Data processing task result verification method and system based on smart contract

Through a smart contract-based method, the system key parameters and CPABE ciphertext are used, combined with blockchain technology, the reliability and privacy security issues of data processing task results are solved, and the reliability and privacy protection of data processing task results are improved.

CN120238351AActive Publication Date: 2025-07-01CHONGQING UNIV
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510383488.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-28
Publication Date
2025-07-01
Estimated Expiration
2045-03-28

AI Technical Summary

Technical Problem

The lack of an effective verification mechanism for data processing task results in the prior art, resulting in low reliability of data processing task results, and lack of protection for sensitive information, which poses a risk of identity inference.

Method used

Using a smart contract-based method, a system key parameter is generated by trusted authoritative organizations, a device and an execution device generates public-private key pairs, a CPABE ciphertext and accumulator values ​​are used to verify data processing tasks, and a blockchain technology is combined to ensure the reliability and privacy of data processing tasks.

Benefits of technology

Improves the reliability of data processing task results, and protects publisher's privacy information to prevent identity inference.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238351A_ABST
    Figure CN120238351A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of block chains and cloud computing, and provides a data processing task result verification method and system.The data processing task result verification method based on the smart contract comprises the steps that an execution device receives auxiliary information sent by a block chain and responds to decryption operation executed by an executor, and the execution device sends the auxiliary information to the block chain; and processing the CPABE ciphertext based on the decryption operation to obtain a decryption set, calculating according to the decryption set and the auxiliary information to obtain a solution proving set, receiving an accumulator value sent by the block chain by the execution device, responding to a verification operation executed by an executor, performing verification according to the accumulator value and the solution proving set to obtain a verification result, and sending the verification result to the execution device. Therefore, the reliability of the data processing task result is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of blockchain and cloud computing, and particularly relates to a method and system for verifying the result of a data processing task based on a smart contract. Background Art

[0002] With the rapid development of technologies such as big data and cloud computing, due to their large storage capacity and huge computing power, more and more enterprises and individuals like to purchase cloud services and even outsource data processing tasks to cloud servers with powerful computing power to complete. Currently, in the traditional data processing task outsourcing solution, the publisher of the data processing task publishes the data processing task to the platform, and the executor of the data processing task receives the corresponding data processing task on the platform. After completing the task, the executor can obtain the corresponding remuneration. Among them, the computing models for data processing task outsourcing basically define a data processing outsourcing task T = <f, D, V>. The task T represents a function for evaluating a data set D, that is, f: D → V, where the value range V represents a set of data that the publisher of the data processing task is interested in. The task of the executor of the data processing task is to calculate f(x) and return the values of all x that satisfy f(x) ∈ V.

[0003] However, there is no complete process for verifying the correctness of the data processing task result returned by the executor, resulting in a low reliability of the data processing task result. At the same time, the task requirements of the publisher of the data processing task and the matching information of the executor of the data processing task are both sensitive information. Due to the lack of protection for task requirements and matching information, there is a possibility that a malicious server infers the identities of the publisher and the executor through task requirements and matching information. However, while protecting sensitive information, it is not desired to break the original multi-user characteristics.

[0004] Therefore, how to verify the data processing task result returned by the executor is an urgent problem to be solved by those skilled in the art. Summary of the Invention

[0005] In view of this, the embodiments of the present invention provide a method and system for verifying the result of a data processing task based on a smart contract to solve the problem of how to verify the data processing task result returned by the executor in the prior art; that is to say, the embodiments of the present invention can improve the reliability of the data processing task result.

[0006] According to one aspect of the present invention, there is provided a method for verifying the result of a data processing task based on a smart contract. The method for verifying the result of a data processing task based on a smart contract includes: a trusted authority generating system key parameters and initializing system variables according to an initialized smart contract, wherein the system key parameters include a system public key and a system private key; the trusted authority obtaining an attribute set and a computing power keyword input by an executor, and generating an attribute private key and a power private key according to the attribute set and the computing power keyword; a publishing device generating a first public-private key pair based on a first public-private key pair obtaining operation executed by a publisher, and an execution device generating a second public-private key pair based on a second public-private key pair obtaining operation executed by the executor; the publishing device generating a demand ciphertext and a CPABE ciphertext based on a ciphertext obtaining operation executed by the publisher, and publishing a data processing task according to the demand ciphertext and the CPABE ciphertext; the execution device obtaining the CPABE ciphertext based on a data processing task matching operation executed by the executor; the publishing device obtaining the second public key in the second public-private key pair based on a second public key obtaining operation executed by the publisher, generating an accumulator value and auxiliary information according to the second public key, and uploading the accumulator value and the auxiliary information to a blockchain; the execution device receiving the auxiliary information sent by the blockchain, and processing the CPABE ciphertext based on a decryption operation executed by the executor to obtain a decryption set, and calculating a solution proof set according to the decryption set and the auxiliary information; the execution device receiving the accumulator value sent by the blockchain, and performing verification according to the accumulator value and the solution proof set based on a verification operation executed by the executor to obtain a verification result.

[0007] In one embodiment, the trusted authority obtaining an attribute set and a computing power keyword input by an executor, and generating an attribute private key and a power private key according to the attribute set and the computing power keyword includes: the trusted authority determining a first numerical value and generating the attribute private key according to the first numerical value; the trusted authority determining a second numerical value, calculating a target numerical value according to the second numerical value, and generating the power private key according to the target numerical value and the computing power keyword.

[0008] In one embodiment, the execution device, in response to a data processing task matching operation performed by the executor, obtains the CP-ABE ciphertext based on the data processing task matching operation, including: the execution device receives the capability private key sent by the trusted authority, and in response to the data processing task matching operation performed by the executor, determines an eighth value based on the data processing task matching operation, and generates a matching trapdoor according to the capability private key and the eighth value; the execution device, in response to a record operation performed by the executor, obtains a first blockchain address based on the record operation, and obtains the CP-ABE ciphertext according to the first blockchain address, the matching trapdoor, and the second public key.

[0009] In one embodiment, the publishing device, in response to a second public key obtaining operation performed by the publisher, obtains the second public key in the second public-private key pair based on the second public key obtaining operation, generates an accumulator value and auxiliary information according to the second public key, and uploads the accumulator value and the auxiliary information to the blockchain, including: the publishing device, in response to the second public key obtaining operation performed by the publisher, obtains the second public key based on the second public key obtaining operation, and generates the accumulator value and the auxiliary information according to the second public key; the publishing device, in response to an upload operation performed by the publisher, uploads the accumulator value and the auxiliary information to the blockchain based on the upload operation.

[0010] In one embodiment, the execution device receives the auxiliary information sent by the blockchain, and in response to a decryption operation performed by the executor, processes the CP-ABE ciphertext based on the decryption operation to obtain a decryption set, and calculates a solution proof set according to the decryption set and the auxiliary information, including: the execution device receives the attribute private key sent by the trusted authority, and in response to the decryption operation performed by the executor, decrypts the CP-ABE ciphertext according to the attribute private key to obtain a decryption data set; the execution device, in response to an information obtaining operation performed by the executor, returns the auxiliary information and the first public key in the first public-private key pair according to the first blockchain address; the execution device receives the value range sent by the blockchain, and in response to a data processing operation performed by the executor, processes the decryption data set, the data task function, and the value range to obtain a decryption set; the execution device, in response to a data calculation operation performed by the executor, calculates the solution proof set according to the decryption set and the auxiliary information.

[0011] In one embodiment, the capability private key generated according to the target value and the computing power keyword is:

[0012] AK = (F1, F2, Q)

[0013] Wherein, F1 is the first item of the ability private key, F2 is the second item of the ability private key, Q is the third item of the ability private key, Q = H1(ability) c , g is the generator of G, h(u′) = a + b·u′, L u′,{u′,u} (0) is the Lagrange interpolation polynomial with respect to u′, L u,{u′,u} (0) is the Lagrange interpolation polynomial with respect to u, c is a random number in Z p , u′ is the second value, H1 is the first hash function, ability is the computing ability keyword.

[0014] In one embodiment, generating a matching trapdoor according to the ability private key and the eighth value, the matching trapdoor is:

[0015] T = (T1, T2, T3)

[0016] Wherein, T1 is the first item of the matching trapdoor, T1 = F1 r′ ·Q, T2 is the second item of the matching trapdoor, T2 = F2 r′ , T3 is the matching

[0017] third item of the trapdoor, T3 = g r′ , F1 is the first item of the ability private key, F2 is the second item of the ability private key, Q is the third item of the ability private key, r′ is the eighth value, g is the generator of G.

[0018] In one embodiment, generating an accumulator value according to the second public key, the accumulator value is:

[0019]

[0020] Wherein, e is a symmetric bilinear pairing G×G→G T , g is the generator of G, pk B is the second public key, H2 is the second hash function, y is the first private key, μ is the seventh value, z is the fifth value, is the i3-th value in the value range V, n is a random integer.

[0021] In one embodiment, calculating the solution proof set according to the decryption set and the auxiliary information, the solution proof set is:

[0022]

[0023] Wherein, H3 is the third hash function, d is a random integer, and j is a random integer.

[0024] According to another aspect of the present invention, there is provided a data processing task result verification system based on a smart contract. The data processing task result verification system based on a smart contract includes: a trusted authority for generating system key parameters and initializing system variables according to an initialized smart contract, wherein the system key parameters include a system public key and a system private key; and the trusted authority for obtaining an attribute set and a computing power keyword input by an executor, and generating an attribute private key and a power private key according to the attribute set and the computing power keyword; a publishing device for generating a first public-private key pair based on a first public-private key pair obtaining operation executed by a publisher; and the publishing device for generating a demand ciphertext and a CPABE ciphertext based on a ciphertext obtaining operation executed by the publisher, and publishing a data processing task according to the demand ciphertext and the CPABE ciphertext; an execution device for generating a second public-private key pair based on a second public-private key pair obtaining operation executed by the executor; and the execution device for obtaining the CPABE ciphertext based on a data processing task matching operation executed by the executor; the publishing device is further for obtaining the second public key in the second public-private key pair based on a second public key obtaining operation executed by the publisher, generating an accumulator value and auxiliary information according to the second public key, and uploading the accumulator value and the auxiliary information to a blockchain; the execution device is further for receiving the auxiliary information sent by the blockchain, and processing the CPABE ciphertext based on a decryption operation executed by the executor to obtain a decryption set, and calculating a solution proof set according to the decryption set and the auxiliary information; and the execution device for receiving the accumulator value sent by the blockchain, and verifying according to the accumulator value and the solution proof set based on a verification operation executed by the executor to obtain a verification result.

[0025] In summary, in the embodiments of the present invention, the execution device receives the auxiliary information sent by the blockchain, and in response to the decryption operation performed by the executor, processes the CPABE ciphertext based on the decryption operation to obtain a decryption set, calculates a solution proof set according to the decryption set and the auxiliary information, the execution device receives the accumulator value sent by the blockchain, and in response to the verification operation performed by the executor, performs verification according to the accumulator value and the solution proof set to obtain a verification result, thereby improving the reliability of the data processing task result. At the same time, the publishing device responds to the ciphertext acquisition operation performed by the publisher, generates a demand ciphertext and a CPABE ciphertext based on the ciphertext acquisition operation, and publishes the data processing task according to the demand ciphertext and the CPABE ciphertext, ensuring the privacy and security of the input data set D of the publisher. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] In the following description of the exemplary embodiments in conjunction with the drawings, more details, features and advantages of the present invention are disclosed, in the drawings:

[0027] Figure 1 A schematic flowchart of a method for verifying the result of a data processing task based on a smart contract disclosed in an embodiment of the present application is shown;

[0028] Figure 2 Shows Figure 1 A schematic flowchart of the steps shown in step S120;

[0029] Figure 3 Shows Figure 1 A schematic flowchart of the steps shown in step S130;

[0030] Figure 4 Shows Figure 1 A schematic flowchart of the steps shown in step S140;

[0031] Figure 5 Shows Figure 1 A schematic flowchart of the steps shown in step S150;

[0032] Figure 6 Shows Figure 1 A schematic flowchart of the steps shown in step S160;

[0033] Figure 7 Shows Figure 1 A schematic flowchart of the steps shown in step S170;

[0034] Figure 8 A schematic structural diagram of a system for verifying the result of a data processing task based on a smart contract disclosed in an embodiment of the present application is shown. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0035] Embodiments of the present invention will now be described in more detail with reference to the accompanying drawings. Although some embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present invention. It should be understood that the drawings and embodiments of the present invention are only for illustrative purposes and are not used to limit the protection scope of the present invention.

[0036] It should be understood that the various steps recited in the method embodiments of the present invention can be executed in a different order and / or executed in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present invention is not limited in this regard.

[0037] The term "comprising" and its variations used herein are open-ended, that is, "including but not limited to". The term "based on" is "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description. It should be noted that the concepts such as "first" and "second" mentioned in the present invention are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.

[0038] It should be noted that the modifications of "one" and "plural" mentioned in the present invention are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly specified in the context, it should be understood as "one or more".

[0039] The names of the messages or information exchanged between multiple devices in the embodiments of the present invention are only for illustrative purposes and are not used to limit the scope of these messages or information.

[0040] It should be noted that the execution entity of a data processing task result verification method based on a smart contract provided by an embodiment of the present invention can be one or more electronic devices, and the present invention does not limit this; among them, the electronic device can be a terminal (i.e., a client) or a server. Then, when the execution entity includes multiple electronic devices, and at least one terminal and at least one server are included in the multiple electronic devices, a data processing task result verification method based on a smart contract provided by an embodiment of the present invention can be jointly executed by the terminal and the server. Correspondingly, the terminals mentioned here can include, but are not limited to: smart phones, tablet computers, laptop computers, desktop computers, smart watches, intelligent voice interaction devices, smart home appliances, vehicle-mounted terminals, aircraft, and so on. The servers mentioned here can be independent physical servers, or a server cluster or distributed system composed of multiple physical servers, or can also be cloud servers that provide basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), as well as big data and artificial intelligence platforms, and so on.

[0041] Based on the above description, an embodiment of the present invention proposes a data processing task result verification method based on a smart contract. This data processing task result verification method based on a smart contract can be executed by the above-mentioned electronic devices (terminals or servers); or, this data processing task result verification method based on a smart contract can be jointly executed by the terminal and the server. For the convenience of description, in the following, it will be described by taking an electronic device executing this data processing task result verification method based on a smart contract as an example.

[0042] Please refer to Figure 1 , which is a schematic flowchart of a data processing task result verification method based on a smart contract disclosed in an embodiment of the present application. By using the data processing task result verification method based on a smart contract, the problem of how to verify the data processing task result returned by the executor is solved, thereby improving the reliability of the data processing task result. It should be noted that the data processing task result verification method based on a smart contract in the embodiment of the present application is not limited to Figure 1 the steps and order in the flowchart shown. According to different requirements, the steps in the shown flowchart can be added, removed, or the order can be changed. In an embodiment of the present application, as Figure 1 shown, the process of the data processing task result verification method based on a smart contract at least includes the following steps.

[0043] S110. The trusted authority generates system key parameters and initializes system variables according to the initialized smart contract. Among them, the system key parameters include a system public key and a system private key.

[0044] In the embodiment of the present invention, the system key parameters include a system public key and a system private key, both of which are initially generated by the trusted authority. The system public key is a set of values that are known and accessible to all participants in the system. The system private key is secretly stored by the trusted authority and is used to generate subsequent attribute private keys, etc.

[0045] The trusted authority selects computational security parameter (CSP) λ, G and G T are two cyclic groups with prime order p, e is a symmetric bilinear pairing G×G→G T , g is the generator of G. Random numbers α, β, a, b, c, u ∈ Z p , generate a polynomial h(x) = a + b·x, calculate h(u) = a + b·u, where, Z p is a finite field that contains integer elements (i.e., from 0 to p - 1). Select three hash functions H1: {0, 1}*→G, H2: {0, 1}*→Z p , H3: G T →Z p . The system public key and system private key are as follows:

[0046] PK = {g, e(g, g) α , g β , g c , g h(u) , H1, H2, H3} Equation (1)

[0047] MSK = {g α , β, a, b, c, u} Equation (2)

[0048] Among them, PK is the system public key, MSK is the system private key, g is the generator of G, e is a symmetric bilinear pairing G×G→G T , G and G T are two cyclic groups with prime order p, h(u) is a value obtained by substituting u into the polynomial h(x), α, β, a, b, c, u are all random numbers in Z p , H1 is the first hash function, H2 is the second hash function, H3 is the third hash function, Z p is a finite field.

[0049] When initializing and deploying a smart contract, initialize the system variables. The system variables may include, for example, the public key of the publisher of a preset task, the public key of the executor of a preset task, etc. The initialization of the smart contract is shown in Table 1 below:

[0050] Table 1 Initialization of Smart Contract

[0051]

[0052] S120. The trusted authority obtains the attribute set and the computing power keyword input by the executor, and generates an attribute private key and a capability private key according to the attribute set and the computing power keyword.

[0053] As Figure 2 shown, in the embodiment of the present invention, Figure 2 the step S120 at least includes the following steps:

[0054] S121. The trusted authority determines a first value, and generates the attribute private key according to the first value.

[0055] In the embodiment of the present invention, the trusted authority selects a random value t1 from Z p as the first value, and generates an attribute private key SK according to the first value t1. The attribute private key SK is as follows:

[0056]

[0057] K = g α ·g β·t1 Formula (4)

[0058] L = g t1 Formula (5)

[0059]

[0060] where K is the first item of the attribute private key, L is the second item of the attribute private key, is the third item of the attribute private key, g is the generator of G, α and β are both random numbers in Z p t1 is the first value, H1 is the first hash function, j is a bit string of 0101, and s is a bit string of 0101.

[0061] S122. The trusted authority determines a second value, calculates a target value according to the second value, and generates the capability private key according to the target value and the computing power keyword.

[0062] In the embodiment of the present invention, the trusted authority selects from Z pSelect a random value from it as the second value u′, substitute u′ into the polynomial h(x) = a + b·x to obtain the target value h(u′). Generate the ability private key AK based on the target value and the computing power keyword, and the trusted authority transmits the ability private key AK to the executor through a preset channel. The ability private key AK is as follows:

[0063] AK = (F1, F2, Q) Formula (7)

[0064]

[0065] QH = H1(ability) c Formula (10)

[0066] Among them, F1 is the first item of the ability private key, F2 is the second item of the ability private key, Q is the third item of the ability private key, g is the generator of G, L u′,{u′,u} (0) is the Lagrange interpolation polynomial about u′, L u,{u′,u} (0) is the Lagrange interpolation polynomial about u, c is a random number in Z p , u′ is the second value, H1 is the first hash function, and ability is the computing power keyword.

[0067] S130. In response to the first public-private key pair acquisition operation performed by the publisher, the publishing device generates a first public-private key pair based on the first public-private key pair acquisition operation. In response to the second public-private key pair acquisition operation performed by the executor, the execution device generates a second public-private key pair based on the second public-private key pair acquisition operation.

[0068] As Figure 3 shown, in the embodiment of the present invention Figure 3 The step S130 at least includes the following steps:

[0069] S131. In response to the first selection operation performed by the publisher, the publishing device determines a third value and a fourth value based on the first selection operation, and generates the first public-private key pair according to the third value and the fourth value.

[0070] In the embodiment of the present invention, in the embodiment of the present invention, in response to the first selection operation performed by the publisher, the publishing device selects a random value from it as the third value y, and selects a random value greater than the number of data items n in the value range V from it as the fourth value t2, and generates the first public-private key pair according to the third value y and the fourth value t2, where the third value y and the fourth value t2 are different values, is a multiplicative cyclic group, including integer elements (that is, from 1 to p - 1). The first public-private key pair is as follows:

[0071]

[0072] wherein, sk A is the first private key, pk A is the first public key, y is the third value, t2 is the fourth value, g is the generator of G, G is a cyclic group with prime order p, and i1 is a random integer belonging to the set [0,..., t2].

[0073] S132. The execution device responds to the second selection operation executed by the executor, determines a fifth value based on the second selection operation, and generates the second public-private key pair according to the fifth value.

[0074] In an embodiment of the present invention, in an embodiment of the present invention, the execution device responds to the second selection operation executed by the executor, and selects a random value as the fifth value z from, and generates a second public-private key pair according to the fifth value z. The second public-private key pair is as follows:

[0075] sk B = z, pk B = g z Formula (12)

[0076] wherein, sk B is the second private key, pk B is the second public key, z is the fifth value, g is the generator of G, and G is a cyclic group with prime order p.

[0077] S140. The publishing device responds to the ciphertext acquisition operation executed by the publisher, generates a demand ciphertext and a CPABE ciphertext based on the ciphertext acquisition operation, and publishes the data processing task according to the demand ciphertext and the CPABE ciphertext.

[0078] As Figure 4 shown, in an embodiment of the present invention, Figure 4 step S140 at least includes the following steps:

[0079] S141. The publishing device responds to the ciphertext acquisition operation executed by the publisher, and generates the demand ciphertext based on the ciphertext acquisition operation.

[0080] In an embodiment of the present invention, the publisher inputs the data processing task requirement keyword demand. The publishing device responds to the ciphertext acquisition operation executed by the publisher, selects a random value as the sixth value r from Z p , and generates a demand ciphertext CT demand according to the sixth value r and the data processing task requirement keyword demand. The demand ciphertext CTdemand As shown in the following formula:

[0081] CT demand =(E0, E1, E2, E3) Formula (13)

[0082] E0 = e(g c·r , H1(demand)) Formula (14)

[0083] E1 = g r Formula (15)

[0084] E2 = g h(u)·r Formula (16)

[0085] E3 = g a·r Formula (17)

[0086] Wherein, E0 is the first item of the demand ciphertext, E1 is the second item of the demand ciphertext, E2 is the third item of the demand ciphertext, E3 is the fourth item of the demand ciphertext, g is the generator of G, r is the sixth value, H1 is the first hash function, demand is the keyword of the data processing task demand, h(u) is a value obtained by substituting u into the polynomial h(x), and a is a random number in Z p random number in.

[0087] S142. The publishing device generates the CPABE ciphertext based on the ciphertext acquisition operation in response to the ciphertext acquisition operation performed by the publisher.

[0088] In the embodiment of the present invention, the publisher inputs the data set D and sets the access policy (M, ρ), where M is an l×n sharing generation matrix, and the function ρ maps each row of the matrix M to an attribute value. The publishing device responds to the ciphertext acquisition operation performed by the publisher and selects a random vector as the first vector v from , where v = (s, m2,..., m n ), for 1≤i2≤l, calculate where is the i2-th row of the matrix M. Select l random values r1,..., r p from Z l , and select a random value as the seventh value μ from , and generate the ciphertext-policy attribute-based encryption (CPABE) ciphertext CT CPABE according to the l random values and the seventh value μ. The CPABE ciphertext CT CPABE is uploaded to the blockchain by the executor calling the smart contract. The CPABE ciphertext CT CPABE is as shown in the following formula:

[0089]

[0090] C = (D || μ) · e(g, g) α·s Formula (19)

[0091] C′ = g s Formula (20)

[0092]

[0093] Where, (M, ρ) is the first item of the CPABE ciphertext, C is the second item of the CPABE ciphertext, C′ is the third item of the CPABE ciphertext, is the fourth item of the CPABE ciphertext, M is an l×n sharing generation matrix, the function ρ maps each row of the matrix M to an attribute value, D is the data set, μ is the seventh value, and e is a symmetric bilinear pairing G×G→G T , g is the generator of G, α and β are both random numbers in Z p , s is a bit string of 0101, is the product of and v, i2 is the i2-th row of the matrix M, v is the first vector, H1 is the first hash function, r i2 is p a random value selected from Z

[0094] S143. The publishing device responds to the data task function input operation executed by the publisher.

[0095] In the embodiment of the present invention, the publisher inputs the data task function f, and the publishing device responds to the data task function input operation executed by the publisher.

[0096] S144. The publishing device publishes the data processing task according to the first public key in the first public-private key pair, the demand ciphertext, the CPABE ciphertext, and the data task function.

[0097] In the embodiment of the present invention, the publishing device is based on the first public key pk A , the demand ciphertext CT demand , the CPABE ciphertext CT CPABE , and the data task function f, and calls the smart contract function issueTask to publish the data processing task on the blockchain and update the relevant information of the data processing task at the same time. The smart contract function issueTask is shown in Table 2 below:

[0098] Table 2 Smart contract function issueTask

[0099]

[0100] S150. The execution device responds to the data processing task matching operation executed by the executor, and obtains the CPABE ciphertext based on the data processing task matching operation.

[0101] As Figure 5 shown, in the embodiment of the present invention, Figure 5 the step S150 at least includes the following steps:

[0102] S151. The execution device receives the capability private key sent by the trusted authority, responds to the data processing task matching operation executed by the executor, determines an eighth value based on the data processing task matching operation, and generates a matching trapdoor according to the capability private key and the eighth value.

[0103] In the embodiment of the present invention, the execution device responds to the data processing task matching operation executed by the executor, and selects a random value from as the eighth value r′, and generates a matching trapdoor T according to the capability private key AK = (F1, F2, Q) and the eighth value r′. The matching trapdoor T is as follows:

[0104] T = (T1, T2, T3) Formula (22)

[0105] T1 = F1 r′ ·Q Formula (23)

[0106] T2 = F2 r′ Formula (24)

[0107] T3 = g r′ Formula (25)

[0108] Wherein, T1 is the first item of the matching trapdoor, T2 is the second item of the matching trapdoor, T3 is the third item of the matching trapdoor, F1 is the first item of the capability private key, F2 is the second item of the capability private key, Q is the third item of the capability private key, r′ is the eighth value, and g is the generator of G.

[0109] S152. The execution device responds to the record operation executed by the executor, obtains the first blockchain address based on the record operation, and obtains the CPABE ciphertext according to the first blockchain address, the matching trapdoor, and the second public key.

[0110] In the embodiment of the present invention, the execution device responds to the record operation executed by the executor, and obtains the first blockchain address address A , and the first blockchain address address A is the address of the publisher on the blockchain. According to the first blockchain address addressA Match the trapdoor T and the second public key pk B = g z , and initiate data processing task matching through the smart contract function tasksMatch. When the data processing task matching is successful, obtain the CPABE ciphertext through the blockchain. The smart contract function tasksMatch is shown in Table 3 below:

[0111] Table 3 Smart contract function tasksMatch

[0112]

[0113] The find function is shown in Table 4 below:

[0114] Table 4 find function

[0115]

[0116] S160. In response to the second public key acquisition operation executed by the publisher, the publishing device obtains the second public key in the second public-private key pair based on the second public key acquisition operation, generates an accumulator value and auxiliary information according to the second public key, and uploads the accumulator value and the auxiliary information to the blockchain.

[0117] As Figure 6 shown, in the embodiment of the present invention, Figure 6 The step S160 at least includes the following steps:

[0118] S161. In response to the second public key acquisition operation executed by the publisher, the publishing device obtains the second public key based on the second public key acquisition operation, and generates the accumulator value and the auxiliary information according to the second public key.

[0119] In the embodiment of the present invention, in response to the second public key acquisition operation executed by the publisher, the publishing device calls the function get pk B to obtain the second public key pk B , and calculates the accumulator value acc and the auxiliary information aux for the value range V. The accumulator value acc is as follows:

[0120]

[0121] where e is a symmetric bilinear pairing G×G→G T , g is the generator of G, pk B is the second public key, H2 is the second hash function, y is the first private key, μ is the seventh numerical value, z is the fifth numerical value, is the i3th numerical value in the value range V, and n is a random integer.

[0122] The auxiliary information aux is as described by the following formula:

[0123]

[0124] Among them, v i is the i4-th value in the value range V, and i4 is a random integer.

[0125] Call the function get pk B as shown in Table 5 below:

[0126] Table 5 Call the function get pk B

[0127]

[0128] S162. In response to the upload operation performed by the publisher, the publishing device uploads the accumulator value and the auxiliary information to the blockchain based on the upload operation.

[0129] In an embodiment of the present invention, in response to the upload operation performed by the publisher, the publishing device calls the smart contract function uploadAcc to upload the accumulator value and the auxiliary information to the blockchain. The smart contract function uploadAcc is as shown in Table 6 below:

[0130] Table 6 Smart contract function uploadAcc

[0131]

[0132] S170. The execution device receives the auxiliary information sent by the blockchain, and in response to the decryption operation performed by the executor, processes the CPABE ciphertext based on the decryption operation to obtain a decryption set, and calculates a solution proof set according to the decryption set and the auxiliary information.

[0133] As Figure 7 shown, in an embodiment of the present invention, Figure 7 Step S170 at least includes the following steps:

[0134] S171. The execution device receives the attribute private key sent by the trusted authority, and in response to the decryption operation performed by the executor, decrypts the CPABE ciphertext according to the attribute private key to obtain a decryption data set.

[0135] In an embodiment of the present invention, the execution device receives the attribute private key sent by the trusted authority and in response to the decryption operation performed by the executor, decrypts the CPABE ciphertext CT according to the attribute private key SK CPABEDecryption is performed to obtain the decrypted data set. When the attribute set S of the executor satisfies the access policy of the ciphertext, let I ∈ [1,..., l] and satisfy I = i5: ρ(i5) ∈ S. Suppose is a set of constants, and this set of constants corresponds to the attribute set S. If is a valid share in M, then can decrypt the data set D and the random number μ. The decryption of the data set D and the random number μ is as follows:

[0136]

[0137] D||μ = C / e(g, g) α·s Formula (30)

[0138] where D is the decrypted data set, μ is the random number, e is a symmetric bilinear pairing G×G→G T , g is the generator of G, α is a random number in Z p , S is the attribute set, and i5 is a random integer.

[0139] S172. The execution device responds to the information acquisition operation executed by the executor and returns the auxiliary information and the first public key in the first public-private key pair according to the first blockchain address.

[0140] In the embodiment of the present invention, the execution device calls the smart contract function getParam to obtain the auxiliary information aux and the first public key pk according to the first blockchain address address A input by the executor. A . The smart contract function getParam is shown in Table 7 below:

[0141] Table 7 Smart contract function getParam

[0142]

[0143] S173. The execution device receives the value range sent by the blockchain and, in response to the data processing operation executed by the executor, processes the decrypted data set, the data task function, and the value range to obtain a decrypted set.

[0144] In the embodiment of the present invention, the execution device responds to the data processing operation executed by the executor, performs the data processing task T = <f, D, V> on the decrypted data set D, the data task function f, and the value range V, and obtains the decrypted set X = {x1,..., x d}.

[0145] S174. The execution device calculates the solution proof set according to the decryption set and the auxiliary information in response to the data calculation operation executed by the executor.

[0146] In an embodiment of the present invention, the execution device calculates the solution proof set Π according to the decryption set X = {x1,..., x d} and the auxiliary information aux in response to the data calculation operation executed by the executor. The solution proof set Π is as follows:

[0147]

[0148] where e is a symmetric bilinear pairing G×G→G T , g is a generator of G, H3 is the third hash function, H2 is the second hash function, z is the fifth numerical value, y is the first private key, d is a random integer, and j is a random integer.

[0149] S180. The execution device receives the accumulator value sent by the blockchain, and in response to the verification operation executed by the executor, verifies according to the accumulator value and the solution proof set to obtain a verification result.

[0150] In an embodiment of the present invention, the execution device calls the smart contract function verifyProof in response to the verification operation executed by the executor, and verifies according to the accumulator value and the solution proof set to obtain a verification result. If the verification result is passed, the reward is paid; if the verification result is not passed, the reward is not paid. The smart contract function verifyProof is shown in Table 8 below:

[0151] Table 8 Smart contract function verifyProof

[0152]

[0153]

[0154] In summary, in the method for verifying the result of a data processing task based on a smart contract of the present application, the execution device receives the auxiliary information sent by the blockchain, and in response to the decryption operation performed by the executor, processes the CPABE ciphertext based on the decryption operation to obtain a decryption set, calculates a solution proof set according to the decryption set and the auxiliary information, the execution device receives the accumulator value sent by the blockchain, and in response to the verification operation performed by the executor, performs verification according to the accumulator value and the solution proof set to obtain a verification result, thereby improving the reliability of the data processing task result. At the same time, the publishing device responds to the ciphertext acquisition operation performed by the publisher, generates a demand ciphertext and a CPABE ciphertext based on the ciphertext acquisition operation, and publishes the data processing task according to the demand ciphertext and the CPABE ciphertext, ensuring the privacy and security of the input data set D of the publisher.

[0155] Please refer to Figure 8 , which is a schematic structural diagram of a system for verifying the result of a data processing task based on a smart contract disclosed in an embodiment of the present application. In one embodiment, as Figure 8 shown, the present application provides a system 100 for verifying the result of a data processing task based on a smart contract. The system 100 for verifying the result of a data processing task based on a smart contract may at least include: a trusted authority 110, a publishing device 130, an execution device 150, and a blockchain 170. Among them, there is information interaction between the trusted authority 110 and the execution device 150 and the blockchain 170, there is information interaction between the publishing device 130 and the blockchain 170, and there is information interaction between the execution device 150 and the blockchain 170.

[0156] The trusted authority 110 is used to generate system key parameters and initialize system variables according to the initialized smart contract, where the system key parameters include a system public key and a system private key. And the trusted authority 110 is used to obtain the attribute set and the computing power keyword input by the executor, and generate an attribute private key and a power private key according to the attribute set and the computing power keyword.

[0157] The publishing device 130 is used to generate a first public-private key pair based on the first public-private key pair acquisition operation in response to the first public-private key pair acquisition operation performed by the publisher. And the publishing device 130 is used to generate a demand ciphertext and a CPABE ciphertext based on the ciphertext acquisition operation in response to the ciphertext acquisition operation performed by the publisher, and publish the data processing task according to the demand ciphertext and the CPABE ciphertext.

[0158] The execution device 150 is configured to generate a second public-private key pair based on the second public-private key pair acquisition operation performed by the executor in response to the second public-private key pair acquisition operation. And the execution device 150 acquires the CP-ABE ciphertext based on the data processing task matching operation in response to the data processing task matching operation performed by the executor.

[0159] The publishing device 130 is further configured to obtain the second public key in the second public-private key pair based on the second public key acquisition operation in response to the second public key acquisition operation performed by the publisher, generate an accumulator value and auxiliary information according to the second public key, and upload the accumulator value and auxiliary information to the blockchain 170.

[0160] The execution device 150 is further configured to receive the auxiliary information sent by the blockchain, and in response to the decryption operation performed by the executor, process the CP-ABE ciphertext based on the decryption operation to obtain a decryption set, and calculate a solution proof set according to the decryption set and the auxiliary information. And the execution device 150 is configured to receive the accumulator value sent by the blockchain, and in response to the verification operation performed by the executor, perform verification according to the accumulator value and the solution proof set to obtain a verification result.

[0161] In summary, in the data processing task result verification system based on smart contracts of the present application, the execution device 150 receives the auxiliary information sent by the blockchain 170, and in response to the decryption operation performed by the executor, processes the CP-ABE ciphertext based on the decryption operation to obtain a decryption set, calculates a solution proof set according to the decryption set and the auxiliary information, the execution device 150 receives the accumulator value sent by the blockchain 170, and in response to the verification operation performed by the executor, performs verification according to the accumulator value and the solution proof set to obtain a verification result, thereby improving the reliability of the data processing task result. At the same time, the publishing device 130 generates a demand ciphertext and a CP-ABE ciphertext based on the ciphertext acquisition operation in response to the ciphertext acquisition operation performed by the publisher, and publishes the data processing task according to the demand ciphertext and the CP-ABE ciphertext, ensuring the privacy and security of the input data set D of the publisher.

[0162] In the description of this specification, the descriptions referring to terms such as "one embodiment", "some embodiments", "examples", "specific examples", "one implementation manner", "one preferred implementation manner" or "some examples" mean that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.

[0163] Although embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the claims and their equivalents.

Claims

1. A method for verifying the results of a data processing task based on a smart contract, characterized in that: The data processing task result verification method based on smart contracts includes: The trusted authority generates system key parameters and initializes system variables according to the initialization smart contract, wherein the system key parameters include a system public key and a system private key; The trusted authority obtains the attribute set and computing capability keyword input by the executor, and generates an attribute private key and a capability private key according to the attribute set and the computing capability keyword; The publishing device generates a first public-private key pair based on the first public-private key pair acquisition operation in response to the publisher's first public-private key pair acquisition operation, and the executing device generates a second public-private key pair based on the second public-private key pair acquisition operation in response to the executor's second public-private key pair acquisition operation; The publishing device generates a required ciphertext and a CPABE ciphertext based on the ciphertext acquisition operation in response to the ciphertext acquisition operation performed by the publisher, and publishes the data processing task according to the required ciphertext and the CPABE ciphertext; The execution device obtains the CPABE ciphertext based on the data processing task matching operation in response to the data processing task matching operation performed by the executor; The issuing device obtains, in response to the second public key acquisition operation performed by the issuer, the second public key in the second public-private key pair based on the second public key acquisition operation, generates an accumulator value and auxiliary information according to the second public key, and uploads the accumulator value and the auxiliary information to the blockchain; The execution device receives the auxiliary information sent by the blockchain, and in response to the decryption operation performed by the executor, processes the CPABE ciphertext based on the decryption operation to obtain a decryption set, and calculates a solution proof set based on the decryption set and the auxiliary information; The execution device receives the accumulator value sent by the blockchain, and in response to the verification operation performed by the executor, performs verification according to the accumulator value and the solution proof set to obtain a verification result.

2. The method for verifying the result of a data processing task based on a smart contract according to claim 1, characterized in that: The trusted authority obtains the attribute set and computing capability keyword input by the executor, and generates an attribute private key and a capability private key according to the attribute set and the computing capability keyword, including: The trusted authority determines a first value, and generates the attribute private key according to the first value; The trusted authority determines a second value, calculates a target value based on the second value, and generates the capability private key based on the target value and the computing capability keyword.

3. The method for verifying the result of a data processing task based on a smart contract according to claim 2 is characterized in that: The execution device obtains the CPABE ciphertext based on the data processing task matching operation in response to the data processing task matching operation performed by the executor, including: The execution device receives the capability private key sent by the trusted authority, and in response to the data processing task matching operation performed by the executor, determines an eighth value based on the data processing task matching operation, and generates a matching trapdoor according to the capability private key and the eighth value; The execution device obtains a first blockchain address based on the recording operation in response to the recording operation performed by the executor, and obtains the CPABE ciphertext according to the first blockchain address, the matching trapdoor, and the second public key.

4. The method for verifying the result of a data processing task based on a smart contract according to claim 3 is characterized in that: The issuing device obtains the second public key in the second public-private key pair based on the second public key obtaining operation in response to the second public key obtaining operation performed by the issuer, generates an accumulator value and auxiliary information according to the second public key, and uploads the accumulator value and auxiliary information to the blockchain, including: The issuing device obtains the second public key based on the second public key obtaining operation in response to the second public key obtaining operation performed by the issuer, and generates the accumulator value and the auxiliary information according to the second public key; The publishing device uploads the accumulator value and the auxiliary information to the blockchain based on the upload operation in response to the upload operation performed by the publisher.

5. The method for verifying data processing task results based on smart contracts according to claim 4 is characterized in that: The execution device receives the auxiliary information sent by the blockchain, and in response to the decryption operation performed by the executor, processes the CPABE ciphertext based on the decryption operation to obtain a decryption set, and calculates a solution proof set according to the decryption set and the auxiliary information, including: The execution device receives the attribute private key sent by the trusted authority, and in response to the decryption operation performed by the executor, decrypts the CPABE ciphertext according to the attribute private key to obtain a decrypted data set; The execution device responds to the information acquisition operation performed by the executor and returns the auxiliary information and the first public key in the first public-private key pair according to the first blockchain address; The execution device receives the value range sent by the blockchain, and in response to the data processing operation performed by the executor, obtains a decrypted set according to the decrypted data set, the data task function and the value range; The execution device calculates the solution proof set according to the decryption set and the auxiliary information in response to the data calculation operation performed by the executor.

6. The method for verifying the result of a data processing task based on a smart contract according to claim 5 is characterized in that: The capability private key is generated according to the target value and the computing capability keyword, and the capability private key is: AK=(F1,F2,Q) Among them, F1 is the first item of the capability private key, F2 is the second item of the capability private key. Q is the third item of the ability private key, Q = H1 (ability) c , g is the generator of G, h(u′)=a+b·u′, L u′,{u′,u} (0) is the Lagrange interpolation polynomial about u′, L u,{u′,u} (0) is the Lagrange interpolation polynomial about u, c is Z p The random number in, u′ is the second numerical value, H1 is the first hash function, and ability is the computing ability keyword.

7. The method for verifying the result of a data processing task based on a smart contract according to claim 6 is characterized in that: The matching trapdoor is generated according to the capability private key and the eighth value, and the matching trapdoor is: T=(T1,T2,T3) Among them, T1 is the first item of the matching trapdoor, T1=F1 r′ Q, T2 is the second item of the matching trapdoor, T2 = F2 r′ , T3 is the third item of the matching trapdoor, T3 = g r′ , F1 is the first item of the capability private key, F2 is the second item of the capability private key, Q is the third item of the capability private key, r′ is the eighth value, and g is the generator of G.

8. The method for verifying data processing task results based on smart contracts according to claim 7 is characterized in that: The accumulator value is generated according to the second public key, and the accumulator value is: where e is a symmetric bilinear pairing G×G→G T , g is the generator of G, pk B is the second public key, H2 is the second hash function, y is the first private key, μ is the seventh value, z is the fifth value, is the i3th value in the value range V, and n is a random integer.

9. The method for verifying the result of a data processing task based on a smart contract according to claim 8, characterized in that: The solution proof set is calculated according to the decryption set and the auxiliary information, and the solution proof set is: in, H3 is the third hash function, d is a random integer, and j is a random integer.

10. A data processing task result verification system based on smart contracts, characterized in that: The data processing task result verification system based on smart contracts includes: a trusted authority, a publishing device, an execution device and a blockchain, wherein: The trusted authority is used to generate system key parameters and initialize system variables according to the initialization smart contract, wherein the system key parameters include a system public key and a system private key; and the trusted authority is used to obtain the attribute set and computing capability keyword input by the executor, and generate an attribute private key and a capability private key according to the attribute set and the computing capability keyword; The publishing device is used to generate a first public-private key pair based on the first public-private key pair acquisition operation in response to the publisher's first public-private key pair acquisition operation; and the publishing device is used to generate a required ciphertext and a CPABE ciphertext based on the ciphertext acquisition operation in response to the publisher's first ciphertext acquisition operation, and publish the data processing task according to the required ciphertext and the CPABE ciphertext; The execution device is used to generate a second public-private key pair based on the second public-private key pair acquisition operation in response to the second public-private key pair acquisition operation performed by the executor; and the execution device is used to obtain the CPABE ciphertext based on the data processing task matching operation in response to the data processing task matching operation performed by the executor; The publishing device is further configured to, in response to a second public key acquisition operation performed by the publisher, obtain a second public key in the second public-private key pair based on the second public key acquisition operation, generate an accumulator value and auxiliary information according to the second public key, and upload the accumulator value and the auxiliary information to the blockchain; The execution device is further used to receive the auxiliary information sent by the blockchain, and in response to the decryption operation performed by the executor, process the CPABE ciphertext based on the decryption operation to obtain a decryption set, and calculate a solution proof set based on the decryption set and the auxiliary information; and the execution device is used to receive the accumulator value sent by the blockchain, and in response to the verification operation performed by the executor, perform verification based on the accumulator value and the solution proof set to obtain a verification result.

Citation Information

Patent Citations

  • Verifiable privacy protection and personalized crowdsourcing task matching method and system under assistance of block chain

    CN115694787A

  • Multi-party privacy calculation method, device and system based on block chain

    CN115883086A

  • Cloud storage deduplication method based on block chain and fusion encryption technology

    CN117828630A

  • Cloud-side collaborative multi-mode private data circulation method based on smart contract

    US20230041862A1