Anti-quantum-attack block chain transaction method and device, equipment and medium

By adopting the dual signature method of asymmetric encryption algorithm and post-quantum encryption algorithm in the blockchain system, the cracking risks faced by traditional cryptography systems in the quantum computing era are solved, and efficient and secure protection of blockchain transaction data is achieved.

CN120218927APending Publication Date: 2025-06-27中电信量子信息科技集团有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510184663.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-19
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

Traditional cryptography systems face cracking risks in the era of quantum computing, especially the threat of Shor algorithm to elliptical curve cryptography, which has led to the challenge of the security of blockchain systems.

Method used

The dual signature method of asymmetric encryption algorithm and post-quantum encryption algorithm is adopted to enhance the security of blockchain transaction data through layer-by-layer protection of the first signature and the second signature.

Benefits of technology

Effectively resist the attacks of quantum computers and ensure that the digital signatures and transaction data in blockchain systems are still safe in the era of quantum computing and are not easily cracked or forged.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120218927A_ABST
    Figure CN120218927A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an anti-quantum-attack block chain transaction method and device, equipment and a medium. The method comprises the following steps: acquiring transaction data, a first encryption algorithm and a second encryption algorithm; the first encryption algorithm comprises an asymmetric encryption algorithm, and the second encryption algorithm comprises a post-quantum encryption algorithm; determining a first signature according to a first encryption algorithm and the transaction data; determining a second signature according to a second encryption algorithm and the first signature; the second signature and the address of the node are broadcasted to a transaction receiving node, so that the transaction receiving node obtains the first public key and the second public key from a public key storage server according to the address of the node to verify the signature, and the transaction is completed; by introducing the post-quantum encryption algorithm, preparation for coping with the quantum computing era is made for the block chain system in advance, and the long-term security and stability of the system are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of blockchain transactions, and in particular, to a blockchain transaction method, device, equipment and medium resistant to quantum attacks. Background Art

[0002] Blockchain technology, as a decentralized distributed ledger technology, relies on cryptography to ensure the immutability of transaction data and the security of transmission. In a blockchain network, each node stores a complete copy of the ledger and uses a consensus protocol to ensure the consistency of the ledger data. Cryptographic technologies, especially public key cryptography, play a crucial role in blockchain and are widely used in aspects such as digital signatures, asset rights confirmation, and identity authentication.

[0003] However, with the rapid development of quantum computing technology, the traditional cryptographic system is facing unprecedented challenges. Quantum computers, with their powerful quantum computing capabilities, can efficiently crack cryptographic schemes based on traditional mathematical problems. In particular, the Shor algorithm can quickly solve the elliptic curve discrete logarithm problem (ECDLP) on a quantum computer, which is the basis of many public key cryptography schemes (such as elliptic curve cryptography). Once a general-purpose quantum computer becomes a reality, hackers may use the Shor algorithm to calculate the corresponding private key by exposing the public key in the blockchain, thus causing a catastrophic attack on the blockchain system.

[0004] Such an attack not only threatens the security of digital assets in the blockchain but also may undermine the trust foundation of the entire blockchain system. Because digital signatures are an important proof of the legitimacy of transactions in the blockchain, if digital signatures can be easily forged or cracked, the authenticity and integrity of transactions cannot be guaranteed. In addition, applications such as identity authentication and asset rights confirmation that rely on public key cryptography will also face serious security risks.

[0005] Therefore, how to ensure the security of the blockchain system in the era of quantum computing has become an urgent problem to be solved. Traditional encryption algorithms and signature schemes can no longer meet future security requirements, and new encryption algorithms and signature schemes that can resist quantum computing attacks must be found to ensure the continuous and stable operation of the blockchain system and the security of transaction data. Summary of the Invention

[0006] In view of the above problems, embodiments of the present invention are proposed to provide a blockchain transaction method, device, equipment and medium resistant to quantum attacks that overcome or at least partially solve the above problems.

[0007] To solve the above problems, on the one hand, an embodiment of the present invention discloses a blockchain transaction method resistant to quantum attacks, which is applied to a transaction initiating node. The method includes:

[0008] Obtain transaction data, a first encryption algorithm, and a second encryption algorithm; the first encryption algorithm includes an asymmetric encryption algorithm, and the second encryption algorithm includes a post-quantum encryption algorithm;

[0009] Obtain transaction data, a first encryption algorithm, and a second encryption algorithm; the first encryption algorithm includes an asymmetric encryption algorithm, and the second encryption algorithm includes a post-quantum encryption algorithm;

[0010] Determine a first signature according to the first encryption algorithm and the transaction data;

[0011] Determine a second signature according to the second encryption algorithm and the first signature;

[0012] Broadcast the second signature and the address of this node to the transaction receiving node, so that the transaction receiving node can obtain the first public key and the second public key from the public key storage server according to the address of this node to verify the signature and complete the transaction.

[0013] Optionally, the determining the second signature according to the second encryption algorithm and the first signature includes:

[0014] Obtain a hybrid signature encoding rule;

[0015] Determine a hybrid signature encoding according to the first signature, the transaction data, and the hybrid signature encoding rule;

[0016] Determine the second signature according to the hybrid signature encoding and the second encryption algorithm.

[0017] Optionally, the determining the second signature according to the second encryption algorithm and the first signature includes:

[0018] Obtain a hybrid signature hashing rule;

[0019] Determine a hybrid signature hash value according to the first signature, the transaction data, and the hybrid signature hashing rule;

[0020] Determine the second signature according to the hybrid signature hash value and the second encryption algorithm.

[0021] Optionally, the determining the second signature according to the second encryption algorithm and the first signature includes:

[0022] Obtain a hybrid signature encryption algorithm;

[0023] Determine the encrypted hybrid signature based on the first signature, the transaction data, and the hybrid signature encryption algorithm;

[0024] Determine the second signature based on the encrypted hybrid signature and the second encryption algorithm.

[0025] On the other hand, an embodiment of the present invention also discloses a blockchain transaction method resistant to quantum attacks, which is applied to a transaction receiving node. The method includes:

[0026] Receive the second signature broadcast by the transaction initiating node and the address information of the transaction initiating node;

[0027] Obtain the first public key and the second public key from the public key storage server according to the address information of the transaction initiating node;

[0028] Determine the first signature according to the second signature and the second public key;

[0029] Determine the transaction data according to the first signature and the first public key;

[0030] Complete the transaction according to the transaction data.

[0031] Optionally, the determining the first signature according to the second signature and the second public key includes:

[0032] Obtain the hybrid signature encoding rule;

[0033] Determine the hybrid signature encoding according to the second signature and the second public key;

[0034] Determine the first signature according to the hybrid signature encoding and the hybrid signature encoding rule.

[0035] Optionally, the determining the first signature according to the second signature and the second public key includes:

[0036] Obtain the hybrid signature hash rule;

[0037] Determine the hybrid signature hash value according to the second signature and the second public key;

[0038] Determine the first signature according to the hybrid signature hash value and the hybrid signature hash rule.

[0039] Optionally, the determining the first signature according to the second signature and the second public key includes:

[0040] Obtain the hybrid signature encryption algorithm;

[0041] Determine the encrypted hybrid signature according to the second signature and the second public key;

[0042] Determine a first signature according to the encrypted hybrid signature and the hybrid signature encryption algorithm.

[0043] On the other hand, an embodiment of the present invention also discloses a blockchain transaction system resistant to quantum attacks. The system includes a transaction initiating node for obtaining transaction data, a first encryption algorithm, and a second encryption algorithm; the first encryption algorithm includes an asymmetric encryption algorithm, and the second encryption algorithm includes a post-quantum encryption algorithm; obtain transaction data, a first encryption algorithm, and a second encryption algorithm; the first encryption algorithm includes an asymmetric encryption algorithm, and the second encryption algorithm includes a post-quantum encryption algorithm; determine a first signature according to the first encryption algorithm and the transaction data; determine a second signature according to the second encryption algorithm and the first signature; broadcast the second signature and the address of this node to a transaction receiving node, so that the transaction receiving node obtains a first public key and a second public key from a public key storage server according to the address of this node for signature verification to complete the transaction.

[0044] A transaction receiving node for receiving the second signature broadcast by the transaction initiating node and the address information of the transaction initiating node; obtaining a first public key and a second public key from a public key storage server according to the address information of the transaction initiating node. Determine a first signature according to the second signature and the second public key; determine transaction data according to the first signature and the first public key; complete the transaction according to the transaction data.

[0045] Optionally, the transaction initiating node is used to obtain a hybrid signature encoding rule; determine a hybrid signature encoding according to the first signature, the transaction data, and the hybrid signature encoding rule; determine the second signature according to the hybrid signature encoding and the second encryption algorithm.

[0046] The transaction receiving node is used to obtain a hybrid signature encoding rule; determine a hybrid signature encoding according to the second signature and the second public key; determine a first signature according to the hybrid signature encoding and the hybrid signature encoding rule.

[0047] Optionally, the transaction initiating node is used to obtain a hybrid signature hashing rule; determine a hybrid signature hash value according to the first signature, the transaction data, and the hybrid signature hashing rule; determine the second signature according to the hybrid signature hash value and the second encryption algorithm.

[0048] The transaction receiving node is used to obtain a hybrid signature hashing rule; determine a hybrid signature hash value according to the second signature and the second public key; determine a first signature according to the hybrid signature hash value and the hybrid signature hashing rule.

[0049] Optionally, the transaction initiation node is used to obtain a hybrid signature encryption algorithm; determine an encrypted hybrid signature according to the first signature, the transaction data, and the hybrid signature encryption algorithm; determine the second signature according to the encrypted hybrid signature and the second encryption algorithm.

[0050] The transaction receiving node is used to obtain a hybrid signature encryption algorithm; determine an encrypted hybrid signature according to the second signature and the second public key; determine the first signature according to the encrypted hybrid signature and the hybrid signature encryption algorithm.

[0051] On the other hand, an embodiment of the invention also discloses a blockchain transaction device resistant to quantum attacks, which is applied to a transaction initiation node. The device includes:

[0052] A transaction data acquisition module, configured to acquire transaction data, a first encryption algorithm, and a second encryption algorithm; the first encryption algorithm includes an asymmetric encryption algorithm, and the second encryption algorithm includes a post-quantum encryption algorithm.

[0053] A first signature determination module, configured to determine a first signature according to the first encryption algorithm and the transaction data.

[0054] A second signature determination module, configured to determine a second signature according to the second encryption algorithm and the first signature.

[0055] A data broadcast module, configured to broadcast the second signature and the address of the local node to a transaction receiving node, so that the transaction receiving node can obtain a first public key and a second public key from a public key storage server according to the address of the local node to verify the signature and complete the transaction.

[0056] Optionally, the second signature determination module includes:

[0057] A first encoding rule acquisition sub-module, configured to acquire a hybrid signature encoding rule.

[0058] A first hybrid encoding acquisition sub-module, configured to determine a hybrid signature encoding according to the first signature, the transaction data, and the hybrid signature encoding rule.

[0059] A first encoding signature acquisition sub-module, configured to determine the second signature according to the hybrid signature encoding and the second encryption algorithm.

[0060] Optionally, the second signature determination module includes:

[0061] A first hash rule acquisition sub-module, configured to acquire a hybrid signature hash rule.

[0062] The first hybrid hash acquisition sub-module is used to determine the hybrid signature hash value according to the first signature, the transaction data, and the hybrid signature hash rule;

[0063] The first hash signature acquisition sub-module is used to determine the second signature according to the hybrid signature hash value and the second encryption algorithm.

[0064] Optionally, the second signature determination module includes:

[0065] The first encryption algorithm acquisition sub-module is used to acquire the hybrid signature encryption algorithm;

[0066] The first hybrid encryption acquisition sub-module is used to determine the encrypted hybrid signature according to the first signature, the transaction data, and the hybrid signature encryption algorithm;

[0067] The first hybrid encryption acquisition sub-module is used to determine the second signature according to the encrypted hybrid signature and the second encryption algorithm.

[0068] On the other hand, an embodiment of the invention also discloses a blockchain transaction device resistant to quantum attacks, which is characterized in that it is applied to a transaction receiving node, and the device includes:

[0069] The transaction data receiving module is used to receive the second signature broadcast by the transaction initiating node and the address information of the transaction initiating node;

[0070] The signature public key receiving module is used to obtain the first public key and the second public key from the public key storage server according to the address information of the transaction initiating node;

[0071] The first signature determination module is used to determine the first signature according to the second signature and the second public key;

[0072] The transaction data determination module is used to determine the transaction data according to the first signature and the first public key;

[0073] The transaction completion module is used to complete the transaction according to the transaction data.

[0074] Optionally, the first signature determination module includes:

[0075] The second encoding rule acquisition sub-module is used to acquire the hybrid signature encoding rule;

[0076] The second hybrid encoding acquisition sub-module is used to determine the hybrid signature encoding according to the second signature and the second public key;

[0077] The first signature acquisition sub-module is used to determine the first signature according to the hybrid signature encoding and the hybrid signature encoding rule.

[0078] Optionally, the first signature determination module includes:

[0079] A second hash rule acquisition sub-module, configured to acquire a hybrid signature hash rule;

[0080] A second hybrid hash acquisition sub-module, configured to determine a hybrid signature hash value according to the second signature and the second public key;

[0081] A second signature acquisition sub-module, configured to determine a first signature according to the hybrid signature hash value and the hybrid signature hash rule.

[0082] Optionally, the first signature determination module includes:

[0083] A second encryption algorithm acquisition sub-module, configured to acquire a hybrid signature encryption algorithm;

[0084] A second hybrid encryption acquisition sub-module, configured to determine an encrypted hybrid signature according to the second signature and the second public key;

[0085] A second signature acquisition sub-module, configured to determine a first signature according to the encrypted hybrid signature and the hybrid signature encryption algorithm.

[0086] Correspondingly, an embodiment of the present invention discloses an electronic device, including: a processor, a memory, and a computer program stored on the memory and capable of running on the processor. When the computer program is executed by the processor, it implements each step of the above-mentioned embodiment of the blockchain transaction method against quantum attacks.

[0087] Correspondingly, an embodiment of the present invention discloses a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements each step of the above-mentioned embodiment of the blockchain transaction method against quantum attacks.

[0088] Embodiments of the present invention have the following advantages: The post-quantum encryption algorithm adopted in the embodiments of the present invention can effectively resist the attacks of quantum computers, especially against the threat of the Shor algorithm to public-key cryptosystems such as elliptic curve cryptography. This means that even in the future when quantum computers become popular, the embodiments of the present invention can ensure the security of digital signatures and transaction data in the blockchain system, and they cannot be easily cracked or forged. By first using an asymmetric encryption algorithm to generate a first signature and then using a post-quantum encryption algorithm to generate a second signature based on this signature, the embodiments of the present invention achieve the effect of double encryption. This layer-by-layer protection not only improves the security of the data but also increases the difficulty for attackers to crack the signature, thus more effectively protecting the transaction data and user assets in the blockchain system. In the embodiments of the present invention, the transaction receiving node only needs to obtain the corresponding first public key and second public key from the public key storage server according to the broadcast second signature and the node address for verification. This design simplifies the verification process, reduces unnecessary communication and computing overhead, and improves the verification efficiency of transactions and the overall performance of the blockchain system.

[0089] With the continuous development of quantum computing technology, traditional encryption algorithms and signature schemes will face increasing challenges. By introducing a post-quantum encryption algorithm, the embodiments of the present invention make preparations for the blockchain system in advance to cope with the era of quantum computing, ensuring the long-term security and stability of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0090] Figure 1 is a flowchart of the steps of an embodiment of a blockchain transaction method for resisting quantum attacks of the present invention;

[0091] Figure 2 is a flowchart of the steps of another embodiment of a blockchain transaction method for resisting quantum attacks of the present invention;

[0092] Figure 3 is a flowchart of the steps of another embodiment of a blockchain transaction method for resisting quantum attacks of the present invention;

[0093] Figure 4 is a schematic diagram of the transaction process of an embodiment of a blockchain transaction method for resisting quantum attacks of the present invention;

[0094] Figure 5 is a schematic diagram of the signature process of an embodiment of a blockchain transaction method for resisting quantum attacks of the present invention;

[0095] Figure 6 is a schematic diagram of the digital envelope encapsulation of an embodiment of a blockchain transaction method for resisting quantum attacks of the present invention;

[0096] Figure 7 is a schematic diagram of the core content of the digital envelope of an embodiment of a blockchain transaction method for resisting quantum attacks of the present invention;

[0097] Figure 8 It is a schematic diagram of the digital envelope explanation step of an embodiment of a blockchain transaction method against quantum attacks of the present invention;

[0098] Figure 9 It is a structural block diagram of an embodiment of a blockchain transaction device against quantum attacks of the present invention;

[0099] Figure 10 It is a structural block diagram of another embodiment of a blockchain transaction device against quantum attacks of the present invention. Detailed implementation manners

[0100] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific implementation manners.

[0101] With the development of quantum computing technology, traditional encryption algorithms such as RSA, ECC (Elliptic Curve Cryptography), etc. are facing the risk of being cracked by quantum computers. To address this challenge, PQC, namely Post-Quantum Cryptography algorithms, have emerged. PQC algorithms aim to study the security of cryptographic algorithms in a quantum environment and design cryptographic systems that are secure in both classical and quantum environments. PQC algorithms are not a specific algorithm but a general term for a series of algorithms.

[0102] One of the core concepts of the embodiments of the present invention is to improve the digital signature in the transaction process of the blockchain by using traditional asymmetric encryption combined with post-quantum encryption algorithms, so that the transaction process of the blockchain has the ability to resist quantum attacks and further ensures the transaction security of the blockchain.

[0103] Refer to Figure 2 , which shows the step flow chart of an embodiment of a blockchain transaction method against quantum attacks of the present invention, and specifically may include the following steps:

[0104] Step 101, obtain transaction data, a first encryption algorithm, and a second encryption algorithm; the first encryption algorithm includes an asymmetric encryption algorithm, and the second encryption algorithm includes a post-quantum encryption algorithm;

[0105] In this step, the transaction initiating node, such as node 1, prepares to initiate a transaction and obtains all the data related to the transaction. This data may include the amount of the transaction, the recipient address, the transaction timestamp, etc. Obtaining transaction data is the starting point of the transaction process to ensure the accuracy of the transaction content.

[0106] In addition, Node 1 needs to obtain and determine the first encryption algorithm to be used, namely the asymmetric encryption algorithm. The asymmetric encryption algorithm, also known as public-key cryptography, is an algorithm in cryptography. It requires the use of two keys: the public key and the private key. These two keys are mathematically related, but knowing the public key does not allow the derivation of the private key. The working principle of the asymmetric encryption algorithm is as follows: data is encrypted using the public key, and only the corresponding private key can decrypt it; conversely, data is encrypted using the private key, and only the corresponding public key can decrypt it.

[0107] At the same time, Node 1 also needs to obtain and determine the second encryption algorithm, namely the post-quantum encryption algorithm. The post-quantum encryption algorithm is a class of encryption algorithms designed specifically to resist attacks from quantum computers. Common post-quantum encryption algorithms include lattice-based algorithms, whose security is based on the intractability of certain problems in lattices, such as the shortest vector problem and the closest vector problem, etc. Hash-based algorithms: such as SPHINCS+. These algorithms utilize the irreversibility and uniqueness of hash functions to achieve the security of digital signatures. Code-based algorithms: These algorithms utilize concepts such as error-correcting codes and linear codes in coding theory to design encryption algorithms.

[0108] In one example, the first encryption algorithm is the SM2 algorithm, and the second encryption algorithm is the dilithium2 algorithm;

[0109] The SM2 algorithm is an asymmetric encryption algorithm released by the China National Cryptography Administration. It performs operations such as key exchange, digital signature, and public-key encryption based on elliptic curve cryptography (ECC). The SM2 algorithm has advantages in terms of security and performance. Especially at the same security level, its key length is shorter than that of the traditional RSA algorithm, and the operation speed is faster. In addition, the SM2 algorithm has become a national standard and industry standard in China and is widely used in various security applications.

[0110] Dilithium2 is actually a version or parameter set of Dilithium. Dilithium is a post-quantum digital signature algorithm based on lattice problems. It performed well in the NIST (National Institute of Standards and Technology) Post-Quantum Cryptography Algorithm Competition and finally became one of the three selected digital signature algorithms in the third round of NIST. The security of the Dilithium algorithm is based on the Learning with Errors over Lattices (LWE) problem and the Small Integer Solution (SIS) problem in lattices, which are considered intractable in the face of quantum computers. In the Dilithium series, there are multiple different parameter sets, named Dilithium2, Dilithium3, and Dilithium5 respectively. Their main differences lie in key size, signature size, and security level. Generally, higher versions (such as Dilithium3 or Dilithium5) offer higher security strength but also result in larger key and signature sizes. For example, the security of Dilithium2 is designed at the 128-bit security level, while Dilithium3 and Dilithium5 are at the 192-bit and 256-bit security levels respectively. This means that Dilithium2 attempts to balance performance and efficiency on the basis of providing sufficient security, making it more suitable for resource-constrained environments;

[0111] Step 102: Determine a first signature according to the first encryption algorithm and the transaction data;

[0112] Node 1 signs the transaction data using the first encryption algorithm to generate a first signature; the first signature is used to ensure the integrity and authenticity of the transaction data and prevent the data from being tampered with during transmission.

[0113] Step 103: Determine a second signature according to the second encryption algorithm and the first signature;

[0114] On the basis of the already generated first signature, Node 1 signs the first signature again using the second encryption algorithm to generate a second signature. The second signature provides an additional security layer, especially against possible future quantum computing attacks, enhancing the security of the transaction.

[0115] Step 104: Broadcast the second signature and the address of this node to the transaction receiving node, so that the transaction receiving node can obtain the first public key and the second public key from the public key storage server according to the address of this node to verify the signature and complete the transaction.

[0116] Node 1 broadcasts the transaction data containing the second signature and its own address to other nodes in the network, such as Node 2, 3, and 4. These receiving nodes obtain the corresponding public keys from the public key storage server according to the address of Node 1, and then use these two public keys to verify the two signatures in the transaction respectively. This step ensures that the recipient of the transaction can verify the authenticity and integrity of the transaction. Through the double-signature and double-verification mechanism, the security of the transaction is greatly improved.

[0117] The post-quantum encryption algorithm adopted in the embodiments of the present invention can effectively resist the attacks of quantum computers, especially against the threat of the Shor algorithm to public key cryptosystems such as elliptic curve cryptography (ECC). This means that even in the future when quantum computers are popularized, the embodiments of the present invention can ensure the security of digital signatures and transaction data in the blockchain system and are not easily cracked or forged. By first using an asymmetric encryption algorithm to generate the first signature and then using a post-quantum encryption algorithm to generate the second signature based on this signature, the embodiments of the present invention achieve the effect of double encryption. This layer-by-layer protection not only improves the security of the data but also increases the difficulty for attackers to crack the signature, thus more effectively protecting the transaction data and user assets in the blockchain system. In the embodiments of the present invention, the transaction receiving node only needs to obtain the corresponding first public key and second public key from the public key storage server according to the broadcast second signature and the node address for verification. This design simplifies the verification process, reduces unnecessary communication and computing overhead, and improves the verification efficiency of transactions and the overall performance of the blockchain system.

[0118] With the continuous development of quantum computing technology, traditional encryption algorithms and signature schemes will face increasing challenges. The embodiments of the present invention introduce a post-quantum encryption algorithm to prepare the blockchain system in advance for the quantum computing era, ensuring the long-term security and stability of the system.

[0119] Refer to Figure 2 , which shows the step flowchart of another embodiment of the blockchain transaction method for resisting quantum attacks of the present invention, and specifically may include the following steps:

[0120] Step 201, obtain transaction data, a first encryption algorithm, and a second encryption algorithm; the first encryption algorithm includes an asymmetric encryption algorithm, and the second encryption algorithm includes a post-quantum encryption algorithm;

[0121] In this step, the transaction initiating node, such as Node 1, prepares to initiate a transaction and obtains all the data related to this transaction. This data may include the amount of the transaction, the recipient address, the transaction timestamp, etc. Obtaining transaction data is the starting point of the transaction process to ensure the accuracy of the transaction content.

[0122] In addition, Node 1 needs to obtain and determine the first encryption algorithm to be used, namely the asymmetric encryption algorithm. The asymmetric encryption algorithm, also known as public-key cryptography, is an algorithm in cryptography. It requires the use of two keys: the public key and the private key. These two keys are mathematically related, but knowing the public key does not allow the derivation of the private key. The working principle of the asymmetric encryption algorithm is: encrypt data using the public key, and only the corresponding private key can decrypt it; conversely, encrypt data using the private key, and only the corresponding public key can decrypt it.

[0123] At the same time, Node 1 also needs to obtain and determine the second encryption algorithm, namely the post-quantum encryption algorithm. The post-quantum encryption algorithm is a class of encryption algorithms designed specifically to resist attacks by quantum computers. Common post-quantum encryption algorithms include lattice-based algorithms, whose security is based on the intractability of certain problems in lattices, such as the shortest vector problem and the closest vector problem, etc. Hash-based algorithms: such as SPHINCS+. These algorithms utilize the irreversibility and uniqueness of hash functions to achieve the security of digital signatures. Code-based algorithms: These algorithms utilize concepts such as error-correcting codes and linear codes in coding theory to design encryption algorithms.

[0124] In one example, the first encryption algorithm is the SM2 algorithm, and the second encryption algorithm is the dilithium2 algorithm;

[0125] The SM2 algorithm is an asymmetric encryption algorithm released by the China National Cryptography Administration. It performs operations such as key exchange, digital signature, and public-key encryption based on elliptic curve cryptography (ECC). The SM2 algorithm has advantages in terms of security and performance. Especially at the same security level, its key length is shorter than that of the traditional RSA algorithm, and the operation speed is faster. In addition, the SM2 algorithm has become a national standard and industry standard in China and is widely used in various security applications.

[0126] Dilithium2 is actually a version or parameter set of Dilithium. Dilithium is a post - quantum digital signature algorithm based on lattice problems. It performed well in the NIST (National Institute of Standards and Technology) post - quantum cryptography algorithm competition and finally became one of the three selected digital signature algorithms in the third round of NIST. The security of the Dilithium algorithm is based on the Learning with Errors over Lattices (LWE) problem and the Small Integer Solution (SIS) problem in lattices, which are considered intractable in the face of quantum computers. In the Dilithium series, there are multiple different parameter sets, named Dilithium2, Dilithium3, and Dilithium5 respectively. Their main differences lie in key size, signature size, and security level. Generally, higher versions (such as Dilithium3 or Dilithium5) provide higher security strength but also result in larger key and signature sizes. For example, the security of Dilithium2 is designed at the 128 - bit security level, while Dilithium3 and Dilithium5 are at the 192 - bit and 256 - bit security levels respectively. This means that Dilithium2 attempts to balance performance and efficiency on the basis of providing sufficient security, making it more suitable for resource - constrained environments;

[0127] Step 202: Determine a first signature according to the first encryption algorithm and the transaction data;

[0128] Node 1 uses the first encryption algorithm to sign the transaction data to generate a first signature; the first signature is used to ensure the integrity and authenticity of the transaction data and prevent the data from being tampered with during transmission.

[0129] Step 203: Obtain the hybrid signature encoding rule;

[0130] Determine how to combine the first signature with other information such as the transaction data itself, timestamp, other signatures, etc., and encode them into a unified hybrid signature encoding.

[0131] In one example, the hybrid signature encoding rule is to combine the first signature and the transaction data itself; the hybrid signature encoding rule can be stored in a preset encoding set, and when needed, the signature encoding rule defined for it is obtained according to business requirements and transaction data;

[0132] Step 204: Determine the hybrid signature encoding according to the first signature, the transaction data, and the hybrid signature encoding rule;

[0133] According to the hybrid signature encoding rules, the first signature and transaction data are combined and encoded into a unified hybrid signature encoding.

[0134] In one example, this process can be to combine the first signature and transaction data according to the provisions of the hybrid signature encoding rules, and convert them into a string or binary data that is easy to transmit and store through a specific encoding method; the encoding rules can be existing methods such as Base64 and Hex. Since encoding methods such as Base64 and Hex are existing technologies, they will not be elaborated here.

[0135] Step 205, determine the second signature according to the hybrid signature encoding and the second encryption algorithm;

[0136] Based on the already generated hybrid signature encoding, Node 1 uses the second encryption algorithm to sign the hybrid signature encoding again to generate the second signature. The second signature provides an additional security layer, especially against possible future quantum computing attacks, enhancing the security of the transaction.

[0137] In another example, the encoding method can also be DER (Distinguished Encoding Rules) encoding:

[0138] For the data format of digital signatures, the SM2 national standard (GM / T 0009-2012 Specification for the Use of SM2 Cryptographic Algorithm) has clear regulations. Usually, when using a hardware encryption machine to generate a digital signature, the signature usually adopts the DER encoding format of ASN.1 (Abstract Syntax Notation One); this encoding format is a coding rule for converting the data structure defined by ASN.1 into a binary format. DER encoding is a type of ASN.1 encoding, which ensures a unique encoding method for data, so it has been widely used in cryptography and data structures that require unique representation.

[0139] The encoding process can be:

[0140] After obtaining the first signature using the first encryption algorithm, the first signature and message data are simply concatenated according to the preset hybrid signature encoding rules, and then the second algorithm is used for secondary signature to generate the initial second signature; then, the first signature and the initial second signature are encoded using the DER encoding method according to the preset hybrid signature encoding rules to finally generate the second signature;

[0141] For example, SM2-PQC hybrid signature: [0x00,0x00,0x00,0x46] + SM2 signature (70 bytes) + PQC signature, where [0x00,0x00,0x00,0x46] indicates that the DER-encoded bytes of the SM2 signature data are the subsequent 70 bytes, and the remaining are the DER-encoded bytes of the PQC signature.

[0142] In one embodiment, step 203 may be: obtaining a hybrid signature hashing rule;

[0143] Obtain a hybrid signature hashing rule that defines how to combine the first signature and transaction data and process them through a hashing function to generate a fixed-length hash value. This hash value will be used to generate the second signature subsequently.

[0144] The hybrid signature hashing rule generally includes the sorting rule of the information to be hashed, the hashing functions to be used such as SHA-256, SHA-3, etc., and the length of the hash value, etc. These rules can be predefined, stored in the system or provided as configuration parameters. They may also be dynamically generated according to specific business requirements.

[0145] Step 204 may be: determining a hybrid signature hash value according to the first signature, the transaction data, and the hybrid signature hashing rule;

[0146] According to the hybrid signature hashing rule, combine the first signature, transaction data, and other relevant information and process them through a hashing function to generate a hybrid signature hash value.

[0147] According to the sorting rule defined in the hybrid signature hashing rule, combine the first signature, transaction data, etc. into an ordered information sequence. Use the combined information sequence as input and process it through the selected hashing function to generate a fixed-length hash value, i.e., the hybrid signature hash value.

[0148] Step 205 may be: determining the second signature according to the hybrid signature hash value and the second encryption algorithm.

[0149] Based on the already generated signature hash value, Node 1 uses the second encryption algorithm to sign the signature hash value again to generate the second signature. The second signature provides an additional security layer, especially against possible future quantum computing attacks, enhancing the security of the transaction.

[0150] By introducing a hash function and a second encryption algorithm, this embodiment not only ensures the integrity and authenticity of transaction data, but also provides stronger security through two-layer signatures. The hybrid signature hash value serves as an intermediate layer, which is both a digest of the original data and the basis for generating the second signature, thus effectively preventing data from being tampered with during transmission and storage.

[0151] In one embodiment,

[0152] Step 203 can also be: Obtain a hybrid signature encryption algorithm;

[0153] Obtain a hybrid signature encryption algorithm, which will be used to encrypt the combination of the first signature and transaction data to generate an encrypted hybrid signature. This encryption algorithm provides an additional security layer to ensure that the hybrid signature cannot be read or tampered with by unauthorized personnel during transmission or storage.

[0154] In one example, this encryption algorithm can be algorithms such as AES (Advanced Encryption Standard), RSA (asymmetric encryption algorithm), or other post-quantum encryption algorithms, and can be dynamically determined according to business needs.

[0155] Step 204 can also be: Determine the encrypted hybrid signature according to the first signature, the transaction data, and the hybrid signature encryption algorithm;

[0156] After combining the first signature and transaction data according to a preset combination rule, calculate according to the obtained encryption algorithm to obtain the encrypted hybrid signature;

[0157] Step 205 can also be: Determine the second signature according to the encrypted hybrid signature and the second encryption algorithm.

[0158] Based on the already generated encrypted hybrid signature, Node 1 uses the second encryption algorithm to sign the encrypted hybrid signature again to generate the second signature. The second signature provides an additional security layer, especially against possible future quantum computing attacks, enhancing the security of the transaction.

[0159] By introducing the hybrid signature encryption algorithm and the encrypted hybrid signature, this embodiment provides a higher level of security for transaction data. Even if an attacker can obtain the encrypted hybrid signature, without the correct decryption key and the private key of the second encryption algorithm, they cannot forge or tamper with the transaction data. This multi-layer encryption and signature strategy is an effective method for protecting sensitive data and ensuring transaction integrity.

[0160] Step 206: Broadcast the second signature and the address of this node to the transaction receiving node, so that the transaction receiving node can obtain the first public key and the second public key from the public key storage server according to the address of this node to verify the signature and complete the transaction.

[0161] Node 1 broadcasts the transaction data containing the second signature and its own address to other nodes in the network, such as Node 2, 3, and 4. These receiving nodes obtain the corresponding public keys from the public key storage server according to the address of Node 1, and then use these two public keys to verify the two signatures in the transaction respectively. This step ensures that the receiving party of the transaction can verify the authenticity and integrity of the transaction. Through the double-signature and double-verification mechanism, the security of the transaction is greatly improved.

[0162] The post-quantum encryption algorithm adopted in the embodiments of the present invention can effectively resist the attacks of quantum computers, especially against the threats of public-key cryptosystems such as the Shor algorithm to elliptic curve cryptography (ECC). This means that even in the future when quantum computers are popularized, the embodiments of the present invention can ensure the security of digital signatures and transaction data in the blockchain system and are not easily cracked or forged. By first using an asymmetric encryption algorithm to generate the first signature and then using a post-quantum encryption algorithm to generate the second signature based on this signature, the embodiments of the present invention achieve the effect of double encryption. This layer-by-layer protection not only improves the security of the data but also increases the difficulty for attackers to crack the signature, thus more effectively protecting the transaction data and user assets in the blockchain system. In the embodiments of the present invention, the transaction receiving node only needs to obtain the corresponding first public key and second public key from the public key storage server according to the broadcast second signature and the node address for verification. This design simplifies the verification process, reduces unnecessary communication and computing overhead, and improves the verification efficiency of transactions and the overall performance of the blockchain system.

[0163] With the continuous development of quantum computing technology, traditional encryption algorithms and signature schemes will face increasing challenges. The embodiments of the present invention introduce a post-quantum encryption algorithm to prepare the blockchain system in advance for the quantum computing era, ensuring the long-term security and stability of the system.

[0164] Refer to Figure 3 , which shows the step flowchart of another embodiment of the blockchain transaction method for resisting quantum attacks of the present invention, and specifically may include the following steps:

[0165] Step 301: Receive the second signature broadcast by the transaction initiating node and the address information of the transaction initiating node;

[0166] The transaction initiating node broadcasts the second signature it generates and its own address information, usually a hash value of a unique identifier or public key. Other nodes, especially those responsible for receiving transactions, listen for these broadcasts on the network and receive this information. This information serves as the basis for the transaction receiving node to subsequently verify the authenticity and integrity of the transaction.

[0167] Step 302, obtain the first public key and the second public key from the public key storage server according to the address information of the transaction initiating node;

[0168] Obtain the first public key and the second public key of the transaction initiating node, which are respectively used to verify the authenticity of the first signature and the second signature. The verification node sends a request to the public key storage server according to the address information of the transaction initiating node, requesting to obtain the corresponding first public key and second public key.

[0169] The public key storage server is a trusted third-party service that stores the public key information of all nodes in the network. It returns the corresponding first public key and second public key to the verification node according to the request.

[0170] In one example, the public key storage server can be deployed on the distributed storage Arweave, using the distributed storage Arweave as the storage backend to securely and reliably store the public key certificates of users. Arweave is a new blockchain storage platform that provides persistent and immutable data storage services for users through its Blockweave technology and native cryptocurrency.

[0171] In one example, the first public key and the second public key can also be obtained from the SM2-PQC certificates issued by the certificate issuance management system in the public key storage server;

[0172] The process of parsing the first public key and the second public key from the SM2-PQC certificate can be:

[0173] The structure of the SM2-PQC certificate can be represented as: [0x00,0x00,0x00,0x41] + SM2 public key byte array (65 bytes) + PQC public key byte array, where [0x00,0x00,0x00,0x41] indicates that the public key bytes of SM2 are the subsequent 65 bytes, and the rest are PQC public key bytes. Thus, the SM2 public key and the PQC public key can be parsed respectively.

[0174] In one embodiment, before signing the transaction data, the transaction initiating node first requests an SM2-PQC digital envelope and an SM2-PQC certificate from the certificate issuance management system in the public key storage server in a preset request format. By parsing the SM2-PQC digital envelope, the dilithium2 private key is obtained; after the parsing is completed, the SM2-PQC certificate is stored in the blockchain distributed storage Arweave through the public key storage server, where the preset request format can be in the form of a PKCS#10 Certificate Signing Request (CSR). PKCS#10 is a standard defined by the Public Key Infrastructure Working Group of the Internet Engineering Task Force and is used to describe the format of a certificate signing request. The CSR contains the applicant's public key and identity information, as well as some other attributes of the certificate such as the validity period and usage. After the applicant generates the CSR, it is sent to the certificate issuing authority. After the certificate issuing authority verifies the information in the request, it will sign the CSR with its own private key to generate a digital certificate.

[0175] Step 303, determine the first signature according to the second signature and the second public key;

[0176] The transaction receiving node uses the second public key obtained from the public key storage server to verify the received second signature. If the second signature verification passes, the verification node will parse the first signature from the second signature. This depends on the specific generation method of the second signature.

[0177] In one embodiment, the step 303 includes the following sub-steps:

[0178] Sub-step S11, obtain the hybrid signature encoding rule;

[0179] Obtain the rule of the hybrid signature. The hybrid signature encoding rule is an agreement formulated according to business needs, which defines how to combine different signatures or data elements into a hybrid signature and how to separate the original elements from this hybrid signature in the subsequent process.

[0180] The transaction receiving node can obtain these rules in one of the following ways: from the public key storage server, the smart contract on the blockchain, or the pre-configured parameters. The obtaining method can also be other specific methods formulated according to the business.

[0181] Sub-step S12, determine the hybrid signature encoding according to the second signature and the second public key;

[0182] Sub-step S13, determine the first signature according to the hybrid signature encoding and the hybrid signature encoding rule.

[0183] Using the hybrid signature encoding and the previously obtained hybrid signature encoding rules, extract the first signature from the hybrid signature. This embodiment can securely and accurately extract the first signature from a second signature containing hybrid information, and then verify the authenticity and integrity of the transaction data in subsequent steps. This design increases the flexibility and security of transaction verification.

[0184] In one embodiment, step 303 may further include the following sub-steps:

[0185] Sub-step S21, obtain the hybrid signature hash rule;

[0186] Obtain the hybrid signature hash rule. The hybrid signature encoding rule is an agreement formulated according to business needs, which defines how to combine different signatures or data elements into a hybrid signature and how to separate the original elements from this hybrid signature in subsequent processes.

[0187] The transaction receiving node can obtain these rules in one of the following ways: from the public key storage server, the smart contract on the blockchain, or the pre-configured parameters. The obtaining method can also be other specific methods formulated according to the business.

[0188] Sub-step S22, determine the hybrid signature hash value according to the second signature and the second public key;

[0189] Sub-step S23, determine the first signature according to the hybrid signature hash value and the hybrid signature hash rule.

[0190] During the signature verification process, it is necessary to determine the first signature according to the hybrid signature hash value and the preset hybrid signature hash rule. If the hash value does not conform to the preset verification rule, then the verification process will not be able to obtain a valid first signature, indicating that there may be a problem or tampering in the signature chain.

[0191] In this embodiment, the first signature is cleverly hidden in the hybrid signature hash value. Such a design not only enhances the complexity of transaction verification but also further improves the security of the data. Because even if the hybrid signature hash value is intercepted, without the corresponding hash rule, it is very difficult to extract the original first signature from it.

[0192] In one embodiment, step 303 may further include the following sub-steps:

[0193] Sub-step S31, obtain the hybrid signature encryption algorithm;

[0194] Obtain a hybrid signature encryption algorithm, which will be used to encrypt the combination of the first signature and the transaction data to generate an encrypted hybrid signature. This encryption algorithm provides an additional layer of security to ensure that the hybrid signature cannot be read or tampered with by unauthorized persons during transmission or storage.

[0195] In one example, this encryption algorithm can be algorithms such as AES (Advanced Encryption Standard), RSA (asymmetric encryption algorithm), etc., and can be dynamically determined according to business needs.

[0196] Sub-step S32, determine the encrypted hybrid signature according to the second signature and the second public key;

[0197] Sub-step S33, determine the first signature according to the encrypted hybrid signature and the hybrid signature encryption algorithm.

[0198] Step 304, determine the transaction data according to the first signature and the first public key;

[0199] By introducing the hybrid signature encryption algorithm and the encrypted hybrid signature, this embodiment provides a higher level of security for the transaction data. Even if an attacker can obtain the encrypted hybrid signature, without the correct decryption key and the private key of the second encryption algorithm, they cannot forge or tamper with the transaction data. This multi-layer encryption and signature strategy is an effective method for protecting sensitive data and ensuring transaction integrity.

[0200] The transaction receiving node uses the first public key obtained from the public key storage server to verify the extracted first signature. This process is similar to step 303, and the purpose is to confirm that the first signature is generated by the transaction initiating node using the corresponding private key to sign the transaction data.

[0201] Transaction data extraction: If the first signature verification passes, the verification node will parse the transaction data from the first signature. These data are the original information that the transaction initiating node hopes to broadcast and be verified in the network, and may include transfer amount, payee address, transaction time, etc.

[0202] Step 305, complete the transaction according to the transaction data.

[0203] In the previous steps, the authenticity and integrity of the transaction data have been verified at multiple levels. At this time, the transaction receiving node will execute corresponding transaction operations according to the instructions or information in the transaction data.

[0204] The post-quantum encryption algorithm adopted in the embodiments of the present invention can effectively resist the attacks of quantum computers, especially against the threat of the Shor algorithm to public key cryptosystems such as Elliptic Curve Cryptography (ECC). This means that even in the future when quantum computers are popularized, the embodiments of the present invention can ensure the security of digital signatures and transaction data in the blockchain system and prevent them from being easily cracked or forged. By first using an asymmetric encryption algorithm to generate a first signature and then using a post-quantum encryption algorithm to generate a second signature based on this signature, the embodiments of the present invention achieve the effect of double encryption. This layer-by-layer protection not only improves the security of data but also increases the difficulty for attackers to crack the signature, thus more effectively protecting the transaction data and user assets in the blockchain system. In the embodiments of the present invention, the transaction receiving node only needs to obtain the corresponding first public key and second public key from the public key storage server according to the broadcast second signature and the node address for verification. This design simplifies the verification process, reduces unnecessary communication and computing overhead, and improves the verification efficiency of transactions and the overall performance of the blockchain system.

[0205] With the continuous development of quantum computing technology, traditional encryption algorithms and signature schemes will face increasing challenges. The embodiments of the present invention introduce a post-quantum encryption algorithm to prepare the blockchain system in advance for the quantum computing era and ensure the long-term security and stability of the system.

[0206] Refer to Figure 4 , which shows a schematic diagram of the transaction process of an embodiment of a blockchain transaction method against quantum attacks of the present invention;

[0207] The figure consists of several blockchain nodes, namely Node 1, Node 2, Node 3, Node 4, a public key storage server, and a blockchain distributed storage protocol, which is used to guide how to perform the distributed storage of the blockchain;

[0208] The transaction cycle is divided into two steps;

[0209] First, in the first step, the transaction initiating node, namely Node 1, initiates a transaction request; among them, the signature method proposed in the embodiments of the present invention is to use a first encryption algorithm and a second encryption algorithm for double signature. Specifically, the first encryption algorithm is the SM2 algorithm, and the second encryption algorithm is the Dilithiun algorithm; then the message with the signature data added is broadcast to Nodes 2, 3, and 4 in the network.

[0210] The second step is to request the public key and verification. After receiving the transaction sent by node 1, nodes 2, 3, and 4 send the address in the transaction to the public key storage server. The public key storage server obtains the user's digital certificate and public key information from the blockchain distributed storage. Nodes 2, 3, and 4 perform signature verification based on the public key sent by the public key storage server, that is, obtain the SM2 public key in the mixed public key to verify the SM2 signature in the signature, and obtain the Dilithiun public key in the mixed public key to verify the Dilithiun signature. If both verification results pass, it is determined that the transaction was indeed sent by node 1 itself and has not been modified during the propagation process.

[0211] Refer to Figure 5 , which shows a schematic diagram of the signature process of an embodiment of a blockchain transaction method against quantum attacks of the present invention;

[0212] The mixed signature key part contains two types of keys:

[0213] SM2 signature key: Specifically used for signature generation and verification under the SM2 algorithm. PQC signature key: Then for post-quantum cryptography, used to generate and verify its specific signature.

[0214] First, the message data is signed using the SM2 algorithm to obtain the SM2 digital signature;

[0215] Then the message data is concatenated to the SM2 digital signature again, and the PQC signature is performed using the Dilithium2 algorithm to obtain the PQC mixed digital signature;

[0216] Finally, the SM2 digital signature and the PQC mixed digital signature are re-encoded using a preset encoding rule and in the way of DER encoding, and finally the SM2-PQC mixed digital signature is generated.

[0217] Refer to Figure 6 , which shows a schematic diagram of the digital envelope encapsulation of an embodiment of a blockchain transaction method against quantum attacks of the present invention;

[0218] Before the user (transaction initiating node) performs information signature, it is necessary to first obtain the post-quantum encryption private key, and then use the post-quantum encryption private key for subsequent post-quantum encryption algorithm signatures, that is, obtain the encryption private key of the second encryption algorithm, and then generate an overlapping signature according to the encryption private key, the second encryption algorithm, and the first signature. One of the implementation methods for obtaining the post-quantum encryption private key is as Figure 6 shown, that is, obtaining the post-quantum private key in the form of a digital envelope.

[0219] First, the user generates their first user public key (SM2 public key) and second user public key (Kyber768 public key), which will be used for subsequent encryption and digital certificate issuance. After generating the two public keys, the user sends an application to the certificate issuance module, and at the same time, the key generation module generates a dilithium2 private key and sends it to the certificate issuance module. After receiving the application and the dilithium2 private key, the certificate issuance module generates a random number randomA, and uses this random number to encrypt the generated dilithium2 private key in the SM4 / ECB (Electronic Codebook) mode to obtain the ciphertext A of the dilithium2 private key.

[0220] Using the Kyber768 public key of the applicant (user), a 32-byte session key is generated based on a preset lattice problem algorithm, and a ciphertext B of variable length is generated based on this.

[0221] Take the first 16 bytes of the session key to obtain a random number E. At the same time, the Certificate Authority (CA) generates a random number randomB, and performs an XOR (Exclusive OR) operation on randomB and the previously obtained random number E to obtain a new random number randomD.

[0222] Then use randomD to encrypt the original randomA plaintext in the SM4 / ECB mode to obtain a 16-byte ciphertext C.

[0223] Furthermore, use the user's SM2 public key to encrypt randomB in the SM4 / ECB mode to obtain an 180-byte ciphertext D.

[0224] Finally, concatenate the 180-byte ciphertext D, the variable-length ciphertext B, and the 16-byte ciphertext C together to form the final ciphertext E. Protect the ciphertext A of the dilithium2 private key and the concatenated ciphertext E together through an encryption protection structure such as ECC.

[0225] The finally generated digital certificate contains the user's SM2 public key, Kyber768 public key, the ciphertext of the dilithium2 private key, and other possible information. These steps ensure the security of the data and the reliability of the certificate.

[0226] Kyber768 is a post - quantum encryption algorithm based on lattice cryptography. Lattice cryptography is a class of cryptographic methods based on the lattice theory in mathematics, and they are considered to be able to resist attacks from quantum computers. In Kyber768, the key encapsulation mechanism allows two communicating parties to generate a shared symmetric key, which can then be used to encrypt and decrypt data. This process is secure even in the case of the emergence of future quantum computers.

[0227] SM4 is a block cipher algorithm issued by the China National Cryptography Administration, also known as "China Commercial Cryptography Algorithm SM4". It is a type of symmetric encryption algorithm, which means that the encryption and decryption processes use the same key. The SM4 algorithm uses a 128 - bit key and a 128 - bit block length, and realizes data encryption and decryption through 32 rounds of encryption operations. Its design goal is to provide high security, high efficiency and high availability.

[0228] The ECB mode is one of the simplest block cipher operating modes. It divides the plaintext into blocks of a fixed size and encrypts each block independently. In the ECB mode, the same plaintext block will be encrypted into the same ciphertext block.

[0229] The exclusive - OR operation is a special logical operation, and its result depends on the comparison of two input bits: if the two input bits are the same, the output is 0; if they are different, the output is 1. This operation has wide applications in computer science and digital circuits, especially in areas such as bit operations, data encryption and error detection.

[0230] ECC is a public - key encryption system based on the algebraic structure of elliptic curves over finite fields. It provides security comparable to RSA, but with a much shorter key length, thus achieving faster computing speed and lower resource utilization. The protection structure of the ECC encryption key pair involves multiple aspects such as key generation, storage, distribution and management;

[0231] The entire process realizes the complete process from the generation of user public and private keys to data encryption and digital certificate issuance by combining multiple encryption algorithms such as SM4, dilithium2, Kyber, etc. and key exchange technologies.

[0232] Refer to Figure 7 And Figure 8 , respectively show the schematic diagram of the core content of the digital envelope of an embodiment of a blockchain transaction method resistant to quantum attacks of the present invention and the schematic diagram of the digital envelope parsing steps of an embodiment of a blockchain transaction method resistant to quantum attacks of the present invention;

[0233] In the embodiments of the present invention, the core content of the digital envelope includes ciphertext A, the public key information of the encryption key pair, and ciphertext E. Among them, ciphertext A is the ciphertext that needs to be finally decrypted, and it contains the encrypted form of the dilithium2 private key; the public key information of the encryption key pair includes the SM2 public key and the Kyber768 public key, and these public keys are used in the subsequent decryption process to ensure that only users holding the corresponding private keys can decrypt the corresponding ciphertexts. And ciphertext E is a ciphertext containing a symmetric key, which will be used to decrypt other ciphertexts in the subsequent steps.

[0234] As Figure 8 shown, a parsing process of the digital envelope can be:

[0235] First, obtain ciphertext E, take the first 180 bytes of it, and then decrypt it using the SM2 private key to obtain plaintext B.

[0236] Then, intercept the middle part from ciphertext E, which can be from 180 bytes after to 16 bytes before the last to obtain ciphertext B, and then decrypt it using the Kyber768 private key to finally obtain plaintext C.

[0237] After obtaining plaintext C, perform an exclusive OR operation on the first 16 bytes of plaintext C and 16 bytes of plaintext B to obtain 16 - byte symmetric key D.

[0238] Intercept the part before the last 16 bytes from ciphertext E to obtain ciphertext C, and then decrypt it using symmetric key D in SM4 (ECB mode) to obtain ciphertext A.

[0239] Finally, decrypt the private key ciphertext A of the encryption key pair using ciphertext A in SM4 (ECB mode) to finally obtain the issued dilithium2 private key.

[0240] The entire process starts with the message data, performs operations through different signature keys, and finally generates and stores the corresponding signature value, thereby ensuring the security and reliability of the data. The hybrid signature system provides double protection for data security by combining SM2 and PQC technologies.

[0241] It should be noted that for the method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of the present invention are not limited by the described action sequence, because according to the embodiments of the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential for the embodiments of the present invention.

[0242] Referring to Figure 9, showing a structural block diagram of an embodiment of a blockchain transaction device resistant to quantum attacks according to the present invention, which may specifically include the following modules:

[0243] A transaction data acquisition module 401, configured to acquire transaction data, a first encryption algorithm, and a second encryption algorithm; the first encryption algorithm includes an asymmetric encryption algorithm, and the second encryption algorithm includes a post-quantum encryption algorithm;

[0244] A first signature determination module 402, configured to determine a first signature according to the first encryption algorithm and the transaction data;

[0245] A second signature determination module 403, configured to determine a second signature according to the second encryption algorithm and the first signature;

[0246] A data broadcast module 404, configured to broadcast the second signature and the address of the local node to a transaction receiving node, so that the transaction receiving node can obtain a first public key and a second public key from a public key storage server according to the address of the local node to verify the signature and complete the transaction.

[0247] In one embodiment, the second signature determination module includes:

[0248] A first encoding rule acquisition sub-module, configured to acquire a hybrid signature encoding rule;

[0249] A first hybrid encoding acquisition sub-module, configured to determine a hybrid signature encoding according to the first signature, the transaction data, and the hybrid signature encoding rule;

[0250] A first encoding signature acquisition sub-module, configured to determine the second signature according to the hybrid signature encoding and the second encryption algorithm.

[0251] In one embodiment, the second signature determination module includes:

[0252] A first hash rule acquisition sub-module, configured to acquire a hybrid signature hash rule;

[0253] A first hybrid hash acquisition sub-module, configured to determine a hybrid signature hash value according to the first signature, the transaction data, and the hybrid signature hash rule;

[0254] A first hash signature acquisition sub-module, configured to determine the second signature according to the hybrid signature hash value and the second encryption algorithm.

[0255] In one embodiment, the second signature determination module includes:

[0256] A first encryption algorithm acquisition sub-module, configured to acquire a hybrid signature encryption algorithm;

[0257] The first hybrid encryption acquisition sub-module is used to determine an encrypted hybrid signature according to the first signature, the transaction data, and the hybrid signature encryption algorithm.

[0258] The first hybrid encryption acquisition sub-module is used to determine the second signature according to the encrypted hybrid signature and the second encryption algorithm.

[0259] The post-quantum encryption algorithm adopted in the embodiments of the present invention can effectively resist the attacks of quantum computers, especially against the threats of public-key cryptosystems such as the elliptic curve cryptography (ECC) by the Shor algorithm. This means that even in the future when quantum computers are popularized, the embodiments of the present invention can ensure the security of digital signatures and transaction data in the blockchain system, and they will not be easily cracked or forged. By first using an asymmetric encryption algorithm to generate the first signature and then using a post-quantum encryption algorithm to generate the second signature based on this signature, the embodiments of the present invention achieve the effect of double encryption. This layer-by-layer protection not only improves the security of data but also increases the difficulty for attackers to crack the signature, thereby more effectively protecting the transaction data and user assets in the blockchain system. In the embodiments of the present invention, the transaction receiving node only needs to obtain the corresponding first public key and second public key from the public key storage server according to the broadcast second signature and the node address for verification. This design simplifies the verification process, reduces unnecessary communication and computing overhead, and improves the verification efficiency of transactions and the overall performance of the blockchain system.

[0260] With the continuous development of quantum computing technology, traditional encryption algorithms and signature schemes will face increasing challenges. The embodiments of the present invention introduce a post-quantum encryption algorithm to prepare the blockchain system in advance for the quantum computing era, ensuring the long-term security and stability of the system.

[0261] The embodiments of the present invention also provide a blockchain transaction system resistant to quantum attacks. The system includes a transaction initiation node, which is used to obtain transaction data, a first encryption algorithm, and a second encryption algorithm; the first encryption algorithm includes an asymmetric encryption algorithm, and the second encryption algorithm includes a post-quantum encryption algorithm; obtain transaction data, a first encryption algorithm, and a second encryption algorithm; the first encryption algorithm includes an asymmetric encryption algorithm, and the second encryption algorithm includes a post-quantum encryption algorithm; determine a first signature according to the first encryption algorithm and the transaction data; determine a second signature according to the second encryption algorithm and the first signature; broadcast the second signature and the address of this node to the transaction receiving node, so that the transaction receiving node obtains the first public key and the second public key from the public key storage server according to the address of this node to verify the signature and complete the transaction.

[0262] A transaction receiving node, configured to receive a second signature and the address information of the transaction initiating node broadcast by the transaction initiating node; obtain a first public key and a second public key from a public key storage server according to the address information of the transaction initiating node. Determine a first signature according to the second signature and the second public key; determine transaction data according to the first signature and the first public key; complete the transaction according to the transaction data.

[0263] In one embodiment, the transaction initiating node is configured to obtain a hybrid signature encoding rule; determine a hybrid signature encoding according to the first signature, the transaction data, and the hybrid signature encoding rule; determine the second signature according to the hybrid signature encoding and the second encryption algorithm;

[0264] The transaction receiving node is configured to obtain a hybrid signature encoding rule; determine a hybrid signature encoding according to the second signature and the second public key; determine the first signature according to the hybrid signature encoding and the hybrid signature encoding rule.

[0265] In one embodiment, the transaction initiating node is configured to obtain a hybrid signature hashing rule; determine a hybrid signature hash value according to the first signature, the transaction data, and the hybrid signature hashing rule; determine the second signature according to the hybrid signature hash value and the second encryption algorithm;

[0266] The transaction receiving node is configured to obtain a hybrid signature hashing rule; determine a hybrid signature hash value according to the second signature and the second public key; determine the first signature according to the hybrid signature hash value and the hybrid signature hashing rule.

[0267] In one embodiment, the transaction initiating node is configured to obtain a hybrid signature encryption algorithm; determine an encrypted hybrid signature according to the first signature, the transaction data, and the hybrid signature encryption algorithm; determine the second signature according to the encrypted hybrid signature and the second encryption algorithm;

[0268] The transaction receiving node is configured to obtain a hybrid signature encryption algorithm; determine an encrypted hybrid signature according to the second signature and the second public key; determine the first signature according to the encrypted hybrid signature and the hybrid signature encryption algorithm.

[0269] The post-quantum encryption algorithm adopted in the embodiments of the present invention can effectively resist the attacks of quantum computers, especially against the threats of public-key cryptosystems such as elliptic curve cryptography (ECC) by the Shor algorithm. This means that even in the future when quantum computers are popularized, the embodiments of the present invention can ensure the security of digital signatures and transaction data in the blockchain system, and they cannot be easily cracked or forged. By first using an asymmetric encryption algorithm to generate a first signature and then using a post-quantum encryption algorithm to generate a second signature based on this signature, the embodiments of the present invention achieve the effect of double encryption. This layer-by-layer protection not only improves the security of data but also increases the difficulty for attackers to crack the signature, thereby more effectively protecting the transaction data and user assets in the blockchain system. In the embodiments of the present invention, the transaction receiving node only needs to obtain the corresponding first public key and second public key from the public key storage server according to the broadcast second signature and the node address for verification. This design simplifies the verification process, reduces unnecessary communication and computing overheads, and improves the verification efficiency of transactions and the overall performance of the blockchain system.

[0270] With the continuous development of quantum computing technology, traditional encryption algorithms and signature schemes will face increasing challenges. The embodiments of the present invention introduce a post-quantum encryption algorithm to prepare the blockchain system in advance for the quantum computing era, ensuring the long-term security and stability of the system.

[0271] Refer to Figure 10 , which shows the structural block diagram of another embodiment of the blockchain transaction device against quantum attacks of the present invention, and specifically may include the following modules:

[0272] A transaction data receiving module 501, configured to receive the second signature broadcast by the transaction initiating node and the address information of the transaction initiating node;

[0273] A signature public key receiving module 502, configured to obtain the first public key and the second public key from the public key storage server according to the address information of the transaction initiating node;

[0274] A first signature determining module 503, configured to determine the first signature according to the second signature and the second public key;

[0275] A transaction data determining module 504, configured to determine the transaction data according to the first signature and the first public key;

[0276] A transaction completion module 505, configured to complete the transaction according to the transaction data.

[0277] In one embodiment, the first signature determining module includes:

[0278] A second coding rule obtaining sub-module, configured to obtain the hybrid signature coding rule;

[0279] A second mixed coding acquisition sub-module, configured to determine a mixed signature code according to the second signature and the second public key;

[0280] A first signature acquisition sub-module, configured to determine a first signature according to the mixed signature code and the mixed signature coding rule.

[0281] In one embodiment, the first signature determination module includes:

[0282] A second hash rule acquisition sub-module, configured to acquire a mixed signature hash rule;

[0283] A second mixed hash acquisition sub-module, configured to determine a mixed signature hash value according to the second signature and the second public key;

[0284] A second signature acquisition sub-module, configured to determine a first signature according to the mixed signature hash value and the mixed signature hash rule.

[0285] In one embodiment, the first signature determination module includes:

[0286] A second encryption algorithm acquisition sub-module, configured to acquire a mixed signature encryption algorithm;

[0287] A second mixed encryption acquisition sub-module, configured to determine an encrypted mixed signature according to the second signature and the second public key;

[0288] A second signature acquisition sub-module, configured to determine a first signature according to the encrypted mixed signature and the mixed signature encryption algorithm.

[0289] The post-quantum encryption algorithm adopted in the embodiments of the present invention can effectively resist the attacks of quantum computers, especially against the threats of public-key cryptosystems such as the Elliptic Curve Cryptography (ECC) by the Shor algorithm. This means that even in the future when quantum computers are popularized, the embodiments of the present invention can ensure the security of digital signatures and transaction data in the blockchain system, and they will not be easily cracked or forged. By first using an asymmetric encryption algorithm to generate a first signature and then using a post-quantum encryption algorithm to generate a second signature based on this signature, the embodiments of the present invention achieve the effect of double encryption. This layer-by-layer protection not only improves the security of data but also increases the difficulty for attackers to crack the signature, thus more effectively protecting the transaction data and user assets in the blockchain system. In the embodiments of the present invention, the transaction receiving node only needs to obtain the corresponding first public key and second public key from the public key storage server according to the broadcast second signature and the node address for verification. This design simplifies the verification process, reduces unnecessary communication and computing overheads, and improves the verification efficiency of transactions and the overall performance of the blockchain system.

[0290] With the continuous development of quantum computing technology, traditional encryption algorithms and signature schemes will face increasing challenges. By introducing post-quantum encryption algorithms in the embodiments of the present invention, the blockchain system is well-prepared to cope with the quantum computing era, ensuring the long-term security and stability of the system.

[0291] For the device embodiments, since they are basically similar to the method embodiments, they are described relatively simply. For the relevant parts, refer to the partial descriptions of the method embodiments.

[0292] The embodiments of the present invention also provide an electronic device, including:

[0293] It includes a processor, a memory, and a computer program stored on the memory and capable of running on the processor. When the computer program is executed by the processor, it implements each process of the above-mentioned method embodiment of a blockchain transaction method resistant to quantum attacks and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.

[0294] The embodiments of the present invention also provide a computer-readable storage medium with a computer program stored thereon. When the computer program is executed by the processor, it implements each process of the above-mentioned method embodiment of a blockchain transaction method resistant to quantum attacks and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.

[0295] Each embodiment in this specification is described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the embodiments, refer to each other.

[0296] Those skilled in the art should understand that the embodiments of the present invention can be provided as methods, devices, or computer program products. Therefore, the embodiments of the present invention can take the form of completely hardware embodiments, completely software embodiments, or embodiments combining software and hardware aspects. Moreover, the embodiments of the present invention can take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.

[0297] Embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal devices generate means for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or in multiple blocks.

[0298] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means implements the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or in multiple blocks.

[0299] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device, so that a series of operation steps are executed on the computer or other programmable terminal device to generate a computer-implemented process. Therefore, the instructions executed on the computer or other programmable terminal device provide steps for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or in multiple blocks.

[0300] Although the preferred embodiments of the embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications to these embodiments once they know the basic creative concepts. Therefore, the appended claims are intended to be construed as including the preferred embodiments and all changes and modifications falling within the scope of the embodiments of the present invention.

[0301] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or terminal device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or terminal device comprising said element.

[0302] The above has introduced in detail a blockchain transaction method, device, equipment and medium resistant to quantum attacks provided by the present invention. Specific examples are used in this text to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation of the present invention.

Claims

1. A blockchain transaction method resistant to quantum attacks, characterized in that: Applied to a transaction initiating node, the method comprises: Acquire transaction data, a first encryption algorithm, and a second encryption algorithm; wherein the first encryption algorithm includes an asymmetric encryption algorithm, and the second encryption algorithm includes a post-quantum encryption algorithm; Determining a first signature according to the first encryption algorithm and the transaction data; Determine a second signature according to the second encryption algorithm and the first signature; The second signature and the address of the current node are broadcasted to the transaction receiving node, so that the transaction receiving node obtains the first public key and the second public key from the public key storage server according to the address of the current node to verify the signature and complete the transaction.

2. The method according to claim 1, characterized in that The determining the second signature according to the second encryption algorithm and the first signature includes: Get the hybrid signature encoding rules; Determine a hybrid signature code according to the first signature, the transaction data, and the hybrid signature coding rule; The second signature is determined according to the hybrid signature encoding and the second encryption algorithm.

3. The method according to claim 1, characterized in that The determining the second signature according to the second encryption algorithm and the first signature includes: Get the hybrid signature hash rule; Determine a hybrid signature hash value according to the first signature, the transaction data, and the hybrid signature hash rule; The second signature is determined according to the hybrid signature hash value and the second encryption algorithm.

4. The method according to claim 1, characterized in that: The determining the second signature according to the second encryption algorithm and the first signature includes: Get the hybrid signature encryption algorithm; Determine an encrypted hybrid signature according to the first signature, the transaction data, and the hybrid signature encryption algorithm; The second signature is determined according to the encrypted hybrid signature and the second encryption algorithm.

5. A blockchain transaction method resistant to quantum attacks, characterized in that: Applied to a transaction receiving node, the method comprises: Receiving a second signature broadcasted by a transaction initiating node and address information of the transaction initiating node; Obtaining a first public key and a second public key from a public key storage server according to the address information of the transaction initiating node; Determine the first signature according to the second signature and the second public key; Determine transaction data according to the first signature and the first public key; The transaction is completed according to the transaction data.

6. The method according to claim 5, characterized in that The determining the first signature according to the second signature and the second public key includes: Get the hybrid signature encoding rules; Determine a mixed signature code according to the second signature and the second public key; A first signature is determined according to the hybrid signature encoding and the hybrid signature encoding rule.

7. The method according to claim 5, characterized in that The determining the first signature according to the second signature and the second public key includes: Get the hybrid signature hash rule; Determine a mixed signature hash value according to the second signature and the second public key; A first signature is determined according to the hybrid signature hash value and the hybrid signature hash rule.

8. The method according to claim 5, characterized in that The determining the first signature according to the second signature and the second public key includes: Get the hybrid signature encryption algorithm; Determine an encrypted mixed signature according to the second signature and the second public key; A first signature is determined according to the encrypted hybrid signature and the hybrid signature encryption algorithm.

9. A blockchain transaction system resistant to quantum attacks, characterized in that: The system includes a transaction initiating node, which is used to obtain transaction data, a first encryption algorithm and a second encryption algorithm; the first encryption algorithm includes an asymmetric encryption algorithm, and the second encryption algorithm includes a post-quantum encryption algorithm; obtain transaction data, a first encryption algorithm and a second encryption algorithm; the first encryption algorithm includes an asymmetric encryption algorithm, and the second encryption algorithm includes a post-quantum encryption algorithm; determine a first signature according to the first encryption algorithm and the transaction data; determine a second signature according to the second encryption algorithm and the first signature; broadcast the second signature and the address of the current node to the transaction receiving node, so that the transaction receiving node obtains the first public key and the second public key from the public key storage server according to the address of the current node to verify the signature and complete the transaction; A transaction receiving node, used to receive the second signature broadcasted by the transaction initiating node and the address information of the transaction initiating node; Obtaining a first public key and a second public key from a public key storage server according to the address information of the transaction initiating node; Determine the first signature based on the second signature and the second public key; determine the transaction data based on the first signature and the first public key; and complete the transaction based on the transaction data.

10. The system according to claim 9, characterized in that The transaction initiating node is used to obtain a hybrid signature encoding rule; determine the hybrid signature encoding according to the first signature, the transaction data, and the hybrid signature encoding rule; Determine the second signature according to the hybrid signature code and the second encryption algorithm; The transaction receiving node is used to obtain a hybrid signature encoding rule; and determine the hybrid signature encoding according to the second signature and the second public key; A first signature is determined according to the hybrid signature encoding and the hybrid signature encoding rule.

11. The system according to claim 9, characterized in that The transaction initiating node is used to obtain a hybrid signature hash rule; determine a hybrid signature hash value according to the first signature, the transaction data, and the hybrid signature hash rule; determine the second signature according to the hybrid signature hash value and the second encryption algorithm; The transaction receiving node is used to obtain a mixed signature hash rule; and determine a mixed signature hash value according to the second signature and the second public key; A first signature is determined according to the hybrid signature hash value and the hybrid signature hash rule.

12. The system according to claim 9, characterized in that The transaction initiating node is used to obtain a hybrid signature encryption algorithm; determine an encrypted hybrid signature according to the first signature, the transaction data, and the hybrid signature encryption algorithm; determine the second signature according to the encrypted hybrid signature and the second encryption algorithm; The transaction receiving node is used to obtain a hybrid signature encryption algorithm; determine the encrypted hybrid signature according to the second signature and the second public key; and determine the first signature according to the encrypted hybrid signature and the hybrid signature encryption algorithm.

13. A blockchain transaction device resistant to quantum attacks, characterized in that: Applied to a transaction initiation node, the device comprises: A transaction data acquisition module, used to acquire transaction data, a first encryption algorithm and a second encryption algorithm; the first encryption algorithm includes an asymmetric encryption algorithm, and the second encryption algorithm includes a post-quantum encryption algorithm; A first signature determination module, configured to determine a first signature according to the first encryption algorithm and the transaction data; A second signature determination module, configured to determine a second signature according to the second encryption algorithm and the first signature; The data broadcast module is used to broadcast the second signature and the address of the current node to the transaction receiving node, so that the transaction receiving node obtains the first public key and the second public key from the public key storage server according to the address of the current node to verify the signature and complete the transaction.

14. A blockchain transaction device resistant to quantum attacks, characterized in that: Applied to a transaction receiving node, the device comprises: A transaction data receiving module, used to receive the second signature broadcasted by the transaction initiating node and the address information of the transaction initiating node; A signature public key receiving module, used to obtain the first public key and the second public key from the public key storage server according to the address information of the transaction initiating node; A first signature determining module, configured to determine a first signature according to the second signature and the second public key; a transaction data determination module, configured to determine transaction data according to the first signature and the first public key; The transaction completion module is used to complete the transaction according to the transaction data.

15. An electronic device, characterized in that: include: A processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein when the computer program is executed by the processor, the steps of a quantum attack-resistant blockchain transaction method as described in any one of claims 1-4 or 5-8 are implemented.

16. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of a blockchain transaction method resistant to quantum attacks as described in any one of claims 1-4 or 5-8 are implemented.