Method and device for generating encryption key and encrypted data communication method

By generating multiple derived private key metadata and chain code coefficients in the key derivation scheme and performing group operation, generating sub-private keys that are difficult to deduce the global key, the risk of calculating the global key after the enemy masters the child private key and the parent public key is solved, and higher key derivation security and the maintenance of the "main public key attributes" are achieved.

CN120185799APending Publication Date: 2025-06-20GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311749029.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-18
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

In the existing key derivation scheme, after the enemy masters the child private key and the parent public key, the global key can be easily calculated, resulting in the overall picture of the key derivation being corrupted.

Method used

The root private key and index code j generate multiple derived private key metadata and chain code coefficients, and the elements of the derived private key tuple and the chain code coefficient are grouped using preset rules to generate sub-private keys. This sub-private key is obtained by combining elements of multiple derived private key tuples and chain code coefficients, making it difficult to deduce the global key.

Benefits of technology

It effectively avoids the vulnerability of the opponent to deduce the parent private key when obtaining the child private key and derived information, enhances the security of key derivation, ensures the "master public key attribute", and improves communication security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120185799A_ABST
    Figure CN120185799A_ABST
Patent Text Reader

Abstract

The invention provides a method and a device for generating an encryption key and an encrypted data communication method. The method for generating the encryption key is executed by a first node, and comprises the following steps: generating derived private key metadata and chain code metadata corresponding to an index code j on the basis of applying a one-way function to connection data formed by a root private key and the index code j, the derived private key metadata being elements forming a derived private key tuple, and the chain code metadata being elements forming a chain code tuple; the chain code data are elements forming a chain code tuple, and the index code j is a round of generating an encryption key; a chain code coefficient corresponding to the index code j is generated based on the connection data of applying a one-way function to the chain code element group and the index code j, and the chain code coefficient corresponding to the index code j is an element forming the weight group; performing pairing operation on all elements of the derived private key tuple and all elements of the weight group according to a preset rule to generate a sub-private key corresponding to the index code j; and generating a first sub-public key based on the sub-private key and the base point P of the elliptic curve.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the technical field of data processing, and more specifically, to a method and device for generating encryption keys and a method for encrypted data communication. Background Art

[0002] Most of the existing key derivation schemes are based on the Bitcoin Improvement Proposal BIP-32. BIP-32 is a standard for hierarchical deterministic wallets that allows users to generate multiple child private keys and child public keys from a single seed without the need to back up a new private key each time. However, the BIP-32 protocol has the risk problem that an adversary can learn the global key derivation due to the possession of the child private key. Summary of the Invention

[0003] The embodiments of the present application provide a method and device for generating encryption keys and a method for encrypted data communication. The following introduces each aspect related to the embodiments of the present application.

[0004] In a first aspect, a method for generating an encryption key is provided. The method is executed by a first node and includes: generating derived private key metadata and chain code metadata corresponding to an index code j based on concatenated data formed by applying a one-way function to a root private key and the index code j, where the derived private key metadata is an element constituting a derived private key tuple, the number of elements in the derived private key tuple is u, u is a positive integer greater than 1, j is less than or equal to u, the chain code data is an element constituting a chain code tuple, the number of elements in the chain code tuple is u, the index code j is the round for generating the encryption key, and the root private key is data obtained by applying the one-way function to a seed; generating a chain code coefficient corresponding to the index code j based on concatenated data formed by applying the one-way function to the chain code tuple and the index code j, where the chain code coefficient corresponding to the index code j is an element constituting a weight group; performing a pairing operation on all elements of the derived private key tuple and all elements of the weight group according to a preset rule to generate a child private key corresponding to the index code j; generating a first child public key based on the child private key and a base point P of an elliptic curve, where the child private key and the first child public key are used to form an asymmetric public key-private key pair of the encryption key corresponding to the first node.

[0005] Second aspect, a device for generating an encryption key is provided, which is applied to a first node. The device includes: a first generation module, configured to generate derived private key metadata and chain code metadata corresponding to the index code j based on applying a one-way function to connection data composed of a root private key and the index code j. The derived private key metadata is an element constituting a derived private key tuple, the number of elements in the derived private key tuple is u, u is a positive integer greater than 1, j is less than or equal to u, the chain code metadata is an element constituting a chain code tuple, the number of elements in the chain code tuple is u, the index code is the round for generating the encryption key, and the root private key is based on applying the one-way function to seed data; a second generation module, configured to generate a chain code coefficient corresponding to the index code j based on applying the one-way function to connection data of the chain code tuple and the index code j. The chain code coefficient corresponding to the index code j is an element constituting a weight group; a private key generation module, configured to perform a pairing operation on all elements of the derived private key tuple and all elements of the weight group according to a preset rule to generate a sub-private key of the index code j; a public key generation module, configured to generate a first sub-public key based on the sub-private key and a base point P of an elliptic curve. The sub-private key and the first sub-public key are used to form an asymmetric public key-private key pair of the encryption key corresponding to the first node.

[0006] Third aspect, a method for encrypted data communication is provided, including: the first node determines the encryption key based on the method for generating an encryption key as described in the first aspect; encrypts the data to be sent based on the encryption key to generate encrypted data; and the first node sends the encrypted data to a second node in the blockchain.

[0007] Fourth aspect, a method for digital signature is provided. The first node generates a sub-private key and a first sub-public key based on the method as described in the first aspect; signs a first message based on the sub-private key to generate a first signature message; and sends the first signature message to a second node. The first signature message is suitable for verification using the first sub-public key to authenticate the first node.

[0008] Fifth aspect, an electronic device is provided, including: a memory for storing code; a processor for executing the code stored in the memory to execute the method as described in the first aspect, the third aspect, or the fourth aspect.

[0009] Sixth aspect, a computer-readable storage medium is provided, on which a computer program is stored. The computer program is used to execute the method as described in the first aspect, the third aspect, or the fourth aspect.

[0010] Seventh aspect, a computer program product is provided, including instructions for executing the method as described in the first aspect, the third aspect, or the fourth aspect.

[0011] In the embodiments of the present application, multiple derived private key metadata and corresponding multiple chain code coefficients are generated through the root private key and the index code j. All elements of the derived private key tuple are paired and combined with all the chain code coefficients to generate a sub-private key corresponding to the index code j. Since the sub-private key is obtained by combining the elements of multiple derived private key tuples with the chain code coefficients, it is impossible to solve the parent private key when the number of known sub-private keys is less than u. Even if the adversary obtains the sub-private key and the derivation information of a certain round, the global key cannot be obtained. In fact, the adversary only obtains a permutation and combination of the sub-private keys in the derived private key tuple and cannot obtain the whole picture of key derivation. The embodiments of the present application help to avoid the vulnerability problem that the adversary can obtain the parent private key if the adversary knows the sub-private key, the parent public key, and the relevant derivation information during key derivation. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] Figure 1 is a schematic diagram of a blockchain.

[0013] Figure 2 is a schematic flowchart of the method for generating an encryption key provided by the embodiments of the present application.

[0014] Figure 3 is Figure 2 a schematic diagram of a possible implementation manner of the method.

[0015] Figure 4 is a schematic flowchart of the method for encrypted data communication provided by the embodiments of the present application.

[0016] Figure 5 is a schematic flowchart of a method for digital signature provided by the embodiments of the present application.

[0017] Figure 6 is a schematic structural diagram of the device for generating an encryption key provided by the embodiments of the present application.

[0018] Figure 7 is a schematic diagram of the composition unit / partial composition unit of the electronic device provided by the embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0019] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments.

[0020] For ease of understanding, some relevant technical knowledge related to the embodiments of the present disclosure will be introduced first. The following relevant technologies can be arbitrarily combined with the technical solutions of the embodiments of the present disclosure as optional solutions, and they all fall within the protection scope of the embodiments of the present disclosure. The embodiments of the present disclosure include at least part of the following contents.

[0021] Mobile Crowdsensing

[0022] In recent years, with the development of the Internet of Things and the mobile Internet, mobile crowdsensing has received extensive attention. Mobile crowdsensing refers to a new data acquisition mode that combines the idea of crowdsourcing and the sensing capabilities of mobile devices. In addition, smartphones, tablets, and wearable devices have been widely deployed and are already equipped with a rich set of sensors, making them excellent sources of information. Different from the sensing method based on traditional sensor networks, mobile crowdsensing uses the wide distribution, flexible mobility, and opportunistic connectivity of the public for large-scale sensing, and integrates implicit or explicit group intelligence to achieve the optimization and enhanced understanding of sensing data, thereby providing intelligent auxiliary support for urban and social management. Mobile crowdsensing can be applied in many important fields, such as public safety, urban management, environmental monitoring, social governance, etc.

[0023] Blockchain

[0024] In essence, blockchain technology is a decentralized distributed database. Specifically, it is also a distributed ledger technology with key features such as decentralization, persistence, anonymity, and audibility. From a technical perspective, blockchain technology is the product of the development of disciplines such as computer science and digital economy, represented by cryptography, P2P networks, database technology, and electronic currency, to a certain stage.

[0025] See Figure 1 , blockchain 100 is a typical distributed collaborative system. The system includes multiple blockchain nodes 110. The multiple blockchain nodes 110 can jointly maintain a growing distributed data record. The data of these records can protect the content and timing through cryptographic technology, making it difficult for any party to tamper with, deny, or forge. The blockchain node 110 can be a device with computing capabilities, such as a laptop, desktop computer, server, server group, blockchain chip, etc. Among them, the server group can be centralized or distributed. In some other implementation manners, the above-mentioned server can also be a server that provides services for the cloud platform.

[0026] Cryptography involves techniques for secure communication between two or more nodes. The nodes can be associated with natural persons, a group of people such as company employees, a banking system, etc. In some cases, two or more nodes can be connected by an insecure communication network. For example, two nodes can be connected by a communication network where a third party may be able to eavesdrop on the communication between the nodes. Therefore, the messages sent between the nodes are sent in encrypted form, and when the message is received in such a case, the intended recipient can decrypt the message with the corresponding decryption key (or other decryption method). Therefore, the security of such communication can depend on whether a third party can be prevented from determining the corresponding decryption key.

[0027] Cryptographic methods include symmetric key algorithms and asymmetric encryption algorithms. In symmetric key algorithms, the key is symmetric, which means that the same symmetric key is used for both the encryption of the plaintext message and the decryption of the ciphertext.

[0028] Asymmetric encryption algorithm is a method for keeping keys secret. Asymmetric encryption algorithms require two keys: a public key and a private key. The public key is abbreviated as the "public key", and the private key is abbreviated as the "private key". The public key and the private key are a pair. If data is encrypted with the public key, only the corresponding private key can be used to decrypt it. Since different keys are used for encryption and decryption, this algorithm is called an asymmetric encryption algorithm. The basic process of implementing confidential information exchange using an asymmetric encryption algorithm is as follows: Party A generates a pair of keys and makes the public key public. Other parties (such as Party B) who need to send information to Party A use this key (Party A's public key) to encrypt the confidential information and then send it to Party A; Party A then decrypts the encrypted information with its own private key. When Party A wants to reply to Party B, it is the opposite. Party A uses Party B's public key to encrypt the data. Similarly, Party B uses its own private key to decrypt it.

[0029] In the traditional identity authentication scenario of mobile crowdsensing, the keys used by each participating party for identity authentication and encryption are independently generated through random numbers, and the keys have no relation to each other. The disadvantage of this method is that if each participating party generates a large number of keys, it is difficult to meet the requirements for key backup and migration using this method. Later, as the blockchain application Bitcoin became more and more well-known to the public, Bitcoin Improvement Proposals (BIPs), such as the BIP-32 protocol, attracted wide attention.

[0030] Key Derivation

[0031] Modern cryptographic systems require that encryption algorithms can be publicly evaluated. The security of the entire cryptographic system does not depend on the secrecy of the cryptographic algorithm or the protection of encryption devices, etc. The factor determining the security of the entire cryptographic system will be the secrecy of the key. The cryptographic algorithm can be made public, and the cryptographic device can be lost, but neither of them endangers the security of the cryptographic system. However, once the key is lost, unauthorized users may be able to steal information. Therefore, in Bitcoin improvement protocols (such as BIP-32), it is proposed that all private keys are derived from a master private key, and all the derived private keys are interrelated.

[0032] BIP-32 is a standard for hierarchical deterministic (HD) wallets. BIP-32 allows users to generate multiple child private keys and child public keys from a single seed, without the need to back up a new private key each time.

[0033] Existing key derivation schemes are basically based on the BIP-32 protocol. In the BIP-32 protocol, the core algorithms involved in key derivation are as follows:

[0034]

[0035] sk j = sk j―1 + h L (mod q)

[0036] PK j = PK j―1 + h L ·P (mod q)

[0037] Where sk j is the child private key, sk j―1 is the parent private key, PK j is the child public key, PK j―1 is the parent public key, chain j―1 is the derivation information. h L and h R are the left and right sequences respectively, P is the base point of the elliptic curve, and q is the order of the base point P. ∥ is the concatenation operator (or juxtaposition), and concatenation is the operation of appending one byte sequence to another byte sequence. mod is the modulo function, is the hash function.

[0038] The hash function is a publicly available one-way function that maps an arbitrarily long message to a shorter, fixed-length value, also known as a hash function or a digest function. The function value obtained by the mapping is called the hash value, digest value, or message digest. Commonly used hash functions include MD5, SHA1, SHA2, and SHA3.

[0039] There is a problem in the algorithm described above. Suppose the adversary obtains the child private key sk j 、Parent public key PK j―1 And derived information chain j―1 . By the parent public key PK j―1 and derived information chain j―1 , the adversary can easily calculate h L , and then the adversary can calculate sk j ―h L (mod q) = sk j―1 , get the parent private key sk j―1 , and so on, the adversary can easily obtain the global key derivation and then obtain the global private key. If the adversary obtains the global private key, then in the identity authentication process in the mobile group sensing scenario, the adversary can use the private key to impersonate the legitimate participant and carry out malicious behavior.

[0040] Although BIP-32 also proposes the use of "hardened" derivation, "hardened" derivation uses the parent private key to derive the child chain code instead of the parent public key, which can destroy the connection between the parent public key and the child chain code. However, using this method increases the coupling degree between private key derivation and public key derivation, which means that the key derivation loses the "master public key attribute". The so-called "master public key attribute" means that users can create and publish master public keys (or root public keys), and any node can calculate child public keys through the public master public key; the child public key corresponding to the child private key is derived from the parent private key, but knowing only the master public key is not enough to recover any private key.

[0041] It can be seen that there is a problem in the BIP-32 protocol that if the adversary obtains the sub-private key, the global key derivation can be obtained.

[0042] Therefore, how to develop a technical solution that cannot derive a global key from a sub-private key is a problem that needs to be solved.

[0043] Based on this, an embodiment of the present application proposes a method for generating an encryption key. Figure 2 1 is a flow chart of a method for generating an encryption key proposed in an embodiment of the application. Figure 2 The method for generating an encryption key in an embodiment of the present application is introduced in detail. Figure 2 The method is performed by a first node to determine an encryption key, and the first node may be any of a plurality of nodes in a blockchain. The plurality of nodes may include a tablet computer, a laptop computer, a desktop computer, a mobile communication device, other forms of computing devices and communication devices, a server device in a network, a client device in a network, one or more nodes in a distributed network, etc. A node may be referred to as a participant or a participant, and the first node may be referred to as a first participant.

[0044] As Figure 2 shown, the method for generating an encryption key mainly may include steps S210 to S240, and the following provides a detailed description of these steps.

[0045] It should be noted that the magnitudes of the sequence numbers of the steps in the embodiments of the present application do not indicate the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not impose any limitation on the implementation process of the embodiments of the present application.

[0046] In step S210, based on applying a one-way function to the concatenated data composed of a root private key and an index code j, derived private key metadata and chain code metadata corresponding to the index code j are generated.

[0047] Among them, the derived private key metadata is an element constituting a derived private key tuple. The number of elements in the derived private key tuple is u, where u is a positive integer greater than 1, and j is less than or equal to u. The chain code metadata is an element constituting a chain code tuple. The number of elements in the chain code tuple is u, and the chain code is also referred to as derived information. The index code j is the round for generating the encryption key. For example, a participant performs the j-th round of generating the encryption key. The root private key is data obtained by applying a one-way function to a seed, and the root private key is also referred to as the master private key.

[0048] That is, multiple pieces of derived private key metadata sequentially form a derived private key tuple according to the index code j (or round). The chain code metadata sequentially forms a chain code tuple according to the index code j.

[0049] In step S220, based on applying a one-way function to the concatenated data of the chain code tuple and the index code j, a chain code coefficient corresponding to the index code j is generated. The chain code coefficient corresponding to the index code j is an element constituting a weight group.

[0050] In step S230, according to a preset rule, all elements of the derived private key tuple are operated with all elements of the weight group to generate a sub-private key corresponding to the index code j.

[0051] The preset rule may be, for example, that the derived private key metadata corresponding to the index code j corresponds one-to-one with the chain code coefficient corresponding to the index code j in the operation. In some implementation manners, the derived private key metadata corresponding to the index code j is multiplied point by point with the chain code coefficient corresponding to the index code j and then added to generate the sub-private key corresponding to the index code j.

[0052] In step S240, based on the sub-private key and the base point P of the elliptic curve, a first sub-public key is generated.

[0053] Among them, the base point P is a generator of the elliptic curve. The sub-private key and the first sub-public key are used to form an asymmetric public key-private key pair of the encryption key corresponding to the first node. The sub-private key is also referred to as the derived private key, and the first sub-public key is also referred to as the derived public key.

[0054] The algorithm for password encryption usually adopts elliptic curve cryptography (ECC). Elliptic curve cryptography is an asymmetric encryption method based on elliptic curve mathematics, which can be expressed by performing addition or multiplication operations on points on an elliptic curve.

[0055] Optionally, q participants can share the elliptic curve parameters E, P, and q of the encryption algorithm. Among them, the elliptic curve E is an elliptic curve defined over the finite field Fq, P is a base point (or generator) of order q on the elliptic curve E, and each node i (or participant) can randomly select a number between [1, q] as its own random number. Taking the secp256k1 elliptic curve as an example, the base point P is the generator of the elliptic curve secp256k1. For example, its coordinate values (in hexadecimal) can be: [79be667ef9dcbbac55a06295ce870b07029bfcdb2dce28d959f2815b16f81798, 483ada7726a3c4655da4fbfc0e1108a8fd17b448a68554199c47d08ffb10d4b8]. The value of the order q (in hexadecimal) can be: fffffffffffffffffffffffffffebaaedce6af48a03bbfd25e8cd0364141.

[0056] In some implementation manners, the one-way function can be a hash function. A hash function is a publicly known one-way function, also known as a hash function or a hashing function. The function value obtained by mapping is called a hash value, a hash value, or a message digest. Commonly used hash functions include MD5, SHA1, SHA2 (such as SHA512), SHA3, HMAC, etc.

[0057] The above data u is a security parameter value, which can be set by yourself according to needs. It describes the complexity of the algorithm being cracked. Generally, u can take 4, 8, 16, 32, 64... It can be understood that u should usually be less than the number of bits of the hash value of the hash function, and the number of bits of the hash value is also the length value of the message digest generated by the hash function. For example, if the hash function adopted is SHA512 and the number of bits of the hash value is 512 bits, then the selected value of u should be less than 512.

[0058] The public key can be used to encrypt the session and verify the digital signature. Only the corresponding private key can decrypt the session data, thus ensuring the security of data transmission. The public key is the part of the key that is made public, while the private key is the non-public part that is kept by the user. For example, data encrypted with the first sub-public key corresponding to index code j can only be decrypted with the sub-private key corresponding to index code j. If the sub-private key corresponding to index code j is used to sign, the corresponding first sub-public key must also be used for authentication.

[0059] The security problem of the above key derivation scheme can be reduced to the discrete logarithm problem. "Finding discrete logarithms" is very difficult. Since the sub-private key is obtained by combining the elements of multiple private key tuples and chain code coefficients, even if the malicious participant (adversary) obtains the sub-private key and chain code (derivative information) of a certain round, it is impossible to obtain the global key if the number of sub-private keys is less than u. In fact, the adversary only obtains a permutation and combination of the sub-private keys in the private key derivation tuple, and cannot obtain the full picture of the key derivation.

[0060] In some implementations, derived public key metadata corresponding to index code j is generated based on derived private key metadata corresponding to index code j and base point P. The derived public key metadata is the elements constituting the derived public key tuple, and the number of elements in the derived public key tuple is u. That is, multiple derived public key metadata sequentially constitute the derived public key tuple according to index code j (or round). All elements of the derived public key tuple are paired with all elements of the weight group according to a preset rule to generate the first child public key corresponding to index code j.

[0061] In some implementations, pairing all elements of the derived private key tuple with all elements of the weight group according to a preset rule to generate a sub-private key of index code j may include: adding the derived private key metadata corresponding to index code j to the coefficient corresponding to index code j after point multiplication to generate the sub-private key corresponding to index code j. And, pairing all elements of the derived public key tuple with all elements of the weight group according to a preset rule to generate a first sub-public key corresponding to index code j may include: adding the derived public key metadata corresponding to index code j to the chain code coefficient corresponding to index code j after point multiplication to generate the first sub-public key corresponding to index code j.

[0062] In some implementations, generating a chain code coefficient corresponding to an index code j based on applying a one-way function to the concatenated data of a chain code tuple and index code j may include: generating a chain code string based on applying a one-way function to the concatenated data consisting of elements in the chain code tuple; generating a chain code coefficient corresponding to the index code j based on applying a one-way function to the concatenated data consisting of the chain code string and index code j.

[0063] In some implementations, the generated encryption key further includes a second sub-public key, which is shared by the first node and the management node. The first node is any one of a plurality of nodes, and the management node, also known as the administrator node, can be the operator of the system and belongs to the system administrator role. The method according to the embodiment of the present application further includes: generating a second sub-public key according to the root public key, the sub-public key, and the public key of the management node. The root public key is determined based on the root private key and the base point P.

[0064] The second sub-public key can be used to implement node tracking. In some implementations, the root public key of a user (i.e., a node) is often stored together with the user's real identity at the management node. When there are malicious users in the system, the management node can use two public keys (the first sub-public key, the second sub-public key), and combine the private key of the management node itself to calculate the root public key of the malicious user. The management node stores the corresponding relationship between the root public key and the identity information. As long as the management node knows the root public key, it also knows the identity information of the malicious user.

[0065] In some implementations, the management node determines the second sub-public key. The steps for the management node to determine the second sub-public key include: the management node obtains the root public key, the public key tuple, the chain code string, and the index code j of the first node; based on applying a one-way function to the concatenated data composed of the chain code string and the index code j, generates the chain code coefficient corresponding to the index code j; multiplies and adds the derived public key metadata corresponding to the index code j and the chain code coefficient corresponding to the index code j to generate the first sub-public key corresponding to the index code j; generates the second sub-public key according to the root public key, the first sub-public key, and the private key of the second node.

[0066] In some implementations, the encryption key is used for the interaction data in the blockchain. The protocol of the blockchain can be BIP-32, or it can be BIP-39, BIP-43, BIP-44. In some embodiments, the encryption key can be used for the encryption and / or decryption of the interaction data in the blockchain. In other embodiments, the encryption key can be used for digital signature and / or authentication in the blockchain.

[0067] In the embodiment of the present application, multiple derived private key metadata and corresponding multiple chain code coefficients are generated through the root private key and index code j, and all elements of the derived private key tuple are paired and combined with all chain code coefficients to generate a child private key corresponding to index code j. Since the child private key is obtained by combining the elements of multiple derived private key tuples and chain code coefficients, "finding discrete logarithms" is very difficult. Even if a malicious participant (adversary) obtains the child private keys and derived information of a certain round, it is impossible to obtain the global key if the number of child private keys is less than u. In fact, the adversary only obtains a permutation and combination of the child private keys in the derived private key tuple and cannot obtain the full picture of the key derivation. The embodiment of the present application helps to avoid the above-mentioned problems in key derivation and makes up for the vulnerability that the adversary can obtain the parent private key when knowing the child private key, the parent public key and related derived information.

[0068] The method for processing data in the embodiment of the application is further described below in conjunction with some possible implementation methods of the embodiment of the application.

[0069] Figure 3 yes Figure 2 A flowchart of a possible implementation of the method. In order to improve the security of key derivation during identity authentication in a blockchain-based mobile group perception scenario, the embodiment of the present application takes the improvement of the key derivation algorithm in the BIP-32 protocol of Bitcoin as an example, so that it can overcome the above-mentioned vulnerability problem to a certain extent, that is, if the adversary knows the child private key, the parent public key and related derived information, it can prevent the adversary from obtaining the parent private key. The method for generating an encryption key in the embodiment of the present application is also a key derivation algorithm. The following is combined with Figure 3 , the key derivation algorithm of the embodiment of the present application is described in detail. Figure 3 As shown, the method for generating an encryption key in an embodiment of the present application mainly includes the following four steps (or sub-algorithms).

[0070] Step 1: Participant i (i.e. the first node) calls the method to generate the encryption key, using the random seed as input to generate the root private key Root public key And chain code derivation parameters Calling a function

[0071] First, by inputting a random seed, we perform a hash function on the seed and calculate

[0072] The private key is derived from a public seed using a one-way hash function, i.e., a hash function. The seed is a string of randomly generated numbers, and this string combined with an index code and a chain code (i.e., derived information) can be used to derive other private keys. In a deterministic wallet, the seed can restore all derived private keys, so creating a simple seed backup is sufficient.

[0073] is a hash function. A hash function is a publicly available one-way function, also known as a hash function or a hashing function. The function value obtained by mapping is called a hash value, a hashing value, or a message digest. Commonly used hash functions include MD5, SHA1, SHA2, SHA3, HMAC, etc. For example, the hash-based message authentication code (HMAC) operation uses a hash algorithm, takes a key and a message as inputs, and generates a message digest as the output. When the specific hash algorithm used is SHA512, HMAC is denoted as HMAC-SHA512. In Figure 3 's embodiment, taking the hash function as SHA512 as an example for illustration, as can be SHA512(seed).

[0074] h L 、h R can respectively take 's first half sequence and second half sequence, or rather, h L 、h R respectively take 's left half sequence and right half sequence. h L 、h R are respectively used as the basis for deriving the root private key and the chain code derivation parameter. When the hash function is SHA512, h L 、h R respectively take 's left 256-bit sequence and right 256-bit sequence, that is, h L 、h R respectively take 's left 32-byte sequence and right 32-byte sequence.

[0075] Then, set the root private key chain code derivation parameter

[0076] Calculate the root public key

[0077] where P is the base point of the elliptic curve, q is the order of the base point P, and q is a prime number. ∥ is a concatenation symbol, and mod is a modulo function.

[0078] Return the root private key root public key and derivation parameters value

[0079] Step 2: Invoked by Participant i, using the root private key of Participant i and chain code derivation parameters as the input of the algorithm to generate the derived private key tuple SKT[u], the derived public key tuple PKT[u] and the chain code string CHAIN. That is, call the function

[0080] First, using the root private key of Participant i and chain code derivation parameters as the input to calculate the

[0081] where j ∈ [1, u], the index code j is the round of signature (or generating the encryption key), and the index code is also called the index number. u is a positive integer greater than 1. It should be understood that u is usually less than the number of bits of the hash value of the hash function. For example, when the hash function is SHA512, u is not greater than 512.

[0082] Then, set the element of the derived private key tuple SKT[j] = h L (mod q), form the chain code metadata chain[j] of the chain code tuple as chain[j] = h R (mod q), and calculate the element of the derived public key tuple PKT[j] = SKT[j]·P.

[0083] It should be understood that for the same random seed of the same Participant i, the value of the chain code metadata chain[j] is fixed.

[0084] Repeat the above steps until j increases to u.

[0085] Calculate the chain code string The chain code is also called the derived information, and the chain code string CHAIN is also called the derived information string. The chain code string CHAIN integrates the information of all chain code metadata chain[j].[[]END]]

[0086] In addition, Participant i (i.e., the first node) can securely send the derived public key tuple PKT[u], the chain code string CHAIN, and the root public key to the manager TA (i.e., the management node).

[0087] Step 3: The algorithm is invoked by Participant i, using the derived private key tuple SKT[u] and the chain code string CHAIN as the input, aiming to obtain the private key and public key required for signing in the j-th round (i.e., the index code j). That is, call the function

[0088] First, calculate the elements of the weight group

[0089] For example, after the chain code string CHAIN is concatenated with the index code j, it is then calculated through the hash function SHA512 to obtain a hash value, and then the hash value is evenly divided into u parts, so as to obtain the coefficients of the weight group

[0090] Then, calculate the private key (or sub-private key) corresponding to the j-th round of signature:

[0091]

[0092] The above formula is a system of linear equations with multiple coefficients

[0093] After that, calculate the public key (or sub-public key) corresponding to the j-th round of signature:

[0094]

[0095] Public key That is the first sub-public key corresponding to the j-th round of signature

[0096] It can be seen that the chain code string CHAIN that integrates all the chain code metadata chain[j] information participates in the derivation of the private key-public key pairs (i.e., sub-private key-first sub-public key pairs) for all rounds j

[0097] Calculate the second sub-public key corresponding to the j-th round of signature:

[0098]

[0099] Among them, MPK is the public key of the administrator TA

[0100] Finally, return the private key and public key pair

[0101] Step 4: This step of the algorithm is called by the administrator TA (i.e., the management node), with the public key tuple PKT[u] and the chain code string CHAIN as inputs, and the purpose is to generate the public key required for the j-th round of signature of participant i That is, call the function

[0102] First, calculate the elements of the weight group

[0103] Then, calculate the public key (or sub-public key) required for the j-th round of signature:

[0104]

[0105] The above formula is a system of linear equations with multiple coefficients.

[0106] Calculate the second sub-public key corresponding to the j-th round of signature:

[0107]

[0108] Wherein, MSK is the private key of the administrator TA, and MPK = MSK·P.

[0109] Finally, return the key pair

[0110] It can be understood that the term "seed" in the embodiments of the present application does not necessarily mean that the seed is the absolute highest-level key in the entire hierarchy or tree. More generally, a key derivation function (CKD) can be applied to any key in the hierarchy to generate one or more child keys therefrom. The "seed" in the embodiments of the present application is just any parent key from which other child keys of a given key set are derived. In an embodiment, the seed itself can be the child key of another key.

[0111] The second sub-public keys determined by the participant i (the first node) and the administrator TA (the management node) are the same, and the proof is as follows.

[0112] In step three, the participant i calculates the second sub-public key corresponding to the j-th round of signature:

[0113]

[0114] Furthermore, Since So it is concluded that:

[0115]

[0116] Which is the second sub-public key corresponding to the j-th round of signature calculated by the administrator TA in step four.

[0117] Set the second public key Can be used to implement node tracking. MPK is the public key of the administrator, is the root public key of the participant i, and the root public key of the participant i and the real identity are often stored together at the administrator TA. Because The administrator TA can use its own private key MSK, through the formula Calculate the root public key of the participant i.

[0118] The administrator TA stores the corresponding relationship between the root public key and the participant identity information. As long as the administrator TA knows the root public key, it also knows the identity information of the participant (or malicious user).

[0119] In the embodiment of the present application, multiple derived private key metadata and corresponding multiple chain code coefficients are generated through the root private key and index code j, and all elements of the derived private key tuple are paired and combined with all chain code coefficients to generate a child private key corresponding to index code j. Since the child private key is obtained by a linear combination of elements of multiple derived private key tuples and chain code coefficients, "finding discrete logarithms" is very difficult.

[0120] is a linear equation with multiple coefficients. Therefore, if the number of sub-private keys is less than u, it is impossible to solve the linear equation system and further obtain the derived key tuples SKT[u] and PKT[u]. In other words, no adversary can derive the first sub-public key from the known j-th round. Based on this, the derived child private key is obtained In the embodiment of the present application, even if an attacker with polynomial computing power (PPT adversary) obtains a certain round of sub-private key As well as derived information, the global key derivation cannot be obtained. In fact, the adversary only obtains a permutation and combination of the sub-private keys in the derived private key tuple, and naturally cannot obtain the full picture of the key derivation.

[0121] The embodiments of the present application help to overcome the aforementioned loopholes in the current key derivation. Even if the adversary knows the child private key, the parent public key and related derivation information, the adversary cannot obtain the parent private key. The embodiments of the present application also realize the separate derivation of private keys and public keys, and the decoupling of the derivation of private keys and public keys, ensuring the "master public key attribute". In actual application scenarios, it is more secure and efficient, which helps to improve communication efficiency.

[0122] The method for generating an encryption key in the embodiment of the present application is applied to interactive data in a blockchain. The protocol of the blockchain may be BIP-32, or may be BIP-39, BIP-43, or BIP-44. In BIP-39, a mnemonic is introduced. Similar to the derivation algorithm for the random seed in BIP-32 in the embodiment of the present application, the random seed may also be further processed in BIP-39 to obtain a mnemonic.

[0123] In some embodiments, the encryption key can be used for encryption and / or decryption of interactive data in the blockchain. In other embodiments, the encryption key can be used for digital signature and / or authentication in the blockchain.

[0124] Figure 4 1 is a flow chart of a method for encrypting data communication provided by an embodiment of the present application. Figure 4 The method for encrypted data communication in the embodiment of the present application is described in detail. Figure 4As shown, the method for encrypted data communication mainly includes steps S410 to S430, which will be described in detail below.

[0125] In step S410, the first node determines an encryption key based on the method for generating an encryption key as described in any of the foregoing.

[0126] The encryption key may include: a private key - public key pair corresponding to the first node and the public key of the second node. The first node is any one of multiple nodes in the blockchain, and the second node is any one of the multiple nodes different from the first node.

[0127] In step S420, the data to be sent is encrypted based on the encryption key to generate encrypted data.

[0128] In step S430, the first node sends the encrypted data to the second node in the blockchain.

[0129] In some implementation manners, an encryption key corresponding to the second node is determined based on the method for generating an encryption key as described in any of the foregoing, such as a private key - public key pair corresponding to the second node; a decryption key is obtained based on the encryption key of the second node. In some embodiments, the decryption key may be the private key corresponding to the second node. The encrypted data is decrypted based on the decryption key to obtain the decrypted data.

[0130] The method for encrypted data communication of the present application will be further described below in conjunction with embodiments.

[0131] Message Encryption Embodiment 1

[0132] The basic process of implementing data secure communication using an asymmetric encryption algorithm is as follows:

[0133] The first node i generates an encryption key based on the method for generating an encryption key as described in any of the foregoing, that is, generates a private key - public key pair corresponding to the j - th round signature (index code j) of the first node i and makes the public key public. The second node t generates a private key - public key pair corresponding to the index code k of the second node t based on the method for generating an encryption key as described in any of the foregoing and makes the public key public.

[0134] The first node i that needs to send information to the second node t uses the public key (the public key of the second node t) to encrypt the first information, and then generates the first encrypted data. The first encrypted data is then sent to the second node t. The second node t decrypts the encrypted first encrypted data with its own private key to obtain the first information. When the second node t wants to reply to the first node i, it is exactly the opposite, using the public key of the first node i The second information is encrypted to generate second encrypted data, which is then sent to the first node i. Similarly, the first node i uses its own private key to decrypt the second encrypted data to obtain the second information.

[0135] Figure 5 It is a schematic flowchart of a digital signature method provided by an embodiment of the present application. The following will be combined with Figure 5 to introduce the digital signature method of the embodiment of the present application in detail. As Figure 5 shown, the digital signature method mainly includes steps S510 to S530, and the following will describe these steps in detail.

[0136] In step S510, the first node generates an encryption key based on the method for generating an encryption key described in any of the foregoing. The encryption key includes a sub-private key and a first sub-public key.

[0137] In step S520, the first message is signed based on the sub-private key to generate a first signature message.

[0138] In step S530, the first signature message is sent to the second node.

[0139] Among them, the first signature message is suitable for verification using the first sub-public key to authenticate the first node.

[0140] Digital signature (also known as electronic signature) is a kind of digital information authentication method similar to an ordinary physical signature written on paper, but implemented using technologies in the field of key encryption. Digital signature can include performing an encryption function, which has a plaintext input and a key input such as a private key.

[0141] The method of the embodiment of the present application may further include: the second node obtains the first signature message and the first sub-public key; uses the first sub-public key of the first node to verify the first signature message to obtain a verification result of the first signature message; and authenticates the first node according to the verification result.

[0142] The embodiment of the present application helps to overcome the above-mentioned vulnerability problems, that is, it avoids the problem that an adversary can obtain the parent private key when knowing the sub-private key, the parent public key, and related derived information. The embodiment of the present application also realizes the separated derivation of the private key and the public key and the decoupling of the derivation of the private key and the public key, ensuring the "master public key attribute", which is more secure and efficient in actual application scenarios and helps to improve communication efficiency.

[0143] The above has described the method embodiment of the present application in detail. The following will be combined with Figures 1 to 5 to describe in detail, and the following will be combined with Figure 6 and Figure 7Describe the device embodiments of the present application in detail. It should be understood that the description of the device embodiments corresponds to the description of the method embodiments. Therefore, for the parts not described in detail, reference can be made to the previous method embodiments.

[0144] Figure 6 FIG. is a schematic structural diagram of a device for generating an encryption key provided by an embodiment of the present application. The device 600 for generating an encryption key is applied to the first node in the blockchain, and the first node can be any node. As Figure 6 shown, the device 600 for generating an encryption key includes a first generation module 610, a second generation module 620, a private key generation module 630, and a public key generation module 640.

[0145] The first generation module 610 is used to generate the derived private key metadata and chain code metadata corresponding to the index code j based on the concatenated data obtained by applying a one-way function to the root private key and the index code j.

[0146] The derived private key metadata is an element that makes up the derived private key tuple. The number of elements in the derived private key tuple is u, where u is a positive integer greater than 1, and j is less than or equal to u. The chain code metadata is an element that makes up the chain code tuple. The number of elements in the chain code tuple is u. The index code is the round of generating the encryption key, and the root private key is data obtained by applying a one-way function to the seed.

[0147] The second generation module 620 is used to generate the chain code coefficient corresponding to the index code j based on the concatenated data obtained by applying a one-way function to the chain code tuple and the index code j. The chain code coefficient corresponding to the index code j is an element that makes up the weight group.

[0148] The private key generation module 630 is used to perform a pairing operation on all elements of the derived private key tuple and all elements of the weight group according to a preset rule to generate the sub-private key of the index code j.

[0149] The public key generation module 640 is used to generate a first sub-public key based on the sub-private key and the base point P, where P is the generator of the elliptic curve. The sub-private key and the first sub-public key are used to form an asymmetric public key-private key pair of the encryption key corresponding to the first node.

[0150] Optionally, the device 600 for generating an encryption key includes a third generation module. The third generation module is used to generate the derived public key metadata corresponding to the index code j according to the derived private key metadata corresponding to the index code j and the base point P. The derived public key metadata is an element that makes up the derived public key tuple. The number of elements in the derived public key tuple is u. The public key generation module 640 is used to perform a pairing operation on all elements of the derived public key tuple and all elements of the weight group according to a preset rule to generate the first sub-public key corresponding to the index code j.

[0151] Optionally, the private key generation module 630 is used to multiply and add the derived private key metadata corresponding to the index code j with the chain code coefficient corresponding to the index code j to generate a sub-private key corresponding to the index code j. Further, the public key generation module 640 is used to multiply and add the derived public key metadata corresponding to the index code j with the chain code coefficient corresponding to the index code j to generate a first sub-public key corresponding to the index code j.

[0152] Optionally, the second generation module 630 is used to generate a chain code string based on applying a one-way function to the concatenated data formed by all elements in the chain code tuple; and generate a chain code coefficient corresponding to the index code j based on applying the one-way function to the concatenated data formed by the chain code string and the index code j.

[0153] Optionally, the encryption key further includes a second sub-public key, which is shared by the first node and the management node. The device 600 for generating the encryption key includes a fourth generation module. The fourth generation module is used to generate the second sub-public key according to the root public key, the sub-public key, and the public key of the management node, where the root public key is determined based on the root private key and the base point P.

[0154] Optionally, the management node determines the second sub-public key. The steps for the management node to determine the second sub-public key include: the management node obtains the root public key, the public key tuple, the chain code string, and the index code j corresponding to the first node; generates a chain code coefficient corresponding to the index code j based on applying a one-way function to the concatenated data formed by the chain code string and the index code j; multiplies and adds the public key metadata corresponding to the index code j with the chain code coefficient corresponding to the index code j to generate a first sub-public key corresponding to the index code j; and generates the second sub-public key according to the root public key, the first sub-public key, and the private key of the second node.

[0155] Optionally, the one-way function is a hash function.

[0156] Optionally, the encryption key is used for the interaction data in the blockchain.

[0157] Figure 7 It is a schematic diagram of the composition unit / partial composition unit of the electronic device provided by the embodiments of the present application. The electronic device 700 can be used to implement the method described in the above method embodiments. The electronic device 700 may include a memory 710 and a processor 720.

[0158] The memory 710 is used to store code.

[0159] The processor 720 is used to execute the code stored in the memory 710 to execute the method as described in any of the above.

[0160] The processor is the computing and control core of an electronic device and is the ultimate execution unit for information processing and program operation. The processor 720 may be a general-purpose processor, including a central processing unit, a micro control unit, a network processor, or other conventional processors. It may also be a dedicated processor, including a digital signal processor, an application specific integrated circuit, a field programmable gate array, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0161] An embodiment of the present application provides a chip, including a processor configured to execute the method described in any of the foregoing.

[0162] An embodiment of the present application further provides a non-volatile computer-readable storage medium, on which a computer program is stored, and the computer program is used to execute the method described in any of the foregoing.

[0163] In the above embodiments, it may be implemented in whole or in part by software, hardware, firmware, or any other combination. When implemented using software, it may be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present disclosure are generated in whole or in part. The computer may be a general-purpose computer, a dedicated computer, a computer network, or other programmable devices. The computer instructions may be stored in a machine-readable storage medium or transmitted from one machine-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The machine-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media integrated. The available medium may be a magnetic medium (such as a floppy disk, a hard disk, a magnetic tape), an optical medium (such as a digital video disc (DVD)), or a semiconductor medium (such as a solid state disk (SSD)), etc.

[0164] Those of ordinary skill in the art will realize that the units and algorithm steps of the examples described in combination with the embodiments of the present disclosure can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present disclosure.

[0165] In several embodiments provided by the present disclosure, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be in an electrical, mechanical, or other form.

[0166] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0167] In addition, the functional units in the various embodiments of the present disclosure can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.

[0168] As described above, the above is only the specific implementation manner of the present disclosure, but the protection scope of the present disclosure is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present disclosure can easily think of changes or substitutions, which should all be covered within the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be subject to the protection scope of the claims.

Claims

1. A method for generating an encryption key, characterized in that, The method is executed by a first node, and the method includes: Generating derived private key metadata and chain code metadata corresponding to the index code j based on applying a one-way function to connection data composed of a root private key and the index code j, where the derived private key metadata is an element constituting a derived private key tuple, the number of elements in the derived private key tuple is u, u is a positive integer greater than 1, j is less than or equal to u, the chain code data is an element constituting a chain code tuple, the number of elements in the chain code tuple is u, the index code j is the round for generating the encryption key, and the root private key is data obtained by applying the one-way function to a seed; Generating a chain code coefficient corresponding to the index code j based on applying the one-way function to connection data of the chain code tuple and the index code j, where the chain code coefficient corresponding to the index code j is an element constituting a weight group; Performing a pairing operation on all elements of the derived private key tuple and all elements of the weight group according to a preset rule to generate a sub-private key corresponding to the index code j; Generating a first sub-public key based on the sub-private key and the base point P of an elliptic curve, where the sub-private key and the first sub-public key are used to form an asymmetric public key-private key pair of the encryption key corresponding to the first node.

2. The method according to claim 1, characterized in that, Including: Generating derived public key metadata corresponding to the index code j based on the derived private key metadata corresponding to the index code j and the base point P, where the derived public key metadata is an element constituting a derived public key tuple, and the number of elements in the derived public key tuple is u; Performing a pairing operation on all elements of the derived public key tuple and all elements of the weight group according to the preset rule to generate the first sub-public key corresponding to the index code j.

3. The method according to claim 2, characterized in that, The step of performing a pairing operation on all elements of the derived private key tuple and all elements of the weight group according to a preset rule to generate a sub-private key of the index code j includes: Multiplying and then adding the derived private key metadata corresponding to the index code j and the chain code coefficient corresponding to the index code j to generate the sub-private key corresponding to the index code j; and The step of performing a pairing operation on all elements of the derived public key tuple and all elements of the weight group according to the preset rule to generate the first sub-public key corresponding to the index code j includes: Multiplying and then adding the derived public key metadata corresponding to the index code j and the chain code coefficient corresponding to the index code j to generate the first sub-public key corresponding to the index code j.

4. The method according to claim 1, characterized in that, The step of generating a chain code coefficient corresponding to the index code j based on applying the one-way function to connection data of the chain code tuple and the index code j includes: Generating a chain code string based on applying the one-way function to connection data composed of all elements in the chain code tuple; Generating the chain code coefficient corresponding to the index code j based on applying the one-way function to connection data of the chain code string and the index code j.

5. The method according to claim 4, characterized in that, The encryption key further includes a second sub-public key shared by the first node and a management node, and the method further includes: Generate the second sub-public key according to the root public key, the sub-public key, and the public key of the management node, where the root public key is determined based on the root private key and the base point P.

6. The method according to claim 5, characterized in that, The management node determines the second sub-public key. The steps for the management node to determine the second sub-public key include: The management node obtains the root public key, the public key tuple, the chain code string, and the index code j of the first node; Generate the chain code coefficient corresponding to the index code j based on applying the one-way function to the concatenated data composed of the chain code string and the index code j; Multiply and add the public key metadata corresponding to the index code j with the chain code coefficient corresponding to the index code j to generate the first sub-public key corresponding to the index code j; Generate the second sub-public key according to the root public key, the first sub-public key, and the private key of the management node.

7. The method according to any one of claims 1 - 6, characterized in that, The one-way function is a hash function.

8. The method according to any one of claims 1 - 6, characterized in that, The encryption key is used for the interaction data in the blockchain.

9. An apparatus for generating an encryption key, characterized in that, Applied to the first node, the device includes: A first generation module, configured to generate the derived private key metadata and the chain code metadata corresponding to the index code j based on applying the one-way function to the concatenated data composed of the root private key and the index code j. The derived private key metadata is an element of the derived private key tuple, the number of elements of the derived private key tuple is u, u is a positive integer greater than 1, j is less than or equal to u, the chain code metadata is an element of the chain code tuple, the number of elements of the chain code tuple is u, the index code is the round for generating the encryption key, and the root private key is based on applying the one-way function to the data of the seed; A second generation module, configured to generate the chain code coefficient corresponding to the index code j based on applying the one-way function to the concatenated data of the chain code tuple and the index code j. The chain code coefficient corresponding to the index code j is an element of the weight group; A private key generation module, configured to perform a pairing operation on all elements of the derived private key tuple and all elements of the weight group according to a preset rule to generate the sub-private key of the index code j; A public key generation module, configured to generate a first sub-public key based on the sub-private key and the base point P of the elliptic curve. The sub-private key and the first sub-public key are used to form an asymmetric public key-private key pair of the encryption key corresponding to the first node.

10. A method for encrypting data communication, characterized in that, Includes: The first node determines the encryption key based on the method for generating the encryption key according to any one of claims 1-8; Encrypt the data to be sent based on the encryption key to generate encrypted data; The first node sends the encrypted data to a second node in the blockchain.

11. According to the method described in claim 10, wherein, The method includes: The second node determines the encryption key corresponding to the second node based on the method for generating the encryption key; The second node receives the encrypted data; Obtain a decryption key based on the encryption key corresponding to the second node; Decrypt the encrypted data based on the decryption key to obtain the decrypted data.

12. An electronic device, wherein, Includes: A memory, configured to store code; A processor, configured to execute the code stored in the memory to execute the method according to any one of claims 1-8 or claims 10-11.

13. A non - volatile computer - readable storage medium, wherein, A computer program is stored thereon, and when the computer program is executed, it is used to implement the method described in any one of claims 1-8 or claims 10-11.