Block chain transaction retrieval method and device
By predetermining the generated group of generics in the blockchain and using the bilinear mapping function to verify transaction attributes, the problem of broker nodes leaking user private keys is solved, and the security of blockchain transaction retrieval is improved.
Patent Information
- Application Number
- CN202510371415.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-07-01
AI Technical Summary
When the prior art performs blockchain transaction retrieval based on hidden addresses through proxy nodes, there is a problem of user real key leakage, resulting in the leakage of user privacy data and reducing the security of transaction retrieval.
By pre-determining the groups generated by the first and second generation elements in the blockchain, the bilinear mapping function is used to verify transaction ownership, avoid direct leakage of user private keys, and improve the security of transaction retrieval.
Without revealing the original private key of the user, verifying transaction ownership through the proxy node improves the security of blockchain transaction retrieval and prevents the leakage of user privacy data.
Smart Images

Figure CN120238276A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this specification belong to the field of blockchain technology, and more particularly to a blockchain transaction retrieval method and device. Background Art
[0002] Blockchain is a new application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, encryption algorithm, etc. In the blockchain system, data blocks are combined into a chain data structure in a sequential manner according to time order, and a distributed ledger that cannot be tampered with or forged is guaranteed by cryptography. Due to the characteristics of blockchain such as decentralization, information cannot be tampered with, and autonomy, blockchain has also received more and more attention and has been widely used in many fields. Summary of the invention
[0003] The purpose of the present invention is to provide a blockchain transaction retrieval method and device, which can prevent the leakage of user privacy data caused by the leakage of user real keys by proxy nodes when performing blockchain transaction retrieval based on stealth addresses through proxy nodes, improve the security of blockchain transaction retrieval based on stealth addresses through proxy nodes, and solve the shortcomings of the prior art.
[0004] To achieve the above-mentioned purpose, the first aspect of the present specification provides a blockchain transaction retrieval method, in which a first group generated by a first generator, a second group generated by a second generator, and a third group are predetermined in the blockchain, and the elements in the first group and the second group are mapped to the third group based on a preset bilinear mapping function; and the public key of the participant of the blockchain is predetermined based on the private key of the participant of the blockchain and the first generator, and the method comprises: the first party among the participants of the blockchain determines a first value belonging to the second group according to the second generator, and determines a second value belonging to the second group according to the private key of the party and the second generator; sends the first value and the second value to a proxy node; the second party among the participants of the blockchain determines a third value belonging to the first group according to the first generator, and determines a fourth value belonging to the first group according to the public key of the recipient; sends a first transaction according to the target hidden address of the recipient represented by the third value and the fourth value; the proxy node obtains the first transaction, and verifies the first value, the second value, the third value and the fourth value based on the bilinear mapping function to determine whether the first transaction is a transaction sent to the first party.
[0005] A second aspect of the specification provides a computing device, including: a processor; and a memory, wherein a program is stored, and when the processor executes the executable code, the method described in the first aspect is implemented.
[0006] In the blockchain transaction retrieval solution provided in the embodiments of this specification, in this blockchain, a first group and a second group respectively generated by a first generator and a second generator can be determined in advance. The elements in the first group and the second group are mapped to a third group based on a preset bilinear mapping function, and the participant public key is generated in advance according to the participant private key and the first generator. Thus, the first party among the blockchain participants can determine a first value belonging to the second group according to the second generator, and determine a second value belonging to the second group according to its own private key and the second generator; and send the first value and the second value to the proxy node. The second party among the blockchain participants can determine a third value belonging to the first group according to the first generator, and determine a fourth value belonging to the first group according to the recipient public key; and send a first transaction according to the recipient's hidden address represented by the third value and the fourth value. Furthermore, the proxy node can obtain the first transaction, and verify the first value, the second value, the third value and the fourth value based on the bilinear mapping function to determine whether the first transaction is a transaction sent to the first party. Through this method, in the case of retrieving blockchain transactions based on hidden addresses through a proxy node, it is possible to prevent the leakage of user privacy data caused by the leakage of the user's real key by the proxy node, and improve the security of retrieving blockchain transactions based on hidden addresses through the proxy node. BRIEF DESCRIPTION OF THE DRAWINGS
[0007] In order to more clearly illustrate the technical solutions of the embodiments of this specification, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments recorded in this specification. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0008] Figure 1 Shows the blockchain architecture diagram in one embodiment;
[0009] Figure 2 Is a schematic diagram of a transaction retrieval solution based on hidden addresses;
[0010] Figure 3 Is a schematic diagram of a transaction retrieval solution in one embodiment of this specification;
[0011] Figure 4 Is a flowchart of a blockchain transaction retrieval method in one embodiment of this specification;
[0012] Figure 5 Is a schematic diagram of a blockchain transaction retrieval method in one embodiment of this specification. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0013] To enable those skilled in the art to better understand the technical solutions in this specification, the following will clearly and completely describe the technical solutions in the embodiments of this specification in conjunction with the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this specification without creative efforts shall fall within the scope of protection of this specification.
[0014] Figure 1 Shows the blockchain architecture diagram in an embodiment. As Figure 1 shown, the blockchain contains, for example, 8 nodes. The connections between the nodes schematically represent P2P (Peer to Peer) connections. All the ledgers can be stored on these nodes, that is, the states of all blocks and all accounts are stored. Among them, each node in the blockchain generates the same state in the blockchain by executing the same transactions, and each node in the blockchain stores the same state database. It can be understood that Figure 1 although 8 nodes are shown in the blockchain in, the embodiments of this specification are not limited thereto, but may include other numbers of nodes. Specifically, the nodes included in the blockchain can meet the Byzantine Fault Tolerance (BFT) requirements. The so-called Byzantine Fault Tolerance requirements can be understood as that Byzantine nodes can exist inside the blockchain, but the blockchain does not exhibit Byzantine behavior externally. Generally, in some Byzantine Fault Tolerance algorithms, it is required that the number of nodes is greater than 3f + 1, where f is the number of Byzantine nodes. For example, the Practical Byzantine Fault Tolerance (PBFT) algorithm.
[0015] Transactions in the blockchain field can refer to task units that are executed and recorded in the blockchain. Transactions usually include a sending field (From), a receiving field (To), and a data field (Data). Among them, in the case of a transfer transaction, the From field represents the account address that initiates the transaction (that is, initiates the transfer task to another account), the To field represents the account address that receives the transaction (that is, receives the transfer), and the Data field includes the transfer amount. In the case of a transaction invoking a smart contract in the blockchain, the From field represents the account address that initiates the transaction, the To field represents the account address of the contract invoked by the transaction, and the Data field includes data such as the function name in the invoked contract and the input parameters for the function, so as to obtain the code of the function from the blockchain and execute the code of the function when the transaction is executed.
[0016] Currently, to protect the privacy of the recipient's identity, some blockchain solutions use stealth addresses to ensure the anonymity of the recipient. The principle of stealth addresses is to let the sender generate a one-time address for each transaction. Even if multiple transactions are made with the same recipient, unrelated parties to the transactions cannot distinguish them. Therefore, stealth addresses help protect the privacy of cryptocurrency payment recipients and the details of their assets. Figure 2 is a schematic diagram of a transaction retrieval scheme based on stealth addresses. As Figure 2 shown, the recipient B of a blockchain transaction can have a public-private key pair (PK B , SK B ), where PK B = SK B ·g, and g is the generator of the elliptic curve. The sender A of the transaction can determine a random number r A , and determine the stealth address of the recipient identified by the binary tuple (R A , T A ) according to r A ), where R A = r A g, T A = H(r A ·PK B ), and H(·) is a hash function. Subsequently, Party A can sign the transaction and send it to the chain. After that, the recipient B can scan the transaction from the chain and extract T A from its recipient address field, and use its own private key SK B to calculate T A ′ = H(SK B ·R A )G. If T A ′ = T A , it can be determined that this transaction is sent to itself, and thus receive this transaction. Otherwise, it is determined that this transaction is not sent to itself. Party B can also scan all transactions on the chain to identify all transactions sent to itself. Since each stealth address is generated based on a one-time random number, the stealth address sent each time is different from the previous one, so the actual recipient of the transaction cannot be determined based on this address. And the recipient can verify the ownership of the transaction after learning the element R A in the stealth address binary tuple. However, such stealth address schemes also have the following problems: that is, the search time is linearly related to the total number of all stealth address transactions. This makes it very difficult for local clients with usually limited computing resources to retrieve from large-scale transactions.
[0017] To enable users to retrieve transactions sent to themselves more quickly from a large number of transactions, some transaction retrieval schemes based on hidden addresses use proxy computing to directly transmit the user's private key to the on-chain proxy node, allowing the proxy node to perform retrieval calculations on behalf of the user's local client to identify each transaction sent to the user, as Figure 3 shown. However, the problem with this scheme is that directly handing the user's private key to the proxy node can utilize the computing resources of the proxy node to speed up transaction retrieval. However, if the proxy node is negligent or malicious, it can not only leak the user's key to others or institutions other than the user himself, enabling others or institutions to retrieve transactions sent to the user, resulting in security issues such as user privacy leakage. Even, there may be a security issue where the proxy party initiates a transaction through the private key, causing the transfer of the user's assets.
[0018] There is also a transaction retrieval scheme based on hidden addresses that sets the user's public-private key pair as a monitoring public-private key pair (including a monitoring public key and a monitoring private key) and a spending public-private key pair (including a spending public key and a spending private key). Among them, the spending private key is used to sign transactions initiated by the user, and the monitoring private key is used to detect transactions related to the user on the blockchain. Thus, the user can send the monitoring private key to the proxy node, enabling the proxy node to retrieve transactions sent to the user in the blockchain through the monitoring private key. However, this scheme still has the following problems: Although this scheme restricts the scope of use of the monitoring private key so that it cannot be used for transaction signing, thus preventing problems such as the proxy node transferring the user's assets. However, if the proxy node is negligent or malicious and leaks the user's monitoring private key to others or institutions other than the user himself, there will still be a security issue where the user's transaction privacy can be leaked.
[0019] To solve the above problems. The embodiments of this specification provide a blockchain transaction retrieval method. Through this method, for example, the recipient B selects a random number to blind the local private key, generates a proxy key and transmits it to the proxy node. The proxy node can traverse and compare each on-chain transaction with the proxy key, and determine the transactions sent to Party B according to the comparison results. Among them, the hidden address sent by the transaction sender is an element in the bilinear group, enabling the method of the proxy node verifying the transaction ownership through the user's private key in the conventional hidden address scheme to be transformed into the method of verifying the transaction ownership by determining whether the bilinear mapping equation of the group element holds.
[0020] The advantages of this method are: not only can the proxy node be used to retrieve transactions whose recipients are the target user, thereby improving the efficiency of transaction retrieval for the target user, but also the random key corresponding to the original private key can be delivered to the proxy node without leaking the original private key of the user, so that the proxy node does not know the original key and can still verify whether any transaction on the chain is the target user's transaction through the random key. This solves the problem of user transaction privacy leakage when the user's private key is directly sent to the proxy node for proxy retrieval.
[0021] The following further describes a blockchain transaction retrieval method provided by an embodiment of this specification. Figure 3 This is a flowchart of a blockchain transaction retrieval method in an embodiment of this specification. In the blockchain, a first group generated by a first generator, a second group generated by a second generator, and a third group are predetermined, and the elements in the first group and the second group are mapped to the third group based on a preset bilinear mapping function; and the public key of the participant of the blockchain is pre-generated based on the private key of the participant of the blockchain and the first generator. Figure 4 As shown, the method at least comprises the following steps:
[0022] Step S401: A first party among the participants of the blockchain determines a first value belonging to a second group according to a second generator, and determines a second value belonging to the second group according to its own private key and the second generator; and sends the first value and the second value to a proxy node;
[0023] Step S403: The second party among the participants of the blockchain determines a third value belonging to the first group according to the first generator, and determines a fourth value belonging to the first group according to the public key of the recipient; and sends a first transaction according to the target hidden address of the recipient represented by the third value and the fourth value;
[0024] Step S405: the proxy node obtains the first transaction, and verifies the first value, the second value, the third value, and the fourth value based on the bilinear mapping function to determine whether the first transaction is a transaction sent to the first party.
[0025] First, in step S401, the first party among the participants of the blockchain determines the first value belonging to the second group according to the second generator, and determines the second value belonging to the second group according to the private key of the party and the second generator. According to different implementations, the blockchain in this step can be different specific types of blockchains, and this specification does not limit this.
[0026] A group is a mathematical structure, usually consisting of a set of elements and an operation (e.g., addition or multiplication), and satisfying the following conditions: Closure, i.e., operating on any two elements in this set results in an element still within this set. Associativity, i.e., the order of the operation does not affect the result. Existence of an identity element: The identity element is a special element in the set such that when operating with other elements, it does not change them. Inverse element: Each element in the set has an "opposite" element such that their operation result is the identity element. The bilinear mapping function of a group is a function defined on two input groups, which can map pairs of their elements to an element in the output group and maintain a linear relationship for each input group. Specifically, the bilinear mapping function e can be expressed as e: G1×G2→G T , where G1 and G2 are the input groups, and G T is the output group, and × represents the Cartesian product. This function can satisfy the following computational properties. Bilinearity: For any element P belonging to G1 and element Q belonging to G2 respectively, it holds that (aP, bQ) = e(aP, Q) b = e(P, bQ) a = e(P, Q) ab . This means that the mapping is linear for both inputs. Non-degeneracy: If g1 and g2 are the generators of G1 and G2 respectively, then e(g1, g2) is the generator of G T . Efficient computability: The mapping e(aP, bQ) can be computed efficiently.
[0027] As mentioned above, in this blockchain, a first group generated by a first generator, a second group generated by a second generator, and a third group can be predetermined. The elements in the first group and the second group can be mapped to the third group based on a preset bilinear mapping function. The first generator and the second generator are respectively used to generate the elements in the first group and the second group. In different embodiments, the specific values of the first generator and the second generator can be different. In different embodiments, the bilinear mapping function used to map the elements in the first group and the second group to the third group can also be different specific mapping functions, and this specification does not limit this.
[0028] Each participating party in this blockchain can also pre-generate its own public key according to its own private key and the first generator, for example, according to the product of its own private key and the first generator, and disclose its own public key to other participating parties. Figure 5 It is a schematic diagram of a blockchain transaction retrieval method in an embodiment of this specification. In Figure 5 the example shown, for example, participating party A can pre-generate its own public-private key pair (PK A , SK A ) and disclose its public key PK A . Among them, PKA = SK A g1, where g1 is the first generator of the first group. For example, Party B can also pre - generate its own public - private key pair (PK B , SK B ), and publish its public key PK B . Among them, PK B = SK B g1.
[0029] In one implementation, the first group and the second group can be additive cyclic groups of prime order q, and the third group is a multiplicative cyclic group of order q. A cyclic group is a group in which all elements can be obtained by repeatedly operating on a specific generator. The order of a group refers to the number of elements in the group. An additive cyclic group of prime order q is a cyclic group that contains q (where q is a prime number) elements and the operation is addition. A multiplicative cyclic group of order q is a cyclic group that contains q elements and the operation is multiplication.
[0030] In different implementations, the specific ways for the first party to determine the first value and the second value can be different. In one implementation, the first value belonging to the second group can be determined according to the first random number of the first party and the second generator, and the second value belonging to the second group can be determined according to the first random number, the private key of the first party, and the second generator. In a specific implementation, the second value can be determined according to the product of the first random number, the private key of the first party, and the second generator.
[0031] Specifically, in the example shown in Figure 5 , for example, the first party (Party B) can generate a random number s, and determine the proxy key k B of the private key SK B . The proxy key k B can be in the form of a binary tuple, denoted as k B =(k1, k2), where k1 = s·g2, k2=(SK B ·s)·g2.
[0032] After determining the first value and the second value, the first value and the second value can be sent to the proxy node. A proxy node is a node that can perform specific operations or tasks on behalf of a user client or a node belonging to the user. According to different implementations, the proxy node can be different specific types of computing devices. For example, it can be a physical or logical computer, or other devices with computing and storage capabilities.
[0033] Then, in step S403, the second party among the participants in the blockchain can determine a third value belonging to the first group based on the first generator, and a fourth value belonging to the first group based on the public key of the recipient. Furthermore, based on the target hidden address of the recipient represented by the third value and the fourth value, the first transaction is sent. In different embodiments, the specific transaction type of the first transaction or the specific purpose it serves may be different, and this specification does not limit this. In one embodiment, the first transaction may be a digital collectible ownership transfer transaction.
[0034] In different embodiments, the specific manner in which the second party determines the third value and the fourth value may be different. In one embodiment, a third value belonging to the first group can be determined based on the second random number of the second party and the first generator, and a fourth value belonging to the first group can be determined based on the second random number and the public key of the recipient.
[0035] Specifically, in Figure 5 the example shown, for example, the second party (participant A) can obtain the public key PK B of participant B, and determine the random number t. Generate a one-time hidden address Y=(Y1, Y2) represented by a binary tuple based on t, where Y1 = t·g1 and Y2 = t·PK B . Then, the hidden address Y can be attached to the recipient address field of transaction T and transaction T is sent in the blockchain.
[0036] Thereafter, in step S405, the proxy node can obtain the first transaction. Furthermore, based on the bilinear mapping function, verify the first value, the second value, the third value, and the fourth value to determine whether the first transaction is a transaction sent to the first party.
[0037] Specifically, in one embodiment, a first mapping result can be determined based on the bilinear mapping function, the third value, and the second value, and a second mapping result can be determined based on the bilinear mapping function, the fourth value, and the first value; if the first mapping result is equal to the second mapping result, it is determined that the recipient of the first transaction is the first party. In another embodiment, if the first mapping result is not equal to the second mapping result, it is determined that the recipient of the second transaction is not the first party
[0038] For example, in Figure 5 the example shown, the proxy node can obtain the on-chain transaction T, and the recipient address field of this transaction is Y=(Y1, Y2). Then, according to the preset mapping function e, calculate the bilinear mappings U = e(Y1, k2) and V = e(Y2, k1) respectively. Furthermore, determine whether the equation U = V holds. If this equation holds, it is determined that transaction T is sent to participant B. If this equation does not hold, it is determined that transaction T is not sent to participant B.
[0039] With this solution, it is possible to overcome the drawbacks of existing solutions such as sending the user's private key or the user's monitoring private key to the proxy node for retrieving transactions. That is, the proxy key is generated based on the real user key but is not the real user key. Without disclosing the user key, the key sent to the user can be retrieved through the proxy key. When retrieval is not required, the proxy key can be conveniently invalidated without changing the real user key, so that even if the random key is leaked, it is difficult to cause the problem of user privacy leakage. When retrieving later, a new proxy key can be regenerated based on the real user key. In different embodiments, the specific method of invalidating the random key can also be different. In one embodiment, for example, after sending the random key to the proxy node, the participating party can send a random key invalidation instruction to the blockchain system. After receiving the instruction, the system marks the random key as invalid, so that the random key can no longer be used for transaction retrieval. In one embodiment, it is also possible to trigger the invalidation of the random key, for example, after a predetermined period of time after the participating party sends the random key to the proxy node.
[0040] Another aspect of this specification provides a computing device, including: a processor; and a memory, in which a program is stored, and when the processor executes the program, the above-mentioned method in any one of the above is implemented.
[0041] Another aspect of this specification provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed in a computer, the computer is made to execute the above-mentioned method in any one of the above.
[0042] Another aspect of this specification provides a computer program product, including computer program / instructions, and when the computer program / instructions are executed by a processor, the above-mentioned method in any one of the above is implemented.
[0043] In the 1990s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to circuit structures such as diodes, transistors, switches, etc.) or software improvements (improvements to method flows). However, with the development of technology, many method flow improvements today can be regarded as direct improvements to hardware circuit structures. Designers almost always obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that an improvement to a method flow cannot be implemented using a hardware entity module. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is an integrated circuit whose logical function is determined by the user programming the device. Designers can program themselves to "integrate" a digital system onto a single PLD, without having to ask a chip manufacturer to design and fabricate a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly implemented using "logic compiler" software, which is similar to the software compilers used in program development and writing. The original code before compilation also has to be written in a specific programming language, which is called a Hardware Description Language (HDL). There is not just one type of HDL, but many, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones currently are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also be aware that by simply performing a little logical programming on the method flow using the above-mentioned several hardware description languages and programming it into an integrated circuit, it is easy to obtain the hardware circuit that implements the logical method flow.
[0044] The controller can be implemented in any suitable manner. For example, the controller can take the form of, for example, a microprocessor or a processor and a computer-readable medium storing computer-readable program code (such as software or firmware) executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of the controller include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that in addition to implementing the controller in the form of pure computer-readable program code, it is entirely possible to logically program the method steps to enable the controller to be implemented in the form of logic gates, switches, application specific integrated circuits, programmable logic controllers, embedded microcontrollers, etc. to achieve the same function. Therefore, such a controller can be considered a hardware component, and the devices included therein for implementing various functions can also be regarded as the structures within the hardware component. Or even, the devices for implementing various functions can be regarded as either software modules for implementing the method or the structures within the hardware component.
[0045] The systems, devices, modules, or units illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a server system. Of course, this application does not exclude that with the development of future computer technologies, the computers for implementing the functions of the above embodiments can be, for example, personal computers, laptop computers, in-vehicle human-machine interaction devices, cellular phones, camera phones, smart phones, personal digital assistants, media players, navigation devices, email devices, game consoles, tablet computers, wearable devices, or any combination of these devices.
[0046] Although one or more embodiments of this specification provide method operation steps as described in the embodiments or flowcharts, more or fewer operation steps may be included based on conventional or non-creative means. The order of steps listed in the embodiments is only one way among the execution orders of numerous steps and does not represent the only execution order. When the actual device or terminal product is executed, it may be executed in the order of the method shown in the embodiments or the drawings or in parallel (such as in an environment of parallel processors or multi-threaded processing, or even in a distributed data processing environment). The terms "comprise", "include" or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, product or device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or also includes elements inherent to such process, method, product or device. Without further limitation, there is no exclusion of additional identical or equivalent elements in the process, method, product or device comprising the said elements. For example, if terms such as first and second are used to denote names, they do not denote any particular order.
[0047] For convenience of description, when describing the above device, it is divided into various modules according to functions for separate description. Of course, when implementing one or more of this specification, the functions of each module can be implemented in the same or multiple software and / or hardware, or the modules implementing the same function can be realized by a combination of multiple sub-modules or sub-units, etc. The device embodiments described above are only illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces, and the indirect coupling or communication connection of the device or unit can be in electrical, mechanical or other forms.
[0048] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing device generate a device for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0049] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to operate in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including an instruction device that implements the functions specified in one or more of the acts Figure 1 of one or more of the acts and / or boxes Figure 1 specified in one or more of the boxes.
[0050] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, so that the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one or more of the acts Figure 1 of one or more of the acts and / or boxes Figure 1 specified in one or more of the boxes.
[0051] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0052] The memory may include non-permanent memory in the computer-readable medium, in the form of random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM). Memory is an example of a computer-readable medium.
[0053] Computer-readable media includes both permanent and non-permanent, removable and non-removable media implemented by any method or technology for storing information. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile discs (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage, graphene storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory media such as modulated data signals and carrier waves.
[0054] Those skilled in the art should understand that one or more embodiments of this specification can be provided as a method, a system, or a computer program product. Therefore, one or more embodiments of this specification can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, one or more embodiments of this specification can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0055] One or more embodiments of this specification can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. One or more embodiments of this specification can also be practiced in a distributed computing environment where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
[0056] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for system embodiments, since they are basically similar to method embodiments, the description is relatively simple, and reference can be made to the corresponding parts of the method embodiments for related content. In the description of this specification, the description of reference terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of this specification. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0057] The above description is only for the embodiments of one or more embodiments of this specification and is not intended to limit one or more embodiments of this specification. For those skilled in the art, one or more embodiments of this specification can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this specification shall be included within the scope of the claims.
Claims
1. A blockchain transaction retrieval method, in the blockchain, a first group generated by a first generator, a second group generated by a second generator, and a third group are pre-determined, and elements in the first group and the second group are mapped to the third group based on a preset bilinear mapping function; Moreover, the public keys of the participants in the blockchain are pre-generated according to the private keys of the participants in the blockchain and a first generator. The method includes: A first party among the participants in the blockchain determines a first value belonging to a second group according to a second generator, and determines a second value belonging to the second group according to its own private key and the second generator; and sends the first value and the second value to a proxy node. A second party among the participants in the blockchain determines a third value belonging to a first group according to the first generator, and determines a fourth value belonging to the first group according to the public key of the recipient. Send a first transaction according to the target hidden address of the recipient represented by the third value and the fourth value. The proxy node obtains the first transaction and verifies the first value, the second value, the third value and the fourth value based on the bilinear mapping function to determine whether the first transaction is a transaction sent to the first party.
2. The method according to claim 1, wherein Verifying the first value, the second value, the third value and the fourth value based on the bilinear mapping function to determine whether the first transaction is a transaction sent to the first party includes: Determine a first mapping result according to the bilinear mapping function, the third value and the second value, and determine a second mapping result according to the bilinear mapping function, the fourth value and the first value; if the first mapping result is equal to the second mapping result, determine that the recipient of the first transaction is the first party.
3. The method according to claim 2 further comprises: If the first mapping result is not equal to the second mapping result, determine that the recipient of the second transaction is not the first party.
4. The method according to claim 1, wherein, Determining a first value belonging to a second group according to a second generator, and determining a second value belonging to the second group according to its own private key and the second generator includes: Determine a first value belonging to a second group according to the first random number of the first party and the second generator, and determine a second value belonging to the second group according to the first random number, the private key of the first party and the second generator.
5. The method according to claim 1, wherein, Determining a third value belonging to a first group according to the first generator, and determining a fourth value belonging to the first group according to the public key of the recipient includes: Determine a third value belonging to a first group according to the second random number of the second party and the first generator, and determine a fourth value belonging to the first group according to the second random number and the public key of the recipient.
6. The method according to claim 4, wherein, Determining a second value belonging to a second group according to the first random number, the private key of the first party and the second generator includes: determining the second value according to the product of the first random number, the private key of the first party and the second generator.
7. The method according to claim 1, wherein, The public keys of the participants in the blockchain are pre-generated according to the private keys of the participants in the blockchain and a first generator, including: pre-generating the public key of the participant according to the product of the private key of the participant and the first generator.
8. The method according to claim 1, wherein The first transaction is a digital collectible ownership transfer transaction.
9. The method according to claim 1, wherein The first group and the second group are additive cyclic groups of prime order q, and the third group is a multiplicative cyclic group of order q.
10. A computer device, including: A processor; And a memory, in which executable code is stored. When the processor executes the executable code, the method according to any one of claims 1-9 is implemented.