Data sharing method and device, electronic equipment and storage medium

Through the combination of key generation and encryption algorithms, the interstellar file system and blockchain technology is solved, and the problem of privacy leakage and high cost in data sharing is realized, a secure and controllable data sharing process is achieved, which reduces actual costs and enhances security.

CN120454997APending Publication Date: 2025-08-08INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510845354.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-23
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

Existing data sharing methods face the risk of privacy leakage in multi-party data sharing. The blockchain stores a large amount of data, resulting in high costs and inefficiency, and neglecting privacy computing needs, resulting in high actual cost and low security of data sharing.

Method used

The key generation algorithm is used to generate public and private keys, encrypt the data, and upload the ciphertext and hash indexes to the private cluster of the interstellar file system. A unique hash index is generated and uploaded to the blockchain. The decentralization and immutable characteristics of the blockchain are used to ensure the transparency and security of the data sharing process.

Benefits of technology

By ensuring the security of data transmission storage, combining distributed storage and unique hash index to achieve rapid data retrieval and integrity verification, reducing the actual cost of data sharing, enhancing the security and controllability of data sharing, and promoting multi-party collaboration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120454997A_ABST
    Figure CN120454997A_ABST
Patent Text Reader

Abstract

The invention provides a data sharing method and device, electronic equipment and a storage medium, and relates to the field of financial science and technology. The method comprises the following steps: generating a public key and a private key by adopting a key generation algorithm; obtaining first original data; encrypting the first original data by adopting a preset encryption algorithm according to the public key and the private key to obtain a first ciphertext; uploading the first ciphertext to an interstellar file system private cluster, so that the interstellar file system private cluster generates a corresponding first unique hash index according to the first ciphertext; obtaining a first unique hash index in the private cluster of the interstellar file system; and uploading the first ciphertext, the first unique hash index and the identification information of the first original data to the block chain, so that the cooperative computing party obtains at least one of the first ciphertext, the first unique hash index and the identification information of the first original data from the block chain. According to the method provided by the invention, the actual cost of data sharing is reduced, and the security of data sharing is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of financial technology, and in particular to a data sharing method, device, electronic device and storage medium. Background Art

[0002] Blockchain technology, with its decentralized, traceable, and tamper-resistant nature, offers new solutions for secure data sharing in healthcare, the Internet of Things, and other fields. Traditional data sharing mechanisms face challenges such as centralized data providers, passive user data management, and limited cross-platform interoperability. Blockchain, through distributed storage and smart contracts, can return data sovereignty to users, enhance transparency, and mitigate the risk of single points of failure. However, with the surge in data volumes, protecting privacy and balancing security and efficiency within the openness and transparency of blockchain have become key challenges.

[0003] In the existing technology, there are various methods for data sharing, mainly through various systems and applications to share data in various ways, such as indexing third-party storage data through smart contracts, using proxy re-encryption to achieve fine-grained access control, or combining edge computing with multi-authority encryption to ensure privacy, or using homomorphic encryption and elliptic curve signatures to protect transmission security, etc.

[0004] However, the above-mentioned existing technical methods face the risk of privacy leakage in multi-party data sharing, because sensitive information can be easily obtained by participants or third parties; blockchain stores large amounts of data, resulting in high costs and inefficiency; existing solutions ignore the needs of privacy computing, increasing the computing burden; and rely on a single platform to process data, making it difficult to ensure integrity and security. These together lead to technical problems such as high actual costs and low security of data sharing. Summary of the Invention

[0005] The present application provides a data sharing method, device, electronic device and storage medium to solve the technical problems of high actual cost and low security of data sharing.

[0006] In a first aspect, the present application provides a data sharing method, applied to an initiator, comprising:

[0007] Use key generation algorithm to generate public key and private key;

[0008] Acquiring first original data;

[0009] Using a preset encryption algorithm, the first original data is encrypted according to the public key and the private key to obtain a first ciphertext;

[0010] Uploading the first ciphertext to the InterPlanetary File System private cluster, so that the InterPlanetary File System private cluster generates a corresponding first unique hash index based on the first ciphertext;

[0011] Get the first unique hash index in the InterPlanetary File System private cluster;

[0012] The first ciphertext, the first unique hash index, and the identification information of the first original data are uploaded to the blockchain, so that the collaborative computing party obtains at least one of the first ciphertext, the first unique hash index, and the identification information of the first original data from the blockchain.

[0013] In a second aspect, the present application provides a data sharing method, which is applied to collaborative computing parties, and the method includes:

[0014] Obtain at least one of the first ciphertext, the first unique hash index, and identification information of the first original data from the blockchain;

[0015] Among them, the identification information of the first ciphertext, the first unique hash index and the first original data is that the initiator uses a key generation algorithm to generate a public key and a private key; obtains the first original data; uses a preset encryption algorithm to encrypt the first original data according to the public key and the private key to obtain a first ciphertext; uploads the first ciphertext to the InterPlanetary File System private cluster, so that the InterPlanetary File System private cluster generates a corresponding first unique hash index based on the first ciphertext; and after obtaining the first unique hash index in the InterPlanetary File System private cluster, uploads it to the blockchain.

[0016] In a third aspect, the present application provides a data sharing device, which is applied to an initiator, and includes:

[0017] A first generation module is used to generate a public key and a private key using a key generation algorithm;

[0018] A first acquisition module, configured to acquire first original data;

[0019] An encryption module, configured to encrypt the first original data using a preset encryption algorithm according to a public key and a private key to obtain a first ciphertext;

[0020] A first uploading module, configured to upload the first ciphertext to the InterPlanetary File System private cluster, so that the InterPlanetary File System private cluster generates a corresponding first unique hash index according to the first ciphertext;

[0021] A second acquisition module is used to obtain a first unique hash index in the InterPlanetary File System private cluster;

[0022] The second uploading module is used to upload the first ciphertext, the first unique hash index and the identification information of the first original data to the blockchain, so that the collaborative computing party obtains at least one of the first ciphertext, the first unique hash index and the identification information of the first original data from the blockchain.

[0023] In a fourth aspect, the present application provides a data sharing device for collaborative computing, the device comprising:

[0024] A third acquisition module is configured to acquire at least one of the first ciphertext, the first unique hash index, and identification information of the first original data from the blockchain;

[0025] Among them, the identification information of the first ciphertext, the first unique hash index and the first original data is that the initiator uses a key generation algorithm to generate a public key and a private key; obtains the first original data; uses a preset encryption algorithm to encrypt the first original data according to the public key and the private key to obtain a first ciphertext; uploads the first ciphertext to the InterPlanetary File System private cluster, so that the InterPlanetary File System private cluster generates a corresponding first unique hash index based on the first ciphertext; and after obtaining the first unique hash index in the InterPlanetary File System private cluster, uploads it to the blockchain.

[0026] In a fifth aspect, an embodiment of the present application provides an electronic device, including: a memory, a processor;

[0027] Memory stores computer-executable instructions;

[0028] The processor executes the computer-executable instructions stored in the memory, so that the processor performs the method of the first aspect or the second aspect as described above.

[0029] In a sixth aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the method of the first or second aspect above.

[0030] In a seventh aspect, an embodiment of the present application provides a computer program product, comprising a computer program, which implements the method of the first or second aspect above when executed by a processor.

[0031] The present application provides a data sharing method, device, electronic device and storage medium, which ensure the security of data transmission and storage through key generation and encryption algorithms, improve data reliability and availability by combining the distributed storage of the InterPlanetary File System private cluster, and generate a unique hash index to achieve rapid data retrieval and integrity verification. The decentralized and tamper-proof characteristics of the blockchain are then used to ensure that the sharing process is transparent and traceable, ultimately enabling collaborative computing parties to securely obtain data, thereby protecting data privacy and promoting multi-party collaboration, effectively balancing the security, controllability and interoperability of data sharing, and achieving the technical effect of reducing the actual cost of data sharing and enhancing the security of data sharing. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0033] Figure 1 A schematic diagram of an application data processing system architecture provided in an embodiment of the present application;

[0034] Figure 2 A schematic diagram of a data sharing method provided in this application embodiment Figure 1 ;

[0035] Figure 3 A schematic diagram of a data sharing method provided in this application embodiment Figure 2 ;

[0036] Figure 4 A model architecture diagram of a data sharing method provided in an embodiment of the present application;

[0037] Figure 5 A flow chart of a data sharing method provided in an embodiment of the present application;

[0038] Figure 6 A schematic diagram of a data sharing method provided in this embodiment of the application Figure 3 ;

[0039] Figure 7 A schematic diagram of a data sharing method provided in this embodiment of the application Figure 4 ;

[0040] Figure 8 A schematic diagram of a data sharing method provided in this application embodiment Figure 5 ;

[0041] Figure 9 A schematic diagram of a data sharing method provided in this application embodiment Figure 6 ;

[0042] Figure 10 A schematic diagram of the structure of a data sharing device provided in an embodiment of the present application Figure 1 ;

[0043] Figure 11 A schematic diagram of the structure of a data sharing device provided in an embodiment of the present application Figure 2 ;

[0044] Figure 12 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application.

[0045] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION

[0046] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.

[0047] It should be noted that the data sharing methods, devices, equipment, storage media and products provided in this application can be used in the field of financial technology, and can also be used in any field other than financial technology. The application fields of the data sharing methods, devices, equipment, storage media and products in this application are not limited.

[0048] Existing technical methods face the risk of privacy leakage in multi-party data sharing because sensitive information can be easily obtained by participants or third parties; blockchain stores large amounts of data, resulting in high costs and inefficiency; existing solutions ignore the needs of privacy computing, increasing the computing burden; and rely on a single platform to process data, making it difficult to ensure integrity and security. These together lead to technical problems such as high actual costs and low security of data sharing.

[0049] In response to the above problems, the present application provides a data sharing method, device, electronic device and storage medium, which ensure the security of data transmission and storage through key generation and encryption algorithms, improve data reliability and availability by combining the distributed storage of the InterPlanetary File System private cluster, and generate a unique hash index to achieve rapid data retrieval and integrity verification. The decentralized and tamper-proof characteristics of the blockchain are then used to ensure that the sharing process is transparent and traceable, ultimately enabling collaborative computing to securely obtain data, thereby protecting data privacy and promoting multi-party collaboration, effectively balancing the security, controllability and interoperability of data sharing, and achieving the technical effect of reducing the actual cost of data sharing and enhancing the security of data sharing.

[0050] Figure 1 This is a schematic diagram of an application data processing system architecture provided by an embodiment of the present application. The application data processing system is a computer device and is applied to a client browser. Figure 1 As shown, the above architecture includes a data acquisition device 101 and a display device 102 .

[0051] It is understood that the structure illustrated in the embodiments of this application does not constitute a specific limitation on the architecture of the application data processing system. In other feasible implementations of this application, the above architecture may include more or fewer components than shown, or combine or split certain components, or arrange the components differently. The specific configuration can be determined based on the actual application scenario and is not limited here. Figure 1 The components shown can be implemented in hardware, software, or a combination of software and hardware.

[0052] In a specific implementation process, the data acquisition device 101 may include an input / output interface and may also include a communication interface. The data acquisition device 101 may be connected to the processing device via the input / output interface or the communication interface.

[0053] The display device 102 may also be a touch screen display or a screen of a terminal device, which is used to receive user instructions while displaying the above-mentioned content to achieve interaction with the user.

[0054] It should be understood that the above-mentioned processing device can be implemented by a processor reading instructions in a memory and executing the instructions, or it can be implemented by a chip circuit.

[0055] In addition, the network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field can know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0056] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.

[0057] Figure 2 A schematic diagram of a data sharing method provided in this application embodiment Figure 1 ,like Figure 2 As shown, the data sharing method provided in the embodiment of the present application is applied to the initiator, including:

[0058] S201. Generate a public key and a private key using a key generation algorithm.

[0059] The initiator uses a key generation algorithm, such as the Paillier Homomorphic Encryption Algorithm (PEncrypt), to generate public and private keys. The public key is used to encrypt data, while the private key is kept securely by the initiator for subsequent data decryption or verification.

[0060] S202: Acquire first original data.

[0061] The initiator obtains the first original data that needs to be shared.

[0062] S203: Using a preset encryption algorithm, encrypt the first original data according to the public key and the private key to obtain a first ciphertext.

[0063] The initiator uses a preset encryption algorithm, such as the key generation algorithm PEncrypt algorithm of the Paillier homomorphic encryption algorithm, to encrypt the first original data using the generated public key and private key to generate a first ciphertext.

[0064] S204: Upload the first ciphertext to the InterPlanetary File System private cluster, so that the InterPlanetary File System private cluster generates a corresponding first unique hash index based on the first ciphertext.

[0065] In this embodiment, the InterPlanetary File System refers to IPFS, which is a distributed file system that can provide a unique hash index for data to ensure the data's immutability and traceability.

[0066] The initiator uploads the encrypted first ciphertext to the IPFS private cluster, and the IPFS private cluster provides it with a corresponding first unique hash index based on the first ciphertext.

[0067] S205: Obtain the first unique hash index in the InterPlanetary File System private cluster.

[0068] The IPFS private cluster generates the corresponding first unique hash index based on the uploaded ciphertext and returns the index to the initiator.

[0069] It should be noted that this first unique hash index is the unique identifier of the data in the IPFS network.

[0070] S206. Upload the first ciphertext, the first unique hash index, and the identification information of the first original data to the blockchain, so that the collaborative computing party obtains at least one of the first ciphertext, the first unique hash index, and the identification information of the first original data from the blockchain.

[0071] The initiator uploads the first ciphertext, the first unique hash index, and the identification information of the first original data to the blockchain. The decentralized and tamper-proof nature of the blockchain ensures the transparency and security of the data sharing process. The collaborating computing parties can obtain this information from the blockchain for subsequent operations.

[0072] The present embodiment provides a data sharing method, which, on the one hand, provides a basis for data encryption by generating public and private keys, ensuring that subsequent encryption operations have mathematical guarantees; on the other hand, obtaining the original data clarifies the data objects that need to be protected, establishing the prerequisites for the encryption process; at the same time, the original data is converted into ciphertext using an encryption algorithm to achieve data confidentiality protection and prevent unauthorized access during transmission and storage; in addition, the ciphertext is uploaded to the IPFS private cluster, and with the help of a distributed storage architecture and a unique hash index generation mechanism, the data is not only persistently stored, but also tamper-proof through the content addressing feature; further, the obtained hash index serves as the unique identity of the data in the IPFS network, providing reliable credentials for subsequent data retrieval and verification; finally, the ciphertext, hash index and identification information are uploaded to the blockchain, and the distributed ledger characteristics of the blockchain are used to construct a tamper-proof and fully traceable data sharing channel, ensuring that the collaborative computing parties can safely obtain data and participate in subsequent computing processes, achieving the technical effect of reducing the actual cost of data sharing and enhancing the security of data sharing.

[0073] Figure 3 A schematic diagram of a data sharing method provided in this application embodiment Figure 2 ,like Figure 3 As shown, the data sharing method provided in the embodiment of the present application is applied to a collaborative computing party, including:

[0074] S301. Obtain at least one of a first ciphertext, a first unique hash index, and identification information of first original data from a blockchain.

[0075] In this embodiment, the identification information of the first ciphertext, the first unique hash index and the first original data is that the initiator uses a key generation algorithm to generate a public key and a private key; obtains the first original data; uses a preset encryption algorithm to encrypt the first original data according to the public key and the private key to obtain a first ciphertext; uploads the first ciphertext to the InterPlanetary File System private cluster, so that the InterPlanetary File System private cluster generates a corresponding first unique hash index based on the first ciphertext; and after obtaining the first unique hash index in the InterPlanetary File System private cluster, uploads it to the blockchain.

[0076] A data sharing method provided in this embodiment realizes the key connection of the data sharing process by allowing collaborative computing parties to obtain ciphertext, hash index or original data identification information from the blockchain. It not only ensures the authority of the data acquisition channel - relying on the tamper-proof characteristics of the blockchain to ensure that the acquired data index is authentic and valid, but also supports collaborative parties to select data access dimensions on demand through a flexible information acquisition mechanism, creating the necessary conditions for subsequent joint computing under the premise of protecting the privacy of the original data, and achieving the technical effect of reducing the actual cost of data sharing and enhancing the security of data sharing.

[0077] Figure 4 A model architecture diagram of a data sharing method provided in an embodiment of the present application, such as Figure 4 As shown, a data sharing method provided by an embodiment of the present application includes a user layer, a data layer, a computing layer, and an infrastructure layer, which correspond to four entities, namely the initiator, the collaborative computing party, the IPFS private cluster, and the blockchain network. These entities work closely together to realize the interaction process at each stage.

[0078] It is understandable that Figure 4 It is only for illustration of the effect and does not affect the scope of protection of this application.

[0079] Figure 5 A flow chart of a data sharing method provided in an embodiment of the present application is shown as follows: Figure 5 As shown, the data sharing method provided in the embodiment of the present application includes:

[0080] S501. The initiator uses a key generation algorithm to generate a public key and a private key.

[0081] S502: The initiator obtains first original data.

[0082] S503: The initiator uses a preset encryption algorithm to encrypt the first original data according to the public key and the private key to obtain a first ciphertext.

[0083] S504: The initiator uploads the first ciphertext to the InterPlanetary File System private cluster.

[0084] S505. The InterPlanetary File System private cluster generates a corresponding first unique hash index based on the first ciphertext.

[0085] S506: The initiator obtains the first unique hash index in the InterPlanetary File System private cluster.

[0086] S507. The initiator uploads the first ciphertext, the first unique hash index, and the identification information of the first original data to the blockchain.

[0087] S508. The collaborative computing party obtains at least one of the first ciphertext, the first unique hash index, and the identification information of the first original data from the blockchain.

[0088] This embodiment provides a data sharing method that ensures the security of data transmission and storage through key generation and encryption algorithms, improves data reliability and availability in combination with the distributed storage of the InterPlanetary File System private cluster, and generates a unique hash index to achieve rapid data retrieval and integrity verification. The decentralized and tamper-proof characteristics of the blockchain are then used to ensure that the sharing process is transparent and traceable, ultimately enabling collaborative computing parties to securely obtain data, thereby protecting data privacy and promoting multi-party collaboration, effectively balancing the security, controllability, and interoperability of data sharing, and achieving the technical effect of reducing the actual cost of data sharing and enhancing the security of data sharing.

[0089] Optional, Figure 6 A schematic diagram of a data sharing method provided in this application embodiment Figure 3 ,like Figure 6 As shown, this embodiment is applied to the initiator on the basis of the above embodiment, and the generation process of the public key and the private key is described in detail, including:

[0090] S601: Determine the first largest prime number and the second largest prime number.

[0091] In this embodiment, the first largest prime number and the second largest prime number are relatively prime.

[0092] In the Paillier homomorphic encryption algorithm, in order to generate the public key and private key, it is first necessary to determine two large prime numbers, called the first large prime number p and the second large prime number q. These two prime numbers must meet the condition of being mutually prime:

[0093]

[0094] That is, their greatest common divisor is 1.

[0095] It should be noted that large prime numbers are chosen to enhance the security of the encryption algorithm, while the coprime condition is to ensure the correctness of subsequent mathematical operations.

[0096] S602: Determine the product of the first largest prime number and the second largest prime number as a public key.

[0097] After determining two large prime numbers, the next step is to determine their product as the public key.

[0098] Specifically, multiply the first largest prime number by the second largest prime number:

[0099]

[0100] The result n is part of the public key. The public key n is used during the encryption process to convert the original data into ciphertext, ensuring the confidentiality of the data during transmission and storage.

[0101] S603: Determine the private key according to the least common multiple of the first largest prime number and the second largest prime number.

[0102] The generation of the private key depends on the least common multiple of these two prime numbers. First, we need to calculate the least common multiple λ of these two prime numbers minus 1:

[0103]

[0104] Wherein, lcm represents the least common multiple.

[0105] Then, the private key b is determined by modular inversion based on λ and another parameter (usually related to the Euler function in the Paillier algorithm). The private key b satisfies:

[0106]

[0107] The private key b is an indispensable key parameter in the decryption process. It allows only the initiator holding the private key to decrypt the ciphertext and restore the original data.

[0108] A data sharing method provided in this embodiment lays a secure mathematical foundation for the Paillier homomorphic encryption algorithm by selecting two large prime numbers and ensuring that they are mutually prime. The use of large prime numbers greatly increases the difficulty of cracking, while the mutual prime condition ensures the feasibility of subsequent key generation. At the same time, using the product of the two large prime numbers as the public key not only simplifies the implementation of the encryption process, but also ensures the universality of data encryption through the publicity of the public key. Any user holding the public key can encrypt the data. In addition, by calculating the lowest common multiple of the two large prime numbers and generating a private key, the security core of the encryption system is constructed. The confidentiality of the private key is directly related to the security of the data. Only the initiator holding the private key can decrypt the ciphertext, thereby realizing controllable data sharing and privacy protection.

[0109] Optional, Figure 7 A schematic diagram of a data sharing method provided in this application embodiment Figure 4 ,like Figure 7 As shown, this embodiment is applied to the initiator on the basis of the above embodiment, and the process of obtaining the first ciphertext is described in detail, including:

[0110] S701: Determine a random number.

[0111] During the encryption process, a random number is required to ensure that the ciphertext generated each time is unique and unpredictable. This random number is randomly selected from all numbers that are coprime with the public key n. It serves as a temporary parameter in the encryption process and does not participate in key generation, but it does affect the final ciphertext.

[0112] S702: Determine an encryption factor based on the random number and the public key.

[0113] The encryption factor can be calculated based on the random number determined in S701 and the public key n generated previously.

[0114] Specifically, the random number is squared modulo n, and the result is the encryption factor. This encryption factor plays a key role in the encryption process, ensuring that even with the same original data and public key, the ciphertext generated each time is different.

[0115] S703. Determine the base number according to the public key.

[0116] The cardinality is determined based on the public key n and the first original data M. In the Paillier encryption algorithm, the cardinality is usually expressed as:

[0117]

[0118] Wherein, M is the first original data, and n is the public key.

[0119] The cardinality is an important parameter in the encryption process. It is closely related to the first original data and the public key, ensuring the correct relationship between the encrypted ciphertext and the first original data.

[0120] S704: Encrypt the first original data using the binomial theorem according to the cardinality and the encryption factor to obtain a first ciphertext.

[0121] After determining the base and encryption factor, the binomial theorem can be used to encrypt the first original data. Specifically, the base and the encryption factor are multiplied and the result is squared modulo n, resulting in the first ciphertext. This process utilizes the binomial theorem to expand and simplify the calculation, improving encryption efficiency.

[0122] Specifically, during the PEncrypt data encryption phase of the Paillier algorithm, the user randomly selects multiple ,in, , and precompute .

[0123] For any first original data , the initiator randomly selects a pre-calculated encryption factor , use it to encrypt and generate the first ciphertext CT:

[0124]

[0125] A data sharing method provided in this embodiment enhances the security of the encryption process by introducing random numbers, ensuring that the ciphertext generated by each encryption is different, and effectively resisting security threats such as replay attacks; secondly, an encryption factor is calculated based on the random number and the public key, providing the necessary intermediate value for the encryption process, ensuring the correctness and security of the encryption; in addition, a cardinality is determined based on the public key and the first original data, and key parameters in the encryption process are constructed, ensuring the correct correspondence between the encrypted ciphertext and the first original data; finally, the binomial theorem is used for encryption processing, which simplifies the calculation process, improves encryption efficiency, and makes the encryption process more efficient and feasible.

[0126] Optional, Figure 8 A schematic diagram of a data sharing method provided in this application embodiment Figure 5 ,like Figure 8 As shown, this embodiment, based on the above embodiment, is applied to the initiator, and describes in detail the specific process of uploading the first ciphertext, the first unique hash index, and the identification information of the first original data to the blockchain, and also provides supplementary explanations of its subsequent processes, including:

[0127] S801: Initiate a transaction request to the blockchain.

[0128] In this embodiment, the on-chain transaction request includes the signature information of the initiator.

[0129] The initiator initiates a transaction request to the blockchain network. This request must include the initiator's digital signature. This signature, generated using asymmetric encryption technology, proves the legitimacy of the transaction initiator to the blockchain network, ensuring that subsequent operations have a trusted identity.

[0130] S802. In response to a signature information verification success request of the smart contract of the blockchain, upload the first ciphertext, the first unique hash index, and the identification information of the first original data to the smart contract of the blockchain.

[0131] The blockchain smart contract first verifies the validity of the initiator's signature, including checking the matching of the signature with the public key and the operation permissions. Once verified, the smart contract permanently stores the first ciphertext, the first unique hash index, and the first original data identification information in a structured form in the blockchain ledger, forming an unalterable data evidence.

[0132] S803: Generate a calculation request according to the public key, the first ciphertext, the calculation method, and the calculation result format.

[0133] Based on business needs, the initiator generates a computation request that explicitly specifies the public key to be used, the first ciphertext to be processed, the computational logic to be executed (e.g., addition), and the expected result format (e.g., aggregate value). These parameters together define the specific specifications of the collaborative computation task.

[0134] S804. Initiate a calculation request to the collaborative computing party through the blockchain, so that the collaborative computing party obtains the calculation result based on the public key, the first ciphertext, the calculation method and the calculation result form, combined with the collaborative computing party's second ciphertext, and uploads the calculation result to the blockchain.

[0135] The blockchain network acts as a trusted relay, broadcasting computation requests to authorized collaborators. Upon receiving the request, the collaborators perform homomorphic addition on the ciphertext, combining it with their own second ciphertext (private data encrypted with the same public key). This generates a ciphertext containing the computation result of both parties, uploads the result to IPFS storage, and records the result hash index on the blockchain.

[0136] S805. Obtain calculation results from the blockchain.

[0137] The initiator queries the hash index of the calculation result through the blockchain smart contract, and then retrieves the complete ciphertext of the calculation result from the IPFS network. This process ensures that the initiator can verify the authenticity of the result source while maintaining the integrity of the data transmission.

[0138] S806. Determine a private key component for decryption based on the private key.

[0139] The initiator extracts the private key components required for decryption from the private key storage, including the private key b and parameter λ in the Paillier algorithm. These components are the mathematical basis for performing ciphertext decryption, and their confidentiality is directly related to data security.

[0140] S807: Decrypt the calculation result according to the private key component and the first ciphertext, and the auxiliary function corresponding to the preset encryption algorithm in the preset decryption algorithm to obtain the target calculation result.

[0141] The initiator uses the private key components b and λ, combined with the auxiliary function L in the Paillier decryption algorithm, to decrypt the calculated ciphertext. For the first original data M, the solution relies on the following calculation:

[0142]

[0143]

[0144] in, Represents the homomorphically encrypted ciphertext to be decrypted, and b is the private key component.

[0145] Through modular inverse operations and integer decomposition technology, the ciphertext result is finally converted into a readable first original data form, completing the entire security calculation process.

[0146] This embodiment provides a data sharing method, which, on the one hand, ensures the authenticity of the transaction initiator's identity through digital signatures to prevent forged requests; on the other hand, uses smart contracts to realize the automated execution of data evidence to ensure the non-tamperability of data on the chain; in addition, the calculation logic is explicitly encoded as verifiable parameters to ensure the traceability of multi-party computing tasks; at the same time, the blockchain broadcast mechanism is used to achieve the secure distribution of computing requests, and the IPFS storage is combined to ensure trusted access to the result data; and, a data acquisition channel for on-chain and off-chain collaboration is constructed, taking into account both result verification efficiency and storage scalability; further, through on-demand extraction of private key components, the risk of key leakage is reduced while ensuring decryption capabilities; finally, the ciphertext calculation results are restored to the first original data through mathematical transformation, and the cross-institutional collaborative computing goal is achieved under the premise of protecting data privacy throughout the process.

[0147] Optional, Figure 9 A schematic diagram of a data sharing method provided in this application embodiment Figure 6 ,like Figure 9 As shown, this embodiment, based on the above embodiment, is applied to the collaborative computing party and provides a supplementary description of the subsequent process of obtaining at least one of the first ciphertext, the first unique hash index, and the identification information of the first original data from the blockchain, including:

[0148] S901. Respond to a computing request initiated by an initiator through a blockchain.

[0149] In this embodiment, the calculation request is generated by the initiator according to the public key, the first ciphertext, the calculation method and the calculation result format.

[0150] The collaborative computing party continuously monitors the blockchain network. When it detects a computing request broadcast by the initiator, it first verifies the legitimacy of the request. Through the blockchain's consensus mechanism and smart contract code, the collaborative computing party confirms that the request contains a valid public key, ciphertext data reference, and computational logic description, and that the initiator's signature has been authenticated by the blockchain network, thus establishing the foundation for task execution.

[0151] S902: Obtain a calculation result based on the public key, the first ciphertext, the calculation method, and the calculation result format, combined with the second ciphertext of the collaborative calculation party.

[0152] The collaborating computing party extracts the second ciphertext (private data encrypted with the same public key) from local secure storage and parses the homomorphic addition operation rules in the computation request. Using the multiplication-equals-addition property of the Paillier encryption system, the homomorphic addition operation is performed in the ciphertext domain:

[0153]

[0154] Among them, E(M) is the ciphertext of the initiator's data, E(M i ) is the collaborative computing party data ciphertext, Represents the multiplication operation of the ciphertext.

[0155] The final result is a form like E(M+M i ) calculation results, and the whole process does not need to expose the original data.

[0156] S903: Upload the calculation results to the blockchain.

[0157] The collaborating parties upload the encrypted results to a private IPFS cluster. After the system generates a new second unique hash index, the collaborating parties write the second hash index and the computational process metadata (such as the public key identifier used and the computational logic version) into the blockchain smart contract. Through the smart contract's event triggering mechanism, the initiator and other participants are automatically notified of the results' readiness, forming a complete chain of evidence for the computational results.

[0158] This embodiment provides a data sharing method that realizes automatic discovery of computing tasks through the monitoring mechanism of the blockchain, and combines the request verification of the smart contract to ensure the credibility of the task source, thereby establishing a secure execution environment for subsequent calculations. At the same time, the ciphertext operation characteristics of Paillier homomorphic encryption are utilized to complete multi-party data joint calculations without trusting a third party, thereby protecting data privacy and ensuring that the calculation results are equivalent to the first original data operation. In addition, through the collaborative storage of IPFS and blockchain, a trusted evidence chain of the calculation results is constructed, the hash index ensures that the results are verifiable, and the smart contract notification mechanism realizes real-time synchronization of the calculation completion status, ultimately forming a complete secure multi-party computing closed loop.

[0159] Figure 10 A schematic diagram of the structure of a data sharing device provided in an embodiment of the present application Figure 1 The device of this embodiment can be in the form of software and / or hardware. Figure 10 As shown, an embodiment of the present application provides a data sharing device 1000, which is applied to an initiator. The device includes: a first generation module 1001, a first acquisition module 1002, an encryption module 1003, a first upload module 1004, a second acquisition module 1005, and a second upload module 1006:

[0160] The first generation module 1001 is used to generate a public key and a private key using a key generation algorithm;

[0161] A first acquisition module 1002 is used to acquire first original data;

[0162] The encryption module 1003 is configured to encrypt the first original data using a preset encryption algorithm according to the public key and the private key to obtain a first ciphertext;

[0163] A first uploading module 1004 is configured to upload the first ciphertext to the InterPlanetary File System private cluster, so that the InterPlanetary File System private cluster generates a corresponding first unique hash index based on the first ciphertext;

[0164] The second acquisition module 1005 is used to obtain a first unique hash index in the InterPlanetary File System private cluster;

[0165] The second uploading module 1006 is used to upload the first ciphertext, the first unique hash index, and the identification information of the first original data to the blockchain, so that the collaborative computing party obtains at least one of the first ciphertext, the first unique hash index, and the identification information of the first original data from the blockchain.

[0166] In a possible implementation, the first generating module 1001 is further configured to:

[0167] Determine a first largest prime number and a second largest prime number; wherein the first largest prime number and the second largest prime number are mutually prime;

[0168] Determine the product of the first largest prime number and the second largest prime number as the public key;

[0169] The private key is determined based on the least common multiple of the first and second largest prime numbers.

[0170] In one possible implementation, the encryption module 1003 is further configured to:

[0171] Determine the random number;

[0172] Determine the encryption factor based on the random number and the public key;

[0173] The first original data is encrypted according to the encryption factor to obtain a first ciphertext.

[0174] In one possible implementation, the encryption module 1003 is further configured to:

[0175] According to the public key, determine the base;

[0176] According to the cardinality and the encryption factor, the first original data is encrypted using the binomial theorem to obtain a first ciphertext.

[0177] In a possible implementation, the second uploading module 1006 is further configured to:

[0178] Initiate a transaction request to the blockchain; the transaction request includes the signature information of the initiator;

[0179] In response to a signature information verification success request of the smart contract of the blockchain, the first ciphertext, the first unique hash index, and the identification information of the first original data are uploaded to the smart contract of the blockchain.

[0180] In a possible implementation, the second uploading module 1006 is further configured to:

[0181] Generate a calculation request according to the public key, the first ciphertext, the calculation method, and the calculation result format;

[0182] A calculation request is initiated to the collaborative computing party through the blockchain, so that the collaborative computing party obtains the calculation result based on the public key, the first ciphertext, the calculation method and the calculation result form, combined with the collaborative computing party's second ciphertext, and uploads the calculation result to the blockchain.

[0183] In a possible implementation, the second uploading module 1006 is further configured to:

[0184] Get the calculation results from the blockchain;

[0185] The calculation results are decrypted using a preset decryption algorithm to obtain the target calculation results.

[0186] This embodiment provides a data sharing device that can execute the method provided in the above method embodiment applied to the initiator. Its implementation principle and technical effects are similar and will not be described in detail in this embodiment.

[0187] Figure 11 A schematic diagram of the structure of a data sharing device provided in an embodiment of the present application Figure 2 The device of this embodiment can be in the form of software and / or hardware. Figure 11 As shown, an embodiment of the present application provides a data sharing device 1100, which is applied to a collaborative computing party. The device includes: a third acquisition module 1101:

[0188] A third acquisition module 1101 is configured to acquire at least one of the first ciphertext, the first unique hash index, and identification information of the first original data from the blockchain;

[0189] Among them, the identification information of the first ciphertext, the first unique hash index and the first original data is that the initiator uses a key generation algorithm to generate a public key and a private key; obtains the first original data; uses a preset encryption algorithm to encrypt the first original data according to the public key and the private key to obtain a first ciphertext; uploads the first ciphertext to the InterPlanetary File System private cluster, so that the InterPlanetary File System private cluster generates a corresponding first unique hash index based on the first ciphertext; and after obtaining the first unique hash index in the InterPlanetary File System private cluster, uploads it to the blockchain.

[0190] In a possible implementation, the third obtaining module 1101 is further configured to:

[0191] Responding to a computation request initiated by an initiator through a blockchain; wherein the computation request is generated by the initiator based on the public key, the first ciphertext, the computation method, and the computation result format;

[0192] Obtaining a calculation result based on the public key, the first ciphertext, the calculation method, and the calculation result format, combined with the second ciphertext of the collaborative calculation party;

[0193] Upload the calculation results to the blockchain.

[0194] This embodiment provides a data sharing device that can execute the method provided in the above-mentioned method embodiment applied to collaborative computing parties. Its implementation principle and technical effects are similar and will not be described in detail in this embodiment.

[0195] Figure 12 This is a schematic diagram of the structure of an electronic device provided by this application. Figure 12 As shown, the electronic device 1200 provided in this embodiment includes: at least one processor 1201 and a memory 1202. Optionally, the device 1200 also includes a communication component 1203. The processor 1201, the memory 1202, and the communication component 1203 are connected via a bus.

[0196] During the specific implementation process, at least one processor 1201 executes the computer-executable instructions stored in the memory 1202, so that at least one processor 1201 executes the above-mentioned method applied to the initiator or the collaborative computing party.

[0197] The specific implementation process of the processor 1201 can refer to the above-mentioned method embodiment applied to the initiator or the collaborative computing party. The implementation principle and technical effects are similar and will not be repeated here in this embodiment.

[0198] In the above embodiments, it should be understood that the processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASICs), etc. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in the present invention may be directly executed by a hardware processor or by a combination of hardware and software modules within the processor.

[0199] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage.

[0200] A bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. Buses can be categorized as address buses, data buses, and control buses. For ease of illustration, the buses in the drawings of this application are not limited to just one bus or just one type of bus.

[0201] An embodiment of the present application also provides a computer program product, including a computer program, which implements the above-mentioned method applied to an initiator or a collaborative computing party when executed by a processor.

[0202] An embodiment of the present application also provides a computer-readable storage medium, in which computer-executable instructions are stored. When a processor executes the computer-executable instructions, the above-mentioned method applied to the initiator or the collaborative computing party is implemented.

[0203] The readable storage medium may be implemented by any type of volatile or non-volatile memory device, or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium may be any available medium that can be accessed by a general-purpose or special-purpose computer.

[0204] An exemplary readable storage medium is coupled to a processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be an integral part of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium can also exist in the device as discrete components.

[0205] The division of units is merely a logical functional division; actual implementations may employ alternative divisions, such as combining or integrating multiple units or components into another system, or omitting or disabling certain features. Furthermore, any direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection between devices or units, either through an interface, electrical, mechanical, or other means.

[0206] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0207] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0208] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the method of the present invention. The aforementioned storage medium includes various media that can store program code, such as USB flash drives, mobile hard drives, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical disks.

[0209] Those skilled in the art will appreciate that all or part of the steps in the above-described method embodiments can be implemented using hardware associated with program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0210] Finally, it should be noted that those skilled in the art will readily identify other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. The present invention is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of the present invention and include common knowledge or customary techniques in the art not disclosed herein. The present invention is not limited to the precise structure described above and illustrated in the accompanying drawings, and various modifications and variations may be made without departing from the scope thereof. The scope of the present invention is limited solely by the appended claims.

Claims

1. A data sharing method, characterized in that: Applied to the initiator, the method includes: Use key generation algorithm to generate public key and private key; Acquiring first original data; Using a preset encryption algorithm, the first original data is encrypted according to the public key and the private key to obtain a first ciphertext; Uploading the first ciphertext to the InterPlanetary File System private cluster, so that the InterPlanetary File System private cluster generates a corresponding first unique hash index based on the first ciphertext; Obtain a first unique hash index in the InterPlanetary File System private cluster; Upload the first ciphertext, the first unique hash index, and the identification information of the first original data to the blockchain, so that the collaborative computing party obtains at least one of the first ciphertext, the first unique hash index, and the identification information of the first original data from the blockchain.

2. The method according to claim 1, characterized in that The key generation algorithm is used to generate the public key and the private key, including: Determine a first largest prime number and a second largest prime number; wherein the first largest prime number and the second largest prime number are mutually prime; Determine the product of the first largest prime number and the second largest prime number as the public key; The private key is determined according to the least common multiple of the first largest prime number and the second largest prime number.

3. The method according to claim 2, characterized in that The method of encrypting the first original data using a preset encryption algorithm to obtain a first ciphertext includes: Determine the random number; Determining an encryption factor based on the random number and the public key; The first original data is encrypted according to the encryption factor to obtain the first ciphertext.

4. The method according to claim 3, characterized in that The step of encrypting the first original data according to the encryption factor to obtain the first ciphertext includes: Determining a base based on the public key; The first original data is encrypted using the binomial theorem according to the cardinality and the encryption factor to obtain the first ciphertext.

5. The method according to any one of claims 1 to 4, characterized in that The uploading of the first ciphertext, the first unique hash index, and the identification information of the first original data to the blockchain includes: Initiate an on-chain transaction request to the blockchain; wherein the on-chain transaction request includes the signature information of the initiator; In response to a signature information verification success request of the smart contract of the blockchain, the first ciphertext, the first unique hash index and the identification information of the first original data are uploaded to the smart contract of the blockchain.

6. The method according to any one of claims 1 to 4, characterized in that After uploading the first ciphertext, the first unique hash index, and the identification information of the first original data to the blockchain, the method further includes: Generate a calculation request according to the public key, the first ciphertext, a calculation method, and a calculation result format; A calculation request is initiated to the collaborative computing party through the blockchain, so that the collaborative computing party obtains the calculation result based on the public key, the first ciphertext, the calculation method and the calculation result form, combined with the second ciphertext of the collaborative computing party, and uploads the calculation result to the blockchain.

7. The method according to claim 6, characterized in that After initiating a computing request to the collaborative computing party through the blockchain, the method further includes: Obtain the calculation result from the blockchain; The calculation result is decrypted using a preset decryption algorithm to obtain the target calculation result.

8. The method according to claim 7, characterized in that The method of using a preset decryption algorithm to decrypt the calculation result to obtain a target calculation result includes: Determining a private key component for decryption based on the private key; The calculation result is decrypted according to the private key component and the first ciphertext, and an auxiliary function in a preset decryption algorithm corresponding to the preset encryption algorithm to obtain a target calculation result.

9. A data sharing method, characterized in that: Applied to a collaborative computing party, the method includes: Obtain at least one of the first ciphertext, the first unique hash index, and identification information of the first original data from the blockchain; Among them, the identification information of the first ciphertext, the first unique hash index and the first original data is that the initiator uses a key generation algorithm to generate a public key and a private key; obtains the first original data; uses a preset encryption algorithm to encrypt the first original data according to the public key and the private key to obtain the first ciphertext; uploads the first ciphertext to the InterPlanetary File System private cluster, so that the InterPlanetary File System private cluster generates the corresponding first unique hash index according to the first ciphertext; and after obtaining the first unique hash index in the InterPlanetary File System private cluster, uploads it to the blockchain.

10. The method according to claim 9, characterized in that After obtaining at least one of the first ciphertext, the first unique hash index, and the identification information of the first original data from the blockchain, the method further includes: Responding to a computation request initiated by the initiator through the blockchain; wherein the computation request is generated by the initiator based on the public key, the first ciphertext, the computation method, and the computation result format; Obtain a calculation result based on the public key, the first ciphertext, the calculation method, and the calculation result format, combined with the second ciphertext of the collaborative computing party; The calculation result is uploaded to the blockchain.

11. A data sharing device, characterized in that: Applied to an initiator, the device includes: A first generation module is used to generate a public key and a private key using a key generation algorithm; A first acquisition module, configured to acquire first original data; an encryption module, configured to encrypt the first original data using a preset encryption algorithm according to the public key and the private key to obtain a first ciphertext; A first uploading module, configured to upload the first ciphertext to an InterPlanetary File System private cluster, so that the InterPlanetary File System private cluster generates a corresponding first unique hash index according to the first ciphertext; A second acquisition module is used to obtain a first unique hash index in the InterPlanetary File System private cluster; The second uploading module is used to upload the first ciphertext, the first unique hash index and the identification information of the first original data to the blockchain, so that the collaborative computing party obtains at least one of the first ciphertext, the first unique hash index and the identification information of the first original data from the blockchain.

12. A data sharing device, characterized in that: Applied to collaborative computing, the device includes: A third acquisition module is configured to acquire at least one of the first ciphertext, the first unique hash index, and identification information of the first original data from the blockchain; Among them, the identification information of the first ciphertext, the first unique hash index and the first original data is that the initiator uses a key generation algorithm to generate a public key and a private key; obtains the first original data; uses a preset encryption algorithm to encrypt the first original data according to the public key and the private key to obtain the first ciphertext; uploads the first ciphertext to the InterPlanetary File System private cluster, so that the InterPlanetary File System private cluster generates the corresponding first unique hash index according to the first ciphertext; and after obtaining the first unique hash index in the InterPlanetary File System private cluster, uploads it to the blockchain.

13. An electronic device, characterized in that: include: a processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 8 or claim 9 or 10.

14. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 8 or claim 9 or 10 when executed by a processor.