transaction identifier; when the elapsed effective duration reaches the preset valid duration and an attribute change request for the transaction identifier is received, update the authorized object attribute set based on the target attribute in the attribute change request; update the encrypted ciphertext based on the public key and the updated object attribute set to obtain an updated encrypted ciphertext; generate an updated object attribute private key based on the private key and the target attribute.

[0024] In one embodiment, the ciphertext update module is further configured to, when the elapsed effective duration reaches the preset valid duration and no attribute change request for the transaction identifier is received, update the key pair of the smart contract; update the encrypted ciphertext based on the public key in the updated key pair and the authorized object attribute set to obtain an updated encrypted ciphertext; update the object attribute private key based on the private key in the updated key pair and the authorized object attribute set to obtain an updated object attribute private key.

[0025] In one embodiment, the set of authorized object attributes includes the object attributes of each authorized user of the transaction identifier, and the device further includes an attribute private key sending module; the attribute private key sending module is configured to encrypt the updated object attribute private key using an encryption key to obtain an encrypted object attribute private key; and send each encrypted object attribute private key to each of the authorized users through a first preset channel; obtain decryption key generation information corresponding to the encryption key, and send the decryption key generation information to each of the authorized users through a second preset channel, where the decryption key generation information is used to generate a decryption key, and the decryption key is used to decrypt the encrypted object attribute private key to obtain the updated object attribute private key.

[0026] In one embodiment, the device further includes:

[0027] A transaction processing module, configured to determine a contract interface corresponding to the transaction identifier; and perform transaction processing according to the transaction information through the contract interface to obtain a transaction result.

[0028] In a third aspect, the present application further provides a computer device. The computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0029] Receive a transaction encryption access request for a smart contract initiated by a request initiator, where the transaction encryption access request is encrypted using the public key in the key pair of the smart contract;

[0030] Use the private key in the key pair to decrypt the transaction encryption access request to obtain a transaction identifier and an object attribute private key, where the object attribute private key is generated based on the private key and the object attributes of the request initiator;

[0031] Based on the smart contract, determine an encrypted ciphertext corresponding to the transaction identifier, where the encrypted ciphertext is obtained by encrypting the transaction information corresponding to the transaction identifier based on the public key and the object attributes in the set of authorized object attributes;

[0032] Decrypt the encrypted ciphertext based on the object attribute private key. When the decryption is successful, it indicates that the authentication is passed, and the transaction information corresponding to the transaction identifier is obtained.

[0033] In a fourth aspect, the present application further provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the following steps are implemented:

[0034] Receive a transaction encryption access request for a smart contract initiated by a request initiator, where the transaction encryption access request is encrypted using the public key in the key pair of the smart contract;

[0035] Use the private key in the key pair to decrypt the transaction encryption access request to obtain a transaction identifier and an object attribute private key, where the object attribute private key is generated based on the private key and the object attributes of the request initiator;

[0036] Based on the smart contract, determine the encrypted ciphertext corresponding to the transaction identifier, where the encrypted ciphertext is obtained by encrypting the transaction information corresponding to the transaction identifier using the public key and the object attributes in the set of authorized object attributes;

[0037] Decrypt the encrypted ciphertext using the object attribute private key. When the decryption is successful, it indicates that the authentication is passed, and the transaction information corresponding to the transaction identifier is obtained.

[0038] In a fifth aspect, the present application also provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the following steps are implemented:

[0039] Receive a transaction encryption access request for a smart contract initiated by a request initiator, where the transaction encryption access request is encrypted using the public key in the key pair of the smart contract;

[0040] Use the private key in the key pair to decrypt the transaction encryption access request to obtain a transaction identifier and an object attribute private key, where the object attribute private key is generated based on the private key and the object attributes of the request initiator;

[0041] Based on the smart contract, determine the encrypted ciphertext corresponding to the transaction identifier, where the encrypted ciphertext is obtained by encrypting the transaction information corresponding to the transaction identifier using the public key and the object attributes in the set of authorized object attributes;

[0042] Decrypt the encrypted ciphertext using the object attribute private key. When the decryption is successful, it indicates that the authentication is passed, and the transaction information corresponding to the transaction identifier is obtained.

[0043] The above-mentioned transaction processing method, device, computer device, computer-readable storage medium, and computer program product receive a transaction encryption access request for a smart contract initiated by a request initiator. The initiated transaction encryption access request is encrypted using the public key in the key pair, making the received request information not easily leaked. The private key in the key pair is used to decrypt the transaction encryption access request to obtain the transaction identifier of the transaction information that the user wants to access and the object attribute private key for verifying the identity of the request initiator. The object attribute private key is generated based on the private key and the object attributes of the request initiator to verify whether the user is an authorized user of the transaction information through the object attribute private key. Based on the smart contract, the encrypted ciphertext corresponding to the transaction identifier is determined, and it is judged whether the user has the permission to call the transaction information according to whether the object attribute private key can decrypt the encrypted ciphertext. The encrypted ciphertext is obtained by encrypting the transaction information corresponding to the transaction identifier based on the public key and the object attributes in the authorized object attribute set, indicating that an authorized object attribute set has been set in advance for the transaction information. The authorized object attribute set includes the object attributes of the authorized users, and it can be judged whether the object attributes of the request initiator are the attributes in the authorized object attribute set of the transaction information. Moreover, the transaction information is encrypted based on the public key and the object attributes to obtain the encrypted ciphertext, so that the transaction information of the user on the blockchain will not be exposed, improving the security of the transaction information. When the decryption is successful, it indicates that the request initiator is an authorized user of the transaction information and has the permission to call the transaction information, and then the transaction information indicated by the transaction identifier in the smart contract is called, thereby improving the security of calling the transaction information. Furthermore, by setting respective encrypted ciphertexts for different transaction information, respective authorized object attribute sets can be set for different transaction information to set respective authorized users, which can improve the fine-grained control of accessing the transaction information and thus improve the security of accessing the transaction information. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Figure 1 is a schematic diagram of the architecture based on the blockchain system in some embodiments;

[0045] Figure 2 is an application environment diagram of the transaction processing method in an embodiment;

[0046] Figure 3 is a schematic flowchart of the transaction processing method in an embodiment;

[0047] Figure 4 is a schematic flowchart of the steps for decrypting the encrypted ciphertext in an embodiment;

[0048] Figure 5 is a schematic diagram of generating a key pair in an embodiment;

[0049] Figure 6Schematic diagram of the relationship between a transaction identifier, a set of object attributes, and object attributes in one embodiment;

[0050] Figure 7 Schematic diagram of the relationship between a transaction identifier, a set of object attributes, and object attributes in another embodiment;

[0051] Figure 8 Schematic diagram of sending respective object attribute private keys to authorized users through a preset channel in one embodiment;

[0052] Figure 9 Sequence diagram of the interaction between a blockchain node and an authorized user in one embodiment;

[0053] Figure 10 Sequence diagram of a transaction processing method in one embodiment;

[0054] Figure 11 Schematic flow diagram of updating an encrypted ciphertext and an object attribute private key in one embodiment;

[0055] Figure 12 Schematic flow diagram of sending respective updated object attribute private keys to authorized users in one embodiment;

[0056] Figure 13 Sequence diagram of a transaction processing method in one embodiment;

[0057] Figure 14 Structural block diagram of a transaction processing device in one embodiment;

[0058] Figure 15 Internal structure diagram of a computer device in one embodiment. Detailed implementation manners

[0059] In order to make the objectives, technical solutions, and advantages of the present application clearer and more understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0060] The blockchain-based transaction processing method provided by the embodiments of the present application can be executed by nodes in a blockchain system. Refer to Figure 1, the blockchain system 100 includes multiple blockchain nodes 102. Each blockchain node 102 can receive input information during normal operation and maintain shared data within the blockchain system based on the received input information. To ensure information interconnection within the blockchain system, there can be information connections between each node in the blockchain system, and nodes can transmit information through the above-mentioned information connections. For example, when any node in the blockchain system receives input information, other nodes in the blockchain system obtain the input information according to the consensus algorithm and store the input information as data in the shared data, so that the data stored on all nodes in the blockchain system is consistent.

[0061] For each node in the blockchain system, there is a corresponding node identifier, and each node in the blockchain system can store the node identifiers of other nodes in the blockchain system, so as to broadcast the generated block to other nodes in the blockchain system according to the node identifiers of other nodes later. Each node can maintain a node identifier list as shown in the following table, and store the node name and node identifier corresponding to each other in the node identifier list. Among them, the node identifier can be an IP (Internet Protocol) address and any other information that can be used to identify the node. Only the IP address is used as an example in Table 1 for illustration.

[0062] Table 1

[0063]

[0064] The transaction processing method provided by the embodiments of this application can be applied to the application environment as Figure 2 shown. Among them, the blockchain node 202 in the blockchain system communicates with the user terminal 204 of the request initiator through the network. The blockchain node 202 receives a transaction encryption access request for a smart contract initiated by the user terminal 204 of the request initiator, and the transaction encryption access request is encrypted with the public key in the key pair of the smart contract. The blockchain node 202 decrypts the transaction encryption access request with the private key in the key pair to obtain a transaction identifier and an object attribute private key, and the object attribute private key is generated based on the private key and the object attribute of the request initiator. The blockchain node 202 determines the encrypted ciphertext corresponding to the transaction identifier based on the smart contract, and the encrypted ciphertext is obtained by encrypting the transaction information corresponding to the transaction identifier with the public key and the object attributes in the authorized object attribute set. The blockchain node 202 decrypts the encrypted ciphertext with the object attribute private key. When the decryption is successful, it indicates that the identity verification is passed, and the transaction information corresponding to the transaction identifier is obtained.

[0065] Among them, the blockchain node 202 can be a terminal or a server. Among them, the terminal can be, but is not limited to, various desktop computers, laptop computers, smart phones, tablet computers, Internet of Things devices, and portable wearable devices. The Internet of Things devices can be smart voice interaction devices, smart home appliances, vehicle-mounted terminals, aircraft, etc. The portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The server can be implemented by an independent server or a server cluster composed of multiple servers.

[0066] It can be understood that Figure 2 the application environment shown is not used to limit this application. In some other embodiments, there may be one or more shared nodes between the blockchain system and the computing resource set. The term "multiple" refers to at least two.

[0067] The embodiments of this application can be applied to various scenarios, including but not limited to cloud technology, artificial intelligence, intelligent transportation, assisted driving, etc.

[0068] In one embodiment, as Figure 3 shown, a transaction processing method is provided. Taking the blockchain node in Figure 2 as an example for illustration, the method includes the following steps:

[0069] Step S302, receive a transaction encryption access request for a smart contract initiated by a request initiator. The transaction encryption access request is encrypted using the public key in the key pair of the smart contract.

[0070] Among them, the transaction access request can be a request to access the transaction information of the smart contract. The transaction encryption access request refers to a request formed by encrypting the request to access the transaction information. The transaction access request can include a transaction viewing request and a transaction execution request. The transaction viewing request is a request to view the transaction information, and the transaction execution request is a request to execute transaction processing according to the transaction information.

[0071] The smart contract can include multiple transaction identifiers, and each transaction identifier indicates a transaction. Each transaction has its own transaction information. The transaction information includes transaction amount, transaction time, identity information of transaction participants, etc.

[0072] The request initiator can be any user, that is, the request initiator can be an authorized user of a certain transaction in the smart contract or not an authorized user. Any user can initiate a transaction encryption access request for the smart contract.

[0073] A smart contract is a protocol defined in digital form that needs to run in a trusted environment, such as a blockchain platform. It is propagated, verified, or executed in an information-based manner, read and executed by a computer, and has the characteristics of being self-service. The decentralization of the blockchain and the anti-tampering of data determine that smart contracts are more suitable for implementation on the blockchain. A smart contract includes multiple contract methods (functions), and each contract method represents a transaction.

[0074] A key pair is a pair of keys used for encryption and decryption, including a public key and a private key. The private key is held by the owner of the key pair and cannot be made public. The public key is made public by the holder of the key pair to others. The public key is used to encrypt data, and the data encrypted with the public key needs to be decrypted with the private key. The private key is used to decrypt the data encrypted with the public key.

[0075] In other embodiments, one of the keys in the key pair can be used to encrypt data, and the other key can be used to decrypt it. For example, if the data is encrypted with the public key, the private key is used to decrypt it; if the data is encrypted with the private key, the public key is used to decrypt it.

[0076] Specifically, the user terminal of the request initiator locally stores the public key in the key pair and the object attribute private key of the request initiator itself, and the blockchain node stores the private key in the key pair.

[0077] In other embodiments, the public key in the key pair is deployed in the smart contract.

[0078] In one of the embodiments, the public key in the key pair can be published on a key repository, or the public key can be broadcast to provide it to all users.

[0079] The request initiator can view the transaction identifiers of the smart contract and select the transaction identifier representing the transaction to be accessed. The request initiator obtains its own object attribute private key, generates a transaction access request based on the selected transaction identifier, and encrypts the transaction access request and the object attribute private key with the public key in the key pair to obtain a transaction encrypted access request. The request initiator sends the transaction encrypted access request to the blockchain node.

[0080] In this embodiment, the request initiator can obtain the object attribute private key and generate a transaction access request based on the transaction identifier and the object attribute private key. The request initiator encrypts the transaction access request with the public key to obtain a transaction encrypted access request.

[0081] In one of the embodiments, the blockchain node obtains a random parameter and generates a key pair for the smart contract based on the random parameter. The key pair includes a public key and a private key. The blockchain node can store the key pair or store the private key in the key pair. The blockchain node can deploy the public key in the key pair in the smart contract.

[0082] In this embodiment, the blockchain node obtains the object attributes of multiple users respectively, and generates a key pair for the smart contract based on the object attributes of multiple users respectively. Among them, the object attribute of a user refers to an attribute that can characterize the characteristics of the user in a certain aspect. The object attribute of a user can be used to verify the identity of the user.

[0083] Further, each object attribute is quantized to obtain an attribute representation quantity corresponding to each object attribute, and a key pair for the smart contract is generated based on each attribute representation quantity.

[0084] In this embodiment, generating a key pair for the smart contract based on random parameters includes: obtaining the object attributes of multiple users respectively; obtaining random parameters, and generating a key pair for the smart contract based on the random parameters and the object attributes of multiple users respectively.

[0085] Specifically, the blockchain node obtains the object attributes of multiple users respectively, and randomly generates multiple parameters, that is, random parameters. Obtain a preset key generation function, input the object attributes and random parameters into the key generation function, and obtain a key pair.

[0086] Step S304, use the private key in the key pair to decrypt the transaction encrypted access request to obtain a transaction identifier and an object attribute private key, where the object attribute private key is generated based on the private key and the object attribute of the request initiator.

[0087] Specifically, after the blockchain node receives the transaction encrypted access request sent by the request initiator, it can obtain the private key in the key pair. The blockchain node uses the private key in the key pair to decrypt the transaction encrypted access request to obtain a transaction identifier and an object attribute private key. The transaction identifier indicates the transaction in the smart contract. The object attribute private key is generated based on the private key and the object attribute of the request initiator.

[0088] Step S306, based on the smart contract, determine the encrypted ciphertext corresponding to the transaction identifier, where the encrypted ciphertext is obtained by encrypting the transaction information corresponding to the transaction identifier based on the public key and the object attributes in the authorized object attribute set.

[0089] Among them, the authorized object attribute set includes the object attributes of each authorized user in the authorized user set. The authorized user set is the summary of users who have the permission to access the transaction information. A user who has the permission to access the transaction information is called an authorized user of the transaction information. A user belonging to the authorized user set of the transaction information has the permission to access the transaction information, and a user not belonging to the authorized user set of the transaction information does not have the permission to access the transaction information. The encrypted ciphertext is used to verify whether the user who requests to call the transaction information is an authorized user of the transaction information, that is, to verify the user identity.

[0090] Specifically, the blockchain node determines the set of authorized users configured for the transaction information indicated by the transaction identifier, as well as the set of object attributes of the set of authorized users. The set of object attributes of the set of authorized users is the set of authorized object attributes. The blockchain node uses the public key in the key pair and the set of authorized object attributes to encrypt the transaction information corresponding to the transaction identifier, obtaining the encrypted ciphertext of the transaction information. The encrypted ciphertext of the transaction information is used as the encrypted ciphertext corresponding to the transaction identifier. The blockchain node deploys the encrypted ciphertext and the transaction identifier in association in the smart contract.

[0091] The blockchain node generates an object attribute private key for each authorized user based on the private key in the key pair and the object attributes of each authorized user in the set of object attributes, and sends the respective object attribute private keys to each authorized user.

[0092] When the blockchain node receives a transaction encryption access request from the request initiator, it decrypts the transaction encryption access request using the private key in the key pair to obtain the transaction identifier and the object attribute private key. The blockchain node determines the encrypted ciphertext corresponding to the transaction identifier in the smart contract.

[0093] Step S308, decrypt the encrypted ciphertext based on the object attribute private key. When the decryption is successful, it indicates that the authentication is passed, and the transaction information corresponding to the transaction identifier is obtained.

[0094] Specifically, the blockchain node decrypts the encrypted ciphertext based on the object attribute private key. When the decryption is successful, the blockchain node displays the transaction information indicated by the transaction identifier in the smart contract. When the decryption fails, the blockchain node rejects the transaction encryption access request.

[0095] In this embodiment, the blockchain node uses the private key in the key pair to decrypt the transaction encryption access request to obtain the transaction identifier, the object attribute private key, and the request time of the transaction identifier. The blockchain node determines the preset effective duration of the encrypted ciphertext. When the request time is within the preset effective duration, it decrypts the encrypted ciphertext based on the object attribute private key. When the request time is outside the preset effective duration, it rejects the transaction encryption access request.

[0096] In one of the embodiments, decrypting the encrypted ciphertext based on the object attribute private key includes:

[0097] The blockchain node determines the reception time when it receives the transaction encryption access request, and determines the preset effective duration of the encrypted ciphertext; when the reception time is within the preset effective duration, it decrypts the encrypted ciphertext based on the object attribute private key; when the reception time is outside the preset effective duration, it rejects the transaction encryption access request.

[0098] In this embodiment, the method further includes: performing transaction processing according to the transaction information to obtain a transaction result. After decrypting to obtain the transaction information, the transaction can be performed according to the transaction information, so that when the user has a specific attribute, the transaction will be decrypted and executed, thereby ensuring the legality of the transaction.

[0099] In this embodiment, a transaction encryption access request for a smart contract initiated by a request initiator is received. The initiated transaction encryption access request is encrypted with the public key in the key pair, so that the received request information is not easily leaked. The private key in the key pair is used to decrypt the transaction encryption access request to obtain the transaction identifier of the transaction information that the user wants to access, and the object attribute private key for verifying the identity of the request initiator. The object attribute private key is generated based on the private key and the object attribute of the request initiator to verify whether the user is an authorized user of the transaction information through the object attribute private key. Based on the smart contract, the encrypted ciphertext corresponding to the transaction identifier is determined, and it is judged whether the user has the permission to call the transaction information according to whether the object attribute private key can decrypt the encrypted ciphertext. The encrypted ciphertext is obtained by encrypting the transaction information corresponding to the transaction identifier based on the public key and the object attributes in the authorized object attribute set, indicating that an authorized object attribute set has been set in advance for the transaction information. The authorized object attribute set includes the object attributes of authorized users, and it can be judged whether the object attribute of the request initiator is an attribute in the authorized object attribute set of the transaction information. Moreover, the transaction information is encrypted based on the public key and the object attribute to obtain the encrypted ciphertext, so that the transaction information of the user on the blockchain will not be exposed, improving the security of the transaction information. When the decryption is successful, it indicates that the request initiator is an authorized user of the transaction information and has the permission to call the transaction information, and then the transaction information indicated by the transaction identifier in the smart contract is called, thereby improving the security of calling the transaction information. Moreover, by setting respective encrypted ciphertexts for different transaction information, respective authorized object attribute sets can be set for different transaction information to set respective authorized users, which can improve the fine-grained control of accessing the transaction information and thus improve the security of accessing the transaction information.

[0100] In one embodiment, as Figure 4 shown, using the private key in the key pair to decrypt the transaction encryption access request to obtain the transaction identifier and the object attribute private key includes step S402:

[0101] Step S402, using the private key in the key pair to decrypt the transaction encryption access request to obtain the transaction identifier, the object attribute private key, and the request time of the transaction identifier.

[0102] Among them, the request time can be the time selected by the request initiator to access the transaction information.

[0103] Specifically, the request initiator can view each transaction identifier in the smart contract, and select the transaction identifier representing the transaction information to be accessed and the request time for requesting access to the transaction information. The request initiator obtains its own object attribute private key, generates a transaction access request based on the selected transaction identifier and request time, and encrypts the transaction access request and the object attribute private key using the public key in the key pair to obtain a transaction encrypted access request. The request initiator sends the transaction encrypted access request to the blockchain node.

[0104] In this embodiment, the request initiator can obtain the object attribute private key, and generate a transaction access request based on the transaction identifier, the request time, and the object attribute private key. The request initiator encrypts the transaction access request using the public key to obtain a transaction encrypted access request.

[0105] The blockchain node receives the transaction encrypted access request, obtains the private key in the key pair, and decrypts the private key in the key pair using the private key to obtain the transaction identifier, the object attribute private key, and the request time of the transaction identifier.

[0106] Decrypting the encrypted ciphertext based on the object attribute private key includes steps S404 - S406:

[0107] Step S404, determine the reception time when the transaction encrypted access request is received, and determine the preset valid duration of the encrypted ciphertext corresponding to the transaction identifier.

[0108] When the blockchain node receives the transaction encrypted access request, it records the reception time of the transaction encrypted access request. The blockchain node determines the encrypted ciphertext corresponding to the transaction identifier, and determines the preset valid duration corresponding to the encrypted ciphertext.

[0109] Step S406, when the request time is within the preset valid duration and the reception time is within the preset valid duration, decrypt the encrypted ciphertext based on the object attribute private key.

[0110] Specifically, the blockchain node detects whether both the request time and the reception time are within the preset valid duration. When the request time is within the preset valid duration and the reception time is within the preset valid duration, the blockchain node decrypts the encrypted ciphertext based on the object attribute private key.

[0111] In this embodiment, when at least one of the request time or the reception time is not within the preset valid duration, it indicates that the identity verification fails, and the decryption process of the encrypted ciphertext is not performed.

[0112] In other embodiments, when the request time is within the preset valid duration and the reception time is not within the preset valid duration, the blockchain node determines the backup ciphertext corresponding to the encrypted ciphertext, decrypts the backup ciphertext based on the object attribute private key. When the decryption is successful, it indicates that the authentication is passed, and the transaction information corresponding to the transaction identifier is obtained.

[0113] In this embodiment, the private key in the key pair is used to decrypt the transaction encrypted access request to obtain the transaction identifier, the object attribute private key, and the request time of the transaction identifier, determine the reception time when the transaction encrypted access request is received, and determine the preset valid duration of the encrypted ciphertext corresponding to the transaction identifier, so as to perform the decryption process on the encrypted ciphertext when both the request time and the reception time are within the valid period of the encrypted ciphertext, which can ensure that the valid periods of the object attribute private key and the ciphertext are consistent.

[0114] In one embodiment, the method further includes:

[0115] Obtain the object attributes of multiple users respectively, and verify the object attributes of multiple users respectively; when the verification passes, generate a key pair for the smart contract based on the object attributes of multiple users respectively.

[0116] Specifically, the blockchain node obtains the object attributes of multiple users respectively, verifies the object attribute of each user to filter out the object attributes that pass the verification and eliminate the object attributes that fail the verification.

[0117] When the object attributes that pass the verification are filtered out, generate multiple parameters randomly, that is, random parameters. Obtain the preset key generation function, and input the object attributes and random parameters into the key generation function to obtain the key pair.

[0118] In this embodiment, when the verification passes, generating a key pair for the smart contract based on the object attributes of multiple users respectively includes: when the verification passes, obtain random parameters, and generate a key pair for the smart contract based on the random parameters and the object attributes of multiple users respectively.

[0119] In this embodiment, the object attributes of each user obtained can be quantized to obtain the attribute representation quantity corresponding to each object attribute. As Figure 5 shown, multiple object attributes include: object attribute a, object attribute b, object attribute c, etc. Use the numerical value 1 to represent object attribute a, use the numerical value 2 to represent object attribute b, use the numerical value 3 to represent object attribute c, then 1 is the attribute representation quantity of object attribute a, 2 is the attribute representation quantity of object attribute b, and 3 is the attribute representation quantity of object attribute c. Further, object attribute c can be further divided into object attribute c1 and object attribute c2, then object attribute c1 can be represented by the numerical value 3.1 and object attribute c2 can be represented by the numerical value 3.2.

[0120] Input the characterization quantities of each attribute and random parameters into the key generation function to obtain a key pair. Further, input the characterization quantities of each attribute and random parameters into the key generation function to obtain a key pair.

[0121] In this embodiment, the object attributes of multiple users are obtained respectively, and the object attributes of multiple users are verified respectively to verify the authenticity of the user attributes and be able to screen out false data. When the verification passes, a key pair for the smart contract is generated based on the object attributes of multiple users respectively, so that the public key and private key in the key pair can incorporate the user attribute information, enabling subsequent combination of data encryption and decryption with user attributes.

[0122] In one of the embodiments, the method further includes:

[0123] According to the object attributes of multiple users respectively, configure an authorized user set and an authorized object attribute set for each transaction identifier of the smart contract. The authorized object attribute set includes the object attributes of each authorized user in the authorized user set; based on the public key in the key pair and the authorized object attribute set of each transaction identifier, encrypt the transaction information corresponding to each transaction identifier to obtain the encrypted ciphertext corresponding to each transaction identifier; generate an object attribute private key for each authorized user according to the private key in the key pair and the object attributes of each authorized user in the authorized object attribute set; send the object attribute private key of each authorized user to each authorized user.

[0124] Specifically, the blockchain node obtains the object attributes of multiple users respectively and combines multiple users into multiple authorized user sets. The blockchain node determines each transaction identifier of the smart contract and configures an authorized user set for each transaction identifier. For each authorized user set, based on the attributes of the users in the authorized user set targeted, generate the object attribute set of the authorized user set targeted, so that each transaction identifier is configured with an authorized user set and an authorized object attribute set.

[0125] Such as Figure 6As shown in the figure, the smart contract has three transaction identifiers, namely A, B, and C, and each transaction identifier indicates the transaction information of a transaction. The blockchain node obtains the object attributes of multiple users and combines the multiple users into 3 authorized user sets, namely authorized user set 1, authorized user set 2, and authorized user set 3. An object attribute set 1 is generated based on the object attributes of each user in the authorized user set 1, an object attribute set 2 is generated based on the object attributes of each user in the authorized user set 2, and an object attribute set 3 is generated based on the object attributes of each user in the authorized user set 3. For example, the object attributes of each user in the authorized user set 1 are object attribute 1, object attribute 2, and object attribute 3, then the object attributes of each user in the generated authorized user set 1 include these 3 object attributes. The authorized user set 1 and the object attribute set 1 are configured for the transaction identifier A, the authorized user set 2 and the object attribute set 2 are configured for the transaction identifier B, and the authorized user set 3 and the object attribute set 3 are configured for the transaction identifier C.

[0126] In this embodiment, multiple users can be combined into the same number of authorized user sets according to the number of transaction identifiers, so that each transaction identifier is configured with an authorized user set, and the authorized user sets configured for different transaction identifiers are different. Or, the number of the combined authorized user sets can be less than the number of transaction identifiers, then the same authorized user set and authorized object attribute set can be configured for different transaction identifiers.

[0127] As Figure 7 shown in the figure, the object attribute set 1 and the authorized user set 1 are configured for the transaction identifier A, the object attribute set 1 and the authorized user set 1 are configured for the transaction identifier B, and the object attribute set 2 and the authorized user set 2 are configured for the transaction identifier C.

[0128] Specifically, the blockchain node obtains the public key in the key pair, and uses the public key and the object attributes in each authorized object attribute set to encrypt the transaction information of each transaction identifier respectively, obtaining the encrypted ciphertext of each transaction information. The encrypted ciphertext of the transaction information is used as the encrypted ciphertext corresponding to the transaction identifier of the transaction information.

[0129] Furthermore, the blockchain node deploys the encrypted ciphertext of each transaction identifier in the smart contract.

[0130] Specifically, the blockchain node obtains the private key in the key pair. For a transaction identifier, based on the private key and the object attributes of each authorized user in the object attribute set of the transaction identifier, the object attribute private key of each authorized user of the transaction identifier is generated. In the same processing manner, the object attribute private keys of the authorized users of each transaction identifier can be generated respectively.

[0131] Specifically, the blockchain node can send the respective object attribute private keys to the authorized users of each transaction identifier. Further, the blockchain node can send the respective object attribute private keys to the authorized users of each transaction identifier through a preset channel. Sending the object attribute private key through a preset channel can separate it from the transfer channels of other requests and data, making the transfer security of the private key better.

[0132] In this embodiment, different preset channels can be set for different transaction identifiers, and through the preset channel corresponding to the transaction identifier, the respective object attribute private keys are sent to the authorized users of the transaction identifier. The blockchain node can determine the preset channel corresponding to each transaction identifier, and for each transaction identifier, based on the preset channel of the targeted transaction identifier, send the respective object attribute private keys of the authorized users of the targeted transaction identifier to each authorized user. Presetting respective channels for each transaction identifier to transfer the object attribute private keys can effectively avoid the batch leakage of object attribute private keys and improve security.

[0133] As Figure 8 shown, the smart contract has three transaction identifiers A, B, and C. Transaction identifier A corresponds to preset channel 1, transaction identifier B corresponds to preset channel 2, and transaction identifier C corresponds to preset channel 3. After the blockchain node generates the object attribute private keys of the authorized users of each transaction identifier, it sends the respective object attribute private keys of the authorized users corresponding to transaction identifier A through preset channel 1, sends the respective object attribute private keys of the authorized users corresponding to transaction identifier B through preset channel 2, and sends the respective object attribute private keys of the authorized users corresponding to transaction identifier C through preset channel 3.

[0134] In this embodiment, according to the respective object attributes of multiple users, an authorized user set and an object attribute set of each authorized user set are configured for each transaction identifier of the smart contract, which can configure respective authorized users for each transaction identifier. The object attribute set includes the object attributes of each authorized user in the authorized user set, so as to encrypt the transaction information corresponding to each transaction identifier based on the public key in the key pair and the authorized object attribute set of each transaction identifier to generate the encrypted ciphertext corresponding to each transaction identifier, and generate the object attribute private key of each authorized user according to the private key in the key pair and the object attributes of each authorized user in the object attribute set, so that subsequently, through the encrypted ciphertext and the object attribute private key, it can be effectively verified whether the user requesting to call the transaction identifier is an authorized user of the transaction identifier, thereby effectively determining whether to execute the user's call request, and can effectively improve the flexibility and security of calling the transaction identifier.

[0135] In one of the embodiments, sending the respective object attribute private keys to each authorized user includes:

[0136] Encrypt the object attribute private key with an encryption key to obtain the encrypted object attribute private key; send each user's encrypted object attribute private key to each authorized user through a first preset channel; obtain the decryption key generation information corresponding to the encryption key, and send the decryption key generation information to each authorized user through a second preset channel. The decryption key generation information is used to generate a decryption key, and the decryption key is used to decrypt the encrypted object attribute private key to obtain the object attribute private key.

[0137] Among them, the encryption key is the key used to encrypt the object attribute private key. The first preset channel is a preset channel for transmitting the encrypted object attribute private key. The second preset channel is a preset channel for transmitting the decryption key generation information. The decryption key generation information is the information for generating the decryption key corresponding to the encryption key.

[0138] Specifically, the blockchain node obtains a preset encryption key, and encrypts the object attribute private key of each authorized user with the preset encryption key to obtain the encrypted object attribute private key of each authorized user.

[0139] The blockchain node sends the encrypted object attribute private key of each authorized user in the set of authorized users to each authorized user through the first preset channel.

[0140] In this embodiment, the preset channel may include a first preset channel and a second preset channel. The first preset channel is used to transmit the encrypted object attribute private key, and the second preset channel is used for the decryption key generation information corresponding to the encryption key.

[0141] The blockchain node obtains the decryption key generation information corresponding to the encryption key, and sends the decryption key generation information to each authorized user in the set of authorized users through the second preset channel. Each authorized user receives their own encrypted object attribute private key through the first preset channel and receives the decryption key generation information through the second preset channel. The authorized user generates a decryption key based on the decryption key generation information, and decrypts the encrypted object attribute private key with the decryption key to obtain the object attribute private key and stores it locally.

[0142] As Figure 9 shown, it is a timing diagram of the interaction between the blockchain node and the authorized user in an embodiment.

[0143] 1) The blockchain node obtains an encryption key, encrypts the object attribute private key with the encryption key to obtain the encrypted object attribute private key;

[0144] 2) The blockchain node calls the first preset channel;

[0145] 3) The blockchain node transmits the encrypted object attribute private key to the authorized user through the first preset channel;

[0146] 4) The blockchain node obtains the decryption key generation information corresponding to the encryption key;

[0147] 5) The blockchain node invokes the second preset channel;

[0148] 6) The decryption key generation information is transmitted to the authorized user through the second preset channel;

[0149] 7) The authorized user receives the decryption key generation information through the second preset channel and generates a decryption key based on the decryption key generation information;

[0150] 8) The authorized user receives the encrypted object attribute private key through the first preset channel, decrypts the encrypted object attribute private key with the decryption key, and obtains the object attribute private key;

[0151] 9) The authorized user stores the object attribute private key locally.

[0152] In this embodiment, the object attribute private key is encrypted with the encryption key to obtain the encrypted object attribute private key. Through the first preset channel, the encrypted object attribute private keys of each authorized user are sent to each authorized user, and the decryption key generation information corresponding to the encryption key is obtained. Through the second preset channel, the decryption key generation information is sent to each authorized user. Using different channels to transmit the object attribute private key and the decryption information of the attribute private key makes the transmission of the key more secure. Moreover, the transmitted attribute private key is the encrypted object attribute private key, so that the user can use the received decryption key generation information to generate a decryption key, and then use the decryption key to decrypt the encrypted object attribute private key, thereby obtaining the object attribute private key, which can further improve the security of the transmission of the attribute private key.

[0153] In one embodiment, the encrypted ciphertext is decrypted based on the object attribute private key. When the decryption is successful, it indicates that the authentication is passed, and the transaction information corresponding to the transaction identifier is obtained, including:

[0154] The encrypted ciphertext is decrypted based on the object attribute private key. When the decryption is successful, the set of authorized users corresponding to the transaction identifier is obtained; when the request initiator belongs to the authorized users in the set of authorized users, it indicates that the authentication is passed, and the transaction information corresponding to the transaction identifier is obtained.

[0155] Specifically, the blockchain node decrypts the encrypted ciphertext based on the object attribute private key. When the decryption is successful, the authorized user set corresponding to the transaction identifier is obtained. The authorized user set includes the user identifiers of multiple authorized users. The blockchain node obtains the user identifier of the request initiator and matches the user identifier of the request initiator with the user identifiers in the authorized user set to determine whether the request initiator belongs to the authorized users in the authorized user set. When the user identifier of the request initiator is the same as any one of the authorized users in the authorized user set, it indicates that the request initiator belongs to the authorized users in the authorized user set, which means that the request initiator passes the identity verification and obtains the transaction information corresponding to the transaction identifier.

[0156] In this embodiment, when decrypting the encrypted ciphertext based on the object attribute private key, when the decryption is successful, the transaction information corresponding to the transaction identifier is not directly obtained, but the authorized user set corresponding to the transaction identifier is obtained, so that the identity of the request initiator can be further verified based on the user identifier of the request initiator, realizing double verification of attributes and user identifiers. When the request initiator belongs to the authorized users in the authorized user set, it means that the identity verification is passed, and then the transaction information corresponding to the transaction identifier is obtained, which can effectively prevent other users from stealing the object attribute private key of the authorized user to access the transaction information, and further improve the privacy of the transaction information deployed on the blockchain.

[0157] In one embodiment, decrypting the encrypted ciphertext based on the object attribute private key includes:

[0158] Determine the current ciphertext state of the encrypted ciphertext. The ciphertext state includes a valid state and an update state; when the ciphertext state indicates that the encrypted ciphertext is in the valid state, decrypt the encrypted ciphertext based on the object attribute private key.

[0159] Among them, the valid state indicates that the encrypted ciphertext is currently valid, and the update state indicates that the encrypted ciphertext is currently being updated. The ciphertext state also includes an invalid state, and the invalid state indicates that the encrypted ciphertext is currently invalid.

[0160] Specifically, the blockchain node determines the encrypted ciphertext corresponding to the transaction identifier based on the smart contract and determines the current ciphertext state of the encrypted ciphertext. The ciphertext state of the encrypted ciphertext includes a valid state, an invalid state, and an update state.

[0161] When the ciphertext state indicates that the encrypted ciphertext is in the valid state, the blockchain node decrypts the encrypted ciphertext based on the object attribute private key.

[0162] When the ciphertext state indicates that the encrypted ciphertext is in the invalid state, the blockchain node rejects the interface encryption call request.

[0163] In this embodiment, the ciphertext state corresponding to the encrypted ciphertext of the transaction identifier is preset to indicate whether the encrypted ciphertext is currently in a valid state, an invalid state, or an updated state. Only when the encrypted ciphertext is valid can it be decrypted and called, making the call to the transaction identifier more rigorous and secure.

[0164] Moreover, the ciphertext state of the encrypted ciphertext can also characterize the state of the object attribute private key of the authorized user. When the encrypted ciphertext is in the updated state, it indicates that the object attribute private key is also in the updated state. When the encrypted ciphertext is in the invalid state, it indicates that the object attribute private key is currently invalid. When the encrypted ciphertext is in the valid state, it indicates that the object attribute private key is currently valid.

[0165] In one embodiment, the method further includes:

[0166] When the ciphertext state indicates that the encrypted ciphertext is in the updated state, determine the backup ciphertext corresponding to the encrypted ciphertext; decrypt the backup ciphertext based on the object attribute private key.

[0167] Wherein, the backup ciphertext refers to a copy of the encrypted ciphertext.

[0168] Specifically, when the ciphertext state indicates that the encrypted ciphertext is in the updated state, the blockchain node determines the backup ciphertext corresponding to the encrypted ciphertext. The blockchain node decrypts the backup ciphertext based on the object attribute private key. When the decryption is successful, call the transaction identifier indicated by the transaction identifier in the smart contract.

[0169] In one of the embodiments, when the ciphertext state indicates that the encrypted ciphertext is in the updated state, determine the backup ciphertext corresponding to the encrypted ciphertext based on the transaction identifier; decrypt the backup ciphertext based on the object attribute private key.

[0170] In this embodiment, the method further includes:

[0171] Determine the preset effective duration of the encrypted ciphertext and determine the elapsed duration of the encrypted ciphertext; when the elapsed duration reaches the preset effective duration, generate a backup ciphertext of the encrypted ciphertext; establish a correspondence between the backup ciphertext and the transaction identifier of the transaction identifier.

[0172] In this embodiment, when the ciphertext state indicates that the encrypted ciphertext is in the updated state, determine the backup ciphertext corresponding to the encrypted ciphertext, decrypt the backup ciphertext based on the object attribute private key, so that when the encrypted ciphertext is in the updated state, it can still respond to user requests, effectively avoiding the impact of policy updates on users and improving the user experience.

[0173] In one embodiment, the method further includes:

[0174] Determine the preset effective duration of the encrypted ciphertext, and determine the elapsed duration of the encrypted ciphertext; when the elapsed duration reaches the preset effective duration, generate a backup ciphertext of the encrypted ciphertext; adjust the current ciphertext status of the encrypted ciphertext from the valid status to the updated status.

[0175] Specifically, the blockchain node determines the preset policy effective duration of the encrypted ciphertext and determines the elapsed duration of the encrypted ciphertext. The blockchain node detects whether the elapsed duration of the encrypted ciphertext reaches the policy effective duration of the encrypted ciphertext. When the elapsed duration reaches the policy effective duration, the blockchain node generates a backup ciphertext of the encrypted ciphertext and adjusts the current ciphertext status of the encrypted ciphertext from the valid status to the updated status.

[0176] In the updated status, update the encrypted ciphertext of the transaction identifier to obtain the updated encrypted ciphertext. Deploy the updated encrypted ciphertext in the smart contract and overwrite the encrypted ciphertext before the update of the transaction identifier.

[0177] In this embodiment, the method further includes:

[0178] When the update of the encrypted ciphertext is completed, adjust it from the updated status to the valid status and delete the backup ciphertext.

[0179] In this embodiment, the method further includes: deleting the correspondence between the backup ciphertext and the transaction identifier.

[0180] As Figure 10 shown, it is a timing diagram of the transaction processing method in an embodiment.

[0181] 1) Receive a transaction encryption access request for the smart contract initiated by the request initiator.

[0182] 2) The blockchain node uses the private key in the key pair to decrypt the transaction encryption access request to obtain the transaction identifier and the object attribute private key.

[0183] 3) The blockchain node determines the encrypted ciphertext corresponding to the transaction identifier based on the smart contract.

[0184] 4) The blockchain node determines the current ciphertext status of the encrypted ciphertext, and the ciphertext status includes the valid status and the updated status.

[0185] 5) When the ciphertext status indicates that the encrypted ciphertext is in the valid status, decrypt the encrypted ciphertext based on the object attribute private key.

[0186] 6) When the ciphertext status indicates that the encrypted ciphertext is in the updated status, determine the backup ciphertext corresponding to the encrypted ciphertext and decrypt the backup ciphertext based on the object attribute private key.

[0187] 7) Whether decrypting the encrypted ciphertext or the backup ciphertext, when the decryption is successful, it indicates that the authentication is passed, and the transaction information corresponding to the transaction identifier is obtained.

[0188] 8) Whether decrypting the encrypted ciphertext or the backup ciphertext, when the decryption fails, it indicates that the authentication fails, and a response result for rejecting access to the transaction information is generated.

[0189] 9) The blockchain node returns a response result for rejecting access to the transaction information to the request initiator.

[0190] In this embodiment, the preset effective duration of the encrypted ciphertext is determined, and the elapsed duration of the encrypted ciphertext is determined. When the elapsed duration reaches the preset effective duration, a backup ciphertext of the encrypted ciphertext is generated, so that during the process of updating the encrypted ciphertext of the transaction identifier, the backup ciphertext can be used to respond to the user's call request for the transaction identifier. The current ciphertext state of the encrypted ciphertext is adjusted from the valid state to the update state to prompt the current state of the encrypted ciphertext to determine whether to use the backup ciphertext to respond to the user request.

[0191] In one embodiment, decrypting the encrypted ciphertext based on the object attribute private key includes:

[0192] Determine the transaction type corresponding to the transaction identifier, and determine the execution node that matches the transaction type; allocate the transaction identifier and the object attribute private key to the execution node to instruct the execution node to decrypt the encrypted ciphertext based on the object attribute private key.

[0193] Among them, the execution node can be a sub-node on the blockchain node, which is used to process requests related to specific types of transactions. The execution node matches the transaction type.

[0194] Specifically, the blockchain node can determine the transaction type corresponding to the transaction identifier to determine the execution node that matches the transaction type. The blockchain node allocates the transaction identifier and the object attribute private key to the execution node. The execution node receives the transaction identifier and the object attribute private key, decrypts the encrypted ciphertext corresponding to the transaction identifier based on the object attribute private key. When the decryption is successful, it indicates that the authentication is passed, and the transaction information corresponding to the transaction identifier is obtained.

[0195] In this embodiment, the transaction identifier, the object attribute private key, and the encrypted ciphertext are allocated to the execution node to instruct the execution node to decrypt the encrypted ciphertext based on the object attribute private key.

[0196] In this embodiment, determining the transaction type corresponding to the transaction identifier and determining the execution node that matches the transaction type enables requests for accessing transaction information of different transaction types to be assigned to specific execution nodes for processing, which can improve the response speed to user requests.

[0197] In one embodiment, the method further includes:

[0198] When the effective duration of the encrypted ciphertext of the transaction identifier reaches a preset effective duration, update the public key and private key in the key pair to obtain an updated key pair; based on the public key in the updated key pair and the authorized object attribute set, update the encrypted ciphertext to obtain an updated encrypted ciphertext.

[0199] The method further includes: generating an updated object attribute private key based on the private key in the updated key pair and the object attributes of each authorized user in the authorized object attribute set.

[0200] In one embodiment, the method further includes:

[0201] When the effective duration of the encrypted ciphertext of the transaction identifier reaches a preset effective duration, update the object attributes of the authorized users in the authorized object attribute set of the transaction identifier to obtain an updated object attribute set; based on the public key in the updated key pair and the authorized object attribute set, update the encrypted ciphertext to obtain an updated encrypted ciphertext.

[0202] The method further includes: generating an updated object attribute private key based on the private key in the key pair and the object attributes of each authorized user in the updated object attribute set.

[0203] In one of the embodiments, the method further includes:

[0204] When the effective duration of the encrypted ciphertext of the transaction identifier reaches a preset effective duration, update the key pair and the authorized object attribute set; based on the public key in the updated key pair and the authorized object attribute set, update the encrypted ciphertext to obtain an updated encrypted ciphertext.

[0205] The method further includes:

[0206] Generating an updated object attribute private key based on the private key in the updated key pair and the object attributes of each authorized user in the updated object attribute set; sending the respective updated object attribute private keys to each authorized user.

[0207] In one embodiment, when receiving an attribute change request from an authorized user, update the authorized object attribute set based on the target attribute in the attribute change request; based on the public key and the updated object attribute set, update the encrypted ciphertext to obtain an updated encrypted ciphertext; generate an updated object attribute private key based on the private key and the target attribute.

[0208] In this embodiment, the method further includes: sending the updated object attribute private key to the authorized user.

[0209] In this embodiment, an encrypted attribute change request from an authorized user is received, and the encrypted attribute change request is encrypted using the public key in the key pair of the smart contract; the private key in the key pair is used to decrypt the encrypted attribute change request to obtain the target attribute.

[0210] In this embodiment, using the private key in the key pair to decrypt the encrypted attribute change request to obtain the target attribute includes: using the private key in the key pair to decrypt the encrypted attribute change request to obtain a transaction identifier, a target attribute, and an object attribute private key; determining, based on the smart contract, the encrypted ciphertext corresponding to the transaction identifier; decrypting the encrypted ciphertext using the object attribute private key, and when the decryption is successful, updating the authorized object attribute set based on the target attribute; updating the encrypted ciphertext based on the public key and the updated object attribute set to obtain an updated encrypted ciphertext; generating an updated object attribute private key based on the private key and the target attribute.

[0211] In one embodiment, the authorized user may be the request initiator. When receiving an attribute change request from the request initiator, updating the authorized object attribute set based on the target attribute in the attribute change request; updating the encrypted ciphertext based on the public key and the updated object attribute set to obtain an updated encrypted ciphertext; generating an updated object attribute private key based on the private key and the target attribute.

[0212] In this embodiment, the method further includes: sending the updated object attribute private key to the request initiator.

[0213] In one embodiment, the method further includes:

[0214] Determining a preset effective duration and an elapsed effective duration of the encrypted ciphertext corresponding to the transaction identifier; when the elapsed effective duration reaches the preset effective duration and an attribute change request for the transaction identifier is received, updating the authorized object attribute set based on the target attribute in the attribute change request; updating the encrypted ciphertext based on the public key and the updated object attribute set to obtain an updated encrypted ciphertext; generating an updated object attribute private key based on the private key and the target attribute.

[0215] Among them, the attribute change request may be a request to change the object attribute. The attribute change request may carry the target attribute that the authorized user needs to change. The target attribute is the object attribute that the authorized user needs to change. The attribute change request is used to request to change the object attribute of the authorized user in the authorized object attribute set to the target attribute.

[0216] Specifically, the blockchain node allows the authorized user to change their own object attribute in the object attribute set, enabling the authorized user to customize their own object attribute.

[0217] An authorized user can obtain custom object attributes and use the custom object attributes as target attributes. The authorized user generates an attribute change request based on the target attributes, and the target attributes are carried in the attribute change request. The authorized user sends the attribute change request to the blockchain node.

[0218] The blockchain node determines the preset valid duration of the encrypted ciphertext corresponding to the transaction identifier and detects the elapsed duration corresponding to the encrypted ciphertext. When it is detected that the elapsed duration reaches the preset valid duration, it is detected whether there is an attribute change request for the transaction identifier.

[0219] When the blockchain node detects that the elapsed duration reaches the preset valid duration and receives an attribute change request from an authorized user, the attribute change request includes target attributes. The blockchain node determines which authorized user set the authorized user belongs to. When the authorized user belongs to multiple authorized user sets, it is necessary to determine each authorized user set to which the authorized user belongs and determine the object attribute set of each authorized user set. In each determined object attribute set, the blockchain node changes the object attributes of the authorized user to the target attributes to obtain each updated object attribute set.

[0220] The blockchain node determines the authorized user set of each updated object attribute set and determines the encrypted ciphertext corresponding to each authorized user set. The determined encrypted ciphertext is the encrypted ciphertext that needs to be updated. For each encrypted ciphertext that needs to be updated, the blockchain node updates the encrypted ciphertext based on the public key in the key pair and the updated object attribute set of the encrypted ciphertext to obtain the updated encrypted ciphertext.

[0221] Furthermore, the blockchain node encrypts the transaction information corresponding to the transaction identifier based on the public key in the key pair and the updated object attribute set to obtain the updated encrypted ciphertext.

[0222] In this embodiment, the function of object attribute change is provided for authorized users. When an attribute change request from an authorized user is received, the authorized user set to which the authorized user belongs is determined. The target attributes of the authorized user are carried in the attribute change request, and the object attribute set of the authorized user set is determined, so as to update the object attribute set where the attributes of each such authorized user are located based on the target attributes. The encrypted ciphertext corresponding to the authorized user set is determined, so as to accurately update each encrypted ciphertext related to the attributes of the authorized user based on the public key and the updated object attribute set, so that the updated encrypted ciphertext can be decrypted by the private key of the user's changed attributes.

[0223] In this embodiment, the method further includes: sending the updated object attribute private key to the authorized user.

[0224] Specifically, the blockchain node generates an object attribute private key for the authorized user based on the private key in the key pair and the target attributes of the authorized user, and sends the object attribute private key of the authorized user to the authorized user through a preset channel.

[0225] In this embodiment, the blockchain node encrypts the object attribute private key updated with the encryption key pair to obtain an encrypted object attribute private key. The blockchain node sends the encrypted object attribute private key to the authorized user who sends the attribute change request through a first preset channel. The blockchain node obtains the decryption key generation information corresponding to the encryption key, and sends the decryption key generation information to the authorized user who sends the attribute change request through a second preset channel. The decryption key generation information is used to generate a decryption key, and the decryption key is used to decrypt the encrypted object attribute private key to obtain the updated object attribute private key.

[0226] In this embodiment, the function of customizing object attributes is provided to the user. When the effective duration reaches the preset effective duration and an attribute change request for the transaction identifier is received, the blockchain node updates the object attribute set and each ciphertext encrypted related to the object attributes of the authorized user, so as to update the ciphertext based on the user's customization or update of the attributes. Moreover, based on the private key in the key pair and the target attributes of the authorized user, the update of the object attribute private key of the authorized user is realized, so that the function of updating the object attribute private key can be provided to the user, enabling the user to update the object attributes and the object attribute private key according to their own needs.

[0227] In one embodiment, the method further includes:

[0228] When the effective duration reaches the preset effective duration and no attribute change request for the transaction identifier is received, update the key pair of the smart contract; based on the public key in the updated key pair and the authorized object attribute set, update the encrypted ciphertext to obtain the updated encrypted ciphertext; based on the private key in the updated key pair and the authorized object attribute set, update the object attribute private key to obtain the updated object attribute private key.

[0229] Specifically, when the blockchain node detects that the effective duration reaches the preset effective duration, it detects whether an attribute change request for the transaction identifier from the authorized user is received. When the effective duration reaches the preset effective duration and no attribute change request for the transaction identifier is received, the blockchain node updates the public key and the private key in the key pair of the smart contract to obtain the updated key pair.

[0230] The blockchain node encrypts the transaction information of the transaction identifier based on the public key in the updated key pair and the authorized set of object attributes of the transaction identifier, and obtains an updated encrypted ciphertext. The authorized set of object attributes includes the object attributes of each authorized user. The blockchain node generates an updated object attribute private key for each authorized user based on the private key in the updated key pair and the object attributes of each authorized user.

[0231] In this embodiment, when the effective duration reaches the preset effective duration and no attribute change request for the transaction identifier is received, the key pair of the smart contract is updated, so that in the case where the ciphertext and the attribute private key need to be updated, it can be determined whether to update the key pair or the object attributes first based on whether the user requests to change the object attributes. In the case where no user requests to change the attributes, the key pair is automatically updated, and then the encrypted ciphertext and the object attribute private key are updated based on the updated key pair, which can ensure the validity of the object attribute private key and the encrypted ciphertext.

[0232] As Figure 11 shown, the processing procedure for updating the encrypted ciphertext and the object attribute private key in an embodiment includes:

[0233] Step S1102, determine the preset effective duration and the effective duration that has elapsed of the encrypted ciphertext corresponding to the transaction identifier.

[0234] Step S1104, determine whether the effective duration that has elapsed reaches the preset effective duration. If so, execute step S1106; otherwise, end.

[0235] Step S1106, when the effective duration that has elapsed reaches the preset effective duration, determine whether there is an attribute change request for the transaction identifier. If so, execute step S1108; otherwise, execute step S1114.

[0236] Step S1108, there is an attribute change request for the transaction identifier, and update the authorized set of object attributes based on the target attributes in the attribute change request.

[0237] Step S1110, update the encrypted ciphertext based on the public key and the updated set of object attributes to obtain an updated encrypted ciphertext.

[0238] Step S1112, generate an updated object attribute private key based on the private key and the target attributes.

[0239] Step S1114, no attribute change request for the transaction identifier is received, and update the key pair of the smart contract.

[0240] Step S1116, update the encrypted ciphertext based on the public key in the updated key pair and the authorized set of object attributes to obtain an updated encrypted ciphertext.

[0241] Step S1118: Update the object attribute private key based on the private key in the updated key pair and the authorized object attribute set to obtain the updated object attribute private key.

[0242] Step S1120: Send the updated object attribute private key of each authorized user to each authorized user.

[0243] In one embodiment, as Figure 12 shown, the authorized object attribute set includes the object attributes of each authorized user of the transaction identifier, and the method further includes:

[0244] Step S1202: Encrypt the updated object attribute private key with the encryption key to obtain the encrypted object attribute private key.

[0245] Specifically, the blockchain node obtains the preset encryption key and encrypts the updated object attribute private key of each authorized user with the preset encryption key to obtain the encrypted object attribute private key of each authorized user.

[0246] Step S1204: Send the encrypted object attribute private key of each authorized user to each authorized user through the first preset channel.

[0247] Specifically, the blockchain node sends the encrypted object attribute private key of each authorized user in the set of each authorized user to each authorized user through the first preset channel.

[0248] In this embodiment, the preset channel may include the first preset channel corresponding to each transaction identifier and the second preset channel corresponding to each transaction identifier. The first preset channel corresponding to each transaction identifier is used to transmit the encrypted object attribute private key of each transaction identifier. The second preset channel corresponding to each transaction identifier is used to transmit the decryption key generation information corresponding to the encryption key.

[0249] Step S1206: Obtain the decryption key generation information corresponding to the encryption key and send the decryption key generation information to each authorized user through the second preset channel. The decryption key generation information is used to generate the decryption key, and the decryption key is used to decrypt the encrypted object attribute private key to obtain the updated object attribute private key.

[0250] Specifically, the blockchain node obtains the decryption key generation information corresponding to the encryption key and sends the decryption key generation information to each authorized user in the set of each authorized user through the second preset channel. Each authorized user receives the encrypted object attribute private key of each user through the first preset channel and receives the decryption key generation information through the second preset channel. The authorized user generates the decryption key based on the decryption key generation information and decrypts the encrypted object attribute private key with the decryption key to obtain the updated object attribute private key and stores it locally.

[0251] In this embodiment, an encryption key is used to encrypt the object attribute private key to obtain an encrypted object attribute private key. Through a first preset channel, the encrypted object attribute private keys of each authorized user are sent to each authorized user, and the decryption key generation information corresponding to the encryption key is obtained. Through a second preset channel, the decryption key generation information is sent to each authorized user. Different channels are used to transmit the object attribute private key and the decryption information of the attribute private key, making the transmission of the key more secure. Moreover, the transmitted attribute private key is the encrypted object attribute private key, enabling the user to generate a decryption key based on the received decryption key generation information, and then using the decryption key to decrypt the encrypted object attribute private key, thereby obtaining an updated object attribute private key, which can further improve the security of the transmission of the attribute private key.

[0252] In one embodiment, the method further includes:

[0253] Determine the contract interface corresponding to the transaction identifier; perform transaction processing according to the transaction information through the contract interface to obtain a transaction result.

[0254] Among them, the contract interface refers to the interface through which a user interacts with and performs operations on a smart contract. For example, the contract interface can be an Application Programming Interface (API).

[0255] Specifically, the blockchain node can pre-set respective contract interfaces for each transaction identifier to execute the transaction indicated by the transaction identifier through the respective contract interfaces.

[0256] After decrypting to obtain the transaction information corresponding to the transaction identifier, the blockchain node can determine the contract interface corresponding to the transaction identifier, call the contract interface, and thus perform transaction processing according to the transaction information through the contract interface to obtain a transaction result.

[0257] In this embodiment, determining the contract interface corresponding to the transaction identifier includes: determining the transaction type corresponding to the transaction identifier and determining the contract interface corresponding to the transaction type.

[0258] In one embodiment, the method further includes:

[0259] Determine the transaction type corresponding to the transaction identifier and determine the contract interface corresponding to the transaction type;

[0260] Call the contract interface, and perform transaction processing according to the transaction information through the contract interface to obtain a transaction result.

[0261] Among them, different types of contract interfaces of the smart contract have different functions, such as recharge interfaces, transfer interfaces, etc., but are not limited to these. Different types of transactions of the smart contract can be executed using different contract interfaces. For example, recharge transactions use recharge interfaces, and transfer transactions can use transfer interfaces.

[0262] Specifically, after decrypting to obtain the transaction information corresponding to the transaction identifier, the blockchain node can determine the transaction type corresponding to the transaction identifier to determine the contract interface used by this transaction type. The blockchain node calls this contract interface and performs transaction processing according to the transaction information through the contract interface to obtain a transaction result.

[0263] For example, if the transaction type is a transfer transaction and the transaction information includes the account information of the transaction initiator, the account information of the recipient, and the transaction amount, the blockchain node can call the contract interface to transfer the transaction amount from the initiator's account to the recipient's account and generate a transaction result after the execution is completed.

[0264] In this embodiment, determining the transaction type corresponding to the transaction identifier to determine the contract interface required for the transaction of this transaction type enables different types of transactions to be executed using different types of contract interfaces. Performing transaction processing according to the transaction information through the contract interface to obtain a transaction result ensures that the transaction is decrypted and executed only when the user has specific attributes, thereby ensuring the legality of the transaction.

[0265] In one embodiment, a transaction processing method is provided, which is applied to a blockchain node and includes:

[0266] Obtain the respective object attributes of multiple users and verify the respective object attributes of multiple users;

[0267] When the verification passes, generate a key pair for the smart contract based on the respective object attributes of multiple users.

[0268] According to the respective object attributes of multiple users, configure an authorized user set and each authorized object attribute set for each transaction identifier of the smart contract. The authorized object attribute set includes the object attributes of each authorized user in the authorized user set; encrypt the transaction information corresponding to each transaction identifier based on the public key in the key pair and the authorized object attribute set of each transaction identifier to obtain the encrypted ciphertext corresponding to each transaction identifier; generate the object attribute private key of each authorized user according to the private key in the key pair and the object attributes of each authorized user in the authorized object attribute set.

[0269] Encrypt the object attribute private key using an encryption key to obtain the encrypted object attribute private key; send each user's encrypted object attribute private key to each authorized user through a first preset channel; obtain the decryption key generation information corresponding to the encryption key, and send the decryption key generation information to each authorized user through a second preset channel. The decryption key generation information is used to generate a decryption key, and the decryption key is used to decrypt the encrypted object attribute private key to obtain the object attribute private key.

[0270] Receive a transaction encryption access request for a smart contract initiated by a request initiator. The transaction encryption access request is encrypted using the public key in the key pair of the smart contract.

[0271] Use the private key in the key pair to decrypt the transaction encryption access request to obtain a transaction identifier and an object attribute private key. The object attribute private key is generated based on the private key and the object attributes of the request initiator.

[0272] Based on the smart contract, determine the encrypted ciphertext corresponding to the transaction identifier. The encrypted ciphertext is obtained by encrypting the transaction information corresponding to the transaction identifier based on the public key and the object attributes in the authorized object attribute set.

[0273] Determine the current ciphertext state of the encrypted ciphertext. The ciphertext state includes a valid state and an update state; when the ciphertext state indicates that the encrypted ciphertext is in a valid state, decrypt the encrypted ciphertext based on the object attribute private key.

[0274] When the ciphertext state indicates that the encrypted ciphertext is in an update state, determine the backup ciphertext corresponding to the encrypted ciphertext; decrypt the backup ciphertext based on the object attribute private key.

[0275] When the decryption is successful, obtain the authorized user set corresponding to the transaction identifier; when the request initiator belongs to the authorized user in the authorized user set, it indicates that the identity verification is passed, and obtain the transaction information corresponding to the transaction identifier.

[0276] Determine the transaction type corresponding to the transaction identifier, and determine the contract interface corresponding to the transaction type;

[0277] Call the contract interface and execute transaction processing according to the transaction information through the contract interface to obtain a transaction result.

[0278] Determine the preset effective duration and the elapsed duration of the encrypted ciphertext corresponding to the transaction identifier.

[0279] When the elapsed duration reaches the preset effective duration and a property change request for the transaction identifier is received, update the authorized object attribute set based on the target attribute in the property change request; update the encrypted ciphertext based on the public key and the updated object attribute set to obtain an updated encrypted ciphertext; generate an updated object attribute private key based on the private key and the target attribute.

[0280] When the effective duration reaches the preset effective duration and no attribute change request for the transaction identifier is received, update the key pair of the smart contract; based on the public key in the updated key pair and the authorized set of object attributes, update the encrypted ciphertext to obtain the updated encrypted ciphertext;

[0281] Based on the private key in the updated key pair and the authorized set of object attributes, update the object attribute private key to obtain the updated object attribute private key.

[0282] Encrypt the updated object attribute private key with the encryption key to obtain the encrypted object attribute private key; send the respective encrypted object attribute private keys to each authorized user through the first preset channel; obtain the decryption key generation information corresponding to the encryption key, and send the decryption key generation information to each authorized user through the second preset channel. The decryption key generation information is used to generate the decryption key, and the decryption key is used to decrypt the encrypted object attribute private key to obtain the updated object attribute private key.

[0283] In one embodiment, as Figure 13 shown, an application scenario of a transaction processing method is provided, which is applied to the blockchain scenario, and the specific processing process is as follows:

[0284] 1) The blockchain node obtains the respective object attributes of multiple users and verifies the respective object attributes of the multiple users.

[0285] 2) When the verification passes, the blockchain node obtains a random parameter and generates a key pair for the smart contract based on the random parameter and the respective object attributes of the multiple users.

[0286] Specifically, the blockchain node uses the ABE (Attribute - Based Encryption) algorithm to generate a global public key and private key. The public key is deployed in the smart contract and can also be transmitted to users through broadcasting, while the private key is stored in the cipher machine or the key management system. Among them, the ABE cipher mechanism is an encryption technology that can determine who can access and use the ciphertext based on the attributes of users and messages. In the system initialization, the key generation center generates the public key and private key. The public key and private key in the key pair are asymmetric.

[0287] The ABE (Attribute - Based Encryption) algorithm includes CP - ABE (ciphertext policy attribute based enctyption) and KP - ABE (key policy attribute based encryption). CP - ABE means that the contract policy is embedded in the ciphertext, and the set of object attributes is embedded in the object attribute private key. Decryption is successful if and only if the object attributes can satisfy the contract policy.

[0288] Before using to obtain public and private keys or for encryption and decryption, the init function must be called.

[0289] ABELib_EXPORT void *kpabe_initCtx();

[0290] / **

[0291] Generate a key pair

[0292] #param1 Function input parameter - context

[0293] #param2 Function output parameter - public key

[0294] #param3 Function output parameter - private key

[0295] @return 0 indicates success, and other values are error codes.

[0296] ABELib_EXPORT int kpabe_generateMasterKeyPair(void *ctx, string &mpk, string &msk);

[0297] / **

[0298] Create a user key

[0299] #param1 Function input parameter - context #param2 Function input parameter - public key #param3 Function input parameter - private key #param4 Function input parameter - attribute value #param5 Function output parameter - user key

[0300] return 0 indicates success, and other values are error codes.

[0301] ABELib_EXPORT int kpabe_generateUserkey(void *ctx, string mpk, string msk, string attr, string userkey);

[0302] / **

[0303] Encryption

[0304] #param1 Function input parameter - context

[0305] #param2 Function input parameter - public key

[0306] #param3 Function input parameter - plaintext

[0307] #param4 Function input parameter - attribute list

[0308] #param5 Function input parameter - number of attributes

[0309] #param6 Function output parameter - ciphertext

[0310] @return 0 indicates success, other values are error codes * /

[0311] ABELib_EXPORT int kpabe_encrypt(void *ctx, string mpk, string plaintext, string *attrs, int size, string &ciphertext);

[0312] / ** Decryption

[0313] #param1 Function input parameter - context

[0314] #param2 Function input parameter - public key

[0315] #param3 Function input parameter - userkey

[0316] #param4 Function input parameter - object attributes

[0317] #param5 Function input parameter - ciphertext

[0318] #param5 Function output parameter - plaintext

[0319] @return 0 indicates success, other values are error codes * /

[0320] ABELib_EXPORT int kpabe_decrypt(void *ctx, string mpk, string userkey, string attr, string ciphertext, string &plaintext);

[0321] / **

[0322] After using the kpabe algorithm, the free function must be called to release

[0323] #param1 Function input parameter - context

[0324] * /

[0325] ABELib_EXPORT void kpabe_freeCtx(void *ctx);

[0326] 3) Based on the respective object attributes of multiple users, the blockchain node configures the authorized user set and the object attribute set of each authorized user set for each transaction identifier of the smart contract. The object attribute set includes the object attributes of each authorized user in the authorized user set; based on the public key in the key pair and the authorized object attribute set of each transaction identifier, encrypts the transaction information corresponding to the transaction identifier to obtain the encrypted ciphertext of each transaction identifier.

[0327] 4) The blockchain node generates the object attribute private key of each authorized user according to the private key in the key pair and the object attributes of each authorized user in the authorized object attribute set.

[0328] 5) The blockchain node obtains the encryption key, encrypts the object attribute private key with the encryption key to obtain the encrypted object attribute private key.

[0329] 6) The blockchain node calls the first preset channel.

[0330] 7) The blockchain node passes the encrypted object attribute private key to the authorized user through the first preset channel;

[0331] 8) The blockchain node obtains the decryption key generation information corresponding to the encryption key.

[0332] 9) The blockchain node calls the second preset channel.

[0333] 10) Passes the decryption key generation information to the authorized user through the second preset channel.

[0334] 11) The authorized user receives the decryption key generation information through the second preset channel and generates the decryption key based on the decryption key generation information.

[0335] 12) The authorized user receives the encrypted object attribute private key through the first preset channel, decrypts the encrypted object attribute private key with the decryption key to obtain the object attribute private key, and stores the object attribute private key locally.

[0336] 13) Receive the transaction encryption access request for the smart contract initiated by the request initiator.

[0337] 14) The blockchain node decrypts the transaction encryption access request with the private key in the key pair to obtain the transaction identifier and the object attribute private key.

[0338] 15) The blockchain node determines the encrypted ciphertext corresponding to the transaction identifier based on the smart contract.

[0339] 16) The blockchain node determines the current ciphertext state of the encrypted ciphertext, and the ciphertext state includes a valid state and an update state.

[0340] 17) When the encrypted ciphertext is in the valid state, decrypt the encrypted ciphertext based on the object attribute private key.

[0341] 18) When the encrypted ciphertext is in the update state, determine the backup ciphertext corresponding to the encrypted ciphertext, and decrypt the backup ciphertext based on the object attribute private key.

[0342] 19) Whether decrypting the encrypted ciphertext or the backup ciphertext, when the decryption is successful, the blockchain node displays the transaction information, determines the transaction type corresponding to the transaction identifier, and determines the contract interface corresponding to the transaction type.

[0343] 20) Invoke the contract interface, and perform transaction processing according to the transaction information through the contract interface to obtain the transaction result.

[0344] 21) Whether decrypting the encrypted ciphertext or the backup ciphertext, when the decryption fails, generate a response result indicating the rejection of the transaction information corresponding to the transaction identifier.

[0345] 22) The blockchain node returns a response result rejecting the call of the transaction identifier to the request initiator.

[0346] 23) The authorized user sends an attribute change request to the blockchain node, and the attribute change request includes the target attribute.

[0347] 24) The blockchain node detects whether the elapsed time since the encrypted ciphertext became effective has reached the preset effective time.

[0348] 25) The blockchain node detects that the elapsed time since the encrypted ciphertext became effective has reached the preset effective time and receives an attribute change request from the authorized user, updates the authorized object attribute set based on the target attribute in the attribute change request; generates an updated object attribute private key based on the private key and the target attribute.

[0349] 26) Update the encrypted ciphertext based on the public key and the updated set of object attributes to obtain an updated encrypted ciphertext.

[0350] 27) When the blockchain node detects that the elapsed effective duration has reached the preset effective duration and has not received an attribute change request for the transaction identifier, update the key pair of the smart contract; update the object attribute private key based on the private key in the updated key pair and the authorized set of object attributes to obtain an updated object attribute private key.

[0351] 28) Update the encrypted ciphertext based on the public key in the updated key pair and the authorized set of object attributes to obtain an updated encrypted ciphertext.

[0352] 29) The blockchain node obtains an encryption key, encrypts the updated object attribute private key using the encryption key to obtain an encrypted object attribute private key.

[0353] 30) The blockchain node invokes a first preset channel and transfers the encrypted object attribute private key to the authorized user through the first preset channel.

[0354] 31) The blockchain node obtains decryption key generation information corresponding to the encryption key, invokes a second preset channel, and transfers the decryption key generation information to the authorized user through the second preset channel.

[0355] 32) The authorized user receives the decryption key generation information through the second preset channel and generates a decryption key based on the decryption key generation information.

[0356] 33) The authorized user receives the encrypted object attribute private key through the first preset channel, decrypts the encrypted object attribute private key using the decryption key to obtain the object attribute private key, and stores the object attribute private key locally.

[0357] In this embodiment, the object attributes of multiple users are obtained respectively, and the object attributes of multiple users are verified respectively to verify the authenticity of the users' attributes and be able to filter out false data. When the verification passes, a key pair for the smart contract is generated based on the object attributes of multiple users respectively, so that the public key and the private key in the key pair can incorporate the attribute information of the users, enabling the subsequent combination of data encryption and decryption with the users' attributes.

[0358] According to the object attributes of multiple users respectively, the authorized user set and the authorized object attribute set are configured for each transaction identifier of the smart contract, and each transaction identifier can be configured with its own authorized users. The authorized object attribute set includes the object attributes of each authorized user in the authorized user set, and based on the public key in the key pair and the object attribute set of each transaction identifier, the transaction information of each transaction identifier is encrypted to obtain the encrypted ciphertext of each transaction identifier, and the encryption of the transaction information can be realized based on the attributes. According to the private key in the key pair and the object attributes of each authorized user in the object attribute set, the object attribute private key of each authorized user is generated, so that subsequently, through the encrypted ciphertext and the object attribute private key, it can be effectively verified whether the user requesting access to the transaction information is the authorized user of the transaction information.

[0359] The object attribute private key is encrypted using the encryption key to obtain the encrypted object attribute private key, and the respective encrypted object attribute private keys are sent to each authorized user through the first preset channel. The decryption key generation information corresponding to the encryption key is obtained, and the decryption key generation information is sent to each authorized user through the second preset channel. Different channels are used to transmit the object attribute private key and the decryption information of the attribute private key, making the transmission of the key more secure. Moreover, the transmitted attribute private key is the encrypted object attribute private key, so that the user can use the received decryption key generation information to generate the decryption key, and then use the decryption key to decrypt the encrypted object attribute private key to obtain the object attribute private key, which can further improve the security of the transmission of the object attribute private key.

[0360] Receive the transaction encryption access request for the smart contract initiated by the request initiator. The initiated transaction encryption access request is encrypted using the public key in the key pair, making the received request information not easily leaked. Use the private key in the key pair to decrypt the transaction encryption access request to obtain the transaction identifier of the transaction identifier that the user needs to call, and the object attribute private key for verifying the identity of the request initiator. This object attribute private key is generated based on the private key and the object attributes of the request initiator, so the object attribute private key can be used to verify whether the user is the authorized user of the transaction information corresponding to the transaction identifier. Based on the smart contract, determine the encrypted ciphertext corresponding to the transaction identifier, and judge whether the user has the permission to access the transaction information according to whether the object attribute private key can decrypt the encrypted ciphertext. When the decryption is successful, it means that the request initiator is the authorized user of the transaction identifier and has the permission to view the transaction information and execute the transaction, then the request initiator is allowed to view the transaction information, thus improving the security of viewing the transaction information and the legality of transaction execution. Moreover, by setting respective encrypted ciphertexts for different transaction information, respective authorized users can be set for different transaction information, and fine-grained control of viewing the transaction information and executing the transaction can be realized.

[0361] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise clearly stated in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.

[0362] Based on the same inventive concept, an embodiment of the present application also provides a transaction processing device for implementing the above-mentioned transaction processing method. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the following transaction processing device can refer to the limitations on the transaction processing method in the above text, and will not be repeated here.

[0363] In one embodiment, as Figure 14 shown, a transaction processing device 1400 is provided, including: a receiving module 1402, a request decryption module 1404, a determination module 1406, and a ciphertext decryption module 1408, where:

[0364] The receiving module 1402 is configured to receive a transaction encryption access request for a smart contract initiated by a request initiator, and the transaction encryption access request is encrypted using the public key in the key pair of the smart contract.

[0365] The request decryption module 1404 is configured to decrypt the transaction encryption access request using the private key in the key pair to obtain a transaction identifier and an object attribute private key, and the object attribute private key is generated based on the private key and the object attribute of the request initiator.

[0366] The determination module 1406 is configured to determine, based on the smart contract, the encrypted ciphertext corresponding to the transaction identifier, and the encrypted ciphertext is obtained by encrypting the transaction information corresponding to the transaction identifier using the public key and the object attributes in the authorized object attribute set.

[0367] The ciphertext decryption module 1408 is configured to decrypt the encrypted ciphertext based on the object attribute private key. When the decryption is successful, it indicates that the authentication is passed, and the transaction information corresponding to the transaction identifier is obtained.

[0368] In this embodiment, a transaction encryption access request for a smart contract initiated by a request initiator is received. The initiated transaction encryption access request is encrypted with the public key in the key pair, so that the received request information is not easily leaked. The private key in the key pair is used to decrypt the transaction encryption access request to obtain the transaction identifier of the transaction information that the user wants to access, and the object attribute private key for verifying the identity of the request initiator. The object attribute private key is generated based on the private key and the object attributes of the request initiator to verify whether the user is an authorized user of the transaction information through the object attribute private key. Based on the smart contract, the encrypted ciphertext corresponding to the transaction identifier is determined, and it is judged whether the user has the permission to call the transaction information according to whether the object attribute private key can decrypt the encrypted ciphertext. The encrypted ciphertext is obtained by encrypting the transaction information corresponding to the transaction identifier based on the public key and the object attributes in the authorized object attribute set, indicating that an authorized object attribute set has been set in advance for the transaction information. The authorized object attribute set includes the object attributes of the authorized users, and it can be judged whether the object attributes of the request initiator are the attributes in the authorized object attribute set of the transaction information. Moreover, the transaction information is encrypted based on the public key and the object attributes to obtain the encrypted ciphertext, so that the transaction information of the user on the blockchain is not exposed, improving the security of the transaction information. When the decryption is successful, it indicates that the request initiator is an authorized user of the transaction information and has the permission to call the transaction information, and then the transaction information indicated by the transaction identifier in the smart contract is called, thereby improving the security of calling the transaction information. Moreover, respective encrypted ciphertexts are set for different transaction information, and respective authorized object attribute sets can be set for different transaction information to set respective authorized users, which can improve the fine-grained control of accessing the transaction information, thereby improving the security of accessing the transaction information.

[0369] In one of the embodiments, the request decryption module 1404 is further configured to use the private key in the key pair to decrypt the transaction encryption access request to obtain the transaction identifier, the object attribute private key, and the request time of the transaction identifier.

[0370] The ciphertext decryption module 1408 is further configured to determine the reception time when the transaction encryption access request is received, and determine the preset effective duration of the encrypted ciphertext corresponding to the transaction identifier; when the request time is within the preset effective duration and the reception time is within the preset effective duration, decrypt the encrypted ciphertext based on the object attribute private key.

[0371] In this embodiment, the private key in the key pair is used to decrypt the transaction encrypted access request to obtain the transaction identifier, the object attribute private key, and the request time of the transaction identifier, determine the reception time when the transaction encrypted access request is received, and determine the preset valid duration of the encrypted ciphertext corresponding to the transaction identifier, so that based on whether both the request time and the reception time are within the valid period of the encrypted ciphertext, when both times are within the valid period, the decryption process of the encrypted ciphertext is executed, which can ensure that the valid period of the object attribute private key is consistent with the valid period of the ciphertext.

[0372] In one embodiment, the device further includes a key generation module; the key generation module is used to obtain the respective object attributes of multiple users, and verify the respective object attributes of the multiple users; when the verification passes, a key pair for the smart contract is generated based on the respective object attributes of the multiple users.

[0373] In this embodiment, the respective object attributes of multiple users are obtained, and the respective object attributes of the multiple users are verified to verify the authenticity of the user attributes and be able to filter out false data. When the verification passes, a key pair for the smart contract is generated based on the respective object attributes of the multiple users, so that the public key and the private key in the key pair can incorporate the user attribute information, enabling the subsequent encryption and decryption of data to be combined with the user attributes.

[0374] In one embodiment, the ciphertext decryption module 1408 is further used to decrypt the encrypted ciphertext based on the object attribute private key. When the decryption is successful, the authorized user set corresponding to the transaction identifier is obtained; when the request initiator belongs to the authorized users in the authorized user set, it indicates that the identity verification is passed, and the transaction information corresponding to the transaction identifier is obtained.

[0375] In this embodiment, when decrypting the encrypted ciphertext based on the object attribute private key, when the decryption is successful, the transaction information corresponding to the transaction identifier is not directly obtained, but the authorized user set corresponding to the transaction identifier is obtained, so that the identity of the request initiator can be further verified based on the user identifier of the request initiator, realizing double verification of attributes and user identifiers. When the request initiator belongs to the authorized users in the authorized user set, it indicates that the identity verification is passed, and then the transaction information corresponding to the transaction identifier is obtained, which can effectively prevent other users from stealing the object attribute private key of authorized users to access transaction information, further improving the privacy of the transaction information deployed on the blockchain.

[0376] In one embodiment, the ciphertext decryption module 1408 is further used to determine the current ciphertext state of the encrypted ciphertext, and the ciphertext state includes a valid state and an update state; when the ciphertext state indicates that the encrypted ciphertext is in the valid state, the encrypted ciphertext is decrypted based on the object attribute private key.

[0377] In this embodiment, the ciphertext status corresponding to the encrypted ciphertext of the transaction identifier is preset to indicate whether the encrypted ciphertext is currently in a valid state, an invalid state, or an updated state. Only when the encrypted ciphertext is valid can the encrypted ciphertext be decrypted and called, making the call to the transaction identifier more rigorous and secure.

[0378] Moreover, the ciphertext status of the encrypted ciphertext can also characterize the status of the object attribute private key of the authorized user. When the encrypted ciphertext is in the updated state, it indicates that the object attribute private key is also in the updated state. When the encrypted ciphertext is in the invalid state, it indicates that the object attribute private key is currently invalid. When the encrypted ciphertext is in the valid state, it indicates that the object attribute private key is currently valid.

[0379] In one embodiment, the ciphertext decryption module 1408 is further configured to, when the ciphertext status indicates that the encrypted ciphertext is in the updated state, determine the backup ciphertext corresponding to the encrypted ciphertext; and decrypt the backup ciphertext based on the object attribute private key.

[0380] In this embodiment, when the ciphertext status indicates that the encrypted ciphertext is in the updated state, determine the backup ciphertext corresponding to the encrypted ciphertext, and decrypt the backup ciphertext based on the object attribute private key, so that when the encrypted ciphertext is in the updated state, the user request can still be responded to, effectively avoiding the impact on the user caused by the policy update and improving the user experience.

[0381] In one embodiment, the device further includes a ciphertext update module; the ciphertext update module is configured to determine the preset valid duration of the encrypted ciphertext and determine the elapsed duration of the encrypted ciphertext;

[0382] When the elapsed duration reaches the preset valid duration, generate a backup ciphertext of the encrypted ciphertext; and adjust the current ciphertext status of the encrypted ciphertext from the valid state to the updated state.

[0383] In this embodiment, determine the preset valid duration of the encrypted ciphertext and determine the elapsed duration of the encrypted ciphertext. When the elapsed duration reaches the preset valid duration, generate a backup ciphertext of the encrypted ciphertext, so that during the process of updating the encrypted ciphertext of the transaction identifier, the call request of the user for the transaction identifier can be responded to through the backup ciphertext. Adjust the current ciphertext status of the encrypted ciphertext from the valid state to the updated state to prompt the current state of the encrypted ciphertext to determine whether to use the backup ciphertext to respond to the user request.

[0384] In one embodiment, the ciphertext decryption module 1408 is further configured to determine the transaction type corresponding to the transaction identifier, determine the execution node that matches the transaction type; and allocate the transaction identifier and the object attribute private key to the execution node to instruct the execution node to decrypt the encrypted ciphertext based on the object attribute private key.

[0385] In this embodiment, the transaction type corresponding to the transaction identifier is determined, and the execution node matching the transaction type is determined, so that requests for accessing transaction information of different transaction types can be assigned to specific execution nodes for processing, which can improve the response speed to user requests.

[0386] In one embodiment, the ciphertext update module is configured to determine the preset valid duration and the elapsed duration of the encrypted ciphertext corresponding to the transaction identifier; when the elapsed duration reaches the preset valid duration and a request for attribute change for the transaction identifier is received, update the authorized object attribute set based on the target attribute in the attribute change request; update the encrypted ciphertext based on the public key and the updated object attribute set to obtain an updated encrypted ciphertext; and generate an updated object attribute private key based on the private key and the target attribute.

[0387] In this embodiment, the function of customizing object attributes is provided to the user. When an authorized user requests to change their own object attributes, the blockchain node will update the object attribute set and each encrypted ciphertext related to the object attributes of the authorized user, so as to update the encrypted ciphertext based on the user's customization or update of the attributes. Moreover, based on the private key in the key pair and the target attributes of the authorized user, the update of the object attribute private key of the authorized user is realized, so that the function of updating the object attribute private key can be provided to the user, enabling the user to update the object attributes and the object attribute private keys according to their own needs.

[0388] In one embodiment, the ciphertext update module is further configured to update the key pair of the smart contract when the elapsed duration reaches the preset valid duration and a request for attribute change for the transaction identifier is not received; update the encrypted ciphertext based on the public key in the updated key pair and the authorized object attribute set to obtain an updated encrypted ciphertext; and update the object attribute private key based on the private key in the updated key pair and the authorized object attribute set to obtain an updated object attribute private key.

[0389] In this embodiment, when the elapsed duration reaches the preset valid duration and a request for attribute change for the transaction identifier is not received, the key pair of the smart contract is updated, so that in the case where the ciphertext and the attribute private key need to be updated, it can be determined whether to update the key pair or the object attributes first based on whether the user requests to change the object attributes. In the case where there is no user request to change the attributes, the key pair is automatically updated, and then the encrypted ciphertext and the object attribute private key are updated based on the updated key pair, which can ensure the validity of the object attribute private key and the encrypted ciphertext.

[0390] In one embodiment, the set of authorized object attributes includes the object attributes of each authorized user with a transaction identifier, and the device further includes an attribute private key sending module; the attribute private key sending module is configured to encrypt the updated object attribute private key using an encryption key to obtain an encrypted object attribute private key; send each encrypted object attribute private key to each authorized user through a first preset channel; obtain decryption key generation information corresponding to the encryption key, and send the decryption key generation information to each authorized user through a second preset channel, where the decryption key generation information is used to generate a decryption key, and the decryption key is used to decrypt the encrypted object attribute private key to obtain the updated object attribute private key.

[0391] In this embodiment, the object attribute private key is encrypted using an encryption key to obtain an encrypted object attribute private key. Each encrypted object attribute private key is sent to each authorized user through a first preset channel. The decryption key generation information corresponding to the encryption key is obtained, and the decryption key generation information is sent to each authorized user through a second preset channel. Using different channels to transmit the object attribute private key and the decryption information for the attribute private key makes the transmission of the key more secure. Moreover, the transmitted attribute private key is the encrypted object attribute private key, enabling the user to generate a decryption key based on the received decryption key generation information, and then use the decryption key to decrypt the encrypted object attribute private key to obtain the updated object attribute private key, which can further improve the security of the transmission of the attribute private key.

[0392] In one embodiment, the device further includes:

[0393] A transaction processing module, configured to determine a contract interface corresponding to the transaction identifier; perform transaction processing according to the transaction information through the contract interface to obtain a transaction result.

[0394] In this embodiment, the transaction processing module is further configured to determine the transaction type corresponding to the transaction identifier, and determine the contract interface corresponding to the transaction type; call the contract interface, and perform transaction processing according to the transaction information through the contract interface to obtain a transaction result.

[0395] Each module in the above transaction processing device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the computer device in hardware form or be independent of it, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above respective modules.

[0396] In one embodiment, a computer device is provided. The computer device can be a terminal or a server. Taking the terminal as an example, its internal structure diagram can be as Figure 15As shown in the figure. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit, and an input device. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface, the display unit, and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, NFC (Near Field Communication), or other technologies. The computer program, when executed by the processor, implements a transaction processing method. The display unit of the computer device is used to form a visually visible picture, which can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the housing of the computer device, or an external keyboard, touchpad, or mouse, etc.

[0397] Those skilled in the art can understand that Figure 15 the structure shown in the figure is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0398] In one embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.

[0399] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.

[0400] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.

[0401] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data that have been authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.

[0402] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the various embodiments provided in this application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the various embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., and are not limited thereto. The processors involved in the various embodiments provided in this application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., and are not limited thereto.

[0403] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the various technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope described in this specification.

[0404] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.

Claims

1. A transaction processing method, characterized in that, The method includes: Receiving a transaction encryption access request for a smart contract initiated by a request initiator, where the transaction encryption access request is encrypted using the public key in the key pair of the smart contract; Using the private key in the key pair to decrypt the transaction encryption access request to obtain a transaction identifier and an object attribute private key, where the object attribute private key is generated based on the private key and the object attribute of the request initiator; Based on the smart contract, determining the encrypted ciphertext corresponding to the transaction identifier, where the encrypted ciphertext is obtained by encrypting the transaction information corresponding to the transaction identifier based on the public key and the object attributes in the authorized object attribute set; Decrypting the encrypted ciphertext based on the object attribute private key. When the decryption is successful, it indicates passing the authentication, and obtaining the transaction information corresponding to the transaction identifier.

2. The method according to claim 1, characterized in that, The step of using the private key in the key pair to decrypt the transaction encryption access request to obtain a transaction identifier and an object attribute private key includes: Using the private key in the key pair to decrypt the transaction encryption access request to obtain a transaction identifier, an object attribute private key, and the request time of the transaction identifier; The step of decrypting the encrypted ciphertext based on the object attribute private key includes: Determining the reception time when the transaction encryption access request is received, and determining the preset valid duration of the encrypted ciphertext corresponding to the transaction identifier; When the request time is within the preset valid duration and the reception time is within the preset valid duration, decrypting the encrypted ciphertext based on the object attribute private key.

3. The method according to claim 1, characterized in that, The method further includes: Obtaining the object attributes of multiple users respectively, and verifying the object attributes of the multiple users respectively; When the verification is passed, generating a key pair for the smart contract based on the object attributes of the multiple users respectively.

4. The method according to claim 1, characterized in that, The step of decrypting the encrypted ciphertext based on the object attribute private key. When the decryption is successful, it indicates passing the authentication, and obtaining the transaction information corresponding to the transaction identifier includes: Decrypting the encrypted ciphertext based on the object attribute private key. When the decryption is successful, obtaining the authorized user set corresponding to the transaction identifier; When the request initiator belongs to the authorized users in the authorized user set, it indicates passing the authentication, and obtaining the transaction information corresponding to the transaction identifier.

5. The method according to claim 4, characterized in that, The step of decrypting the encrypted ciphertext based on the object attribute private key includes: Determining the current ciphertext state of the encrypted ciphertext, where the ciphertext state includes a valid state and an update state; When the ciphertext state indicates that the encrypted ciphertext is in the valid state, decrypting the encrypted ciphertext based on the object attribute private key.

6. The method according to claim 5, characterized in that, The method further includes: When the ciphertext state indicates that the encrypted ciphertext is in the update state, determining the backup ciphertext corresponding to the encrypted ciphertext; Decrypting the backup ciphertext based on the object attribute private key.

7. The method according to claim 1, characterized in that, The step of decrypting the encrypted ciphertext based on the object attribute private key includes: Determining the transaction type corresponding to the transaction identifier, and determining the execution node matching the transaction type; Distribute the transaction identifier and the object attribute private key to the execution node to instruct the execution node to decrypt the encrypted ciphertext based on the object attribute private key.

8. The method according to claim 1, characterized in that, The method further includes: Determine the preset valid duration and the elapsed duration of the encrypted ciphertext corresponding to the transaction identifier; When the elapsed duration reaches the preset valid duration and a property change request for the transaction identifier is received, update the authorized object attribute set based on the target attribute in the property change request; Update the encrypted ciphertext based on the public key and the updated object attribute set to obtain an updated encrypted ciphertext; Generate an updated object attribute private key based on the private key and the target attribute.

9. The method according to claim 8, characterized in that, The method further includes: When the elapsed duration reaches the preset valid duration and no property change request for the transaction identifier is received, update the key pair of the smart contract; Update the encrypted ciphertext based on the public key in the updated key pair and the authorized object attribute set to obtain an updated encrypted ciphertext; Update the object attribute private key based on the private key in the updated key pair and the authorized object attribute set to obtain an updated object attribute private key.

10. The method according to claim 8, characterized in that, The authorized object attribute set includes the object attributes of each authorized user of the transaction identifier, and the method further includes: Encrypt the updated object attribute private key with an encryption key to obtain an encrypted object attribute private key; Send each encrypted object attribute private key to each of the authorized users through a first preset channel; Obtain decryption key generation information corresponding to the encryption key, and send the decryption key generation information to each of the authorized users through a second preset channel. The decryption key generation information is used to generate a decryption key, and the decryption key is used to decrypt the encrypted object attribute private key to obtain the updated object attribute private key.

11. The method according to any one of claims 1 to 10, characterized in that, The method further includes: Determine the transaction type corresponding to the transaction identifier and determine the contract interface corresponding to the transaction type; Invoke the contract interface and perform transaction processing according to the transaction information through the contract interface to obtain a transaction result.

12. A transaction processing device, characterized in that, The device includes: A receiving module, configured to receive a transaction encryption access request for a smart contract initiated by a request initiator, where the transaction encryption access request is encrypted with the public key in the key pair of the smart contract; A request decryption module, configured to decrypt the transaction encryption access request with the private key in the key pair to obtain a transaction identifier and an object attribute private key, where the object attribute private key is generated based on the private key and the object attribute of the request initiator; A determination module, configured to determine, based on the smart contract, an encrypted ciphertext corresponding to the transaction identifier, where the encrypted ciphertext is obtained by encrypting the transaction information corresponding to the transaction identifier based on the public key and the object attributes in the authorized object attribute set; A ciphertext decryption module, configured to decrypt the encrypted ciphertext based on the object attribute private key. When the decryption is successful, it indicates that the authentication is passed, and the transaction information corresponding to the transaction identifier is obtained.

13. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method described in any one of claims 1 to 11.

14. A computer-readable storage medium, on which a computer program is stored, characterized in that, When the computer program is executed by a processor, it implements the steps of the method described in any one of claims 1 to 11.

15. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method described in any one of claims 1 to 11.